A PLC runtime abnormal behavior identification method and system based on a behavior model

By monitoring the execution sequence of PLC programs, system resources, and input/output behavior, a behavioral model is constructed, which solves the problem that PLCs cannot accurately and promptly identify abnormal behavior in industrial control networks. This enables rapid identification and proactive defense against abnormal behavior, improving the system's security and stability.

CN117150406BActive Publication Date: 2026-06-02ZHEJIANG SUPCON RES

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG SUPCON RES
Filing Date
2023-09-04
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing PLCs are unable to accurately and promptly identify abnormal behavior in industrial control networks, making it difficult to prevent safety hazards.

Method used

An abnormal behavior identification method based on behavior models is adopted. By monitoring the execution sequence of PLC programs, system resources, and input/output behavior, normal and abnormal behavior models are constructed to achieve rapid identification and proactive defense against abnormal behavior.

Benefits of technology

It enables accurate identification and timely defense against abnormal behavior in PLC programs, thereby improving the security and stability of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117150406B_ABST
    Figure CN117150406B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of industrial control safety, in particular to a PLC runtime abnormal behavior identification method and system based on a behavior model, which comprises the following steps: S1, in the PLC program running process, a behavior monitoring module performs real-time monitoring and preliminarily judges abnormal behavior; S2, normal behavior and abnormal behavior are filtered out respectively according to the monitoring results of the behavior monitoring module, and behavior rule extraction is performed on the behavior monitoring module; and S3, behavior modeling is performed based on the extracted behavior rules, normal behavior model generation or update of behavior rule information files is performed on the detected normal behavior, and abnormal behavior model learning of abnormal characteristics, rapid abnormal identification and measure processing are performed on the detected abnormal behavior. The application uses a data model to describe the normal behavior model of the control behavior and the process behavior through the dependent relationship of the normal input and output data of the control and controlled process, so that the intrusion behavior can be accurately identified, and active defense can be performed.
Need to check novelty before this filing date? Find Prior Art