Industrial control system security vulnerability analysis method and system for petroleum refining scene

By constructing a functional control structure model and conducting multi-dimensional causal analysis, the shortcomings in the analysis of security vulnerabilities of industrial control systems in the petroleum refining scenario were addressed, enabling global risk identification and management optimization, and improving the system's security and reliability.

CN119806065BActive Publication Date: 2025-12-26HUAZHONG UNIV OF SCI & TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411862605.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-12-26
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

Existing technologies for analyzing the security vulnerabilities of industrial control systems in petroleum refining scenarios lack systematic and effective analysis in dynamic interactive scenarios, making it difficult to comprehensively identify potential security risks. Furthermore, traditional methods suffer from human uncertainty and insufficient analytical depth.

Method used

By constructing a functional control structure model, we identify the target tasks, key functions, and interactive objects of the petroleum refining system, divide the control structure hierarchy, analyze the behavior and feedback of control components, identify unsafe control behaviors (UCA), and conduct causal analysis from multiple dimensions to deduce safety vulnerabilities.

Benefits of technology

It enables a comprehensive analysis of the safety vulnerabilities of petroleum refining systems, accurately identifies potential hazards, reduces safety risks, optimizes safety management, improves analysis efficiency and accuracy, and reduces economic losses and environmental risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119806065B_ABST
    Figure CN119806065B_ABST
Patent Text Reader

Abstract

The application belongs to the field of safety engineering, and discloses a kind of industrial control system security vulnerability analysis method and system for petroleum refining scene, the method first determines system target task, key function and interactive object, determines unacceptable loss, hazard and safety constraint;Then, the control structure level of system is divided, control behavior, feedback and other information are determined, functional control structure model is established and four types of unsafe control behaviors are determined;After that, cause analysis is carried out, and a variety of loss scenarios are generated, cause factors are analyzed from the aspects of process model, system environment, communication defects, functional structure and functional dependency;Finally, for each unsafe control behavior, the cause factors under all loss scenarios are merged, artificial inspection and classification are carried out, and key security vulnerability is determined. The application can comprehensively analyze the security vulnerability of the industrial control system under the petroleum refining scene, and provide a reference basis for evaluating system security risk and developing security reinforcement measures.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of safety engineering in the production of the petroleum refining industry, but is not limited to it, and particularly relates to an industrial control system security vulnerability analysis method and system for a petroleum refining scene. BACKGROUND

[0002] Petroleum refining devices belong to basic industrial infrastructure and undertake the tasks of crude oil processing, separation and conversion, finally producing various petroleum products. The safe and stable operation of petroleum refining relies on highly integrated industrial control systems, which are responsible for real-time monitoring and adjustment of key parameters in the production process. In recent years, there have been many network attack incidents targeting petroleum refining devices, especially industrial control systems, worldwide, causing huge economic losses and endangering national security. All network attacks need to exploit the security vulnerabilities of industrial control systems, so a comprehensive and in-depth security vulnerability analysis can help design security reinforcement programs, improve security protection capabilities and reduce the network security risks of industrial control systems.

[0003] Current vulnerability analysis methods for industrial control systems mostly come from the information technology (IT) field, usually focusing on security vulnerabilities caused by network protocol vulnerabilities, software vulnerabilities, authentication mechanism defects, etc., and rarely involving security vulnerabilities caused by control component interactions. Invention patent (CN201810437213.9) proposes a vulnerability checking method for industrial control systems, which receives client instructions and calls test cases by configuring a threat detection system, sends a large amount of data to the device under test for threat detection, availability detection and compatibility detection, and finally mines the vulnerabilities of the system. The invention still focuses on vulnerability analysis of network protocol and software level defects, and lacks consideration of security vulnerabilities caused by control component interactions. The methods widely used in the traditional hazard analysis field, such as fault tree, failure mode and effects analysis (FMEA) method, hazard and operability analysis (HAZOP) method, etc., although involving the interaction behavior between some components or units, belong to static analysis in nature, which is difficult to guide the security vulnerability analysis in dynamic interaction scenarios, and these methods need to be combined with risk assessment when applied to security vulnerability analysis, which not only increases the analysis difficulty, but also introduces human uncertainty. Invention patent (CN202310087731.3) discloses an industrial control system vulnerability assessment method, which constructs a minimum check unit for vulnerability assessment, manually configures the evaluation function, statistical function, weight parameter, etc. of each check unit, and finally calculates the score and assesses the vulnerability of the industrial control system by calculating the overall score and weight. This method is essentially a static risk assessment technology, and introduces human uncertainty in the evaluation index and weight setting, and the analysis result obtained finally is difficult to effectively guide the actual security reinforcement work.

[0004] In view of the above analysis, the existing technical problems in the prior art are:

[0005] The method widely used in the traditional hazard analysis field belongs to static analysis in nature, which is difficult to guide the security vulnerability analysis in the dynamic interactive scene, and these methods need to be combined with risk assessment when applied to security vulnerability analysis, which not only increases the analysis difficulty, but also introduces human uncertainty. SUMMARY

[0006] In view of the problems existing in the prior art, the present application provides an industrial control system security vulnerability analysis method and system for the oil refining scene.

[0007] The present application is realized in that an industrial control system security vulnerability analysis method for the oil refining scene, characterized in that the industrial control system security vulnerability analysis method for the oil refining scene, the method specifically comprises:

[0008] S1: determining the target task, key function and interactive object of the oil refining system, determining the unacceptable loss of system level, hazard and safety constraint;

[0009] S2: dividing the control structure level of the system, collecting the configuration information of the control components including the controller, sensor and actuator, and the corresponding controlled variable representation; determining the control behavior, feedback, input and output information between the control components, and establishing a functional control structure model;

[0010] S3: analyzing the control behavior in the functional control structure model, and identifying the unsafe control behavior UCA that may cause harm;

[0011] S4, generating loss scenarios for unsafe control behavior UCA, conducting cause analysis, and analyzing the cause factors leading to UCA occurrence from five dimensions of process model defects, system environment defects, communication defects, structure defects and functional dependency defects;

[0012] S5: for each unsafe control behavior UCA, merging all cause factors in its loss scenario, classifying according to five dimensions, and deriving its security vulnerability respectively.

[0013] Further, in S1, the target task is the main purpose or expected result of the system, which defines the basic task that the system needs to complete and the effect that the system needs to finally achieve;

[0014] The key function refers to the core function that the system must have in order to achieve the target task, which is the main functional module or component part on which the system depends to complete the target task;

[0015]

[0015] Interaction objects are all participants involved in the process of realizing the key functions, including personnel and devices, which together form the functional control structure of the system;

[0016] System-level unacceptable loss refers to conditions that are completely unacceptable from the perspective of the target task, which will bring great economic loss to the system, or pose a serious threat to the environment and personnel safety;

[0017] Hazard refers to any event or condition in the system that can cause unacceptable loss, which can have a major impact on the safety of the system, personnel, environment or economy, and these hazards are usually controllable, but if effective control measures are not taken, they can lead to disastrous consequences;

[0018] Safety constraints refer to restrictive requirements that must be followed during design and operation to ensure that the system can operate safely and stably, which can come from regulations, industry standards, technical specifications, or be derived by reverse analysis of hazards. For each identified hazard, corresponding safety constraints must be established to prevent the hazard from causing system-level unacceptable loss.

[0019] Further, the control structure level of the system is divided into low control level, medium control level and high control level;

[0020] The low control level is responsible for specific, real-time operations, including control of sensors and actuators; the medium control level is responsible for monitoring and coordinating low-level control, including scheduling, optimizing control or state monitoring in the production process; the high control level is responsible for the macro planning and decision-making of the entire system, involving decision-making and the realization of the target task.

[0021] Further, the collection control component includes configuration information of controllers, sensors and actuators, and corresponding controlled variable representations; the controller is responsible for calculating the deviation between the sensor feedback information and the set target, and outputting the control signal to adjust the actuator, and the configuration information it needs to collect includes control strategy, control target, control algorithm parameters, input and output signals, and configuration bit number;

[0022] The role of the sensor is to measure the controlled variable and convert the measurement result into an electrical signal or a digital signal for analysis by the controller, and the configuration information it needs to collect includes the measured variable, the measurement range, the measurement accuracy, the output signal type, and the configuration bit number;

[0023] The actuator receives the instructions of the controller and performs the corresponding physical action to change the state of the system, and the configuration information it needs to collect includes the control object, the execution mode, the response time, the input signal type, the output range, and the configuration bit number;

[0024] Each controlled variable is measured by a specific sensor and fed back to the controller through the signal provided by its sensor. The controller generates a control signal according to the difference between the set value and the feedback value of the controlled variable, and then adjusts the actuator, so that the controlled variable remains within the desired range.

[0025] Further, the control behaviors, feedbacks, input and output information between each control component are determined to establish a functional control structure model. The control behavior describes how the control component processes the input information and generates the corresponding output, which is usually described by a mathematical model or a control algorithm, such as PID control, fuzzy control, etc. The feedback mechanism ensures that the system can adjust the input according to the output result during operation to achieve the purpose of self-correction. The input refers to the information obtained from other components or external environment, and the output is the control instruction or feedback information of the component.

[0026] Further, in S3, the unsafe control behavior identification method in the petroleum refining scene includes:

[0027] 3.1 Determine the main function, safety responsibility, and related control behavior of each interactive object;

[0028] 3.2 Develop a process model for each interactive object to determine the process model variables and corresponding states, and keep the controlled variables within the safety parameter range;

[0029] 3.3 Determine the process model variables and corresponding states of all interactive objects, list the combinations of these variables, and identify four types of unsafe control behaviors (UCA) based on the standards established by STPA, including (i) providing control behavior; (ii) not providing control behavior; (iii) providing control behavior too early, too late, or out of order; (iv) control behavior stops too early or lasts too long.

[0030] Further, in S4, the loss scenario generation method and cause analysis method for petroleum refining devices include:

[0031] 4.1 Generate loss scenarios for four types of unsafe control behaviors UCA, and divide them into two categories: (i) situations that lead to unsafe control behaviors UCA; (ii) situations where control behaviors are not executed correctly or completely;

[0032] 4.2 According to the classification of loss scenarios, determine the involved cause factors, and design a functional control structure for cause analysis;

[0033] 4.3 Perform cause analysis on the generated loss scenarios from five dimensions, including process model defects, system environment defects, communication defects, structural defects, and functional dependency defects;

[0034] Further, in the S5, the safety vulnerability derivation method for the petroleum refining device, comprising:

[0035] 5.1 Check whether the loss scene of each unsafe control action UCA is comprehensive and has omissions;

[0036] 5.2 Merge the cause factors of all loss scenes under each unsafe control action UCA, eliminate repeated, approximate or redundant cause factors, and classify according to the process model defects, system environment defects, communication defects, structure defects and functional dependency defects five dimensions, and derive the safety vulnerability respectively;

[0037] 5.3 Derive the safety vulnerability for all cause factors under the same unsafe control action UCA, and merge according to different defect types;

[0038] 5.4 All safety vulnerabilities are summarized to eliminate repeated or redundant results, and the whole safety vulnerability analysis result of the system is obtained.

[0039] Another object of the present application is to provide an industrial control system safety vulnerability analysis system for the petroleum refining scene, which specifically comprises:

[0040] The definition module is used to determine the target task, key function and interactive object of the system, the system level unacceptable loss, the hazard and safety constraint;

[0041] The control structure hierarchical division module is used to collect control components, determine the control behavior, feedback, input and output information between the control components, and establish a functional control structure model;

[0042] The unsafe control action identification module is used to analyze the control behavior in the functional control structure model, and identify the unsafe control action UCA that may cause hazards;

[0043] The loss scene generation method and cause analysis module is used to generate loss scenes for the unsafe control action UCA, perform cause analysis, and analyze the cause factors leading to the occurrence of UCA;

[0044] The safety vulnerability derivation module is used to combine the cause factors of all loss scenes under each unsafe control action UCA, classify according to five dimensions, and derive the safety vulnerability respectively.

[0045] In combination with the above technical solutions and the technical problems solved, the technical solutions protected by the present application have the following advantages and positive effects:

[0046] First, the present application solves the existing technical problems in industrial application:

[0047] 1. Lack of systematicity in system safety analysis in petroleum refining scenarios

[0048] Existing safety vulnerability analysis of industrial control systems is mostly limited to single devices or local functions, lacking systematicity and global perspective, which cannot fully identify potential safety risks. In the petroleum refining scenario, the complex multi-level control structure and interactive behavior further increase the difficulty of vulnerability identification, leading to insufficient investigation of safety hazards and unpredictable hazards.

[0049] 2. Insufficient analysis of unsafe control actions (UCAs)

[0050] Traditional safety analysis methods cannot effectively identify hidden unsafe control actions (UCAs) in the system, especially potential risks in multi-component, multi-path interactive processes. Neglecting UCA may lead to failure of critical control tasks and cause equipment damage or safety accidents.

[0051] 3. Limited cause analysis dimensions, lack of detailed classification framework

[0052] Existing methods for cause analysis of safety hazards are mostly based on a single factor, such as device failure or communication failure, and fail to comprehensively analyze the causes of UCA from multiple dimensions (such as process model defects, communication defects, functional dependency defects, etc.), which limits the depth and accuracy of analysis.

[0053] 4. Inaccurate classification and derivation of security vulnerabilities

[0054] Due to the lack of a unified classification framework, existing analysis techniques for vulnerability classification and derivation often rely on experience and cannot provide effective solutions for specific safety problems. This limits the practical application of safety analysis results in risk assessment and system optimization.

[0055] Significant technical progress of the invention

[0056] 1. Provide a systematic safety analysis method

[0057] The present invention constructs a functional control structure model to comprehensively analyze the hierarchical structure and interactive behavior of industrial control systems in the petroleum refining scenario. By dividing control components and their behavior paths, it accurately describes control signal flow and feedback mechanisms, and systematically identifies potential safety hazards at the system level. This systematic approach fills the gap in global analysis of existing technologies.

[0058] 2. Accurate identification of unsafe control actions (UCAs)

[0059] The application combines control behavior analysis and functional control structure model to comprehensively identify unsafe control actions (UCAs) in petroleum refining scenarios that may cause harm, including missing, errors, delays, etc. By analyzing the impact of UCA on system tasks, the depth and accuracy of safety analysis are significantly improved.

[0060] 3. Multi-dimensional cause analysis

[0061] For each UCA, the application conducts cause analysis from five dimensions, including:

[0062] 1. Process model defects: Identify the deviation of the controller's understanding of the current state and target state.

[0063] 2. System environment defects: Consider the impact of external environmental changes on system safety.

[0064] 3. Communication defects: Analyze the delay, packet loss or distortion problems in signal transmission.

[0065] 4. Structural defects: Detect vulnerabilities in hardware and software design.

[0066] 5. Functional dependency defects: Evaluate the impact of other module failures on the current control task.

[0067] This multi-dimensional analysis framework significantly improves the comprehensiveness and targeted understanding of the cause factors.

[0068] 4. Classification and vulnerability derivation

[0069] The application combines the cause factors in all loss scenarios and derives the safety vulnerability of the system from the above five dimensions. By establishing a standardized vulnerability classification system, the application provides a more accurate vulnerability assessment method, making the analysis results more operable.

[0070] Value in industrial applications:

[0071] 1. Improve the safety and reliability of petroleum refining systems

[0072] The application provides targeted improvement suggestions by systematically identifying and classifying safety vulnerabilities, significantly reducing safety risks in petroleum refining processes and ensuring reliable operation of industrial control systems.

[0073] 2. Optimize safety management and risk control

[0074] The comprehensive safety analysis method provided by the application can help enterprises optimize the safety management system, improve risk prediction and early warning capabilities, and provide technical support for establishing a sound industrial safety protection system.

[0075] 3. Reduce economic losses and environmental risks

[0076] By effectively identifying unsafe control actions (UCAs) and their contributing factors, the present application helps to prevent equipment failures, production interruptions, and environmental pollution incidents caused by safety hazards, reducing economic losses and environmental risks for enterprises.

[0077] 4. Improve the efficiency and standardization of safety analysis

[0078] Compared with traditional experience-dependent analysis methods, the present application provides a standardized and systematic analysis process, significantly improving the efficiency of safety analysis and providing a reliable tool for promoting safety technology in the oil refining industry.

[0079] Through the above technical progress, the present application provides an effective solution for safety analysis and improvement of industrial control systems in the oil refining scenario, which is of great significance for promoting the development of safety technology for industrial control systems.

[0080] Second, the expected income and business value of the technical solution of the present application after transformation: it can provide a safety vulnerability analysis solution for the industrial control systems used by domestic oil refining enterprises and similar large chemical production enterprises, reducing the major harm and loss caused by the use of safety vulnerabilities by network attacks. At the same time, referring to the HAZOP analysis widely used by current chemical production enterprises in safety compliance, the single analysis quotation is usually 150 to 500 thousand, and there are more than 200 chemical production plants reaching million tons in China. Considering that the technical solution proposed by the present application reaches the level of HAZOP analysis in practicality, and considering that it is more comprehensive, it can be used as an alternative analysis solution, therefore it has great business value.

[0081] The technical solution of the present application fills the technical gap in the industry at home and abroad: the safety vulnerability analysis of industrial control systems at home and abroad comes from the information technology (IT) field, usually focusing on the defects of network protocols, software, authentication mechanisms, etc., and almost not considering the safety vulnerabilities caused by the interaction between control components. The technical solution proposed by the present application is based on the dynamic interaction behavior of control components, uses STPA technology to model the function control structure, and deduces the safety vulnerability on the basis of identifying unsafe control actions, which fills the technical gap.

[0082] The technical scheme of the present application solves the technical problems that people have been eager to solve but have always failed to succeed: 1) The security vulnerability analysis of the prior art on the industrial control system is mostly limited to a single device or a local function, such as network protocol, software vulnerability or authentication mechanism defect, etc., lacking systematic and global perspective, and being unable to comprehensively identify potential security risks. In fact, even if all the devices pass the security certification and vulnerability detection, when facing denial of service (DoS) attacks, the current industrial control system often cannot effectively defend and respond in time, which is due to the lack of consideration of the security vulnerability at the communication level (such as IP address exposure, insufficient communication bandwidth, and inability to effectively distinguish and process invalid data packets, etc.); 2) After obtaining explicit unsafe control behavior, it is another difficult problem for the industry to determine which dimensions to analyze the causes. The traditional method is limited to control component failure or communication failure, so the security vulnerability that can be analyzed is limited. The present application considers defects in multiple dimensions in cause analysis, including process model defects, system environment defects, communication defects, structural defects and functional dependency defects, which expands the depth and breadth of analysis and can more effectively guide security reinforcement work.

[0083] The technical scheme of the present application overcomes technical bias: current vulnerability analysis of industrial control systems is generally derived from vulnerability analysis in the information technology (IT) field, common methods include fuzz testing, symbolic execution and static code analysis, and techniques in the risk analysis field are not usually used. As a representative method in the risk analysis field, STPA is applied to security vulnerability analysis in the present application, aiming to comprehensively analyze the security vulnerability of the system from the system level, especially the security vulnerability caused by the interaction of control components which has been long neglected. BRIEF DESCRIPTION OF DRAWINGS

[0084] Figure 1 is a flowchart of the industrial control system security vulnerability analysis method for the petroleum refining scene provided by the embodiment of the present application;

[0085] Figure 2 is a control structure level schematic diagram of a reaction regeneration system provided by the embodiment of the present application;

[0086] Figure 3 is a functional control structure model schematic diagram of a reaction regeneration system provided by the embodiment of the present application;

[0087] Figure 4 is a classification and cause factor schematic diagram of a loss scenario provided by the embodiment of the present application;

[0088] Figure 5 is a functional control structure schematic diagram of a protection device control unit for cause analysis provided by the embodiment of the present application;

[0089] Figure 6 is a system block diagram of an industrial control system security vulnerability analysis system for a petroleum refining scenario provided by an embodiment of the present application;

[0090] Figure 7 is a temperature monitoring result schematic diagram of a refining system provided by an embodiment of the present application;

[0091] Figure 8 is a network communication rate monitoring result schematic diagram provided by an embodiment of the present application;

[0092] Figure 9 is a container pressure and safety valve opening monitoring result schematic diagram provided by an embodiment of the present application;

[0093] Figure 10 is a temperature monitoring result schematic diagram of a plurality of sensors provided by an embodiment of the present application; DETAILED DESCRIPTION

[0094] In order to make the purpose, technical solutions and advantages of the present application clearer and more apparent, the present application is further described in detail below in combination with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0095] An embodiment of the present application provides an industrial control system security vulnerability analysis method for a petroleum refining scenario. Here, a reaction regeneration system, which is the most common and easy to cause dangerous accidents in a petroleum refining system, is taken as an example for security vulnerability analysis. The flowchart is as shown in Figure 1 , which comprises:

[0096] S1, determining the target task, key function and interactive object of the system, determining the system-level unacceptable loss, hazard and safety constraint;

[0097] Specifically, the target task is the main purpose or expected result of the system, which defines the basic task that the system needs to complete and the effect that the system needs to finally achieve. The understanding deviation of the target task will directly affect the accuracy of the vulnerability analysis;

[0098] The key function refers to the core function that the system must have in order to achieve the target task. They are the main functional modules or components on which the system depends to complete the target task;

[0099] The interactive object refers to all participants involved in the process of implementing the key function, including personnel and devices. These participants together constitute the functional control structure of the system;

[0100] Table 1 takes the reaction regeneration system as an example to show the target task, key function and main interactive object.

[0101] Table 1 Target tasks, key functions and main interactive objects of the reaction regeneration system

[0102]

[0103] System-level unacceptable loss refers to conditions that are completely unacceptable from the perspective of target tasks, which will bring great economic loss to the system, or pose a serious threat to the environment and personnel safety;

[0104] Hazard refers to any event or condition in the system that can cause unacceptable loss, which can have a major impact on the safety of the system, personnel, environment or economy, and these hazards are usually controllable, but if effective control measures are not taken, they can lead to disastrous consequences;

[0105] Safety constraints refer to restrictive requirements that must be followed during design and operation to ensure that the system can operate safely and stably, which are usually derived from regulations, industry standards, technical specifications, or through reverse analysis of hazards. For each identified hazard, corresponding safety constraints must be established to prevent the hazards from causing system-level unacceptable loss.

[0106] For the reaction regeneration system, examples of system-level unacceptable loss, hazard and safety constraint are shown in Table 2.

[0107] Table 2 Examples of system-level unacceptable loss, hazard and safety constraint of the reaction regeneration system

[0108]

[0109] S2, divide the control structure hierarchy of the system, collect the configuration information of control components including controllers, sensors and actuators, and the corresponding controlled variable representation; determine the control behavior, feedback, input and output information between control components, and establish a functional control structure model, including:

[0110] Taking the reaction regeneration system as an example, its control structure hierarchy is shown in Figure 2 The control unit of the reaction regeneration system can be divided into four parts: protection device control unit, auxiliary control unit, reaction process control unit and regeneration process control unit. The protection device control unit belongs to SIS, which ensures that the system will not enter a dangerous state due to failure or deviation, and is responsible for the safety of the entire system; the auxiliary control unit ensures the efficient operation of the reaction and regeneration processes, including the feeding of steam, cooling water or compressed air, etc., to meet the material and environmental requirements of the reaction process; the reaction process control unit and the regeneration process control unit are responsible for real-time adjustment of the controlled variables, maximizing efficiency and product yield, while avoiding dangerous situations such as overpressure or uncontrolled reactions.

[0111] Specifically, the control structure hierarchy of a system refers to the organization of control components into different levels according to different functional and management levels in a complex system. Each level of control components has different functions and coordinates the relationship between various control components to achieve the target task of the system and ensure the efficient operation and stability of the system. It is usually divided into low-level control, middle-level control and high-level control. The low-level control is responsible for specific and real-time operations, such as sensor and actuator control, which directly interacts with the physical system to adjust specific operating variables; the middle-level control is responsible for monitoring and coordinating the low-level control, usually involving decision-making for multiple low-level controls. For example, scheduling, optimization control or state monitoring in the production process; the high-level control is responsible for the macro planning and decision-making of the entire system, involving decision-making and target task implementation.

[0112] To further improve the control structure, especially the information of the low-level control structure, it is necessary to collect the configuration information of the control components, including controllers, sensors and actuators, as well as the corresponding controlled variable representation. Among them, the controller is responsible for calculating the deviation between the sensor feedback information and the set target, and outputting the control signal to adjust the actuator; the function of the sensor is to measure the controlled variable and convert the measurement result into an electrical signal or a digital signal for the controller to analyze; the actuator receives the instructions of the controller and performs the corresponding physical action to change the system state. For the reaction regeneration system, the types and examples of configuration information of its controller, sensor and actuator are shown in Table 3.

[0113] Table 3 Types and examples of configuration information of controller, sensor and actuator of reaction regeneration system

[0114]

[0115] Each controlled variable is measured by a specific sensor and fed back to the controller through the signal provided by its sensor. The controller generates a control signal according to the difference between the set value and the feedback value of the controlled variable, and then adjusts the actuator so that the controlled variable remains within the desired range.

[0116] Then, the control behavior, feedback, input and output information between the control components need to be determined to establish a functional control structure model. Among them, the control behavior describes how the control component processes the input information and generates the corresponding output, which is usually described using mathematical models or control algorithms, such as PID control, fuzzy control, etc.; the feedback mechanism ensures that the system can adjust the input according to the output result during operation to achieve self-correction; the input refers to the information obtained from other components or external environment, and the output is the control instruction or feedback information of the component. Taking the reaction regeneration system as an example, its functional control structure model is shown in Figure 3 .

[0117] S3, analyze the control behaviors in the functional control structure model, identify the control behaviors that can lead to hazards according to the STPA criteria, and identify four types of unsafe control actions (UCAs), including:

[0118] Determine the main functions, safety responsibilities, and related control behaviors of each interactive object. For the reaction regeneration system, the main functions, safety responsibilities, and related control behaviors of the key interactive objects are shown in Table 4.

[0119] Table 4 Examples of main functions, safety responsibilities, and related control behaviors of key interactive objects of the reaction regeneration system

[0120]

[0121]

[0122] At the same time, a process model needs to be developed for each interactive object to determine the process model variables and corresponding states, and to keep the controlled variables within the safe parameter range. These process models provide information for the controller's decision-making by checking the impact of environmental factors on the controlled process state. Table 5 shows the process model variables and their states of the protection device control, which is one of the important interactive objects of the reaction regeneration system.

[0123] Table 5 Examples of process model variables and their states of the protection device control

[0124]

[0125] After determining the process model variables and corresponding states of all interactive objects, various combinations of these variables can be listed, and it can be evaluated whether the control operations performed under these combinations constitute a hazard. In this process, the standards established by STPA need to be combined to determine the four types of unsafe control actions (UCAs). These standards include: (1) providing control actions; (2) not providing control actions; (3) providing control actions too early, too late, or out of order; (4) control actions stop too early, or last too long. As an illustration, the present invention takes the key interactive object "protection device control unit" of the reaction regeneration system as an example, and takes one of the related control behaviors "opening / closing emergency steam valve" to generate four types of unsafe control actions (UCAs), as shown in Table 6.

[0126] Table 6 Examples of unsafe control actions of the protection device control unit

[0127]

[0128]

[0129] S4, generate loss scenarios for unsafe control actions UCA, conduct cause analysis, and analyze the cause factors leading to UCA from five dimensions of process model defects, system environment defects, communication defects, structure defects and functional dependency defects, including;

[0130] For the four types of unsafe control actions UCA, the loss scenarios involved in the present application are mainly divided into two cases: (1) the situation leading to unsafe control actions UCA, which is usually caused by unsafe controller behavior or insufficient feedback information. (2) The situation of incorrect or incomplete control behavior execution, which is usually caused by problems in the control path or control process. The classification and cause factors of these loss scenarios are shown in Figure 4

[0131] According to the classification and cause factors of the loss scenarios, the cause factors involved are determined by querying the "Industrial Control System Network Security Guide (NIST SP 800-82)" published by the National Institute of Standards and Technology and the international standard IEC61511 for process industry safety instrument systems, and the functional control structure for cause analysis is prepared. The present application takes the protection device control unit in the reaction regeneration system as the object, and designs the functional control structure for cause analysis, as shown in Figure 5

[0132] Then, the cause analysis is carried out for the generated loss scenarios, and each loss scenario will be analyzed from five dimensions, including process model defects, system environment defects, communication defects, structure defects and functional dependency defects. The present application takes the protection device control unit in the reaction regeneration system as the object, and takes the loss scenario "no feedback information" of the unsafe control action "failure to open the emergency steam valve when emergency steam release is needed, resulting in high pressure in the system, which may cause equipment damage or explosion risk" as an example to carry out cause analysis, and the results are shown in Table 7.

[0133] Table 7 Example of loss scenario and cause analysis results

[0134]

[0135]

[0136] S5, for each unsafe control action UCA, merge all cause factors under all loss scenarios, conduct manual inspection and classification, and deduce the safety vulnerability under different dimensions, including;

[0137] ​​Check whether the loss scenarios of each unsafe control action UCA are comprehensive and complete. This process can be discussed with plant engineers and operators, and can also refer to the hazard and operability analysis (HAZOP) report of the oil refining plant. Then, combine the cause factors of all loss scenarios under each unsafe control action UCA, eliminate the repeated, approximate or redundant cause factors, and classify them according to the five dimensions of process model defects, system environment defects, communication defects, structural defects and functional dependency defects, and derive their safety vulnerabilities respectively. The invention demonstrates how to derive the corresponding safety vulnerabilities of the cause factors related to "process model defects" in Table 7, as shown in Table 8.

[0138] Table 8 Safety vulnerability derivation example

[0139]

[0140]

[0141] Finally, the safety vulnerabilities of all cause factors under the same unsafe control action UCA are derived and combined according to different defect types. The invention takes the protection device control unit in the reaction regeneration system as an object, and carries out safety vulnerability analysis around the cause factors of the unsafe control action "failing to open the emergency steam valve when emergency steam release is needed, resulting in excessive pressure in the system and possibly causing equipment damage or explosion risk". The analysis results are shown in Table 9.

[0142] Table 9 Safety vulnerability analysis results of protection device control unit

[0143]

[0144] According to the above process, the loss scenario generation and cause analysis of other unsafe control actions UCA can be carried out respectively, and the safety vulnerabilities of each are derived. Finally, all the safety vulnerabilities are summarized and the repeated or redundant results are eliminated, and the complete safety vulnerability analysis results of the reaction regeneration system are obtained. For other subsystems of the oil refining plant, such as the fractionation system, the absorption stabilization system, the energy recovery system, etc., safety vulnerability analysis can also be carried out according to the above process.

[0145] If the system structure and equipment of the oil refining plant are changed in the later maintenance, the functional control structure and the unsafe control action UCA need to be updated in order to generate new loss scenarios and identify new safety vulnerabilities that may cause hazards.

[0146] In the context of oil refining, the first step is to identify the target tasks, key functions, and interacting objects of the industrial control system. This includes the specific tasks and interaction logic that each module in the system needs to implement, as well as the definition of unacceptable losses and hazards. Safety constraints are used to limit system behavior and ensure that critical functions are not compromised or unacceptable losses occur under various operating conditions. For example, by analyzing the interaction between controllers and actuators, explicit safety thresholds and functional limits are defined, laying the foundation for subsequent safety analysis.

[0147] By dividing the hierarchical structure of the industrial control system, all control components (such as controllers, sensors, actuators) and their configuration information are collected to establish a complete structural model of control behavior. The model includes:

[0148] The flow direction of control behavior (mapping of control signals and feedback paths).

[0149] The representation of controlled variables (such as temperature, pressure, flow, etc. Key variables).

[0150] This functional control structure model not only describes the physical connection of the system, but also shows the control logic and interaction relationship. The establishment of the model aims to identify potential risk points in the control path and vulnerabilities in the control signal transmission, providing data support for subsequent analysis.

[0151] Using the functional control structure model, analyze "unsafe control behavior (UCA)" that may lead to system failure or danger, including:

[0152] Control behavior loss: such as the failure of actuators to receive control signals in a timely manner.

[0153] Control signal error: the controller sends incorrect instructions leading to unexpected operations.

[0154] Control signal delay: feedback information does not arrive in time, leading to operations beyond safety thresholds.

[0155] For each UCA, combined with its possible loss scenarios, analyze the cause factors from the following five dimensions:

[0156] (1). Process model defects: the controller's understanding of the current state or target state is incorrect.

[0157] (2). System environment defects: environmental changes have not been effectively adapted by the control system.

[0158] (3). Communication defects: control signals are lost or distorted during transmission.

[0159] (4). Structural defects: there are logical vulnerabilities in the hardware or software design of the system.

[0160] (5). Function-dependent defect: Other sub-functions or modules that depend on it fail.

[0161] According to the identified UCA and its loss scenario causing factors, each factor is classified and analyzed, combined with the five-dimensional characteristics of the system, and the specific security vulnerability is derived. Each vulnerability corresponds to one or more UCAs, and the influence range, key trigger conditions and potential consequences of the vulnerability can be revealed through multi-dimensional combined analysis. Finally, by classifying the vulnerability characteristics, the system can provide direct security protection strategies for design improvement and risk avoidance. This process not only improves the understanding of the source of vulnerability, but also provides a scientific basis for formulating targeted protection measures.

[0162] As shown in Figure 6 The embodiment of the present application provides an industrial control system security vulnerability analysis system for a petroleum refining scene, which specifically comprises:

[0163] A definition module is configured to determine target tasks, key functions and interactive objects of the system, system-level unacceptable losses, hazards and safety constraints.

[0164] A control structure level division module is configured to collect control components, determine control behaviors, feedback, input and output information between the control components, and establish a functional control structure model.

[0165] An unsafe control behavior identification module is configured to analyze the control behaviors in the functional control structure model and identify unsafe control behaviors UCA that can cause hazards.

[0166] A loss scenario generation method and cause analysis module is configured to generate loss scenarios for the unsafe control behaviors UCA, perform cause analysis, and analyze the cause factors leading to the occurrence of the UCA.

[0167] A security vulnerability derivation module is configured to combine all cause factors of each unsafe control behavior UCA in all loss scenarios, classify them according to five dimensions, and derive their security vulnerabilities respectively.

[0168] Embodiment 1: Security vulnerability analysis of the temperature control module of the refining system

[0169] 1. System overview

[0170] In the petroleum refining process, the temperature control module is used to adjust the temperature in the reactor to ensure that the chemical reaction is carried out within a safe range. The module includes temperature sensors, temperature controllers, cooling devices and heating devices. The target task is to maintain the reaction temperature within the range of 550℃±10℃.

[0171] 2. Functional control structure model

[0172] Controller: Receives temperature sensor feedback signals and sends heating or cooling instructions based on the set target temperature.

[0173] Sensor: Monitors reactor temperature in real-time and transmits data to the controller.

[0174] Actuator: Initiates heating or cooling devices upon receiving controller instructions.

[0175] 3. UCA identification

[0176] 1. No control action provided: Cooling device not initiated, reaction temperature rapidly increases, exceeding safety threshold.

[0177] 2. Control action provided too late: Cooling device initiated too late, reaction temperature may have approached or exceeded safety threshold, resulting in ineffective temperature regulation, drastic temperature fluctuations, and system loss of control.

[0178] 3. Control action stopped too early: Cooling device stopped too early, resulting in insufficient cooling and exceeding safety threshold.

[0179] 4. Cause analysis

[0180] 1. Process model defect: Controller unable to correctly perceive temperature change trend.

[0181] 2. Communication defect: Signal transmission between temperature sensor and controller lost or delayed.

[0182] 3. Structural defect: Mechanical failure of cooling device actuator.

[0183] 5. Vulnerability derivation

[0184] Integrated analysis shows that the main vulnerability of the temperature control module is communication delay and process model error. These issues may cause temperature to exceed safety range, endangering equipment safety.

[0185] Example 2: Security vulnerability analysis of petroleum refining pressure control system

[0186] 1. System overview

[0187] In the petroleum refining system, the pressure control system is used to regulate the pressure in the reactor to prevent the risk of explosion caused by excessive pressure. The module includes a pressure sensor, a controller, a safety valve, and an exhaust system.

[0188] 2. Functional control structure model

[0189] Controller: Sends control signals to open or close safety valve based on pressure value feedback from pressure sensor.

[0190] Sensor: Monitors real-time pressure changes in reactor.

[0191] Actuator: receives controller signals to adjust the open / close state of the safety valve.

[0192] 3. UCA identification

[0193] 1. No control behavior provided: the safety valve fails to open properly, leading to continuous pressure rise and equipment rupture.

[0194] 2. Control behavior provided: the safety valve is closed during the opening process, resulting in delayed pressure relief.

[0195] 3. Control behavior stopped too early: the safety valve is closed too early, causing pressure to exceed the safety threshold.

[0196] 4. Cause analysis

[0197] 1. Process model defect: the controller did not consider normal pressure fluctuations when setting the pressure range.

[0198] 2. System environment defect: high ambient temperature causes sensor misalignment.

[0199] 3. Functional dependency defect: exhaust system piping is blocked, preventing pressure release.

[0200] 5. Vulnerability derivation

[0201] The analysis results show that the main vulnerability of the system lies in the process model defect of the controller and the system environment defect. Once these links fail, it may cause high pressure accidents, and the monitoring and optimization of these two aspects should be strengthened.

[0202] These two examples accurately reveal the potential safety vulnerability in the system by modeling the functional control structure of the temperature control and pressure control modules of the petroleum refining system, UCA identification and cause analysis. These analyses provide key data support for developing improvement plans and improving system reliability.

[0203] II. Related evidence of the technical effects obtained by the embodiments of the present application.

[0204] Example 1: Safety vulnerability analysis of the temperature control module of the refining system

[0205] Figure 7The temperature monitoring results of the refining system are shown, and the time sampling interval is 100 seconds. It can be seen that from 2100 seconds, the temperature gradually rises and exceeds the safety threshold of 560°C at about 2200 seconds. After that, the adjustment of the temperature control module fails, and the temperature continues to rise until it reaches the warning value of 650°C, at which point the protection device controller starts to terminate the reaction. According to the vulnerability derivation results, the network communication rate monitoring data and the process model of the temperature control module are retrieved respectively. The network communication rate monitoring results are shown in Table 9, and it can be seen that from about 1900 seconds, the communication rate starts to slowly decline from the set 15M / s, and by 3000 seconds, the average communication rate has decreased to about 5M / s, which is a serious communication delay and does not meet the data transmission rate requirements in industrial scenarios. In addition, the process model of the temperature control module is shown in Table 10, and it can be seen that its process model variables do not include network communication rate, so it cannot timely monitor and respond to communication delay, which is a process model defect. Figure 8

[0206] Table 10 Process model variables and their states of the temperature control module of the refining system

[0207]

[0208] Example 2: Security vulnerability analysis of the petroleum refining pressure control system

[0209] Figure 9 The monitoring results of the container pressure and safety valve opening of the refining system are shown, and the time sampling interval is 100 seconds. It can be seen that from about 4000 seconds, the container pressure gradually rises, the adjustment of the pressure control module fails, and reaches the safety threshold of 0.5Mpa at about 5000 seconds, at which point the protection device controller starts to terminate the reaction. Correspondingly, the safety valve opening normally remains at 30%, and from 4000 seconds, the valve opening gradually decreases to 10% at 4500 seconds, which is the direct cause of the pressure rise. According to the vulnerability derivation results, the process model of the pressure control module and the temperature monitoring results of multiple sensors are retrieved respectively. The process model of the pressure control module is shown in Table 11, and it can be seen that its pressure state is divided into four situations: too low (<0.1Mpa), normal (0.1-0.25Mpa), too high (>0.25Mpa) and shutdown (0Mpa), which is the commonly used state range based on rules. However, considering the volume of different containers, the fluctuation of feed pressure, etc., sufficient margin should be left in actual application, for example, setting the normal range to 0.08-0.28Mpa to prevent the controller from frequently acting due to the fluctuation of the pressure value around 0.1Mpa, and applying unnecessary control signals to the safety valve. The temperature monitoring results of multiple sensors are shown in Table 12, and it can be seen that from about 4000 seconds, the temperature of the first sensor gradually rises, and from about 4500 seconds, the temperature of the second sensor gradually rises, which is the direct cause of the pressure rise. Figure 10 ​As shown, it can be seen that after the temperature exceeds 630°C, the reading of sensor #1, which is closer to the hot feed inlet, is significantly affected and lags behind the monitoring result of normal sensor #2, which is due to the fact that the reading of sensor #1 is inaccurate because of the excessively high ambient temperature.

[0210] Table 11 Process model variables of the refining system pressure control module and their states

[0211]

[0212] It should be noted that the embodiments of the present application can be realized by hardware, software, or a combination of software and hardware. The hardware part can be realized by special logic; the software part can be stored in a memory and executed by a suitable instruction execution system, such as a microprocessor or a specially designed hardware. Those skilled in the art can understand that the above-mentioned devices and methods can be realized by computer executable instructions and / or included in processor control codes, for example, such codes are provided on a carrier medium, such as a magnetic disk, a CD or a DVD-ROM, a programmable memory, such as a read-only memory (firmware), or a data carrier, such as an optical or electronic signal carrier. The devices of the present application and their modules can be realized by hardware circuits, such as very large scale integrated circuits or gate arrays, semiconductors, such as logic chips, transistors, etc., or programmable hardware devices, such as field programmable gate arrays, programmable logic devices, etc., by software executed by various types of processors, or by a combination of the above-mentioned hardware circuits and software, such as firmware.

[0213] The above description is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any modification, equivalent replacement, and improvement made by those skilled in the art within the technical range disclosed by the present application, as long as it is within the spirit and principle of the present application, should be covered by the protection scope of the present application.

Claims

1. A method for analyzing security vulnerability of an industrial control system in a petroleum refining scenario, characterized in that, The method specifically comprises: S1: determining the target task, key function and interactive object of the petroleum refining system, determining the system-level unacceptable loss, hazard and safety constraint; S2: dividing the control structure level of the system, collecting the configuration information of the control components including the controller, sensor and actuator, and the corresponding controlled variable representation; determining the control behavior, feedback, input and output information between the control components, and establishing a functional control structure model; S3: analyzing the control behavior in the functional control structure model, and identifying the unsafe control behavior UCA that may cause hazards; S4: generating a loss scenario for the unsafe control behavior UCA, performing cause analysis, and analyzing the cause factors of the occurrence of UCA from five dimensions of process model defects, system environment defects, communication defects, structure defects and functional dependency defects; S5: for each unsafe control behavior UCA, merging the cause factors under all loss scenarios, classifying according to the five dimensions, and respectively deriving the security vulnerability; The safety constraint is derived by reverse analysis of the hazard. For each identified hazard, a corresponding safety constraint must be established to prevent these hazards from causing system-level unacceptable loss; the system-level unacceptable loss refers to conditions that are completely unacceptable from the perspective of the target task of the petroleum refining plant, which will cause great economic loss to the system or pose a serious threat to the environment and personnel safety; The control structure level of the system is divided into low control level, medium control level and high control level; The low control level is responsible for specific and real-time operation, including control of sensors and actuators; the medium control level is responsible for monitoring and coordination of low-level control, including scheduling, optimization control or state monitoring in the production process; the high control level is responsible for the macro planning and decision-making of the whole system, involving decision-making and target task implementation.

2. The method of claim 1, wherein the method is applied to a petroleum refining scenario. The controller configuration information to be collected includes control strategy, control target, control algorithm parameter, input and output signal, and configuration bit number; the sensor configuration information to be collected includes measurement variable, measurement range, measurement accuracy, output signal type, and configuration bit number; the actuator configuration information to be collected includes control object, execution mode, response time, input signal type, output range, and configuration bit number.

3. The method of claim 1, wherein the method is applied to a petroleum refining scenario. The judgment criteria of the unsafe control behavior include providing control behavior, not providing control behavior, providing control behavior too early, too late or out of order, and control behavior stopping too early or lasting too long.

4. The method of claim 1, wherein the method is applied to a petroleum refining scenario. The loss scenario types include the situation of causing unsafe control behavior, the situation of incorrect or incomplete control behavior execution.

5. The method of claim 1, wherein the method is applied to a petroleum refining scenario. The cause analysis includes five aspects, namely process model defects, system environment defects, communication defects, structure defects and functional dependency defects.

6. A system based on the method for analyzing security vulnerability of an industrial control system in a petroleum refining scene according to any one of claims 1-5, characterized in that, The system specifically comprises: A definition module for determining the target task, key function and interactive object of the system, system-level unacceptable loss, hazard and safety constraint; A control structure level division module for collecting control components, determining the control behavior, feedback, input and output information between the control components, and establishing a functional control structure model; A control structure level division module for collecting control components, determining the control behavior, feedback, input and output information between the control components, and establishing a functional control structure model; An unsafe control action identification module is configured to analyze control actions in the functional control structure model and identify unsafe control actions (UCAs) that may cause harm; A loss scenario generation method and a cause analysis module are configured to generate loss scenarios for the unsafe control actions (UCAs), perform cause analysis, and analyze cause factors leading to the UCAs. A safety vulnerability derivation module is configured to, for each unsafe control action (UCA), combine cause factors in all loss scenarios of the UCA, classify the cause factors according to five dimensions, and derive safety vulnerabilities of the UCA, respectively.

Citation Information

Patent Citations

  • Frangibility inspection method and device for industrial control system

    CN108616400A

  • A method for industrial control system vulnerability assessment

    CN116430823B

  • Fault diagnosis and pre-warning system in oil refining production process and establishment method thereof

    CN104238545A

  • Method, device and equipment for determining cause scene of intelligent ship navigation system

    CN118884934A