Industrial control network risk assessment arrangement method and system based on narrow-sense network security atlas
Through the orchestration method based on the narrow network security knowledge graph, the industrial control network risk assessment tools are automatically integrated and implemented, and the problems of high complexity and low efficiency of risk assessment in the existing technology are solved, achieving more efficient risk assessment and improvement of industrial control network security.
Patent Information
- Application Number
- CN202510219683.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-05-30
AI Technical Summary
The existing industrial control network risk assessment technology has the problems of high difficulty in carrying out independent work, numerous tools rely on expert experience, and low evaluation efficiency.
The orchestration method based on the narrow sense of network security knowledge graph is adopted, and plans are automatically implemented and reports are generated by setting evaluation rules, building knowledge graphs, atomizing security tools, building security event models, refining script scenarios and plans, and integrating the orchestration architecture.
It reduces the complexity of risk assessment work, improves assessment efficiency, consolidates expert experience, and enhances the enterprise's independent assessment capabilities and the security of industrial control networks.
Smart Images

Figure CN120074918A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial control network risk assessment, and particularly to an industrial control network risk assessment orchestration method and system based on a narrow network security knowledge graph. Background Art
[0002] With the integrated development of new-generation information technologies such as cloud computing, big data, and 5G, industrial control networks are gradually deeply connected to office networks, the Internet, and third-party networks. While industrial control networks become more intelligent and automated, the relevance and complexity of the systems are also continuously increasing, which also brings more security challenges. As an active defense means that can proactively screen system risk problems, the application of risk assessment in industrial control network security is becoming increasingly important.
[0003] Risk assessment is a common risk elimination method for IT systems in the field of information security. When applied to the field of industrial control network security, it has the following limitations: it needs to be implemented by network security professional and technical personnel with high skills, has strong professionalism, and it is difficult to independently carry out risk assessment work; various security tools are required during the assessment process, there are many tools in each stage, the usage scenarios of different tools are different and overly rely on expert experience; most of the risk assessment process is mainly manual, and the tools are scattered, resulting in low efficiency. Therefore, it is necessary to reasonably orchestrate each tool, reduce the complexity of the assessment work, solidify the existing expert experience, improve the enterprise's independent assessment ability, and further improve the security of industrial control networks.
[0004] The narrow network security knowledge graph centrally embodies the core knowledge base of network security and its associated relationships. Usually, around specific network security topics, such as threat intelligence, attack techniques, vulnerability management, risk assessment, etc., refined knowledge organization and classification are carried out. Different from the broad network security knowledge graph with a wider coverage but more resource consumption, it focuses on more specific and clear security information organization and reasoning. The goal is to assist in detecting, predicting, and defending network attacks by constructing a semantic security information database.
[0005] Therefore, an industrial control network risk assessment orchestration method and system based on a narrow network security knowledge graph are proposed. Summary of the Invention
[0006] The purpose of the present invention is to provide an industrial control network risk assessment orchestration method and system based on a narrow network security knowledge graph, so as to overcome the deficiencies of the prior art that it is difficult to independently carry out risk assessment work, there are many security tools used in the assessment process, overly rely on expert experience, most of the risk assessment process is mainly manual, and the tools are scattered, resulting in low efficiency.
[0007] To achieve the above object, the present invention provides the following technical solutions: On the one hand, the present invention provides an industrial control network risk assessment orchestration method based on a narrow-sense network security knowledge graph, comprising the following steps: S1, setting evaluation rules; specifically, setting evaluation rules includes setting evaluation content and setting evaluation order; S2, constructing a narrow-sense network security knowledge graph according to the set evaluation content and set evaluation order, and obtaining an application tool set of the narrow-sense network security knowledge graph of a specific technical type at each implementation stage of the industrial control network risk assessment; S3, atomizing the tools according to the application tool set of the narrow-sense network security knowledge graph to form an atomic security tool set; S4, constructing a security event model, where the security event model includes security event types and security event attributes; obtaining the specific tools used by specific security events in the security event model according to the formed atomic security work set; S5, fusing and analyzing the attack scenarios in the security event attributes corresponding to the security event types to extract scenario scripts; S6, executing corresponding preplans for different scenario scripts, and dynamically adjusting the preplan execution steps using decision logic, and dynamically adjusting the preplan execution steps using decision logic; S7, integrating the atomic security tool set using an orchestration architecture, flowing according to time sequence and conditional branches, and completing the operation of the preplan corresponding to the scenario script; S8, identifying trigger conditions to execute the preplan; executing the set preplans under different scenario scripts according to different trigger conditions; S9, after the preplan execution is completed, generating and outputting a report.
[0008] Further, in S1, the set evaluation content formulates the specific content of the industrial control network risk assessment; the set evaluation order formulates the execution steps of the specific evaluation content; The steps for setting the evaluation content include: Setting general risk assessment content according to common risk assessment scenarios; Setting specific risk assessment content according to specific risk assessment scenarios and specific business security requirements.
[0009] Further, in S2, a mode system with a structure of "implementation stage - type category - application tool" dimension is formed through the narrow-sense network security knowledge graph; the application tool set of the narrow-sense network security knowledge graph is obtained under the theme of the industrial control network risk assessment according to this narrow-sense network security knowledge graph.
[0010] Further, in S3, the atomic security tool set includes tool descriptions, entry files, parameter configuration files, and tool icons.
[0011] Further, in S4, according to relevant security requirements, the security event model centralizes relevant security threat intelligence, defines security event types and security event attributes, and designs each stage of the attack chain using the MITRE ATT&CK attack matrix.
[0012] Further, in S5, the scenario script includes malware detection, data leakage detection, credential abuse detection, insider threat detection, vulnerability exploitation detection, lateral movement detection, and phishing attack detection.
[0013] Further, in S7, the orchestration architecture includes an event trigger, a task scheduler, a decision engine, a task executor, and a feedback and optimization module.
[0014] Further, in S8, the triggering conditions include: triggering conditions based on system status or resource consumption, triggering conditions based on scheduled tasks, and triggering conditions based on user behavior.
[0015] Further, in S9, the output report content includes the detection details of security events, suggestions for subsequent maintenance, and audit logs for subsequent analysis, and the report is sent to the relevant person in charge for subsequent handling.
[0016] In a second aspect, there is provided an industrial control network risk assessment and orchestration system based on a narrow network security knowledge graph, including: An evaluation module: setting evaluation rules; setting evaluation rules specifically includes setting evaluation content and setting evaluation order; A first construction module: constructing a narrow network security knowledge graph according to the set evaluation content and set evaluation order to obtain an application tool set of the narrow network security knowledge graph; An atomization module: atomizing the tools according to the application tool set of the narrow network security knowledge graph to form an atomic security tool set; A second construction module: constructing a security event model, where the security event model includes security event types and security event attributes; obtaining the specific tools used by specific security events in the security event model according to the formed atomic security work set; A fusion and refinement module: fusing and analyzing the attack scenarios in the security event attributes corresponding to the security event types to refine the scenario script; An orchestration architecture module: integrating the atomic security tool set using the orchestration architecture, flowing according to time sequence and conditional branches, and completing the operation of the corresponding plan for the scenario script; An execution module: identifying the triggering conditions to execute the plan; executing the set plan under different scenario scripts according to different triggering conditions; An output module: after the plan is executed, generating and outputting a report.
[0017] Compared with the prior art, the present invention has the following beneficial technical effects: The present invention provides an industrial control network risk assessment and orchestration method based on a narrow network security knowledge graph. By constructing a narrow network security knowledge graph, a pattern system is formed, integrating a large number of scattered security tools, and clearly displaying the usage scenarios and relevant connections of each security tool in a graphical manner; by constructing a security event model, the security event types and attributes are displayed in a structured framework, and through the association rules within the model, the connections of each security event are displayed in the form of an attack chain. The attack technology types and attack impacts adopted by the security events included in the attack activity are displayed through a graphical interface, and the specific tools used for a specific security event are obtained by combining the security event model with the atomic security tool set; by setting scenario and pre-plan scripts, the attack scenarios in one or more security events are centrally displayed. For different attack scenarios, scenario scripts for the invocation of multiple atomic security tools according to time sequence, conditions, and requirements are formed. For different scenario scripts, corresponding pre-plans are executed, and the execution steps of the pre-plan are dynamically adjusted using decision logic; by implementing an orchestration architecture, the atomic security tools are integrated to complete the operation of the pre-plan corresponding to the scenario script, solidifying expert experience, reducing the complexity of the assessment work, and improving the assessment efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a schematic flowchart of the industrial control network risk assessment and orchestration method based on a narrow network security knowledge graph in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work shall fall within the protection scope of the present invention.
[0020] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.
[0021] Example 1 Refer to Figure 1 , the embodiment of the present invention provides an industrial control network risk assessment and orchestration method based on a narrow-sense network security knowledge graph, including the following steps: S1, set evaluation rules; setting evaluation rules specifically includes setting evaluation content and setting evaluation order; The setting of evaluation content formulates the specific content of industrial control network risk assessment; the setting of evaluation order formulates the steps for carrying out the specific evaluation content.
[0022] The setting of evaluation content formulating the specific content of industrial control network risk assessment includes the following steps: Set general risk assessment content according to common risk assessment scenarios; Set specific risk assessment content according to specific risk assessment scenarios and specific business security requirements.
[0023] The setting of evaluation order is carried out in sequence according to the evaluation content.
[0024] S2, construct a narrow-sense network security knowledge graph according to the set evaluation content and set evaluation order, and obtain an application tool set of the narrow-sense network security knowledge graph of specific technical types in each implementation stage of industrial control network risk assessment; Form a mode system with the structure of "implementation stage - type category - application tool" through the narrow-sense network security knowledge graph; the application tool set of the narrow-sense network security knowledge graph is obtained under the theme of industrial control network risk assessment; The implementation stage is determined based on the evaluation content, which is the stage of using specific technologies in the evaluation process, including information collection, asset identification, vulnerability identification, threat identification, etc.; The type category is the specific technical type adopted in the implementation stage. For example, information collection can include port scanning, service identification, path identification, etc.; The application tool is the specific tool corresponding to the type category technology in a specific implementation stage. For example, the port scanning type tool in the information collection stage can include Nmap, etc.
[0025] S3, atomize the tools according to the application tool set of the narrow-sense network security knowledge graph to form an atomic security tool set; the atomic tool is the most independent and refined functional unit in the orchestration architecture, and each unit performs a clear and single task.
[0026] The atomic security tools include the tools involved in the application tool set, as well as the input and output standardization tools for completing semantic conversion, which are convenient for the combination and invocation between all tools. The atomic security tool structure includes tool descriptions, entry files, parameter configuration files, and tool icons.
[0027] S4. Construct a security event model, which includes security event types and security event attributes; obtain the specific tools used for specific security events in the security event model based on the formed atomic security work set. A security event model is a structured framework used to describe, organize, and analyze security events in a network, including event types and event attributes; a security event refers to an event or behavior related to network security, including attacks, abnormal activities, and potential threats, which can affect the confidentiality, integrity, and availability of systems, networks, and data. Security events can be obtained from alarm logs or intelligence information; security event types are distinguished based on the source, nature, target, and attack methods of the events, including network attacks, malware infections, unauthorized access, data breaches, etc.; security event attributes are used to describe the details and characteristics of events, including event time, event source, affected resources, attack methods, and threat levels, etc. Specific tools used for specific security events in the atomic security tool set can be corresponding to the security event types in the security event model.
[0028] The security event model demonstrates the development process of security events through an attack chain. The attack chain describes each step of an attacker from initial access to the final target and can be implemented based on the MITRE ATT&CK attack matrix. The MITRE ATT&CK attack matrix is a comprehensive knowledge base that records and classifies tactics, techniques, and sub-techniques in network attack behaviors. The security event model concentrates relevant security threat intelligence according to relevant security requirements, defines event types and event attributes, and designs each stage of the attack chain using the MITRE ATT&CK attack matrix.
[0029] The security event model collects security event data from network security devices, log systems, and intelligence platforms, classifies the event data in real time, and analyzes event types, threat levels, etc. according to the model structure. Through the association rules within the model, find the connections between different events, reveal broader attack activities, and display the attack technique types and attack impacts of the security events included in the attack activities through a graphical interface.
[0030] S5. Conduct a fusion analysis on the attack scenarios in the security event attributes corresponding to the security event types, and refine the scenario script. Conduct a fusion analysis on the attack scenarios in the security event attributes corresponding to a single security event type or multiple security event types, and refine the general scenario script. A scenario script is a response plan for dealing with specific security events through automated process orchestration. Each scenario script represents the operation and processing scenarios of one or more specific security events. For different processing scenarios, multiple atomic security tools form scenario scripts called according to time sequence, conditions, and requirements.
[0031] The playbook scenarios include malware detection, data leakage detection, credential abuse detection, insider threat detection, exploit detection, lateral movement detection, phishing attack detection, etc.
[0032] S6. Execute the corresponding pre-defined plan for different playbook scenarios, and dynamically adjust the plan execution steps using decision logic; and dynamically adjust the plan execution steps using decision logic; A pre-defined plan is a series of pre-defined response steps and operation processes for dealing with specific playbook scenarios; for each pre-defined plan, define which events or conditions will trigger the execution of the plan. When the event or condition is triggered, the pre-defined plan will be automatically executed. Decision logic is the intelligent judgment mechanism in the pre-defined plan, which can decide which action should be taken based on the characteristics, environment or context of the event. During the operation of the pre-defined plan, the decision logic dynamically adjusts the response steps according to different conditions and context changes.
[0033] The response steps describe in detail the operations to be taken during the operation of the pre-defined plan, including detection, analysis, notification, review, etc.
[0034] The decision logic makes appropriate adjustments based on input conditions, conditional branches and feedback mechanisms to ensure the normal operation of the entire pre-defined plan.
[0035] S7. Integrate the atomic security toolset using an orchestration architecture, and complete the operation of the pre-defined plan corresponding to the playbook scenario according to the time sequence and conditional branch flow; integrate security services and data flow management through an orchestration engine, automated workflow and task scheduling.
[0036] The orchestration architecture includes an event trigger, a task scheduler, a decision engine, a task executor, and a feedback and optimization module; the event trigger is used for the trigger conditions of the operation of the pre-defined plan, which can be triggered by logs, monitoring tools and manual input conditions, etc.; once the event trigger detects the trigger condition, the task scheduler starts the pre-defined task flow and executes tasks sequentially or in parallel; the decision engine is used for dynamically adjusting the task flow, which can make intelligent decisions based on pre-defined rules and real-time analysis feedback, and dynamically adjust the response steps; the task executor is responsible for the specific task execution, calling specific atomic security tools to execute tasks, such as port scanning, IP scanning, running security scans, vulnerability scans and vulnerability verification, etc.; the feedback and optimization module is responsible for collecting the results and feedback of task execution, which is used to optimize the process and decision logic.
[0037] S8. Identify the trigger conditions to execute the pre-defined plan; execute the pre-defined plan set under different playbook scenarios according to different trigger conditions; The trigger conditions include: trigger conditions based on system status or resource consumption, trigger conditions based on regular tasks, and trigger conditions based on user behavior.
[0038] S9. After the pre-defined plan is executed, generate and output a report.
[0039] The execution of the plan for any script scenario will generate a report. Combining multiple plan reports can form a final risk assessment report. The report content includes the detection details of security incidents, suggestions for subsequent maintenance, and audit logs for subsequent analysis. Analyze the system risk threats in detail, sort each threat according to the impact level, and send the report to the relevant person in charge for subsequent handling.
[0040] Embodiment 2 The present invention also provides an industrial control network risk assessment orchestration system based on a narrow sense network security knowledge graph, which is implemented by using the above method: Including: Evaluation module: Set evaluation rules; setting evaluation rules specifically includes setting evaluation content and setting evaluation order; First construction module: Construct a narrow sense network security knowledge graph according to the set evaluation content and set evaluation order, and obtain an application tool set of the narrow sense network security knowledge graph of specific technical types in each implementation stage of the industrial control network risk assessment; Atomization module: Atomize the tools according to the application tool set of the narrow sense network security knowledge graph to form an atomic security tool set; Second construction module: Construct a security event model, and the security event model includes security event types and security event attributes; obtain the specific tools used by specific security events in the security event model according to the formed atomic security work set; Fusion and refinement module: Fusion-analyze the attack scenarios in the security event attributes corresponding to the security event types, and refine the script scenarios; Orchestration architecture module: Integrate the atomic security tool set by using the orchestration architecture, and transfer according to time sequence and conditional branches to complete the operation of the plan corresponding to the script scenario; Execution module: Identify the trigger conditions and execute the plan; execute the set plan under different script scenarios according to different trigger conditions; Output module: After the plan execution is completed, generate and output a report.
[0041] Only some exemplary embodiments of the present invention are described by way of illustration above. Without doubt, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the protection scope of the claims of the present invention.
[0042] Various modifications to these embodiments will be apparent to those of ordinary skill in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein; Finally: The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. An industrial control network risk assessment and orchestration method based on a narrow network security knowledge graph, characterized in that: The following steps are involved: S1, setting evaluation rules; setting evaluation rules specifically includes setting evaluation content and setting evaluation order; S2, construct a narrow network security knowledge graph according to the set evaluation content and the set evaluation order, and obtain an application tool set of the narrow network security knowledge graph of specific technical types under each implementation stage of industrial control network risk assessment; S3, atomize the tools according to the application tool set of the narrow network security knowledge graph to form an atomic security tool set; S4, construct a security event model, which includes security event types and security event attributes; obtain specific tools used for specific security events in the security event model based on the formed atomic security work set; S5, integrating and analyzing the attack scenarios in the security event attributes corresponding to the security event type, and extracting the scenario scenarios; S6, executing corresponding plans for different script scenarios, and dynamically adjusting the execution steps of the plans using decision logic; S7 uses the orchestration architecture to integrate the atomic security tool set, and completes the operation of the corresponding plan for the script scenario according to the timing and conditional branch flow; S8, identifying trigger conditions and executing the plan; executing the plan set in different script scenarios according to different trigger conditions; S9, the plan is executed and a report is generated and output.
2. The method for arranging industrial control network risk assessment based on a narrow network security knowledge graph according to claim 1 is characterized in that: In S1, the setting of the assessment content formulates the specific content of the industrial control network risk assessment; the setting of the assessment sequence formulates the steps for carrying out the specific content of the assessment; Setting up the assessment involves the following steps: Set general risk assessment content based on common risk assessment scenarios; Set specific risk assessment content based on specific risk assessment scenarios and specific business security requirements.
3. The method for arranging industrial control network risk assessment based on a narrow network security knowledge graph according to claim 1 is characterized in that: In S2, a model system having a structure of implementation stage-type category-application tool dimensions is formed through a narrow network security knowledge graph; the application tool set of the narrow network security knowledge graph is obtained under the theme of industrial control network risk assessment based on the narrow network security knowledge graph.
4. According to claim 1, a method for arranging industrial control network risk assessment based on a narrow network security knowledge graph is characterized in that: In the S3, the atomic security tool set includes tool descriptions, entry files, parameter configuration files and tool icons.
5. The method for arranging industrial control network risk assessment based on a narrow network security knowledge graph according to claim 1 is characterized in that: In S4, the security event model concentrates relevant security threat intelligence according to relevant security requirements, defines security event types and security event attributes, and uses the MITRE ATT&CK attack matrix to design each stage of the attack chain.
6. According to claim 1, a method for arranging industrial control network risk assessment based on a narrow network security knowledge graph is characterized in that: In S5, the script scenarios include malware detection, data leakage detection, credential abuse detection, internal threat detection, vulnerability exploitation detection, lateral movement detection, and phishing attack detection.
7. According to claim 1, a method for arranging industrial control network risk assessment based on a narrow network security knowledge graph is characterized in that: In S7, the orchestration architecture includes event triggers, task schedulers, decision engines, task executors, and feedback and optimization modules.
8. According to claim 1, a method for arranging industrial control network risk assessment based on a narrow network security knowledge graph is characterized in that: In S8, the triggering conditions include: a triggering condition based on system status or resource consumption, a triggering condition based on a periodic task, and a triggering condition based on user behavior.
9. According to claim 1, a method for arranging industrial control network risk assessment based on a narrow network security knowledge graph is characterized in that: In S9, the output report content includes the detection details of the security incident, suggestions for subsequent maintenance and an audit log for subsequent analysis.
10. An industrial control network risk assessment and orchestration system based on a narrow network security knowledge graph, characterized in that: include: Evaluation module: setting evaluation rules; setting evaluation rules specifically includes setting evaluation content and setting evaluation order; The first construction module: constructs a narrow network security knowledge graph according to the set evaluation content and the set evaluation order, and obtains an application tool set of the narrow network security knowledge graph of specific technical types in each implementation stage of industrial control network risk assessment; Atomization module: Atomize the tools according to the application tool set of the narrow network security knowledge graph to form an atomic security tool set; The second building module: building a security event model, which includes security event types and security event attributes; obtaining specific tools used for specific security events in the security event model based on the formed atomic security work set; Fusion and extraction module: Fusion and analysis of attack scenarios in security event attributes corresponding to security event types to extract scenario scenarios; Orchestration architecture module: Use the orchestration architecture to integrate the atomic security tool set, flow according to the timing and conditional branches, and complete the operation of the corresponding plan of the script scenario; Execution module: Identify trigger conditions and execute plans; execute plans set in different script scenarios according to different trigger conditions; Output module: After the plan is executed, a report is generated and output.
Citation Information
Cited By
Industrial control network security analysis method and system based on knowledge graph, and medium
CN121000513A