Intrusion Detection and Defense System and Method for the Industrial Control Network of Gates and Pumps in the Water Conservancy Industry

By building a virus transmission sequence chart and real-time update rule base, the problems of virus regeneration and mutation are solved, and the safety and stability of the gate pump industrial control network in the water conservancy industry are improved.

CN119728243BActive Publication Date: 2025-07-18NINGBO HONGTAI WATER RESOURCES INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411900381.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-07-18
Estimated Expiration
2044-12-23

AI Technical Summary

Technical Problem

The existing technology cannot effectively detect and prevent the regeneration and mutation of viruses, resulting in the safety and stability of the gate pump industrial control network in the water conservancy industry.

Method used

The intrusion detection module, virus cleaning module, regenerated virus deep analysis module and advance prevention module are used to construct a virus transmission sequence chart through numerical estimation methods and deep learning algorithms, and the rule base of the intrusion detection system is updated in real time to identify and prevent virus regeneration and mutation.

Benefits of technology

The detection efficiency and accuracy of the intrusion detection system are improved, and the safety and stability of the gate pump industrial control network in the water conservancy industry are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728243B_ABST
    Figure CN119728243B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of water conservancy industry network security technology. Specifically, it relates to an intrusion detection and prevention system and method for the gate pump industrial control network in the water conservancy industry. It includes an intrusion detection module, a virus cleaning module, a deep analysis module for regenerated viruses, and an early prevention module. According to the virus regeneration analysis unit, based on the numerical estimation method, it judges the situation of virus regeneration, prevents regenerated and mutated viruses in advance, constructs a virus transmission sequence chart through the basic reproduction number and the number of finally infected nodes, compares the characteristics and information of new viruses with the historical virus transmission sequence chart, and judges historical viruses or new viruses according to the comparison results. The analysis data is imported into the established neural network model, and these characteristics are converted into rules by using the rule generation algorithm and updated into the rule base of the intrusion detection system in real time, thereby expanding the rule base of the intrusion detection system and improving the detection efficiency and accuracy of the intrusion detection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security in the water conservancy industry. Specifically, it relates to an intrusion detection and prevention system and method for the industrial control network of sluice pumps in the water conservancy industry. Background Art

[0002] With the continuous development and in-depth research of various network applications, network attacks such as computer viruses, Trojans, and hacker attacks have become increasingly rampant. At present, network security incidents have entered a high-incidence period, which has had a serious impact on the production and life of the entire society. As a key information infrastructure involving multiple industries, the industrial control system is an important part of the modern production process. However, with the development of the networking and informatization of the industrial control system, the possibility of it being attacked by the network is also rising rapidly, and the impact on the industrial control system is showing an increasingly fierce development trend.

[0003] In the prior art, when detecting and preventing network viruses, a honeypot system usually simulates vulnerable systems, services, or information to attract and deceive potential viruses, thereby collecting information about virus behavior and strategies. Then, the captured data is input into the established neural network model, and new intrusion rules for virus behavior are obtained based on the output data. The new intrusion rules in the intrusion rules replace the corresponding old rules, and at the same time, the old rules are deleted. Although this method can reduce the system burden of the intrusion detection system, improve the detection efficiency and accuracy, and has a preventive effect. However, since viruses have the phenomenon of mutation and regeneration, and the above method cannot detect whether the virus has the possibility of regeneration, and the mutated virus will show different behaviors from before. Different behaviors correspond to different intrusion rules. By calculating the similarity between sequences through the virus sequence comparison method in the prior art, and then judging whether the mutated virus is mutated from the historical virus. This method requires processing a large amount of data, occupying system resources, and sequence comparison is usually only carried out for known virus sequences. For newly emerging and unknown viruses, or viruses with large mutations, the comparison results cannot accurately reflect the similarity between viruses, thereby affecting the control of sluice pumps in the water conservancy industry. Summary of the Invention

[0004] The purpose of the present invention is to provide an intrusion detection and prevention system and method for the industrial control network of sluice pumps in the water conservancy industry to solve the problems raised in the above background art.

[0005] To achieve the above object, the present invention aims to provide an intrusion detection and prevention system for the industrial control network of sluice pumps in the water conservancy industry, including an intrusion detection module, a virus cleaning module, a deep analysis module for regenerated viruses, and an early prevention module;

[0006] The intrusion detection module is used to obtain the data parameters sent in the information honeypot environment through an intrusion detection system and preprocess them;

[0007] The virus cleaning module analyzes the obtained data parameters to obtain virus parameters, matches and identifies them in combination with the existing intrusion detection system rule library, and determines whether to clean the virus according to the matching and identification results;

[0008] The regenerative virus in-depth analysis module obtains the status of all nodes in the network. Through a numerical estimation method, based on the node infection rate, node recovery rate, and node average infection period, it calculates the reproduction number and virus transmission range of each virus spreading in the network, constructs a virus transmission sequence chart, stores the virus transmission sequence chart and historical virus data in the virus library, establishes an indexing mechanism, compares the virus transmission sequence chart with the historical virus transmission sequence chart, and determines whether the current virus belongs to the historical virus according to the comparison result;

[0009] The early prevention module analyzes based on the evaluation results using a deep learning algorithm and updates the rule library of the intrusion detection system according to the analysis results.

[0010] As a further improvement of this technical solution, in the intrusion detection module, the data parameters sent in the information honeypot environment are obtained. The data parameters include network traffic data, system logs, file contents, and user behavior data, and the obtained data parameters are analyzed. Irrelevant and redundant information is removed through data cleaning, and the cleaned data is converted into a unified standard format using data standardization technology.

[0011] As a further improvement of this technical solution, in the regenerative virus in-depth analysis module, the status of all nodes in the network is first obtained and divided. The node status is divided into normal status, infected status, isolated status, and recovered status.

[0012] As a further improvement of this technical solution, the regenerative virus in-depth analysis module includes a virus regenerability analysis unit. The specific steps of the numerical estimation method in the virus regenerability analysis unit are as follows:

[0013] The first step: Set parameters. The node infection rate ( ) represents the average number of other nodes infected by each infected node per unit time;

[0014] The node recovery rate ( ) is the probability that each infected node recovers (or is removed) per unit time;

[0015] The node average infection period ( ) is the average time that an infected node remains in the infected state;

[0016] Step 2: Set the basic reproduction number of the virus It is the average number of new nodes that an infected node can infect during its entire infection period in an environment where all nodes are uninfected;

[0017] Step 3: Calculate the basic reproduction number;

[0018] 。

[0019] As a further improvement of this technical solution, in the virus reproductive analysis unit, the virus transmission range is based on the SIR model, and the specific estimation method is as follows:

[0020] ;

[0021] Among them, is the total number of network nodes, is the basic reproduction number, is the number of finally infected nodes, and the basic reproduction number is a threshold parameter. When the virus can spread in the network. When the virus will gradually die out;

[0022] Then, the calculated basic reproduction number and the number of finally infected nodes are integrated according to the time series to construct a sequence of virus transmission changes in the network transmission and form a data set, and a virus transmission sequence chart is constructed based on the data set.

[0023] As a further improvement of this technical solution, the steps of constructing a virus transmission sequence chart in the virus reproductive analysis unit are as follows:

[0024] Use the basic reproduction number of the virus and the number of finally infected nodes as data sources for two dimensions respectively, and construct a virus transmission sequence chart with time as the coordinate;

[0025] Among them, mark and connect the basic reproduction number and the number of finally infected nodes of the virus at different times to form a line chart, and this line chart reflects the curve of the virus transmission range change; and, the historical virus parameter information in the rule library is marked in the chart at the same time;

[0026] The historical virus parameter information includes virus type, basic reproduction number, number of finally infected nodes, and time.

[0027] As a further improvement of this technical solution, the regenerated virus in-depth analysis module includes establishing a data storage unit, and the method of establishing an indexing mechanism in the established data storage unit is shown as follows:

[0028] Based on the hash index, the data source in the virus transmission sequence chart is replaced with a fixed-length hash value through a hash function;

[0029] Using the hash value as the index key and the historical virus parameter information and the storage location of the chart in the virus library as the index value, a hash index table is constructed.

[0030] As a further improvement of this technical solution, the regenerated virus depth analysis module includes a virus evaluation unit. In the virus evaluation unit, the virus transmission sequence chart is compared with the historical virus transmission sequence chart. The comparison steps are as follows:

[0031] Based on the dynamic time warping algorithm, the time dimension of the virus transmission sequence chart and the historical virus chart is compared through dynamic programming to find the best matching path between the two time series, calculate their similarity, and calculate the basic reproduction number similarity and the final infected node number similarity respectively according to the Euclidean distance metric method;

[0032] Respectively set the preset ranges of the basic reproduction number similarity and the final infected node number similarity, and then compare. If the similarities fall into the preset ranges of the basic reproduction number and the final infected node number similarity respectively, it is determined as a historical virus. If only one of the similarities or neither falls into the preset ranges of the basic reproduction number and the final infected node number similarity, it is determined as a mutant virus.

[0033] As a further improvement of this technical solution, the early prevention module is based on the neural network model in the deep learning algorithm. The extracted virus features and corresponding labels are used to train the neural network model. During the training process, the recognition performance of the model is optimized by adjusting the model parameters and the learning rate parameters, and the cross-validation method is used to evaluate the generalization ability of the model;

[0034] Combined with the extracted virus features and corresponding labels, the rule generation algorithm is used to convert these features into rules and update them to the rule library of the intrusion detection system in real time.

[0035] The second object of the invention is to provide a method for intrusion detection and defense for the gate-pump industrial control network in the water conservancy industry, including the following method steps:

[0036] S1. Through the intrusion detection system, obtain the data parameters sent in the information honeypot environment and preprocess them;

[0037] S2. Analyze the obtained data parameters to obtain virus parameters, and combine the virus parameters with the existing rule library of the intrusion detection system for matching and identification, and confirm whether to remove the virus according to the matching and identification results;

[0038] S3. Obtain the status of all nodes in the network. Through numerical estimation methods, calculate the reproduction number and the virus transmission range of each virus spreading in the network based on the node infection rate, the node recovery rate, and the average infection period of the nodes. Then construct a virus transmission sequence chart, store the virus transmission sequence chart and the historical virus data in the virus library, establish an indexing mechanism, compare the virus transmission sequence chart with the historical virus transmission sequence chart, and determine whether the current virus belongs to the historical virus according to the comparison result;

[0039] S4. Analyze based on the deep learning algorithm in combination with the evaluation results, and update the rule library of the intrusion detection system according to the analysis results.

[0040] Compared with the prior art, the beneficial effects of the present invention are:

[0041] In the intrusion detection and defense system for the gate-pump industrial control network in the water conservancy industry, the virus regeneration analysis unit judges the virus regeneration situation based on numerical estimation methods, prevents the regenerated and mutated viruses in advance, constructs a virus transmission sequence chart through the basic reproduction number and the number of finally infected nodes, compares the new virus manifestation characteristics and information with the historical virus transmission sequence chart, and determines whether it is a historical virus or a new virus according to the comparison result. According to the analysis of the new virus, import the analysis data into the established neural network model, use the rule generation algorithm to convert these characteristics into rules, and update them to the rule library of the intrusion detection system in real time, thereby expanding the rule library of the intrusion detection system and improving the detection efficiency and accuracy of the intrusion detection system. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 It is a block diagram of the intrusion detection and defense system for the gate-pump industrial control network in the water conservancy industry according to the present invention;

[0043] Figure 2 It is a flowchart of the intrusion detection and defense method for the gate-pump industrial control network in the water conservancy industry according to the present invention.

[0044] The meanings of the reference numerals in the figure are as follows:

[0045] 100, intrusion detection module; 200, virus cleaning module; 300, deep analysis module for regenerated viruses; 301, virus regeneration analysis unit; 302, establish data storage unit; 303, virus evaluation unit; 400, advance prevention module. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] Next, the technical solutions in the present invention will be clearly and completely described in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without making creative efforts belong to the scope of protection of the present invention.

[0047] As Figure 1 shown, an intrusion detection and prevention system for the sluice pump industrial control network in the water conservancy industry is provided, including an intrusion detection module 100, a virus cleaning module 200, a deep analysis module 300 for regenerated viruses, and an early prevention module 400;

[0048] The intrusion detection module 100 is used to obtain the data parameters sent in the information honeypot environment through the intrusion detection system and preprocess them;

[0049] The virus cleaning module 200 analyzes the obtained data parameters to obtain virus parameters, matches and identifies them in combination with the virus parameters and the existing intrusion detection system rule library, and determines whether to clean the virus according to the matching and identification results;

[0050] The deep analysis module 300 for regenerated viruses obtains the status of all nodes in the network, calculates the reproduction number and virus transmission range of each virus spreading in the network based on the node infection rate, node recovery rate, and average node infection period through numerical estimation methods, constructs a virus transmission sequence chart, stores the virus transmission sequence chart and historical virus data in the virus library, establishes an indexing mechanism, compares the virus transmission sequence chart with the historical virus transmission sequence chart, and determines whether the current virus belongs to the historical virus according to the comparison result;

[0051] The early prevention module 400 analyzes based on the evaluation results using a deep learning algorithm and updates the rule library of the intrusion detection system according to the analysis results.

[0052] In the intrusion detection module 100, the data parameters sent in the information honeypot environment are obtained. The data parameters include network traffic data, system logs, file contents, and user behavior data, and the obtained data parameters are analyzed. Irrelevant and redundant information is removed through data cleaning, and the cleaned data is converted into a unified standard format using data standardization techniques.

[0053] Among them, in order to further improve the quality and usability of the data, data standardization techniques are adopted, which include data coding standardization, data format standardization, data naming standardization, etc. Through standardization processing, it can be ensured that data from different sources and in different formats can be converted into a unified standard format, thus facilitating subsequent analysis and processing.

[0054] Then, according to the obtained data parameters, real-time monitoring and virus scanning technologies are used to obtain the virus signature, the path of the infected file, the behavior pattern of the virus, the risk level, etc. from the data parameters. Since the rule library already contains information such as the signatures, behavior patterns, and signatures of known viruses, through matching, the module can detect the type and characteristics of the virus. If the virus parameters match successfully with a certain virus in the rule library, the virus cleaning module 200 will identify the virus and take corresponding measures to remove the virus, such as: isolating the infected file, deleting the virus code, restoring the original state of the file, etc., and continue to monitor abnormal behaviors after cleaning the virus. If the match is unsuccessful, continue to monitor abnormal behaviors. Secondly, during the cleaning process, the module will ensure that no additional damage is caused to the system and will retain the user's data and files as much as possible for normal use.

[0055] Since the virus will continuously replicate and mutate during the propagation process, when the virus is in the stage of replication and regeneration without mutation, each copy it generates will contain the same signature. This is because the signature is generated based on the original code or data pattern of the virus. If the original code or data pattern remains unchanged, the signature will not change. Therefore, the replicated virus can be removed by the virus cleaning module 200.

[0056] On the contrary, some viruses will mutate during the replication process, such as by changing some of their own parts (such as code segments, encryption methods, etc.) to avoid being detected and removed by antivirus software. At this time, it is impossible to match and identify through the existing intrusion detection system rule library, thus reducing the accuracy of detection.

[0057] In the regenerated virus in-depth analysis module 300, first, the states of all nodes in the network are obtained and divided. The node states are divided into normal state, infected state, isolated state, and restored state. By dividing the states of all nodes in the network, the security status of the network can be more clearly understood, and corresponding security measures can be taken to deal with potential virus threats. This helps to improve the security, stability, and reliability of the network.

[0058] Furthermore, the regenerated virus in-depth analysis module 300 includes a virus regeneration analysis unit 301. The specific steps of the numerical estimation method in the virus regeneration analysis unit 301 are as follows:

[0059] The first step: Set parameters. The node infection rate ( ) represents the average number of other nodes infected by each infected node per unit time;

[0060] The node recovery rate ( ): The probability that each infected node recovers (or is removed) per unit time;

[0061] Average infection period of nodes ( ): The average time an infected node remains in an infected state;

[0062] Step 2: Set the basic reproduction number of the virus It is the average number of new nodes that an infected node can infect during its entire infection period in an environment where all nodes are uninfected;

[0063] Step 3: Calculate the basic reproduction number;

[0064] .

[0065] For example: The infection rate of nodes 2 (i.e., each infected node infects 2 new nodes per day), and the recovery rate of nodes 1 (i.e., each infected node has a 1 probability of recovery), it can be calculated that:

[0066] 10 days, 2;

[0067] That is to say, in this example, the basic reproduction number is 2, meaning that each infected node can infect 3 new nodes on average during the corresponding infection period.

[0068] In the virus reproduction analysis unit 301, the virus transmission range is based on the SIR model, and the specific estimation method is as follows:

[0069] ;

[0070] Among them, is the total number of network nodes, is the basic reproduction number, is the number of finally infected nodes, and the basic reproduction number is a threshold parameter. When , the virus can spread in the network. When , the virus will gradually die out.

[0071] It should be noted that: The above estimation method is only applicable to simple cases and assumes that the network is uniformly mixed (i.e., each node has an equal chance of contacting other nodes).

[0072] Through example calculation , assuming the infection rate of nodes 2, the recovery rate of nodes 1, and the total number of network nodes 1000, the number of finally infected nodes can be calculated to estimate the virus transmission range in the network:

[0073] 98;

[0074] Then, integrate the calculated basic reproduction number and the final number of infected nodes according to the time series, construct a sequence of virus transmission changes in network transmission to form a data set, and construct a virus transmission sequence chart based on the data set.

[0075] The steps of constructing a virus transmission sequence chart in the virus reproduction analysis unit 301 are as follows:

[0076] Use the basic reproduction number of the virus and the final number of infected nodes as data sources for two dimensions, and use time as the coordinate to construct a virus transmission sequence chart; First, when constructing a virus transmission sequence chart, it is necessary to first determine the data source basic reproduction number and the final number of infected nodes, and then determine the time coordinate. The time coordinate is used to represent the time series of virus transmission, usually in days, hours or other time units. By recording the virus transmission situation at each time point, the time series data of virus transmission is constructed. Set the coordinate axes, X-axis: represents the time coordinate, in days, hours or other time units, Y-axis: the left axis represents the basic reproduction number ( ), and the right axis represents the final number of infected nodes (can be adjusted according to needs).

[0077] Among them, mark and connect the basic reproduction number and the final number of infected nodes of the virus at different times to form a line chart, and this line chart reflects the curve of the transmission range change of the virus; And, simultaneously mark the historical virus parameter information in the rule library in the chart;

[0078] The historical virus parameter information includes virus type, basic reproduction number, final number of infected nodes and time.

[0079] By comparing the historical virus parameters, it is easier to identify the characteristics and types of the current virus, which helps to classify and name it more accurately, as well as the subsequent analysis work of the virus.

[0080] Furthermore, the regenerated virus depth analysis module 300 includes establishing a data storage unit 302, and the method of establishing an indexing mechanism in the data storage unit 302 is shown as follows:

[0081] Based on the hash index, the data source in the virus transmission sequence chart is replaced with a fixed-length hash value through a hash function; using the hash value as the index key and the historical virus parameter information and the storage location of the chart in the virus library as the index value, a hash index table is constructed. Suppose there is a virus, and its basic reproduction number R0_T1 at a certain time point T1 is 3.5, and the final number of infected nodes N_T1 is 1000. We use the SHA-256 hash function to convert it into a hash value: Hash(R0_T1)= SHA-256("3.5")="e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855";

[0082] Hash(N_T1)=SHA-256("1000")="5eb63bbbe01eeed093cb22bb8f5acdc33dc222c0b0d8606f6084e0b5b6d4c745";

[0083] Then, we create two entries in the hash index table:

[0084] Index key: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855;

[0085] Index value: {Virus type: "VirusA", Time point: "T1", Basic reproduction number: "3.5", Hash value of the final number of infected nodes: "5eb63bbbe01eeed093cb22bb8f5acdc33dc222c0b0d8606f6084e0b5b6d4c745", Chart storage location: " / path / to / virusA_T1_chart"}.

[0086] The regenerated virus in-depth analysis module 300 includes a virus evaluation unit 303. In the virus evaluation unit 303, the virus transmission sequence chart is compared with the historical virus transmission sequence chart. The comparison steps are as follows:

[0087] Based on the dynamic time warping algorithm, the time dimensions of the virus transmission sequence chart and the historical virus chart are compared through dynamic programming to find the best matching path between the two time series, calculate the similarity between them, and calculate the similarity of the basic reproduction number and the similarity of the final number of infected nodes respectively according to the Euclidean distance metric method;

[0088] For example: Virus A: [(2.5,100), (3.0,200), (2.8,150)];

[0089] Historical virus B: [(2.4, 90), (2.9, 190), (2.7, 140), (3.1, 210)];

[0090] Step 1: Construct distance matrices D_R0 and D_N (only partial shown):

[0091] D_R0: [0, 0.1, 0.2, 0.3] [0.1, 0, 0.1, 0.2] [0.2, 0.1, 0, 0.1];

[0092] D_N: [0, 10, 20, 30] [10, 0, 10, 20] [20, 10, 0, 10];

[0093] Step 2: Use dynamic programming to solve for the optimal matching path (simplified process, full matrix not shown);

[0094] Step 3: Backtrack the optimal matching path (e.g., [(1, 1), (2, 2), (3, 3)]);

[0095] Step 4: Calculate the cumulative distance and similarity (here only as an example);

[0096] Calculate the individual Euclidean distances of the basic reproduction number and the number of finally infected nodes (aggregation of the entire sequence):

[0097] Euclidean distance of the basic reproduction number: sqrt ...;

[0098] Euclidean distance of the number of finally infected nodes: sqrt ...;

[0099] Separate set the preset ranges of similarity for the basic reproduction number and the number of finally infected nodes, and then compare. If the similarities fall within the preset ranges of similarity for the basic reproduction number and the number of finally infected nodes respectively, it is determined as a historical virus. If only one of the similarities or neither falls within the preset ranges of similarity for the basic reproduction number and the number of finally infected nodes, it is determined as a mutant virus.

[0100] Suppose there is a virus to be determined, whose value is 3.2 and the number of finally infected nodes is 6000. At the same time, we have a historical virus database that records the R0 values and the number of finally infected nodes of various historical viruses

[0101] If the values of historical viruses are mostly between 2 and 4, we can set the preset range of similarity as ±0.5 (i.e., similar if between 1.5 and 4.5);

[0102] The number of finally infected nodes is mostly between 1000 and 10000, and the preset similarity range of the number of finally infected nodes is ±2%, that is, it is similar between 800 and 12000;

[0103] Calculate Similarity:

[0104] Assume that the average value of the value of each virus in the historical virus database is 3, then the similarity of the virus to be determined is |(3.2 - 3) / 3| ≈ 0.067, which is less than the preset similarity range of ±0.5 (that is, it is similar within 0.5), so the similarity falls within the preset range;

[0105] Calculate the similarity of the number of finally infected nodes:

[0106] Assume that the average value of the number of finally infected nodes of each virus in the historical virus database is 5000, then the similarity of the number of finally infected nodes of the virus to be determined is |(6000 - 5000) / 5000| = 0.2, which is less than the preset similarity range of the number of finally infected nodes of ±20% (that is, it is similar within 0.2), so the similarity of the number of finally infected nodes also falls within the preset range.

[0107] The early prevention module 400 is based on the neural network model in the deep learning algorithm, and uses the extracted virus features and corresponding labels (i.e., virus species or variants) to train the neural network model. During the training process, by adjusting the model parameters and learning rate parameters, the recognition performance of the model is optimized, and the cross-validation method is used to evaluate the generalization ability of the model;

[0108] Combined with the extracted virus features and corresponding labels, use the rule generation algorithm to convert these features into rules and update them to the rule library of the intrusion detection system in real time. In this way, according to the virus regeneration analysis unit 301, based on the numerical estimation method, judge the virus regeneration situation, prevent the regenerated and mutated viruses in advance, and construct a virus transmission sequence chart through the basic reproduction number and the number of finally infected nodes. Compare the new virus manifestation features and information with the historical virus transmission sequence chart, and judge the historical virus or new virus according to the comparison result. According to the analysis of the new virus, import the analysis data into the established neural network model, use the rule generation algorithm to convert these features into rules, and update them to the rule library of the intrusion detection system in real time, thereby expanding the rule library of the intrusion detection system, improving the detection efficiency and accuracy of the intrusion detection system, and ensuring the smooth operation of the pump gate.

[0109] Such as Figure 2As shown, a method for intrusion detection and prevention of the gate pump industrial control network in the water conservancy industry is presented, including the following method steps:

[0110] S1. Through the intrusion detection system, obtain the data parameters sent in the information honeypot environment and preprocess them;

[0111] S2. Analyze the obtained data parameters to obtain virus parameters, match and identify them by combining the virus parameters with the existing intrusion detection system rule library, and confirm whether to remove the virus according to the matching and identification results;

[0112] S3. Obtain the status of all nodes in the network. Through the numerical estimation method, calculate the reproduction number and virus transmission range of each virus spreading in the network based on the node infection rate, node recovery rate, and average node infection period, and construct a virus transmission sequence chart. Store the virus transmission sequence chart and historical virus data in the virus library, establish an indexing mechanism, compare the virus transmission sequence chart with the historical virus transmission sequence chart, and judge whether the current virus belongs to the historical virus according to the comparison result;

[0113] S4. Analyze based on the deep learning algorithm in combination with the evaluation results, and update the rule library of the intrusion detection system according to the analysis results.

[0114] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.

Claims

1. An intrusion detection and prevention system for the sluice pump industrial control network in the water conservancy industry, characterized in that: It includes an intrusion detection module (100), a virus cleaning module (200), a deep analysis module for regenerated viruses (300), and a preventive module (400); The intrusion detection module (100) is used to obtain the data parameters sent in the information honeypot environment through the intrusion detection system and preprocess them; The virus cleaning module (200) analyzes the obtained data parameters to obtain virus parameters, matches and identifies them in combination with the existing intrusion detection system rule base, and determines whether to clean the virus according to the matching and identification results; The deep analysis module for regenerated viruses (300) obtains the status of all nodes in the network. Through the numerical estimation method, based on the node infection rate, node recovery rate, and average node infection period, it calculates the reproduction number and virus transmission range of each virus in the network, constructs a virus transmission sequence chart, stores the virus transmission sequence chart and historical virus data in the virus library, establishes an indexing mechanism, compares the virus transmission sequence chart with the historical virus transmission sequence chart, and determines whether the current virus belongs to the historical virus according to the comparison result; The deep analysis module for regenerated viruses (300) includes a virus regeneration analysis unit (301). The specific steps of the numerical estimation method in the virus regeneration analysis unit (301) are as follows: Step 1: Set parameters. The node infection rate ( ) represents the average number of other nodes infected by each infected node per unit time; Node recovery rate ( ): The probability that each infected node recovers per unit time; Average infection period of nodes ( ): The average time that an infected node remains in an infected state; Step 2: Set the basic reproduction number of the virus It is the average number of new nodes that an infected node can infect during its entire infectious period in an environment where all nodes are uninfected; Step 3: Calculate the basic reproduction number; ; The steps of constructing the virus transmission sequence chart in the virus regeneration analysis unit (301) are specifically as follows: Use the basic reproduction number and the final number of infected nodes of the virus as the data sources of two dimensions, and construct a virus transmission sequence chart with time as the coordinate; Among them, mark and connect the basic reproduction number and the final number of infected nodes of the virus at different times to form a line chart, and this line chart reflects the change curve of the virus transmission range; and at the same time mark the historical virus parameter information in the rule base in the chart; The historical virus parameter information includes virus type, basic reproduction number, final number of infected nodes, and time; The deep analysis module for regenerated viruses (300) includes a data storage unit establishment (302). The method of establishing the indexing mechanism in the data storage unit establishment (302) is shown as follows: Based on the hash index, use the hash function to convert the data source in the virus transmission sequence chart into a fixed-length hash value; Use the hash value as the index key, and use the historical virus parameter information and the storage location of the chart in the virus library as the index value to construct a hash index table; The deep analysis module for regenerated viruses (300) includes a virus evaluation unit (303). The comparison of the virus transmission sequence chart with the historical virus transmission sequence chart in the virus evaluation unit (303) is as follows: Based on the dynamic time warping algorithm, use the dynamic programming method to compare the time dimensions of the virus transmission sequence chart and the historical virus chart, find the best matching path between the two time series, calculate their similarity, and according to the Euclidean distance metric method, calculate the similarity of the basic reproduction number and the similarity of the final number of infected nodes respectively; Set the preset ranges of the basic reproduction number similarity and the final number of infected nodes similarity respectively, and then compare them. If the similarities fall within the preset ranges of the basic reproduction number and the final number of infected nodes similarity respectively, it is determined to be a historical virus. If only one of the similarities or neither of them falls within the preset ranges of the basic reproduction number and the final number of infected nodes similarity, it is determined to be a mutant virus; The early prevention module (400) analyzes based on a deep learning algorithm in combination with the evaluation results, and updates the rule library of the intrusion detection system according to the analysis results.

2. The intrusion detection and prevention system for the sluice pump industrial control network in the water conservancy industry according to claim 1, characterized in that: In the intrusion detection module (100), obtain the data parameters sent in the information honeypot environment. The data parameters include network traffic data, system logs, file contents, and user behavior data, and analyze the obtained data parameters. Remove irrelevant and redundant information through data cleaning, and use data standardization technology to convert the cleaned data into a unified standard format.

3. The intrusion detection and prevention system for the gate pump industrial control network in the water conservancy industry according to claim 1, characterized in that: In the regenerated virus in-depth analysis module (300), first divide the states of all nodes obtained in the network. The node states are divided into normal state, infected state, isolated state, and recovered state.

4. The intrusion detection and prevention system for the sluice pump industrial control network in the water conservancy industry according to claim 1, characterized in that: In the virus regenerability analysis unit (301), the virus transmission range is based on the SIR model. The specific estimation method is as follows: ; Among them, is the total number of network nodes, is the basic reproduction number, is the number of finally infected nodes, and the basic reproduction number is a threshold parameter. When , the virus can spread in the network. When , the virus will gradually die out; Then integrate the calculated basic reproduction number and the final number of infected nodes in time series, construct a sequence of virus transmission changes in network transmission and form a data set, and construct a virus transmission sequence chart according to the data set.

5. The intrusion detection and prevention system for the gate pump industrial control network in the water conservancy industry according to claim 1, characterized in that: The early prevention module (400) is based on the neural network model in the deep learning algorithm, uses the extracted virus features and corresponding labels to train the neural network model. During the training process, optimize the recognition performance of the model by adjusting the model parameters and learning rate parameters, and use the cross-validation method to evaluate the generalization ability of the model; Combined with the extracted virus features and corresponding labels, use the rule generation algorithm to convert these features into rules and update them in real time to the rule library of the intrusion detection system.

6. A method for intrusion detection and prevention of the industrial control network of sluice pumps in the water conservancy industry, characterized in that, It includes the following method steps: S1. Through the intrusion detection system, obtain the data parameters sent in the information honeypot environment and preprocess them; S2. Analyze the obtained data parameters to obtain virus parameters, match and identify them in combination with the existing rule library of the intrusion detection system, and confirm whether to remove the virus according to the matching and identification results; S3. Obtain the states of all nodes in the network. Through the numerical estimation method, calculate the reproduction number and the virus transmission range of each virus in the network based on the node infection rate, the node recovery rate, and the average node infection period, and construct a virus transmission sequence chart. Store the virus transmission sequence chart and the historical virus data in the virus library, establish an indexing mechanism, compare the virus transmission sequence chart with the historical virus transmission sequence chart, and judge whether the current virus belongs to the historical virus according to the comparison result; The specific steps of the numerical estimation method are as follows: Step 1: Set parameters. The node infection rate ( ) represents the average number of other nodes infected by each infected node per unit time. Node recovery rate ( ): The probability that each infected node recovers per unit time; Average Infection Period of Nodes ( ): The average time that an infected node remains in an infected state; Step 2: Set the basic reproduction number of the virus It is the average number of new nodes that an infected node can infect during its entire infection period in an environment where all nodes are uninfected; The third step: Calculate the basic reproduction number; ; The steps of constructing the virus transmission sequence chart are specifically as follows: Taking the basic reproduction number of the virus and the number of ultimately infected nodes as data sources in two dimensions, a virus transmission sequence chart is constructed with time as the coordinate; Among them, the basic reproduction number and the number of ultimately infected nodes of the virus at different times are marked and connected to form a line chart, which reflects the change curve of the transmission range of the virus; moreover, the historical virus parameter information in the rule base is marked in the chart at the same time; The historical virus parameter information includes virus type, basic reproduction number, number of ultimately infected nodes, and time; The method for establishing the indexing mechanism is shown as follows: Based on hash indexing, the data source in the virus transmission sequence chart is converted into a fixed-length hash value through a hash function; Using the hash value as the index key, the historical virus parameter information and the storage location of the chart in the virus library are used as index values to construct a hash index table; The comparison of the virus transmission sequence chart and the historical virus transmission sequence chart is as follows: Based on the dynamic time warping algorithm, the time dimensions of the virus transmission sequence chart and the historical virus chart are compared through dynamic programming to find the best matching path between the two time series, calculate their similarity, and calculate the basic reproduction number similarity and the number of ultimately infected nodes similarity respectively according to the Euclidean distance metric method; The preset ranges of the basic reproduction number similarity and the number of ultimately infected nodes similarity are set respectively, and then compared. If the similarities fall within the preset ranges of the basic reproduction number and the number of ultimately infected nodes similarity respectively, it is determined as a historical virus. If only one of the similarities or neither falls within the preset ranges of the basic reproduction number and the number of ultimately infected nodes similarity, it is determined as a mutant virus; S4. Analyze based on the deep learning algorithm in combination with the evaluation results, and update the rule base of the intrusion detection system according to the analysis results.

Citation Information

Patent Citations

  • Computer virus vaccine broadcasting method in distributed environment

    CN101169747A

  • Network security risk evaluation and autonomic defense system

    CN106850551A