Intrusion device detection method and system based on RS485 bus fail-safe bias voltage

By sampling the voltage amplitude characteristics of the fail-safe bias voltage and gateway communication signal in the RS485 bus network, channel fingerprints are constructed and differential processing is performed to identify intrusion devices. This solves the problems of high cost and insufficient resource utilization of existing methods and achieves low-cost and accurate detection.

CN118646560BActive Publication Date: 2025-10-14XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410673304.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-28
Publication Date
2025-10-14
Estimated Expiration
2044-05-28

AI Technical Summary

Technical Problem

The existing intrusion device detection method in RS485 bus network is costly, signal feature extraction is cumbersome and does not fully utilize bus communication resources. It also lacks the ability to identify the impact of bus idle time voltage signal.

Method used

The fail-safe bias voltage signal at any position of the RS485 bus and the communication signal of the gateway device at the communication time are sampled during the network idle time. The voltage amplitude characteristics are extracted and the channel fingerprint is collaboratively constructed. The difference signal is generated through differential processing, and the detection threshold is generated using the constant false alarm rate constraint to identify the intrusion device.

Benefits of technology

It reduces detection costs and time requirements, achieves accurate detection of external intrusion devices, simplifies the feature extraction process, reduces hardware and computing overhead, and improves the interpretability of the detection model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118646560B_ABST
    Figure CN118646560B_ABST
Patent Text Reader

Abstract

The application discloses an intrusion device detection method and system based on RS485 bus fault safety bias voltage, unauthorized access of external intrusion devices in the RS485 bus causes changes in the amplitude of the fault safety bias voltage at the idle time of the bus and the communication signal of the gateway device; the bias voltage at the idle time of the bus and the gateway communication signal at the communication time are sampled, the voltage amplitude characteristics are extracted respectively and the channel fingerprints are cooperatively constructed, the external intrusion device is identified and detected through the difference generated by the channel fingerprints; the cooperative use of the two kinds of bus communication resources, i.e. the fault safety bias voltage at the idle time of the bus and the gateway communication signal at the communication time, can significantly reduce the demand of the detection method for the sampling frequency and the detection time; based on the side channel monitoring, the bus resources are not occupied, the detection threshold is dynamically generated based on the constant false alarm rate constraint, the detection environment is adapted in real time, the detection cost is reduced, and the precise detection of various external intrusion devices in the RS485 bus network is realized in a low-cost manner.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of intrusion detection, and particularly relates to an intrusion device detection method and system based on a fault safety bias voltage of an RS485 bus. BACKGROUND

[0002] The RS485 bus is widely used in real-time distributed control in industrial control systems (ICSs) due to its simplicity and stability. A real-world RS485 bus network contains hundreds of interconnected devices, presenting a wide range of network layouts. However, due to the limitations of computing resources and real-time communication requirements, most industrial control protocols (such as Modbus, etc.) in the RS485 network lack security measures such as authentication and encryption, and attackers can directly connect external intrusion devices to these communication lines to launch various attacks, posing a significant threat to the stable operation of ICSs.

[0003] The current detection method for intrusion devices in the RS485 bus mainly has the following deficiencies in actual design:

[0004] (1) High detection cost. Most existing methods use high sampling frequency acquisition devices to sample the communication signals in the bus to construct fine channel fingerprints, which has high hardware requirements for detection tools.

[0005] (2) Complicated signal feature extraction. Existing methods generally need to extract multi-dimensional features (time domain and frequency domain features) of communication signals to train machine learning models to identify changes in physical characteristics in communication signals.

[0006] (3) Not fully utilizing communication resources in the bus. Existing methods only consider the difference identification on normal communication signals and do not consider the influence of intrusion devices on bus idle time voltage signals. SUMMARY

[0007] The technical problem to be solved by the application is to provide an intrusion device detection method and system based on a fault safety bias voltage of an RS485 bus to solve the technical problem of high detection cost of external intrusion devices by existing methods.

[0008] The application adopts the following technical solutions:

[0009] The intrusion device detection method based on the fault safety bias voltage of the RS485 bus comprises the following steps:

[0010] In the network initialization phase, the fault safety bias voltage signal at any position of the RS485 bus and the gateway device communication signal at the communication time are sampled at the network idle time;

[0011] extracting voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal respectively and constructing the channel fingerprint cooperatively;

[0012] resampling the fail-safe bias voltage signal and the gateway device communication signal in the detection stage, generating channel features to be detected, and performing differential processing with the channel fingerprint to generate a difference signal;

[0013] generating a detection threshold under the condition of constant false alarm rate, detecting whether there is an intrusion signal in the difference signal, and finally judging whether the external intrusion device exists.

[0014] Preferably, M segments of fail-safe bias voltage signals and M gateway device communication signals at any position of the RS485 bus are collected when the network is idle.

[0015] Preferably, extracting voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal respectively specifically includes:

[0016] standardizing high and low level sampling points in each gateway device communication signal to the same voltage level to obtain amplitude features;

[0017] averaging M segments of fail-safe bias voltage signals and M standardized gateway device communication signals to reduce noise intensity and construct the channel fingerprint.

[0018] More preferably, the standardization process is as follows:

[0019]

[0020] wherein, represents a gateway device communication signal, and represents high and low level sampling points in a gateway device communication signal, represents an average operator of sampling points.

[0021] More preferably, the averaging process is as follows:

[0022]

[0023] wherein, , represents sampling points after splicing a segment of fail-safe bias voltage signal and a gateway device communication signal, is the channel fingerprint, is a segment of fail-safe bias voltage signal, is Gaussian white noise still remaining in the channel fingerprint, represents the number of sampling points obtained from a segment of fail-safe bias voltage signal and a gateway device communication signal.

[0024] Preferably, the difference signal Specifically:

[0025]

[0026] in, To reflect the intrusion signal of the external intrusion device, is the Gaussian white noise in the difference signal, attacked indicates that there is an external intrusion device in the network, and no attack indicates that there is no intrusion device in the network.

[0027] Preferably, let is the original condition when the network is not attacked, is an alternative condition for the network to be attacked by external intrusion devices; then , , represents normal distribution, and a likelihood ratio decision equation is derived based on the Bayesian criterion as a detection model for detecting external intrusion devices. When the detection model detects that the channel feature is greater than the detection threshold, there is an external intrusion device in the RS485 bus network.

[0028] More preferably, the detection model is specifically:

[0029]

[0030] in, is the difference signal, for The standard deviation of is the number of sampling points obtained from a fail-safe bias voltage signal and a gateway device communication signal, Computes the lower bound of the integration of the probability density in the standard normal distribution table.

[0031] More preferably, under the constant false alarm rate constraint condition, when the constant false alarm rates are set to 0.01%, 0.1% and 1%, respectively, The values ​​are 3.59, 3.09 and 2.32 respectively.

[0032] In a second aspect, an embodiment of the present invention provides an intrusion device detection system based on an RS485 bus fail-safe bias voltage, comprising:

[0033] The sampling module samples the fail-safe bias voltage signal at any position of the RS485 bus and the communication signal of the gateway device at the communication time during the network initialization phase and the network idle time;

[0034] An extraction module extracts the voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal respectively and collaboratively constructs a channel fingerprint;

[0035] a difference module, which resamples the fault safety bias voltage signal and the gateway device communication signal in the detection stage, generates channel features to be detected, and performs difference processing with the channel fingerprint to generate a difference signal;

[0036] a detection module, which generates a detection threshold under the condition of constant false alarm rate constraint, detects whether there is an intrusion signal in the difference signal, and finally judges whether the external intrusion device exists.

[0037] In a third aspect, a computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the above-mentioned intrusion device detection method based on the RS485 bus fault safety bias voltage when executing the computer program.

[0038] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium including a computer program, and the computer program implements the steps of the above-mentioned intrusion device detection method based on the RS485 bus fault safety bias voltage when executed by a processor.

[0039] Compared with the prior art, the present application has at least the following beneficial effects:

[0040] The intrusion device detection method based on the RS485 bus fault safety bias voltage can inevitably cause changes in the amplitude of the fault safety bias voltage and the communication signal of the gateway device at the bus idle time due to the unauthorized access of the external intrusion device in the RS485 bus. The bias voltage at the bus idle time and the gateway communication signal at the communication time are sampled, the voltage amplitude features are extracted respectively and the channel fingerprint is constructed cooperatively, and the external intrusion device is detected by identifying the difference generated on the channel fingerprint. The cooperative use of the fault safety bias voltage at the bus idle time and the gateway communication signal at the communication time can significantly reduce the demand of the detection method for the sampling frequency and the detection time; the detection method is based on side channel monitoring and does not occupy bus resources, and the detection threshold is generated dynamically based on the constant false alarm rate constraint, which can adapt to the detection environment in real time, reduce the detection overhead, and realize the precise detection of various external intrusion devices in the RS485 bus network at a very low cost.

[0041] Further, the equivalent circuit of the RS485 field bus network with fault safety bias is constructed, the influence of the field bus communication and the intrusion device during the idle time on the signal amplitude is analyzed theoretically, and the effectiveness of the cooperative use of the bias voltage at the idle time and the gateway communication signal at the communication time to construct the channel fingerprint is proved.

[0042] Furthermore, relying on the analysis of equivalent circuits, a signal normalization process is designed to extract only the voltage amplitude characteristics of the signal in the time domain, which simplifies the feature dimensions required to be extracted in the traditional intrusion detection process and reduces the storage, computing overhead and hardware cost of the detection method.

[0043] Furthermore, the channel fingerprint is constructed using the bias voltage during idle time and the gateway communication signal during communication time. The full utilization of bus communication and channel resources during idle time can reflect the channel status more comprehensively and quickly, reduce detection time, and detect intrusion devices in a timely manner.

[0044] Furthermore, the use of the assumed detection principle and constant false alarm rate constraints breaks away from the training process of traditional machine learning methods, further reducing detection costs while improving the interpretability of the detection model.

[0045] It can be understood that the beneficial effects of the second aspect mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here.

[0046] In summary, the present invention utilizes the influence of external intrusion devices on the fail-safe bias voltage signal and the gateway device communication signal, adopts side-channel monitoring to passively sample the two signals, and identifies the changes in the voltage amplitude characteristics in the signal based on the hypothesis testing principle and constant false alarm rate constraints, thereby realizing an intrusion device detection method based on the RS485 bus fail-safe bias voltage.

[0047] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 The input conditions and corresponding output states of the RS485 receiver;

[0049] Figure 2 It is the equivalent circuit of RS485 bus network;

[0050] Figure 3 Figure 1 shows the bias voltage signal (BV signal) and the gateway device communication signal (CV signal).

[0051] Figure 4 This is a connection diagram of the intrusion device and monitoring equipment in the smart distribution cabinet in a real scenario;

[0052] Figure 5 This is the observation signal diagram of the power distribution cabinet under the influence of the intrusion device;

[0053] Figure 6Detection performance diagrams under different sampling frequencies and different averaging times, where (a) is the detection accuracy based on different sampling frequencies when the averaging times M is fixed at 10, and (b) is the detection accuracy based on different averaging times M when the sampling frequency is fixed at 20KS / s;

[0054] Figure 7 is a flow chart of the present invention;

[0055] Figure 8 A schematic diagram of a computer device provided in accordance with an embodiment of the present invention;

[0056] Figure 9 The block diagram of a chip provided according to one embodiment of the present invention is shown. DETAILED DESCRIPTION

[0057] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0058] In the description of the present invention, it is to be understood that the terms “include” and “comprise” indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.

[0059] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0060] It should be further understood that the term "and / or" as used in the present specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects are in an "or" relationship.

[0061] It should be understood that although the terms "first," "second," and "third" may be used to describe preset ranges in embodiments of the present invention, these preset ranges should not be limited to these terms. These terms are merely used to distinguish one preset range from another. For example, without departing from the scope of embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.

[0062] The word "if," as used herein, may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.

[0063] The accompanying drawings illustrate various schematic diagrams of structures according to embodiments disclosed herein. These figures are not drawn to scale; for clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.

[0064] The present invention provides an intrusion device detection method based on the RS485 bus fail-safe bias voltage. The method samples the bus bias voltage during idle time and the gateway communication signal during communication time, extracts voltage amplitude characteristics from each, and collaboratively constructs a channel fingerprint. External intrusion devices are detected by identifying the differences generated in the channel fingerprint. The collaborative utilization of two bus communication resources, the fail-safe bias voltage during idle time and the gateway communication signal during communication time, can significantly reduce the detection method's requirements for sampling frequency and detection time. The detection method is based on side-channel monitoring and does not occupy bus resources. At the same time, it dynamically generates detection thresholds based on constant false alarm rate constraints, adapts to the detection environment in real time, reduces detection overhead, and achieves extremely low-cost accurate detection of various external intrusion devices in an RS485 bus network.

[0065] See also Figure 7 The present invention provides an intrusion device detection method based on the RS485 bus fail-safe bias voltage. The connection of an external intrusion device causes the impedance distribution of the RS485 bus network to change. This change is reflected in the BV signal when the bus is idle and the CV signal when the gateway is communicating. Based on this, combined with the analysis of the RS485 network equivalent circuit, the specific steps are as follows:

[0066] S1. The gateway device periodically sends a communication signal;

[0067] In the normal operation of the RS485 bus network, each terminal device needs to rely on the command of the gateway device to periodically perform the established actions. Therefore, the gateway device periodically sends communication signals, which is a common workflow in the RS485 bus network.

[0068] S2. Collect M segments of fail-safe bias voltage signals (BV signals) and M gateway device communication signals (CV signals) at any location on the RS485 bus.

[0069] S201. When the network is physically secure (for example, during network initialization or after a thorough security check), M segments of BV signals and M CV signals are collected for constructing a channel fingerprint. Figure 3 The signal diagram of a BV signal and a CV signal is shown. At this time, after executing S3, M BV signals and M CV signals will be stored as a channel fingerprint reflecting the channel security status.

[0070] S202 , during the detection process (ie, not the first time of collecting BV and CV signals), after completing S3 , the M segments of BV signals and M CV signals will proceed to step S4 .

[0071] S3, voltage amplitude feature extraction and collaborative averaging;

[0072] S301: First, the high-level and low-level sampling points in each CV signal are normalized to the same voltage level to obtain amplitude characteristics. This normalization process is expressed as:

[0073]

[0074] in, Indicates a gateway device communication signal (CV signal), and Respectively represent the high level and low level sampling points in a CV signal, Represents the average operator of the sampling points. The BV signal is a DC voltage signal and does not require a normalization process to extract amplitude features.

[0075] S302: To reduce noise interference during detection, M segments of BV signals and M standardized CV signals are averaged to reduce noise intensity and construct a channel fingerprint. The averaging process is expressed as:

[0076]

[0077] in, , Indicates the sampling point after a BV signal and a CV signal are spliced ​​together. is the channel fingerprint, is a BV signal. is the Gaussian white noise that still remains in the channel fingerprint, Indicates the number of sampling points that can be obtained from a BV signal and a CV signal.

[0078] S4, reconstructing the channel characteristics and performing differential analysis with the channel fingerprint to generate a difference signal;

[0079] In the detection phase, the M segments of BV signals and M CV signals are resampled, and the channel features to be detected are generated in the same way as the channel fingerprint construction process. , then and channel fingerprint Perform differential operation to obtain the difference signal:

[0080]

[0081] in, is the difference signal, To reflect the intrusion signal of the external intrusion device, is the Gaussian white noise in the difference signal. "Attacked" indicates that there is an external intrusion device in the network, and "no attack" indicates that there is no intrusion device in the network.

[0082] S5. Dynamic threshold generation and intrusion detection based on constant false alarm rate constraint;

[0083] set up is the original condition when the network is not attacked, This is an alternative condition for the network to be attacked by external intrusion devices; is Gaussian white noise, then we have and , represents a normal distribution. Based on the Bayesian criterion, we can derive the likelihood ratio decision equation, which also serves as a detection model for external intrusion devices:

[0084]

[0085] in, is the difference signal, express The standard deviation of Indicates the number of sampling points that can be obtained from a BV signal and a CV signal. Indicates the integral lower limit of the probability density calculated in the standard normal distribution table. Under the condition of constant false alarm rate constraint, when the constant false alarm rate is set to 0.01%, 0.1% and 1%, The values ​​of are 3.59, 3.09 and 2.32 respectively. In the present invention, in order to ensure the minimum false alarm rate of the detection model, The value is set to 3.59 by default.

[0086] If the channel characteristics detected by the detection model are greater than the detection threshold, it means that there is an external intrusion device in the RS485 bus network, and step S6 is executed. If the channel characteristics are less than the detection threshold, the RS485 bus network is judged to be in a safe state at this time, and the channel characteristics at this time are updated as the channel fingerprint used for the next detection.

[0087] S6. There is an external intrusion device in the RS485 bus network, generating an alarm.

[0088] In another embodiment of the present invention, an intrusion device detection system based on RS485 bus fail-safe bias voltage is provided. The system can be used to implement the above-mentioned intrusion device detection method based on RS485 bus fail-safe bias voltage. Specifically, the intrusion device detection system based on RS485 bus fail-safe bias voltage includes module, module, module, module and module.

[0089] Among them, the sampling module samples the fail-safe bias voltage signal at any position of the RS485 bus and the communication signal of the gateway device at the communication time during the network initialization phase and the idle time of the network;

[0090] An extraction module extracts the voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal respectively and collaboratively constructs a channel fingerprint;

[0091] The differential module resamples the fail-safe bias voltage signal and the gateway device communication signal during the detection phase to generate the channel feature to be detected, and performs differential processing with the channel fingerprint to generate a difference signal;

[0092] The detection module generates a detection threshold under the condition of constant false alarm rate constraint, detects whether there is an intrusion signal in the difference signal, and finally determines whether there is an external intrusion device.

[0093] In another embodiment of the present invention, a terminal device is provided, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the intrusion device detection method based on the RS485 bus fault safety bias voltage, including:

[0094] During the network initialization phase, the fail-safe bias voltage signal at any position of the RS485 bus and the gateway device communication signal at the communication time are sampled during the network idle time; the voltage amplitude characteristics of the fail-safe bias voltage signal and the gateway device communication signal are extracted respectively, and the channel fingerprint is collaboratively constructed; during the detection phase, the fail-safe bias voltage signal and the gateway device communication signal are resampled to generate the channel characteristics to be detected, and differential processing is performed with the channel fingerprint to generate a difference signal; under the condition of constant false alarm rate constraint, a detection threshold is generated to detect whether there is an intrusion signal in the difference signal, and finally it is determined whether there is an external intrusion device.

[0095] In another embodiment of the present invention, a storage medium is provided, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in a terminal device, used to store programs and data. It is understood that the computer-readable storage medium herein may include both built-in storage media in the terminal device and, of course, extended storage media supported by the terminal device. The computer-readable storage medium provides storage space, which stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for being loaded and executed by a processor. These instructions may be one or more computer programs (including program code). It should be noted that the computer-readable storage medium herein may be a high-speed RAM memory or a non-volatile memory, such as at least one disk storage device.

[0096] The processor may load and execute one or more instructions stored in a computer-readable storage medium to implement the corresponding steps of the intrusion device detection method based on the RS485 bus fail-safe bias voltage in the above embodiment; the processor may load and execute the following steps:

[0097] During the network initialization phase, the fail-safe bias voltage signal at any position of the RS485 bus and the gateway device communication signal at the communication time are sampled during the network idle time; the voltage amplitude characteristics of the fail-safe bias voltage signal and the gateway device communication signal are extracted respectively, and the channel fingerprint is collaboratively constructed; during the detection phase, the fail-safe bias voltage signal and the gateway device communication signal are resampled to generate the channel characteristics to be detected, and differential processing is performed with the channel fingerprint to generate a difference signal; under the condition of constant false alarm rate constraint, a detection threshold is generated to detect whether there is an intrusion signal in the difference signal, and finally it is determined whether there is an external intrusion device.

[0098] See also Figure 8 The terminal device is a computer device. The computer device 60 of this embodiment includes: a processor 61, a memory 62, and a computer program 63 stored in the memory 62 and executable by the processor 61. When executed by the processor 61, the computer program 63 implements the method for calculating the fluid composition in a reservoir-stimulated wellbore according to the embodiment. To avoid repetition, a detailed description thereof is omitted here. Alternatively, when executed by the processor 61, the computer program 63 implements the functions of each model / unit in the system for calculating the fluid composition in a reservoir-stimulated wellbore according to the embodiment. To avoid repetition, a detailed description thereof is omitted here.

[0099] The computer device 60 may be a desktop computer, a notebook computer, a PDA, a cloud server, or other computing devices. The computer device 60 may include, but is not limited to, a processor 61 and a memory 62. It will be understood by those skilled in the art that Figure 8 This is merely an example of the computer device 60 and does not constitute a limitation of the computer device 60 . The computer device 60 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device may also include input and output devices, network access devices, buses, etc.

[0100] The processor 61 can be a central processing unit (CPU), and can also be other general-purpose processors, central processing units, graphics processing units, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic components, quantum computing-based data processing logic components, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0101] The memory 62 can be an internal storage unit of the computer device 60, such as a hard disk or a memory of the computer device 60. The memory 62 can also be an external storage device of the computer device 60, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 60.

[0102] Further, the memory 62 can include both an internal storage unit and an external storage device of the computer device 60. The memory 62 is used to store computer programs and other programs and data required by the computer device. The memory 62 can also be used to temporarily store data that has been output or will be output.

[0103] Any reference to memory, database, or other media used in the various embodiments provided herein may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM may be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0104] The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may include, but are not limited to, general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic units, data processing logic units based on quantum computing, and the like.

[0105] See also Figure 9 The terminal device is a chip. The chip 600 of this embodiment includes a processor 622, which may be one or more, and a memory 632 for storing a computer program executable by the processor 622. The computer program stored in the memory 632 may include one or more modules, each corresponding to a set of instructions. In addition, the processor 622 may be configured to execute the computer program to perform the above-mentioned generalizable monocular absolute depth map estimation method.

[0106] In addition, the chip 600 may further include a power supply component 626 and a communication component 650. The power supply component 626 may be configured to perform power management of the chip 600, and the communication component 650 may be configured to implement communication, such as wired or wireless communication, of the chip 600. In addition, the chip 600 may further include an input / output interface 658. The chip 600 may operate based on an operating system stored in the memory 632.

[0107] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0108] An embodiment of the present invention provides an attack scenario of an application example of an intrusion device detection method based on the fail-safe bias voltage of an RS485 bus. In this attack scenario, three different external intrusion devices (protocol converters) are connected to the bus in a real power distribution cabinet based on the RS485 bus to eavesdrop on key communication information broadcast on the bus without any encryption. The following case is used for a specific analysis.

[0109] See also Figure 1 The RS485 standard specifies that the minimum differential bus voltage for the receiver to output the correct logical state is ±0.2V. A differential bus voltage greater than 0.2V indicates that the receiver outputs a logic "high", while a differential bus voltage less than -0.2V indicates that the receiver outputs a logic "low". However, during network idle periods (for example, between each gateway communication command), no transmitter actively drives the bus, thereby reducing the differential bus voltage. The differential voltage of 0V during idle time is an undefined input level for a standard RS485 receiver. Faced with such an undefined input, the receiver may output an incorrect logic state or oscillate. Fail-safe biasing is the primary solution to this problem. Standard RS485 equipment contains a DC voltage source, pull-up and pull-down resistors, and their voltage divider action provides a differential DC bus voltage greater than 0.2V, i.e. Figure 1 The fail-safe bias voltages shown ensure that all receiver outputs go to a defined logic “high” state when no driver is actively driving the bus.

[0110] See also Figure 2 , RS485 devices act as drivers (i.e., sending instructions devices) or receivers (i.e., receiving instructions devices) according to their status. Figure 2 As shown in Figure 1, the gateway is the driver in the network, where the terminal device is the receiver. The equivalent model of the driver consists of a Differential signal source It is used to send command voltage signals with opposite phases and equal amplitudes. The equivalent model of the receiver consists of two resistors The common feature of the driver and receiver is the integration of DC voltage source , pull-up and pull-down resistors for fail-safe biasing ; To facilitate circuit analysis, Figure 2 The DC voltage source, pull-up, and pull-down resistors of each benign device have the same value. Figure 2 There is a gateway device and n receiver terminals interconnected, with terminal resistors at both ends To simplify the analysis, the network topology is converted to a “lumped equivalent circuit” where Represents the equivalent input resistance of all transceiver pull-up or pull-down resistors, Represents the equivalent input resistance of all receivers; the differential voltage By solving for the line voltage and Get, expressed as:

[0111]

[0112] in, represents the impedance set of all resistors in the network, and They are DC voltage sources and differential signal sources and The proportional function.

[0113] Accordingly, Indicates the bias voltage signal (BV signal) during network idle period (i.e. when no driver is active in the network). Indicates the command voltage signal (CV signal) during network communication. In the attacked RS485 network, there is an input resistor A listening intruder device (i.e. acting as a receiver) is connected to the bus. Its DC voltage source and pull-up / pull-down resistors are represented by and Then, the differential voltage in the attacked network is Expressed as:

[0114]

[0115] in, Indicates that the output impedance value is greater than the value due to the influence of the intrusion device Therefore, the BV signal and CV signal become and Based on the above analysis, the access of intrusion equipment will inevitably cause changes in the network impedance distribution, which is reflected in the amplitude of the BV signal and the CV signal. and to detect intrusion devices by using the differences between them.

[0116] See also Figure 4 The power distribution cabinet contains eight different smart meters and a gateway, which monitors and manages the power consumption of all electrical appliances in the 420-square-meter laboratory. The smart meters and gateway are interconnected via an RS485 bus with a baud rate of 9.6 kbit / s. The gateway sends Modbus / RTU request commands to each smart meter every 5 ms to obtain each meter's measurement data. Each request command is 80 bits long. To carry out the attack, three common commercially available protocol converters—ZLAN, KonNaD, and MOXA—were used as intrusion devices to connect to the power distribution cabinet. Table 1 lists the electrical configuration of each device in the power distribution cabinet.

[0117] Table 1 Electrical configuration of each device in the power distribution cabinet

[0118]

[0119] The detection tool consists of a PC and a PicoScope oscilloscope. The PicoScope is used to sample the differential voltage signal in the network, with the initial sampling rate set to 100 kS / s. The PC is used to process the sampling points and store the channel fingerprint. When the distribution cabinet communicates at a baud rate of 9.6 kbit / s, the number of sampling points for the 5 ms interval BV signal and the 80-bit CV signal is 500 and 800, respectively. Correspondingly, before and after the intrusion device is connected, a BV signal and a standardized CV signal in the distribution cabinet are as follows: Figure 5 As shown in the figure, as the input resistance of the intrusion device increases, the amplitude of the intrusion signal decreases. Specifically, under the influence of ZLAN, the amplitude differences between the BV and CV signals are approximately 0.2V and 0.25V, respectively. Under the influence of KonNaD, the amplitude differences are both 0.05V, while under the influence of MOXA, they exhibit the smallest amplitude differences, at 1mV and 7mV, respectively.

[0120] Table 2 shows the performance of detecting different intrusion devices when using only CV signal and when using BV signal + CV signal combination. For ZLAN and KonNaD, both detection signals can achieve 100% accuracy and 0% false alarm rate, without the need for multiple averaging to enhance the signal-to-noise ratio. However, for Figure 5MOXA, which has the least impact on signal amplitude, requires averaging 14 CV signals to achieve 100% accuracy when using only CV signals for detection. However, the combined detection of BV and CV signals requires averaging 3 times to achieve 100% accuracy. Their respective detection time costs are 254ms and 100.5ms respectively. This result shows that the joint detection of BV and CV signals can significantly reduce the detection delay. In addition, the consistent 0% false alarm rate in all scenarios verifies the accuracy of the proposed method based on The appropriateness of the generated detection threshold (i.e., under the minimum constant false alarm rate constraint).

[0121] Table 2 Detection performance for different intrusion devices

[0122]

[0123] In order to evaluate the detection performance under different sampling rates, we tested the MOXA in the power distribution cabinet and tested it 10 times on average (i.e. ). Adjust the sampling rate to 20KS / s, 40KS / s, 60KS / s, 80KS / s, 100KS / s, and collect the signal with a baud rate of 9.6kbit / s, corresponding to The values ​​are 260, 520, 780, 1040, and 1300. Figure 6 As shown in the figure, detection accuracy increases with increasing sampling rate; the combined use of BV and CV signals achieves 100% accuracy at a sampling rate of 60 kS / s, while relying solely on CV signals for detection only achieves 66.10% accuracy at 100 kS / s. These results indicate that combining BV and CV signals for detection significantly reduces sampling costs.

[0124] In addition, if Figure 6 As shown in (b), when a 20 kS / s sampling rate (2× the baud rate) is used, the improved signal-to-noise ratio due to the increase in the number of averaging times can compensate for the detection performance based on fewer sampling points.

[0125] Specifically, when When the sampling rate is 20KS / s, the combined use of BV signal and CV signal for detection can also achieve 100% accuracy, but the detection time will be greater.

[0126] In summary, the present invention provides an intrusion device detection method and system based on the RS485 bus fail-safe bias voltage, which samples the bias voltage during bus idle time and the gateway communication signal during communication time, extracts voltage amplitude characteristics respectively and collaboratively constructs a channel fingerprint, and detects external intrusion devices by identifying the differences generated on the channel fingerprint. The collaborative use of the two bus communication resources, the fail-safe bias voltage during bus idle time and the gateway communication signal during communication time, can significantly reduce the detection method's requirements for sampling frequency and detection time; the detection method is based on side channel monitoring and does not occupy bus resources. At the same time, it dynamically generates detection thresholds based on constant false alarm rate constraints, adapts to the detection environment in real time, reduces detection overhead, and achieves accurate detection of various types of external intrusion devices in the RS485 bus network in an extremely low-cost manner.

[0127] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0128] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0129] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the present invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0130] In the embodiments provided by the present invention, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical functional division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interface, indirect coupling or communication connection of devices or units, and can be electrical, mechanical, or other forms.

[0131] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0132] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0133] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the above-mentioned various method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0134] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0135] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0136] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0137] The above content is only for explaining the technical idea of ​​the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.

Claims

1. A method for detecting intrusion devices based on RS485 bus fail-safe bias voltage, characterized in that: The following steps are involved: During the network initialization phase, the fail-safe bias voltage signal at any position on the RS485 bus and the communication signal of the gateway device at the communication moment are sampled; The voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal are extracted separately and the channel fingerprint is constructed collaboratively. Specifically: Normalizing the high-level and low-level sampling points in the communication signal of each gateway device to the same voltage level to obtain amplitude characteristics; Averaging M segments of fail-safe bias voltage signals and M standardized gateway device communication signals to reduce noise intensity and construct a channel fingerprint; The standardization process is as follows: in, Indicates a gateway device communication signal, and Respectively represent the high level and low level sampling points in the communication signal of a gateway device, represents the average operator of the sampling points; The averaging process is as follows: in, , Represents the sampling point after a fail-safe bias voltage signal and a gateway device communication signal are spliced ​​together. is the channel fingerprint, is a fail-safe bias voltage signal, is the Gaussian white noise that still remains in the channel fingerprint, Represents the number of sampling points obtained from a fail-safe bias voltage signal and a gateway device communication signal; In the detection phase, the fail-safe bias voltage signal and the gateway device communication signal are resampled to generate the channel feature to be detected, and the difference signal is generated by performing differential processing with the channel fingerprint. Specifically: in, is the channel characteristic signal to be detected, To reflect the intrusion signal of the external intrusion device, is the Gaussian white noise in the difference signal, attacked means there is an external intrusion device in the network, and no attack means there is no intrusion device in the network; A detection threshold is generated under the condition of constant false alarm rate constraint to detect whether there is an intrusion signal in the difference signal, and finally determine whether there is an external intrusion device.

2. The intrusion device detection method based on RS485 bus fail-safe bias voltage according to claim 1, wherein When the network is idle, M segments of fail-safe bias voltage signals and M gateway device communication signals are collected at any location on the RS485 bus.

3. The intrusion device detection method based on RS485 bus fail-safe bias voltage according to claim 1, wherein make is the original condition when the network is not attacked, is an alternative condition for the network to be attacked by external intrusion devices; then , , represents the normal distribution, and the likelihood ratio decision equation is derived based on the Bayesian criterion as a detection model for detecting external intrusion devices; When the detection model detects that the channel characteristics are greater than the detection threshold, there is an external intrusion device in the RS485 bus network.

4. The intrusion device detection method based on RS485 bus fail-safe bias voltage according to claim 3, wherein The specific detection model is: in, is the difference signal, for The standard deviation of is the number of sampling points obtained from a fail-safe bias voltage signal and a gateway device communication signal, Computes the lower bound of the integration of the probability density in the standard normal distribution table.

5. The intrusion device detection method based on RS485 bus fail-safe bias voltage according to claim 4, wherein Under the constant false alarm rate constraint, when the constant false alarm rate is set to 0.01%, 0.1% and 1%, The values ​​are 3.59, 3.09 and 2.32 respectively.

6. An intrusion device detection system based on RS485 bus fail-safe bias voltage, characterized in that: include: The sampling module samples the fail-safe bias voltage signal at any position of the RS485 bus and the communication signal of the gateway device at the communication time during the network initialization phase and the network idle time; The extraction module extracts the voltage amplitude features of the fail-safe bias voltage signal and the gateway device communication signal respectively and collaboratively constructs the channel fingerprint, specifically: Normalizing the high-level and low-level sampling points in the communication signal of each gateway device to the same voltage level to obtain amplitude characteristics; Averaging M segments of fail-safe bias voltage signals and M standardized gateway device communication signals to reduce noise intensity and construct a channel fingerprint; The standardization process is as follows: in, Indicates a gateway device communication signal, and Respectively represent the high level and low level sampling points in the communication signal of a gateway device, represents the average operator of the sampling points; The averaging process is as follows: in, , Represents the sampling point after a fail-safe bias voltage signal and a gateway device communication signal are spliced ​​together. is the channel fingerprint, is a fail-safe bias voltage signal, is the Gaussian white noise that still remains in the channel fingerprint, Represents the number of sampling points obtained from a fail-safe bias voltage signal and a gateway device communication signal; The differential module resamples the fail-safe bias voltage signal and the gateway device communication signal during the detection phase to generate the channel characteristics to be detected, and performs differential processing with the channel fingerprint to generate a difference signal. Specifically: in, is the channel characteristic signal to be detected, To reflect the intrusion signal of the external intrusion device, is the Gaussian white noise in the difference signal, attacked means there is an external intrusion device in the network, and no attack means there is no intrusion device in the network; The detection module generates a detection threshold under the condition of constant false alarm rate constraint, detects whether there is an intrusion signal in the difference signal, and finally determines whether there is an external intrusion device.

Citation Information

Patent Citations

  • Industrial control system physical intrusion attack detection method based on serial communication bus signal analysis

    CN108520187A

  • Deep SVDD-based vehicle external intrusion detection method and system

    CN113359666A