Verification-free vulnerability intelligent matching method for industrial control system

Through multi-dimensional information collection and analysis, combined with vulnerability matching methods based on rules, pattern matching and machine learning algorithms, the accuracy and system occupancy problems of the existing verification-free vulnerability intelligent matching methods of industrial control systems are solved, and more efficient and reliable vulnerability detection is achieved.

CN120030546APending Publication Date: 2025-05-23浙江齐安信息科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411952710.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing verification-free vulnerability intelligent matching method of industrial control systems has problems such as low matching accuracy and high system occupancy, which affects its use effect.

Method used

Vulnerability-related information about industrial control systems is collected through various methods, including vulnerability scanning, industrial equipment fingerprint recognition, log analysis and traffic monitoring, comprehensive analysis and evaluation, establish a vulnerability matching library, and intelligent vulnerability matching is carried out through the combination of rules, pattern matching and machine learning algorithms.

Benefits of technology

It improves the accuracy and intelligence of vulnerability matching, enhances the comprehensiveness and reliability of detection, can promptly discover problems in the matching process, and optimizes vulnerability matching strategies to ensure that the system operates efficiently while ensuring the quality of matching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030546A_ABST
    Figure CN120030546A_ABST
Patent Text Reader

Abstract

The invention discloses a verification-free vulnerability intelligent matching method for an industrial control system. The method comprises the following steps: step 1, firstly, collecting vulnerability related information of the industrial control system; 2, analyzing the vulnerability related information of the industrial control system to obtain industrial control system evaluation information; 3, collecting type information of the industrial control system, and establishing a vulnerability matching library according to the evaluation information of the industrial control system and the type information of the industrial control system; 4, performing verification-free vulnerability intelligent matching through the established vulnerability matching library, and sending out warning information for warning when a vulnerability is matched; 5, in the vulnerability matching process, the vulnerability matching process is monitored in real time, and vulnerability matching related information is obtained; and step 6, analyzing the vulnerability matching related information to obtain matching evaluation information. According to the invention, better verification-free vulnerability intelligent matching can be carried out, and the safety of the industrial control system is further ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of vulnerability detection, and in particular to a verification-free vulnerability intelligent matching method for an industrial control system. Background Art

[0002] Industrial control system vulnerabilities refer to security defects or weaknesses in industrial control systems. These vulnerabilities may cause the system to be illegally accessed, controlled or destroyed by attackers, thus posing a serious threat to the security of industrial production processes and infrastructure.

[0003] In the process of detecting vulnerabilities in industrial control systems, a verification-free vulnerability intelligent matching method is used to detect vulnerabilities.

[0004] The existing verification-free vulnerability intelligent matching method has problems such as low matching accuracy and high system occupancy, which has a certain impact on the use of the verification-free vulnerability intelligent matching method. Therefore, a verification-free vulnerability intelligent matching method for industrial control systems is proposed. Summary of the invention

[0005] In view of the defects in the prior art, the present invention provides an industrial control system verification-free vulnerability intelligent matching method, comprising the following steps:

[0006] Step 1: Collect information related to the vulnerabilities of the industrial control system;

[0007] Step 2: Analyze the vulnerability-related information of the industrial control system to obtain the industrial control system evaluation information, that is, evaluate the status of the industrial control system, such as whether there are many vulnerabilities;

[0008] Step 3: Collect the industrial control system type information again, and establish a vulnerability matching library based on the industrial control system evaluation information and industrial control system type information;

[0009] Step 4: Perform verification-free vulnerability intelligent matching through the established vulnerability matching library, and issue a warning message when a vulnerability is matched, alerting the user to discover the vulnerability;

[0010] Step 5: During the vulnerability matching process, monitor the vulnerability matching process in real time and obtain vulnerability matching related information;

[0011] Step 6: Analyze the vulnerability matching related information, obtain the matching evaluation information, and evaluate the matching effect and system occupancy status of the verification-free vulnerability library.

[0012] Furthermore, the specific process of collecting information related to the vulnerability of the industrial control system is as follows:

[0013] S1: Use vulnerability scanning tools to scan the network where the industrial control system is located, detect the open ports, services and potential vulnerabilities of the system, and obtain the first vulnerability information;

[0014] S2: Perform fingerprint recognition of industrial equipment, identify the type, model, and version information of the equipment in the industrial control system, determine the known vulnerabilities it has, and obtain the second vulnerability information;

[0015] S3: Perform log analysis and collect various logs of the industrial control system, including operating system logs, application logs, and equipment operation logs. Use log management and analysis tools to extract security-related event information from the logs to obtain third-party vulnerability information.

[0016] S4: Perform traffic monitoring and analysis, deploy network traffic monitoring equipment, monitor and analyze the traffic in the industrial control system network in real time, identify data packets that do not conform to the normal communication mode through the detection of traffic data, and obtain the fourth vulnerability information;

[0017] The first vulnerability information, the second vulnerability information, the third vulnerability information and the fourth vulnerability information constitute vulnerability related information.

[0018] Furthermore, the process of obtaining the industrial control system evaluation information is as follows:

[0019] SS1: Classify vulnerabilities. According to the preset vulnerability classification standards, classify the collected vulnerability-related information and obtain vulnerability classification information. The vulnerability classification information includes high-risk vulnerabilities, medium-risk vulnerabilities and low-risk vulnerabilities.

[0020] SS2: After classification, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are extracted;

[0021] SS3: Then, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are processed to obtain the risk score of the industrial control system. The risk score of the industrial control system is processed to obtain the industrial control system evaluation information.

[0022] Furthermore, the process of obtaining the risk score of the industrial control system is as follows:

[0023] Extract the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3;

[0024] Calculate the sum of K1, K2 and K3 to obtain the total vulnerability risk number, and mark the total vulnerability risk number as Kk;

[0025] Calculate the ratio Kk1 of K1 to Kk, the ratio Kk2 of K2 to Kk, and the ratio Kk3 of K3 to Kk;

[0026] By the formula (Kk2+Kk3)-Kk1=K 差 , get the industrial control system risk score K差 ;

[0027] The process of processing the risk score of the industrial control system, that is, obtaining the evaluation information of the industrial control system, is as follows:

[0028] When the risk score K of the industrial control system 差 is greater than the preset value a1, the evaluation information of the industrial control system is generated. At this time, the evaluation information of the industrial control system is a first-level industrial control system evaluation, that is, the risk of this industrial control system is small;

[0029] When the risk score K of the industrial control system 差 is between the preset values a1 and a2, the evaluation information of the industrial control system is generated. At this time, the evaluation information of the industrial control system is a second-level industrial control system evaluation, that is, there is a certain risk in this industrial control system;

[0030] When the risk score K of the industrial control system 差 is less than the preset value a2, the evaluation information of the industrial control system is generated. At this time, the evaluation information of the industrial control system is a third-level industrial control system evaluation, that is, the risk of this industrial control system is large.

[0031] Furthermore, the process of establishing the vulnerability matching library is as follows:

[0032] S(1): Collect the industrial control system type information, which includes the brand, model, version, industrial control protocol used, and the architecture and topology of the industrial control system;

[0033] S(2): According to the obtained evaluation information of the industrial control system and the system type information, select the vulnerability information with the highest matching degree with the current industrial control system from the preset databases (public vulnerability databases, security announcements issued by industrial control system manufacturers, and reports of professional security research institutions) as the benchmark vulnerability information, and associate and integrate the benchmark vulnerability information with the system type information to construct a real-time vulnerability matching library for the industrial control system that needs to perform non-verified vulnerability matching. The real-time vulnerability matching library includes detailed feature information of the vulnerability, detection methods, and corresponding repair measures.

[0034] Furthermore, the specific process of step four is as follows:

[0035] SS(1): Perform matching based on rules;

[0036] First, formulate rules. According to the feature information of each vulnerability in the vulnerability matching library, write corresponding matching rules. After the operation data of the industrial control system is collected in real time, compare the operation data of the industrial control system with the preset matching rules one by one;

[0037] For network traffic data, check whether there is a port access mode that meets the description in the rules. If there is a port access mode that does not meet the description in the rules, an alert message is generated to warn;

[0038] For system log data, check whether there are error codes or abnormal operation records related to the rules. When there are error codes or abnormal operation records, generate warning information to warn;

[0039] SS(2): Perform pattern matching detection:

[0040] Extract standard behavior patterns of various vulnerabilities from the vulnerability matching library, and perform pattern recognition on the real-time collected industrial control system operation data, which includes network traffic data and device status data;

[0041] Use a string matching algorithm to find out whether there is a segment consistent with the pattern template in the operation data of the industrial control system. When there is a segment consistent with the pattern template, an alarm message is generated to warn;

[0042] For network traffic data, the data packet content is compared with the pattern template. When there is a segment that is consistent with the pattern template, an alert message is generated to warn;

[0043] For the equipment status data, check whether the equipment status change sequence conforms to a specific pattern. When the equipment status data does not conform to the specific pattern, generate a warning message to warn;

[0044] SS(3) uses machine learning algorithms for detection:

[0045] Clean and normalize the industrial control system operation data collected in real time to make it suitable for the input requirements of the machine learning algorithm;

[0046] Use historical normal operation data to train the anomaly detection model, input the industrial control system data collected in real time into the trained model, and the model determines whether there is an anomaly based on the degree of deviation between the industrial control system data and the trained model;

[0047] When the degree of deviation exceeds the set threshold, it is considered that there may be abnormal behavior related to the vulnerability, and a warning message is generated to warn;

[0048] Extract vulnerability-related features from the industrial control system operation data. The vulnerability-related features include the protocol type, port number, and data length in the network traffic, and the event type, timestamp, and user ID in the system log. Combine and filter the above vulnerability-related features to form a feature vector for classification.

[0049] Use pre-labeled historical data to train the classification model. During the training process, the model learns the relationship between different features and vulnerabilities and establishes the classification decision boundary.

[0050] The industrial control system data collected in real time is converted into feature vectors and input into the trained classification model. The model determines whether the data belongs to the vulnerability category based on the learned decision boundary. If it is determined to be a vulnerability category, an alert message is generated for warning.

[0051] The results of rule-based matching, pattern matching and machine learning algorithms are integrated, and the weights can be set. The weight of rule-based matching results is 0.3, the weight of pattern matching results is 0.3, and the weight of machine learning algorithm results is 0.4;

[0052] The matching scores of the three algorithms are weighted and summed according to the weights to obtain the final matching score. When the final matching score exceeds the set threshold, it is determined that there may be a corresponding vulnerability, and a warning message is generated for warning.

[0053] Furthermore, the matching evaluation information includes matching effect evaluation and resource occupancy evaluation:

[0054] Matching evaluation information includes first-level matching evaluation, second-level matching evaluation and third-level matching evaluation. The specific process of matching evaluation information is as follows:

[0055] Extract vulnerability matching related information, which is obtained through manual inspection, reports from professional security assessment agencies, and system vulnerability scanning;

[0056] Vulnerability matching related information includes a list of actual vulnerabilities in the industrial control system. The vulnerability list includes vulnerability information and resource usage information matched by the vulnerability library.

[0057] Organize the vulnerability information matched by the vulnerability library, extract the vulnerability list matched by the vulnerability library from the records of the vulnerability matching process, and also record the relevant detailed information of each matching vulnerability;

[0058] Calculate the accuracy of the matching index, traverse the vulnerability list matched by the vulnerability library, and for each matched vulnerability, search and verify it in the actual vulnerability list. If the corresponding vulnerability is found in the actual vulnerability list, the match is considered correct;

[0059] The number of correctly matched vulnerabilities is counted and marked as Tp, and the total number of matched vulnerabilities is recorded as Tm;

[0060] The accuracy rate Tt1 is obtained through the formula Tt1=Tp / Tm;

[0061] Then calculate the recall rate: traverse the actual vulnerability list, and for each actual vulnerability, check whether there is a corresponding match in the vulnerability list matched by the vulnerability library. If so, it is recorded as a successful match;

[0062] The actual number of successfully matched vulnerabilities is counted, marked as Tp, and the total number of existing vulnerabilities is recorded as Tv;

[0063] The recall rate Tt2 is obtained through the formula Tt2 = Tp / Tv;

[0064] Evaluation and Analysis Based on the calculated accuracy Tt1 and recall Tt2, the matching effect of the verification-free vulnerability library is evaluated;

[0065] When the precision rate Tt1 and the recall rate Tt2 are both greater than or equal to the preset value, a first-level matching evaluation is generated;

[0066] When either the precision rate Tt1 or the recall rate Tt2 is less than the preset value, a secondary matching evaluation is generated;

[0067] When both the precision rate Tt1 and the recall rate Tt2 are less than the preset values, a three-level matching evaluation is generated.

[0068] Furthermore, the resource occupancy assessment includes a primary resource assessment, a secondary resource assessment and a tertiary resource assessment;

[0069] The specific process of resource occupancy evaluation is as follows: extracting resource occupancy information, which includes CPU occupancy, memory occupancy and network bandwidth occupancy;

[0070] When the CPU usage, memory usage, and network bandwidth usage are all less than the preset values, a first-level resource assessment is generated;

[0071] When any one of the CPU usage, memory usage and network bandwidth usage is greater than or equal to the preset value, a secondary resource evaluation is generated;

[0072] When any two or more of the CPU usage, memory usage, and network bandwidth usage are greater than or equal to the preset value, a third-level resource assessment is generated.

[0073] Compared with the prior art, the present invention has the following advantages: the verification-free vulnerability intelligent matching method for industrial control systems comprehensively collects vulnerability-related information of industrial control systems from different dimensions by using vulnerability scanning tools, industrial equipment fingerprint recognition, log analysis, and traffic monitoring and analysis, thereby ensuring full grasp of vulnerability information of industrial control systems.

[0074] The collected vulnerability information is classified, and the risk score of the industrial control system is calculated according to the number of high, medium and low risk vulnerabilities, and then the industrial control system assessment information is obtained. This quantitative assessment method can accurately judge the risk status of the industrial control system through clear formulas and threshold settings, providing a targeted basis for subsequent vulnerability matching and processing.

[0075] Vulnerability matching is performed based on rules, pattern matching detection, and machine learning algorithms. The three results are integrated and weighted summed by setting weights to obtain the final matching score. This multi-dimensional matching method and result fusion strategy improves the accuracy and intelligence of vulnerability matching and greatly enhances the comprehensiveness and reliability of detection.

[0076] Evaluate the matching effect of the vulnerability matching library, and measure the accuracy and completeness of the matching by calculating the accuracy and recall rate. At the same time, evaluate resource usage, including indicators such as CPU usage, memory usage, and network bandwidth usage. Classify according to different evaluation results to fully understand the effect of the vulnerability matching process and the use of system resources, which helps to adjust and optimize the vulnerability matching strategy in a timely manner, ensuring that the system runs efficiently while ensuring the quality of matching.

[0077] Real-time monitoring is performed during the vulnerability matching process to obtain vulnerability matching related information and analyze it to obtain matching evaluation information. This real-time monitoring and feedback mechanism can promptly discover problems in the matching process. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for the specific embodiments or the description of the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual scale.

[0079] Figure 1 It is the overall flow chart of the present invention. DETAILED DESCRIPTION

[0080] The following embodiments of the technical solution of the present invention are described in detail in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and are therefore only used as examples, and cannot be used to limit the protection scope of the present invention.

[0081] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should have the common meanings understood by those skilled in the art to which the invention belongs.

[0082] like Figure 1 As shown, the verification-free vulnerability intelligent matching method for industrial control systems includes the following steps:

[0083] Step 1: Collect information related to the vulnerabilities of the industrial control system;

[0084] Step 2: Analyze the vulnerability-related information of the industrial control system to obtain the industrial control system evaluation information, that is, evaluate the status of the industrial control system, such as whether there are many vulnerabilities;

[0085] Step 3: Collect the industrial control system type information again, and establish a vulnerability matching library based on the industrial control system evaluation information and industrial control system type information;

[0086] Step 4: Perform verification-free vulnerability intelligent matching through the established vulnerability matching library, and issue a warning message when a vulnerability is matched, alerting the user to discover the vulnerability;

[0087] Step 5: During the vulnerability matching process, monitor the vulnerability matching process in real time and obtain vulnerability matching related information;

[0088] Step 6: Analyze the vulnerability matching related information, obtain the matching evaluation information, and evaluate the matching effect and system occupancy status of the verification-free vulnerability library.

[0089] The specific process of collecting information related to the vulnerability of the industrial control system is as follows:

[0090] S1: Use vulnerability scanning tools to scan the network where the industrial control system is located, detect the open ports, services and potential vulnerabilities of the system, and obtain the first vulnerability information;

[0091] S2: Perform fingerprint recognition of industrial equipment, identify the type, model, and version information of the equipment in the industrial control system, determine the known vulnerabilities it has, and obtain the second vulnerability information;

[0092] S3: Perform log analysis and collect various logs of the industrial control system, including operating system logs, application logs, and equipment operation logs. Use log management and analysis tools to extract security-related event information from the logs to obtain third-party vulnerability information.

[0093] S4: Perform traffic monitoring and analysis, deploy network traffic monitoring equipment, monitor and analyze the traffic in the industrial control system network in real time, identify data packets that do not conform to the normal communication mode through the detection of traffic data, and obtain the fourth vulnerability information;

[0094] The first vulnerability information, the second vulnerability information, the third vulnerability information and the fourth vulnerability information constitute vulnerability related information;

[0095] The above process achieves multi-dimensional information acquisition. Step S1 uses vulnerability scanning tools to scan the network and detect the ports and services open to the system. Port and service information is an important basis for understanding the network exposure of industrial control systems. By mastering this information, you can know which ports and services may have potential vulnerabilities, thereby providing a clear direction for subsequent security protection. For example, certain specific ports may be common targets of hacker attacks. If the scan finds that these ports are open and have potential vulnerabilities, you can take timely measures to close the ports or strengthen protection.

[0096] Step S2 uses industrial equipment fingerprint identification to obtain the type, model, and version information of the device, and then determines the known vulnerabilities. Industrial equipment of different models and versions may have specific, discovered vulnerabilities. Identifying this information can conduct targeted vulnerability investigation and repair of the device. For example, a certain model of industrial control equipment has a remote code execution vulnerability in a specific version. After determining the device information through fingerprint identification, it can quickly determine whether the device has this risk.

[0097] Step S3 collects and analyzes various logs, extracting security-related event information from operating system logs, application logs, and device operation logs. Logs are the "black box" of system operation, recording various operations and events that occur in the system. By analyzing logs, you can find security-related information such as abnormal user logins and system errors, which helps trace attack paths and discover potential security threats. For example, the log records multiple failed login attempts by an unknown user, which may be a sign of a brute force attack.

[0098] Step S4 monitors network traffic in real time and identifies abnormal data packets through traffic monitoring and analysis. Normal industrial control system network traffic has certain patterns and rules. By detecting and identifying data packets that do not conform to normal patterns, network attack behaviors can be discovered in a timely manner. For example, detecting a large number of abnormal external connection requests or abnormal data transmission patterns may mean that the system is under network attack.

[0099] Effectively improve the accuracy and comprehensiveness of vulnerability detection. The four steps collect information from industrial control systems from different angles, complement each other, and can more comprehensively discover potential vulnerabilities. A single information collection method may miss certain types of vulnerabilities, and the combined use of multiple methods can greatly improve the coverage of vulnerability detection. For example, vulnerability scanning tools may not be able to detect known vulnerabilities based on specific device models and versions, but industrial equipment fingerprint recognition can make up for this deficiency; log analysis and traffic monitoring can discover some abnormal behaviors and potential threats that are difficult to detect in network scanning and device identification.

[0100] Through the integration and analysis of multi-dimensional information, the existence and severity of vulnerabilities can be more accurately determined. Information from different sources corroborates each other and can provide richer context to help security personnel more accurately assess risks. For example, when a vulnerability scanning tool finds a potential vulnerability in a port, and traffic monitoring finds abnormal network traffic on the port, and related security events are recorded in the log, the authenticity and severity of the vulnerability can be more certain, so that more effective countermeasures can be taken.

[0101] During the analysis of the vulnerability-related information of the industrial control system, when it is found that the industrial control system is in an abnormal state, the recommended repair information is directly generated to suggest the user to make preliminary repairs to the system, and then perform overall vulnerability matching after repairing some vulnerabilities;

[0102] The process of determining whether the industrial control system is in an abnormal state is as follows:

[0103] Extracting vulnerability related information Vulnerability related information also includes real-time vulnerability quantity information and vulnerability type information;

[0104] Vulnerability types include high-risk vulnerabilities, low-risk vulnerabilities, and specific types of vulnerabilities;

[0105] Set the vulnerability number baseline based on the average and standard deviation of historical vulnerability scanning data. For example, if the average number of vulnerabilities discovered per month in the past three months is 10 and the standard deviation is 3, then the vulnerability number baseline can be set to 10±3.

[0106] When the number of vulnerabilities found in a vulnerability scan exceeds the vulnerability baseline (for example, the number of vulnerabilities found in two consecutive scans is greater than 13), it is determined that the number of vulnerabilities is in an abnormal growth state, that is, the industrial control system is in an abnormal state;

[0107] Select key components in the industrial control system, including core controllers, data servers, and key network equipment;

[0108] When vulnerability scanning finds that the number of vulnerabilities in key system components is greater than the preset value, and the vulnerability type is a high-risk vulnerability, the industrial control system will be judged to be in an abnormal state even if the overall number of vulnerabilities does not exceed the vulnerability number baseline;

[0109] Because high-risk vulnerabilities can be easily exploited by attackers, causing serious damage to industrial control systems, such as production interruptions, data leakage, equipment damage, etc.

[0110] The number of times a specific type of vulnerability appears within a preset time period is extracted from vulnerability-related information (for example, more than 5 vulnerabilities of the same type are found in a single scan), and these vulnerabilities are distributed on different system components. This may indicate that the system has overall network security architecture defects or has been subjected to targeted attack attempts, and the industrial control system is determined to be in an abnormal state.

[0111] The specific process for performing the initial repair is as follows:

[0112] The user performs preliminary repair operations on the system in descending order of severity based on the generated recommended repair information;

[0113] After completing the initial repair of some vulnerabilities, run the vulnerability scanning tool again, and this time enable the verification-free vulnerability matching function. Verification-free vulnerability matching means that during the scanning process, the information of the fixed vulnerabilities is quickly compared with the current system status without the need to perform a complete vulnerability detection process for these fixed vulnerabilities, thereby greatly shortening the scanning time and improving efficiency.

[0114] The process of obtaining the industrial control system evaluation information is as follows:

[0115] SS1: Classify vulnerabilities. According to the preset vulnerability classification standards, classify the collected vulnerability-related information and obtain vulnerability classification information. The vulnerability classification information includes high-risk vulnerabilities, medium-risk vulnerabilities and low-risk vulnerabilities.

[0116] SS2: After classification, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are extracted;

[0117] SS3: Then, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are processed to obtain the risk score of the industrial control system. The risk score of the industrial control system is processed to obtain the industrial control system evaluation information.

[0118] The process of obtaining the risk score of the industrial control system is as follows:

[0119] Extract the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3;

[0120] Calculate the sum of K1, K2 and K3 to obtain the total vulnerability risk number, and mark the total vulnerability risk number as Kk;

[0121] Calculate the ratio Kk1 of K1 to Kk, the ratio Kk2 of K2 to Kk, and the ratio Kk3 of K3 to Kk;

[0122] By the formula (Kk2+Kk3)-Kk1=K 差 , get the industrial control system risk score K 差 ;

[0123] The specific process of processing the risk score of the industrial control system, that is, obtaining the industrial control system assessment information, is as follows:

[0124] When the industrial control system risk score K 差When it is greater than the preset value a1, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a first-level industrial control system evaluation, that is, the risk of the industrial control system is relatively low;

[0125] When the industrial control system risk score K 差 When the value is between the preset values ​​a1 and a2, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a level 2 industrial control system evaluation, which means that the industrial control system has certain risks.

[0126] When the industrial control system risk score K 差 When it is less than the preset value a2, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a level 3 industrial control system evaluation, which means that the industrial control system has a high risk.

[0127] The above process realizes quantitative risk assessment. By classifying vulnerabilities and calculating corresponding risk scores, the security status of complex industrial control systems is converted into specific values, providing a unified and intuitive measurement standard. Compared with simply describing which vulnerabilities exist, risk scores can more concisely reflect the overall risk level of the system, making it easier for security managers to quickly understand the security status of the system. For example, different industrial control systems may have different types and numbers of vulnerabilities. Through risk scoring, their risk sizes can be directly compared without having to analyze the specific circumstances of each vulnerability in detail.

[0128] It highlights the key risks, differentiates the risk levels, and divides the vulnerabilities into three categories: high, medium, and low risk, which can clearly highlight the impact of different vulnerabilities on system security. High-risk vulnerabilities may lead to serious consequences such as system paralysis and data leakage. By clarifying their number and proportion, they are reflected in the calculation of risk scores, allowing security managers to quickly focus on the vulnerabilities that pose the greatest threat to the system, give priority to handling these key issues, and effectively reduce the possibility of the system suffering from major security accidents.

[0129] Different risk levels of vulnerabilities require different handling strategies. For high-risk vulnerabilities, emergency measures need to be taken immediately to repair them; medium-risk vulnerabilities can be repaired according to actual conditions; low-risk vulnerabilities can be monitored regularly. This targeted protection strategy can maximize the security of industrial control systems under limited resource conditions.

[0130] As the operation and environment of industrial control systems change, the vulnerability situation will also change continuously. By regularly classifying, scoring and evaluating vulnerabilities, the risk status of the system can be dynamically tracked and the changing trend of risks can be discovered in a timely manner. For example, if the risk score of an industrial control system gradually increases, it means that the system may have new security issues or the impact of the original vulnerability is expanding, and timely measures need to be taken to deal with it.

[0131] The process of establishing the vulnerability matching library is as follows:

[0132] S(1): Collecting industrial control system type information, including the brand, model, version, industrial control protocol used, and system architecture and topology of the industrial control system;

[0133] S(2): Based on the acquired industrial control system assessment information and system type information, the vulnerability information with the highest matching degree with the current industrial control system is screened out from a preset database (a public vulnerability database, security bulletins issued by industrial control system manufacturers, and reports from professional security research institutions) as the baseline vulnerability information. The baseline vulnerability information is associated and integrated with the system type information to construct a real-time vulnerability matching library for the industrial control system that requires verification-free vulnerability matching. The real-time vulnerability matching library includes detailed feature information of the vulnerability, detection methods, and corresponding repair measures.

[0134] Comprehensive information collection: In addition to vulnerability information, detailed architecture information of the industrial control system needs to be collected, including network topology, device connection relationships, operating system and application versions, control logic, etc. This information can be obtained by manually drawing network topology diagrams, compiling device lists, and communicating with system administrators, or it can be collected and organized using automated network discovery and asset management tools.

[0135] Vulnerability data integration and cleaning: Obtain vulnerability information from multiple authoritative vulnerability databases (such as CVE, NVD, ICS-CERT, etc.) and security bulletins issued by manufacturers, and integrate and cleanse this data. Remove duplicate data, correct erroneous or inconsistent information, and ensure the accuracy and completeness of vulnerability data.

[0136] Establish a feature library: For different types of vulnerabilities, extract their unique feature information, such as specific port numbers, protocol behaviors, code snippets, system call sequences, etc., and organize these feature information into a feature library that can be used for matching. The establishment of the feature library can adopt a rule-based method, or it can be combined with a machine learning algorithm for automatic feature extraction and classification, so as to more efficiently identify and match vulnerabilities.

[0137] Build a vulnerability matching library: Associate the organized and feature-extracted vulnerability information with the corresponding system architecture information to build a complete vulnerability matching library. The library should be able to quickly locate possible vulnerabilities based on various feature information of the industrial control system, and provide detailed vulnerability descriptions, repair suggestions and other related information to provide data support for subsequent intelligent vulnerability matching.

[0138] The specific process of step 4 is as follows:

[0139] SS(1): Matching based on rules;

[0140] First, formulate rules. According to the characteristic information of each vulnerability in the vulnerability matching library, write corresponding matching rules. After collecting the operating data of the industrial control system in real time, compare the operating data of the industrial control system with the pre-set matching rules one by one.

[0141] For network traffic data, check whether there is a port access mode that meets the description in the rules. If there is a port access mode that does not meet the description in the rules, an alert message is generated to warn;

[0142] For system log data, check whether there are error codes or abnormal operation records related to the rules. When there are error codes or abnormal operation records, generate warning information to warn;

[0143] SS(2): Perform pattern matching detection:

[0144] Extract standard behavior patterns of various vulnerabilities from the vulnerability matching library, and perform pattern recognition on the real-time collected industrial control system operation data, which includes network traffic data and device status data;

[0145] Use a string matching algorithm to find out whether there is a segment consistent with the pattern template in the operation data of the industrial control system. When there is a segment consistent with the pattern template, an alarm message is generated to warn;

[0146] For network traffic data, the data packet content is compared with the pattern template. When there is a segment that is consistent with the pattern template, an alert message is generated to warn;

[0147] For the equipment status data, check whether the equipment status change sequence conforms to a specific pattern. When the equipment status data does not conform to the specific pattern, generate a warning message to warn;

[0148] SS(3) uses machine learning algorithms for detection:

[0149] Clean and normalize the industrial control system operation data collected in real time to make it suitable for the input requirements of the machine learning algorithm;

[0150] Use historical normal operation data to train the anomaly detection model, input the industrial control system data collected in real time into the trained model, and the model determines whether there is an anomaly based on the degree of deviation between the industrial control system data and the trained model;

[0151] When the degree of deviation exceeds the set threshold, it is considered that there may be abnormal behavior related to the vulnerability, and a warning message is generated to warn;

[0152] Extract vulnerability-related features from the industrial control system operation data. The vulnerability-related features include the protocol type, port number, and data length in the network traffic, and the event type, timestamp, and user ID in the system log. Combine and filter the above vulnerability-related features to form a feature vector for classification.

[0153] Use pre-labeled historical data to train the classification model. During the training process, the model learns the relationship between different features and vulnerabilities and establishes the classification decision boundary.

[0154] The industrial control system data collected in real time is converted into feature vectors and input into the trained classification model. The model determines whether the data belongs to the vulnerability category based on the learned decision boundary. If it is determined to be a vulnerability category, an alert message is generated for warning.

[0155] The results of rule-based matching, pattern matching and machine learning algorithms are integrated, and the weights can be set. The weight of rule-based matching results is 0.3, the weight of pattern matching results is 0.3, and the weight of machine learning algorithm results is 0.4;

[0156] The matching scores of the three algorithms are weighted and summed according to the weights to obtain the final matching score. When the final matching score exceeds the set threshold, it is determined that there may be a corresponding vulnerability, and a warning message is generated for warning;

[0157] The above process realizes the complementary advantages of detection methods. It can compile rules based on known vulnerability characteristics to quickly and accurately detect specific types of vulnerabilities. For network traffic data, port access modes can be directly checked according to the rules; for system log data, relevant error codes or abnormal operation records can be quickly found. This method is simple and direct, and is highly efficient for detecting known and clearly characterized vulnerabilities. It can detect obvious signs of vulnerabilities at the first time, providing support for timely warnings and processing.

[0158] Standard behavior patterns are extracted from the vulnerability matching library to perform pattern recognition on network traffic and device status data. Whether it is searching for pattern fragments in the data through string matching algorithms or checking the device status change sequence, some abnormal patterns hidden in the data can be found. This method can detect some vulnerabilities with specific behavior patterns that are difficult to cover by some rules, expand the scope of detection, and improve the ability to identify complex vulnerabilities.

[0159] By cleaning and normalizing the operating data of the industrial control system, the anomaly detection model and classification model are trained using the historical normal operation data. The anomaly detection model can determine whether there is an anomaly based on the degree of deviation between the data and normal behavior, and the classification model can learn the relationship between different features and vulnerabilities, thereby effectively detecting unknown and complex vulnerabilities. The machine learning algorithm has strong adaptability and learning ability, and can continuously optimize the detection effect as the data accumulates, and discover new vulnerability threats.

[0160] It can also improve the accuracy and reliability of detection. The three detection methods analyze the operating data of the industrial control system from different angles. Rule-based matching focuses on known features, pattern matching detection focuses on behavioral patterns, and machine learning algorithm detection emphasizes the overall characteristics and abnormalities of the data. Through multi-dimensional detection, various possible vulnerability situations can be more comprehensively covered, the probability of missed detection and false detection of vulnerabilities can be reduced, and the accuracy of detection results can be improved.

[0161] The results of the three algorithms are combined according to certain weights to give full play to the advantages of each method. Different algorithms may perform differently in different scenarios. The final matching score is obtained by weighted summation, which can comprehensively consider various factors and make the detection results more reliable. For example, for some vulnerabilities with obvious known features, rule-based matching may be more accurate; while for some new vulnerabilities that are difficult to describe with rules, machine learning algorithms may be more effective. By fusing the results, more accurate judgments can be made in different situations.

[0162] Regardless of the detection method used, once a possible vulnerability is found, an alert message will be generated to warn. This timely feedback mechanism allows security managers to respond quickly and take appropriate measures to deal with the vulnerability, reducing the time window for the vulnerability to be exploited and reducing security risks. For example, when abnormal network traffic is found or abnormal operation records are found in the system log, relevant personnel can be notified immediately to investigate and handle it, avoiding further expansion of security incidents.

[0163] Matching evaluation information includes matching effect evaluation and resource usage evaluation:

[0164] Matching evaluation information includes first-level matching evaluation, second-level matching evaluation and third-level matching evaluation. The specific process of matching evaluation information is as follows:

[0165] Extract vulnerability matching related information, which is obtained through manual inspection, reports from professional security assessment agencies, and system vulnerability scanning;

[0166] Vulnerability matching related information includes a list of actual vulnerabilities in the industrial control system. The vulnerability list includes vulnerability information and resource usage information matched by the vulnerability library.

[0167] Organize the vulnerability information matched by the vulnerability library, extract the vulnerability list matched by the vulnerability library from the records of the vulnerability matching process, and also record the relevant detailed information of each matching vulnerability;

[0168] Calculate the accuracy of the matching index, traverse the vulnerability list matched by the vulnerability library, and for each matched vulnerability, search and verify it in the actual vulnerability list. If the corresponding vulnerability is found in the actual vulnerability list, the match is considered correct;

[0169] The number of correctly matched vulnerabilities is counted and marked as Tp, and the total number of matched vulnerabilities is recorded as Tm;

[0170] The accuracy rate Tt1 is obtained through the formula Tt1=Tp / Tm;

[0171] Then calculate the recall rate: traverse the actual vulnerability list, and for each actual vulnerability, check whether there is a corresponding match in the vulnerability list matched by the vulnerability library. If so, it is recorded as a successful match;

[0172] The actual number of successfully matched vulnerabilities is counted, marked as Tp, and the total number of existing vulnerabilities is recorded as Tv;

[0173] The recall rate Tt2 is obtained through the formula Tt2 = Tp / Tv;

[0174] Evaluation and Analysis Based on the calculated accuracy Tt1 and recall Tt2, the matching effect of the verification-free vulnerability library is evaluated;

[0175] When the precision rate Tt1 and the recall rate Tt2 are both greater than or equal to the preset value, a first-level matching evaluation is generated;

[0176] When either the precision rate Tt1 or the recall rate Tt2 is less than the preset value, a secondary matching evaluation is generated;

[0177] When both the precision rate Tt1 and the recall rate Tt2 are less than the preset values, a three-level matching evaluation is generated.

[0178] The resource occupation assessment includes primary resource assessment, secondary resource assessment and tertiary resource assessment;

[0179] The specific process of resource occupancy evaluation is as follows: extracting resource occupancy information, which includes CPU occupancy, memory occupancy and network bandwidth occupancy;

[0180] When the CPU usage, memory usage, and network bandwidth usage are all less than the preset values, a first-level resource assessment is generated;

[0181] When any one of the CPU usage, memory usage and network bandwidth usage is greater than or equal to the preset value, a secondary resource evaluation is generated;

[0182] When any two or more of the CPU usage, memory usage, and network bandwidth usage are greater than or equal to the preset value, a third-level resource evaluation is generated;

[0183] The accuracy (Tt1) and recall (Tt2) are calculated by clear formulas, presenting the effect of vulnerability matching in a quantitative form. The accuracy reflects the actual correct proportion of matched vulnerabilities, while the recall reflects the proportion of actually existing vulnerabilities that are successfully matched. These two indicators complement each other and allow security personnel to clearly and accurately understand the performance of the vulnerability matching library in identifying vulnerabilities, rather than relying solely on vague qualitative judgments.

[0184] Different levels of matching evaluation are performed based on the calculation results of accuracy and recall. When at different evaluation levels, it can help security personnel quickly locate problems in the vulnerability matching process. For example, if the accuracy is low, it may mean that there are misjudgments in the matching rules; if the recall rate is low, it may be that the vulnerability matching library is not comprehensive enough or there are omissions in the detection method. Through this precise positioning, it is convenient to optimize and improve the vulnerability matching system in a targeted manner.

[0185] The vulnerability matching effects under different time periods or different configurations can be compared and analyzed. For example, after updating the vulnerability matching library or adjusting the detection algorithm, the accuracy and recall rates are calculated again, and the changes in the evaluation level are observed to determine whether the improvement measures are effective. This provides a strong basis for the continuous optimization of the vulnerability matching system, helps to continuously improve the matching effect, and more effectively discover vulnerabilities in industrial control systems.

[0186] Using CPU occupancy, memory occupancy, and network bandwidth occupancy as evaluation indicators can fully reflect the occupation of industrial control system resources by the vulnerability matching process. These resources are key elements for the normal operation of industrial control systems. By monitoring their occupancy in real time, we can promptly understand whether the vulnerability matching task affects the normal operation of the system.

[0187] The resource usage is graded and evaluated based on preset values. When the resource usage is at different levels, corresponding measures can be taken to ensure the stable operation of the system. In the first-level resource evaluation, it means that the resource usage is at a low level and the system operation is not affected; the second-level resource evaluation indicates that you may need to pay attention to the resource usage; the third-level resource evaluation indicates that the resource usage is too high and you may need to adjust the vulnerability matching strategy or optimization algorithm to avoid system performance degradation or even crash due to resource exhaustion.

[0188] The resource occupancy assessment results can provide a reference for resource planning of industrial control systems. For situations where resource occupancy is high, when upgrading hardware or deploying the system, you can consider increasing the corresponding resource configuration in advance to meet the needs of vulnerability matching tasks. At the same time, it also helps to reasonably allocate resources among multiple security tasks to ensure that the security and stability of the entire industrial control system are balanced.

[0189] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.

Claims

1. An intelligent matching method for industrial control system vulnerabilities without verification, characterized in that: The following steps are involved: Step 1: Collect information related to the vulnerabilities of the industrial control system; Step 2: Analyze the vulnerability-related information of the industrial control system and obtain the industrial control system assessment information; Step 3: Collect the industrial control system type information again, and establish a vulnerability matching library based on the industrial control system evaluation information and industrial control system type information; Step 4: Perform verification-free vulnerability intelligent matching through the established vulnerability matching library, and issue a warning message when a vulnerability is matched; Step 5: During the vulnerability matching process, monitor the vulnerability matching process in real time and obtain vulnerability matching related information; Step 6: Analyze the vulnerability matching related information to obtain matching evaluation information.

2. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 1 is characterized in that: The specific process of collecting information related to the vulnerability of the industrial control system is as follows: S1: Use vulnerability scanning tools to scan the network where the industrial control system is located, detect the open ports, services and potential vulnerabilities of the system, and obtain the first vulnerability information; S2: Perform fingerprint recognition of industrial equipment, identify the type, model, and version information of the equipment in the industrial control system, determine the known vulnerabilities it has, and obtain the second vulnerability information; S3: Perform log analysis and collect various logs of the industrial control system, including operating system logs, application logs, and equipment operation logs. Use log management and analysis tools to extract security-related event information from the logs to obtain third-party vulnerability information. S4: Perform traffic monitoring and analysis, deploy network traffic monitoring equipment, monitor and analyze the traffic in the industrial control system network in real time, identify data packets that do not conform to the normal communication mode through the detection of traffic data, and obtain the fourth vulnerability information; The first vulnerability information, the second vulnerability information, the third vulnerability information and the fourth vulnerability information constitute vulnerability related information.

3. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 2 is characterized in that: The process of obtaining the industrial control system evaluation information is as follows: SS1: Classify vulnerabilities. According to the preset vulnerability classification standards, classify the collected vulnerability-related information and obtain vulnerability classification information. The vulnerability classification information includes high-risk vulnerabilities, medium-risk vulnerabilities and low-risk vulnerabilities. SS2: After classification, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are extracted; SS3: Then, the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3 are processed to obtain the risk score of the industrial control system. The risk score of the industrial control system is processed to obtain the industrial control system evaluation information.

4. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 2 is characterized in that: The process of obtaining the risk score of the industrial control system is as follows: Extract the number of high-risk vulnerabilities K1, the number of medium-risk vulnerabilities K2, and the number of low-risk vulnerabilities K3; Calculate the sum of K1, K2 and K3 to obtain the total vulnerability risk number, and mark the total vulnerability risk number as Kk; Calculate the ratio Kk1 of K1 to Kk, the ratio Kk2 of K2 to Kk, and the ratio Kk3 of K3 to Kk; By the formula (Kk2+Kk3)-Kk1=K 差 , get the industrial control system risk score K 差 ; The specific process of processing the risk score of the industrial control system, that is, obtaining the industrial control system assessment information, is as follows: When the industrial control system risk score K 差 When it is greater than the preset value a1, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a first-level industrial control system evaluation, that is, the risk of the industrial control system is relatively low; When the industrial control system risk score K 差 When the value is between the preset values ​​a1 and a2, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a level 2 industrial control system evaluation, which means that the industrial control system has certain risks. When the industrial control system risk score K 差 When it is less than the preset value a2, the industrial control system evaluation information is generated. At this time, the industrial control system evaluation information is a third-level industrial control system evaluation, that is, the industrial control system has a relatively high risk.

5. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 1 is characterized in that: The process of establishing the vulnerability matching library is as follows: S(1): Collecting industrial control system type information, including the brand, model, version, industrial control protocol used, and system architecture and topology of the industrial control system; S(2): Based on the acquired industrial control system assessment information and system type information, the vulnerability information with the highest matching degree with the current industrial control system is screened out from a preset database as the baseline vulnerability information. The baseline vulnerability information is associated and integrated with the system type information to construct a real-time vulnerability matching library for the industrial control system that requires verification-free vulnerability matching. The real-time vulnerability matching library includes detailed feature information of the vulnerability, detection methods, and corresponding repair measures.

6. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 1 is characterized in that: The specific process of step 4 is as follows: SS(1): Matching based on rules; First, formulate rules. According to the characteristic information of each vulnerability in the vulnerability matching library, write corresponding matching rules. After collecting the operating data of the industrial control system in real time, compare the operating data of the industrial control system with the pre-set matching rules one by one. For network traffic data, check whether there is a port access mode that meets the description in the rules. If there is a port access mode that does not meet the description in the rules, an alert message is generated to warn; For system log data, check whether there are error codes or abnormal operation records related to the rules. When there are error codes or abnormal operation records, generate warning information to warn; SS(2): Perform pattern matching detection: Extract standard behavior patterns of various vulnerabilities from the vulnerability matching library, and perform pattern recognition on the real-time collected industrial control system operation data, which includes network traffic data and device status data; Use a string matching algorithm to find out whether there is a segment consistent with the pattern template in the operation data of the industrial control system. When there is a segment consistent with the pattern template, an alarm message is generated to warn; For network traffic data, the data packet content is compared with the pattern template. When there is a segment that is consistent with the pattern template, an alert message is generated to warn; For the equipment status data, check whether the equipment status change sequence conforms to a specific pattern. When the equipment status data does not conform to the specific pattern, generate a warning message to warn; SS(3) uses machine learning algorithms for detection: Clean and normalize the industrial control system operation data collected in real time to make it suitable for the input requirements of the machine learning algorithm; Use historical normal operation data to train the anomaly detection model, input the industrial control system data collected in real time into the trained model, and the model determines whether there is an anomaly based on the degree of deviation between the industrial control system data and the trained model; When the degree of deviation exceeds the set threshold, it is considered that there may be abnormal behavior related to the vulnerability, and a warning message is generated to warn; Extract vulnerability-related features from the industrial control system operation data. The vulnerability-related features include the protocol type, port number and data length in the network traffic, the event type, timestamp and user ID in the system log, and combine and filter the above vulnerability-related features to form a feature vector for classification; Use pre-labeled historical data to train the classification model. During the training process, the model learns the relationship between different features and vulnerabilities and establishes the classification decision boundary. The industrial control system data collected in real time is converted into feature vectors and input into the trained classification model. The model determines whether the data belongs to the vulnerability category based on the learned decision boundary. If it is determined to be a vulnerability category, an alert message is generated for warning. The results of rule-based matching, pattern matching and machine learning algorithms are integrated, and the weights can be set. The weight of rule-based matching results is 0.3, the weight of pattern matching results is 0.3, and the weight of machine learning algorithm results is 0.4; The matching scores of the three algorithms are weighted and summed according to the weights to obtain the final matching score. When the final matching score exceeds the set threshold, it is determined that there may be a corresponding vulnerability, and a warning message is generated for warning.

7. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 1 is characterized in that: Matching evaluation information includes matching effect evaluation and resource usage evaluation: Matching evaluation information includes first-level matching evaluation, second-level matching evaluation and third-level matching evaluation. The specific process of matching evaluation information is as follows: Extract vulnerability matching related information, which is obtained through manual inspection, reports from professional security assessment agencies, and system vulnerability scanning; Vulnerability matching related information includes a list of actual vulnerabilities in the industrial control system. The vulnerability list includes vulnerability information and resource usage information matched by the vulnerability library. Organize the vulnerability information matched by the vulnerability library, extract the vulnerability list matched by the vulnerability library from the records of the vulnerability matching process, and also record the relevant detailed information of each matching vulnerability; Calculate the accuracy of the matching index, traverse the vulnerability list matched by the vulnerability library, and for each matched vulnerability, search and verify it in the actual vulnerability list. If the corresponding vulnerability is found in the actual vulnerability list, the match is considered correct; The number of correctly matched vulnerabilities is counted and marked as Tp, and the total number of matched vulnerabilities is recorded as Tm; The accuracy rate Tt1 is obtained through the formula Tt1=Tp / Tm; Then calculate the recall rate: traverse the actual vulnerability list, and for each actual vulnerability, check whether there is a corresponding match in the vulnerability list matched by the vulnerability library. If so, it is recorded as a successful match; The actual number of successfully matched vulnerabilities is counted, marked as Tp, and the total number of existing vulnerabilities is recorded as Tv; The recall rate Tt2 is obtained through the formula Tt2 = Tp / Tv; Evaluation and Analysis Based on the calculated accuracy Tt1 and recall Tt2, the matching effect of the verification-free vulnerability library is evaluated; When the precision rate Tt1 and the recall rate Tt2 are both greater than or equal to the preset value, a first-level matching evaluation is generated; When either the precision rate Tt1 or the recall rate Tt2 is less than the preset value, a secondary matching evaluation is generated; When both the precision rate Tt1 and the recall rate Tt2 are less than the preset values, a three-level matching evaluation is generated.

8. The verification-free vulnerability intelligent matching method for industrial control systems according to claim 7 is characterized in that: The resource occupation assessment includes primary resource assessment, secondary resource assessment and tertiary resource assessment; The specific process of resource occupancy evaluation is as follows: extracting resource occupancy information, which includes CPU occupancy, memory occupancy and network bandwidth occupancy; When the CPU usage, memory usage, and network bandwidth usage are all less than the preset values, a first-level resource assessment is generated; When any one of the CPU usage, memory usage and network bandwidth usage is greater than or equal to the preset value, a secondary resource evaluation is generated; When any two or more of the CPU usage, memory usage, and network bandwidth usage are greater than or equal to the preset value, a third-level resource assessment is generated.