Ecological environment safety management method for industrial equipment

Through the combination of dynamic trust evaluation and adaptive policy arbitrator, the dynamic and multi-dimensional problems of industrial equipment security protection are solved, real-time trust quantification and threat identification of industrial equipment are realized, and the security and reliability of the system are improved.

CN120050118AActive Publication Date: 2025-05-27KINGWAY FOSHAN ELECTRONICS TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510517572.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-27
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

The prior art is difficult to achieve comprehensive and dynamic security protection for industrial equipment, especially when facing cross-device collaboration features in advanced persistent threat (APT) attacks.

Method used

The device's trust score is generated through the dynamic trust evaluation engine, the threat level is determined based on device status timing data, network traffic data and process behavior data, and security control measures are adjusted using an adaptive policy arbitrator.

Benefits of technology

Real-time trust quantification of equipment, users and environments is realized, and it can effectively identify and defend against various security threats in industrial equipment and improve the overall security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050118A_ABST
    Figure CN120050118A_ABST
Patent Text Reader

Abstract

The invention discloses an ecological environment safety management method for industrial equipment, and belongs to the technical field of industrial equipment management, and the method comprises the following steps: S1, generating a trust score for equipment through a dynamic trust evaluation engine; s2, if the trust score is lower than a preset threshold value, determining a threat level according to the equipment state time sequence data, the network flow data and the process behavior data; and S3, a self-adaptive strategy arbiter is adopted to adjust safety control measures according to the threat level. The ecological environment safety management method of the industrial equipment solves the problem that an existing safety management mode is difficult to realize comprehensive and dynamic safety protection of the industrial equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial equipment management, and particularly relates to an ecological environment security management method for industrial equipment. Background Art

[0002] Industrial equipment security control faces a complex and changeable threat environment. The traditional static protection method is role-based access control, which cannot cope with the dynamic access and behavior drift of industrial equipment and is difficult to handle the increasing security challenges. Security issues in multiple dimensions such as device identity authentication, behavior analysis, and protocol parsing are intertwined, forming a difficult technical problem, resulting in the difficulty of single-dimensional log analysis or traffic detection in identifying the cross-device collaborative characteristics of APT (Advanced Persistent Threat) attacks. Therefore, the current security management method is difficult to achieve all-round and dynamic security protection for industrial equipment. Summary of the Invention

[0003] In order to overcome the defects existing in the prior art, the present invention provides an ecological environment security management method for industrial equipment to solve the above problems.

[0004] The technical solution adopted by the present invention to solve its technical problems is: an ecological environment security management method for industrial equipment, including the following steps: S1: Generate a trust score for the device through a dynamic trust assessment engine; S2: If the trust score is lower than a preset threshold, determine the threat level according to the device status time series data, network traffic data, and process behavior data; S3: Use an adaptive policy arbiter to adjust the security control measures according to the threat level.

[0005] It should be noted that in the step S1, the basic trust weight is adjusted through the behavior entropy value of the device, and the dynamic trust data is calculated according to the basic trust value and the basic trust weight; Obtain historical credit data and environmental correction data, and calculate the trust score through the historical credit data, environmental correction data, and dynamic trust data.

[0006] Preferably, in the step S1, the behavior entropy value is calculated through the network traffic burstiness and the instruction cycle standard deviation. When the behavior entropy value is lower than a preset threshold, the basic trust weight is increased, and when the behavior entropy value is higher than a preset threshold, the basic trust weight is decreased.

[0007] Optionally, in step S2, obtain the device status time-series data, extract the time-series features from the device status time-series data through the LSTM-Attention model and perform weighted processing to obtain the weighted feature data; predict the future trend of the device status based on the time-series features and the weighted feature data, and output the prediction data; calculate the residual based on the difference between the prediction data and the actual observed data to obtain the prediction result.

[0008] It should be noted that in step S2, obtain the network traffic data, and verify the protocol compliance of the network traffic data by using a protocol state machine to obtain the compliance result.

[0009] It should be noted that in step S2, obtain the process behavior data, construct a process behavior baseline based on the process behavior data during normal operation, and construct a Markov chain model based on the historical process behavior data; Compare the process behavior data of the current process with the process behavior baseline, and use the process behavior data that deviates from the process behavior baseline as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; preset the threshold of the transition probability, and when the output transition probability exceeds the threshold, determine that the process behavior data is abnormal to obtain the judgment result.

[0010] Specifically, in step S2, perform weighted fusion on the prediction result, the compliance result, and the judgment result through a cross-modal attention mechanism to obtain the final threat score, and determine the threat level according to the final threat score; in step S3, the adaptive policy arbiter obtains the system load and the threat level, and judges the protection requirements according to the system load and the threat level to adjust the security control measures.

[0011] Specifically, in step S2, before predicting the device status time-series data through the LSTM-Attention model, normalize the device status time-series data; divide the continuous time series of the normalized device status time-series data into windows of a fixed length and perform missing value processing; The beneficial effects of the present invention are as follows: in the ecological environment security management method of the industrial device, the dynamic trust evaluation engine calculates the dynamic trust value in real time based on the device fingerprint and the user context, breaks through the static permission model, realizes the real-time trust quantification of the device, the user, and the environment, and uses the multi-modal threat perception network to fuse the device status time-series data (vibration / temperature), network traffic data (protocol fingerprint), and process behavior data (CPU / memory mode) to construct a three-dimensional threat detection space to determine the threat level. Finally, the adaptive policy arbiter dynamically switches the security control measures according to the real-time threat level. This multi-dimensional and dynamic security management method can effectively identify and defend various security threats in industrial devices, and improve the overall security and reliability of the system. Brief Description of the Drawings

[0012] Figure 1 It is a flowchart of the ecological environment safety management method for industrial equipment in an embodiment of the present invention; Figure 2 It is a flowchart block diagram of the ecological environment safety management method for industrial equipment in an embodiment of the present invention. Detailed Embodiments

[0013] The following further describes the detailed embodiments of the present invention with reference to the drawings. It should be noted here that the description of these embodiments is for helping to understand the present invention, but does not constitute a limitation to the present invention. In addition, the technical features involved in the following described various embodiments of the present invention can be combined with each other as long as they do not conflict with each other.

[0014] As Figure 1 and 2 shown, an ecological environment safety management method for industrial equipment includes the following steps: S1: Generate a trust score for the device through a dynamic trust assessment engine; S2: If the trust score is lower than a preset threshold, determine the threat level according to the device status time series data, network traffic data, and process behavior data; S3: Use an adaptive policy arbiter to adjust the security control measures according to the threat level to uniformly manage the security of industrial equipment.

[0015] In the ecological environment safety management method for industrial equipment, the dynamic trust assessment engine calculates the dynamic trust value in real time based on the device fingerprint and user context, breaks through the static permission model, realizes the real-time trust quantification of the device, user, and environment, uses the multi-modal threat perception network to fuse the device status time series data (vibration / temperature), network traffic data (protocol fingerprint), and process behavior data (CPU / memory mode), constructs a three-dimensional threat detection space to determine the threat level, and finally the adaptive policy arbiter dynamically switches the security control measures according to the real-time threat level. This multi-dimensional and dynamic security control method can effectively identify and defend various security threats in industrial equipment, and improve the overall security and reliability of the system.

[0016] It is worth noting that in step S1, the basic trust weight is adjusted through the behavior entropy value of the device, and the dynamic trust data is calculated according to the basic trust value and the basic trust weight; Obtain the historical credit data and environment correction data, and calculate the trust score through the historical credit data, environment correction data, and dynamic trust data.

[0017] During the initialization phase, a unique hardware DNA is generated when the device is registered (by fusing the TPM 2.0 measurement value with the response of the PUF physical unclonable function). During runtime updates, the behavioral entropy value is calculated every 5 minutes (based on the burstiness of network traffic and the standard deviation of instruction cycles), and the basic trust weight is dynamically adjusted.

[0018] After adjusting the trust weight, the credit score is obtained according to the following formula ; is the adjusted basic trust weight, is the basic trust value; is the historical credit mean (using a sliding window or exponentially decaying weighting); is the environmental correction factor (such as device authentication strength, geographical location risk); is the historical weight coefficient, is the environmental weight coefficient, and it needs to satisfy .

[0019] Preferably, in the step S1, the behavioral entropy value is calculated based on the burstiness of network traffic and the standard deviation of instruction cycles. When the behavioral entropy value is lower than the preset threshold, the basic trust weight is increased; when the behavioral entropy value is higher than the preset threshold, the basic trust weight is decreased.

[0020] For the behavioral entropy value, when the entropy value is lower than the preset threshold, it indicates that the behavior is predictable, and at this time, the trust weight can be increased; when the entropy value is higher than the preset threshold, it indicates that the behavior is complex or abnormal, and at this time, the trust weight needs to be decreased. The behavioral entropy value ; is the network traffic burstiness index (such as the coefficient of variation or peak-to-mean ratio); is the standard deviation of the instruction cycle; and are the weight coefficients (and need to satisfy ); max(⋅) is the normalization factor (historical data or theoretical maximum); the network traffic burstiness and the standard deviation of the instruction cycle are obtained through data collection.

[0021] Optionally, in the step S2, the device status time-series data is obtained, and the time-series features are extracted from the device status time-series data through the LSTM-Attention model and weighted to obtain the weighted feature data; the future trend of the device status is predicted based on the time-series features and the weighted feature data, and the prediction data is output; the residual is calculated according to the difference between the prediction data and the actual observed data, and it is determined whether the residual exceeds the normal range (for example, when collecting vibration signals in the device healthy state, calculating the standard deviation σ of each feature, and defining the normal range of each feature as [-3σ, +3σ]) to obtain the prediction result for detecting abnormal mechanical vibrations.

[0022] Specifically, to obtain the residual between the predicted data and the actual observed data, the following execution steps are required: LSTM extracts temporal features: First, window the device status temporal data and input it into a bidirectional LSTM network; the LSTM can capture long-term dependencies in the data, thereby learning the potential patterns and regularities in the temporal data; through two layers of bidirectional LSTM networks, the LSTM network can process information simultaneously in the forward and backward directions of time, improving the ability to understand complex device status temporal data; Attention mechanism focuses on critical moments: After extracting the temporal features, use the time-step attention mechanism to weight these temporal features to obtain weighted feature data, focusing on the critical moments that have the greatest impact on the prediction; the attention mechanism assigns different weights according to the importance of each time step, thus highlighting the data at important time points; Prediction: Based on the temporal features extracted by the LSTM and the features focused by the attention mechanism, predict the future trend of the device status through a pre-trained model, and output the predicted data of the device; subsequently, this predicted data will be compared with the actual observed data; Calculate the residual: The residual of the device status temporal data refers to the difference between the predicted data and the actual observed data.

[0023] In this embodiment, analyzing the residual can help detect anomalies; when the value of the residual exceeds the predetermined normal range, it may indicate abnormal mechanical vibration of the device, indicating potential faults or problems.

[0024] Process the device status temporal data through a long short-term memory network (LSTM) and an attention mechanism (Attention) to judge abnormal mechanical vibration. Collect acceleration data during device operation through a vibration sensor to obtain device status temporal data. Separate the frequency domain features and time-frequency domain features of the device status temporal data, and obtain the temporal dependence feature representation according to the separated frequency domain features and time-frequency domain features processed by the long short-term memory network. Use time-step attention to focus on the critical moments of the temporal dependence feature representation, and finally output the prediction result. In this embodiment, the long short-term memory network (LSTM) will input windowed device status temporal data and use two layers of bidirectional LSTM to capture long-term dependencies.

[0025] Classification of abnormal mechanical vibration detection through multi - feature combination: warning level, mild abnormality level, and severe fault level. Among them, a slight deviation threshold is set. When a single feature deviates from the baseline and is within the slight deviation threshold, and the duration is less than the set value, it is the warning level. A feature deviation quantity threshold is set. When the number of features deviating from the baseline and within the slight deviation threshold is greater than the feature deviation quantity threshold, or when the duration of a single feature deviating from the baseline and within the slight deviation threshold is greater than or equal to the set value, it is the mild abnormality level. A safety threshold is set. When a feature exceeds the safety threshold and the envelope spectrum energy rises exponentially, it is the severe fault level.

[0026] Among them, single - feature deviation refers to the deviation between a certain feature (such as vibration, temperature, etc.) and the expected value in the normal state. Slight deviation means that these deviations are relatively small and usually do not immediately affect the normal operation of the device, but may be early signs of potential problems. For example, the vibration amplitude of the device increases slightly but has not exceeded the safety limit, which may indicate a slight abnormality in the device and may develop into a more serious problem in the future.

[0027] Feature values refer to the numerical features extracted from the signal (such as vibration frequency, temperature, pressure, etc.). The feature value exceeding the safety threshold means that some feature values exceed the pre - set safety standards or critical values, which is usually a sign that the system detects abnormalities or risks. For example, the device temperature exceeds the set maximum safety temperature, which may cause device damage or accidents and requires emergency treatment measures.

[0028] The exponential increase of the envelope spectrum energy usually means that the signal energy index obtained through envelope analysis gradually increases. Envelope spectrum analysis is mainly used to identify mechanical faults in the device, such as gear damage or bearing faults. When the envelope spectrum energy index rises, it usually indicates that the fault condition of the device is deteriorating. Trend prediction needs to pay attention to this change in order to take measures early. The process of trend prediction generally includes the following steps: Data collection: Collect historical operation data of the device or system, including time - series data of various feature values (such as vibration signals, temperature changes, etc.); Feature extraction: Extract key features from the original signal, such as frequency - domain features and time - domain features, etc.; Trend analysis: Use statistical methods or machine - learning algorithms (such as time - series analysis, regression analysis, etc.) to analyze the change trend of the envelope spectrum energy index of the extracted key features; Trend prediction: Based on historical data and trend analysis models, predict the change direction and amplitude of features in the future period of time; if the trend shows that the feature value exceeds the safety threshold and the envelope spectrum energy rises exponentially, an alarm is issued through the system.

[0029] Subsequently, the baseline will be updated through a sliding window to adapt to the slow changes caused by device aging. Additionally, transfer learning will be used to reuse the existing model on new devices and fine-tune it with a small amount of data.

[0030] Specifically, in step S2, network traffic data is obtained, and the protocol compliance of the network traffic data is verified using a protocol state machine to obtain a compliance result for the OPC UA (Object Linking and Embedding, Unified Architecture) protocol, in order to intercept unconventional read and write sequences.

[0031] In the OPC UA protocol, verifying protocol compliance is the key to ensuring secure and reliable communication. By analyzing the characteristics of network traffic data, the protocol state machine can detect abnormal behaviors and ensure that sessions comply with the specifications. The characteristics of network traffic data include the average traffic per second, traffic peak, number of connections, session duration, and bidirectional traffic ratio. For the average traffic per second and traffic peak, the average traffic per second is calculated using the traffic values of historical data (such as 30 days), and then the traffic standard deviation is calculated using the average traffic per second. The peak threshold corresponding to the traffic peak is set as the average traffic per second + 3 times the traffic standard deviation. When the traffic peak exceeds the peak threshold, abnormal traffic, such as a DoS attack or abuse, is determined. For the number of connections, the concurrent connections per single IP / service are counted according to the service (HTTP / SSH), where HTTP (HyperText Transfer Protocol) is the hypertext transfer protocol and SSH (Secure Shell) is the secure shell protocol. A connection number baseline is set. When the number of connections exceeds twice the connection number baseline and the duration exceeds the set value, it is determined as a network scanning activity or a botnet activity. For the session duration, corresponding timeout thresholds are set respectively for short session services (such as HTTP) and long connection services (such as databases) in the session. When the short session service exceeds its corresponding timeout threshold (such as 5 minutes), it is determined that the short session service has timed out. When the long connection service exceeds its corresponding timeout threshold (such as 2 hours), it is determined that the long connection service has timed out. For the bidirectional traffic ratio, a threshold for the upload traffic ratio per single session is set. When the upload traffic ratio per single session is greater than the threshold for the upload traffic ratio per single session, data leakage is determined. A threshold for the download traffic ratio per single session is set. When the download traffic ratio per single session is greater than the threshold for the download traffic ratio per single session, data abuse download is determined. The protocol state machine analyzes based on these characteristics and obtains a compliance result based on the above judgments.

[0032] It should be noted that in the step S2, process behavior data is obtained, a process behavior baseline is constructed based on the process behavior data during normal operation, and a Markov chain model is constructed based on historical process behavior data; The process behavior data of the current process is compared with the process behavior baseline, and the process behavior data that deviates from the process behavior baseline is used as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; a threshold of the transition probability is preset, and when the output transition probability exceeds the threshold, the process behavior data is determined to be abnormal, and a judgment result is obtained. In the above way, abnormal DLL (Dynamic Link Library) loading or memory injection is identified (such as detecting the exploitation of the CVE-2023-1234 vulnerability, where CVE (Common Vulnerabilities and Exposures) is a standard created and maintained by MITRE for recording and classifying software vulnerabilities).

[0033] The purpose of obtaining process behavior data is to analyze the normal behavior patterns of processes and identify abnormal activities. Specifically, the process can be divided into the following key links: Constructing the process behavior baseline: First, based on the process behavior data during normal operation (such as file operations, memory access, network connections, etc.), a process behavior baseline is constructed, which describes the typical behavior patterns of processes under normal circumstances and provides a reference for subsequent anomaly detection; Establishing the Markov chain model: Through the analysis of historical process behavior data, a Markov chain model is constructed, which can capture the transition relationships between process behaviors; the Markov chain model uses the transition probabilities between states to simulate the behaviors of processes in different states and provides a quantitative basis for detecting anomalies; Process behavior judgment and anomaly identification: During the actual monitoring process, the behavior data of the current process is compared with the process behavior baseline, and the process behavior data that deviates from the process behavior baseline is used as the input of the Markov chain model; through the input data, using the mechanism of the Markov chain model to capture the transition relationships between process behaviors, the transition probability of the process behavior data is output; through the transition probability and the preset threshold of the transition probability, a judgment result can be obtained. For example, when the output transition probability exceeds the threshold, the process behavior data is determined to be abnormal, and it is considered that the behavior data of the current process may have malicious behaviors such as abnormal DLL loading or memory injection, thus obtaining a judgment result.

[0034] For example, when detecting vulnerabilities such as CVE-2023-1234, malicious processes may use abnormal DLL loading or memory injection behaviors to execute attacks. By judging the deviation from the baseline behavior of the process and combining the transition probabilities of the Markov chain model, such abnormal behaviors can be effectively identified, thus realizing the detection of vulnerability exploitation. This process helps identify potential malicious activities and enhance the detection ability of security threats through behavior analysis and model prediction.

[0035] Specifically, in the step S2, the prediction result, the compliance result, and the judgment result are weighted and fused through a cross-modal attention mechanism to obtain a final threat score, and the threat level is obtained according to the interval where the final threat score is located; the interval is divided according to the degree of damage of the threat to the system function, data integrity, or security.

[0036] Specifically, in the cross-modal attention weighted fusion process, different types of data (such as device status time-series data, network traffic data, process behavior data) are processed and fused into a final threat score; For the prediction result, it is usually numerical, such as threat probability, risk score, or classification result (such as the intensity level of the threat); for the compliance result, it is boolean (compliant / non-compliant) or categorical (such as compliant, minor violation, serious violation, etc.); for the judgment result, it is categorical (such as: whether it is a malicious behavior) or numerical (such as: the risk score of the malicious behavior); for these different types of results, the cross-modal attention mechanism can perform weighted fusion in the following ways: Feature representation: First, the results of different data sources (such as prediction scores, compliance labels, and judgment results) are transformed into a unified feature space through appropriate embedding or vector representation. For example, the boolean compliance result can be converted into a numerical representation of 0 or 1, and the classification result can be converted through one-hot encoding. Cross-modal attention mechanism: The cross-modal attention mechanism calculates the relationships and importance between various data types and automatically assigns weights to different modalities (such as prediction results, compliance results, and judgment results). This can be achieved through a self-attention mechanism. For example, for each input result, the model calculates the contribution weight of it to the final threat score and adjusts the fusion degree of each result according to these weights; Weighted fusion: The final weighted fusion is to weight and combine each modality (prediction score, compliance label, and judgment result) according to the attention weights to obtain a comprehensive threat score, which is usually a numerical output; Threat level classification: Based on the comprehensive score, map it to different threat levels according to predefined intervals; for example, a threat score lower than a certain threshold indicates a low threat, and exceeding a certain threshold indicates a high threat, and then give the corresponding threat types according to the threat score (such as cybersecurity threats, physical threats, operational threats).

[0037] Conduct threat classification according to different data types (device status time-series data, network traffic data, and process behavior data) to obtain different threat types, including cybersecurity threats (DDoS attacks (fully known as Distributed Denial of Service attacks), malware, unauthorized access), physical threats (device physical damage, environmental interference), and operational threats (misconfiguration, human operation errors).

[0038] In the step S3, the adaptive policy arbiter obtains the system load and threat level, judges the protection requirements according to the system load and threat level, and adjusts the security control measures. Through the elastic security policy and the dynamic degradation mechanism based on the linkage between load and threat, ensure business continuity in high-concurrency scenarios.

[0039] The adaptive policy arbiter adjusts the security control measures by looking up a table. For example, when the threat level is low and the system load is less than 60%, enable national cipher SM9 encryption and lightweight auditing; when the threat level is medium and the system load is between 60% and 80%, activate the hardware TEE (Trusted Execution Environment) to isolate critical processes; when the threat level is high and the system load is greater than or equal to 80%, trigger device-level fusing and pass through the cloud forensics sandbox.

[0040] Finally, through protocol semantic abstraction (mapping Modbus / Profinet instructions to unified operation primitives), achieve unified orchestration of security policies for cross-vendor devices to solve the fragmentation problem of multi-vendor device security management.

[0041] It should be noted that in the step S2, before predicting the device status time-series data through the LSTM-Attention model, normalize the device status time-series data (such as using Min-Max normalization or Z-Score normalization to eliminate dimensional differences); divide the continuous time series of the normalized device status time-series data into windows of a fixed length (such as a 60-second window with a step of 10 seconds), and perform missing value processing, such as interpolation filling or removing abnormal windows, to obtain complete device status time-series data.

[0042] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings, but the present invention is not limited to the described embodiments. For those skilled in the art, without departing from the principle and spirit of the present invention, various changes, modifications, substitutions, and variations made to these embodiments still fall within the protection scope of the present invention.

Claims

1. A method for managing the ecological environment safety of industrial equipment, characterized in that: The following steps are involved: S1: Generate a trust score for the device through a dynamic trust assessment engine; S2: If the trust score is lower than the preset threshold, the threat level is determined based on the device status time series data, network traffic data, and process behavior data; S3: Using an adaptive policy arbitrator to adjust security control measures according to the threat level.

2. The method for ecological environment safety management of industrial equipment according to claim 1, characterized in that: In the step S1, the basic trust weight is adjusted by the behavior entropy value of the device, and the dynamic trust data is calculated according to the basic trust value and the basic trust weight; Historical credit data and environmental correction data are obtained, and a trust score is calculated using the historical credit data, environmental correction data, and dynamic trust data.

3. The method for ecological environment safety management of industrial equipment according to claim 2, characterized in that: In step S1, the behavior entropy value is calculated by the network traffic burstiness and the instruction cycle standard deviation. When the behavior entropy value is lower than the preset threshold, the basic trust weight is increased, and when the behavior entropy value is higher than the preset threshold, the basic trust weight is reduced.

4. The method for ecological environment safety management of industrial equipment according to claim 1, characterized in that: In step S2, the device status time series data is obtained, and the time series features are extracted from the device status time series data through the LSTM-Attention model and weighted processing is performed to obtain weighted feature data; the future trend of the device status is predicted based on the time series features and the weighted feature data, and the predicted data is output; the residual is calculated based on the difference between the predicted data and the actual observed data to obtain the prediction result.

5. The method for ecological environment safety management of industrial equipment according to claim 4, characterized in that: In the step S2, network traffic data is obtained, and the protocol compliance of the network traffic data is verified using a protocol state machine to obtain a compliance result.

6. The method for ecological environment safety management of industrial equipment according to claim 5, characterized in that: In the step S2, process behavior data is obtained, a process behavior baseline is constructed based on the process behavior data during normal operation, and a Markov chain model is constructed based on historical process behavior data; The process behavior data of the current process is compared with the process behavior baseline, and the process behavior data that deviates from the process behavior baseline is used as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; a threshold of the transition probability is preset, and when the output transition probability exceeds the threshold, the process behavior data is judged as abnormal, and a judgment result is obtained.

7. The method for managing the ecological environment safety of industrial equipment according to claim 6, characterized in that: In step S2, the prediction result, the compliance result and the judgment result are weighted and fused through a cross-modal attention mechanism to obtain a final threat score, and the threat level is determined according to the final threat score; In step S3, the adaptive policy arbitrator obtains the system load and threat level, determines the protection requirements according to the system load and threat level, and adjusts the security control measures.

8. The method for ecological environment safety management of industrial equipment according to claim 4, characterized in that: In step S2, before predicting the device status time series data through the LSTM-Attention model, the device status time series data is normalized; the continuous time series of the normalized device status time series data is divided into windows of fixed length, and missing value processing is performed.

Citation Information

Patent Citations

  • Industrial control network security protection monitoring system

    CN109474607A

  • Power terminal safety protection method and system

    CN114584405A

  • Security protection method, system and equipment based on Internet of Things equipment and medium

    CN118138339A

  • Self-adaptive zero-trust network evaluation method and system based on edge calculation

    CN118869267A

  • Network management method and device based on artificial intelligence, equipment and storage medium

    CN118890290A