Self-adaptive industrial equipment anti-attack method and electronic equipment

By detecting the interval time and data buffer size of industrial protocol communication, dynamically adjusting the request sending rate, solving the problem of anti-attack and normal business balance of industrial equipment in the prior art, and improving the security and stability of the industrial control network.

CN120165963APending Publication Date: 2025-06-17BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510474227.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively balance the relationship between industrial equipment's attack resistance and normal business, and it is difficult to adapt to the dynamically changing industrial network environment, resulting in insufficient response capabilities when facing new and complex attacks.

Method used

By continuously detecting the request-response and request-request interval time of industrial protocol communication, it is judged whether the request is abnormal, and whether the request is abnormal based on the occupancy amount of the received data buffer size. When an abnormal request is detected, a cache delayed sending strategy is adopted to dynamically adjust the request sending rate to avoid network congestion.

Benefits of technology

It effectively improves the anti-attack ability of industrial equipment, balances the relationship between attack defense and normal business, enhances the security and stability of the industrial control network, reduces the impact on normal business, and improves the system's response efficiency to abnormal attack behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165963A_ABST
    Figure CN120165963A_ABST
Patent Text Reader

Abstract

The invention provides a self-adaptive industrial equipment anti-attack method and electronic equipment. The adaptive industrial equipment anti-attack method comprises the following steps: continuously detecting a request-response interval time and a request-request interval time of industrial protocol communication, and judging whether a request is abnormal or not based on the request-response interval time and the request-request interval time; judging whether the request is abnormal or not based on the obtained occupied limit of the size of the data buffer area received by the industrial equipment application; and when the request is abnormal, the request is cached and sent in a delayed manner. Through the adaptive strategy, the relationship between attack defense and normal services is effectively balanced, misjudgment or excessive limitation of the normal services is avoided, and the purposes of enhancing the security and stability of the industrial control network, reducing the influence on the normal services and improving the response efficiency of the system to abnormal attack behaviors are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control network security, and in particular relates to an adaptive anti-attack method for industrial equipment and an electronic device. Background Art

[0002] In the industrial control network environment, industrial equipment responsible for controlling the production process generally has characteristics such as old systems, difficult upgrades, and low processing performance, and is easily vulnerable to denial-of-service attacks. At present, deploying anti-attack means such as firewalls at the network level can effectively raise the attack threshold. However, due to the limited computing power of industrial control devices, their ability to process normal request services is very limited. If there are excessive service requests, it may cause a denial-of-service attack. At this time, a service request anti-attack technology based on the industrial protocol layer is needed to reduce the consumption of device resources.

[0003] Existing denial-of-service attacks can generally be divided into two categories: network layer attacks and application layer attacks. Network layer attacks are represented by Flood attacks. Attackers send a large number of forged data packets (such as SYN Flood, ICMP Flood, etc.) to the target device, consuming the network bandwidth and computing resources of the device, and ultimately causing the device to be unable to process legitimate requests normally and paralyzing the entire system. For network layer attacks, current defense strategies mainly focus on the monitoring and management of network traffic, and effectively mitigate the threats brought by Flood attacks through means such as traffic limitation, traffic cleaning, and malicious packet filtering.

[0004] On the other hand, application layer attacks mainly target application protocols in industrial control systems and are represented by rapid request attacks (such as HTTP Flood, Slowloris, etc.). Attackers send legal but malicious protocol requests at high frequencies, causing the device to have an excessive processing load and ultimately being unable to respond to normal requests in a timely manner. Since the commonly used industrial protocols (such as Modbus, S7, DNP3, etc.) in industrial control systems are relatively simple in design and lack built-in security mechanisms, it is more difficult to defend against application layer attacks. The current main defense strategy is based on application protocol feature matching technology. The incoming data packets are analyzed through an industrial protocol application engine, the request characteristics of common protocols are matched, and abnormal traffic is identified and filtered. At the same time, the processing pressure on the device is also reduced by restricting the rate and frequency of requests, thereby preventing system resources from being maliciously consumed.

[0005] In the existing technical solutions, although the protocol feature matching technology has achieved certain effects in restricting the request rate at the protocol level, the application engine can only selectively discard packets when reducing the request rate. This method may cause significant jitter in normal services, affecting the stability and reliability of industrial systems. In addition, rate limiting requires accurate setting of thresholds, but setting them too large or too small may weaken the anti-attack effect and even have a negative impact on normal services. This is mainly because setting the thresholds requires considering the complex relationship between the actual industrial network environment and device characteristics, and accurately determining these thresholds is quite challenging in practical applications.

[0006] Therefore, there are the following two main drawbacks in the existing technical solutions: one is the inability to effectively balance the relationship between attack defense and normal services, which is prone to misjudgment or excessive restriction of normal services; the other is the difficulty in adapting to the dynamically changing industrial network environment and the lack of response ability in the face of new and complex attacks. Summary of the Invention

[0007] In view of the problems existing in the prior art, the present invention provides an adaptive anti-attack method for industrial devices and an electronic device.

[0008] In a first aspect, an embodiment of the present disclosure provides an adaptive anti-attack method for industrial devices, including:

[0009] Continuously detecting the request-response interval time and the request-request interval time of industrial protocol communication, and determining whether the request is abnormal based on the request-response interval time and the request-request interval time;

[0010] Determining whether the request is abnormal based on the occupied quota of the industrial device application receiving data buffer size obtained;

[0011] When the request is abnormal, cache and delay the sending of the request.

[0012] Optionally, the continuously detecting the request-response interval time of industrial protocol communication and determining whether the request is abnormal based on the request-response interval time includes:

[0013] If it is detected that the request-response interval time for consecutive n times is greater than the average interval time, it is determined that the request is too fast.

[0014] Optionally, the caching and delaying the sending of the request includes:

[0015] When the request-response interval time for consecutive n times is greater than the average interval time, the delay for delayed sending

[0016] where T s,avg is the average request-response interval time, T s,currentis the request-request current interval time, T s,current is the request-response current interval time.

[0017] Optionally, the interval time of the request-request for continuously detecting industrial protocol communication, and determining whether the request is abnormal based on the interval time of the request-request, is characterized by including:

[0018] If it is detected that the request-request interval time for n consecutive times is less than the average interval time, it is determined that the request is too fast.

[0019] Optionally, the caching and delaying the sending of the request includes:

[0020] When the request-request interval time for n consecutive times is less than the average interval time, the delay time for delaying the sending is the difference between the average request-request interval time and the request-request current interval time.

[0021] Optionally, in the determination of whether the request is abnormal based on the occupied quota of the industrial device application receiving data buffer size obtained, the share of each request is calculated based on the total number of entities in the network, the weight coefficient assigned to the entity, and the receiving data buffer size.

[0022] Optionally, the determination of whether the request is abnormal based on the occupied quota of the industrial device application receiving data buffer size obtained includes, when the occupied quota is insufficient, caching and delaying the sending of the request.

[0023] Optionally, caching and delaying the sending of the request includes: caching the request in the corresponding delay queue and sending it by a timer task.

[0024] Optionally, the caching of the request in the corresponding delay queue and sending it by a timer task includes:

[0025] If the delay time for delaying the sending is not equal to 0, insert the request into the cache queue and start the timer task;

[0026] If the length of the cache queue is not 0, insert the request at the end of the cache queue and immediately send the first request in the cache queue;

[0027] If the length of the cache queue is greater than n, discard the new request;

[0028] If the length of the cache queue is 0, immediately send the new request.

[0029] In a second aspect, an embodiment of the present disclosure further provides an electronic device, and the electronic device includes:

[0030] At least one processor; and,

[0031] A memory communicatively connected to the at least one processor; wherein,

[0032] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the adaptive industrial device anti-attack method according to any one of the first aspect.

[0033] The adaptive industrial device anti-attack method and electronic device provided by the present invention. In the adaptive industrial device anti-attack method, when the processing delay of the industrial device is too large, the request sending rate of each request-end entity can be dynamically adjusted to avoid network congestion. When a request attack is detected, the attack requests are intelligently filtered, further improving its anti-attack ability. Through this adaptive strategy, the relationship between attack defense and normal services is effectively balanced, avoiding misjudgment or excessive restriction of normal services, achieving the purpose of enhancing the security and stability of the industrial control network, reducing the impact on normal services, and at the same time improving the response efficiency of the system to abnormal attack behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] By describing the exemplary embodiments of the present disclosure in more detail in conjunction with the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent. Among them, in the exemplary embodiments of the present disclosure, the same reference numerals generally represent the same components.

[0035] Figure 1 It is a flowchart of an adaptive industrial device anti-attack method provided by an embodiment of the present disclosure;

[0036] Figure 2 It is a schematic block diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] The embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings.

[0038] It should be clear that the following illustrates the implementation manners of the present disclosure through specific specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without making creative efforts belong to the scope of protection of the present disclosure.

[0039] Note that the following description pertains to various aspects of embodiments within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of the aspects set forth herein can be used to implement a device and / or practice a method. Additionally, this device can be implemented and this method can be practiced using other structures and / or functionality in addition to one or more of the aspects set forth herein.

[0040] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure schematically. The diagrams only show the components related to the present disclosure and are not drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0041] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the aspects can be practiced without these specific details.

[0042] For ease of understanding, as Figure 1 shown, this embodiment discloses an adaptive anti-attack method for industrial equipment, including:

[0043] Continuously detect the request-response interval time and the request-request interval time of industrial protocol communication, and determine whether the request is abnormal based on the request-response interval time and the request-request interval time;

[0044] Determine whether the request is abnormal based on the occupancy rate of the size of the received data buffer of the industrial equipment application obtained;

[0045] When the request is abnormal, cache the request and send it after a delay.

[0046] Optionally, the continuously detecting the request-response interval time of industrial protocol communication and determining whether the request is abnormal based on the request-response interval time includes:

[0047] If it is detected that the request-response interval time for n consecutive times is greater than the average interval time, it is determined that the request is too fast.

[0048] Optionally, the caching and delaying the sending of the request includes:

[0049] When the request-response interval time for n consecutive times is greater than the average interval time, the delay for delayed sending

[0050] Among them, T s,avg is the average request - response interval time, and T s,current is the current request - request interval time, and T s,current is the current request - response interval time.

[0051] Optionally, for the interval time of request - request for continuously detecting industrial protocol communication, and determining whether a request is abnormal based on the request - request interval time, it is characterized by including:

[0052] If it is detected that the request - request interval times for consecutive n times are all less than the average interval time, it is determined that the request is too fast.

[0053] Optionally, the caching and delaying the sending of requests includes:

[0054] When the request - request interval times for consecutive n times are all less than the average interval time, the delaying time for delaying the sending is the difference between the average request - request interval time and the current request - request interval time.

[0055] Optionally, in the determination of whether a request is abnormal based on the occupied quota of the receiving data buffer size of the industrial device application obtained, the share of each request is calculated based on the total number of entities in the network, the weight coefficient assigned to the entity, and the receiving data buffer size.

[0056] Optionally, the determination of whether a request is abnormal based on the occupied quota of the receiving data buffer size of the industrial device application obtained includes, when the occupied quota is insufficient, caching and delaying the sending of the request.

[0057] Optionally, caching and delaying the sending of requests includes: caching the request in the corresponding delay queue and sending it by a timer task.

[0058] Optionally, the caching of the request in the corresponding delay queue and sending it by a timer task includes:

[0059] If the delaying time for delaying the sending is not equal to 0, insert the request into the cache queue and start the timer task;

[0060] If the length of the cache queue is not 0, insert the request at the end of the cache queue and immediately send the first request in the cache queue;

[0061] If the length of the cache queue is greater than n, discard the new request;

[0062] If the length of the cache queue is 0, immediately send the new request.

[0063] The adaptive industrial equipment anti-attack method in this embodiment mainly uses two mechanisms to jointly feedback and control the rate of application protocol requests, specifically as follows:

[0064] The first mechanism is to determine whether the requests are too fast by continuously detecting the fluctuations in the average interval time of "request-response" and the average interval time of "request-request" in industrial protocol communication. Consider the following two cases:

[0065] 1) If it is detected that the "request-response" interval time for consecutive n times is greater than the average interval time, it indicates that the response speed of the industrial equipment application is getting slower and the request sending rate needs to be restricted;

[0066] 2) If it is detected that the "request-request" interval time for consecutive n times is less than the average interval time, it indicates that the requests sent by the request-side entity are getting faster and the request sending rate needs to be restricted;

[0067] The second mechanism characterizes the maximum request processing capacity acceptable to the industrial equipment application according to the size Quota of the data reception buffer of the industrial equipment application. According to Quota and the number of request-side entities in the network, it continuously and dynamically allocates the "request" sending quota Budget for all request sides in the network. Whenever a request is sent, the sending quota needs to be consumed. Whenever a device response is received, the corresponding quota is restored. If the quota is insufficient, the request sending rate will be inhibited. Budget i is the share of entity i, w i is the weight coefficient assigned to entity i, Count is the total number of entities in the network, and the Budget calculation formula is as follows:

[0068]

[0069] The implementation method of inhibiting the sending rate is to cache the requests and send them after a delay. The requests are cached in the corresponding delay queue and sent by the timer task. There are three cases of sending delays:

[0070] 1) The requests are too fast, the average "request-request" interval time is T c,avg , and the current "request-request" interval time is T c,current . The delay time T c,current triggered by judging n consecutive "request-request" interval times T wait is calculated as follows:

[0071] T wait = T c,avg - T c,current

[0072] 2) The response becomes slower, the average "request-response" interval time is T s,avgThe current interval time of "request - request" is T s,current and the delay time T triggered by n consecutive "request - response" interval times T c,current is judged. The calculation formula is as follows: wait Calculation formula is as follows:

[0073]

[0074] The delay time T triggered by the judgment of insufficient sending quota wait The calculation formula is as follows:

[0075] T wait = T c,avg - T c,current

[0076] The specific implementation process is described as follows:

[0077] Step S01: Obtain the IP address of the industrial device and the type of industrial protocol. The IP address of the industrial device, the type of industrial protocol, and the priority weight w of the IP address of the request - side entity are configured for this solution by the user

[0078] i .

[0079] Step S02: Obtain the buffer size of the industrial protocol. By packet sampling, parse and obtain the value of the "scale window size" field of the industrial device application's tcp connection and set it as the global Quota value of the device application

[0080]

[0081] Step S03: Read the service traffic packets in a loop. Read n service traffic packets in a loop (n can be specified as 5, 10, 20, etc. The smaller the value, the more attention is paid to the short time period, and the larger the value, the more attention is paid to the long time period), establish the initial average time intervals T of "request - response"

[0082] and "request - request", and transfer to S04 or S08 according to the received service type. T s,avg and T c,avg adopt the exponential moving average calculation formula as follows:

[0083]

[0084]

[0085]

[0086] T avg is the average interval time, T avg,old is the previous average interval time, and T current is the current "request - response" or "request - request" interval time

[0085] ​​Step S04: Receive the response message, calculate the current "request-response" interval time,

[0086] Calculate T based on the recorded last request calculation and response time s,current The formula is as follows:

[0087] T s,current = response time - request time.

[0088] Step S05: Compare the average "request-response" interval time, set the waiting time for the next request,

[0089] Set a counter variable c to record the number of times the average interval time is continuously greater than the current interval time. Initially, c = 0. For each new time interval: If T s,current > T s,avg , then c = c + 1; otherwise c = 0. When c < n, set the delay waiting time T wait = 0; when c >= n (the value of n in S03), calculate T wait , go to S06. The process calculation formula is expressed as follows:

[0090]

[0091] S(t,n) is 1 to trigger the update delay time, and the delay time T wait The calculation formula is as follows:

[0092]

[0093] Step S06: Restore the sending quota,

[0094] Whenever the response of a request is received, it means that the response end has completed the processing of the request, and the sending quota consumed by the previous request end can be restored. The consumed quota is represented by cost all The consumption of the previous request is represented by cost last The calculation formula is as follows:

[0095] cost all = cost all - cost last .

[0096] Step S07: Update the average "request-response" interval time

[0097] Update and calculate T s,avg The calculation formula is as follows:

[0098]

[0099] Step S08: Receive the request message, determine whether to wait,

[0100] If T wait is not 0, it means waiting is required, go to step S13; otherwise go to step S09.

[0101] Step S09: Receive a request message, calculate the current "request - request" interval time,

[0102] Based on the recorded last request time and this request time, calculate T c,current The formula is as follows:

[0103] T c,current = this request time - last request time.

[0104] Step S10: The "request - request" interval time is less than the "request - request" average interval time for n consecutive times.

[0105] Set a counter variable c to record the number of times the average interval time is continuously greater than the current interval time. Initially, c = 0. For each new time interval: If T c,current < T c,avg , then c = c + 1; otherwise c = 0. When c >= n (the value of n in S03); when c < n, set T wait = 0. The calculation process is expressed by the formula as follows:

[0106]

[0107] S(t, n) triggers a delayed transmission, and the delay time T wait is the current "request - request" average interval time:

[0108] T wait = T c,avge - T c,current .

[0109] Step S11: Update the "request - request" average interval time,

[0110] Update and calculate T c,avg , and the calculation formula is as follows:

[0111]

[0112] Step S12: Determine whether the transmission quota is met.

[0113] First, calculate the quota of the current request - side entity. It is necessary to obtain all request - side entities and weights in the current environment. Quota is the global share, w i is the weight coefficient assigned to the current entity, and Count is the total number of entities in the network. Calculate the current quota Budget i :

[0114]

[0115] Secondly, calculate whether the current remaining quota is sufficient for sending. The quota consumed by the current request is cost current The calculation is as follows:

[0116] rest = Budget i - cost current - cost all

[0117] If rest ≥ 0, then cost all = cost all + cost current , T wait = 0

[0118] Otherwise, calculate the delay time. The delay time T wait The calculation formula:

[0119] T wait = T c,avge - T c,current .

[0120] Step S13: Limit the speed of sending requests

[0121] If T wait ≠ 0, insert the request into the cache queue and start the timer task

[0122] If the length of the cache queue is not 0, insert the request at the end of the cache queue and immediately send the first request in the cache queue

[0123] If the length of the cache queue is greater than n, discard the new request

[0124] If the length of the cache queue is 0, immediately send the new request

[0125] Step S14: The timer task sends the cached requests

[0126] The timer task sends the requests in the cache queue in chronological order. If the queue is empty, close the timer

[0127] Due to its adaptability and flexibility, the solution disclosed in this embodiment is applicable to industrial control systems of various scales and types. Its generality enables rapid deployment in different industrial environments and network configurations, saving the time and cost of customized development; its flexibility allows enterprises to quickly deploy and promote, thus seizing the market opportunity promptly. Since this solution can adaptively identify normal business traffic and abnormal traffic, it significantly reduces the false alarm rate and the probability of false flow limiting events. For enterprises, there is no need to increase costs for frequently adjusting network settings and handling false alarms.

[0128] The electronic device disclosed in this embodiment includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and these computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0129] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the electronic device executes all or part of the steps of the adaptive industrial device anti-attack method in the foregoing embodiments of the present disclosure.

[0130] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included in the protection scope of the present disclosure.

[0131] As Figure 2 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiments of the present disclosure. Figure 2 The shown electronic device is only an example and should not bring any limitations to the functions and usage scope of the embodiments of the present disclosure.

[0132] As Figure 2As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage device into the random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.

[0133] Generally, the following devices can be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device, etc.; an output device including, for example, a display screen, etc.; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device can allow the electronic device to communicate with other devices (such as edge computing devices) wirelessly or wiredly to exchange data. Although Figure 2 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices can be implemented or had.

[0134] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processing device, all or part of the steps of the adaptive industrial device anti-attack method of the embodiment of the present disclosure are executed.

[0135] For a detailed description of this embodiment, reference can be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.

[0136] The computer-readable storage medium disclosed in this embodiment stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the adaptive industrial device anti-attack method of the foregoing embodiments of the present disclosure are executed.

[0137] The above computer-readable storage medium includes but is not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or external hard drives), media with built-in rewritable non-volatile memories (such as memory cards), and media with built-in ROMs (such as ROM cartridges).

[0138] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, which will not be repeated herein.

[0139] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purposes of illustration and facilitating understanding, and not for limitation. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0140] In the present disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0141] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a separate listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). In addition, the term "exemplary" does not mean that the described examples are preferred or better than other examples.

[0142] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.

[0143] Various changes, substitutions, and alterations to the technology described herein may be made without departing from the teachings defined by the appended claims. Additionally, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Processes, machines, manufactures, compositions of events, means, methods, or acts that are currently existing or later to be developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0144] The foregoing description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0145] The foregoing description has been presented for purposes of illustration and description. Additionally, this description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although numerous example aspects and embodiments have been discussed above, those skilled in the art will recognize some variations, modifications, alterations, additions, and subcombinations thereof.

Claims

1. An adaptive industrial equipment anti-attack method, characterized in that: include: Continuously detect the request-response interval and request-request interval of industrial protocol communication, and determine whether the request is abnormal based on the request-response interval and request-request interval; Determine whether the request is abnormal based on the occupied amount of the industrial equipment application receiving data buffer size; When a request is abnormal, the request is cached and sent with a delay.

2. The adaptive industrial equipment anti-attack method according to claim 1, characterized in that: The continuously detecting the request-response interval of the industrial protocol communication and judging whether the request is abnormal based on the request-response interval includes: If it is detected that the request-response interval for n consecutive times is greater than the average interval, it is judged that the request is too fast.

3. The adaptive industrial equipment anti-attack method according to claim 2, characterized in that: The step of caching and delaying the request includes: When the request-response intervals for n consecutive times are all greater than the average interval, Among them, T s,avg is the average request-response interval, T s,current is the request-to-request current interval, T s,current Is the current request-response interval.

4. The adaptive industrial equipment anti-attack method according to claim 1, characterized in that: The method of continuously detecting the request-request interval of the industrial protocol communication and judging whether the request is abnormal based on the request-request interval is characterized by comprising: If it is detected that the request-request interval for n consecutive times is less than the average interval, it is judged that the request is too fast.

5. The adaptive industrial equipment anti-attack method according to claim 4, characterized in that: The step of caching and delaying the request includes: When the request-to-request intervals for n consecutive times are all less than the average interval, the delay time for delayed sending is the difference between the average request-to-request interval and the current request-to-request interval.

6. The adaptive industrial equipment anti-attack method according to claim 1, characterized in that: The request is judged to be abnormal based on the acquired occupied amount of the industrial equipment application receiving data buffer size, and the share of each request is calculated based on the total number of entities in the network, the weight coefficient assigned to the entity and the receiving data buffer size.

7. The adaptive industrial equipment anti-attack method according to claim 1, characterized in that: The determining whether the request is abnormal based on the acquired occupied quota of the size of the industrial equipment application receiving data buffer includes, when the occupied quota is insufficient, caching and delaying the sending of the request.

8. The adaptive industrial equipment anti-attack method according to claim 1, characterized in that: The request is cached and sent with delay, including: the request is cached in a corresponding delay queue and sent by a timer task.

9. The adaptive industrial equipment anti-attack method according to claim 8, characterized in that: The request is cached in a corresponding delay queue and sent by a timer task, including: If the delay time of the delayed transmission is not equal to 0, the request is inserted into the cache queue and the timer task is started; If the cache queue length is not 0, insert the request to the end of the cache queue and send the first request in the cache queue immediately; If the cache queue length is greater than n, the new request is discarded; If the buffer queue length is 0, send the new request immediately.

10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the adaptive industrial equipment anti-attack method described in any one of claims 1-9.