Fieldbus network silent intrusion device detection method and related device thereof
By sampling and differentially comparing the communication signals of benign terminal devices in the fieldbus network, and using the hypothesis testing principle to generate detection thresholds, the problem of detecting silent intrusion devices is solved, and fast and low-cost intrusion device detection is achieved in the fieldbus network.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XI AN JIAOTONG UNIV
- Filing Date
- 2023-11-02
- Publication Date
- 2026-05-29
Smart Images

Figure CN117375976B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of intrusion detection technology, specifically relating to a method for detecting silent intrusion devices in a fieldbus network and related equipment. Background Technology
[0002] The rapid development of distributed control technology has led to the widespread application of fieldbus networks in industrial control systems (ICSs). In systems such as smart cities and smart homes, a massive number of terminal devices (e.g., sensors and actuators) are connected via fieldbuses. The complex wiring and weak physical boundary protection make it easy for attackers to connect unauthorized external devices to any location on the bus and launch attacks. Furthermore, various bus protocols are designed to ensure real-time data transmission and lack the ability to carry complex encryption algorithms; intrusive devices can remain lurking in the network for extended periods, silently eavesdropping on network communications without generating any abnormal traffic, leading to the leakage of critical system information.
[0003] Current methods for detecting silent intrusion devices on industrial control systems' fieldbuses face the following main difficulties in practical design:
[0004] (1) Silent external intrusion devices do not generate any abnormal traffic when eavesdropping on the network, making traditional network traffic-based intrusion detection systems (IDSs) completely ineffective.
[0005] (2) Most existing methods that use dedicated detection equipment to actively send detection signals are prone to interfering with the normal operation of benign terminals and may also introduce additional operational risks to industrial control systems.
[0006] (3) Most existing detection methods do not take into account the interference caused by changes in the detection environment after deployment and the aging of benign terminal equipment, and cannot guarantee the long-term effectiveness of the methods. Summary of the Invention
[0007] The technical problem to be solved by the present invention is to provide a method and related equipment for detecting silent intrusion devices in fieldbus networks, which addresses the shortcomings of the prior art and solves the technical problem that silent intrusion devices that do not generate any abnormal traffic cannot be identified in the digital signal domain (content and statistical characteristics of network traffic).
[0008] The present invention adopts the following technical solution:
[0009] A method for detecting silent intrusion devices in a fieldbus network includes the following steps:
[0010] The communication signals of all benign terminal devices in the fieldbus network are sampled; the amplitude characteristics of the communication signals are extracted and channel state characteristics reflecting the connection status of the terminal devices are constructed collaboratively; the channel state characteristics are differentially compared with the channel state group fingerprint stored in the monitoring equipment, and the detection threshold is generated in a low-computational-cost manner using the hypothesis testing principle, and intrusion signal detection is performed in the differential signals.
[0011] Specifically, sampling of normal communication signals involves the following steps:
[0012] At any node location on the bus network, the communication signals generated by all benign terminal devices on the bus are passively sampled in units of one communication cycle, and the number of communication cycles N to be sampled is determined based on the signal-to-noise ratio of the current communication signals of each device. After meeting the requirements of the current scenario, it is determined whether it is the first sampling of the periodic communication signal. If the fingerprint database of the monitoring device is empty, the processed sampled data is stored as a channel state group fingerprint, which serves as a fingerprint signal reflecting the physical security of the network.
[0013] Furthermore, benign terminal devices periodically report measurement data or execute predetermined instructions, and the resulting communication data is transmitted on the bus in the form of broadcast. The periodic transmission of measurement data or predetermined instructions is a common workflow in various industrial control systems.
[0014] Specifically, extracting the amplitude characteristics of communication signals and collaboratively constructing channel state characteristics reflecting the connection status of terminal devices involves the following steps:
[0015] The high and low level sampling points of each observed signal are standardized to the same voltage level; the channel state characteristics are collaboratively characterized using the voltage amplitude characteristics of each benign terminal in the network; for the N instructions generated by the i-th device, the amplitude signals are integrated using a window-skipping average, and then further integrated based on the arithmetic mean of the signals from the n benign terminals. This leads to the final channel state characteristics.
[0016] Specifically, the channel state characteristics are differentially compared with the channel state group fingerprints stored in the monitoring equipment to obtain the difference signal:
[0017]
[0018] Where Δ(·) represents the subtraction operator, and θ represents the intrusion signal and The proportionality coefficient between them; ω s [k] represents Gaussian white noise in the difference signal, noattack indicates that the network has not been compromised, and attacked indicates that the network has been compromised by an intruding device.
[0019] Specifically, intrusion signal detection in differential signals involves:
[0020] If an intrusion signal is detected in the difference signal, it is determined that the fieldbus network has been subjected to unauthorized connection of a silent intrusion device, and an alarm message is sent to the operation and maintenance center.
[0021] If no intrusion signal is detected in the difference signal, the fieldbus network is determined to be in a physically secure state, and the monitoring equipment will then transmit the channel state characteristics. Update the channel state group fingerprint to be used for the next detection and switch to continue listening state.
[0022] Furthermore, the detection model for intrusion devices is as follows:
[0023]
[0024] The false positive rate (FPR) of the detection model is:
[0025]
[0026] in, This represents the detectable feature obtained by calculating the product between the difference signal and the channel state group fingerprint, where λ represents the threshold adjustment coefficient, and η0 represents the likelihood ratio detection threshold in hypothesis testing theory; η s It is an adaptive detection threshold adjusted by a threshold adjustment coefficient, N. s s represents the number of sampling points obtained on a command differential signal. d [k] represents the difference signal obtained by differentially comparing the channel state characteristics with the channel state group fingerprints stored in the monitoring equipment. H1 represents the channel state group fingerprint, and H1 represents the alternative hypothesis that the network is under attack. H0 This represents the null hypothesis that the network has not been attacked, and σ represents the standard deviation of Gaussian white noise in the difference signal. This represents the probability density function of the detectable feature given the null hypothesis as a priori. Indicates detectable features L represents the energy of the channel group fingerprint. The integral variable after substitution.
[0027] Secondly, embodiments of the present invention provide a silent intrusion device detection system for fieldbus networks, comprising:
[0028] The sampling module samples the communication signals of all benign terminal devices in the fieldbus network;
[0029] The module extracts the amplitude characteristics of communication signals and collaboratively constructs channel state characteristics that reflect the connection status of terminal devices;
[0030] The detection module performs differential comparison between the channel state characteristics and the channel state group fingerprint stored in the monitoring device, and generates a detection threshold in a low-computational-cost manner using the hypothesis testing principle, and detects intrusion signals in the differential signals.
[0031] Thirdly, a computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the above-described fieldbus network silent intrusion device detection method.
[0032] Fourthly, embodiments of the present invention provide a computer-readable storage medium including a computer program, which, when executed by a processor, implements the steps of the above-described fieldbus network silent intrusion device detection method.
[0033] Compared with the prior art, the present invention has at least the following beneficial effects:
[0034] A method for detecting silent intrusion devices in a fieldbus network is proposed. This method utilizes monitoring equipment to sample the normal communication signals of all benign terminal devices in the fieldbus network, extracting amplitude features and collaboratively constructing channel state features reflecting the connection status of the terminal devices. These features are then differentially compared with a pre-stored channel state fingerprint in the monitoring equipment. A detection threshold is generated using hypothesis testing principles at low computational cost, enabling rapid detection of intrusion signals within the differential signals. This effectively determines the presence of external silent intrusion devices in the fieldbus network. The detection scheme also supports rapid updates of the channel state fingerprint, adapting to changes in the detection environment. This solves the security problem of passively and adaptively detecting external silent intrusion devices in a fieldbus network.
[0035] Furthermore, from the perspective of constructing the equivalent circuit of the fieldbus network, the slight influence of external silent intrusion devices on the voltage amplitude of communication signals was analyzed, thereby generating an intrusion signal reflecting the presence of the intrusion device in the analog signal domain (voltage signal).
[0036] Furthermore, the amplitude characteristics of the communication signals are extracted and a channel state reflecting the connection status of the terminal devices is constructed in a coordinated manner. This eliminates the need for complex waveform alignment, simplifies the differential process between channel state characteristics and channel state group fingerprints, and utilizes the amplitude characteristics of the communication signals of each benign device to globally reflect the connection status of the devices.
[0037] Furthermore, the channel state characteristics are differentially compared with the channel state group fingerprints stored in the monitoring equipment to obtain the difference signal, which is then used for intrusion detection based on the hypothesis testing principle. By performing window-skipping averaging and arithmetic averaging on the differences generated in the channel state group fingerprints, the interference of environmental noise on the detection is minimized.
[0038] Furthermore, by utilizing hypothesis testing principles in the differential signals, detection thresholds can be quickly generated under constant false alarm rate constraints. This eliminates the high cost of training with a large number of data samples required in traditional machine learning-based detection models, ensuring both real-time detection and low computational cost.
[0039] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.
[0040] In summary, this invention utilizes the impact of intrusion devices on the load of the bus network to uncover the differences in the voltage amplitude of communication signals, and uses hypothesis testing principles to realize a method for detecting silent intrusion devices in fieldbus networks based on channel state group fingerprints.
[0041] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0042] Figure 1 This diagram illustrates the impact of intrusive devices on the impedance distribution of the fieldbus network.
[0043] Figure 2 This is an observational signal diagram of a benign terminal periodically sending commands under the influence of an intrusive device.
[0044] Figure 3 This is a group fingerprint of channel states based on the voltage amplitude characteristics of the observed signal;
[0045] Figure 4 This is a connection diagram of intrusion devices and monitoring devices in a real-world smart power distribution cabinet.
[0046] Figure 5 A diagram showing the observed signals of the distribution cabinet under the influence of intruding equipment;
[0047] Figure 6 This is a flowchart of the present invention;
[0048] Figure 7 A schematic diagram of a computer device provided in an embodiment of the present invention;
[0049] Figure 8 This is a block diagram of a chip according to an embodiment of the present invention;
[0050] Figure 9 Schematic diagrams of four intrusion scenarios designed for the use of three different protocol converters as intrusion devices in a real power distribution cabinet;
[0051] Figure 10 The diagram shows the observed signals in the distribution cabinet under four intrusion scenarios. Detailed Implementation
[0052] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] In the description of this invention, it should be understood that the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0054] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0055] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Additionally, the character " / " in this invention generally indicates that the preceding and following objects have an "or" relationship.
[0056] It should be understood that although terms such as first, second, third, etc., may be used in the embodiments of the present invention to describe the preset range, these preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from one another. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.
[0057] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0058] The accompanying drawings illustrate various structural schematic diagrams according to embodiments disclosed in this invention. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.
[0059] This invention provides a method for detecting silent intrusion devices in a fieldbus network. By sampling the normal communication signals of all benign terminal devices in the fieldbus network using monitoring equipment, amplitude features are extracted and collaboratively constructed to reflect the connection status of the terminal devices. These features are then differentially compared with a pre-stored channel state fingerprint in the monitoring equipment. A detection threshold is generated using hypothesis testing principles with low computational cost, enabling rapid detection of intrusion signals within the differential signals. This effectively determines the presence of external silent intrusion devices in the fieldbus network. The detection scheme also supports rapid updates of the channel state fingerprint, adapting to changes in the detection environment. This solves the security problem of being unable to passively and adaptively detect external silent intrusion devices in a fieldbus network.
[0060] The present invention provides an application example of an attack scenario for a silent intrusion device detection method for fieldbus networks based on channel state group fingerprinting. In an RS485 / CAN bus network, an attacker directly connects an external intrusion device to the bus and uses the device to silently listen to and steal unencrypted communication information broadcast on the bus, endangering the security and stable operation of the network. The following case provides a detailed analysis.
[0061] Please see Figure 1 In common RS485 / CAN fieldbuses, differential twisted-pair cables are used to transmit signals and commands in order to resist common-mode noise. Termination resistors are connected across both ends of the cable to cancel signal reflections, and the resistance value of each termination resistor is matched with the characteristic impedance of the cable. Figure 1 The equivalent circuit of a fieldbus network connected to n benign terminal devices is shown, where the input resistance of each terminal device when receiving messages (receive mode) is represented by Z. i ,(i=1,2,...,n).
[0062] When the i-th device sends a message (send mode), it is equivalent to having internal resistance. Differential signal source x i (t). At this point, the input resistance of each authorized device, the network cable resistance, and the network termination resistance together constitute the resistance distribution set representing all resistances in the initial network.
[0063] When the input resistance is Z intru When an intrusion device is accessed without authorization, the corresponding resistance distribution set of the attacked network changes. Verification through real and simulation experiments revealed that for any authorized device i, when sending a message, and The output resistance values are all different.
[0064] Therefore, the differences under any device number i can be shared. It indicates the presence of an intruding device.
[0065] Essentially, when any device communicates with other node devices, the fieldbus network exhibits a unique impedance distribution. The access behavior of an intruding device causes a change in this impedance distribution, which is reflected in the differential signal of any device's message, thus generating n intrusion signals. This invention attempts to extract and collaboratively utilize these n intrusion signals to detect the presence of an intruding device.
[0066] Please see Figure 6 Unauthorized access by any silent intrusion device will inevitably alter the bus network load, and the resulting changes in the bus network load can be observed from the voltage amplitude characteristics of the communication signals of any benign terminal device. In response to this type of intrusion, and based on the above analysis of network impedance distribution, this invention provides a method for detecting silent intrusion devices in a fieldbus network, comprising the following steps:
[0067] S1. Each benign terminal device periodically sends communication data;
[0068] Under normal operating conditions of a fieldbus network, each benign terminal device periodically reports measurement data or executes predetermined instructions. The resulting communication data is transmitted on the bus in a broadcast manner. The periodic transmission of measurement data or predetermined instructions is a common workflow in various industrial control systems.
[0069] S2. Use monitoring equipment to collect communication signals from all benign terminals within one communication cycle;
[0070] The monitoring equipment used can be directly connected to any location on the fieldbus like a normal node, without requiring any hardware or software modifications to existing terminals or the bus topology, ensuring zero disruption to the normal operation of the fieldbus network. Specific steps include:
[0071] S201. When the communication signal is sampled for the first time at any node of the bus network using a monitoring device, the differential signal of any command sent by the i-th device is represented as discrete point x. i [k], Figure 2 The observed signal diagram is shown when a benign terminal periodically sends commands under the influence of an intruding device. The observed signals are generated by the i-th device in the initial network.
[0072] The observed signal y of the N instructions generated by the i-th device i [k] is:
[0073]
[0074] Where k = 1, 2, ..., N·N s N s N represents the number of sampling points that can be obtained from the differential signal of a single instruction. s The value of N is determined by the bit length l of the instruction frame, the communication baud rate B, and the sampling rate f, i.e., N s =l·f / B.
[0075] Furthermore, the symbol f(·) indicates the impedance distribution The operator affecting the interaction between the observed signal and the command differential signal. ω i [k] represents Gaussian white noise under environmental influence. At this time, the observation signals of all n benign terminals are stored in the monitoring device as channel state group fingerprints after step S3 is completed.
[0076] S202. When the monitoring equipment performs the intrusion detection process before the first sampling, the observed signals of all n benign terminals will directly execute step S4 after step S3 is completed.
[0077] If at this time, in the attacked fieldbus, due to Due to the influence of this, the observation signal of the i-th device command will correspondingly become y i [k] and The voltage amplitude difference between them can reflect the presence of an intrusion device; this difference is the intrusion signal generated by the insertion of the intrusion device.
[0078] S3. Signal amplitude feature extraction and collaborative averaging;
[0079] S301. To simplify the extraction process of intrusion signals, the high-level and low-level sampling points of each observed signal are first standardized to the same voltage level.
[0080] Please see Figure 3 This is a channel state group fingerprint based on the voltage amplitude characteristics of the observed signal; the normalization process of the observed signal is represented as follows:
[0081]
[0082] in, and They represent y respectively i [k] represents the high and low level sampling points, and ave(·) represents the average operator of the sampling points.
[0083] S302. To minimize the interference of environmental noise on intrusion signals, the voltage amplitude characteristics of each benign terminal in the network are used to collaboratively characterize the channel state characteristics. For the N instructions generated by the i-th device, the amplitude signals are integrated by window skipping and averaging. Then, the arithmetic average of the signals from the n benign terminals is further integrated. This leads to the final channel state characteristics;
[0084] The process of using window averaging to integrate the amplitude signal can be represented as follows:
[0085]
[0086] Integrating n benign terminals based on arithmetic mean The process is represented as:
[0087]
[0088] Where k = 1, 2, ..., N s .
[0089] S4. Comparison of amplitude differences based on channel state group fingerprints;
[0090] Combining the above steps, the channel state fingerprint obtained in the initial network state is represented as follows: The channel state features acquired during the post-deployment detection process are represented as follows:
[0091] The channel state characteristics are differentially compared with the channel state fingerprint stored in the monitoring equipment to obtain the difference signal:
[0092]
[0093] Where Δ(·) represents the subtraction operator, and θ represents the intrusion signal and The proportionality coefficient between them; this proportionality coefficient is an unknown parameter under the influence of different intrusion device input resistances and access locations; ω s [k] represents Gaussian white noise in the difference signal.
[0094] S5. Intrusion signal detection based on hypothesis testing principle;
[0095] Let H0 be the null hypothesis that the network is not under attack, and H1 be the alternative hypothesis that the network is under attack. Then we have
[0096]
[0097] Where k = 1, 2, ..., N s .
[0098] Let ω s The variance of [k] is σ 2 , i.e., ω s [k]~N(0,σ 2 ); then s d [k] satisfies (s) d [k]|H0)~N(0,σ 2 )and Accordingly, N s 3D joint Gaussian random variable s d The probability density function is expressed as:
[0099]
[0100]
[0101] Based on p(s) d |H1), the estimated value of θ is calculated based on the maximum likelihood estimation and is expressed as θ e The details are as follows:
[0102]
[0103] At this point, the likelihood ratio decision equation is derived based on the Bayesian criterion, which is the detection model for intrusion devices in this invention:
[0104]
[0105] in, This represents the detectable features obtained by calculating the product between the difference signal and the channel state group fingerprint. η represents the threshold adjustment coefficient, and η0 represents the likelihood ratio detection threshold in hypothesis testing theory; η s It is an adaptive detection threshold adjusted by a threshold adjustment coefficient.
[0106] Furthermore, the false alarm rate of the detection model is expressed as:
[0107]
[0108] The above formula represents the control of the false alarm rate of the detection model by adjusting λ.
[0109] Based on the standard normal distribution table, considering that the maximum false alarm rate is 0%, 1%, and 10%, the corresponding λ values are 3.9, 2.58, and 1.65, respectively. To obtain the lowest false alarm rate, this invention sets λ to 3.9 in actual deployment.
[0110] If an intrusion signal is detected in the difference signal, it is determined that the fieldbus network has been subjected to unauthorized connection by a silent intrusion device, and step S6 is continued; if no intrusion signal is detected in the difference signal, the fieldbus network is determined to be in a physically secure state, and the monitoring device will then transfer the channel state feature y c [k] is updated to the channel state group fingerprint to be used in the next detection, and then switched to continue listening state, ending the current intrusion detection process.
[0111] Please see Figure 4 This diagram illustrates the connection of intrusion and monitoring devices in a real-world smart distribution cabinet. It includes eight benign terminal devices: four smart meters and four electromagnetic relays. These devices periodically report their measurement data to the gateway via the Modbus RTU protocol, with a communication baud rate of B = 9.6 kbit / s. All data segments in the commands are four bytes, corresponding to a bit length l of 80 for each Modbus RTU frame. The input resistance of each benign terminal in receive mode is approximately 12 kΩ. The protocol converter, acting as an intrusion device, connects to the fieldbus, and its input resistance is also approximately 12 kΩ in eavesdropping (i.e., receive mode). The monitoring tool consists of a commercially available AD7606 data acquisition module (maximum sampling frequency of 200 kHz) and a Raspberry Pi. This monitoring tool is deployed on the fieldbus of the distribution cabinet, passively sampling the normal communication signals of all benign terminals within one communication cycle at a sampling rate f = 100 kHz and detecting potential intrusion devices.
[0112] Please see Figure 5 This is an observation signal diagram of the distribution cabinet under the influence of intrusion equipment. Considering the data loss during the sampling process of the AD7606 module, the sampling point N is obtained from a Modbus RTU frame. s The value is 800. As can be seen from the figure, the high-level voltage of the observed signal differs by approximately 0.07V before and after the intrusion device is connected to the distribution cabinet. Under these conditions, the detection method achieves 100% accuracy in detecting silent intrusion devices, with a false alarm rate of 0%.
[0113] S6. Based on the detection results of the difference signal, if the fieldbus network is subjected to unauthorized access by an external silent intrusion device, the monitoring device will send an alarm message to the operation and maintenance center so that the operation and maintenance personnel can carry out rapid investigation.
[0114] In another embodiment of the present invention, a fieldbus network silent intrusion device detection system is provided. This system can be used to implement the above-mentioned fieldbus network silent intrusion device detection method. Specifically, the fieldbus network silent intrusion device detection system includes a sampling module, a construction module, and a detection module.
[0115] The sampling module samples the communication signals of all benign terminal devices in the fieldbus network.
[0116] The module extracts the amplitude characteristics of communication signals and collaboratively constructs channel state characteristics that reflect the connection status of terminal devices;
[0117] The detection module performs differential comparison between the channel state characteristics and the channel state group fingerprint stored in the monitoring device, and generates a detection threshold in a low-computational-cost manner using the hypothesis testing principle, and detects intrusion signals in the differential signals.
[0118] In another embodiment of the present invention, a terminal device is provided, comprising a processor and a memory. The memory stores a computer program, the computer program including program instructions, and the processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to achieve a corresponding method flow or corresponding function. The processor described in this embodiment of the present invention can be used in the operation of a fieldbus network silent intrusion device detection method, including:
[0119] The communication signals of all benign terminal devices in the fieldbus network are sampled; the amplitude characteristics of the communication signals are extracted and channel state characteristics reflecting the connection status of the terminal devices are constructed collaboratively; the channel state characteristics are differentially compared with the channel state group fingerprint stored in the monitoring equipment, and the detection threshold is generated in a low-computational-cost manner using the hypothesis testing principle, and intrusion signal detection is performed in the differential signals.
[0120] Please see Figure 7The terminal device is a computer device. In this embodiment, the computer device 60 includes a processor 61, a memory 62, and a computer program 63 stored in the memory 62 and executable on the processor 61. When executed by the processor 61, the computer program 63 implements the fluid composition calculation method in the reservoir stimulation wellbore of this embodiment. To avoid repetition, details are omitted here. Alternatively, when executed by the processor 61, the computer program 63 implements the functions of each model / unit in the fieldbus network silent intrusion device detection system of this embodiment. To avoid repetition, details are omitted here.
[0121] Computer device 60 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. Computer device 60 may include, but is not limited to, a processor 61 and a memory 62. Those skilled in the art will understand that... Figure 7 This is merely an example of computer device 60 and does not constitute a limitation on computer device 60. It may include more or fewer components than shown, or combine certain components, or different components. For example, computer device may also include input / output devices, network access devices, buses, etc.
[0122] The processor 61 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0123] The memory 62 can be an internal storage unit of the computer device 60, such as a hard disk or RAM of the computer device 60. The memory 62 can also be an external storage device of the computer device 60, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. equipped on the computer device 60.
[0124] Furthermore, the memory 62 may include both internal storage units of the computer device 60 and external storage devices. The memory 62 is used to store computer programs and other programs and data required by the computer device. The memory 62 can also be used to temporarily store data that has been output or will be output.
[0125] Please see Figure 8 The terminal device is a chip. In this embodiment, the chip 600 includes a processor 622, which may be one or more, and a memory 632 for storing computer programs executable by the processor 622. The computer program stored in the memory 632 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processor 622 may be configured to execute the computer program to perform the above-described fieldbus network silent intrusion device detection method.
[0126] Additionally, chip 600 may also include a power supply component 626 and a communication component 650. The power supply component 626 can be configured to perform power management of chip 600, and the communication component 650 can be configured to enable communication of chip 600, such as wired or wireless communication. Furthermore, chip 600 may also include an input / output (I / O) interface 658. Chip 600 can operate on an operating system stored in memory 632.
[0127] In another embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium (memory). This computer-readable storage medium is a memory device in a terminal device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and extended storage media supported by the terminal device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device.
[0128] One or more instructions stored in a computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the fieldbus network silent intrusion device detection method in the above embodiments; one or more instructions in the computer-readable storage medium are loaded and executed by the processor to perform the following steps:
[0129] The communication signals of all benign terminal devices in the fieldbus network are sampled; the amplitude characteristics of the communication signals are extracted and channel state characteristics reflecting the connection status of the terminal devices are constructed collaboratively; the channel state characteristics are differentially compared with the channel state group fingerprint stored in the monitoring equipment, and the detection threshold is generated in a low-computational-cost manner using the hypothesis testing principle, and intrusion signal detection is performed in the differential signals.
[0130] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0131] Please see Figure 9 , for in the basis Figure 4 Four different intrusion scenarios were designed using three different protocol converters as intrusion devices in a real power distribution cabinet. The input resistance of the intrusion devices varied in scenarios I-III, being 12kΩ, 48kΩ, and 96kΩ respectively. Scenario IV simulated a coordinated attack involving multiple intrusion devices, where the input resistance from these devices could not be directly measured.
[0132] Please see Figure 10 The figure shows the observed signals in the distribution cabinet under four intrusion scenarios. It can be seen from the figure that the amplitude of the intrusion signal decreases as the input resistance of the intrusion device increases. Furthermore, the parallel connection of multiple intrusion devices within the network leads to a significant amplification of the intrusion signal.
[0133] Specifically, in scenario I(Z) intru =12kΩ) and Scene II (Z intru In scenario III (Z = 48kΩ), the amplitude differences between the observed signals before and after the attack are approximately 0.07V and 0.03V, respectively. intru In the 96kΩ range, there was only a minimum difference of about 6mV. Furthermore, in scenario IV with two intrusion devices, the most significant difference between the observed signals was 0.08V.
[0134] Before performing the test, the instructions from eight devices within a reporting cycle (i.e., N) are first used as the basis. i The channel state group fingerprint is constructed using the parameters (i = 1, i = 1, 2, ..., 8). During the detection process, the generation of each detection sample is also based on the instructions from these eight devices within a reporting cycle. Table 1 shows the detection performance of different λ-based detection methods in various intrusion scenarios.
[0135] Table 1 shows the detection performance of the detection method in various intrusion scenarios based on a threshold adjustment coefficient λ = 3.9.
[0136]
[0137] As shown in Table 1, due to the smallest intrusion signal in intrusion scenario III, the detection performance is lower than other scenarios. At λ = 3.9, the detection method can detect scenarios I (Z... intru =12kΩ) and Scene II (Z intru =48kΩ) to achieve 100% detection accuracy.
[0138] Furthermore, in scenarios involving multiple intrusion devices (Scenario IV), the detection accuracy can also reach 100%. For Scenario III (Z), where the intrusion device input resistance is the highest... intru The detection performance (96kΩ) decreased, but the detection accuracy remained above 99%.
[0139] In summary, this invention provides a method and related equipment for detecting silent intrusion devices in fieldbus networks. By utilizing the impact of intrusion devices on the load of the fieldbus network, it aims to uncover the differences in the voltage amplitude of communication signals. By employing hypothesis testing principles, it implements a method for detecting silent intrusion devices in fieldbus networks based on channel state group fingerprints. This solves the security technical problem of the inability to passively and adaptively detect external silent intrusion devices in fieldbus networks.
[0140] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0141] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0142] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0143] In the embodiments provided by this invention, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0145] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0146] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random-access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0147] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0148] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0149] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0150] The above content is only for illustrating the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solution based on the technical concept proposed in this invention shall fall within the scope of protection of the claims of this invention.
Claims
1. A method for detecting silent intrusion devices in a fieldbus network, characterized in that, Includes the following steps: The communication signals of all benign terminal devices in the fieldbus network are sampled; Extract the amplitude characteristics of communication signals and collaboratively construct channel state characteristics that reflect the connection status of terminal devices; The channel state characteristics are differentially compared with the channel state group fingerprint stored in the monitoring equipment. The detection threshold is generated in a low-computational-cost manner using the hypothesis testing principle, and intrusion signal detection is performed in the differential signal. The difference signal is obtained by differentially comparing the channel state characteristics with the channel state group fingerprint stored in the monitoring equipment. : in, This represents the subtraction operator. Indicates intrusion signal and The proportionality coefficient between them; This represents Gaussian white noise in the difference signal. This indicates that the network has not been compromised. This indicates that the network has been compromised by an intruding device; The detection model for intrusion devices is as follows: False alarm rate of detection model for: in, This represents the detectable features obtained by calculating the product between the difference signal and the channel state group fingerprint. This represents the threshold adjustment coefficient. This represents the likelihood ratio detection threshold in hypothesis testing theory. It is an adaptive detection threshold adjusted by a threshold adjustment coefficient. This represents the number of sampling points obtained on a command differential signal. This represents the difference signal obtained by differentially comparing the channel state characteristics with the channel state group fingerprints stored in the monitoring equipment. Represents the channel state group fingerprint. This represents the alternative hypothesis that the network is under attack. The null hypothesis that the network has not been attacked This represents the standard deviation of Gaussian white noise in the difference signal. This represents the probability density function of the detectable feature given the null hypothesis as a priori. Indicates detectable features , The energy of the channel group fingerprint is represented. Indicates to The integral variable after substitution.
2. The method for detecting silent intrusion devices in a fieldbus network according to claim 1, characterized in that, The sampling of normal communication signals is specifically as follows: At any node location on the bus network, the communication signals generated by all benign terminal devices on the bus are passively sampled in units of one communication cycle, and the number of communication cycles to be sampled is determined based on the signal-to-noise ratio of the current communication signals of each device. After meeting the requirements of the current scenario, determine whether it is the first sampling of periodic communication signals. If the fingerprint database of the monitoring device is empty, store the processed sampled data as channel state group fingerprints, which serve as fingerprint signals reflecting network physical security.
3. The method for detecting silent intrusion devices in a fieldbus network according to claim 2, characterized in that, Benign terminal devices periodically report measurement data or execute predetermined instructions, and the resulting communication data is transmitted on the bus in the form of broadcast. The periodic transmission of measurement data or predetermined instructions is a common workflow in various industrial control systems.
4. The method for detecting silent intrusion devices in a fieldbus network according to claim 1, characterized in that, The extraction of amplitude features of communication signals and the collaborative construction of channel state features reflecting the connection status of terminal devices are specifically as follows: The high and low level sampling points of each observed signal are standardized to the same voltage level; the channel state characteristics are collaboratively characterized using the voltage amplitude characteristics of each benign terminal in the network, for the Generated by a device The instruction uses a windowed average to integrate the amplitude signal, and then further integrates it based on an arithmetic average. A benign terminal This allows us to derive the final channel state characteristics.
5. The method for detecting silent intrusion devices in a fieldbus network according to claim 1, characterized in that, Intrusion signal detection in differential signals specifically involves: If an intrusion signal is detected in the difference signal, it is determined that the fieldbus network has been subjected to unauthorized connection of a silent intrusion device, and an alarm message is sent to the operation and maintenance center. If no intrusion signal is detected in the difference signal, the fieldbus network is determined to be in a physically secure state, and the monitoring equipment will then transmit the channel state characteristics. Update the channel state group fingerprint to be used for the next detection and switch to continue listening state.
6. A silent intrusion device detection system using a fieldbus network, characterized in that, include: The sampling module samples the communication signals of all benign terminal devices in the fieldbus network; The module extracts the amplitude characteristics of communication signals and collaboratively constructs channel state characteristics that reflect the connection status of terminal devices; The detection module performs differential comparison between the channel state characteristics and the channel state group fingerprint stored in the monitoring device, and generates a detection threshold in a low-computational-cost manner using the hypothesis testing principle, and detects intrusion signals in the differential signals. The difference signal is obtained by differentially comparing the channel state characteristics with the channel state group fingerprint stored in the monitoring equipment. : in, This represents the subtraction operator. Indicates intrusion signal and The proportionality coefficient between them; This represents Gaussian white noise in the difference signal. This indicates that the network has not been compromised. This indicates that the network has been compromised by an intruding device; The detection model for intrusion devices is as follows: False alarm rate of the detection model for: in, This represents the detectable features obtained by calculating the product between the difference signal and the channel state group fingerprint. This represents the threshold adjustment coefficient. This represents the likelihood ratio detection threshold in hypothesis testing theory. It is an adaptive detection threshold adjusted by a threshold adjustment coefficient. This represents the number of sampling points obtained on a command differential signal. This represents the difference signal obtained by differentially comparing the channel state characteristics with the channel state group fingerprints stored in the monitoring equipment. Represents the channel state group fingerprint. This represents the alternative hypothesis that the network is under attack. The null hypothesis that the network has not been attacked This represents the standard deviation of Gaussian white noise in the difference signal. This represents the probability density function of the detectable feature given the null hypothesis as a priori. Indicates detectable features , The energy of the channel group fingerprint, Indicates to The integral variable after substitution.
7. A chip, characterized in that, A memory on which computer programs are stored; A processor for executing the computer program in the memory to implement the steps of the method according to any one of claims 1-5.
8. An electronic device, characterized in that, Includes the chip as described in claim 7.