Nuclear power plant full-range analog machine network intrusion prevention method, medium and equipment

By adopting deep learning anomaly behavior detection model and threat scoring algorithm in the full-range simulator network of nuclear power plants, real-time detection and automatic defense against network threats, the problem of traditional protection technology being difficult to cope with complex network attacks has been solved, and the warning accuracy and response speed of network security has been significantly improved.

CN119945753APending Publication Date: 2025-05-06YANGJIANG NUCLEAR POWER
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510033336.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The full-range simulator communication network of nuclear power plants faces complex and hidden cyber attacks, and traditional protection technologies are difficult to achieve timely and effective detection and defense.

Method used

A full-range simulator network intrusion prevention method is adopted, and by collecting data flow information, an abnormal behavior detection model based on deep learning is used to detect real-time, quantify the degree of threat, generate threat logs, and automatically execute defense measures.

Benefits of technology

Significantly improve the early warning accuracy and response speed of network security incidents, enhance network confrontation capabilities, effectively strengthen the security barriers of simulators, and ensure the stable operation of industrial control networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945753A_ABST
    Figure CN119945753A_ABST
Patent Text Reader

Abstract

The invention relates to a nuclear power plant full-range simulator network intrusion prevention method, a medium and equipment. The method comprises the following steps: S1, collecting data flow information of an analog machine network; and S2, based on a preset abnormal behavior detection model, carrying out deep analysis on the data flow information so as to detect abnormal data existing in the data flow information in real time. And S3, based on a preset threat scoring algorithm, performing quantitative evaluation on the threat degree of the abnormal data to generate a threat log. S4, judging whether a threat behavior exists or not according to the threat log; and if yes, giving an alarm for the threat behavior, and automatically executing corresponding defense measures. According to the invention, the early warning precision and response speed of the network security event can be obviously improved, the network confrontation capability is enhanced, the security barrier of the analog machine is effectively enhanced, and the stable operation of the industrial control network is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of nuclear power network security, and in particular to a network intrusion defense method, medium and equipment for a full-range simulator of a nuclear power plant. Background Art

[0002] The communication network of the full-range simulator of a nuclear power plant is a type of industrial control network in a nuclear power plant, and faces unprecedented network security threats. The frequent occurrence of network attacks has exposed the limitations of traditional protection technologies, especially for complex and hidden process attacks, which are often difficult to detect and defend in a timely and effective manner. These traditional technologies mainly rely on static rule matching and signature recognition, and are insufficient to deal with variant or unknown attack patterns, increasing the risk of nuclear facilities being damaged and seriously threatening the safe and stable operation of nuclear power plants. Summary of the invention

[0003] The technical problem to be solved by the present invention is to provide a network intrusion defense method, medium and equipment for a full-range simulator of a nuclear power plant.

[0004] The technical solution adopted by the present invention to solve the technical problem is: a network intrusion defense method for a full-range simulator of a nuclear power plant, the method comprising the following steps:

[0005] S1, collect data flow information of the simulator network;

[0006] S2. Based on a preset abnormal behavior detection model, deeply analyze the data stream information to detect abnormal data in the data stream information in real time;

[0007] S3. Based on a preset threat scoring algorithm, quantitatively assess the threat level of the abnormal data to generate a threat log;

[0008] S4. Determine whether there is any threatening behavior according to the threat log; if so, issue an alarm for the threatening behavior and automatically execute corresponding defense measures.

[0009] In some embodiments, the abnormal behavior detection model includes an input layer, an embedding layer, an LSTM layer, a self-attention layer and an output layer, and step S2 includes:

[0010] S21, forming a first time series data matrix according to the data stream information through the input layer, wherein the first time series data matrix is ​​a time series data matrix with low-dimensional features;

[0011] S22, performing high-dimensional mapping on the time series data matrix through the embedding layer to generate a second time series data matrix, where the second time series data matrix is ​​a time series data matrix with high-dimensional features;

[0012] S23, capturing the long-term dependencies in the second time series data matrix through the LSTM layer to output a third time series data matrix;

[0013] S24, assigning weights to each moment of the third time series data matrix through the self-attention layer to obtain an attention score matrix;

[0014] S25, performing a weighted sum operation on the attention score matrix to generate a context vector;

[0015] S26. Calculate an abnormality score for the context vector through the output layer to distinguish normal data from abnormal data.

[0016] In some embodiments, the simulator network includes a plurality of detection engines, each detection engine is provided with the abnormal behavior detection model, and step S3 includes:

[0017] S31, performing threat scoring on the detection engine, and obtaining a set of abnormal events generated by different detection engines, wherein the set of abnormal events includes a threat score corresponding to each detection engine;

[0018] S32, assigning weights to the threat scores of each of the detection engines;

[0019] S33: performing weighted summation on all detection engines that have completed weight allocation to obtain a comprehensive threat score, and generating the threat log according to the comprehensive threat score.

[0020] In some embodiments, in step S4, the step of alerting the threatening behavior and automatically executing corresponding defense measures includes:

[0021] The threatening behavior is blocked by a preset blocking method, and an alarm is issued by voice and / or SMS. The defense measures corresponding to the threatening behavior are determined according to a preset threat defense correspondence table, and the defense measures are automatically executed.

[0022] In some embodiments, determining the defense measures corresponding to the threat behavior according to a preset threat defense correspondence table includes:

[0023] When the threat behavior is that the logic server calculation executed by the DCS simulation data processing in the non-safety-level DCS system is not aligned with the initialization simulation operating condition scenario of the model simulation server of the nuclear power simulator, the corresponding defense measures are: intercepting and correcting inconsistent instructions to prevent potential threats at the source; and recording inconsistent events, judging the importance and urgency of the events through intelligent analysis, and automatically notifying the administrator; or

[0024] Determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes:

[0025] When the threatening behavior is that the model simulation server of the nuclear power simulator issues an instruction, and the KDS system returns that the instruction is invalid within the specified time, the corresponding defense measures are: when the preset threshold is exceeded, the abnormal mode is identified and the instruction is automatically resent; if multiple retransmissions fail, the operation is interrupted and all abnormal events and their handling processes are recorded.

[0026] In some embodiments, determining the defense measures corresponding to the threat behavior according to a preset threat defense correspondence table includes:

[0027] When the threatening behavior is that the model simulation server of the nuclear power simulator issues an instruction, and the safety-level DCS system, non-safety-level DCS system, KDA system, KDS system and PGU system return the instruction failure within the specified time, the corresponding defense measures are: when a timeout occurs, automatically activate the redundant instruction path or enable the backup instruction set, use the intelligent decision support system to select the optimal redundant path, and record the cause of the timeout event.

[0028] In some embodiments, determining the defense measures corresponding to the threat behavior according to a preset threat defense correspondence table includes:

[0029] When the threat behavior is that during the operation of the model simulation server of the nuclear power simulator, due to the disorder of model calculation parameters, some modules have overflowed, the corresponding defense measures are: capturing abnormal calculation modes to automatically adjust the calculation parameters, and recording all abnormal calculation behaviors and their context information, and notifying the administrator; or

[0030] When the threat behavior is a security-level DCS software exit prompt, the corresponding defense measures are: restart the software using an automated script or service, identify the cause of the abnormal exit and take corresponding measures, and record detailed information about the software exit event, including system status and logs before and after the exit.

[0031] In some embodiments, the method further comprises:

[0032] Tracing back the saved historical traffic data packets within any time range, and gradually and deeply analyzing the historical traffic data packets at the MAC, IP, application, and session levels to restore historical security events and diagnose the root causes of the historical security events; and / or

[0033] Conduct targeted analysis and disposal of application modules for specific security scenarios to generate a comprehensive analysis report; the comprehensive analysis report covers network security ratings, risk trends, asset security status and threat event statistics.

[0034] In addition, the present invention also provides a computer-readable storage medium, which stores a computer program, and the computer program is suitable for loading by a processor to execute the steps of the network intrusion defense method for a full-range simulator of a nuclear power plant as described above.

[0035] In addition, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the steps of the above-mentioned nuclear power plant full-range simulator network intrusion defense method by calling the computer program stored in the memory.

[0036] The implementation of the nuclear power plant full-range simulator network intrusion defense method, medium and equipment of the present invention has the following beneficial effects: the present invention deeply integrates intrusion detection and active defense mechanisms to monitor and defend against internal and external threats in the full-range simulator network in real time, which can significantly improve the warning accuracy and response speed of network security incidents, enhance network confrontation capabilities, effectively strengthen the security barriers of the simulator, and ensure the stable operation of the industrial control network. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The present invention will be further described below with reference to the accompanying drawings and embodiments, in which:

[0038] Figure 1 It is a flow chart of a network intrusion defense method for a full-range simulator of a nuclear power plant provided by the present invention;

[0039] Figure 2 It is a flow chart of a network intrusion defense method for a full-range simulator of a nuclear power plant provided by the present invention;

[0040] Figure 3 It is a flow chart of a network intrusion defense method for a full-range simulator of a nuclear power plant provided by the present invention. DETAILED DESCRIPTION

[0041] In order to have a clearer understanding of the technical features, purposes and effects of the present invention, the specific implementation methods of the present invention are now described in detail with reference to the accompanying drawings. In the following description, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", "connected", "fixed", "set" and the like should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral body; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements. When an element is referred to as being "on" or "under" another element, the element can be "directly" or "indirectly" located on the other element, or there may be one or more intermediate elements. The terms "first", "second", "third", etc. are only for the convenience of describing the present technical solution, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first", "second", "third", etc. can explicitly or implicitly include one or more of the features. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances.

[0042] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present invention. However, it should be clear to those skilled in the art that the present invention may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present invention.

[0043] In a preferred embodiment, reference Figure 1 The network intrusion defense method for the full range simulator of a nuclear power plant of this embodiment comprises the following steps:

[0044] S1. Collect data flow information of the simulator network. It can be understood that data flow information refers to various data packets (i.e., traffic data packets) flowing in the simulator system network, including but not limited to key information such as traffic size, source / destination port number, and protocol type.

[0045] S2. Based on the preset abnormal behavior detection model, the data flow information is deeply analyzed to detect abnormal data in the data flow information in real time. It can be understood that an independent industrial control network security platform is built for the network characteristics of the full range of nuclear power simulators, integrating comprehensive flow data collection, intelligent correlation analysis and rapid emergency response mechanisms. Using data analysis technology, the abnormal behavior detection model based on deep learning (also known as ABDM) is used to deeply analyze various data packets flowing in the network, and detect potential internal and external intrusion behaviors, abnormal traffic, and equipment and application failures in real time to ensure that security risks are intelligently perceived and dynamically evaluated. Specifically, the core of ABDM is to integrate the long short-term memory network (LSTM) and the self-attention mechanism to deeply model the time series data of network traffic to identify abnormal data.

[0046] S3. Based on the preset threat scoring algorithm, the threat level of abnormal data is quantitatively evaluated to generate threat logs. It can be understood that the threat scoring algorithm (TSA) is adopted to implement a multi-dimensional and multi-layer threat detection strategy, combined with preset rules, intelligent analysis and behavior models, to quantitatively evaluate the threat level of network events or behaviors, generate detailed threat logs, and achieve fine monitoring of network activities. Provide visual threat analysis tools to support deep drilling, correlation analysis and attack link reconstruction of detected events, so as to quickly locate and understand attack patterns.

[0047] S4. Determine whether there is threatening behavior based on the threat log. If so, an alarm is issued for the threatening behavior, and corresponding defense measures are automatically executed. Specifically, the threatening behavior can be blocked by a preset blocking method, and an alarm can be issued by voice and / or SMS, and the defense measures corresponding to the threatening behavior can be determined from the preset threat defense correspondence table, and the defense measures can be automatically executed. In other words, equipped with an automated event confirmation, response and blocking mechanism, once a threat is discovered, the system can take immediate action to reduce manual intervention time and improve response speed. Combined with security policies, it supports multiple blocking methods such as TCP RESET and DNS hijacking, and realizes efficient handling of events through multi-channel alarms such as voice and SMS.

[0048] This embodiment deeply integrates intrusion detection and active defense mechanisms to monitor and defend against internal and external threats in the full-range simulator network in real time, which can significantly improve the warning accuracy and response speed of network security incidents, enhance network confrontation capabilities, effectively strengthen the security barriers of the simulator, and ensure the stable operation of the industrial control network.

[0049] In some embodiments, reference Figure 2 ,The abnormal behavior detection model includes an input layer, an embedding layer, an LSTM layer, a self-attention layer and an output layer. Step S2 includes:

[0050] S21, through the input layer, a first time series data matrix is ​​formed according to the data flow information, and the first time series data matrix is ​​a time series data matrix with low-dimensional features. In other words, the input layer receives the flow data from the simulator network, including but not limited to the flow size, source / destination port number, protocol type and other key features, to form a time series data matrix X∈R N×T×F , where N represents the number of samples, T represents the length of the time series, and F represents the feature dimension.

[0051] S22, the time series data matrix is ​​mapped to a high dimension through the embedding layer to generate a second time series data matrix, and the second time series data matrix is ​​a time series data matrix of high-dimensional features. In other words, the embedding layer maps the original low-dimensional features to a high-dimensional space to enhance the feature expression capability. Specifically, through the weight matrix W emb ∈R F×D Transform and generate new features (i.e., the second time series data matrix) to represent X emb =X·W emb , where D is the feature dimension after embedding. In this step, through matrix multiplication, the original low-dimensional feature vector X is transformed into a weight matrix W. emb Mapped into a higher-dimensional space. By re-representing features in a high-dimensional space, the feature expression capability can be enhanced, which helps the model better capture complex patterns and relationships in the data, thereby improving the model's ability to detect and analyze potential intrusion behaviors, abnormal traffic, and device and application failures in network traffic.

[0052] S23, capture the long-term dependency in the second time series data matrix through the LSTM layer to output the third time series data matrix. That is, the LSTM unit is used to capture the long-term dependency in the time series, and the output matrix H∈R N ×T×D′ , D′ is the size of the LSTM hidden layer. It can be understood that in network security detection, network traffic data has time series characteristics. Normal network communication has regularity over a period of time, such as the communication frequency between devices and the distribution of data packet sizes in a specific period of time. Intrusion or anomaly will break the long-term dependency. LSTM captures this relationship and learns the normal traffic pattern over a long period of time. It can more accurately identify anomalies that deviate from the normal pattern. For example, a large number of abnormal connections during abnormal time of stable normal communication devices. LSTM can better detect and improve the sensitivity to potential intrusions, enhance the accuracy of complex network attacks and system anomalies, and deal with complex and hidden attacks that are difficult to detect with traditional technologies. The object captured by the LSTM layer is the high-dimensional feature X output by the embedding layer emb ,These features have been preliminarily processed and can better represent the complex characteristics of the original data.

[0053] S24. Assign weights to each moment of the third time series data matrix through the self-attention layer to obtain an attention score matrix. That is, by calculating the attention score matrix, weights are assigned to each moment of the time series, thereby highlighting important information. The calculation formula for the self-attention weight A is A=Softmax(H·W a ), where W a ∈R D′×1 is the attention weight matrix. It should be noted that W a ∈R D′×1 is the weight matrix used to calculate the attention score. a After calculation and processing by the Softmax function, A is the attention score matrix. This matrix can reasonably assign weights to each moment of the time series, so that the model can pay more attention to the moment information that is more important for judging the network security status (such as whether there is intrusion behavior, abnormal traffic, etc.) when processing data, which helps to improve the entire model's ability to understand and judge various situations in complex network environments.

[0054] S25. Perform a weighted sum operation on the attention score matrix to generate a context vector. That is, through the weighted sum operation, the context vector C∈R of each sample is generated. N×D′ , the formula is C = H·A T .

[0055] S26. The output layer calculates the anomaly score of the context vector to distinguish normal data from abnormal data. That is, the output layer uses the fully connected layer to output the final anomaly score. Specifically, the model can be trained through a binary classification loss function (such as cross entropy loss) to distinguish normal and abnormal traffic. The output layer weight matrix W out ∈R D′×2 and the bias vector b out ∈R 2 It is used to generate the final output Y of the model, and the calculation formula is Y = σ (C·W out +b out ), where σ is an activation function, such as Sigmoid, which is used to convert the output into a probability form. In this step, the fully connected layer is a layer in the neural network that fully connects each neuron in the previous layer to each neuron in this layer. By learning the appropriate weight matrix and bias vector, the input data is linearly transformed and output after being processed by the activation function. Here, it is used to calculate the anomaly score based on the context vector obtained by the previous processing to distinguish normal from abnormal traffic.

[0056] It can be understood that this embodiment breaks through the bottleneck of related technologies and establishes a comprehensive network security management system that integrates data collection, in-depth analysis, intelligent early warning and active defense. The system is deployed in the full-range simulator industrial control network through bypass, and uses advanced data processing and machine learning algorithms to not only achieve instant interception of external intrusions, but also insight into and defense against potential internal security threats. In response to the shortcomings of the prior art, the present invention emphasizes the real-time monitoring of network traffic and the deep backtracking analysis capabilities of historical data, and ensures rapid response and accurate identification of abnormal traffic through high-performance data packet collection and intelligent security detection and analysis. The core functions cover multi-dimensional threat detection, in-depth event analysis, flexible traffic backtracking, and efficient event handling and fault diagnosis, forming a closed-loop network security protection mechanism.

[0057] In some embodiments, reference Figure 3 The simulator network includes multiple detection engines, each detection engine is provided with an abnormal behavior detection model, and step S3 includes:

[0058] S31, perform threat scoring on the detection engines, and obtain a set of abnormal events generated by different detection engines, where the set of abnormal events includes the threat score corresponding to each detection engine. Specifically, it can be assumed that E = {e 1 ,e 2 ,...,e m} is used to represent the set of abnormal events generated by different detection engines, where e i The threat score provided by the i-th engine has a value range of [0,1], and the larger the value, the higher the threat level. In other words, by using the anomaly detection engine interface (network traffic monitoring, device and application status monitoring), a global request is made for all data. After defining the flow data table, the abnormal behavior data is obtained by judging whether the indicator value in the anomaly detection engine is within the acquisition range.

[0059] S32: weight the threat score of each detection engine. Specifically, a weight w may be assigned to the score of each abnormal threat engine. i The weights are determined based on the historical performance of each engine, professional fields, and other factors to meet constraints.

[0060] S33, perform weighted summation on all detection engines that have completed weight assignment to obtain a comprehensive threat score, and generate a threat log based on the comprehensive threat score. In other words, the comprehensive threat score S is calculated by weighted summation, and the formula is:

[0061] It should be noted that the simulator network is complex and a single engine has limitations. The comprehensive threat score can evaluate the network security status from an overall perspective, provide accurate decision-making basis for defense measures, avoid misjudgment of threats due to the limitations of a single engine, and ensure appropriate response. At the same time, each engine will produce false positives, and the comprehensive threat score can reduce their impact, reduce unnecessary alarms, and make up for the risk of missed reports by a single engine, use the complementarity of engines to discover potential threats, and enhance detection capabilities. In addition, the network environment changes dynamically and the means of attack are constantly evolving. The comprehensive threat score can dynamically adjust the weight according to the engine performance, better adapt to changes, integrate the attack features detected by multiple engines, accurately assess the degree of threat, and promptly activate the defense mechanism to effectively respond to complex and changing network security conditions.

[0062] Based on the above embodiment, the method may further include: tracing back the saved historical traffic data packets within any time range, and gradually and deeply analyzing the historical traffic data packets through the MAC, IP, application, and session levels to restore the historical security events and diagnose the root causes of the historical security events. In other words, this step can achieve dynamic traffic tracing and fault diagnosis. The historical traffic data packets can be traced back within any time range, and the historical security events can be quickly restored and the root causes of the faults can be diagnosed through the gradual and in-depth analysis of the MAC, IP, application, and session levels.

[0063] Targeted analysis and disposal of application modules for specific security scenarios are performed to generate a comprehensive analysis report, which covers network security ratings, risk trends, asset security status and threat event statistics. In this embodiment, through advanced threat defense and intelligent learning, deep detection and analysis of secret tunnel communication and hijacked communication are achieved, and customized feature rules and behavior models are used to enhance the ability to identify new attacks and abnormal behaviors. Combined with user behavior analysis, abnormal access patterns are identified to ensure compliance, and detection models are continuously optimized through machine learning to adapt to the evolution of attack technologies. Customized scenario applications and comprehensive security reports are provided. Specifically, application modules for specific security scenarios (such as ransomware detection) are provided for targeted analysis and disposal to enhance the pertinence and effectiveness of defense. A comprehensive analysis report is generated, covering network security ratings, risk trends, asset security status and threat event statistics, providing decision support and reinforcement suggestions for maintenance personnel. Achieve high-availability system architecture and compliance assurance: Design a highly available and scalable system deployment model to ensure uninterrupted operation of services and meet strict performance requirements. Follow strict security and data protection standards, including data encryption, security authentication, log management and monitoring, as well as the legal and compliant procurement and use of third-party components to ensure the overall security and compliance of the system.

[0064] This embodiment constructs a customized network protection model based on the specific needs of the CPR1000 unit. By integrating the analysis methods of artificial and machine intelligence, it deeply analyzes network risks and attack patterns, aiming to accurately characterize the characteristics of attackers, extract key security intelligence, and tailor a highly adaptable defense strategy for the simulator industrial control network. This method aims to significantly improve the warning accuracy and response speed of network security events, enhance network confrontation capabilities, provide a more solid protection barrier for the critical information infrastructure of nuclear power plants, and ensure the stable and healthy development of the nuclear energy industry. In other words, this method adopts a flexible configuration and bypass deployment strategy, integrates high-performance data packet processing and security detection and analysis functions, can accurately identify a variety of network attack behaviors, and quickly start a response mechanism, effectively curbing a variety of threats including network scanning and illegal access, marking that the network security protection of the full range of nuclear power simulators has entered a new intelligent era. This method deeply mines and analyzes the industrial control network data of the full range of simulators, uses visualization, correlation analysis and other technologies, accurately identifies threat events and blocks them immediately, and supports deep diagnosis of network failures and application failures, which greatly enhances the efficiency and accuracy of safety management and lays a solid foundation for the digital safety operation of nuclear power plants.

[0065] In a specific implementation, the system mainly includes the following components: Data acquisition module: responsible for collecting data flow information of each component in the simulator system, including but not limited to key information such as traffic size, source / destination port number, protocol type, etc. Abnormal behavior detection model (ABDM): based on deep learning technology, especially the integration of long short-term memory network (LSTM) and self-attention mechanism, it is used to perform deep modeling on the time series data of network traffic, and detect potential internal and external intrusion behaviors, abnormal traffic, and equipment and application failures in real time. Threat scoring algorithm (TSA): adopts multi-dimensional and multi-layer threat detection strategies, combined with preset rules, intelligent analysis and behavior models, to quantitatively evaluate the threat level of network events or behaviors and generate detailed threat logs. Rapid emergency response mechanism: when ABDM and TSA detect threats, the mechanism can immediately trigger corresponding defense measures, such as automatically correcting inconsistent instructions, resending instructions, starting redundant instruction paths, etc. Visual monitoring interface: provides an intuitive user interface for displaying system operation status, threat level, detected abnormal events and other information. Security management platform: used to configure system parameters, update rule base, manage user permissions, etc.

[0066] It can be understood that the information from the data collection module is the basis. The traffic characteristics it covers can reflect the basic status of the network, help TSA to preliminarily screen risk behaviors based on preset rules, and can discover potential anomalies that have not been identified by ABDM. The abnormal data output by ABDM allows TSA to accurately locate threats, conduct in-depth analysis of complex anomalies, and combine multi-dimensional strategies to determine whether it is an organized attack and assess the degree of threat. The two work together to complement each other. Data flow information provides a broad monitoring foundation, and abnormal data provides in-depth clues, which together improve the accuracy and reliability of the system's detection of network threats and avoid misjudgments and missed judgments.

[0067] The following is an exemplary description of the abnormal behavior detection behavior model and threat scoring algorithm through relevant codes.

[0068] #Define the input layer:

[0069] N,T,F=100,50,10#Number of samples, length of time series, and feature dimension.

[0070] input_layer=Input(shape=(T,F)).

[0071] #Embedding layer:

[0072] D=20 # Feature dimension after embedding.

[0073] embedding_matrix=tf.Variable(tf.random.normal([F,D]), name='embedding_matrix').

[0074] X_emb=Lambda(lambda x:tf.matmul(x, embedding_matrix))(input_layer).

[0075] #LSTM layer:

[0076] D_prime=10 #Size of LSTM hidden layer.

[0077] lstm_layer=LSTM(units=D_prime, return_sequences=True)(X_emb).

[0078] #Self-attention layer:

[0079] Wa=tf.Variable(tf.random.normal([D_prime,1]),name='attention_weights').

[0080] attention_scores=Lambda(lambda x:tf.matmul(x,Wa))(lstm_layer).

[0081] attention_scores=Softmax(axis=1)(attention_scores).

[0082] #Context vector generation:

[0083] context_vector=Lambda(lambdax:tf.matmul(x[0],x[1],transpose_a=True))(lst m_layer,attention_scores).

[0084] #Output layer:

[0085] output_dim=2 #Dimension of anomaly score.

[0086] W_out=tf.Variable(tf.random.normal([D_prime,output_dim]),name='output_weights').

[0087] b_out=tf.Variable(tf.zeros([output_dim]), name='output_bias').

[0088] Y=Lambda(lambda x:sigmoid(tf.matmul(x[0],x[1])+x[2]))(context_vector,W_out,b_out).

[0089] #Build the model:

[0090] model=Model(inputs=input_layer, outputs=Y).

[0091] #Calculate the comprehensive threat score:

[0092] def calculate_threat_score(events,weights):.

[0093] # Initialize the comprehensive score:

[0094] total_score=0.

[0095] #Traverse all events and their corresponding weights:

[0096] for event,weight in zip(events.keys(),weights.values()):.

[0097] #Calculate the weighted score for a single event:

[0098] score=events[event]*weight.

[0099] #Add to total score:

[0100] total_score+=score.

[0101] return total_score.

[0102] #Call function to calculate comprehensive threat score:

[0103] threat_score=calculate_threat_score(events,weights).

[0104] #Draw a bar chart to show the score of each event:

[0105] plt.bar(event_labels, event_scores, color='skyblue', label='EventScores').

[0106] #Add the rating value above the bar chart:

[0107] for i,v in enumerate(event_scores):.

[0108] plt.text(i,v+0.02,str(v),ha='center').

[0109] #Draw a line graph to show the weight distribution:

[0110] plt.plot(event_labels, weight_values, marker='o', linestyle='-', color='red', label='Weights').

[0111] In some embodiments, determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes:

[0112] When the threat behavior is that the logical server calculation performed by the DCS simulation data processing in the non-safety-level DCS system is not aligned with the initialization simulation operating scenario of the model simulation server of the nuclear power simulator, the corresponding defense measures are: intercept and correct inconsistent instructions to prevent potential threats at the source. And record inconsistent events, judge the importance and urgency of the events through intelligent analysis, and automatically notify the administrator. When the threat behavior is that the model simulation server of the nuclear power simulator sends instructions, and the KDS system returns the instruction failure within the specified time, the corresponding defense measures are: when the preset threshold is exceeded, identify abnormal patterns and automatically resend instructions. If multiple retransmissions fail, the operation is interrupted, and all abnormal events and their processing processes are recorded.

[0113] When the threat behavior is that the model simulation server of the nuclear power simulator issues an instruction, and the safety-level DCS system, non-safety-level DCS system, KDA system, KDS system and PGU system return the instruction failure within the specified time, the corresponding defense measures are: when a timeout occurs, automatically activate the redundant instruction path or enable the backup instruction set, use the intelligent decision support system to select the optimal redundant path, and record the cause of the timeout event. When the threat behavior is that during the operation of the model simulation server of the nuclear power simulator, due to the disorder of the model calculation parameters, some modules overflow, the corresponding defense measures are: capture the abnormal calculation mode to automatically adjust the calculation parameters, and record all abnormal calculation behaviors and their context information, and notify the administrator. When the threat behavior is the exit prompt of the safety-level DCS software, the corresponding defense measures are: restart the software using an automated script or service, identify the cause of the abnormal exit and take corresponding measures, and record the detailed information of the software exit event, including the system status and logs before and after the exit.

[0114] In this embodiment, different threat types and their corresponding defense measures are predefined. When ABDM and TSA detect specific threats, they will automatically trigger and execute corresponding defense measures to quickly respond to and handle threats. The defense measures are designed to be automatically executed. Because the nuclear power simulator network is time-sensitive and manual intervention is difficult to prevent threats in time, automatic execution can instantly start defense operations. In addition, the entire system is highly integrated and all parts work together. After detecting a threat signal, the response mechanism can immediately execute measures to achieve efficient automated defense and ensure network security.

[0115] In other words, corresponding monitoring means and defense measures are designed for the detection and response of specific risks, that is, for the common risks in the simulator system, to ensure that the system can identify and handle these faults in the first time, thereby improving the stability and security of the system.

[0116] Risk 1: L1 and calculation in non-safety-level DCS are not aligned or consistent with the initialization IC of 3KM. It should be noted that 3KM is the model simulation server of the nuclear power simulator, which is generated and integrated by transmitting model data to present the user-facing interface. 3KM data is the data of various simulation models integrated on the server, such as pump model / valve model / pipeline model / core model, etc. L1 is a logical server for DCS simulation data processing and execution, which is used for analysis, processing and transmission of underlying data, and simulates the control station in the cabinet of the on-site DCS. IC is used to present different simulation operating conditions in model simulation and is saved in the simulation model in the form of data, such as normal operating conditions / transient operating conditions / rush-to-grid conditions of nuclear power.

[0117] Monitoring methods: Deploy an intrusion detection system (IDS) to monitor the data flow between the non-security-level DCS and 3KM in real time, and use machine learning models to analyze data consistency.

[0118] Defensive measures: Use automated scripts or software tools to automatically correct inconsistent instructions. Use an intrusion prevention system (IPS) to intercept and correct inconsistent instructions to prevent potential threats at the source. Record inconsistent events, and use intelligent analysis to determine the importance and urgency of the events, and automatically notify administrators.

[0119] Risk 2: When 3KM issues an instruction, KDS returns the instruction invalid within the specified time.

[0120] Monitoring methods: Combine network monitoring tools and machine learning algorithms to monitor the delay in sending and receiving instructions and set reasonable thresholds.

[0121] Defense measures: When the preset threshold is exceeded, the intrusion detection system is used to identify abnormal patterns and automatically resend the instructions. If multiple resends fail, the intrusion prevention system is used to interrupt the operation to prevent potential attacks. All abnormal events and their handling process are recorded for further analysis.

[0122] Risk 3: When 3KM issues a command, the return command from the safety-level DCS and non-safety-level DCS, KDA, KDS, and PGU becomes invalid within the specified time.

[0123] Monitoring methods: Set up a command response timeout mechanism based on time series analysis, and use an intrusion detection system to monitor the response time.

[0124] Defense measures: When a timeout occurs, the intrusion prevention system automatically activates the redundant instruction path or enables the backup instruction set. An intelligent decision support system is used to select the optimal redundant path and record the cause of the timeout event.

[0125] Risk 4: During the operation of 3KM, some modules may overflow due to disordered model calculation parameters.

[0126] Monitoring methods: Implement a dynamic parameter monitoring system based on machine learning and set up a threshold alarm mechanism.

[0127] Defense measures: Automatically adjust computing parameters to avoid overflows. Use intrusion detection systems to capture abnormal computing patterns and intervene through intrusion prevention systems. Record all abnormal computing behaviors and their context information and notify administrators for investigation.

[0128] Risk 5: Safety-level DCS software exit prompt.

[0129] Monitoring methods: Use real-time monitoring tools and intelligent algorithms to monitor software status.

[0130] Defensive measures: When the software exits abnormally, restart the software using an automated script or service. Use an intrusion detection system to identify the cause of the abnormal exit and take appropriate measures through the intrusion prevention system. Record detailed information about the software exit event, including system status and logs before and after the exit, for subsequent analysis.

[0131] The real-time detection and active defense system for network intrusion of the full-range simulator of nuclear power plants has been deployed on the full-range simulators of relevant nuclear power plants, which can realize the following functions, including real-time monitoring of data packets in the network, rapid identification and early warning of potential threats. The intelligent algorithm can accurately identify abnormal behaviors and attack characteristics such as network scanning, FTP access, illegal remote connection, flood attack, etc., and can take timely measures to prevent them. It can be customized according to different needs to meet the security protection needs in different scenarios. Data-driven, improve security management capabilities, and conduct comprehensive risk assessment and in-depth mining analysis of the simulator DCS network architecture and data. Through visual analysis of threat events, drill-down correlation analysis, and attack chain correlation analysis, the system can quickly identify and confirm threat risks, respond and block disposal in a timely manner, and ensure the security of the network and system.

[0132] This embodiment has the following characteristics and technical effects:

[0133] 1) Simulator network-specific detection model: Develop a deep detection model suitable for the full range of CPR1000 simulator DCS networks, accurately extract the unique attack features and failure modes of simulator networks, and improve the recognition accuracy and response speed of complex network attacks and system anomalies in a simulated environment.

[0134] 2) Innovative deployment architecture: A physically isolated deployment model is adopted, combined with bypass mirroring technology of switches, routers and other network devices, to achieve lossless, real-time monitoring of industrial control network traffic, which not only ensures the independence and security of the detection system, but also ensures extensive coverage and deep perception of internal and external threats.

[0135] 3) Deep learning-driven threat identification engine: It integrates multi-dimensional feature rules, artificial intelligence algorithms and behavioral analysis models to significantly improve the accuracy and breadth of threat detection. It can quickly identify and warn of unknown attacks in complex network environments, effectively filling the blind spots of traditional protection measures.

[0136] 4) Holographic traffic backtracking and advanced analysis capabilities: Supports instant drag-and-drop backtracking of historical traffic, achieves in-depth analysis and visualization from MAC, IP to application layer, and combines technologies such as WEB protocol decoding to provide detailed and traceable analysis scenarios for security incidents, greatly enhancing the efficiency of incident response and root cause analysis.

[0137] 5) Intelligent active defense and fault self-healing mechanism: Integrates threat confirmation, immediate response and automatic blocking functions, combined with sophisticated fault diagnosis logic, can handle security incidents in real time and assist in network and equipment fault repair, effectively shortening the time window from detection to handling and improving system resilience.

[0138] 6) Full-cycle security situation awareness and closed-loop management: From threat detection, in-depth analysis, traffic backtracking to event handling and fault diagnosis, a closed-loop management process is formed. Especially in traffic backtracking analysis, a refined review of network activities in any period of time is achieved to ensure the root cause tracing and comprehensive understanding of security incidents, providing detailed data support and decision-making basis for the safe operation and maintenance of the simulator network.

[0139] In another preferred embodiment, the computer-readable storage medium of this embodiment stores a computer program, and the computer program is suitable for loading by a processor to execute the steps of the network intrusion defense method for a full-range simulator of a nuclear power plant in the above embodiment. This embodiment can significantly improve the early warning accuracy and response speed of network security incidents, enhance network confrontation capabilities, effectively strengthen the security barriers of the simulator, and ensure the stable operation of the industrial control network by deeply integrating intrusion detection and active defense mechanisms to monitor and defend internal and external threats in the full-range simulator network in real time.

[0140] In another preferred embodiment, the computer device of this embodiment includes a memory and a processor, the memory stores a computer program, and the processor executes the steps of the network intrusion defense method for the full-range simulator of a nuclear power plant in the above embodiment by calling the computer program stored in the memory. This embodiment can significantly improve the early warning accuracy and response speed of network security incidents, enhance network confrontation capabilities, effectively strengthen the security barriers of the simulator, and ensure the stable operation of the industrial control network by deeply integrating intrusion detection and active defense mechanisms to monitor and defend internal and external threats in the full-range simulator network in real time.

[0141] The computer-readable storage medium of the present invention can be any computer-readable storage medium that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.

[0142] The processor of the present invention is used to provide computing and control capabilities to support the operation of the entire system. It should be understood that in the embodiment of the present application, the processor can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0143] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0144] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0145] It can be understood that the above embodiments only express the preferred implementation modes of the present invention, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the patent scope of the present invention. It should be pointed out that, for ordinary technicians in this field, the above technical features can be freely combined without departing from the concept of the present invention, and several deformations and improvements can be made, which all belong to the protection scope of the present invention. Therefore, all equivalent changes and modifications made to the scope of the claims of the present invention should belong to the coverage of the claims of the present invention.

Claims

1. A network intrusion defense method for a full range simulator of a nuclear power plant, characterized in that: The method comprises the following steps: S1, collect data flow information of the simulator network; S2. Based on a preset abnormal behavior detection model, deeply analyze the data stream information to detect abnormal data in the data stream information in real time; S3. Based on a preset threat scoring algorithm, quantitatively assess the threat level of the abnormal data to generate a threat log; S4. Determine whether there is any threatening behavior according to the threat log; if so, issue an alarm for the threatening behavior and automatically execute corresponding defense measures.

2. The network intrusion defense method for a full range simulator of a nuclear power plant according to claim 1 is characterized in that: The abnormal behavior detection model includes an input layer, an embedding layer, an LSTM layer, a self-attention layer and an output layer. Step S2 includes: S21, forming a first time series data matrix according to the data stream information through the input layer, wherein the first time series data matrix is ​​a time series data matrix with low-dimensional features; S22, performing high-dimensional mapping on the time series data matrix through the embedding layer to generate a second time series data matrix, where the second time series data matrix is ​​a time series data matrix with high-dimensional features; S23, capturing the long-term dependencies in the second time series data matrix through the LSTM layer to output a third time series data matrix; S24, assigning weights to each moment of the third time series data matrix through the self-attention layer to obtain an attention score matrix; S25, performing a weighted sum operation on the attention score matrix to generate a context vector; S26. Calculate an abnormality score for the context vector through the output layer to distinguish normal data from abnormal data.

3. The network intrusion defense method for a full range simulator of a nuclear power plant according to claim 1, characterized in that: The simulator network includes a plurality of detection engines, each detection engine is provided with the abnormal behavior detection model, and step S3 includes: S31, performing threat scoring on the detection engine, and obtaining a set of abnormal events generated by different detection engines, wherein the set of abnormal events includes a threat score corresponding to each detection engine; S32, assigning weights to the threat scores of each of the detection engines; S33: performing weighted summation on all detection engines that have completed weight allocation to obtain a comprehensive threat score, and generating the threat log according to the comprehensive threat score.

4. The method for network intrusion defense of a full-range simulator of a nuclear power plant according to claim 1, characterized in that: In step S4, the threatening behavior is warned and corresponding defense measures are automatically executed, including: The threatening behavior is blocked by a preset blocking method, and an alarm is issued by voice and / or SMS. The defense measures corresponding to the threatening behavior are determined according to a preset threat defense correspondence table, and the defense measures are automatically executed.

5. The network intrusion defense method for a full range simulator of a nuclear power plant according to claim 4 is characterized in that: Determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes: When the threat behavior is that the logic server calculation executed by the DCS simulation data processing in the non-safety-level DCS system is not aligned with the initialization simulation operating condition scenario of the model simulation server of the nuclear power simulator, the corresponding defense measures are: intercepting and correcting inconsistent instructions to prevent potential threats at the source; and recording inconsistent events, judging the importance and urgency of the events through intelligent analysis, and automatically notifying the administrator; or Determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes: When the threatening behavior is that the model simulation server of the nuclear power simulator issues an instruction, and the KDS system returns that the instruction is invalid within the specified time, the corresponding defense measures are: when the preset threshold is exceeded, the abnormal mode is identified and the instruction is automatically resent; if multiple retransmissions fail, the operation is interrupted and all abnormal events and their handling processes are recorded.

6. The network intrusion defense method for a full range simulator of a nuclear power plant according to claim 4 is characterized in that: Determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes: When the threatening behavior is that the model simulation server of the nuclear power simulator issues an instruction, and the safety-level DCS system, non-safety-level DCS system, KDA system, KDS system and PGU system return the instruction failure within the specified time, the corresponding defense measures are: when a timeout occurs, automatically activate the redundant instruction path or enable the backup instruction set, use the intelligent decision support system to select the optimal redundant path, and record the cause of the timeout event.

7. The method for network intrusion defense of a full-range simulator of a nuclear power plant according to claim 4, characterized in that: Determining the defense measures corresponding to the threat behavior according to the preset threat defense correspondence table includes: When the threat behavior is that during the operation of the model simulation server of the nuclear power simulator, due to the disorder of model calculation parameters, some modules have overflowed, the corresponding defense measures are: capturing abnormal calculation modes to automatically adjust the calculation parameters, and recording all abnormal calculation behaviors and their context information, and notifying the administrator; or When the threat behavior is a security-level DCS software exit prompt, the corresponding defense measures are: restart the software using an automated script or service, identify the cause of the abnormal exit and take corresponding measures, and record detailed information about the software exit event, including system status and logs before and after the exit.

8. The network intrusion defense method for a full range simulator of a nuclear power plant according to claim 1, characterized in that: The method further includes: Tracing back the saved historical traffic data packets within any time range, and gradually and deeply analyzing the historical traffic data packets at the MAC, IP, application, and session levels to restore historical security events and diagnose the root causes of the historical security events; and / or Conduct targeted analysis and disposal of application modules for specific security scenarios to generate a comprehensive analysis report; the comprehensive analysis report covers network security ratings, risk trends, asset security status and threat event statistics.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which is suitable for being loaded by a processor to execute the steps of the network intrusion defense method for a full-range simulator of a nuclear power plant as described in any one of claims 1 to 8.

10. A computer device, characterized in that: It comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the steps of the network intrusion defense method for a full-range simulator of a nuclear power plant as described in any one of claims 1 to 8 by calling the computer program stored in the memory.

Citation Information

Cited By

  • Network traffic security auditing and defending method based on process injection and related equipment

    CN120128424A

  • Analyzing and processing method for detecting application layer attack by using large model

    CN120692066A