Industrial data forensic analysis method, system, equipment, medium and product
Through real-time data acquisition of industrial production equipment and mining of time-series data association rules, association rules are generated to determine the network attack process, which solves the problem of fuzzy traceability of attack process in the existing technology, and achieves more efficient detection and monitoring capabilities.
Patent Information
- Application Number
- CN202411554183.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-01
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-11-01
AI Technical Summary
The existing industrial data forensics methods are difficult to clarify the attack process, which leads to vague traceability.
By collecting and storing the production parameters of the attacked industrial production equipment in real time, mining the association rules of time sequence data, and generating association rules to determine the process of network attacks. Specific steps include frequent subsequence mining, association rule generation, mutation operation, evaluation and verification.
It realizes clear traceability of the attack process, improves the system's detection speed and monitoring capabilities, and solves the problem of vague traceability of the attack process.
Smart Images

Figure CN119439913B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the industrial field, and in particular to an industrial data forensic analysis method, system, equipment, medium and product. Background Art
[0002] In recent years, the degree of industrialization and informatization has gradually deepened, and the importance of industrial data has become increasingly obvious. Industrial data plays a vital role in supporting the coordinated development of the entire industry and multiple fields of the industrial economy. Considering the importance of industrial data security, the ability of industrial systems to protect against external attacks is particularly important. Therefore, it is necessary to quickly and accurately analyze network attack activities to avoid large-scale key data leakage and destruction incidents. For the attack activities that may be faced in the industrial field, there are problems such as wide coverage and high harm. It is necessary to clarify the process of the attack event and improve the system's targeted protection capabilities. Industrial data forensic analysis can integrate data acquisition technology and multi-source data analysis algorithms to achieve data security analysis and forensics in key industrial industries and the retrospective restoration of attack events, but the existing industrial data forensics methods make the tracing process of the attack process vague and difficult. Summary of the invention
[0003] The purpose of this application is to provide an industrial data forensics analysis method, system, equipment, medium and product, which can solve the problem of ambiguity and difficulty in tracing the attack process.
[0004] To achieve the above objectives, this application provides the following solutions:
[0005] In a first aspect, the present application provides an industrial data forensic analysis method, comprising:
[0006] During the time period when the attacked industrial production equipment is attacked by the network, the values of various industrial equipment production parameters of the attacked industrial production equipment are collected in real time to obtain an industrial equipment production data set;
[0007] The values of the production parameters of each industrial equipment in the industrial equipment production data set are stored according to the collection time to obtain time series data;
[0008] Perform association rule mining on time series data, determine the process of network attack based on the association rules obtained, and complete industrial data forensic analysis;
[0009] The association rules of the time series data are mined, and the process of network attack is determined according to the association rules obtained by mining, so as to complete the industrial data forensic analysis, specifically including:
[0010] Perform frequent subsequence mining on time series data;
[0011] Generate association rules based on the mined frequent subsequences; the antecedents and consequents of the association rules are both industrial equipment production parameters;
[0012] For any association rule, a mutation operation is performed on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set; the normal industrial equipment production data set includes the values of the production parameters of each industrial equipment when the attacked industrial production equipment is not subjected to a network attack;
[0013] On the basis of the mutation operation, the attacked industrial production equipment is operated and the values of the production parameters of each industrial equipment are collected in real time to obtain a set of mutant industrial equipment production data;
[0014] According to the mutant industrial equipment production data set and the normal industrial equipment production data set, determining whether both the antecedent and the consequent in the association rule contain values of the industrial equipment production parameters that conform to the association rule;
[0015] If yes, then the confidence and support corresponding to the association rule are calculated according to the variant industrial equipment production data set, and the association rule is evaluated according to the confidence and support corresponding to the association rule to obtain an evaluation result;
[0016] If not, return to the step of mining frequent subsequences on time series data;
[0017] If the evaluation result meets the preset standard, the process of the network attack is determined according to the association rule to complete the industrial data forensic analysis;
[0018] If the evaluation result does not meet the preset standard, the process returns to the step of performing frequent subsequence mining on the time series data.
[0019] Optionally, the industrial equipment production parameters include: sensor data, process data and equipment status data.
[0020] Optionally, the value of each industrial equipment production parameter in the industrial equipment production data set is stored according to the collection time to obtain time series data, specifically including:
[0021] Decrypting the encrypted value of each industrial equipment production parameter in the industrial equipment production data set to obtain the decrypted value of each industrial equipment production parameter;
[0022] Performing standardization operations on the values of each non-encrypted industrial equipment production parameter and the decrypted values of each industrial equipment production parameter in the industrial equipment production data set to obtain a pre-processed industrial equipment production data set;
[0023] The corresponding collection time is marked for each data in the pre-processed industrial equipment production data set to obtain time series data.
[0024] Optionally, evaluating the association rule according to the confidence and support corresponding to the association rule to obtain an evaluation result specifically includes:
[0025] If the confidence corresponding to the association rule is greater than a preset confidence threshold, and the support corresponding to the association rule is greater than a preset support threshold, then the evaluation result of the association rule meets the preset standard;
[0026] If the confidence corresponding to the association rule is not greater than a preset confidence threshold, or the support corresponding to the association rule is not greater than a preset support threshold, then the evaluation result of the association rule does not meet the preset standard.
[0027] Optionally, frequent subsequence mining is performed on the time series data, specifically:
[0028] The PrefixSpan algorithm is used to mine frequent subsequences in time series data.
[0029] Optionally, calculating the confidence and support corresponding to the association rule according to the variant industrial equipment production data set specifically includes:
[0030] For association rule A→B, according to the formula Calculate the support of association rule A→B Support(A→B);
[0031] Among them, Count(A→B) represents the total number of records in the variant industrial equipment production data set for which the association rule A→B holds, and N is the total number of records in the variant industrial equipment production data set;
[0032] According to the formula Calculate the confidence of the association rule A→B Confidence(A→B);
[0033] Among them, Support(A∪B) is the support for the simultaneous occurrence of antecedent A and consequent B, and Support(A) is the support for the occurrence of antecedent A.
[0034] In a second aspect, the present application provides an industrial data forensics analysis system, comprising:
[0035] The production data collection and sorting subsystem is used to collect the values of various industrial equipment production parameters of the attacked industrial production equipment in real time during the time period when the attacked industrial production equipment is attacked by the network to obtain an industrial equipment production data set; the values of various industrial equipment production parameters in the industrial equipment production data set are stored according to the collection time to obtain time series data;
[0036] The industrial data forensic analysis subsystem is used to mine association rules for time series data, determine the process of network attacks based on the association rules obtained, and complete industrial data forensic analysis;
[0037] The industrial data forensic analysis subsystem includes:
[0038] Frequent pattern mining submodule, used to mine frequent subsequences of time series data;
[0039] The association rule generation submodule is used to generate association rules based on the mined frequent subsequences; the antecedents and consequents of the association rules are both industrial equipment production parameters;
[0040] The node chain verification submodule is used to perform a mutation operation on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set for any association rule; the normal industrial equipment production data set includes the values of the production parameters of each industrial equipment when the attacked industrial production equipment is not subjected to a network attack; on the basis of the mutation operation, the attacked industrial production equipment is operated and the values of the production parameters of each industrial equipment are collected in real time to obtain a mutated industrial equipment production data set; based on the mutated industrial equipment production data set and the normal industrial equipment production data set, it is determined whether the antecedent and consequent in the association rule both have values of the industrial equipment production parameters that meet the association rule;
[0041] The association rule evaluation submodule is used to calculate the confidence and support corresponding to the association rule based on the variant industrial equipment production data set, and evaluate the association rule according to the confidence and support corresponding to the association rule to obtain the evaluation result; if not, return to the step of frequent subsequence mining of time series data; if the evaluation result meets the preset standard, determine the process of network attack according to the association rule, and complete the industrial data forensic analysis; if the evaluation result does not meet the preset standard, return to the step of frequent subsequence mining of time series data.
[0042] In a third aspect, the present application provides a computer device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the industrial data forensic analysis methods described above.
[0043] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the industrial data forensic analysis methods described above.
[0044] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements any of the industrial data forensic analysis methods described above.
[0045] According to the specific embodiments provided in this application, this application has the following technical effects:
[0046] The present application provides an industrial data forensic analysis method, system, device, medium and product, which mines frequent subsequences of time series data; generates association rules according to the mined frequent subsequences; performs mutation operation on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set; runs the attacked industrial production equipment on the basis of the mutation operation and collects the value of each industrial equipment production parameter in real time to obtain a mutant industrial equipment production data set; judges whether the antecedent and consequent in the association rule both contain the value of the industrial equipment production parameter that meets the association rule according to the mutant industrial equipment production data set and the normal industrial equipment production data set; if so, The confidence and support corresponding to the association rules are calculated, and the association rules are evaluated according to the confidence and support corresponding to the association rules to obtain the evaluation results; if not, the step of frequent subsequence mining on time series data is returned; if the evaluation result meets the preset standard, the process of network attack is determined according to the association rules to complete the industrial data forensic analysis; if the evaluation result does not meet the preset standard, the step of frequent subsequence mining on time series data is returned. By mining association rules on time series, it is possible to analyze and obtain evidence from the data and probability levels, obtain the correct attack path, improve the detection speed and monitoring capabilities of the system, and solve the problem of ambiguity and difficulty in tracing the attack process. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0048] Figure 1 A schematic diagram of a process flow of an industrial data forensic analysis method provided in one embodiment of the present application;
[0049] Figure 2 It is a flowchart of the steps of the PrefixSpan algorithm;
[0050] Figure 3 An architectural diagram of an industrial data forensics analysis system provided in one embodiment of the present application;
[0051] Figure 4A schematic diagram of the structure of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0052] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0053] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0054] In an exemplary embodiment, Figure 1 As shown, an industrial data forensic analysis method is provided, comprising the following steps:
[0055] Step 201 , during the time period when the attacked industrial production equipment is subjected to a network attack, the values of various industrial equipment production parameters of the attacked industrial production equipment are collected in real time to obtain an industrial equipment production data set.
[0056] Step 202: The value of each industrial equipment production parameter in the industrial equipment production data set is stored according to the collection time to obtain time series data.
[0057] Step 203, perform association rule mining on the time series data, determine the process of the network attack (referring to the situation where anomalies occur after the network attack occurs, that is, after a target is attacked, which targets will subsequently have anomalies) based on the association rules obtained by mining, and complete the industrial data forensic analysis. Specifically, the main steps of the process are as follows:
[0058] Step a: Perform frequent subsequence mining on time series data.
[0059] Step b: Generate association rules based on the mined frequent subsequences; the antecedents and consequents of the association rules are both industrial equipment production parameters.
[0060] Step c: for any association rule, perform a mutation operation on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set; the normal industrial equipment production data set includes the industrial equipment production data when the attacked industrial production equipment is not subjected to a network attack.
[0061] Step d: running the attacked industrial production equipment on the basis of the mutation operation and collecting industrial equipment production data in real time to obtain a set of mutated industrial equipment production data.
[0062] Step e: judging whether both the antecedent and the consequent in the association rule contain values of the industrial equipment production parameters that meet the association rule according to the mutant industrial equipment production data set and the normal industrial equipment production data set.
[0063] Step f: If yes, then the confidence and support corresponding to the association rule are calculated based on the variant industrial equipment production data set, and the association rule is evaluated based on the confidence and support corresponding to the association rule to obtain an evaluation result. Specifically, if the confidence corresponding to the association rule is greater than a preset confidence threshold, and the support corresponding to the association rule is greater than a preset support threshold, then the evaluation result of the association rule is in compliance with the preset standard; if the confidence corresponding to the association rule is not greater than the preset confidence threshold, or the support corresponding to the association rule is not greater than the preset support threshold, then the evaluation result of the association rule is not in compliance with the preset standard.
[0064] Step g: If not, return to the step of mining frequent subsequences on time series data.
[0065] Step h: If the evaluation result meets the preset standard, the process of network attack is determined according to the association rule to complete the industrial data forensic analysis.
[0066] Step i: If the evaluation result does not meet the preset standard, return to the step of performing frequent subsequence mining on the time series data.
[0067] The implementation of the above steps 201 to 203 can solve the problem of difficulty in tracing the attack process.
[0068] In an exemplary embodiment, during the time period when the attacked industrial production equipment is attacked by the network, the values of the production parameters of the attacked industrial production equipment are collected in real time to obtain an industrial equipment production data set, specifically:
[0069] Step 1.1: Industrial data collection.
[0070] In the industrial production environment, information collection methods are used to collect relevant information data sources such as multi-source heterogeneous different equipment and systems, and the values of the collected industrial equipment production parameters are parsed through specific interfaces and protocols. Industrial equipment production parameters mainly include sensor data, process data and equipment status data, which need to be collected by specific technical means. Sensor data includes data such as temperature, humidity, pressure, current and voltage, and needs to be collected through corresponding types of sensors, such as using resistance temperature detectors (RTD) to collect temperature data and using pressure sensors to collect pressure. Process data includes production rate, quality parameters and process parameters, which are collected and recorded by process control systems (such as DCS or PLC). Equipment status data includes operating load, computer efficiency, data transmission speed and CPU occupancy, which are measured by network monitoring tools or data acquisition cards (DAQ). The system and the acquisition channel maintain the update frequency, and the values of industrial equipment production parameters are updated to the system in real time to ensure the timeliness and accuracy of the data. Collect relevant data from the front end of industrial equipment, which includes sensors, controllers and data acquisition devices.
[0071] In the process of industrial equipment production, due to the diversity of equipment structure, the values of various industrial equipment production parameters are highly complex and have a large amount of information. They need to be processed in specific links before they can be efficiently analyzed. Therefore, it is necessary to pre-process the values of the collected industrial equipment production parameters. In an exemplary embodiment, the values of the industrial equipment production parameters in the industrial equipment production data set are stored according to the collection time to obtain time series data, which specifically includes:
[0072] The encrypted values of the industrial equipment production parameters in the industrial equipment production data set are decrypted to obtain the decrypted values of the industrial equipment production parameters.
[0073] Standardization operations are performed on the values of each non-encrypted industrial equipment production parameter and the decrypted values of each industrial equipment production parameter in the industrial equipment production data set to obtain a preprocessed industrial equipment production data set.
[0074] The corresponding collection time is marked for each data in the pre-processed industrial equipment production data set to obtain time series data.
[0075] In an exemplary embodiment, the value of each encrypted industrial equipment production parameter in the industrial equipment production data set is decrypted to obtain the value of each decrypted industrial equipment production parameter; the value of each non-encrypted industrial equipment production parameter in the industrial equipment production data set and the value of each decrypted industrial equipment production parameter are respectively standardized to obtain the preprocessed industrial equipment production data set, specifically:
[0076] Step 1.2: Data preprocessing.
[0077] In view of the multi-source heterogeneous data collected, the encrypted files are decrypted and the asymmetric encryption and decryption algorithm RSA is used to obtain the key to read the data. Asymmetric encryption and decryption first uses the recipient's public key to encrypt the data through the RSA algorithm, and then transmits the encrypted data to the recipient. The recipient uses his private key to decrypt the data and restore the original content. The RSA algorithm provides secure data transmission and identity authentication because the separation of public and private keys ensures the security of the data. Even if the public key is made public, only the private key holder can decrypt the data.
[0078] After obtaining the decrypted data content, the decrypted data content and the non-encrypted industrial equipment production data are managed (standardized) in a coordinated manner. The Open Platform Communication Unified Architecture (OPC UA) is adopted to support cross-platform data standard unification. OPC UA standardizes the data structure and semantics of different devices and systems by defining a unified data model and information model, ensuring cross-platform data consistency and interoperability. It provides a set of standardized services and interfaces for data access and processing, and supports flexible custom data type extensions. Through these mechanisms, OPC UA achieves data standardization and promotes seamless integration and efficient communication between devices and systems.
[0079] In an exemplary embodiment, each data in the preprocessed industrial equipment production data set is labeled with the corresponding collection time to obtain time series data, specifically:
[0080] Step 1.3: Timing arrangement.
[0081] The data collected during the industrial production process may be relatively chaotic, and further time series sorting is required (marking the corresponding collection time for each data in the pre-processed industrial equipment production data set) to obtain time series data. The sorting process completes the combination of industrial equipment production parameters and time dimension information, indicating the specific time point of data collection, and ensuring the traceability and authenticity of the information. In the process of sorting the collected data, combined with the characteristics of time series data, a time series database (TSDB) is specifically constructed, and the time series data is stored in the time series database.
[0082] Among them, the steps of building a time series database are well-known steps, mainly including: first, optimize data storage, the standards include partitioning (partitioning by time range) and compression (using algorithms to reduce storage requirements). TSDB will index the timestamp field to speed up time range queries, and may create secondary indexes to improve the efficiency of queries by other fields. Using data aggregation techniques such as downsampling and aggregation can reduce storage requirements and increase query speed. In addition, adopt data cleaning strategies, including data elimination (deleting or archiving expired data) and data merging (defragmentation). Finally, time series modeling is used to ensure time consistency (such as time synchronization), which helps to avoid problems caused by timestamp deviation. TSDB can efficiently process, store and query time series data, design and optimize from the time dimension, organize and manage messy data in time order, achieve high concurrency, high throughput data writing and high-speed data aggregation, and obtain easy-to-process time series data.
[0083] Applying the PrefixSpan algorithm to mine time series data can effectively discover frequent patterns and potential laws in the operation of equipment. The PrefixSpan algorithm mines frequent subsequences by recursively expanding prefixes in the data sequence, thereby revealing the law of changes in the operation status of the equipment over time, and providing valuable basis for equipment maintenance and optimization. Based on the mined frequent subsequences, association rules can be generated to explore the intrinsic relationship between different equipment states, support more accurate fault prediction and the formulation of preventive measures, and realize the main process of forensic analysis. In an exemplary embodiment, frequent subsequence mining is performed on time series data; each association rule is generated according to each mined frequent subsequence, specifically:
[0084] Step 2.1: Use the PrefixSpan algorithm to mine frequent patterns. The itemsets are sensor data, process data, and equipment status data with time. Use the PrefixSpan algorithm to process the sorted time series data. According to the algorithm logic, the frequently appearing sequence strings in the equipment time series data are mined to find the parts that are significantly different from the normal operating state. These parts may contain security threats or abnormal situations. Specific data fluctuation forms can imply the behavior logic of the attacker. The specific process is as follows: Figure 2 As shown, including:
[0085] First, expand the prefix to be matched. Select an initial empty prefix, scan all sequences, and calculate the frequent subsequences based on the prefix, then recursively expand the prefix to be matched to find longer frequent subsequences.
[0086] Then record the number of occurrences of the prefix and perform frequent pattern mining. Calculate the frequency of all possible subsequences and compare them with the set minimum support threshold to determine which subsequences are frequent. For each frequent subsequence, record its number of occurrences in all sequences. The frequency calculation formula is:
[0087]
[0088] Among them, Support(S) is the support of subsequence S, Count(S) is the number of times subsequence S appears in all sequences, and N is the total number of sequences.
[0089] Then perform recursive processing. For each frequent subsequence found, recursively expand the prefix to find a longer frequent subsequence. At this time, it is necessary to delete prefixes that appear less than 2 times. If all prefixes are deleted, return the prefix processed in the last step; if there are still prefixes that have not been deleted, solve the projection database and record them in the data set. This process will continue until no more frequent subsequences can be found. During the recursive process, the algorithm uses a "projection database" to retain only those sequences that contain the current prefix, thereby reducing the complexity of the calculation. For each new prefix, the algorithm divides the projection database into multiple subsets and recursively performs prefix expansion in each subset.
[0090] Step 2.2: Generate association rules. Based on the frequent subsequences obtained by mining, analyze the antecedents and contingents of a specific sequence, and try to generate association rules to describe how events occur in chronological order. Frequent subsequences are usually the impact of attacks on different modules. Analyze the correlation between them, find the attack type, attack purpose and attack method, and discover the order and logic of abnormal occurrence of industrial production equipment after the attack, reveal the abnormal behavior path, and issue an early warning for the next module that may have abnormalities. Specifically:
[0091] Generate association rules based on the mined frequent subsequences. Each rule consists of an antecedent and a consequent, describing the probability of the consequent occurring when the antecedent occurs. The confidence calculation formula for association rule A→B is:
[0092]
[0093] Among them, Support(A∪B) is the support for the simultaneous occurrence of antecedent A and consequent B, and Support(A) is the support for the occurrence of antecedent A.
[0094] After being processed by the PrefixSpan algorithm, we can mine the frequently occurring abnormal sequences in the time series data, and determine that the specific module corresponding to the system has an abnormality based on the pattern of the abnormal sequence. At the same time, the algorithm determines which specific modules have specific association rules based on probability, and finds out the law of abnormal data appearance when an attack occurs. If this law is likely to occur, it indicates that there is an association rule. Based on the association rules of frequent sequences, we can sort out the process of network attacks and complete the main part of the forensic analysis process. The specific steps include:
[0095] Step a.1: Perform frequent sequence mining to find the abnormal time series data with the highest probability of occurrence.
[0096] Step b.1: Establish association rules between abnormal data and discover the connections between abnormal data.
[0097] Step c.1: Based on the connections between the anomalies, sort out the order in which the anomalies occurred in chronological order, and clarify the logic and process of the anomalies caused by external attacks.
[0098] After completing the time series data mining and association rule generation of the PrefixSpan algorithm, in order to ensure the stability, reliability and effectiveness of the mining results in practical applications, it is necessary to perform system result verification and testing, that is, to verify and evaluate the association rules. In an exemplary embodiment, the verification and evaluation of the association rules specifically includes:
[0099] Step 3.1: Node chain verification. Node chain verification is a specific verification method based on the logic of the responsibility chain model and is used for forensic analysis problems. From the mined frequent subsequences, some typical sequence patterns are selected as basic patterns, and the basic patterns are mutated to a certain extent, including insertion, deletion and other operations, to generate new sequences after mutation. Test whether the association rules also undergo the same type of changes under the mutated new sequences, and determine the stability and reliability of the mined association rules.
[0100] In order to determine whether the derived association rules are reliable and whether there is an association relationship between specific modules (modules that establish specific association patterns in association rules and will be abnormal due to attacks), the node chain verification method is adopted. Node chain verification requires that on the basis of the normal operation time series data, mutation operations (such as insertion, deletion, etc.) are applied to these normal operation time series data to generate a mutated new sequence, and verify whether the generation logic of the new sequence conforms to the association rules that have been analyzed to complete the verification of the association rules. The specific steps of node chain verification are: first, the nodes (predecessors or postdefects) involved in the association rules to be verified need to be selected, and each node corresponds to the normal operation time series data; then a specific node is selected, and the normal operation data corresponding to the node is mutated (the data change of the node is realized by inserting interference data and deleting existing data) to obtain the abnormal data of the node; then, the attacked industrial production equipment is operated under the premise of the abnormal data of the specific node, so that the influence of the mutation is diffused through the rule chain, and the mutated time series data is generated; finally, the generated new time series data is compared with the time series data during normal operation, and whether the same type of mutation occurs, it is judged whether all the nodes included in the association rules have abnormal data. If the anomaly appears in all modules involved in the association rule in chronological order, that is, the occurrence of the anomaly data conforms to the association rule, then the verification of the selected association rule is completed. If the anomaly data does not conform to the association rule, it indicates that the association rule is not accurate enough and frequent sequence mining and association rule determination need to be re-performed.
[0101] Step 3.2: Association rule evaluation: Through statistical verification of support and confidence, determine whether the obtained association rules have high universality and accuracy, and determine whether they can be used as the result of the forensic analysis process.
[0102] After verifying the association rules, it is necessary to evaluate the verification situation and determine the accuracy of the obtained association rules. Support and confidence are selected as indicators for evaluating association rules. If the support and confidence after the association rule verification are greater than the set threshold, it means that the association rule has universality and accuracy and can be used as the result of forensic analysis. Among them, support indicates the prevalence of the association rule in the data, that is, the proportion of the number of records containing the rule in the data set to the total number of records; confidence indicates the reliability of the association rule, that is, the probability that the consequent will also occur when the antecedent occurs.
[0103] Therefore, it is necessary to repeat the verification of association rules (step 3.1) many times, eliminate the influence of accidental events through large sample verification, and count the support of association rules; after each association rule verification, record the probability of the subsequent mutation when the antecedent mutation occurs, evaluate the association rules according to the proportion of the occurrence of the event, and obtain the confidence of the association rules. Construct a comprehensive evaluation framework of support and confidence, comprehensively analyze whether the indicators meet the required threshold of industrial equipment, and evaluate whether the obtained association rules can be used as the result of forensic analysis.
[0104] In an exemplary embodiment, the confidence and support corresponding to the association rule are calculated according to the variant industrial equipment production data set, specifically including:
[0105] For association rule A→B, according to the formula Calculate the support Support(A→B) of the association rule A→B.
[0106] Among them, Count(A→B) represents the total number of records in the variant industrial equipment production data set where the association rule A→B holds true, that is, the number of times A and B appear simultaneously in the data collected at all times, and N is the total number of records in the variant industrial equipment production data set, that is, the number of sampling times.
[0107] According to the formula Calculate the confidence of the association rule A→B, Confidence(A→B).
[0108] Among them, Support(A∪B) is the support for the simultaneous occurrence of antecedent A and consequent B, and Support(A) is the support for the occurrence of antecedent A.
[0109] This application collects industrial equipment production data when industrial equipment is attacked, decrypts and standardizes it, and stores the data according to a trusted timestamp; combined with the changes in the data after the attack, a sequence data mining algorithm is used to find frequent subsequences in the time series data, generate association rules based on frequent subsequences, clarify the attacker's attack logic and methods, and analyze the process of the attack. Chain verification is performed near key time nodes to determine the impact on industrial data after a specific type of attack occurs, confirm the accuracy of the obtained association rules, and complete the forensic analysis of the attack event.
[0110] It has the following technical effects:
[0111] 1. The production data of industrial equipment is marked with a trusted timestamp to ensure the accuracy and reliability of the data sequence; the data is sorted separately according to the time sequence to ensure that the information is clear and easy to analyze.
[0112] 2. The method of producing time series data association rules based on the PrefixSpan algorithm can be used to analyze from the data level, quickly find abnormal data according to the timeline principle, and determine the data location and time range where abnormalities frequently occur; and analyze the correlation between abnormal events based on probability, and analyze the rules of system abnormalities after the attack, which improves the reliability of the analysis as a whole and reduces the possibility of missed detection and false detection.
[0113] 3. The node chain verification and association rule evaluation methods are adopted to introduce mutations to determine whether the related parts also change after the changes occur, and then determine the correctness of the forensic analysis process. The chain verification method ensures the robustness and accuracy of the verification; the association rule evaluation can determine whether the association rules are reliable based on the indicators and whether they can be used as the result of forensic analysis.
[0114] 4. It improves the rigor of forensic analysis, detects and performs reasoning analysis at the data level, and realizes probability-based forensic analysis. The chain verification link further improves the credibility of the results and can be widely used in forensic analysis in industrial production scenarios.
[0115] 5. This application completes the establishment of association rules for industrial system production equipment, realizes the time-series forensic analysis of the attack process, and achieves efficient and accurate analysis and tracing.
[0116] 6. This application combines the timeline principle to perform time series processing on the collected data, add it to the time series database, and realize the integration of time information and data information. On this basis, the PrefixSpan algorithm is introduced to find frequently occurring abnormal sequences and mine association rules, and analyze the time series data from the perspective of frequency of occurrence. The analysis results are then verified through node chain verification and association rule evaluation to ensure the accuracy of association rules in specific scenarios.
[0117] Based on the same inventive concept, the embodiment of the present application also provides an industrial data forensics analysis system for implementing the industrial data forensics analysis method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more industrial data forensics analysis system embodiments provided below can refer to the limitations of the industrial data forensics analysis method above, and will not be repeated here.
[0118] In an exemplary embodiment, Figure 3 As shown, an industrial data forensic analysis system is provided, including:
[0119] The production data collection and sorting subsystem is used to collect the values of various industrial equipment production parameters of the attacked industrial production equipment in real time during the time period when the attacked industrial production equipment is subjected to a network attack to obtain an industrial equipment production data set; the value of each industrial equipment production parameter in the industrial equipment production data set is stored according to the collection time to obtain time series data.
[0120] The industrial data forensics analysis subsystem is used to mine association rules for time series data, determine the process of network attacks based on the association rules obtained by mining, and complete industrial data forensics analysis.
[0121] The industrial data forensics analysis subsystem is used to mine association rules for time series data, determine the process of network attacks based on the association rules obtained by mining, and complete industrial data forensics analysis.
[0122] The industrial data forensic analysis subsystem includes:
[0123] The frequent pattern mining submodule is used to mine frequent subsequences of time series data.
[0124] The association rule generation submodule is used to generate each association rule according to each frequent subsequence mined; the antecedent and consequent of the association rule are both industrial equipment production parameters.
[0125] The node chain verification submodule is used to perform a mutation operation on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set for any association rule; the normal industrial equipment production data set includes the values of the production parameters of each industrial equipment when the attacked industrial production equipment is not subjected to a network attack; on the basis of the mutation operation, the attacked industrial production equipment is operated and the values of the production parameters of each industrial equipment are collected in real time to obtain a mutated industrial equipment production data set; based on the mutated industrial equipment production data set and the normal industrial equipment production data set, it is determined whether the antecedent and consequent in the association rule both contain values of the industrial equipment production parameters that meet the association rule.
[0126] The association rule evaluation submodule is used to calculate the confidence and support corresponding to the association rule based on the variant industrial equipment production data set, and evaluate the association rule according to the confidence and support corresponding to the association rule to obtain the evaluation result; if not, return to the step of frequent subsequence mining of time series data; if the evaluation result meets the preset standard, determine the process of network attack according to the association rule, and complete the industrial data forensic analysis; if the evaluation result does not meet the preset standard, return to the step of frequent subsequence mining of time series data.
[0127] As an optional implementation method, the production data collection and collation subsystem includes a production data collection and collation module, and the industrial data forensic analysis subsystem includes a time series data association rule mining module and an association rule analysis result verification and testing module. The production data collection and collation module is used to realize the acquisition and processing of industrial equipment production data and complete the preliminary preparation for forensic analysis. The time series data association rule mining module is used to implement the main module of the forensic analysis process, find the specific ways in which external attacks affect the system, and confirm the association rules of anomalies. The association rule analysis result verification and testing module is used to complete the subsequent verification and evaluation of the forensic analysis process and realize the subsequent processing flow of forensic analysis.
[0128] As an optional implementation, the production data collection and sorting module includes an industrial data collection submodule, a data preprocessing submodule and a time series sorting submodule. The time series data association rule mining module includes a frequent pattern mining submodule and a generation association rule submodule. The association rule analysis result verification and testing module includes a node chain verification submodule and an association rule evaluation submodule. In the production data collection and sorting module, the industrial data collection submodule first completes the industrial data collection, and then the data preprocessing submodule performs data preprocessing on the collected data, and then the time series sorting submodule and the time series sorting submodule perform time series sorting according to the timeline principle; on the basis of obtaining the time series data, the frequent pattern mining submodule in the time series data association rule mining module is executed to find abnormal time series data, and then the generation association rule submodule is executed to complete the main part of the forensic analysis; on the basis of obtaining the association rules, the node chain verification submodule and the association rule evaluation submodule are executed in sequence.
[0129] As an optional implementation,
[0130] The industrial data acquisition submodule is used to parse the interface protocol and obtain multi-source heterogeneous data of industrial production equipment.
[0131] The data preprocessing submodule is used to obtain and decrypt the encrypted file content and perform standardized processing on different types of data.
[0132] The time series arrangement submodule is used to arrange the processed data according to the timeline principle and build a time series database.
[0133] The frequent pattern mining submodule is used to analyze industrial data types and mine the abnormal data with high occurrence frequency to obtain various frequent subsequences.
[0134] The association rule generation submodule is used to combine the regularity of abnormal data occurrence, find out the specific parts with association to obtain association rules, and determine the process of abnormal occurrence.
[0135] The node chain verification submodule is used to determine whether the obtained association rules are correct and whether the associated modules will be abnormal after being attacked.
[0136] The association rule evaluation submodule is used to evaluate the accuracy of the association rules and determine whether the obtained association rules can be used as the result of forensic analysis based on the set indicators.
[0137] In an exemplary embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 4 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store industrial data forensic analysis data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an industrial data forensic analysis method is implemented.
[0138] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components. In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the above-mentioned method embodiments when executing the computer program.
[0139] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by a processor, the above-mentioned method embodiments are implemented.
[0140] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the above-mentioned method embodiments are implemented.
[0141] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0142] In this application, all actions to obtain signals, information or data are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0143] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM may be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0144] The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. The non-relational database may include a distributed database based on blockchain, etc., but is not limited thereto. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but is not limited thereto.
[0145] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0146] This article uses specific examples to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the method and core ideas of this application. At the same time, for those skilled in the art, according to the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. An industrial data forensic analysis method, characterized in that: The industrial data forensic analysis method comprises: During the time period when the attacked industrial production equipment is attacked by the network, the values of various industrial equipment production parameters of the attacked industrial production equipment are collected in real time to obtain an industrial equipment production data set; The values of the production parameters of each industrial equipment in the industrial equipment production data set are stored according to the collection time to obtain time series data; Perform association rule mining on time series data, determine the process of network attack based on the association rules obtained, and complete industrial data forensic analysis; The association rules of the time series data are mined, and the process of network attack is determined according to the association rules obtained by mining, so as to complete the industrial data forensic analysis, specifically including: Perform frequent subsequence mining on time series data; Generate association rules based on the mined frequent subsequences; the antecedents and consequents of the association rules are both industrial equipment production parameters; For any association rule, a mutation operation is performed on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set; the normal industrial equipment production data set includes the values of the production parameters of each industrial equipment when the attacked industrial production equipment is not subjected to a network attack; On the basis of the mutation operation, the attacked industrial production equipment is operated and the values of the production parameters of each industrial equipment are collected in real time to obtain a set of mutant industrial equipment production data; According to the mutant industrial equipment production data set and the normal industrial equipment production data set, determining whether both the antecedent and the consequent in the association rule contain values of the industrial equipment production parameters that conform to the association rule; If yes, then the confidence and support corresponding to the association rule are calculated according to the variant industrial equipment production data set, and the association rule is evaluated according to the confidence and support corresponding to the association rule to obtain an evaluation result; If not, return to the step of mining frequent subsequences on time series data; If the evaluation result meets the preset standard, the process of the network attack is determined according to the association rule to complete the industrial data forensic analysis; If the evaluation result does not meet the preset standard, the process returns to the step of performing frequent subsequence mining on the time series data.
2. The industrial data forensic analysis method according to claim 1, characterized in that: Industrial equipment production parameters include: sensor data, process data and equipment status data.
3. The industrial data forensic analysis method according to claim 1, characterized in that: The values of each industrial equipment production parameter in the industrial equipment production data set are stored according to the collection time to obtain time series data, specifically including: Decrypting the encrypted value of each industrial equipment production parameter in the industrial equipment production data set to obtain the decrypted value of each industrial equipment production parameter; Performing standardization operations on the values of each non-encrypted industrial equipment production parameter and the decrypted values of each industrial equipment production parameter in the industrial equipment production data set to obtain a pre-processed industrial equipment production data set; The corresponding collection time is marked for each data in the pre-processed industrial equipment production data set to obtain time series data.
4. The industrial data forensic analysis method according to claim 1, characterized in that: The association rule is evaluated according to the confidence and support corresponding to the association rule to obtain an evaluation result, which specifically includes: If the confidence corresponding to the association rule is greater than a preset confidence threshold, and the support corresponding to the association rule is greater than a preset support threshold, then the evaluation result of the association rule meets the preset standard; If the confidence corresponding to the association rule is not greater than a preset confidence threshold, or the support corresponding to the association rule is not greater than a preset support threshold, then the evaluation result of the association rule does not meet the preset standard.
5. The industrial data forensic analysis method according to claim 1, characterized in that: Frequent subsequence mining of time series data is performed as follows: The PrefixSpan algorithm is used to mine frequent subsequences in time series data.
6. The industrial data forensic analysis method according to claim 1, characterized in that: Calculating the confidence and support corresponding to the association rule according to the variant industrial equipment production data set, specifically including: For association rule A→B, according to the formula Calculate the support of association rule A→B Support(A→B); Among them, Count(A→B) represents the total number of records in the variant industrial equipment production data set for which the association rule A→B holds, and N is the total number of records in the variant industrial equipment production data set; According to the formula Calculate the confidence of the association rule A→B Confidence(A→B); Among them, Support(A∪B) is the support for the simultaneous occurrence of antecedent A and consequent B, and Support(A) is the support for the occurrence of antecedent A.
7. An industrial data forensic analysis system, characterized in that: The industrial data forensic analysis system comprises: The production data collection and sorting subsystem is used to collect the values of various industrial equipment production parameters of the attacked industrial production equipment in real time during the time period when the attacked industrial production equipment is attacked by the network to obtain an industrial equipment production data set; the values of various industrial equipment production parameters in the industrial equipment production data set are stored according to the collection time to obtain time series data; The industrial data forensic analysis subsystem is used to mine association rules for time series data, determine the process of network attacks based on the association rules obtained, and complete industrial data forensic analysis; The industrial data forensic analysis subsystem includes: Frequent pattern mining submodule, used to mine frequent subsequences of time series data; The association rule generation submodule is used to generate association rules based on the mined frequent subsequences; the antecedents and consequents of the association rules are both industrial equipment production parameters; The node chain verification submodule is used to perform a mutation operation on the numerical value corresponding to the antecedent or consequent in the association rule in the normal industrial equipment production data set for any association rule; the normal industrial equipment production data set includes the values of the production parameters of each industrial equipment when the attacked industrial production equipment is not subjected to a network attack; on the basis of the mutation operation, the attacked industrial production equipment is operated and the values of the production parameters of each industrial equipment are collected in real time to obtain a mutated industrial equipment production data set; based on the mutated industrial equipment production data set and the normal industrial equipment production data set, it is determined whether the antecedent and consequent in the association rule both have values of the industrial equipment production parameters that meet the association rule; The association rule evaluation submodule is used to calculate the confidence and support corresponding to the association rule based on the variant industrial equipment production data set, and evaluate the association rule according to the confidence and support corresponding to the association rule to obtain the evaluation result; if not, return to the step of performing frequent subsequence mining on the time series data; if the evaluation result meets the preset standard, determine the process of network attack according to the association rule, and complete the industrial data forensic analysis; if the evaluation result does not meet the preset standard, return to the step of performing frequent subsequence mining on the time series data.
8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the industrial data forensic analysis method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the industrial data forensics analysis method described in any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the industrial data forensics analysis method described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Web attack stage analysis method and system based on Web log
CN114915479A
Method for improving safety of industrial control system by adopting vulnerability mining and attack tracing
CN115378650A