Water industrial control system information security and control security linkage protection system
By designing the information security and control security linkage protection system of the water industry control system, the dual challenges of information security and control security faced by the water industry control system in the process of intelligence and networking are solved, and the coordinated response between information security and control security is achieved, and the security stability and control accuracy of the system are improved.
Patent Information
- Application Number
- CN202510364639.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-26
AI Technical Summary
In the process of intelligence and networking, the water industry control system faces the dual challenges of information security and control security. The existing technology is difficult to achieve effective coordination between information security and control security, and cannot cope with complex security threat scenarios.
A linkage protection system for information security and control security of water industry control systems is designed, including data acquisition module, information security risk assessment module, control security risk assessment module, linkage decision-making module and protection execution module. The system collects equipment operation data and network data packets in real time, analyzes information security and controls security risks, formulates and implements linkage protection strategies, and achieves a coordinated response between information security and control security.
It realizes a coordinated response between information security and control security, can promptly identify and respond to abnormal network attacks and control indicators, improves the security stability and control accuracy of the system, and reduces the overall impact of security risks on the system.
Smart Images

Figure CN119892508B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly to a linkage protection system for information security and control security of water conservancy industrial control systems. Background Art
[0002] As a key infrastructure for ensuring the rational allocation of water resources, the stable operation of water conservancy facilities, and the effective monitoring and treatment of water environment, water conservancy industrial control systems are widely used in fields such as urban water supply, sewage treatment, flood control and irrigation, and hydropower generation. In recent years, with the deep integration of information technology and industrial control technology, the intelligence and networking level of water conservancy industrial control systems have been continuously improved. While improving production efficiency and optimizing resource allocation, they are also facing increasingly severe security challenges.
[0003] Traditional water conservancy industrial control systems are relatively closed and have a high degree of isolation from external networks. The security protection mainly focuses on the stability and reliability of the equipment itself. However, nowadays, in order to achieve remote monitoring, data sharing, and intelligent management, water conservancy industrial control systems are gradually opening network interfaces and interconnecting with enterprise internal networks and the Internet. This transformation exposes the system to a complex and changing network environment, and security threats such as software intrusion and network attacks continue to emerge.
[0004] In terms of information security, water conservancy industrial control systems face many problems. On the one hand, there are a large number of network devices, sensors, and controllers in the system. The operating systems and application programs they run may have security vulnerabilities. For example, some old devices use embedded operating systems that have not been updated for a long time and are easily exploited by hackers for attacks. On the other hand, the security of data transmission during network communication is also difficult to guarantee. Traditional encryption methods may not be able to meet the real-time and reliability requirements of water conservancy industrial control systems, and there is a risk of data being stolen or tampered with during transmission. In addition, new network attack methods are constantly emerging, such as advanced persistent threat (APT) attacks, which have extremely strong concealment and pertinence, can lurk in the system for a long time to steal key information or damage the system operation, and existing information security protection technologies are difficult to effectively respond to.
[0005] Control security is also an important concern for water conservancy industrial control systems. Key control indicators such as water level, flow rate, and water quality are directly related to the normal operation and function realization of the system. However, in actual operation, factors such as equipment failures and external environmental changes will cause abnormal fluctuations in control indicators. For example, during heavy rain, the river flow rate increases rapidly. If the water level control equipment cannot be adjusted in a timely and accurate manner, it may trigger flood disasters; when the water quality monitoring equipment fails and is not discovered and processed in a timely manner, it may cause unqualified water to enter the water supply system, endangering the health of residents. In addition, there are also challenges in the collaborative work between different control devices. The communication and control command transmission between devices may be delayed or incorrect, affecting the control accuracy and stability of the entire system.
[0006] At present, the security protection measures for water industrial control systems are mostly carried out separately for information security and control security. Information security protection mainly relies on network security devices such as firewalls and intrusion detection systems, focusing on preventing external network attacks; control security mainly ensures the normal operation of devices and the stability of control indicators through technologies such as device redundancy and fault diagnosis. This separate protection mode cannot achieve the effective coordination of information security and control security, and it is difficult to cope with complex security threat scenarios. For example, when a network attack is detected, the device control strategy cannot be adjusted in time to reduce the impact of the risk on the system operation; when the device control is abnormal, it is also impossible to timely discover whether there is an attack behavior caused by an information security vulnerability. Summary of the Invention
[0007] The purpose of the present invention is to provide a linkage protection system for information security and control security of a water industrial control system to solve the problems raised in the above background technology.
[0008] To achieve the above purpose, the present invention provides the following technical solution: A linkage protection system for information security and control security of a water industrial control system, the system includes:
[0009] A data acquisition module, used to collect the operation data of various devices in the water industrial control system in real time, including water level sensor data, flow sensor data, water quality monitoring data, and packet information in the system network, and mark the collected data as original monitoring data;
[0010] An information security risk assessment module, used to analyze the network packets in the collected original monitoring data, extract information security-related characteristic values, and calculate the information security risk coefficient. The specific calculation method is: obtain the set of characteristic vectors of normal network connections from the local database , the currently monitored network connection characteristic vector is t, and through the cosine similarity formula calculate the similarity between t and each normal characteristic vector, and take the minimum similarity value min(cos(t, s i )), let the information security risk coefficient R1 = 1 - min(cos(t, s i ));
[0011] A control security risk assessment module, used to evaluate the control security risk according to the original monitoring data; for the water level sensor data, obtain the normal fluctuation range [a, b] of the water level from the local database, and set the current water level value as h. If h [a, b], calculate the water level deviation coefficient ; similarly calculate the deviation coefficients of the flow sensor data and the water quality monitoring data, and comprehensively calculate the control security risk coefficient through the weighted average method , where w j is the weight of each index, dj is the deviation coefficient of the corresponding index;
[0012] The linkage decision-making module is used to receive the information security risk coefficient R1 and the control security risk coefficient R2, and obtain the risk thresholds T1 and T2 from the local database; if R1 > T1 or R2 > T2, formulate a linkage protection strategy according to the risk type and level;
[0013] The protection execution module executes corresponding protection operations according to the protection strategy formulated by the linkage decision-making module.
[0014] Preferably, when the data acquisition module acquires network data packets, it adopts the deep packet inspection method, and the specific implementation is as follows: obtain the signature library of known threat software from the local database and perform byte-by-byte matching on the content of the acquired data packets. If any signature c in the signature library is included in the data packets i , mark the data packet as a suspected risk data packet and record the relevant information.
[0015] Preferably, when the information security risk assessment module analyzes the network connection characteristics, it calculates the activity index of the network connection. The specific calculation method is as follows: within the unit time Δt, count the number of connection establishments n1 and the number of disconnections n2 of the network connection. The network connection activity , incorporate this activity index into the calculation of the information security risk coefficient. The improved information security risk coefficient , where α is the activity influence factor.
[0016] Preferably, when the control security risk assessment module evaluates the traffic control security risk, it performs linear regression analysis on the traffic data within a period of time. Let the traffic data sequence be q1, q2,..., q p , establish a linear regression equation , where ω is the time variable, and calculate the slope β of the regression equation 1; If |β1| exceeds the normal slope threshold S0 obtained from the local database, increase the weight of the traffic control security risk coefficient. The adjusted control security risk coefficient , where γ is the weight adjustment factor, and sign(β1) is the sign function, which takes values according to the positive or negative of β1.
[0017] Preferably, when the linkage decision-making module formulates a protection strategy, it obtains the priority list of each service from the local database. When facing risks, it gives priority to ensuring the operation of high-priority services; if there are multiple executable protection strategies, select the strategy with the least impact on high-priority services to execute.
[0018] Preferably, when the protection execution module executes the protection strategy for adjusting the device control instruction, it adopts a control instruction verification mechanism; before sending a new control instruction, the instruction is first simulated and executed in a simulation environment, and the parameters of the simulation environment are consistent with those of the actual water conservancy industrial control system; by comparing the simulation execution result with the expected result, if the difference exceeds the allowable error range obtained from the local database, the control instruction is regenerated.
[0019] Preferably, the data acquisition module also collects the hardware status data of the devices in the water conservancy industrial control system and calculates the comprehensive health index of the device hardware status. The specific calculation method is as follows: obtain the normal range of each hardware parameter from the local database , represents different hardware parameters, and the current hardware parameter value is x i , calculate the health sub-index of each hardware parameter , the comprehensive health index of the device hardware status , where is the weight of each hardware parameter.
[0020] Preferably, the information security risk assessment module and the control security risk assessment module incorporate the comprehensive health index of the device hardware status into the risk assessment system; if the comprehensive health index H is lower than the health threshold H0 obtained from the local database, the information security risk coefficient and the control security risk coefficient are increased, and the adjustment formulas are respectively and , where δ1 and δ2 are adjustment coefficients.
[0021] Preferably, when formulating the protection strategy, the linkage decision-making module considers the system recovery cost; obtain the recovery cost list corresponding to different protection strategies from the local database, and preferentially select the protection strategy with a lower recovery cost to execute under the premise of meeting the risk prevention and control requirements.
[0022] Preferably, after the protection execution module executes the protection operation, it records the operation log; the operation log includes the protection strategy name, execution time, execution result, affected devices and business information, and regularly uploads the operation log to the remote security management center for backup and analysis.
[0023] Compared with the prior art, the beneficial effects of the present invention are:
[0024] The present invention collects network data packets in real time through a data collection module, and uses deep packet inspection technology to perform byte-by-byte matching with a known threat software signature library, enabling precise identification of suspected risk data packets. For example, in a certain water supply network, data packets containing specific threat software signatures were detected in a timely manner, effectively preventing potential threat software from invading. When analyzing network connection characteristics, the information security risk assessment module not only extracts abnormal characteristics of network connections and protocols, but also calculates network connection activity indicators and incorporates them into the calculation of the information security risk coefficient. This innovation makes the risk assessment more comprehensive and accurate, can reflect changes in the network security status in real time, detect abnormal network behaviors in a timely manner, and give early warnings of potential information security threats.
[0025] Based on the device operation data, the control security risk assessment module calculates the deviation coefficient for key control indicators such as water level, flow rate, and water quality in combination with their normal fluctuation ranges, and obtains the control security risk coefficient through weighted average of various indicators. When evaluating the security risk of flow control, the change trend of the flow rate is also considered, and the slope is calculated through linear regression analysis. If the slope is abnormal, the weight of the risk coefficient is adjusted. In the water flow control of a water conservancy project, this method has been successfully applied to detect abnormal change trends of the flow rate in advance, timely adjust the control strategy, avoid serious consequences such as damage to water conservancy facilities caused by abnormal flow rates, greatly improve the reliability of the control security risk assessment, and ensure the stable operation of the water conservancy industrial control system.
[0026] The linkage decision-making module receives the information security risk coefficient and the control security risk coefficient. After comparing them with the preset risk thresholds, it formulates a linkage protection strategy according to the risk type and level. This mechanism breaks the limitation of the traditional separate protection of information security and control security, and realizes the coordinated response of the two. When facing an increase in the information security risk coefficient caused by a network attack, it can quickly adjust the device control instructions, such as cutting off some non-critical business network connections, and at the same time start the standby security system to ensure that high-priority services are not affected; when the control security risk coefficient exceeds the standard, it can also timely check whether there are attack behaviors caused by information security vulnerabilities, and then take targeted protection measures to effectively reduce the impact of security risks on the overall system.
[0027] When the protection execution module executes the protection policy for adjusting the device control instruction, it adopts a control instruction verification mechanism. The instruction is simulated and executed in a simulation environment, and the simulation environment parameters are consistent with the actual system. By comparing the simulation execution result with the expected result, the accuracy of the instruction is ensured. In the equipment control of a sewage treatment plant, the instruction for adjusting the operation frequency of the sewage treatment pump is executed after being simulated and verified, avoiding the damage caused by incorrect instructions to the equipment and system operation, and improving the reliability and security of the protection policy execution. In addition, the protection execution module records detailed operation logs after performing operations and uploads them to the remote security management center regularly, facilitating the traceability analysis of the system operation situation, timely discovering potential problems, and continuously optimizing the protection policy.
[0028] When formulating the protection policy, the linkage decision-making module fully considers the system business priority and recovery cost. It obtains the list of business priorities from the local database and gives priority to ensuring the operation of high-priority services when facing risks, and selects the policy with the least impact on high-priority services for execution. In the urban water supply system, the raw water supply service, as a high-priority service, can be given priority to be guaranteed when facing risks, ensuring the safety of residents' water use. At the same time, it obtains the list of recovery costs corresponding to different protection policies, and preferentially selects the policy with a lower recovery cost for execution on the premise of meeting the risk prevention and control requirements, effectively balancing the relationship between security protection and economic cost, and improving the comprehensive benefit of the system operation. The data acquisition module collects device hardware status data, such as temperature, voltage, etc., and calculates the comprehensive health index of the device hardware status. The information security risk assessment module and the control security risk assessment module incorporate the comprehensive health index into the risk assessment system. If the comprehensive health index is lower than the health threshold, the information security risk coefficient and the control security risk coefficient are appropriately increased. During the operation of a certain waterworks equipment, by monitoring the device hardware status, the potential hardware failure risks are timely discovered, and the risk coefficients are adjusted accordingly, and maintenance measures are taken in advance to avoid safety accidents caused by equipment failures, further improving the system's security protection system and enhancing the overall reliability and stability of the system. Description of the Drawings
[0029] Figure 1 It is the working principle diagram of the information security and control security linkage protection system of the water industrial control system described in the present invention;
[0030] Figure 2 It is the working flow chart of the deep packet detection method;
[0031] Figure 3 It is the working flow chart of the control security risk assessment module. Detailed Implementation Modes
[0032] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0033] Please refer to Figures 1 - 3 , the present invention provides a technical solution: a water works industrial control system information security and control security linkage protection system, and the system includes:
[0034] Data acquisition module: This module is responsible for collecting the operation data of various devices in the water works industrial control system in real time, covering water level sensor data, flow sensor data, water quality monitoring data, and at the same time collecting packet information in the system network. The collected data will be marked as original monitoring data.
[0035] Information security risk assessment module: Deeply analyze the network packets in the collected original monitoring data, and extract information security-related characteristic values. Obtain the set of characteristic vectors of normal network connections from the local database , the currently monitored network connection characteristic vector is t, and through the cosine similarity formula calculate the similarity between t and each normal characteristic vector, and take the minimum similarity value min(cos(t, s i ))), and set the information security risk coefficient R1 = 1 - min(cos(t, s i ))), so as to evaluate the information security risk.
[0036] Control security risk assessment module: Evaluate the control security risk based on the sensor data. Taking the water level sensor data as an example, obtain the normal fluctuation range [a, b] of the water level from the local database, and set the current water level value as h. If h [a, b], calculate the water level deviation coefficient ; similarly calculate the deviation coefficients of the flow sensor data and the water quality monitoring data, and comprehensively calculate the control security risk coefficient through the weighted average method , where w j is the weight of each index, and d j is the deviation coefficient of the corresponding index.
[0037] Linkage decision-making module: Receive the information security risk coefficient R1 and the control security risk coefficient R2, and obtain the risk thresholds T1 and T2 from the local database; if R1 > T1 or R2 > T2, formulate a linkage protection strategy according to the risk type and level.
[0038] Protection Execution Module: According to the protection strategy formulated by the Linkage Decision-making Module, execute corresponding protection operations to ensure the safe and stable operation of the water conservancy industrial control system.
[0039] The present invention will be further described below with specific examples by using Embodiments 1 to 6:
[0040] Embodiment 1
[0041] This embodiment mainly realizes that the Data Acquisition Module can more accurately detect risk data packets and collect device hardware status data for evaluating the device health status, improving the system's perception ability of potential threats and the overall control ability of the device operating status.
[0042] Implementation of Deep Packet Inspection: When collecting network data packets, the Data Acquisition Module adopts the deep packet inspection method. Obtain the signature library of known threat software from the local database , and perform byte-by-byte matching on the content of the collected data packets. During actual operation, when a new data packet enters the system, the Data Acquisition Module will start the matching program, and compare the content of the data packet with each signature c1 in the signature library byte by byte. Once it is found that the data packet contains any signature in the signature library, the data packet will be immediately marked as a suspected risk data packet, and relevant information will be recorded in detail, such as the source IP address, destination IP address, port number, data packet size, discovery time, etc. of the data packet. These recorded information will provide key clues for subsequent security analysis.
[0043] Collection of Hardware Status Data and Calculation of Health Index: The Data Acquisition Module is also responsible for collecting the hardware status data of the devices in the water conservancy industrial control system and calculating the comprehensive health index of the device hardware status. Obtain the normal range of each hardware parameter from the local database , represents different hardware parameters, and the current value of the hardware parameter is x i . For each hardware parameter, calculate the health sub-index h according to whether it is within the normal range i : For example, for the hardware parameter of the CPU temperature of a certain device, the normal range is [30°C, 70°C]. If the currently measured CPU temperature is 45°C, since 45°C is within the normal range, the health sub-index h of this hardware parameter CPU温度 = 1; if the currently measured value is 80°C, which is not within the normal range, then calculate .
[0044] The comprehensive health index of the device hardware status , where is the weight of each hardware parameter. In practical applications, the weights can be reasonably allocated according to the importance of the hardware device to the system operation. For example, the parameter weight of the core processing chip can be set relatively high, while the parameter weight of some auxiliary hardware is relatively low. Through the calculation of the comprehensive health index, the overall health status of the device hardware can be intuitively understood, providing strong support for early device maintenance and fault warning.
[0045] Embodiment 2
[0046] This embodiment aims to further optimize the evaluation accuracy of the information security risk assessment module. By introducing the network connection activity index and incorporating the comprehensive health index of the device hardware status into the evaluation system, the information security risks faced by the system can be more comprehensively reflected.
[0047] When the information security risk assessment module analyzes the network connection characteristics, it calculates the network connection activity index. Within the unit time Δt, the number of network connection establishment times n1 and disconnection times n2 are counted. The network connection activity , and this activity index is incorporated into the calculation of the information security risk coefficient. The improved information security risk coefficient , where α is the activity influence factor. In the actual system operation, if within the unit time Δt = 1 minute, the number of network connection establishment times n1 = 10 times and the disconnection times n2 = 5 times, then the network connection activity times / minute. Suppose the originally calculated information security risk coefficient R1 = 0.3 and the activity influence factor α = 0.01, then the improved information security risk coefficient . In this way, the impact of the dynamic changes in the network connection on the information security risk can be more accurately evaluated.
[0048] The information security risk assessment module incorporates the comprehensive health index of the device hardware status into the risk assessment system. If the comprehensive health index H is lower than the health threshold H0 obtained from the local database, the information security risk coefficient and the control security risk coefficient are increased, and the adjustment formulas are respectively , where δ1 is the adjustment coefficient. For example, suppose R1 = 0.4, H = 0.6, H0 = 0.8, and δ1 = 0.5, then the adjusted information security risk coefficient . This means that when the device hardware health condition is poor, the system will correspondingly increase the evaluation of the information security risk in order to take more stringent protection measures in a timely manner.
[0049] Embodiment 3
[0050] This embodiment optimizes the control security risk assessment module. By performing linear regression analysis on traffic data and incorporating the comprehensive health index of device hardware status into the assessment, it more accurately assesses the control security risk and provides a more reliable risk assessment basis for the safe and stable operation of the system.
[0051] When the control security risk assessment module assesses the traffic control security risk, it performs linear regression analysis on the traffic data over a period of time. Let the traffic data sequence be q1, q2,..., q p , and establish a linear regression equation , where ω is the time variable. Through the linear regression algorithm, calculate the slope β1 of the regression equation. If |β1| exceeds the normal slope threshold S0 obtained from the local database, increase the weight of the traffic control security risk coefficient, and the adjusted control security risk coefficient , where γ is the weight adjustment factor and sign(β1) is the sign function, which takes values according to the positive or negative of β1. For example, in a certain period, linear regression analysis of the traffic data gives the regression equation q = 5 + 2t, then the slope β1 = 2. If the normal slope threshold S0 = 1.5 obtained from the local database and the weight adjustment factor γ = 0.2, since β1 > 0, sign(β1) = 1, assuming the original control security risk coefficient R2 = 0.3, then the adjusted control security risk coefficient . This indicates that when the change trend of the traffic data exceeds the normal range, the system will increase the consideration of the traffic control security risk.
[0052] The control security risk assessment module incorporates the comprehensive health index of the device hardware status into the risk assessment system. If the comprehensive health index H is lower than the health threshold H0 obtained from the local database, increase the control security risk coefficient, and the adjustment formula is , where δ2 is the adjustment coefficient. Assume R2 = 0.35, H = 0.5, H0 = 0.7, δ2 = 0.4, then the adjusted control security risk coefficient . In this way, the health status of the device hardware is closely associated with the control security risk, making the risk assessment more comprehensive and accurate.
[0053] Example 4
[0054] This embodiment optimizes the process of formulating protection strategies by the linkage decision-making module, considering business priorities and system recovery costs to ensure that when facing risks, protection strategies can be formulated that not only guarantee the operation of critical services but also have cost-effectiveness.
[0055] When formulating a protection strategy, the linkage decision-making module obtains the priority list of each service from the local database. When facing risks, it gives priority to ensuring the operation of high-priority services. For example, in a waterworks industrial control system, the water supply service usually has a higher priority, while some auxiliary water quality monitoring data statistics services have a relatively lower priority. If the system detects an information security risk or a control security risk, the linkage decision-making module will first judge the affected services and their priorities. If the risk affects the water supply service, even if there are other low-priority services affected at the same time, it will give priority to adopting a protection strategy to ensure the normal operation of the water supply service. If there are multiple executable protection strategies, the strategy with the least impact on high-priority services will be selected for execution. Suppose there are two current protection strategies. Strategy A will cause the water supply service to be interrupted for 5 minutes, but can quickly restore system security; Strategy B will not interrupt the water supply service, but the time to restore system security is longer and it may affect other low-priority services. In this case, the linkage decision-making module will, according to the service priority and the impact of the strategy on the service, give priority to selecting Strategy B for execution.
[0056] When formulating a protection strategy, the linkage decision-making module considers the system recovery cost. It obtains the recovery cost list corresponding to different protection strategies from the local database, and under the premise of meeting the risk prevention and control requirements, it gives priority to selecting the protection strategy with a lower recovery cost for execution. For example, for a certain risk situation, there are three protection strategies. The recovery cost of Strategy A is 1000 yuan, the recovery cost of Strategy B is 800 yuan, and the recovery cost of Strategy C is 1200 yuan. When all three strategies can effectively prevent and control risks, the linkage decision-making module will give priority to selecting Strategy B for execution to reduce the cost investment in system recovery.
[0057] Embodiment 5
[0058] This embodiment mainly realizes the reliability guarantee of the protection execution module when executing the protection strategy, ensures the correctness of the instruction through the control instruction verification mechanism, and at the same time provides an important basis for system security analysis and fault troubleshooting by recording the operation log.
[0059] When the protection execution module executes the protection policy for adjusting the device control instruction, it adopts a control instruction verification mechanism. Before sending a new control instruction, the instruction is first simulated and executed in a simulation environment, and the parameters of the simulation environment are the same as those of the actual water industrial control system. The simulation environment will be built according to the parameters of the actual system, including the device model, performance parameters, network configuration, operating environment, etc. For example, for a control instruction to adjust the pump speed, the actual operating state of the pump will be simulated in the simulation environment, the speed of the simulated pump will be adjusted according to the instruction, and the simulation execution result will be recorded. By comparing the simulation execution result with the expected result, if the difference exceeds the allowable error range obtained from the local database, the control instruction will be regenerated. Suppose the instruction to adjust the pump speed is expected to adjust the pump speed to 1500 revolutions per minute. In the simulation execution, the actual adjusted speed is 1450 revolutions per minute, and the allowable error range obtained from the local database is ±30 revolutions per minute. Since 1450 revolutions per minute is within the allowable error range, the instruction can be sent to the actual system for execution; if the simulation execution result is 1400 revolutions per minute, which exceeds the allowable error range, the control instruction needs to be regenerated until the simulation execution result meets the requirements.
[0060] After the protection execution module executes the protection operation, it records the operation log. The operation log includes the protection policy name, execution time, execution result, affected devices and business information. For example, for a certain protection operation, the protection policy name is "Blocking abnormal network connections", the execution time is "October 15, 2024 10:00:00", the execution result is "Successfully blocked the abnormal network connection from IP address 192.168.1.100", the affected device is "Firewall device FW-01", and the affected business is "Some non-critical data transmission services". The protection execution module will regularly upload the operation log to the remote security management center for backup and analysis. In actual applications, the upload time window can be set from 2:00 to 3:00 in the early morning every day, and the operation log of the previous day will be packaged and uploaded to the remote security management center. The remote security management center can centrally manage and analyze these logs, and through technologies such as data mining and machine learning, discover potential security threat patterns and system operation problems, providing strong support for further optimizing the protection policy and enhancing system security.
[0061] Embodiment Six
[0062] This embodiment takes the water industrial control system composed of multiple water plants and sewage treatment plants under a large water service group as an example to elaborate in detail the application of the information security and control security linkage protection system of the water industrial control system of the present invention in an actual scenario. Taking two specific scenarios as examples:
[0063] Scenario 1: Abnormal Detection of Pump Operation in the Intake Pump House: There are 5 pumps in the intake pump house of a water plant. The normal operation pattern recorded in the local database is that generally 3 to 4 pumps operate in combination, and the remaining pumps are in standby state. The data acquisition module collects the operation status data of the pumps in real time. When it is detected that more than 4 pumps are simultaneously shut down, or all 5 pumps are fully started, the control security risk assessment module will calculate a relatively high control security risk coefficient R2 based on these abnormal data. After receiving this risk coefficient, the linkage decision-making module compares it with the risk threshold T2. If R2 > T2, it is determined that there is a possibility of an attack, and a protection strategy for alarm and interception of relevant control instructions is formulated. The protection execution module executes this strategy, sends an alarm message to the operation and maintenance personnel, intercepts the control instructions that may cause abnormal operations, and records the operation logs, including the alarm time, the content of the intercepted instructions, the information of the affected pump equipment, etc., and uploads them to the remote security management center.
[0064] Scenario 2: Abnormal Detection of Sludge Discharge Operation in the Sedimentation Tank: The sludge discharge operation in the sedimentation tank of a water plant is regular and will only start after accumulating enough sludge. The relevant operation pattern data is stored in the local database. The data acquisition module collects the instructions for controlling the sludge discharge operation and the sludge volume data of the sedimentation tank in real time. When it is detected that there is a large difference between the instructions for controlling the sludge discharge operation and the pattern, for example, a sludge discharge instruction is received when the sludge volume far from reaches the start standard, the control security risk assessment module calculates a relatively high control security risk coefficient. The linkage decision-making module determines the possibility of an attack based on the comparison result of the risk coefficient and the threshold, and formulates corresponding protection strategies, such as alarm and interception of sludge discharge instructions. The protection execution module executes the strategy, sends an alarm signal to notify the operation and maintenance personnel, intercepts the abnormal sludge discharge instructions, and records the operation logs, and uploads the relevant information to the remote security management center for analysis.
[0065] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0066] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. Water conservancy industrial control system information security and control safety linkage protection system, characterized by: include: The data acquisition module is used to collect the operating data of various equipment in the water conservancy industrial control system in real time, including water level sensor data, flow sensor data, water quality monitoring data, and data packet information in the system network, and mark the collected data as original monitoring data; The information security risk assessment module is used to analyze the network data packets in the collected original monitoring data, extract the information security related feature values, and calculate the information security risk coefficient. The specific calculation method is: obtain the feature vector set of normal network connections from the local database , the currently monitored network connection feature vector is t, through the cosine similarity formula Calculate the similarity between t and each normal feature vector, and take the minimum similarity value min(cos(t,s i )), let the information security risk factor R1=1-min(cos(t,s i )); The control safety risk assessment module assesses the control safety risk based on the original monitoring data; for the water level sensor data, the normal water level fluctuation range [a, b] is obtained from the local database, and the current water level value is set to h. If h [a, b], calculate the water level deviation coefficient ; The deviation coefficients of flow sensor data and water quality monitoring data are calculated in the same way as the water level sensor data; Comprehensively consider the deviation coefficients of various indicators and calculate the control safety risk coefficient through the weighted average method , where w j is the weight of each indicator, d j is the deviation coefficient of the corresponding indicator; The data acquisition module also collects the hardware status data of the equipment in the water conservancy industrial control system and calculates the comprehensive health index of the equipment hardware status. The specific calculation method is: obtain the normal range of each hardware parameter from the local database , Indicates different hardware parameters. The current hardware parameter value is x i , calculate the health sub-index of each hardware parameter , a comprehensive health index of the device hardware status ,in is the weight of each hardware parameter; The information security risk assessment module and the control security risk assessment module incorporate the comprehensive health index of the equipment hardware status into the risk assessment system; If the comprehensive health index H is lower than the health threshold H0 obtained from the local database, the information security risk factor and the control security risk factor are increased, and the adjustment formulas are: and , where δ1 and δ2 are adjustment coefficients; Linkage decision module, used to receive information security risk coefficient and control safety risk factors , obtain risk thresholds T1 and T2 from the local database; if >T1 or >T2, formulate linkage protection strategies according to risk types and levels; The protection execution module performs corresponding protection operations according to the protection strategy formulated by the linkage decision module.
2. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: When the data collection module collects network data packets, it uses a deep packet inspection method, which is specifically implemented as follows: obtaining a signature library of known threat software from a local database , match the collected data packet content byte by byte, if the data packet contains any of the signature codes in the signature library c i , the data packet is marked as a suspected risk data packet and the relevant information is recorded.
3. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: When analyzing the network connection characteristics, the information security risk assessment module calculates the activity index of the network connection. The specific calculation method is: within a unit time Δt, the number of network connection establishment times n1 and disconnection times n2 are counted, and the network connection activity index is , the activity index is incorporated into the calculation of the information security risk coefficient, and the improved information security risk coefficient , where α is the activity influencing factor.
4. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: When evaluating the flow control safety risk, the control safety risk assessment module performs a linear regression analysis on the flow data within a period of time. Suppose the flow data sequence is q1, q2, ..., q p , establish the linear regression equation , where ω is the time variable, calculate the slope β of the regression equation 1; If |β1| exceeds the normal slope threshold S0 obtained from the local database, the weight of the flow control safety risk coefficient is increased, and the adjusted control safety risk coefficient , where γ is the weight adjustment factor, sign(β1) is the sign function, and takes values according to the positive or negative value of β1.
5. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: When formulating protection strategies, the linkage decision module obtains a priority list of each business from the local database. When facing risks, it gives priority to ensuring the operation of high-priority businesses. If there are multiple executable protection strategies, the strategy with the least impact on high-priority businesses is selected for execution.
6. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: The protection execution module adopts a control instruction verification mechanism when executing the protection strategy of adjusting the equipment control instructions; before sending a new control instruction, the instruction is first simulated and executed in a simulation environment, and the parameters of the simulation environment are consistent with the actual water conservancy industrial control system; by comparing the simulation execution result with the expected result, if the difference exceeds the allowable error range obtained from the local database, the control instruction is regenerated.
7. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: The linkage decision module considers the system recovery cost when formulating the protection strategy; obtains the recovery cost list corresponding to different protection strategies from the local database, and gives priority to the protection strategy with lower recovery cost on the premise of meeting the risk prevention and control requirements.
8. The water conservancy industrial control system information security and control safety linkage protection system according to claim 1 is characterized in that: After executing the protection operation, the protection execution module records the operation log; the operation log includes the protection policy name, execution time, execution result, affected equipment and business information, and regularly uploads the operation log to the remote security management center for backup and analysis.
Citation Information
Patent Citations
Industrial control system information security test system and method
CN111698267A
Industrial control system safety protection method and device, terminal equipment and storage medium
CN117609995A