Industrial control system security situation assessment and prediction method

By using a combination of long-term and short-term memory network with attention mechanism and subjective objective evaluation in industrial control systems, security events are extracted and evaluated, and the problems of difficulty in exploring safety hazard characteristics and relying on subjective experience in the prior art are solved, and more efficient security situation evaluation and prediction are achieved.

CN120012091APending Publication Date: 2025-05-16韩永承
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311531902.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The safety situation evaluation and prediction methods of existing industrial control systems have problems such as difficulty in exploring safety hazard characteristics and the safety situation evaluation is too reliant on subjective experience.

Method used

A long-term and short-term memory network with attention mechanism is used to establish a security event extraction model, a security situation evaluation model is combined with a combination of subjective quantitative empowerment and objective quantitative empowerment, and a security situation prediction model is established using gate cycle units and particle swarm optimization algorithm.

Benefits of technology

It improves the ability to discover safety hazards in industrial control systems, reduces the dependence of evaluation results on subjective experience, and achieves a more scientific and reasonable safety situation assessment and prediction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012091A_ABST
    Figure CN120012091A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of industrial control system security, and particularly discloses an industrial control system security situation assessment and prediction method, which comprises the following steps: establishing a security event extraction model in an industrial control system, extracting security events in the industrial control system, and calculating the security situation of the industrial control system; establishing a security situation assessment model combining subjective quantitative weighting and objective quantitative weighting, performing assessment weighting on the extracted security event, calculating the security situation variable quantity of the industrial control system caused by the security event and the current security situation value of the industrial control system, establishing a security situation prediction model of the industrial control system, and predicting the security situation of the industrial control system. And predicting the security situation of the future industrial control system. Compared with the prior art, the method has high security event mining capability, can effectively extract security events in an industrial control system from complex multi-dimensional industrial control data, can reduce the influence of personal knowledge limitation in a traditional security assessment method, is more scientific and reasonable in security situation assessment, and has popularization and application values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field:

[0001] The present invention relates to the field of industrial control system security, and in particular to a method for assessing and predicting the security situation of an industrial control system. Background technology:

[0002] With the continuous development of technology, industrial control systems have gradually expanded their application scenarios and scale in various industries. The integrated interconnection and functional expansion of some industrial control systems have brought many challenges to the security of industrial control systems. Security problems in industrial control systems will not only affect the production of enterprises, but may also threaten the safety of people's lives and property and national security.

[0003] At present, for the security situation assessment and prediction of industrial control systems, the method of abnormal behavior detection is generally used to discover security risks. By analyzing factors such as the assets in the system, the threats faced by the system, and the vulnerabilities of the system, the security situation can be assessed and predicted.

[0004] At present, the volume of data in industrial control systems is growing explosively, and the attack methods against industrial control systems are becoming more and more diverse. When processing massive multi-dimensional industrial control data, traditional security analysis methods have limitations such as difficulty in discovering the characteristics of security risks and over-reliance on subjective experience in security situation evaluation. Therefore, how to achieve security situation assessment and prediction of industrial control systems is an urgent problem to be solved. Summary of the invention:

[0005] In order to solve the problems in the existing security situation assessment and prediction of industrial control systems, such as the difficulty in discovering the characteristics of security risks and the over-reliance on subjective experience in security situation evaluation, the present invention proposes a security situation assessment and prediction method for industrial control systems.

[0006] The present invention proposes a method for assessing and predicting the security situation of an industrial control system, which is characterized by: the method has the following specific steps:

[0007] Step 1: Using the long short-term memory network with attention mechanism, a security event extraction model in industrial control systems is established to perform feature learning on industrial control data. The industrial control data to be detected is input into the trained model to extract security events in the industrial control system.

[0008] Step 2: Establish an industrial control system security situation assessment model that combines subjective quantitative weighting with objective quantitative weighting. Use this model to perform weighted assessment on the security events extracted in step 1, and calculate the change in the industrial control system security situation caused by the security event and the current industrial control system security situation value.

[0009] Step 3: Use the gated recurrent unit to establish an industrial control system security situation prediction model, learn the historical security situation values ​​of the industrial control system, use the particle swarm optimization algorithm to optimize the model parameters, input the industrial control system security situation time series into the optimized and trained model, and predict the future industrial control system security situation.

[0010] According to the method for assessing and predicting security situation of industrial control systems according to claim 1, the specific steps of the summarized step 1 are as follows:

[0011] Step 101: Processing industrial control data, using deletion and completion methods to process values ​​that deviate too much from the normal range and missing values ​​in the industrial control data. Standardize industrial control data from different sources to increase the comparability between various types of data.

[0012] Step 102: Data division, dividing the industrial control data processed in step 101 into a training set and a validation set.

[0013] Step 103: Building a feature extraction model, using a long short-term memory network with an attention mechanism to build an industrial control data feature extraction model.

[0014] Step 104: Model training, selecting a reasonable activation function, loss function, and hyperparameters for the feature extraction model, and using the data set divided in step 102 for model training.

[0015] Step 105: Security event extraction, using the trained model to extract security events from new industrial control data.

[0016] According to the industrial control system security situation assessment and prediction method of claim 1, the specific steps of the summarized step 2 are as follows:

[0017] Step 201: Establish a subjective quantitative weighting model consisting of a "security situation layer", a "security requirement layer" and a "security event layer". Compare and rank the elements at the same level based on their security impact, construct a judgment matrix, and calculate the subjective quantitative weight of each element's impact on the security situation.

[0018] Step 202: Decompose the functional components in the industrial control system, determine the functional components affected by the security incident, and calculate the objective quantitative weight of the impact of each security incident on the security situation of the industrial control system.

[0019] Step 203: Calculate the comprehensive weight of the security event based on the subjective quantization weight and the objective quantization weight, and then calculate the industrial control system security situation value, and divide the industrial control system security situation level.

[0020] According to the method for assessing and predicting security situation of industrial control systems according to claim 1, the specific steps of the summarized step 3 are as follows:

[0021] Step 301: Establish an industrial control system security situation prediction model based on a gate cycle unit, use part of the historical security situation data to train the model, and use the particle swarm optimization algorithm to optimize the parameters of the prediction model to obtain an optimized industrial control system security situation prediction model.

[0022] Step 302: Input the industrial control system security situation sequence into the optimized industrial control system security situation prediction model to obtain a security situation prediction value.

[0023] The present invention provides an industrial control system security situation assessment and prediction method, which has the following advantages and positive effects:

[0024] 1. The present invention has a high ability to discover potential safety hazards and can timely discover safety incidents in industrial control systems in complex multi-dimensional industrial control data.

[0025] 2. The present invention adopts a combination of subjective and objective evaluation to establish an industrial control system security situation assessment model, which reduces the influence of personal bias and knowledge limitations in traditional evaluation methods, and the evaluation results are more scientific and reasonable. Description of the drawings:

[0026] Figure 1 This is a structural diagram of the security event extraction model in an embodiment of the present invention.

[0027] Figure 2 This is a diagram showing the security event extraction effect in an embodiment of the present invention.

[0028] Figure 3 This is a diagram for dividing the security assessment object area in an embodiment of the present invention.

[0029] Figure 4 It is a hierarchical structure diagram of the security assessment model in an embodiment of the present invention.

[0030] Figure 5 This is a diagram showing the security situation prediction effect in an embodiment of the present invention.

[0031] Figure 6 The figure is a flow chart of the method of the present invention. Specific implementation method:

[0032] The present invention proposes a method for assessing and predicting the security situation of an industrial control system. In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution used in the present invention will be described clearly and completely in combination with the accompanying drawings in the present invention. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0033] An embodiment of the present invention provides a method for assessing and predicting the security situation of an industrial control system, comprising:

[0034] Step 1: Using the long short-term memory network with attention mechanism, a security event extraction model in industrial control systems is established to perform feature learning on industrial control data. The industrial control data to be detected is input into the trained model to extract security events in the industrial control system.

[0035] Step 101: Processing industrial control data, using deletion and completion methods to process values ​​that deviate too much from the normal range and missing values ​​in the industrial control data. Standardize industrial control data from different sources to increase the comparability between various types of data.

[0036] The data set used in this embodiment is the power system attack data set of Mississippi State University. The fixed value interpolation method is used to replace the infinite value in the data set with a larger fixed value that is 3 orders of magnitude higher than the maximum value of the same type of data. The data of different dimensions in the data set are standardized using Z-Score standardization to increase the comparability between different types of data.

[0037] Step 102: Data division, dividing the industrial control data processed in step 101 into a training set and a validation set.

[0038] In this embodiment, the preprocessed data is divided into a training set and a test set to provide data support for the long short-term memory network model training. In this paper, the training set and the test set are divided according to a ratio of 9:1.

[0039] Step 103: Building a feature extraction model, using a long short-term memory network with an attention mechanism to build an industrial control data feature extraction model.

[0040] In this embodiment, a long short-term memory network with an attention mechanism is used to build a security event extraction model. Figure 1 Give the structure of the model.

[0041] Step 104: Model training, selecting a reasonable activation function, loss function, and hyperparameters for the feature extraction model, and using the data set divided in step 102 for model training.

[0042] In this embodiment, the activation function of the feature extraction model used is "Adam", the loss function is "cross entropy loss function", the batch size is 128, the number of iterations is 50, and the split training set and test set are used for model training.

[0043] Step 105: Security event extraction, using the trained model to extract security events from new industrial control data.

[0044] In this embodiment, the trained model is used to extract security events from 3649 sets of data. The data contains industrial control data of normal working scenarios and industrial control data of 36 types of security event scenarios. The number of each type of security event is basically the same. Figure 2 The security event extraction results are given.

[0045] Step 2: Establish an industrial control system security situation assessment model that combines subjective quantitative weighting with objective quantitative weighting. Use this model to perform weighted assessment on the security events extracted in step 1, and calculate the change in the industrial control system security situation caused by the security event and the current industrial control system security situation value.

[0046] Step 201: Establish a subjective quantitative weighting model consisting of a "security situation layer", a "security requirement layer" and a "security event layer". Compare and rank the elements at the same level based on their security impact, construct a judgment matrix, and calculate the subjective quantitative weight of each element's impact on the security situation.

[0047] The evaluation object of this embodiment has a high degree of basic structural repeatability in terms of physical structure. Since the more elements involved in the comparison when constructing the judgment matrix, the more likely it is to bring about a greater subjective bias, in this embodiment, the evaluation object is divided into four areas for security situation assessment, and finally a combined calculation is performed to obtain the security situation of the industrial control system. Figure 3 The scope of regional division is given. A three-layer subjective quantitative model of "security situation layer", "security requirement layer" and "security event layer" is established for each region. The task goal of the security situation layer is to evaluate the security situation. The security requirement layer includes three elements: "field equipment security requirements", "field control security requirements" and "process monitoring security requirements". The security event layer corresponds to different security events. Figure 4 A specific hierarchical structure is given. In each layer, the safety impact importance of each element is compared, and the comparison results are assigned values ​​to construct a judgment matrix.

[0048] Taking the construction of the judgment matrix for the security situation assessment of the R1 region as an example, we first construct the judgment matrix of the “security demand layer” to the “security situation layer”, as shown in Table 1.

[0049] Table 1R1 Regional Security Demand Layer Judgment Matrix

[0050]

[0051]

[0052] Considering the impact of security incidents on "field equipment security requirements", "field control security requirements" and "process monitoring security requirements", a judgment matrix of the "security incident layer" for each element of the "security requirements layer" is constructed, as shown in Table 2-4.

[0053] Table 2 R1 area field equipment safety demand judgment matrix

[0054]

[0055] Table 3 R1 area field control safety demand judgment matrix

[0056]

[0057] Table 4 R1 area process monitoring safety demand judgment matrix

[0058]

[0059] The judgment matrix established in Tables 2 to 4 is calculated using the sum-product method. The characteristic vector of the security situation in the R1 area is [0.2, 0.4, 0.4], and the maximum characteristic root is 3; the characteristic vector of the field equipment safety demand is [0.1942, 0.1082, 0.0639, 0.6336], and the maximum characteristic root is: 4.1068; the characteristic vector of the field control safety demand is [0.04168875, 0 .0261,0.0166,0.2093,0.1654,0.0276,0.0195,0.0146,0.1845,0.1294,0.1654], the largest characteristic root is: 11.4049; the eigenvector of process monitoring safety requirements is [0.5389941,0.16373107,0.29727483], and the largest characteristic root is: 3.0088.

[0060] Substitute the weights of the security requirement layer and the security event layer into W Si =∑ j=1 W Qj *W Ei By performing weighted calculation, we can obtain the subjective quantitative weight of each security event on the industrial control system. Among them, the weight of the security demand layer is W Qj , the security event layer weight is W Ei , the subjective quantitative weight W of security event i Si The calculation results are shown in Table 5.

[0061] Table 5 Comprehensive weight of security events in R1 region

[0062]

[0063] Step 202: Decompose the functional components in the industrial control system, determine the functional components affected by the security incident, and calculate the objective quantitative weight of the impact of each security incident on the security situation of the industrial control system.

[0064] Analyzing the functional components of the R1 area in this embodiment, the R1 area mainly realizes the power transmission and disconnection functions, wherein the intelligent electronic device realizes real-time data monitoring and control command issuance, the circuit breaker realizes the switch function of closing or disconnecting the current in the loop, and the transmission line realizes the power transmission function. There are three main functional components in the R1 area, namely, the intelligent electronic device R1, the circuit breaker BR1, and the transmission line L1.

[0065] The number of functional components affected by security event i is recorded as M i , count the number of functional components affected by all currently known security incidents and record it as M SUM The ratio of the number of functional components affected by security event i to the number of functional components affected by all known security events is used to define the functional component impact weight of security event i, which is expressed as:

[0066]

[0067] Step 203: Calculate the comprehensive weight of the security event based on the subjective quantization weight and the objective quantization weight, and then calculate the industrial control system security situation value, and divide the industrial control system security situation level.

[0068] In this embodiment, W Si is the combined weight of subjective quantitative weighting, W Oi is the objective quantitative weighting of the functional component impact weight, and the comprehensive weight of security event i is W i * , substitute the subjective quantitative weight and the objective quantitative weight into The comprehensive weight of each security event can be obtained, and the results are shown in Table 6.

[0069] Table 6 R1 regional security situation combined weights

[0070]

[0071] In the R2, R3, and R4 regions, the combined weights of security events are calculated according to the above method. When no security events occur in the industrial control system, the security situation value of the industrial control system is 1. When a security event is extracted, Q is recorded as the change in the security situation of the industrial control system, as shown in the following formula, where n represents the number of regions that extract the same security event at the same time.

[0072]

[0073] When a security event is extracted, the security situation value of the industrial control system H = 1-Q. In order to avoid uneven distribution of the system security situation value and the failure to clearly reflect the trend of system security situation changes, H is normalized using the known historical security situation value H. * =(HH MIN ) / (1-H MIN ), where H MIN is the minimum value of the known industrial control system security situation. The calculation results are shown in Table 7.

[0074] Table 7 Industrial control system security status value

[0075]

[0076]

[0077] The security situation of industrial control systems is divided into levels according to the normalized security situation value. Level 1, industrial control system security situation value 0.9-1; Level 2, industrial control system security situation value 0.8-0.9; Level 3, industrial control system security situation value 0.7-0.8; Level 4, industrial control system security situation value 0.6-0.7; Level 5, industrial control system security situation value 0-0.6.

[0078] Step 3: Use the gated recurrent unit to establish an industrial control system security situation prediction model, learn the historical security situation values ​​of the industrial control system, use the particle swarm optimization algorithm to optimize the model parameters, input the industrial control system security situation time series into the optimized and trained model, and predict the future industrial control system security situation.

[0079] Step 301: Establish an industrial control system security situation prediction model based on a gate cycle unit, use part of the historical security situation data to train the model, and use the particle swarm optimization algorithm to optimize the parameters of the prediction model to obtain an optimized industrial control system security situation prediction model.

[0080] In this embodiment, the security situation values ​​of the industrial control system at 9 consecutive moments are used as a set of inputs to predict the security situation value of the industrial control system at the next moment, as shown in Table 8.

[0081] Table 8 Prediction model input data

[0082]

[0083]

[0084] During model training, 552 historical data were used for model training, the mean square error was used as the loss function, the optimizer was "Adam", the number of iterations was 50, a gated recurrent unit prediction model with two hidden layers was constructed, and the particle swarm optimization model parameters were used to obtain 60 neurons in the first hidden layer, 60 neurons in the second hidden layer, and a batch size of 16.

[0085] Step 302: Input the industrial control system security situation sequence into the optimized industrial control system security situation prediction model to obtain a security situation prediction value.

[0086] In this embodiment, the trained prediction model is used to predict 180 pieces of data. Figure 5 The predicted results and true values ​​are given.

Claims

1. A method for assessing and predicting security situation of industrial control systems, characterized by: The specific steps of this method are as follows: Step 1: Using the long short-term memory network with attention mechanism, a security event extraction model in industrial control systems is established to perform feature learning on industrial control data. The industrial control data to be detected is input into the trained model to extract security events in the industrial control system. Step 2: Establish an industrial control system security situation assessment model that combines subjective quantitative weighting with objective quantitative weighting. Use this model to perform weighted assessment on the security events extracted in step 1, and calculate the change in the industrial control system security situation caused by the security event and the current industrial control system security situation value. Step 3: Use the gated recurrent unit to establish an industrial control system security situation prediction model, learn the historical security situation values ​​of the industrial control system, use the particle swarm optimization algorithm to optimize the model parameters, input the industrial control system security situation time series into the optimized and trained model, and predict the future industrial control system security situation.

2. The method for assessing and predicting the security situation of an industrial control system according to claim 1 is characterized in that The specific steps of step 1 reviewed are as follows: Step 101: Processing industrial control data, using deletion and completion methods to process values ​​that deviate too much from the normal range and missing values ​​in the industrial control data. Standardize industrial control data from different sources to increase the comparability between various types of data. Step 102: Data division, dividing the industrial control data processed in step 101 into a training set and a validation set. Step 103: Building a feature extraction model, using a long short-term memory network with an attention mechanism to build an industrial control data feature extraction model. Step 104: Model training, selecting a reasonable activation function, loss function, and hyperparameters for the neural network model, and using the data set divided in step 102 for model training. Step 105: Security event extraction, using the trained model to extract security events from new industrial control data.

3. The method for assessing and predicting the security situation of an industrial control system according to claim 1 is characterized in that The specific steps of step 2 reviewed are as follows: Step 201: Establish a subjective quantitative weighting model consisting of a "security situation layer", a "security requirement layer", and a "security event layer". Compare and rank the elements at the same level based on their security impact, construct a judgment matrix, and calculate the subjective quantitative weight of each element's impact on the security situation. Step 202: Decompose the functional components in the industrial control system, determine the functional components affected by the security incident, and calculate the objective quantitative weight of the impact of each security incident on the security situation of the industrial control system. Step 203: Calculate the comprehensive weight of the security event based on the subjective quantization weight and the objective quantization weight, and then calculate the industrial control system security situation value, and divide the industrial control system security situation level.

4. The method for assessing and predicting the security situation of an industrial control system according to claim 1 is characterized in that The specific steps of step 3 reviewed are as follows: Step 301: Establish an industrial control system security situation prediction model based on a gate cycle unit, use part of the historical security situation data to train the model, and use the particle swarm optimization algorithm to optimize the parameters of the prediction model to obtain an optimized industrial control system security situation prediction model. Step 302: Input the industrial control system security situation sequence into the optimized industrial control system security situation prediction model to obtain a security situation prediction value.