Network security monitoring method, system and device for industrial internet and storage medium

By marking and evaluating the importance and level of associated terminal devices in the buffer zone, calculating the correlation score, and generating interference information, the problem of insufficient identification of external network attack information is solved, and the network security of the industrial internet is improved.

CN119652676BActive Publication Date: 2026-01-02BEIJING SHENZHOU HUIAN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510168276.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2026-01-02
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

In existing technologies, external network attack information is identified and cleared in the buffer zone, but the actual target of the attack information is not identified. This allows hackers to find weak nodes in the industrial internet through trial and error, causing security risks.

Method used

By acquiring the purpose encoding and request task of abnormal request information, associated terminal devices are marked, the importance level and association degree score of associated terminal devices are calculated, and interference information is generated to clarify the attack direction and avoid trial and error.

Benefits of technology

It improves the network security of the industrial internet, prevents hackers from finding weaknesses in internal areas, and enhances the ability to identify and protect against attack directions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652676B_ABST
    Figure CN119652676B_ABST
Patent Text Reader

Abstract

The application relates to a network security monitoring method, system and device of an industrial internet and a storage medium, and belongs to the technical field of network security. The method is applied to a buffer area and comprises the following steps: acquiring abnormal request information, wherein the abnormal request information comprises a destination code and a request task, the destination code is the code of a terminal device used for executing the request task, and the terminal device with the destination code is marked as a destination terminal device; determining an association code according to the destination code and the request task, marking a terminal device with the association code as an association terminal device, and the association terminal device is located in an internal area; calculating an association degree score of the association code according to an importance level and an association level of the association terminal device; and generating interference information according to the association degree score. The application has the effect of improving the network security of the industrial internet.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, in particular to a network security monitoring method, system and device for industrial internet and a storage medium. BACKGROUND

[0002] At present, network security technology is very mature. On the hardware, various types of network security devices such as firewall, virtual private network (VPN) device, intrusion detection system and intrusion prevention system, switch, encryption device and network security audit device are set. On the software, security policies deployed in various network security devices are included, such as identity and access management software, encryption software, security information and time management software and vulnerability scanning software. Through multi-layer protection of hardware devices and software systems, the target device is protected from network attacks.

[0003] In order to protect the data communication security performance of industrial internet, the industrial internet is divided into an internal area and a buffer area, and the internal area and the buffer area also form a local area network. The internal area stores core target devices that need to be encrypted, and the buffer area stores public server facilities and network security devices, such as enterprise Web servers, FTP servers and forums. When an external network accesses the industrial internet, it can only access the terminal devices in the buffer area, but cannot directly access the terminal devices in the internal network.

[0004] In the prior art, when the attack information sent by the external network is identified in the buffer area, the attack information in the buffer area is usually directly cleared. However, with the development of hacker technology, if only the attack information in the buffer area is cleared without understanding the actual node that the attack information wants to attack, it may lead to finding the weak node of the industrial internet after the hacker continuously tries and errors, thereby causing security risks to the industrial internet. SUMMARY

[0005] In order to improve the network security of the industrial internet, the present application provides a network security monitoring method, system, device and storage medium for industrial internet.

[0006] In the first aspect of the present application, a network security monitoring method for industrial internet is provided. The method is applied in the buffer area, and includes:

[0007] Obtaining abnormal request information, the abnormal request information including a destination code and a request task, the destination code being the code of a terminal device for executing the request task, and the terminal device with the destination code being marked as a destination terminal device;

[0008] According to the purpose code and the request task, an associated code is determined, a terminal device with the associated code is marked as an associated terminal device, and the associated terminal device is located in an internal area;

[0009] According to the importance level and the association level of the associated terminal device, an association degree score of the associated code is calculated.

[0010] According to the association degree score, interference information is generated.

[0011] By adopting the technical solution, when it is determined that the request information is abnormal request information, the associated terminal device located in the internal area is determined according to the purpose code and the request task of the abnormal request information. Since the terminal device located in the internal area needs to be kept secret, after the associated terminal device is obtained, the association degree score of the associated code of the associated terminal device is calculated according to the importance level and the association level of the associated terminal device in the internal area, the importance degree of the associated terminal device in the internal area is evaluated through the association degree score, and finally the interference information is generated according to the importance degree. Therefore, it can be known that the application can identify the attack direction of the abnormal request information in the buffer area, and then generate the interference information according to the attack direction, so as to avoid that the hacker finds the weak point of the internal area in the trial and error process, thereby improving the network security of the industrial internet.

[0012] In a possible implementation manner, the calculation of the association degree score of the associated code according to the importance level and the association level of the associated terminal device comprises:

[0013] An initial score is calculated according to a historical association number of the associated code;

[0014] A first score is calculated according to the initial score and the importance level of the associated terminal device;

[0015] A second score is calculated according to the initial score and the association level of the associated terminal device;

[0016] The association degree score of the associated code is calculated according to the first score and the second score.

[0017] By adopting the technical solution, when the association degree score is calculated, the initial score is obtained based on the historical association number of the associated code, the first score and the second score are respectively obtained by adjusting the initial score based on the importance level of the associated terminal device and the association level of the associated terminal device, and finally the association degree score is obtained through the first score and the second score, so that the accuracy of the association degree score calculated by the application is improved.

[0018] In a possible implementation manner, the initial score is calculated by the following calculation formula:

[0019] The initial score = the historical association times * the preset score,

[0020] The historical association times refer to the association times of the association code in the monitoring time period, and the score range to which the preset score belongs is 3-10.

[0021] By using the above technical solution, the initial score is proportional to the historical association times, and when the historical association times are larger, the initial score is also higher, thereby providing data support for timely paying attention to the association terminal device with more association times.

[0022] In a possible implementation manner, the first score is calculated according to the initial score and the importance level of the association terminal device, including:

[0023] matching a corresponding security level according to the type of the association terminal device;

[0024] determining the security level of the data processed by the association terminal device;

[0025] selecting, as the importance level, the security level that is the highest among the security level corresponding to the type of the association terminal device and the security level of the data processed by the association terminal device;

[0026] matching a corresponding weight according to the importance level;

[0027] calculating the first score according to the initial score and the weight corresponding to the importance level.

[0028] By using the above technical solution, when the first score is calculated, the security level of the association terminal device itself and the security level of the data processed by the association terminal device are fully considered, and finally the security level that is the highest among the security levels is selected as the importance level. Then, the first score is calculated according to the weight corresponding to the importance level and the initial score, so that the accuracy of the calculated first score is higher.

[0029] In a possible implementation manner, the first score is calculated by the following calculation formula, including:

[0030] F1=S(1+p),

[0031] wherein, F1 is the first score, S is the initial score, and p is the weight corresponding to the importance level.

[0032] In a possible implementation manner, the second score is calculated according to the initial score and the association level of the association terminal device, including:

[0033] According to the interaction frequency of the associated terminal device and other terminal devices in the internal area, a primary association level is determined;

[0034] According to the primary association level, a proportion of traffic used by the associated terminal device when interacting and a total proportion of traffic used by the internal area, a final association level is determined;

[0035] According to the final association level, a corresponding weight is matched;

[0036] Based on the initial score and the weight corresponding to the final association level, a second score is calculated.

[0037] By using the above technical solution, when calculating the second score, the interaction frequency of the associated terminal device and other terminal devices and the amount of traffic occupied are fully considered, so that the information flow of the associated terminal device is evaluated. According to the weight mapped by the information flow, the second score is calculated according to the weight and the initial score, so that the accuracy of the calculated second score is higher.

[0038] In a possible implementation manner, the determining the association code according to the purpose code and the request task comprises:

[0039] Identifying the type of the abnormal request information;

[0040] Calling terminal devices in the internal area that participate in executing the type of request information when the purpose terminal device executes the type of request information, taking the terminal devices as first associated terminal devices, and taking the code of the first associated terminal devices as a first code;

[0041] Taking terminal devices in the internal area that generate the same or similar response data to the abnormal request information as second associated terminal devices, and taking the code of the second associated terminal devices as a second code;

[0042] According to the first code and the second code, the association code is obtained.

[0043] By using the above technical solution, terminal devices in the internal area that have a corresponding relationship with the abnormal request information are all marked as associated terminal devices, so that the attack direction of the abnormal request information is conveniently evaluated in a wide range, and the accuracy of the evaluated result is ensured.

[0044] In a second aspect of the present application, an industrial internet network security monitoring system is provided. The system comprises:

[0045] The data acquisition module is configured to acquire abnormal request information, wherein the abnormal request information comprises a destination code and a request task, and the destination code is a code of a terminal device used to execute the request task, and the terminal device with the destination code is marked as a destination terminal device;

[0046] The data determination module is configured to determine an association code according to the destination code and the request task, and the terminal device with the association code is marked as an association terminal device, wherein the association terminal device is located in an internal area;

[0047] The data calculation module is configured to calculate an association degree score of the association code according to an importance level and an association level of the association terminal device.

[0048] The data generation module is configured to generate interference information according to the association degree score.

[0049] In a third aspect of the present application, an industrial internet network security monitoring device is provided. The device comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement any of the above industrial internet network security monitoring methods.

[0050] In a fourth aspect of the present application, a computer readable storage medium is provided, which stores a computer program, and the program is executed by a processor to implement any of the above industrial internet network security monitoring methods.

[0051] In summary, the present application has the following beneficial technical effects:

[0052] When the request information is determined to be abnormal request information, the association terminal device located in the internal area is determined according to the destination code and the request task of the abnormal request information. Since the terminal device located in the internal area needs to be kept secret, after obtaining the association terminal device, the association degree score of the association code of the association terminal device is calculated according to the importance level and the association level of the association terminal device in the internal area, the importance of the association terminal device in the internal area is evaluated through the association degree score, and finally the interference information is generated according to the importance. Therefore, the present application can identify the attack direction of the abnormal request information in the buffer area, generate interference information according to the attack direction, avoid hackers finding weak points in the internal area in the trial-and-error process, and improve the network security of the industrial internet. BRIEF DESCRIPTION OF DRAWINGS

[0053] Figure 1 is a schematic diagram of an exemplary operating environment of an embodiment of the present application.

[0054] Figure 2A network security monitoring method flow chart of an industrial internet of the embodiments of the present application.

[0055] Figure 3 A block diagram of a network security monitoring system of an industrial internet of the embodiments of the present application.

[0056] Legend: 100, local area network; 110, internal area; 120, buffer area; 121, data acquisition module; 122, data determination module; 123, data calculation module; 124, data generation module; 200, external network. DETAILED DESCRIPTION

[0057] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0058] Figure 1 A schematic diagram showing an exemplary operating environment in which the embodiments of the present application can be implemented is shown, which includes a local area network 100 and an external network 200, the local area network 100 including an internal area 110 and a buffer area 120. When the external network 200 and the local area network 100 exchange information, the information exchange is performed through the buffer area 120.

[0059] Specifically, the internal area 110 is where core and confidential terminal devices are placed, such as various types of sensors, core servers, and important terminal devices such as memories. The terminal devices in the internal area 110 can access the terminal devices in the buffer area 120 and the terminal devices in the external network 200.

[0060] The buffer area 120 is where public server facilities and network security devices are stored, such as enterprise Web servers, FTP servers, forums, and the like, and network security devices such as routers, firewalls, security gateways, and switches. By setting the buffer area 120, the internal area 110 can be isolated from the external network 200, so that the external network 200 cannot directly access the internal area 110, and when the external network 200 accesses the local area network 100, the request information sent by the external network 200 needs to be subjected to security verification by the network security device, such as user identity verification, access control, authority management, and multi-factor identity verification.

[0061] The external network 200 can be another local area network 100, and can also be a wide area network. Since the terminal devices contained in the external network 200 are various, and the hiding ability of the terminal devices with aggressiveness in the external network 200 is relatively strong, it is difficult to trace the source through the network. Therefore, many local area networks 100 can only passively perform security verification on the external network 200 with which it communicates, and when a terminal device with aggressiveness is identified, it can usually only intercept the access of the terminal device with aggressiveness, and it is difficult to trace and remove the security risk from the source. Therefore, many terminal devices with aggressiveness usually indiscriminately attack various local area networks 100, and can find weak nodes of the local area network 100 after multiple trial and error, and then attack the entire local area network 100 on a large scale.

[0062] Based on the security risks existing when the current local area network 100 communicates with the external network 200, the application provides an industrial internet network security monitoring method, which is applied to Figure 1 the buffer area 120 in the industrial internet network security monitoring method. As shown in Figure 2 the main process of the industrial internet network security monitoring method is described as follows.

[0063] Step S100, acquire abnormal request information, and the abnormal request information includes destination coding and request task.

[0064] When the external network 200 sends request information to the local area network 100, the security network device first performs security verification on the request information. The specific security verification can be one or more of the above-mentioned user identity verification, access control, permission management, etc. The application does not limit this. If the request information passes the security verification, the request information is executed; if the request information does not pass the security verification, the request information is marked as abnormal request information, and step S200 is entered.

[0065] Specifically, the abnormal request information includes destination coding and request task. The destination coding is the coding of the terminal device that executes the request task. The coding can be the IP address of the terminal device, and can also be the MAC coding or the serial number. It should be noted that the terminal device with the destination coding is referred to as the destination terminal device hereinafter.

[0066] The request task contains the specific content of the request information, which specifies the data content returned by the destination terminal device after executing the request task, for example, specifies that the destination terminal device A returns the temperature control data of the local area network 100 after executing the request task.

[0067] Step S200, determine the associated coding according to the request task and the destination coding, and the terminal device with the associated coding is located in the internal area 110.

[0068] Based on the abnormal request information, the type of the abnormal request information is first identified. The specific identification method can be to obtain the type of the abnormal request information through protocol analysis, or to use a predefined pattern or rule to match the content of the request task, such as regular expression, keyword matching, specific format matching, etc. Then, according to the matching result, the type of the abnormal request information is determined.

[0069] After obtaining the type of the abnormal request information, the terminal device in the internal area 110 that participates in the execution of the request of this type when the destination terminal device executes the request information of this type is called, and the terminal device is taken as the first associated terminal device, and the code of the first associated terminal device is taken as the first code. At the same time, a terminal device that can generate the same or similar response data as the abnormal request information and is located in the internal area 110 is also taken as the second associated terminal device, and the code of the second associated terminal device is taken as the second code.

[0070] The response data of the abnormal request information refers to the data returned to the terminal device after the destination terminal device executes the request information. Generally, when the request information is not marked as abnormal request information, the destination terminal device will generate response data for the request information. However, when the request information is marked as abnormal request information, the destination terminal device stops running the abnormal request information, but according to the historical execution data, judges the response data generated when executing the normal request information of the same type as the abnormal request information, and takes the response data as the response data of the abnormal request information. For example, the request information is to obtain the temperature control data in the local area network 100, and the returned temperature control data is taken as the response data. If the information of requesting the temperature control data is identified as abnormal request information, the temperature control data is still taken as the response data, and the sensor generating the temperature control data is taken as the second associated terminal device, and the code of the second associated terminal device is taken as the second code.

[0071] Finally, based on the obtained first code and second code, the codes are uniformly referred to as associated codes. It should be noted that the terminal devices with associated codes are uniformly referred to as associated terminal devices.

[0072] Step S300, according to the importance level and the association level of the associated terminal device, the association degree score of the associated code is calculated.

[0073] Since the terminal devices in the internal network are mostly core devices or devices that need to be encrypted, when they are marked as associated terminal devices, their importance in the internal area 110 needs to be evaluated. The higher the security level of the associated terminal device, the greater the loss when it is attacked. The higher the degree of association between the associated terminal device and other terminal devices in the internal area 110, the wider the protection surface when it is attacked, and the higher the difficulty of protection. Therefore, close attention needs to be paid to these two types of associated terminal devices.

[0074] In this example, the importance of the two types of associated terminal devices is evaluated by calculating the association degree score of the associated code. For each associated terminal device, its association degree score needs to be calculated. For ease of illustration, the process of calculating the association degree score of one of the associated codes is taken as an example below:

[0075] Step S310: Calculate an initial score according to the historical association times of the associated code.

[0076] In one specific example, the historical association times refer to the association times of the associated code in a monitoring period. The monitoring period can be one month, three months, half a year, or one year. The selected monitoring period needs to be determined according to the frequency of attacks on the local area network 100 in actual application. The higher the frequency of attacks on the local area network 100, the shorter the monitoring period, so as to not only reduce data redundancy, but also ensure the accuracy of the obtained association times.

[0077] The initial score is determined according to the historical association times. In one specific example, one association time corresponds to a preset score. In this example, the preset score is randomly taken from the score range 3-10, to avoid the situation that the difference between the initial scores of two associated codes is greater when the difference between their historical association times is greater, thereby affecting the accuracy of the subsequent calculation of the association degree score. In this example, the historical association times of the associated code are directly proportional to the initial score, i.e., initial score = historical association times * preset score.

[0078] Step S320: Calculate a first score according to the initial score and the importance level of the associated terminal device.

[0079] Specifically, the importance level of the associated terminal device is determined according to the type of the associated terminal device and the data security level processed by the associated terminal device. The application sets a corresponding security level for each type of terminal device in advance, for example, a first security level, a second security level and a third security level are set, and the first security level > the second security level > the third security level. The memory for saving all data and the core server with the highest security level are placed in the first security level, and the edge sensor is placed in the second security level because it only generates part of the data. The terminal device for early warning is placed in the third security level because it neither saves data nor generates data, but only gives an early warning when a terminal device failure is detected.

[0080] Meanwhile, the importance level of the associated terminal device is also determined according to the security level of the data processed by the terminal device. For example, a first security level, a second security level, a third security level, a fourth security level and a fifth security level are set, and the first security level > the second security level > the third security level > the fourth security level > the fifth security level. The data used for encrypting the memory and the core server is placed in the first security level because it has the highest security level. The data in the memory has a higher integrity, so it can be placed in the second security level. The core server runs control logic for controlling different terminal devices, so the core server is also placed in the second security level. The data collected by the edge sensor is placed in the third security level. The early warning information generated by the early warning terminal device is placed in the fourth security level. Finally, the information uploaded from the buffer area 120 is placed in the fifth security level.

[0081] Therefore, after obtaining the associated terminal device, a corresponding security level is matched according to the type of the associated terminal device, and then the importance level of the associated terminal device is finally confirmed according to the security level of the data processed by the associated terminal device. The importance level selected in this example is that from the security level corresponding to the type of the associated terminal device and the security level of the data processed, the highest security level is selected as the importance level of the associated terminal device. For example, the type of the core server B itself is in the first security level. If the core server B needs to further process the data in the memory, the highest security level of the core server B is the first security level because the data in the memory is in the second security level. The first security level will also be the importance level of the core server B.

[0082] In this example, different importance levels correspond to different weights. Therefore, the weights can be matched according to the importance level. For example, the weight is 100% for the first security level, 60% for the second security level, and 10% for the third security level. It should be noted that the above weights are merely examples and can be adjusted as needed in actual use.

[0083] Based on the initial score and the weights corresponding to the importance level, the first score is calculated as: F1 = S(1+p), where F1 is the first score, S is the initial score, and p is the weight corresponding to the importance level.

[0084] Step S330: Calculate the second score based on the initial score and the association level of the associated terminal device.

[0085] Specifically, the association level is determined based on the frequency of interaction between the associated terminal device and other terminal devices and the amount of data traffic during the interaction. For example, if the interaction frequency ranges are pre-set as 0-10, 11-30, 31-50, 51-80, 81-100, and above 100, and 0-10, 11-30, 31-50, 51-80, 81-100, and above 100 correspond to association levels six, five, four, three, two, and one, respectively, then the association level corresponding to the interaction frequency of the associated terminal device is determined based on the interaction frequency range it falls into, and this association level is used as the primary association level. Then, the proportion of traffic used by the associated terminal device during interaction to the total traffic used in the internal area is calculated to determine the final association level. For example, if the interaction frequency of associated terminal device C is 55, and the calculated proportion is 5%, then the association value is calculated as: L = 55 + 5% * 100, that is, the association value L of the associated terminal device is 60 points. Since 60 still falls within the range of 51-80, the association level of associated terminal device C corresponds to level three.

[0086] Different association levels correspond to different weights. The weights are matched according to the association level. For example, the weight is 100% for level 1, 85% for level 2, 65% for level 3, 45% for level 4, 25% for level 5, and 5% for level 6. It should also be noted that the above weights are just examples and can be adjusted as needed in actual use.

[0087] Based on the initial score and the weights corresponding to the association level, the second score is calculated as: F2 = S(1+q), where F2 is the second score, S is the initial score, and q is the weight corresponding to the association level.

[0088] Step S334, calculating the relevance score of the associated code according to the first score and the second score.

[0089] In one specific example, the calculation formula for calculating the relevance score of the associated code is: D=F1+F2, that is, the sum of the first score and the second score as the relevance score.

[0090] In other examples, the calculation formula for calculating the relevance score of the associated code is: D=max(F1,F2), that is, from the first score and the second score, the maximum value is selected as the relevance score.

[0091] In general, the relevance score of the associated code is calculated according to the importance level and the association level of the associated terminal device.

[0092] Step S400, generating interference information according to the relevance score.

[0093] Based on the relevance score, the associated code with a relevance score higher than the score threshold is taken as the target code, and for the terminal device corresponding to the target code, a random code information is generated as interference information. Specifically, the interference region is provided in the buffer area 120, and the interference region is used to generate interference information. When the abnormal request information is received again in the buffer area 120 and the relevance score of the associated terminal device corresponding to the abnormal request information has been higher than the score threshold, the buffer area 120 first calls the interference information in the interference region, and then performs the work of clearing the abnormal request information, avoiding that the terminal device with attack in the external network finds the weak node in the local area network 100 according to the clues of the previous access, or avoiding that when the terminal device with attack is strong in attack, the security risk caused by the incomplete clearing of the abnormal request information.

[0094] Figure 3 A block diagram of a network security monitoring system of an industrial internet according to an embodiment of the present application is shown, which includes a data acquisition module 121, a data determination module 122, a data calculation module 123 and a data generation module 124.

[0095] The data acquisition module 121 is used to acquire abnormal request information, and the abnormal request information includes a request task and a destination code.

[0096] The data determination module 122 is used to determine the associated code according to the request task and the destination code, and the terminal device with the associated code is located in the internal area 110.

[0097] The data calculation module 123 is used to calculate the relevance score of the associated code according to the importance level and the association level of the associated terminal device.

[0098] The data generation module 124 is configured to generate interference information according to the correlation score.

[0099] The modules described in the embodiments of the present application can be implemented in the form of software or in the form of hardware. The described modules can also be arranged in a processor, for example, a processor can be described as including a data acquisition module 121, a data determination module 122, a data calculation module 123, and a data generation module 124. In some cases, the names of these modules do not constitute a limitation on the modules themselves, for example, the data acquisition module 121 can also be described as a "module for acquiring abnormal request information".

[0100] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the described modules can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0101] In order to better execute the program of the above method, the present application also provides an industrial internet network security monitoring device, which comprises a memory and a processor.

[0102] The memory can be used to store instructions, programs, codes, code sets or instruction sets. The memory can include a program storage area and a data storage area, wherein the program storage area can store instructions for implementing an operating system, instructions for at least one function, and instructions for implementing the above-mentioned industrial internet network security monitoring method, etc.; the data storage area can store data involved in the above-mentioned industrial internet network security monitoring method, etc.

[0103] The processor can include one or more processing cores. The processor executes various functions and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory, and calling data stored in the memory. The processor can be at least one of an application specific integrated circuit, a digital signal processor, a digital signal processing device, a programmable logic device, a field programmable gate array, a central processing unit, a controller, a microcontroller, and a microprocessor. It can be understood that, for different devices, the electronic devices used to implement the functions of the above-mentioned processor can also be other devices, and the embodiments of the present application do not make specific limitations.

[0104] The present application also provides a computer readable storage medium, for example, including: a U disk, a mobile hard disk, a read only memory (Read Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and various media that can store program codes. The computer readable storage medium stores a computer program capable of being loaded by the processor and executing the above-mentioned industrial internet network security monitoring method.

[0105] The above description is merely exemplary of the application and the principles thereof. It is to be understood that those skilled in the art will be able to devise various arrangements which, although not explicitly described or shown herein, embody the principles of the application and are included within its spirit and scope. Furthermore, there are several variations to the application described herein which have not been described but will be understood by those skilled in the art. For example, the features of the application described and shown can be combined with other features of the application described and shown (but not limited to) in the patent specification and drawings.

Claims

1. A network security monitoring method of an industrial internet, applied to a buffer area (120), comprising: obtaining abnormal request information, the abnormal request information comprising a destination code and a request task, the destination code being a code of a terminal device for executing the request task, and the terminal device with the destination code being marked as a destination terminal device, the abnormal request information being information marked when information security check of request information sent by an external network to a local network fails; determining an association code according to the destination code and the request task, marking a terminal device with the association code as an association terminal device, the local network comprising an internal area (110) and the buffer area (120), and the association terminal device being located in the internal area (110); calculating an association degree score of the association code according to an importance level and an association level of the association terminal device, the importance level being an importance degree of the association terminal device in the internal area (110), and the association level being determined according to an interaction frequency and a traffic size in an interaction process of the association terminal device and other terminal devices; generating interference information according to the association degree score; wherein the calculating of the association degree score of the association code according to the importance level and the association level of the association terminal device comprises: calculating an initial score value according to a historical association number of the association code; calculating a first score value according to the initial score value and the importance level of the association terminal device; calculating a second score value according to the initial score value and the association level of the association terminal device; and calculating the association degree score of the association code according to the first score value and the second score value; wherein the calculating of the first score value according to the initial score value and the importance level of the association terminal device comprises: matching a corresponding security level according to a type of the association terminal device; determining a security level of data processed by the association terminal device; selecting a security level with a highest security level from the security level corresponding to the type of the association terminal device and the security level of the data processed by the association terminal device as the importance level; matching a corresponding weight according to the importance level; and calculating the first score value according to the initial score value and the weight corresponding to the importance level; wherein the determining of the association code according to the destination code and the request task comprises: identifying a type of the abnormal request information; calling terminal devices located in the internal area (110) and participating in execution of the type of request information as first association terminal devices when the destination terminal device executes the type of request information, and taking codes of the first association terminal devices as first codes; taking terminal devices generating same or similar response data of the abnormal request information and located in the internal area (110) as second association terminal devices, and taking codes of the second association terminal devices as second codes; and obtaining the association code according to the first codes and the second codes; and wherein the initial score value is calculated according to the following formula: ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ 2.The network security monitoring method of the industrial internet according to claim 1, wherein, ​ The initial score = the historical association times * the preset score, wherein the historical association times refer to the association times of the association code in the monitoring time period, and the preset score belongs to a score range of 3-10 points. 3.The network security monitoring method of the industrial internet according to claim 1, wherein, The first score is calculated by the following calculation formula, including: F1=S(1+p), Wherein, F1 is the first score, S is the initial score, and p is the weight corresponding to the importance level. 4.The network security monitoring method of the industrial internet according to claim 1, wherein, The second score is calculated according to the initial score and the association level of the associated terminal device, including: Determine the primary association level according to the interaction frequency of the associated terminal device and other terminal devices in the internal area (110); Determine the final association level according to the primary association level, the proportion of the traffic used by the associated terminal device in the interaction to the overall traffic used by the internal area (110); Match the corresponding weight according to the final association level; Calculate the second score based on the initial score and the weight corresponding to the final association level.

5. A cyber security monitoring system for an industrial internet, characterized by, Including: The data acquisition module (121) is configured to acquire abnormal request information, wherein the abnormal request information includes a destination code and a request task, the destination code is the code of a terminal device used to execute the request task, the terminal device with the destination code is marked as a destination terminal device, and the abnormal request information is information marked as failing in information security check when a request information is sent from an external network to a local area network; The data determination module (122) is configured to determine an association code according to the destination code and the request task, and mark a terminal device with the association code as an associated terminal device, wherein the local area network includes an internal area (110) and a buffer area (120), and the associated terminal device is located in the internal area (110); The data calculation module (123) is configured to calculate the association degree score of the association code according to the importance level and the association level of the associated terminal device, wherein the importance level is the importance of the associated terminal device in the internal area (110), and the association level is determined according to the interaction frequency and the traffic size in the interaction process of the associated terminal device and other terminal devices; The data generation module (124) is configured to generate interference information according to the association degree score. The calculation of the association degree score of the association code according to the importance level and the association level of the associated terminal device includes: Calculate the initial score according to the historical association times of the association code; Calculate the first score according to the initial score and the importance level of the associated terminal device; Calculate the second score according to the initial score and the association level of the associated terminal device; Calculate the association degree score of the association code according to the first score and the second score; The calculation of the first score according to the initial score and the importance level of the associated terminal device includes: Match a corresponding security level according to the type of the associated terminal device; Determine the security level of the data processed by the associated terminal device; Selecting one of a security level corresponding to a type of the associated terminal device and a security level of data processed by the associated terminal device as an important level, the one having a highest security level; Matching a corresponding weight according to the important level; Calculating the first score according to the initial score and the weight corresponding to the important level; The determining the associated code according to the purpose code and the request task comprises: Identifying a type of the abnormal request information; Calling a terminal device in the internal area (110) and participating in the execution of the request information of the type when the purpose terminal device executes the request information of the type, taking the terminal device as a first associated terminal device, and taking a code of the first associated terminal device as a first code; Taking a terminal device in the internal area (110) and generating the same or similar response data of the abnormal request information as a second associated terminal device, and taking a code of the second associated terminal device as a second code; Obtaining the associated code according to the first code and the second code.

6. A cyber security monitoring apparatus of an industrial internet, characterized by, A computer program product, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the method according to any one of claims 1-4 when executing the program.

7. A computer-readable storage medium, characterized in that, A computer program product, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the method according to any one of claims 1-4 when executing the program.

Citation Information

Patent Citations

  • Security early warning method and device based on security state of associated node, and electronic equipment

    CN115296840A