A network risk detection method and system
By constructing a network diagram and using random walk and Skip-Gram models for node embedding representation, the detection problem of IT system attacking OT system after IT and OT systems in rail transit system is solved, efficient identification and risk assessment of abnormal communication is achieved, and the security of OT system is ensured.
Patent Information
- Application Number
- CN202410955585.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-17
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-07-17
AI Technical Summary
The prior art is difficult to effectively detect the attacks on the OT system by the security threat of IT and OT systems after the convergence of IT and OT systems in rail transit systems, making it difficult to identify operational risks.
By constructing a network graph, marking communication types and network areas, using random walks and Skip-Gram models to generate node embedding representations, perform cluster detection and score calculations, and identify abnormal communication risks.
It improves the accuracy of detection of abnormal communications in rail transit systems, can timely identify potential risk communications, and ensures the safety of the OT system.
Smart Images

Figure CN119011198B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and particularly relates to a network risk detection method and system. Background Art
[0002] The network in the rail transit industry has some special points compared with ordinary networks, mainly reflected in its unique operation requirements, security requirements, complexity, real-time nature, etc.
[0003] The network in the rail transit industry usually mixes IT and OT systems. IT systems: including ticket systems, passenger information systems, back-end management systems, etc., which process the business requirements of traditional information technologies. OT systems: including signal systems, train control systems, platform door control systems, etc., which directly affect the safety of trains and passengers. In the current network, it is necessary to achieve the effective integration of IT and OT systems to improve operation efficiency, and at the same time, the proper isolation of the two must also be ensured to prevent the spread of security threats.
[0004] IT systems are exposed to the public and are more vulnerable to network threats. Due to the integration of IT and OT systems, security vulnerabilities in IT systems may be exploited to attack OT systems, resulting in direct operation risks.
[0005] In the prior art, abnormal traffic is usually used for risk detection. When attacking OT through IT, the data all flows within the system, and it is very difficult to effectively detect abnormal behaviors. Summary of the Invention
[0006] To solve the problems in the prior art, the present invention provides a network risk detection method, including the following steps: collecting network data in the rail transit system; converting the network data into a representation form of nodes and edges, where the nodes are devices and the edges are communication relationships; marking the communication types and network regions of the network data, the communication types including: data transmission, control instructions, signal transmission, and the network regions including: IT system region and OT system region; setting the weights of the edges according to the communication types and network regions, and embedding the nodes into a low-dimensional space to obtain a first communication graph; performing cluster detection on the first communication graph, and determining the first score between the first node and the second node according to whether the first node and the second node are in the same cluster; calculating the representation distance between the first node and the second node according to the first communication graph to obtain the second score between the first node and the second node; calculating the comprehensive score of the first node and the second node by weighting the first score and the second score. If the comprehensive score is greater than a preset value, there is a risk communication between the first node and the second node.
[0007] Further, the setting of the weights of the edges according to the communication types and network regions includes:
[0008] Construct a network graph G=(V, E)
[0009] Where the node set V represents the devices or system components in the rail transit system;
[0010] The edge set E represents the communication or interaction relationship between nodes;
[0011] E ={(u, v, weight uv )|u, v ∈ V}
[0012] Where
[0013] u, v represent devices or system components;
[0014] weight uv Represents the weight of the edge, reflecting the threat weight of the communication type and network area conversion;
[0015] The weight weight of the edge uv Is calculated based on the following formula:
[0016] weight uv = w type + w region Where:
[0017] w type Represents the weight of the communication type;
[0018] w region Represents the weight of network area conversion.
[0019] Furthermore, when performing cluster detection on the first communication graph, first use the random walk strategy to generate a node sequence for each node.
[0020] Furthermore, after using the random walk strategy to generate a node sequence for each node, use the Skip-Gram model to train the generated node sequence to obtain the embedded representation of the nodes.
[0021] Furthermore, after obtaining the embedded representation of the nodes, for each point e in the embedding space p , find all points N(e p ) within the radius of ∈
[0022] N(e p ) = {e q ∈ E|dist(e p , e q ) ≤ ò}
[0023] Where e p Represents the embedding vector of point p;
[0024] ∈ represents the neighborhood radius dist(e p, e q ) represents the embedding vector e p and e q the distance between
[0025] E represents all nodes;
[0026] If |N(e p )| ≥ MinPts then e p is a core point;
[0027] Starting from the core point, all points that are density-reachable are grouped into the same cluster; the point e q from the point e p is density-reachable if and only if there exists a point chain
[0028] e p1 , e p2 … e pn such that e p1 = e p , e pn = e q and e pi+1 ∈ N(e pi ).
[0029] Furthermore, the first score between the first node and the second node is determined according to whether the first node and the second node are in the same cluster, specifically:
[0030] For each edge, calculate the first score according to the clustering result
[0031]
[0032] Furthermore, according to the first communication graph, calculate the representation distance between the first node and the second node, and the second score between the first node and the second node is specifically:
[0033] Score_2(i, j) = ‖e i - e j ‖2.
[0034] Furthermore, the weighted calculation of the first score and the second score for the comprehensive score of the first node and the second node includes:
[0035] CAS(i, j) = α·Score_1(i, j) + β·Score_2(i, j)
[0036] where CAS(i, j) is the comprehensive score, and α and β are weight parameters.
[0037] Furthermore, if the comprehensive score is greater than the preset value, it includes:
[0038] When the comprehensive score is higher than the average level by 50%, it is considered that there is a risk between nodes i and j.
[0039] The present invention also discloses a network risk detection system, which at least includes a memory and a CPU. The memory stores a computer program for executing any of the foregoing methods, and the CPU executes it.
[0040] Through the above technical solutions, the present invention can produce the following beneficial effects:
[0041] By assigning weights to each edge to reflect the threat weights of different communication types and network area conversions, the security risks of different types of communication can be captured more accurately.
[0042] Networks usually have a very large amount of data. Therefore, high-dimensional graph data is converted into embedding vectors in a low-dimensional space for better clustering and anomaly detection.
[0043] By clustering nodes that often communicate in clusters, and considering different communication protocols and communication area switches in the network graph. When two nodes are not in the same cluster and are far apart, it indicates that there is abnormal traffic between two nodes that do not often communicate, and there may be a risk between these two nodes, improving the accuracy of anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] Next, with reference to the drawings and specific embodiments, the present invention will be preferably described.
[0047] This embodiment solves the above problems through the following steps:
[0048] In one embodiment, referring to Figure 1 , the present invention provides a network risk detection method, including the following steps:
[0049] To obtain a preliminary dataset containing devices and communication relationships, network data in the rail transit system is collected. Network communication data and network traffic data can be collected from various data sources in the rail transit system: from devices such as switches, routers, and firewalls. System logs: collected from devices such as servers, control systems, and sensors. Communication records: communication records between devices.
[0050] Convert the network data into a representation of nodes and edges, where the nodes are devices and the edges are communication relationships; collect raw data, extract information about nodes and edges, and prepare for subsequent steps to obtain a preliminary dataset containing devices and communication relationships.
[0051] Meanwhile, clean the data, extract useful information, and mark the communication type and network area attributes. Mark the communication type and network area of the network data. The communication types include: data transmission, control instructions, and signal transmission. The network areas include: IT system area and OT system area. In the rail transit system, the IT system is usually used for user data transmission, while the OT system is mostly for control instructions and signal transmission. Based on this, if there is a problem of an attack from the IT to the OT system, the attacker may send harmful control instructions from the IT system to the OT, and steal signal data from the OT system and transfer it to the IT system. Therefore, the main principle of this embodiment is to detect unconventional combinations of data types (data transmission, control instructions, signal transmission) and network areas (IT system area and OT system area) to determine whether there are risks in the network.
[0052] To be able to reflect the roles of different communication areas and communication types, set the weight of the edge according to the communication type and network area.
[0053] Construct a network graph G=(V,E)
[0054] where the node set V represents devices or system components in the rail transit system.
[0055] The edge set E represents the communication or interaction relationship between nodes, and each edge has communication type and network area attributes.
[0056] E ={(u,v,weight uv )∣u,v∈V}
[0057] where
[0058] u,v represent devices or system components.
[0059] weight uv represents the weight of the edge, reflecting the threat weight of the conversion of communication type and network area.
[0060] The weight of the edge weightuv It can be calculated based on the following formula:
[0061] weight uv = w type + w region Where:
[0062] w type : The weight of the communication type.
[0063] w region The weight of network area conversion.
[0064] By assigning weights to each edge to reflect the threat weights of different communication types and network area conversions, the security risks of different types of communication can be captured more accurately. For example, the communication of IT systems is more vulnerable to attacks, while the communication of OT systems directly affects operational security. Therefore, assigning different weights helps for more accurate anomaly detection.
[0065] Since the network usually has a very large amount of data, the high-dimensional graph data is converted into an embedded vector in a low-dimensional space for better clustering and anomaly detection, and the nodes are embedded into the low-dimensional space to obtain a first communication graph. Cluster detection is performed on the first communication graph, and a first score between the first node and the second node is determined according to whether the first node and the second node are in the same cluster.
[0066] First, to capture the relationships between nodes (the structural information of the graph), a random walk strategy is used to generate a node sequence.
[0067] The path selection method for random walk starting from a node controls the behavior of the random walk by adjusting two parameters p and q, so that the walk can capture both local information (the relationships of neighboring nodes) and global information (the relationships of distant nodes).
[0068] Where p is the return parameter that controls the probability of returning to the previous node during the walk. A smaller p value encourages the walk to return to the previous node, thus increasing the tendency of depth-first search (DFS). A larger p value reduces the probability of returning to the previous node, making the walk more like breadth-first search (BFS).
[0069] q is the exploration parameter that controls the probability of visiting a node far from the previous node during the walk. A smaller q value encourages the walk to reach a node far from the initial node, thus increasing the tendency of breadth-first search (BFS). A larger q value reduces the probability of reaching a node far from the initial node, making the walk more like depth-first search (DFS).
[0070] Start walking from a certain starting node u. Randomly select the next node: According to the probability between nodes, select the next node v from the neighbors of the current node t to continue walking: Repeat step 2 until the predetermined number of walking steps T is reached. Generate a node sequence: Record the node sequence generated by each walk.
[0071] Starting from each node, perform a random walk for a fixed number of steps to generate a node sequence
[0072] S v ={v1,v2,...,v T}
[0073] Where:
[0074] S v : The random walk sequence starting from node v.
[0075] T: The number of walking steps.
[0076] Using the random walk strategy, the local and global structural information of the graph can be captured. By converting the high-dimensional graph data into low-dimensional embedding vectors, important structural information is retained, which helps to improve the effects of clustering and anomaly detection.
[0077] Then use the Skip-Gram model to train the generated node sequence to learn the embedding representation of the nodes
[0078]
[0079] Where v t represents a node, ω represents the window size, P(v t |v t-w ,…,v t+w ) represents the embedding representation of v t , v t represents, P(v t+j |v t ) and v t+j are the conditional probabilities believed. The Skip-Gram model is a word embedding model, originally used for word vector learning in natural language processing. Its goal is to predict the context words given a word. In this embodiment, the node sequence is similar to the word sequence in a sentence, and the Skip-Gram model is used to learn the low-dimensional embedding representation of the nodes. P(v t+j |v t ) can be calculated by the Skip-Gram model.
[0080] For each point e p in the embedding space, find all points N(e p ) within the radius of ∈
[0081] N(ep ) = {e q ∈ E | dist(e p , e q ) ≤ δ}
[0082] where e p represents the embedding vector of point p;
[0083] ∈ represents the neighborhood radius dist(e p , e q ) represents the distance between the embedding vectors e p and e q ;
[0084] E represents all nodes.
[0085] If |N(e p )| ≥ MinPts, then e p is a core point
[0086] Starting from the core point, all points that are density-reachable are grouped into the same cluster. Point e q is density-reachable from point e p if and only if there exists a point chain
[0087] e p1 , e p2 … e pn , such that e p1 = e p , e pn = e q and e pi+1 ∈ N(e pi ).
[0088] For each edge, calculate the first score according to the clustering result
[0089]
[0090] This step can identify clusters of any shape. It does not require specifying the number of clusters in advance and is suitable for the complex and changing network environment of the rail transit system.
[0091] Furthermore, to evaluate two uncommon nodes, the representation distance between the first node and the second node can be calculated according to the first communication graph, and the second score between the first node and the second node can be obtained.
[0092] Score_2(i, j) = ‖e i - e j ‖₂
[0093] Then, the comprehensive score of the first node and the second node is calculated by weighting the first score and the second score. If the comprehensive score is greater than the preset value, there is a risk communication between the first node and the second node.
[0094] CAS(i,j)=α·Score_1(i,j)+β·Score_2(i,j)
[0095] Among them, α and β are weight parameters, which can be set according to experimental data.
[0096] Through the above steps, the comprehensive anomaly score of each node pair can be obtained. When the comprehensive anomaly score is higher than the preset threshold, or significantly higher than the average level (such as more than 50% of the average level), it is considered that there is a risk between nodes i and j, and nodes i and j can be physically isolated for further diagnosis.
[0097] Through the above method, nodes that communicate frequently can be clustered in a clustered manner, and different communication protocols and communication area switching are considered in the network diagram. When two nodes are not in the same cluster and are far apart, it means that there is abnormal traffic between the two nodes that do not communicate frequently, and there may be risks between the two nodes.
[0098] On the other hand, the present invention also provides a network risk detection system.
[0099] The system at least includes a memory and a CPU, wherein the memory stores a computer program for executing any one of the aforementioned methods, and the CPU executes the computer program.
[0100] Furthermore, the specific implementation methods of the above-mentioned network risk detection system are the same as a network risk detection method, and all further technical solutions in a network risk detection method are completely introduced into a network risk detection system.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
[0102] The present invention does not particularly specify the structure of some modules, which shall be subject to the contents recorded in the prior art. The prior art mentioned in the above background technology section and the specific embodiment section of the present invention can be used as part of the present invention to understand the meaning of some technical features or parameters. The scope of protection of the present invention shall be subject to the contents actually recorded in the claims.
Claims
1. A network risk detection method, characterized in that The method includes the following steps: Collect network data in the rail transit system; Convert the network data into a representation of nodes and edges, where the nodes are devices and the edges are communication relationships; Mark the communication type and network area of the network data. The communication type includes: data transmission, control instruction, signal transmission, and the network area includes: IT system area and OT system area; Set the weights of the edges according to the communication type and network area, and embed the nodes into a low-dimensional space to obtain a first communication graph; Perform cluster detection on the first communication graph, and determine the first score between the first node and the second node according to whether the first node and the second node are in the same cluster; Calculate the representation distance between the first node and the second node according to the first communication graph to obtain the second score between the first node and the second node; Calculate the comprehensive score of the first node and the second node by weighting the first score and the second score. If the comprehensive score is greater than the preset value, there is a risk communication between the first node and the second node.
2. The network risk detection method according to claim 1, wherein The setting of the weights of the edges according to the communication type and network area includes: Construct a network graph G=(V,E) where the node set V represents devices or system components in the rail transit system; the edge set E represents the communication or interaction relationship between nodes; E = {(u, v, weight uv ) | u, v ∈ V} where u,v represent devices or system components; weight uv Indicates the weight of an edge, reflecting the threat weight of communication type and network area conversion; The weight of the edge uv Calculated based on the following formula: weight uv = w type + w region where: w type Indicates the weight of the communication type; w region Represents the weight for network area conversion.
3. The network risk detection method according to claim 2, characterized in that When performing cluster detection on the first communication graph, first use a random walk strategy to generate a node sequence for each node.
4. A network risk detection method according to claim 3, characterized in that After using the random walk strategy to generate a node sequence for each node, use the Skip-Gram model to train the generated node sequence to obtain the embedded representation of the nodes.
5. A network risk detection method according to claim 4, wherein After obtaining the embedding representation of the nodes, for each point e in the embedding space p , find all points within the radius ∈ N(e p ) N(e p ) = {e q ∈ E | dist(e p , e q ) ≤ ò} where e p represents the embedding vector of point p; ∈ represents the neighborhood radius dist(e p , e q ) represents the embedding vector e p and e q the distance between E represents all nodes; If |N(e p )| ≥ MinPts then e p is a core point; Starting from the core point, all points that are density-reachable are grouped into the same cluster; point e q Starting from point e p is density-reachable if and only if there exists a chain of points e p1 , e p2 … e pn such that e p1 = e p , e pn = e q and e pi+1 ∈ N(e pi ).
6. The network risk detection method according to claim 5, wherein Determining the first score between the first node and the second node according to whether the first node and the second node are in the same cluster is specifically: for each edge, calculate the first score according to the clustering result 7. A network risk detection method according to claim 6, characterized in that Calculating the representation distance between the first node and the second node according to the first communication graph to obtain the second score between the first node and the second node is specifically: Score_2(i,j) = ‖e i - e j ‖₂。 8. A network risk detection method according to claim 7, characterized in that Calculating the comprehensive score of the first node and the second node by weighting the first score and the second score includes: CAS(i,j)=α·Score_1(i,j)+β·Score_2(i,j) where CAS(i,j) is the comprehensive score, and α and β are weight parameters.
9. The network risk detection method according to claim 8, characterized in that If the comprehensive score is greater than the preset value includes: When the comprehensive score is higher than the average level by 50%, it is considered that there is a risk between nodes i and j.
10. A network risk detection system, characterized in that The system includes at least a memory and a CPU. The memory stores a computer program for executing the method according to any one of claims 1-9, and the CPU executes it.
Citation Information
Patent Citations
Network attack response method and device, computer equipment and storage medium
CN116723052A
Threat detection method based on graph neural network in industrial Internet of Things
CN118353712A