Information security attack protection test system and method for domestic PLC system

By designing an information security attack protection testing system based on the device layer, logic layer and interface layer, simulating information security attacks and monitoring the system status in real time, the problem of lack of testing the information security attack protection capabilities of domestic PLC systems in the existing technology is solved, and the reliability and fault tolerance capabilities of domestic PLC systems are improved.

CN120065895APending Publication Date: 2025-05-30709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510231274.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The lack of methods for testing the information security attack protection capabilities of domestic PLC systems in the prior art has led to low reliability and fault tolerance capabilities of domestic PLC systems.

Method used

Design an information security attack protection testing system based on the device layer, logic layer and interface layer, simulate various information security attacks through the information security simulation attack platform, launch an attack on the target PLC system, and monitor the system status in real time through the upper industrial control machine to verify the protection, diagnosis and recovery capabilities of the PLC system.

Benefits of technology

It improves the protection, diagnosis and recovery capabilities of domestic PLC systems under information security attacks, thereby improving the reliability and fault tolerance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120065895A_ABST
    Figure CN120065895A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information security, and particularly discloses an information security attack protection test system and method for a domestic PLC system, and the system comprises an information security simulation attack platform, a target PLC system, and an upper industrial control computer. Wherein the information security simulation attack platform is used for initiating an information security attack to the target PLC system; the target PLC system is used for identifying and defending the information security attack and reporting the system state of the target PLC system to the upper industrial personal computer; and the upper industrial personal computer is used for monitoring the system state of the target PLC system in real time. The system can improve the reliability and fault-tolerant capability of a domestic PLC system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security technology. More specifically, it relates to an information security attack protection test system and method for domestic programmable logic controllers (PLCs). Background Art

[0002] Currently, domestic PLC systems generally use physical isolation to isolate from the Internet. However, since general PLC control protocols do not have mechanisms such as encryption and authentication, as long as an attacker can communicate with the PLC, simply constructing malformed data can achieve the purpose of damaging the PLC system. Therefore, domestic PLC systems need to have certain information security protection means and capabilities to resist general network information security attacks. In the prior art, there is no method for testing the information security attack protection ability of domestic PLC systems, resulting in low reliability and fault tolerance of domestic PLC systems. Summary of the Invention

[0003] Aiming at the deficiencies of the prior art, the purpose of this application is to provide an information security attack protection test system and method for domestic PLC systems, aiming to solve the problem of low reliability and fault tolerance of domestic PLC systems caused by the lack of a method for testing the information security attack protection ability of domestic PLC systems in the prior art.

[0004] To achieve the above purpose, in the first aspect, this application provides an information security attack protection test system for domestic PLC systems, including an information security simulation attack platform, a target PLC system, and a host industrial control computer, where: The information security simulation attack module is used to launch an information security attack on the target PLC system; The target PLC system is used to identify and defend against the information security attack and report the system status of the target PLC system to the host industrial control computer; The host industrial control computer is used to monitor the system status of the target PLC system in real time.

[0005] This application designs an information security attack protection test system for domestic PLC systems based on the device layer, logic layer, and interface layer, develops an information security simulation attack software platform, simulates various information security attacks that a general PLC system may suffer, launches an information security attack on the target PLC system, and then monitors the system status of the target PLC system in real time through the host industrial control computer to verify the protection, diagnosis, and recovery capabilities of the domestic PLC system when suffering from information security attacks, and improve the reliability and fault tolerance of the domestic PLC system.

[0006] According to the information security attack protection test system for domestic PLC systems provided by this application, the information security simulation attack platform is specifically used for one or more of the following: Launching a Distributed Denial of Service (DDOS) attack on the target PLC system; Launching a simulated host computer configuration software attack on the target PLC system; A firmware attack is launched on the target PLC system.

[0007] This application verifies the protection, diagnosis, and recovery capabilities of domestic PLC systems when subjected to information security attacks by artificially introducing DDOS attacks, simulating host computer configuration attacks, firmware attacks, and other information security attacks into the target PLC system, thereby improving the reliability and fault tolerance of domestic PLC systems.

[0008] According to the information security attack protection test system for domestic PLC systems provided by this application, the information security simulation attack platform is specifically used for: By forging communication data packets to arbitrarily send control commands, the normal operation of the target PLC system is interfered with; The operating environment of the central processing unit (CPU) module of the target PLC system is destroyed by disassembling maliciously tampered firmware and / or malicious code.

[0009] According to the information security attack protection test system for domestic PLC systems provided in this application, the information security simulation attack platform, the target PLC system and the host industrial computer are connected via an industrial network switch.

[0010] This application uses an industrial network switch to connect the information security simulation attack platform, the target PLC system and the host industrial computer to increase stability, reliability and security.

[0011] In a second aspect, the present application provides an information security attack protection test method for a domestic PLC system, which is applied to the information security attack protection test system for a domestic PLC system described in the first aspect, including: Launch information security attacks on the target PLC system through the information security simulation attack platform; Identify and defend against the information security attack through the target PLC system, and report the system status of the target PLC system to the upper industrial computer; The system status of the target PLC system is monitored in real time by the upper industrial computer.

[0012] According to the information security attack protection test method for domestic PLC systems provided by this application, launching an information security attack on the target PLC system through the information security simulation attack platform includes one or more of the following: Launching a distributed denial of service (DDOS) attack on the target PLC system through the information security simulation attack platform; Launching a simulated upper computer configuration software attack on the target PLC system through the information security simulation attack platform; Launching a firmware attack on the target PLC system through the information security simulation attack platform.

[0013] According to the information security attack protection test method for domestic PLC systems provided by this application, launching a simulated upper computer configuration software attack on the target PLC system through the information security simulation attack platform includes: The information security simulation attack platform wantonly sends control commands by forging communication data packets to interfere with the normal operation of the target PLC system; Launching a firmware attack on the target PLC system through the information security simulation attack platform includes: The information security simulation attack platform disassembles and maliciously tampers with the firmware and / or malicious code to damage the operating environment of the central processing unit (CPU) module of the target PLC system.

[0014] In a third aspect, this application provides an electronic device, including: at least one memory for storing programs; at least one processor for executing the programs stored in the memory. When the programs stored in the memory are executed, the processor is used to execute the information security attack protection test method for domestic PLC systems described in the second aspect or any one of the possible implementation manners of the second aspect.

[0015] In a fourth aspect, this application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program runs on a processor, the processor is caused to execute the information security attack protection test method for domestic PLC systems described in the second aspect or any one of the possible implementation manners of the second aspect.

[0016] In a fifth aspect, this application provides a computer program product. When the computer program product runs on a processor, the processor is caused to execute the information security attack protection test method for domestic PLC systems described in the second aspect or any one of the possible implementation manners of the second aspect.

[0017] It can be understood that the beneficial effects of the above second to fifth aspects can refer to the relevant descriptions in the first aspect above, and will not be elaborated here.

[0018] Generally speaking, compared with the prior art, the above technical solution conceived by this application has the following beneficial effects: By designing an information security attack protection test system for domestic PLC systems based on the device layer, logic layer, and interface layer, developing an information security simulation attack software platform, simulating various information security attacks that a general PLC system may suffer, launching information security attacks on the target PLC system, and then monitoring the system status of the target PLC system in real time through the upper industrial control computer, verifying the protection, diagnosis, and recovery capabilities of domestic PLC systems when suffering information security attacks, and improving the reliability and fault tolerance of domestic PLC systems. Brief Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0020] Figure 1 is one of the structural schematic diagrams of the information security attack protection test system for domestic PLC systems provided by the embodiments of this application; Figure 2 is the second structural schematic diagram of the information security attack protection test system for domestic PLC systems provided by the embodiments of this application; Figure 3 is the flow schematic diagram of the information security attack protection test provided by the embodiments of this application; Figure 4 is the flow schematic diagram of the information security attack protection test method for domestic PLC systems provided by the embodiments of this application; Figure 5 is the structural schematic diagram of the electronic device provided by the embodiments of this application. Detailed Embodiments

[0021] In order to make the purpose, technical solutions, and advantages of this application clearer, the following further details this application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described here are only used to explain this application and are not used to limit this application.

[0022] The term "and / or" in this article is an association relationship describing associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The symbol " / " in this article represents an "or" relationship between associated objects. For example, A / B represents A or B.

[0023] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.

[0024] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" refers to two or more. For example, a plurality of processing units refers to two or more processing units, etc.; a plurality of elements refers to two or more elements, etc.

[0025] Next, in combination with Figures 1-3 the information security attack protection test system for domestic PLC systems provided in the embodiments of the present application will be introduced.

[0026] Figure 1 is one of the structural schematic diagrams of the information security attack protection test system for domestic PLC systems provided in the embodiments of the present application. As Figure 1 shown, the system includes an information security simulation attack platform 110, a target programmable logic controller PLC system 120, and an upper industrial control computer 130, where: The information security simulation attack platform 110 is used to initiate an information security attack on the target PLC system; Optionally, information security simulation attack software can be run on the information security simulation attack platform, and this software can generate various types of information security attacks, including but not limited to DDOS attacks, viruses, etc.

[0027] Optionally, the information security simulation attack platform has a certain computing ability.

[0028] Optionally, relevant personnel can operate the information security simulation attack platform to control the information security simulation attack software to initiate an information security attack on the CPU module of the target PLC system. After the test is completed, control the information security simulation attack software to cancel all attacks.

[0029] The target PLC system 120 is used to identify and defend against information security attacks, and report the system status of the target PLC system to the upper industrial control computer; Optionally, the target PLC system is the PLC system to be tested, and it can be composed of a power supply module, a CPU module with secure and trustworthy functions, and other common peripheral modules such as I / O modules, etc., on which a logic control test program is running.

[0030] Optionally, the CPU module has a certain information security protection ability and can identify and defend against information security attacks on the PLC.

[0031] The upper industrial control computer 130 is used to monitor the system status of the target PLC system in real time.

[0032] Optionally, the upper industrial control computer can run a domestic PLC independent logic configuration software. The domestic PLC logic configuration software can debug and run the logic control program downloaded in the target PLC system online, and provide status diagnostic words to display the relevant working status of the PLC system.

[0033] Optionally, when conducting an information security attack on the target PLC system, it is possible to observe whether the security protection diagnostic words displayed by the PLC logic configuration software are correct, whether the relevant security protection plays a protective role, whether the test query function is affected, and whether the target PLC system and the internal logic control program in it return to normal operation after the attack stops, so as to monitor the working status and information security protection status of the target PLC system in real time.

[0034] An information security attack protection test system for a domestic PLC system provided by the present application designs an information security attack protection test system for a domestic PLC system based on the device layer, logic layer, and interface layer, develops an information security simulation attack software platform, simulates various information security attacks that a general PLC system may suffer, launches an information security attack on the target PLC system, and then monitors the system status of the target PLC system in real time through the upper industrial control computer to verify the protection, diagnosis, and recovery capabilities of the domestic PLC system when suffering from information security attacks, and improve the reliability and fault tolerance of the domestic PLC system.

[0035] In some embodiments, the information security simulation attack platform 110 is specifically used for one or more of the following: Launch a distributed denial of service (DDOS) attack on the target PLC system; Launch a simulated upper computer configuration software attack on the target PLC system; Launch a firmware attack on the target PLC system.

[0036] Optionally, the information security simulation attack platform can launch a DDOS attack on the target PLC system, attack the communication port of the upper industrial control computer by the target PLC system, and block the normal communication between the PLC system and the upper industrial control computer.

[0037] Optionally, after the DDOS attack, it is possible to observe the independent logic configuration software on the upper industrial control computer and whether the communication link between the upper industrial control computer and the target PLC system is normal, and whether the DDOS attack is identified and blocked in the information security diagnostic words, so as to determine whether the target PLC system successfully defends against the DDOS attack.

[0038] Optionally, the information security simulation attack platform may launch a simulated upper computer configuration software attack against the target PLC system. A simulated upper computer configuration software attack refers to simulating the behavior of a malicious attacker through simulation or actual penetration means, targeting vulnerabilities or configuration defects in the upper industrial control computer, including vulnerability exploitation attacks, identity authentication bypass, and other methods.

[0039] Optionally, after performing the simulated upper computer configuration software attack, it is possible to observe whether the autonomous logic configuration software on the upper industrial control computer and the test program in the target PLC system are operating abnormally, and whether the information security diagnostic word indicates an unauthenticated access and control, to determine whether the target PLC system has successfully defended against the simulated upper computer configuration software attack.

[0040] Optionally, the information security simulation attack platform may launch a firmware attack against the target PLC system. A firmware attack refers to malicious behavior targeting the firmware in an embedded device, and by tampering with, implanting, or exploiting firmware vulnerabilities, achieving persistent control of the device, data theft, or physical damage, including methods such as malicious firmware implantation and firmware vulnerability exploitation.

[0041] Optionally, after performing the firmware attack, it is possible to observe whether the autonomous logic configuration software on the upper industrial control computer and the test program in the target PLC system are operating abnormally, and whether the information security diagnostic word indicates a firmware verification exception, to determine whether the target PLC system has successfully defended against the firmware attack.

[0042] In some embodiments, the information security simulation attack platform 110 is specifically configured to: Arbitrarily send control commands by forging communication data packets to interfere with the normal operation of the target PLC system; Maliciously tamper with the firmware and / or malicious code through disassembly to damage the operating environment of the central processing unit (CPU) module of the target PLC system.

[0043] Optionally, when the information security simulation attack platform conducts a simulated upper computer configuration software attack on the target PLC system, it can intercept and analyze the control command network communication data frames between the upper industrial control computer and the target PLC system, and use replayed or forged control command data packets, mainly online debugging commands for the autonomous logic configuration software, including start, stop, online value modification, etc., to interfere with the normal operation of the PLC system.

[0044] Optionally, when the information security simulation attack platform conducts a solid-state attack on the target PLC system, under the condition of obtaining the authentication conditions of the target PLC system, it can send firmware that has been maliciously tampered with through disassembly or malicious code injection to upgrade or change the firmware within the target PLC system.

[0045] In some embodiments, the information security simulation attack platform 110, the target PLC system 120, and the upper industrial control computer 130 are connected through an industrial network switch.

[0046] Figure 2 It is the second structural schematic diagram of the information security attack protection test system for domestic PLC systems provided by the embodiments of the present application. As Figure 2 shown, the external communication network port of the target PLC system CPU module, the upper industrial control computer, and the information security simulation attack platform are connected through an industrial network switch, increasing stability, reliability, and security.

[0047] Figure 3 It is the flow schematic diagram of the information security attack protection test provided by the embodiments of the present application. As Figure 3 shown, in one embodiment of the present application, the test process is as follows: 1. Run the information security simulation attack control software on the information security simulation attack platform, and initiate an information security attack on the PLC system under test. The attack methods are as follows: 1a. Select the DDOS attack, attack the communication port of the PLC to the upper industrial control computer, and block the normal communication of the PLC system to the upper industrial control computer; 1b. Select to simulate the upper industrial control configuration software attack, and wantonly send control commands such as start / stop, debugging, and configuration software upgrade by forging communication data packets to interfere with the normal operation of the PLC control system; 1c. Select the firmware attack, and damage the runtime environment of the PLC system CPU module by disassembling and maliciously tampering with the firmware and injecting malicious code; 2. The PLC system under test defends against information security attacks through methods such as firewalls, active encryption during the interaction process, and firmware encryption; 3. Observe the state of the PLC system under test on the upper industrial control computer through the independent logic configuration software.

[0048] Figure 4 It is the flow schematic diagram of the information security attack protection test method for domestic PLC systems provided by the embodiments of the present application. As Figure 4 shown, it includes: Step 400, initiate an information security attack on the target PLC system through the information security simulation attack platform; Step 410, identify and defend against information security attacks through the target PLC system, and report the system state of the target PLC system to the upper industrial control computer; Step 420, monitor the system state of the target PLC system in real time through the upper industrial control computer.

[0049] In some embodiments, step 400 specifically includes one or more of the following: Step 4001: Launch a Distributed Denial of Service (DDOS) attack on the target PLC system through an information security simulation attack platform; Step 4002: Launch a simulated upper computer configuration software attack on the target PLC system through an information security simulation attack platform; Step 4003: Launch a firmware attack on the target PLC system through an information security simulation attack platform.

[0050] In some embodiments, step 4002 specifically includes: The information security simulation attack platform wantonly sends control commands by forging communication data packets to interfere with the normal operation of the target PLC system; Step 4003 specifically includes: The information security simulation attack platform disassembles and maliciously tampers with the firmware and / or malicious code to damage the operating environment of the Central Processing Unit (CPU) module of the target PLC system.

[0051] It should be understood that the above method is executed by the system in the above embodiments. The implementation principles and technical effects of the execution steps in the method are similar to those described in the above system. The working process of this method can refer to the corresponding process in the above system and will not be elaborated here.

[0052] Based on the method in the above embodiments, Figure 5 The schematic diagram of the physical structure of an electronic device is exemplified. As Figure 5 shown, an embodiment of the present application provides an electronic device, which may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the logical instructions in the memory 530 to execute the information security attack protection test method for the domestic PLC system in the above embodiments.

[0053] In addition, when the logical instructions in the above memory 530 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or this part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the information security attack protection test method for the domestic PLC system described in each embodiment of the present application.

[0054] Based on the method in the above embodiments, an embodiment of the present application provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program runs on a processor, the processor is caused to execute the information security attack protection test method for the domestic PLC system in the above embodiments.

[0055] Based on the method in the above embodiments, an embodiment of the present application provides a computer program product. When the computer program product runs on a processor, the processor is caused to execute the information security attack protection test method for the domestic PLC system in the above embodiments.

[0056] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0057] The method steps in the embodiments of the present application may be implemented in a hardware manner or by a processor executing software instructions. The software instructions may be composed of corresponding software modules. The software modules may be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, removable hard disks, CD-ROMs, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC.

[0058] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0059] It can be understood that the various numerical numbers involved in the embodiments of the present application are only for convenience of description and are not used to limit the scope of the embodiments of the present application.

[0060] Those skilled in the art can easily understand that the above is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. An information security attack protection test system for domestic PLC systems, characterized in that: It includes an information security simulation attack platform, a target programmable logic controller (PLC) system, and an upper industrial computer, including: The information security simulation attack platform is used to launch an information security attack on the target PLC system; The target PLC system is used to identify and defend against the information security attack, and report the system status of the target PLC system to the upper industrial computer; The upper industrial computer is used to monitor the system status of the target PLC system in real time.

2. The information security attack protection test system for domestic PLC systems according to claim 1 is characterized in that: The information security simulation attack platform is specifically used for one or more of the following: Launching a distributed denial of service (DDOS) attack on the target PLC system; Launching a simulated host computer configuration software attack on the target PLC system; A firmware attack is launched on the target PLC system.

3. The information security attack protection test system for domestic PLC systems according to claim 1 or 2, characterized in that: The information security simulation attack platform is specifically used for: By forging communication data packets to arbitrarily send control commands, the normal operation of the target PLC system is interfered with; The operating environment of the central processing unit (CPU) module of the target PLC system is destroyed by disassembling maliciously tampered firmware and / or malicious code.

4. The information security attack protection test system for domestic PLC systems according to claim 1 is characterized in that: The information security simulation attack platform, the target PLC system and the upper industrial computer are connected via an industrial network switch.

5. A method for testing information security attack protection against domestic PLC systems, characterized in that: The information security attack protection test system for the domestic PLC system used in any one of claims 1 to 4 comprises: Launch information security attacks on the target PLC system through the information security simulation attack platform; Identify and defend against the information security attack through the target PLC system, and report the system status of the target PLC system to the upper industrial computer; The system status of the target PLC system is monitored in real time by the upper industrial computer.

6. The information security attack protection test method for the domestic PLC system according to claim 5 is characterized in that: The information security attack launched on the target PLC system through the information security simulation attack platform includes one or more of the following: Launching a distributed denial of service (DDOS) attack on the target PLC system through an information security simulation attack platform; Launching a simulated host computer configuration software attack on the target PLC system through an information security simulation attack platform; A firmware attack is launched to the target PLC system through an information security simulation attack platform.

7. The information security attack protection test method for the domestic PLC system according to claim 5 or 6 is characterized in that: The information security simulation attack platform is used to launch a simulated host computer configuration software attack on the target PLC system, including: The information security simulation attack platform sends control commands arbitrarily by forging communication data packets, thereby interfering with the normal operation of the target PLC system; The launching of a firmware attack on the target PLC system through an information security simulation attack platform includes: The information security simulation attack platform destroys the operating environment of the central processing unit (CPU) module of the target PLC system by disassembling maliciously tampered firmware and / or malicious code.

8. An electronic device, characterized in that: include: at least one memory for storing a computer program; At least one processor is used to execute the program stored in the memory. When the program stored in the memory is executed, the processor is used to execute the information security attack protection test method for the domestic PLC system as described in any one of claims 5-7.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program runs on a processor, the processor executes the information security attack protection test method for a domestic PLC system as described in any one of claims 5 to 7.

10. A computer program product, characterized in that When the computer program product runs on a processor, the processor executes the information security attack protection test method for a domestic PLC system as described in any one of claims 5 to 7.