Industrial control system attack path identification method based on alarm sequence probability

Through the method based on alarm sequence probability, combined with accessibility analysis and dynamic attack path recognition, the problems of weak attack path recognition capabilities and high computational complexity of the industrial control system are solved, efficient and accurate attack path recognition is achieved, and time factors are taken into account.

CN119996044AActive Publication Date: 2025-05-13DALIAN UNIV OF TECH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510274416.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-05-13
Estimated Expiration
2045-03-10

AI Technical Summary

Technical Problem

The existing industrial control system attack path recognition methods have problems such as weak identification capabilities, high computational complexity, and failure to effectively consider time factors.

Method used

Using an approach based on the probability of the alarm sequence, efficient and accurate attack path recognition is achieved through reachability analysis, modeling of basic attack elements, calculating the node transfer probability and node reachability probability, generating a probability attack map based on the alarm information and dynamic attack path recognition.

Benefits of technology

It improves the reliability and accuracy of attack path identification, makes up for the lack of time-based factors that the existing methods do not consider, and is more realistic attack graph model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996044A_ABST
    Figure CN119996044A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of industrial internet information security, and discloses an industrial control system attack path identification method based on alarm sequence probability. On the basis of an attack graph technology, the vulnerability life cycle and alarm correlation analysis are integrated, so that efficient and accurate attack path identification can be realized. According to the method, reachable information and vulnerability information existing in a topological relation among hosts of an industrial control system are collected, and quantization based on a vulnerability level is carried out on node state transfer in topology. Alarm information obtained by an intrusion detection system is introduced, the alarm information is mapped and matched to a corresponding node, so that real attacks are better fitted, dynamic attack intention posteriori estimation inference and attack path reverse search are finally carried out on an obtained probability attack graph, and dynamic risk assessment of potential attack paths of the industrial control system is realized. According to the heuristic path identification method, the attack graph is reconstructed, so that the identification reliability and accuracy are improved, and a protector can concentrate limited resources to perform key node protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial Internet information security, and in particular to an industrial control system attack path identification method based on alarm sequence probability. Background Art

[0002] In recent years, with the development of industrial Ethernet and wireless interconnection technology, industrial control systems (ICS) have gradually moved from the original closed and isolated state to open and interconnected, thereby greatly improving the flexibility and scalability of the system and promoting production automation and intelligence. However, due to the low protection, high real-time performance, and conflict between security benefits and economic benefits of ICS systems, they are more vulnerable to attacks than traditional IT systems. Security incidents in related fields occur from time to time, such as the XZ Utils supply chain attack on industrial software; the BlackBasta ransomware attack on the Swiss automation giant ABB; and the man-in-the-middle attack on Siemens S7 PLC. The protection of industrial control systems is imminent. Traditional methods mainly rely on intrusion detection technology to isolate and analyze the vulnerabilities of a single node in the industrial control system. However, in reality, the nodes of the industrial control network are coupled and interact with each other. Attackers can use the association between the networks to invade, penetrate, and move, and finally launch attacks on key assets and destroy industrial processes.

[0003] Attack graph is a vulnerability assessment method based on graph theory. It is a directed network graph formed by integrating network configuration, vulnerability information and the relationship between hosts. The vertices usually represent elements such as hosts, services, vulnerabilities, permissions, etc., and the directed edges represent the changes between the corresponding elements. Attack graph can intuitively display all possible attack paths and is suitable for multi-stage and multi-step network attacks. When the attack invades, the attacker uses the vulnerability to obtain the permissions of a certain node based on his initial permissions, and then invades other nodes in turn, and finally invades the target node in the network. Attack graph can effectively identify potential attack paths from the attacker's perspective, and concentrate limited resources for targeted protection. The existing methods of identifying attack paths using attack graphs mainly include: exhaustive method, which uses graph traversal algorithms such as depth-first or breadth-first to list all possible paths. For large networks, its computational complexity is extremely high; simplification method, by limiting the maximum number of steps or establishing a local attack graph based on important assets, the number of redundant and meaningless attack paths can be effectively reduced, but it also causes changes in the topological structure, thereby losing key information. The present invention adopts attack path identification based on alarm sequence, which is essentially a heuristic graph search method, which uses alarm information for a posteriori estimation and infers attack intent, thereby identifying effective attack paths. Summary of the invention

[0004] In view of the problems of weak recognition ability in existing attack path recognition methods, the present invention provides an industrial control system attack path recognition method based on alarm sequence probability. This method integrates vulnerability life cycle and alarm correlation analysis based on attack graph technology to achieve efficient and accurate attack path recognition.

[0005] The technical solution of the present invention is as follows: a method for identifying an attack path of an industrial control system based on alarm sequence probability, the steps are as follows:

[0006] Step 1: Reachability analysis;

[0007] Conduct reachability analysis on the logical and physical correlations between the host nodes in the industrial control system network, and collect information on industrial control system accessibility, system vulnerability information, and intrusion detection system data;

[0008] Step 2: Modeling the basic elements of the attack;

[0009] Define an attribute attack graph, which is obtained by correlating the industrial control system access information and system vulnerability information collected in step 1 reachability analysis to show the attacker's goals and potential complete attack paths;

[0010] Step 3: Calculate the node transfer probability and node reachability probability;

[0011] Step 4: Generate a probabilistic attack graph based on the warning information;

[0012] According to the definition of the attack elements of the attribute attack graph in step 2 and the node transfer probability in step 3, a probability attack graph is generated based on the attribute attack graph based on the idea of ​​graph traversal;

[0013] Step 5: Dynamic attack path identification;

[0014] Using the probabilistic attack graph generation method introduced in step 4, at the initial time t (0) When there is no alarm, a probabilistic attack graph is generated, and the reachability probability of each prior node and the reachability probability of the posterior node are calculated; the reachability probability of the posterior node of each target attribute node is compared, and the target attribute node with the largest probability is the maximum attack intention; starting from the maximum attack intention, the reverse depth search algorithm is used to search for the node with the largest posterior node reachability probability in the parent node in turn, and add it to the attack path until the initial attribute node is added to the attack path, forming t (0) The maximum probability attack path Path_0 at the next moment t (1) , generate warning information o i (1), update the a posteriori reachability probability and maximum attack intention of each node, and use the updated maximum attack intention as the starting point to reversely search for the node with the largest probability of reaching the alarm node or a posteriori node in the parent node, and add it to the attack path at the current moment to form t (1) The maximum probability attack path Path_1 at time t (2) -t (t) Repeat the above process at all times and finally output t (t) The maximum attack intention at the moment and the maximum probability attack path Path_t.

[0015] The attribute attack graph includes two basic elements: nodes and directed edges. The nodes represent the status information of the industrial control system, including host attributes, atomic attacks, and alarm information, corresponding to attribute nodes s, attack nodes a, and alarm nodes o, respectively. The directed edges represent the utilization relationship between nodes, that is, the state migration from one node to another. According to the different types of nodes connected by the directed edges, the directed edges are divided into the prerequisite directed edges E from the attribute node s to the attack node a. S×A and the post-result directed edge E from attack node a to attribute node s A×S Two major categories.

[0016] The attribute attack graph is defined as a binary Att_G=<N,E> , where Att_G represents the attack graph, N is the node set, and E is the directed edge set;

[0017] The node set N is defined as the triple N =<S,A,O> , S is the attribute node set, which indicates the permissions that can be obtained before and after the attack. It consists of the initial node set S0 and the target node set S d , process node set S I Composition: S = S0 ∪ S I ∪S d , the basic form is:

[0018] S={s i |s i =(id_s i ,ip_s i ,privilege)}

[0019] Among them, id_s i Represents attribute node s i Number, ip_s i Indicates i The IP address of the i the permissions possessed or acquired;

[0020] A is the atomic attack set. In the attribute attack graph, an atomic attack refers to an indivisible attack action performed by an attacker using a vulnerability. This attack action is not affected by the association relationship between nodes. The basic form is:

[0021] A={a i |a i =(id_a i ,ip_a i ,id_vul,level_vul)}

[0022] where id_a i Indicates attack node a i Number, ip_a i Indicates a i The IP address of i The number of the vulnerability being attacked. level_vul indicates the level of the vulnerability published, which is divided into high-level H, medium-level M, and low-level L.

[0023] O is the warning sequence. For a certain attack a i , if there is o i ->a i , that is o i Can be mapped to attack a i If it is above, it means there is an alarm message. i ∈O; the basic form of the alarm sequence is:

[0024] O={o i |o i =(time,id_o i ,ip_o i ,ids_class)}

[0025] Where time indicates the occurrence of an alarm o i Time, id_o i Indicates o i Number, ip_o i Indicates o i IP address, ids_class indicates the alarm information is generated. i The type of IDS;

[0026] A directed edge set E is defined as a binary pair E = <E S×A ,E A×S >, E S×A is a set of precondition directed edges, connecting from attribute node s to attack node a, indicating that the attacker must have the permission on the attribute node, i.e., the precondition, to carry out this atomic attack; the basic form is:

[0027] E S×A ={e ij |eij =(id_s i ,ip_s i ,id_a j ,ip_a j ,p ij )}

[0028] where e ij Represented by attribute node s i Pointing to attack node a j Directed edge, id_s i 、ip_s i Respectively represent s i ID and IP address, id_a j ip_a j Respectively represent a j Number and IP address, p ij Indicates attachment to e ij The weight between the attributes of the nodes is i With attack node a j The probability of successful transfer between

[0029] E A×S is a directed edge set of post-results, connecting the attack node a to the attribute node s, indicating that the attacker obtains the subsequent attribute node permissions after executing an atomic attack;

[0030] E A×S ={e ij |e ij =(id_a i ,ip_a i ,id_s j ,ip_s j ,p ij )}

[0031] where e ij Indicates that the attack node a i Points to attribute node s j The directed edge of id_a i ip_a i Respectively represent a i Number and IP address, id_s j 、ip_s j Respectively represent s j Number and IP address, p ij Indicates attack node a i To attribute node s j The probability of successful transfer.

[0032] The node transfer probability refers to the probability of state migration of nodes at both ends of the directed edge of the attribute attack graph along the directed edge; the node transfer probability is a real number in the range of 0-1 attached to the directed edge, including the node transfer probability attached to the precondition directed edge and the node transfer probability attached to the postcondition directed edge;

[0033] The node transfer from attribute node s to attack node a is regarded as an atomic attack launched by using the host attribute on attribute node s. The node transfer probability is equivalent to the attack occurrence probability, that is, the attack occurrence probability is mapped to the premise condition directed edge E S×A The node transfer probability of the attack is calculated as follows: multiply the atomic attack probability output by the basic measurement group of the general vulnerability scoring system that introduces the host impact factor and the time impact factor output by the vulnerability life cycle model;

[0034] The node transfer from attack node a to attribute node s is regarded as a successful atomic attack on the host and obtains the host attribute. At this time, the node transfer probability is equivalent to the attack success probability, that is, the attack success probability is mapped to the post-result directed edge E A×S Based on the node transfer probability, the attack success probability is calculated according to the vulnerability classification.

[0035] The basic measurement group of the universal vulnerability scoring system that introduces the host impact factor is Att_Ato i =2×v×AV×AC×Au,Att_Ato i is the atomic attack probability, and the subscript represents the i-th vulnerability;

[0036] v is the host impact factor. The host impact factor varies according to the host type. The difficulty of vulnerability attacks is from difficult to easy: database, server, PC, PLC. The corresponding host impact factors are set to 0.625, 0.750, 0.875, and 1.000;

[0037] AV is the attack path in the Common Vulnerability Scoring System basic metric group, which describes the attack methods taken by the attacker, including local attack, adjacent network, and network attack. CVSS stipulates that the corresponding values ​​of AV are 0.395, 0.646, and 1.000 respectively;

[0038] AC is the attack complexity in the basic metric group of the Common Vulnerability Scoring System, which describes the complexity of the attacker's attack on the vulnerability, including high complexity, medium complexity, and low complexity. The corresponding values ​​of AC are specified to be 0.350, 0.610, and 0.710 respectively;

[0039] Au is the identity authentication in the basic metric group of the common vulnerability scoring system, which describes whether the attacker needs to pass identity authentication or the number of authentications when attacking, including multiple authentications, single authentication, and no authentication required. The corresponding values ​​of Au are specified to be 0.450, 0.560, and 0.704 respectively.

[0040] The vulnerability life cycle model is expressed as:

[0041]

[0042] According to the system vulnerability information obtained in the reachability analysis, the dates of the latest and oldest vulnerabilities in the industrial control system are recorded in days, and the date difference is recorded as the time span of the system vulnerability △year. All vulnerability information collected by NVD within the time span △year is collected, including vulnerability classification information as L, M, H, and information on changes in status with the year; P of different vulnerability levels is calculated respectively. (level) λ1-λ6 in:

[0043]

[0044]

[0045] λ3=1-λ2-λ4,λ6=1-λ5

[0046] After obtaining the parameters of the vulnerability lifecycle management model, time reasoning is performed in days. At the initial time t0, the state probability distribution vector SV (0) =[1,0,0,0,0], after t days, SV (t) =SV (0) ×P t , where SV (t) (4) represents the probability that the vulnerability is in S4, i.e., exploitable state, after t days; define the time impact factor. For vulnerability i on the host, its time impact factor after t days Among them level i Indicates the level of vulnerability i.

[0047] The node reachability probability is a measure of the overall probability of an attacker successfully reaching the node; the attribute attack graph association structure reasoning is performed, and the connection relationship is divided into a sequential relationship, a conjunction relationship, and a disjunction relationship according to the different parent-child node connections; the node reachability probability is calculated by a top-down recursive method, and the child node reachability probability is calculated according to the parent node reachability probability, the parent-child node transfer probability, and the parent-child node association relationship; based on the node definition and the association relationship between the nodes obtained by reasoning, a directed link from the initial node to the transition node to the target node is defined; the directed link is composed of the above-mentioned nodes and the directed edges associated therewith, and the directed link is regarded as an attack path.

[0048] The a priori node reachability probability refers to the node reachability probability when the attack node does not have an alarm node mapped to it; the a posteriori node reachability probability refers to the node reachability probability when the attack node has an alarm node mapped to it; the relationship between the a posteriori node reachability probability and the a priori node reachability probability is:

[0049]

[0050] Among them, P(a i ) represents the prior probability of reachability, P(a i |o i ) represents the posterior reachability probability, d i Indicates the detection rate of the IDS corresponding to the alarm node, u i Indicates the false alarm rate of the IDS corresponding to the alarm node. The probabilistic attack graph is equivalent to exhaustively enumerating the child nodes and matching the parent nodes for each attribute node and attack node according to the accessible information of the industrial system until all nodes are traversed; at the same time, the alarm information generated by the IDS arranged at each layer of the industrial control system network is used to indicate the attack behavior information occurring on the host, and the probability of a valid alarm information corresponds to an atomic attack; on the basis of the above-generated probabilistic attack graph, by establishing a mapping between the alarm node and the atomic attack node, the probabilistic attack graph is reconstructed, and finally the maximum probability attack path is identified.

[0051] The accessible information of the industrial control system specifically includes the detailed configuration of each host, the type of service running, the trust relationship between hosts, and the network topology; the intrusion detection system data specifically includes IDS performance data, firewall access control and filtering rules; the system vulnerability information specifically includes the vulnerability information existing on each host of the industrial control system.

[0052] The beneficial effects of the present invention are as follows: first, the alarm information generated by the intrusion detection system is introduced into the dynamic identification of the attack graph, and the probability attack graph is reconstructed by using the posterior estimation to improve the reliability and accuracy of the path identification; second, for the single vulnerability atomic attack, a vulnerability life cycle based on the absorbing Markov chain is established, and it is used as a time domain influencing factor to map it to the node transfer probability, thereby making up for the lack of the existing method that does not consider the time factor or the time model is too simple; third, the correlation structure between the attack graphs is comprehensively summarized, including the sequential, disjunctive and conjunction relationships, so that the attack graph model is more practical. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 It is a structural diagram of an industrial control system attack path identification method based on alarm sequence probability of the present invention;

[0054] Figure 2It is a flow chart of an industrial control system attack path identification method based on alarm sequence probability of the present invention;

[0055] Figure 3 It is a vulnerability life cycle state transition diagram based on the absorbing Markov chain of the present invention;

[0056] Figure 4 It is a schematic diagram of various association relationships of the network topology of the present invention;

[0057] Figure 5 This is a network topology diagram of an industrial control system according to an embodiment of the present invention;

[0058] Figure 6 is a probability attack graph when no alarm information is generated in an embodiment of the present invention;

[0059] Figure 7 It is a schematic diagram of a process of dynamically identifying attack paths based on alarm sequences according to an embodiment of the present invention. DETAILED DESCRIPTION

[0060] The specific implementation of the present invention is further described below in conjunction with the accompanying drawings and technical solutions.

[0061] In a basic implementation of the present invention, there are five steps, which are used to identify the nodes and paths that the attacker is most likely to attack online based on the network topology of the industrial control system. The specific implementation steps are as follows:

[0062] Step 1: Reachability Analysis

[0063] Conduct reachability analysis on the logical and physical correlations between the host nodes in the industrial control system network, and collect information on industrial control system accessibility, system vulnerability information, and intrusion detection system data (IDS). This information includes detailed configuration of each host, the type of service running, trust relationships between hosts, network topology, IDS performance data, firewall access control and filtering rules, and vulnerability information on the host.

[0064] Industrial control system accessibility information: Use the host scanning tool Nmap to obtain the applications, services and their corresponding port numbers running on each host node. There is information and data transmission and dependence between different hosts with the same port, and they can be regarded as "connected", that is, there is a reachable relationship between the two. Combined with firewall filtering and access control rules, and the trust relationship between hosts, the network topology is comprehensively determined. The accessibility information can be represented in the form of a 0-1 square matrix, where rows and columns represent the industrial control host numbers, respectively. The element value of 0 indicates that the host corresponding to the row number is not connected to the host corresponding to the column number, and 1 indicates that it is connected. For an industrial control system with N hosts, the corresponding reachability matrix is ​​P_Reach[N×N], where the element P_Reach ijIt means that the i-th host can reach the j-th host, and the diagonal elements of the P_Reach matrix are all 1. The reachable access matrix of the embodiment is as follows:

[0065]

[0066] System vulnerability information: Scan system vulnerabilities through the vulnerability scanning tool Nessus, and use the National Vulnerability Database (NVD) to unify the vulnerability description, including the Common Vulnerabilities and Exposures (CVE) identifier and the Common Vulnerability Scoring System (CVSS) score. For all published vulnerabilities, there is a unique "ID card" in the format of: CVE-Vulnerability Disclosure Year-Year Number. In addition, for each vulnerability, NVD will also derive a severity score of 0-10 from the three sub-metric groups of foundation, time, and environment, comprehensive availability, impact, etc., with 0 being the lowest and 10 being the highest. Taking the Windows SMB protocol vulnerability used by the ransomware WannaCry as an example, its CVE identifier is CVE-2017-0144, and the CVSS score is 8.8 (HIGH). Based on the above, the host vulnerability data is finally output, and the host vulnerability configuration information of the embodiment is shown in Table 1.

[0067] Table 1 Host vulnerability configuration information table of the embodiment

[0068]

[0069] Intrusion detection system data IDS. From historical data, obtain indicators such as the detection rate, false alarm rate, and missed alarm rate of IDS on the attacked host, and provide a data source for the subsequent reachability probability based on alarm information. The size of each indicator depends on the IDS detection method and the host type (PC, PLC, database, server, etc.).

[0070] Step 2: Modeling the basic elements of the attack

[0071] An attack graph is a directed graph that can be used to perform correlation analysis based on the reachable topology and vulnerability relationships between networks, thereby visually displaying the attacker's targets and potential complete attack paths. An attack graph contains basic elements such as nodes and directed edges. Nodes represent elements such as host attributes, atomic attacks, and alarm information, and directed edges represent the utilization relationship between nodes, that is, the migration from one node to another. In order to achieve dynamic prediction of attack paths based on alarms, after performing reachability analysis, the basic elements of the attack model need to be modeled.

[0072] (1) Basic definition of attack graph

[0073] According to the different definitions of nodes and directed edges and the different relationships between them, it can be divided into two categories: state attack graph and attribute attack graph. The present invention uses attribute attack graph, which is defined as the binary Att_G =<N,E> , where Att_G represents the attack graph, N is the node set, and E is the directed edge set.

[0074] (2) Node set N

[0075] The node set N is defined as the triple N =<S,A,O> , S is the attribute node set, which indicates the permissions that can be obtained before and after the attack. It consists of the initial node set S0 and the target node set S d , process node set S I Composition: S = S0 ∪ S I ∪S d , the basic form is:

[0076] S={s i |s i =(id_s i ,ip_s i ,privilege)}

[0077] where id_s i Represents attribute node s i Number, ip_s i Indicates i The IP address of the i The permissions to possess or obtain.

[0078] A is the atomic attack set. In the attack graph, an atomic attack (Network Atomic Attack, NAA) refers to an indivisible attack action performed by an attacker using a vulnerability. This attack action is not affected by the relationship between nodes. The basic form is:

[0079] A={a i |a i =(id_a i ,ip_a i ,id_vul,level_vul)}

[0080] where id_a i Indicates attack node a i Number, ip_a i Indicates a i The IP address of i The vulnerability number of the attack. Here, the CVE vulnerability unified identifier published by NVD is used. level_vul indicates the level of the vulnerability published by NVD, which is divided into high level (H), medium level (M), and low level (L).

[0081] O is the warning sequence. For a certain attack a i , if there is a corresponding matching o i ->a i , then there is an alarm message o i ∈O. It reflects that the IDS intrusion detection system in the real industrial control network successfully detects a vulnerability attack and issues an alarm. The basic form is:

[0082] O={o i |o i =(time,id_o i ,ip_o i ,ids_class)}

[0083] Where time indicates the occurrence of an alarm o i Time, id_o i Indicates o i Number, ip_o i Indicates o i IP address, ids_class indicates the alarm information is generated. i The type of IDS.

[0084] (3) Directed edge set E

[0085] A directed edge set E is defined as a binary pair E = <E S×A ,E A×S >, E S×A is a set of precondition directed edges, connecting the attribute node s to the attack node a, indicating that the attacker must have the permissions on the attribute node, that is, the precondition, to carry out this atomic attack. The basic form is:

[0086] E S×A ={e ij |e ij =(id_s i ,ip_s i ,id_a j ,ip_a j ,p ij )}

[0087] where e ij Represented by attribute node s i Pointing to attack node a j Directed edge, id_s i 、ip_s i Respectively represent s i ID and IP address, id_a j ip_a j Respectively represent a j Number and IP address, p ij Indicates attachment to eij The weight between the attributes of the nodes is i With attack node a j The probability of a successful transfer between .

[0088] E A×S It is a directed edge set of post-results, connecting the attack node a to the attribute node s, indicating that the attacker obtains the subsequent attribute node permissions after executing an atomic attack. The basic form is:

[0089] E A×S ={e ij |e ij =(id_a i ,ip_a i ,id_s j ,ip_s j ,p ij )}

[0090] where e ij Indicates that the attack node a i Points to attribute node s j The directed edge of id_a i ip_a i Respectively represent a i Number and IP address, id_s j 、ip_s j Respectively represent s j Number and IP address, p ij Indicates attack node a i To attribute node s j The probability of successful transfer.

[0091] Step 3: Calculate node transfer probability and node reachability probability

[0092] The node transfer probability refers to the probability of state migration of nodes at both ends of the directed edge of the attribute attack graph along the directed edge; the node transfer probability is a real number in the range of 0-1 attached to the directed edge, including the node transfer probability attached to the precondition directed edge and the node transfer probability attached to the postcondition directed edge;

[0093] The node transfer from attribute node s to attack node a is regarded as an atomic attack launched by using the host attribute on attribute node s. The node transfer probability is equivalent to the attack occurrence probability, that is, the attack occurrence probability is mapped to the premise condition directed edge E S×A The node transfer probability of the attack is calculated as follows: multiply the atomic attack probability output by the basic measurement group of the general vulnerability scoring system that introduces the host impact factor and the time impact factor output by the vulnerability life cycle model;

[0094] The node transfer probability between the attack node a and the attribute node s is equivalent to a successful attack on the host in the actual system. Similarly, the attack success probability can be mapped to the post-result edge E A×S Based on the transfer probability, the attack success probability is calculated according to the vulnerability classification.

[0095] Define the node reachability probability to measure the overall probability of an attacker successfully reaching the node. Perform attribute attack graph association structure reasoning. According to the different parent-child node connections, the connection relationship can be divided into three types: sequential relationship, conjunction relationship, and disjunction relationship. Based on the node definition and the association relationship between nodes derived by reasoning, define a directed link from the initial node to the target node via the transition node. The link consists of the above nodes and the directed edges associated with them. The link can be regarded as an attack path.

[0096] (1) Node transfer probability

[0097] In order to calculate the reachability probability of each node in the attack graph and thus realize the attack path prediction, it is necessary to calculate the node transfer probability attached to each directed edge. According to the different types of directed edges, the attack occurrence and success probabilities can be mapped to the probabilities of the precondition and post-result directed edges respectively. The following calculates the attack occurrence probability and attack success probability respectively.

[0098] An atomic attack is equivalent to a vulnerability exploit. The difficulty of vulnerability exploitation is negatively correlated with the probability of attack. The more difficult the vulnerability is to exploit, the lower the probability of attack. The vulnerability exploitability equation is defined in the basic metric group of the general vulnerability scoring system, which defines indicators such as access vector (AV), access complexity (AC), and authentication (Au), but does not consider the impact of the host on exploitability. On this basis, the present invention introduces the host impact factor v and calculates the probability of atomic attack (hereinafter referred to as atomic attack probability) according to the improved exploitability equation:

[0099] Att_Ato i =2×v×AV×AC×Au

[0100] Among them, the subscript represents the i-th vulnerability, and the calculation methods of v, AV, AC, and Au are shown in Table 2.

[0101] Table 2 Calculation of various factors of atomic attack probability

[0102]

[0103] The probability of an attack not only depends on the atomic attack probability, but also on the time factor. The longer the vulnerability is discovered, the more likely it is to be exploited. The time impact factor is introduced to quantify the degree of time impact on the vulnerability. The time utilization probability calculation and reasoning are performed below. A vulnerability life cycle model is established, and the vulnerability status is divided into "generation", "discovery", "disclosure", "exploitation", and "invalidation". A complete life cycle of a vulnerability will start from generation, be discovered and disclosed over time, and eventually be exploited or invalidated. The vulnerability life cycle state transition diagram is shown below Figure 3 shown.

[0104] Since the vulnerability life cycle state is discrete, has no aftereffect, and has two target states, it is consistent with the absorbing Markov chain. Therefore, a vulnerability life cycle model based on the absorbing Markov chain can be established. The generation, discovery, and disclosure are used as the transition states S1, S2, and S3 of the absorbing Markov chain, and the two target states of utilization and failure are used as the absorbing states S4 and S5. The vulnerability life cycle model established by combining the absorbing Markov chain and the state transition diagram can be expressed as:

[0105]

[0106] According to the time span △year of each host vulnerability in the embodiment obtained in step 1, all vulnerability information collected by NVD within the time span △year is collected, including vulnerability classification information (L, M, H) and information on status changes with the year, and P of different vulnerability levels is calculated respectively. (level) λ1-λ6 in:

[0107]

[0108] λ3=1-λ2-λ4,λ6=1-λ5

[0109] After obtaining the parameters of the vulnerability lifecycle management model, time reasoning is performed in days. At the initial time t0, the state probability distribution vector SV (0) =[1,0,0,0,0], after t days, SV (t) =SV (0) ×P t , where SV (t) (4) represents the probability that the vulnerability is in S4, i.e., exploitable state, after t days. In summary, the time impact factor is defined. For vulnerability i on the host, its time impact factor after t days is Among them level i Indicates the level of vulnerability i.

[0110] After calculating the atomic attack probability and time impact factor, the attack occurrence probability attached to the precondition is obtained, and then the attack success probability is calculated. In actual attacks, the attack occurrence probability and attack success probability are related. Whether a vulnerability attack occurs and whether it is successful are related to the difficulty of the vulnerability attack, and the attack difficulty has been considered in the attack occurrence probability. Therefore, the general method regards the success probability as 1. In order to avoid loss of generality, the present invention assigns different attack success probabilities (0.8, 0.9, 1) to vulnerabilities of different levels (H, M, L) based on historical data.

[0111] The node transition probability can finally be expressed as:

[0112]

[0113] (2) Node reachability probability

[0114] Node transition probability p ij It represents the difficulty of state transfer between different nodes, which depends only on the atomic attack on the host and its corresponding individual factors, and has nothing to do with the causal relationship of the network topology. The node reachability probability measures the overall probability that an attacker can successfully reach the node in a given attack graph, represented by the capital letter P. The node reachability probability takes into account the association structure between nodes. The calculation of the reachability probability between different association structures will be introduced in Section (3).

[0115] (3) Attack graph association structure

[0116] First, use Pre(ai / si) to represent the parent node of node ai / si, and use Post(ai / si) to represent the child node of node ai / si. Similar to the intersection and union of random events, the parent and child nodes are divided into sequential, conjunction, and disjunction relationships according to the number of connected directed edges and node distribution.

[0117] In the case of a succession relationship, a single node is connected to a single node, and there is a unique corresponding connection between the parent and child nodes. The succession relationship is the simplest form. i The probability of reaching i ), when s j =Post(a i ) and a i =Pre(s j ), the child node s j The probability of reaching j )=P(a i ) ij , similarly, we can find the known parent node s i The reachability probability of child node a j The probability of being reached.

[0118] Conjunction relationship, multiple nodes are connected to a single node. According to the difference between parent and child nodes, it can be divided into multiple attack nodes connected to a single attribute node, or multiple attribute nodes connected to a single attack node. The classification is explained below. Multiple attack nodes are connected to a single attribute node. If any attack node is reachable, the attribute node is reachable. The attribute node reachability probability can be expressed as: s j =Post(a i ),i=1,2,…,n,n≥2, it is known that each P(a i ), When multiple attribute nodes are connected to a single attack node, the attack node is reachable only when all attribute nodes are reachable. The reachability probability of the attack node can be expressed as: j =Post(s i ),i=1,2,…,n,n≥2, it is known that each P(s i ),

[0119] Disjunctive relationship, a single node is connected to multiple nodes, there is a connection between the parent node and each child node, each child node has a unique parent node, which can be regarded as a combination of multiple successive relationships. The disjunctive relationship has nothing to do with the type of parent and child nodes. Take the attribute node as the parent node and the attack node as the child node as an example to calculate the reachability probability of each child node: s i =Pre(a j ),j=1,2,…,n,n≥2, it is known that P(s i ),right P(a j )=P(s i ) ij ,j=1,2,…,n. Similarly, we can calculate the reachability probability of each child node when the attack node is the parent node and the attribute node is the child node.

[0120] The above-mentioned relationship diagrams are as follows Figure 4 shown.

[0121] (4) Attack Path

[0122] The attack path represents the directed link from the initial attribute node to the target attribute node via the transition attribute node. The link consists of the above nodes and the directed edges associated with them. It is defined as the attack path Path, Path = ⊥→s0→a1→…→s d , for any element τ in Path i (τ i ∈S or A) has τ i+1 =Post(τ i )∈Path, let l=Length(Path) be the sum of all nodes on the path, representing the attack path length, np is the number of attack paths, then s0 to s dThe set of all attack paths is PATHS = {Path (1) ,Path (2) ,...,Path (np)}.

[0123] Step 4: Generate an attack graph based on the alert information

[0124] According to the definition and calculation of attack elements and association rules, a probabilistic attack graph is generated based on the idea of ​​graph traversal, which is essentially equivalent to exhaustively enumerating the child nodes and matching the parent nodes for each attribute node and attack node according to the reachable relationship of the network topology until all nodes are traversed. To facilitate analysis and fit the actual system at the same time, assumptions are made: Assumption 1 The attacker has "memory", and the attribute nodes that have obtained permissions will not be re-acquired after an attack, that is, the attack graph is acyclic; Assumption 2 Atomic attacks will only occur when all the prerequisite attribute node permissions of the attack node are met; Assumption 3 When any prerequisite attack node of an attribute node is met, the permission of the attribute node will be obtained. For the embodiment, the probabilistic attack graph is generated from the network topology structure as shown in the following figure: Figure 6 As shown in the figure. The initial attribute node is the attacker's position and authority before the attack, the target attribute node is the attacker's intention, and the transition attribute node and attack node are the nodes that may be used or reached on the attack path. There are 24 attack paths from the initial to the target attribute node, with the shortest path length of 8 and the longest path length of 16.

[0125] The alarm information generated by the IDS deployed at each layer of the industrial control network can be used to indicate the attack behavior information occurring on the host. The probability of a valid alarm information corresponds to an atomic attack. Therefore, based on the attack graph generated above, by establishing a mapping between the alarm node and the atomic attack node, the probabilistic attack graph can be reconstructed, and finally the maximum probability attack path can be identified.

[0126] For attacking node a i =(id_a i ,ip_a i ,id_vul,level_vul), if IDS detects the existence of the attack at a certain moment, it generates a corresponding i Warning information o i =(time, id_alerm, ip_alerm, ids_class), and the two IP values ​​are equal, then there is a mapping relationship between the two, which is reflected in the probability attack graph as an extended directed edge pointing to the attack node. In addition, affected by the change in network topology, the node reachability probability also needs to be reconstructed and probabilistic reasoning is performed: before and after the alarm a i The reachability probabilities are P(a i ) and P(a i |o i), the former is called the priori node reachability probability, and the latter is the posterior node reachability probability. According to the total probability and Bayesian formula, the posterior reachability probability is:

[0127]

[0128] where d i 、u i They represent the detection rate and false alarm rate of the corresponding IDS, respectively. The detection rate d i It indicates the probability of IDS correctly alerting when facing an intrusion attack, and the false alarm rate u i It indicates the probability that the IDS will mistakenly report normal behavior as an attack. It depends on the host and the type of IDS. The calculation method is as follows:

[0129] Table 3 IDS detection matrix

[0130] Detected as Intrusion Detected as non-invasive Actually an invasion TA FNA Practically non-invasive FA TNA

[0131]

[0132] For the obtained posterior node reachability probability P(a i |o i ), if it is less than 50%, it means the corresponding If it is greater than 50%, it is equivalent to detecting normal behavior as attack behavior, resulting in a false alarm; if the posterior probability is less than the prior probability, it means that the alarm information is inconsistent with the original attack and a false alarm has occurred. That is, only when the posterior probability is greater than 50% and greater than the prior probability, the corresponding alarm is a true alarm, otherwise it is a false alarm. After obtaining the posterior node reachability probability, the reachability probabilities of all subsequent child nodes are re-corrected as the association relationship is transmitted. In layman's terms, the above process can be summarized as follows: after the IDS detects an attack, the probability of the attack is greatly increased, and because the attack target has not been reached, the attack will not stop, and the reachability probabilities of subsequent nodes associated with the attack will also increase.

[0133] Initial time t (0) No alarm occurs, and the resulting probability attack graph is denoted as Att_G (0) , if the alarm sequence detected by IDS over time is O = {o i (1) ,o j (2) ,...,o n (t)}, based on the above method, the probability attack graph set ATTS = {Att_G (1) ,Att_G (2) ,...,Att_G (t)}.

[0134] Step 5: Dynamic attack path identification

[0135] Using the attack graph generation method introduced in step 4, at the initial time t (0) When there is no alarm, a probabilistic attack graph is generated, and the reachability probability of each prior and a posteriori node is calculated. At this time, since there is no alarm information, the reachability probability of the prior and a posteriori nodes is equal. Compare the reachability probability of the a posteriori nodes of each target attribute node, and the target attribute node with the largest probability is the maximum attack intention. Starting from the maximum attack intention, the reverse depth search algorithm is used to search for the node with the largest probability of the a posteriori node in the parent node, and add it to the attack path until the initial attribute node is formed. (0) The maximum probability attack path Path_0 at the next moment t (1) , generate warning information o i (1) , update the posterior node reachability probability and maximum attack intention of each node, and use the updated maximum attack intention as the starting point to reversely search for the node with the highest probability of reaching the alarm node or posterior node in the parent node, and add it to the attack path to form Path_1. And so on, t (2) -t (t) Repeat the above process at all times and finally output t (t) The maximum attack intention at the moment and the maximum probability attack path Path_t.

[0136] For the embodiment, the above dynamic attack path identification method is used in the alarm sequence O={o i (1) ,o j (2) ,o n (3) ,o f (4) The maximum attack intention and attack path change over time when Figure 7 As shown, the maximum attack intention inferred by the final comprehensive posterior knowledge estimation is s9, the reachable probability of s9 is 46.07%, and the maximum probability attack path is successfully identified.

[0137] In summary, the industrial control system attack path identification method based on alarm sequence probability of the present invention utilizes the topological relationship between the hosts of the industrial control system, collects the vulnerability relationship therein, and quantifies the node state transition in the topology based on the vulnerability level. The alarm information obtained by the intrusion detection system is introduced and mapped to the corresponding nodes to better fit the actual attack. Finally, the dynamic attack intention posterior estimation inference and attack path reverse search are performed on the obtained probabilistic attack graph, realizing the dynamic risk assessment of the potential attack path of the industrial control system.

[0138] The above is an explanation of the principle of the method according to the ideal embodiment of the present invention. The present invention is not limited by the above embodiment. Through the above description, those skilled in the art can make various changes and modifications without departing from the technical idea of ​​the present invention. The technical scope of the present invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.

Claims

1. A method for identifying attack paths of industrial control systems based on alarm sequence probability, characterized in that: Here are the steps: Step 1: Reachability analysis; Conduct reachability analysis on the logical and physical correlations between the host nodes in the industrial control system network, and collect information on industrial control system accessibility, system vulnerability information, and intrusion detection system data; Step 2: Modeling the basic elements of the attack; Define an attribute attack graph, which is obtained by correlating the industrial control system access information and system vulnerability information collected in step 1 reachability analysis to show the attacker's goals and potential complete attack paths; Step 3: Calculate the node transfer probability and node reachability probability; Step 4: Generate a probabilistic attack graph based on the warning information; According to the definition of the attack elements of the attribute attack graph in step 2 and the node transfer probability in step 3, a probability attack graph is generated based on the attribute attack graph based on the idea of ​​graph traversal; Step 5: Dynamic attack path identification; Using the probabilistic attack graph generation method introduced in step 4, at the initial time t (0) When there is no alarm, a probabilistic attack graph is generated, and the reachability probability of each priori node and the reachability probability of each a posteriori node are calculated; Compare the reachability probabilities of each target attribute posterior node, and the target attribute node with the largest probability is the one with the greatest attack intention; Starting from the maximum attack intention, the reverse depth search algorithm is used to search for the node with the highest probability of being reachable by the posterior node in the parent node, and add it to the attack path until the initial attribute node is added to the attack path to form t (0) The maximum probability attack path Path_0 at the next moment t (1) , generate warning information o i (1) , update the posterior node reachability probability and maximum attack intention of each node, and use the updated maximum attack intention as the starting point to reversely search for the alarm node or the node with the largest posterior node reachability probability in the parent node, and add it to the attack path at the current moment to form t (1) The maximum probability attack path Path_1 at time t (2) -t (t) Repeat the above process at all times and finally output t (t) The maximum attack intention at the moment and the maximum probability attack path Path_t.

2. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 1 is characterized in that: The attribute attack graph includes two basic elements: nodes and directed edges; the nodes represent the status information of the industrial control system, including host attributes, atomic attacks, and alarm information, corresponding to attribute nodes s, attack nodes a, and alarm nodes o respectively; The directed edges represent the utilization relationship between nodes, that is, the state migration from one node to another. According to the different types of nodes connected by the directed edges, the directed edges are divided into the prerequisite directed edges E from the attribute node s to the attack node a. S×A and the post-result directed edge E from attack node a to attribute node s A×S Two major categories.

3. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 2 is characterized in that: The attribute attack graph is defined as a binary Att_G=<N,E> , where Att_G represents the attack graph, N is the node set, and E is the directed edge set; The node set N is defined as the triple N =<S,A,O> , S is the attribute node set, which indicates the permissions that can be obtained before and after the attack. It consists of the initial node set S0 and the target node set S d , process node set S I Composition: S = S0 ∪ S I ∪S d , the basic form is: S={s i |s i =(id_s i ,ip_s i ,privilege)} Among them, id_s i Represents attribute node s i Number, ip_s i Indicates i The IP address of the i the permissions possessed or acquired; A is the atomic attack set. In the attribute attack graph, an atomic attack refers to an indivisible attack action performed by an attacker using a vulnerability. This attack action is not affected by the association relationship between nodes. The basic form is: A={a i |a i =(id_a i ,ip_a i ,id_vul,level_vul)} where id_a i Indicates attack node a i Number, ip_a i Indicates a i The IP address of i The number of the vulnerability being attacked. level_vul indicates the level of the vulnerability published, which is divided into high-level H, medium-level M, and low-level L. O is the warning sequence. For a certain attack a i , if there is o i ->a i , that is o i Can be mapped to attack a i If it is above, it means there is an alarm message. i ∈O; the basic form of the alarm sequence is: O={o i |o i =(time,id_o i ,ip_o i ,ids_class)} Where time indicates the occurrence of an alarm o i Time, id_o i Indicates o i Number, ip_o i Indicates o i IP address, ids_class indicates the alarm information is generated. i The type of IDS; The directed edge set E is defined as the binary pair E = <E S×A ,E A×S >, E S×A is a set of precondition directed edges, connecting from attribute node s to attack node a, indicating that the attacker must have the permission on the attribute node, i.e., the precondition, to carry out this atomic attack; the basic form is: E S×A ={e ij |e ij =(id_s i ,ip_s i ,id_a j ,ip_a j ,p ij )} where e ij Represented by attribute node s i Pointing to attack node a j Directed edge, id_s i 、ip_s i Respectively represent s i ID and IP address, id_a j ip_a j Respectively represent a j Number and IP address, p ij Indicates attachment to e ij The weight between the attributes of the nodes is i With attack node a j The probability of successful transfer between E A×S is a directed edge set of post-results, connecting the attack node a to the attribute node s, indicating that the attacker obtains the subsequent attribute node permissions after executing an atomic attack; E A×S ={e ij |e ij =(id_a i ,ip_a i ,id_s j ,ip_s j ,p ij )} where e ij Indicates that the attack node a i Points to attribute node s j The directed edge of id_a i ip_a i Respectively represent a i Number and IP address, id_s j 、ip_s j Respectively represent s j Number and IP address, p ij Indicates attack node a i To attribute node s j The probability of successful transfer.

4. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 1 is characterized in that: The node transfer probability refers to the probability of state migration of nodes at both ends of the directed edge of the attribute attack graph along the directed edge; the node transfer probability is a real number in the range of 0-1 attached to the directed edge, including the node transfer probability attached to the precondition directed edge and the node transfer probability attached to the postcondition directed edge; The node transfer from attribute node s to attack node a is regarded as an atomic attack launched by using the host attribute on attribute node s. The node transfer probability is equivalent to the attack occurrence probability, that is, the attack occurrence probability is mapped to the premise condition directed edge E S×A The node transfer probability of the attack is calculated as follows: multiply the atomic attack probability output by the basic measurement group of the general vulnerability scoring system that introduces the host impact factor and the time impact factor output by the vulnerability life cycle model; The node transfer from attack node a to attribute node s is regarded as a successful atomic attack on the host and obtains the host attribute. At this time, the node transfer probability is equivalent to the attack success probability, that is, the attack success probability is mapped to the post-result directed edge E A×S Based on the node transfer probability, the attack success probability is calculated according to the vulnerability classification.

5. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 4 is characterized in that: The basic measurement group of the universal vulnerability scoring system that introduces the host impact factor is Att_Ato i =2×v×AV×AC×Au,Att_Ato i is the atomic attack probability, and the subscript represents the i-th vulnerability; v is the host impact factor. The host impact factor varies according to the host type. The difficulty of vulnerability attacks is from difficult to easy: database, server, PC, PLC. The corresponding host impact factors are set to 0.625, 0.750, 0.875, and 1.000; AV is the attack path in the Common Vulnerability Scoring System basic metric group, which describes the attack methods taken by the attacker, including local attack, adjacent network, and network attack. CVSS stipulates that the corresponding values ​​of AV are 0.395, 0.646, and 1.000 respectively; AC is the attack complexity in the basic metric group of the Common Vulnerability Scoring System, which describes the complexity of the attacker's attack on the vulnerability, including high complexity, medium complexity, and low complexity. The corresponding values ​​of AC are specified to be 0.350, 0.610, and 0.710 respectively; Au is the identity authentication in the basic metric group of the common vulnerability scoring system, which describes whether the attacker needs to pass identity authentication or the number of authentications when attacking, including multiple authentications, single authentication, and no authentication required. The corresponding values ​​of Au are specified to be 0.450, 0.560, and 0.704 respectively.

6. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 4 is characterized in that: The vulnerability life cycle model is expressed as: According to the system vulnerability information obtained in the reachability analysis, the dates of the latest and oldest vulnerabilities in the industrial control system are recorded in days, and the date difference is recorded as the time span of the system vulnerability △year. All vulnerability information collected by NVD within the time span △year is collected, including vulnerability classification information as L, M, H, and information on changes in status with the year; P of different vulnerability levels is calculated respectively. (level) λ1-λ6 in: After obtaining the parameters of the vulnerability lifecycle management model, time reasoning is performed in days. At the initial time t0, the state probability distribution vector SV (0) =[1,0,0,0,0], after t days, SV (t) =SV (0) ×P t , where SV (t) (4) represents the probability that the vulnerability is in S4, i.e., exploitable state, after t days; define the time impact factor. For vulnerability i on the host, its time impact factor after t days Among them level i Indicates the level of vulnerability i.

7. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 1 is characterized in that: The node reachability probability is the overall probability of measuring the attacker's successful arrival at the node; the attribute attack graph association structure reasoning is performed, and the connection relationship is divided into a sequential relationship, a conjunction relationship, and a disjunction relationship according to the different parent-child node connections; the node reachability probability is calculated by a top-down recursive method, and the child node reachability probability is calculated according to the parent node reachability probability, the parent-child node transfer probability, and the parent-child node association relationship; Based on the node definition and the association relationship between the nodes obtained by reasoning, a directed link is defined from the initial node via the transition node to the target node; the directed link is composed of the above nodes and the directed edges associated therebetween, and the directed link is regarded as an attack path.

8. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 7 is characterized in that: The a priori node reachability probability refers to the node reachability probability when the attack node does not have an alarm node mapped to it; the a posteriori node reachability probability refers to the node reachability probability when the attack node has an alarm node mapped to it; the relationship between the a posteriori node reachability probability and the a priori node reachability probability is: Among them, P(a i ) represents the prior probability of reachability, P(a i |o i ) represents the posterior reachability probability, d i Indicates the detection rate of the IDS corresponding to the alarm node, u i Indicates the false alarm rate of the IDS corresponding to the alarm node.

9. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 1, characterized in that: The probabilistic attack graph is equivalent to exhaustively enumerating the child nodes and matching the parent nodes for each attribute node and attack node according to the accessible information of the industrial system until all nodes are traversed; at the same time, the alarm information generated by the IDS arranged at each layer of the industrial control system network is used to indicate the attack behavior information occurring on the host, and the probability of a valid alarm information corresponds to an atomic attack; on the basis of the probabilistic attack graph generated above, by establishing a mapping between the alarm node and the atomic attack node, the probabilistic attack graph is reconstructed, and finally the maximum probability attack path is identified.

10. The method for identifying attack paths of industrial control systems based on alarm sequence probability according to claim 1, characterized in that: The accessible information of the industrial control system specifically includes the detailed configuration of each host, the type of service running, the trust relationship between hosts, and the network topology; the intrusion detection system data specifically includes IDS performance data, firewall access control and filtering rules; the system vulnerability information specifically includes the vulnerability information existing on each host of the industrial control system.

Citation Information

Patent Citations

  • Method for reconstructing network attack path based on frequent pattern-growth algorithm

    CN101931570A

  • Network intrusion situation intention evaluation method based on alarm integration

    CN108769051A

  • Multi-step attack scene mining method based on neural network and Bayesian network attack graph

    CN109327480A

  • Physical watermark detection method for replay attack of industrial control system

    CN114563996A

  • Method for generating attack graphs based on markov chains

    US20240056470A1