An ecological environment safety management method for industrial equipment
Through the combination of dynamic trust evaluation and adaptive policy arbitrator, the problem of all-round and dynamic protection in industrial equipment security management is solved, effective identification and defense of APT attacks is achieved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202510517572.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-24
AI Technical Summary
The existing industrial equipment security management methods are difficult to achieve comprehensive and dynamic security protection, and it is impossible to effectively identify and defend against advanced persistent threat (APT) attacks.
The dynamic trust evaluation engine is used to generate trust scores, combine device status timing data, network traffic data and process behavior data to determine the threat level, and adjust security control measures through an adaptive policy arbitrator, and use multimodal threat perception network converged device status, network traffic and process behavior data to build a three-dimensional threat detection space.
It realizes multi-dimensional and dynamic security control of industrial equipment, can effectively identify and prevent various security threats, and improve the security and reliability of the system.
Smart Images

Figure CN120050118B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial equipment management, and particularly relates to an ecological environment security management method for industrial equipment. Background Art
[0002] Industrial equipment security control faces a complex and changeable threat environment. The traditional static protection method is role-based access control, which cannot cope with the dynamic access and behavior drift of industrial equipment and is difficult to handle the increasing security challenges. Security issues in multiple dimensions such as device identity authentication, behavior analysis, and protocol parsing are intertwined, forming a thorny technical problem, resulting in the difficulty of single-dimensional log analysis or traffic detection in identifying the cross-device collaborative characteristics of APT (Advanced Persistent Threat) attacks. Therefore, the current security management method is difficult to achieve all-round and dynamic security protection for industrial equipment. Summary of the Invention
[0003] In order to overcome the defects existing in the prior art, the present invention provides an ecological environment security management method for industrial equipment to solve the above problems.
[0004] The technical solution adopted by the present invention to solve its technical problems is: an ecological environment security management method for industrial equipment, including the following steps:
[0005] S1: Generate a trust score for the device through a dynamic trust evaluation engine;
[0006] S2: If the trust score is lower than a preset threshold, determine the threat level according to the device status time series data, network traffic data, and process behavior data;
[0007] S3: Use an adaptive policy arbiter to adjust the security control measures according to the threat level.
[0008] It should be noted that in the step S1, the basic trust weight is adjusted through the behavior entropy value of the device, and the dynamic trust data is calculated according to the basic trust value and the basic trust weight;
[0009] Obtain historical credit data and environmental correction data, and calculate the trust score through the historical credit data, environmental correction data, and dynamic trust data.
[0010] Preferably, in the step S1, the behavior entropy value is calculated through the network traffic burstiness and the instruction cycle standard deviation. When the behavior entropy value is lower than a preset threshold, the basic trust weight is increased; when the behavior entropy value is higher than a preset threshold, the basic trust weight is decreased.
[0011] Optionally, in the step S2, obtain the device status time-series data, extract the time-series features from the device status time-series data through the LSTM-Attention model and perform weighted processing to obtain the weighted feature data; predict the future trend of the device status based on the time-series features and the weighted feature data, and output the prediction data; calculate the residual according to the difference between the prediction data and the actual observed data to obtain the prediction result.
[0012] It should be noted that in the step S2, obtain the network traffic data, and verify the protocol compliance of the network traffic data by using a protocol state machine to obtain the compliance result.
[0013] It should be noted that in the step S2, obtain the process behavior data, construct a process behavior baseline based on the process behavior data during normal operation, and construct a Markov chain model based on the historical process behavior data;
[0014] Compare the process behavior data of the current process with the process behavior baseline, and use the process behavior data that deviates from the process behavior baseline as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; preset the threshold of the transition probability, and when the output transition probability exceeds the threshold, determine that the process behavior data is abnormal to obtain the judgment result.
[0015] Specifically, in the step S2, perform weighted fusion on the prediction result, the compliance result, and the judgment result through a cross-modal attention mechanism to obtain the final threat score, and determine the threat level according to the final threat score; in the step S3, the adaptive policy arbiter obtains the system load and the threat level, and judges the protection requirement according to the system load and the threat level to adjust the security control measures.
[0016] Specifically, in the step S2, before predicting the device status time-series data through the LSTM-Attention model, normalize the device status time-series data; divide the continuous time series of the normalized device status time-series data into windows of a fixed length and perform missing value processing;
[0017] The beneficial effects of the present invention are as follows: In the ecological environment security management method of the industrial equipment, the dynamic trust assessment engine calculates the dynamic trust value in real time based on the device fingerprint and user context, breaks through the static permission model, realizes the real-time trust quantification of the device, user, and environment, and uses the multi-modal threat perception network to fuse the device status time-series data (vibration / temperature), network traffic data (protocol fingerprint), and process behavior data (CPU / memory mode) to construct a three-dimensional threat detection space to determine the threat level. Finally, the adaptive policy arbiter dynamically switches the security control measures according to the real-time threat level. This multi-dimensional and dynamic security control method can effectively identify and defend various security threats in industrial equipment, improving the overall security and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a flowchart of the ecological environment security management method of industrial equipment in an embodiment of the present invention;
[0019] Figure 2 It is a flowchart block diagram of the ecological environment security management method of industrial equipment in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The following further describes the specific embodiments of the present invention with reference to the drawings. It should be noted here that the description of these embodiments is for helping to understand the present invention, but does not constitute a limitation to the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0021] As Figure 1 and 2 shown, an ecological environment security management method for industrial equipment includes the following steps:
[0022] S1: Generate a trust score for the device through a dynamic trust assessment engine;
[0023] S2: If the trust score is lower than a preset threshold, determine the threat level according to the device status time-series data, network traffic data, and process behavior data;
[0024] S3: Use an adaptive policy arbiter to adjust the security control measures according to the threat level to uniformly manage the security of the industrial equipment.
[0025] In the ecological environment security management method of the industrial device, the dynamic trust evaluation engine calculates the dynamic trust value in real time based on the device fingerprint and the user context, breaks through the static permission model, realizes the real-time trust quantification of the device, user, and environment, and uses the multi-modal threat perception network to fuse the device state time-series data (vibration / temperature), network traffic data (protocol fingerprint), and process behavior data (CPU / memory mode) to construct a three-dimensional threat detection space to determine the threat level. Finally, the adaptive policy arbiter dynamically switches the security control measures according to the real-time threat level. This multi-dimensional and dynamic security control method can effectively identify and defend various security threats in industrial devices, improving the overall security and reliability of the system.
[0026] It should be noted that in step S1, the basic trust weight is adjusted through the behavior entropy value of the device, and the dynamic trust data is calculated based on the basic trust value and the basic trust weight.
[0027] The historical credit data and the environment correction data are obtained, and the trust score is calculated through the historical credit data, the environment correction data, and the dynamic trust data.
[0028] In the initialization stage, a unique hardware DNA (fusing the TPM 2.0 measurement value and the PUF physical unclonable function response) is generated during device registration. During runtime update, the behavior entropy value (based on the burstiness of network traffic and the standard deviation of the instruction cycle) is calculated every 5 minutes, and the basic trust weight is dynamically adjusted.
[0029] After adjusting the trust weight, the credit score is obtained according to the following formula ; is the adjusted basic trust weight, is the basic trust value; is the historical credit mean (sliding window or exponentially decaying weighted); is the environment correction factor (such as device authentication strength, geographical location risk); is the historical weight coefficient, is the environment weight coefficient, and it needs to satisfy .
[0030] Preferably, in step S1, the behavior entropy value is calculated through the burstiness of network traffic and the standard deviation of the instruction cycle. When the behavior entropy value is lower than the preset threshold, the basic trust weight is increased; when the behavior entropy value is higher than the preset threshold, the basic trust weight is decreased.
[0031] For the behavior entropy value, when the entropy value is lower than the preset threshold, it indicates that the behavior is predictable, and at this time, the trust weight can be increased; when the entropy value is higher than the preset threshold, it indicates that the behavior is complex or abnormal, and at this time, the trust weight needs to be decreased. The behavior entropy value ; is the burstiness index of network traffic (such as the coefficient of variation or the peak-to-mean ratio); is the standard deviation of the instruction cycle; and is the weight coefficient (which needs to satisfy ); max(⋅) is the normalization factor (historical data or theoretical maximum); the burstiness of network traffic and the standard deviation of the instruction cycle are obtained through data collection.
[0032] Optionally, in the step S2, device status time-series data is obtained, and time-series features are extracted from the device status time-series data through an LSTM-Attention model and weighted to obtain weighted feature data; the future trend of the device status is predicted based on the time-series features and the weighted feature data, and prediction data is output; the residual is calculated according to the difference between the prediction data and the actual observed data, and it is judged whether the residual exceeds the normal range (for example, when collecting vibration signals in the healthy state of the device, the standard deviation σ of each feature is calculated, and the normal range of each feature is defined as [-3σ, +3σ]) to obtain a prediction result for detecting abnormal mechanical vibration.
[0033] Specifically, to obtain the residual between the prediction data and the actual observed data, the following steps need to be executed:
[0034] LSTM extracts time-series features: First, the device status time-series data is windowed and input into a bidirectional LSTM network; LSTM can capture long-term dependencies in the data, thereby learning the potential patterns and regularities in the time-series data; through two layers of bidirectional LSTM networks, the LSTM network can process information simultaneously in the forward and backward directions of time, improving the ability to understand complex device status time-series data.
[0035] The attention mechanism focuses on critical moments: After extracting the time-series features, the time-step attention mechanism is used to weight these time-series features to obtain weighted feature data, focusing on the critical moments that have the greatest impact on the prediction; the attention mechanism assigns different weights according to the importance of each time step, thus highlighting the data at important time points.
[0036] Prediction: Based on the time-series features extracted by LSTM and the features focused by the attention mechanism, the future trend of the device status is predicted through a pre-trained model, and the prediction data of the device is output; this prediction data will be compared with the actual observed data later.
[0037] Calculating the residual: The residual of the device status time-series data refers to the difference between the prediction data and the actual observed data.
[0038] In this embodiment, analyzing the residuals can help detect anomalies; when the value of the residual exceeds a predetermined normal range, it may indicate abnormal mechanical vibration of the device, indicating potential faults or problems.
[0039] Process the time-series data of the device state through a Long Short-Term Memory network (LSTM) and an Attention mechanism to judge abnormal mechanical vibration. Collect acceleration data during the operation of the device through a vibration sensor to obtain the time-series data of the device state. Separate the frequency-domain features and time-frequency domain features of the device state time-series data, and obtain the time-series dependence feature representation according to the frequency-domain features and time-frequency domain features separated by processing through the Long Short-Term Memory network. Use time-step attention to focus on the critical moments of the time-series dependence feature representation, and finally output the prediction result. In this embodiment, the Long Short-Term Memory network (LSTM) will input windowed time-series data of the device state and use two-layer bidirectional LSTM to capture long-term dependencies.
[0040] Perform level classification for abnormal mechanical vibration detection through joint multi-feature: warning level, mild anomaly level, and severe fault level. Among them, set a slight deviation threshold. When a single feature deviates from the baseline and is within the slight deviation threshold, and the duration is less than the set value, it is the warning level. Set a feature deviation quantity threshold. When the number of features deviating from the baseline and within the slight deviation threshold is greater than the feature deviation quantity threshold, or when the duration of a single feature deviating from the baseline and within the slight deviation threshold is greater than or equal to the set value, it is the mild anomaly level. Set a safety threshold. When a feature exceeds the safety threshold and the envelope spectrum energy rises exponentially, it is the severe fault level.
[0041] Among them, single-feature deviation means that there is a deviation between a certain feature (such as vibration, temperature, etc.) and the expected value in the normal state. Slight deviation means that these deviations are relatively small and usually do not immediately affect the normal operation of the device, but may be early signs of potential problems. For example, the vibration amplitude of the device increases slightly but does not exceed the safety limit, which may indicate a slight anomaly in the device and may develop into a more serious problem in the future.
[0042] The feature value refers to the numerical features extracted from the signal (such as vibration frequency, temperature, pressure, etc.). The feature value exceeding the safety threshold means that some feature values exceed the pre-set safety standard or critical value, which is usually a sign that the system detects anomalies or risks. For example, the device temperature exceeds the set maximum safety temperature, which may cause device damage or accidents and requires emergency treatment measures.
[0043] The increase in the envelope spectrum energy index generally refers to the gradual increase in the signal energy index obtained through envelope analysis. Envelope spectrum analysis is mainly used to identify mechanical faults in equipment, such as gear damage or bearing faults. When the envelope spectrum energy index rises, it usually indicates that the fault condition of the equipment is deteriorating, and trend prediction needs to pay attention to this change in order to take measures early. The process of trend prediction generally includes the following steps:
[0044] Data collection: Collect historical operation data of the equipment or system, including time series data of various characteristic values (such as vibration signals, temperature changes, etc.);
[0045] Feature extraction: Extract key features from the original signal, such as frequency domain features and time domain features, etc.;
[0046] Trend analysis: Use statistical methods or machine learning algorithms (such as time series analysis, regression analysis, etc.) to analyze the change trend of the envelope spectrum energy index of the extracted key features;
[0047] Trend prediction: Based on historical data and trend analysis models, predict the change direction and amplitude of the features in the future for a period of time; if the trend shows that the feature value exceeds the safety threshold and the envelope spectrum energy rises exponentially, an alarm is issued through the system.
[0048] Subsequently, the baseline will be updated through a sliding window to adapt to the slow changes caused by equipment aging; in addition, transfer learning will be used to reuse the existing model on new equipment and fine-tune it with a small amount of data.
[0049] Specifically, in step S2, network traffic data is obtained, and the OPC UA (Object Linking and Embedding, Unified Architecture) protocol compliance of the network traffic data is verified by using a protocol state machine to obtain a compliance result, so as to intercept unconventional read and write sequences.
[0050] In the OPC UA protocol, verifying protocol compliance is the key to ensuring communication security and reliability. By analyzing the characteristics of network traffic data, the protocol state machine can detect abnormal behaviors and ensure that sessions comply with the specifications. The characteristics of network traffic data include the average traffic per second, traffic peak, number of connections, session duration, and two-way traffic ratio;
[0051] For the average traffic per second and traffic peak, the average traffic per second is calculated using the traffic values of historical data (such as 30 days), and then the traffic standard deviation is calculated using the average traffic per second. The peak threshold corresponding to the traffic peak is set as the average traffic per second + 3 times the traffic standard deviation; when the traffic peak exceeds the peak threshold, it is determined that there is abnormal traffic, such as a DoS attack or abuse;
[0052] For the number of connections, count the concurrent connections of a single IP / service by service (HTTP / SSH), where HTTP (HyperText Transfer Protocol) is the hypertext transfer protocol and SSH (Secure Shell) is the secure shell protocol; set a connection number baseline. When the number of connections exceeds twice the connection number baseline and the duration exceeds the set value, it is determined that there is scanning network activity or botnet activity;
[0053] For the session duration, set corresponding timeout thresholds for short session services (such as HTTP) and long connection services (such as databases) in the session respectively. When the short session service exceeds its corresponding timeout threshold (such as 5 minutes), it is determined that the short session service times out. When the long connection service exceeds its corresponding timeout threshold (such as 2 hours), it is determined that the long connection service times out;
[0054] For the two-way traffic ratio, set a threshold for the proportion of upload traffic in a single session. When the proportion of upload traffic in a single session is greater than the threshold for the proportion of upload traffic in a single session, it is determined that there is data leakage; set a threshold for the proportion of download traffic in a single session. When the proportion of download traffic in a single session is greater than the threshold for the proportion of download traffic in a single session, it is determined that there is data abuse download;
[0055] The protocol state machine analyzes based on these features and obtains a compliance result based on the above judgments.
[0056] It should be noted that in step S2, process behavior data is obtained, a process behavior baseline is constructed based on the process behavior data during normal operation, and a Markov chain model is constructed based on historical process behavior data;
[0057] The process behavior data of the current process is compared with the process behavior baseline, and the process behavior data that deviates from the process behavior baseline is used as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; a threshold for the transition probability is preset. When the output transition probability exceeds the threshold, the process behavior data is determined to be abnormal, and a judgment result is obtained. In the above way, abnormal DLL (Dynamic Link Library) loading or memory injection is identified (such as detecting the exploitation of the CVE-2023-1234 vulnerability, where CVE (Common Vulnerabilities and Exposures) is a standard created and maintained by MITRE for recording and classifying software vulnerabilities).
[0058] The purpose of obtaining process behavior data is to analyze the normal behavior pattern of the process and identify abnormal activities. Specifically, the process can be divided into the following key links:
[0059] Constructing the Process Behavior Baseline: First, based on the process behavior data during normal operation (such as file operations, memory access, network connections, etc.), construct a process behavior baseline. This process behavior baseline describes the typical behavior patterns of processes under normal circumstances and provides a reference for subsequent anomaly detection;
[0060] Establishing the Markov Chain Model: Through the analysis of historical process behavior data, construct a Markov chain model. This Markov chain model can capture the transition relationships between process behaviors; the Markov chain model uses the transition probabilities between states to simulate the behaviors of processes in different states and provides a quantitative basis for detecting anomalies;
[0061] Judging Process Behaviors and Identifying Anomalies: During the actual monitoring process, compare the behavior data of the current process with the process behavior baseline, and use the process behavior data that deviates from the process behavior baseline as the input of the Markov chain model; through the input data, utilize the mechanism of the Markov chain model to capture the transition relationships between process behaviors, and output the transition probability of this process behavior data; through the transition probability and the preset threshold of the transition probability, the judgment result can be obtained. For example, when the output transition probability exceeds the threshold, the process behavior data is judged as abnormal, and it is considered that the behavior data of the current process may have malicious behaviors such as abnormal DLL loading or memory injection, thus obtaining the judgment result.
[0062] For example, when detecting vulnerabilities such as CVE-2023-1234, malicious processes may use abnormal DLL loading or memory injection behaviors to execute attacks. By judging the deviation from the process behavior baseline of the behavior and combining the transition probabilities of the Markov chain model, such abnormal behaviors can be effectively identified, thus realizing the detection of vulnerability exploitation. This process helps to identify potential malicious activities and improve the detection ability of security threats through behavior analysis and model prediction.
[0063] Specifically, in the step S2, through the cross-modal attention mechanism, weightedly fuse the prediction result, the compliance result, and the judgment result to obtain the final threat score, and obtain the threat level according to the interval where the final threat score is located; the interval is divided according to the degree of damage of the threat to the system function, data integrity, or security.
[0064] Specifically, during the cross-modal attention weighted fusion process, different types of data (such as device status time-series data, network traffic data, process behavior data) are processed and fused into the final threat score;
[0065] For prediction results, they are usually numerical, such as threat probability, risk score, or classification results (e.g., the intensity level of a threat); for compliance results, they are boolean (compliant / non-compliant) or categorical (e.g., compliant, minor violation, serious violation, etc.); for judgment results, they are categorical (e.g., whether it is a malicious behavior) or numerical (e.g., the risk score of a malicious behavior); for these different types of results, the cross-modal attention mechanism can perform weighted fusion in the following ways:
[0066] Feature representation: First, the results from different data sources (such as prediction scores, compliance markers, and judgment results) are transformed into a unified feature space through appropriate embeddings or vector representations. For example, boolean compliance results can be converted into numerical representations of 0 or 1, and classification results can be transformed through one-hot encoding;
[0067] Cross-modal attention mechanism: The cross-modal attention mechanism calculates the relationships and importance between various data types and automatically assigns weights to different modalities (such as prediction results, compliance results, and judgment results). This can be achieved through a self-attention mechanism. For example, for each input result, the model calculates the contribution weight of it to the final threat score and adjusts the fusion degree of each result according to these weights;
[0068] Weighted fusion: The final weighted fusion combines each modality (prediction score, compliance marker, and judgment result) according to the attention weights to obtain a comprehensive threat score, which is usually a numerical output;
[0069] Threat level classification: According to the comprehensive score, it is mapped to different threat levels according to predefined intervals; for example, a threat score lower than a certain threshold indicates a low threat, and exceeding a certain threshold indicates a high threat, and then the corresponding threat types (such as cybersecurity threats, physical threats, operational threats) are given according to the threat score.
[0070] Threat classification is performed according to different data types (device status time-series data, network traffic data, and process behavior data) to obtain different threat types, including cybersecurity threats (DDoS attacks (fully known as Distributed Denial of Service attacks), malware, unauthorized access), physical threats (device physical damage, environmental interference), and operational threats (misconfiguration, human operation errors).
[0071] In the step S3, the adaptive policy arbiter obtains the system load and threat level, judges the protection requirements according to the system load and threat level, and adjusts the security control measures. Through the elastic security policy and the dynamic degradation mechanism based on the linkage between the load and the threat, the business continuity in the high-concurrency scenario is guaranteed.
[0072] The adaptive policy arbiter adjusts the security control measures by looking up a table. For example, when the threat level is low and the system load is less than 60%, the national cryptography SM9 encryption and lightweight auditing are enabled; when the threat level is medium and the system load is between 60% and 80%, the hardware TEE (Trusted Execution Environment) is activated to isolate the critical processes; when the threat level is high and the system load is greater than or equal to 80%, the device-level fusing is triggered and the cloud forensics sandbox is passed through.
[0073] Finally, through the protocol semantic abstraction (mapping Modbus / Profinet instructions to unified operation primitives), the unified orchestration of security policies for cross-vendor devices is realized to solve the problem of fragmentation in the security management of multi-vendor devices.
[0074] It should be noted that in the step S2, before predicting the device status time-series data through the LSTM-Attention model, the device status time-series data is normalized (for example, using Min-Max normalization or Z-Score normalization to eliminate the dimension difference); the continuous time series of the normalized device status time-series data is divided into windows of a fixed length (such as a 60-second window with a step size of 10 seconds), and missing value processing is performed, such as interpolation filling or removing abnormal windows, to obtain complete device status time-series data.
[0075] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings, but the present invention is not limited to the described embodiments. For those skilled in the art, without departing from the principle and spirit of the present invention, various changes, modifications, substitutions, and variations to these embodiments still fall within the protection scope of the present invention.
Claims
1. An ecological environment safety management method for industrial equipment, characterized in that, It includes the following steps: S1: Generate a trust score for the device through a dynamic trust assessment engine; In the step S1, adjust the basic trust weight through the behavior entropy value of the device, and calculate the dynamic trust data according to the basic trust value and the basic trust weight; Obtain historical credit data and environmental correction data, and calculate the trust score through the historical credit data, environmental correction data and dynamic trust data; Among them, the behavioral entropy value is calculated through the burstiness of network traffic and the standard deviation of instruction cycles. When the behavioral entropy value is lower than a preset threshold, the basic trust weight is increased; when the behavioral entropy value is higher than the preset threshold, the basic trust weight is decreased; the behavioral entropy value ; is the burstiness index of network traffic; is the standard deviation of the instruction cycle; and are weight coefficients; max(⋅) is a normalization factor; S2: If the trust score is lower than a preset threshold, determine the threat level according to the device status time series data, network traffic data and process behavior data; the device status time series data includes vibration signals and temperature signals, the network traffic data includes the average traffic per second, traffic peak value, number of connections, session duration and two-way traffic ratio, and the process behavior data includes file operations, memory access and network connections; For the device status time series data, extract time series features from the device status time series data through the LSTM-Attention model and perform weighted processing to obtain weighted feature data; predict the future trend of the device status according to the time series features and the weighted feature data, and output prediction data; calculate the residual according to the difference between the prediction data and the actual observation data, and judge whether the residual exceeds the normal range to obtain a prediction result; For the network traffic data, use a protocol state machine to verify the protocol compliance of the network traffic data to obtain a compliance result; For the process behavior data, construct a process behavior baseline based on the process behavior data during normal operation, and construct a Markov chain model based on the historical process behavior data; compare the process behavior data of the current process with the process behavior baseline, and use the process behavior data that deviates from the process behavior baseline as the input of the Markov chain model; the Markov chain model outputs the transition probability of the process behavior data; preset a threshold for the transition probability, and when the output transition probability exceeds the threshold, judge the process behavior data as abnormal to obtain a judgment result; Perform weighted fusion on the prediction result, the compliance result and the judgment result through a cross-modal attention mechanism to obtain a final threat score, and determine the threat level according to the final threat score; S3: Use an adaptive policy arbiter to adjust the security control measures according to the threat level.
2. The ecological environment safety management method for an industrial device according to claim 1, characterized in that: In the step S3, the adaptive policy arbiter obtains the system load and the threat level, judges the protection requirements according to the system load and the threat level, and adjusts the security control measures.
3. The ecological environment safety management method for an industrial device according to claim 1, characterized in that: In the step S2, before predicting the device status time series data through the LSTM-Attention model, normalize the device status time series data; divide the continuous time series of the normalized device status time series data into windows of a fixed length and perform missing value processing.
Citation Information
Patent Citations
Industrial control network security protection monitoring system
CN109474607A
Network management method and device based on artificial intelligence, equipment and storage medium
CN118890290A
Network security protection method and system
CN119011238A
Iterable trust policy-based information access security system, equipment and medium
CN119363436A
Power dispatching boundary data behavior anomaly detection method and system based on Markov chain
CN119496657A