Method and system for network risk analysis of chemical process control system based on multi-layer business process modeling

Through multi-layer business process modeling and improved failure mode analysis, a business security model and attack fault tree model of the chemical process control system are constructed, which solves the limitations of risk assessment and insufficient identification of network attacks in chemical process control systems and realizes comprehensive risk identification and dynamic monitoring of the system.

CN119544357BActive Publication Date: 2025-10-10HUAZHONG UNIV OF SCI & TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411757283.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-03
Publication Date
2025-10-10
Estimated Expiration
2044-12-03

AI Technical Summary

Technical Problem

Existing technologies in chemical process control systems lack consideration of the cascading propagation of information layer network attacks, resulting in functional safety failures. In addition, insufficient analysis of the importance of equipment assets and task execution processes makes it difficult to fully identify critical failure paths.

Method used

A multi-layer business process modeling method is adopted to build a business security model of the chemical process control system using the BPMN2.0 standard. Combined with the improved failure mode and effects analysis method, an attack fault tree model is constructed to conduct risk analysis of business activities.

Benefits of technology

It achieves a comprehensive risk assessment of chemical process control systems, identifies security risks in each task link, improves the accuracy of risk analysis and the system's ability to resist cyber attacks, and supports dynamic real-time monitoring and optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544357B_ABST
    Figure CN119544357B_ABST
Patent Text Reader

Abstract

The application belongs to the field of safety engineering in chemical industry production, and discloses a chemical process control system network risk analysis method based on multi-layer business process modeling and application, which comprises the following steps: analyzing the business process and data interaction relationship of the chemical process, and constructing a multi-layer business process model based on the BPMN2.0 standard; replacing the original device-centered method, an improved failure mode and consequence analysis centered on the basic business unit is proposed, the potential failure mode of the task is identified, the failure cause and consequence under different attack intentions are clarified, and the attack fault tree model is generated; finally, the risk analysis of the business activity is carried out. The application considers the role and importance of assets in the task execution process, can comprehensively cover the entire complete failure path under the integration of information security and functional safety, can more comprehensively identify the safety risks in each task link, and further improves the accuracy of risk analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to, but is not limited to, the field of safety engineering technology in chemical industry production, and in particular relates to a chemical process control system network risk analysis method and system based on multi-layer business process modeling. Background Art

[0002] With the increasing automation and digitalization of industries, chemical process control systems are facing not only existing fault problems but also security issues caused by threats such as cyberattacks. Therefore, how to ensure the safe and stable operation of the system has become a key research issue.

[0003] Currently, most business risk assessment methods analyze information security from the perspective of information generation, display, access, transmission, and storage (e.g., Invention Patent 201710994902.5) and business functions and data risk assessment within the network infrastructure (e.g., Invention Patent 2017110120552.X). However, for chemical process control systems, business process risk assessment solely from the perspective of the information layer is far from sufficient. Some approaches consider physical layer business nodes, but these primarily target e-commerce, power generation, and manufacturing (e.g., Invention Patent 202010923638.8, and the paper "Information Security Risk Assessment Based on Business Process Modeling" in the Journal of Beijing Institute of Graphic Communication, Vol. 23-4). Due to the continuous and complex nature of chemical process production operations, these methods lack consideration of continuously operating process variables and the complex interactions between equipment and tasks, making them difficult to directly apply.

[0004] In view of the above analysis, the technical problems that need to be solved urgently in the existing technology are:

[0005] The business process risk assessment method based on the information security domain lacks consideration of scenarios where network attacks at the information layer cascade downward, leading to functional safety failures.

[0006] Traditional risk assessment methods for chemical process control systems based on equipment assets fail to consider the role and importance of chemical equipment in the task execution process. Furthermore, there is no one-to-one correspondence between equipment assets and business tasks, making it difficult to discover critical failure paths that affect the safe operation of the business.

[0007] Therefore, a method is needed that considers the role and importance of assets in the task execution process and can comprehensively cover the entire failure path under the integration of information security and functional safety, and more comprehensively identify the security risks in each task link. Summary of the Invention

[0008] In response to the problems existing in the prior art, the present invention provides a chemical industry risk analysis method and system based on a multi-layer business process model.

[0009] The present invention is implemented as follows: a chemical process control system network risk analysis method based on multi-layer business process modeling, the method specifically comprising:

[0010] S1: Build a multi-layer business security model for a chemical process control system based on the Business Process Model and Notation 2.0 (BPMN2.0) standard;

[0011] S2: Conduct potential safety failure analysis of business activities based on the improved failure mode and effects analysis method to guide the construction of attack fault tree models;

[0012] S3: Risk analysis of conducting business activities.

[0013] Furthermore, the S1 comprises the following steps:

[0014] (1) Analyze the business production types in the chemical process control system, mainly including two types of business: management business model and production business, and determine the business scope and objectives.

[0015] Specifically, the production management business model includes sub-business processes such as production planning and scheduling management, equipment management, safety and environmental management, and the production business model includes sub-businesses such as production process operation, equipment operation and monitoring, and raw material and product processing.

[0016] (2) Clarify the system topology level to which each sub-business process belongs, and analyze the dynamic and static information related to the BPMN2.0 business model.

[0017] Specifically, dynamic business information includes business processes and business activities. A business process is a set of activities organized according to specific rules, business relationships, and a sequential order; a business activity is a collection of one or more tasks. Static business information includes the supporting components, dependent resources, and executors required to achieve the goals of the business activities.

[0018] (3) Analyze the system hierarchy of the distribution of four types of data flows, namely business flow, information flow, control flow and material flow, included in the business activities of the management business model and the production business model, the connection relationship between devices and the data transmitted interactively.

[0019] Specifically, business flow describes the process and sequence of various business activities within the enterprise; information flow is effectively transmitted between different departments and links through networks and systems to provide data support for decision-making; control flow refers to the data flow process for monitoring and adjusting each link in the production process; material flow refers to the flow and transfer of materials from raw materials to finished products in the production process.

[0020] (4) Based on the interactive dependency between business processes and business data, the business construction standard BPMN2.0 is used to generate a fine-grained chemical process control system business process model, and the chemical process control system business model is verified and optimized.

[0021] Furthermore, S2 replaces the original device-centric method and proposes a safety failure analysis method that improves failure mode and effect analysis centered on business basic units, including the following steps:

[0022] (1) Clarify the scope of failure analysis, determine the system losses and hazards caused by business activities, analyze the failure events that cause losses and hazards, and use improved failure mode and effect analysis methods to identify failure modes under network attack intentions.

[0023] Specifically, the business failure mode is composed of the following aspects, that is, business failure mode = {business attribute + deviation guide word},

[0024] Specifically, business attributes can be divided into the following four categories: business services, business values, business execution time, and business execution sequence. Deviation guide words are determined based on the different failure types of business attributes. Deviation guide words for business services include {lack, excess}, which are two categories in total; deviation guide words for business values ​​include {excess, too little}, which are two categories in total; deviation guide words for business execution time include {too early, too late}, which are two categories in total; and deviation guide words for business execution sequence include {omission, duplication, out of order}, which are three categories in total.

[0025] (2) Analyze the failure causes and consequences of the chemical process control system business process failure to guide the construction of subsequent attack fault trees.

[0026] Furthermore, the step S3 includes the following steps:

[0027] (1) The failure modes, failure causes, and failure consequences obtained by the above-mentioned safety failure analysis module are mapped with the elements in the attack fault tree model, and then the attack fault tree model is constructed.

[0028] (2) Decompose the attack fault tree model into static subtrees. Analyze the basic events of the attack fault subtrees in different topological structure levels associated with the business process;

[0029] (3) Solve the minimum cut set of static subtrees at each topological level according to the principle of the minimum set of events that cannot cause the top event to occur after removing any event;

[0030] (4) Risk analysis is performed through minimum cut sets and structural importance.

[0031] Another object of the present invention is to provide a chemical process control system risk analysis system based on a multi-layer business process model, the system specifically comprising:

[0032] Model construction module, building a multi-layer business model for chemical processes based on the business construction standard BPMN2.0;

[0033] The safety failure analysis module analyzes the business processes and behaviors that cause losses and harm to chemical process control systems. It uses an improved failure mode and effects analysis method to identify the failure modes that occur in each basic unit of business activities (i.e., tasks) under different cyber attack intentions, and analyzes the failure causes and consequences.

[0034] The risk analysis module analyzes the related events that lead to business process failure, constructs an attack fault tree model from the perspective of business process failure, task failure, and equipment failure, and performs risk analysis based on the minimum cut set and structural importance.

[0035] In combination with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are as follows:

[0036] First, in terms of business process modeling, it provides a business process model construction solution for the chemical industry, effectively filling the technical gap in this field, meeting the basic needs of chemical production and management business process description, and providing effective support for the collaborative work of business analysts and system security engineers.

[0037] When analyzing the supporting role of equipment assets in chemical process systems in business processes, it is possible to identify the complex many-to-many relationship between equipment and tasks, allowing equipment assets and business tasks to be flexibly configured to adapt to diverse business needs.

[0038] In terms of failure process analysis, traditional FMEA methods are device-centric and tend to be limited to device failure modes and risks. The improved FMEA method, guided by business fundamentals, accurately identifies task failure modes, focuses on key aspects of the business process and business continuity, and identifies potential risks at the business level, better meeting actual application needs.

[0039] Through a comprehensive business process risk analysis solution that integrates information security and functional safety, we ensure that the complete system failure path of the attack propagation can be effectively identified in the face of cyber attacks. This allows for a more comprehensive identification of security risks in every business link, thereby improving the accuracy of risk analysis and supporting enterprises in enhancing their resilience in an increasingly complex environment.

[0040] Second, the technical solution of the present invention effectively solves the following technical problems in the prior art in industrial applications and achieves significant technological progress:

[0041] 1. Technical issues

[0042] 1) Limitations of risk analysis in traditional chemical process control systems

[0043] Existing technologies mainly focus on risk analysis at a single level, lacking correlation analysis between business processes, task units, and equipment levels, and are unable to fully reveal the potential risks in chemical processes.

[0044] 2) Insufficient identification of failure modes in cyber attack scenarios

[0045] Chemical control systems face complex cyber attack scenarios. Existing technologies make it difficult to accurately identify the failure mode analysis of task units under attack intent, resulting in non-targeted defense measures.

[0046] 3) Risk assessment models lack hierarchy and dynamism

[0047] Traditional risk assessment methods lack multi-level modeling capabilities from the equipment layer to the business process, and cannot dynamically reflect the complexity of the system and the real-time changing risk status.

[0048] 2. Significant technological advancements

[0049] 1) Multi-layer business process modeling enables comprehensive analysis

[0050] This paper builds a multi-layered business model for a chemical process control system based on BPMN 2.0, combining business processes, task units, and equipment status to form a hierarchical analysis framework that comprehensively covers all aspects of the chemical process. This modeling approach makes risk analysis more accurate and efficient.

[0051] 2) Improve failure mode analysis to enhance its specificity

[0052] By introducing an improved Failure Mode and Effects Analysis (FMEA), the present invention can identify the failure mode of each task unit under the intention of a network attack, and conduct an in-depth analysis of the causes and consequences of the failure, thereby providing targeted security protection recommendations.

[0053] 3) Attacking the fault tree model to enhance risk assessment depth

[0054] The present invention structures the relationship between business process failure and task and equipment failure by attacking the fault tree model, and can qualitatively analyze the event path leading to chemical process failure, providing a scientific basis for system security optimization.

[0055] 4) Combining qualitative and quantitative risk analysis

[0056] By using minimum cut sets and structural importance analysis, the present invention not only qualitatively reveals the key risk points, but also quantitatively evaluates the impact of each event on the system, thereby achieving comprehensive and accurate risk assessment.

[0057] 5) Dynamic risk assessment supports real-time monitoring

[0058] The present invention supports real-time updating and dynamic risk assessment, can timely update the model according to system operation data, respond quickly to risk status, and improve the safety and adaptability of chemical control systems.

[0059] 6) Industrial application value

[0060] This invention significantly improves the safety, stability and reliability of chemical process control systems in complex scenarios, promotes the digital transformation of the industry, and has important practical application value, especially in the fields of network security, chemical process optimization and risk management. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 This is an overall flow chart of a risk analysis method based on a chemical process control system business model provided by an embodiment of the present invention;

[0062] Figure 2 This is a schematic diagram of a production process operation business model of a chemical process control system provided by an embodiment of the present invention;

[0063] Figure 3 A relationship diagram of enterprise levels, tasks related to each level, and dependent equipment assets, in an example of risk analysis for fractionation tower top temperature control execution provided by an embodiment of the present invention;

[0064] Figure 4 This is an attack-fault tree diagram of the temperature control execution of the distillation tower top provided by an embodiment of the present invention;

[0065] Figure 5 The invention provides a chemical process control system risk analysis system based on a multi-layer business process model. DETAILED DESCRIPTION

[0066] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0067] like Figure 1 As shown, an embodiment of the present invention provides a chemical process control system network risk analysis method based on multi-layer business process modeling, which specifically includes:

[0068] S1: Build a multi-layer business security model for a chemical process control system based on the BPMN2.0 standard;

[0069] S2: Conduct potential safety failure analysis of business activities based on the improved failure mode and effects analysis method to guide the construction of attack fault tree models;

[0070] S3: Risk analysis of conducting business activities.

[0071] 1. Data collection and modeling of multi-layer business security models

[0072] First, key signal data from chemical process control systems, such as sensor data, control signals, and operating instructions, is categorized and organized according to the logical relationships between business activities and processes. Using the BPMN 2.0 standard, a multi-layered structure for management and production business activities is defined, generating a multi-layered business security model. Key signal data is then mapped to the nodes of each business activity, creating a dynamic, traceable model.

[0073] 2. Failure mode extraction and analysis of signal data

[0074] At the nodes of business activities, combined with signal data characteristics, an improved Failure Mode and Effects Analysis (FMEA) method is used to identify potential signal failure modes at each node. For example, failure causes and consequences such as signal transmission delays, incorrect operating instructions, or sensor failures are analyzed one by one through this method. The results of this analysis document the correlation between failure modes and signal characteristics, providing foundational data for subsequent risk modeling.

[0075] 3. Construction of attack fault tree model driven by signal data

[0076] Based on the results of failure mode analysis, chemical process control system signal data is used as node input, and an attack fault tree model is constructed layer by layer, from business activity failure to equipment failure. Signal data is used to quantify the failure probability of critical paths in the fault tree. Combined with minimum cut set analysis, potential cyber attack intentions and the paths leading to the failure of critical business activities are identified.

[0077] 4. Risk Analysis and Assessment of Signal Data

[0078] Using a fault tree model, we analyze the structural importance and probability of key signal data nodes, assessing the risk level of each node. Furthermore, combined with real-time monitoring of signal data, we dynamically assess the potential failure risks in business activities. Ultimately, signal data is used to generate risk analysis reports, guiding the development of risk mitigation strategies and the safety optimization of chemical process control systems.

[0079] S1 builds a standard BPMN2.0 chemical process control system business model based on the business, including:

[0080] (1) The business production types in the chemical process control system are analyzed, mainly including two types of business: management business model and production business, and the business goals and specific business processes are determined.

[0081] Among them, the production management business model includes production planning and scheduling management, equipment management, safety and environmental management and other sub-businesses. The risk analysis of the chemical process control system based on the multi-layer business process model, the production business model includes production process operation, equipment operation and monitoring, raw material and product processing and other sub-businesses.

[0082]

[0083] (2) Clarify the system topology hierarchy to which each sub-business process belongs, and analyze the dynamic and static information related to the BPMN2.0 business model. The dynamic information of the business includes business processes and business activities. A business process is a group of activities that are combined according to certain rules, business relationships, and their sequence; a business activity is a collection of one or more tasks. The static information of the business includes the supporting components or dependent resources and executors that achieve the goals of the business activities.

[0084] The business processes, business activities, tasks involved, and dependent resources of the production management business are as follows:

[0085]

[0086]

[0087] The business processes, business activities, tasks involved, and dependent resources of the production execution business are as follows:

[0088]

[0089] (3) Based on the overall structure of the business process of the chemical process control system, the data types of business activities are divided into four categories: business flow, control flow, information flow and material flow, and the characteristics of different data types are analyzed. The sending role and the executing role of the business data flow are analyzed, the interaction between the resources relied on by the business activities of different system topology levels is determined, and the detailed business flow chart is developed, so as to verify and optimize the business model of the chemical process control system.

[0090] Specifically, the business flow describes the process and sequence of various business activities within the enterprise; the information flow is effectively transmitted between different departments and links through the network and system, providing data support for decision-making; the control flow refers to the data flow process of monitoring and adjusting each link of the production process; and the material flow refers to the flow and transfer of materials from raw materials to finished products in the production process.

[0091]

[0092] (4) Based on the business, the standard BPMN2.0 is used to draw a high-level flow chart to show the overall structure of the main business processes of the chemical process control system. Taking the production process operation business process as an example, the business process model is constructed based on the BPMN2.0 standard as shown in Figure 2 .

[0093] The S2 comprises the following steps:

[0094] Taking the catalytic cracking fractionation unit of the chemical process control system as an example, the enterprise levels involved in the temperature control execution process of the fractionation tower, the related tasks of each level and the dependent equipment assets are analyzed, as shown in Figure 3 .

[0095] (1) The scope of failure analysis is determined, the system loss and harm caused by task failure are determined, and the task-centered improvement failure mode and consequence analysis method is improved to identify the failure mode.

[0096] Specifically, the business failure mode is composed of the following aspects, i.e., business failure mode = {business attribute + deviation guide word}.

[0097] Specifically, the business attribute can be divided into the following four categories: business service, business numerical value, business execution time and business execution sequence. According to the different failure types of business attributes, the deviation guide words are determined, wherein the deviation words of the business service type = {lack, excess}, a total of two categories; the deviation words of the business numerical value type = {too much, too little}, a total of two categories; the deviation words of the business execution time type = {too early, too late}, a total of two categories; and the deviation words of the business execution sequence type = {omission, repetition, wrong sequence}, a total of three categories.

[0098]

[0099] (2) Based on the improved failure mode and effects analysis method, the causes and consequences of task failure are analyzed, and the scenario of task failure is constructed. Taking the catalytic cracking fractionation unit as an example, the failure modes, causes and consequences of the related tasks in the temperature control execution process of the distillation tower top are analyzed in detail, which is convenient for guiding the construction of subsequent attack fault trees.

[0100]

[0101] S3, taking the top temperature control of a fractionation tower in a fractionation unit in catalytic cracking as an example, provides a method for performing risk analysis on a business process of a chemical process control system, comprising the following steps:

[0102] (1) Map the failure modes, failure causes, and failure consequences obtained by the above-mentioned safety failure analysis module with the elements in the attack fault tree model, and then construct a fault tree model. Failure consequences are the impact or results brought about by the failure mode, mapped as top-level events TE (Top Event); failure modes represent the failure conditions or deviations that occur in the system, mapped as intermediate events IE (Intermediate Events) in the fault tree; failure causes are the direct factors that cause specific failure modes, mapped as basic events x in the fault tree i (Basic Events), which are the root causes that directly cause the failure.

[0103] (2) Based on the fault tree, the failure of the tower top temperature control caused by network attack factors is taken into consideration and the attack fault tree is constructed as follows: Figure 4 As shown in Figure 2. Specifically, the attack tree consists of nodes and logical relationships. Nodes include root nodes and leaf nodes, and logical relationships include AND, OR, and sequential AND. The root node represents the compromised information or control device, and the leaf nodes represent the attack method and existing vulnerabilities.

[0104] (3) Decompose the attack fault tree model into static subtrees. Specifically, the attack fault tree basic event set X1 of the task in the enterprise layer is {x1, x2, ... x7}; the attack fault tree basic event set X2 of the task in the monitoring layer is {x8, x9, ... x 18}; The basic event set of the attack fault tree of the task in the control layer X3 = {x 19 ,x 20 ,…x 28}; The attack fault tree basic event set X4 of the task in the physical layer = {x 29}.

[0105] (4) Solve the minimum cut set of static subtrees at each level according to the following principles. Specifically, first perform logic gate analysis: the output event of the AND gate will only occur when all input events occur. Therefore, all input events connected to the AND gate constitute a cut set. The output event of the OR gate will occur when any input event occurs. Therefore, each input event of the OR gate can constitute a cut set independently. Next, solve the minimum cut set: the smallest set of events that will not cause the top event to occur after removing any event.

[0106] Specifically, there are 6 minimum cut sets of static attack fault subtree in the enterprise layer, namely {x1}, {x2}, {x3}, {x4}, {x5, x6}, {x5, x7}; there are 9 minimum cut sets of static attack fault subtree in the control layer, namely {x 19}、{x 23}、{x 26}、{x 27}、{x 28}、{x 20 , x 21}、{x 20 , x 22}、{x 20 , x 24}、{x 20 , x 25}.

[0107] (5) Risk analysis is performed through the minimum cut set and structural importance. The structural importance of a basic event is analyzed by using the minimum cut set. i The structural importance coefficient is represented by ST(i). The minimum cut set solution for structural importance must follow three rules:

[0108] The structural importance of the cut set with only one bottom event in the minimum cut set is the largest.

[0109] When the number of bottom events in the minimum cut set is equal, the bottom event structure with more occurrences has greater importance.

[0110] When the number of bottom events in the minimum cut set is unequal, the minimum cut set with fewer bottom events has greater structural importance than the one with more.

[0111] Specifically, the importance of basic events in the enterprise layer and the control layer can be obtained:

[0112] ST(1)=ST(2)=ST(3)=ST(4)>ST(5)>ST(6)=ST(7) (Equation 1)

[0113] ST(19)=ST(23)=ST(26)=ST(27)=ST(28)>ST(20)>ST(21)=ST(22)=ST(24)=ST(25) (Equation 2)

[0114] (6) Information security risk analysis of business processes based on the attack fault tree model: According to Formula 1 and Formula 2, the structural importance of equipment failure events in functional safety is higher than that of network attack events in information security. The structural degree is positively correlated with the impact of the accident, and the risk it brings is also greater.

[0115] (7) Information security risk analysis of business processes based on the attack fault tree model: This risk analysis method takes into account the relationship between the topological hierarchy, tasks, and devices associated with the business process. Multiple devices perform a task, such as management software and enterprise resource planning systems, which both affect the control scheme design task. The greater the structural importance of the task, the greater the risk of task failure. A device performs multiple tasks, such as a controller that performs two tasks, parameter adjustment and instruction issuance. The more tasks a device performs, the more task failures will be affected by device damage, and the greater the risk of device failure.

[0116] like Figure 5 As shown, an embodiment of the present invention provides a chemical process control system network risk analysis system based on multi-layer business process modeling, specifically including:

[0117] Model construction module, which builds a multi-layer business model of the chemical process control system based on the business construction standard BPMN2.0;

[0118] The safety failure analysis module analyzes the business processes and behaviors that cause losses and harm to chemical process control systems. It uses an improved failure mode and effects analysis method to identify the failure modes that occur in each basic unit of business activities (i.e., tasks) under different cyber attack intentions, and analyzes the failure causes and consequences.

[0119] The risk analysis module analyzes the related events that lead to business process failure, constructs an attack fault tree model from the perspective of business process failure, task failure, and equipment failure, and performs risk analysis based on the minimum cut set and structural importance.

[0120] The system uses a model-building module to establish a multi-layered business model for chemical process control systems based on the Business Process Model and Notation 2.0 (BPMN 2.0) standard. The model covers multiple levels, from high-level business objectives to specific tasks and activities. It clearly describes the operational steps, resource allocation, and relationships between tasks within the chemical process, providing a structured framework and data support for subsequent risk analysis.

[0121] The system's safety failure analysis module employs an improved Failure Mode and Effects Analysis (FMEA) methodology to identify failure modes across various business behaviors within the chemical process control system. Using tasks as fundamental units and incorporating the unique business processes of chemical systems, this module assesses failure scenarios under various cyberattack intents and conducts in-depth analysis of the causes and potential consequences of failures. For example, a failure could be caused by equipment failure, network communication interruption, or command error, while the consequences could be the stagnation of critical tasks or unstable chemical process operations.

[0122] By integrating the business process characteristics of chemical control systems, the safety failure analysis module identifies cyberattack intent. The system can identify potential threat patterns at the business activity level for attack scenarios within chemical production (such as information tampering, command spoofing, or denial of service attacks), thereby inferring the attacker's intent. These identification results guide the risk analysis module in constructing a more targeted attack fault tree model.

[0123] The risk analysis module further analyzes the correlation between business process failures and task and equipment failures. By constructing an attack fault tree model, it decomposes the complex risk factors of chemical process control systems into more easily analyzable sub-events. The fault tree model begins with a chemical process failure as the top event and progressively links upward from the equipment and task layers, comprehensively depicting the path leading to the top event.

[0124] Based on the attack fault tree model, the risk analysis module utilizes minimal cut sets and structural importance methods. Minimal cut sets are used to identify key event combinations that can lead to service failures in the system, while structural importance is used to assess the impact of each event on the overall system risk. These analysis results help identify weak links in the system and provide a concrete technical basis for optimizing and protecting chemical process control systems.

[0125] Ultimately, the system combines failure mode analysis and fault tree analysis results to provide risk management recommendations for chemical process control systems. For example, the analysis results can be used to adjust task allocation, strengthen equipment maintenance, or optimize network security configurations. The system also supports dynamic risk assessment, updating models and reassessing risks based on real-time data, ensuring the safety and stability of chemical process control systems in complex environments.

[0126] This invention belongs to the field of safety engineering technology in chemical industry production and is applicable to safety risk situation awareness equipment or safety assessment and management equipment for chemical process control systems. Through comprehensive analysis of equipment and task nodes, this invention promptly identifies potential high-risk points in the system under cyber attacks. Combined with analysis methods based on multi-layer business process models, this technology can provide early warnings of risks during system operation, helping managers take proactive countermeasures and prevent accidents.

[0127] By testing different task flows of various chemical process control systems, potential risk points in each task node are identified, with strong risk coverage. After risk identification, risk warning information can be effectively output to help managers understand and control risks in a timely manner.

[0128] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware portion can be implemented using dedicated logic; the software portion can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. Those skilled in the art will appreciate that the above-mentioned devices and methods can be implemented using computer-executable instructions and / or contained in processor control code, for example, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above-mentioned hardware circuits and software, such as firmware.

[0129] The above description is only a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with this technical field within the technical scope disclosed by the present invention and within the spirit and principles of the present invention should be covered by the scope of protection of the present invention.

Claims

1. A chemical process control system network risk analysis method based on multi-layer business process modeling, characterized by: The method specifically includes: S1: Based on the key signal data of the chemical process control system, including sensor data, control signals, and operating instructions, data is classified and organized according to the logical relationship between business activities and processes, and a multi-layer business model of the chemical process control system is constructed. The key signal data is mapped to business activity nodes. S2: Using an improved Failure Mode and Effects Analysis (FMEA) method, combined with signal data characteristics, identify potential signal failure modes at business activity nodes, including signal transmission delays, incorrect operating instructions, and sensor failures, and record the association between failure modes and signal characteristics; S3: Based on the analysis results obtained by the improved failure mode and effects analysis method, an attack fault tree model is constructed, which is expanded layer by layer from business activity failure to equipment failure. Through minimum cut set analysis and structural importance assessment, potential network attack paths and key failure nodes of business activities are identified; S4: Based on the fault tree model, risk level assessment is performed on business activity nodes corresponding to key signal data. The risks of business activities are dynamically analyzed through real-time signal data monitoring, and risk analysis reports are generated to guide risk mitigation strategies and safety optimization of chemical process control systems. The S2 adopts an improved failure mode and effects analysis method centered on the business basic unit, including the following steps: (1) Clarify the scope of failure analysis, determine the system losses and harms caused by business activities, analyze the failure events that cause losses and harms, and use improved failure mode and effect analysis methods to identify failure modes that occur under the intention of network attacks; (2) Analyze the failure causes and consequences of the chemical process control system business process failure to guide the construction of subsequent attack fault trees; The failure mode = {business attribute + deviation guide word}, ​​business attributes are divided into the following four categories: business service, business value, business execution time, and business execution sequence. The deviation guide word is determined according to the different failure types of business attributes, among which the deviation word of the business service type = {lack, redundancy}; the deviation word of the business value type = {too much, too little}; the deviation word of the business execution time type = {too early, too late}; the deviation word of the business execution sequence type = {omission, repetition, wrong order}.

2. The chemical process control system network risk analysis method based on multi-layer business process modeling as claimed in claim 1 is characterized in that: Said S1, said chemical process control system multi-layer business model is constructed in the following manner: (1) Analyze the business production types in the chemical process control system, including the management business model and the production business, and determine the business objectives and specific business processes; the production management business model includes production planning and scheduling management, equipment management, safety and environmental management sub-business processes, and the production business model includes production process operation, equipment operation and monitoring, and raw material and product processing sub-businesses; (2) Clarify the system topology level to which each sub-business process belongs, and analyze the dynamic and static information related to the BPMN2.0 business model; (3) Based on the overall structure of the chemical process control system business process, the data types of business activities are divided into four types: business flow, control flow, information flow and material flow, and the characteristics of different data types are analyzed; the issuing role and execution role of business data flow are analyzed, and the interaction relationship between the resources that business activities at different system topology levels depend on is determined, so as to develop a detailed business process diagram and verify and optimize the business model of the chemical process control system; (4) Draw a high-level flowchart based on the business construction standard BPMN2.0 to show the overall structure of the main business processes of the chemical process control system.

3. The chemical process control system network risk analysis method based on multi-layer business process modeling as claimed in claim 2 is characterized in that: The management business model includes production planning and scheduling management, equipment management, safety and environmental management sub-business processes, and the production business model includes production process operation, equipment operation and monitoring, and raw material and product processing sub-businesses; the dynamic information of the business includes business processes and business activities, among which the business process is a group of activities combined according to certain rules, business relationships and their sequence, and the business activity is a collection of one or more tasks. The static information of the business includes the supporting components or dependent resources and executors for completing the business activity goals; the business flow describes the process and sequence of various business activities within the enterprise, and the information flow is effectively transmitted between different departments and links through the network and system to provide data support for decision-making; the control flow refers to the data flow process for monitoring and adjusting each link of the production process; the material flow refers to the flow and transfer of materials from raw materials to finished products in the production process.

4. The chemical process control system network risk analysis method based on multi-layer business process modeling as claimed in claim 1 is characterized in that: Said S3 comprises the following steps: (1) Mapping the failure modes, failure causes, and failure consequences obtained in step S2 with the elements in the attack fault tree model, and then constructing the attack fault tree model; (2) Decompose the attack fault tree model into static subtrees; Analyze the basic events of the attack fault subtree in the topology structure level associated with the business process; (3) Solve the minimum cut set of static subtrees at each topological level according to the principle of the minimum set of events that cannot lead to the occurrence of the top event after removing any event; (4) Risk analysis is performed through the minimum cut set and the structural importance of basic events.

5. A network risk analysis system using the chemical process control system network risk analysis method based on multi-layer business process modeling as described in any one of claims 1 to 4, characterized in that: The system specifically includes: Model construction module, which builds a multi-layer business model of the chemical process control system based on the business construction standard BPMN2.0; The safety failure analysis module analyzes the business processes / activities that cause losses and harm to chemical process control systems. It uses an improved failure mode and effects analysis method to identify the failure modes of each basic unit of business activities under different cyber attack intentions, and analyzes the failure causes and consequences. The risk analysis module analyzes the related events that lead to business process failure, constructs an attack fault tree model from the perspectives of business process failure, task failure, and equipment failure, and performs risk analysis based on the minimum cut set and the structural importance of basic events.

Citation Information

Patent Citations

  • Risk assessment method and system based on business process

    CN107730128A

  • Power Internet of Things security vulnerability evaluation method integrating service security

    CN112087445A

  • Software FMEA (failure mode and effects analysis) method based on level dependency modeling

    CN103473400A

  • Data-driven dynamic risk evaluation method

    CN115600350A