Trusted attack risk assessment method for trusted DCS (Distributed Control System) and related device

By using a pre-trained trusted attack risk assessment model in a trusted DCS system, combining GRU gated neural network and convolutional neural network, the user operation record data is automatically processed, and the problem of operation and maintenance personnel manually analyze risk level lag is solved, achieving more efficient and accurate risk assessment, and enhancing the system's security and operation and maintenance efficiency.

CN120010445APending Publication Date: 2025-05-16XIAN THERMAL POWER RES INST CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510145503.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In a trusted DCS system, operation and maintenance personnel need to manually pay full attention to all attributes of operation logs and audit information to judge the risk level, resulting in serious lag in risk level analysis and affecting the safe operation of the system.

Method used

By obtaining the real-time operation record data of the user of the system to be evaluated, performing preprocessing, it is input into the pre-trained trusted attack risk assessment model, and a model combining GRU-gated neural network and convolutional neural network is used for risk assessment.

Benefits of technology

It effectively improves the efficiency of operation and maintenance personnel to review logs and audits, improves the real-time and accuracy of trusted attack risk assessment of trusted attacks in trusted DCS systems, enhances the trustworthiness and security of the system, and improves the efficiency and response speed of the system operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010445A_ABST
    Figure CN120010445A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of credible distributed control system risk assessment, and discloses a credible attack risk assessment method for a credible DCS system and a related device, and the method comprises the steps: obtaining user real-time operation record data of a to-be-assessed system; the user real-time operation record data of the to-be-evaluated system comprises a real-time operation log and auditing information of a user; preprocessing the user real-time operation record data of the to-be-evaluated system to generate a preprocessed real-time data set; inputting the preprocessed real-time data set into a pre-trained trusted attack risk assessment model, and outputting to obtain a trusted attack risk assessment result of the to-be-assessed system; the pre-trained trusted attack risk assessment model comprises an input layer, a GRU gating neural network, a convolutional neural network and a full-connection output layer; according to the method, the log reviewing and auditing efficiency of operation and maintenance personnel is improved, the real-time performance and the accuracy of credible attack risk assessment of the credible DCS system are improved, and the credibility and the safety of the system are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of risk assessment of trusted distributed control systems, and in particular relates to a trusted attack risk assessment method and related devices for a trusted DCS system. Background Art

[0002] Distributed Control System (DCS) is a new type of control device that uses computer technology to centrally monitor, operate, manage and decentralized control industrial production processes; the trusted DCS system is based on the traditional DCS system and improves the security of the system by introducing a trusted computing system.

[0003] During the operation of the trusted DCS system, error tracing and risk level analysis are achieved by continuously recording user operation logs and audit information. However, due to the large amount of data, poor readability and unclear hazard information in operation logs and audit information, operation and maintenance personnel often need to manually pay attention to all attributes of operation logs and audit information to judge the risk level in system risk level analysis, resulting in serious lag in risk level analysis, which creates great hidden dangers for the safe operation of the system. Summary of the invention

[0004] In view of the technical problems existing in the prior art, the present invention provides a trusted attack risk assessment method and related devices for a trusted DCS system to solve the technical problem that in the existing system risk level analysis, operation and maintenance personnel often need to manually pay full attention to all attributes of operation logs and audit information to judge the risk level, resulting in serious lag in risk level analysis and creating great hidden dangers for the safe operation of the system.

[0005] In order to achieve the above object, the technical solution adopted by the present invention is: The present invention provides a trusted attack risk assessment method for a trusted DCS system, comprising: Acquire real-time user operation record data of the system to be evaluated; wherein the real-time user operation record data of the system to be evaluated includes log information and audit information of preset real-time operation behaviors in the system to be evaluated; Preprocessing the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set; The preprocessed real-time data set is input into a pre-trained trusted attack risk assessment model, and a trusted attack risk assessment result of the system to be evaluated is output; wherein the pre-trained trusted attack risk assessment model includes an input layer, a GRU gated neural network, a convolutional neural network and a fully connected output layer.

[0006] Furthermore, the preset real-time operation behaviors include login, operation commands, access resources and policy configuration; The log information of the preset real-time operation behavior includes the operation type, operation user name, operation timestamp, operation object, operation result and operation execution process of the preset real-time operation behavior; the audit information of the preset real-time operation behavior includes the audit log and audit report of the preset real-time operation behavior.

[0007] Furthermore, the process of preprocessing the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set is as follows: Performing data cleaning, standardization and feature extraction on the real-time user operation record data of the system to be evaluated to obtain pre-processed real-time user operation record data; wherein, during the feature extraction process, a unique hot encoding technique is used to extract features; The preprocessed user real-time operation record data is converted into a data format suitable for processing by a machine learning model to obtain a preprocessed real-time data set.

[0008] Furthermore, the input layer is used to read input features from the preprocessed real-time data set; wherein the input features are a three-dimensional matrix, and the three-dimensional matrix includes a time step dimension, a sequence dimension, and a time point dimension; Specifically, the input features of each time step dimension include a sequence of preset length; the input features of each sequence dimension include a number of user operation record data before the current time point; wherein each user operation record data is regarded as a time point; the input features of each time point dimension are input feature vectors of preset length, and the input feature vectors of preset length include the operation type of the operation behavior, the operation user name, the operation timestamp, the operation object, the operation result and the operation execution process.

[0009] Furthermore, the GRU gated neural network includes 128 GRU units; each GRU unit includes a reset gate and an update gate; the convolutional layer of the convolutional neural network is set with 64 filters, the convolution kernel size is 3, and the maximum pooling method is selected.

[0010] Furthermore, the fully connected output layer is used to output a risk level value and obtain a trusted attack risk assessment result of the system to be assessed according to a preset risk level range; wherein the risk level value is a floating point data.

[0011] The present invention also provides a trusted attack risk assessment system for a trusted DCS system, comprising: A real-time data acquisition module is used to acquire the real-time operation record data of the user of the system to be evaluated; wherein the real-time operation record data of the user of the system to be evaluated includes the real-time operation log and audit information of the user; A real-time data processing module is used to pre-process the real-time operation record data of the user of the system to be evaluated to generate a pre-processed real-time data set; The risk assessment module is used to input the preprocessed real-time data set into a pre-trained trusted attack risk assessment model, and output a trusted attack risk assessment result of the system to be evaluated; wherein the pre-trained trusted attack risk assessment model includes an input layer, a GRU gated neural network, a convolutional neural network and a fully connected output layer.

[0012] The present invention also provides a trusted attack risk assessment device for a trusted DCS system, comprising: a processor suitable for executing a computer program; A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by the processor, the trusted attack risk assessment method for a trusted DCS system is executed.

[0013] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the trusted attack risk assessment method for a trusted DCS system is implemented.

[0014] The present invention also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the trusted attack risk assessment method for a trusted DCS system is implemented.

[0015] Compared with the prior art, the present invention has the following beneficial effects: The trusted attack risk assessment method for a trusted DCS system provided by the present invention effectively improves the efficiency of log review and auditing by operation and maintenance personnel by acquiring and preprocessing real-time operation record data of users and using a pre-trained trusted attack risk assessment model to perform risk assessment, thereby effectively improving the real-time and accuracy of trusted attack risk assessment of a trusted DCS system, enhancing the credibility and security of the system, and improving the system operation and maintenance efficiency and response speed; specifically, by acquiring real-time operation logs and audit information of users, it is ensured that the data source of risk assessment is the latest and most accurate, which helps to timely discover and respond to potential attack risks; by preprocessing real-time operation record data to generate a more standardized and unified data set, the processing efficiency and accuracy of subsequent risk assessment models are improved; and Using the pre-trained trusted attack risk assessment model for risk assessment can make full use of the model's learning and generalization capabilities to quickly and accurately assess potential attack risks. The pre-trained trusted attack risk assessment model uses a combination of GRU gated neural networks and convolutional neural networks, which can effectively capture the temporal and spatial features in user operation record data, and improve the accuracy and robustness of risk assessment. Specifically, the GRU network is used to process sequence data to capture abnormal events with time correlation, and the dependencies between user operations can be captured. The convolutional neural network is used to capture anomalies that may be caused by a group of operations in a short period of time, and the spatial features in the user operation record data are captured, so that the model can better understand user operation behavior and accurately assess potential attack risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A flow chart of a trusted attack risk assessment method for a trusted DCS system provided in Example 1; Figure 2 A structural block diagram of a trusted attack risk assessment system for a trusted DCS system provided in Example 2; Figure 3 This is a structural block diagram of a trusted attack risk assessment device for a trusted DCS system provided in Example 3. DETAILED DESCRIPTION

[0017] In order to make the technical problems, technical solutions and beneficial effects solved by the present invention more clearly understood, the present invention is further described in detail in the following specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0018] Example 1 As attached Figure 1 As shown, this embodiment 1 provides a trusted attack risk assessment method for a trusted DCS system, comprising the following steps: Step 1: Obtain historical user operation record data of the system to be evaluated; wherein the historical user operation record data of the system to be evaluated includes log information and audit information of preset historical operation behaviors in the system to be evaluated.

[0019] Specifically, the process of obtaining the user historical operation record data of the system to be evaluated is as follows: Based on the TCP / IP protocol, the backend of the system to be evaluated is accessed, and the log information and audit information of the preset historical operation behaviors in the system to be evaluated are obtained through a predetermined data interface; wherein, the preset historical operation behaviors include login, operation commands, access resources and policy configuration; specifically, the operation type, operation user name, operation timestamp, operation object, operation result and operation execution process of the preset historical operation behaviors; the audit information of the preset historical operation behaviors includes the audit log and audit report of the preset operation behaviors; it should be noted that during the operation of the trusted DCS system, the user's login, operation commands, access resources and policy configuration behaviors will generate operation logs and audit information to record the response information generated when the trusted DCS system performs the above-mentioned operation behaviors.

[0020] Step 2: preprocess the user historical operation record data of the system to be evaluated to generate a preprocessed historical data set.

[0021] Specifically, the implementation process of preprocessing the user historical operation record data of the system to be evaluated is as follows: Step 21, perform data cleaning, standardization and feature extraction on the user historical operation record data of the system to be evaluated to obtain pre-processed user historical operation record data; wherein, the data cleaning process includes the steps of removing invalid or duplicate record data and filling missing values; the standardization process includes the steps of standardizing the data format or converting the data type to ensure the instruction and consistency of the input historical data; since the operation type, operation user name, operation object and operation execution process of the operation behavior are all string type data, the unique hot encoding technology is used to extract features during the feature extraction process.

[0022] Step 22: Convert the preprocessed user historical operation record data into a data format suitable for processing by a machine learning model to obtain a preprocessed historical data set.

[0023] Step 3: construct a credible attack risk assessment model; use the preprocessed historical data set to train the constructed credible attack risk assessment model to obtain a pre-trained credible attack risk assessment model.

[0024] In this embodiment 1, the trusted attack risk assessment model includes an input layer, a GRU gated neural network, a convolutional neural network and a fully connected output layer.

[0025] The input layer is used to read input features from a preprocessed historical data set or a preprocessed real-time data set; wherein the input features are a three-dimensional matrix, and the three-dimensional matrix includes a time step dimension, a sequence dimension and a time point dimension; specifically, the input features of each time step dimension include a sequence of a preset length; preferably, the sequence of the preset length is specifically a sequence of a length of 1000; the input features of each sequence dimension include a number of user operation record data before the current time point; preferably, the input features of each sequence dimension include 1000 user operation record data before the current time point; wherein each user operation record data is regarded as a time point; the input features of each time point dimension are input feature vectors of a preset length, and the input feature vectors of the preset length include the operation type of the operation behavior, the operation user name, the operation timestamp, the operation object, the operation result and the operation execution process.

[0026] The GRU gated neural network is used to capture information in a longer sequence; specifically, it is used to capture abnormal events with time correlation; for example, anomalies that may be caused by a series of discontinuous operating behaviors on a time series; preferably, the GRU gated neural network includes 128 GRU units; wherein, the GRU gated neural network is used to receive the data output by the input layer, with an input matrix of the shape of (sequence length, feature dimension) and an output feature vector of length 128; wherein, sequence length is the sequence length, and feature dimension is the feature dimension.

[0027] The convolutional neural network is used to capture anomalies that may be caused by a group of operating behaviors in a short period of time; wherein the convolutional neural network is used to receive the data output by the input layer, with the input shape being a (sequence length, feature dimension) type matrix; the convolutional layer of the convolutional neural network is set with 64 filters, the convolution kernel size is 3, the activation function is ReLU, and the maximum pooling method is selected; the output length of the convolutional neural network is a feature vector of N; wherein N depends on the configuration result of the network parameters of the convolutional neural network.

[0028] The fully connected output layer is used to output the risk level value, and obtain the trusted attack risk assessment result of the system to be assessed according to the preset risk level range; specifically, the fully connected output layer takes the feature vector output by the GRU gated neural network and the convolutional neural network as input, obtains a vector with a length of 128+N through a vector splicing algorithm, and finally calculates the risk level value according to the vector with a length of 128+N; the risk level value is floating point data, and the preset risk level range includes safe level, low risk level, medium risk level, high risk level and dangerous level; wherein the risk level value range of the safe level is (0, 0.2), the risk level value range of the low risk level is (0.2, 0.4), the risk level value range of the medium risk level is (0.4, 0.6), the risk level value range of the high risk level is (0.6, 0.8), and the risk level value range of the dangerous level is (0.8, 1.0).

[0029] In this embodiment 1, the process of training the constructed trusted attack risk assessment model using the preprocessed historical data set to obtain the pre-trained trusted attack risk assessment model is as follows: The preprocessed historical data set is divided into a training set and a test set; the constructed trusted attack risk assessment model is trained using the training set to adjust the preset model parameters until the loss is continuously reduced to below 1e-4; wherein the preset model parameters include a learning rate and a batch size; thereafter, the performance of the trained model on unseen data is evaluated using the test set to ensure that a model with optimal model parameters is obtained through training, and a pre-trained trusted attack risk assessment model is output; during the model training process, the loss and accuracy of the test set are calculated at the end of each training to monitor the learning effect of the model.

[0030] It should be noted that during the operation of the model, the preset data interface with the trusted server in the trusted DCS system can be used to read the user's annotations on the operation logs and audit information, and the logs and audit alarm information can be annotated on the trusted management platform. The annotated logs and audit alarm information can be used to fine-tune the trusted attack risk assessment model to ensure the optimal model. Or, when a large number of log and audit information are updated, a re-learning function is performed to ensure that the model is optimal; specifically, all existing log and audit information in the trusted server is obtained and input into the trusted attack risk assessment model for re-training.

[0031] Step 4: Obtain the real-time user operation record data of the system to be evaluated; wherein the real-time user operation record data of the system to be evaluated includes the log information and audit information of the preset real-time operation behavior in the system to be evaluated. Specifically, the preset real-time operation behavior includes login, operation command, access resource and policy configuration; the log information of the preset real-time operation behavior includes the operation type, operation user name, operation timestamp, operation object, operation result and operation execution process of the preset real-time operation behavior; the audit information of the preset real-time operation behavior includes the audit log and audit report of the preset real-time operation behavior.

[0032] It should be noted that the process of obtaining the real-time user operation record data of the system to be evaluated is the same as the process of obtaining the user historical operation record data of the system to be evaluated in the above step 1, and will not be repeated here.

[0033] Step 5: Preprocess the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set. The process of preprocessing the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set is as follows: Performing data cleaning, standardization and feature extraction on the real-time user operation record data of the system to be evaluated to obtain pre-processed real-time user operation record data; wherein, during the feature extraction process, a unique hot encoding technique is used to extract features; The preprocessed user real-time operation record data is converted into a data format suitable for processing by a machine learning model to obtain a preprocessed real-time data set.

[0034] Step 6: Input the preprocessed real-time data set into the pre-trained trusted attack risk assessment model, and output a trusted attack risk assessment result of the system to be assessed.

[0035] Step 7: Display the trusted attack risk assessment result of the system to be evaluated. If the trusted attack risk assessment result of the system to be evaluated is of medium risk level or above, while displaying the trusted attack risk assessment result of the system to be evaluated, a preset alarm signal is output; preferably, the preset alarm signal includes an alarm flashing light and a language reminder.

[0036] The trusted attack risk assessment method for a trusted DCS system described in Example 1 extracts risk features from the operation logs and audits of users and systems for automatic and intelligent risk warnings; wherein, a GRU network is used to process sequence data to capture abnormal events with time correlation, and the dependencies between user operations can be captured; a convolutional neural network is used to capture anomalies that may be caused by a group of operations in a relatively short period of time, and spatial features in user operation record data are captured, which effectively improves the efficiency of operation and maintenance personnel in reviewing logs and audits, and provides more acute and accurate risk identification capabilities.

[0037] Example 2 As attached Figure 2 As shown, this embodiment 2 provides a trusted attack risk assessment system for a trusted DCS system, including a historical data acquisition module, a historical data processing module, a model training module, a real-time data acquisition module, a real-time data processing module, a risk assessment module and an assessment result display module.

[0038] A historical data acquisition module is used to acquire the user historical operation record data of the system to be evaluated; wherein the user historical operation record data of the system to be evaluated includes the log information and audit information of the preset historical operation behavior in the system to be evaluated. A historical data processing module is used to pre-process the user historical operation record data of the system to be evaluated to generate a pre-processed historical data set. A model training module is used to construct a trusted attack risk assessment model; the constructed trusted attack risk assessment model is trained using the pre-processed historical data set to obtain a pre-trained trusted attack risk assessment model. A real-time data acquisition module is used to acquire the user real-time operation record data of the system to be evaluated; wherein the user real-time operation record data of the system to be evaluated includes the log information and audit information of the preset real-time operation behavior in the system to be evaluated. A real-time data processing module is used to pre-process the user real-time operation record data of the system to be evaluated to generate a pre-processed real-time data set. A risk assessment module is used to input the pre-processed real-time data set into the pre-trained trusted attack risk assessment model, and output the trusted attack risk assessment result of the system to be evaluated. An assessment result display module is used to display the trusted attack risk assessment result of the system to be evaluated.

[0039] Example 3 As attached Figure 3 As shown, this embodiment 3 provides a trusted attack risk assessment device for a trusted DCS system, including: a memory for storing a computer program; a processor for implementing the steps of a trusted attack risk assessment method for a trusted DCS system when executing the computer program.

[0040] When the processor executes the computer program, the steps of the above-mentioned trusted attack risk assessment method for a trusted DCS system are implemented; for example: Obtain user historical operation record data of the system to be evaluated; wherein the user historical operation record data of the system to be evaluated includes log information and audit information of preset historical operation behaviors in the system to be evaluated; preprocess the user historical operation record data of the system to be evaluated to generate a preprocessed historical data set; construct a trusted attack risk assessment model; use the preprocessed historical data set to train the constructed trusted attack risk assessment model to obtain a pre-trained trusted attack risk assessment model; obtain user real-time operation record data of the system to be evaluated; wherein the user real-time operation record data of the system to be evaluated includes log information and audit information of preset real-time operation behaviors in the system to be evaluated; preprocess the user real-time operation record data of the system to be evaluated to generate a preprocessed real-time data set; input the preprocessed real-time data set into the pre-trained trusted attack risk assessment model, and output a trusted attack risk assessment result of the system to be evaluated; and display the trusted attack risk assessment result of the system to be evaluated.

[0041] Alternatively, when the processor executes the computer program, the functions of each module in the above-mentioned trusted attack risk assessment system for a trusted DCS system are implemented, for example: A historical data acquisition module is used to acquire the user historical operation record data of the system to be evaluated; wherein the user historical operation record data of the system to be evaluated includes the log information and audit information of the preset historical operation behavior in the system to be evaluated. A historical data processing module is used to pre-process the user historical operation record data of the system to be evaluated to generate a pre-processed historical data set. A model training module is used to construct a trusted attack risk assessment model; the constructed trusted attack risk assessment model is trained using the pre-processed historical data set to obtain a pre-trained trusted attack risk assessment model. A real-time data acquisition module is used to acquire the user real-time operation record data of the system to be evaluated; wherein the user real-time operation record data of the system to be evaluated includes the log information and audit information of the preset real-time operation behavior in the system to be evaluated. A real-time data processing module is used to pre-process the user real-time operation record data of the system to be evaluated to generate a pre-processed real-time data set. A risk assessment module is used to input the pre-processed real-time data set into the pre-trained trusted attack risk assessment model, and output the trusted attack risk assessment result of the system to be evaluated. An assessment result display module is used to display the trusted attack risk assessment result of the system to be evaluated.

[0042] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of completing preset functions, and the instruction segments are used to describe the execution process of the computer program in the trusted attack risk assessment device for a trusted DCS system.

[0043] The trusted attack risk assessment device for a trusted DCS system may be a computing device such as a desktop computer, a notebook, a PDA, and a cloud server. The trusted attack risk assessment device for a trusted DCS system may include, but is not limited to, a processor and a memory. Those skilled in the art will appreciate that the above is an example of a trusted attack risk assessment device for a trusted DCS system and does not constitute a limitation on the trusted attack risk assessment device for a trusted DCS system. It may include more components than the above, or a combination of certain components, or different components. For example, the trusted attack risk assessment device for a trusted DCS system may also include input and output devices, network access devices, buses, etc.

[0044] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The processor is the control center of the trusted attack risk assessment device for a trusted DCS system, and uses various interfaces and lines to connect various parts of the entire trusted attack risk assessment device for a trusted DCS system.

[0045] The memory may be used to store the computer program and / or module, and the processor implements various functions of the trusted attack risk assessment device for a trusted DCS system by running or executing the computer program and / or module stored in the memory and calling the data stored in the memory.

[0046] The memory may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (SmartMediaCard, SMC), a secure digital (SecureDigital, SD) card, a flash card (FlashCard), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0047] Example 4 This embodiment 4 also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the trusted attack risk assessment method for a trusted DCS system are implemented.

[0048] If the module / unit integrated in the trusted attack risk assessment system for a trusted DCS system is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.

[0049] Based on such understanding, the present invention implements all or part of the processes in the above-mentioned trusted attack risk assessment method for a trusted DCS system, and can also be completed by instructing related hardware through a computer program, and the computer program can be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above-mentioned trusted attack risk assessment method for a trusted DCS system can be implemented. Wherein, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or preset intermediate form, etc.

[0050] The computer-readable storage medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc.

[0051] It should be noted that the content contained in the computer-readable storage medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable storage media do not include electrical carrier signals and telecommunication signals.

[0052] Example 5 This embodiment 5 provides a computer product, which includes a computer program, which is stored in a computer-readable storage medium; a processor of a trusted attack risk assessment device for a trusted DCS system reads the computer program from the computer-readable storage medium, and the processor executes the computer program, so that the trusted attack risk assessment device for a trusted DCS system can execute the trusted attack risk assessment method for a trusted DCS system described in embodiment 1, which will not be repeated here.

[0053] It should be noted that a person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods.

[0054] The trusted attack risk assessment method for a trusted DCS system described in the present invention extracts trusted attack risk features from the operation logs and audit information of users and systems through a trusted attack risk assessment model based on a GRU gated neural network and a convolutional neural network, so as to realize automatic and intelligent trusted attack risk warning, effectively improve the processing efficiency of log review and audit by operation and maintenance personnel, and provide more acute and accurate risk identification capabilities.

[0055] The above embodiment is only one of the implementation methods that can realize the technical solution of the present invention. The scope of protection claimed by the present invention is not limited only to this embodiment, but also includes changes, replacements and other implementation methods that can be easily thought of by any technician familiar with the technical field within the technical scope disclosed by the present invention.

Claims

1. A trusted attack risk assessment method for a trusted DCS system, characterized in that: include: Acquire real-time user operation record data of the system to be evaluated; wherein the real-time user operation record data of the system to be evaluated includes log information and audit information of preset real-time operation behaviors in the system to be evaluated; Preprocessing the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set; The preprocessed real-time data set is input into a pre-trained trusted attack risk assessment model, and a trusted attack risk assessment result of the system to be evaluated is output; wherein the pre-trained trusted attack risk assessment model includes an input layer, a GRU gated neural network, a convolutional neural network and a fully connected output layer.

2. The method for assessing the risk of a trusted attack on a user-trusted DCS system according to claim 1, characterized in that: The preset real-time operation behaviors include login, operation commands, access resources and policy configuration; The log information of the preset real-time operation behavior includes the operation type, operation user name, operation timestamp, operation object, operation result and operation execution process of the preset real-time operation behavior; The audit information of the preset real-time operation behavior includes an audit log and an audit report of the preset real-time operation behavior.

3. A trusted attack risk assessment method for a trusted DCS system according to claim 1, characterized in that: The process of preprocessing the real-time user operation record data of the system to be evaluated to generate a preprocessed real-time data set is as follows: Performing data cleaning, standardization and feature extraction on the real-time user operation record data of the system to be evaluated to obtain pre-processed real-time user operation record data; wherein, during the feature extraction process, a unique hot encoding technique is used to extract features; The preprocessed user real-time operation record data is converted into a data format suitable for processing by a machine learning model to obtain a preprocessed real-time data set.

4. A trusted attack risk assessment method for a trusted DCS system according to claim 2, characterized in that: The input layer is used to read input features from the preprocessed real-time data set; wherein the input features are a three-dimensional matrix, and the three-dimensional matrix includes a time step dimension, a sequence dimension, and a time point dimension; Specifically, the input features of each time step dimension include a sequence of preset length; the input features of each sequence dimension include a number of user operation record data before the current time point; wherein each user operation record data is regarded as a time point; the input features of each time point dimension are input feature vectors of preset length, and the input feature vectors of preset length include the operation type of the operation behavior, the operation user name, the operation timestamp, the operation object, the operation result and the operation execution process.

5. The trusted attack risk assessment method for a trusted DCS system according to claim 1, characterized in that: The GRU gated neural network includes 128 GRU units, wherein each GRU unit includes a reset gate and an update gate; the convolutional layer of the convolutional neural network is set with 64 filters, the convolution kernel size is 3, and the maximum pooling method is selected.

6. A trusted attack risk assessment method for a trusted DCS system according to claim 1, characterized in that: The fully connected output layer is used to output a risk level value and obtain a trusted attack risk assessment result of the system to be assessed according to a preset risk level interval; wherein the risk level value is a floating point data.

7. A trusted attack risk assessment system for a trusted DCS system, characterized in that: include: A real-time data acquisition module is used to acquire real-time user operation record data of the system to be evaluated; wherein the real-time user operation record data of the system to be evaluated includes log information and audit information of preset real-time operation behaviors in the system to be evaluated; A real-time data processing module is used to pre-process the real-time operation record data of the user of the system to be evaluated to generate a pre-processed real-time data set; The risk assessment module is used to input the preprocessed real-time data set into a pre-trained trusted attack risk assessment model, and output a trusted attack risk assessment result of the system to be evaluated; wherein the pre-trained trusted attack risk assessment model includes an input layer, a GRU gated neural network, a convolutional neural network and a fully connected output layer.

8. A trusted attack risk assessment device for a trusted DCS system, characterized in that: include: a processor suitable for executing a computer program; A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by the processor, the trusted attack risk assessment method for a trusted DCS system according to any one of claims 1 to 6 is executed.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the trusted attack risk assessment method for a trusted DCS system is implemented as described in any one of claims 1 to 6.

10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the trusted attack risk assessment method for a trusted DCS system according to any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Trusted attack risk assessment method for trusted DCS system and related apparatus

    WO2026166021A1