Water plant network security early warning method and system

By collecting and analyzing the historical data and real-time traffic of the water production plant network, establishing a network behavior baseline and generating vulnerability threat values, the timely warning of the water production plant network security threat is solved, efficient security risk positioning and protection strategy deployment is achieved, and the stable operation of the network is ensured.

CN120017398AActive Publication Date: 2025-05-16HANGZHOU SHUIWU KONGGU GRP CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510239998.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-05-16
Estimated Expiration
2045-03-03

AI Technical Summary

Technical Problem

The water production plant network faces complex security threats. Traditional network security protection methods cannot detect potential security risks in a timely and accurate manner, resulting in slow response and difficulty in ensuring the stable operation of the network.

Method used

By collecting historical network data of the water production plant network, establishing a network behavior baseline, capturing protocol instruction sequences in real time and performing abnormal indicator analysis, synchronously monitoring network traffic to generate vulnerability threat values, weighted sum to generate weighted comprehensive values, generating warning levels based on the weighted comprehensive values ​​and deploying corresponding security protection strategies.

Benefits of technology

It has achieved comprehensive and meticulous monitoring of the water production plant network, accurately positioned potential security risks, provided unified quantitative standards, improved the efficiency of network security warning, effectively reduced network security risks, and ensured the stable and reliable operation of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017398A_ABST
    Figure CN120017398A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a water plant network security early warning method and system, and the method comprises the steps: collecting the historical network data of a water plant network; establishing a network behavior baseline of the water plant network based on the historical network data; capturing a protocol instruction sequence of the water plant network in real time, and performing abnormal index analysis on the protocol instruction sequence by using the network behavior baseline to obtain an abnormal network index of the water plant network; synchronously monitoring the network flow of the water plant network to obtain equipment flow data of the water plant network, and generating a vulnerability threat value of the water plant network based on the equipment flow data; performing weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; and generating an early warning level of the water plant network according to the weighted comprehensive value and a preset weighted threshold value, and performing security protection strategy deployment on the water plant network according to the early warning level. According to the invention, the efficiency of water plant network security early warning can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a network security early warning method and system for a water treatment plant. Background Art

[0002] With the widespread application of information technology, the security threats faced by water plant networks are becoming increasingly complex and diverse. Traditional network security protection methods are often based on rule matching or post-detection, which cannot detect potential security risks in a timely and accurate manner, resulting in slow response to network attacks and difficulty in ensuring the stable operation of water plant networks.

[0003] For example, some covert attacks may use abnormal protocol instruction interactions to penetrate the network without triggering conventional detection mechanisms; at the same time, abnormal fluctuations in network traffic may also indicate the existence of security vulnerabilities, but existing technologies make it difficult to accurately assess them. In addition, due to the lack of comprehensive analysis and quantitative evaluation of network behavior, there is a lack of unified standards for judging network security, making it difficult for network administrators to quickly and accurately understand the security level of the network and take effective protective measures in a timely manner. Therefore, how to improve the efficiency of network security early warning in water plants and promptly detect and respond to potential security threats has become an urgent problem to be solved. Summary of the invention

[0004] The present invention provides a water plant network security early warning method and system, the main purpose of which is to solve the problem of low efficiency in water plant network security early warning.

[0005] To achieve the above purpose, the present invention provides a water plant network security early warning method, comprising: Collecting historical network data of the water plant network, wherein the historical network data includes: user behavior data and program running status; Establishing a network behavior baseline of the water plant network based on the user behavior data and the program running status; Capturing the protocol instruction sequence of the water plant network in real time, performing abnormal index analysis on the protocol instruction sequence using the network behavior baseline, and obtaining an abnormal network index of the water plant network; Synchronously monitoring the network traffic of the water plant network to obtain device traffic data of the water plant network, and generating a vulnerability threat value of the water plant network based on the device traffic data; Performing weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; The early warning level of the water plant network is generated according to the weighted comprehensive value and a preset weighted threshold, and a security protection strategy is deployed for the water plant network according to the early warning level.

[0006] Optionally, the collecting of historical network data of the water plant network includes: Acquire user behavior data of the water plant network, wherein the user behavior data includes: operation records, login and logout times, and access resource paths of users in the water plant network; Collecting the program running status of the water plant network, wherein the program running status includes: the running time, CPU occupancy, memory usage and error log of each application program in the water plant network; The user behavior data and the program running status are aligned according to timestamps to generate a historical network data set of the water plant network.

[0007] Optionally, establishing a network behavior baseline of the water plant network based on the user behavior data and the program running status includes: Extracting access path features of the water plant network based on the user behavior data; Extracting the duration distribution characteristics of the water plant network based on the program running status; Performing parameter fitting on the duration distribution characteristics to obtain Weibull distribution parameters of the water plant network; The access path characteristics and the Weibull distribution parameters are integrated to generate a network behavior baseline of the water plant network.

[0008] Optionally, extracting access path features of the water plant network based on the user behavior data includes: Constructing a directed graph of the water plant network based on the access resource path in the user behavior data , where the nodes in the directed graph are Represents a resource, and the edges in the directed graph Indicates the jump relationship of the access path; Calculate the degree centrality of each node in the directed graph, select nodes whose degree centrality is higher than a preset degree centrality threshold as hot resources, and extract the shortest path between nodes to form a critical path; An access path feature of the water plant network is generated according to the critical path and the hot resources.

[0009] Optionally, extracting the duration distribution characteristics of the water plant network based on the program running state includes: A duration histogram and a duration cumulative distribution function of the water plant network are generated based on the running time of each application in the water plant network, wherein the duration cumulative distribution function is: in, is the cumulative distribution function of duration, is the total number of times the application has been run, is the index variable of the application running, The limit of measuring the length of a single run, is the indicator function, It is The duration of a single run of the application; The duration distribution characteristics of the water plant network are generated based on the duration histogram and the duration cumulative distribution function.

[0010] Optionally, the using the network behavior baseline to perform abnormal index analysis on the protocol instruction sequence to obtain an abnormal network index of the water plant network includes: Calculating the probability distribution of the protocol instructions in the protocol instruction sequence one by one; The dispersion of the protocol instructions is quantified based on the probability distribution and a preset Shannon entropy algorithm, wherein the preset Shannon entropy algorithm is as follows: in, is the decentralization of the protocol instructions, is the number of protocol instruction types, is the identifier of the protocol instruction in the protocol instruction sequence, is determined based on the probability distribution The probability of occurrence of protocol-like instructions; The Shannon entropy is numerically compared with the historical entropy value in the network behavior baseline, and the entropy deviation of the Shannon entropy is determined based on the comparison result of the numerical comparison, wherein the calculation formula of the entropy deviation is as follows: in, is the entropy deviation of the Shannon entropy, is the Shannon entropy, is the historical entropy value in the network behavior baseline; Perform abnormal protocol screening on the protocol instruction sequence according to the entropy deviation to obtain abnormal protocols of the water plant network; Aggregate the entropy deviations of all the abnormal protocols to generate an abnormal network index of the water plant network.

[0011] Optionally, generating the vulnerability threat value of the water plant network based on the device flow data includes: Identify redundant devices in the water plant network based on the device flow data, and configure threat coefficient attenuation factors for the redundant devices; The flow deviation of the water plant network is generated based on the equipment flow data and a preset flow deviation algorithm, wherein the preset flow deviation algorithm is: in, is the flow deviation of the waterworks network, is the inbound traffic in the device traffic data, is the historical mean of inbound traffic, is the outbound traffic in the device traffic data, is the historical mean of outbound traffic, is the peak flow rate in the device flow data, is the historical average of the peak traffic volume, is the historical standard deviation of inbound traffic, is the historical standard deviation of outbound traffic; A vulnerability threat value of the water plant network is generated based on the flow deviation and the threat coefficient attenuation factor.

[0012] Optionally, generating the warning level of the water plant network according to the weighted comprehensive value and a preset weighted threshold includes: The weighted comprehensive value Compare with the preset weighted threshold, where the preset weighted threshold is and ,and ; when When the first level warning is triggered, When the alarm is triggered, the second level warning is triggered.

[0013] Optionally, the deploying a security protection strategy for the water plant network according to the warning level includes: The security protection strategy of the water plant network is adjusted according to the warning level, wherein the security protection strategy is: when a level 1 warning is triggered, abnormal devices in the water plant network are isolated and traffic cleaning is enabled; when a level 2 warning is triggered, access to non-critical resources in the water plant network is restricted and log monitoring is enhanced; The warning level and the safety protection strategy are dynamically updated to the safety control center of the water plant network.

[0014] In order to solve the above problems, the present invention also provides a water plant network security early warning system, the system comprising: A data collection module, used to collect historical network data of the water plant network, wherein the historical network data includes: user behavior data and program running status; A baseline establishment module, used to establish a network behavior baseline of the water plant network based on the user behavior data and the program running status; An abnormal index analysis module, used for capturing the protocol instruction sequence of the water plant network in real time, performing abnormal index analysis on the protocol instruction sequence using the network behavior baseline, and obtaining an abnormal network index of the water plant network; A vulnerability threat value generating module, used for synchronously monitoring the network traffic of the water plant network, obtaining the equipment traffic data of the water plant network, and generating a vulnerability threat value of the water plant network based on the equipment traffic data; A weighted comprehensive module, used for performing weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; A strategy deployment module is used to generate an early warning level for the water plant network according to the weighted comprehensive value and a preset weighted threshold, and to deploy a security protection strategy for the water plant network according to the early warning level.

[0015] The present invention collects historical network data of the water plant network, establishes a network behavior baseline, captures protocol instruction sequences in real time and analyzes abnormal indicators in combination with the baseline, and simultaneously monitors network traffic to generate vulnerability threat values, thereby comprehensively and carefully monitoring network conditions from multiple dimensions, achieving accurate positioning of potential security risks, and weightedly summing abnormal indicators and vulnerability threat values ​​to obtain a weighted comprehensive value, providing a unified quantitative standard for network security conditions, generating different warning levels according to the weighted comprehensive value and preset thresholds, and formulating corresponding security protection strategies for warnings at each level. This hierarchical warning and targeted protection mechanism avoids the limitations of a single warning method, and can quickly take effective measures to ensure network security and stability when the network faces serious threats, and can also prevent risks in a gentle manner when minor abnormalities occur in the network, thereby reducing the impact on the normal operation of the network, greatly improving the efficiency of network security warnings in water plants, effectively reducing network security risks, and effectively ensuring the stable and reliable operation of the water plant network. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A schematic diagram of a process flow of a water plant network security early warning method provided by an embodiment of the present invention; Figure 2 A functional module diagram of a network security early warning system for a water plant provided by an embodiment of the present invention; The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION

[0017] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0018] The embodiment of the present application provides a network security early warning method for a water treatment plant. The execution subject of the network security early warning method for a water treatment plant includes but is not limited to at least one of the electronic devices such as a server and a terminal that can be configured to execute the method provided by the embodiment of the present application. In other words, the network security early warning method for a water treatment plant can be executed by software or hardware installed on a terminal device or a server device. The server includes but is not limited to: a single server, a server cluster, a cloud server or a cloud server cluster, etc. The server can be an independent server, or it can be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (Content Delivery Network, CDN) and big data and artificial intelligence platforms.

[0019] Reference Figure 1 FIG. 1 is a flow chart of a network security early warning method for a water treatment plant provided by an embodiment of the present invention. In this embodiment, the network security early warning method for a water treatment plant includes: S1. Collecting historical network data of the water treatment plant network.

[0020] In the embodiment of the present invention, the collecting of historical network data of the water plant network includes: Acquire user behavior data of the water plant network, wherein the user behavior data includes: operation records, login and logout times, and access resource paths of users in the water plant network; Collecting the program running status of the water plant network, wherein the program running status includes: the running time, CPU occupancy, memory usage and error log of each application program in the water plant network; The user behavior data and the program running status are aligned according to timestamps to generate a historical network data set of the water plant network.

[0021] In detail, user behavior data records user operations (such as login, file access), timestamps, access paths (such as accessing the water quality monitoring server from the console); program operation status monitors program operation parameters (such as reverse osmosis control software operation time, CPU occupancy), and error logs (such as water pump control program crashes).

[0022] Furthermore, user operation and program running data are integrated by timestamp (for example, when a user accesses the server at 10:00, the CPU usage of the anti-infiltration software during that period is also recorded).

[0023] In detail, user A logged into the system at 8:00, and the access path was "Console → Water Quality Monitoring Server → Water Pump Control Interface"; the reverse osmosis program ran from 8:00 to 8:30, with a peak CPU usage of 85%, memory usage of 1.2 GB, and no error logs during the period.

[0024] In detail, after data alignment, a record is generated: {Time: 8:00, User Operation: Login, Program: Reverse Osmosis Control, CPU: 85%, Memory: 1.2GB}.

[0025] In detail, user behavior data is obtained, which reflects the user's operation trajectory and time information in the water plant network, such as when the user logged in, what operations were performed, and what resource paths were accessed. This is a record of network activities from the user's perspective.

[0026] In detail, the program running status data is collected. This data records the running parameters and error conditions of each application in the water plant network from the system level, such as running time, CPU occupancy, memory usage, and error logs, which helps to understand the running status of programs in the network.

[0027] Furthermore, through timestamp alignment, user operations and the program running status at the same moment can be correlated to form a complete historical network data set with a time series relationship.

[0028] S2. Establishing a network behavior baseline of the water plant network based on the user behavior data and the program running status.

[0029] In the embodiment of the present invention, the establishing of the network behavior baseline of the water plant network based on the user behavior data and the program running status includes: Extracting access path features of the water plant network based on the user behavior data; Extracting the duration distribution characteristics of the water plant network based on the program running status; Performing parameter fitting on the duration distribution characteristics to obtain Weibull distribution parameters of the water plant network; The access path characteristics and the Weibull distribution parameters are integrated to generate a network behavior baseline of the water plant network.

[0030] In detail, a directed graph is constructed to represent the jump relationship between resources and access paths. On this basis, the node degree centrality is calculated to find popular resources, the shortest path between nodes is extracted to form the key path, and finally the access path characteristics are obtained. This step is to mine the characteristics of the network resource access level from the perspective of user operations.

[0031] In detail, the program running status data covers the running time, CPU occupancy, memory usage, and error logs of each application. Among them, the running time is an important indicator. By generating a duration histogram and a cumulative distribution function of the duration, the distribution of the program running time can be intuitively displayed. Based on these charts and functions, the duration distribution features can be extracted to reflect the overall law of the program running time. This step is to mine the characteristics of the network from the time dimension of program running.

[0032] In detail, after obtaining the duration distribution characteristics, in order to more accurately describe and analyze the distribution law of program running time, the parameter fitting method is adopted, and Weibull distribution is used for fitting. Weibull distribution is a commonly used probability distribution. The corresponding distribution parameters can be obtained through fitting. These parameters can further quantify the distribution characteristics of program running time.

[0033] Specifically, the access path features obtained from the user behavior perspective and the Weibull distribution parameters obtained from the program running time perspective are fused. This is because a complete network behavior baseline needs to comprehensively consider the characteristics of both user operations and program running. The network behavior baseline generated after fusion can fully and accurately represent the normal behavior pattern of the water plant network.

[0034] In detail, the extracting the access path features of the water plant network based on the user behavior data includes: Constructing a directed graph of the water plant network based on the access resource path in the user behavior data , where the nodes in the directed graph are Represents a resource, and the edges in the directed graph Indicates the jump relationship of the access path; Calculate the degree centrality of each node in the directed graph, select nodes whose degree centrality is higher than a preset degree centrality threshold as hot resources, and extract the shortest path between nodes to form a critical path; An access path feature of the water plant network is generated according to the critical path and the hot resources.

[0035] In detail, a directed graph is constructed and the degree centrality of nodes is counted. For example, the water quality monitoring server is visited 100 times and has the highest degree centrality.

[0036] Furthermore, Weibull distribution fitting refers to using the distribution fitting parameters of the historical running time, for example: the shape parameter is 1.5 and the scale parameter is 25.

[0037] In detail, in the directed graph, the degree centrality of the "water quality monitoring server" node is 0.8, where the preset degree centrality threshold is 0.5, then the "water quality monitoring server" is marked as a hot resource; the key path is "control console → water quality monitoring server → water pump control interface".

[0038] In detail, when the scale parameter in the Weibull distribution parameter is 25, it means that the program running time is concentrated around 25 minutes.

[0039] In detail, the access resource path in the user behavior data records the user's access process from one resource to another in the water plant network.

[0040] In detail, after the directed graph is constructed, the degree centrality of each node in the graph is calculated. Degree centrality is an indicator to measure the importance of a node in the graph, which reflects the closeness of the connection between the node and other nodes. By setting a preset degree centrality threshold, the nodes with degree centrality higher than the threshold are screened out as hot resources. These hot resources are usually key resources that are frequently accessed in the network. At the same time, the shortest paths between nodes are extracted. These shortest paths represent the most direct and most commonly used access paths between resources, forming key paths.

[0041] In detail, the key paths and popular resources reflect the main modes and important nodes of resource access in the water plant network. By combining them, the access path characteristics of the water plant network can be generated. These characteristics can summarize the laws and characteristics of resource access in the network, providing an important basis for subsequent network behavior analysis and security warning.

[0042] In detail, the extracting the duration distribution characteristics of the water plant network based on the program running state includes: A duration histogram and a duration cumulative distribution function of the water plant network are generated based on the running time of each application in the water plant network, wherein the duration cumulative distribution function is: in, is the cumulative distribution function of duration, is the total number of times the application has been run, is the index variable of the application running, The limit of measuring the length of a single run, is the indicator function, It is The duration of a single run of the application; The duration distribution characteristics of the water plant network are generated based on the duration histogram and the duration cumulative distribution function.

[0043] In detail, the cumulative distribution of program running time is counted, for example: 90% of the reverse osmosis program running time is ≤ 30 minutes.

[0044] In detail, the duration histogram graphically displays the distribution of application runtime. It divides the runtime into different intervals and counts the frequency of runtime in each interval, so as to quickly understand the concentration of runtime in each interval.

[0045] In detail, the cumulative distribution function of duration describes the distribution of runtime from another perspective. It indicates that the runtime of the application is less than or equal to The probability of By calculating this function, we can more accurately grasp the overall distribution characteristics of the application running time.

[0046] For example, the histogram can show the main concentration interval of the running time and whether there is an abnormal long-tail distribution; the cumulative distribution function can tell the probability corresponding to different time limits.

[0047] Furthermore, some malware or attack behaviors may cause the application running time to grow or shrink abnormally. For example, hackers can implant malicious code to cause the application to fall into an infinite loop, which can significantly increase the running time; or malicious programs can quickly exhaust system resources, causing the application to end running early. The duration distribution feature can detect these potential abnormal behaviors in a timely manner and provide important clues for network security early warning.

[0048] Furthermore, when an abnormality occurs in the network, the duration distribution characteristics can be used as an important reference for fault diagnosis and problem location. By comparing the running time when the abnormality occurs with the normal duration distribution characteristics, the scope of investigation can be narrowed down and the application or system component that may have problems can be quickly identified. For example, if the running time of multiple related applications is abnormal in a specific time period, it may mean that there are general problems in the network environment or system during that time period.

[0049] S3. Capturing the protocol instruction sequence of the water plant network in real time, using the network behavior baseline to perform abnormal index analysis on the protocol instruction sequence, and obtaining an abnormal network index of the water plant network.

[0050] In the embodiment of the present invention, after the protocol instruction sequence of the water plant network is captured in real time, it is necessary to perform statistical analysis on the frequency of occurrence of each protocol instruction therein. The probability distribution of each type of protocol instruction in the protocol instruction sequence is calculated one by one, which is the basis for subsequent quantitative analysis. By counting the number of occurrences of different protocol instructions and dividing it by the total number of protocol instructions, the probability of occurrence of each protocol instruction is obtained, and the distribution of the protocol instructions in the sequence is clearly presented.

[0051] In the embodiment of the present invention, the abnormal index analysis of the protocol instruction sequence using the network behavior baseline to obtain the abnormal network index of the water plant network includes: Calculating the probability distribution of the protocol instructions in the protocol instruction sequence one by one; The dispersion of the protocol instructions is quantified based on the probability distribution and a preset Shannon entropy algorithm, wherein the preset Shannon entropy algorithm is as follows: in, is the decentralization of the protocol instructions, is the number of protocol instruction types, is the identifier of the protocol instruction in the protocol instruction sequence, is determined based on the probability distribution The probability of occurrence of protocol-like instructions; The Shannon entropy is numerically compared with the historical entropy value in the network behavior baseline, and the entropy deviation of the Shannon entropy is determined based on the comparison result of the numerical comparison, wherein the calculation formula of the entropy deviation is as follows: in, is the entropy deviation of the Shannon entropy, is the Shannon entropy, is the historical entropy value in the network behavior baseline; Perform abnormal protocol screening on the protocol instruction sequence according to the entropy deviation to obtain abnormal protocols of the water plant network; Aggregate the entropy deviations of all the abnormal protocols to generate an abnormal network index of the water plant network.

[0052] For example, the "read water quality data" command in the Modbus protocol accounts for 90%.

[0053] In detail, the historical entropy value represents the dispersion characteristics of the protocol instructions of the water plant network under normal operation; the entropy deviation reflects the degree of deviation of the current protocol instruction dispersion from the normal situation.

[0054] Specifically, in network communications, protocol instructions are the basis for interaction between devices. Under normal circumstances, the appearance of various types of protocol instructions will show certain regularities and distributions. When there are more types of protocol instructions and the probability of their appearance is more uniform, the value of Shannon entropy will be larger, which means that the dispersion of protocol instructions is higher; conversely, if the Shannon entropy value is smaller, it means that the distribution of protocol instructions is more concentrated, and there may be abnormal situations.

[0055] In detail, covert attacks often use some abnormal protocol instruction interactions to achieve the purpose of intrusion, and do not want to be easily detected. By calculating the Shannon entropy to quantify the dispersion of protocol instructions, such abnormal changes can be keenly captured. Once the Shannon entropy value of the protocol instruction deviates from the normal range, it indicates that there may be covert attack behavior, thereby enhancing the ability to identify covert attacks and issuing network security warnings in advance.

[0056] In detail, the attack scenario is covert scanning resulting in a concentration of protocol instructions (e.g., 80% are port detection instructions).

[0057] Specifically, if the entropy deviation of a protocol instruction exceeds a certain threshold, it means that the appearance of the protocol instruction is significantly different from the normal state, and it is judged as an abnormal protocol. In this way, abnormal protocols that may pose security risks can be accurately identified from a large number of protocol instructions.

[0058] S4. Synchronously monitor the network traffic of the water plant network to obtain device traffic data of the water plant network, and generate a vulnerability threat value of the water plant network based on the device traffic data.

[0059] In the embodiment of the present invention, the synchronous monitoring of the network traffic of the water plant network to obtain the equipment traffic data of the water plant network includes: The equipment flow data of the water plant network is collected synchronously, wherein the equipment flow data includes: a time series record of the inbound flow, outbound flow and flow peak of each network device in the water plant network.

[0060] In the embodiment of the present invention, the generating of the vulnerability threat value of the water plant network based on the device flow data includes: Identify redundant devices in the water plant network based on the device flow data, and configure threat coefficient attenuation factors for the redundant devices; The flow deviation of the water plant network is generated based on the equipment flow data and a preset flow deviation algorithm, wherein the preset flow deviation algorithm is: in, is the flow deviation of the waterworks network, is the inbound traffic in the device traffic data, is the historical mean of inbound traffic, is the outbound traffic in the device traffic data, is the historical mean of outbound traffic, is the peak flow rate in the device flow data, is the historical average of the peak traffic volume, is the historical standard deviation of inbound traffic, is the historical standard deviation of outbound traffic; A vulnerability threat value of the water plant network is generated based on the flow deviation and the threat coefficient attenuation factor.

[0061] In an embodiment of the present invention, identifying redundant devices in the water plant network based on the device traffic data means that when the device activity is less than 20% of the average value, the device is determined to be a redundant device, for example: the average daily traffic of the backup server is less than 1GB.

[0062] Furthermore, after obtaining the equipment flow data of the water plant network, the equipment in the network is first analyzed. By evaluating the activity of the equipment, such as the inbound flow, outbound flow and other indicators in the equipment flow data, when the equipment activity is less than a certain proportion of the average value (such as 20%), the equipment is determined to be a redundant equipment. Since redundant equipment may not be the core operating equipment in the network, even if it has abnormal traffic, the actual threat to the entire network is relatively small, so a threat coefficient attenuation factor is configured for these redundant devices, which is used to subsequently adjust the impact of these devices on the overall vulnerability threat value.

[0063] In detail, by identifying redundant devices and configuring attenuation factors, we avoid over-evaluation of network security threats due to traffic fluctuations of redundant devices. At the same time, the traffic deviation algorithm comprehensively considers the comparison of multiple traffic indicators and historical data, and can more accurately measure the degree of abnormality of network traffic. The vulnerability threat value generated by combining the two can accurately reflect the actual security threats currently faced by the water plant network due to traffic problems, providing a more reliable basis for network security early warning.

[0064] Furthermore, the normalized deviation of real-time traffic from the historical mean, for example, when only inbound traffic increases suddenly , the deviation is ; When the threat coefficient attenuation factor is When the vulnerability threat value is .

[0065] For example: real-time inbound traffic (Historical average , standard deviation ), deviation ; Traffic peak (Historical average ), contribution value ; Assume that the threat coefficient attenuation factor is , the deviation of outbound traffic is , then the total deviation , after the redundant device decays .

[0066] S5. Perform weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network.

[0067] In the embodiment of the present invention, it is assumed that the maximum value of the abnormality index is , the maximum vulnerability threat value , the abnormal indicator is , the vulnerability threat value is , the weight of the abnormal index is , the weight of the vulnerability threat value is , then the weighted comprehensive value of the water plant network is .

[0068] Specifically, the weighted comprehensive value provides a unified quantitative standard for the security status of the water plant network. Network administrators can intuitively understand the security level of the network based on this value, avoiding the trouble of complex comparison and judgment between multiple different indicators. At the same time, this unified standard also facilitates the comparison and analysis of security status between different water plant networks in different time periods, which helps to discover the changing trend of network security status.

[0069] S6. Generate an early warning level for the water plant network according to the weighted comprehensive value and a preset weighted threshold, and deploy a security protection strategy for the water plant network according to the early warning level.

[0070] In an embodiment of the present invention, generating the warning level of the water plant network according to the weighted comprehensive value and a preset weighted threshold includes: The weighted comprehensive value Compare with the preset weighted threshold, where the preset weighted threshold is and ,and ; when When the first level warning is triggered, When the alarm is triggered, the second level warning is triggered.

[0071] In the embodiment of the present invention, the deploying of security protection strategy for the water plant network according to the warning level includes: The security protection strategy of the water plant network is adjusted according to the warning level, wherein the security protection strategy is: when a level 1 warning is triggered, abnormal devices in the water plant network are isolated and traffic cleaning is enabled; when a level 2 warning is triggered, access to non-critical resources in the water plant network is restricted and log monitoring is enhanced; The warning level and the safety protection strategy are dynamically updated to the safety control center of the water plant network.

[0072] Furthermore, assuming , ,like , a second-level warning is triggered, wherein the security protection strategy of the second-level warning is to restrict access to non-critical resources and enhance the frequency of log monitoring. For example, restricting access to non-critical resources means prohibiting access to the backup server, and enhancing the frequency of log monitoring means scanning every 5 minutes.

[0073] In detail, the security protection strategy for the first-level warning is to isolate abnormal devices and enable traffic cleaning. For example, isolating abnormal devices can block the attack source IP, and enabling traffic cleaning can filter abnormal protocol traffic, that is, isolating PLC controllers with abnormal traffic and starting the cloud cleaning center to filter malicious traffic. Among them, isolating abnormal devices can prevent abnormal behavior from spreading further and avoid causing greater impact on other devices and the entire network; enabling traffic cleaning can filter out malicious traffic and ensure the normal operation of the network.

[0074] In detail, when the second-level warning is triggered, the security threat is relatively small, but it still needs to be taken seriously, so measures are taken to restrict access to non-critical resources and enhance log monitoring. Restricting access to non-critical resources can reduce potential attack surfaces and reduce security risks; enhancing log monitoring helps to detect abnormal behaviors in a timely manner and provide more information for subsequent security analysis and processing.

[0075] In detail, the warning level and corresponding security protection strategy are dynamically updated to the security control center of the water plant network. The security control center is the core hub of network security management. Timely updating of this information can ensure that network managers can fully understand the security status of the network and make effective management and decisions based on the latest warnings and strategies.

[0076] In general, by setting different weighted thresholds and dividing warning levels, it is possible to carry out graded warnings according to the different degrees of network security risks. This grading method makes the warning more targeted and avoids the problem of overreaction or underreaction that may be caused by the use of a single warning mechanism. For example, when there is only a slight abnormality in the network, the second-level warning is triggered and relatively mild protective measures are taken, which can prevent security risks without causing excessive interference to the normal operation of the network; when the network faces serious threats, the first-level warning is triggered and strong protective measures are taken in time to ensure the security and stability of the network.

[0077] like Figure 2 The figure shows a functional module diagram of a network security early warning system for a water treatment plant provided by an embodiment of the present invention.

[0078] The network security early warning system 100 for water treatment plants of the present invention can be installed in an electronic device. According to the functions to be implemented, the network security early warning system 100 for water treatment plants may include a data acquisition module 101, a baseline establishment module 102, an abnormal index analysis module 103, a vulnerability threat value generation module 104, a weighted synthesis module 105, and a strategy deployment module 106. The module of the present invention may also be referred to as a unit, which refers to a series of computer program segments that can be executed by an electronic device processor and can complete fixed functions, which are stored in the memory of the electronic device.

[0079] In this embodiment, the functions of each module / unit are as follows: The data collection module 101 is used to collect historical network data of the water plant network, wherein the historical network data includes: user behavior data and program running status; The baseline establishing module 102 is used to establish a network behavior baseline of the water plant network based on the user behavior data and the program running status; The abnormal index analysis module 103 is used to capture the protocol instruction sequence of the water plant network in real time, perform abnormal index analysis on the protocol instruction sequence using the network behavior baseline, and obtain an abnormal network index of the water plant network; The vulnerability threat value generating module 104 is used to synchronously monitor the network traffic of the water plant network, obtain the equipment traffic data of the water plant network, and generate the vulnerability threat value of the water plant network based on the equipment traffic data; The weighted comprehensive module 105 is used to perform weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; The strategy deployment module 106 is used to generate an early warning level of the water plant network according to the weighted comprehensive value and a preset weighted threshold, and to deploy a security protection strategy for the water plant network according to the early warning level.

[0080] In the several embodiments provided by the present invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are only illustrative, for example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.

[0081] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0082] In addition, each functional module in each embodiment of the present invention may be integrated into one processing unit, each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional modules.

[0083] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0084] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.

Claims

1. A water plant network security early warning method, characterized in that: The method comprises: Collecting historical network data of the water plant network, wherein the historical network data includes: user behavior data and program running status; Establishing a network behavior baseline of the water plant network based on the user behavior data and the program running status; Capturing the protocol instruction sequence of the water plant network in real time, performing abnormal index analysis on the protocol instruction sequence using the network behavior baseline, and obtaining an abnormal network index of the water plant network; Synchronously monitoring the network traffic of the water plant network to obtain device traffic data of the water plant network, and generating a vulnerability threat value of the water plant network based on the device traffic data; Performing weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; The early warning level of the water plant network is generated according to the weighted comprehensive value and a preset weighted threshold, and a security protection strategy is deployed for the water plant network according to the early warning level.

2. The water plant network security early warning method according to claim 1, characterized in that: The collecting of historical network data of the water plant network includes: Acquire user behavior data of the water plant network, wherein the user behavior data includes: operation records, login and logout times, and access resource paths of users in the water plant network; Collecting the program running status of the water plant network, wherein the program running status includes: the running time, CPU occupancy, memory usage and error log of each application program in the water plant network; The user behavior data and the program running status are aligned according to timestamps to generate a historical network data set of the water plant network.

3. The water plant network security early warning method according to claim 1, characterized in that: The establishing of a network behavior baseline of the water plant network based on the user behavior data and the program running status includes: Extracting access path features of the water plant network based on the user behavior data; Extracting the duration distribution characteristics of the water plant network based on the program running status; Performing parameter fitting on the duration distribution characteristics to obtain Weibull distribution parameters of the water plant network; The access path characteristics and the Weibull distribution parameters are integrated to generate a network behavior baseline of the water plant network.

4. The water plant network security early warning method according to claim 3, characterized in that: The extracting the access path features of the water plant network based on the user behavior data includes: Constructing a directed graph of the water plant network based on the access resource path in the user behavior data , where the nodes in the directed graph are Represents a resource, and the edges in the directed graph Indicates the jump relationship of the access path; Calculate the degree centrality of each node in the directed graph, select nodes whose degree centrality is higher than a preset degree centrality threshold as hot resources, and extract the shortest path between nodes to form a critical path; An access path feature of the water plant network is generated according to the critical path and the hot resources.

5. The water plant network security early warning method according to claim 3, characterized in that: The extracting the duration distribution characteristics of the water plant network based on the program running state includes: A duration histogram and a duration cumulative distribution function of the water plant network are generated based on the running time of each application in the water plant network, wherein the duration cumulative distribution function is: in, is the cumulative distribution function of duration, is the total number of times the application has been run, is the index variable of the application running, The limit of measuring the length of a single run, is the indicator function, It is The duration of a single run of the application; The duration distribution characteristics of the water plant network are generated based on the duration histogram and the duration cumulative distribution function.

6. The water plant network security early warning method according to claim 1, characterized in that: The using the network behavior baseline to perform abnormal index analysis on the protocol instruction sequence to obtain the abnormal network index of the water plant network includes: Calculating the probability distribution of the protocol instructions in the protocol instruction sequence one by one; The dispersion of the protocol instructions is quantified based on the probability distribution and a preset Shannon entropy algorithm, wherein the preset Shannon entropy algorithm is as follows: in, is the decentralization of the protocol instructions, is the number of protocol instruction types, is the identifier of the protocol instruction in the protocol instruction sequence, is determined based on the probability distribution The probability of occurrence of protocol-like instructions; The Shannon entropy is numerically compared with the historical entropy value in the network behavior baseline, and the entropy deviation of the Shannon entropy is determined based on the comparison result of the numerical comparison, wherein the calculation formula of the entropy deviation is as follows: in, is the entropy deviation of the Shannon entropy, is the Shannon entropy, is the historical entropy value in the network behavior baseline; Perform abnormal protocol screening on the protocol instruction sequence according to the entropy deviation to obtain abnormal protocols of the water plant network; Aggregate the entropy deviations of all the abnormal protocols to generate an abnormal network index of the water plant network.

7. The water plant network security early warning method according to claim 1, characterized in that: The generating the vulnerability threat value of the water plant network based on the device flow data includes: Identify redundant devices in the water plant network based on the device flow data, and configure threat coefficient attenuation factors for the redundant devices; The flow deviation of the water plant network is generated based on the equipment flow data and a preset flow deviation algorithm, wherein the preset flow deviation algorithm is: in, is the flow deviation of the waterworks network, is the inbound traffic in the device traffic data, is the historical mean of inbound traffic, is the outbound traffic in the device traffic data, is the historical mean of outbound traffic, is the peak flow rate in the device flow data, is the historical average of the peak traffic volume, is the historical standard deviation of inbound traffic, is the historical standard deviation of outbound traffic; A vulnerability threat value of the water plant network is generated based on the flow deviation and the threat coefficient attenuation factor.

8. The water plant network security early warning method according to claim 1, characterized in that: Generating the warning level of the water plant network according to the weighted comprehensive value and a preset weighted threshold value includes: The weighted comprehensive value Compare with the preset weighted threshold, where the preset weighted threshold is and ,and ; when When the first level warning is triggered, When the alarm is triggered, the second level warning is triggered.

9. The water plant network security early warning method according to any one of claims 1 to 8, characterized in that: The deploying of security protection strategies for the water plant network according to the warning level includes: The security protection strategy of the water plant network is adjusted according to the warning level, wherein the security protection strategy is: when a level 1 warning is triggered, abnormal devices in the water plant network are isolated and traffic cleaning is enabled; when a level 2 warning is triggered, access to non-critical resources in the water plant network is restricted and log monitoring is enhanced; The warning level and the safety protection strategy are dynamically updated to the safety control center of the water plant network.

10. A water plant network security early warning system, characterized in that: The system comprises: A data collection module, used to collect historical network data of the water plant network, wherein the historical network data includes: user behavior data and program running status; A baseline establishment module, used to establish a network behavior baseline of the water plant network based on the user behavior data and the program running status; An abnormal index analysis module, used for capturing the protocol instruction sequence of the water plant network in real time, performing abnormal index analysis on the protocol instruction sequence using the network behavior baseline, and obtaining an abnormal network index of the water plant network; A vulnerability threat value generating module, used for synchronously monitoring the network traffic of the water plant network, obtaining the equipment traffic data of the water plant network, and generating a vulnerability threat value of the water plant network based on the equipment traffic data; A weighted comprehensive module, used for performing weighted summation on the abnormal index and the vulnerability threat value to obtain a weighted comprehensive value of the water plant network; A strategy deployment module is used to generate an early warning level for the water plant network according to the weighted comprehensive value and a preset weighted threshold, and to deploy a security protection strategy for the water plant network according to the early warning level.

Citation Information

Patent Citations

  • Method for mining unknown network protocol hidden behaviors through clustering instruction sequences

    CN105681297A

  • Method and device for identifying abnormal traffic of Internet of Vehicles based on instruction sequence

    CN114422623A

  • Network security intelligent protection method and system based on endogenous security mechanism

    CN118972157A

  • Ore wharf production network security situation awareness and monitoring early warning method and device

    CN119316217A

  • Network data risk assessment system for computer

    CN119449432A