A method for generating industrial control honeypot telemetry mimic data using power IED equipment
By deploying the industrial control honeypot function on the communication board of the power IED equipment and using the Markov chain to calculate the network state vector to generate pseudo-telemetry data, the problems of low simulation and low interactivity of the existing industrial control honeypot system are solved, efficient honeypot data generation is achieved, and operation and maintenance costs are reduced.
Patent Information
- Application Number
- CN202310429340.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-20
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2043-04-20
AI Technical Summary
Existing industrial control honeypot systems in power systems have problems such as low simulation, low interactivity and easy detection. Deploying real IED devices as honeypots will increase costs and operation and maintenance burdens.
An industrial control honeypot function is deployed on the communication board of the power IED device, and the network state vector is calculated using the Markov chain to generate highly simulated and interactive pseudo-telemetry data, including current, voltage, frequency, phase, power and circuit breaker position. The pseudo-telemetry data generation is achieved through the idle core processor of the existing IED device.
It achieves the goal of improving the simulation and interactivity of the honeypot without increasing additional equipment investment, increasing the complexity of network attackers, reducing operation and maintenance costs, and complying with the operating logic of the power system.
Smart Images

Figure CN116614256B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network communication security for transformer substation protection and control equipment, and in particular to a method for generating industrial control honeypot telemetry mimic data by electric power IED equipment. Background Art
[0002] The current cybersecurity situation in the industrial, energy, and power sectors is severe, with numerous cybersecurity attacks targeting industrial control systems. Deploying an industrial control honeypot system is an effective method for proactively defending against cybersecurity attacks. It can trap attackers, analyze their behavioral characteristics and methods, provide deceptive data, and increase the complexity of attacks. Currently, both domestic and international honeypots, whether Internet honeypots or industrial control honeypots, primarily utilize virtualized honeypot systems. These honeypots are deployed on industrial control network services, typically using virtualized device technology and running a entrapment honeypot function based on a common protocol. However, these general-purpose honeypot systems also have certain drawbacks. They have low fidelity, low interactivity, and are easily detected. Furthermore, achieving complex and large-scale honeypots requires increased investment costs.
[0003] Using real physical devices as honeypots offers certain advantages. First, the topology and network connections of the monitoring system deployed on the power grid are realistic. Real IEDs offer more comprehensive functionality, high simulation accuracy, and improved interactivity. However, the use of real IEDs specifically designed to capture honeypot functionality increases substation costs, and the presence of distributed IEDs also increases honeypot operation and maintenance costs.
[0004] To improve the simulation, interactivity, authenticity, and deceptiveness of power industrial control network trapping honeypots, using real physical devices as trapping honeypots requires addressing the issues of secure isolation from normal functionality and the generation of simulated data. Generally speaking, minor or severe faults in the network environment of IEDs can significantly impact the performance of network-based distributed control systems, leading to equally severe faults in the power system's operating conditions. Summary of the Invention
[0005] The purpose of this section is to summarize some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the abstract and title of this application to avoid blurring the purpose of this section, the abstract and the title of the invention, and such simplifications or omissions should not be used to limit the scope of the present invention.
[0006] Therefore, the purpose of the present invention is to provide a method for generating telemetry mimic data for industrial control honeypots using power IED equipment. By estimating the network status and operating conditions of the IED equipment, more reasonable telemetry mimic data can be obtained. Even without increasing the investment in separate honeypot equipment, the highly interactive telemetry data mimicry function of the honeypot can be realized by using existing IED equipment boards.
[0007] To solve the above technical problems, according to one aspect of the present invention, the present invention provides the following technical solutions:
[0008] A method for generating industrial control honeypot telemetry mimic data for electric power IED equipment, comprising:
[0009] S1. Deploy the industrial control honeypot function on the communication board or function board of the power IED equipment and generate it through mimicking data;
[0010] S2. Based on the complexity of the network environment in which the power IED device is located and the attacker's simultaneous destructive attacks on the network and data theft, the network state vector of the power IED device's operating environment is calculated based on the Markov chain;
[0011] S3. When the attacker communicates with the power protocol running in the honeypot and steals data, he generates highly reliable simulated telemetry data of current, voltage, frequency, phase, power, circuit breaker position, and switch position based on the network state vector of the power IED equipment and the basic telemetry data based on the power specification.
[0012] As a preferred solution for the method of generating industrial control honeypot telemetry mimic data by a power IED device described in the present invention, the power IED device includes a power grid relay protection device, a measurement and control device, and a safety control device.
[0013] As a preferred solution of the method for generating industrial control honeypot telemetry mimic data for a power IED device according to the present invention, the specific steps of calculating the network state vector of the operating environment of the power IED device based on the Markov chain are as follows:
[0014] According to the network security environment of the power IED equipment, the three states of normal operation S0, slight disturbance S1 and serious fault S2 are divided, and the state transition matrix based on Markov chain is generated;
[0015] When the power IED device is initially running, an initial state vector S0 (S00, S01, S02) is established based on the current network traffic and power protocol link status information, which respectively represent the normal operation state probability, slight disturbance state probability, and serious fault state probability implied by the initial state;
[0016] When the network where the power IED device is located is attacked by the nth round of network attack, the state vector Sn(Sn0, Sn1, Sn2) after the transfer is calculated by multiplying the initial state and the state transfer matrix;
[0017] Then, when the industrial control honeypot function running in the power IED device is accessed by the attacker to access the telemetry data, it provides various types of telemetry data after mimicking;
[0018] When the state vector Sn reaches a convergent steady state and no longer changes after the nth round of network attack, Sn is used as the reference value, the state transfer matrix is reset, and the initial state S0 is re-established to form a closed loop again.
[0019] As a preferred solution for the method of generating industrial control honeypot telemetry mimic data using an electric power IED device described in the present invention, when the network in which the electric power IED device is located is subjected to the nth round of network attack, the state Sn (Sn0, Sn1, Sn2) after the transfer is calculated based on the multiplication of the initial state and the state transfer matrix. The IED device itself can still perceive the change in the network security environment in which it is located during the attack, and responds to the iterative adjustment of Sn. The vector Sn represents the possible probability distribution of the current system state, and various telemetry data of the industrial control honeypot mimicry deployed by the current IED are calculated based on the probability distribution.
[0020] As a preferred solution of the method for generating industrial control honeypot telemetry mimic data for a power IED device according to the present invention, the specific steps of calculating various telemetry data of the industrial control honeypot mimicry deployed by the current IED according to the probability distribution are as follows:
[0021] Establish a telemetry basic value vector Pn[Pn0, Pn1, Pn2], where Pn0 represents the telemetry value of the current actual system operation, Pn1 represents the telemetry value that the system can maintain long-term operation under fault conditions, and Pn2 represents the telemetry value of the maximum fault state that the system can withstand;
[0022] The corresponding telemetry simulation value is obtained by multiplying the IED device state vector Sn and the telemetry basic value vector Pn.
[0023] Compared with the existing technology, the present invention has the following beneficial effects: the industrial control honeypot function of the present invention is deployed on the communication board of the power IED equipment to form a physical honeypot rather than a virtual honeypot, and the idle core processor of the communication board is used to realize the generation of mimetic data for the entrapped honeypot, thereby achieving high interactivity and obfuscation of the honeypot data, and increasing the complexity for network attackers to steal the basic operation data of the power grid.
[0024] In addition, the present invention has a small amount of computation and is suitable for the embedded computing environment of real physical IED devices. It performs pseudo-computation on the data in real power IED devices without the need to run a complex simulation system locally or obtain pseudo-data from a honeypot host. It conducts a probability estimation of the network status and operating conditions of the IED devices, thereby generating corresponding telemetry values based on the status and complying with the operating conditions and logic of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and detailed embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be derived from these drawings without inventive effort. Among them:
[0026] Figure 1 This is a flow chart of a method for generating industrial control honeypot telemetry mimic data for an electric power IED device according to the present invention;
[0027] Figure 2 The present invention provides a flow chart of a method for generating industrial control honeypot telemetry mimic data for an electric power IED device based on a Markov chain to calculate the network state vector of the operating environment of the electric power IED device. DETAILED DESCRIPTION
[0028] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0029] Next, the present invention is described in detail with reference to schematic diagrams. For ease of illustration, cross-sectional views of device structures may be partially enlarged and not to scale when describing the embodiments of the present invention. Furthermore, the schematic diagrams are merely illustrative and should not limit the scope of protection of the present invention. Furthermore, in actual production, three-dimensional dimensions, including length, width, and depth, should be included.
[0030] To make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0031] The present invention provides a method for generating telemetry mimic data for an industrial control honeypot using an electric power IED device. By estimating the network status and operating conditions of the IED device, relatively reasonable telemetry mimic data is obtained. Even without increasing the investment in a separate honeypot device, the highly interactive telemetry data mimic function of the honeypot is realized by using existing IED device boards.
[0032] Figure 1The flowchart of the method for generating industrial control honeypot telemetry mimic data by a power IED device of the present invention is shown. Figure 1 In this embodiment, a power IED device implements an industrial control honeypot telemetry mimetic data generation method. First, the power IED device includes power grid relay protection equipment, measurement and control equipment, safety control equipment, etc. The power IED device is generally based on a multi-CPU board design, that is, one CPU board is used for substation control layer network communication, defined as a communication management board, one or more CPU boards are used to run its power grid protection control or safety and stability control functions, defined as functional boards, and the communication board communicates with the functional board through the backplane high-speed bus of the device. In addition to the communication board and the functional board, the device is generally also equipped with some I / O boards, AC boards, etc.
[0033] The present invention mainly discusses the deployment of a trapping honeypot function on a communication board. This function does not interact with the functional board, reducing the risk of affecting the main functional board. In addition, the telemetry mimicry data generation for the industrial control honeypot provided by the present invention can be run on both the functional module and the communication management module of the IED device due to its limited computing overhead.
[0034] The specific steps are as follows:
[0035] S1. Deploy the industrial control honeypot function on the communication board or function board of the power IED equipment to realize the trapping honeypot function under the local real system, and generate mimic data to ensure the high interactivity of the honeypot data. Utilize the idle core processor of the communication board to realize the mimic data generation of the trapping honeypot, so as to achieve the high interactivity and obfuscation of the honeypot data, and increase the complexity for network attackers to steal the basic operation data of the power grid;
[0036] S2. Based on the complexity of the network environment in which the power IED device is located and the attacker's simultaneous destructive attacks on the network and data theft, the network state vector of the power IED device's operating environment is calculated based on the Markov chain;
[0037] S3. When the attacker communicates with the power protocol running in the honeypot and steals data, he generates highly reliable simulated telemetry data of current, voltage, frequency, phase, power, circuit breaker position, and switch position based on the network state vector of the power IED equipment and the basic telemetry data based on the power specification.
[0038] In this embodiment, if Figure 2 As shown, the specific steps of calculating the network state vector of the operating environment of the power IED device based on the Markov chain are as follows:
[0039] According to the network security environment of the power IED equipment, the three states of normal operation S0, slight disturbance S1 and serious fault S2 are divided, and the state transition matrix based on Markov chain is generated. Generally speaking, if there is a slight or serious fault in the network environment where the IED equipment is located, it will significantly affect the performance of the network-based distributed control system, and then cause the power system operating conditions to have faults of equal severity. For example, the S matrix
[0040] During the initial operation of the power IED device, an initial state vector S0 (S00, S01, S02) is established based on the current network traffic and power protocol link status information, which respectively represent the normal operation state probability, slight disturbance state probability, and serious fault state probability implied by the initial state, for example, S0 = [0.90 0.05 0.05]; when the network where the power IED device is located is subjected to the nth round of network attack, the state vector Sn (Sn0, Sn1, Sn2) after the transfer is calculated by multiplying the initial state and the state transfer matrix. If the IED device itself can sense the change in the network security environment during the attack, Sn should be iteratively adjusted. The vector Sn represents the possible probability distribution of the current system state, and the various telemetry data of the industrial control honeypot deployed by the current IED are calculated based on the probability distribution. After the third round of attack,
[0041] Then, when the industrial control honeypot function running in the power IED device is accessed by the attacker to access the telemetry data, it provides various types of telemetry data after mimicking;
[0042] When the state vector Sn reaches a convergent steady state and no longer changes after the nth round of network attack, Sn is used as the reference value, the state transfer matrix is reset, and the initial state S0 is re-established to form a closed loop again.
[0043] In this embodiment, the specific steps of calculating various telemetry data of the industrial control honeypot mimicry currently deployed by the IED according to the probability distribution are as follows:
[0044] Establish a telemetry basic numerical vector Pn[Pn0, Pn1, Pn2], where Pn0 represents the telemetry value of the current actual system operation, Pn1 represents the telemetry value that the system can maintain long-term operation under fault conditions, and Pn2 represents the telemetry value of the maximum fault state that the system can withstand. Taking the A-phase secondary current (rated value 1A) of a running three-phase AC transmission system as an example, Pn0 is the actual A-phase secondary current telemetry value of the IED, Pn1 can be 1.5A to 2A, and Pn2 can be 10A to 20A. Taking the A-phase secondary voltage (rated value 57.7V) of a running three-phase AC transmission system as an example, Pn0 is the actual A-phase secondary voltage telemetry value of the IED, Pn1 can be 67V to 87V, and Pn2 can be 87V to 115V.
[0045] The corresponding telemetry simulation value is obtained by multiplying the IED device state vector Sn and the telemetry basic value vector Pn.
[0046] As described above, the industrial control honeypot function of the present invention is deployed on the communication board of the power IED device to form a physical honeypot rather than a virtual honeypot. The idle core processor of the communication board is used to realize the generation of mimic data for trapping the honeypot, thereby achieving high interactivity and deceptiveness of the honeypot data, and increasing the complexity for network attackers to steal basic power grid operation data. In addition, the present invention has a small amount of computation and is suitable for the embedded computing environment of real physical IED devices. It performs mimic operations on the data in the real power IED device without the need to run a complex simulation system locally or obtain mimic data from the honeypot host. It performs a probability estimate of the network status and operating conditions of the IED device, thereby generating corresponding telemetry data according to the status, and conforming to the operating conditions and logic of the power system.
[0047] Although the present invention has been described above with reference to embodiments, various modifications may be made thereto and equivalent components may be substituted without departing from the scope of the present invention. In particular, as long as there are no structural conflicts, the various features of the embodiments disclosed herein may be combined with each other in any manner, and the omission of an exhaustive description of such combinations in this specification is solely for the sake of space and resource conservation. Therefore, the present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.
Claims
1. A method for generating industrial control honeypot telemetry mimic data for power IED equipment, characterized in that: include: S1. Deploy the industrial control honeypot function on the communication board or function board of the power IED equipment and generate it through mimicking data; S2. Based on the complexity of the network environment in which the power IED device is located and the attacker's simultaneous destructive attacks on the network and data theft, the network state vector of the power IED device's operating environment is calculated based on the Markov chain; S3. When the attacker communicates with the power protocol running in the honeypot and steals data, he generates highly reliable simulated telemetry data of current, voltage, frequency, phase, power, circuit breaker position, and switch position based on the network state vector of the power IED device and the basic telemetry data based on the power specification. The specific steps of calculating the network state vector of the operating environment of the power IED device based on the Markov chain are as follows: According to the network security environment of the power IED equipment, the three states of normal operation S0, slight disturbance S1 and serious fault S2 are divided, and the state transition matrix based on Markov chain is generated; When the power IED device is initially running, an initial state vector S0 (S00, S01, S02) is established based on the current network traffic and power protocol link status information, which respectively represent the normal operation state probability, slight disturbance state probability, and serious fault state probability implied by the initial state; When the network where the power IED device is located is attacked by the nth round of network attack, the state vector Sn(Sn0, Sn1, Sn2) after the transfer is calculated by multiplying the initial state and the state transfer matrix; Then, when the industrial control honeypot function running in the power IED device is accessed by the attacker to access the telemetry data, it provides various types of telemetry data after mimicking; When the state vector Sn reaches a converged steady state and no longer changes after the nth round of network attack, Sn is used as a reference value to reset the state transfer matrix and re-establish the initial state S0, thus forming a closed loop again. When the network where the power IED device is located is subjected to the nth round of network attack, the state Sn (Sn0, Sn1, Sn2) after the transfer is calculated by multiplying the initial state and the state transfer matrix. The IED device itself can still sense the change in the network security environment during the attack and respond to Sn iterative adjustment. The vector Sn represents the possible probability distribution of the current system state, and various telemetry data of the industrial control honeypot deployed by the current IED are calculated based on the probability distribution. The specific steps of calculating various telemetry data of the industrial control honeypot mimicry currently deployed by the IED according to the probability distribution are as follows: Establish a telemetry basic value vector Pn[Pn0, Pn1, Pn2], where Pn0 represents the telemetry value of the current actual system operation, Pn1 represents the telemetry value that the system can maintain long-term operation under fault conditions, and Pn2 represents the telemetry value of the maximum fault state that the system can withstand; The corresponding telemetry simulation value is obtained by multiplying the IED device state vector Sn and the telemetry basic value vector Pn.
2. The method for generating industrial control honeypot telemetry mimic data for power IED equipment according to claim 1, characterized in that: The power IED equipment includes grid relay protection equipment, measurement and control equipment, and safety control equipment.
Citation Information
Patent Citations
Industrial control network honey net safety protection system based on cloud deployment
CN109889488A
Method and device for establishing operation chain of Markov chain
CN115589338A