An industrial control network security early warning system

CN116781335BActive Publication Date: 2026-09-22SHANDONG PUBLISHING DIGITAL INTEGRATION IND RES INST CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310674534.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-07
Publication Date
2026-09-22
Estimated Expiration
2043-06-07

Smart Images

  • Figure CN116781335B_ABST
    Figure CN116781335B_ABST
Patent Text Reader

Abstract

The application discloses an industrial control network security early warning system, and relates to the technical field of industrial control networks, comprising: a basic information exchange layer, comprising a plurality of data transmission channels; the basic information exchange layer classifies information data connected by the system based on characteristics, accesses corresponding data transmission channels through a local area network, and transmits the information data to a control platform layer through the corresponding data transmission channels; the control platform layer sends a model request to a big data platform based on the classification of the information data received by the basic information exchange layer; the big data platform transmits corresponding types of big data early warning models to the control platform layer based on the model request of the control platform; and a local database is used to store the big data early warning models received by the control platform. The application classifies information data based on characteristics, thereby facilitating separate early warning of larger information data, reducing the working intensity of the early warning system, and avoiding the problem of long result delay caused by large data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control network technology, and more specifically, to an industrial control network security early warning system. Background Technology

[0002] Industrial data communication and control networks are network technologies that have developed in the field of automatic control in recent years. They are a product of the integration of computer networks, communication technologies, and automatic control technologies. Industrial control networks adapt to the development trend and needs of enterprise information integration systems and integrated management and control systems. They are an extension of IT technology in the field of automatic control and are local area networks in the field of automatic control.

[0003] Furthermore, with the continuous integration of industrial control systems and the Internet, the uncontrollability of the security and stability of industrial control networks is also increasing.

[0004] A search revealed a Chinese patent (publication number: CN107040551A) that discloses a method and system for early warning of industrial control network security. This patent includes: acquiring security-related data of control events in an industrial control network; performing CEP analysis on the security-related data; and performing security analysis of the control events based on the CEP analysis results. The CEP analysis includes: statistically summarizing the security-related data within a fixed time window to determine the relevant attributes of the control events; and performing correlation analysis on the control events by combining the relevant attributes of the control events with a preset rule engine to obtain the correlation between each control event.

[0005] In existing technologies, when providing early warnings for industrial control networks in industrial-intensive sectors, the large amount of data transmitted results in high network latency, and the models and algorithms for safety early warning are relatively simple with limited processing capabilities. Summary of the Invention

[0006] In view of the shortcomings of existing technologies, the purpose of this invention is to provide an industrial control network security early warning system.

[0007] To achieve the above objectives, the present invention provides the following technical solution: an industrial control network security early warning system, comprising a control platform layer, a basic information exchange layer, a big data platform, a local database, inspection equipment, and an early warning module;

[0008] The basic information exchange layer includes multiple data transmission channels. After classifying the information data connected to the system based on features, the basic information exchange layer accesses the corresponding data transmission channels through the local area network and transmits the data to the control platform layer through the corresponding data transmission channels.

[0009] The characteristics of information data classification include: 1. Spatial classification; 2. Domain classification; 3. Frequency classification;

[0010] The control platform layer is used to receive various types of information data from the basic information exchange layer, and the control platform layer sends model requests to the big data platform based on the classification of the information data.

[0011] The big data platform transmits the corresponding type of big data early warning model to the control platform layer based on the model request from the control platform.

[0012] After receiving the big data early warning model, the control platform stores it in the local database. After receiving various information data from the basic information exchange layer, the control platform first compares it with the big data early warning model in the local database to obtain comparison information I.

[0013] The inspection equipment is used to intermittently input key information data from each data transmission channel and transmit it to the control platform layer;

[0014] After receiving key information data, the control platform layer compares it with the information data transmitted by the basic information exchange layer to obtain comparison information II.

[0015] The early warning module sends early warning information of the corresponding level based on comparison information I and comparison information II.

[0016] Furthermore, the data transmission channel includes a gateway module, a network connection module, a micro data processing module, and a low-latency early warning module;

[0017] The low-latency early warning module includes a primary model comparison unit, which sets up a primary early warning model corresponding to the production task based on the production task of the data transmission channel.

[0018] The network connection module includes a CAN bus unit, a VAN bus unit, and a wireless transmission unit. The network connection module is used to receive corresponding information data, and after receiving it, it copies it twice and transmits it to the micro data processing module and the gateway module respectively.

[0019] The micro data processing module is used to identify information data, obtain task nodes for information data, match task nodes with information data to obtain identification datasets, and transmit them to the low-latency early warning module.

[0020] After acquiring the identification dataset, the low-latency early warning module matches the task nodes with the first-level early warning module to obtain the node early warning model. Then, it compares the node early warning model with the information data to obtain the discrete coefficient α and transmits it to the gateway module.

[0021] During operation, the network connection module prioritizes transmitting the first piece of information data to the micro data processing module, so that the low-latency early warning module can compare the information data with the first-level early warning model.

[0022] When the network connection module transmits the second set of information data to the gateway module, the gateway module binds the discrete coefficient α with the second set of information data.

[0023] Furthermore, when the low-latency early warning module is entered into the primary early warning model, it is in read-only mode to prevent it from being rewritten.

[0024] Furthermore, the method for obtaining the primary early warning model includes the following steps:

[0025] Step 1: Establish enterprise task templates for each data transmission channel, and divide the enterprise task templates into multiple task nodes;

[0026] Step 2: Preset the comparison thresholds for each task node in the enterprise task template;

[0027] Step 3: The control platform will compare the information data received from the basic information exchange layer with the big data early warning model of the big data platform;

[0028] The comparison results include:

[0029] A1: If the comparison result is less than the comparison threshold, the information data is marked as "recordable" and entered into the enterprise task template;

[0030] A2: If the comparison result is not less than the threshold, then mark it as "needs to be replaced" when entering information data into the enterprise task template;

[0031] When the information data is subsequently tested, the information data that meets the A1 result will be replaced with the information data marked as "needs to be replaced".

[0032] Furthermore, the inspection equipment includes a positioning module, a protocol module, a processing module, a data input module, and an intranet connection module;

[0033] When in use, the inspection equipment is moved by inspection personnel to various work areas;

[0034] Furthermore, upon entering the work area, the inspection equipment obtains the corresponding data transmission channel through the positioning module and connects to the corresponding local area network through the protocol module.

[0035] The data entry module is used to enter manually input verification information data and transmit it to the processing module;

[0036] The processing module obtains corresponding information data from the local area network based on the verification information data and marks it as comparison information data;

[0037] The processing module matches the verification information data with the comparison information data, generates key information data, and transmits it to the intranet connection module.

[0038] The intranet connection module is used to connect unidirectionally with the control platform layer, and after receiving key information data, it transmits it to the control platform layer.

[0039] Furthermore, the method for obtaining the comparison information I includes the following steps:

[0040] S1: Generate a continuous linear model by using the information data with the time axis as the coordinate.

[0041] S2: The linear model is modified based on the discrete coefficient α to obtain the warning area;

[0042] S3: Compare each big data early warning model with the early warning area; during the comparison, the early warning data that is the same as the information data in each big data early warning model is taken as the starting point and distributed along the coordinates;

[0043] S4: Filter the big data early warning models that fall into the early warning area as comparison models, and obtain the fluctuation trend I of each comparison model;

[0044] S5: Calculate the linear model fluctuation trend II in step S1, and compare fluctuation trend II with fluctuation trend I to obtain comparison information I;

[0045] Among them, Comparison Information I includes multiple big data early warning models.

[0046] Furthermore, the method for obtaining the comparison information II includes the following steps:

[0047] Q1: Obtain the duration and time points of continuous input of multiple verification information data;

[0048] Q2: Match the reference information data with the information data of the corresponding data transmission channel to obtain continuous data information for the corresponding time period;

[0049] Q3: Match the duration and time points of the verification information with continuous data to obtain the verification data information segment;

[0050] Q4: Compare multiple verification data with the calibration data information segment;

[0051] The comparison results include:

[0052] Z1: If the information data of each verification data and the corresponding time node in the information segment of the calibration data are the same, then the information data is normal;

[0053] Z2: If at least one set of verification data differs from the information data at the corresponding time node within the verification data information segment, then the information data after that time node will be monitored, and an early warning module will be used to issue a warning.

[0054] Furthermore, the warning information includes any combination of the following types;

[0055] Security incident level: The level of information data corruption represented by the corresponding big data early warning model;

[0056] Equipment level: This refers to the damage level of the corresponding production equipment, and includes the type of damage that caused the data and maintenance information.

[0057] Failure frequency of similar equipment: This refers to the failure rate of similar equipment, and includes the service life, usage conditions, job type, and operation method of the similar equipment at the time of failure.

[0058] Security assessment: When a corresponding information data alert is issued, the loss data of the corresponding event in the big data is included, as well as the time, cost and subsequent data processing methods for handling the corresponding event.

[0059] Compared with the prior art, the present invention has the following beneficial effects:

[0060] This invention classifies information data according to its characteristics, thereby facilitating the separate early warning of large amounts of information data, reducing the workload of the early warning system, and avoiding the problem of long delays in results due to large data.

[0061] Furthermore, based on historical data of corresponding types of information data, this invention generates a corresponding first-level early warning model. When data is generated in each data transmission channel, it is first compared with the first-level early warning model to realize the monitoring of fluctuations in the ontological data. It can also reduce the number of model comparisons between the control platform layer and the big data platform, thereby achieving the technical objective of rapid early warning.

[0062] On the other hand, the present invention uses inspection equipment to manually and intermittently check the data in the data transmission channel, and compares the actual data of the data generating device with the data transmitted through the network to obtain the accuracy and stability of the network transmission data. Attached Figure Description

[0063] Figure 1 This is a system block diagram of an industrial control network security early warning system;

[0064] Figure 2 This is a system block diagram of the data transmission channel in this invention;

[0065] Figure 3 This is a system block diagram of the inspection equipment in this invention; Detailed Implementation

[0066] Example 1

[0067] Reference Figures 1 to 3As shown, an industrial control network security early warning system includes a control platform layer, a basic information exchange layer, a big data platform, a local database, inspection equipment, and an early warning module.

[0068] The basic information exchange layer includes N data transmission channels. After classifying the information data connected to the system based on the work domain, the basic information exchange layer accesses the corresponding data transmission channel through the local area network and transmits it to the control platform layer through the corresponding data transmission channel.

[0069] The data transmission channel includes a gateway module, a network connection module, a micro data processing module, and a low-latency early warning module;

[0070] The low-latency early warning module includes a primary model comparison unit. Based on the production tasks of the data transmission channel, the primary model comparison unit sets up a primary early warning model corresponding to the production tasks, and the primary early warning model is set to read-only mode.

[0071] The method for obtaining the Level 1 early warning model includes the following steps:

[0072] Step 1: Establish enterprise task templates for each data transmission channel, and divide the enterprise task templates into multiple task nodes;

[0073] Step 2: Preset the comparison thresholds for each task node in the enterprise task template;

[0074] Step 3: The control platform will compare the information data received from the basic information exchange layer with the big data early warning model of the big data platform;

[0075] In this embodiment, the comparison result is: if the comparison result is less than the comparison threshold, the information data is marked as "recordable" and entered into the enterprise task template;

[0076] After recording continuous information data for one cycle, a first-level early warning model is obtained.

[0077] The network assembly module includes a CAN bus unit, a VAN bus unit, and a wireless transmission unit. The network assembly module is used to receive the corresponding information data, and after receiving it, it copies it twice and transmits it to the micro data processing module and the gateway module respectively.

[0078] The micro data processing module is used to identify information data, acquire task nodes for information data, match task nodes with information data to obtain identification datasets, and transmit them to the low-latency early warning module.

[0079] After acquiring the identification dataset, the low-latency early warning module matches the task nodes with the first-level early warning module to obtain the node early warning model. Then, it compares the node early warning model with the information data to obtain the discrete coefficient α and transmits it to the gateway module.

[0080] During operation, the network connection module prioritizes transmitting the first piece of information data to the micro data processing module, so that the low-latency early warning module can compare the information data with the first-level early warning model.

[0081] When the network connection module transmits the second set of information data to the gateway module, the gateway module binds the discrete coefficient α with the second set of information data.

[0082] The control platform layer is used to receive various types of information data from the basic information exchange layer, and based on the classification of the information data, the control platform layer sends model requests to the big data platform.

[0083] Based on the model requests from the control platform, the big data platform transmits the corresponding type of big data early warning model to the control platform layer;

[0084] After receiving the big data early warning model, the control platform stores it in the local database. After receiving various information data from the basic information exchange layer, the control platform first compares it with the big data early warning model in the local database to obtain comparison information I.

[0085] The method for obtaining comparison information I includes the following steps:

[0086] S1: Generate a continuous linear model by using the information data with the time axis as the coordinate.

[0087] S2: The linear model is modified based on the discrete coefficient α to obtain the warning area;

[0088] S3: Compare each big data early warning model with the early warning area; during the comparison, the early warning data that is the same as the information data in each big data early warning model is taken as the starting point and distributed along the coordinates;

[0089] S4: Filter the big data early warning models that fall into the early warning area as comparison models, and obtain the fluctuation trend I of each comparison model;

[0090] S5: Calculate the linear model fluctuation trend II in step S1, and compare fluctuation trend II with fluctuation trend I to obtain comparison information I;

[0091] Among them, the comparison information I includes multiple big data early warning models, and among these multiple big data early warning models is a set of big data early warning models β that represent normal operation.

[0092] The inspection equipment is used to intermittently input key information data from each data transmission channel and transmit it to the control platform layer;

[0093] In this embodiment, the inspection equipment is carried by designated inspection personnel and is periodically inspected within the area corresponding to each data transmission channel;

[0094] The inspection equipment includes a positioning module, a protocol module, a processing module, a data entry module, and an intranet connection module;

[0095] When in use, the inspection equipment is moved by inspection personnel to various work areas;

[0096] Furthermore, upon entering the work area, the inspection equipment obtains the corresponding data transmission channel through the positioning module and connects to the corresponding local area network through the protocol module.

[0097] The data entry module is used to enter manually input verification information data and transmit it to the processing module;

[0098] The processing module retrieves the corresponding information data from the local area network based on the verification information data and marks it as the comparison information data;

[0099] The processing module matches the verification information data with the comparison information data, generates key information data, and transmits it to the intranet connection module.

[0100] The intranet connection module is used to connect unidirectionally to the control platform layer, and after receiving key information data, it transmits it to the control platform layer.

[0101] After receiving key information data, the control platform layer compares it with the information data transmitted by the basic information exchange layer to obtain comparison information II;

[0102] The method for obtaining comparison information II includes the following steps:

[0103] Q1: Obtain the duration and time points of continuous input of multiple verification information data;

[0104] Q2: Match the reference information data with the information data of the corresponding data transmission channel to obtain continuous data information for the corresponding time period;

[0105] Q3: Match the duration and time points of the verification information with continuous data to obtain the verification data information segment;

[0106] Q4: Compare multiple verification data with the calibration data information segment;

[0107] The comparison results are as follows: if the information data of each verification data point is the same as the information data of the corresponding time node in the information segment of the calibration data, then the information data is normal.

[0108] Furthermore, in this embodiment, if the fluctuation trend II in step S5 is the same as the fluctuation trend I of the big data early warning model β, it indicates that the industrial control network is working normally.

[0109] The early warning module sends early warning information of the corresponding level based on comparison information I and comparison information II.

[0110] The early warning information includes the security incident level, equipment level, and security assessment;

[0111] In this embodiment, the security event level, device level, and security assessment are all at the lowest risk level, indicating that the device can function normally.

[0112] Example 2

[0113] An industrial control network security early warning system includes a control platform layer, a basic information exchange layer, a big data platform, a local database, inspection equipment, and an early warning module;

[0114] The basic information exchange layer includes N data transmission channels. After classifying the information data connected to the system based on the workspace, the basic information exchange layer accesses the corresponding data transmission channels through the local area network and transmits them to the control platform layer through the corresponding data transmission channels.

[0115] The data transmission channel includes a gateway module, a network connection module, a micro data processing module, and a low-latency early warning module;

[0116] The low-latency early warning module includes a primary model comparison unit, which is equipped with a primary early warning model that corresponds to the production task and is in read-only mode.

[0117] In this embodiment, the comparison result is: if the comparison result is not less than the threshold, then when the information data is entered into the enterprise task template, it is marked as "needs to be replaced";

[0118] When the information data is subsequently tested, the information data that meets the A1 result will be replaced with the information data marked as "needs to be replaced".

[0119] The network assembly module includes a CAN bus unit, a VAN bus unit, and a wireless transmission unit. The network assembly module is used to receive the corresponding information data, and after receiving it, it copies it twice and transmits it to the micro data processing module and the gateway module respectively.

[0120] The micro data processing module is used to identify information data, acquire task nodes for information data, match task nodes with information data to obtain identification datasets, and transmit them to the low-latency early warning module.

[0121] After acquiring the identification dataset, the low-latency early warning module matches the task nodes with the first-level early warning module to obtain the node early warning model. Then, it compares the node early warning model with the information data to obtain the discrete coefficient α and transmits it to the gateway module.

[0122] During operation, the network connection module prioritizes transmitting the first piece of information data to the micro data processing module, so that the low-latency early warning module can compare the information data with the first-level early warning model.

[0123] When the network connection module transmits the second set of information data to the gateway module, the gateway module binds the discrete coefficient α with the second set of information data.

[0124] The control platform layer is used to receive various types of information data from the basic information exchange layer, and based on the classification of the information data, the control platform layer sends model requests to the big data platform.

[0125] Based on the model requests from the control platform, the big data platform transmits the corresponding type of big data early warning model to the control platform layer;

[0126] After receiving the big data early warning model, the control platform stores it in the local database. After receiving various information data from the basic information exchange layer, the control platform first compares it with the big data early warning model in the local database to obtain comparison information I.

[0127] The method for obtaining comparison information I includes the following steps:

[0128] S1: Generate a continuous linear model by using the information data with the time axis as the coordinate.

[0129] S2: The linear model is modified based on the discrete coefficient α to obtain the warning area;

[0130] S3: Compare each big data early warning model with the early warning area; during the comparison, the early warning data that is the same as the information data in each big data early warning model is taken as the starting point and distributed along the coordinates;

[0131] S4: In this embodiment, a total of 5 big data early warning models fall into the early warning area. The big data early warning models that fall into the early warning area are screened as comparison models, and the fluctuation trend I of each comparison model is obtained.

[0132] S5: Calculate the linear model fluctuation trend II in step S1, and compare fluctuation trend II with fluctuation trend I.

[0133] The inspection equipment is used to intermittently input key information data from each data transmission channel and transmit it to the control platform layer;

[0134] The inspection equipment includes a positioning module, a protocol module, a processing module, a data entry module, and an intranet connection module;

[0135] When in use, the inspection equipment is moved by inspection personnel to various work areas;

[0136] Furthermore, upon entering the work area, the inspection equipment obtains the corresponding data transmission channel through the positioning module and connects to the corresponding local area network through the protocol module.

[0137] The data entry module is used to enter manually input verification information data and transmit it to the processing module;

[0138] The processing module retrieves the corresponding information data from the local area network based on the verification information data and marks it as the comparison information data;

[0139] The processing module matches the verification information data with the comparison information data, generates key information data, and transmits it to the intranet connection module.

[0140] The intranet connection module is used to connect unidirectionally to the control platform layer, and after receiving key information data, it transmits it to the control platform layer.

[0141] After receiving key information data, the control platform layer compares it with the information data transmitted by the basic information exchange layer to obtain comparison information II;

[0142] The method for obtaining comparison information II includes the following steps:

[0143] Q1: Obtain the duration and time points of six consecutive input sets of verification information data;

[0144] Q2: Match the reference information data with the information data of the corresponding data transmission channel to obtain continuous data information for the corresponding time period;

[0145] Q3: Match the duration and time points of the verification information with continuous data to obtain the verification data information segment;

[0146] Q4: Compare multiple verification data with the calibration data information segment;

[0147] The comparison results are as follows: if the information data of each verification data and the information data of the corresponding time node in the verification data information segment are the same, then the information data is normal.

[0148] In this embodiment, after comparison, the comparison result of Q4 is: if the information data of each verification data is the same as the information data of the corresponding time node in the verification data information segment, then the information data transmission is normal;

[0149] A set of big data early warning models that do not represent normal operation show the same fluctuation trend I as fluctuation trend II, obtaining comparative information I. The control platform layer obtains the corresponding early warning information's security event level, equipment level, equipment level, frequency of damage to similar equipment, and security assessment by reading the big data early warning model, and sends the early warning information through the early warning module.

[0150] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of this template.

Claims

1. An industrial control network security early warning system, characterized in that, include: The basic information exchange layer includes multiple data transmission channels. After classifying the information data connected to the system based on features, the basic information exchange layer accesses the corresponding data transmission channels through the local area network and transmits the data to the control platform layer through the corresponding data transmission channels. The control platform layer, based on the information data classification received from the basic information exchange layer, sends model requests to the big data platform. A big data platform, which transmits the corresponding type of big data early warning model to the control platform layer based on the model request from the control platform; A local database, which is used to store the big data early warning models received by the control platform; After receiving various information data from the basic information exchange layer, the control platform first compares it with the big data early warning model in the local database to obtain comparison information I; Inspection equipment, used for intermittently inputting key information data from various data transmission channels and transmitting it to the control platform layer, the inspection equipment includes: The inspection device includes a positioning module and a protocol module. The positioning module obtains the corresponding data transmission channel, and the protocol module connects to the corresponding local area network. The data entry module is used to enter manually input verification information data and transmit it to the processing module; The processing module, based on the verification information data, obtains the corresponding information data from the local area network and marks it as the comparison information data; Furthermore, the processing module matches the verification information data with the comparison information data, generates key information data, and transmits it to the intranet connection module; The intranet connection module is used to connect unidirectionally with the control platform layer, and after receiving key information data, it transmits it to the control platform layer. After receiving key information data, the control platform layer compares it with the information data transmitted by the basic information exchange layer to obtain comparison information II. The early warning module sends early warning information of the corresponding level based on comparison information I and comparison information II.

2. The industrial control network security early warning system according to claim 1, characterized in that, The data transmission channel includes: The low-latency early warning module includes a primary model comparison unit, which is equipped with a primary early warning model corresponding to the production task. A network connection module is used to receive corresponding information data, copy it twice, and transmit it to the micro data processing module and the gateway module respectively. The micro data processing module is used to identify and acquire information data task nodes, match task nodes with information data to obtain identification datasets, and transmit them to the low-latency early warning module. After acquiring the identification dataset, the low-latency early warning module matches the task nodes with the first-level early warning module to obtain the node early warning model. Then, it compares the node early warning model with the information data to obtain the discrete coefficient α and transmits it to the gateway module.

3. The industrial control network security early warning system according to claim 2, characterized in that, When the low-latency early warning module is entered into the primary early warning model, it is in read-only mode.

4. The industrial control network security early warning system according to claim 3, characterized in that, The method for obtaining the primary early warning model includes the following steps: Step 1: Establish enterprise task templates for each data transmission channel, and divide the enterprise task templates into multiple task nodes; Step 2: Preset the comparison thresholds for each task node in the enterprise task template; Step 3: The control platform will compare the information data received from the basic information exchange layer with the big data early warning model of the big data platform; The comparison results include: A1: If the comparison result is less than the comparison threshold, the information data is marked as "recordable" and entered into the enterprise task template; A2: If the comparison result is not less than the threshold, then mark it as "needs to be replaced" when entering information data into the enterprise task template; When inspecting the information data in the future, the information data marked "needs to be replaced" will be replaced with information data that meets the A1 standard.

5. The industrial control network security early warning system according to claim 2, characterized in that, The method for obtaining the comparison information I includes the following steps: S1: Generate a continuous linear model by using the information data with the time axis as the coordinate. S2: The linear model is modified based on the discrete coefficient α to obtain the warning area; S3: Compare each big data early warning model with the early warning area; during the comparison, the early warning data that is the same as the information data in each big data early warning model is taken as the starting point and distributed along the coordinates; S4: Filter the big data early warning models that fall into the early warning area as comparison models, and obtain the fluctuation trend I of each comparison model; S5: Calculate the linear model fluctuation trend II in step S1, and compare fluctuation trend II with fluctuation trend I to obtain comparison information I.

6. The industrial control network security early warning system according to claim 1, characterized in that, The method for obtaining the comparison information II includes the following steps: Q1: Obtain the duration and time points of continuous input of multiple verification information data; Q2: Match the reference information data with the information data of the corresponding data transmission channel to obtain continuous data information for the corresponding time period; Q3: Match the duration and time points of the verification information with continuous data to obtain the verification data information segment; Q4: Compare multiple verification data with the calibration data information segment.

7. The industrial control network security early warning system according to claim 6, characterized in that, The comparison results for Q4 include: Z1: If the information data of each verification data and the corresponding time node in the information segment of the calibration data are the same, then the information data is normal; Z2: If at least one set of verification data differs from the information data at the corresponding time node within the verification data information segment, then the information data after that time node will be monitored, and an early warning module will be used to issue a warning.

8. The industrial control network security early warning system according to claim 1, characterized in that, The early warning information includes any combination of security event level, equipment level, frequency of damage to similar equipment, or security assessment.

Citation Information

Patent Citations

  • Industrial control network security warning method and system

    CN107040551A

  • Network information security intelligent analysis early warning management system based on multi-dimensional analysis

    CN114826691A

  • Industrial control safety risk analysis system and method

    CN115001934A