Industrial Internet of Things equipment control and monitoring system
By using multiple secure access control devices, access control modules and network monitoring modules in the industrial Internet of Things equipment control and monitoring system, the problem that the prior art cannot achieve accurate access control and dynamic expansion of the complex network structure of the industrial Internet of Things is solved, and efficient network traffic monitoring and security guarantee are achieved.
Patent Information
- Application Number
- CN202510084588.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-06
Smart Images

Figure CN119945771A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet of Things, and specifically to an industrial Internet of Things equipment control and monitoring system. Background Art
[0002] In recent years, with the rapid development of industrial Internet of Things technology, enterprises have realized the intelligentization and networking of production processes, greatly improving production efficiency and product quality. The industrial Internet of Things connects sensors, machines, equipment and systems to realize data collection, transmission, analysis and management, making information exchange between machines and machines, and between people and machines more convenient, and providing real-time monitoring and predictive maintenance support for equipment, effectively reducing failure rates and downtime, and promoting the optimal allocation and refined management of production resources. At the same time, as a super engine of new industrialization and a powerful pillar of the new industrial revolution, the industrial Internet has become a strategic choice for countries to seize the commanding heights of the industry. Countries are focusing on the development of the industrial Internet of Things to accelerate the rapid development of manufacturing and digital economy. In the process of the development of industrial Internet technology, my country has also seized the opportunity to maintain synchronous development and has taken many measures to vigorously promote the construction of the Internet of Things. At present, promoting the innovative development of the industrial Internet has become the core of the transformation and upgrading of the manufacturing industry and the development of intelligent manufacturing. It is a key path to promote the deep integration of the real economy and the digital economy, and an important choice to promote high-quality and sustainable economic development.
[0003] In the current digital age, the Industrial Internet of Things, as an important part of the new generation of information technology, is gradually being applied to various fields of society to promote economic and social development. However, with the increase in the complexity of network structure and the number of terminals, the Industrial Internet of Things is facing increasingly severe and complex network security threats and challenges. First, the Industrial Internet integrates a variety of wireless access technologies and uses multiple network protocols such as cellular networks (3G / 4G / 5G), industrial Ethernet (Modbus TCP / IP, EtherCat), and low-power network protocols (Wi-Fi, NB-IoT), forming a complex and diverse heterogeneous multi-domain network environment, resulting in different security mechanisms, requirements, and threats, which increases the difficulty of network protection. Secondly, the characteristics of industrial terminal devices, such as the large variety, large number, and wide distribution, lead to more unsafe attack entrances between the network and the outside world, and traditional network access control mechanisms are difficult to effectively support the secure access of industrial terminal devices. In addition, the limited computing and storage capabilities of the Industrial Internet of Things devices themselves, and the inconvenience of firmware updates and upgrades, lead to the fact that they can only ensure security based on performance, and cannot deploy complex security strategies. When faced with complex attack methods, it is difficult to ensure their security. These security threats not only involve the leakage of personal privacy and commercial secrets, but also endanger national security. Therefore, a safer and more effective device access control and network detection technology is needed to ensure the efficient operation and safe management of industrial Internet of Things networks and devices, and to solve the growing network security needs in complex network environments.
[0004] Access control technology is a method used to manage and monitor access to systems, networks, or devices. This technology aims to ensure that only authorized users or devices can obtain the required resources, thereby improving the security and manageability of the system. Network monitoring technology refers to real-time monitoring and analysis of network traffic, device status, security events, etc. to ensure the normal operation of the network, detect potential problems and threats, and improve network performance and security. The two technologies can detect and process abnormal traffic while monitoring the IIoT network to protect the IIoT network environment. However, as the topology of the current IIoT system becomes increasingly complex, the existing IIoT access control and network monitoring technologies do not take into account the complex network structure of the IIoT and cannot achieve accurate access control and dynamic expansion of terminal devices at the edge of the network. Summary of the invention
[0005] The present application provides an industrial Internet of Things device control and monitoring system to solve the problem that the existing industrial Internet of Things access control and network monitoring technologies do not take into account the complex network structure of the industrial Internet of Things and cannot achieve accurate access control and dynamic expansion of terminal devices at the edge of the network.
[0006] The present application provides an industrial Internet of Things device control and monitoring system, including more than two security access control devices, more than two access control modules and a network monitoring module.
[0007] Each security access control device is connected to at least one industrial Internet of Things device; the access control module is deployed on the security access control device, and the access control module includes a security control module and a log recording module; the industrial Internet of Things includes a top-level switch, and the network monitoring module is deployed on a dynamic monitoring device connected to the top-level switch, and the network monitoring module includes a traffic monitoring module, a traffic log module, an anomaly detection module and a device linkage management module.
[0008] Furthermore, the security control module is implemented through iptables, and through the custom iptables filtering rule configuration of network information, the real-time addition, modification and deletion of filtering rules and the switching of network management modes can also be completed; the logging module implements network packet filtering and logging through iptables, and the logging module reads the iptables log file, processes the information in the log file and records it in the log database, and the logging module supports querying and screening of key data.
[0009] Furthermore, the operation steps of the access control module specifically include a rule formulation step, an analysis and filtering step, and a judgment step.
[0010] The rule formulation step is used to deploy the access control device of the access control module to access the network and serve the industrial Internet of Things devices as a gateway, and the administrator formulates access control rules on the gateway; the analysis and filtering step is to analyze and filter the forwarded data packets according to the access control rules through the gateway; the judgment step is used to judge whether the data packet meets the release rule conditions. If the data packet meets the release rule conditions, the data packet is forwarded to the security access control device and a copy is sent to the network monitoring module; if the data packet does not meet the release rule conditions, the data packet is directly discarded and the relevant information of the data packet is recorded in the log file.
[0011] Furthermore, the network monitoring module includes a traffic monitoring module, a traffic log module, an anomaly detection module, a device linkage module and a device management module.
[0012] The traffic monitoring module is implemented through the libpcap library and can parse the captured traffic; the traffic log module records the monitored traffic information by storing the traffic monitoring module in a database; the anomaly detection module includes an anomaly handling rule configuration and processing function, and stores the anomaly handling rules through a database; the device linkage module is used for linkage with the network security access control device, including switching the access control device firewall mode, managing the access control device and traffic filtering rules; the device management module can obtain all devices currently connected to the network.
[0013] Furthermore, the steps of running the network monitoring module specifically include a rule configuration step, a data packet receiving step, a matching step and an alarm step.
[0014] The rule configuration step is to run the network monitoring module and pre-configure the anomaly detection rules by the administrator; the data packet receiving step is to capture the released data packet forwarded by the access control module through the network monitoring module; the matching step is to parse the captured data packet and match it with the configured anomaly detection rules; the alarm step is to determine whether there is an anomaly detection rule that meets the parsed information in the data packet. If so, the data packet is regarded as an abnormal data packet, the matching is interrupted, an abnormal alarm is issued, the abnormal event is recorded, and the abnormal data packet information is submitted to the access control module; if not, the network monitoring module receives and continues to capture and monitor the next data packet.
[0015] Furthermore, the industrial Internet of Things equipment control and monitoring system also includes a shallow analysis module and a deep analysis module.
[0016] The shallow analysis module passes the data packets captured by the network monitoring module to the shallow analysis module through shared content. The shallow analysis module is used to read the binary content of the data packet, parse out the basic information, and preliminarily detect whether there are suspected abnormal data packets in the basic information; the deep analysis module is when the shallow analysis module detects a suspected abnormal data packet and the shallow analysis module is insufficient to provide the information required for abnormality detection, the abnormal data is saved as a file and handed over to the deep analysis module. The deep analysis module uses the scapy library to complete the deep analysis of the data link layer, network layer, transport layer, and application layer protocols, extracts the information required for abnormal rule matching, and completes deep abnormality matching.
[0017] The present application provides an industrial Internet of Things device control and monitoring system, which can flexibly support the addition and deletion of access control modules, meet the complex network environment of the industrial Internet of Things, and support the expansion of functional modules or the update and upgrade of existing modules; secondly, different access control modules can formulate personalized filtering rules and strategies according to the business and traffic characteristics of the terminal equipment connected to realize differentiated access control functions; at the same time, the network traffic monitoring module adopts a layered traffic parsing and anomaly detection method, so that the calculation and analysis of the network traffic monitoring equipment is more efficient, with lower requirements on system resources and lower packet loss rate; the network monitoring module quickly throws out the exception and sends it to the access control module corresponding to the terminal equipment where the exception occurs, and sets access control rules for the exception, which can realize targeted exception handling, more efficient processing, and realize accurate access control and dynamic expansion of terminal equipment at the edge of the network. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0019] Figure 1 is a schematic diagram of an industrial Internet of Things device control and monitoring system according to an embodiment of the present application; Figure 2 is a flow chart of the operation steps of the access control module described in the application embodiment; Figure 3 It is a schematic diagram of the process mechanism of the access control module operation described in the application embodiment; Figure 4 is a flowchart of the operation steps of the network monitoring module described in the application embodiment; Figure 5 It is a schematic diagram of the process mechanism of the network monitoring module operation described in the application embodiment; Figure 6 It is a schematic diagram of the operation of the shallow analysis module and the deep analysis module described in the application embodiment. DETAILED DESCRIPTION
[0020] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.
[0021] like Figure 1As shown, the present application provides an industrial Internet of Things device control and monitoring system, including more than two security access control devices, more than two access control modules and a network monitoring module. The access control module and the network monitoring module realize real-time dynamic detection and protection of the industrial Internet of Things network through feedback control, wherein the attack data packet sent by the malicious device will be sent to the network security access control device via the switch first, and the access control device will copy the data packet and send it to the network dynamic monitoring device while forwarding the data packet to the access device. After the monitoring device detects a data packet anomaly (such as protocol / port anomaly, content anomaly, traffic anomaly, quantity anomaly), it will generate a filtering rule to apply to the security access control device, and subsequent data packets from malicious devices will be discarded by the security access control device and cannot be sent to the network, thereby achieving the effect of access control.
[0022] In order to cope with the sudden disconnection of the access control device, the access control module rules are managed and backed up in the network monitoring module center. When the security access control device is disconnected and restarted, the access control rules are synchronized with the rules in the central database to achieve rapid recovery of the access control rules.
[0023] Each security access control device is connected to at least one industrial Internet of Things device; the access control module is deployed on the security access control device, and the access control module includes a security control module and a log recording module; the industrial Internet of Things includes a top-level switch, and the network monitoring module is deployed on a dynamic monitoring device connected to the top-level switch, and the network monitoring module includes a traffic monitoring module, a traffic log module, an anomaly detection module and a device linkage management module.
[0024] Furthermore, the security control module is implemented through iptables, and through the custom iptables filtering rule configuration of network information, the real-time addition, modification and deletion of filtering rules and the switching of network management modes can also be completed; the logging module implements network packet filtering and logging through iptables, and the logging module reads the iptables log file, processes the information in the log file and records it in the log database, and the logging module supports querying and screening of key data.
[0025] like Figure 2 As shown, the operation steps of the access control module specifically include step S12) a rule formulation step, step S13) an analysis and filtering step, and step S14) a judgment step.
[0026] Step S12) rule formulation step, the access control device that deploys the access control module accesses the network and serves the industrial Internet of Things devices as a gateway, and the administrator formulates access control rules on the gateway.
[0027] Step S13) Analysis and filtering step: The gateway analyzes and filters the forwarded data packets according to the access control rules.
[0028] Step S14) is a judgment step, which judges whether the data packet meets the release rule conditions. If the data packet meets the release rule conditions, the data packet is forwarded to the security access control device, and a copy is sent to the network monitoring module; if the data packet does not meet the release rule conditions, the data packet is directly discarded, and the relevant information of the data packet is recorded in the log file.
[0029] In this embodiment, the release rule conditions are manually set according to needs, and the specific content is not described again.
[0030] like Figure 3 As shown, in this embodiment, the process mechanism of the access control module operation is: the security access control device (switch / wireless router) acts as a gateway for the access device to provide network services, that is, forwarding of data packets. Because the data packets will be filtered by the FORWARD chain of iptables when forwarding, the purpose of controlling the access device can be achieved by configuring corresponding rules on the FORWARD chain.
[0031] After the administrator configures the corresponding rules on the access control software, the iptables of the security access control device will analyze and filter the forwarded data packets. Those that meet the release conditions will be forwarded to the security access control device, and a copy will be sent to the network monitoring device to help with subsequent rule formulation. If the data packet does not meet the release conditions, it will be discarded directly and the relevant information will be recorded in the log file. The two sub-modules cooperate with each other to achieve real-time filtering and processing of the traffic of all terminals connected to the current access control device on the industrial Internet of Things, and query and filter the traffic logs.
[0032] Furthermore, the network monitoring module includes a traffic monitoring module, a traffic log module, an anomaly detection module, a device linkage module and a device management module.
[0033] The traffic monitoring module is implemented through the libpcap library and can parse the captured traffic; the traffic log module records the monitored traffic information by storing the traffic monitoring module in a database; the anomaly detection module includes anomaly handling rule configuration and processing functions, and stores the anomaly handling rules through a database; the device linkage module is used for linkage with the network security access control device, including switching the access control device firewall mode, managing the access control device and traffic filtering rules. When abnormal traffic is detected, the user can quickly disconnect the corresponding abnormal device with one click according to the IP information of the abnormal traffic, discard the network traffic with the source IP and target IP of the device, and realize the exception handling linked with the access control device; the device management module can obtain all devices currently connected to the network, which is used to inform the user which known devices in the subnet segment have been connected, and whether the access device is abnormal. The user can manually disconnect or reconnect the device in the device management interface of the front-end web UI.
[0034] like Figure 4 As shown, the steps of the network monitoring module operation specifically include step S21) rule configuration step, step S22) data packet receiving step, step S23) matching step and step S24) alarm step.
[0035] Step S21) rule configuration step, by running the network monitoring module, and the administrator pre-configures the anomaly detection rules; Step S22) a data packet receiving step, capturing the released data packet forwarded by the access control module through the network monitoring module; Step S23) matching step, parsing the captured data packets and matching them with the configured anomaly detection rules; Step S24) Alarm step, determine whether there is an abnormal detection rule in the data packet that meets the parsing information. If so, the data packet is regarded as an abnormal data packet, the matching is interrupted, an abnormal alarm is issued, and an abnormal event is recorded. The abnormal event includes the abnormal type and abnormal data packet parsing information, and the abnormal data packet information is submitted to the access control module; if not, the network monitoring module receives and continues to capture and monitor the next data packet.
[0036] like Figure 5As shown, in this embodiment, the process mechanism of the operation of the network monitoring module is as follows: the network monitoring module is used to detect possible abnormal traffic and provide a control basis for the security access control device (switch / wireless router). The device access control software transmits the released data packets to the network security dynamic monitoring software. The administrator configures the abnormal detection rules in the detection software in advance. The released data packets are captured and parsed by the monitoring software and matched with the configured rules. If there is an abnormal rule that meets the parsing information in the match, the data packet is regarded as abnormal, the match is interrupted, an abnormal alarm is issued, and an abnormal event (including the abnormal type and abnormal data packet parsing information) is recorded. The abnormal data packet information is submitted to the device access control software, and the abnormal processing is completed in conjunction with the security access control device; if no abnormal rule that meets the requirements is found after matching all rules, the data packet is regarded as normal, and the monitoring software continues to capture and monitor the next data packet. The rule configuration and abnormal event records are stored in the database. The network monitoring module updates the abnormal rules in real time by polling the rule database, and automatically writes to the abnormal event database after detecting the abnormality.
[0037] Furthermore, the industrial Internet of Things equipment control and monitoring system also includes a shallow analysis module and a deep analysis module for multi-level data packet analysis and anomaly detection.
[0038] The shallow parsing module passes the data packets captured by the network monitoring module to the shallow parsing module through shared content. The shallow parsing module is used to read the binary content of the data packet and parse out basic information, which includes five-tuple, timestamp, data packet size and other information, and preliminarily detect whether there are suspected abnormal data packets in the basic information; the deep parsing module is when the shallow parsing module detects a suspected abnormal data packet and the shallow parsing module is insufficient to provide the information required for abnormality detection, the abnormal data is saved as a file and handed over to the deep parsing module. The deep parsing module uses the scapy library to complete the deep parsing of the data link layer, network layer, transport layer, and application layer protocols, extracts the information required for abnormal rule matching, and completes deep abnormality matching.
[0039] like Figure 6As shown, the high-resolution module and the deep-resolution module implement the specific process of network monitoring and anomaly detection as follows: data packet analysis and anomaly detection are actually divided into two parts: shallow and deep. Shallow analysis and detection are independently developed by this project based on the libpcap library, and the processing efficiency is relatively high. By binding the network device with the libpcap module and setting the relevant capture parameters, the binary content of the network data packet received by the device can be read, and the basic information such as the five-tuple, timestamp, and data packet size can be parsed from the binary content of the data packet, and a preliminary detection can be made whether it is a suspected abnormal data packet. If a suspected abnormal data packet is detected and the shallow analysis is not enough to provide the information required for anomaly detection, the data packet is forwarded to the deep analysis; scapy is used to complete the deep analysis of the data link layer, network layer, transport layer, and application layer protocols, and the information required for abnormal rule matching is extracted from it to complete the deep abnormal matching. And by pipeline the workflow of the sniffer module and split it into multi-process tasks for CPU multi-core parallel processing, the efficiency of traffic analysis and exception handling is improved.
[0040] The advantage of the present application is that it provides an industrial Internet of Things equipment control and monitoring system that can flexibly support the addition and deletion of access control modules, meet the complex network environment of the industrial Internet of Things, and support the expansion of functional modules or the update and upgrade of existing modules; secondly, different access control modules can formulate personalized filtering rules and strategies according to the business and traffic characteristics of the terminal equipment connected to realize differentiated access control functions; at the same time, the network traffic monitoring module adopts a layered traffic parsing and anomaly detection method, so that the calculation and analysis of the network traffic monitoring equipment is more efficient, with lower requirements on system resources and lower packet loss rate; the network monitoring module quickly throws out the exception and sends it to the access control module corresponding to the terminal equipment where the exception occurs, and sets access control rules for the exception, which can realize targeted exception handling, more efficient processing, and realize accurate access control and dynamic expansion of terminal equipment at the edge of the network.
[0041] The above is a detailed introduction to an industrial Internet of Things equipment control and monitoring system provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. An industrial Internet of Things equipment control and monitoring system, characterized in that: include: Two or more security access control devices, each of which is connected to at least one industrial Internet of Things device; Two or more access control modules, which are deployed on a security access control device, the access control modules including a security control module and a log recording module; and The network monitoring module includes a top-level switch in the industrial Internet of Things. The network monitoring module is deployed on a dynamic monitoring device connected to the top-level switch. The network monitoring module includes a traffic monitoring module, a traffic log module, an anomaly detection module and a device linkage management module.
2. The industrial Internet of Things equipment control and monitoring system according to claim 1, characterized in that: The security control module is implemented through iptables. Through the custom iptables filtering rule configuration of network information, the real-time addition, modification and deletion of filtering rules and the switching of network management mode can also be completed; The log recording module uses iptables to implement network packet filtering and log recording. The log recording module reads the iptables log file, processes the information in the log file and records it in the log database. The log recording module supports querying and screening of key data.
3. The industrial Internet of Things equipment control and monitoring system according to claim 1, characterized in that: The operation steps of the access control module specifically include the following steps: A rule formulation step, in which an access control device that deploys an access control module accesses the network and serves the industrial Internet of Things devices as a gateway, and an administrator formulates access control rules on the gateway; An analysis and filtering step, wherein the gateway analyzes and filters the forwarded data packets according to the access control rules; as well as A determination step, determining whether the data packet meets the release rule conditions, and if the data packet meets the release rule conditions, forwarding the data packet to the security access control device, and sending a copy to the network monitoring module; If the data packet does not meet the release rule conditions, the data packet is directly discarded and relevant information of the data packet is recorded in a log file.
4. The industrial Internet of Things equipment control and monitoring system according to claim 1, characterized in that: The network monitoring module includes: The traffic monitoring module is implemented through the libpcap library and can parse the captured traffic; The traffic log module records the traffic information monitored by the traffic monitoring module through the database storage; Anomaly detection module, including anomaly handling rule configuration and processing functions, storing the anomaly handling rules through a database; Device linkage module, used for linkage with network security access control devices, including switching access control device firewall mode and managing access control devices and traffic filtering rules; and The device management module can obtain all devices currently connected to the network.
5. The industrial Internet of Things equipment control and monitoring system according to claim 1, characterized in that: The steps of running the network monitoring module specifically include the following steps: A rule configuration step, running the network monitoring module, and having an administrator pre-configure anomaly detection rules; Data packet receiving step, the network monitoring module captures the released data packet forwarded by the access control module; The matching step parses the captured data packets and matches them with the configured anomaly detection rules; and The alarm step determines whether there is an abnormal detection rule in the data packet that meets the parsed information. If so, the data packet is regarded as an abnormal data packet, the matching is interrupted, an abnormal alarm is issued, the abnormal event is recorded, and the abnormal data packet information is submitted to the access control module; if not, the network monitoring module receives and continues to capture and monitor the next data packet.
6. The industrial Internet of Things equipment control and monitoring system according to claim 1, characterized in that: Also includes: A shallow parsing module, which transmits the data packets captured by the network monitoring module to the shallow parsing module through shared content, and the shallow parsing module is used to read the binary content of the data packets, parse out the basic information, and preliminarily detect whether there are suspected abnormal data packets in the basic information; as well as The deep analysis module, when the shallow analysis module detects a suspected abnormal data packet and the shallow analysis module is insufficient to provide the information required for anomaly detection, the abnormal data is saved as a file and handed over to the deep analysis module. The deep analysis module uses the scapy library to complete the deep analysis of the data link layer, network layer, transport layer, and application layer protocols, extracts the information required for abnormal rule matching, and completes deep anomaly matching.