Network attack detection method and system for numerical control equipment
By setting up sniffers and network monitoring units in the intranet of the industrial control system, simulating the operating status of CNC equipment, and combining deep packet inspection and artificial intelligence algorithms, the problem of difficulty in dealing with advanced network attacks on CNC equipment in existing technologies is solved. Real-time detection and response to complex attacks are achieved, ensuring the security and stability of the industrial control system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-24
- Publication Date
- 2026-04-07
AI Technical Summary
Existing security measures are insufficient to effectively combat advanced and complex cyberattacks on CNC equipment, leading to an increased risk of production disruptions and data breaches.
Sniffers and network monitoring units are set up in the intranet of the industrial control system to simulate the operating status of CNC equipment. The network communication content is analyzed through deep packet inspection technology and artificial intelligence algorithms to monitor and identify abnormal behavior in real time, and respond through a multi-level alarm mechanism.
It enables real-time detection and response to complex and advanced cyberattacks, ensuring the safe and stable operation of industrial control systems and improving the ability to identify and defend against potential threats.
Smart Images

Figure CN118869307B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a network attack detection method and system for numerical control equipment. BACKGROUND
[0002] With the wide application of industrial control systems (ICS), numerical control equipment plays an increasingly important role in industrial production. Numerical control equipment communicates with other industrial control system components through a network to achieve automation control and production. However, with the increasing degree of networking, numerical control equipment also faces more and more network security threats. For example, malicious software, distributed denial of service (DDoS) attacks, phishing and man-in-the-middle attacks, etc., can cause numerical control equipment failure, production interruption and even data leakage.
[0003] Existing security protection means, such as firewalls and traditional intrusion detection systems (IDS), often have difficulty in dealing with advanced and complex attacks on numerical control equipment. Therefore, there is an urgent need for a new security protection scheme that can detect and respond to network attacks in real time to ensure the safe operation of numerical control equipment and industrial control systems. SUMMARY
[0004] In view of the many problems existing in the prior art, the present application provides a network attack detection method and system for numerical control equipment. The present application simulates the operating state of numerical control equipment by setting up a sniffer and a network monitoring unit in the internal network of the industrial control system to attract and capture potential attack traffic. The network communication content captured by the sniffer is analyzed in detail by deep packet inspection technology and artificial intelligence algorithms, and compared with the pre-recorded normal communication content. When an anomaly is detected, the system will trigger the corresponding alarm signal, and through a multi-level protection mechanism, ensure timely response and processing. The system can monitor and analyze network traffic in real time, effectively identify and prevent various complex and advanced network attacks, and ensure the safe and stable operation of the industrial control system.
[0005] A network attack detection method for numerical control equipment, comprising the following steps:
[0006] A protection unit is set up between the internal network and the external network of the industrial control system;
[0007] The internal network monitoring unit is connected to the protection unit, and the internal network monitoring unit is connected to the industrial control network server;
[0008] The network monitoring unit is connected to the sniffer, and the network monitoring unit is connected to the internal network monitoring unit;
[0009] The network communication content intercepted by the sniffer connected to the internal network monitoring unit is recorded;
[0010] mirroring network communication content of the internal network monitoring unit to the network monitoring unit;
[0011] comparing the intercepted network communication content with normal network communication content at the network monitoring unit;
[0012] triggering a primary alarm when there is a difference between the intercepted network communication content and the normal network communication content;
[0013] triggering a secondary alarm when an anomaly is found in the network communication content at the internal network monitoring unit.
[0014] Preferably, mirroring the network communication content comprises selecting communication content directed to the numerical control device from normal network communication content passing through the internal network monitoring unit and forwarding to the network monitoring unit.
[0015] Preferably, the method of comparing the intercepted network communication content with normal network communication content uses an artificial intelligence-based method to identify abnormal network communication content from normal network communication content.
[0016] Preferably, the artificial intelligence-based method comprises using OneClassSVM, KMeans or Deep SVDD algorithm for anomaly detection.
[0017] Preferably, the primary alarm triggering method specifically comprises when the sniffer intercepts network communication content directed to the numerical control device and there is a difference between the network communication content directed to the numerical control device and normal network communication content directed to the numerical control device, the network monitoring unit sends a primary alarm signal to the analysis unit through the internal network monitoring unit and the protection unit.
[0018] Preferably, the secondary alarm triggering method specifically comprises using the internal network monitoring unit to record normal network communication content directed to non-numerical control devices, comparing the recorded network communication content with new network communication content in the method of comparing the intercepted network communication content with normal network communication content, and when the comparison result is different, the internal network monitoring unit sends the secondary alarm signal to the analysis unit through the protection unit.
[0019] An internal network security system, comprising:
[0020] a protection unit for establishing a connection with an external network;
[0021] an internal network monitoring unit connected to the protection unit;
[0022] a sniffer and a network monitoring unit connected to the internal network monitoring unit;
[0023] The sniffer is used to simulate the numerical control equipment and record the network communication content directed to the numerical control equipment.
[0024] The network monitoring unit is used to compare the recorded network communication content with normal network communication content and generate an alarm signal when a difference is found.
[0025] Preferably, the sniffer is a simulation emulator used to simulate the numerical control equipment, record network communication content, and forward to the network monitoring unit.
[0026] Preferably, the network monitoring unit is a component that combines network communication content comparison and alarm signal generation.
[0027] Preferably, the analysis unit generates warning information according to the primary and secondary warning signals, and detects the behavior characteristics of attacks in combination with the network communication content recorded in the sniffer and the network communication content recorded in the internal network monitoring unit.
[0028] Compared with the prior art, the advantages and beneficial effects of the present application are that:
[0029] The present application achieves the effects of attack trapping and abnormal behavior recording of numerical control equipment through simulation emulation technology means.
[0030] The present application achieves the effects of deep analysis and abnormal detection of complex network communication content through deep packet inspection (DPI) and artificial intelligence algorithms.
[0031] The present application achieves the effects of timely response and defense of network attacks of different severity through a multi-level alarm triggering mechanism. BRIEF DESCRIPTION OF DRAWINGS
[0032] Figure 1 is a flowchart of the method of the present application;
[0033] Figure 2 is a structural block diagram of the system of the present application. DETAILED DESCRIPTION
[0034] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments can be practiced without these specific details. In addition, in the following description, descriptions of well-known structures and techniques are omitted to avoid unnecessarily obscuring the concept of the present disclosure.
[0035] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the terms "comprises", "comprising", "includes", "including" and the like are specifically intended to be open-ended and to mean that other features, steps, operations, and / or components can be added.
[0036] All terms used herein including technical and scientific terms have the meanings commonly understood by one of ordinary skill in the art unless otherwise defined herein. It should be noted that the terms used herein are defined as having meanings consistent with the context of the specification, and should not be interpreted in an idealized or overly formal way.
[0037] As Figure 1 A network attack detection method of a numerical control device, comprising the following steps:
[0038] A protection unit is set between the internal network and the external network of the industrial control system;
[0039] The main function of the protection unit is to establish a security barrier between the internal network and the external network of the industrial control system to prevent external network attacks from directly threatening the numerical control device in the internal network. The protection unit usually adopts multiple security technical means such as firewall, intrusion detection system (IDS), intrusion prevention system (IPS), etc. The firewall can filter the data packets in and out of the internal network by defining access control policies, and only allows legitimate data flow to pass through. The intrusion detection system and the intrusion prevention system can monitor network traffic in real time, identify and prevent suspicious or malicious activities.
[0040] In the present application, the setting of the protection unit not only blocks unauthorized external access, but also contains an advanced monitoring and defense mechanism. Through the protection unit, all network communication contents in and out of the internal network will be strictly examined.
[0041] In the embodiment, the protection unit can adopt a firewall technology based on deep packet inspection (DPI). DPI can deeply inspect the content of each data packet, not limited to the header information of the data packet. Through this technology, the protection unit can identify and analyze the application layer protocol in the data packet, further improving the accuracy and effectiveness of detection and defense. For example, when a data packet tries to transmit malicious code through the HTTP protocol, DPI can detect this anomaly and prevent it from passing through, thereby protecting the numerical control device in the internal network from being invaded.
[0042] The internal network monitoring unit is connected to the protection unit, and the internal network monitoring unit is connected to the industrial control network server;
[0043] The primary function of the intranet monitoring unit in this invention is to monitor and analyze network traffic within the industrial control system's intranet in real time to identify potential security threats and abnormal behaviors. By connecting the intranet monitoring unit to the protection unit, all data flows entering and leaving the intranet are ensured to undergo rigorous monitoring and filtering, effectively preventing unauthorized access and attacks. Simultaneously, the intranet monitoring unit connects to the industrial control network server, enabling it to comprehensively monitor all operations and communication activities within the industrial control system and take timely response measures upon detecting anomalies.
[0044] In principle, the internal network monitoring unit acts as a second line of defense between the internal and external networks. The protection unit handles the first layer of security checks, blocking most external threats. The internal network monitoring unit, however, delves deeper into the internal network, conducting more detailed inspections of legitimate traffic passing through the protection unit. Its connection method allows it to perform detailed analysis and recording of data packet content, source, destination, and other information after the data packets have passed through the protection unit.
[0045] During implementation, the intranet monitoring unit's work includes the following steps:
[0046] Packet Capture and Analysis: The intranet monitoring unit, connected to the protection unit, captures all network communication content passing through the protection unit in real time. These packets include communication requests to various devices and servers within the industrial control system. The intranet monitoring unit performs in-depth analysis of these packets, including protocol parsing, packet header and payload inspection, to identify potential security threats.
[0047] Anomaly Detection: The intranet monitoring unit uses various techniques to detect anomalies in captured data packets. These techniques may include feature-based detection (e.g., known malicious IP addresses, malware signatures, etc.), behavior-based detection (e.g., abnormal communication patterns, frequent port scans, etc.), and artificial intelligence-based detection (e.g., using machine learning models to identify abnormal communication content).
[0048] Log recording and auditing: All analyzed data packets and their analysis results are logged by the internal network monitoring unit. These logs are used not only for real-time security monitoring but also for post-incident auditing and analysis, helping security personnel understand the attack process and scope of impact, and improve security strategies.
[0049] Alerts and Response: When the internal network monitoring unit detects anomalies or potential security threats, it immediately triggers an alarm and sends the alarm information to the relevant security management system via an interface connected to the industrial control network server. This ensures that security personnel receive the alert and take appropriate response measures as soon as an attack occurs.
[0050] For example, an attacker might attempt to transmit malicious code via a seemingly normal HTTP request. This request passes the initial check by the protection unit and then enters the internal network monitoring unit. The internal network monitoring unit performs a detailed analysis of the HTTP request, checking its payload for any known malicious code characteristics. If an anomaly is detected, the internal network monitoring unit immediately logs the event and triggers an alarm to notify the security management system. In this way, the attack can be prevented before the attacker actually executes the malicious code, protecting the CNC equipment within the industrial control system from damage.
[0051] In summary, the design of the intranet monitoring unit, connecting it to the protection unit and the industrial control network server, enables the intranet monitoring unit to fully utilize its monitoring, analysis, and response functions. Through collaborative work with the protection unit, the intranet monitoring unit not only improves the overall security of the industrial control system's intranet but also enhances the system's ability to detect and respond to complex and advanced threats, thereby ensuring the stable and secure operation of the industrial control system.
[0052] The network monitoring unit is connected to the sniffer, and the network monitoring unit is also connected to the intranet monitoring unit;
[0053] In this invention, the network monitoring unit, as a core component, is responsible for in-depth analysis and review of network communication content. Through its connection with a sniffer, the network monitoring unit can receive network communication data captured by the sniffer in real time. With the assistance of the intranet monitoring unit, the sniffer simulates the normal operating environment of CNC equipment, thereby guiding potential attackers to target the sniffer. The connection between the network monitoring unit and the intranet monitoring unit ensures comprehensive analysis and monitoring of all communication content within the intranet.
[0054] The role of the network monitoring unit is to perform detailed inspection and comparison of network communications intercepted by sniffers to identify potential security threats. Its workflow includes data reception, parsing, analysis, and alert generation. By working in conjunction with sniffers and internal network monitoring units, the network monitoring unit can form a highly efficient monitoring and defense system.
[0055] A sniffer simulates one or more CNC machines within an industrial control system's intranet. These machines appear to be functioning normally, but are actually used to guide and capture malicious activities by attackers. The network communications captured by the sniffer include all communication requests directed to these simulated machines. Due to the sniffer's location and role, attackers have difficulty detecting its presence and therefore mistake it for a legitimate target.
[0056] After receiving data from the sniffer, the network monitoring unit performs deep analysis on the data packets to extract key information such as source address, destination address, protocol type, and payload content. Then, the network monitoring unit compares this information with normal network communication content to detect abnormal behavior. Specific comparison methods can include rule-based detection, statistical analysis, and machine learning algorithms.
[0057] By connecting to the intranet monitoring unit, the network monitoring unit is not limited to analyzing sniffer data, but can also monitor communication activities throughout the entire intranet. This comprehensive monitoring ensures that even if attackers bypass the sniffer and directly attack other devices on the intranet, the network monitoring unit can detect and respond in a timely manner.
[0058] For example, an attacker might attempt to send malicious commands using a sniffer simulating a CNC machine. The sniffer captures these commands and transmits them to the network monitoring unit. The network monitoring unit performs deep analysis on these commands, identifying differences from normal commands. If these commands contain malicious code or abnormal behavior, the network monitoring unit immediately generates an alert and notifies the security management system through the internal network monitoring unit for further action.
[0059] First, the combination of sniffer and network monitoring units can effectively trap and detect attacker behavior, providing detailed attack data for analysis. Second, through comprehensive monitoring by the intranet monitoring unit, the security of the entire industrial control system's intranet is significantly improved, and any potential attack behavior can be detected and dealt with in a timely manner. Furthermore, the deep analysis and comparison functions of the network monitoring unit ensure efficient detection of complex and advanced attacks, thus providing multi-layered security for the industrial control system.
[0060] In summary, the design, which connects the network monitoring unit to the sniffer and the intranet monitoring unit, achieves comprehensive protection of the industrial control system's intranet through multi-layered monitoring and in-depth analysis, effectively enhancing the system's security and defense capabilities. Through this design, the present invention can provide stable and reliable security in complex and ever-changing network environments, ensuring the normal operation of the industrial control system.
[0061] The intercepted network communication content is recorded by a sniffer connected to the intranet monitoring unit;
[0062] In this invention, a sniffer serves as a key component, used to capture and record network communication content within the intranet, particularly communication data from CNC equipment. The sniffer connects to the intranet monitoring unit, enabling it to receive and analyze network traffic in real time to detect potential attacks and abnormal behavior. The sniffer's primary function is to simulate the normal operating state of CNC equipment, enticing attackers to target it, thereby intercepting all network communication content targeting these simulated devices.
[0063] A sniffer passively monitors data streams within an internal network, capturing all passing network communication data. Its workflow includes packet interception, parsing, storage, and transmission. The core technology of a sniffer is Deep Packet Inspection (DPI), which allows the sniffer to deeply analyze the content of each data packet, rather than simply examining the packet header. Through DPI, the sniffer can identify and record detailed information within the data packets, such as source address, destination address, protocol type, and payload content.
[0064] The sniffer accomplishes its task through the following steps:
[0065] Packet interception: A sniffer simulates one or more CNC machines within the internal network. All network communication data destined for these machines passes through the sniffer. Due to the presence of these simulated devices, attackers may mistake them for legitimate CNC machines and launch an attack. The sniffer intercepts all data packets flowing to these simulated devices through passive listening mode.
[0066] Deep Packet Inspection (DPI): Intercepted packets are analyzed in detail using DPI technology. The sniffer examines each layer of the packet, including application layer protocols, to extract key information. This information includes, but is not limited to: source address, destination address, port number, protocol type, packet length, and payload content. Through DPI, the sniffer can identify potential threats in the packets, such as malicious code, abnormal commands, or abnormal traffic patterns.
[0067] Data storage and transmission: The parsed data packets are stored in the sniffer's local memory and simultaneously transmitted to the internal network monitoring unit. The internal network monitoring unit further analyzes and processes this data to identify potential security threats and abnormal behaviors. The stored data can be used for post-incident auditing and analysis, helping security personnel understand the specific process and characteristics of the attack.
[0068] Real-time alerts and response: When the sniffer detects abnormal or malicious activity, it immediately generates an alert and notifies the security management system via the internal network monitoring unit. These alerts include detailed anomaly information to help security personnel quickly identify and respond to attacks. Depending on the severity of the anomaly, the sniffer can trigger different levels of alerts (such as Level 1 and Level 2 alerts) to allow for appropriate response measures.
[0069] For example, an attacker might attempt to send malicious code commands using a sniffer simulating a CNC machine. The sniffer captures these commands and parses them using DPI (Distributed Proof-of-Injection) technology, identifying the malicious code characteristics contained within. The sniffer immediately logs this data and generates an alert to notify the internal network monitoring unit. The internal network monitoring unit further analyzes this data and, upon confirming the attack, notifies the security management system to take measures to prevent the malicious code from spreading and executing within the internal network.
[0070] Using the method of this invention, the sniffer can effectively capture and record network communication content targeting CNC equipment, providing detailed data support for subsequent security analysis and response. Its connection to the internal network monitoring unit enables the entire system to work collaboratively, forming a comprehensive network security defense system. This not only improves the detection capability of complex and advanced threats but also ensures the safe and stable operation of the industrial control system.
[0071] The sniffer connects to the internal network monitoring unit and uses deep packet inspection technology to capture and record network communication content in real time. It identifies and responds to attacks in their early stages, effectively protecting CNC equipment within the industrial control system from cyberattacks. Through this design, the present invention provides a high level of security in industrial control network environments, ensuring the continuity and safety of industrial production processes.
[0072] Mirror the network communication content of the intranet monitoring unit to the network monitoring unit;
[0073] Preferably, mirroring the network communication content includes: selecting communication content directed to the CNC equipment from the normal network communication content through the intranet monitoring unit, and forwarding it to the network monitoring unit.
[0074] In this invention, the main function of the intranet monitoring unit is to monitor and analyze network communication content within the intranet in real time to detect potential security threats. By mirroring network communication content to the network monitoring unit, it can be ensured that all critical communication content can be examined and analyzed in detail, thereby improving the system's security and defense capabilities. Mirroring technology plays a crucial role here, allowing network communication data to be copied and transmitted to the review unit for further processing without affecting normal communication.
[0075] Mirroring network communication content refers to creating copies of network traffic within the intranet monitoring unit and sending these copies to the network monitoring unit. Mirroring technology typically involves using the port mirroring function of a network switch or employing specialized network probe devices to capture and copy network data streams. In this way, the intranet monitoring unit can monitor and analyze network communication without affecting the actual transmission of communication traffic.
[0076] The network communication process of a mirror includes the following steps:
[0077] Packet Capture and Selection: The intranet monitoring unit captures all network communication data passing through it in real time. From the captured packets, the intranet monitoring unit selects communication content destined for the CNC equipment according to predefined rules and policies. These rules can be based on factors such as the packet's source address, destination address, port number, and protocol type. For example, the intranet monitoring unit can be configured to capture and mirror only communication packets destined for a specific IP address (i.e., the CNC equipment).
[0078] Packet mirroring: Selected packets are copied to form a mirror copy. These mirrored packets retain all the information of the original packets, including header information and payload content. The mirroring process can be implemented through the port mirroring function of a network switch, or through hardware-level capture and copying using network probe devices.
[0079] Packet forwarding: Mirrored data packets are forwarded to the network monitoring unit via the connection of the internal network monitoring unit. Upon receiving these mirrored data packets, the network monitoring unit performs in-depth analysis and review. In this way, the network monitoring unit can obtain critical communication content within the internal network in real time and perform detailed security analysis.
[0080] Deep analysis and review: The network monitoring unit performs deep analysis on the received mirrored data packets to check for anomalies or potential threats. The analysis process includes layered packet analysis (e.g., parsing application layer protocols), feature matching (e.g., identifying known malicious code characteristics), and behavioral analysis (e.g., detecting abnormal communication patterns). This detailed review effectively identifies and prevents various network attacks and security threats.
[0081] For example, the intranet monitoring unit captures an HTTP request directed to a CNC machine. According to predefined rules, the intranet monitoring unit selects and mirrors this HTTP request, forwarding it to the network monitoring unit. The network monitoring unit performs a deep analysis of the HTTP request and discovers malicious code characteristics in the request payload. At this point, the network monitoring unit generates an alert and notifies the intranet monitoring unit and the security management system, thereby enabling timely measures to prevent the malicious code from spreading within the intranet.
[0082] Mirroring technology enables detailed inspection of all critical communication content, significantly improving intranet security. Mirrored data packets can be transmitted to the network monitoring unit in real time, ensuring that any potential threats can be quickly identified and dealt with. Through deep analysis and detailed review, the network monitoring unit can accurately identify complex and advanced network attacks, improving detection accuracy and effectiveness. The application of mirroring technology allows intranet monitoring and security audits to be conducted without affecting normal communication traffic, ensuring system stability and normal operation.
[0083] The network monitoring unit compares the intercepted network communication content with normal network communication content.
[0084] Preferably, the method for comparing intercepted network communication content with normal network communication content uses an artificial intelligence-based approach to identify abnormal network communication content from normal network communication content.
[0085] In this invention, the network monitoring unit detects and identifies potential security threats and abnormal behaviors by comparing intercepted network communication content with normal network communication content. The core of this process lies in its ability to accurately distinguish between normal communication traffic and abnormal traffic that may be malicious. Through this comparison, the system can detect and respond to various network attacks and anomalies in real time.
[0086] The comparison process includes data reception, feature extraction, model training, and anomaly detection. The network monitoring unit first receives intercepted network communication content from the internal network monitoring unit and sniffer, while simultaneously acquiring normal network communication content as a benchmark. Through deep analysis and feature extraction of this data, feature vectors are generated for comparison. Then, based on these feature vectors, an artificial intelligence model is trained to identify abnormal network communication content.
[0087] Preferred AI-based methods include using OneClassSVM, KMeans, or Deep SVDD algorithms for anomaly detection.
[0088] Artificial intelligence-based methods are used to identify anomalies from normal network communication content, and include the following steps:
[0089] Data Collection and Preprocessing: The network monitoring unit receives a large amount of network communication data from the intranet monitoring unit and sniffers. Normal network communication content typically comes from historical data and verified normal operation records. After collection, this data needs to be preprocessed, including data cleaning, noise reduction, and standardization, to ensure data consistency and accuracy.
[0090] Feature extraction: Preprocessed data needs to have features extracted for training and detection. The feature extraction process includes parsing the header and payload of data packets to extract key fields such as source address, destination address, port number, protocol type, packet length, and timestamp. These features can effectively characterize the behavior and patterns of network communication.
[0091] Model training: Using the extracted features, artificial intelligence-based algorithms are employed for model training. Commonly used algorithms include OneClassSVM, KMeans, and Deep SVDD. Specifically:
[0092] OneClassSVM (Single Class Support Vector Machine): Primarily used for anomaly detection. When training the model, only normal data is used to build a separation interface that distinguishes normal data from potentially anomalous data.
[0093] KMeans: A clustering algorithm that identifies outliers by dividing data into different clusters. Normal data points cluster together, while outliers are usually isolated.
[0094] Deep SVDD (Deep Support Vector Data Description): Combining deep learning and traditional SVDD, it can effectively process high-dimensional and complex network data and identify potential anomalies.
[0095] Anomaly detection and comparison: The trained model is used to detect intercepted network communication content in real time. The network monitoring unit inputs the characteristics of the intercepted communication data into the model for comparison and judgment. If a data point is detected to deviate from the normal data distribution range, it is considered an anomaly, and an alarm is generated.
[0096] For example, the network monitoring unit receives a network communication data packet captured by a sniffer. First, the data packet undergoes preprocessing and feature extraction to generate a feature vector. Then, the feature vector is input into a trained OneClassSVM model for comparison. The model determines that the data packet differs significantly from normal communication content and marks it as anomalous data. At this point, the network monitoring unit generates an alert and notifies the internal network monitoring unit and security management system to take further action.
[0097] This AI-based approach has yielded significant results. First, through automated and intelligent anomaly detection, it significantly improves the efficiency and accuracy of detection. Second, by utilizing machine learning algorithms, it can process and analyze large-scale, highly complex network data, enabling the timely detection of potential threats. Furthermore, these methods are adaptive and scalable, allowing for continuous optimization and improvement of detection models as the network environment changes.
[0098] By comparing intercepted network communication content with normal network communication content in the network monitoring unit, and especially by using artificial intelligence-based methods for anomaly detection, this invention achieves efficient and secure monitoring of the industrial control system's intranet. This method can not only identify complex and advanced network attacks in real time, but also provide timely response and defense, ensuring the safe and stable operation of the industrial control system.
[0099] A Level 1 alarm is triggered when there is a difference between the intercepted network communication content and the normal network communication content.
[0100] In this invention, one of the core functions of the network monitoring unit is to compare intercepted network communication content with normal network communication content to detect anomalies. When a significant difference is detected between the two, the system triggers a Level 1 alarm. The Level 1 alarm triggering mechanism is designed to quickly identify and respond to potential threats, thereby protecting CNC equipment within the industrial control system from attacks.
[0101] The Level 1 alert is triggered based on comparative analysis results. When the network monitoring unit detects an abnormal difference between intercepted network communication content and normal communication content, the system considers it a potential security threat. In practice, difference detection can be achieved through various technical means, including feature-based matching, statistical analysis, and machine learning algorithms. These techniques can identify various abnormal behaviors such as abnormal traffic patterns, malicious code characteristics, and unauthorized access attempts.
[0102] The specific implementation steps include:
[0103] Data capture and parsing: The sniffer captures network communication content directed at the CNC equipment in real time and transmits it to the network monitoring unit. The network monitoring unit performs in-depth analysis on this data to extract key information such as source address, destination address, protocol type, and payload content.
[0104] Feature comparison: The network monitoring unit compares intercepted network communication content with predefined normal communication content. Normal communication content typically comes from historical data and verified operation records. During the comparison process, the system examines various aspects of the data packets, including communication frequency, packet length, protocol usage, and content patterns.
[0105] Difference detection: Based on the comparison results, the network monitoring unit identifies any abnormal characteristics. For example, if a network request to a CNC machine contains unknown commands or abnormal data patterns, the system will mark it as abnormal. These anomalies may include instructions that do not conform to normal operating patterns, malicious code contained in data packets, or abnormally high communication frequencies.
[0106] Alarm Trigger: When an abnormal difference is detected, the network monitoring unit generates a Level 1 alarm. The alarm signal is transmitted to the analysis unit through the intranet monitoring unit and the protection unit. The analysis unit is responsible for further processing the alarm signal, assessing the severity of the threat, and taking appropriate response measures.
[0107] Preferably, the first-level alarm triggering method specifically involves the network monitoring unit sending a first-level alarm signal to the analysis unit through the intranet monitoring unit and the protection unit when the network communication content intercepted by the sniffer pointing to the CNC equipment differs from the normal network communication content pointing to the CNC equipment.
[0108] For example, an attacker might attempt to control CNC equipment by sending malicious commands. A sniffer captures these commands and transmits them to the network monitoring unit. The network monitoring unit parses and compares these commands, discovering that they contain anomalous opcodes or unauthorized commands. The system identifies these anomalies and triggers a Level 1 alarm. The alarm signal is transmitted through the intranet monitoring unit to the protection unit, which then sends it to the analysis unit. Upon receiving the alarm, the analysis unit immediately takes measures to prevent the execution of the malicious commands and notifies security personnel for further investigation.
[0109] The effects of this design are significant. First, real-time anomaly detection and alarm triggering ensure the system can respond in the early stages of an attack, thereby minimizing potential damage. Second, through multi-layered monitoring and comparative analysis, the system can accurately identify complex and advanced attack behaviors, improving detection accuracy and response timeliness. Furthermore, the primary alarm triggering mechanism enables the system to react quickly to potential threats, ensuring the safety of CNC equipment within the industrial control system.
[0110] When there is a difference between the intercepted network communication content and the normal network communication content, a level one alarm is triggered. The optimized alarm triggering method ensures efficient identification and response to abnormal communication of critical equipment. This invention achieves comprehensive protection of the industrial control system intranet and improves the system's security and defense capabilities.
[0111] When an anomaly is detected in the network communication content at the intranet monitoring unit, a level two alarm is triggered.
[0112] In this invention, the triggering mechanism of the secondary alarm is used to detect and respond to abnormal communication behavior occurring in the intranet, especially those communications that are not directly targeting CNC equipment but may still pose a security threat. This mechanism identifies abnormal differences by comparing normal network communication content recorded by the intranet monitoring unit with new network communication content, thereby triggering an alarm and taking corresponding protective measures.
[0113] Level 2 alerts are triggered based on comprehensive monitoring and analysis of network communication content. The intranet monitoring unit continuously records all network communication activity within the intranet and establishes a baseline for normal communication content. When new communication content emerges, the system compares it to the normal baseline to detect any abnormal behavior. In this way, the system can discover hidden and sophisticated attack attempts and respond promptly.
[0114] The specific implementation steps include:
[0115] Data logging and baseline establishment: The intranet monitoring unit continuously records all network communication content directed to non-CNC equipment. This communication content includes normal operations and communication traffic within the intranet, constituting the system's normal communication baseline. The baseline data undergoes preprocessing, including data cleaning and standardization, to ensure its consistency and accuracy.
[0116] New Data Capture and Parsing: When new network communication content passes through the intranet monitoring unit, the system captures and parses this data, extracting key information such as source address, destination address, protocol type, and payload content. The parsing process is similar to the baseline establishment process, ensuring data consistency.
[0117] Anomaly Detection: The intranet monitoring unit compares new network communication content with established normal communication benchmarks. During the comparison, the system checks various characteristics, including communication frequency, packet length, protocol usage, and content patterns. If there are significant differences between the new data and the benchmark data, the system considers an anomaly detected.
[0118] Triggering an Alert: When an anomaly is detected, the intranet monitoring unit generates a Level 2 alert signal. This signal is sent to the analysis unit via the protection unit, which further assesses the severity of the anomaly and takes appropriate response measures. Level 2 alerts are typically used to identify more covert or complex attack behaviors that require more detailed analysis and processing.
[0119] Preferably, the secondary alarm triggering method specifically involves using the intranet monitoring unit to record normal network communication content directed to devices other than the CNC equipment, and comparing the intercepted network communication content with the normal network communication content. The recorded network communication content is compared with new network communication content. When the comparison result shows a difference, the intranet monitoring unit sends the secondary alarm signal to the analysis unit through the protection unit.
[0120] For example, the internal network monitoring unit detects abnormal traffic pointing to an internal network server. This traffic includes a large number of login attempts, indicating potential brute-force attacks. The internal network monitoring unit compares this new communication content with a normal login traffic baseline, finding an unusually high frequency of login attempts and unauthorized access requests. After identifying these anomalies, the system generates a level-two alert and sends it to the analysis unit through the protection unit. Upon receiving the alert, the analysis unit immediately assesses the risk and notifies security personnel to take measures, such as locking suspicious accounts and blocking abnormal IP addresses.
[0121] First, the two-level alert mechanism ensures that all potential threats within the intranet can be identified in a timely manner, even if these threats are not directly targeting CNC equipment. Second, by comparing normal baselines with new communication content, the system can accurately identify complex and covert attack behaviors, improving detection accuracy and response timeliness. Furthermore, the triggering and processing mechanism of the two-level alerts enables the system to maintain a high level of defense against multi-layered security threats.
[0122] When an anomaly is detected in the network communication content at the intranet monitoring unit, a level two alarm is triggered. The optimized alarm triggering method ensures efficient identification and response to abnormal communication of non-CNC equipment. This invention achieves comprehensive protection of the industrial control system intranet and improves the system's security and defense capabilities.
[0123] like Figure 2 As shown, an intranet security system includes:
[0124] The protection unit is used to establish a connection with the external network;
[0125] An intranet monitoring unit is connected to the protection unit;
[0126] The sniffer and network monitoring unit are connected to the intranet monitoring unit;
[0127] The sniffer is used to simulate the CNC equipment and record the network communication content directed to the CNC equipment;
[0128] The network monitoring unit is used to compare the recorded network communication content with normal network communication content, and generate an alarm signal when a difference is found.
[0129] In this invention, the intranet security system is designed to protect CNC equipment within the industrial control system from external network attacks. This system achieves comprehensive network security defense through the collaborative work of multiple components.
[0130] First, the protection unit establishes a connection to the external network, its primary function being to act as a security barrier between the industrial control system's internal network and the external network. By applying technologies such as firewalls and intrusion prevention systems (IPS), the protection unit filters and monitors all network traffic entering and leaving the internal network, preventing unauthorized access and potential attacks. The protection unit ensures that only legitimate data packets can pass through, protecting critical equipment within the internal network from direct external threats.
[0131] The intranet monitoring unit connects to the protection unit, and its main function is to monitor and analyze network communications within the intranet in real time. The intranet monitoring unit not only records normal communication content within the intranet but also captures new network communication data in real time and compares it with the recorded normal communication content to detect any abnormal or suspicious activity. In this way, the intranet monitoring unit can promptly detect and respond to potential threats within the intranet, ensuring the security of the industrial control system.
[0132] The sniffer and network monitoring unit are connected to the internal network monitoring unit. The sniffer is used to simulate CNC equipment and record network communications directed to these devices. By simulating the normal operating environment of CNC equipment, the sniffer attracts and captures potential attack traffic. This simulation technology enables the sniffer to effectively record attacker behavior and provide detailed data for subsequent security analysis.
[0133] The network monitoring unit compares network communication content recorded by the sniffer with normal network communication content. When a significant difference is detected, the network monitoring unit generates an alert signal. This comparison process involves deep packet inspection (DPI) technology and AI-based anomaly detection algorithms to ensure the system can accurately identify various complex attack behaviors. The network monitoring unit not only monitors network traffic in real time but also generates alert signals, enabling the system to respond promptly when potential threats are detected.
[0134] Preferably, the sniffer is a simulator used to simulate the CNC machine tool, record network communication content, and forward it to the network monitoring unit. Through this simulation, the sniffer can effectively attract and capture attack traffic, providing the network monitoring unit with detailed analytical data. For example, in one embodiment, the sniffer can simulate a CNC machine tool, capturing all network requests and instructions directed to that machine tool. This data is then transmitted to the network monitoring unit for in-depth analysis and comparison.
[0135] Preferably, the network monitoring unit is a component that combines network communication content comparison and alarm signal generation. Upon receiving an alarm signal, the analysis unit further assesses the severity of the anomaly and takes appropriate response measures. For example, the analysis unit can lock the attacked device, block abnormal communication traffic, or notify security personnel for further investigation.
[0136] Preferably, the analysis unit generates warning information based on level one and level two warning signals, and combines this information with network communication content recorded in the sniffer and the intranet monitoring unit to detect the behavioral characteristics of the attack. For example, when the sniffer captures abnormal network communication content and triggers a level one alarm, the analysis unit evaluates the detailed information of the alarm and, in conjunction with data from the intranet monitoring unit, confirms the specific nature and scope of the attack, thereby taking the most appropriate protective measures.
[0137] Through multi-layered monitoring and analysis, the system can comprehensively protect CNC equipment within the intranet and prevent various potential network attacks. It can capture and analyze network communication content in real time, responding promptly in the early stages of an attack to reduce potential damage. Utilizing deep packet inspection and AI-based algorithms, the system can accurately identify complex and advanced attack behaviors, improving detection accuracy and effectiveness. Through the collaborative work of protection units, intranet monitoring units, sniffer, and network monitoring units, the system forms a multi-layered defense barrier, providing comprehensive security for industrial control systems.
[0138] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects.
[0139] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for detecting network attacks on CNC equipment, characterized in that, Includes the following steps: Set up a protection unit between the internal network and the external network of the industrial control system; The intranet monitoring unit is connected to the protection unit, and the intranet monitoring unit is connected to the industrial control network server; The network monitoring unit is connected to the sniffer, and the network monitoring unit is also connected to the intranet monitoring unit; The intercepted network communication content is recorded by a sniffer connected to the intranet monitoring unit; The sniffer simulates one or more CNC devices in the intranet, and all network communication data directed to these devices will pass through the sniffer; the intercepted data packets are analyzed in detail using DPI technology, and the analyzed data is transmitted to the intranet monitoring unit to attract and capture potential attack traffic and form a restricted data source for CNC devices; The network communication content of the intranet monitoring unit is mirrored to the network monitoring unit; wherein, communication content pointing to the CNC equipment is selected from the normal network communication content passing through the intranet monitoring unit and forwarded to the network monitoring unit; the mirroring technology uses the port mirroring function of the network switch, or uses a network probe device to capture and copy the network data stream, so that the network communication data can be copied and transmitted to the review unit without affecting normal communication, and the data packets processed by the mirroring are transmitted to the network monitoring unit in real time; The network monitoring unit performs in-depth analysis and review of the received mirrored data packets to identify anomalies or potential threats; the network monitoring unit compares the intercepted network communication content with normal network communication content. A Level 1 alarm is triggered when there is a difference between the intercepted network communication content and the normal network communication content; a Level 2 alarm is triggered when an anomaly is detected in the network communication content at the intranet monitoring unit. The specific method for triggering the first-level alarm is as follows: when the network communication content intercepted by the sniffer pointing to the CNC equipment is different from the normal network communication content pointing to the CNC equipment, the network monitoring unit sends the first-level alarm signal to the analysis unit through the intranet monitoring unit and the protection unit. The specific method for triggering the secondary alarm is to use the intranet monitoring unit to record normal network communication content that is directed to devices other than the CNC equipment, and to compare the intercepted network communication content with the normal network communication content. When the comparison result shows a difference, the intranet monitoring unit sends the secondary alarm signal to the analysis unit through the protection unit. The method for comparing intercepted network communication content with normal network communication content uses an artificial intelligence-based approach to identify abnormal network communication content from normal network communication content.
2. The detection method according to claim 1, characterized in that, Artificial intelligence-based methods include using OneClassSVM, KMeans, or Deep SVDD algorithms for anomaly detection.
3. An intranet security system for implementing the network attack detection method for CNC equipment according to any one of claims 1-2, characterized in that, The system includes: The protection unit is used to establish a connection with the external network; An intranet monitoring unit is connected to the protection unit; The sniffer and network monitoring unit are connected to the intranet monitoring unit; The sniffer is used to simulate the CNC equipment and record the network communication content directed to the CNC equipment; The network monitoring unit is used to compare the recorded network communication content with normal network communication content, and generate an alarm signal when a difference is found.
4. The intranet security system according to claim 3, characterized in that, The sniffer is a simulator used to simulate the CNC equipment, record network communication content, and forward it to the network monitoring unit.
5. The intranet security system according to claim 3, characterized in that, The network monitoring unit is a component that combines network communication content comparison and alarm signal generation.
6. The intranet security system according to claim 3, characterized in that, The analysis unit generates warning information based on the first and second level warning signals, and combines the network communication content recorded in the sniffer and the network communication content already recorded in the intranet monitoring unit to detect the behavioral characteristics of the attack.
Citation Information
Patent Citations
Industrial control network security detection method and device, electronic equipment and storage medium
CN111343205A
Industrial control network security detection system
CN112738077A