An industrial control system security threat response disposal method based on digital twinning
By constructing a security threat response and handling method for industrial control systems using digital twin technology and reinforcement learning, this method solves the problems of lack of flexibility and cross-domain conflicts in the response strategies of industrial control systems in existing technologies, and achieves efficient and accurate security threat response, ensuring the security and stability of industrial control systems.
Patent Information
- Application Number
- CN202310395555.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-13
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2043-04-13
AI Technical Summary
Existing security threat response and handling methods for industrial control systems rely on expert experience, making it difficult to flexibly handle different situations and failing to effectively combine the security requirements of the information domain and the physical domain, resulting in a lack of flexibility and comprehensiveness in response strategies.
A digital twin technology is used to construct a security threat response and handling method for industrial control systems. By detecting the status and attack types of industrial control systems, response strategies are found using a policy library. Combined with risk assessment and reinforcement learning, the best strategy is trained to build a twin system covering network information security and functional safety, achieving virtual-physical interconnection and rapid response.
It enables efficient and accurate response and handling of industrial control systems under network attacks, avoids dual security conflicts, provides highly realistic scenarios for cross-domain detection and verification, and ensures the security and stability of industrial control systems.
Smart Images

Figure CN116545656B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method for responding to and handling security threats to industrial control systems based on digital twins. Background Technology
[0002] In industrial control systems (ICS), attacks from the network not only affect cyberspace security but also industrial production in the physical environment. The rapid development of digitalization and networking makes transmission and communication functions in ICS vulnerable to malicious attacks. Consequently, the functional safety of the physical space is threatened due to cyberspace information security concerns. Both the physical and cyberspace aspects of ICS face new security challenges, and the interconnectedness and overlap between them make defense more difficult. Security mechanisms implemented in cyberspace may affect the physical space, and attacks on the physical space may also affect the analysis and judgment in cyberspace. Because the relationship between the information domain (cyberspace) and the physical domain (physical space) often relies on domain expert knowledge, existing response and handling methods are mostly based on fixed rule bases established through expert experience. On the one hand, this limits the applicable scenarios and makes it difficult to flexibly and dynamically handle different situations; on the other hand, it restricts the comprehensive or in-depth exploration of effective response and handling strategies due to limitations in expert experience.
[0003] Therefore, how to automate the construction of response and handling methods that meet information security and functional safety requirements as much as possible is an urgent problem to be solved. Summary of the Invention
[0004] In view of this, embodiments of the present invention provide a method for responding to and handling security threats to industrial control systems based on digital twins, so as to construct a response and handling method that meets the requirements of information security and functional safety.
[0005] One aspect of this invention provides a method for responding to and handling security threats in industrial control systems based on digital twins, comprising:
[0006] When an industrial control system is detected to be under a network attack, the current state of the industrial control system and the type of network attack are determined.
[0007] Search the preset strategy library for the target response strategy corresponding to the attack type;
[0008] If no corresponding target response strategy is found, multiple preset risk assessment methods will be used to conduct network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system, with risk values ranging from low to high.
[0009] The first risk assessment method that passes both network information security testing and industrial control equipment functional safety testing will be used as the emergency response strategy, and the emergency response strategy will be implemented.
[0010] Preferably, the target response strategy is used to protect the network information security of the industrial control system, and when the target response strategy is executed, the network information security of the industrial control system does not conflict with the security of the industrial control equipment.
[0011] Preferably, the construction process of the industrial control digital twin system includes:
[0012] Digital twins of general information equipment in industrial control systems are constructed using cloud virtualization technology;
[0013] Construct a timing diagram of the logical structure of the industrial control system;
[0014] Constructing a digital twin network for industrial networks;
[0015] The digital twin is connected to the control equipment in the industrial control system through a virtual-physical interconnection method, and an industrial control digital twin system is constructed based on the digital twin, the timing relationship diagram, and the digital twin network.
[0016] Preferably, if the physical state of the general information device changes, the state of the digital twin in the industrial control digital twin system changes synchronously with the physical state.
[0017] Preferably, it further includes:
[0018] The industrial control digital twin system is trained using simulated network attacks or from historical network attacks.
[0019] Preferably, it further includes:
[0020] The current state, the attack type, and the emergency response strategy are stored in the strategy library.
[0021] Preferably, it further includes:
[0022] When the industrial control system is attacked again, the parameters of the industrial control digital twin system are adjusted and the strategy library is updated according to the system status of the industrial control system, whether the industrial control equipment is turned on, and the reward function used to achieve the set expectation.
[0023] Another aspect of this invention provides a security threat response and handling device for industrial control systems based on digital twins, comprising:
[0024] An attack determination unit is used to determine the current state of the industrial control system and the type of network attack when a network attack is detected on the industrial control system.
[0025] The strategy lookup unit is used to search for the target response strategy corresponding to the attack type from a preset strategy library;
[0026] The risk assessment unit is used to perform network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system if no corresponding target response strategy is found. Multiple preset risk assessment methods are used to conduct network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system, with risk values ranging from low to high.
[0027] The strategy execution unit is used to take the first risk assessment method that passes network information security detection and industrial control equipment functional safety detection as the emergency response strategy and execute the emergency response strategy.
[0028] Preferably, the target response strategy is used to protect the network information security of the industrial control system, and when the target response strategy is executed, the network information security of the industrial control system does not conflict with the security of the industrial control equipment.
[0029] Preferably, it also includes a system building unit for building the industrial control digital twin system;
[0030] The system building unit includes:
[0031] The first building unit is used to construct digital twins of general information equipment in industrial control systems using cloud virtualization technology;
[0032] The second building unit is used to construct the timing diagram of the logic structure of the industrial control system.
[0033] The third building block is used to construct a digital twin network of the industrial network;
[0034] The fourth construction unit is used to connect the digital twin with the control equipment in the industrial control system through a virtual-physical interconnection method, and to construct the industrial control digital twin system based on the digital twin, the timing relationship diagram and the digital twin network.
[0035] Preferably, if the physical state of the general information device changes, the state of the digital twin in the industrial control digital twin system changes synchronously with the physical state.
[0036] Preferably, it further includes:
[0037] The system training unit is used to train the industrial control digital twin system using simulated network attacks or network attacks from historical records.
[0038] Preferably, it further includes:
[0039] The policy storage unit is used to store the current state, the attack type, and the emergency response policy in the policy library.
[0040] Preferably, it further includes:
[0041] The parameter processing unit is used to adjust the parameters of the industrial control digital twin system and update the strategy library when the industrial control system is attacked again, based on the system status of the industrial control system, whether the industrial control equipment is turned on, and the reward function used to achieve the set expectation.
[0042] Another aspect of the present invention provides an electronic device, including a processor and a memory;
[0043] The memory is used to store programs;
[0044] The processor executes the program to implement the above-described method.
[0045] Another aspect of this invention provides a computer-readable storage medium storing a program that is executed by a processor to implement the above-described method.
[0046] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions, causing the computer device to perform the method described above.
[0047] This invention provides a method for responding to and handling security threats to industrial control systems based on digital twins. The method includes: when a network attack is detected on the industrial control system, determining the current state of the system and the type of attack; searching a pre-set strategy library for a target response strategy corresponding to the attack type; if no corresponding target response strategy is found, performing network information security testing and industrial control equipment functional safety testing on the industrial control digital twin system using multiple pre-set risk assessment methods, ranked from low to high risk values; and executing the first risk assessment method that passes both network information security testing and industrial control equipment functional safety testing as an emergency response strategy. This invention constructs a twin system covering both cyberspace and physical space, realizing digital twins of the industrial control network and the industrial site, providing a highly realistic scenario for industrial control response and handling that meets cross-domain detection and verification requirements. Furthermore, this invention's strategy-based response and handling scheme proposes the construction of a strategy set for twin system conflict detection and the handling of realistic attack scenarios based on the strategy set, forming a rapid and efficient response and handling mechanism. Attached Figure Description
[0048] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 A flowchart illustrating a security threat response and handling method for an industrial control system based on digital twins, provided in an embodiment of the present invention;
[0050] Figure 2 A framework example diagram of a response and handling framework for an industrial control system based on digital twins provided in an embodiment of the present invention;
[0051] Figure 3 A flowchart illustrating a strategy set-based response handling method is provided as an embodiment of the present invention.
[0052] Figure 4 A flowchart illustrating a reinforcement learning-based training response handling strategy is provided as an embodiment of the present invention.
[0053] Figure 5 This is a structural block diagram of a security threat response and handling device for an industrial control system based on digital twin, provided in an embodiment of the present invention. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0055] Reference Figure 1 This invention provides a method for responding to and handling security threats in industrial control systems based on digital twins, specifically including the following steps:
[0056] Step S100: When an industrial control system is detected to be under a network attack, determine the current state of the industrial control system and the type of network attack.
[0057] Step S110: Search for the target response strategy corresponding to the attack type from the preset strategy library.
[0058] Specifically, the target response strategy is used to protect the network information security of the industrial control system, and when the target response strategy is executed, the network information security of the industrial control system does not conflict with the security of the industrial control equipment.
[0059] Step S120: If no corresponding target response strategy is found, multiple preset risk assessment methods will be used to perform network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system, with risk values ranging from low to high.
[0060] Specifically, the construction process of an industrial control digital twin system may include:
[0061] S1. Use cloud virtualization technology to build digital twins of general information equipment in industrial control systems.
[0062] S2. Construct the timing diagram of the logical structure of the industrial control system.
[0063] S3, constructing a digital twin network for industrial networks.
[0064] S4. Connect the digital twin with the control equipment in the industrial control system through a virtual-physical interconnection method, and construct an industrial control digital twin system based on the digital twin, the timing relationship diagram, and the digital twin network.
[0065] It should be noted that if the physical state of the general information device changes, the state of the digital twin in the industrial control digital twin system will change synchronously with the physical state.
[0066] To optimize the industrial control digital twin system, the present invention can also utilize simulated network attacks or train the industrial control digital twin system from historical network attacks.
[0067] Step S130: Use the first risk assessment method that passes the network information security test and the industrial control equipment functional safety test as the emergency response strategy, and execute the emergency response strategy.
[0068] Furthermore, the present invention can also store the current state, the attack type, and the emergency response strategy in a strategy library.
[0069] Furthermore, in order to obtain a more suitable response strategy, the present invention may also include:
[0070] When the industrial control system is attacked again, the parameters of the industrial control digital twin system are adjusted and the strategy library is updated according to the system status of the industrial control system, whether the industrial control equipment is turned on, and the reward function used to achieve the set expectation.
[0071] To describe the invention in more detail, specific examples will be used to illustrate its practical application.
[0072] Embodiments of this invention can use digital twins for responding to and handling security threats in industrial control systems, such as... Figure 2As shown, the industrial control system response and handling framework based on digital twins of this invention has a three-layer structure: 1) a virtual-physical interconnection layer; 2) a digital twin layer; and 3) a core computing layer. The virtual-physical interconnection layer includes various field devices of the industrial control system, which collect sensor data and event logs and provide them to the data twin layer. In the data twin layer, the collected industrial control system status data is analyzed / optimized, and the system's time-series relationships are represented using an Automation Markup Language (AML). Various hypothetical network attacks and real-world network attacks are simulated in the digital twin layer. In the core computing layer, a digital twin model is trained based on the time-series relationships received from the data twin layer. Based on the twin model and in conjunction with network attacks, a dual-security fusion response and handling strategy learning based on reinforcement learning is studied. The learned optimal strategy set is stored in the digital twin layer for rapid response to network attacks.
[0073] This invention uses a digital twin platform for industrial control systems to simulate network attack activities and replication modes to reproduce malicious attack activities against industrial control systems. It takes corresponding response and handling measures based on the attack, and selects the optimal response and handling security use cases based on reinforcement learning and saves them to a policy database to support response and handling in actual industrial control systems.
[0074] 1. Digital twin model construction.
[0075] This invention's digital twin model includes twins of industrial control networks and industrial sites, covering both the information and physical domains. The digital twin model replicates industrial control networks and twin industrial sites based on virtualization technology, virtual-physical interconnection technology, and digital twin technology.
[0076] First, the industrial control system network is reproduced. Because industrial control equipment (such as PLCs and DCSs) is relatively closed and difficult to virtualize, industrial control network twins can adopt a combined virtual and physical approach. For the host computer, SCDADA, data server, and other components built from general-purpose information equipment, cloud virtualization technology can be used for reproduction. For dedicated industrial control equipment such as PLCs, DCSs, and RTUs, physical devices are used for reproduction. Virtual and physical devices are connected through a virtual-physical interconnection method.
[0077] Then, the industrial logic structure is analyzed. A TECG (Technical Engineering and Technology) model is used to construct a time-series graph of events to represent the logical structure of the industrial control system. Based on the extraction of event time sequences and the mining of invariant rules from historical data of the industrial control system, the model is pre-trained. Figure 2As shown, after log data analysis in the digital twin layer, the data is transmitted to the core cloud layer for model pre-training. Large-scale data computation using AI algorithms yields the pre-trained model. A physical layer data twin model is then constructed based on real-time data. The digital twin model ensures real-time consistency between the physical and digital models, and its capabilities include simulating / copying network attacks, security defense models, and storing policy sets.
[0078] Digital twins for industrial control systems need to ensure their real-time performance. If the state of physical equipment in the real world changes, the digital twin should immediately update the corresponding twin model to achieve consistency between the virtual and real worlds. However, this approach ignores the cost of model retraining and the inability to respond promptly to the industrial control system during retraining. This invention divides the training of the digital twin model into offline and online modes. First, in offline mode, the corresponding digital twin model is pre-trained based on historical dataset logs of the industrial control equipment. Then, the digital twin model is optimized online based on real-time data. This avoids the cost of large-scale model training while simultaneously synchronizing the real-time state of the physical layer industrial equipment.
[0079] To facilitate the maintenance and updates of industrial field digital twin systems, a digital twin can be constructed for each equipment entity, clearly defining the input / output interfaces between devices and establishing connections between these independent digital twins. This results in a highly clustered, loosely coupled industrial control system model. When relevant data is updated, the corresponding digital twin can be updated individually without affecting the operation of the overall digital twin system.
[0080] 2. Response and handling schemes for industrial control systems based on strategy sets.
[0081] Based on the idea of storing a set of strategies in a digital twin layer to enable rapid response and handling in the face of network attacks, this invention proposes a strategy-based response and handling scheme for industrial control systems.
[0082] Under normal circumstances, different types of network attacks are reproduced using the virtual-physical interconnection layer and the digital twin layer, and different attacks are dealt with accordingly. During the response and handling process, it is determined whether the current response and handling measures targeting the information domain affect the security of the physical domain. By combining reinforcement learning algorithms, the optimal set of response strategies for the current type of attack is found, and the triples constructed from <current system state, attack type, and response strategy> are stored in the strategy library.
[0083] When a real network attack event is detected in the live network, such as Figure 3As shown, based on the current system status and attack type, the strategy library is searched, and the corresponding response strategy is selected. If no response strategy for the attack type can be found, a risk assessment method is used to find the corresponding response strategy sequence. The sequence is then quickly passed through the industrial control digital twin system for dual-security conflict detection in order of risk value from low to high. Strategies without dual-security conflicts are executed as response strategies, and the triples are added to the strategy library.
[0084] 3. Training of response and handling strategies based on reinforcement learning.
[0085] To meet the requirements of optimal strategies, industrial control systems need to continuously simulate or reproduce network attacks and execute different strategies at the digital twin layer in order to derive the corresponding optimal response and handling strategy. This invention employs reinforcement learning to continuously learn the optimal strategy during subsequent network attack activities and update the corresponding strategy database.
[0086] The corresponding reinforcement learning model consists of:
[0087] System status: The system status of the industrial control system proposed in this paper includes the number of physical layer devices operating normally, whether the communication between the digital twin layer and the virtual-physical interconnection layer is interrupted, and the event sequence of the current system.
[0088] Agent Actions: In this system, agent actions are defined as response and handling strategies when facing threats. A response and handling strategy is represented by {0, 1}, where {0} indicates the device is off and {1} indicates it is on. Therefore, the correct system response is represented by a sequence of the operating states of all devices.
[0089] Reward Function: The industrial control system selects a response and handling strategy to minimize the harm caused by network attacks and quickly restore normal industrial production. Therefore, the reward function of the system in this paper mainly includes five parts: reward delay, whether the response and handling strategy will cause communication interruption, whether the response and handling strategy conforms to the event time relationship sequence, whether the response and handling strategy violates the invariant rules of the industrial control system, and whether the parameters of each physical layer device are normal.
[0090] This invention employs deep reinforcement learning to search for the optimal response strategy, with the training objective being to maximize the expected reward. Figure 4 It demonstrates the process of deep reinforcement learning, which learns the best strategy through continuous "trial and error" and stores it in a standardized database in the digital twin layer.
[0091] The key difference between this invention and existing technologies lies in their approaches. Existing industrial control system (ICS) security threat response and handling largely rely on expert experience, lacking flexibility. Digital twin solutions primarily focus on the twin's functionality and safety in the industrial environment, neglecting the relationship between the information and physical domains, as well as the interactions between the twins. This invention, through an industrial control digital twin system covering both the information and physical domains, can monitor network and industrial status in real time. Based on the twin system and reinforcement learning training of optimal strategies, it ensures that the ICS can efficiently, rationally, and accurately respond to network attacks, avoiding system malfunctions caused by dual-security conflicts.
[0092] Responses to cyberattacks can lead to security conflicts, and existing solutions often rely on expert knowledge and experience to select appropriate strategies. This invention proposes a digital twin-based method for responding to and handling security threats in industrial control systems, which offers the following benefits:
[0093] 1. A response and handling framework for industrial control systems based on digital twins was constructed to monitor the system status in real time. By effectively linking the twin system and response and handling strategies, the information domain and physical domain were integrated.
[0094] 2. Construct a twin system covering the information domain and the physical domain, realize industrial control network twins through virtual-physical interconnection, and realize industrial site twins through AI technology, providing a highly realistic scenario for industrial control response and handling that meets cross-domain detection and verification requirements.
[0095] 3. A strategy-based response and handling scheme is proposed, including the construction of a strategy set for twin system conflict detection and the handling of real attack scenarios based on the strategy set, thus forming a rapid and efficient response and handling mechanism.
[0096] 4. A method for selecting the best response and handling strategy based on reinforcement learning is proposed. The best response and handling strategy effectively supports the construction of the strategy library, ensuring efficient, reasonable and accurate means to deal with industrial control security threats and avoiding losses caused by dual security conflicts due to dealing with network attacks.
[0097] Reference Figure 5 This invention provides a security threat response and handling device for industrial control systems based on digital twins, comprising:
[0098] An attack determination unit is used to determine the current state of the industrial control system and the type of network attack when a network attack is detected on the industrial control system.
[0099] The strategy lookup unit is used to search for the target response strategy corresponding to the attack type from a preset strategy library;
[0100] The risk assessment unit is used to perform network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system if no corresponding target response strategy is found. Multiple preset risk assessment methods are used to conduct network information security testing and industrial control equipment functional safety testing in the industrial control digital twin system, with risk values ranging from low to high.
[0101] The strategy execution unit is used to take the first risk assessment method that passes network information security detection and industrial control equipment functional safety detection as the emergency response strategy and execute the emergency response strategy.
[0102] This invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to perform... Figure 1 The method shown.
[0103] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this invention are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is altered and sub-operations described as part of a larger operation are executed independently.
[0104] Furthermore, although the invention has been described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the described functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the invention. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional skill of an engineer. Therefore, those skilled in the art can implement the invention as set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of the invention, which is determined by the full scope of the appended claims and their equivalents.
[0105] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0106] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0107] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0108] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0109] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0110] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
[0111] The above is a detailed description of the preferred embodiments of the present invention. However, the present invention is not limited to the embodiments described. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the present invention. All such equivalent modifications or substitutions are included within the scope defined by the claims of the present invention.
Claims
1. A method for responding to and handling security threats in industrial control systems based on digital twins, characterized in that, include: When an industrial control system is detected to be under a network attack, the current state of the industrial control system and the type of network attack are determined. Search the preset strategy library for the target response strategy corresponding to the attack type; If no corresponding target response strategy is found, the response and handling strategy sequence corresponding to multiple preset risk assessment methods will be used in the industrial control digital twin system to conduct network information security testing and industrial control equipment functional safety testing, in order of risk value from low to high. The first risk assessment method that passes both network information security testing and industrial control equipment functional safety testing will be used as the emergency response strategy, and the emergency response strategy will be implemented. The construction process of the industrial control digital twin system includes: Digital twins of general information equipment in industrial control systems are constructed using cloud virtualization technology; Construct a timing diagram of the logical structure of the industrial control system; Constructing a digital twin network for industrial networks; The digital twin is connected to the control equipment in the industrial control system through a virtual-physical interconnection method, and an industrial control digital twin system is constructed based on the digital twin, the timing relationship diagram, and the digital twin network.
2. The method for responding to and handling security threats in an industrial control system based on digital twins according to claim 1, characterized in that, The target response strategy is used to protect the network information security of the industrial control system, and when the target response strategy is executed, the network information security of the industrial control system does not conflict with the security of the industrial control equipment.
3. The method for responding to and handling security threats in an industrial control system based on digital twins according to claim 1, characterized in that, If the physical state of the general information device changes, the state of the digital twin in the industrial control digital twin system will change synchronously with the physical state.
4. The method for responding to and handling security threats in an industrial control system based on digital twins according to claim 1, characterized in that, Also includes: The industrial control digital twin system is trained using simulated network attacks or from historical network attacks.
5. A method for responding to and handling security threats in an industrial control system based on digital twins as described in claim 1, characterized in that, Also includes: The current state, the attack type, and the emergency response strategy are stored in the strategy library.
6. The method for responding to and handling security threats in an industrial control system based on digital twins according to claim 1, characterized in that, Also includes: When the industrial control system is attacked again, the parameters of the industrial control digital twin system are adjusted and the strategy library is updated according to the system status of the industrial control system, whether the industrial control equipment is turned on, and the reward function used to achieve the set expectation.
7. A security threat response and handling device for industrial control systems based on digital twins, characterized in that, include: An attack determination unit is used to determine the current state of the industrial control system and the type of network attack when a network attack is detected on the industrial control system. The strategy lookup unit is used to search for the target response strategy corresponding to the attack type from a preset strategy library; The risk assessment unit is used to perform network information security testing and industrial control equipment functional safety testing on the industrial control digital twin system if no corresponding target response strategy is found. The sequence of response and handling strategies corresponding to multiple preset risk assessment methods is arranged from low to high risk value. The strategy execution unit is used to take the first risk assessment method that passes network information security detection and industrial control equipment functional safety detection as an emergency response strategy and execute the emergency response strategy. The system also includes a system construction unit for constructing the industrial control digital twin system; The system building unit includes: The first building unit is used to construct digital twins of general information equipment in industrial control systems using cloud virtualization technology; The second building unit is used to construct the timing diagram of the logic structure of the industrial control system. The third building block is used to construct a digital twin network of the industrial network; The fourth construction unit is used to connect the digital twin with the control equipment in the industrial control system through a virtual-physical interconnection method, and to construct the industrial control digital twin system based on the digital twin, the timing relationship diagram and the digital twin network.
8. A security threat response and handling device for industrial control systems based on digital twins according to claim 7, characterized in that, The target response strategy is used to protect the network information security of the industrial control system, and when the target response strategy is executed, the network information security of the industrial control system does not conflict with the security of the industrial control equipment.
9. A security threat response and handling device for industrial control systems based on digital twins according to claim 7, characterized in that, If the physical state of the general information device changes, the state of the digital twin in the industrial control digital twin system will change synchronously with the physical state.
10. A security threat response and handling device for industrial control systems based on digital twins according to claim 7, characterized in that, Also includes: The system training unit is used to train the industrial control digital twin system using simulated network attacks or network attacks from historical records.
11. A security threat response and handling device for industrial control systems based on digital twins according to claim 7, characterized in that, Also includes: The policy storage unit is used to store the current state, the attack type, and the emergency response policy in the policy library.
12. A security threat response and handling device for industrial control systems based on digital twins according to claim 7, characterized in that, Also includes: The parameter processing unit is used to adjust the parameters of the industrial control digital twin system and update the strategy library when the industrial control system is attacked again, based on the system status of the industrial control system, whether the industrial control equipment is turned on, and the reward function used to achieve the set expectation.
13. An electronic device, characterized in that, Including the processor and memory; The memory is used to store programs; The processor executes the program to implement the method as described in any one of claims 1 to 6.
14. A computer-readable storage medium, characterized in that, The storage medium stores a program that is executed by a processor to implement the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Safety control method and device combining RPA and AI, electronic equipment and medium
CN114448693A
Network Security Management System based theSimulation Technique
KR1020040022112A