Industrial field network security online monitoring system

By introducing asset identification, topology analysis, risk assessment and decision support modules into the industrial network security monitoring system, combined with stateless scanning technology and graph convolutional network, it solves the problem that traditional systems are difficult to prevent new attacks and identify potential vulnerabilities, and realizes automation and intelligence of network security management, and improves security protection capabilities.

CN120050104AInactive Publication Date: 2025-05-27SAISHENG DIGITAL ECONOMY RESEARCH INSTITUTE (GUANGZHOU) CO LTD

Patent Information

Application Number
CN202510234692.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional industrial network security monitoring systems have static protection, lack of dynamic updates and intelligent evaluation capabilities, making it difficult to effectively prevent new attacks and identify potential security vulnerabilities, resulting in the inability to detect and deal with security risks in a timely manner.

Method used

An online monitoring system for network security in the industrial field is designed, including asset identification module, topology analysis module, risk assessment module, dynamic update module and decision support module. Through the combination of stateless scanning technology, graph convolution network and vulnerability library, it can identify device status in real time, analyze network topology, dynamically evaluate risks and provide intelligent decision support.

Benefits of technology

It realizes the automation and intelligence of network security management, can promptly detect potential security threats, provide accurate protective measures and emergency response solutions, and improves network security protection capabilities and response speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050104A_ABST
    Figure CN120050104A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security in the industrial field, and discloses an industrial field network security online monitoring system, which comprises an asset identification module, a topology analysis module, a risk assessment module, a dynamic updating module, a decision support module and a visualization module, the system obtains equipment information in the network through a stateless scanning technology, constructs an equipment topological graph, and evaluates equipment risks based on a graph convolutional network; by monitoring the equipment state and the topological structure in real time, the system can dynamically update the risk score and provide an accurate safety assessment result; and according to an evaluation result, the system generates a network security management decision suggestion, and helps a network administrator to effectively manage and cope with the network security risk through multi-dimensional visual display of an equipment state, a risk score, vulnerability information and the like. The method has the advantages of comprehensive equipment identification, dynamic risk assessment, intelligent decision support, visual display and the like, and the efficiency and the automation level of network security management are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security in the industrial field, specifically an online monitoring system for network security in the industrial field. Background Art

[0002] With the rapid development of information technology, network security in the industrial field faces increasingly complex challenges. Traditional network security protection mainly relies on technologies such as static firewalls and intrusion detection systems. Although these means can provide a certain degree of protection against known threats, they lack effective prevention and response mechanisms for new attacks and potential security vulnerabilities. At the same time, traditional network security monitoring mostly relies on manual intervention and regular inspections, which has a certain lag, resulting in security risks not being discovered and processed in a timely manner.

[0003] In addition, existing technologies often focus on single-dimensional risk assessment and lack comprehensive device identification and network topology analysis. This makes it difficult for network managers to clearly understand the connection relationships between devices, potential vulnerability points, and the risk levels of different devices when facing complex devices and changing network topologies. Moreover, existing network security protection systems lack the ability of dynamic update and intelligent evaluation, and cannot automatically adjust the risk assessment results when the device status or network topology changes, resulting in the management of the network security situation not being consistent with the actual network situation. Summary of the Invention

[0004] In view of the deficiencies of the prior art, the present invention provides an online monitoring system for network security in the industrial field, which is a comprehensive network security monitoring system capable of real-time identifying device status, analyzing network topology, dynamically evaluating risks, and providing intelligent decision-making support, so as to improve the automation and intelligence levels of network security management.

[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: An online monitoring system for network security in the industrial field, including: An asset identification module, used to obtain device information in the network through stateless scanning technology and construct a device topology map; A topology analysis module, used to perform topology data analysis on the device topology map to identify the connection patterns and potential vulnerability points between devices; A risk assessment module, which scores the security risks of devices based on a graph convolutional network and generates a risk assessment result in combination with a vulnerability database; A dynamic update module, used to periodically update device information and topological structure and adjust the risk assessment result in real time; A decision support module, which generates network security decision-making suggestions according to the risk assessment result.

[0006] Preferably, the asset identification module includes: Device scanning unit, which is used to scan devices in the network through stateless scanning technology, identify basic information of the devices, including IP address, device type, manufacturer information, operating system version, and port opening status; Device topology construction unit, which is used to construct the network topology structure between devices according to the device scanning results, and generate a connection relationship diagram between devices; Device classification unit, which is used to classify devices into different categories according to device characteristics, including industrial control systems, Internet of Things terminals, and other network devices, and identify their security characteristics according to the device categories.

[0007] Preferably, the device topology construction unit constructs the device topology through the following steps: According to the device information provided by the device scanning unit, identify the physical connection relationship between devices; Analyze the communication data packets between devices based on the network communication protocol to determine the logical connection relationship between devices; Combine the physical connection and the logical connection to generate a complete topology structure diagram between devices, including the IP address, type, connection port, and communication path information of the devices; Optimize the topology structure diagram according to the device communication frequency and interaction mode to ensure that the secure communication path between devices is accurately identified.

[0008] Preferably, the topology analysis module includes: Topology data acquisition unit, which is used to extract the connection relationship information between devices from the device topology diagram, including the connection path, port information, and communication protocol of the devices; Topology structure analysis unit, which is used to analyze the stability, reliability, and potential vulnerability points of the device topology structure based on the connection relationship between devices; Key node identification unit, which is used to identify key device nodes in the network, including core switches, routers, and bridging nodes between devices, and evaluate their security risks; Vulnerability point analysis unit, which is used to analyze the weak links in the network topology, identify potential attack surfaces and security hazards.

[0009] Preferably, the risk assessment module includes: Risk score calculation unit, which is used to score the security risks of devices based on the graph convolutional network, considering device vulnerabilities, manufacturer repair status, and the network connection relationship between devices; Vulnerability information matching unit, which is used to obtain vulnerability information related to devices from the vulnerability database and match it with the device risk score to generate a comprehensive risk score; Security situation analysis unit, which is used to analyze the network security situation by combining the risk score of the device and the network topology information, identify potential threats, and evaluate the security protection requirements; A dynamic assessment unit for real - time updating the risk score of a device and adjusting the risk assessment result according to changes in the network environment and device status.

[0010] Preferably, the risk score calculation unit calculates the risk score through the following steps: Obtain the vulnerability information of the device, including the severity, repair status, and vulnerability type of known vulnerabilities; Analyze the network connection relationships of the device, including the communication paths, port opening conditions, and communication protocols between devices, and evaluate the potential attack surface exposed by the device; Based on the graph convolutional network model, combine the vulnerability information and network connection relationships of the device to calculate the preliminary risk score of each device; adjust the risk score according to the network environment where the device is located and its role, considering the importance of the device and its core position in the network; Output the final risk score of the device, reflecting the current security status and potential risks of the device.

[0011] Preferably, the dynamic update module includes: A device status monitoring unit for real - time monitoring of changes in the status of devices in the network, including the online, offline, and configuration changes of devices; A topology structure update unit for dynamically updating the network topology information of devices according to device status changes to ensure the accuracy of the topology structure; A risk assessment trigger unit for triggering the risk assessment module to recalculate the risk score of the device according to topology structure updates or device status changes; A data synchronization unit for synchronously updating the device status, topology information, and risk assessment results with the system database to ensure the consistency and timeliness of information.

[0012] Preferably, the decision - making support module includes: A risk priority assessment unit for assessing the security risk priority of a device according to the risk score and vulnerability information of the device; a protection strategy generation unit for generating network security protection strategies according to the risk priority, providing protection suggestions and countermeasures; An emergency response recommendation unit for recommending emergency response measures for high - risk devices according to the risk assessment results to reduce potential security threats; A decision - making output unit for outputting network security management decision - making suggestions according to the generated protection strategies and emergency response measures for network administrators to make decisions.

[0013] Preferably, the system further includes: A visualization module for visually displaying the risk score, network topology structure, vulnerability information, and protection strategies of the device through a graphical interface.

[0014] The present invention also provides an online monitoring method for network security in the industrial field, including the following steps: Obtain device information in the network through stateless scanning technology and construct a device topology map; Conduct topological data analysis on the device topology map to identify the connection patterns and vulnerability points between devices; Generate a device risk score based on a graph convolutional network combined with a vulnerability database and output a risk assessment result; Periodically update the device information and topological structure and adjust the risk assessment result in real time; Generate network security management decision-making suggestions based on the risk assessment result; Multidimensionally visualize the device status and risk assessment result by region, manufacturer, and vulnerability category.

[0015] The present invention provides an online monitoring system for network security in the industrial field. It has the following beneficial effects: 1. Through the combination of stateless scanning technology and a graph convolutional network, the present invention can accurately identify various devices in the network and generate a detailed risk score for the devices. This comprehensive device identification and risk assessment ability helps to timely discover potential security threats and provides data support for network security protection, ensuring the security of the network environment.

[0016] 2. By periodically updating the device information and network topological structure, the present invention adjusts the risk score of the device in real time. This dynamic update mechanism can cope with changes in device status and adjustments to the network topology, ensuring that the risk assessment result always remains accurate and timely, and improving the response speed and predictability to network security threats.

[0017] 3. Based on the device risk score and network security situation, the present invention can generate targeted security management decision-making suggestions and provide clear protection measures and emergency response plans for network administrators. These decision-making supports help administrators make timely and effective security decisions, thus effectively reducing security hazards and coping with sudden security incidents.

[0018] 4. The present invention provides multi-dimensional visualization based on regions, manufacturers, vulnerability categories, etc., enabling the network device status, topological structure, and risk assessment result to be intuitively presented in a graphical manner. This visualization improves network administrators' understanding and control of the security situation and facilitates the timely discovery and repair of potential vulnerabilities.

[0019] 5. Through automated device scanning, topological analysis, and risk assessment, the present invention reduces the need for manual intervention, improves the efficiency and accuracy of network security management. Combined with intelligent risk assessment and decision-making support, the system can autonomously identify security threats and provide corresponding countermeasures, thus effectively enhancing the network security protection ability. Brief Description of the Drawings

[0020] Figure 1 is a schematic structural diagram of the system of the present invention; Figure 2 is a schematic flowchart of the method of the present invention. Detailed Embodiments

[0021] Next, in conjunction with the accompanying drawings of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0022] Please refer to the attached Figure 1 , the present invention provides an industrial network security online monitoring system, aiming to improve the security of industrial control systems (ICS), Internet of Things (IoT) terminals, and other network devices. By realizing real-time identification of device assets, analysis of network topologies, dynamic adjustment of risk assessments, and intelligent support for security decisions, this system effectively guarantees the security of industrial networks.

[0023] As Figure 1 shown, the industrial network security online monitoring system may include: an asset identification module, a topology analysis module, a risk assessment module, a dynamic update module, a decision support module, and a visualization module. These modules cooperate with each other to jointly complete the functions of network security monitoring, risk assessment, and protection strategy formulation.

[0024] The following are the detailed descriptions of each module in the method of the present invention, and a comprehensive elaboration is carried out on the specific implementation principles, technical details, and processes of each module.

[0025] For the asset identification module, in this embodiment, the design and implementation of the asset identification module are achieved through the collaborative work of three main units, aiming to realize the automatic identification, classification of devices in the network, and detection of their security features. Through a series of steps such as device scanning, topology construction, and device classification, this module comprehensively obtains the key information of network devices, thereby optimizing the security and manageability of the network environment.

[0026] First, the asset identification module includes a device scanning unit. This unit uses stateless scanning technology to scan devices in the network and identify the basic information of the devices. Specifically, stateless scanning technology can obtain the device's IP address, device type, manufacturer information, operating system version, and port opening status by sending specific data packets and analyzing the responses in the network. This technology avoids the performance loss and network load problems that may be brought by traditional scanning methods, ensuring the device identification task is completed efficiently and with low impact.

[0027] For example, when the device scanning unit starts to execute, it may send simple probe packets to each device in the network to obtain its response information. By analyzing the responses returned by the devices, the system can further identify the manufacturer information, operating system type and its version number of the devices, and even determine whether the ports of the devices are open to the outside world. This information provides key data support for subsequent topology construction and device classification.

[0028] Next, the device topology construction unit constructs the network topology structure between devices based on the device scanning results. The specific operations include identifying the physical connection relationships between devices, analyzing communication protocols to determine logical connection relationships, and finally generating a complete topology structure diagram of the devices. In this step, the identification of physical connection relationships mainly relies on the device information provided by the scanning unit, such as the IP address and connection ports of the devices, which can help determine the relative positions of the devices in the physical network.

[0029] In addition, the topology construction unit further determines the logical connection relationships by analyzing the communication data packets between devices in the network. The data packets in network communication protocols (such as the TCP / IP protocol) carry details about the communication between devices, and these details help the system identify which devices have communication relationships. The logical connection information obtained by this unit in this way, combined with the physical connection information, finally generates a complete topology diagram of network devices, including key data such as the IP address, device type, connection ports, and communication paths of each device.

[0030] To ensure that the communication paths between devices are not only correct but also secure, the topology construction unit will also optimize the topology structure diagram according to the communication frequency and interaction mode of the devices. The goal of this optimization step is to ensure that the communication paths of each device in the network can be accurately identified and potential security risks are avoided, such as insecure port exposure or unauthorized communication between devices.

[0031] Finally, the device classification unit is responsible for classifying the devices in the network into different categories according to their characteristics and further identifying their security features. Specifically, this unit will identify and distinguish industrial control systems, Internet of Things terminals, and other types of network devices based on the device's scan information and network behavior. Each type of device may have different security requirements and protection characteristics according to its specific functions and usage environments. Therefore, classifying devices is a very important step.

[0032] For example, industrial control systems usually have extremely high requirements for network stability and security, while Internet of Things devices may have more security vulnerabilities and external attack risks. By classifying devices, the asset identification module can provide more precise security protection measures for different types of devices.

[0033] In this embodiment, through the coordinated work of device scanning, topology construction, and the device classification unit, the asset identification module can comprehensively identify the basic information of devices in the network, the connection relationships between devices, and provide support for the security protection of devices. This module not only improves the accuracy of network device identification but also enhances the security of the network topology structure, providing an important foundation for subsequent security monitoring and protection.

[0034] For the topology analysis module, in this embodiment, through the collaborative action of multiple functional units, the topology analysis module can comprehensively analyze and evaluate the stability, security, and potential vulnerabilities of the network topology structure. This module aims to improve the network's security protection ability and the ability to respond to potential attacks by obtaining topology data, analyzing the topology structure, identifying key nodes, and evaluating vulnerable points.

[0035] First, the topology data acquisition unit is responsible for extracting the connection relationship information between devices from the device topology diagram. The main task of this unit is to collect and organize the connection paths, port information, and communication protocols between devices in the network. Through the data transmitted from the device scanning module or the device topology construction module, the topology data acquisition unit can accurately obtain the physical connections and logical communication information between devices.

[0036] For example, assume that there is a core switch and multiple terminal devices in the network. By analyzing the connection information of these devices, the topology data acquisition unit can identify the connection paths between the switch and each device, the port information used (such as port numbers and port types), and the communication protocols adopted between devices (such as TCP / IP, UDP, etc.). These information provide the basic data for subsequent topology structure analysis.

[0037] Next, based on the connection relationships between devices, the topology analysis unit analyzes the stability, reliability, and potential vulnerabilities of the network topology. By comprehensively evaluating the device connection methods, communication modes, and load conditions, this unit analyzes the reliability of each node and connection in the network. Specifically, the topology analysis unit will evaluate whether there is redundancy in the communication paths between devices, whether the entire network may be paralyzed due to the failure of certain nodes or links, or whether some devices in the network may become targets for attackers.

[0038] For example, when the topology analysis unit detects a single communication path in the network and this path depends on a critical node (such as a switch or router), it will determine whether the reliability of this path is high enough and whether redundant connections need to be added to ensure network stability. If this single path fails, it may lead to the interruption of the entire network service, and the system may automatically suggest adding a backup path or taking other measures to enhance network reliability.

[0039] Subsequently, the critical node identification unit is used to identify critical device nodes in the network and evaluate their security risks. Critical nodes are usually crucial devices or connection points in the network, such as core switches, routers, and bridging nodes between devices. The security of these critical nodes directly affects the operation and security of the entire network. Therefore, it is crucial to identify these nodes and evaluate their potential security risks.

[0040] For example, the core switch is usually responsible for the traffic scheduling of the entire network. If it fails, it may lead to the paralysis of the entire network. Similarly, the bridging nodes in the network (nodes connecting different subnets) may also become targets for attackers. The critical node identification unit identifies these important nodes by analyzing the device and connection information in the network topology and evaluates the possible attack risks they face.

[0041] Finally, the vulnerability analysis unit is responsible for analyzing the weak links in the network topology, identifying potential attack surfaces and security hazards. By comprehensively analyzing factors such as the connection relationships between devices in the network, protocol usage, and node importance in the network, this unit identifies possible weak links in the network topology. For example, some devices may be exposed to the public network and there is a risk of unauthorized access; some devices may use outdated protocols or have known vulnerabilities, becoming potential attack surfaces.

[0042] In vulnerability analysis, the system can use security scanning tools or vulnerability libraries to analyze the security of devices and ports, detect whether there are known security vulnerabilities, whether there are devices using weak passwords or default settings, and whether the firmware of some devices needs to be updated, etc. Through this analysis, the system can timely discover potential security hazards in the network and put forward corresponding improvement suggestions.

[0043] In summary, in this embodiment, through the cooperation of four core units, the topology analysis module has completed a comprehensive analysis of the network topology structure. The topology data acquisition unit extracts the connection relationship information between devices, providing a basis for subsequent analysis; the topology structure analysis unit evaluates the stability and reliability of the network; the key node identification unit identifies and evaluates the security risks of key device nodes; and the vulnerability analysis unit reveals potential security hazards in the network. Through these analyses, the system can provide a detailed network health report for network managers and provide data support for subsequent security protection measures.

[0044] For the risk assessment module, in this embodiment, the risk assessment module conducts a security risk assessment of the devices in the network through the collaborative work of multiple units, combining the graph convolutional network (GCN) and a formulated risk calculation method. This module generates a risk score for each device by considering device vulnerabilities, vendor repair status, network connection relationships between devices, and the centrality of devices, and adjusts it in real time to cope with changes in the network environment and device status.

[0045] First, the risk score calculation unit is the core unit of this module, responsible for calculating the security risk score of each device. This unit calculates the risk score through the following steps: 1. Obtain the vulnerability information of the device: For each device, first obtain its vulnerability information, including the severity, repair status, and vulnerability type of known vulnerabilities. This information usually comes from the vulnerability library related to the device. Let the vulnerability information of the device be V i , where V i = {v 1 , v 2 , …, v n}, and each vulnerability v k has a severity S k and a repair status R k . Based on the severity and repair status of the vulnerability, a preliminary risk assessment is conducted. The risk score of the vulnerability can be expressed as: where S k is the severity of the vulnerability, R k is the repair status, and R v is the vulnerability risk score of the device. If the vulnerability is not repaired and the repair status R k = 0, the risk score is the severity of the vulnerability; if the vulnerability has been repaired and R k = 1, the impact of the vulnerability on the risk score is zero.

[0046] 2. Analyze the network connection relationships of the devices: The network connection relationship includes the communication path between devices, the port opening status, and the communication protocol. Let the connection relationship between device i and device j be C ij , which will affect the potential attack surface exposed by the device. The network exposure risk of the device can be expressed as: where C ij is the connection strength between device i and device j, and P ij is the port exposure situation of communication between devices (such as whether the port is open, the use of security protocols, etc.). If there are multiple exposed ports between devices and insecure protocols are used, the value of P ij is larger, and the risk score R c will also be higher.

[0047] 3. Calculate the risk score based on the graph convolutional network model: The graph convolutional network (GCN) is used to consider the dependency relationship and network structure between devices. Through the graph convolutional network, the risk score of a device can combine its position in the entire network and the influence of other devices. Let the preliminary risk score of device i be then the risk score R i of device i can be expressed as: R i =σ(W·(R v +R c )); where σ is the activation function (such as the ReLU function), W is the weight matrix of the graph convolutional network, R v is the vulnerability risk, and R c is the connection risk. Through the training of the graph convolutional network, this process can calculate a more accurate device risk score based on the connection relationship and vulnerability information between devices.

[0048] 4. Adjust the risk score according to the role of the device in the network: Devices with different roles in the network (such as core switches, routers, etc.) have different impacts on the entire network, and the importance of the device will affect the adjustment of the risk score. For example, if there is a vulnerability in a core device, it may pose a threat to the security of the entire network. Let the importance of device i be I i , and its adjusted risk score can be expressed as: where α is the adjustment factor, indicating the impact of device importance on the risk score. For core devices, I i is larger, so its risk score will be correspondingly increased.

[0049] Finally, the comprehensive risk score of the device Reflects the current security status of the device and potential risks. This score provides an important basis for subsequent security protection measures and emergency responses.

[0050] Secondly, the vulnerability information matching unit is responsible for obtaining vulnerability information related to the device from the vulnerability database and matching it with the risk score of the device. Through this unit, the system can supplement the vulnerability information of the device, thereby generating a more accurate comprehensive risk score. Let the vulnerability information of device i be V i , and the vulnerability information matching unit calculates the vulnerability risk score of the device by comparing the information in the vulnerability database: Among them, S k is the impact of additional vulnerability information related to the device in the vulnerability database, is the adjusted vulnerability risk score.

[0051] Then, the security situation analysis unit combines the risk score of the device and the network topology information to analyze the security situation of the entire network. This unit identifies potential threats and evaluates security protection requirements by analyzing the dependencies between devices. Let the risk scores of all devices in the network be R = {R 1 , R 2 , …, R n}, then the overall security situation of the network can be calculated by the following formula: Among them, C i is the contribution degree of device i to network security, and R network is the overall security risk score of the network. Through this analysis, the system can identify which devices pose significant threats to network security and provide a basis for subsequent security reinforcement.

[0052] Finally, the dynamic evaluation unit is responsible for real-time updating the risk score of the device. As the device status and network environment change, the risk score of the device needs to be dynamically adjusted. Let the device status change be ΔS i , then the real-time risk score of the device can be expressed as: Through this dynamic evaluation, the risk assessment module can respond to network changes in a timely manner to ensure the accuracy and timeliness of the risk assessment results.

[0053] In summary, the risk assessment module in this embodiment comprehensively and accurately evaluates the security risks of devices in the network through the collaborative work of multiple core units, combining a graph convolutional network and a formulaic risk calculation method. The risk score calculation unit generates a preliminary risk score for each device by analyzing vulnerability information and device connection relationships, in combination with the graph convolutional network model; the vulnerability information matching unit improves the score; the security situation analysis unit evaluates the security situation of the entire network; and the dynamic evaluation unit ensures the real-time update of the risk score. The combined action of these methods ensures that the network security monitoring and protection work can be carried out efficiently and accurately.

[0054] For the dynamic update module, in this embodiment, the dynamic update module is mainly used to monitor device status changes in real time, update network topology information, trigger risk assessment, and perform data synchronization to ensure that all information in the system always remains accurate and up-to-date. Through the coordinated work of four core units, namely device status monitoring, topology structure update, risk assessment triggering, and data synchronization, the dynamic update module can achieve an immediate response to device status changes.

[0055] First of all, the main task of the device status monitoring unit is to monitor the status changes of devices in the network in real time. These changes include the online and offline status of devices and changes in device configurations. The changes in device status may be caused by various reasons, such as the addition, deletion, or configuration update of devices. This unit obtains the current status of devices through real-time communication between the network management system and the devices, and transfers the changed device status information to other modules for subsequent processing.

[0056] In this embodiment, the status of a device can be represented in the following ways: Online status: The device has successfully connected to the network and started to work normally.

[0057] Offline status: The device is disconnected or has stopped working.

[0058] Configuration change status: The device configuration has changed, such as an IP address change or a port configuration change.

[0059] When the device status changes, the device status monitoring unit will detect these changes in a timely manner and notify other modules of the system to ensure that the network management system can make adaptive adjustments when the device status changes.

[0060] Next, the topology structure update unit is responsible for dynamically updating the network topology information of devices according to changes in device status. The network topology is a structure diagram composed of physical and logical connections between devices. When a device goes online, offline, or its configuration changes, the topology structure needs to be adjusted accordingly. The topology structure update unit can obtain information on device status changes in real time and update the connection relationships between devices based on this information to ensure the accuracy of the topology structure.

[0061] For example, assume that a device is added to the network. The topology update unit will automatically identify the connection points of the new device and update its connection relationships with other devices in the topology graph. If a device goes offline, the system will remove the device from the topology graph and update the connection paths. Configuration changes to a device (such as a change in port number or IP address) also require updating the topology information. The goal of this process is to ensure that the network topology graph always reflects the true state of the network.

[0062] For the update of the topology structure, the specific process can be expressed by the following formula. Assume that the topology structure of the devices in the network is T = {T 1 , T 2 , …, T n}, where T i represents the connection relationships of each device with other devices. When the device status changes, the topology update can be expressed as: T new = T old ∪ ΔT; where ΔT represents the topology update caused by the device status change, and T new is the updated topology structure.

[0063] Subsequently, after the topology structure is updated or the device status changes, the risk assessment trigger unit will trigger the risk assessment module to recalculate the risk score of the device. The risk score of a device is calculated based on factors such as the vulnerability information of the device, the network connection relationships, and the importance of the device, and these factors may change after the device status changes. For example, the online of a device may lead to the exposure of new attack surfaces, while the offline of a device may reduce the potential risks of the network. The risk assessment trigger unit sends a request for re - assessment to the risk assessment module in a timely manner by monitoring the topology structure change or device status change.

[0064] When the risk assessment module recalculates the risk score, the system will re - evaluate the device risks in the network according to the updated topology structure and device status. This process is triggered by the following formula: where represents the new risk score of device i under the updated topology structure and device status, T new is the updated network topology information, and S i is the status information of device i.

[0065] Finally, the data synchronization unit is responsible for synchronously updating the device status, topology information, and risk assessment results with the system database to ensure that the information in the system always remains consistent and up-to-date. Changes in device status, updates to the topology structure, and updates to the risk assessment results all need to be promptly reflected in the system database for subsequent queries and analysis.

[0066] In this embodiment, data synchronization can be represented by the following formula: where D sync represents the set of information synchronously updated to the database, including the device status S i , the updated topology information T new and the recalculated risk score

[0067] Through the operation of the data synchronization unit, the system can ensure information consistency among all modules, providing accurate basic data for subsequent decision-making and network management.

[0068] In summary, the dynamic update module in this embodiment realizes an immediate response to changes in device status through the coordinated operation of units such as device status monitoring, topology structure update, risk assessment trigger, and data synchronization. The device status monitoring unit continuously detects changes in the device status; the topology structure update unit dynamically updates the network topology information according to changes in the device status; the risk assessment trigger unit triggers the risk assessment module to recalculate the risk score after topology changes or device status changes; and the data synchronization unit ensures that all information is synchronized with the system database. Through this series of operations, the dynamic update module ensures that the network management system can flexibly respond to changes in device status and provide timely and effective risk assessment results, thereby enhancing the security and management efficiency of the network.

[0069] For the decision support module, in this embodiment, the decision support module aims to provide scientific decision support for network administrators to address potential security risks in the network. This module helps network administrators identify high-risk devices in the network and provides corresponding protection measures and emergency response suggestions through steps such as risk priority assessment, protection strategy generation, emergency response recommendation, and decision output.

[0070] First, the function of the risk priority assessment unit is to evaluate the security risk priority of devices based on the risk scores and vulnerability information of the devices. Through the risk score R i and vulnerability information V i of the devices, this unit can comprehensively evaluate the security threats faced by the devices and determine the security risk priority of the devices according to the evaluation results. Specifically, the risk priority P i of the devices can be calculated by the following formula: Among them, R i is the risk score of device i, V ij is the severity or impact value of the j-th vulnerability on device i, and w 1 and w 2 are the weighting coefficients of the risk score and vulnerability information respectively. This formula reflects the comprehensive security risk of the device, taking into account the risk score of the device itself and the vulnerability information it may have, and can accurately evaluate the security risk priority of the device.

[0071] For example, if the vulnerability information of a certain device shows the existence of multiple serious vulnerabilities and its risk score is high, the risk priority calculated by the above formula will be high, and the system will pay attention to these devices first to avoid potential security threats.

[0072] Next, the protection strategy generation unit generates network security protection strategies according to the risk priority, providing protection suggestions and countermeasures. According to the device risk priority P i calculated above, this unit generates corresponding protection strategies for each device. For example, for high-risk devices, the protection strategy generation unit may recommend more stringent security measures, such as restricting port access, enabling multi-factor authentication mechanisms, or performing device isolation, etc.

[0073] For example, for devices with a higher risk priority, the protection strategy may include restricting external access, updating firmware and applying patches, etc.; for devices with a lower risk priority, only regular monitoring and vulnerability scanning may be required.

[0074] For example, if a device has a high risk priority, the protection strategy generation unit may recommend a deep security review and firewall reinforcement for it to reduce the risk of being attacked.

[0075] Subsequently, the emergency response recommendation unit recommends emergency response measures for high-risk devices according to the risk assessment results. The task of the emergency response recommendation unit is to recommend targeted emergency response measures according to the risk assessment results of the device, especially the status of high-risk devices. Emergency response measures usually include operations such as temporarily isolating the device, enabling emergency firewall rules, and blocking potential attack sources.

[0076] For example, if the risk score of a certain key device is higher than the set threshold, the emergency response recommendation unit may recommend immediately isolating the device and repairing the vulnerabilities to prevent potential attacks from affecting the entire network.

[0077] Finally, the decision output unit outputs network security management decision suggestions based on the generated protection strategies and emergency response measures. These suggestions are for the reference of network administrators to help them make appropriate security decisions. The decision output unit combines the protection strategies, emergency response measures, and the overall network security situation to provide comprehensive decision support to the administrator.

[0078] This process provides network administrators with a comprehensive protection plan based on risk assessment, helping them make timely and effective decisions in the face of security threats.

[0079] For example, if the risk scores of multiple devices are relatively high, the decision output unit may recommend strengthening the overall protection of the network, giving priority to handling the security issues of high-risk devices, and preparing emergency response measures to deal with possible attacks.

[0080] In summary, the decision support module in this embodiment comprehensively supports network security management decisions through functional units such as risk priority assessment, protection strategy generation, emergency response recommendation, and decision output. The risk priority assessment unit evaluates the security risk priorities of devices based on their risk scores and vulnerability information; the protection strategy generation unit generates network security protection strategies according to the priorities; the emergency response recommendation unit recommends emergency response measures for high-risk devices; the decision output unit comprehensively generates network security management decision suggestions. Through the collaborative work of these modules, the decision support module provides efficient and accurate decision support to network administrators, improving the security and management efficiency of the network.

[0081] Regarding the visualization module, in this embodiment, the design and implementation of the visualization module aim to display the device status, topology, risk assessment results, and network security situation in the network in a graphical way, providing an intuitive and easy-to-understand interface for network administrators, thereby supporting more effective network management and decision-making. Through the collaborative work of multiple sub-units, this module converts complex network data into intuitive graphics and reports, enabling administrators to quickly identify potential problems and take corresponding protection measures.

[0082] First, the task of the device status visualization unit is to visually display the current status of each device in the network (such as online, offline, configuration changes, etc.). The status information of devices is usually obtained in real time by the device status monitoring unit and presented through a graphical interface. For example, online devices may be displayed by green dots, while offline devices may be displayed by red dots or markings. Device configuration changes may be indicated by change marks or color changes.

[0083] In graphical displays, the device status visualization unit typically uses device icons, color coding, etc., so that network administrators can visually view the health status of devices. For example, assume that the status of a certain device changes to offline. The device status visualization unit will immediately mark the device in red in the graphical interface to alert the administrator that the device may need to be checked and repaired. The dynamic changes in device status can be presented through real-time charts or status update panels to ensure that administrators can timely obtain the changes in device status in the network.

[0084] Next, the topology visualization unit is responsible for converting the device topology in the network into a visualized network diagram to show the physical and logical connection relationships between devices. The topology information is usually provided by the device topology construction unit, which generates a connection diagram between devices by analyzing device scan results and network communication data.

[0085] The visualization of the topology can adopt the node-edge model, where each device is represented as a node, and the connection relationship between devices is represented by edges (lines). Important devices in the network, such as core switches and routers, may be identified by larger and more prominent nodes, while information such as communication paths and connection ports between devices can be represented by different colors, thicknesses, or solid / dashed lines of the edges.

[0086] The topology diagram not only shows the connection relationships between devices but can also combine dynamic data to show information such as the communication frequency and load conditions of devices. For example, the connection lines between devices can be differentiated by changes in color or width according to different communication frequencies to help administrators identify bottlenecks or high-traffic areas in the network.

[0087] The risk assessment visualization unit converts the device risk scores calculated by the risk assessment module into a visualized form to facilitate administrators to quickly identify high-risk devices. The risk scores are usually represented by numerical values or color coding. The higher the numerical value, the greater the risk, and the color may change from green (low risk) to yellow and red (high risk) to visually present the security risks existing in the network.

[0088] For example, assume that a certain device has a high risk score. The risk assessment visualization unit will display the risk score of the device in red and mark the corresponding numerical value to alert the administrator that the device may have security risks. The system can also, through an interactive function, allow administrators to click on a specific device to view its detailed risk information, such as vulnerability types, vulnerability repair status, and connection relationships between devices, etc., so as to help administrators deeply analyze device risks.

[0089] The security situation visualization unit converts the output information of the network security situation analysis unit into a graphical interface to display the security status of the entire network. Through this unit, administrators can see the security situation of the entire network, including high-risk areas, potential attack surfaces, key nodes, etc. The security situation of the network is usually presented in the form of charts, heat maps or pie charts to help administrators identify potential threats and vulnerabilities in the network.

[0090] For example, the system can display high-risk areas in the network through a heat map, and the depth of color reflects the security risk level of the area. Administrators can click on different areas to view the detailed information of related devices and take targeted protection measures. The security situation visualization unit can also update the network security situation based on real-time data to help administrators quickly respond to security issues that occur in the network.

[0091] The data report visualization unit is responsible for presenting the detailed security report of the network in the form of charts or dashboards to help administrators view and analyze the historical security data of the network. The data report visualization unit usually combines the network historical status, vulnerability scan results, emergency response records, etc. to generate a comprehensive security report. The data in the report can include the progress of vulnerability repair, device health status, risk score changes, etc., and are presented through various charts and trend lines.

[0092] For example, the data report visualization unit can generate a line chart showing the change in the risk score of devices in the network in the past 30 days to help administrators identify which devices have significant changes in risk scores. Such charts not only help administrators understand the changes in the network security situation but also provide a basis for subsequent security policy adjustments.

[0093] The interaction function is an important part of the visualization module. It allows administrators to interact with the graphical interface to obtain more detailed information. Through the interaction function, administrators can click on any node in the device or topology diagram to view the detailed status, risk score, vulnerability information, communication data, etc. of the device. The design of the interaction interface usually includes operations such as zooming in, zooming out, dragging, and clicking, enabling administrators to flexibly view and analyze different parts of the network.

[0094] For example, in the topology structure diagram, administrators can click on a certain node to view the detailed information of the device, including the devices it is connected to, communication protocols, port opening conditions, vulnerability information, etc. In addition, administrators can also adjust the perspective by dragging the topology diagram to view the structure of the entire network.

[0095] In summary, through the coordinated work of sub-units such as device status visualization, topology visualization, risk assessment visualization, security posture visualization, and data report visualization, the visualization module in this embodiment presents complex network security information to network administrators in a graphical and intuitive manner. In this way, administrators can more easily understand the health status of the network, identify security risks, assess risks, and take corresponding protection measures. The visualization function of this module not only improves the efficiency of network security management but also enhances the administrator's real-time monitoring ability of the network status.

[0096] Generally speaking, the system of the present invention includes functional modules such as asset identification, topology analysis, risk assessment, dynamic update, decision support, and visualization. Through device scanning and classification, the system can automatically identify devices in the network and construct the topology structure between devices. Combining technologies such as graph convolutional networks, the system dynamically calculates the security risks of devices and updates the risk scores in real time when the device status changes. Based on the risk assessment results, the system generates protection strategies and emergency response measures, and displays the network topology, device status, and security posture through a graphical interface to help network administrators make scientific decisions. This system improves the automation level of network security management and supports the real-time monitoring, risk identification, and effective protection of the network.

[0097] Please refer to the appendix Figure 2 , the present invention also provides an online monitoring method for network security in the industrial field, which realizes the real-time monitoring and risk assessment of network devices through the following steps: S1. Obtain device information in the network through stateless scanning technology and construct a device topology map. In this step, by sending probe packets to devices in the network, basic information of the devices is obtained, including IP addresses, device types, operating system versions, etc., and a network topology map is generated based on the connection relationships between devices, showing the physical and logical connections between devices.

[0098] S2. Conduct topology data analysis on the device topology map to identify connection patterns and vulnerability points between devices. The system analyzes the connection relationships between devices to identify possible vulnerable links, such as redundant paths, single points of failure, or weak connections between devices, and provides a basis for subsequent security analysis.

[0099] S3. Generate device risk scores based on graph convolutional networks combined with a vulnerability database and output the risk assessment results. Combining the vulnerability information of devices and network topology data, the system uses the graph convolutional network model to evaluate the risk scores of devices, thereby obtaining the potential security risks of each device and outputting relevant risk assessment results.

[0100] S4. Periodically update the device information and topology structure, and adjust the risk assessment results in real time. The device status and topology structure will change over time. The system will regularly obtain the latest status information of the devices and adjust the risk assessment results of the devices based on the updated topology structure to ensure that the risk assessment remains up-to-date.

[0101] S5. Generate network security management decision suggestions according to the risk assessment results. Based on the risk scores of the devices and the latest status of the network topology, the system generates corresponding security management decision suggestions, including protection measures, emergency response plans, etc., to help administrators make timely and effective decisions.

[0102] S6. Multidimensionally visualize the device status and risk assessment results by region, manufacturer, and vulnerability category. Through the graphical interface, the system displays the device status, risk assessment results, and vulnerability information in different dimensions, facilitating administrators to intuitively view the security posture of the network and make corresponding adjustments.

[0103] Through the above steps, the online network security monitoring method in the industrial field can comprehensively monitor the status, risks, and topology structure of network devices, provide timely and effective security management decision support, and achieve dynamic risk assessment and response.

[0104] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. The online monitoring system for network security in the industrial field is characterized by: include: The asset identification module is used to obtain device information in the network through stateless scanning technology and build a device topology map; A topology analysis module, used to perform topology data analysis on the device topology map to identify connection modes and potential vulnerabilities between devices; The risk assessment module performs security risk scoring on devices based on graph convolutional networks and generates risk assessment results in combination with the vulnerability library; Dynamic update module, used to periodically update device information and topology structure, and adjust risk assessment results in real time; The decision support module generates network security decision recommendations based on risk assessment results.

2. The industrial network security online monitoring system according to claim 1 is characterized in that: The asset identification module includes: The device scanning unit is used to scan the devices in the network through stateless scanning technology to identify the basic information of the devices, including IP address, device type, manufacturer information, operating system version and port opening status; A device topology construction unit, used to construct a network topology structure between devices and generate a connection relationship diagram between devices according to the device scanning results; The device classification unit is used to classify devices into different categories according to their characteristics, including industrial control systems, IoT terminals and other network devices, and identify their security characteristics according to the device categories.

3. The industrial network security online monitoring system according to claim 2 is characterized in that: The device topology construction unit constructs the device topology by the following steps: Identify the physical connection relationship between devices according to the device information provided by the device scanning unit; Analyze the communication data packets between devices based on the network communication protocol to determine the logical connection relationship between devices; Combine physical and logical connections to generate a complete topology diagram between devices, including the device's IP address, type, connection port, and communication path information; Optimize the topology diagram based on device communication frequency and interaction mode to ensure that secure communication paths between devices are accurately identified.

4. The industrial network security online monitoring system according to claim 1 is characterized in that: The topology analysis module includes: A topology data acquisition unit, used to extract connection relationship information between devices from the device topology diagram, including the connection path, port information and communication protocol of the device; Topology analysis unit, used to analyze the stability, reliability and potential vulnerabilities of the device topology based on the connection relationship between devices; Key node identification unit, used to identify key device nodes in the network, including core switches, routers, and bridge nodes between devices, and assess their security risks; Vulnerability analysis unit, used to analyze weak links in network topology and identify potential attack surfaces and security risks.

5. The industrial network security online monitoring system according to claim 1 is characterized in that: The risk assessment module includes: The risk scoring calculation unit is used to score the security risk of the device based on the graph convolutional network, taking into account the device vulnerabilities, the manufacturer's repair status, and the network connection relationship between the devices; A vulnerability information matching unit is used to obtain vulnerability information related to the device from the vulnerability library and match it with the device risk score to generate a comprehensive risk score; Security situation analysis unit, which is used to analyze network security situation, identify potential threats and evaluate security protection needs by combining the risk score of the device and network topology information; The dynamic assessment unit is used to update the risk score of the device in real time and adjust the risk assessment results according to changes in the network environment and device status.

6. The industrial network security online monitoring system according to claim 5 is characterized in that: The risk score calculation unit calculates the risk score by the following steps: Obtain device vulnerability information, including the severity, repair status, and vulnerability type of known vulnerabilities; Analyze the network connection relationship of the device, including the communication path, port openness and communication protocol between devices, and evaluate the potential attack surface exposed by the device; Based on the graph convolutional network model, the preliminary risk score of each device is calculated by combining the device's vulnerability information and network connection relationship; Adjust the risk score based on the network environment in which the device is located and its role, taking into account the importance of the device and its core position in the network; Output the final risk score of the device, reflecting the current security status and potential risks of the device.

7. The industrial network security online monitoring system according to claim 1 is characterized in that: The dynamic update module includes: The device status monitoring unit is used to monitor the status changes of devices in the network in real time, including the online and offline status of devices and configuration changes; The topology update unit is used to dynamically update the network topology information of the device according to the change of the device status to ensure the accuracy of the topology structure; A risk assessment trigger unit, used to trigger the risk assessment module to recalculate the risk score of the device according to the topology update or device status change; The data synchronization unit is used to synchronize and update the device status, topology information and risk assessment results with the system database to ensure the consistency and timeliness of the information.

8. The industrial network security online monitoring system according to claim 1 is characterized in that: The decision support module includes: A risk priority assessment unit, used to assess the security risk priority of a device based on the risk score and vulnerability information of the device; The protection strategy generation unit is used to generate network security protection strategies according to risk priorities and provide protection suggestions and response measures; The emergency response recommendation unit is used to recommend emergency response measures for high-risk equipment based on risk assessment results to reduce potential security threats; The decision output unit is used to output network security management decision suggestions based on the generated protection strategies and emergency response measures for network administrators to make decisions.

9. The industrial network security online monitoring system according to claim 1 is characterized in that: The system further comprises: The visualization module is used to visualize the risk score, network topology, vulnerability information and protection strategy of the device through a graphical interface.

10. An industrial network security online monitoring method, based on an industrial network security online monitoring system as claimed in any one of claims 1 to 9, characterized in that: The following steps are involved: Obtain device information in the network through stateless scanning technology and build a device topology map; Performing topological data analysis on the device topology map to identify connection patterns and vulnerabilities between devices; Generate device risk scores based on graph convolutional networks and vulnerability libraries, and output risk assessment results; Periodically update device information and topology, and adjust risk assessment results in real time; Generate cybersecurity management decision recommendations based on risk assessment results; The device status and risk assessment results are displayed in a multi-dimensional visual manner by region, manufacturer, and vulnerability category.

Citation Information

Patent Citations

  • Risk assessment method based on system network topology structure

    CN114372269A

  • Integrated network management system of mobile network

    CN117336777A

  • Network security protection system based on GIS

    CN119232641A

  • Systems, Program Product and Methods For Performing a Risk Assessment Workflow Process For Plant Networks and Systems

    US20120180133A1

Cited By

  • Vulnerability visualization method and system of network assets based on dynamic topology and storage medium

    CN120880808A

  • A vulnerability visualization method and system of network assets based on dynamic topology and a storage medium

    CN120880808B

  • Security assessment method and system for industrial control system of industrial computer

    CN120993886A

  • Industrial control network security effectiveness verification method

    CN121077938A

  • A method for verifying security effectiveness of an industrial control network

    CN121077938B