Industrial control network threat intelligence analysis method based on large model driving
Through the industrial control network threat intelligence analysis method driven by a large model, combined with multi-dimensional feature adaptive learning and dynamic adjustment strategies, the problems of low identification accuracy and weak generalization ability in the existing technology are solved, and accurate identification and efficient response of industrial control network threats are achieved.
Patent Information
- Application Number
- CN202510429049.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The existing industrial-control network threat detection methods cannot fully capture the complex relationship between multi-dimensional features, resulting in a decrease in recognition accuracy. The pre-trained model has weak generalization ability when facing dynamically changing networks, making it difficult to deal with new attacks.
The industrial control network threat intelligence analysis method is adopted based on large-model-driven industrial-controlled network network threat intelligence fusion, through multi-dimensional feature adaptive learning and threat intelligence, network data is collected in real time, abnormal risk index and actual threat index are calculated, data sampling rate and standard synchronization are dynamically adjusted, and data processing efficiency is optimized.
It realizes accurate identification and prediction of industrial-controlled network threats, reduces false alarm rates and missed alarm rates, improves response speed and resource utilization, enhances adaptability to new threats, and improves network security, stability and intelligent defense capabilities.
Smart Images

Figure CN119945804A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to an industrial control network threat intelligence analysis method driven by a large model. Background Art
[0002] With the widespread application of industrial control networks (ICS), they play an important role in key infrastructure fields such as electricity, petroleum, chemical industry, and manufacturing. However, the complexity, heterogeneity, and interconnection of industrial control networks with external networks have made them face increasing security threats, including malicious attacks, abnormal intrusions, and data tampering. Due to the high real-time and continuous characteristics of industrial control networks, traditional security protection measures are difficult to effectively identify and respond to potential threats, resulting in increasing network security risks and posing a serious threat to system stability and data integrity.
[0003] The patent document with publication number CN115941237A discloses a threat detection method and device for an industrial control network, the method comprising: obtaining multiple target feature parameters in the industrial control network; determining a feature mutual information value between every two target feature parameters; determining a state fusion index based on the multiple feature mutual information values; and performing threat detection on the state fusion index using a pre-trained threat detection model.
[0004] It can be seen that the threat detection method for the industrial control network has the following problems: the method only determines the state fusion index through the feature mutual information value, and cannot fully capture the complex relationship between multi-dimensional features, resulting in a decrease in the recognition accuracy of potential threat features; the pre-trained threat detection model is difficult to cope with new attacks or unseen threat patterns when facing dynamically changing industrial control networks, and its generalization ability is weak; the calculation of the state fusion index depends on the feature mutual information value, lacks dynamic evaluation of multi-dimensional features such as real-time traffic and instruction execution frequency, and cannot accurately reflect the state of complex networks. Summary of the invention
[0005] To this end, the present invention provides an industrial control network threat intelligence analysis method based on large model driving, which is used to overcome the problem of low threat intelligence response speed in the prior art due to the single feature mutual information calculation through multi-dimensional feature adaptive learning and threat intelligence fusion.
[0006] To achieve the above object, the present invention provides an industrial control network threat intelligence analysis method based on large model drive, comprising: Collect the real-time traffic, real-time instruction execution frequency, real-time access frequency and all intelligence security events within the preset historical time of each node to be analyzed in the monitoring area divided based on the preset network topology in the industrial control network; Determine a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree; Determine an abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node; Determine a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes determined within a preset determination time period; Calculate an actual threat index based on the abnormal risk index of each threat node and the intelligence security event; Use a preset big data model to predict all of the threat nodes to form a number of predicted threat indexes; According to the actual threat index and the predicted threat index, a preset data sampling rate in the preset network topology is adjusted to form an adjusted sampling rate, or the preset standard synchronization degree is adjusted to form an adjusted standard synchronization degree; Using the preset big data model to predict the threat node re-determined based on the adjusted sampling rate or the adjusted standard synchronization, to form a target threat index; Output an industrial control network threat intelligence analysis report based on the target threat index.
[0007] Further, determining a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree includes: Calculate the standard deviation of the real-time traffic within a preset first determined time period to form a real-time traffic fluctuation value; Calculating the standard deviation of the instruction execution frequency within the preset first time period to form a real-time frequency fluctuation value; A number of temporary high-risk nodes are determined according to the real-time traffic fluctuation value, the real-time frequency fluctuation value and the preset standard synchronization degree.
[0008] Further, determining a number of temporary high-risk nodes according to the real-time traffic fluctuation value, the real-time frequency fluctuation value and the preset standard synchronization degree includes: Normalizing the real-time flow fluctuation value to form a normalized flow fluctuation value; Normalizing the real-time frequency fluctuation value to form a normalized frequency fluctuation value; Calculating the correlation coefficient between the normalized flow fluctuation value and the normalized frequency fluctuation value to form a change synchronization degree; When the change synchronization degree is less than the preset standard synchronization degree, the node to be analyzed is determined to be a temporary high-risk node, so as to determine a number of the temporary high-risk nodes.
[0009] Further, determining the abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node includes: Normalizing the real-time traffic to form a normalized traffic, normalizing the real-time instruction execution frequency to form a normalized execution frequency, and normalizing the real-time access frequency to form a normalized access frequency; The normalized traffic, the preset traffic weight, the normalized execution frequency, the preset execution frequency weight, the normalized access frequency and the preset access frequency weight are weighted and summed to obtain the abnormal risk index.
[0010] Further, determining a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes determined within a preset determination time period includes: Calculate the standard deviation of the abnormal risk index of a single temporary high-risk node to form an index fluctuation value; Calculate the standard deviation of the real-time traffic of a single temporary high-risk node to form a risk traffic fluctuation value; Draw a change curve of the index fluctuation value within the preset determination time to form an index fluctuation curve; Draw a change curve of the risk flow fluctuation value within the preset determination time to form a risk flow fluctuation curve; Calculating the cosine similarity of the index fluctuation curve and the risk flow fluctuation curve to form a change consistency; A number of threat nodes are determined according to the change consistency of any two adjacent temporary high-risk nodes.
[0011] Further, determining a number of threat nodes according to the change consistency of any two adjacent temporarily high-risk nodes includes: Calculating the relative deviation of the consistency of the two changes to form a consistency deviation; When the consistency deviation is greater than a preset consistency deviation threshold, it is determined that the corresponding two temporary high-risk nodes are both threat nodes, so as to determine a number of threat nodes.
[0012] Further, calculating the actual threat index according to the abnormal risk index of each threat node and the intelligence security event includes: Obtain the number of occurrences, timestamps, and event types of the intelligence security events; When the number of occurrences is greater than a preset number of occurrences threshold, a weighted time interval is calculated according to a preset weight combination corresponding to the event type and any two adjacent timestamps to form a plurality of weighted time intervals; logarithmically varying each of the weighted time intervals to form a plurality of logarithmically weighted intervals; Calculating the reciprocal of the sum of the standard deviation of all the logarithmic weighted intervals in the preset sliding window and a preset constant to form a distribution concentration; The actual threat index is calculated according to the distribution concentration and the abnormal risk index.
[0013] Further, calculating the actual threat index according to the distribution concentration and the abnormal risk index includes: When the distribution concentration is greater than the preset standard concentration, the abnormal risk index is increased according to the relative deviation between the distribution set and the preset standard concentration and a preset index calculation coefficient to form the actual threat index.
[0014] Further, adjusting a preset data sampling rate in the preset network topology according to the actual threat index and the predicted threat index to form an adjusted sampling rate, or adjusting the preset standard synchronization degree to form an adjusted standard synchronization degree includes: Calculating an absolute value of a relative deviation between the actual threat index and the predicted threat index to form a plurality of index deviations; When the index deviation is greater than a preset index deviation threshold, the threat node is determined to be a misjudged node, forming a plurality of misjudged nodes; The preset data sampling rate is adjusted according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or the preset standard synchronization degree is adjusted to form the adjusted standard synchronization degree.
[0015] Further, adjusting the preset data sampling rate according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or adjusting the preset standard synchronization degree to form the adjusted standard synchronization degree includes: When the number of the misjudged nodes is within a preset misjudged number range, calculating the standard deviation of the number of the misjudged nodes to form a misjudged number fluctuation value; When the misjudgment number fluctuation value is greater than the preset misjudgment fluctuation threshold, the preset data sampling rate is increased according to the relative deviation between the misjudgment number fluctuation value and the preset misjudgment fluctuation threshold point and the preset first adjustment coefficient to form the adjusted sampling rate; When the number of the misjudged nodes is greater than the maximum value of the preset misjudgment number range, the preset standard synchronization degree is increased according to the relative deviation between the number of the misjudged nodes and the maximum value and the preset second adjustment coefficient to form the adjusted standard synchronization degree.
[0016] Compared with the prior art, the beneficial effect of the present invention lies in that, through large-model driven intelligent analysis, combined with real-time monitoring, historical intelligence data and dynamic adjustment strategies, accurate identification and prediction of industrial control network threats are achieved, potential threats can be discovered earlier, and the false alarm rate and missed alarm rate are effectively reduced through the calculation of abnormal risk index and actual threat index. By adaptively adjusting the data sampling rate and standard synchronization, data processing efficiency is optimized, redundant collection and calculation burden are avoided, response speed and resource utilization are improved, and combined with multi-level risk assessment and prediction models, the adaptability to new threats is enhanced, and targeted intelligence analysis reports can be generated for different threat levels, providing strong support for network security defense and plan formulation, thereby comprehensively improving the security, stability and intelligent defense capabilities of industrial control networks.
[0017] Furthermore, by calculating the traffic and instruction frequency fluctuation values in real time and combining them with synchronization judgment, it is possible to quickly and accurately identify potential high-risk nodes, avoid missing low-frequency but abnormal threat behaviors, and provide an efficient and reliable foundation for subsequent threat node screening and threat index calculation.
[0018] Furthermore, normalization processing is used to eliminate the influence of different data dimensions and improve calculation accuracy; correlation coefficient calculation can accurately evaluate the synchronization of traffic and instruction execution frequency and reduce the misjudgment rate; synchronization threshold determination enables the system to dynamically identify abnormal behavior, effectively improve the ability to perceive potential security threats, and ensure the security and stability of the industrial control network.
[0019] Furthermore, through normalization and weighted calculation, the importance of each indicator to risk assessment is fully considered, so that the abnormal risk index can accurately reflect the abnormal degree of the node. By setting weight distribution, the calculation method can be adjusted according to different industrial control network environments, enhancing adaptability and avoiding the influence of different data ranges on the calculation results.
[0020] Furthermore, through standard deviation calculation, curve drawing and cosine similarity analysis, the correlation between abnormal risk index and traffic fluctuation is accurately portrayed, which can more comprehensively identify the risk evolution trend. Compared with single threshold judgment, this method can dynamically adapt to the fluctuation of industrial control network environment, avoid false positives and false negatives, and improve the accuracy of threat detection. At the same time, based on the joint analysis of adjacent high-risk nodes, more threatening target nodes can be discovered to enhance the overall defense capability.
[0021] Furthermore, by calculating the consistency deviation and comparing it with the preset threshold, errors with small fluctuations can be effectively eliminated, and only nodes with large fluctuation differences are judged as threat nodes, thereby improving the accuracy of threat node identification, helping to reduce misjudgments caused by data noise or slight system fluctuations, and ensuring that real and threatening nodes are identified in a timely manner.
[0022] Furthermore, the actual threat index of each threat node can be accurately evaluated by combining information such as the frequency, type, and time interval of the event. The use of logarithmic changes and smoothing processing can help reduce the interference caused by data fluctuations and improve the accuracy and stability of threat assessment.
[0023] Furthermore, by increasing the abnormal risk index when the distribution concentration is higher than the preset standard concentration, security threats with high frequency and dense time distribution can be more accurately identified. High distribution concentration usually means that certain threat behaviors have strong correlation or persistence, and relying solely on the abnormal risk index may ignore these long-term accumulated risks. Therefore, introducing a calculation coefficient to dynamically amplify the abnormal risk index helps to improve the sensitivity of detection, enhance the ability to respond to potential threats, and reduce the possibility of misjudgment or omission.
[0024] Furthermore, dynamic adjustments through misjudgment analysis can reduce false positives and missed negatives and improve the adaptability of the detection system. When there are many misjudged nodes, increasing the data sampling rate helps enhance the system's perception capabilities and capture more fine-grained threat features; adjusting the standard synchronization can optimize the accuracy of data analysis and reduce misjudgments caused by data synchronization errors, thereby improving the reliability and intelligence of the overall detection system.
[0025] Furthermore, by dynamically adjusting the data sampling rate and standard synchronization, this method can reduce the false positive rate while ensuring detection accuracy. When the false positive rate fluctuates greatly, increasing the data sampling rate can more accurately capture the risk changes, and when the number of false positive nodes is too large, increasing the standard synchronization can optimize global coordination and reduce false positives caused by instability, thereby improving the accuracy of threat detection and network security protection capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 This is a flow chart of the industrial control network threat intelligence analysis method driven by a large model in this embodiment; Figure 2 This is a decision logic diagram for determining temporary high-risk nodes in this embodiment; Figure 3 This is a logic diagram for determining threat nodes in this embodiment; Figure 4 This is a decision logic diagram for determining misjudged nodes in this embodiment. DETAILED DESCRIPTION
[0027] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0028] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.
[0029] See also Figure 1 As shown, it is a flow chart of the industrial control network threat intelligence analysis method driven by a large model in this embodiment; This embodiment provides an industrial control network threat intelligence analysis method based on a large model drive, including: Collect the real-time traffic, real-time instruction execution frequency, real-time access frequency and all intelligence security events within the preset historical time of each node to be analyzed in the monitoring area divided based on the preset network topology in the industrial control network; Determine a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree; Determine an abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node; Determine a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes determined within a preset determination time period; Calculate an actual threat index based on the abnormal risk index of each threat node and the intelligence security event; Use a preset big data model to predict all of the threat nodes to form a number of predicted threat indexes; According to the actual threat index and the predicted threat index, a preset data sampling rate in the preset network topology is adjusted to form an adjusted sampling rate, or the preset standard synchronization degree is adjusted to form an adjusted standard synchronization degree; Using the preset big data model to predict the threat node re-determined based on the adjusted sampling rate or the adjusted standard synchronization, to form a target threat index; Output an industrial control network threat intelligence analysis report based on the target threat index.
[0030] The preset network topology is a network structure planned in advance according to the business logic, equipment distribution and communication path of the industrial control network. It adopts a hierarchical and partitioned architecture design, including the control layer, data layer and equipment layer, and divides different monitoring areas according to network security areas (Zones) and parallel communication channels (Conduits). This topology combines industrial security standards such as IEC 62443 and NIST SP800-82 for security zoning, clearly defines the interaction relationship between key devices (such as PLC, RTU, HMI), and configures access control, traffic monitoring and anomaly detection mechanisms at key nodes.
[0031] Using a distributed data collection architecture, traffic probes, log collection modules, and behavior monitoring agents are deployed in each monitoring area of the industrial control network to capture real-time network traffic, instruction execution frequency, and access frequency. Traffic probes parse data packets through deep packet inspection (DPI) and NetFlow / IPFIX technology to extract key features; log collection modules collect device operation logs through Syslog, SNMP, and OPC UA protocols; behavior monitoring agents are deployed on terminals or border gateways to obtain instruction execution status using memory forensics and system call monitoring. At the same time, the system calls the historical security intelligence database, and extracts relevant security events within the preset historical time through log analysis platforms such as ELK (Elasticsearch, Logstash, Kibana) or Splunk, combined with the time series database (TSDB), to achieve comprehensive and accurate data collection. Among them, the historical security intelligence database stores all security events within the preset historical time in the industrial control network, including identified network attack behaviors, abnormal traffic characteristics, abnormal instruction records, abnormal access frequency, virus intrusion logs, misoperation data, and processed security event reports. The database adopts a distributed storage architecture (such as HDFS or MongoDB), supports multi-dimensional data query and time series analysis, and can provide efficient and reliable data support for big data model training and threat index prediction.
[0032] In this embodiment, the real-time traffic, real-time instruction execution frequency, real-time access frequency and historical intelligence security events are normalized, weighted and trend analyzed, and the logical relationship between them is clearly established. The abnormal fluctuation of real-time traffic can indicate the risk of network attack, the sharp increase of instruction execution frequency indicates illegal operation, and the abnormal change of access frequency reflects possible intrusion behavior; at the same time, historical intelligence security events provide background reference for these real-time indicators, making risk assessment more specific and representative. Combining these parameters, potential threat nodes can be accurately located, detection accuracy and response speed can be improved, and the security protection of industrial control networks can be effectively supported.
[0033] The preset historical duration refers to the length of the time window for collecting intelligence security events and node behavior data, which depends on the response speed of the industrial control network, the amount of data accumulation, and the security analysis cycle. It is usually set between 7 and 30 days. In this embodiment, it is set to 14 days to ensure that enough historical behavior data is captured to provide more representative data for the big data model.
[0034] The preset standard synchronization degree refers to the synchronization threshold of the fluctuation of data flow and execution frequency between different nodes to be analyzed, which depends on the communication protocol, clock synchronization accuracy and data packet transmission delay of the industrial control network. It is usually set between 95% and 99.9%. In this embodiment, it is set to 98%, which can improve the accuracy of risk node determination and reduce the risk of misjudgment due to clock drift.
[0035] The preset data sampling rate refers to the frequency of data extraction when collecting data from each node to be analyzed, which depends on the network bandwidth, data traffic load and storage capacity, and is usually set between 1Hz and 10Hz. In this embodiment, it is set to 5Hz, which can take into account both data integrity and processing efficiency.
[0036] The preset big data model used in this embodiment is a multi-layer time series analysis model based on deep learning, combined with anomaly detection mechanism for threat intelligence analysis. The following is a detailed introduction from initial parameters, model training process to the final output model: 1. Initial model parameters (1) Model structure: Input layer: including real-time traffic, instruction execution frequency, access frequency, historical intelligence events and other multi-dimensional data; Hidden layer: A bidirectional LSTM / GRU network is used, with the number of layers set to 2-3, and each layer contains 128 to 256 neurons; Attention mechanism: The attention mechanism is introduced to give higher weight to abnormal behaviors at key time steps, improving the model's perception ability; Output layer: Generates a predicted threat index, and the output is a risk index between 0 and 1.
[0037] (2) Initialization parameters: Learning rate: 0.001 (using adaptive optimizer Adam); Batch size: 64 Weight initialization: Use Xavier initialization to prevent gradient disappearance or explosion; Loss function: Use mean squared error (MSE) or cross entropy loss function for risk prediction.
[0038] 2. Model training process (1) Data preprocessing: Data normalization: normalize input features such as real-time traffic, instruction frequency, and access frequency to 0-1; Data enhancement: A sliding time window is introduced into historical intelligence events for feature extraction, and noisy data is combined for model robustness training.
[0039] (2) Model training phase: Training set / validation set division: divide the training data and validation data into 8:2 to prevent overfitting; Training rounds: set to 50-100 rounds, and terminate early when the validation loss does not decrease significantly through the early stopping mechanism; Loss optimization: Use the Adam optimizer for gradient updates and adjust the learning rate to avoid falling into the local optimum.
[0040] (3) Anomaly detection mechanism: Perform abnormal behavior detection based on autoencoders, and cluster and label abnormal data that appear during training; A threshold judgment mechanism is used to classify the model output results into risk indexes (0.7 and above are high risk).
[0041] 3. Final output model parameters (1) Model weight: After multiple rounds of training, the top five best model weights are retained, and the model with the best performance is selected for deployment using the cross-validation method.
[0042] (2) Hyperparameter adjustment: The learning rate is adjusted to 0.0005 to improve the model stability; The number of LSTM / GRU units is optimized to 128 to achieve a balance between computing efficiency and performance; Dropout is set to 0.2-0.3 to prevent overfitting.
[0043] (3) Model performance indicators: Accuracy: more than 95%; F1 value: between 0.93-0.96; AUC: reaches 0.97, ensuring the reliability of threat index prediction.
[0044] Outputting the industrial control network threat intelligence analysis report according to the target threat index includes: when the target threat index is greater than the preset security index, displaying the node number, threat level and related data of the corresponding threat node in the form of a chart to output the industrial control network threat intelligence analysis report.
[0045] The preset security index is a threshold used to determine whether the target threat index exceeds the safety range, which depends on the network security strategy, historical threat data and risk tolerance, and is usually set between 0.7 and 0.9. In this embodiment, it is set to 0.85, which can provide early warning when the risk is close to the critical state, effectively reducing security threats.
[0046] First, a monitoring area is preset in the industrial control network to collect the real-time traffic, instruction execution frequency, access frequency, and historical intelligence security events of each node to be analyzed. Subsequently, temporary high-risk nodes are determined by real-time traffic and synchronization, their abnormal risk index is calculated, and threat nodes are identified based on the index and traffic characteristics. Next, the actual threat index of the threat node is calculated, and the predicted threat index of all nodes to be analyzed is predicted using a big data model. By comparing the actual and predicted results, the data sampling rate or standard synchronization of the network topology is adjusted, and then the big model is used again for prediction, and the target threat index is finally determined. Based on this, an industrial control network threat intelligence analysis report is generated to provide support for security decision-making.
[0047] Through intelligent analysis driven by large models, combined with real-time monitoring, historical intelligence data and dynamic adjustment strategies, accurate identification and prediction of industrial control network threats are achieved, potential threats can be discovered earlier, and the false alarm rate and missed alarm rate are effectively reduced through the calculation of abnormal risk index and actual threat index. By adaptively adjusting the data sampling rate and standard synchronization, data processing efficiency is optimized, redundant collection and calculation burden are avoided, response speed and resource utilization are improved, and combined with multi-level risk assessment and prediction models, the adaptability to new threats is enhanced, and targeted intelligence analysis reports can be generated for different threat levels, providing strong support for network security defense and plan formulation, thereby comprehensively improving the security, stability and intelligent defense capabilities of industrial control networks, and effectively solving the problem of low threat intelligence response speed due to the single feature mutual information calculation.
[0048] Specifically, determining a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree includes: Calculate the standard deviation of the real-time traffic within a preset first determined time period to form a real-time traffic fluctuation value; Calculating the standard deviation of the instruction execution frequency within the preset first time period to form a real-time frequency fluctuation value; A number of temporary high-risk nodes are determined according to the real-time traffic fluctuation value, the real-time frequency fluctuation value and the preset standard synchronization degree.
[0049] The preset first determined time length is the time window for calculating the real-time traffic fluctuation value and the real-time frequency fluctuation value, which depends on the traffic characteristics of the industrial control network, the changing law of the instruction execution frequency and the system response time. It is usually set between 5 minutes and 10 minutes. In this embodiment, it is set to 6 minutes. It can improve the identification accuracy of high-risk nodes while balancing the capture of data fluctuation characteristics and computing overhead.
[0050] First, the real-time traffic standard deviation of each node to be analyzed is calculated within the preset first determined time length to form a real-time traffic fluctuation value, and the standard deviation of the instruction execution frequency within the same time length is calculated to form a real-time frequency fluctuation value. Subsequently, these two fluctuation values are compared with the preset standard synchronization degree, and nodes with large synchronization deviation and abnormal fluctuation characteristics are screened out and determined as temporary high-risk nodes.
[0051] By calculating the traffic and instruction frequency fluctuation values in real time and combining them with synchronization determination, it is possible to quickly and accurately identify potential high-risk nodes, avoid missing low-frequency but abnormal threat behaviors, and provide an efficient and reliable foundation for subsequent threat node screening and threat index calculation.
[0052] Please continue reading Figure 2 As shown, it is a determination logic diagram for determining temporary high-risk nodes in this embodiment; Determining a number of temporary high-risk nodes according to the real-time traffic fluctuation value, the real-time frequency fluctuation value, and the preset standard synchronization degree includes: Normalizing the real-time flow fluctuation value to form a normalized flow fluctuation value; Normalizing the real-time frequency fluctuation value to form a normalized frequency fluctuation value; Calculating the correlation coefficient between the normalized flow fluctuation value and the normalized frequency fluctuation value to form a change synchronization degree; When the change synchronization degree is less than the preset standard synchronization degree, the node to be analyzed is determined to be a temporary high-risk node, so as to determine a number of the temporary high-risk nodes.
[0053] First, the real-time traffic fluctuation value and the real-time frequency fluctuation value are normalized to obtain the normalized traffic fluctuation value and the normalized frequency fluctuation value to eliminate the influence of different dimensions on the calculation. Then, the correlation coefficient between the normalized traffic fluctuation value and the normalized frequency fluctuation value is calculated to form the change synchronization degree, which is used to measure whether the change trends of the two are consistent. When the change synchronization degree is less than the preset standard synchronization degree, it indicates that the traffic fluctuation of the node is abnormally out of sync with the change of the instruction execution frequency, which may pose a security risk, so it is judged as a temporary high-risk node.
[0054] Normalization processing can eliminate the influence of different data dimensions and improve calculation accuracy; correlation coefficient calculation can accurately evaluate the synchronization of traffic and instruction execution frequency and reduce the misjudgment rate; synchronization threshold determination enables the system to dynamically identify abnormal behavior, effectively improve the perception of potential security threats, and ensure the security and stability of the industrial control network.
[0055] Specifically, determining the abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node includes: Normalizing the real-time traffic to form a normalized traffic, normalizing the real-time instruction execution frequency to form a normalized execution frequency, and normalizing the real-time access frequency to form a normalized access frequency; The normalized traffic, the preset traffic weight, the normalized execution frequency, the preset execution frequency weight, the normalized access frequency and the preset access frequency weight are weighted and summed to obtain the abnormal risk index.
[0056] By normalizing the real-time traffic, real-time instruction execution frequency, and real-time access frequency, normalized traffic, normalized execution frequency, and normalized access frequency are formed respectively, ensuring that data of different dimensions can be calculated uniformly. Subsequently, the preset traffic weight, preset execution frequency weight, and preset access frequency weight are introduced, and the normalized data is weighted and summed to calculate the abnormal risk index of each temporary high-risk node, which is used to measure its abnormality and provide a quantitative basis for subsequent threat analysis.
[0057] Through normalization and weighted calculation, the importance of each indicator to risk assessment is fully considered, so that the abnormal risk index can accurately reflect the abnormal degree of the node. By setting weight distribution, the calculation method can be adjusted according to different industrial control network environments, enhancing adaptability and avoiding the influence of different data ranges on the calculation results.
[0058] Specifically, determining a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes determined within a preset determination time includes: Calculate the standard deviation of the abnormal risk index of a single temporary high-risk node to form an index fluctuation value; Calculate the standard deviation of the real-time traffic of a single temporary high-risk node to form a risk traffic fluctuation value; Draw a change curve of the index fluctuation value within the preset determination time to form an index fluctuation curve; Draw a change curve of the risk flow fluctuation value within the preset determination time to form a risk flow fluctuation curve; Calculating the cosine similarity of the index fluctuation curve and the risk flow fluctuation curve to form a change consistency; A number of threat nodes are determined according to the change consistency of any two adjacent temporary high-risk nodes.
[0059] First, the standard deviation of the abnormal risk index and real-time traffic of a single temporary high-risk node is calculated respectively to obtain the index fluctuation value and the risk traffic fluctuation value, which are used to measure the degree of risk change. Then, within the preset judgment time, the change curves of the two, namely the index fluctuation curve and the risk traffic fluctuation curve, are drawn to observe the trend changes in the time dimension. Next, the cosine similarity of the two curves is calculated to obtain the change consistency, which is used to quantify the correlation between the two variables. Finally, based on the change consistency of any two adjacent temporary high-risk nodes, the nodes with higher threat levels are screened out, and several threat nodes are determined to provide a basis for subsequent analysis.
[0060] Through standard deviation calculation, curve drawing and cosine similarity analysis, the correlation between abnormal risk index and traffic fluctuation is accurately portrayed, which can more comprehensively identify the risk evolution trend. Compared with single threshold judgment, this method can dynamically adapt to the fluctuation of industrial control network environment, avoid false positives and false negatives, and improve the accuracy of threat detection. At the same time, based on the joint analysis of adjacent high-risk nodes, more threatening target nodes can be discovered, enhancing the overall defense capability.
[0061] Please continue reading Figure 3 As shown, it is a determination logic diagram for determining threat nodes in this embodiment; Determining a number of threat nodes according to the change consistency of any two adjacent temporarily high-risk nodes includes: Calculating the relative deviation of the consistency of the two changes to form a consistency deviation; When the consistency deviation is greater than a preset consistency deviation threshold, it is determined that the corresponding two temporary high-risk nodes are both threat nodes, so as to determine a number of threat nodes.
[0062] The preset consistency deviation threshold refers to the critical value used to determine whether two temporary high-risk nodes are considered threat nodes, which depends on the tolerance of data fluctuations, the characteristics of the network environment, and the level of security requirements. It is usually set between 0.1 and 0.3. In this embodiment, it is set to 0.2, which can effectively filter out small fluctuations while retaining threat signals with large differences, thereby improving the detection accuracy of threat nodes.
[0063] First, the change consistency of any two adjacent temporary high-risk nodes is calculated, and then the relative deviation between the two change consistency is further calculated, that is, the consistency deviation. When the consistency deviation exceeds the preset consistency deviation threshold, the two nodes are determined to be threat nodes and are included in the threat node set, thereby further determining several threat nodes.
[0064] By calculating the consistency deviation and comparing it with the preset threshold, errors with small fluctuations can be effectively eliminated, and only nodes with large fluctuation differences can be identified as threat nodes, thereby improving the accuracy of threat node identification, helping to reduce misjudgments caused by data noise or slight system fluctuations, and ensuring that real and threatening nodes are identified in a timely manner.
[0065] Specifically, calculating the actual threat index according to the abnormal risk index of each threat node and the intelligence security event includes: Obtain the number of occurrences, timestamps, and event types of the intelligence security events; When the number of occurrences is greater than a preset number of occurrences threshold, a weighted time interval is calculated according to a preset weight combination corresponding to the event type and any two adjacent timestamps to form a plurality of weighted time intervals; logarithmically varying each of the weighted time intervals to form a plurality of logarithmically weighted intervals; Calculating the reciprocal of the sum of the standard deviation of all the logarithmic weighted intervals in the preset sliding window and a preset constant to form a distribution concentration; The actual threat index is calculated according to the distribution concentration and the abnormal risk index.
[0066] The preset occurrence threshold refers to the minimum number of occurrences of the same type of event within a certain time period, which depends on the normal activity frequency of the network system and is usually set between 3 and 10 times. In this embodiment, it is set to 5 times, which can reduce misjudgment and ensure that only more frequent events are analyzed, thereby improving processing efficiency and accuracy.
[0067] The preset sliding window refers to the length of the time period used to analyze the time interval when calculating the threat index. It is usually set according to the nature of the event and the analysis requirements. It is usually set to 30 minutes to 1 hour. In this embodiment, it is set to 1 hour, which can balance the real-time and accuracy of the data and avoid the impact of excessive time fluctuations on the calculation.
[0068] The preset constant refers to a fixed value used when calculating the distribution concentration, which is used to balance the calculation results of the standard deviation, and is based on experience or the statistical characteristics of actual data. It is usually set to 1-5, and is set to 2 in this embodiment. Appropriate constants help stabilize the calculation process and avoid unreasonable effects of excessive or small fluctuations on the final results.
[0069] Event types are classified according to different security threats or network risks, and are specifically set to three types in this embodiment: Intrusion incident: Unauthorized access or attack, usually a high-risk security threat.
[0070] Data breach incident: The leakage or theft of sensitive data affects company privacy and data security.
[0071] Equipment failure incident: Equipment or system failure leads to service interruption or security vulnerability. Although it affects system stability, the direct security threat is relatively low.
[0072] The preset weight combination is set according to the severity of the event type and the priority of network security. The specific settings are as follows: Intrusion event weight: a relatively high weight, usually set between 0.6 and 1. In this embodiment, it is set to 0.6 because intrusion events pose the greatest threat to network security.
[0073] Data leakage event weight: medium weight, usually set between 0.3 and 0.5. In this embodiment, it is set to 0.3 because data leakage may affect data privacy but usually does not directly damage the function of the system.
[0074] Equipment failure event weight: a lower weight, usually set between 0.1 and 0.2, and is set to 0.1 in this embodiment because equipment failure is usually a problem of system stability but does not immediately pose a serious security threat.
[0075] First, the number of occurrences, timestamps, and event types of intelligence security events are obtained. Then, when the number of occurrences of an event is greater than the preset threshold, the weighted time interval is calculated based on the preset weight and timestamp of the event type. Then, the weighted time interval is logarithmically changed to obtain a logarithmic weighted interval, and the inverse of the sum of its standard deviation and a preset constant is calculated to form the distribution concentration. Finally, the actual threat index is calculated based on the distribution concentration and the abnormal risk index to complete the threat level assessment of the threat node.
[0076] By combining information such as the frequency, type, and time interval of events, the actual threat index of each threat node can be accurately assessed. The use of logarithmic changes and smoothing can help reduce the interference caused by data fluctuations and improve the accuracy and stability of threat assessment.
[0077] Specifically, calculating the actual threat index according to the distribution concentration and the abnormal risk index includes: When the distribution concentration is greater than the preset standard concentration, the abnormal risk index is increased according to the relative deviation between the distribution set and the preset standard concentration and the preset index calculation coefficient to form the actual threat index, and the relative deviation between the distribution set and the preset standard concentration is positively correlated with the actual threat index.
[0078] The preset standard concentration is used to measure whether the time distribution of security incidents is too dense. It depends on the statistical characteristics of historical security intelligence data, including the frequency and distribution pattern of incidents. It is usually set between 0.3 and 0.7. In this embodiment, it is set to 0.5, which can effectively distinguish normal low-frequency security incidents from high-risk intensive incidents, avoid overreaction to occasional incidents, and ensure warnings for highly concentrated risk behaviors.
[0079] The preset index calculation coefficient is used to adjust the amplification of the abnormal risk index, which depends on the risk assessment sensitivity of the system and the needs of the actual application scenario. It is usually set between 1.2 and 2.5, and is set to 1.8 in this embodiment to ensure that the adjustment of the threat level in the case of high distribution concentration is neither overly exaggerated nor too conservative, thereby improving the accuracy and practicality of threat identification.
[0080] First, the distribution concentration is calculated and compared with the preset standard concentration. When the distribution concentration is greater than the preset standard concentration, its relative deviation is calculated, and combined with the preset index calculation coefficient, the abnormal risk index is adjusted to increase it, thereby forming an actual threat index.
[0081] By increasing the abnormal risk index when the distribution concentration is higher than the preset standard concentration, security threats with high frequency and dense time distribution can be more accurately identified. High distribution concentration usually means that certain threat behaviors have strong correlation or persistence, and relying solely on the abnormal risk index may ignore these long-term accumulated risks. Therefore, introducing a calculation coefficient to dynamically amplify the abnormal risk index helps to improve the sensitivity of detection, enhance the ability to respond to potential threats, and reduce the possibility of misjudgment or omission.
[0082] Please continue reading Figure 4 As shown, it is a determination logic diagram for determining misjudged nodes in this embodiment; Adjusting the preset data sampling rate in the preset network topology according to the actual threat index and the predicted threat index to form an adjusted sampling rate, or adjusting the preset standard synchronization to form an adjusted standard synchronization includes: Calculating an absolute value of a relative deviation between the actual threat index and the predicted threat index to form a plurality of index deviations; When the index deviation is greater than a preset index deviation threshold, the threat node is determined to be a misjudged node, forming a plurality of misjudged nodes; The preset data sampling rate is adjusted according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or the preset standard synchronization degree is adjusted to form the adjusted standard synchronization degree.
[0083] The preset index deviation threshold is a threshold used to determine whether the deviation between the actual threat index and the predicted threat index is too large. It depends on the misjudgment rate of historical data, the error range of the threat detection model, and the accuracy requirements of business needs. It is usually set between 5% and 20%. In this embodiment, it is set to 10%. While ensuring the stability of the detection system, it can adapt to different types of threat fluctuations and reduce resource waste caused by misjudgment.
[0084] By analyzing the relative deviation between the actual threat index and the predicted threat index, the misjudged nodes can be identified and the data sampling rate or standard synchronization degree can be dynamically adjusted. First, the absolute value of the relative deviation between the two is calculated to obtain the index deviation. When the index deviation exceeds the preset index deviation threshold, the threat node is considered to be misjudged, and the number of misjudged nodes is recorded. Then, the number of misjudged nodes is counted within the preset adjustment time, and the data sampling rate or standard synchronization degree is adjusted accordingly, so that the system can adapt to the network status more accurately and improve the accuracy and stability of detection.
[0085] Dynamic adjustment through misjudgment analysis can reduce false positives and missed negatives and improve the adaptability of the detection system. When there are many misjudgment nodes, increasing the data sampling rate helps enhance the system's perception capabilities and capture more fine-grained threat features; adjusting the standard synchronization can optimize the accuracy of data analysis and reduce misjudgments caused by data synchronization errors, thereby improving the reliability and intelligence of the overall detection system.
[0086] Specifically, adjusting the preset data sampling rate according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or adjusting the preset standard synchronization to form the adjusted standard synchronization includes: When the number of the misjudged nodes is within a preset misjudged number range, calculating the standard deviation of the number of the misjudged nodes to form a misjudged number fluctuation value; When the misjudgment number fluctuation value is greater than the preset misjudgment fluctuation threshold, the preset data sampling rate is increased according to the relative deviation between the misjudgment number fluctuation value and the preset misjudgment fluctuation threshold point and the preset first adjustment coefficient to form the adjusted sampling rate, and the relative deviation between the misjudgment number fluctuation value and the preset misjudgment fluctuation threshold point is positively correlated with the adjusted sampling rate; When the number of misjudged nodes is greater than the maximum value of the preset misjudgment number range, the preset standard synchronization degree is increased according to the relative deviation between the number of misjudged nodes and the maximum value and the preset second adjustment coefficient to form the adjusted standard synchronization degree, and the relative deviation between the number of misjudged nodes and the maximum value is positively correlated with the adjusted standard synchronization degree.
[0087] The preset misjudgment number range is the allowable range of the number of misjudged nodes, which depends on the accuracy requirements and misjudgment tolerance of the system. It is usually set between 10 and 100. In this embodiment, it is set to [30, 70], which can ensure that the system can make reasonable adjustments when the number of misjudged nodes is too large, and will not cause excessive interference to normal operations.
[0088] The preset false positive fluctuation threshold is the threshold of the false positive number fluctuation value, which depends on the system's false positive tolerance and the accuracy requirements of data sampling. It is usually set between 5% and 20%. In this embodiment, it is set to 10%, which can balance the system response speed and false positive control. When the false positive fluctuation is large, the sampling and synchronization can be adjusted in time to avoid the accumulation of false positives.
[0089] The preset first adjustment coefficient is a weight coefficient used to adjust the data sampling rate. It depends on the network environment and the frequency of change of real-time data. It is usually set between 1 and 5. In this embodiment, it is set to 3. While maintaining system stability, it can speed up the response to misjudgment fluctuations and ensure rapid adjustment of the data sampling rate.
[0090] The preset second adjustment coefficient is a weight coefficient used to adjust the standard synchronization degree. It depends on the system's requirements for synchronization accuracy and the overall load of the network. It is usually set between 0.5 and 3. In this embodiment, it is set to 2. It can effectively improve the synchronization degree in time when a large misjudgment occurs in the system, thereby ensuring the consistency and accuracy of data processing.
[0091] First, the number of misjudged nodes within the preset adjustment time is counted, and its standard deviation is calculated to form the misjudgment number fluctuation value. When the misjudgment number fluctuation value exceeds the preset misjudgment fluctuation threshold, the preset data sampling rate is increased according to its relative deviation and the preset first adjustment coefficient to improve the data acquisition accuracy. When the number of misjudged nodes exceeds the maximum value of the preset misjudgment number range, the preset standard synchronization is increased according to the relative deviation between the number of misjudged nodes and the maximum value and the preset second adjustment coefficient to enhance the overall consistency and stability of the system.
[0092] By dynamically adjusting the data sampling rate and standard synchronization, this method can reduce the false positive rate while ensuring detection accuracy. When the false positive rate fluctuates greatly, increasing the data sampling rate can more accurately capture the risk changes, and when the number of false positive nodes is too large, increasing the standard synchronization can optimize global coordination and reduce false positives caused by instability, thereby improving the accuracy of threat detection and network security protection capabilities.
[0093] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
Claims
1. A method for analyzing industrial control network threat intelligence based on a large model, characterized in that: include: Collect the real-time traffic, real-time instruction execution frequency, real-time access frequency and all intelligence security events within the preset historical time of each node to be analyzed in the monitoring area divided based on the preset network topology in the industrial control network; Determine a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree; Determine an abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node; Determine a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes determined within a preset determination time period; Calculate an actual threat index based on the abnormal risk index of each threat node and the intelligence security event; Use a preset big data model to predict all of the threat nodes to form a number of predicted threat indexes; According to the actual threat index and the predicted threat index, a preset data sampling rate in the preset network topology is adjusted to form an adjusted sampling rate, or the preset standard synchronization degree is adjusted to form an adjusted standard synchronization degree; Using the preset big data model to predict the threat node re-determined based on the adjusted sampling rate or the adjusted standard synchronization, to form a target threat index; Output an industrial control network threat intelligence analysis report based on the target threat index.
2. The industrial control network threat intelligence analysis method based on large model drive according to claim 1 is characterized in that: Determining a number of temporary high-risk nodes according to the real-time traffic, the real-time instruction execution frequency and the preset standard synchronization degree includes: Calculate the standard deviation of the real-time traffic within a preset first determined time period to form a real-time traffic fluctuation value; Calculating the standard deviation of the instruction execution frequency within the preset first time period to form a real-time frequency fluctuation value; A number of temporary high-risk nodes are determined according to the real-time traffic fluctuation value, the real-time frequency fluctuation value and the preset standard synchronization degree.
3. The industrial control network threat intelligence analysis method based on large model drive according to claim 2 is characterized in that: Determining a number of temporary high-risk nodes according to the real-time traffic fluctuation value, the real-time frequency fluctuation value, and the preset standard synchronization degree includes: Normalizing the real-time flow fluctuation value to form a normalized flow fluctuation value; Normalizing the real-time frequency fluctuation value to form a normalized frequency fluctuation value; Calculating the correlation coefficient between the normalized flow fluctuation value and the normalized frequency fluctuation value to form a change synchronization degree; When the change synchronization degree is less than the preset standard synchronization degree, the node to be analyzed is determined to be a temporary high-risk node, so as to determine a number of the temporary high-risk nodes.
4. The industrial control network threat intelligence analysis method based on large model drive according to claim 3 is characterized in that: Determining the abnormal risk index according to the real-time traffic, the real-time instruction execution frequency, and the real-time access frequency of the temporary high-risk node includes: Normalizing the real-time traffic to form a normalized traffic, normalizing the real-time instruction execution frequency to form a normalized execution frequency, and normalizing the real-time access frequency to form a normalized access frequency; The normalized traffic, the preset traffic weight, the normalized execution frequency, the preset execution frequency weight, the normalized access frequency and the preset access frequency weight are weighted and summed to obtain the abnormal risk index.
5. The industrial control network threat intelligence analysis method based on large model drive according to claim 4 is characterized in that: Determining a number of threat nodes according to the abnormal risk index and the real-time traffic of any two adjacent temporary high-risk nodes within a preset determination time includes: Calculate the standard deviation of the abnormal risk index of a single temporary high-risk node to form an index fluctuation value; Calculate the standard deviation of the real-time traffic of a single temporary high-risk node to form a risk traffic fluctuation value; Draw a change curve of the index fluctuation value within the preset determination time to form an index fluctuation curve; Draw a change curve of the risk flow fluctuation value within the preset determination time to form a risk flow fluctuation curve; Calculating the cosine similarity of the index fluctuation curve and the risk flow fluctuation curve to form a change consistency; A number of threat nodes are determined according to the change consistency of any two adjacent temporary high-risk nodes.
6. The industrial control network threat intelligence analysis method based on large model drive according to claim 5 is characterized in that: Determining a number of threat nodes according to the change consistency of any two adjacent temporarily high-risk nodes includes: Calculating the relative deviation of the consistency of the two changes to form a consistency deviation; When the consistency deviation is greater than a preset consistency deviation threshold, it is determined that the corresponding two temporary high-risk nodes are both threat nodes, so as to determine a number of threat nodes.
7. The industrial control network threat intelligence analysis method based on large model drive according to claim 6 is characterized in that: Calculating the actual threat index according to the abnormal risk index of each threat node and the intelligence security event includes: Obtain the number of occurrences, timestamps, and event types of the intelligence security events; When the number of occurrences is greater than a preset number of occurrences threshold, a weighted time interval is calculated according to a preset weight combination corresponding to the event type and any two adjacent timestamps to form a plurality of weighted time intervals; logarithmically varying each of the weighted time intervals to form a plurality of logarithmically weighted intervals; Calculating the reciprocal of the sum of the standard deviation of all the logarithmic weighted intervals in the preset sliding window and a preset constant to form a distribution concentration; The actual threat index is calculated according to the distribution concentration and the abnormal risk index.
8. The industrial control network threat intelligence analysis method based on large model drive according to claim 7 is characterized in that: Calculating the actual threat index according to the distribution concentration and the abnormal risk index includes: When the distribution concentration is greater than the preset standard concentration, the abnormal risk index is increased according to the relative deviation between the distribution set and the preset standard concentration and a preset index calculation coefficient to form the actual threat index.
9. The industrial control network threat intelligence analysis method based on large model drive according to claim 8 is characterized in that: Adjusting the preset data sampling rate in the preset network topology according to the actual threat index and the predicted threat index to form an adjusted sampling rate, or adjusting the preset standard synchronization to form an adjusted standard synchronization includes: Calculating an absolute value of a relative deviation between the actual threat index and the predicted threat index to form a plurality of index deviations; When the index deviation is greater than a preset index deviation threshold, the threat node is determined to be a misjudged node, forming a plurality of misjudged nodes; The preset data sampling rate is adjusted according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or the preset standard synchronization degree is adjusted to form the adjusted standard synchronization degree.
10. The industrial control network threat intelligence analysis method based on large model drive according to claim 9 is characterized in that: Adjusting the preset data sampling rate according to the number of the misjudged nodes within the preset adjustment time to form the adjusted sampling rate, or adjusting the preset standard synchronization to form the adjusted standard synchronization includes: When the number of the misjudged nodes is within a preset misjudged number range, calculating the standard deviation of the number of the misjudged nodes to form a misjudged number fluctuation value; When the misjudgment number fluctuation value is greater than the preset misjudgment fluctuation threshold, the preset data sampling rate is increased according to the relative deviation between the misjudgment number fluctuation value and the preset misjudgment fluctuation threshold point and the preset first adjustment coefficient to form the adjusted sampling rate; When the number of the misjudged nodes is greater than the maximum value of the preset misjudgment number range, the preset standard synchronization degree is increased according to the relative deviation between the number of the misjudged nodes and the maximum value and the preset second adjustment coefficient to form the adjusted standard synchronization degree.
Citation Information
Patent Citations
Threat detection method and device for industrial control network
CN115941237A
Threat management method and system in industrial control system network
CN109688142A
Intrusion detection method and system for industrial control network
CN115378711A
Intelligent detection and early warning system and method for network security
CN116707976A
Network node threat index detection method and device
CN117614637A
Cited By
Medical risk early warning method based on big data
CN120317690A