An industrial OT domain security event monitoring method and system based on behavior chain analysis

By building a historical security incident behavior chain experience database and multimodal monitoring, combined with hierarchical alarm and false alarm suppression mechanisms, the limitations of single-point detection and delayed response in the industrial OT domain are solved, and accurate identification and rapid response to complex behavior chains are achieved, thereby improving the flexibility and accuracy of OT domain security incident monitoring.

CN120151119BActive Publication Date: 2025-10-17FENGTAI SCI & TECH (BEIJING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510629445.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-10-17
Estimated Expiration
2045-05-16

AI Technical Summary

Technical Problem

Existing technologies in the industrial OT domain have single-point detection limitations, high false alarm rates, and delayed responses. They are unable to effectively identify equipment interlocking failures triggered by attackers through a combination of compliant instructions, and lack a verification mechanism for the spatiotemporal correlation of behavior chains, resulting in false alarms or missed alarms.

Method used

By building an experience database of historical security incident behavior chains, combining the spatiotemporal correlation analysis of multimodal monitoring elements, real-time monitoring of OT domain operation data flows, identifying behavior chains, and introducing hierarchical alarm and false alarm suppression mechanisms, the experience database is dynamically updated to improve system robustness.

Benefits of technology

It achieves accurate identification of complex behavior chains, reduces false alarm rates, improves response speed, reduces economic losses, and can adapt to new attack methods in a timely manner, thereby improving the flexibility and accuracy of OT domain security event monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151119B_ABST
    Figure CN120151119B_ABST
Patent Text Reader

Abstract

This application discloses a method and system for monitoring industrial OT security incidents based on behavioral chain analysis. By building an empirical database of historical security incident behavioral chains and combining spatiotemporal correlation analysis of multimodal monitoring elements, this method accurately identifies events ranging from single-point anomalies to complex behavioral chains. Dynamic updates and false alarm suppression mechanisms are introduced to enhance system robustness, and a hierarchical alerting strategy significantly reduces computational load and improves response speed. This method effectively addresses industry pain points in industrial OT security incident monitoring, such as delayed response to new attack modes, fragmented multimodal data, and the inability to identify device interlocking failures triggered by attackers using compliant command combinations. This method represents significant technological advancement and has significant industrial application value.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of industrial safety monitoring. In particular, it relates to an industrial OT domain security event monitoring method and system based on behavior chain analysis. BACKGROUND

[0002] The OT domain of the industrial scene mainly focuses on real-time control of physical devices and management of industrial processes, involving industrial control systems (such as SCADA, DCS, PLC), sensors, automation devices, etc. In the OT domain, the primary task is to ensure production safety and ensure normal and stable production. Therefore, in the promotion of industrial intelligence, the OT domain security event monitoring method for real-time collection of device data, real-time monitoring and analysis of devices, and timely discovery of problems has always been highly valued, and mainly relies on high-quality single-point anomaly detection, and the security monitoring of the OT domain is realized through sensor threshold judgment or control instruction blacklist filtering scheme. This "single-point" analysis method, although it reacts quickly in dealing with single-device faults and handling single events, has the following disadvantages:

[0003] 1. Single-point detection has limitations: only monitoring isolated nodes (such as temperature sensor over-limit), unable to identify device interlocking failures triggered by attackers through compliant instruction combination.

[0004] 2. High false alarm rate: lack of behavior chain spatiotemporal correlation verification mechanism, prone to false alarms due to accidental fluctuations or operation errors, causing economic losses.

[0005] 3. Response lag: the behavior chain alarm scheme in other technical fields needs to wait for the complete attack chain to be formed before triggering the alarm, and cannot start preventive measures in the early stages of the attack.

[0006] Due to the above disadvantages of current detection, as attack methods diversify and update, a more flexible OT domain security monitoring method is needed. On the other hand, advanced persistent threats (APT) often form attack chains through multi-node, multi-stage covert operations, and traditional methods lack analysis of the spatiotemporal correlation of behavior sequences, which is prone to false positives or false negatives.

[0007] Therefore, there is an urgent need for a more flexible and effective industrial OT domain security event monitoring method. SUMMARY

[0008] The embodiment of the application provides a kind of based on behavior chain analysis industrial OT field security event monitoring method and system.The experience library of historical security event behavior chain is constructed, in combination with the spatio-temporal correlation analysis of multi-modal monitoring elements, the accurate identification from single-point anomaly to complex behavior chain is realized, and dynamic updating and false alarm suppression mechanism is introduced to improve system robustness, and the hierarchical alarm strategy can greatly reduce the calculation load and improve response speed.

[0009] In the first aspect, the embodiment of the application provides a kind of based on behavior chain analysis industrial OT field security event monitoring method, comprising the following steps:

[0010] S1, the experience library of historical security event behavior chain is constructed, and the experience library stores the behavior chain when security event occurs in the OT field, each behavior chain contains at least three key behavior nodes and its spatio-temporal correlation, and the quantitative description of accompanying phenomenon;

[0011] S2, the multi-modal monitoring elements of each behavior node in the OT field are extracted, and the multi-modal monitoring elements include numerical sensor data features, device visual morphology features and control instruction sequence features;

[0012] S3, real-time monitoring OT field operation data stream, and according to the multi-modal monitoring elements of each behavior node and its spatio-temporal correlation, the behavior chain of real-time OT field operation data stream is identified;

[0013] S4, when the matching degree of the behavior chain of real-time OT field operation data stream and any behavior chain in the experience library exceeds the preset threshold, hierarchical alarm is generated.

[0014] Further, the behavior chain in the experience library of historical security event behavior chain includes:

[0015] The spatio-temporal correlation defines: including the order and interval length of the behavior of the behavior node, the physical topology correlation of the node device involved;

[0016] The quantitative description of accompanying phenomenon includes: environmental parameter abnormal fluctuation mode, adjacent device state correlation change.

[0017] Further, the multi-modal monitoring elements include:

[0018] Numerical sensor data features: the data features obtained by trend analysis and mutation point detection on numerical sensor data;

[0019] Device visual morphology features: the appearance state change features of device obtained by industrial camera;

[0020] Control instruction sequence features: the result obtained by analyzing the compliance of PLC control instruction sequence.

[0021] Further, it also has:

[0022] Behavior chain tracking mode: when detecting that the behavior node in the behavior chain of the real-time OT domain operation data stream is the first key behavior node of a certain behavior chain in the experience library, start full-chain monitoring of the behavior chain of the real-time OT domain operation data stream.

[0023] Further, it also includes:

[0024] Experience library dynamic updating mechanism: allows the expert system to add, delete and modify the behavior chain nodes in the experience library;

[0025] Version control module, using blockchain technology to record the modification record.

[0026] Further, the hierarchical alarm includes:

[0027] Primary early warning stage: generate a preventive prompt when detecting a behavior chain leading node;

[0028] Intermediate alarm stage: start emergency plan preloading when a key node is continuously triggered;

[0029] Emergency alarm stage: trigger the device interlocking protection mechanism when the complete behavior chain condition is met.

[0030] Further, it also has a false alarm suppression mechanism: filter false alarms by verifying the matching condition of accompanying phenomena.

[0031] In a second aspect, the embodiments of the present application provide an industrial OT domain security event monitoring system based on behavior chain analysis, comprising:

[0032] Historical security event behavior chain experience library: the experience library stores multiple behavior chains of security events occurring in the OT domain, each behavior chain contains at least three key behavior nodes and their spatio-temporal correlation, and a quantitative description of accompanying phenomena;

[0033] Data acquisition module: used to extract multi-modal monitoring elements of each behavior node in the OT domain, the multi-modal monitoring elements including numerical sensor data features, device visual morphology features, and control instruction sequence features;

[0034] Behavior chain construction module: used to monitor the OT domain operation data stream in real time, and identify the behavior chain of the real-time OT domain operation data stream according to the multi-modal monitoring elements of each behavior node and their spatio-temporal correlation;

[0035] Real-time analysis module: when detecting that the matching degree between the behavior chain of the real-time OT domain operation data stream and any behavior chain in the historical security event behavior chain experience library exceeds a preset threshold, generate a hierarchical alarm.

[0036] In a third aspect, the embodiments of the present application provide an industrial control host, which comprises a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the computer program, when executed by the processor, implements the method of any one of the above first aspect.

[0037] In a fourth aspect, the embodiments of the present application provide a computer readable storage medium storing a computer program, and the computer program, when executed by a processor, implements the method of any one of the above first aspect.

[0038] It can be understood that the beneficial effects of the above-mentioned second aspect to fourth aspect can be referred to the related description in the above-mentioned first aspect, which will not be repeated here.

[0039] Compared with the prior art, the embodiments of the present application have the beneficial effects that: the method can identify the means of attack by the attacker through the combination of compliance instructions, and can greatly improve the attack identification capability of the security event, and can inhibit the false alarm triggered by accidental fluctuations or operation misjudgment, and can reduce the economic loss caused by no alarm. The conditional start of the behavior chain tracking mode can greatly reduce the system burden of the behavior chain monitoring. The hierarchical alarm strategy can start preventive measures in the early stage of attack without waiting for the formation of the complete attack chain, which can greatly improve the response speed and reduce the production loss. At the same time, in specific application, the verification process of the accompanying phenomenon is introduced, which can significantly reduce the false alarm rate. And the dynamic updating mechanism of the experience base of the method supports the continuous iteration of the knowledge base, which can adapt to new attack methods in time, and in some embodiments, the block chain storage technology is applied to the version iteration and modification of the experience base, which further improves the security and flexibility of the experience base, so that the monitoring system can safely realize self-evolution. The method effectively solves the industry pain points such as "new attack mode reaction lag", "multi-modal data fragmentation", "unable to identify the device interlocking failure triggered by the attacker through the combination of compliance instructions", and has significant technical progress and industrial application value. BRIEF DESCRIPTION OF DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0041] Figure 1is a step schematic diagram of an industrial OT domain security event monitoring method based on behavior chain analysis provided by an embodiment of the present application;

[0042] Figure 2 is an event behavior chain analysis diagram of a certain attack event provided by an embodiment of the present application;

[0043] Figure 3 is a schematic diagram of an industrial OT domain security event monitoring system based on behavior chain analysis provided by an embodiment of the present application;

[0044] Figure 4 is a schematic diagram of an industrial control host for industrial OT domain security event monitoring based on behavior chain analysis provided by an embodiment of the present application. DETAILED DESCRIPTION

[0045] In the following description, for the purpose of explanation and not limitation, specific details are set forth, such as particular system configurations, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present application with unnecessary detail.

[0046] It should be understood that the term "comprises" as used in the specification and the appended claims indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0047] It should also be understood that the term "and / or" as used herein refers to any one of the associated listed items, combinations of one or more of the associated listed items, and all possible combinations thereof.

[0048] As used in the description of the application and the appended claims, the term "if" can be interpreted as meaning "when" or "upon" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be interpreted as meaning "upon determining" or "in response to determining" or "upon detecting [a described condition or event]" or "in response to detecting [a described condition or event]", depending on the context.

[0049] In addition, in the description of the present application and the appended claims, the terms "first", "second", "third", etc. are only used for differentiation in description, and cannot be understood as indicating or implying relative importance.

[0050] Reference to“one embodiment” or“some embodiments” or“one implementation” or“some implementations” etc. in the present application description means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrases“in one embodiment” or“in some embodiments” or“in other embodiments” or“in still other embodiments” or other similar phrases in various places in the description are not necessarily all referring to the same embodiment, although the application can be so interpreted. Rather, the applicant’s intention is that each of the phrases in the above list refers to one or more embodiments or implementations.

[0051] Embodiments of the present application provide an industrial OT domain security event monitoring method and system based on behavior chain analysis. In the embodiments, by constructing a historical security event behavior chain experience library, combining spatio-temporal correlation analysis of multi-modal monitoring elements, accurate identification from single-point anomaly to complex behavior chain is realized, and a dynamic updating and false alarm suppression mechanism is introduced to improve the robustness of the system. The hierarchical alarm strategy can greatly reduce the computational load and improve the response speed. The main steps are shown in FIG. 1, which include:

[0052] S1, constructing a historical security event behavior chain experience library, the experience library stores a plurality of behavior chains when security events occur in the OT domain, each behavior chain contains at least three key behavior nodes and their spatio-temporal correlation relationship, and quantitative description of accompanying phenomena;

[0053] S2, extracting multi-modal monitoring elements of each behavior node in the OT domain, the multi-modal monitoring elements include numerical sensor data features, device visual morphology features, and control instruction sequence features;

[0054] S3, real-time monitoring of OT domain operation data flow, and identifying the behavior chain of real-time OT domain operation data flow according to the multi-modal monitoring elements of each behavior node and their spatio-temporal correlation relationship;

[0055] S4, when the matching degree of the behavior chain of real-time OT domain operation data flow with any behavior chain in the experience library exceeds a preset threshold, a hierarchical alarm is generated.

[0056] Each step is described in detail as follows:

[0057] S1, constructing a historical security event behavior chain experience library, the experience library stores a plurality of behavior chains when security events occur in the OT domain, each behavior chain contains at least three key behavior nodes and their spatio-temporal correlation relationship, and quantitative description of accompanying phenomena;

[0058] The monitoring system of one embodiment of the present application has an experience base storing historical security event behavior chains, which store the behavior chains when the OT domain device is attacked. Each behavior chain contains at least three key behavior nodes and their spatio-temporal correlation relationship, and a quantitative description of the accompanying phenomenon. Specifically:

[0059] In one embodiment, each behavior chain is defined as a triple, containing three key conditions: node information, spatio-temporal correlation, and accompanying phenomenon:

[0060] (1) Key behavior node information: contains at least three operation events in chronological order (such as instruction tampering, sensor anomalies, device state changes, etc.).

[0061] (2) Spatio-temporal correlation relationship: includes the time correlation relationship between nodes - time interval constraints (including the order and interval length of the behavior nodes), and the spatial correlation relationship - physical topology correlation.

[0062] (3) Accompanying phenomenon: includes environmental parameter abnormal fluctuation patterns (such as temperature, vibration) and quantitative change patterns of adjacent device states.

[0063] As shown in Figure 2 , take an attack event of a pump station in a petrochemical plant as an example. The attack event mainly tampered with the PLC instructions, causing the pump body to leak. For this security event, according to the monitoring method of the present application, key behavior nodes need to be extracted, and the spatio-temporal correlation relationship between the behavior nodes and the accompanying surrounding environmental phenomena need to be modeled.

[0064] After a large number of observation experiments, it is found that the number of key behavior nodes required to define a security event is at least 3, because too few behavior nodes, such as 2, will cause a large number of false positives due to unclear definition. Through experiments and theoretical deduction, it is proved that the number of key behavior nodes cannot be less than 3. At the same time, the number of key nodes is not the more the better, because too many behavior nodes, although it will improve the definition accuracy, but increases the monitoring workload and reduces the efficiency of system recognition, therefore, it needs to be measured according to the system capacity and requirements. In the embodiment of the present application, the definition of the behavior chain of the attack behavior: 3 key behaviors are extracted as behavior nodes. The 3 key behaviors are "PLC instruction tampering", "pressure sensor data mutation", and "pump body visual monitoring discovers leakage", and it is found that the surrounding environment temperature rises due to the leakage. According to the above behavior chain characteristics, the spatio-temporal correlation modeling is as follows:

[0065] (1) Time sequence constraint: define the time window between behavior nodes. For example, node N1 (instruction tampering) occurs, and node N2 (pressure mutation) must appear within 5 seconds, otherwise it is determined as an unrelated event.

[0066] (2) Physical topology correlation: Build adjacency matrix based on device location and communication path. For example, pump body and pressure sensor are directly connected through pipeline, then the correlation weight is set to 1, otherwise 0.

[0067] (3) Accompanying phenomenon: Ambient temperature rises, temperature rise rate ≥ 0.5℃ / s.

[0068] According to the above modeling conditions and the actual monitoring content, the behavior chain of the security event is established and stored in the experience library. The behavior chain storage format is as follows:

[0069] {

[0070] "chain_id": "ATTACK_001",

[0071] "nodes": [

[0072] {

[0073] "node_id": "N1",

[0074] "device": "PLC_01",

[0075] "action": "instruction tampering",

[0076] "timestamp": "t1"

[0077] },

[0078] {

[0079] "node_id": "N2",

[0080] "device": "pressure sensor_02",

[0081] "action": "data mutation (+20%)",

[0082] "timestamp": "t2",

[0083] "time_constraint": "t2 - t1 ≤ 5s"

[0084] },

[0085] {

[0086] "node_id": "N3",

[0087] "device": "pump body_03",

[0088] "action": "visual leakage",

[0089] "topology_constraint": "Distance to N2 device < 2m"

[0090] }

[0091] ],

[0092] "accompanying_effects": {

[0093] "env_temperature": "Rising rate > 0.5 °C / s",

[0094] "valve_status": "Adjacent valve opening closed (correlation coefficient < -0.8)"

[0095] }

[0096] }

[0097] S2, extract the multi-modal monitoring elements of each behavior node in the OT domain, the multi-modal monitoring elements including numerical sensor data features, device visual morphology features, and control instruction sequence features:

[0098] In one embodiment, the multi-modal monitoring elements related to the safety event behavior chain definition stored in the experience library in step S1 need to be extracted using various corresponding monitoring devices. Specifically, the multi-modal monitoring elements of each behavior node in the OT domain mainly include: multi-modal monitoring elements including numerical sensor data features, device visual morphology features, and control instruction sequence features. The descriptions of each multi-modal monitoring element are as follows:

[0099] Numerical sensor data features: data features obtained by trend analysis and mutation point detection on numerical sensor data.

[0100] In one embodiment, the numerical sensor data features are trend analysis—identify long-term trends by calculating the mean and standard deviation of the data measured by the sensor within a sliding window. For example, for temperature sensor data, the window size is set to 30 sampling points (corresponding to 1.5 seconds), and if the mean of the last 3 windows exceeds the historical baseline by 10%, it is marked as “slow warming”.

[0101] In another embodiment, the numerical sensor data features are mutation point detection—use the cumulative sum (CUSUM) algorithm to detect instantaneous abnormalities by cumulative deviation. For example, set the threshold h to 3 times the standard deviation, and trigger an alarm when the cumulative deviation exceeds h.

[0102] Therefore, in one embodiment, when the normal fluctuation range of a certain flow sensor is ±5%, if the flow value is detected to increase by 15% within 0.5 seconds, and the cumulative value according to the CUSUM algorithm exceeds the threshold value, it is determined to be a "sudden abnormality".

[0103] Device visual morphology features: device appearance state change features obtained through industrial cameras;

[0104] In one embodiment, the device visual morphology feature acquisition is completed through the following steps:

[0105] S201, image acquisition: obtaining device appearance images (resolution 256x256) through industrial cameras.

[0106] S202, feature extraction: using a lightweight convolutional neural network (such as MobileNetV3) to extract a 128-dimensional feature vector.

[0107] S203, anomaly determination: calculating the cosine similarity between the real-time image features and the reference library, and marking as abnormal (such as cracks on the pump body surface) when the cosine similarity is less than 0.85.

[0108] (3) Control instruction sequence features: the results obtained by analyzing the compliance of PLC control instruction sequences:

[0109] In one embodiment, the control instruction sequence features are implemented through whitelist rules - by defining regular expression patterns of legal PLC instructions:

[0110] First, define the legal instruction sequence: predefine the state transition table (such as "start → set parameters → stop").

[0111] Then, perform abnormal path detection: detect undefined instruction jumps (such as "start → stop" skipping the "parameter setting" step, then determine that it is a violation).

[0112] In another embodiment, the control instruction sequence features are implemented through context verification - by checking whether the instruction parameters meet the current state of the device. For example, receiving the "open cooling valve" instruction in the pump body closed state is marked as suspicious.

[0113] S3, real-time monitoring of OT domain operation data flow, and identifying the behavior chain of the real-time OT domain operation data flow according to the multi-modal monitoring elements of the behavior nodes and their spatio-temporal correlation:

[0114] The step is to integrate the real-time multi-modal monitoring elements of each behavior node of the OT domain extracted in step S2 into a behavior chain of the real-time OT domain operation data stream according to the spatio-temporal correlation relationship. The spatio-temporal correlation relationship features of the behavior chain and the behavior chains in the experience library include: time sequence features, physical topology correlation features, and the multi-modal feature similarity features described above, which are the main sources of calculation parameters for subsequent calculation of the matching degree of the real-time behavior chain and the behavior chains in the experience library.

[0115] S4, when it is detected that the matching degree of the behavior chain of the real-time OT domain operation data stream and any behavior chain in the experience library exceeds a preset threshold, generating a hierarchical alarm:

[0116] In an embodiment of the present application, the matching degree of the behavior chain of the real-time operation data stream of the OT domain and the behavior chain (hereinafter referred to as the historical behavior chain) in the experience library is obtained by comprehensively calculating the time sequence features, the physical topology correlation features, and the monitored multi-modal feature similarity features.

[0117] The matching degree is calculated by the following dynamic formula to obtain the matching degree value of the real-time behavior chain and the historical behavior chain:

[0118] P = a x T + b x M + g x C;

[0119] Wherein, T is the time sequence similarity score, M is the topology similarity, C is the feature similarity, a, b, g are dynamic adjustment coefficients.

[0120] Different thresholds are set according to different levels of alarms, such as P≥0.6 for primary warning, P≥0.75 for intermediate warning, and P≥0.85 for emergency warning.

[0121] As can be seen from the formula, the quantitative measurement and calculation of the similarity of each index are the basis for hierarchical alarm and an important guarantee for improving monitoring effect.

[0122] In an embodiment of the present application, the similarity calculation process of each index is as follows:

[0123] 1. Time sequence feature similarity T calculation:

[0124] The key point of time sequence feature similarity calculation is to align the time stamp sequences of the real-time behavior chain and the historical behavior chain, and eliminate the influence of time scale difference on the matching result. In this embodiment, the dynamic time warping (DTW) algorithm is used to solve this problem. The advantage of the dynamic time warping (DTW) algorithm is to allow elastic stretching and alignment of time sequences, which is especially suitable for time deviation caused by device response delay in industrial scenarios. The deviation is calculated mainly by setting a time window (i.e. the maximum allowed time stretching range) and calculating the path deviation (calculating the cumulative deviation of the time stamps after alignment, and the smaller the deviation, the higher the score).

[0125] The following is an example:

[0126] In the timing feature matching operation of the attack chain of a certain oil pump station:

[0127] ‌The time window parameter is: the maximum allowed time scaling range is set to ±30% (for example, if the historical chain length is 100 seconds, the real-time chain length is allowed to be matched within 70-130 seconds).

[0128] ‌The historical chain timestamp: the node time sequence is 0s, 25s, 50s (total length 50 seconds).

[0129] ‌The real-time chain timestamp: the detected node time sequence is 0s, 18s, 45s (total length 45 seconds).

[0130] ‌DTW alignment process:

[0131] ‌Alignment path:

[0132] Historical chain node 1 (0s) → real-time chain node 1 (0s);

[0133] Historical chain node 2 (25s) → real-time chain node 2 (18s);

[0134] Historical chain node 3 (50s) → real-time chain node 3 (45s).

[0135] (2)‌Path deviation calculation:

[0136] Node 1 deviation: |0-0|=0 seconds.

[0137] Node 2 deviation: |25-18|=7 seconds.

[0138] Node 3 deviation: |50-45|=5 seconds.

[0139] ‌Total deviation: 0+7+5=12 seconds.

[0140] (3) Timing similarity T calculation:

[0141] Maximum allowed deviation: 50 seconds x 30%=15 seconds.

[0142] Timing similarity T score formula:

[0143] Timing similarity score=1-total deviation / maximum allowed deviation.

[0144] Calculation result: 1-12 / 15=0.2 → normalized and mapped to timing similarity T score 0.93 (full score 1.0).

[0145] 2、‌Topology similarity M calculation:

[0146] The key point of the topology feature similarity calculation is to verify whether the physical topology association of the real-time behavior chain and the historical behavior chain is consistent, and to ensure the physical reachability of the attack path. In this embodiment, by means of topology modeling (adjacency matrix: for example, the connection between PLC and valve is recorded as 1, and 0 otherwise), a overlap ratio threshold is set to measure whether the topology association is consistent, and the overlap ratio of the device connection matrix is compared (for example, the connection between PLC and valve in the real-time chain, and the same connection exists in the historical chain, and then the score is increased).

[0147] The following is an example:

[0148] In the topology similarity calculation of a valve control attack chain:

[0149] The devices in the historical behavior chain in the experience library include: PLC101, valve203, SCADA.

[0150] An adjacency matrix is established (the connection is recorded as 1, and 0 otherwise)

[0151] The physical connection relationship of the device is: PLC101→valve203→SCADA, and the adjacency matrix of the historical behavior chain established therefrom is: [[0, 1, 0], [0, 0, 1], [0, 0, 0]].

[0152] The devices in the real-time behavior chain monitored include: PLC101, valve203, SCADA.

[0153] The physical connection relationship of the device is: PLC101→valve203→SCADA, and the adjacency matrix of the historical behavior chain established therefrom is: [[0, 1, 0], [0, 0, 1], [0, 0, 0]].

[0154] (2) Topology similarity M calculation:

[0155] The same number of connections: 2 (PLC101→valve203, valve203→SCADA).

[0156] Total number of connections: 2 (total number of connections of the historical chain).

[0157] Overlap ratio: 2 / 2=100%→topology similarity M score=1.0.

[0158] Determination result: match.

[0159] In another embodiment, the connection relationship of the historical behavior chain is unchanged, and the devices in the real-time behavior chain monitored include: PLC101, valve203, RTU305.

[0160] Device physical connection relationship is: PLC101 → valve203 → RTU305, the historical behavior chain adjacency matrix established by this is: [[0, 1, 0], [0, 0, 1], [0, 0, 0]];

[0161] ‌Overlap ratio calculation‌:

[0162] Same connection number: 1 (PLC101 → valve203).

[0163] Total connection number: 2 (total connection number of historical behavior chain).

[0164] ‌Overlap ratio‌: 1 / 2 = 50% → Topology similarity M score = 0.5, lower than threshold 60%, judged as mismatch.

[0165] 3、‌Feature similarity C calculation‌:

[0166] The key point of feature similarity calculation is to calculate the feature similarity of each multi-modal monitoring element of the real-time behavior chain obtained in step S2, including numerical sensor data features, device visual morphology features, and control instruction sequence features, with the historical behavior chain. In this embodiment, in order to improve the system adaptability, a dynamic model is used for similarity calculation. The dynamic adjustment coefficient is used to realize dynamic adjustment for different systems or different states of the system. That is, by adjusting the weights of numerical sensor data features, device visual morphology features, and control instruction sequence features, the feature similarity calculation is more in line with the actual monitoring accuracy requirements.

[0167] The following is an example:

[0168] The valve operating feature similarity calculation:

[0169] The feature similarity dynamic model calculates the feature similarity C value using the following formula:

[0170] C=α×S+β×V+γ×O;

[0171] Wherein, S is the numerical sensor data feature similarity, V is the device visual morphology feature similarity, O is the control instruction sequence feature similarity, and α, β, γ are dynamic adjustment coefficients, including the following steps:

[0172] (1) Extracting feature vectors of each node

[0173] a、‌Historical behavior chain‌ (valve forced opening) each node feature vector is as follows:

[0174] Numerical sensor data features: 0.9 (normalized data feature value when the oil pressure mutation amplitude in the historical behavior chain reaches the threshold value 120%),

[0175] Device visual features: [0.12, 0.45,..., 0.33] (128-dimensional vector extracted by MobileNetV3),

[0176] Control instruction sequence features: 02 (instruction type code, such as "memory read" coded as 01, "valve opening" coded as 02).

[0177] b、‌Real-time behavior chain‌ (detected valve operation) node feature vector as follows:

[0178] Numerical sensor features: 0.85 (oil pressure mutation amplitude is threshold 115%),

[0179] Device visual features: [0.15, 0.42,..., 0.30],

[0180] Control instruction features: 02.

[0181] (2) Cosine similarity calculation of each feature vector:

[0182] Numerical sensor feature similarity: |0.9-0.85|=0.05 → similarity=0.95.

[0183] Device visual feature similarity: cosine similarity=0.92.

[0184] Control instruction feature similarity: complete match, similarity=1.0.

[0185] (3) Feature similarity C calculation

[0186] C=α×S+β×V+γ×O (In this embodiment, the matching degree of numerical sensors is emphasized, so α=0.6, β=0.3, γ=0.1)

[0187] Therefore, C=0.6×0.95+0.3×0.92+0.1×1.0=0.57+0.276+0.1=0.946

[0188] That is, at this time, the feature similarity between the real-time behavior chain and the historical behavior chain is 0.946.

[0189] In summary, in one embodiment of the present application, the matching degree value calculation of the above-mentioned oil pump station attack chain comprehensive judgment embodiment is as follows:

[0190] Set: α=0.4, β=0.3, γ=0.3;

[0191] ‌Timing feature similarity T: 0.93 → contribution value=0.4×0.93=0.372.

[0192] ‌Topology similarity M: 1.0 → contribution value = 0.3 x 1.0 = 0.3.

[0193] ‌Feature similarity C: 0.946 → contribution value = 0.3 x 0.946 = 0.284.

[0194] Matching value P: 0.372 + 0.3 + 0.284 = 0.956 ≥ 0.8 → trigger emergency alarm.

[0195] In another embodiment, the industrial OT domain security event monitoring method based on behavior chain analysis also has a false alarm suppression mechanism: that is, by verifying the matching of accompanying phenomena to filter false alarms.

[0196] In this embodiment, the accompanying phenomena include abnormal fluctuation patterns of environmental parameters (such as temperature, vibration) and quantized change patterns of adjacent device states. In addition to the matching value P, the matching degree of the historical behavior chains in the behavior chain experience library of the real-time OT domain operation data stream is also a matching degree of the accompanying phenomena. After determining that the alarm needs to be triggered by the matching value P in the above embodiment, it is further necessary to verify whether the change of the adjacent device state is consistent with the operation logic (for example, the pump motor current should rise synchronously when the valve is opened).

[0197] For example, in one false alarm filtering embodiment, a behavior chain matches a historical behavior chain of an attack event in the experience library by 88% through the matching degree monitoring of the real-time behavior chain described above, reaching the trigger level of emergency alarm, but according to the record, the accompanying phenomenon of the historical behavior chain is that the fluctuation of oil pressure is greater than 0.8 MPa. But the oil pressure monitoring device on site shows that the current oil pressure fluctuation ΔP is 0.7 MPa (lower than the threshold value 0.8), and it is determined that this is a false alarm, and no emergency alarm measures are taken.

[0198] In one embodiment, the industrial OT domain security event monitoring method based on behavior chain analysis adopts a hierarchical alarm strategy, which includes:

[0199] Primary warning stage: generate a preventive prompt when the leading node of the behavior chain is detected:

[0200] ‌In the primary warning stage, since the attack event has just started to execute, when the real-time behavior chain matches the historical behavior chain, some leading nodes located at the front end of the behavior chain have already matched the leading nodes at the front end of the historical behavior chain relative to the attack event, that is, the matching value is already greater than 0. When the attack event continues, the matching value will continue to rise. In order to ensure the sensitivity of the monitoring system, in some embodiments, a threshold range for the primary warning stage is set, and when the matching value is in this range, the primary warning is started and corresponding measures are taken.

[0201] For example, when the behavior chain leading node is detected, when the matching value P reaches the interval [0.5, 0.7), the operation of the preliminary warning stage is performed - a risk prompt is pushed to the operation interface.

[0202] Example: PLC memory read operation is detected, and a prompt "potential suspicious behavior, manual verification is recommended" is given

[0203] Intermediate alarm stage: emergency plan preloading is started when the key node is triggered continuously

[0204] Intermediate warning stage, as the attack event unfolds, at this time the real-time behavior chain matches the historical behavior chain, part of the nodes of the real-time behavior chain have matched the key nodes with high weights in the historical behavior chain relative to the attack event, at this time the matching value will accelerate the rise. In some embodiments, a threshold range for the intermediate warning stage is set, when the matching value is in this interval, the intermediate warning is started and corresponding measures are taken.

[0205] For example, when the behavior chain continuously triggers the key node, when the matching value P reaches the interval [0.7, 0.8), the operation of the intermediate warning stage is performed - the emergency plan (such as the valve closing instruction) is preloaded.

[0206] Example: Valve opening and alarm suppression operations are continuously detected, and the oil line isolation preplan is started.

[0207] (3) Emergency alarm stage: trigger the device interlocking protection mechanism when the complete behavior chain condition is met

[0208] Emergency warning stage, as the attack event progresses, at this time the real-time behavior chain matches the historical behavior chain, most of the nodes of the real-time behavior chain have matched the nodes of the historical behavior chain relative to the attack event, at this time according to the matching result, the complete behavior chain condition is met, triggering the device interlocking protection mechanism, which can confirm that an attack event is occurring, and an alarm needs to be issued and immediate measures need to be taken. In some embodiments, a threshold range for the emergency alarm stage is set, when the matching value is in this interval, the emergency alarm is started and corresponding measures are taken

[0209] For example, when the matching value P of the behavior chain and the historical behavior chain is greater than or equal to 0.8, the operation of the emergency alarm stage is immediately performed - the device interlocking protection (such as cutting off the PLC communication port) is immediately triggered, and full resources are allocated for attack tracing.

[0210] Example: complete matching of tampering attack chain, execute valve emergency closing and log evidence.

[0211] In one embodiment, the industrial OT domain security event monitoring method based on behavior chain analysis has a behavior chain tracking mode. Specifically, when a behavior node in the behavior chain of the real-time OT domain operation data stream is detected, and the behavior node is the first key behavior node of a behavior chain in the experience library, full-chain monitoring of the behavior chain of the real-time OT domain operation data stream is started.

[0212] For example, the system also has the following hierarchical tracking analysis processing strategy:

[0213] (1) When the leading node of the behavior chain is detected, and the matching degree value P reaches the interval [0.5, 0.7), the operation of the primary tracking analysis stage is performed - 10% of the computing resources are allocated for continuous tracking of subsequent nodes.

[0214] (2) When the key node is continuously triggered by the behavior chain, and the matching degree value P reaches the interval [0.7, 0.8), the operation of the intermediate tracking analysis stage is performed - 30% of the resources are allocated to verify the accompanying phenomena.

[0215] (3) When the matching degree value P of the behavior chain and the historical behavior chain is greater than or equal to 0.8, the operation of the emergency tracking analysis stage is immediately performed - full resources are allocated for attack tracing.

[0216] The advantage of using the behavior chain tracking mode is that it can achieve a balance between saving system resources and comprehensive security monitoring. In order to ensure the accuracy of the output results, the industrial OT domain security event monitoring method based on behavior chain analysis needs to compare the characteristics of the real-time behavior chain with the characteristics of the historical behavior chain. This will undoubtedly occupy system resources. And with the complexity of historical behavior chains, more computing resources are needed, so full-time real-time whole-chain behavior chain comparison analysis of all OT domain devices is difficult in practical applications. Using the behavior chain tracking mode of the present embodiment, only when the first key behavior historical behavior chain node of a behavior chain in the experience library is detected, part of the system resources is mobilized, and full-chain monitoring of the behavior chain of the real-time OT domain operation data stream is started. And with the increase of the matching value, the computing resources for tracking and verification are also increased, thereby accelerating the operation process of subsequent verification comparison, achieving timely and rapid acquisition of matching results to meet the rapid early warning needs. At the same time, with the investment of computing resources, other accompanying phenomena are also verified, further improving the accuracy of early warning. This "slow in front and fast in back" verification process not only conforms to the characteristics of most attacks, but also maximizes the use of limited system computing resources and minimizes the impact on normal production business.

[0217] In one embodiment, the industrial OT domain security event monitoring method based on behavior chain analysis further comprises:

[0218] Experience base dynamic updating mechanism: allow the expert system to add, delete or modify the behavior chain node in the experience base.

[0219] With the continuous development of attack and defense technology, various new attack methods emerge in an endless stream, which requires continuous updating or adding of behavior chains in the experience base. At the same time, for some common attack methods, many system designers have designed iterative versions in the OT domain, which have avoided the attack in advance by system means. This part of the historical behavior chain simply wastes system storage and computing resources in the experience base and loses its value, so it needs to be removed.

[0220] In this embodiment, the system has a visual editing interface: allows security experts to add new attack chains (such as new ransomware behavior patterns). Or delete or edit the nodes of the historical behavior chains stored at present.

[0221] In one embodiment, in order to ensure the continuity and traceability of the security expert's modification of the experience base content, the modified version of the experience base needs to be controlled, so a version control module is set up in the system to provide complete version control for the previous modification of the experience base content.

[0222] In one embodiment, in order to realize the complete version control of the previous modification of the experience base content, the system uses blockchain technology to store the modification records.

[0223] In this embodiment, the system uses blockchain technology to generate a unique version number for each modification, record the operator, time and modification content.

[0224] For example, when adding a key node "PLC102 writes unauthorized instructions" to the behavior chain ID "ATTACK-2024-010" in the experience base, the version number generation process using blockchain storage is as follows:

[0225] {

[0226] "block hash": "0x9a3f...",

[0227] "timestamp": "2025-04-30T09:32:15Z",

[0228] "operation record": [

[0229] {

[0230] "type": "add node",

[0231] "behavior chain ID": "ATTACK-2024-010",

[0232] "Node details": "PLC 102 wrote unauthorized instruction",

[0233] "Digital signature": "ECDSA-SHA256"

[0234] }

[0235] ],

[0236] "Merkle root": "0x5c7d..."

[0237] }

[0238] The modification record is stored by using the blockchain technology, has many advantages such as traceability and tamper resistance, and can improve the completeness of the experience library.

[0239] Based on the same technical concept, as shown in Figure 3 , the embodiment of the application further provides an industrial OT domain security event monitoring system based on behavior chain analysis. For the convenience of description, only the part related to the embodiment of the application is shown. Referring to Figure 3 , the device comprises:

[0240] A historical security event behavior chain experience library: the experience library stores a plurality of behavior chains of security events occurring in the OT domain, each behavior chain comprises at least three key behavior nodes and their spatio-temporal correlation relationship, and a quantitative description of accompanying phenomena;

[0241] A data acquisition module: used for extracting a plurality of modal monitoring elements of each behavior node in the OT domain, the plurality of modal monitoring elements comprising numerical sensor data features, device visual form features, and control instruction sequence features;

[0242] A behavior chain construction module: used for monitoring the OT domain operation data stream in real time, and identifying the behavior chain of the real-time OT domain operation data stream according to the plurality of modal monitoring elements of each behavior node and their spatio-temporal correlation relationship;

[0243] A real-time analysis module: when the matching degree between the behavior chain of the real-time OT domain operation data stream and any behavior chain in the historical security event behavior chain experience library exceeds a preset threshold, a hierarchical alarm is generated.

[0244] It should be understood that the size of the serial number of each step in the above embodiment does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the application.

[0245] It should be noted that the information interaction, execution process and the like between the above devices / units, since based on the same concept as the method embodiments of the application, the specific functions and the technical effects brought by them can be referred to the method embodiment part, and will not be repeated here.

[0246] It should be clearly understood by those skilled in the art that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit. In addition, the specific name of each functional unit and module is only for convenient distinction, and does not limit the protection scope of the present application. The specific working process of the unit and module in the system can refer to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0247] As shown in Figure 4 The embodiment of the present application also provides a work control host, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps in any of the method embodiments when executing the work control host program.

[0248] The embodiment of the present application provides a computer program product, which, when running on a terminal, enables the terminal to implement the steps in each of the method embodiments.

[0249] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the present application can implement all or part of the processes in the above-mentioned embodiment methods through a computer program to instruct relevant hardware to complete, and the computer program can be stored in a computer readable storage medium. When the computer program is executed by a processor, the steps of each method embodiment described above can be implemented. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms. The computer readable medium at least includes any entity or device capable of carrying the computer program code to the photographing device / target device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium. For example, U disk, mobile hard disk, magnetic disk or optical disk, etc. In some jurisdictions, according to legislation and patent practice, the computer readable medium can not be an electrical carrier signal and a telecommunication signal.

[0250] In the above embodiments, the description of each embodiment has its own focus, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0251] Those skilled in the art can appreciate that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0252] In the embodiments provided in the present application, it should be understood that the disclosed apparatus / network device and method can be implemented in other ways. For example, the apparatus / network device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual coupling or direct coupling or communication connection between each other can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0253] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may also be distributed to multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiment scheme according to actual needs.

[0254] The above embodiments are only used to illustrate the technical solutions of the present application, but not limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can still be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A method for monitoring industrial OT domain security events based on behavior chain analysis, characterized in that: The following steps are involved: S1. Build a historical security incident behavior chain experience database, which stores multiple behavior chains when security incidents occur in the OT domain. Each behavior chain contains at least three key behavior nodes and their spatiotemporal relationships, a quantitative description of the accompanying phenomena, and multimodal monitoring elements of the three key behavior nodes. The multimodal monitoring elements include numerical sensor data features, device visual morphology features, and control instruction sequence features. The spatiotemporal relationship definition includes the order and duration of the behaviors of the behavior nodes, and the physical topological relationship of the node devices involved; the quantitative description of the accompanying phenomenon includes the abnormal fluctuation pattern of environmental parameters and the changes in the status of adjacent devices; S2, extract the multimodal monitoring elements of each behavior node in the OT domain; S3. Real-time monitoring of OT domain operation data flows, and identifying the behavior chain of the real-time OT domain operation data flows based on the multimodal monitoring elements of each behavior node and their spatiotemporal correlations; S4. When the behavior chain of the real-time OT domain operation data flow is detected and the degree of matching with any behavior chain in the experience database exceeds the preset threshold, a graded alarm is generated. The matching degree is calculated based on the time series characteristics, physical topology association characteristics, and multimodal characteristics using the following dynamic formula to calculate the matching value between the real-time behavior chain and the historical behavior chain: P = α × T + β × M + γ × C; Among them, T is the temporal similarity score, M is the topological similarity, C is the feature similarity, and α, β, and γ are dynamic adjustment coefficients.

2. The industrial OT domain security event monitoring method based on behavior chain analysis according to claim 1 is characterized in that: The multimodal monitoring elements include: Numerical sensor data features: Data features obtained by trend analysis and mutation point detection of numerical sensor data; Device visual morphological features: features of device appearance changes acquired through industrial cameras; Control instruction sequence characteristics: are the results obtained by analyzing the compliance of the PLC control instruction sequence.

3. The industrial OT domain security event monitoring method based on behavior chain analysis according to claim 1 is characterized in that: Also features: Behavior chain tracking mode: When it is detected that the behavior node in the behavior chain of the real-time OT domain operation data flow is the first key behavior node of a behavior chain in the experience library, full-chain monitoring of the behavior chain of the real-time OT domain operation data flow is initiated.

4. The industrial OT domain security event monitoring method based on behavior chain analysis according to claim 1 is characterized in that: Also includes: Dynamic update mechanism of experience database: allows the expert system to add, delete and modify the behavior chain nodes in the experience database; The version control module uses blockchain technology to store modification records.

5. The industrial OT domain security event monitoring method based on behavior chain analysis according to claim 1 is characterized in that: The graded alarms include: Primary warning stage: Generate preventive prompts when the leading node of the behavior chain is detected; Intermediate alarm stage: when key nodes are triggered continuously, emergency plan preloading is started; Emergency alarm stage: When the complete behavior chain conditions are met, the equipment interlock protection mechanism is triggered.

6. The industrial OT domain security event monitoring method based on behavior chain analysis according to claim 1 is characterized in that: It also has a false alarm suppression mechanism: it filters out false alarms by verifying the matching of accompanying phenomena.

7. An industrial OT domain security event monitoring system based on behavior chain analysis, characterized in that: include: Historical security incident behavior chain experience database: This database stores multiple behavior chains of security incidents that occurred in the OT domain. Each behavior chain contains at least three key behavior nodes and their spatiotemporal relationships, a quantitative description of accompanying phenomena, and multimodal monitoring elements of the three key behavior nodes. The multimodal monitoring elements include numerical sensor data features, device visual morphology features, and control instruction sequence features. The spatiotemporal relationship definition includes the order and duration of the behaviors of the behavior nodes, and the physical topological relationship of the node devices involved; the quantitative description of the accompanying phenomenon includes the abnormal fluctuation pattern of environmental parameters and the changes in the status of adjacent devices; Data acquisition module: used to extract multimodal monitoring elements of each behavior node in the OT domain. The multimodal monitoring elements include numerical sensor data features, device visual morphology features, and control instruction sequence features. Behavior chain construction module: used to monitor the OT domain operation data flow in real time and identify the behavior chain of the real-time OT domain operation data flow based on the multimodal monitoring elements of each behavior node and their spatiotemporal correlation; Real-time analysis module: When the behavior chain of the real-time OT domain operation data stream is detected and the degree of match with any behavior chain in the historical security event behavior chain experience library exceeds the preset threshold, a graded alarm is generated. The matching degree is calculated based on time series characteristics, physical topology association characteristics, and multimodal characteristics using the following dynamic formula: P = α × T + β × M + γ × C; Among them, T is the temporal similarity score, M is the topological similarity, C is the feature similarity, and α, β, and γ are dynamic adjustment coefficients.

8. An industrial control host, characterized in that: The industrial control host includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the method according to any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Event monitoring method and device based on Kubernetes cluster and computer program product

    CN118689732A

  • Universal online predictive maintenance system for oil and gas pipelines

    CN119919106A