System and method for analyzing and controlling network traffic
By introducing a situation-aware network traffic analysis and control system into the edge computing system, and using data analysis models to identify and distinguish different types of network traffic, the problem of traffic control in edge computing is solved, enabling the protection of critical traffic and flexible control of non-critical traffic, thereby improving the security and stability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2022-04-26
- Publication Date
- 2026-06-02
AI Technical Summary
In the open application ecosystem of edge computing, existing technologies struggle to effectively distinguish and control different types of network traffic, impacting data security and stability. In particular, under dynamic network links and malicious threats, traditional methods are prone to false alarms or suppression of non-malicious traffic.
A situation-aware network traffic analysis and control system is adopted. Through policy definition permission components and network traffic analysis control components, machine-executable components and data analysis models are used to identify and distinguish between type-1 and type-2 traffic, providing dynamic control policies and improving identification and control based on context understanding and historical data.
It enables fine-grained control over different types of network traffic, reduces false alarms, ensures the transmission of critical traffic while allowing flexibility for non-critical traffic, and protects data privacy and system stability.
Smart Images

Figure CN117203941B_ABST
Abstract
Description
Technical Field
[0001] The subject matter disclosed herein relates to systems and methods for analyzing and controlling network traffic associated with at least one device residing between a first network and a second network.
[0002] Furthermore, the subject matter disclosed herein relates to a computer program and a computer-readable medium carrying the computer program. Background Technology
[0003] Edge computing enriches automated control with digital industrial applications located close to, and especially at, the shop floor. This means proximity to industrial machines, actuators, and other equipment. While adding new capabilities such as increased production transparency and optimization, predictive maintenance, condition monitoring, and visual perception, it also defines a middleman between operational and information technologies that must be carefully protected for platform stability, data privacy, and other IT security reasons. This aspect becomes even more critical in the context of open application ecosystems that allow OEMs, customers, and third parties to deploy and run their own applications on edge and / or IIoT (Industrial Internet of Things) devices—devices located close to critical production assets that analyze data and feed information back to operational equipment that influences production-related control flows. On the one hand, effective application scenarios, production control, and data privacy must not be negatively impacted, and on the other hand, the scope and flexibility of edge application scenarios must not be reduced without explicit transparency and control.
[0004] In such an edge ecosystem, the challenge is to allow third-party applications to flexibly extend traditional shop floor functionality while simultaneously protecting operators’ production processes, hardware assets, data privacy, and the added stability of edge platforms and applications, even in the presence of bugs, malicious applications, or external malicious threats.
[0005] One aspect of this issue is the need for devices for data and data flow control that can provide the necessary protection within an open application ecosystem approach for edge computing.
[0006] Regarding data traffic control, it is essential to properly assess and differentiate different types of network traffic in order to protect operators' production processes, hardware assets, data privacy, and the stability of edge platforms and edge applications, even in the presence of faulty or malicious applications or external malicious threats.
[0007] One possible approach is to apply a network bandwidth throttling method. In this method, a quota-oriented transmission buffer controls network link bandwidth over time, allowing time-limited traffic bursts, limiting traffic to a restricted upper limit of network bandwidth, and refilling the burst buffer over time if the traffic bandwidth is not fully utilized. This strategy allows for continuous operation of traffic related to, for example, high-frequency data, while simultaneously allowing for bandwidth-limited continuous or time-limited bursts for other traffic with several restrictions.
[0008] This strategy exhibits several drawbacks and limitations. It cannot strictly distinguish between different continuous and bursty traffic on the same network channel; instead, it simultaneously evaluates the union of all types of traffic on each channel. The boundary characteristics and thresholds of the control mechanism are not dynamic because they cannot automatically understand the actual use case in the form of a combined scenario formed by the contributions of individual traffic flows.
[0009] Using this traditional method, it is impossible to distinguish different types of traffic when traffic characteristics are similar. In dynamic network link situations, even valid Type-1 traffic can be analyzed as false positives (Type-2 / malicious traffic) and suppressed due to a lack of intelligence needed to understand the situation. The same applies to Type-2 traffic situations, which are more prone to error in dynamic scenarios because they frequently occur when edge applications initiate ad-hoc Type-2 network communications (such as attempting to download extremely large images or reporting that they are not suitable for bursty bandwidth quotas and are therefore suppressed, leading to customer dissatisfaction with inappropriate platform network quality).
[0010] From the context of Digital Rights Management (DRM) (e.g., https: / / www.capgemini.com / 2015 / 11 / drm-for-things-managingrights-and-permissions-for-iot, https: / / link.spr.inger.com / article / 10.1007 / s11042-020-086832), critical data is protected here by combining licensed applications with digital encryption. While this approach prevents unauthorized data access, it does not address the issue of properly handling mixed Type-1 and Type-2 traffic scenarios where protected data cannot be correctly categorized. DRM systems are also difficult to integrate and maintain (DRM license management on the client side), leading to increased costs associated with the development, testing, and necessary licensing of the DRM runtime.
[0011] Therefore, a sustainable and reliable solution to the above problems is needed. Summary of the Invention
[0012] To achieve this objective, the present invention provides a system for analyzing and controlling network traffic associated with at least one device residing between a first network and a second network, the system comprising: a memory storing machine-executable components; and a processor operatively coupled to the memory and configured to execute the machine-executable components, wherein the machine-executable components include a policy definition and authorization component and a network traffic analysis and control component, wherein the policy definition and authorization component is configured to provide at least one first data analysis model and at least one second data analysis model to the network traffic analysis and control component, the network traffic analysis and control component being configured to receive input data representing the network traffic, apply the at least one first data analysis model to or run on the input data, wherein the at least one first data analysis model identifies at least one network traffic condition, and applies the at least one second data analysis model to the at least one network traffic condition, wherein the at least one second data analysis model generates at least one rule that enables network traffic to be controlled according to the at least one rule.
[0013] Therefore, this system is a situation-aware decision-making system for analyzing and controlling network traffic, providing means for data and data traffic control, and thus enabling the required protection to be achieved in the open application ecosystem approach of edge computing.
[0014] It enables the correct identification of different categories (situations) of network transmissions and the accurate assessment and differentiation of different types of network traffic.
[0015] For example, Type-1 traffic can be traffic that is potentially time-critical (regarding workshop functionality) to system functionality, including critical edge applications based on essential network traffic scenarios (e.g., edge-arriving traffic with high-frequency, high-quality motion control or drivetrain data) as the operational foundation. Inappropriate context awareness and uncontrolledability of network conditions, characterized by data frequency and bandwidth, jitter, and latency, can adversely affect the data security and / or stability of edge computing platforms and applications.
[0016] Type-1 traffic must be properly classified, for example, to distinguish between valid high-frequency machine tool data transmission and invalid overload situations, such as faulty edge applications running high-frequency traffic congesting I / O resources and causing critical functions to become potentially unavailable.
[0017] Type-2 traffic can be any other network traffic that is not time-critical, such as best-effort data import from customer systems (e.g., maintenance tasks), best-effort import of back-end information for improving data analytics (e.g., external CAD / CAM models), or web-based best-effort access to data from ecosystem applications running on the Siemens IIoT / edge computing platform (e.g., downloading 2D / 3D charts and PDF reports). Because the combination of multiple Type-2 traffic requests can result in a Type-1 traffic situation, it is important to properly understand and assess the contribution of each individual traffic request to the overall network traffic situation, including both erroneous and potentially malicious network traffic.
[0018] Therefore, the system can guarantee data transmission associated with the first type of traffic (type-1 above), while allowing as much flexibility as possible in data transmission associated with the second type of traffic (type 2 above), and simultaneously detect and isolate invalid traffic.
[0019] In one implementation, network traffic associated with at least one device can be network traffic arriving at at least one device, network traffic on that device, and network traffic leaving that device.
[0020] In one implementation, the input data includes network traffic data and network traffic context data representing the context in which the network traffic occurs, wherein at least one first data analysis model performs context-based identification of at least one network traffic condition.
[0021] Therefore, this system allows for context-based understanding of overall traffic conditions and fine-grained control over individual network links, overcoming the aforementioned limitations.
[0022] This context-based approach for situational understanding and flexible control strategies helps reduce false alarm inferences in existing techniques.
[0023] In one implementation, network traffic data may include at least one of bandwidth, jitter, data loss frequency, latency, and network protocol.
[0024] In one implementation, network traffic context data may include at least one of the following: user identification that initiated the network traffic, permission information associated with the network traffic, information associated with the system environment (production or testing), and external temperature.
[0025] In one embodiment, the network traffic analysis and control component includes a network traffic analyzer component and a network traffic controller component, wherein the network traffic analyzer component is configured to apply / run the at least one first data analysis model to the input data, and the network traffic controller component is configured to apply the at least one second data analysis model to the at least one network traffic condition and control the network traffic according to the at least one rule.
[0026] In one implementation, a first data analysis model and / or a second data analysis model are trained or defined on historical network traffic data.
[0027] In one implementation, at least one first data analysis model analyzes the statistical and / or random and / or temporal correlations of network traffic to identify at least one network traffic scenario.
[0028] In one implementation, the at least one network traffic situation includes streaming continuous high-frequency sensor data from the first network to the system and / or requesting the download of files from the system by the second network.
[0029] In one implementation, the first data analysis model and / or the second data analysis model are based on or include a rule engine, a complex event processing engine, a constraint inferencer, a temporal logic inferencer, a descriptive logic inferencer, a simulation-based analyzer, a statistical inferencer, a mathematical optimizer, a neural network classifier, or a combination of one or more of these.
[0030] In one implementation, the network traffic analysis control component is configured to receive input data continuously as an input data stream and / or in the form of batch input data (e.g., every microsecond, millisecond, second, or minute), and while receiving the input data, to run at least one first data analysis model on the input data, wherein the at least one first data analysis model determines the correlation between the network traffic and past and / or current and / or expected / predicted network traffic (to identify the at least one network traffic condition).
[0031] Systems that use network traffic context data provide a general and flexible mechanism for protecting sensitive data (in terms of increased usability for application code developers) because they do not distinguish between “restricted” and “unrestricted” data, but rather assess and control all types of Type-1 and Type-2 network traffic in the same homogeneous way by understanding the full context of arrival, departure, and network traffic on the device that changes over time.
[0032] Therefore, depending on a comprehensive analysis of past, current, and anticipated scenarios of individual and combined traffic flows, the system can proactively control network traffic arriving at, departing from, and on devices. These scenarios can be relevant to derive information about system and network stability, as well as data privacy, based on historical, current, and / or simulated data.
[0033] In one implementation, the network traffic analysis control component includes or is configured to access a data repository (e.g., a file or database) for storing historical network traffic metrics and / or statistics, which are used to improve identification quality based on historical information.
[0034] To achieve the above objectives, the present invention also provides a computer-implemented method for analyzing and controlling network traffic associated with at least one device residing between a first network and a second network. The system includes a memory storing a machine-executable component, a processor operatively coupled to the memory and configured to execute the machine-executable component, wherein the machine-executable component includes a policy definition and permission component and a network traffic analysis and control component. The method includes: providing at least one first data analysis model and at least one second data analysis model to the network traffic analysis and control component by the policy definition and permission component; receiving input data representing the network traffic by the network traffic analysis and control component; applying the at least one first data analysis model to the input data by the network traffic analysis and control component, wherein the at least one first data analysis model identifies at least one network traffic condition; applying the at least one second data analysis model to the at least one network traffic condition by the network traffic analysis and control component, wherein the at least one second data analysis model generates at least one rule that enables network traffic control according to the at least one rule; and controlling the network traffic by the network traffic analysis and control component according to the at least one rule. Attached Figure Description
[0035] The above and other objects and advantages of the invention will become apparent upon consideration of the following detailed description of certain aspects, which only illustrate a few possible modes of practice. The description is taken in conjunction with the accompanying drawings, wherein like reference numerals always denote like parts, and wherein:
[0036] Figure 1 This is a block diagram illustrating a computing system that can be used to facilitate communication between OT- and IT- networks;
[0037] Figure 2 This is based on one possible implementation method. Figure 1 The block diagram,
[0038] Figure 3 This is based on one possible implementation method. Figure 1 The block diagram,
[0039] Figure 4 It is a flowchart of a method that can be executed by a network traffic control system, and
[0040] Figure 5 It is a computer-readable medium containing computer programs. Detailed Implementation
[0041] Figure 1 The computing system 100 includes one or more IIoT (Industrial Internet of Things) or edge devices 101, OT (Operational Technology) network 110, IT network 120, and network traffic control system 200.
[0042] For simplicity and where appropriate, one or more IIoT or edge devices are referred to below as device 101. Device 101 resides between OT network 110 and IT network 120.
[0043] OT network 110 may include one or more OT devices 111, such as industrial sensors and automation controllers. Each OT device 111 may be designed to communicate with other devices in OT network 110 and with one or more IIoT / edge devices 101. Some OT devices may be designed and used as OT data sources 112 that provide data (e.g., automation data and / or sensor signals) or OT data receivers 113 that receive data (e.g., automation control inputs and sensor and / or automation configuration data), or combinations thereof. Data sources may be referred to as data providers, data receivers may be referred to as data consumers, and combinations thereof may be referred to as data producers and consumers.
[0044] IT network 120 may include IT devices such as Manufacturing Execution System (MES), Enterprise Resource Planning (ERP) system, Computerized Maintenance Management System (CMMS), databases or data lakes in the field or cloud. Each element 121 in IT network 120 may be designed to communicate with other devices in IT network 120 and with one or more IIoT / edge devices 101. These elements may be designed and used as IT data source 122 that provides data (e.g., MES and ERP data or maintenance tasks from CMMS) or IT data receiver 123 that receives data (e.g., motor and workpiece quality data, predictive maintenance-related information, or detected process anomalies), or a combination thereof (IT data producers and consumers).
[0045] Device 101 is configured to establish a connection between OT 110 and IT network 120, and to process data from both networks and / or data on device 101 itself by routing between the networks, and optionally to process data to and from applications (e.g., in the field of data analytics) running on device 101 in proximity to industrial equipment (e.g., electric motors or machine tools).
[0046] Each IIoT / edge device 101 includes an application runtime space 102 that can host and run one or more applications 103 (e.g., data analytics applications). The application runtime space 102 can be designed as the runtime environment for the applications 103. Some applications 103 can be designed and used as data receivers 104 and / or data sources 105.
[0047] Data receiver 104 can be configured to receive data arriving at device 101 and data from application 103 running on device 101.
[0048] The network traffic control system 200 includes a policy definition and permission component 201, a network traffic analyzer component 202, and a network traffic controller component 203. The network traffic analyzer component 202 and the network traffic controller component 203 may correspond to the network traffic analysis and control component according to the present invention.
[0049] Each component can be implemented as a software and / or hardware component. For example, some components can be implemented as an ASIC (Application-Specific Integrated Circuit) integrated with one or more IIoT / edge devices 101. In one implementation, some components of the network traffic control system can be incorporated into a system-on-a-chip (SoC), which can be integrated with one or more IIoT / edge devices 101.
[0050] In one implementation, each IIoT / edge device 101 includes a network traffic analyzer component 202 and a network traffic controller component 203, such that different network traffic analyzer components 202 and network traffic controller components 203 reside on different IIoT / edge devices 101.
[0051] The policy definition permission component 201 can reside on device 101 (not shown) or a server, such as a backend server, for example, on an on-premises backend server or a cloud backend server.
[0052] The policy definition permission component 201 can be configured to receive data 204 based on network traffic data (device-specific network traffic data) associated with one or more IIoT / edge devices 101. This can also be historical or real-time data. The policy definition permission component 201 can also be configured to retrieve data from a data lake containing historical network traffic data associated with one or more IIoT / edge devices 101. This data can be device-specific network traffic data, or, if requested for IT security reasons, it can be preprocessed, anonymized / pseudo-named data characteristics regarding relevant network traffic features. Data 204 represents different network traffic control scenarios or situations.
[0053] In addition, the policy definition permission component is configured to generate (or provide) at least one first and at least one second data analysis model 205, 206 based on the received data 204.
[0054] In one implementation, data 204 includes device-specific network traffic data from different IIoT / edge devices 101, and policy definition permission component 201 generates different first and second data analysis models 205, 206 for different IIoT / edge devices 101.
[0055] The first data analysis model 205 and / or the second data analysis model 206 can be based on one or more neural networks. In this case, data 204 can be used as training data for the neural network.
[0056] The first and second data analysis models 205 and 206 are designed or configured to analyze and control device-specific network traffic based on the network traffic arriving at the device.
[0057] In one implementation, the first data analysis model 205 and / or the second data analysis model 206 are based on or include a rule engine, a complex event processing engine, a constraint inferencer, a temporal logic inferencer, a descriptive logic inferencer, a simulation-based analyzer, a statistical inferencer, a mathematical optimizer, a neural network classifier, or a combination of one or more of these.
[0058] In one implementation, the first data analysis model 205 includes a simulation-based analyzer and a neural network classifier. In this case, network traffic patterns can be classified based on expected / predicted network traffic.
[0059] In one implementation, the policy definition permission component 201 can be configured to allow manual (e.g., human) definition of rules, constraints or other types of policies, such that the first data analysis model 205 and / or the second data analysis model 206 can be designed as manually definable rule sets.
[0060] In one implementation, the policy definition permission component 201 can be configured to provide computer-aided support for manually defined one or more tasks, such as supervised machine learning. In this case, the first data analysis model 205 and / or the second data analysis model 206 can be designed as models based on machine learning algorithms, such as neural network-based models.
[0061] In one implementation, the policy definition permission component 201 can be configured to generate a first data analysis model 205 and / or a second data analysis model 206 completely automatically, i.e., without human interaction, for example, by utilizing unsupervised training. After generating the first data analysis model 205 and / or the second data analysis model 206, the policy definition permission component 201 can present the results to the user for acceptance.
[0062] The at least one first data analysis model 205 is transmitted to the network traffic analyzer component 202 of the corresponding IIoT / edge device.
[0063] At least one second data analysis model 206 is transmitted to the network traffic controller component 203 of the corresponding IIoT / edge device.
[0064] The network traffic analyzer component 202 may be located at one of the IIoT / edge devices or IIoT / edge device 101, and is configured to receive input data representing network traffic, and utilize at least one first data analysis model 205 to identify at least one network traffic condition. In one embodiment, the network traffic analyzer component 202 generates a description of at least one network traffic condition.
[0065] The network traffic associated with device 101 includes network traffic arriving at device 101, network traffic on device 101, and network traffic leaving device 101.
[0066] In one implementation, the input data includes network traffic data and network traffic context data representing the context in which the network traffic occurs. In this case, at least one first data analysis model 205 performs context-based identification of at least one network traffic condition.
[0067] Examples of network traffic data include, but are not limited to, at least one of the following: bandwidth, jitter, frequency of data loss, latency, network protocol, etc.
[0068] Examples of network traffic context data include, but are not limited to, at least one of the following: user identification that initiated the network traffic, permission information associated with the network traffic (e.g., whether the requester is permitted to use the network traffic), information associated with the system environment (production or testing), and external temperature.
[0069] Specifically, when the first and / or second data analysis model is based on a neural network or machine learning algorithm, the policy definition permission component 201 can use the received input data for training a new model or for further training of an existing model. In this case, it is transmitted to the policy definition permission component 201 as data 204.
[0070] In order to determine network traffic conditions, the first data analysis model 205 is designed to apply statistical, random, and / or temporal correlations of network traffic, namely, traffic arriving at and / or leaving one or more IIoT / edge devices 101 and / or traffic on one or more IIoT / edge devices 101 (on-device traffic).
[0071] Time correlation can be analyzed at predetermined time points or over (a predetermined) time period.
[0072] In one implementation, the network traffic analyzer component 202 can be configured to receive input data continuously and / or in batches (e.g., every microsecond, millisecond, second, or minute) as an input data stream. Upon receiving input data, the network traffic analyzer component 202 can run at least one first data analysis model 205 on the input data. During runtime, at least one first data analysis model 205 determines the correlation between network traffic and past and / or current and / or expected / predicted network traffic. For example, the network traffic analyzer component 202 can be configured to store input data at the beginning of a time period for which correlations are analyzed, such that past traffic can refer to traffic received within that predetermined time period. Typically, it will not be confused with historical network traffic. The expected network traffic can be generated, for example, through one of the aforementioned machine learning-based algorithms, such as through a simulation-based analyzer.
[0073] For example, the output of the first data analysis model 205 may be continuous high-frequency sensor data flowing to device 101 on OT network 110 and / or from IT network 120. Figure 2 The web client 121 in the ) receives a request to download large files in bulk from a third-party app.
[0074] Another example of this at least one network traffic scenario is a high-frequency (e.g., data points every 2 milliseconds) stream of high-quality data from a specific device in the OT network 110 prior to receiving a request to export high-frequency granular data to the IT network 120. In one implementation, before transmitting high-quality data to the IT network 120 ( Figure 3 Previously, high-frequency streams of high-quality data could be buffered on one of the IIoT / edge devices 101, for example, for several hours or a day.
[0075] In addition, the first data analysis model 205 can be used to assess initial overload, system stability criticality, and / or data privacy threats (e.g., if the receiver is not authorized to access industrial IoT data of a certain quality).
[0076] Network traffic analyzer component 202 is configured to transmit identified network traffic information to network traffic controller component 203. This can be done periodically or continuously. In particular, the information is transmitted in a computer-readable representation. For example, network traffic analyzer component 202 can generate JSON- or XML-based output.
[0077] In other words, the network traffic analyzer component 202 (periodically or continuously) sends the analysis results of the derived network traffic situation performed by means of one or more first data analysis models 205 to the network traffic controller component 203.
[0078] In one implementation, the network traffic controller component 203 may be based on or include a rule engine, a complex event processing engine, a constraint inferencer, a temporal logic inferencer, a descriptive logic inferencer, a simulation-based analyzer, a statistical inferencer, a mathematical optimizer, a neural network classifier, or a combination of one or more of these.
[0079] In one implementation, the network traffic controller component 203 is located at or at one of the IIoT / edge devices and is configured to use at least one second data analysis model 206 to control network traffic arriving at and / or leaving one or more IIoT / edge devices 101 and / or traffic on one or more IIoT / edge devices 101 (on-device traffic).
[0080] Figure 1 , Figure 2 and Figure 3 A network traffic controller component 203 is shown, comprising three interfaces 203a, 203b, and 203c, each of which can be used to allow unrestricted data transmission, completely block data transmission, or transform data in some way before transmission. Interface 203a is an interface to OT network 110, particularly to OT data receiver 113; interface 203b is an interface to application 103 within device 101; and interface 203c is an interface to IT network 120, particularly to OT data receiver 123.
[0081] In one implementation, the communication link between OT network 110, device 101, and IT network 120 can be protected by cryptographic means. For example, the information flow can be encoded using public key encryption or similar methods.
[0082] The network traffic controller component 203 uses data received from the network traffic analyzer component 202 (identified network traffic conditions) as input data to one or more second data analysis models 206, which output one or more rules or instructions regarding how to continue processing network traffic within the scope of the identified network traffic conditions. These instructions may include instructions associated with actions to be performed on the network traffic. Furthermore, the network traffic controller component 203 is configured to control network traffic according to one or more instructions / rules.
[0083] In other words, based on data / information associated with the classification of at least one network traffic situation received from the network traffic analyzer component 202, the network traffic controller component 203 controls the network traffic in the corresponding network traffic situation according to the output of one or more second data analysis models 206.
[0084] As mentioned above, the network traffic controller component 203 can periodically or continuously receive input from the network traffic analyzer component 202. This can improve the functionality and quality of network traffic control. Functionality and quality depend on the analysis of past, current, and / or predicted future network traffic conditions, and optionally on the correlation between multiple network traffic conditions.
[0085] Sending data (periodically or continuously) associated with identified network traffic conditions from the network traffic analyzer component 202 allows the network traffic controller component 203 to be configured and network traffic control to be improved.
[0086] The result of this configuration process is a network traffic controller component 203 that executes one or more second data analysis models 206, which define one or more control policies for each new / existing network traffic, either once, periodically, or continuously. The control policies (a set of rules and weights for the neural network) can allow for dynamic transformation of traffic, or blocking / delaying of selected traffic, by removing multiple portions of the transmitted industrial IoT data or by reducing the quality of the industrial IoT data (e.g., reducing the data resolution in data streams such as camera image streams, time-series data streams, and event data streams, and setting an optional data quality field to the new resolution value and an optional reason field containing the reason for the quality reduction due to transparency).
[0087] In summary, the network traffic control system 200 allows for the appropriate identification and control of different categories (situations) of network traffic in order to correctly assess and differentiate different types of network traffic.
[0088] In one implementation, there are two types of network traffic. Type-1 traffic is a type that is potentially time-critical (regarding shop floor functionality) to system functionality, which includes critical IIoT / edge applications (e.g., edge device arrival traffic with high-frequency, high-quality motion control or drivetrain data) as the basis for operation based on essential network traffic scenarios. Inappropriate context awareness and inadequate controllability of networking conditions, characterized by data frequency and bandwidth, jitter, and latency, can adversely affect the data security and / or stability of edge computing platforms and applications.
[0089] Type-2 traffic encompasses all other network traffic that is not time-critical for edge computing functions, such as best-effort data imports from customer systems (e.g., maintenance tasks), best-effort imports of contextual information to improve data analytics (e.g., external CAD / CAM models), or best-effort web-based access to data from ecosystem applications running on the Siemens IIoT / Edge Computing Platform (e.g., downloading 2D / 3D graphics and PDF reports). Because the combination of multiple Type-2 traffic requests can result in a Type-1 traffic situation, it is desirable to correctly understand and assess the contribution of each individual traffic request to the overall network traffic situation, including both erroneous and potentially malicious network traffic.
[0090] It is important to be able to classify Type-1 traffic, for example, to distinguish between valid high-frequency machine tool data transmission and invalid overload situations, such as faulty IIoT / edge device applications running high-frequency traffic congesting I / O resources and causing potential unavailability of critical functions.
[0091] The following description is essentially limited to and Figure 1 Differences in exemplary implementations, see reference Figure 1 The exemplary implementation described herein relates to a system that maintains the same characteristics.
[0092] Figure 2 It shows Figure 1 In system 100, the policy definition permission component 201 provides the same set of rules 205 and 206 to the network traffic analyzer component 202 and the network traffic controller component 203. This set includes two rules:
[0093] 1) Allow periodic downloads of large blocks of data, where downloads must follow each other with a delay of at least 5 minutes.
[0094] 2) Block all other traffic.
[0095] OT network 110 is designed as a machine network, and IT network 120 is designed as a factory network. OT device 111 can be designed as a machine tool, which may include control units and connector devices for high-frequency machine data transmission. Web client 121 in factory network 120 can continuously request monitoring reports.
[0096] Machine data source 110 provides Type-1 traffic, i.e., high-frequency machine tool data (stream), to network traffic analyzer component 202. Application 103 running on device 101 further requests this data. It is understood that the requests and streaming data pass through network traffic analyzer component 202 and network traffic controller component 203. For example, the data stream to application 103 will pass through interface 203b of network traffic controller component 203.
[0097] Application 103 running on device 101 may be a third-party app (i.e., an app not developed by the entity managing the machines and / or the factory network, nor by the entity managing the devices). Application 103 may be a third-party high-frequency machine data monitoring application. App 103 may include a web server for downloading monitoring reports from machine network 110.
[0098] After analyzing network traffic according to the rules provided by the policy definition permission component 201, the network traffic analyzer component 202 identifies the following network traffic conditions: "Third-party edge application 103 is continuously receiving high-quality data from machine 111 on OT network 110; there are batch download requests for large files of third-party app 103 by web client 121 in IT (factory) network 120," and passes this information to the network traffic controller component 203. In this case, the first data analysis model 205 and the second data analysis model 206 can be based on the rule engine.
[0099] Under the conditions proposed by the policy definition permission component 201, and based on the identified network traffic conditions, the network traffic controller component 203 can perform the following actions on the network traffic.
[0100] • Allows files to be downloaded via interface 203c to web client 123 on factory network 120 with maximum bandwidth, without converting or blocking traffic.
[0101] • Block all other outgoing traffic (e.g., traffic to machine tool data receiver 113),
[0102] • If a new traffic request is received or existing traffic characteristics are changed, the situation is reassessed.
[0103] Go to Figure 3 The policy definition permission component 201 defines the following rules:
[0104] 1) Allow all streaming traffic to the client, provided there is no overload.
[0105] 2) Overload or unauthorized receiver (data privacy): Reduce the frequency of data points to redirect all outgoing traffic to the IT network.
[0106] OT network 110 can be designed as a machine network, and IT network 120 can be designed as a factory network. OT device 111 can be designed as a machine tool, which may include a control unit and connector devices for high-frequency machine data transmission. Web client 121 in factory network 120 can continuously request high-frequency and / or high-quality data.
[0107] The network traffic analyzer component 202 provides the following network traffic information for network traffic analysis: "Third-party machine data monitoring application 103 is continuously receiving high-quality data from machine 111 on OT network 110; there are requests for high-quality data to be transmitted frequently from third-party app 103 by web client 121 in IT (factory) network 120, which will lead to network overload or system instability."
[0108] Based on the above rules and the identified network traffic conditions, the network traffic controller component 203 controls the network traffic accordingly:
[0109] • Transformed and transmitted via interface 203c: Low-quality / low-frequency data is transmitted to a web client 123 in an IT network 120 with limited bandwidth.
[0110] • Block all other outgoing traffic.
[0111] • If a new traffic request is received or existing traffic characteristics are changed, the situation is reassessed.
[0112] It should be understood that if data associated with network data is used to improve the first data analysis model 205 and the second data analysis model 206 provided by the policy definition and permission component 201, the quality of network traffic analysis and control can be improved. When available, the improved model can be uploaded to the network traffic analyzer component 202 and / or the network traffic controller component 203 and deployed there to replace the old model.
[0113] In one implementation, the network traffic analyzer includes or accesses a data repository (e.g., a file or database) for storing historical network traffic metrics / statistics, which are used to improve the classification quality of components based on historical information.
[0114] In one implementation, the network traffic controller 203 of the network channel and / or the transmitted data and / or network statistics / metrics and / or analysis models and / or network traffic analyzer 202 components is configured to be protected by cryptographic symmetric or asymmetric encryption for arrival, departure and / or data transmission on the device for confidentiality reasons.
[0115] Figure 4 This demonstrates that network traffic control systems, such as those controlled by... Figures 1 to 3 The flowchart of the method executed by the network traffic control system 200.
[0116] The method includes step S1 - the policy definition permission component 201 provides at least one first data analysis model 205 and at least one second data analysis model 206 to the network traffic analysis and control component, which may include a network traffic analyzer component 202 and a network traffic controller component 203.
[0117] Step S2 - The network traffic analysis and control component receives input data representing network traffic.
[0118] Step S3 - The network traffic analysis and control component applies at least one first data analysis model 205 to the input data, wherein the at least one first data analysis model 205 identifies at least one network traffic condition.
[0119] Step S4 - The network traffic analysis and control component applies the at least one second data analysis model 206 to the at least one network traffic situation, wherein the at least one second data analysis model 206 generates at least one rule that can control network traffic based on the at least one rule.
[0120] Step S5 - The network traffic analysis and control component controls network traffic according to at least one rule.
[0121] Figure 5 A computer-readable medium 2000 having a computer program 2001 is shown. The computer program 2001 includes instructions that, when executed by the network traffic control system 200, cause the network traffic control system 200 to perform the steps of the method described above.
[0122] The above embodiments of the invention are presented for illustrative purposes and not for limitation. In particular, the embodiments described with respect to the drawings are merely a few examples of the embodiments described in the introductory section. The technical features described with respect to the system can be applied to enhance the methods disclosed herein, and vice versa.
Claims
1. A system for analyzing and controlling network traffic associated with at least one device (101) residing between a first network (110) and a second network (120), the system (200) comprising: The memory for storing machine-executable components (201, 202, 203) A processor, operatively coupled to the memory, and configured to execute the machine-executable components (201, 202, 203), wherein the machine-executable components (201, 202, 203) include a policy definition and permission component (201) and a network traffic analysis and control component (202, 203), wherein the policy definition and permission component (201) is configured to... - Provide at least one first data analysis model (205) and at least one second data analysis model (206) to the network traffic analysis and control components (202, 203). The network traffic analysis and control components (202, 203) are configured to - Receive input data, wherein the input data includes network traffic data and network traffic context data representing the context in which the network traffic occurred. - The at least one first data analysis model (205) is applied to the input data, wherein the at least one first data analysis model (205) performs context-based identification of at least one network traffic condition. - The at least one second data analysis model (206) is applied to the at least one network traffic condition, wherein the at least one second data analysis model (206) generates at least one rule, and the network traffic can be controlled according to the at least one rule. - Control the network traffic according to at least one of the rules.
2. The system according to claim 1, wherein, The network traffic associated with the at least one device (101) is the network traffic arriving at the at least one device (101), the network traffic on the at least one device (101), and the network traffic leaving the at least one device (101).
3. The system according to claim 1 or 2, wherein, The network traffic data includes at least one of bandwidth, jitter, data loss frequency, latency, and network protocol.
4. The system according to any one of claims 1 to 3, wherein, The network traffic context data includes at least one of the following: identification of the user initiating the network traffic, permission information associated with the network traffic, information associated with the system environment, and external temperature.
5. The system according to any one of claims 1 to 4, wherein, The network traffic analysis and control component includes a network traffic analyzer component (202) and a network traffic controller component (203), wherein The network traffic analyzer component (202) is configured to apply the at least one first data analysis model (205) to the input data, and The network traffic controller component (203) is configured to apply the at least one second data analysis model (206) to the at least one network traffic condition and to control the network traffic according to the at least one rule.
6. The system according to any one of claims 1 to 5, wherein, The first data analysis model (205) and / or the second data analysis model (206) are trained or defined on historical network traffic data.
7. The system according to any one of claims 1 to 6, wherein, The at least one first data analysis model (205) analyzes the statistical and / or random and / or temporal correlation of network traffic to identify the at least one network traffic situation.
8. The system according to any one of claims 1 to 7, wherein, The at least one network traffic scenario includes streaming continuous high-frequency sensor data from the first network to the system and / or requesting the second network to download files from the system.
9. The system according to any one of claims 1 to 8, wherein, The first data analysis model (205) and / or the second data analysis model (206) are based on or include a rule engine, a complex event processing engine, a constraint inferencer, a temporal logic inferencer, a descriptive logic inferencer, a simulation-based analyzer, a statistical inferencer, a mathematical optimizer, a neural network classifier, or a combination of one or more of these.
10. The system according to any one of claims 1 to 9, wherein, The network traffic analysis and control components (202, 203) are configured to receive the input data continuously as an input data stream and / or in batches as input data. While receiving the input data, the at least one first data analysis model (205) is run on the input data, wherein the at least one first data analysis model (205) determines the correlation between the network traffic and past and / or current and / or expected network traffic.
11. The system according to any one of claims 1 to 10, wherein, The network traffic analysis and control components (202, 203) include or are configured to access a data repository for storing historical network traffic metrics and / or statistics, which are used to improve identification quality based on historical information.
12. A computer-implemented method for analyzing and controlling network traffic associated with at least one device (101) residing between a first network (110) and a second network (120), the system (200) comprising: The memory for storing machine-executable components (201, 202, 203) A processor, operatively coupled to the memory and configured to execute the machine-executable components (201, 202, 203), wherein the machine-executable components (201, 202, 203) include a policy definition and permission component (201) and a network traffic analysis and control component (202, 203), the method comprising: The policy definition permission component (201) provides at least one first data analysis model (205) and at least one second data analysis model (206) to the network traffic analysis and control components (202, 203). The network traffic analysis and control components (202, 203) receive input data, which includes network traffic data and network traffic context data representing the context in which the network traffic occurs. The network traffic analysis and control components (202, 203) apply the at least one first data analysis model (205) to the input data, wherein the at least one first data analysis model (205) performs context-based identification of at least one network traffic condition. The network traffic analysis and control components (202, 203) apply the at least one second data analysis model (206) to the at least one network traffic condition, wherein the at least one second data analysis model (206) generates at least one rule, and the network traffic can be controlled according to the at least one rule. The network traffic is controlled by the network traffic analysis and control components (202, 203) according to the at least one rule.
13. A computer program comprising instructions that, when executed by a computing system, cause the computing system to perform the steps of the method according to claim 12.
14. A computer-readable medium comprising instructions that, when executed by a computing system, cause the computing system to perform the steps of the method according to claim 12.