Modbus TCP Replay Attack Detection and Control Method Based on Industrial Network Isolator

Through the industrial control gate, the IP address verification and response packet type judgment of the Modbus TCP protocol data packets is solved, and the security and stability of industrial intranet equipment is improved.

CN119316222BActive Publication Date: 2025-07-08CHINA GRID CLOUD ANXIN CLOUD COMPUTING (SHANDONG) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411682823.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-07-08
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

The existing Modbus TCP protocol is vulnerable to playback attacks in industrial intranets. The existing detection methods have high error detection rates and high modification costs, so they cannot effectively defend against playback attacks.

Method used

Through the industrial control gate, the IP address verification of the data packet sent by the client is used to determine the packet type, and the communication or release the packet is blocked according to the response packet type, and the effective time range is reset to detect the playback attack.

Benefits of technology

It realizes zero-trust replay attack detection, reduces the error detection rate, improves the security of Modbus TCP communication equipment, and maintains the stability of the industrial intranet.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316222B_ABST
    Figure CN119316222B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a Modbus TCP replay attack detection and control method based on an industrial network gateway, which relates to the field of network security. The method includes: when the time for the client to send a data packet is within a preset valid time range, the data packet is allowed to pass or discarded by comparing the source IP address of the data packet with the cached legitimate address; when the time for the client to send a data packet is not within the preset valid time range, the type of the data packet is determined; if the data packet is a TCP handshake packet, the data packet is allowed to pass; if the data packet is a request packet, the first response packet corresponding to the data packet is sent to the client, and the client generates a second response packet according to the first response packet; according to the type of the second response packet, the corresponding blocking packet is used to block the communication and reset the preset valid time range for the next detection of the data packet sent by the client, or the data packet is allowed to pass. In this way, replay attacks can be accurately identified, the false detection rate can be reduced, and the security of devices using Modbus TCP communication and the stability of the industrial intranet can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security, and in particular, to a method for detecting and controlling Modbus TCP replay attacks based on an industrial network gateway. Background Art

[0002] When the Modbus TCP protocol was designed, it was considered that its communication environment belonged to the industrial intranet and there would be no mixed traffic. Therefore, the protocol removed the verification information and had no authentication or authorization, making it extremely vulnerable to attack behaviors such as data replay and illegal tampering, which could lead to device anomalies. Therefore, it is necessary to detect and control these attack behaviors to avoid device anomalies.

[0003] Common detection methods for replay attack behaviors generally include function code verification, MAC / IP binding verification, rough verification based on time difference, communication encryption control, and verification methods based on sequence numbers and responses. However, these methods still have a relatively high false detection rate. For example, when the traffic of a terminal device passes through a switching device such as a router, the terminal MAC address will be replaced by the MAC address of the switching device, and at this time, the MAC / IP binding function fails; using only the average time difference of recorded requests for rough verification will have obvious anomalies during network fluctuations, and the cost of adding timestamps or random values is very high, which is not suitable for large-scale on-site environments; due to the fact that the protocol itself does not support encryption and the transformation cost is too high, communication encryption control is not applicable in on-site environments; when using compliant data packets for replay, when the server is stable enough, the replay traffic can basically proceed normally, and at this time, the verification method based on sequence numbers and responses fails. Summary of the Invention

[0004] The present disclosure provides a method, device, equipment, and storage medium for detecting and controlling Modbus TCP replay attacks based on an industrial network gateway.

[0005] According to a first aspect of the present disclosure, there is provided a method for detecting and controlling Modbus TCP replay attacks based on an industrial network gateway. The method includes:

[0006] When the time when the client sends a data packet is within a preset valid time range, the data packet is allowed to pass or discarded by comparing the source IP address of the data packet with the cached legal address.

[0007] When the time when the client sends a data packet is not within the preset valid time range, the type of the data packet is determined; if the data packet is a TCP handshake packet, the data packet is allowed to pass; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet based on the first response packet.

[0008] According to the type of the second response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range for detecting the data packets sent by the client next time, or release the data packets.

[0009] In some realizable ways of the first aspect, by comparing the source IP address of the data packet with the cached legitimate address, release or discard the data packet, including:

[0010] If the source IP address of the data packet is a legitimate address, release the data packet.

[0011] If the source IP address of the data packet is an illegal address, discard the data packet.

[0012] In some realizable ways of the first aspect, if the data packet is a request packet, before / after / at the same time of sending the first response packet corresponding to the constructed data packet to the client, including:

[0013] Extract the transaction ID in the data packet.

[0014] Set the transaction ID of the first response packet according to the transaction ID in the data packet.

[0015] In some realizable ways of the first aspect, according to the type of the second response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range for detecting the data packets sent by the client next time, or release the data packet, including:

[0016] If the second response packet is a request packet, compare the transaction ID of the second response packet with the transaction ID of the first response packet; if the transaction ID of the second response packet is equal to the transaction ID of the first response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range.

[0017] If the second response packet is an error prompt packet or a connection termination packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range.

[0018] Otherwise, release the data packet.

[0019] In some realizable ways of the first aspect, using the blocking packet corresponding to the data packet to block the communication, including:

[0020] Record the source IP address of the data packet as an illegal address, and send the blocking packet corresponding to the data packet to the client to block the communication.

[0021] In some realizable ways of the first aspect, the method further includes:

[0022] Record the source IP address of the released data packet as a legitimate address.

[0023] According to a second aspect of the present disclosure, there is provided a Modbus TCP replay attack detection and control module based on an industrial network gateway. The module includes:

[0024] A drainage module, a replay attack detection module, and a packet encapsulation module that are connected in sequence; wherein, the replay attack detection module is further connected to a control module.

[0025] The drainage module is configured to receive data packets sent by a client and send the data packets to the replay detection module.

[0026] The replay attack detection module is configured to receive data packets. When the time when the client sends a data packet is within a preset valid time range, the data packet is allowed to pass or discarded according to the comparison result between the source IP address of the data packet and the cached legitimate address.

[0027] It is further configured to, when the time when the client sends a data packet is not within the preset valid time range, determine the type of the data packet; if the data packet is a TCP handshake packet, the data packet is allowed to pass; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet according to the first response packet.

[0028] It is further configured to, according to the type of the second response packet, block the communication using the blocking packet corresponding to the data packet and reset the preset valid time range for the next detection of data packets sent by the client, or allow the data packet to pass.

[0029] The control module is configured to compare the source IP address of the data packet with the cached legitimate address.

[0030] The packet encapsulation module is configured to construct the first response packet corresponding to the data packet; it is also configured to construct a blocking packet.

[0031] In some implementable ways of the second aspect, the control module is further configured to cache the source IP address of the data packet.

[0032] The packet encapsulation module is further configured to extract the transaction ID in the data packet and set the transaction ID of the first response packet according to the transaction ID in the data packet.

[0033] According to a third aspect of the present disclosure, there is provided an electronic device. The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method as described above.

[0034] According to a fourth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to cause a computer to execute the method as described above.

[0035] In the present disclosure, when the time for the client to send a data packet is within the preset valid time range, the data packet is allowed or discarded by comparing the source IP address of the data packet with the cached legal address; when the time for the client to send a data packet is not within the preset valid time range, the type of the data packet is determined; if the data packet is a TCP handshake packet, the data packet is allowed; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet based on the first response packet; according to the type of the second response packet, the communication is blocked using the blocking packet corresponding to the data packet and the preset valid time range is reset for the next detection of the data packet sent by the client, or the data packet is allowed. In this way, zero-trust replay attack detection is achieved, replay attacks that conform to the replay rules can be accurately identified, the false detection rate is reduced, the security of devices using Modbus TCP communication in the industrial control environment is improved, and the stability of the industrial intranet is maintained.

[0036] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. Brief Description of the Drawings

[0037] Combined with the drawings and referring to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more obvious. The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. In the drawings, the same or similar reference numerals represent the same or similar elements, where:

[0038] Figure 1 The flowchart of a Modbus TCP replay attack detection and control method based on an industrial control network gateway provided by an embodiment of the present disclosure is shown.

[0039] Figure 2 The structural diagram of a Modbus TCP replay attack detection and control device based on an industrial control network gateway provided by an embodiment of the present disclosure is shown.

[0040] Figure 3 The structural diagram of an exemplary electronic device capable of implementing the embodiments of the present disclosure is shown. Detailed Description of the Embodiments

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.

[0042] In addition, the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this text generally indicates that the associated objects before and after are in an "or" relationship.

[0043] In response to the problems in the background art, the embodiments of the present disclosure provide a Modbus TCP replay attack detection and control method based on an industrial control network gateway. When the time when the client sends a data packet is within a preset valid time range, by comparing the source IP address of the data packet with the cached legitimate address, the data packet is allowed to pass or discarded; when the time when the client sends a data packet is not within the preset valid time range, the type of the data packet is judged; if the data packet is a TCP handshake packet, the data packet is allowed to pass; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet according to the first response packet; according to the type of the second response packet, the communication is blocked using the blocking packet corresponding to the data packet and the preset valid time range is reset for the next detection of the data packet sent by the client, or the data packet is allowed to pass. In this way, zero-trust replay attack detection is achieved, replay attacks that conform to the replay rules can be accurately identified, the false detection rate is reduced, the security of devices using Modbus TCP communication in the industrial control environment is improved, and the stability of the industrial internal network is maintained.

[0044] The following combines the accompanying drawings and details the Modbus TCP replay attack detection and control method provided by the embodiments of the present disclosure through specific embodiments.

[0045] Figure 1 The flowchart of a Modbus TCP replay attack detection and control method provided by the embodiments of the present disclosure is shown. Method 100 includes the following steps:

[0046] S110, when the time when the client sends a data packet is within a preset valid time range, by comparing the source IP address of the data packet with the cached legitimate address, the data packet is allowed to pass or discarded.

[0047] In some embodiments, by comparing the source IP address of the data packet with the cached legitimate address and allowing the data packet to pass or discarding it, includes:

[0048] If the source IP address of the data packet is a legitimate address, the data packet is allowed to pass.

[0049] If the source IP address of the data packet is an illegal address, the data packet is discarded.

[0050] S120. When the time when the client sends a data packet is not within the preset valid time range, determine the type of the data packet. If the data packet is a TCP handshake packet, release the data packet. If the data packet is a request packet, send the first response packet corresponding to the constructed data packet to the client so that the client can generate a second response packet based on the first response packet.

[0051] In some embodiments, before / after / at the same time as sending the first response packet corresponding to the constructed data packet to the client if the data packet is a request packet, it includes:

[0052] Extract the transaction ID in the data packet.

[0053] Set the transaction ID of the first response packet according to the transaction ID in the data packet.

[0054] In some embodiments, setting the transaction ID of the first response packet according to the transaction ID in the data packet includes:

[0055] The transaction ID in the data packet is denoted as X, and set the transaction ID of the first response packet to X + 1.

[0056] S130. According to the type of the second response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range for detecting the data packet sent by the client next time, or release the data packet.

[0057] In some embodiments, according to the type of the second response packet, using the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range for detecting the data packet sent by the client next time, or release the data packet, includes:

[0058] If the second response packet is a request packet, compare the transaction ID of the second response packet with the transaction ID of the first response packet. If the transaction ID of the second response packet is equal to the transaction ID of the first response packet, it means that the data packet is replay attack data, so use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range.

[0059] If the second response packet is an error prompt packet or a connection termination packet, it is considered that the data packet is replay attack data that conforms to the replay rule, so use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range.

[0060] Otherwise, release the data packet.

[0061] In some embodiments, using the blocking packet corresponding to the data packet to block the communication includes:

[0062] Record the source IP address of the data packet as an illegal address, and send the blocking packet corresponding to the data packet to the client to block the communication.

[0063] In some embodiments, method 100 further includes:

[0064] Recording the source IP address of the released data packet as a legitimate address.

[0065] According to an embodiment of the present disclosure, when the time when the client sends a data packet is within a preset valid time range, by comparing the source IP address of the data packet with the cached legitimate address, the data packet is released or discarded; when the time when the client sends a data packet is not within the preset valid time range, the data packet type is determined; if the data packet is a TCP handshake packet, the data packet is released; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet according to the first response packet; according to the type of the second response packet, the communication is blocked using the blocking packet corresponding to the data packet and the preset valid time range is reset for the next detection of the data packet sent by the client, or the data packet is released. In this way, zero-trust replay attack detection is achieved, replay attacks that conform to the replay rules can be accurately identified, the false detection rate is reduced, the security of devices using Modbus TCP communication in the industrial control environment is improved, and the stability of the industrial intranet is maintained.

[0066] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present disclosure is not limited by the described action sequence, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present disclosure.

[0067] The above is the introduction of the method embodiments. The following further illustrates the solution of the present disclosure through device embodiments.

[0068] Figure 2 The structure diagram of a Modbus TCP replay attack detection and control device provided by an embodiment of the present disclosure is shown. Module 200 includes:

[0069] A drainage module 210, a replay attack detection module 220, and a packet sealing module 240 that are connected in sequence; wherein, the replay attack detection module is further connected to a control module 230.

[0070] The drainage module 210 is configured to receive the data packet sent by the client and send the data packet to the replay detection module 220.

[0071] In some embodiments, the drainage module 210 is specifically configured to:

[0072] Send the data packet sent by the client to the replay detection module 220 through the Modbus TCP communication port.

[0073] The replay attack detection module 220 is used to receive data packets. When the time when the client sends a data packet is within the preset valid time range, according to the comparison result between the source IP address of the data packet and the cached legal address, the data packet is allowed to pass or discarded.

[0074] It is also used when the time when the client sends a data packet is not within the preset valid time range to determine the data packet type; if the data packet is a TCP handshake packet, the data packet is allowed to pass; if the data packet is a request packet, the first response packet corresponding to the constructed data packet is sent to the client so that the client can generate a second response packet according to the first response packet.

[0075] It is also used to block communication using the blocking packet corresponding to the data packet according to the type of the second response packet and reset the preset valid time range for the next detection of the data packet sent by the client, or allow the data packet to pass.

[0076] In some embodiments, the replay attack detection module 220 is specifically used for:

[0077] Blocking communication using the blocking packet corresponding to the data packet according to the type of the second response packet and resetting the preset valid time range for the next detection of the data packet sent by the client, or allowing the data packet to pass, includes:

[0078] If the second response packet is a request packet, compare the transaction ID of the second response packet with the transaction ID of the first response packet; if the transaction ID of the second response packet is equal to the transaction ID of the first response packet, use the blocking packet corresponding to the data packet to block communication and reset the preset valid time range.

[0079] If the second response packet is an error prompt packet or a connection termination packet, use the blocking packet corresponding to the data packet to block communication and reset the preset valid time range.

[0080] Otherwise, allow the data packet to pass.

[0081] Further, blocking communication using the blocking packet corresponding to the data packet includes:

[0082] Record the source IP address of the data packet as an illegal address, and send the blocking packet corresponding to the data packet to the client to block communication; specifically, record the source IP address of the data packet as an illegal address, and at the same time cache the recorded illegal address into the packet module, and send the blocking packet corresponding to the data packet to the client to block communication.

[0083] The control module 230 is used to compare the source IP address of the data packet with the cached legal address.

[0084] In some embodiments, the control module 230 is further configured to cache the source IP address of the data packet.

[0085] Specifically, the control module 230 is further configured to cache the source IP address of the data packet recorded as a legal address and / or an illegal address.

[0086] The packet module 240 is configured to construct a first response packet corresponding to the data packet; and is further configured to construct a blocking packet.

[0087] In some embodiments, the packet module 240 is further configured to:

[0088] Extract the transaction ID in the data packet, and set the transaction ID of the first response packet according to the transaction ID in the data packet.

[0089] Specifically, if the data packet is a request packet, before / after / at the same time of sending the first response packet corresponding to the constructed data packet to the client, it includes:

[0090] Extract the transaction ID in the data packet.

[0091] Set the transaction ID of the first response packet according to the transaction ID in the data packet.

[0092] It can be understood that Figure 2 Each module / unit in the module 200 shown has the function of implementing each step in the method 100 provided by the embodiments of the present disclosure, and can achieve its corresponding technical effects. For the sake of brevity, they will not be described in detail here.

[0093] Figure 3 The structure diagram of an exemplary electronic device capable of implementing the embodiments of the present disclosure is shown. The electronic device 300 is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 300 can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0094] As Figure 3As shown, the electronic device 300 includes a computing unit 301, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 302 or a computer program loaded from a storage unit 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the electronic device 300 can also be stored. The computing unit 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An I / O interface 305 is also connected to the bus 304.

[0095] Multiple components in the electronic device 300 are connected to the I / O interface 305, including: an input unit 306, such as a keyboard, a mouse, etc.; an output unit 307, such as various types of displays, speakers, etc.; a storage unit 308, such as a magnetic disk, an optical disc, etc.; and a communication unit 309, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 309 allows the electronic device 300 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0096] The computing unit 301 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 301 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 301 executes the various methods and processes described above, such as method 100. For example, in some embodiments, method 100 can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 308. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 300 via the ROM 302 and / or the communication unit 309. When the computer program is loaded into the RAM 303 and executed by the computing unit 301, one or more steps of method 100 described above can be executed. Alternatively, in other embodiments, the computing unit 301 can be configured to execute method 100 in any other appropriate manner (e.g., by means of firmware).

[0097] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.

[0098] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0099] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0100] It should be noted that the present disclosure also provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute method 100 and achieve the corresponding technical effects achieved by the method of the embodiments of the present disclosure. For the sake of brevity of description, it will not be repeated here.

[0101] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0102] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with the systems and techniques described herein).

[0103] Or in a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0104] A computer system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, or a server of a distributed system, or a server incorporating a blockchain.

[0105] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0106] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A Modbus TCP replay attack detection and control method based on an industrial network gateway, characterized in that Including: When the time when the client sends a data packet is within the preset valid time range, by comparing the source IP address of the data packet with the cached legitimate address, the data packet is either allowed to pass or discarded; When the time when the client sends a data packet is not within the preset valid time range, determine the data packet type; If the data packet is a TCP handshake packet, allow the data packet to pass; If the data packet is a request packet, send the first response packet corresponding to the constructed data packet to the client so that the client can generate a second response packet based on the first response packet; wherein, before / after / at the same time as sending the first response packet corresponding to the constructed data packet to the client if the data packet is a request packet, it includes: extracting the transaction ID in the data packet; setting the transaction ID of the first response packet according to the transaction ID in the data packet; If the second response packet is a request packet, compare the transaction ID of the second response packet with the transaction ID of the first response packet; if the transaction ID of the second response packet is equal to the transaction ID of the first response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range; If the second response packet is an error prompt packet or a connection termination packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range; Otherwise, allow the data packet to pass.

2. The method according to claim 1, wherein The allowing or discarding of the data packet by comparing the source IP address of the data packet with the cached legitimate address includes: If the source IP address of the data packet is a legitimate address, allow the data packet to pass; If the source IP address of the data packet is an illegal address, discard the data packet.

3. The method according to claim 1, wherein The using of the blocking packet corresponding to the data packet to block the communication includes: Recording the source IP address of the data packet as an illegal address and sending the blocking packet corresponding to the data packet to the client to block the communication.

4. The method according to claim 1, wherein The method further includes: Recording the source IP address of the allowed data packet as a legitimate address.

5. A Modbus TCP replay attack detection and control device based on an industrial network gateway, characterized in that, Including: A diversion module, a replay attack detection module, and a packet module connected in sequence; wherein, the replay attack detection module is also connected to a control module; The diversion module is used to receive the data packet sent by the client and send the data packet to the replay detection module; The replay attack detection module is used to receive the data packet. When the time when the client sends the data packet is within the preset valid time range, according to the comparison result between the source IP address of the data packet and the cached legitimate address, the data packet is either allowed to pass or discarded; It is also used when the time when the client sends the data packet is not within the preset valid time range to determine the data packet type; if the data packet is a TCP handshake packet, allow the data packet to pass; if the data packet is a request packet, send the first response packet corresponding to the constructed data packet to the client so that the client can generate a second response packet based on the first response packet; It is also used if the second response packet is a request packet to compare the transaction ID of the second response packet with the transaction ID of the first response packet; if the transaction ID of the second response packet is equal to the transaction ID of the first response packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range; if the second response packet is an error prompt packet or a connection termination packet, use the blocking packet corresponding to the data packet to block the communication and reset the preset valid time range; otherwise, allow the data packet to pass; A control module, configured to compare the source IP address of a data packet with the cached legitimate addresses; A packet encapsulation module, configured to construct a first response packet corresponding to the data packet; further configured to construct a blocking packet; further configured to extract the transaction ID in the data packet and set the transaction ID of the first response packet according to the transaction ID in the data packet.

6. The apparatus according to claim 5, wherein the control module is further configured to cache the source IP address of the data packet.

7. An electronic device, characterized in that, Comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Message replay attack detection method, message replay attack detection device and electronic equipment

    CN109768991A

  • Security reinforcement method for Modbus TCP protocol

    CN113824705A