An asset dynamic digital fingerprint construction system for power industrial control network security

By designing an asset dynamic digital fingerprint construction system in the power industrial control network, collecting and analyzing equipment data in real time, identifying and building dynamic digital fingerprints, the problem of inability to adapt to network asset changes and identifying abnormal equipment in the existing technology is solved, and efficient and accurate security monitoring and threat warning are achieved.

CN119558875BActive Publication Date: 2025-05-13BEIJING HUADIAN TIANREN ELECTRIC POWER CONTROL TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510125470.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-13
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

The prior art relies on static fingerprint libraries and fixed similarity thresholds in the power industrial control network, and cannot adapt to network asset changes and identify abnormal devices in real time. It lacks multi-dimensional in-depth analysis of asset behavior characteristics, and does not involve continuous monitoring and behavioral analysis, making it difficult to detect potential security threats.

Method used

A dynamic digital fingerprint construction system for asset is designed, and equipment data is collected in real time through the data acquisition module, and normal and abnormal devices are identified in multiple stages, byte fluctuation thresholds are adjusted, and dynamic digital fingerprints based on device behavior characteristics are constructed to realize real-time security monitoring and threat warning.

Benefits of technology

It significantly improves the security of the power industrial control network, can identify abnormal equipment in real time, avoid false alarms and missed reports, dynamically adjusts the threshold to deal with changes in equipment behavior, ensures the efficiency and accuracy of security detection, and provides strong device identity authentication support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119558875B_ABST
    Figure CN119558875B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of power industrial control network asset management, and in particular to an asset dynamic digital fingerprint construction system for power industrial control network security, including a data acquisition module, a first determination module, a second determination module, an identification module, an adjustment module, and a construction module. The present invention significantly improves the security of the power industrial control network through precise multi-level data acquisition, behavior analysis, and threshold adjustment. The system can collect key behavior data of the equipment in real time, such as the number of bytes of data packets, memory usage, and the number of login failures. Through multi-stage screening, it can accurately identify normal and abnormal equipment to avoid false positives and false negatives. The system adjusts the byte number fluctuation threshold to flexibly respond to dynamic changes in equipment behavior, ensure the efficiency and accuracy of security detection, and effectively solve the problem of being unable to adapt to changes in network assets and identify abnormal equipment in real time due to reliance on static fingerprint libraries and fixed similarity thresholds.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power industrial control network asset management, and in particular to an asset dynamic digital fingerprint construction system for power industrial control network security. Background Art

[0002] With the rapid development of informatization and automation, power industrial control systems play a vital role in modern energy management. However, with the continuous upgrading of network attack technology, power industrial control systems are facing unprecedented security threats. In particular, the wide variety of equipment and assets in the network and the complex and changeable operating environment make dynamic management and security protection of assets more difficult. Therefore, how to effectively identify and monitor various assets in the power industrial control network and ensure its safe operation has become a major issue that needs to be solved in the current power industry.

[0003] The patent application document with the Chinese patent application publication number CN109214831A discloses a method for constructing a fingerprint of a network asset of a power monitoring system and identifying an asset. The method includes: step 1, constructing an index system for extracting fingerprints of a network asset of a power monitoring system; step 2, constructing a fingerprint library of a power monitoring network asset; step 3, collecting the communication traffic of an unknown network asset, comparing it with the network asset fingerprint in the power monitoring network asset fingerprint library, and calculating the fingerprint similarity Rg between the unknown network asset fingerprint F′ and the g-th network asset fingerprint Fg in the network asset fingerprint library AF of the power monitoring system: sorting the fingerprint similarities of all network assets in descending order to obtain the maximum similarity R: R=max(R1, R2,..., Rn); judging the identification result D of the unknown network asset according to R: when R≥0.9, judging that the unknown network asset is successfully identified, the unknown network asset is the same or similar network asset as the known network asset; when R<0.9, judging that the unknown network asset is unidentified, adding the unknown network asset fingerprint F′ to the network asset fingerprint library AF of the power monitoring system, and realizing the automatic update of the network asset fingerprint library.

[0004] It can be seen that the method for constructing network asset fingerprints and identifying assets in the power monitoring system has the following problems: the method relies on a fixed network asset fingerprint library. When new unknown assets are added, the fingerprint library needs to be manually updated, and it cannot adapt to changes in network assets in real time; the method uses a single means of judging the similarity of network asset fingerprints, which leads to misidentification or missed identification, and lacks multi-dimensional in-depth analysis of asset behavior characteristics; the single fingerprint matching method adopted by the method is not suitable for diversified attacks or equipment anomalies in complex network environments, and does not fully consider dynamic behavior patterns and real-time security monitoring; the method does not involve continuous monitoring and behavior analysis of network assets, and it is difficult to detect potential security threats or abnormal activities in a timely manner, so it lacks flexibility and comprehensiveness. Summary of the invention

[0005] To this end, the present invention provides an asset dynamic digital fingerprint construction system for power industrial control network security, which is used to overcome the problems in the prior art that it cannot adapt to network asset changes and identify abnormal devices in real time due to reliance on static fingerprint libraries and fixed similarity thresholds through dynamic behavior analysis and real-time adjustment mechanisms.

[0006] To achieve the above-mentioned purpose, the present invention provides an asset dynamic digital fingerprint construction system for power industrial control network security, comprising:

[0007] The data acquisition module is used to collect the real-time data packet byte count, real-time memory usage rate and real-time login failure count during the operation of each power industrial control equipment;

[0008] A first determination module, connected to the data acquisition module, for determining a number of first temporary devices according to the number of bytes of the real-time data packet and a preset byte number fluctuation threshold;

[0009] A second determination module, which is connected to the data acquisition module and the first determination module respectively, and is used to determine a number of second temporary devices according to the number of bytes of the real-time data packet and the real-time memory usage rate of the first temporary device;

[0010] an identification module, which is connected to the data acquisition module and the second determination module respectively, and is used to identify a number of normal devices and abnormal devices according to the real-time number of login failures of the second temporary device;

[0011] An adjustment module, connected to the identification module, for adjusting the preset byte number fluctuation threshold according to the number of abnormal devices within a preset adjustment time period to form an adjusted byte number fluctuation threshold;

[0012] A construction module is connected to the data acquisition module, the adjustment module and the identification module respectively, and is used to construct a digital fingerprint according to the real-time data packet byte number, the real-time memory usage rate and the real-time login failure number of the normal device identified based on the adjustment byte number fluctuation threshold.

[0013] Furthermore, the first determining module includes:

[0014] A byte number fluctuation calculation unit, used to calculate a standard deviation of the number of bytes of the real-time data packet within a preset first determined time length to form a byte number fluctuation value;

[0015] A first determination unit is connected to the byte data fluctuation calculation unit, and is used to determine that the power industrial control device is the first temporary device when the byte number fluctuation value is greater than the preset byte number fluctuation threshold, so as to form a plurality of the first temporary devices.

[0016] Furthermore, the second determining module includes:

[0017] A first fluctuation calculation unit, used for calculating a standard deviation of the number of bytes of the real-time data packet within a preset second determined time length to form a first temporary fluctuation value;

[0018] A second fluctuation calculation unit, used for calculating the standard deviation of the real-time memory usage rate within the preset second determined time period to form a second temporary fluctuation value;

[0019] The second determining unit is connected to the first fluctuation calculating unit and the second fluctuation calculating unit respectively, and is used to determine a number of second temporary devices according to the first temporary fluctuation value and the second temporary fluctuation value.

[0020] Further, the second determining unit includes:

[0021] A first curve drawing subunit is used to draw a change curve within the preset second determined time period according to the first temporary fluctuation value to form a first curve;

[0022] A second curve drawing subunit is used to draw a change curve within the preset second determined time period according to the second temporary fluctuation value to form a second curve;

[0023] a consistency calculation subunit, which is connected to the first curve drawing subunit and the second curve drawing subunit respectively, and is used to calculate the cosine similarity between the first curve and the second curve to form a consistency;

[0024] The second determination subunit is connected to the consistency calculation subunit, and is used to determine the first temporary device as the second temporary device to form a plurality of second temporary devices when the consistency is less than a preset consistency threshold.

[0025] Furthermore, the identification module includes:

[0026] An average value calculation unit, used to calculate the average value of the real-time login failure times within a preset historical period to form a failure number average value;

[0027] A number fluctuation calculation unit, used to calculate the standard deviation of the number of real-time login failures within the preset historical time period to form a number fluctuation value;

[0028] A threshold setting unit, which is connected to the mean value calculation unit and the number fluctuation calculation unit respectively, and is used to set a historical number threshold according to the failure number mean value and the number fluctuation value;

[0029] The identification unit is connected to the threshold setting unit and is used to identify a number of normal devices and abnormal devices according to the real-time login failure times and the historical times threshold within a preset identification time.

[0030] Furthermore, the identification unit includes:

[0031] A comparison subunit, used to compare the number of failed logins with the historical number threshold to form a number comparison result;

[0032] an identification subunit connected to the comparison subunit, and configured to identify the second temporary device as an abnormal device when the comparison result shows that the number of logins is greater than the historical number threshold, thereby forming a plurality of abnormal devices;

[0033] The identification subunit is further used to identify non-abnormal devices among all the power industrial control devices as normal devices to form a plurality of normal devices.

[0034] Furthermore, the adjustment module includes:

[0035] A quantity fluctuation calculation unit, used to calculate the standard deviation of the device quantity of the abnormal device to form a quantity fluctuation value;

[0036] An adjustment module is connected to the quantity fluctuation calculation unit and is used to reduce the preset byte number fluctuation threshold according to the relative deviation between the quantity fluctuation value and the preset quantity fluctuation threshold and the preset adjustment coefficient when the quantity fluctuation value is greater than the preset quantity fluctuation threshold, so as to form an adjusted byte number fluctuation threshold.

[0037] Furthermore, the building blocks include:

[0038] A behavior analysis unit, configured to analyze the number of bytes of the real-time data packet, the real-time memory usage rate, and the number of real-time login failures according to a preset behavior analyzer to form a plurality of device behavior feature vectors;

[0039] A combining unit, used for combining the device behavior feature vectors through a preset encoder to form a feature combination;

[0040] A construction unit is connected to the combination unit and is used to construct the digital fingerprint according to the feature combination.

[0041] Furthermore, the combination unit comprises:

[0042] A splicing subunit, used for weighted splicing of the device behavior feature vectors to form a multi-dimensional vector;

[0043] A combining subunit, connected to the splicing subunit, for combining the multi-dimensional vectors through the preset encoder to form a feature combination;

[0044] The preset encoder is generated by a preset constructor.

[0045] Furthermore, the asset dynamic digital fingerprint construction system for power industrial control network security also includes:

[0046] An alarm module is connected to the adjustment module and the identification module respectively, and is used to issue an alarm according to the abnormal device formed based on the adjustment byte number fluctuation threshold.

[0047] Compared with the prior art, the beneficial effect of the present invention is that, through precise multi-level data collection, behavior analysis and threshold adjustment, the security of the power industrial control network is significantly improved. The system can collect key behavior data of the equipment in real time, such as the number of data packet bytes, memory usage and number of login failures. Through multi-stage screening, normal and abnormal devices can be accurately identified to avoid false alarms and missed alarms. The system can flexibly respond to dynamic changes in device behavior by adjusting the byte number fluctuation threshold to ensure the efficiency and accuracy of security detection. The dynamic digital fingerprint constructed based on the device behavior characteristics provides strong support for device identity authentication. Once the device behavior deviates, the system can respond quickly and issue an alarm to protect the system from potential security threats, effectively solving the problem of relying on static fingerprint libraries and fixed similarity thresholds that cannot adapt to changes in network assets and identify abnormal devices in real time.

[0048] Furthermore, by calculating the fluctuation value of the number of bytes in the data packet, devices with abnormal data traffic can be effectively identified, providing a reliable basis for subsequent anomaly detection and analysis. It can dynamically adapt to the network fluctuations of the device, improve the detection sensitivity and accuracy of the system, and help to timely discover potential security risks or equipment failures.

[0049] Furthermore, by combining the fluctuations of the number of data packet bytes and the memory usage rate, the second determination module can more accurately identify whether the device is in an abnormal state, avoiding misjudgment or missed judgment that may be caused by fluctuations in a single dimension.

[0050] Furthermore, by comparing the similarity of the fluctuation values ​​of the two groups of devices, devices with possible abnormal behavior can be effectively screened out, improving the accuracy and reliability of device identification. By calculating the cosine similarity, the consistency of the devices in different monitoring dimensions can be more accurately reflected, further improving the system's detection capability and sensitivity to device status changes in the power industrial control network.

[0051] Furthermore, through statistical analysis based on historical data, abnormal login behavior of devices can be effectively identified. By calculating the mean and standard deviation, the threshold setting unit can dynamically adjust the abnormal identification standard of each device, improving the adaptability and accuracy of the system. This method can timely detect abnormal behavior of devices, reduce false positives and false negatives, and improve the security of power industrial control networks.

[0052] Furthermore, the comparison of real-time data and historical thresholds helps to accurately distinguish between normal and abnormal devices. By dynamically monitoring and comparing the number of login failures, potential security risk devices can be quickly identified and timely measures can be taken to strengthen the security protection of the power industrial control network.

[0053] Furthermore, by adjusting the byte number fluctuation threshold according to the fluctuation in the number of abnormal devices, it is possible to dynamically adapt to changes in device conditions in the network, improve the system's sensitivity to abnormal situations, optimize the threshold setting, and avoid misjudgments due to excessive or small fluctuations.

[0054] Furthermore, through the collaboration of the behavior analysis unit and the combination unit, the construction module can comprehensively capture the operating characteristics and potential security threats of the power industrial control equipment, and generate digital fingerprints based on multiple dimensions. These digital fingerprints can effectively distinguish between normal and abnormal equipment, and enhance the system's ability to identify security incidents in complex environments.

[0055] Furthermore, through weighted splicing and encoder combination, the combination unit can fully integrate information from different feature dimensions, improve the ability to express device behavior characteristics, and make the constructed digital fingerprint more accurate and reliable. This method can ensure that when facing complex power industrial control equipment, its comprehensive status can be accurately reflected, providing stronger support for anomaly detection and safety warning. In addition, the preset encoder can automatically generate combination strategies, ensuring flexibility and adaptability to meet the needs of different devices and scenarios.

[0056] Furthermore, the alarm module can monitor abnormal changes in power industrial control equipment in real time and issue an alarm in time when the equipment is abnormal, avoiding potential threats or attacks on the system and ensuring the safe and stable operation of the power industrial control network. Through early warning, effective protective measures can be taken to reduce the probability of accidents and improve the reliability and security of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 This is a schematic diagram of a system for constructing dynamic digital fingerprints of assets for power industrial control network security in this embodiment;

[0058] Figure 2 A decision logic diagram for determining a first temporary device by a first determination unit in this embodiment;

[0059] Figure 3 A decision logic diagram for determining a second temporary device by a second determination subunit in this embodiment;

[0060] Figure 4 This is a decision logic diagram for the identification subunit of this embodiment to identify abnormal devices. DETAILED DESCRIPTION

[0061] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0062] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0063] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside" and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the drawings. This is merely for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.

[0064] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0065] See also Figure 1 As shown, it is a schematic diagram of the asset dynamic digital fingerprint construction system for power industrial control network security in this embodiment;

[0066] This embodiment provides a system for constructing dynamic digital fingerprints of assets for power industrial control network security, including:

[0067] The data acquisition module is used to collect the real-time data packet byte count, real-time memory usage rate and real-time login failure count during the operation of each power industrial control equipment;

[0068] A first determination module, connected to the data acquisition module, for determining a number of first temporary devices according to the number of bytes of the real-time data packet and a preset byte number fluctuation threshold;

[0069] A second determination module, which is connected to the data acquisition module and the first determination module respectively, and is used to determine a number of second temporary devices according to the number of bytes of the real-time data packet and the real-time memory usage rate of the first temporary device;

[0070] an identification module, which is connected to the data acquisition module and the second determination module respectively, and is used to identify a number of normal devices and abnormal devices according to the real-time number of login failures of the second temporary device;

[0071] An adjustment module, connected to the identification module, for adjusting the preset byte number fluctuation threshold according to the number of abnormal devices within a preset adjustment time period to form an adjusted byte number fluctuation threshold;

[0072] A construction module is connected to the data acquisition module, the adjustment module and the identification module respectively, and is used to construct a digital fingerprint according to the real-time data packet byte number, the real-time memory usage rate and the real-time login failure number of the normal device identified based on the adjustment byte number fluctuation threshold.

[0073] The data acquisition module collects the operation data of the equipment by monitoring the network communication and system status of the power industrial control equipment in real time. Specifically, it uses network sniffing technology or API interface to capture the data packets transmitted during the device communication process in real time and count the number of bytes of each data packet. At the same time, by monitoring the operating system of the device, the real-time memory usage data is obtained. In addition, by recording the login log of the device, the real-time number of login failures of the device is calculated and extracted. The real-time number of login failures refers to the number of login failures that occur within a unit of time. These data are continuously monitored and recorded to ensure that they can reflect the real-time operation status of the equipment and provide basic information for subsequent behavior analysis and digital fingerprint construction.

[0074] The preset byte number fluctuation threshold is used to determine the fluctuation range of the power industrial control equipment during the data packet transmission process. It depends on the fluctuation range of the normal network load and communication mode of the equipment. It is generally set between 1% and 10%. In this embodiment, it is set to 5%, which can effectively balance the sensitivity and false alarm rate. It can capture abnormal fluctuations in time and avoid misjudgment due to normal fluctuations, thereby ensuring the stability and accuracy of the system.

[0075] The preset adjustment time is used to determine the time window for considering data fluctuations when performing equipment status analysis. This time directly affects the ability to identify changes in equipment status and usually depends on the operating cycle of the equipment and the regularity of data changes. It is generally set between 30 minutes and 24 hours. In this embodiment, it is set to 1 hour, which can capture the changing trend of the equipment status and avoid excessive volatility of the collected data due to too short a time, thereby ensuring the reliability of the data and the accuracy of the analysis.

[0076] First, the real-time data of the power industrial control equipment is collected through the data acquisition module, including information such as the number of data packet bytes, memory usage, and number of login failures. The first determination module performs preliminary screening based on the number of real-time data packet bytes and the preset fluctuation threshold to determine the first temporary device. The second determination module further combines the number of real-time data packet bytes and memory usage to screen out the second temporary device. The identification module identifies normal devices and abnormal devices by comparing the number of real-time login failures. The adjustment module adjusts the byte number fluctuation threshold according to the fluctuation of the number of abnormal devices to optimize the system response. Finally, the construction module constructs a dynamic digital fingerprint of each device based on the adjusted threshold and device behavior data to accurately identify and track the behavior pattern of the device.

[0077] Through precise multi-level data collection, behavior analysis and threshold adjustment, the security of the power industrial control network has been significantly improved. The system can collect key behavior data of the equipment in real time, such as the number of data packet bytes, memory usage and number of login failures. Through multi-stage screening, it can accurately identify normal and abnormal devices to avoid false alarms and missed reports. The system adjusts the byte fluctuation threshold to flexibly respond to dynamic changes in device behavior to ensure the efficiency and accuracy of security detection. The dynamic digital fingerprint built based on the device behavior characteristics provides strong support for device authentication. Once the device behavior deviates, the system can respond quickly and issue an alarm to protect the system from potential security threats. It effectively solves the problem of relying on static fingerprint libraries and fixed similarity thresholds that cannot adapt to changes in network assets and identify abnormal devices in real time.

[0078] Please continue reading Figure 2 As shown, it is a decision logic diagram of the first determination unit determining the first temporary device in this embodiment;

[0079] Specifically, the first determining module includes:

[0080] A byte number fluctuation calculation unit, used to calculate a standard deviation of the number of bytes of the real-time data packet within a preset first determined time length to form a byte number fluctuation value;

[0081] A first determination unit is connected to the byte data fluctuation calculation unit, and is used to determine that the power industrial control device is the first temporary device when the byte number fluctuation value is greater than the preset byte number fluctuation threshold, so as to form a plurality of the first temporary devices.

[0082] The preset first determination time length is a time period for calculating the standard deviation of the fluctuation of the number of bytes of the device data packet, which is usually set between 10 seconds and 30 seconds, depending on the operating characteristics of the device and the network fluctuation rate. In this embodiment, it is set to 20 seconds, which can balance the sensitivity of detection and calculation efficiency, and can not only capture the short-term fluctuation of the device in time, but also avoid the influence of too long a delay, thereby improving the accuracy and response speed of monitoring.

[0083] The byte number fluctuation calculation unit calculates the standard deviation of the number of bytes of the real-time data packet of the power industrial control device within the preset first determination time length to form a byte number fluctuation value. Then, the first determination unit compares the byte number fluctuation value with the preset byte number fluctuation threshold. When the fluctuation value exceeds the threshold, it is determined that the device is a first temporary device and may be abnormal or faulty.

[0084] By calculating the fluctuation value of the number of bytes in the data packet, devices with abnormal data traffic can be effectively identified, providing a reliable basis for subsequent anomaly detection and analysis. It can dynamically adapt to the network fluctuations of the device, improve the detection sensitivity and accuracy of the system, and help to promptly discover potential security risks or equipment failures.

[0085] Specifically, the second determination module includes:

[0086] A first fluctuation calculation unit, used for calculating a standard deviation of the number of bytes of the real-time data packet within a preset second determined time length to form a first temporary fluctuation value;

[0087] A second fluctuation calculation unit, used for calculating the standard deviation of the real-time memory usage rate within the preset second determined time period to form a second temporary fluctuation value;

[0088] The second determining unit is connected to the first fluctuation calculating unit and the second fluctuation calculating unit respectively, and is used to determine a number of second temporary devices according to the first temporary fluctuation value and the second temporary fluctuation value.

[0089] The preset second determination time refers to the time window set when calculating the fluctuation of device data, which is usually set between 1 hour and 24 hours, depending on the operation cycle of the device and the frequency of data changes. In this embodiment, it is set to 3 hours, which can effectively balance the stability of device operation and real-time data fluctuations, avoid noise introduced by too short a time window, and ensure sufficient time to accurately evaluate the device status.

[0090] By analyzing the real-time operation data of the power industrial control equipment. First, the first fluctuation calculation unit calculates the standard deviation of the number of bytes of the real-time data packet within the preset second determination time length to generate a first temporary fluctuation value. Then, the second fluctuation calculation unit calculates the standard deviation of the real-time memory usage rate to generate a second temporary fluctuation value. Then, the second determination unit combines the fluctuation values ​​of the two to further screen out a number of second temporary devices. The core of this module is to comprehensively analyze the operation characteristics of the equipment through multi-dimensional fluctuation calculations and identify equipment that may have problems.

[0091] By combining the fluctuations of the number of data packet bytes and the memory usage rate, the second determination module can more accurately identify whether the device is in an abnormal state, avoiding misjudgment or missed judgment that may be caused by fluctuations in a single dimension.

[0092] Please continue reading Figure 3 As shown, it is a decision logic diagram of the second determination subunit determining the second temporary device in this embodiment;

[0093] Specifically, the second determining unit includes:

[0094] A first curve drawing subunit is used to draw a change curve within the preset second determined time period according to the first temporary fluctuation value to form a first curve;

[0095] A second curve drawing subunit is used to draw a change curve within the preset second determined time period according to the second temporary fluctuation value to form a second curve;

[0096] a consistency calculation subunit, which is connected to the first curve drawing subunit and the second curve drawing subunit respectively, and is used to calculate the cosine similarity between the first curve and the second curve to form a consistency;

[0097] The second determination subunit is connected to the consistency calculation subunit, and is used to determine the first temporary device as the second temporary device to form a plurality of second temporary devices when the consistency is less than a preset consistency threshold.

[0098] The preset consistency threshold refers to the critical value for judging whether two fluctuation change curves belong to the same type of device behavior when comparing them. It usually depends on the operating characteristics and behavior patterns of the device, especially in the case of large fluctuations or abnormal changes. It is usually set between 0.7 and 0.9 to balance sensitivity and false positive rate. In this embodiment, it is set to 0.8, which can better capture devices with significantly different fluctuation behaviors, while avoiding misjudging normal devices as abnormal devices, ensuring the accuracy of recognition and the stability of the system.

[0099] The first and second curves are generated by plotting the change curves of the first temporary fluctuation value and the second temporary fluctuation value within the preset second determination time. Then, the cosine similarity between the two curves is calculated as a consistency index. When the consistency is less than the preset consistency threshold, the second determination unit will confirm the first temporary device as the second temporary device, helping to further screen out devices that meet the specific behavior pattern.

[0100] By comparing the similarity of the fluctuation values ​​of the two groups of equipment, the equipment that may have abnormal behavior can be effectively screened out, improving the accuracy and reliability of equipment identification. By calculating the cosine similarity, the consistency of the equipment in different monitoring dimensions can be more accurately reflected, further improving the system's detection capability and sensitivity to equipment status changes in the power industrial control network.

[0101] Specifically, the identification module includes:

[0102] An average value calculation unit, used to calculate the average value of the real-time login failure times within a preset historical period to form a failure number average value;

[0103] A number fluctuation calculation unit, used to calculate the standard deviation of the number of real-time login failures within the preset historical time period to form a number fluctuation value;

[0104] a threshold setting unit, which is connected to the mean value calculation unit and the number fluctuation calculation unit respectively, and is used to set a historical number threshold according to the failure number mean value and the number fluctuation value, wherein the historical number threshold is the sum of the failure number mean value and twice the number fluctuation value;

[0105] The identification unit is connected to the threshold setting unit and is used to identify a number of normal devices and abnormal devices according to the real-time login failure times and the historical times threshold within a preset identification time.

[0106] The preset historical duration is the range of historical data used to calculate the number of failed logins, which usually depends on the system's historical analysis window for abnormal behavior. It is generally set between 7 and 30 days to ensure that the long-term behavior of the device can be reflected. In this embodiment, it is set to 15 days so that the normal and abnormal usage patterns of the device can be fully captured, while avoiding the historical information being no longer relevant due to the data being too long.

[0107] The preset identification time is a real-time data analysis window for analyzing device login failures, which depends on the real-time requirements for abnormal detection. It is usually set between 1 hour and 12 hours. In this embodiment, it is set to 6 hours, which can identify abnormal behavior of the device in a shorter time while ensuring the accuracy of the analysis results.

[0108] The average value calculation unit first calculates the average value of the number of failed logins within the preset historical duration to obtain the average value of the number of failed logins; then, the number fluctuation calculation unit calculates the standard deviation within the duration to obtain the number fluctuation value. Based on these two values, the threshold setting unit sets a historical number threshold for each device. Finally, the identification unit compares the real-time number of failed logins within the preset identification duration with the historical number threshold to identify abnormal devices and normal devices.

[0109] Through statistical analysis based on historical data, abnormal login behavior of devices can be effectively identified. By calculating the mean and standard deviation, the threshold setting unit can dynamically adjust the abnormal identification standard of each device, improving the adaptability and accuracy of the system. This method can timely detect abnormal behavior of devices, reduce false positives and false negatives, and improve the security of power industrial control networks.

[0110] Please continue reading Figure 4 As shown, it is a decision logic diagram of the identification subunit identifying abnormal devices in this embodiment;

[0111] Specifically, the identification unit includes:

[0112] A comparison subunit, used to compare the number of failed logins with the historical number threshold to form a number comparison result;

[0113] an identification subunit connected to the comparison subunit, and configured to identify the second temporary device as an abnormal device when the comparison result shows that the number of logins is greater than the historical number threshold, thereby forming a plurality of abnormal devices;

[0114] The identification subunit is further used to identify non-abnormal devices among all the power industrial control devices as normal devices to form a plurality of normal devices.

[0115] The comparison subunit compares the real-time login failure times with the historical times threshold to form a times comparison result. If the login failure times are greater than the historical times threshold, the identification subunit identifies the device as an abnormal device and forms an abnormal device list. At the same time, the identification subunit also identifies all non-abnormal devices as normal devices to form a normal device list.

[0116] Comparison of real-time data and historical thresholds helps to accurately distinguish between normal and abnormal devices. By dynamically monitoring and comparing the number of login failures, potential security risk devices can be quickly identified and timely measures can be taken to strengthen the security protection of the power industrial control network.

[0117] Specifically, the adjustment module includes:

[0118] A quantity fluctuation calculation unit, used to calculate the standard deviation of the device quantity of the abnormal device to form a quantity fluctuation value;

[0119] An adjustment module is connected to the quantity fluctuation calculation unit and is used to reduce the preset byte number fluctuation threshold according to the relative deviation between the quantity fluctuation value and the preset quantity fluctuation threshold and the preset adjustment coefficient when the quantity fluctuation value is greater than the preset quantity fluctuation threshold, so as to form an adjusted byte number fluctuation threshold, wherein the relative deviation between the quantity fluctuation value and the preset quantity fluctuation threshold is positively correlated with the adjusted byte number fluctuation threshold.

[0120] The preset number fluctuation threshold refers to the standard for determining when to trigger the adjustment of the byte number fluctuation threshold during the calculation of abnormal device number fluctuations. It depends on the system's tolerance for device number fluctuations. It is usually set to be triggered when the device number fluctuations are more significant. It is usually set between 10% and 20% of the device number. In this embodiment, it is set to 15%, which can help balance overly frequent adjustments with the stability of network security protection and prevent frequent adjustments due to too many small fluctuations.

[0121] The preset adjustment coefficient refers to the coefficient used to adjust the change range of the byte number fluctuation threshold when the number fluctuation exceeds the threshold. It depends on the system's sensitivity to the adjustment range and is usually set between 1-3. The specific value is determined according to the system's fault tolerance. In this embodiment, it is set to 2, which can control the threshold adjustment range to avoid excessive adjustments that lead to fluctuations in system performance, while ensuring that the system can respond quickly to a wide range of abnormal situations.

[0122] First, the standard deviation of the number of abnormal devices is calculated by the quantity fluctuation calculation unit to form a quantity fluctuation value. When the quantity fluctuation value exceeds the preset quantity fluctuation threshold, the adjustment module reduces the original byte number fluctuation threshold according to the relative deviation between the quantity fluctuation value and the preset quantity fluctuation threshold, combined with the preset adjustment coefficient, to form an adjusted byte number fluctuation threshold.

[0123] By adjusting the byte count fluctuation threshold according to the fluctuation in the number of abnormal devices, it is possible to dynamically adapt to changes in device conditions in the network, improve the system's sensitivity to abnormal situations, optimize threshold settings, and avoid misjudgments due to excessive or small fluctuations.

[0124] Specifically, the building blocks include:

[0125] A behavior analysis unit, configured to analyze the number of bytes of the real-time data packet, the real-time memory usage rate, and the number of real-time login failures according to a preset behavior analyzer to form a plurality of device behavior feature vectors;

[0126] A combining unit, used for combining the device behavior feature vectors through a preset encoder to form a feature combination;

[0127] A construction unit is connected to the combination unit and is used to construct the digital fingerprint according to the feature combination.

[0128] The behavior analysis unit uses a preset behavior analyzer to perform statistics and pattern recognition on data such as the number of real-time packet bytes, real-time memory usage, and real-time login failures. The analyzer processes this data in real time based on preset algorithm models (such as time series analysis, anomaly detection, machine learning models, etc.) to extract the behavioral characteristics of the device. Specifically, the behavior analyzer monitors the fluctuations and trend changes of these parameters and compares them with historical data to identify the normal and abnormal behaviors of the device within a specific period of time, and then generates device behavior feature vectors. These vectors can accurately reflect the operating status, potential failures, or security threats of the device.

[0129] A preset behavior analyzer is a tool or module designed based on specific algorithms and models. It aims to conduct in-depth analysis of the operating data of the equipment and identify potential patterns and anomalies. It is a rule-based analysis system, statistical model or machine learning algorithm. In the power industrial control network, the behavior analyzer includes a time series analysis model to evaluate the fluctuation trend of the number of bytes in the data packet, or use a clustering algorithm to detect the normal and abnormal behavior patterns of the equipment. Neural network models or support vector machine (SVM) models trained with historical data can monitor the real-time collected equipment data in real time and generate equipment behavior feature vectors. These feature vectors can be further used for tasks such as anomaly detection, equipment health assessment and security threat warning.

[0130] The behavior analysis unit first uses the preset behavior analyzer to analyze the real-time data packet byte count, real-time memory usage, and real-time login failure times to generate several device behavior feature vectors. These feature vectors reflect the operating status and abnormal behavior patterns of the device. Subsequently, the combination unit uses the preset encoder to combine these device behavior feature vectors to generate an overall feature combination. Finally, the construction unit constructs a digital fingerprint based on the generated feature combination to form a unique identifier for each power industrial control device for subsequent security analysis and identification.

[0131] Through the collaboration of the behavior analysis unit and the combination unit, the building module can comprehensively capture the operating characteristics and potential security threats of the power industrial control equipment, and generate digital fingerprints based on multiple dimensions. These digital fingerprints can effectively distinguish between normal and abnormal equipment, and enhance the system's ability to identify security incidents in complex environments.

[0132] Specifically, the combination unit includes:

[0133] A splicing subunit, used for weighted splicing of the device behavior feature vectors to form a multi-dimensional vector;

[0134] A combining subunit, connected to the splicing subunit, for combining the multi-dimensional vectors through the preset encoder to form a feature combination;

[0135] The encoder is generated by the constructor DymalicFinger(Q, K, V) = Concat(DymalicFinger1, DymalicFinger2, ..., DymalicFingerh) WO, where WO is the linear transformation matrix of behavior analysis, DymalicFinger1 represents the fingerprint matrix of the first single attention, and the others are deduced to the hth;

[0136] Q (query vector), K (key vector) and V (value vector) are calculated through the self-attention mechanism and are used to establish relationships and weights between multiple features. Q is used to query relevant information, K is used to match queries, and V is the output obtained by weighting the matches. Concat refers to splicing multiple vectors or matrices into a larger vector according to a specific dimension. In this embodiment, multiple single attention matrices (such as DymalicFinger1, DymalicFinger2, ..., DymalicFingerh) are spliced ​​to form a comprehensive dynamic fingerprint matrix. Finally, WO is a linear transformation matrix, and the spliced ​​matrix is ​​finally processed to obtain the desired feature combination. This process effectively extracts the behavioral characteristics of power industrial control equipment through weighted splicing and transformation, and constructs an accurate dynamic digital fingerprint.

[0137] The final processing results in the expected combination:

[0138] Self-Attention Mechanism: Self-Attention mechanism weights each feature by calculating the relationship between the query vector (Q), key vector (K), and value vector (V).

[0139] Q (query vector) is used to find relevant information.

[0140] K (key vector) is used to match the query.

[0141] V (value vector) is the final weighted output, which is a weighted combination based on the query and match situations.

[0142] In this way, the network can establish connections between different parts of the input, thereby effectively capturing the relationship between multi-dimensional features.

[0143] Concatenation: Multiple attention matrices (such as DymalicFinger1, DymalicFinger2, ..., DymalicFingerh) are concatenated to form a comprehensive feature vector. This process is equivalent to concatenating each single attention matrix together according to a specific dimension to obtain a larger matrix or vector.

[0144] This concatenation operation combines feature information at different levels, allowing the model to comprehensively consider relationship information at different levels.

[0145] Linear transformation (WO): The concatenated comprehensive feature matrix is ​​processed by a linear transformation matrix WO. This transformation matrix can be a weight matrix, which aims to map the concatenated multi-dimensional feature vector to the final required feature space to obtain the final "dynamic digital fingerprint".

[0146] The purpose of linear transformation is to adjust the combination of features through training learned weights to make it meet the task requirements and further improve the accuracy and recognition ability of fingerprints.

[0147] First, the concatenation subunit performs weighted concatenation of multiple device behavior feature vectors to form a data vector containing multiple dimensions. This concatenation process can integrate device behavior information from different sources, such as the number of data packet bytes, memory usage, and number of login failures. Then, the combination subunit further combines the concatenated multi-dimensional vectors through a preset encoder to generate a more comprehensive feature combination. This feature combination can accurately reflect the overall behavior characteristics of the device and provide an important basis for the subsequent construction of digital fingerprints.

[0148] Through weighted splicing and encoder combination, the combination unit can fully integrate information from different feature dimensions, improve the ability to express device behavior characteristics, and make the constructed digital fingerprint more accurate and reliable. This method can ensure that when facing complex power industrial control equipment, its comprehensive status can be accurately reflected, providing stronger support for anomaly detection and safety warning. In addition, the preset encoder can automatically generate combination strategies, ensuring flexibility and adaptability to meet the needs of different devices and scenarios.

[0149] Specifically, the asset dynamic digital fingerprint construction system for power industrial control network security also includes:

[0150] An alarm module is connected to the adjustment module and the identification module respectively, and is used to issue an alarm according to the abnormal device formed based on the adjustment byte number fluctuation threshold.

[0151] Alerts include: abnormal device alerts, which alert you when device behavior is abnormal (such as the number of failed logins or abnormal memory usage); device fluctuation limit alerts, which are triggered when the device's byte count fluctuates beyond a preset threshold; security risk alerts, which issue early warnings when behaviors similar to attack patterns are identified; device abnormality frequent alerts, which are used for devices that frequently experience abnormalities; overload alerts, which are triggered when a device is overloaded for a long time; and device failure alerts, which detect device failures or system problems. These alerts ensure the security and stability of the power industrial control network and help managers take timely countermeasures.

[0152] The alarm module monitors the changes of abnormal devices by connecting with the adjustment module and the identification module. When the identification module identifies an abnormal device based on the adjustment byte number fluctuation threshold, the alarm module issues an alarm based on this information to remind relevant personnel to deal with the abnormal situation in a timely manner, thereby effectively improving the system's monitoring and response capabilities.

[0153] The alarm module can monitor abnormal changes in power industrial control equipment in real time and issue an alarm in time when the equipment is abnormal, avoiding potential threats or attacks on the system and ensuring the safe and stable operation of the power industrial control network. Through early warning, effective protective measures can be taken to reduce the probability of accidents and improve the reliability and security of the network.

[0154] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0155] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An asset dynamic digital fingerprint construction system for power industrial control network security, characterized in that: include: The data acquisition module is used to collect the real-time data packet byte count, real-time memory usage rate and real-time login failure count during the operation of each power industrial control equipment; A first determination module, connected to the data acquisition module, for determining a number of first temporary devices according to the number of bytes of the real-time data packet and a preset byte number fluctuation threshold; A second determination module, which is connected to the data acquisition module and the first determination module respectively, and is used to determine a number of second temporary devices according to the number of bytes of the real-time data packet and the real-time memory usage rate of the first temporary device; an identification module, which is connected to the data acquisition module and the second determination module respectively, and is used to identify a number of normal devices and abnormal devices according to the real-time number of login failures of the second temporary device; An adjustment module, connected to the identification module, for adjusting the preset byte number fluctuation threshold according to the number of abnormal devices within a preset adjustment time period to form an adjusted byte number fluctuation threshold; A construction module is connected to the data acquisition module, the adjustment module and the identification module respectively, and is used to construct a digital fingerprint according to the real-time data packet byte number, the real-time memory usage rate and the real-time login failure number of the normal device identified based on the adjustment byte number fluctuation threshold.

2. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 1 is characterized in that: The first determining module comprises: A byte number fluctuation calculation unit, used to calculate a standard deviation of the number of bytes of the real-time data packet within a preset first determined time length to form a byte number fluctuation value; A first determination unit is connected to the byte number fluctuation calculation unit, and is used to determine that the power industrial control device is the first temporary device when the byte number fluctuation value is greater than the preset byte number fluctuation threshold, so as to form a plurality of the first temporary devices.

3. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 2 is characterized in that: The second determining module comprises: A first fluctuation calculation unit, used for calculating a standard deviation of the number of bytes of the real-time data packet within a preset second determined time length to form a first temporary fluctuation value; A second fluctuation calculation unit, used for calculating the standard deviation of the real-time memory usage rate within the preset second determined time period to form a second temporary fluctuation value; The second determining unit is connected to the first fluctuation calculating unit and the second fluctuation calculating unit respectively, and is used to determine a number of second temporary devices according to the first temporary fluctuation value and the second temporary fluctuation value.

4. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 3 is characterized in that: The second determining unit includes: A first curve drawing subunit is used to draw a change curve within the preset second determined time period according to the first temporary fluctuation value to form a first curve; A second curve drawing subunit is used to draw a change curve within the preset second determined time period according to the second temporary fluctuation value to form a second curve; a consistency calculation subunit, which is connected to the first curve drawing subunit and the second curve drawing subunit respectively, and is used to calculate the cosine similarity between the first curve and the second curve to form a consistency; The second determination subunit is connected to the consistency calculation subunit, and is used to determine the first temporary device as the second temporary device to form a plurality of second temporary devices when the consistency is less than a preset consistency threshold.

5. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 4 is characterized in that: The identification module comprises: An average value calculation unit, used to calculate the average value of the real-time login failure times within a preset historical period to form a failure number average value; A number fluctuation calculation unit, used to calculate the standard deviation of the number of real-time login failures within the preset historical time period to form a number fluctuation value; a threshold setting unit, which is connected to the mean value calculation unit and the number fluctuation calculation unit respectively, and is used to set a historical number threshold according to the failure number mean value and the number fluctuation value; The identification unit is connected to the threshold setting unit and is used to identify a number of normal devices and abnormal devices according to the number of real-time login failures within a preset identification time and the historical number threshold.

6. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 5 is characterized in that: The identification unit comprises: A comparison subunit, used to compare the number of failed logins with the historical number threshold to form a number comparison result; an identification subunit connected to the comparison subunit, and configured to identify the second temporary device as an abnormal device when the comparison result shows that the number of failed logins is greater than the historical number threshold, thereby forming a plurality of abnormal devices; The identification subunit is further used to identify non-abnormal devices among all the power industrial control devices as normal devices to form a plurality of normal devices.

7. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 6 is characterized in that: The adjustment module comprises: A quantity fluctuation calculation unit, used to calculate the standard deviation of the device quantity of the abnormal device to form a quantity fluctuation value; An adjustment module is connected to the quantity fluctuation calculation unit and is used to reduce the preset byte number fluctuation threshold according to the relative deviation between the quantity fluctuation value and the preset quantity fluctuation threshold and the preset adjustment coefficient when the quantity fluctuation value is greater than the preset quantity fluctuation threshold, so as to form an adjusted byte number fluctuation threshold.

8. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 7 is characterized in that: The building blocks include: A behavior analysis unit, configured to analyze the number of bytes of the real-time data packet, the real-time memory usage rate, and the number of real-time login failures according to a preset behavior analyzer to form a plurality of device behavior feature vectors; A combining unit, used for combining the device behavior feature vectors through a preset encoder to form a feature combination; A construction unit is connected to the combination unit and is used to construct the digital fingerprint according to the feature combination.

9. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 8 is characterized in that: The combined unit comprises: A splicing subunit, used for weighted splicing of the device behavior feature vectors to form a multi-dimensional vector; A combining subunit, connected to the splicing subunit, for combining the multi-dimensional vectors through the preset encoder to form a feature combination; The preset encoder is generated by a preset constructor.

10. The asset dynamic digital fingerprint construction system for power industrial control network security according to claim 1 is characterized in that: The asset dynamic digital fingerprint construction system for power industrial control network security also includes: An alarm module is connected to the adjustment module and the identification module respectively, and is used to issue an alarm according to the abnormal device formed based on the adjustment byte number fluctuation threshold.

Citation Information

Patent Citations

  • A Hash fingerprint based on position information and DNA information, and a construction method and application thereof

    CN109214831A

  • A system and method for on-chain asset coherence confirmation

    CN109658104A

  • Token management method, supply chain financial system and electronic device

    CN110443701A