An APT attack detection system and detection method based on the industrial Internet of Things

By designing a RAPTOR system, using multiple data sources to detect industrial IoT APT attacks, the limitations of detection solutions in the existing technology are solved, early and network-wide angle detection and accurate reconstruction of APT attacks are realized, and useful APT activity diagrams are constructed.

CN116436691BActive Publication Date: 2025-07-29SHIZUISHAN POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310502160.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2025-07-29
Estimated Expiration
2043-05-04

AI Technical Summary

Technical Problem

The existing industrial Internet of Things systems have limitations in detection solutions when detecting APT attacks. They cannot effectively utilize multiple data sources, cannot detect in real time, and lack detection of APT attacks across the entire network. The data set lacks multi-stage attack characteristics and cannot accurately reconstruct APT attack activities.

Method used

A detection APT attack system based on the industrial Internet of Things was designed. The best data source was tracked from multiple data sources through the data acquisition module, and the function extraction module was used to perform function extraction and aggregation detection scores in the APT attack stage. The APT attack stage detection & association engine module was used to detect the invariant APT attack stage in ISAM, and generate APT activity maps.

Benefits of technology

It realizes early detection of APT attacks in an industrial Internet of Things environment, uses multiple data sources to improve detection accuracy, build compact APT activity maps, and provides support for network security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0004214208540000041
    Figure BDA0004214208540000041
  • Figure BDA0004214208540000042
    Figure BDA0004214208540000042
  • Figure BDA0004214208540000151
    Figure BDA0004214208540000151
Patent Text Reader

Abstract

The present invention provides a detection APT attack system and a detection method based on the industrial Internet of Things, belonging to the field of industrial Internet of Things. The system includes: a data acquisition module that traces a predetermined optimal data source for detecting different attack stages of APT from data of various sources; a data preparation module that compresses and stores the acquired data source; a function extraction module that scans the data source in real time for function extraction of different attack stages of APT, and obtains a deterministic optimal data source through an aggregated detection scoring method; a function processing module that performs APT function detection on the data set corresponding to the deterministic optimal data source to obtain characteristics of different attack stages of APT; an APT attack stage detection & correlation engine module that uses the deterministic optimal data source and the characteristics of different attack stages of APT to detect invariant APT attack stages in the ISAM, and correlates attack stages using the attributes of the APT attack stages; an APT activity graph generation module that obtains an APT activity graph using the relevance of the APT attack stages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of industrial Internet of Things, and particularly relates to a detection APT attack system and a detection method based on the industrial Internet of Things. Background Art

[0002] The Internet of Things (IoT) is a network of low-power and limited-processing-capability sensing devices that exchange data with each other and with or systems (such as gateways, cloud servers), typically using wired and wireless technologies. The Industrial Internet of Things (IIoT) refers to the extension of the IoT in the industrial domain and application areas. With the high attention of the IIoT to machine-to-machine (M2M) communication, big data, and machine learning, the IIoT enables industries and enterprises to have higher efficiency and reliability in operations. The difference between the industrial Internet of Things and the Internet of Things lies in the intersection of information technology (IT) and operational technology (OT). However, this convergence expands the attack surface and increases the potential risk of launching cyberattacks against such critical systems. An even more important issue is related to traditional OT systems, which are usually isolated but are becoming increasingly closely connected to new IT technologies. Sophisticated attackers can easily access such industrial Internet of Things systems and disrupt their operations for a long time.

[0003] Compared with traditional ICS (Industrial Control System) and OT (Operational Technology) networks, IIoT systems are more vulnerable to APT adversaries, mainly because of the increased connection to the IT network (allowing attackers to move laterally), and the introduction of M2M communication, connecting various new types of intelligent devices. In addition, the ICS itself is also a major target of APT attacks. This is because ICS devices usually run on legacy proprietary software that was not designed with security in mind and is not patched or updated regularly due to concerns about downtime of critical systems. APT attacks can be used to collect intelligence related to ICS, disrupt industrial processes, shut down critical systems, and endanger human lives. Such APT attacks launched by well-resourced groups have occurred many times in the past.

[0004] Security solutions commonly deployed in IT networks, such as firewalls, NIDS (Network Intrusion Detection System), and SIEM (Security Information and Event Management) products, are not common in ICS and OT networks. Therefore, there is an urgent need to design a system that can detect ongoing APT attack activities early in the industrial Internet of Things environment to avoid major damage. Such a system should meet the following requirements:

[0005] 1) It does not rely on the deployment of proprietary third-party security solutions, whose functions may vary depending on the vendor. Instead, the system should operate using existing open-source code and off-the-shelf information sources.

[0006] 2) Detect APT attack strategies with high accuracy and low false positive or false negative rates.

[0007] 3) Be able to reconstruct APT attack activities with sufficient details and present them in a compact, high-level form for cybersecurity analysts to use for further analysis and mitigation of attacks.

[0008] In recent years, APT detection in enterprise network setups has received great attention in computer security literature, but there are certain limitations:

[0009] 1) Most are only targeted at enterprise networks and are not applicable to industrial IoT.

[0010] 2) Most are designed using audit log-based sources. For example, some are designed using enterprise logs, and some are designed using network IDS alerts. Since these works are all based on a single data source, they cannot utilize the information provided by other data sources. In addition, these works can only detect a subset of the APT attack phases.

[0011] 3) Among them, graph-based methods specifically tend to suffer from the problem of dependency explosion, which means that over time, each graph node generates many edges, and these edges generate new nodes, and so on. Backtracking to infer paths through the graph will exponentially increase the number of possible paths.

[0012] 4) Some solutions work offline rather than in real time, which means they assume that all the data required for APT detection is available at once. Although some solutions claim that they work in real time, they do not provide the time delays encountered in APT detection.

[0013] 5) The vast majority of the other works mentioned above do not detect APT activities from a whole-network perspective.

[0014] Moreover, when detecting APT, datasets in ICS (Industrial Control Systems) are utilized, but existing datasets all have certain limitations:

[0015] 1) Many existing ICS datasets highly depend on features related to sensor measurements, actuator states, and specific parameters of industrial protocol packets, which limits their use in different industrial systems.

[0016] 2) Most datasets lack clear attack classifications and do not incorporate multi-stage attacks related to updated IIoT connection protocols and services (such as CoAP, MQTT).

[0017] 3) The X-IIoTID dataset addresses the above-mentioned drawbacks of previous datasets. However, all of the above datasets, including X-IIoTID, only provide pre-determined ML features extracted from network flows and do not include the original traffic traces from which additional features can be extracted. Additionally, the X-IIoTID dataset only provides host logs and IDS alert logs collected at the edge gateway because, according to the dataset authors, the edge gateway is the highest-priority target for attackers. The dataset does not include APT activities.

[0018] Therefore, how to implement an effective solution for detecting APT activities in the industrial Internet of Things environment to address the above-mentioned deficiencies is an urgent problem to be solved in this field. Summary of the Invention

[0019] To solve the above problems existing in the prior art, the present invention provides a detection APT attack system and a detection method based on the industrial Internet of Things. The technical problems to be solved by the present invention are achieved through the following technical solutions:

[0020] In a first aspect, an embodiment of the present invention provides a detection APT attack system based on the industrial Internet of Things, including:

[0021] A data acquisition module for tracing pre-determined optimal data sources for detecting different attack stages of industrial Internet of Things APT from data of various sources;

[0022] A data preparation module for compressing and storing the acquired data sources;

[0023] A function extraction module for real-time scanning of the compressed and stored data sources for function extraction of different attack stages of APT and obtaining a deterministic optimal data source through an aggregated detection scoring method; wherein the function extraction includes command and control, discovery, lateral movement, fieldbus scanning, and CE communication spoofing;

[0024] A function processing module for performing APT function detection on the dataset corresponding to the deterministic optimal data source to obtain features of different attack stages of APT;

[0025] An APT attack stage detection & correlation engine module for using the deterministic optimal data source and the features of different attack stages of APT to detect invariant APT attack stages in the ISAM and correlating attack stages using the attributes of the APT attack stages;

[0026] An APT activity graph generation module for obtaining an APT activity graph using the correlation of APT attack stages.

[0027] In an embodiment of the present invention, the tracing of pre-determined optimal data sources for detecting different attack stages of industrial Internet of Things APT from data of various sources includes:

[0028] The best data source is obtained through network traffic tracking in different stages of APT attacks, the best data source is obtained through IDS alerts in the discovery stage and fieldbus scanning stage, and the best data source is obtained through host logs in the lateral movement stage.

[0029] In one embodiment of the present invention, the formula used in the aggregated detection scoring method includes:

[0030]

[0031] Π ia is defined as:

[0032]

[0033] where a∈{command and control, discovery, lateral movement, fieldbus scanning, CE communication spoofing}; d a represents the aggregated detection score of a; wi a is the weight assigned to the i-th data source for detecting attack phase a, which is also the indicator function; ia In the example, =A indicates that the data source is the optimal detection for attack phase a; ≠A indicates that the data source is not the optimal detection for attack phase a; the weight assigned to the primary optimal data source determined for the attack phase is greater than the weight assigned to the secondary optimal data source. If the aggregate detection score d a If it is greater than the predefined threshold τ, then the attack phase a is considered to have been detected, otherwise it is considered not detected.

[0034] In one embodiment of the present invention, the APT attack stage detection & correlation engine module adopts corresponding detection methods for different APT attack stages when performing APT attack stage detection; wherein,

[0035] The command and control phase detection method includes: filtering out the public network server IP addresses other than VPN servers from the network traffic trace, and sending or receiving TCP [PSH, ACK] and [ACK] / UDP packets to or from the IIoT test bed host IP address; if the filter generates multiple such packets, extracting the packet arrival time; and using an algorithm based on discrete time signal coding and autocorrelation function to test the periodicity of the previously obtained packet arrival time. If the packet arrival is found to be periodic, it is determined that the command and control phase has been detected;

[0036] The detection methods in the discovery stage include: decomposing the network traffic traces collected on the host into smaller traces at fixed time intervals; classifying each trace using an ML algorithm, where all traces are assumed to belong to either normal traces or scan traces; a normal trace in the discovery stage refers to a trace that does not contain network scan packets, and a scan trace refers to a trace that contains network scan packets; if a trace is classified as a scan trace, it is determined that the Discovery attack stage has been detected; for each trace, the features for ML classification are extracted only from the TCP / UDP headers, rather than from the payloads of the respective packets; among them, the ML features selected for scan traffic detection are the first type of preset ML features;

[0037] The detection methods in the lateral movement stage include: using the authentication logs on the network host for detection; and determining that a lateral movement between machines has been detected when a login meeting the preset suspicious attributes is found; among them, the logins with the preset suspicious attributes include: the machine from which the user starts to log in to another machine is part of other detected APT attack stages and usually precedes the lateral movement;

[0038] The detection methods in the fieldbus scanning stage include: splitting the network traffic traces collected from the network interface of the edge gateway connected to the control element into smaller traces at fixed time intervals; classifying each trace using an ML algorithm, where all traces are assumed to belong to either normal traces or fieldbus scan traces; a normal trace in the fieldbus scanning stage refers to a trace that does not contain fieldbus scan packets, and a fieldbus scan trace refers to a trace that contains fieldbus scan packets; if a trace is classified as a fieldbus scan trace, it is determined that the fieldbus scan attack stage has been detected; for each trace, the features for ML classification are extracted only from the TCP headers, rather than from the payloads of the respective packets; among them, the ML features selected for scan traffic detection are the second type of preset ML features;

[0039] The detection methods in the CE communication spoofing stage include: determining that the CE communication spoofing stage has been detected if there are multiple TCP connections from the edge gateway to the control element on the target port specific to the IA protocol, or if the original TCP connection has been terminated.

[0040] In an embodiment of the present invention, the first type of preset ML features includes:

[0041] The unique number of TCP SYN / UDP destination IP addresses;

[0042] The number of unique TCP SYN / UDP destination ports for each destination IP address, including the maximum value, minimum value, and average value;

[0043] The number of TCP half-open connections;

[0044] Number of TCP RESET packets;

[0045] Packet length, including maximum value, minimum value, and average value;

[0046] Packet arrival interval time, including maximum value, minimum value, and average value.

[0047] In an embodiment of the present invention, the second type of preset ML features includes:

[0048] Number of TCP three-way handshakes based on the destination IP address, including maximum value, minimum value, and average value;

[0049] Number of TCP RESET messages;

[0050] Number of TCP FIN messages;

[0051] Message length, including number of bytes, maximum value, minimum value, and average value;

[0052] Message arrival interval time, including number of seconds, maximum value, minimum value, and average value.

[0053] In an embodiment of the present invention, the APT attack phase detection & correlation engine module is specifically used for:

[0054] Check whether the initial stage of command and control in the proposed ISAM can be detected on any enterprise-level Internet-facing host;

[0055] If the detection is successful, check the discovery stage on the same host where the command and control stage is detected;

[0056] If the discovery stage is detected, look for signs of the lateral movement stage on the same host;

[0057] If the lateral movement stage is detected, continue to check the discovery stage, and then perform the above-mentioned lateral movement stage on the host accessed after the lateral movement;

[0058] If the host accessed after the lateral movement is an edge gateway, start looking for the fieldbus scanning stage at the edge gateway. If detected, check whether the CE communication spoofing stage can be detected.

[0059] In an embodiment of the present invention, the APT activity graph generation module is specifically used for:

[0060] When the APT attack phase detection & correlation engine module detects each stage of APT activities, an APT activity graph is constructed by using the detected stages, their attribute information, and the relevance of the attack stages.

[0061] In one embodiment of the present invention, the process of constructing the APT activity diagram includes:

[0062] Step 1, generating a directed graph of the APT activity diagram;

[0063] Among them, the APT activity diagram is a directed graph G(V, E), where each node, N v is the total number of nodes in the graph, corresponding to a machine represented by its IP address, and is part of one of the detected attack phases; an edge, N e is the total number of edges in the graph;

[0064] Step 2, expanding and connecting APT nodes;

[0065] Among them, if in one or more phases of the APT attack, the machine corresponding to node v i is connected to the machine corresponding to node v k , then expand from node v i in the graph to another node v k ;

[0066] Step 3, defining the attributes of each edge;

[0067] Among them, each edge has an attribute, {s1, s2,...}, where is an attack phase that allows a connection between the two machines corresponding to the nodes at both ends of the edge.

[0068] In a second aspect, an embodiment of the present invention provides a method for detecting APT attacks based on industrial Internet of Things, which uses the system for detecting APT attacks based on industrial Internet of Things described in the first aspect to complete the detection.

[0069] Advantages of the present invention:

[0070] 1. A system RAPTOR for detecting ongoing APT activities in the industrial Internet of Things environment is proposed, filling the gap in detecting APT activities in the industrial Internet of Things environment;

[0071] 2. Data from various sources are used, such as network packet traces, host logs (including audit logs), and NIDS and HIDS alerts, rather than being limited to specific or proprietary data sources. The best data sources for detecting each APT attack phase are identified and used;

[0072] 3. A new dataset is used to evaluate the performance of RAPTOR, and this dataset includes attack TTPs close to real APT attacks in the ICS / OT environment;

[0073] 4. A new attack phase detection and correlation method is adopted, which uses open source and is easy to operate on the obtained data sources;

[0074] 5. In combination with APT detection in the IIoT setting that combines IT and OT environments, the APT attack phases for designing the detection system have been applied to the IIoT setting;

[0075] 6. APT activity detection is carried out from the perspective of the entire network, rather than detecting APT attacks only on a single host;

[0076] 7. RAPTOR constructs a compact and high-level APT activity graph, which is very useful for network security analysts. Description of the Drawings

[0077] Figure 1 It is a schematic diagram of the existing IIoT APT invariant state machine.

[0078] Figure 2 It is a schematic structural diagram of a detection APT attack system based on industrial Internet of Things provided by an embodiment of the present invention.

[0079] Figure 3 It is a flowchart of the method for detecting APT attacks based on industrial Internet of Things of the present invention. Detailed Embodiment

[0080] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0081] In order to facilitate the understanding of the solution of the embodiment of the present invention, first, a certain introduction to the relevant background technology is made.

[0082] IIoT (Industrial Internet of Things) systems are becoming increasingly vulnerable to attacks by APT (Advanced Persistent Threat) adversaries. Past APT attacks on industrial Internet of Things systems, such as the attack on the Ukrainian power grid in 2016 that caused a one-hour power outage in the capital Kiev; the attack on a Saudi petrochemical plant in 2017 that almost shut down the plant's safety controller, which indicates that APT attacks can disrupt industrial processes, shut down critical systems and endanger human lives.

[0083] In recent years, APT detection in enterprise network settings has received significant attention in computer security literature. For example, Milajerdi et al. proposed a high-confidence APT campaign detection system called HOLMES. It maps the activities in host audit logs and enterprise security alerts to the cyber kill chain, correlates the alerts generated by APT steps based on the information flow between low-level entities (files, processes, etc.), and constructs a high-level scenario graph encapsulating the information flow between the attack TTPs and the entities involved in the TTPs. CONAN is an APT detection system that makes two main modifications to the method of HOLMES: First, it utilizes a state-based detection framework where all processes and files are represented as data structures similar to finite state automata; second, it focuses on three continuous attack phases of APT: 1) deploying and executing the attacker's code, 2) collecting sensitive information or causing damage, 3) communicating with the C&C server or stealing sensitive data. Wilkens et al. proposed a method for constructing an APT attack graph from intrusion detection system (IDS) alerts to assist human analysts. The IDS alerts are clustered into meta-alerts and individual alerts, assigned potential attack phases, and finally used to synthesize an APT scenario graph based on the kill chain state machine.

[0084] Irshad et al. proposed TRACE, a provenance tracking system for enterprise-level APT detection. TRACE provides host-level provenance tracking at the granularity of program execution units and integrates the provenance collected from individual hosts to construct a distributed enterprise-wide causal graph. Hopper focuses on detecting a single APT attack phase: lateral movement within the enterprise network. It does this by constructing a login activity graph between the machines in the network and identifying suspicious login sequences. Then a path inference algorithm is deployed to identify the broader paths to which each login "caused" by the same user belongs. Finally, an anomaly detection algorithm is applied to conservatively infer the set of login paths that are most likely to reflect lateral movement. However, all of the above work has certain limitations (as described previously).

[0085] And, in the past, researchers have built datasets (including network traffic, system logs, etc.) to design IDSs for ICS (Industrial Control Systems). Morris et al. provided a labeled dataset that includes network traffic captured during the normal operation of a laboratory-scale natural gas pipeline system, as well as during 35 network attacks affecting the Modbus protocol (such as reconnaissance, response injection, command injection, and DoS). Similarly, Pan et al. have generated a dataset consisting of synchronized phasor measurement data and audit logs from a power system test bench, with a total of 10,000 simulated instances. The dataset includes 25 scenarios, including single-line-to-ground (SLG) faults, normal operation, and network attacks (relay trip command injection, relay function disabling, and SLG fault replay) in the power system. Another dataset has been collected from the Secure Water Treatment (SWaT) test bench

[17] , including sensor and actuator readings during normal operation and 36 attacks (such as bias attacks, replay, single-point, and multi-point attacks). The final dataset includes 946,772 samples and consists of 51 attributes.

[0086] Recently, Myers et al. generated two datasets consisting of ICS device logs and network traffic captures from two separate industrial process setups, during normal operation and during attacks (command injection, flood, etc.) on the test bench PLC. Marcio et al. built a dataset consisting of six pre-determined ML-based traffic level features extracted from network traffic captured during normal and attack operations from a SCADA system test bench consisting of a free water storage tank control system. Finally, Muna et al. proposed the X-IIoTID intrusion dataset for modern industrial IoT systems. The dataset covers various attack scenarios and attacks related to updated IIoT connection protocols generated according to predefined attack classifications. The data collected includes end-to-end network traffic (from physical field devices to edge gateways, from edge gateways to the cloud and enterprise devices), host logs and computing resources, and IDS warning logs (OSSEC, Zeek) collected by the edge gateway during normal operation and when the test bench is attacked. The final dataset consists of 820,834 instances and 59 features. However, all of the above datasets have certain limitations (as described previously).

[0087] Regarding the existing IIoT attack framework, Muna et al. proposed a general industrial IoT attack lifecycle framework, including the following stages: reconnaissance, weaponization, exploitation, lateral movement, command and control, infiltration, and tampering. MITRE also released the Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework for ICS, including the following tactics and stages: initial access, execution, persistence, privilege escalation, evasion, discovery, lateral movement, collection, command and control, suppression of response functions, compromise of process control, and impact.

[0088] Regarding the detection of APT attack endpoints in the existing technology, it should be noted that real APT campaigns in the industrial Internet of Things (IIoT) environment do not follow all the stages in the above attack framework. In addition, each tactic in the attack framework contains many techniques, and new techniques are regularly added. It is almost impossible to simulate all possible attack techniques and then use them for detection in continuous APT activities. Therefore, using the IIoT attack lifecycle framework and the MITRE ATT&CK framework for ICS, certain "invariant" attack stages / tactics have been identified: command and control, discovery, lateral movement, fieldbus scanning, and CE communication spoofing. These attack tactics include only a few techniques, and these techniques have not changed significantly in APT campaigns over the years (and are not expected to change significantly in the future). It is easier to model these invariant attack tactics and use them for APT detection. See Figure 1 the IIoT APT Invariant State Machine (IASM) shown in , which models typical APT activities in the IIoT environment as a finite state machine. The states in the IASM represent the states of APT movement, and the state transitions are brought about by the deployment of the previously identified invariant APT tactics. In the industrial Internet of Things environment, most real APT activities follow the proposed IASM.

[0089] Among them, the IASM is described as follows: Once APT attackers obtain all the resources and information required for an attack campaign (ready-to-attack state), they will enter the target IIoT network (infected entry host state) by compromising one or more hosts facing the public network and establish communication with a command and control server or C&C server (establishing a foothold state). Next, the attackers scan other hosts connected to the infected machine and attempt to gain control of one of the discovered hosts (infected new host state) by exploiting a CVE vulnerability or stealing the remote access credentials of the discovered host and then logging in. The attackers may attempt to move through the IIoT network by gaining control of more hosts, thus maintaining the same infected new host state and using the same strategy outlined above. Once the attackers reach the edge gateway (infected edge gateway phase), they scan the control elements (PLC / RTU / SIS) and their slave devices connected via fieldbus protocols. Fieldbus refers to Modbus and other similar open-source or proprietary vendor protocols (e.g., Profibus / Profinet, CAN) used to communicate with their respective vendor control elements. Subsequently, they spoof the communication with the discovered control elements and their slave servers to obtain more information about them (collecting ICS intelligence state) and remotely execute commands on the control elements (executing CE commands state). Depending on the goals set by the APT adversary (merely collecting ICS intelligence or executing the required commands on the CE), they may deliberately or forcefully end the activity due to detection by cybersecurity analysts (goal achieved or APT detected state).

[0090] Regarding the main threat model of the current industrial Internet of Things, it is assumed that only a few machines in the enterprise layer of the target IIoT network are connected to the Internet (through firewalls / IDS). All other machines in the enterprise layer and other layers (platform layer, edge layer) are isolated from the Internet, although some of them can still communicate with the machines connected to the Internet in the enterprise layer. APT attackers can enter the target IIoT network through enterprise-level machines facing the Internet (remote access) or other machines accessible to factory operators / engineers (internal attack). Once inside the enterprise-level network, the attackers can move laterally between machines until they reach the edge layer consisting of edge gateways, control elements, and sensors / actuators. The attackers are considered resource-rich in terms of computing resources, financial support, hacking techniques, and time, which is true for most APT organizations.

[0091] Based on the above, for APT detection, the inventors analyzed and found that an APT campaign usually consists of various stages that occur one after another (to be described later). However, not all the stages defined in the existing attack frameworks appear simultaneously in real-world APT attacks. Each stage of an APT campaign is associated with the previously executed stage. For example, in terms of the chronological order of execution, the target host is affected. Therefore, if some individual attack stages can be detected, the above fact can be used to correlate the detected stages and reconstruct the APT campaign within a certain acceptable error range.

[0092] Based on this analysis, to address the limitations of the X-IIoTID dataset in APT detection, an embodiment of the present invention provides a system for detecting APT attacks based on the industrial Internet of Things, abbreviated as RAPTOR. In this system, a new dataset is constructed using an IIoT test platform based on the Brown-IIoTbed architecture. The dataset includes raw traffic traces from the test platform hosts, host logs, audit-based host system sources, as well as host or network IDS alerts, individual APT attack stages, and APT campaigns based on real attacks collected during the normal operation of the test platform. The dataset also includes IIoT-specific attack stages / tactics. The following is a specific description.

[0093] In a first aspect, an embodiment of the present invention provides a system for detecting APT attacks based on the industrial Internet of Things. As Figure 2 shown, the system for detecting APT attacks based on the industrial Internet of Things may include:

[0094] A data acquisition module, configured to trace predetermined optimal data sources for detecting different attack stages of industrial Internet of Things APT from data of various sources;

[0095] A data preparation module, configured to compress and store the acquired data sources;

[0096] A function extraction module, configured to perform real-time scanning of the compressed and stored data sources for function extraction of different APT attack stages, and obtain a deterministic optimal data source through an aggregated detection scoring method; wherein, the function extraction includes command and control, discovery, lateral movement, fieldbus scanning, and CE communication spoofing;

[0097] A function processing module, configured to perform APT function detection on the dataset corresponding to the deterministic optimal data source to obtain characteristics of different APT attack stages;

[0098] An APT attack stage detection & correlation engine module, configured to use the deterministic optimal data source and the characteristics of different APT attack stages to detect invariant APT attack stages in the ISAM, and correlate attack stages using the attributes of the APT attack stages;

[0099] An APT activity graph generation module, which is used to obtain an APT activity graph by using the relevance of APT attack phases.

[0100] Generally speaking, RAPTOR proposed in the embodiments of the present invention uses data from different sources, such as network traffic traces, audit logs, HIDS / NIDS alerts, and host logs. The data is processed before feature extraction and then processed before sending the features to the APT attack phase detection and correlation engine, which uses a predetermined optimal data source to detect invariant APT attack phases in the ISAM. The specific detection method for detecting attack phases will be explained later. The attributes of the attack phases are used to detect and correlate the attack phases, and the APT activities are reconstructed, which are presented in the form of a graph. Network security analysts can use the APT activity graph (ACG) constructed in this way to propose appropriate actions to mitigate attack activities or conduct forensic analysis.

[0101] The following is a specific description.

[0102] Regarding the data acquisition module, as described above, the embodiments of the present invention use data from various sources for APT detection instead of limiting themselves to specific or proprietary data sources. However, not all of these data sources are required to detect each APT phase. Compared with other data sources, some data sources may be redundant or have limitations. Therefore, the embodiments of the present invention analyze the data sources in the context of each invariant APT phase and select the optimal data source.

[0103] 1) Command and control: Most rootkits and malware regularly exchange keep-alive packets with the C&C server to maintain the connection throughout the infection, which can be captured by network traffic traces. By default, network IDS rules are not configured to detect C&C server message exchanges. Audit-based sources that capture network socket file read or write operations can also be used to detect connections established between compromised hosts and public C&C servers. However, due to the problems of pruning false dependencies originating from benign activities and noise in the source graph, the embodiments of the present invention believe that using audit-based sources to extract C&C communications may not justify the resulting computational cost. Therefore, only network traffic traces are sufficient for this purpose.

[0104] 2) Discovery: This stage can be detected through network traffic tracing because scanning other targets causes TCP / UDP packets to be sent from the compromised machine to other machines in the target network. This stage can also be detected from the alerts generated by open-source network IDSs (such as Snort or Suricata). However, not all organizations can deploy network IDSes. Additionally, slow and stealthy scans may be able to completely avoid IDSes. If network IDS alerts are available, embodiments of the present invention can use them to improve the accuracy of detection.

[0105] 3) Lateral movement: This stage can be detected through login logs on the target computer because during lateral movement, the attacker logs in to target computers that are connected to the same or a different subnet as the compromised computer. IDS alerts are not helpful for detecting lateral movement because by default, IDS rules are not configured to do so, and lateral movement is not as frequent as the events that IDSes are expected to detect (such as DoS attacks, port scans, SMB probes, etc.). Network traffic traces can contain evidence of lateral movement in the TCP or UDP packets exchanged between the compromised source machine and the target machine, and thus, they can be used to improve the accuracy of lateral movement detection.

[0106] 4) Fieldbus scanning: This stage can be detected through network traffic tracing because scanning target control elements through the fieldbus protocol causes TCP packets to be sent from the edge gateway to the connection control element on a specific port number. This stage can also be detected from the alerts generated by open-source network IDSs (such as Snort or Suricata) configured with custom modules. If network IDS alerts are available, embodiments of the present invention can use them to improve the accuracy of detection.

[0107] 5) CE communication spoofing: Since the attacker needs to send appropriately crafted packets on the link between the edge gateway and the control element, network traffic tracing can be used to detect the attacker's spoofing of control element communication.

[0108] The research results of embodiments of the present invention regarding the predetermined optimal data sources for detecting various APT attack stages in the industrial Internet of Things are summarized in Table 1.

[0109] Table 1

[0110] Attack Phase Audit Origin Network Traffic Tracking IDS Alert Host Log Command and Control × √ × × Discovery × √(P) √ × Lateral Movement × √ × √(P) Fieldbus Scanning × √(P) √ × CE Communication Spoofing × √ × ×

[0111] That is, tracing the predetermined optimal data sources for detecting different attack stages of APT in the industrial Internet of Things from data from various sources includes:

[0112] During different attack stages of APT, predetermined optimal data sources are obtained through network traffic tracing, and in the discovery stage and fieldbus scanning stage, predetermined optimal data sources are obtained through IDS alerts, and in the lateral movement stage, predetermined optimal data sources are obtained through host logs.

[0113] In this article, the predetermined optimal data source can be directly used as the deterministic optimal data source, or further determined through a function extraction module.

[0114] For the function extraction module, according to the previous description, multiple data sources can be used to detect each APT attack stage. For an attack stage, a ∈ {command and control, discovery, lateral movement, fieldbus scanning, CE communication spoofing}, the function extraction module can implement multi-data source detection, specifically realized by using an aggregated detection scoring method. Among them, the formula adopted by the aggregated detection scoring method includes:

[0115]

[0116] Π ia is defined as:

[0117]

[0118] where a ∈ {command and control, discovery, lateral movement, fieldbus scanning, CE communication spoofing}; d a represents the aggregated detection score of a; wi a is the weight assigned to the i-th data source for detecting the attack stage a, and is also an index function; in Π ia = A means that the data source is the optimal detection for the attack stage a; ≠ A means that the data source is not the optimal detection for the attack stage a; the weight assigned to the main optimal data source determined for the attack stage is greater than the weight assigned to the secondary optimal data source. If the aggregated detection score d a is greater than the predefined threshold τ, it is considered that the attack stage a has been detected, otherwise it is considered not detected. At this time, the deterministic optimal data source refers to the predetermined optimal data source that satisfies the condition d a > τ.

[0119] Regarding the APT attack stage detection & correlation engine module, first, the APT attack stage detection is analyzed and explained.

[0120] When the APT attack stage detection & correlation engine module performs APT attack stage detection, corresponding detection methods are adopted for different APT attack stages; among them,

[0121] ①In the command and control phase, the compromised machine establishes a connection with the C&C server, which is a public server, and communicates with it regularly. Therefore, if there are multiple packet exchanges for the public IP address of a suspected host, it indicates that the host communicates with the C&C server. In an embodiment of the present invention, TCP [PSH, ACK] and [ACK] / UDP packets sent or received by the public server IP address (except for VPN servers) to the IIoT test bench host IP address are filtered from the network traffic trace (pcap format). If the filter generates multiple such packets, the embodiment of the present invention extracts the packet arrival time. In addition, since many malware forces periodic communication between the compromised machine and the C&C server, the embodiment of the present invention uses an algorithm based on discrete-time signal coding and autocorrelation function proposed in the prior art to test the periodicity of the previously obtained packet arrival times. If it is found that the packet arrivals are periodic, it can be inferred that the command and control phase has been detected. It should be noted that there may be machines in the enterprise layer that communicate with public servers. For example, web pages are retrieved from a web server via HTTPS. Packets exchanged with these legitimate public servers contribute noise to the detection of the time period we extracted. The ACF (autocorrelation function) can reliably detect the presence of periodic noise.

[0122] Therefore, the detection method for the command and control phase includes: filtering the public server IP address except for the VPN server from the network traffic trace, sending or receiving TCP [PSH, ACK] and [ACK] / UDP packets of the IIoT test bench host IP address; if the filter generates multiple such packets, extracting the packet arrival time; and using an algorithm based on discrete-time signal coding and autocorrelation function to test the periodicity of the previously obtained packet arrival times. If it is found that the packet arrivals are periodic, it is determined that the command and control phase has been detected.

[0123] ②The detection method for the discovery phase includes: decomposing the network traffic trace collected on the host into smaller traces of a fixed time; using an ML algorithm for classification for each trace, such as a decision tree, SVM, etc.; where all traces are assumed to belong to a normal trace or a scan trace; a normal trace in the discovery phase refers to a trace that does not contain network scan packets, and a scan trace refers to a trace that contains network scan packets; if the trace is classified as a scan trace, it is determined that the Discovery attack phase has been detected; for each trace, the features for ML classification are extracted only from the TCP / UDP headers, rather than from the payloads of the respective packets, because the network traffic may be encrypted. Among them, the selected ML features for scan traffic detection are the first type of preset ML features;

[0124] Among them, the first type of preset ML features includes:

[0125] The unique number of TCP SYN / UDP destination IP addresses;

[0126] The number of unique TCP SYN / UDP destination ports for each destination IP address, including the maximum value, minimum value, and average value;

[0127] The number of TCP half-open connections;

[0128] The number of TCP RESET packets;

[0129] Packet length, including the maximum value, minimum value, and average value;

[0130] Packet arrival interval time, including the maximum value, minimum value, and average value.

[0131] The motivation behind the feature selection in the discovery phase is as follows: The intuition behind selecting the first two features is that port scanning tools used by attackers send TCP / UDP requests to multiple IP addresses to find open ports and services running on these ports. The third set of features is selected because during the port scanning process for an IP address, many TCP connection requests are sent to ports that are not open and no response / acknowledgment is sent back, thus forming TCP connections that remain half-open. The fourth feature attempts to utilize the fact that once a TCP connection is formed with an IP address on a certain port number, the port scanning tool only exchanges data for a short period of time, and then the connection will be reset. Compared with the packet length in a normal TCP connection, the port scanning packet length is usually shorter, which makes the fifth set of features useful for classification. Finally, the goal of the sixth feature set is the short time interval between the transmissions of port scanning packets compared with normal packets.

[0132] ③In the lateral movement phase, according to the method of the embodiment of the present invention, the authentication logs on the network host are used to detect this phase. The embodiment of the present invention looks for logins that meet the following suspicious attributes: The machine from which the user starts to log in to another machine is part of other detected APT attack phases, usually preceding the lateral movement, for example, command and control and discovery. For example, if user1 logs in from machine a to machine b, and machine a is in a different subnet, since machine b and machine a have been identified as part of the previously detected discovery phase, the embodiment of the present invention can conclude that a lateral movement from machine a to machine b has been detected.

[0133] Therefore, the detection method for the lateral movement stage includes: detecting using the authentication logs on the network host; and determining that a lateral movement between machines has been detected when a login meeting the preset suspicious attributes is found; wherein, the login with the preset suspicious attributes includes: the machine where the user starts to log in to another machine is part of other detected APT attack stages and usually precedes the lateral movement.

[0134] ④ The fieldbus scanning stage is similar to the discovery stage in detection. Specifically:

[0135] The detection method for the fieldbus scanning stage includes: splitting the network traffic traces collected from the edge gateway network interface connected to the control element into smaller traces of a fixed time; classifying each trace using the ML algorithm, where all traces are assumed to belong to normal traces or fieldbus scanning traces; a normal trace in the fieldbus scanning stage refers to a trace that does not contain fieldbus scanning packets, and a fieldbus scanning trace refers to a trace that contains fieldbus scanning packets; if a trace is classified as a fieldbus scanning trace, it is determined that the fieldbus scanning attack stage has been detected; for each trace, the features for ML classification are only extracted from the TCP header, rather than from the payloads of individual data packets, because the network traffic may be encrypted; among them, the ML features selected for scan traffic detection are the second type of preset ML features;

[0136] The second type of preset ML features includes:

[0137] The number of TCP three-way handshakes based on the destination IP address, including the maximum value, minimum value, and average value;

[0138] The number of TCP RESET packets;

[0139] The number of TCP FIN packets;

[0140] The packet length, including the number of bytes, maximum value, minimum value, and average value;

[0141] The packet arrival interval time, including the number of seconds, maximum value, minimum value, and average value.

[0142] The motivation behind the feature selection in the fieldbus scanning stage is: The intuition behind selecting the first three features is that usually during fieldbus scanning, the attacker tries to establish a TCP connection with fieldbus devices (PLC / RTU), but the first few attempts are unsuccessful.

[0143] After the connection is established, the fieldbus scanner requests device enumeration data and finally closes the connection. If the scanner also attempts to enumerate fieldbus slaves, it traverses the list of slave IDs in sequence. Since there are no slave servers on all SIDs, the TCP connection may only be reset when the fieldbus scanner establishes a new connection. Similarly, compared with the packet length in a normal TCP connection, the fieldbus scan packet length is usually shorter, which makes the fourth set of features useful for classification. Finally, the goal of the fifth feature set is the short time interval between fieldbus scan packet transmissions compared with normal packets.

[0144] For easy visual display, see Table 2, which shows the comparison of the ML features selected for APT attack phase detection in the discovery phase and the fieldbus scan phase, that is, the comparison of the first type of preset ML features and the second type of preset ML features.

[0145] Table 2

[0146]

[0147] ⑤In the CE communication spoofing phase, if an attacker attempts to spoof communication with a control element using one of the standard industrial automation (IA) protocols (e.g., IEC 61850, IEC 61131-3), then there will be multiple TCP connections from the edge gateway to the control element on the target port specific to the IA protocol, or the original TCP connection will be terminated by the attacker, leaving only the attacker's TCP connection active.

[0148] Therefore, the detection method for the CE communication spoofing phase includes: if there are multiple TCP connections from the edge gateway to the control element on the target port specific to the IA protocol, or the original TCP connection has been terminated, it is determined that the CE communication spoofing phase has been detected.

[0149] Regarding the relevance of APT attack phases, three conditions need to be met for attack phase B to occur after attack phase A:

[0150] 1. The source IP address of phase A needs to match the source IP address of phase B.

[0151] 2. When phase A involves the attacker moving from one machine to another (e.g., lateral movement), then the destination IP address of phase A should match the source IP address of phase B.

[0152] 3. The timestamp of phase A should be earlier than the timestamp of phase B.

[0153] The APT attack phase detection & correlation engine module is specifically used for:

[0154] Check whether the initial stage of command and control in the proposed ISAM can be detected on any Internet-facing host at the enterprise level;

[0155] If the detection is successful, check the discovery stage on the same host where the command and control stage is detected;

[0156] If the discovery stage is detected, look for signs of the lateral movement stage on the same host;

[0157] If the lateral movement stage is detected, continue to check the discovery stage, and then perform the lateral movement stage as described above on the host accessed after the lateral movement; where,

[0158] If the host accessed after the lateral movement is an edge gateway, start looking for the fieldbus scanning stage at the edge gateway. If detected, check whether the CE communication spoofing stage can be detected.

[0159] Among them, the associated part engine of the APT attack stage detection & association engine module is abbreviated as ASDC.

[0160] The above complete attack stage detection and association algorithm is shown in Table 3.

[0161] Table 3

[0162]

[0163] Handling false positives or negatives in ML classification: RAPTOR is designed to handle false positives or negatives in ML-based detection. For example, let's assume there is a false positive, that is, a packet trace is classified as a scan, although it is normal, and the discovery stage is marked as detected. The ASDC engine will not detect the subsequent attack stages in the IASM. Therefore, RAPTOR will know that there is a false positive in detecting the early attack stages. It is also possible to have false negatives, that is, the packet trace is being scanned but is classified as normal. Therefore, the ASDC engine will not call the detection of the subsequent attack stages in the IASM. Embodiments of the present invention propose to handle false positives and negatives by adopting the pattern of classification results for a sufficient number of iterative packet traces.

[0164] For the APT activity graph generation module, where the APT activity graph generation module is specifically used for:

[0165] When the APT attack stage detection & association engine module detects each stage of APT activities, it constructs an APT activity graph by using the detected stages and their attribute information and the relevance of the attack stages.

[0166] Among them, the construction process of the APT activity graph includes:

[0167] Step 1, generate a directed graph of the APT activity diagram;

[0168] Among them, the APT activity diagram is a directed graph G(V,E), where each node, N v is the total number of nodes in the graph, corresponding to a machine represented by its IP address, which is part of one of the detected attack phases; an edge, N e is the total number of edges in the graph;

[0169] Step 2, expand and connect APT nodes;

[0170] Among them, if in one or more phases of the APT attack, the machine corresponding to node v i is connected to the machine corresponding to node v k , then expand from node v i in the graph to another node v k ;

[0171] Step 3, define the attributes of each edge;

[0172] Among them, each edge has an attribute, {s1, s2,...}, where is an attack phase that allows a connection between the two machines corresponding to the nodes at both ends of the edge.

[0173] The APT attack detection system based on industrial Internet of Things (abbreviation: RAPTOR) provided by the embodiments of the present invention is a system for detecting ongoing APT activities in the industrial Internet of Things environment. The embodiments of the present invention adopt a new attack phase detection and correlation method, which operates using open-source and easily obtainable data sources. At the same time, the embodiments of the present invention use RAPTOR to construct a compact and high-level APT activity diagram, which is very useful for network security analysts. Also, the embodiments of the present invention use a new dataset to evaluate the performance of RAPTOR, and this dataset includes attack TTPs close to real APT attacks in the ICS / OT environment.

[0174] The main component of RAPTOR in the embodiments of the present invention is the APT attack phase detection and correlation engine. It takes various off-the-shelf, non-proprietary data sources, such as host logs, network traffic traces, as input. The best data sources for detecting each APT attack phase are identified and used, and attack strategies are detected, including those specific to the IIoT environment, which are part of ongoing APT activities. RAPTOR combines APT detection in the IIoT settings of IT and OT environments. The APT attack phases for designing the detection system have been adapted to the IIoT settings. Then, they are pieced together according to the attributes of the attack strategies to generate an APT attack activity graph, which is a high-level representation of APT activities on the entire target IIoT network, enabling network security analysts to use it for analyzing and mitigating attacks. RAPTOR performs APT activity detection from the perspective of the entire network rather than detecting APT attacks only on a single host. The performance evaluation of its APT detection phase shows high precision and low false positive and negative rates, and it can construct an APT activity graph for APT attacks (modeled on real-world attacks on ICS / OT infrastructures) executed on the IIoT test platform in the embodiments of the present invention.

[0175] In a second aspect, please also refer to Figure 3 , embodiments of the present invention propose a method for detecting APT attacks based on industrial Internet of Things, characterized in that the detection is completed by using the APT attack detection system based on industrial Internet of Things described in the first aspect.

[0176] For specific content, please refer to the description in the first aspect and will not be elaborated here.

[0177] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. An APT attack detection system based on the industrial Internet of Things, characterized in that, Including: A data acquisition module, configured to trace pre-determined optimal data sources for detecting different attack stages of industrial Internet of Things APT from data of various sources, where the different attack stages of APT specifically refer to the command and control stage, discovery stage, lateral movement stage, fieldbus scanning stage, and CE communication spoofing stage in the development order; A data preparation module, configured to compress and store the data obtained from each of the pre-determined optimal data sources to form compressed stored data; A function extraction module, configured to scan the compressed stored data in real time for function extraction of the different attack stages of APT, and obtain a deterministic optimal data source through an aggregated detection scoring method; wherein, the function extraction includes command and control, discovery, lateral movement, fieldbus scanning, and CE communication spoofing; A function processing module, configured to perform APT function detection on the data set corresponding to the deterministic optimal data source to obtain characteristics of different attack stages of APT; An APT attack stage detection and correlation engine module, configured to use the deterministic optimal data source and the characteristics of different attack stages of APT to detect invariant APT attack stages in the ISAM, and correlate the different attack stages of APT using the attributes of the APT attack stages; An APT activity diagram generation module, configured to obtain an APT activity diagram using the correlation of different attack stages of APT; The tracing of pre-determined optimal data sources for detecting different attack stages of industrial Internet of Things APT from data of various sources includes: Obtaining pre-determined optimal data sources through network traffic tracing in each of the different attack stages of APT, and obtaining pre-determined optimal data sources for the discovery stage and the fieldbus scanning stage through IDS alerts, and obtaining pre-determined optimal data sources for the lateral movement stage through host logs; The formula adopted by the aggregated detection scoring method includes: Π ia is defined as: where a ∈ {command and control, discovery, lateral movement, fieldbus scanning, CE communication spoofing}; aggregated detection score d a represents the aggregated detection score for attack phase a; wi a is the weight assigned to the i-th data source for detecting the attack phase a, and is also an indicator function; Π ia in, =A indicates that the i-th data source is the optimal detection for the attack phase a; ≠A indicates that the data source is not the optimal detection for the attack phase a; if the aggregated detection score d a is greater than the predefined threshold τ, it is considered that the attack phase a has been detected, otherwise it is considered not detected.

2. The APT attack detection system based on the industrial Internet of Things according to claim 1, wherein The characteristics of different attack stages of APT include first-class preset ML characteristics and second-class preset ML characteristics, and the APT function detection is to detect the first-class preset ML characteristics and the second-class preset ML characteristics from the IP headers of the data set corresponding to the deterministic optimal data source, where: The first-class preset ML characteristics include: the number of unique TCP SYN / UDP destination IP addresses; the number of unique TCP SYN / UDP destination ports, the maximum value of the port number, the minimum value of the port number, and the average value of the port number for each TCP SYN / UDP destination IP address; the number of TCP half-open connections; the number of TCP RESET packets; the length of the TCP RESET packet, the maximum value of the TCP RESET packet, the minimum value of the TCP RESET packet, and the average value of the TCP RESET packet; the arrival interval time of the TCP RESET packet, the maximum value of the interval time, the minimum value of the interval time, and the average value of the interval time; The second type of preset ML features includes: the number of TCP three-way handshakes, the maximum value of the number of handshakes, the minimum value of the number of handshakes, and the average value of the number of handshakes based on the TCP SYN / UDP destination IP address; the number of TCP RESET packets; the number of TCP FIN packets; the packet length, including the number of bytes, the maximum length, the minimum length, and the average length; the packet arrival interval time, including the number of seconds, the maximum interval time, the minimum interval time, and the average interval time.

3. The detection APT attack system based on industrial Internet of things according to claim 2, characterized in that When performing APT attack stage detection, the APT attack stage detection and correlation engine module adopts corresponding detection methods for different APT attack stages; among them, The detection method for the command and control stage includes: the filter filters out the public network server IP addresses other than the VPN server from the network traffic trace, and sends or receives TCP [PSH,ACK] and [ACK] / UDP packets of the IIoT test bench host IP address; if the filter generates at least two packets, the packet arrival time is extracted; and an algorithm based on discrete-time signal coding and autocorrelation function is used to test the periodicity of the previously obtained packet arrival time. If it is found that the packet arrival is periodic, it is determined that the command and control stage has been detected; The detection method for the discovery stage includes: decomposing the network traffic trace collected on the host into smaller traces of a fixed time; using an ML algorithm to classify each trace, where all traces are assumed to belong to a normal trace or a scan trace; a normal trace in the discovery stage refers to a trace that does not contain network scan packets, and a scan trace refers to a trace that contains network scan packets; if a trace is classified as a scan trace, it is determined that the Discovery attack stage has been detected; for each trace, the features for ML classification are only extracted from the TCP / UDP headers, rather than from the payloads of the respective packets; among them, the ML features selected for scan traffic detection are the first type of preset ML features; The detection method for the lateral movement stage includes: using the host logs on the network host for detection; and determining that a lateral movement between machines has been detected when a login meeting the preset suspicious attributes is found; among them, the login with the preset suspicious attributes includes: the machine where the user starts to log in to another machine is part of other detected APT attack stages and usually precedes the lateral movement; The detection method in the fieldbus scanning stage includes: splitting the network traffic traces collected from the edge gateway network port connected to the control element into smaller traces of a fixed time; classifying each trace using an ML algorithm, where all traces are assumed to belong to normal traces or fieldbus scanning traces; a normal trace in the fieldbus scanning stage refers to a trace that does not contain fieldbus scanning packets, and a fieldbus scanning trace refers to a trace that contains fieldbus scanning packets; if a trace is classified as a fieldbus scanning trace, it is determined that the fieldbus scanning attack stage has been detected; for each trace, the features for ML classification are extracted only from the TCP header, rather than from the payloads of individual packets; among them, the ML features selected for scanning traffic detection are the second type of preset ML features; The detection method in the CE communication spoofing stage includes: if there are at least 2 TCP connections from the edge gateway to the control element on the target port of the IA protocol, or the original TCP connection has been terminated, it is determined that the CE communication spoofing stage has been detected.

4. The APT attack detection system based on industrial Internet of things according to claim 3, characterized in that The APT attack stage detection and correlation engine module is specifically used for: Checking whether the initial stage of the command and control stage in the proposed ISAM can be detected on any Internet-facing host at the enterprise level; If the detection is successful, the discovery stage will be checked on the same host where the command and control stage is detected; If the discovery stage is detected, signs of the lateral movement stage will be searched for on the same host; If signs of the lateral movement stage are detected, continue to check the discovery stage, and then perform the lateral movement stage on the host accessed after the lateral movement; If the host accessed after the lateral movement is the edge gateway, start looking for the fieldbus scanning stage at the edge gateway; if the fieldbus scanning stage is detected, check whether the CE communication spoofing stage can be detected.

5. The detection APT attack system based on the industrial Internet of Things according to claim 4, characterized in that The APT activity diagram generation module is specifically used for: When the APT attack stage detection and correlation engine module detects each stage of APT activity, an APT activity diagram is constructed by using the detected different APT attack stages and their attribute information and the correlation of the different APT attack stages.

6. A method for detecting APT attacks based on the industrial Internet of Things, characterized in that, Using the APT attack detection system based on industrial Internet of Things according to any one of claims 1 to 5 to complete the detection, the steps include: Step S1, tracing the predetermined optimal data sources for detecting different APT attack stages in industrial Internet of Things from data from various sources, and the different APT attack stages specifically refer to the command and control stage, discovery stage, lateral movement stage, fieldbus scanning stage, and CE communication spoofing stage in the development order; Step S2, compressing and storing the data obtained from each of the predetermined optimal data sources to form compressed stored data; Step S3, scanning the compressed stored data in real time to extract the functions of the different APT attack stages, and obtaining the deterministic optimal data source through an aggregated detection scoring method; among them, the function extraction includes command and control, discovery, lateral movement, fieldbus scanning, and CE communication spoofing; Step S4: Perform APT function detection on the dataset corresponding to the deterministic best data source to obtain the characteristics of different APT attack stages; Step S5: Use the deterministic best data source and the characteristics of different APT attack stages to detect the invariant APT attack stages in the ISAM, and associate the different APT attack stages using the attributes of the APT attack stages; Step S6: Obtain the APT activity graph using the relevance of different APT attack stages.

7. The method for detecting APT attacks based on industrial Internet of Things according to claim 6, characterized in that, The construction process of the APT activity graph includes: Step 1: Generate a directed graph of the APT activity graph; Among them, the APT activity diagram directed graph is denoted as the directed graph G(V, E), where v i is a node in the directed graph G(V, E), and v i ∈V N v is the total number of nodes in the directed graph G(V, E), and v i corresponds to a machine represented by an IP address; e j is an edge in the directed graph G(V, E), and e j ∈E N e is the total number of edges in the directed graph G(V, E); Step 2: Expand and connect APT nodes; Among them, if in at least one attack stage of the APT attack, the machine corresponding to node v i is connected to the machine corresponding to node v k , then in the directed graph G(V, E), node v i is extended to the node v k ; Step 3: Define the attributes of each edge; Among them, each edge e j has an attribute s representing the attack phase l , s l ∈ {Command and Control, Discovery, Lateral Movement, Fieldbus Scanning, CE Communication Spoofing}.

Citation Information

Patent Citations

  • Multi-step attack detection method based on multi-source abnormal event correlation analysis

    CN106790186A

  • Multidimensional deep-level APT (Advanced Persistent Threat) attack detection method

    CN107370755A