An industrial control network intelligent exposure surface identification and risk assessment system and method

By designing an intelligent exposed face recognition and risk assessment system in the industrial control network, using data acquisition, processing and management modules, combined with the adjustment function of the analysis module, the problem of the abnormal equipment operating environment in the prior art is solved, and the accuracy and efficiency of exposed face recognition are improved.

CN119628967BActive Publication Date: 2025-05-13BEIJING HUADIAN TIANREN ELECTRIC POWER CONTROL TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510147999.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-13
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

The prior art cannot adjust the operating environment of abnormal equipment while identifying exposed surfaces based on the operation of each device in the industrial control network, affecting the efficiency of exposed surface recognition.

Method used

An intelligent exposed face recognition and risk assessment system for industrial control networks is designed, including data acquisition module, data processing module, equipment management module and analysis module. By collecting the original data of the device, determining the redundant parameters and data stability parameters, setting data labels, and adjusting the number of servers and repeaters based on the statistical number of data labels and fluctuations to adjust the operating environment of the device.

Benefits of technology

It realizes the timely adjustment of the equipment operating environment when identifying exposed faces, improves the accuracy and efficiency of exposed face recognition, and ensures the stable operation of industrial control network equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119628967B_ABST
    Figure CN119628967B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of industrial control network security technology, and in particular to an industrial control network intelligent exposure surface identification and risk assessment system and method, comprising a data acquisition module, a data processing module, a device management module and an analysis module. Based on the operating parameters of each device in the industrial control network monitored by the data acquisition module, a data label is set for each device, each data label represents the operating status of the corresponding device, and each device is processed based on the number and fluctuation parameters of the devices of each data label. When it is determined that the operation of each device is abnormal, the operating environment of each device is adjusted in time to ensure the stable operation of each device in the industrial control network, and the devices with exposed surfaces are discovered in time, and each device is adaptively processed, thereby improving the accuracy of exposure surface identification, and thus improving the exposure surface identification efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control network security, and in particular to an industrial control network intelligent exposure surface identification and risk assessment system and method. Background Art

[0002] Intelligent exposure identification and risk assessment of industrial control networks, and timely discovery and repair of potential security vulnerabilities are important means to ensure the security of industrial control networks.

[0003] For example, Chinese patent publication number: CN118869307A discloses a network attack detection method and system for numerical control equipment, including a protection unit, an intranet monitoring unit, a sniffer and a network monitoring unit; the sniffer simulates the operation status of the numerical control equipment and captures the network communication content directed to the numerical control equipment; the network monitoring unit compares these communication contents with normal communication contents and uses deep packet inspection and artificial intelligence algorithms to identify abnormal behaviors; when an abnormality is detected, the system triggers a first-level or second-level alarm signal to notify the analysis unit for further processing;

[0004] However, the above technical solution has the following problems:

[0005] It is impossible to adjust the operating environment of each abnormal device while identifying the exposed surface based on the operating conditions of each device in the industrial control network, which affects the identification efficiency of the exposed surface. Summary of the invention

[0006] To this end, the present invention provides an industrial control network intelligent exposure surface identification and risk assessment system and method, which is used to overcome the problem in the prior art that it is impossible to adjust the operating environment of each abnormal device while identifying the exposure surface based on the operating conditions of each device in the industrial control network, thereby affecting the identification efficiency of the exposure surface.

[0007] In one aspect, the present invention provides an industrial control network intelligent exposure surface identification and risk assessment system, comprising:

[0008] Data acquisition module, which is used to collect raw data of each device in the industrial control network, including data flow and device logs;

[0009] A data processing module connected to the data acquisition module, used to determine redundant parameters based on the acquired logs of each device and to determine data stability parameters based on the historical data flow within each preset inspection period;

[0010] A device management module, which is connected to the data acquisition module and the data processing module respectively, and is used to set a data label for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period;

[0011] An analysis module is connected to the device management module and is used to determine the fluctuation parameter based on the data stability parameter of each device with hidden dangers, to issue an alarm message of the existence of an exposed surface of each abnormally operating device based on the statistical number of devices with each data tag and the fluctuation parameter, to adjust the number of servers connected to each device to a corresponding value, or to adjust the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter.

[0012] Furthermore, the device management module is used to set a data label for each device based on the data flow of a single device within a preset inspection period, including:

[0013] If the data flow is less than or equal to the first preset data flow, the data tag of the device is determined as a stable operation device;

[0014] If the data flow is less than or equal to the second preset data flow and greater than the first preset data flow, a redundant parameter is determined based on the acquired logs of each device, and a data tag is set for a single device based on the redundant parameter;

[0015] If the data flow is greater than the second preset data flow, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for the single device based on the data stability parameter.

[0016] Furthermore, the data processing module is used to determine the redundancy parameter, traverse each transmission log within a preset inspection period to determine the ratio of the amount of duplicate data to the total amount of data in each transmission log, and obtain the redundancy parameter;

[0017] The device management module is used to set a data tag for a single device based on redundant parameters, including:

[0018] If the redundant parameter is less than or equal to the preset redundant parameter, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for a single device based on the data stability parameter;

[0019] If the redundancy parameter is greater than the preset redundancy parameter, the data tag of the individual device is determined as a pending operation device.

[0020] Furthermore, the data processing module is used to determine the data stability parameter, solve the variance of each historical data flow in each preset inspection period, and obtain the data stability parameter;

[0021] The device management module is used to set a data tag for a single device based on a data stability parameter, including:

[0022] If the data stability parameter is less than or equal to the preset data stability parameter, the data tag of the single device is determined as an abnormally operating device;

[0023] If the data stability parameter is greater than the preset data stability parameter, the data tag of the individual device is determined as a hidden danger operating device.

[0024] Furthermore, the analysis module is used to process each device based on the statistical number of devices of each data tag, including:

[0025] If the number of stably operating devices is the largest, the operation of each device is determined to be qualified, and each device is controlled to continue to operate using the current operating parameters;

[0026] If the number of pending operation devices is the largest, adjusting the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device;

[0027] If the number of hidden danger operating equipment is the largest, the fluctuation parameter is determined based on the data stable parameter of each hidden danger operating equipment, and each equipment is processed based on the fluctuation parameter;

[0028] If the number of abnormally operating devices is the largest, it is determined that the operation of each device is abnormal, and an alarm message is issued indicating that each abnormally operating device has an exposed surface.

[0029] Further, the analysis module is used to adjust the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device, wherein:

[0030] The increase range of the first preset data flow and the second preset data flow determined based on the number of devices is proportional to the number of devices.

[0031] Furthermore, the analysis module is used to process each device based on the fluctuation parameter.

[0032] To determine the fluctuation parameter, obtain the difference between the maximum value of the data stable parameter of each hidden danger operation equipment and the average value of the data stable parameter of each hidden danger operation equipment, and obtain the fluctuation parameter;

[0033] If the fluctuation parameter is less than or equal to the preset fluctuation parameter, the number of servers connected to each device is adjusted to a corresponding value based on the number of devices running with hidden dangers;

[0034] If the fluctuation parameter is greater than the preset fluctuation parameter, the number of repeaters connected to each device is adjusted to a corresponding value based on the fluctuation parameter.

[0035] Furthermore, the analysis module is used to adjust the number of servers connected to each device to a corresponding value based on the number of devices running with hidden dangers, wherein:

[0036] The number determined by the analysis module is proportional to the number of devices with hidden dangers.

[0037] Further, the analysis module is used to adjust the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter, wherein:

[0038] The increase in the number of repeaters connected to each device determined by the analysis module is proportional to the fluctuation parameter.

[0039] On the other hand, the present invention also provides a risk assessment method using the above-mentioned industrial control network intelligent exposure surface identification and risk assessment system, comprising:

[0040] Collect the original data of each device in the industrial control network, including data flow and device logs;

[0041] Determine redundant parameters based on the acquired logs of each device, and determine data stability parameters based on the historical data flow within each preset inspection period;

[0042] Setting data labels for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period;

[0043] Determine the fluctuation parameter based on the data stable parameter of each hidden danger running device, issue the alarm information of the exposed surface of each abnormal running device based on the statistical number of devices of each data tag and the fluctuation parameter, adjust the number of servers connected to each device to the corresponding value, or adjust the number of repeaters connected to each device to the corresponding value based on the fluctuation parameter;

[0044] Or, determine whether the operation of each device is qualified, and control each device to continue to operate using the current operating parameters.

[0045] Compared with the prior art, the beneficial effect of the present invention lies in that, based on the operating parameters of each device in the industrial control network monitored by the data acquisition module, a data label is set for each device, each data label represents the operating status of the corresponding device, and each device is processed based on the statistical number and fluctuation parameters of each data label, so that when the operation of each device is determined to be abnormal, the operating environment of each device is adjusted in time to ensure the stable operation of each device in the industrial control network, timely discover the equipment with exposed surfaces, adaptively process each device, improve the accuracy of exposed surface identification, and thus improve the identification efficiency of exposed surfaces.

[0046] Furthermore, by acquiring the data flow frequency related to the device, the data label of the device in the current preset inspection cycle is monitored. The data label includes stable operation equipment, pending operation equipment, hidden danger operation equipment and abnormal operation equipment. The stable operation equipment represents that the equipment is stable in operation. When the data flow is less than or equal to the second preset data flow and greater than the first preset data flow, the data flow of a single device is abnormally high. At this time, the redundant parameter is determined to divide the data label of the single device in detail based on the redundant parameter; the redundant parameter represents the repeated transmission of data transmitted by the device. When the redundant parameter is greater than the preset redundant parameter, in this case, there is a large amount of redundant data due to the device itself. Since the data flow is high due to multiple repeated transmissions, the device in this case is divided into a pending operation device, and the pending operation device is a device with too high redundant data; when the redundant parameter is less than or equal to the preset redundant parameter, the device transmission is normal. In this case, since the single device is a device with too many paths, a single device has multiple network interfaces, multiple physical lines and multiple different communication protocols. In this case, the complexity of routing selection increases due to too many paths, and the network will switch between different paths many times, causing data transmission anomalies and resulting in abnormally high transmission traffic. When the data traffic is greater than the second preset data traffic, the data traffic is abnormally too high. In this case, the data stability parameter is determined, and the data label of the single device is determined based on the data stability parameter. The data stability parameter characterizes the data traffic fluctuation of the single device in each preset inspection cycle. When the data stability parameter is less than or equal to the preset data stability parameter, the single device has stable transmission in each historical preset inspection cycle, and the data label of the single device is determined as an abnormally operating device. The abnormally operating device characterizes the risk of an exposed surface in the single device. When the data stability parameter is greater than the preset data stability parameter, the data traffic amplitude of the single device is large, and the data label of the single device is determined as a hidden danger operating device. The data labels of each device are accurately divided to characterize the actual operation of the equipment in the industrial control network, thereby improving the accuracy of exposed surface identification, and thereby improving the efficiency of exposed surface identification.

[0047] Furthermore, each device is processed based on the number of devices with each data label that is statistically obtained. When the number of devices in stable operation is the largest, each device is in stable operation, and each device is controlled to continue to operate using the current operating parameters. When the number of pending operating devices is the largest, there are devices with a large amount of redundant data due to high device heterogeneity. In this case, the first preset data flow and the second preset data flow for determining the data label of the device are adjusted to coordinate the evaluation criteria of the device according to the actual situation of each device, thereby improving the accuracy of the equipment rating. When the number of devices in operation with hidden dangers is the largest, each device is processed based on the fluctuation parameter, which characterizes the deviation of the data stability parameter of each device in operation with hidden dangers. When the fluctuation parameter is less than or equal to the preset fluctuation parameter, each device in operation with hidden dangers is processed based on the fluctuation parameter. There is a situation where the stable data flow is too large. At this time, the number of servers is adjusted to ensure the effective transmission of each transmission data and reduce the transmission failure rate. When the fluctuation parameter is greater than the preset fluctuation parameter, the electromagnetic interference of the external environment causes the various devices to have different degrees of large transmission data. The electromagnetic interference causes the signal transmitted by the device to be distorted, making it impossible for the receiver to correctly identify the data, resulting in the device repeatedly sending data or sending erroneous data, increasing the data flow. At this time, the number of repeaters is increased to improve the stability of communication between devices. By eliminating signal attenuation and distortion, it is ensured that the devices can communicate continuously and stably, reducing communication interruptions or errors caused by signal weakening. While ensuring the stable operation of the industrial control network, the error rate of exposed surface identification is reduced, thereby improving the identification efficiency of the exposed surface. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 This is a module block diagram of the industrial control network intelligent exposure surface identification and risk assessment system according to an embodiment of the present invention;

[0049] Figure 2 This is a flowchart of the steps of the method for intelligent exposure surface identification and risk assessment of industrial control networks according to an embodiment of the present invention;

[0050] Figure 3 A logical decision diagram of setting a data label for each device based on data traffic by a device management module in an embodiment of the present invention;

[0051] Figure 4 This is a logic decision diagram for setting a data label for a single device based on redundant parameters by a device management module according to an embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0053] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0054] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the term "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0055] See also Figure 1 , Figure 2 , Figure 3 as well as Figure 4 As shown, they are respectively a module block diagram of the industrial control network intelligent exposure surface identification and risk assessment system according to an embodiment of the present invention, a step flow chart of the industrial control network intelligent exposure surface identification and risk assessment method, a logical decision diagram of the device management module dividing the operation level of the device based on data flow, and a logical decision diagram of the device management module dividing the operation level of a single device based on redundant parameters; an industrial control network intelligent exposure surface identification and risk assessment system and method according to an embodiment of the present invention, including:

[0056] See also Figure 1 As shown, it is a module block diagram of the industrial control network intelligent exposure surface identification and risk assessment system according to an embodiment of the present invention. The industrial control network intelligent exposure surface identification and risk assessment system according to the present invention includes:

[0057] Data acquisition module, which is used to collect raw data of each device in the industrial control network, including data flow and device logs;

[0058] A data processing module connected to the data acquisition module, used to determine redundant parameters based on the acquired logs of each device and to determine data stability parameters based on the historical data flow within each preset inspection period;

[0059] A device management module, which is connected to the data acquisition module and the data processing module respectively, and is used to set a data label for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period;

[0060] An analysis module is connected to the device management module and is used to determine the fluctuation parameter based on the data stability parameter of each device with hidden dangers, to issue an alarm message of the existence of an exposed surface of each abnormally operating device based on the statistical number of devices with each data tag and the fluctuation parameter, to adjust the number of servers connected to each device to a corresponding value, or to adjust the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter.

[0061] Specifically, based on the operating parameters of each device in the industrial control network monitored by the data acquisition module, a data label is set for each device, each data label represents the operating status of the corresponding device, and each device is processed based on the statistical number of devices and fluctuation parameters of each data label, so that when the operation of each device is determined to be abnormal, the operating environment of each device can be adjusted in time to ensure the stable operation of each device in the industrial control network, timely discover the equipment with exposed surfaces, and adaptively process each device, thereby improving the accuracy of exposed surface identification, thereby improving the identification efficiency of exposed surfaces.

[0062] See also Figure 2 As shown, they are respectively a flowchart of the steps of the method for intelligent exposure surface identification and risk assessment of industrial control networks according to an embodiment of the present invention. The method for intelligent exposure surface identification and risk assessment of industrial control networks according to the present invention comprises:

[0063] S1, collects the original data of each device in the industrial control network, including data flow and device logs;

[0064] S2, determining redundant parameters based on the acquired logs of each device, and determining data stability parameters based on the historical data flow within each preset inspection period;

[0065] S3, setting a data label for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period;

[0066] S4, determining the fluctuation parameter based on the data stable parameter of each hidden danger running device, issuing the alarm information of the exposed surface of each abnormal running device based on the number of devices with each data tag and the fluctuation parameter, adjusting the number of servers connected to each device to a corresponding value, or adjusting the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter;

[0067] Or, determine whether the operation of each device is qualified, and control each device to continue to operate using the current operating parameters.

[0068] Please refer to Figure 3 As shown in the figure, they are respectively logic decision diagrams for classifying the operation level of the device based on data flow by the device management module of the embodiment of the present invention. The device management module of the present invention is used to set a data label for each device based on the data flow of a single device within a preset inspection period, including:

[0069] If the data flow is less than or equal to the first preset data flow, the data tag of the device is determined as a stable operation device;

[0070] If the data flow is less than or equal to the second preset data flow and greater than the first preset data flow, a redundant parameter is determined based on the acquired logs of each device, and a data tag is set for a single device based on the redundant parameter;

[0071] If the data flow is greater than the second preset data flow, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for the single device based on the data stability parameter.

[0072] Specifically, the first preset data flow rate is selected within the interval [0.5, 1], and the second preset data flow rate is selected within the interval [5, 10], and the unit is GB.

[0073] See also Figure 4 As shown, they are respectively logic decision diagrams for classifying the operation level of a single device based on redundant parameters by the device management module of an embodiment of the present invention, and the data processing module of the present invention is used to determine the redundant parameters, traverse each transmission log within a preset inspection period to determine the ratio of the amount of duplicate data to the total amount of data in each transmission log, and obtain the redundant parameters;

[0074] The device management module is used to set a data tag for a single device based on redundant parameters, including:

[0075] If the redundant parameter is less than or equal to the preset redundant parameter, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for a single device based on the data stability parameter;

[0076] If the redundancy parameter is greater than the preset redundancy parameter, the data tag of the individual device is determined as a pending operation device.

[0077] Specifically, the preset redundant parameter is selected within the interval [0.45, 0.55].

[0078] Specifically, the data processing module is used to determine the data stability parameter, solve the variance of each historical data flow in each preset inspection period, and obtain the data stability parameter;

[0079] The device management module is used to set a data tag for a single device based on a data stability parameter, including:

[0080] If the data stability parameter is less than or equal to the preset data stability parameter, the data tag of the single device is determined as an abnormally operating device;

[0081] If the data stability parameter is greater than the preset data stability parameter, the data tag of the individual device is determined as a hidden danger operating device.

[0082] Specifically, the preset data stability parameter is selected within the interval [0.5Q0, 0.8Q0], and Q0 is the average value of each data flow of the device in each historical preset inspection cycle.

[0083] Specifically, by acquiring the data flow frequency related to the device, the data label of the device in the current preset inspection cycle is monitored. The data label includes stable operation equipment, pending operation equipment, hidden danger operation equipment and abnormal operation equipment. The stable operation equipment represents that the equipment is stable. When the data flow is less than or equal to the second preset data flow and greater than the first preset data flow, the data flow of a single device is abnormally high. At this time, the redundant parameter is determined to divide the data label of the single device in detail based on the redundant parameter; the redundant parameter represents the repeated transmission of data transmitted by the device. When the redundant parameter is greater than the preset redundant parameter, in this case, there is a large amount of redundant data due to the device itself. Since the data flow is high due to multiple repeated transmissions, the device in this case is divided into a pending operation device, and the pending operation device is a device with too high redundant data; when the redundant parameter is less than or equal to the preset redundant parameter, the device transmission is normal. In this case, since a single device is a device with too many paths, a single device has multiple network interfaces, multiple physical lines and multiple different communication protocols. In this case, the complexity of routing selection increases due to too many paths, and the network will switch between different paths many times, causing data transmission anomalies and resulting in abnormally high transmission traffic. When the data traffic is greater than the second preset data traffic, the data traffic is abnormally too high. In this case, the data stability parameter is determined, and the data label of the single device is determined based on the data stability parameter. The data stability parameter characterizes the data traffic fluctuation of the single device in each preset inspection cycle. When the data stability parameter is less than or equal to the preset data stability parameter, the single device has stable transmission in each historical preset inspection cycle, and the data label of the single device is determined as an abnormally operating device. The abnormally operating device characterizes the risk of an exposed surface in the single device. When the data stability parameter is greater than the preset data stability parameter, the data traffic amplitude of the single device is large, and the data label of the single device is determined as a hidden danger operating device. The data labels of each device are accurately divided to characterize the actual operation of the equipment in the industrial control network, thereby improving the accuracy of exposed surface identification, and thereby improving the efficiency of exposed surface identification.

[0084] Specifically, the analysis module is used to process each device based on the number of devices with each data tag counted, including:

[0085] If the number of stably operating devices is the largest, the operation of each device is determined to be qualified, and each device is controlled to continue to operate using the current operating parameters;

[0086] If the number of pending operation devices is the largest, adjusting the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device;

[0087] If the number of hidden danger operating equipment is the largest, the fluctuation parameter is determined based on the data stable parameter of each hidden danger operating equipment, and each equipment is processed based on the fluctuation parameter;

[0088] If the number of abnormally operating devices is the largest, it is determined that the operation of each device is abnormal, and an alarm message is issued indicating that each abnormally operating device has an exposed surface.

[0089] Specifically, the analysis module is used to adjust the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device, wherein:

[0090] The increase range of the first preset data flow and the second preset data flow determined based on the number of devices is proportional to the number of devices.

[0091] In this embodiment, optionally,

[0092] comparing the number of devices connected to the single pending operation device with the first preset number of devices and the second preset number of devices;

[0093] If the number of devices is less than or equal to the first preset number of devices, the first preset data flow rate is adjusted to 1.11 times the initial first preset data flow rate, and the second preset data flow rate is adjusted to 1.12 times the initial second preset data flow rate;

[0094] If the number of devices is less than or equal to the second preset number of devices and greater than the first preset number of devices, the first preset data flow rate is adjusted to 1.21 times the initial first preset data flow rate, and the second preset data flow rate is adjusted to 1.22 times the initial second preset data flow rate;

[0095] If the number of devices is greater than the second preset number of devices, the first preset data flow rate is adjusted to 1.28 times the initial first preset data flow rate, and the second preset data flow rate is adjusted to 1.29 times the initial second preset data flow rate;

[0096] The first preset number of devices is 5, and the second preset number of devices is 15.

[0097] Specifically, the analysis module is used to process each device based on the fluctuation parameter, including:

[0098] To determine the fluctuation parameter, obtain the difference between the maximum value of the data stable parameter of each hidden danger operation equipment and the average value of the data stable parameter of each hidden danger operation equipment, and obtain the fluctuation parameter;

[0099] If the fluctuation parameter is less than or equal to the preset fluctuation parameter, the number of servers connected to each device is adjusted to a corresponding value based on the number of devices running with hidden dangers;

[0100] If the fluctuation parameter is greater than the preset fluctuation parameter, the number of repeaters connected to each device is adjusted to a corresponding value based on the fluctuation parameter.

[0101] Specifically, the preset fluctuation parameter L0 is selected within the interval [0.6J0, 0.7J0], and J0 is the average value of the data stability parameters of each hidden danger operating equipment.

[0102] Specifically, each device is processed based on the number of devices with each data label that is statistically analyzed. When the number of devices in stable operation is the largest, each device is in stable operation, and each device is controlled to continue to operate using the current operating parameters. When the number of pending operating devices is the largest, there are devices with a large amount of redundant data due to high device heterogeneity. In this case, the first preset data flow and the second preset data flow for determining the data label of the device are adjusted to coordinate the evaluation criteria of the device according to the actual situation of each device, thereby improving the accuracy of the equipment rating. When the number of devices with hidden dangers is the largest, each device is processed based on the fluctuation parameter, which characterizes the deviation of the data stability parameter of each hidden danger operating device. When the fluctuation parameter is less than or equal to the preset fluctuation parameter, each hidden danger operating device is There is a situation where the stable data flow is too large. At this time, the number of servers is adjusted to ensure the effective transmission of each transmission data and reduce the transmission failure rate. When the fluctuation parameter is greater than the preset fluctuation parameter, the electromagnetic interference of the external environment causes the various devices to have different degrees of large transmission data. The electromagnetic interference causes the signal transmitted by the device to be distorted, making it impossible for the receiver to correctly identify the data, resulting in the device repeatedly sending data or sending erroneous data, increasing the data flow. At this time, the number of repeaters is increased to improve the stability of communication between devices. By eliminating signal attenuation and distortion, it is ensured that the devices can communicate continuously and stably, reducing communication interruptions or errors caused by signal weakening. While ensuring the stable operation of the industrial control network, the error rate of exposed surface identification is reduced, thereby improving the identification efficiency of the exposed surface.

[0103] Specifically, the analysis module is used to adjust the number of servers connected to each device to a corresponding value based on the number of devices running with hidden dangers, wherein:

[0104] The number of servers determined based on the number of vulnerable operating devices is proportional to the number of vulnerable operating devices.

[0105] In this embodiment, optionally,

[0106] comparing the number of the hidden danger operating equipment with the first preset operating number and the second preset operating number;

[0107] If the number of devices with hidden dangers is less than or equal to the first preset number of devices, the number of servers connected to each device is adjusted to 1.12 times the initial number of servers;

[0108] If the number of devices with hidden dangers is less than or equal to the second preset number of devices and greater than the first preset number of devices, the number of servers connected to each device is adjusted to 1.23 times the initial number of servers;

[0109] If the number of devices with hidden dangers is greater than the second preset number of devices, the number of servers connected to each device is adjusted to 1.29 times the initial number of servers;

[0110] The first preset running quantity is 0.7N0, and the second preset running quantity is 0.8N0, where N0 is the total quantity of each device.

[0111] Specifically, the analysis module is used to adjust the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter, wherein:

[0112] The increase in the number of repeaters connected to each device determined based on the fluctuation parameter is proportional to the fluctuation parameter.

[0113] In this embodiment, optionally,

[0114] Comparing the fluctuation parameter with a first preset comparison parameter and a second preset comparison parameter;

[0115] If the fluctuation parameter is less than or equal to the first preset comparison parameter, the number of repeaters of each device is adjusted to 1.13 times the initial number of repeaters;

[0116] If the fluctuation parameter is less than or equal to the second preset comparison parameter and greater than the first preset comparison parameter, the number of repeaters of each device is adjusted to 1.23 times the initial number of repeaters;

[0117] If the fluctuation parameter is greater than the second preset comparison parameter, the number of repeaters of each device is adjusted to 1.33 times the initial number of repeaters;

[0118] The first preset comparison parameter is 1.5L0, and the second preset comparison parameter is 2.6L0.

[0119] Specifically, the headless browser tool Selenium WebDriver, Mozilla Firefox browser and its driver GeckoDriver are used to automatically access the specified URL and generate webpage screenshots for abnormally running devices;

[0120] Specifically, the URL of the abnormally running device is obtained, the URL is input into the WebDriver instance, and the URL is loaded and the page is rendered in the background by calling the browser and its plug-in.

[0121] After the page rendering is completed, the screenshot file stream is output and written to the specified directory by the JAVA program for program analysis and manual review.

[0122] Specifically, when using Selenium to start the Chrome browser, you need to add the --headless parameter to enable the headless mode; if the headless browser does not work properly due to GPU-related issues, you can disable GPU acceleration by adding the --disable-gpu parameter to ensure that the screenshot file can be obtained.

[0123] Specifically, by setting an implicit wait or an explicit wait, we can ensure that the page is fully loaded before taking a screenshot. This can solve the problem that in headless mode, since we cannot directly see the browser interface, it is difficult to determine when the page is fully loaded, resulting in incomplete or missing content in the captured image.

[0124] Specifically, since Selenium interacts with the browser based on the WebDriver protocol, its stability will be affected by many factors such as network conditions and browser performance. In order to improve the stability of the code, a retry mechanism is used to solve potential errors and abnormal situations.

[0125] Specifically, when saving a screenshot file, you need to ensure that the specified file path exists and that the program has write permission.

[0126] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0127] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An industrial control network intelligent exposure surface identification and risk assessment system, characterized in that: include: Data acquisition module, which is used to collect raw data of each device in the industrial control network, including data flow and device logs; A data processing module connected to the data acquisition module, used to determine redundant parameters based on the acquired logs of each device and to determine data stability parameters based on the historical data flow within each preset inspection period; A device management module, which is connected to the data acquisition module and the data processing module respectively, and is used to set a data label for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period; An analysis module connected to the device management module, for determining a fluctuation parameter based on the data stability parameter of each hidden danger running device, for issuing an alarm message of an exposed surface of each abnormal running device based on the number of devices with each data tag and the fluctuation parameter, and for adjusting the number of servers connected to each device to a corresponding value, or, based on the fluctuation parameter, adjusting the number of repeaters connected to each device to a corresponding value; The device management module is used to determine the redundant parameter under the condition that the data flow is less than or equal to the second preset data flow and greater than the first preset data flow; Traversing each transmission log within a preset inspection period to determine the ratio of the amount of duplicate data to the total amount of data in each transmission log, and obtaining a redundancy parameter; The device management module is used to set a data tag for a single device based on redundant parameters, including: If the redundant parameter is less than or equal to the preset redundant parameter, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for a single device based on the data stability parameter; If the redundancy parameter is greater than the preset redundancy parameter, the data tag of the individual device is determined as a pending operation device.

2. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 1 is characterized in that: The device management module is used to set a data label for each device based on the data flow of a single device within a preset inspection period, including: If the data flow is less than or equal to the first preset data flow, the data tag of the device is determined as a stable operation device; If the data flow is greater than the second preset data flow, a data stability parameter is determined based on the historical data flow in each preset inspection period, and a data label is set for the single device based on the data stability parameter.

3. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 2 is characterized in that: The data processing module is used to determine the data stability parameter, solve the variance of each historical data flow in each preset inspection period, and obtain the data stability parameter; The device management module is used to set a data tag for a single device based on a data stability parameter, including: If the data stability parameter is less than or equal to the preset data stability parameter, the data tag of the single device is determined as an abnormally operating device; If the data stability parameter is greater than the preset data stability parameter, the data tag of the individual device is determined as a hidden danger operating device.

4. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 3 is characterized in that: The analysis module is used to process each device based on the number of devices with each data tag counted, including: If the number of stably operating devices is the largest, the operation of each device is determined to be qualified, and each device is controlled to continue to operate using the current operating parameters; If the number of pending operation devices is the largest, adjusting the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device; If the number of hidden danger operating equipment is the largest, the fluctuation parameter is determined based on the data stable parameter of each hidden danger operating equipment, and each equipment is processed based on the fluctuation parameter; If the number of abnormally operating devices is the largest, it is determined that the operation of each device is abnormal, and an alarm message is issued indicating that each abnormally operating device has an exposed surface.

5. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 4 is characterized in that: The analysis module is used to adjust the first preset data flow rate and the second preset data flow rate for determining the data tag to corresponding values ​​based on the number of devices connected to the single pending operation device, wherein: The increase range of the first preset data flow and the second preset data flow determined based on the number of devices is proportional to the number of devices.

6. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 5 is characterized in that: The analysis module is used to process each device based on the fluctuation parameter. To determine the fluctuation parameter, obtain the difference between the maximum value of the data stable parameter of each hidden danger operation equipment and the average value of the data stable parameter of each hidden danger operation equipment, and obtain the fluctuation parameter; If the fluctuation parameter is less than or equal to the preset fluctuation parameter, the number of servers connected to each device is adjusted to a corresponding value based on the number of devices running with hidden dangers; If the fluctuation parameter is greater than the preset fluctuation parameter, the number of repeaters connected to each device is adjusted to a corresponding value based on the fluctuation parameter.

7. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 6 is characterized in that: The analysis module is used to adjust the number of servers connected to each device to a corresponding value based on the number of devices running with hidden dangers, wherein: The number determined by the analysis module is proportional to the number of devices with hidden dangers.

8. The industrial control network intelligent exposure surface identification and risk assessment system according to claim 7 is characterized in that: The analysis module is used to adjust the number of repeaters connected to each device to a corresponding value based on the fluctuation parameter, wherein: The increase in the number of repeaters connected to each device determined by the analysis module is proportional to the fluctuation parameter.

9. A risk assessment method using the industrial control network intelligent exposure surface identification and risk assessment system according to any one of claims 1 to 8, characterized in that: include: Collect the original data of each device in the industrial control network, including data flow and device logs; Determine redundant parameters based on the acquired logs of each device, and determine data stability parameters based on the historical data flow within each preset inspection period; Setting data labels for each device based on the data flow, redundant parameters and data stability parameters of each device within a preset inspection period; Determine the fluctuation parameter based on the data stable parameter of each hidden danger running device, issue the alarm information of the exposed surface of each abnormal running device based on the statistical number of devices of each data tag and the fluctuation parameter, adjust the number of servers connected to each device to the corresponding value, or adjust the number of repeaters connected to each device to the corresponding value based on the fluctuation parameter; Or, determine whether the operation of each device is qualified, and control each device to continue to operate using the current operating parameters.

Citation Information

Patent Citations

  • Network attack detection method and system for numerical control equipment

    CN118869307A

  • Online security situation evaluation method and system for electric power industrial control terminal

    CN111669375A