Intelligent Protection Method and System for Heterogeneous Industrial Control Networks Based on Large Models
By building a multi-dimensional security threat knowledge base and training related models, intelligent collaborative protection of the heterogeneous industrial control network environment is solved, and vulnerabilities and attack behaviors in the heterogeneous industrial control network are not discovered and blocked in a timely manner, achieving efficient security threat detection and protection.
Patent Information
- Application Number
- CN202510199287.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-24
AI Technical Summary
There are a large number of undisclosed vulnerabilities and potential attacks in the heterogeneous industrial control network environment that have not been discovered and blocked in a timely manner, resulting in security incidents such as device operation interruption, data theft and ransomware from time to time, seriously endangering the network security of the infrastructure.
The first large model that introduced the gate control mechanism is used to process the collected non-standardized multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to build a multi-dimensional knowledge base for security threats. Based on this knowledge base, the second large model is trained, and preset security vulnerability mining strategies and intrusion detection strategies are used to detect and protect the target heterogeneous industrial control terminal system and network.
It realizes intelligent collaborative protection of heterogeneous industrial control network environments, automatically verify the exploitability of security vulnerabilities, evaluate the risks of attack behavior, and handles vulnerabilities and attack behaviors accordingly, improving the accuracy of the multi-dimensional knowledge base of security threats and the reliability of detection results.
Smart Images

Figure CN119696931B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security technologies, and particularly to an intelligent protection method, system, electronic device and readable storage medium for heterogeneous industrial control networks based on large models. Background Art
[0002] With the popularization and development of global logistics digitization, more and more industrial Internet of Things scenarios have applied deeply coupled heterogeneous industrial control networks (IT networks and OT networks) to support networking and intelligent applications in various scenarios. However, the heterogeneous industrial control networks have brought fragmented software supply chains, and the interconnection networking requirements have brought various potential attack paths, making the existing general vulnerability detection and intrusion prevention often unable to be directly applied to such heterogeneous industrial control network environments. There are a large number of unpublicized vulnerabilities and potential attack behaviors that have not been discovered and blocked in time, resulting in security incidents such as equipment operation interruption, data theft and ransomware occurring from time to time, seriously endangering the network security of the infrastructure.
[0003] Although the prior art can perform vulnerability mining and intrusion detection on industrial Internet of Things devices. However, due to the wide range of sources and diverse forms of security threats in the heterogeneous industrial control network environment, the existing security protection means have limitations in dealing with complex threats, lacking an effective mechanism to integrate the vulnerability mining results, intrusion detection information and multi-source security threat data in the heterogeneous industrial control network environment, and unable to achieve intelligent collaborative protection.
[0004] It should be noted that the information disclosed in the background art part of this invention is only intended to deepen the understanding of the general background art of this invention, and should not be regarded as an admission or any form of suggestion that this information constitutes the prior art known to those skilled in the art. Summary of the Invention
[0005] The purpose of the present invention is to provide an intelligent protection method, system, electronic device and readable storage medium for heterogeneous industrial control networks based on large models, which can automatically verify the exploitability of security vulnerabilities, evaluate the risk of attack behaviors, and perform corresponding processing on vulnerabilities and attack behaviors, so as to achieve intelligent collaborative protection in the heterogeneous industrial control network environment.
[0006] To achieve the above object, the present invention provides an intelligent protection method for heterogeneous industrial control networks based on large models, including: using a first large model with a gated mechanism to process the collected non-standard multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to construct a multi-dimensional knowledge base of security threats; training a second large model based on the multi-dimensional knowledge base of security threats, and using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system to obtain the security vulnerability mining results of the target heterogeneous industrial control terminal system; using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to detect intrusions in the target heterogeneous industrial control network to obtain the attack behavior detection results of the target heterogeneous industrial control network; and taking corresponding protection measures according to the security vulnerability mining results and the attack behavior detection results.
[0007] Optionally, the using a first large model with a gated mechanism to process the collected non-standard multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to construct a multi-dimensional knowledge base of security threats includes: using a first large model with a gated mechanism to integrate and normalize the non-standard multi-source data to obtain security threat information; converting the security threat information into nodes and edges in a knowledge graph, and storing the knowledge graph using a graph database, thereby constructing a multi-dimensional knowledge base of security threats.
[0008] Optionally, the using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system to obtain the security vulnerability mining results of the target heterogeneous industrial control terminal system includes: performing static taint analysis on the target heterogeneous industrial control terminal system based on a static taint analysis method of shared keywords to obtain a first vulnerability mining result; performing hybrid dynamic testing on the target heterogeneous industrial control terminal system based on a dynamic fuzz testing method assisted by binary slicing to obtain a second vulnerability mining result; and analyzing the first vulnerability mining result and the second vulnerability mining result using the second large model based on the chain of thought technique and prompt engineering to obtain the security vulnerability mining results of the target heterogeneous industrial control terminal system.
[0009] Optionally, the static taint analysis method based on shared keywords performs static taint analysis on the target heterogeneous industrial control terminal system to obtain a first vulnerability mining result, including: analyzing sensitive data or critical operations existing in the target heterogeneous industrial control terminal system, and determining keywords related to the sensitive data or the critical operations; scanning the source code of the target heterogeneous industrial control terminal system to find code segments containing the keywords; analyzing the context of the found code segments, and checking for vulnerability points according to the analysis results of the context of the code segments to obtain a first vulnerability mining result.
[0010] Optionally, the dynamic fuzz testing method based on binary slicing assistance performs hybrid dynamic testing on the target heterogeneous industrial control terminal system to obtain a second vulnerability mining result, including: using a binary slicing tool to analyze the target program of the target heterogeneous industrial control terminal system to determine a code path related to the test target of the target heterogeneous industrial control terminal system; analyzing the logical structure and input-output relationship of the sliced code according to the code path; generating random input data according to the analysis results of the logical structure and input-output relationship of the sliced code; inputting the input data into the target program to perform dynamic fuzz testing on the target program; and finding vulnerabilities according to the dynamic fuzz testing result of the target program to obtain a second vulnerability mining result.
[0011] Optionally, the intrusion detection of the target heterogeneous industrial control network using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to obtain an attack behavior detection result of the target heterogeneous industrial control network includes: a multi-dimensional traffic characterization algorithm based on lightweight feature extraction extracts features of the traffic of the target heterogeneous industrial control network from the time dimension, space dimension, and content dimension, and performs feature association on different stages of cross-domain multi-hop attack behaviors based on the extracted time dimension features, space dimension features, and content dimension features to obtain a feature association result; based on the multi-dimensional knowledge base of security threats, respectively construct a dynamically updated information technology network detection rule set and an operation technology network detection rule set, and combine the feature association result to perform a preliminary screening of real-time alarms for traditional attack types and unknown threats to obtain a preliminary screening result; construct an attack sample based on the multi-dimensional knowledge base of security threats and the preliminary screening result; input the attack sample into a meta-learning small model and at least one intrusion detection model for multi-model collaborative real-time intrusion detection to obtain an attack behavior detection result of the target heterogeneous industrial control network.
[0012] Optionally, constructing an attack sample based on the multi-dimensional security threat knowledge base and the preliminary screening results includes: obtaining vulnerability information based on the multi-dimensional security threat knowledge base, where the vulnerability information includes vulnerability type, scope of influence, and triggering conditions; combining the vulnerability information with the preliminary screening results to determine potential attack scenarios and potential attack paths; and constructing an attack sample according to the potential attack scenarios and the potential attack paths.
[0013] To achieve the above object, the present invention further provides an intelligent protection system for heterogeneous industrial control networks based on a large model, including: a knowledge base construction module configured to process non-standard multi-source data collected related to security vulnerabilities and attack behaviors in a heterogeneous industrial control network environment by using a first large model introducing a gating mechanism to construct a multi-dimensional security threat knowledge base; a security vulnerability mining module configured to train a second large model based on the multi-dimensional security threat knowledge base and use a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities of a target heterogeneous industrial control terminal system to obtain a security vulnerability mining result of the target heterogeneous industrial control terminal system; an intrusion detection module configured to perform intrusion detection on a target heterogeneous industrial control network by using a preset intrusion detection strategy based on the multi-dimensional security threat knowledge base to obtain an attack behavior detection result of the target heterogeneous industrial control network; and an intelligent collaborative protection module configured to take corresponding protection measures according to the security vulnerability mining result and the attack behavior detection result.
[0014] To achieve the above object, the present invention further provides an electronic device including a processor and a memory, where a computer program is stored on the memory, and when the computer program is executed by the processor, the intelligent protection method for heterogeneous industrial control networks based on a large model described above is implemented.
[0015] To achieve the above object, the present invention further provides a readable storage medium, where a computer program is stored in the readable storage medium, and when the computer program is executed by a processor, the intelligent protection method for heterogeneous industrial control networks based on a large model described above is implemented.
[0016] Compared with the prior art, the intelligent protection method, system, electronic device and readable storage medium for heterogeneous industrial control networks based on large models provided by the present invention have the following beneficial effects: By using a first large model with a gating mechanism to process the non-standard multi-source data collected related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment, a multi-dimensional knowledge base of security threats is constructed, which can improve the performance and accuracy of the large model in processing complex language structures, thereby effectively ensuring the accuracy of the constructed multi-dimensional knowledge base of security threats; By training a second large model based on the multi-dimensional knowledge base of security threats and using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system, the accuracy of the obtained security vulnerability mining results can be effectively guaranteed; By using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to detect intrusions in the target heterogeneous industrial control network, the accuracy of the obtained attack behavior detection results can be effectively guaranteed. In summary, the present invention can automatically verify the exploitability of security vulnerabilities, evaluate the risks of attack behaviors, and perform corresponding processing on vulnerabilities and attack behaviors, thereby realizing the intelligent collaborative protection of the heterogeneous industrial control network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a flowchart of an intelligent protection method for a heterogeneous industrial control network based on a large model provided by an embodiment of the present invention.
[0018] Figure 2 It is a flowchart of constructing a multi-dimensional knowledge base of security threats provided by an embodiment of the present invention.
[0019] Figure 3 It is a flowchart of obtaining security vulnerability mining results provided by an embodiment of the present invention.
[0020] Figure 4 It is a flowchart of obtaining attack behavior detection results provided by an embodiment of the present invention.
[0021] Figure 5 It is a structural block diagram of an intelligent protection system for a heterogeneous industrial control network based on a large model provided by an embodiment of the present invention.
[0022] Figure 6 It is a schematic diagram of an intelligent protection system for a heterogeneous industrial control network based on a large model provided by an embodiment of the present invention.
[0023] Figure 7 It is a structural block diagram of an electronic device provided by an embodiment of the present invention.
[0024] Among them, the description of the attached drawing reference numerals is as follows: knowledge base construction module - 110; security vulnerability mining module - 120; intrusion detection module - 130; intelligent collaborative protection module - 140; processor - 210; communication interface - 220; memory - 230; communication bus - 240. Specific implementation manners
[0025] The following further elaborates on the intelligent protection method, system, electronic device, and readable storage medium for heterogeneous industrial control networks proposed by the present invention in conjunction with the attached drawings and specific implementation manners. According to the following description, the advantages and features of the present invention will be clearer. It should be noted that the structures, proportions, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those skilled in this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present invention. Any modification of the structure, change in the proportional relationship, or adjustment of the size, under the condition of being the same or similar to the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed in the present invention.
[0026] The core idea of the present invention is to provide an intelligent protection method, system, electronic device, and readable storage medium for heterogeneous industrial control networks based on large models, which can automatically verify the exploitability of security vulnerabilities, evaluate the risks of attack behaviors, and perform corresponding processing on vulnerabilities and attack behaviors, thereby realizing intelligent collaborative protection in heterogeneous industrial control network environments.
[0027] It should be noted that the intelligent protection method for heterogeneous industrial control networks based on large models provided by the present invention can be applied to the intelligent protection system for heterogeneous industrial control networks based on large models provided by the present invention. The intelligent protection system for heterogeneous industrial control networks based on large models can be configured on an electronic device. Among them, the electronic device can be a personal computer, a mobile terminal, etc. The mobile terminal can be a hardware device such as a mobile phone or a tablet computer with various operating systems.
[0028] It should also be noted that the "heterogeneous industrial control network" referred to in the present invention refers to a network architecture that integrates an IT network connected to the Internet and an OT network connected to industrial operation devices in an industrial control system; the "heterogeneous industrial control terminal system" refers to an embedded operating system on an Internet of Things terminal device; the "intrusion detection" refers to the process of systematically monitoring network or system activities to identify potential security threats; the "gating mechanism" refers to controlling the flow of information by introducing gating units in a neural network to improve the model's processing ability for complex data; the "large model" refers to a natural language processing model trained with a large amount of text data and having a large number of parameters and a highly complex structure.
[0029] To achieve the above idea, the present invention provides an intelligent protection method for heterogeneous industrial control networks based on large models. Please refer toFigure 1 , which is a flowchart of an intelligent protection method for heterogeneous industrial control networks based on large models provided by an embodiment of the present invention. As Figure 1 shown, the intelligent protection method for heterogeneous industrial control networks based on large models includes the following steps: Step S100, using a first large model with a gating mechanism to process the collected non-standard multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to construct a multi-dimensional knowledge base of security threats; Step S200, training a second large model based on the multi-dimensional knowledge base of security threats, and using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system to obtain the security vulnerability mining result of the target heterogeneous industrial control terminal system; Step S300, using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to perform intrusion detection on the target heterogeneous industrial control network to obtain the attack behavior detection result of the target heterogeneous industrial control network; Step S400, taking corresponding protection measures according to the security vulnerability mining result and the attack behavior detection result.
[0030] By using a first large model with a gating mechanism to process the collected non-standard multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to construct a multi-dimensional knowledge base of security threats, the present invention can improve the performance and accuracy of the large model in processing complex language structures, thereby effectively ensuring the accuracy of the constructed multi-dimensional knowledge base of security threats; by training a second large model based on the multi-dimensional knowledge base of security threats and using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system, the accuracy of the obtained security vulnerability mining result can be effectively ensured; by using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to perform intrusion detection on the target heterogeneous industrial control network, the accuracy of the obtained attack behavior detection result can be effectively ensured. In summary, the present invention can automatically verify the exploitability of security vulnerabilities, evaluate the risk of attack behaviors, and perform corresponding processing of vulnerabilities and attack behaviors, thereby realizing intelligent collaborative protection of the heterogeneous industrial control network environment.
[0031] It should be noted that although Figure 1 it is described by taking Step S200 being executed first and then Step S300 as an example, as can be understood by those skilled in the art, this does not constitute a limitation to the present invention. In some other embodiments, Step S300 can also be executed first and then Step S200, or Step S200 and Step S300 can be executed in parallel.
[0032] Furthermore, the first large model with a gating mechanism can be trained through the following process: First, design a suitable gating unit to control the flow of information in the large model. The gating unit can dynamically adjust the transmission and processing of information according to the characteristics of the input data and the task requirements. For example, the attention mechanism can be used as the gating unit to make the large model pay more attention to important information parts and ignore irrelevant or noisy information. Then, train and optimize the first large model: During the training process of the first large model, introduce the gating mechanism and optimize the performance and accuracy of the first large model by adjusting the parameters of the gating unit; then use a large amount of heterogeneous industrial control network security threat intelligence data (i.e., non-standardized multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment) for training to let the first large model learn how to effectively process complex language structures and diverse information sources. Finally, adopt appropriate evaluation metrics, such as accuracy, recall rate, F1 value, etc., to evaluate the performance of the first large model after introducing the gating mechanism and compare it with the first large model without using the gating mechanism to verify the effectiveness of the gating mechanism.
[0033] Please continue to refer to Figure 2 , which is a flowchart of constructing a multi-dimensional knowledge base for security threats provided by an embodiment of the present invention. As Figure 2 shown, in some exemplary embodiments, the step S100, using the first large model with a gating mechanism to process the collected non-standardized multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to construct a multi-dimensional knowledge base for security threats, includes: step S110, using the first large model with a gating mechanism to perform integration and normalization processing on the non-standardized multi-source data to obtain security threat information; step S120, converting the security threat information into nodes and edges in the knowledge graph and storing the knowledge graph using a graph database, thereby constructing a multi-dimensional knowledge base for security threats.
[0034] Since the security threat intelligence data collected from different sources (i.e., non-standardized multi-source data related to security vulnerabilities and attack behaviors in heterogeneous industrial control network environments) may include information such as vulnerability descriptions, attack techniques, affected systems, business specifications, etc., and may also contain some semi-structured or unstructured data, such as tables in security reports, key information in pictures, etc., by leveraging the natural language processing capabilities of the first large model with a gated mechanism, these data can be understood and integrated to extract key information, such as vulnerability types, attack methods, business specifications, etc.; by using the first large model with a gated mechanism to normalize the non-standardized multi-source data, a unified data format and standard can be specified for data from different sources. For example, vulnerability information can be standardized according to fields such as vulnerability number, vulnerability name, vulnerability description, scope of impact, repair suggestions, etc. At the same time, the first large model with a gated mechanism can also clean and transform data from different sources, remove duplicate information, correct incorrect data, and convert it into a unified format. By using the first large model with a gated mechanism to further analyze and process the normalized non-standardized multi-source data, deeper security threat information can be extracted, such as potential attack paths, possible attack consequences, etc.
[0035] Specifically, vulnerabilities in security threat information can be used as nodes, and the relationships between vulnerabilities and affected systems, attack means, etc. can be used as edges.
[0036] Furthermore, the first large model with a gated mechanism can output the obtained security threat information in the form of reports, charts, database records, etc. according to the user's requirements and specific output formats.
[0037] In some exemplary embodiments, the non-standardized multi-source data is collected through the following steps: using an automated tool to regularly scan the vulnerability database to obtain newly discovered security vulnerability information related to heterogeneous industrial control networks, and subscribing to the mailing lists and RSS feeds of security vendors and research institutions to receive the latest security threat intelligence in a timely manner; screening and classifying the collected security vulnerability information and security threat intelligence according to the characteristics of the heterogeneous industrial control network.
[0038] Thus, by screening the collected security vulnerability information and security threat intelligence, irrelevant information can be removed; by classifying the collected security vulnerability information and security threat intelligence according to vulnerability types, attack means, business specifications, affected industrial control systems, etc., subsequent processing can be facilitated. Specifically, the sources of the non-standardized multi-source data include: vulnerability databases such as the National Information Security Vulnerability Database (CNNVD), the National Vulnerability Database (NVD) of the United States, etc.; reports and research results of industrial control security manufacturers; security forums and communities such as FreeBuf, Anquanke, etc., where users share experiences and cases regarding industrial control network security; reports released by professional security research institutions.
[0039] Please continue to refer to Figure 3 , which is a flowchart for obtaining the security vulnerability mining results provided by an embodiment of the present invention. As Figure 3 shown, in some exemplary embodiments, the step S200, based on the second large model, uses a preset security vulnerability mining strategy to perform security vulnerability mining on the target heterogeneous industrial control terminal system to obtain the security vulnerability mining results of the target heterogeneous industrial control terminal system, including: step S210, performing static taint analysis on the target heterogeneous industrial control terminal system based on the static taint analysis method of shared keywords to obtain the first vulnerability mining result; step S220, performing hybrid dynamic testing on the target heterogeneous industrial control terminal system based on the dynamic fuzz testing method assisted by binary slicing to obtain the second vulnerability mining result; step S230, based on the chain of thought technology and prompt engineering, using the second large model to analyze the first vulnerability mining result and the second vulnerability mining result to obtain the security vulnerability mining results of the target heterogeneous industrial control terminal system.
[0040] Thus, through the above steps S210 to S230, not only can the comprehensiveness, accuracy, and depth of vulnerability mining be effectively improved, but also the complexity and diversity of the heterogeneous industrial control terminal system can be adapted, effectively ensuring the comprehensiveness, efficiency, and intelligence of security vulnerability mining.
[0041] Specifically, a large amount of security vulnerability data of heterogeneous industrial control terminal systems can be obtained based on the multi-dimensional security threat knowledge base, including known vulnerability types, vulnerability characteristics, and repair methods, etc. These data are used to train the second model, enabling the second model to learn how to identify and analyze security vulnerabilities. Specifically, deep learning techniques such as neural networks and recurrent neural networks can be employed to construct and train the second model. Further, the trained second model is optimized to improve its accuracy and efficiency. For example, techniques such as hyperparameter tuning and model compression can be used to optimize the performance of the second model. By leveraging the chain-of-thought technique, the second model gradually analyzes the first vulnerability mining result and the second vulnerability mining result. For example, for the discovered buffer overflow vulnerability, the second model can gradually analyze aspects such as the manifestation form of the vulnerability, possible causes, and scope of influence, providing a deeper understanding of the vulnerability. Through the chain-of-thought technique, the second model can generate a detailed vulnerability report, including information such as a description of the vulnerability, repair suggestions, and risk assessment. In terms of prompt engineering, by designing appropriate prompts, the second model can be guided to perform specific vulnerability mining tasks. For example, prompts such as "Find buffer overflow vulnerabilities" and "Analyze SQL injection risks" can be used to make the second model focus on specific types of vulnerability mining.
[0042] In some exemplary embodiments, the step S210, the static taint analysis method based on shared keywords, performs static taint analysis on the target heterogeneous industrial control terminal system to obtain the first vulnerability mining result, including: analyzing sensitive data or critical operations existing in the target heterogeneous industrial control terminal system, and determining keywords related to the sensitive data or the critical operations; scanning the source code of the target heterogeneous industrial control terminal system to find code segments containing the keywords; analyzing the context of the found code segments, and checking for vulnerability points based on the analysis results of the context of the code segments to obtain the first vulnerability mining result.
[0043] Specifically, different types of industrial control terminal systems have different specific keywords. For example, in an industrial control system, possible keywords include "sensor data", "control instructions", "communication protocol", etc.; for a system involving user input and database interaction, possible keywords include "user input", "database query", "SQL statement", etc. Scan the source code of the target heterogeneous industrial control terminal system to find code segments containing shared keywords. Analyze the context of these code segments to determine the source and flow of data. For example, if a code segment containing the keyword "user input" is found, trace the propagation path of the input data in the system to see if there is any situation where it is used without proper verification or filtering. Check possible vulnerability points, such as buffer overflow, SQL injection, command injection, etc. For buffer overflow, check whether the length limit of the input data and the memory allocation are reasonable; for SQL injection, check whether the SQL statements of user input are sufficiently filtered and escaped.
[0044] In some exemplary embodiments, step S220, the hybrid dynamic testing method based on binary slicing assistance is used to perform hybrid dynamic testing on the target heterogeneous industrial control terminal system to obtain a second vulnerability mining result, including: using a binary slicing tool to analyze the target program of the target heterogeneous industrial control terminal system to determine the code path related to the test target of the target heterogeneous industrial control terminal system; analyzing the logical structure and input-output relationship of the sliced code according to the code path; generating random input data according to the analysis results of the logical structure and input-output relationship of the sliced code; inputting the input data into the target program to perform dynamic fuzz testing on the target program; and finding vulnerabilities according to the dynamic fuzz testing result of the target program to obtain a second vulnerability mining result.
[0045] Specifically, for a heterogeneous industrial control terminal system, key control programs, communication modules, or data processing modules can be selected as test targets. Using a binary slicing tool to analyze the target program of the target heterogeneous industrial control terminal system can determine the code path related to the function or data of the test target. For example, if the security of a communication module is to be tested, the code path related to data reception and processing can be found through binary slicing. Further analyzing the sliced code can help understand its logical structure and input-output relationship, providing guidance for subsequent fuzz testing.
[0046] Then, generate random input data, including combinations of various possible boundary values, outliers, and legal values. Input these input data into the target program and observe the behavior and output of the target program. An automated testing tool can be used to execute this process, and the running state, error messages, and crashes of the target program can be recorded.
[0047] Finally, analyze the test results and find possible vulnerabilities. For example, if the target program crashes or produces abnormal behavior under specific input data, there may be vulnerabilities such as buffer overflow, memory leak, logic error, etc. Further, different types of fuzz testing techniques can be combined, such as mutation-based fuzz testing, generation-based fuzz testing, and protocol-based fuzz testing, to improve the effect of vulnerability mining.
[0048] Please continue to refer to Figure 4 , which is a flow chart of obtaining attack behavior detection results provided by one embodiment of the present invention. Figure 4 As shown, in some exemplary embodiments, the step S300, based on the security threat multi-dimensional knowledge base, uses a preset intrusion detection strategy to perform intrusion detection on the target heterogeneous industrial control network to obtain the attack behavior detection result of the target heterogeneous industrial control network, including: step S310, based on a multi-dimensional traffic characterization algorithm for lightweight feature extraction, feature extraction of the traffic of the target heterogeneous industrial control network from the time dimension, space dimension and content dimension, and based on the extracted time dimension features, space dimension features and content dimension features, feature association is performed on different stages of cross-domain multi-hop attack behavior to obtain feature association results; step S320. Based on the multidimensional knowledge base of security threats, dynamically updated information technology network detection rule sets and operational technology network detection rule sets are respectively constructed, and in combination with the feature association results, real-time alarms of traditional attack types and unknown threats are preliminarily screened to obtain preliminary screening results. Step S330. Based on the multidimensional knowledge base of security threats and the preliminary screening results, attack samples are constructed. Step S340. The attack samples are input into a meta-learning small model and at least one intrusion detection model to perform multi-model collaborative real-time intrusion detection to obtain attack behavior detection results of the target heterogeneous industrial control network.
[0049] Since a cross-domain multi-hop attack may exhibit different characteristics at different time and spatial locations, associating the different stages of the cross-domain multi-hop attack behavior based on the extracted time dimension features, space dimension features, and content dimension features can help to better understand the overall picture of the attack; by using meta-learning small models and other intrusion detection models for collaborative detection, multiple different types of models can be combined to improve the accuracy and reliability of detection.
[0050] Specifically, the time series characteristics of the target heterogeneous industrial control network traffic can be analyzed, such as the peak time, trough time, periodicity, etc. of the traffic. The characteristics in the time dimension can be extracted by statistically analyzing indicators such as the traffic volume and the number of data packets in different time periods. At the same time, consider the source and destination of the traffic, that is, the spatial distribution characteristics of the traffic. The spatial characteristics of the traffic can be determined by analyzing information such as IP addresses, port numbers, and protocol types. For example, some attacks may come from a specific IP address range or a specific network area. By extracting the characteristics in the spatial dimension, the sources of these abnormal traffic can be better identified. By analyzing the content of the data packets of the traffic, key information is extracted as a characteristic. Further, deep packet inspection (DPI) technology or machine learning algorithms can be used to identify specific patterns or keywords in the data packets. For example, for attack traffic, it may contain specific attack codes or malicious instructions. By extracting the characteristics in the content dimension, these attack traffic can be detected more accurately.
[0051] Further, based on the multi-dimensional knowledge base of security threats, detection rule sets for IT (Information Technology) networks and OT (Operational Technology) networks are respectively constructed. These detection rules can include signature-based detection rules, behavior-based detection rules, etc. For known vulnerability attacks, the characteristics and attack methods of the vulnerabilities can be used to construct signature detection rules. For unknown threats, behavior-based detection rules can be used to discover potential attacks by analyzing the abnormal behavior of the traffic.
[0052] In some exemplary embodiments, the step S330, constructing an attack sample based on the multi-dimensional knowledge base of security threats and the preliminary screening result, includes: obtaining vulnerability information based on the multi-dimensional knowledge base of security threats, where the vulnerability information includes vulnerability type, scope of influence, and triggering conditions; combining the vulnerability information with the preliminary screening result to determine potential attack scenarios and potential attack paths; constructing an attack sample according to the potential attack scenarios and the potential attack paths.
[0053] Specifically, by deeply analyzing the discovered heterogeneous industrial control terminal vulnerabilities (i.e., the vulnerabilities recorded in the multi-dimensional security threat knowledge base), characteristic information of the vulnerabilities can be extracted, such as vulnerability types, affected scopes, triggering conditions, etc. For example, vulnerability scanning tools, security analysis software, etc. can be used to analyze the vulnerabilities to obtain detailed vulnerability information. Combining the obtained vulnerability information with the preliminary screening results obtained in step S320, possible attack scenarios and attack paths (i.e., potential attack scenarios and potential attack paths) can be determined. For example, if the preliminary screening results show the existence of abnormal traffic from an external network, and the discovered vulnerability information indicates that this vulnerability can be exploited by external attackers, then it can be inferred that there may be an external attack against this vulnerability.
[0054] According to the analysis results of potential attack scenarios and potential attack paths, attack samples are constructed to simulate possible attack behaviors. Attack samples can include malicious data packets, attack scripts, etc. Attack samples can be used for further testing and analysis to verify the effectiveness of detection and the reliability of protection measures.
[0055] Furthermore, a large number of attack samples (which can be sourced from the multi-dimensional security threat knowledge base) and normal traffic samples can be collected for training the meta-learning small model. The meta-learning small model can be a deep learning-based model, such as a convolutional neural network (CNN), a recurrent neural network (RNN), etc. During the training process, the meta-learning small model learns the characteristics and patterns of different types of attacks, as well as the characteristics of normal traffic. By continuously adjusting the parameters of the meta-learning small model, the detection accuracy of the meta-learning small model for attacks and the false alarm rate for normal traffic are improved.
[0056] Furthermore, techniques such as ensemble learning and multi-modal fusion can be used to combine multiple different types of models to improve the detection accuracy and reliability. For example, the meta-learning small model can be combined with signature-based intrusion detection models, behavior-based intrusion detection models, etc. to jointly monitor network traffic in real time. Since different types of models can detect attacks from different perspectives and complement each other, the detection effect can be effectively improved.
[0057] Furthermore, when an attack behavior is detected, an alarm is issued in a timely manner, and corresponding protection measures are taken, such as blocking attack traffic, isolating the attacked device, etc.; when a vulnerability is detected, corresponding vulnerability repair strategies can be adopted based on the multi-dimensional security threat knowledge base.
[0058] In some exemplary embodiments, the intelligent protection method for heterogeneous industrial control networks based on large models provided by the present invention further includes: updating the multi-dimensional security threat knowledge base according to the security vulnerability mining results and the attack behavior detection results. Thereby, the accuracy and comprehensiveness of the multi-dimensional security threat knowledge base can be ensured, and further, the intelligent collaborative protection effect of the heterogeneous industrial control network environment can be effectively improved.
[0059] Based on the same inventive concept, the present invention also provides an intelligent protection system for heterogeneous industrial control networks based on large models. Please continue to refer to Figure 5 and Figure 6 , wherein, Figure 5 is a structural block diagram of an intelligent protection system for heterogeneous industrial control networks based on large models provided by an embodiment of the present invention; Figure 6 is a schematic diagram of an intelligent protection system for heterogeneous industrial control networks based on large models provided by an embodiment of the present invention. As Figure 5 and Figure 6 shown, the intelligent protection system for heterogeneous industrial control networks based on large models provided by the present invention includes: a knowledge base construction module 110 configured to process the non-standard multi-source data collected related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment by using a first large model introducing a gating mechanism to construct a multi-dimensional security threat knowledge base; a security vulnerability mining module 120 configured to train a second large model based on the multi-dimensional security threat knowledge base and use a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities of a target heterogeneous industrial control terminal system to obtain security vulnerability mining results of the target heterogeneous industrial control terminal system; an intrusion detection module 130 configured to perform intrusion detection on a target heterogeneous industrial control network by using a preset intrusion detection strategy based on the multi-dimensional security threat knowledge base to obtain attack behavior detection results of the target heterogeneous industrial control network; and an intelligent collaborative protection module 140 configured to take corresponding protection measures according to the security vulnerability mining results and the attack behavior detection results.
[0060] It should be noted that the intelligent protection system for heterogeneous industrial control networks based on large models provided by the present invention can be used to execute the intelligent protection method for heterogeneous industrial control networks based on large models described above. The technical principles, the technical problems solved, and the technical effects produced by the two are similar. Those skilled in the art of this technology can clearly understand that for the convenience and brevity of description, for more content about the intelligent protection system for heterogeneous industrial control networks based on large models provided by the present invention, reference can be made to the content described above about the intelligent protection method for heterogeneous industrial control networks based on large models provided by the present invention, which will not be elaborated here.
[0061] Based on the same inventive concept, the present invention also provides an electronic device. Please refer to Figure 7, which is a structural block diagram of an electronic device provided by an embodiment of the present invention. As Figure 7 shown, the electronic device includes: a processor 210, a communication interface 220, a memory 230, and a communication bus 240. Among them, the processor 210, the communication interface 220, and the memory 230 complete mutual communication through the communication bus 240. The processor 210 can call the computer program in the memory 230 to execute the above-mentioned heterogeneous industrial control network intelligent protection method based on a large model. Since the electronic device provided by the present invention and the heterogeneous industrial control network intelligent protection method provided by the present invention belong to the same inventive concept, the electronic device provided by the present invention has at least all the beneficial effects of the heterogeneous industrial control network intelligent protection method provided by the present invention. For specific details, reference can be made to the relevant descriptions above. Therefore, the beneficial effects of the electronic device provided by the present invention will not be elaborated one by one here.
[0062] It should be noted that the computer program in the memory 230 can be implemented in the form of a software functional unit and sold or used as an independent product. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or this part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the heterogeneous industrial control network intelligent protection method described in the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0063] The present invention also provides a readable storage medium. The computer program stored in the readable storage medium can implement the above-mentioned heterogeneous industrial control network intelligent protection method when executed by a processor. Since the readable storage medium provided by the present invention and the heterogeneous industrial control network intelligent protection method provided by the present invention belong to the same inventive concept, the readable storage medium provided by the present invention has at least all the beneficial effects of the heterogeneous industrial control network intelligent protection method provided by the present invention. Therefore, for the beneficial effects of the readable storage medium provided by the present invention, reference can be made to the relevant descriptions of the beneficial effects of the heterogeneous industrial control network intelligent protection method provided by the present invention above, and they will not be elaborated one by one here.
[0064] In summary, compared with the prior art, the intelligent protection method, system, electronic device and readable storage medium for heterogeneous industrial control networks based on large models provided by the present invention have the following beneficial effects: By using a first large model with a gating mechanism to process the non-standard multi-source data collected related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment, a multi-dimensional knowledge base of security threats can be constructed, which can improve the performance and accuracy of the large model in processing complex language structures, thereby effectively ensuring the accuracy of the constructed multi-dimensional knowledge base of security threats; By training a second large model based on the multi-dimensional knowledge base of security threats and using a preset security vulnerability mining strategy based on the second large model to mine security vulnerabilities in the target heterogeneous industrial control terminal system, the accuracy of the obtained security vulnerability mining results can be effectively ensured; By using a preset intrusion detection strategy based on the multi-dimensional knowledge base of security threats to detect intrusions in the target heterogeneous industrial control network, the accuracy of the obtained attack behavior detection results can be effectively ensured. In summary, the present invention can automatically verify the exploitability of security vulnerabilities, evaluate the risks of attack behaviors, and perform corresponding processing on vulnerabilities and attack behaviors, thereby realizing intelligent collaborative protection of the heterogeneous industrial control network environment.
[0065] It should be noted that the above description is only a description of the preferred embodiments of the present invention, and does not limit the scope of the present invention in any way. Any changes and modifications made by those of ordinary skill in the field of the present invention according to the above disclosure are within the scope of protection of the present invention.
Claims
1. A large model-based intelligent protection method for heterogeneous industrial control networks, characterized in that: include: The first model that introduces the gating mechanism is used to process the collected non-standardized multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to build a multi-dimensional knowledge base of security threats; A second large model is obtained based on the security threat multi-dimensional knowledge base training, and a preset security vulnerability mining strategy is used to mine security vulnerabilities of a target heterogeneous industrial control terminal system based on the second large model to obtain security vulnerability mining results of the target heterogeneous industrial control terminal system; Based on the security threat multi-dimensional knowledge base, a preset intrusion detection strategy is used to perform intrusion detection on the target heterogeneous industrial control network to obtain attack behavior detection results of the target heterogeneous industrial control network; Taking corresponding protective measures according to the security vulnerability mining results and the attack behavior detection results; The method of performing intrusion detection on a target heterogeneous industrial control network based on the security threat multi-dimensional knowledge base using a preset intrusion detection strategy to obtain an attack behavior detection result of the target heterogeneous industrial control network includes: A multi-dimensional traffic characterization algorithm based on lightweight feature extraction is used to extract features of the target heterogeneous industrial control network traffic from the time dimension, space dimension, and content dimension. Based on the extracted time dimension features, space dimension features, and content dimension features, feature association is performed on different stages of cross-domain multi-hop attack behaviors to obtain feature association results. Based on the security threat multi-dimensional knowledge base, dynamically updated information technology network detection rule sets and operational technology network detection rule sets are respectively constructed, and combined with the feature association results, real-time alarms of traditional attack types and unknown threats are preliminarily screened to obtain preliminary screening results; Constructing an attack sample based on the security threat multidimensional knowledge base and the preliminary screening results; The attack sample is input into a meta-learning small model and at least one intrusion detection model to perform multi-model collaborative real-time intrusion detection to obtain attack behavior detection results of the target heterogeneous industrial control network.
2. The large model-based intelligent protection method for heterogeneous industrial control networks according to claim 1 is characterized in that: The first model using the gating mechanism is used to process the collected non-standardized multi-source data related to security vulnerabilities and attack behaviors in the heterogeneous industrial control network environment to build a multi-dimensional knowledge base of security threats, including: The non-standardized multi-source data is integrated and normalized using a first model that introduces a gating mechanism to obtain security threat information; The security threat information is converted into nodes and edges in a knowledge graph, and a graph database is used to store the knowledge graph, thereby constructing a multi-dimensional knowledge base of security threats.
3. The large model-based intelligent protection method for heterogeneous industrial control networks according to claim 1 is characterized in that: The method of performing security vulnerability mining on the target heterogeneous industrial control terminal system using a preset security vulnerability mining strategy based on the second large model to obtain security vulnerability mining results of the target heterogeneous industrial control terminal system includes: Based on a static taint analysis method of shared keywords, a static taint analysis is performed on the target heterogeneous industrial control terminal system to obtain a first vulnerability mining result; Based on the binary slicing-assisted dynamic fuzz testing method, a hybrid dynamic test is performed on the target heterogeneous industrial control terminal system to obtain a second vulnerability mining result; Based on the thinking chain technology and prompt word engineering, the second large model is used to analyze the first vulnerability mining result and the second vulnerability mining result to obtain the security vulnerability mining result of the target heterogeneous industrial control terminal system.
4. The large model-based intelligent protection method for heterogeneous industrial control networks according to claim 3 is characterized in that: The static taint analysis method based on shared keywords performs static taint analysis on the target heterogeneous industrial control terminal system to obtain a first vulnerability mining result, including: Analyze sensitive data or key operations in the target heterogeneous industrial control terminal system, and determine keywords related to the sensitive data or the key operations; Scanning the source code of the target heterogeneous industrial control terminal system to find out the code segment containing the keyword; The context of the found code segment is analyzed, and based on the analysis result of the context of the code segment, the vulnerability point is checked to obtain a first vulnerability mining result.
5. The large model-based intelligent protection method for heterogeneous industrial control networks according to claim 3 is characterized in that: The binary slicing-assisted dynamic fuzzy testing method performs a hybrid dynamic test on the target heterogeneous industrial control terminal system to obtain a second vulnerability mining result, including: Analyzing the target program of the target heterogeneous industrial control terminal system using a binary slicing tool to determine a code path related to a test target of the target heterogeneous industrial control terminal system; Analyzing the logical structure and input-output relationship of the sliced code according to the code path; Generate random input data according to the analysis results of the logical structure and input-output relationship of the sliced code; Inputting the input data into the target program to perform dynamic fuzz testing on the target program; According to the dynamic fuzzy test result of the target program, vulnerabilities are found to obtain a second vulnerability mining result.
6. The large model-based intelligent protection method for heterogeneous industrial control networks according to claim 1 is characterized in that: The constructing of attack samples based on the security threat multi-dimensional knowledge base and the preliminary screening results includes: Based on the security threat multi-dimensional knowledge base, vulnerability information is obtained, wherein the vulnerability information includes vulnerability type, impact scope and triggering condition; combining the vulnerability information with the preliminary screening results to determine potential attack scenarios and potential attack paths; An attack sample is constructed according to the potential attack scenario and the potential attack path.
7. A large-model-based intelligent protection system for heterogeneous industrial control networks, characterized in that: include: a knowledge base construction module configured to process the collected non-standardized multi-source data related to security vulnerabilities and attack behaviors in a heterogeneous industrial control network environment using a first large model that introduces a gating mechanism, so as to construct a multi-dimensional knowledge base of security threats; A security vulnerability mining module is configured to obtain a second large model based on the security threat multi-dimensional knowledge base training, and to perform security vulnerability mining on a target heterogeneous industrial control terminal system using a preset security vulnerability mining strategy based on the second large model to obtain a security vulnerability mining result of the target heterogeneous industrial control terminal system; An intrusion detection module is configured to perform intrusion detection on a target heterogeneous industrial control network using a preset intrusion detection strategy based on the security threat multi-dimensional knowledge base, so as to obtain an attack behavior detection result of the target heterogeneous industrial control network; as well as An intelligent collaborative protection module, configured to take corresponding protection measures according to the security vulnerability mining results and the attack behavior detection results; The method of performing intrusion detection on a target heterogeneous industrial control network based on the security threat multi-dimensional knowledge base using a preset intrusion detection strategy to obtain an attack behavior detection result of the target heterogeneous industrial control network includes: A multi-dimensional traffic characterization algorithm based on lightweight feature extraction is used to extract features of the target heterogeneous industrial control network traffic from the time dimension, space dimension, and content dimension. Based on the extracted time dimension features, space dimension features, and content dimension features, feature association is performed on different stages of cross-domain multi-hop attack behaviors to obtain feature association results. Based on the security threat multi-dimensional knowledge base, dynamically updated information technology network detection rule sets and operational technology network detection rule sets are respectively constructed, and combined with the feature association results, real-time alarms of traditional attack types and unknown threats are preliminarily screened to obtain preliminary screening results; Constructing an attack sample based on the security threat multidimensional knowledge base and the preliminary screening results; The attack sample is input into a meta-learning small model and at least one intrusion detection model to perform multi-model collaborative real-time intrusion detection to obtain attack behavior detection results of the target heterogeneous industrial control network.
8. An electronic device, characterized in that: It comprises a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the large model-based intelligent protection method for heterogeneous industrial control networks described in any one of claims 1 to 6 is implemented.
9. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the large model-based intelligent protection method for heterogeneous industrial control networks described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Data mining method and early warning system based on optimal feature subset strategy
CN116860838A
Asset risk tracing method and device
CN119205351A