Distributed security estimation method and device, equipment and storage medium
By determining the differential data in a distributed multi-sensor system and actively reacquiring the prediction data of neighboring nodes, the false alarm problem of traditional systems when dealing with wireless channel attacks is solved, and the accuracy of system state estimation is improved.
Patent Information
- Application Number
- CN202510592961.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-06-17
AI Technical Summary
When traditional distributed multi-sensor systems handle wireless channel attacks, they are prone to false alarms of normal data, resulting in significant differences in the performance losses of the security state estimator and system state estimation.
By determining the difference data between detection nodes and actively reacquiring the prediction data of neighboring nodes according to preset conditions, a new detection mechanism is used to confirm the credibility of the data, thereby improving the accuracy of security state estimation.
It effectively reduces the false alarm of data noise caused by normal interference during information transmission, reduces the number of times the estimated data of abandoned neighbor nodes, and improves the accuracy of the entire system state estimation.
Smart Images

Figure CN120165981A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computers, and particularly to a distributed security estimation method, device, equipment and medium. Background Art
[0002] In the field of industrial control, industrial control systems are widely used in key infrastructure fields such as intelligent manufacturing, power grids, drinking water treatment, temperature regulation, and oil and gas extraction. Currently, in order to accurately monitor the real-time operation of industrial control systems, the systems are equipped with multiple measurement sensors for real-time monitoring of the system status, and the measured data collected is processed through distributed data transmission and fusion rules.
[0003] For the distributed implementation method, wireless transmission technology is usually used to realize data communication between each detection node. However, there are cases of wireless network attacks in wireless transmission technology. To solve this problem, the traditional implementation method adopts a scheme of a security state estimator with an attack detector. Its basic idea is to compare the residual formed by the sensor's own estimation and the information transmitted by neighbors with a given threshold (attack detector). If the residual is greater than the threshold, the neighbor information is discarded; if the residual is less than or equal to the threshold, the neighbor information is retained. Then, the detection result is brought into the state estimator update equation to realize the real-time security estimation of the state of the industrial control system.
[0004] However, the traditional implementation method has false alarms for normal data, directly discarding suspicious data, resulting in excessive performance loss of the security state estimator, and obvious differences in the estimation of the system state by each node in the distributed implementation, making it impossible to accurately determine the system state.
[0005] Therefore, there is an urgent need for a solution to solve the above problems. Summary of the Invention
[0006] In view of this, the present invention provides a distributed security estimation method. One or more embodiments of the present invention also relate to a distributed security estimation device, a computing device, and a computer-readable storage medium to solve the technical defects existing in the prior art.
[0007] In the first aspect of the present invention, a distributed security estimation method is provided for any detection node in a distributed multi-sensor system, including: Determine the first detection data of the detection node and the second detection data of the adjacent node, and determine the first difference data according to the first detection data and the second detection data; If the first difference data meets the first preset condition, obtain the third detection data of the adjacent node through a predetermined method, and determine the second difference data according to the first detection data and the third detection data; If the second difference data meets the second preset condition, determine the security estimation data of the system according to the first detection data and the third detection data.
[0008] In some embodiments of the present invention, the method further includes: If the first difference data does not meet the first preset condition, determine the security estimation data of the system through the first detection data and the second detection data.
[0009] In some embodiments of the present invention, the method further includes: Obtain a plurality of fourth detection data of adjacent nodes through a predetermined method, where the fourth detection data is the detection data of the adjacent nodes within a predetermined time before the third detection data; Determine the security estimation data of the system according to the first detection data, the third detection data, and the plurality of fourth detection data.
[0010] In some embodiments of the present invention, the method further includes: If the number of adjacent nodes is greater than a predetermined value, obtain the second detection data of each adjacent node, and determine the first difference data corresponding to each adjacent node according to the second detection data of each adjacent node and the first detection data; If the first difference data of the adjacent node does not meet the first preset condition, then classify the adjacent node into the first classification set, If the first difference data of the adjacent node meets the first preset condition, classify the adjacent node into the second classification set; Construct a second detection data set based on the second detection data of all adjacent nodes in the first classification set; Obtain the third detection data of all adjacent nodes in the second classification set through a predetermined method to construct a third detection data set; Determine the security estimation data of the system based on the first detection data, the second detection data set, and the third detection data set.
[0011] In some embodiments of the present invention, obtaining the third detection data of all adjacent nodes in the second classification set through a predetermined method to construct a third detection data set includes: Obtain the third detection data of each adjacent node in the second classification set through a predetermined method; Determine the second difference data of the adjacent nodes in the second classification set according to the third detection data and the first detection data; If the second difference data meets the second preset condition, add the third detection data of the adjacent nodes in the second classification set to the third detection data set.
[0012] In some embodiments of the present invention, determining the first detection data of the detection node includes: Determine the historical safety estimation data of the detection node and the system matrix of the system; Determine the state prediction data of the system based on the historical safety estimation data and the system matrix data, and use the state prediction data as the first detection data.
[0013] In some embodiments of the present invention, determining the first detection data of the detection node further includes: Determine the measurement data and the measurement matrix of the detection node sensor; Determine the measurement prediction data based on the state prediction data and the measurement matrix; Determine the difference between the measurement data and the measurement prediction data; Determine the safety estimation data based on the difference and the state prediction data.
[0014] A second aspect of the present invention further provides a distributed safety estimation device for any detection node in a distributed multi-sensor system, including: A first data confirmation module, configured to determine the first detection data of the detection node and the second detection data of the adjacent node, and determine the first difference data according to the first detection data and the second detection data; A second data confirmation module, configured to, if the first difference data meets a first preset condition, obtain the third detection data of the adjacent node in a predetermined manner, and determine the second difference data according to the first detection data and the third detection data; A safety estimation module, configured to, if the second difference data meets a second preset condition, determine the safety estimation data of the system according to the first detection data and the third detection data.
[0015] A third aspect of the present invention further provides a computing device, including: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned distributed safety estimation method are implemented.
[0016] A fourth aspect of the present invention further provides a computer-readable storage medium, which stores computer-executable instructions. When the instructions are executed by a processor, the steps of the above-mentioned distributed safety estimation method are implemented.
[0017] The present invention has the following beneficial effects: when it is detected that the predicted data of an adjacent node is quite different from the predicted data of the current detection node, a safer method is adopted to actively re-acquire the predicted data of the adjacent node, and a new detection mechanism is used for the re-acquired predicted data to confirm whether it is attacked data. On the one hand, it can effectively reduce the false alarms of data noise caused by normal interference in the information transmission process. On the other hand, it can effectively reduce the number of times of estimated data of abandoned adjacent nodes, effectively reduce the performance loss of the security state estimator, and thus improve the accuracy of the overall system state estimation. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is a schematic flowchart of a distributed security estimation method provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a distributed multi-sensor system provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of the communication topology relationship between multiple detection nodes provided by an embodiment of the present invention; Figure 4 It is a comparison diagram of the real and estimated temperature heat maps of each region in a certain application scenario provided by an embodiment of the present invention; Figure 5 It is a curve graph showing the change of the temperature estimation error of an industrial control sensor corresponding to multiple detection nodes over time provided by an embodiment of the present invention; Figure 6 It is a curve graph showing the change of the average temperature estimation error of an industrial control sensor corresponding to multiple detection nodes over time provided by an embodiment of the present invention; Figure 7 It is a schematic structural diagram of a distributed security estimation device provided by an embodiment of the present invention; Figure 8 It is a schematic structural diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] Many specific details are set forth in the following description in order to provide a thorough understanding of the present invention. However, the present invention can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0020] The terms used in one or more embodiments of the present invention are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of the present invention. The singular forms "a" and "the" used in one or more embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of the present invention refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0021] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of the present invention to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of the present invention, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0022] The present invention aims to solve the problem of data processing against channel attacks in traditional distributed multi-sensor systems. In traditional implementations, in order to accurately monitor the real-time operation of an industrial control system, the system is equipped with multiple measurement sensors for real-time monitoring of various system states and communicating wirelessly at the detection nodes where each measurement sensor is located. However, the communication transmission process is vulnerable to wireless channel attacks, resulting in abnormal data transmitted between each detection node, making it impossible to accurately obtain the measurement data detected by all detection nodes, and ultimately affecting the real-time estimation of the system state.
[0023] As Figure 1 shown, to solve the above problems, a first aspect of the present invention proposes a distributed security estimation method for any detection node in a distributed multi-sensor system, including: Step S1, determining first detection data of the detection node and second detection data of adjacent nodes, and determining first difference data based on the first detection data and the second detection data; Step S2, if the first difference data meets a first preset condition, obtaining third detection data of the adjacent node by a predetermined method and determining second difference data based on the first detection data and the third detection data; Step S3, if the second difference data meets a second preset condition, determining security estimation data of the system based on the first detection data and the third detection data.
[0024] In an embodiment of the present invention, the detection node is a computer device with wireless communication capabilities and is equipped with corresponding measurement sensors. One or more measurement sensors are deployed on the detection node, and the type of measurement sensor can be set based on the requirements of the monitoring object. For example, it can be a temperature sensor, a humidity sensor, or other sensors used to determine the physical state or working state of the monitoring object. The detection node and adjacent nodes use wireless communication to transfer data.
[0025] The first detection data is the predicted data of the state of the industrial control system at the next moment by the corresponding detection node based on the prior safety estimation data on its own node.
[0026] The second detection data is the predicted data of the state of the industrial control system at the next moment by the corresponding adjacent node based on the prior safety estimation data on its own node.
[0027] The third detection data is the predicted data of the state of the industrial control system at the next moment re - obtained by the detection node through a secure information transmission method (for example, an encrypted method) from the adjacent detection node.
[0028] The safety estimation data refers to the data used to evaluate the current state of the industrial control system obtained by each detection node in the distributed multi - sensor system according to its own sensor data through a predetermined algorithm or the method proposed in the present invention. It is the data that excludes the noise error of the actual sensor and the interference caused by attacks during the communication process, and is the safety estimation data representing a certain measurement type. For example, if the sensor measurement type is a temperature sensor, the corresponding safety estimation data is the reliable data representing the temperature (as mentioned above, through the corresponding algorithm, the reliable data that compensates for or eliminates the noise error of the sensor itself, communication errors, etc.). The system state may be one or more. For example, it can be the temperature state of each area of the current industrial control system, or the humidity state corresponding to each area, or the power consumption state of the devices in each area of the industrial control system, etc., which is determined by the characteristics of the specific monitoring object.
[0029] In step S1, first, confirm the predicted data of the state at the next moment on the detection node based on the prior safety estimation data. It should be noted that the so - called prior safety estimation data refers to the prior safety estimation data determined according to the method provided by the present invention. In the embodiment of the present invention, the prior safety estimation data is the previous safety estimation data.
[0030] Further, receive the safety estimation data sent by the adjacent node communicating with the detection node through wireless communication. That is, this safety estimation data is the safety estimation data previously generated by the adjacent node using the same method or other methods. Specifically, suppose there is a detection node in a distributed multi - sensor system and a detection node to detect the node is used as the execution node where the method provided by the present invention is located. Then, the detection node is the corresponding adjacent node. The security estimation data of the detection node is represented by . The security estimation data of the detection node received by the detection node is represented by . In the formula, is the corresponding moment, represents the moment previous to the moment represents that the data may be attacked. In particular, can also be used to represent the current moment, represents the next moment, which is only used to mark the front and back relationship of the time series data of the same type.
[0031] Furthermore, after determining and , calculate the difference between the two to obtain the corresponding first difference data , and determine whether the preset condition is satisfied, that is: ; Among them, represents the valid marker value of the second detection data, that is, it represents whether the difference between the predicted data (note, not the security estimation data) of the industrial control system at the moment by the detection node and the detection node according to the prior security estimation data in their respective nodes meets the preset conditions. The result is of binary type, that is, either 0 or 1. is a preset detection threshold, represents the two-norm of the vector. When the first difference data , is 0, indicating that the first difference data meets the first preset condition, that is, the predicted data gap between the detection node and the detection node is relatively large. The generation of this gap may be due to the change in the environment of the spatial positions corresponding to the two, resulting in a large difference in the data collected by their respective sensors, and further resulting in a large difference in the predicted data of the industrial control system at the moment . Of course, it may also be due to the existence of channel attacks in wireless communication, resulting in interference in the data during the transmission stage, resulting in a large gap. If is 1, it means that the predicted data gap between the detection node and the detection node is within the allowable range, and the wirelessly transmitted data is trustworthy.
[0032] In step S2, if the value is 0, it indicates that the first difference data meets the first preset condition. Then the detection node actively sends a corresponding data acquisition request to the detection node in an encrypted manner, requesting the detection node to retransmit the corresponding prediction data in the same encrypted manner , and are the same data on the detection node , but are distinguished due to differences in the transmission method.
[0033] Furthermore, after obtaining the prediction data retransmitted by the detection node , according to the prediction data of the detection node , calculate the corresponding second difference data , and further determine whether the second difference data meets the second preset condition, that is: .
[0034] Among them, is the valid flag of the second difference data, indicating that it is determined that this data may have been tampered with by an external network attack, indicating that it is considered to be trustworthy data. The parameter is a pre-given retransmission detection threshold, and satisfies . If is 1, it is considered that the second difference data meets the second preset condition, and the retransmitted prediction data is trustworthy, otherwise it is untrustworthy.
[0035] In step S3, if is 1, that is, the second difference data meets the second predetermined condition, then according to the retransmitted prediction data and the prediction data of the detection node determine the corresponding security estimation data on the detection node , and the calculation method is: ; is the security estimation data of the industrial control system for the detection node .
[0036] Furthermore, in some embodiments of the present invention, when determining the corresponding security estimation data, it is necessary to combine the sampling data of the corresponding sensors on the detection node and the prediction data of the sensors.
[0037] Specifically, first determine the measurement value of the sensor of the corresponding type. The measurement value of the sensor is .
[0038] Furthermore, combine the measurement value of the sensor at the +1 moment and the predicted data of the measurement value at the moment to determine the safety estimation data of the detection node . The corresponding calculation method of the safety estimation data is: .
[0039] Among them, is the corresponding gain matrix. Effectively combine the actual sensor data to more accurately obtain the safety estimation data of the corresponding detection node at .
[0040] In some embodiments of the present invention, the method further includes: If the first difference data does not meet the first preset condition, determine the safety estimation data of the system through the first detection data and the second detection data.
[0041] In this embodiment, if the value of the valid flag corresponding to the first difference data is 1, that is, the first difference data does not meet the first preset condition. It means that the difference between the predicted data corresponding to the detection node and the detection node is within the allowable range, and the wirelessly transmitted data is credible. The second detection data can be directly used to determine the safety estimation data of the detection node at the moment . Specifically, the calculation method is: .
[0042] As before, in the formula, is the first detection data, is the second detection data, is the valid flag of the first difference data.
[0043] Furthermore, in some embodiments of the present invention, combine the sampling data of the corresponding sensor on the detection node and the predicted data of the sensor. The corresponding calculation method is: .
[0044] In the formula, is the first detection data, is the second detection data, is a valid marker for the first difference data, is the detection node at the measured value at time +1, is the detection node at the predicted data of the measured value at time +1, the corresponding gain matrix.
[0045] In some embodiments of the present invention, the method further includes: Obtaining a plurality of fourth detection data of adjacent nodes in a predetermined manner, where the fourth detection data is the detection data of the adjacent nodes within a predetermined time before the third detection data; Determining the security estimation data of the system according to the first detection data, the third detection data, and the plurality of fourth detection data.
[0046] In this embodiment, when the first difference data meets the preset conditions, if only the predicted data of the adjacent nodes at time +1 is re-obtained, there may be a certain coincidence. For this reason, in this embodiment, when obtaining the predicted data of the detection node at time +1 through an encryption method, the predicted data of the detection node at at multiple times before time +1 is simultaneously obtained to construct a set , representing the set of predicted data of the detection node at time that is determined to transmit suspicious information (including the predicted data at time k+1 ), that is: ). .
[0047] Furthermore, determine the predicted data at the same previous time on the detection node , that is: , where ; m represents the number of predicted data before time k+1.
[0048] Furthermore, the calculation method for determining the security estimation data based on the first detection data, the third detection data, and the fourth detection data is: ; In the formula, represents the first detection data at the same time as the fourth detection data on the detection node , that is, the previous predicted data of the state of the industrial control system on the detection node .
[0049] Further, if the sampled data of the sensors corresponding to the detection nodes is combined with the predicted data of the sensors, the corresponding calculation method is as follows: 。
[0050] In some embodiments of the present invention, the method further includes: If the number of adjacent nodes is greater than a predetermined value, obtain the second detection data of each adjacent node, and determine the first difference data corresponding to each adjacent node according to the second detection data and the first detection data of each adjacent node; If the first difference data of the adjacent nodes does not meet the first preset condition, divide the adjacent nodes into the first classification set, If the first difference data of the adjacent nodes meets the first preset condition, divide the adjacent nodes into the second classification set; Construct a second detection data set based on the second detection data of all adjacent nodes in the first classification set; Obtain the third detection data of all adjacent nodes in the second classification set through a predetermined method to construct a third detection data set; Determine the security estimation data of the system based on the first detection data, the second detection data set, and the third detection data set.
[0051] In this embodiment, if the number of detection nodes in the distributed multi-sensor system exceeds 2, that is, there are multiple detection nodes. The communication relationship between the detection nodes can be described by an undirected graph in graph theory Describe. Then there will be different first difference data between different detection nodes. It is possible that the first difference data between some nodes meets the first preset condition, while the first difference data between some nodes does not meet the first preset condition.
[0052] Therefore, in this embodiment, the adjacent nodes corresponding to the situation where the first difference data is greater than the preset threshold , and there may be a situation of being attacked are divided into the second classification set. On the contrary, the adjacent nodes that do not meet the first preset condition, that is, the first data difference data is less than , and the adjacent nodes that can be considered data-safe are divided into the first classification set.
[0053] Further, construct a second detection data set with the second detection data of all adjacent nodes in the first classification set.
[0054] Further, for the adjacent nodes in the second classification set, actively re-obtain their predicted data at the corresponding moment through an encrypted method , and calculate the corresponding second difference data therewith. Then determine whether the second difference data meets the second preset condition, that is, Whether the value is 1. If it is 1, the predicted data of the adjacent node (the third detection data) is considered credible. If the value is 0, it is considered that the predicted data of the adjacent node (the third detection data) is not credible and can be directly discarded. Finally, the third detection data set is constructed with all credible third detection data.
[0055] Then, the security estimation data of the detection node is determined based on the first detection data, the second detection data set, and the third detection data set. The specific calculation method is as follows: ; In the formula, is the corresponding scaling factor, which is a pre-given constant and takes values in the interval where represents the number of neighbors of the sensor node with the most neighbors; is the sum of the differences between each second detection data in the second detection data set and the first detection data ; is the sum of the differences between each third detection data in the third detection data set and the first detection data .
[0056] Further, in some embodiments of the present invention, in combination with the sampling data of the corresponding sensor on the detection node and the predicted data of the sensor, the corresponding calculation method is: ; Further, in some embodiments of the present invention, if considering the uncertainty existing when actively encrypting to re-obtain the corresponding predicted data, the security estimation data is determined by obtaining multiple prior third detection data, that is, the corresponding fourth detection data, then the corresponding calculation method is: .
[0057] In the formula, represents the set of adjacent nodes where the detection node is determined to transmit suspicious information at time. is the difference between the corresponding third detection data and the first detection data whether it satisfies the detection threshold representation value, taking values of 0 or 1.
[0058] In some embodiments of the present invention, the third detection data set is constructed by obtaining the third detection data of all adjacent nodes in the second classification set in a predetermined manner, including: Obtain the third detection data of each adjacent node in the second classification set in a predetermined manner; Determine the second difference data of the adjacent nodes in the second classification set according to the third detection data and the first detection data; If the second difference data meets the second preset condition, add the third detection data of the adjacent nodes in the second classification set to the third detection data set.
[0059] In this embodiment, for the adjacent nodes in the second classification set, actively re-obtain their predicted data at the corresponding moment in an encrypted manner , and calculate the corresponding second difference data therefrom. Then determine whether the second difference data meets the second preset condition, that is whether the value of is 1. If it is 1, it is considered that the predicted data of the adjacent node (the third detection data) is credible. If the value of is 0, it is considered that the predicted data of the adjacent node (the third detection data) is not credible and can be directly discarded. Finally, construct the third detection data set with all credible third detection data.
[0060] In some embodiments of the present invention, determining the first detection data of the detection node includes: Determine the historical security estimation data of the detection node and the system matrix of the system; Determine the state prediction data of the system based on the historical security estimation data and the system matrix data, and use the state prediction data as the first detection data.
[0061] In this embodiment, the historical security estimation data is the prior security estimation data, for example, the security estimation data at the previous moment. According to the security estimation data at the previous moment, predict the state prediction data of the industrial control system at the current moment.
[0062] Specifically, the calculation method is as follows: ; wherein, represents the corresponding detection node by the security estimation data at the moment for the predicted data of the state of the industrial control system at the moment; is the system matrix.
[0063] In some embodiments of the present invention, determining the first detection data of the detection node further includes: Determine the measurement data of the sensor of the detection node and the measurement matrix; Determine the measurement prediction data based on the state prediction data and the measurement matrix; Determine the difference between the measured data and the measured prediction data; Determine the safety estimation data based on the difference and the status prediction data.
[0064] In this embodiment, as before, the measured prediction data of the detection node sensor is , and its calculation process is as follows: . The measured value of the sensor of the detection node , then according to the measurement value and the measured prediction data calculate the corresponding difference, that is .
[0065] Furthermore, the calculation method of the safety estimation data according to this difference is: .
[0066] The present invention has the following beneficial effects: when it is detected that the prediction data of the adjacent node is quite different from the prediction data of the current detection node, a safer method is adopted to actively re-obtain the prediction data of the adjacent node, and a new detection mechanism is used for the re-obtained prediction data to confirm whether it is attacked data. On the one hand, it can effectively reduce the false alarm of data noise caused by normal interference in the information transmission process. On the other hand, it can effectively reduce the number of times of estimated data of the discarded adjacent nodes, effectively reduce the performance loss of the safety state estimator, and thus improve the accuracy of the overall system state estimation.
[0067] Compared with the timeout retransmission mechanism in the traditional network communication field, the active request retransmission rule based on the suspicious information of adjacent nodes proposed by the present invention can quickly actively request the retransmission of suspicious neighbor data according to the detection result of the local attack detector. Enhance the availability of data.
[0068] Compared with the single design of attack detection under network attacks, the present invention additionally adds a retransmission data attack detector on the basis of implementing single data attack detection, and the designed double-threshold mechanism can effectively reduce the false alarm rate of attack detection.
[0069] Compared with the design of the safety state estimation scheme in this field, the improved safety state estimation method of the present invention adds a correction term based on retransmitted data on the basis of existing results, effectively suppresses the influence of network attacks, and further enhances the estimation performance of distributed collaborative fusion estimation.
[0070] Furthermore, the simulation implementation and technical verification process of the distributed safety estimation method proposed by the present invention are as follows: Simulation implementation process: Symbol meaning: is the set of real numbers, is dimensional real vector, is Row Column real matrix, Is the identity matrix of appropriate dimension, Is a column vector all of whose elements are 1.
[0071] Glossary of technical terms: 1. If , then Denotes the 2-norm of the vector ; if , then Denotes the matrix 2-norm; 2. For any matrix , Denotes the transpose of the matrix ; Denotes the inverse matrix of the matrix ; Denotes the sum of all the main diagonal elements of the matrix, denoted as the trace of the matrix.
[0072] 3. For any random variable , Denotes the expectation (also known as the mean) of the variable ; Denotes the conditional expectation of under the event ; Denotes the probability of the variable , Denotes Follows a Gaussian distribution with expectation 0 and variance .
[0073] The technical solution adopted by the present invention is a system security state estimation method based on retransmission of suspicious information. Considering that the industrial control process is linearly updated, the system model at this time can be modeled in the following form: (1) Wherein, Is the state of the industrial control system, and the initial state is . Is the system matrix, Is the process noise following a Gaussian distribution with expectation 0 and variance , Is the time step of the system operation. Since the control input can be integrated into through feedback, formula (1) can describe any linear process. Considering that there are ( ) industrial sensor measurements of the system state, and modeling it in the following form: (2) Where is the measurement value of the sensor at moment, is the measurement matrix, is the sensor at moment, the measurement noise also follows a Gaussian distribution with a mean of 0 and a variance of and satisfies and are independent of each other. The communication relationship between sensors can be described by an undirected graph in graph theory where is the set of labels of sensor nodes, is the set of communication edges between sensor nodes that can communicate with each other. If industrial sensor nodes and node establish communication, then let the communication relationship between them be , otherwise, . If sensor node can communicate with node , then node is called a neighbor of node ; the set composed of all neighbors of node is called the neighbor set of node , denoted as . Next, the specific technical solution of the present invention will be introduced step by step.
[0074] Figure 2 shows the structural schematic diagram of the corresponding distributed multi-sensor system of the industrial control system modeled by the present invention. In the figure, each detection node is provided with a sensor, a detector (multiple attack detectors), a buffer, and an estimator (a security estimator).
[0075] The first step: Design a local predictive state estimator and a real-time data security detector: For the industrial control system modeled as, under the process noise , each edge industrial sensor can represent the state at moment predicted according to the state at moment as: (3); where represents the predicted value of the system state by the secure estimation data of node at moment for , , . The specific form of is given in step three and satisfies the initial estimated value. Define the node At the system state prediction error at time is , then for any node , an upper bound of the prediction error covariance matrix can be expressed as: (4); where is the upper bound of the estimation error covariance of node at time, and its specific form is also given by step three, and it satisfies the initial error covariance matrix is a positive definite matrix. The parameter satisfies , where is a positive constant.
[0076] It should be noted that the iterative formulas of the prediction state equation (3) and the prediction covariance matrix (4) are general formulas, and relevant methods of linear Kalman filtering can be referred to: Considering the requirements of distributed collaborative fusion estimation of edge sensors, each node will transmit prediction information according to the communication relationship modeled as , that is, the predicted value and the upper bound matrix of the prediction error covariance . Each transmitted data packet can be defined as: (5); It means that at time, node transmits data to node and , where and respectively represent the values modified by external network attacks during the data transmission process and . Specifically, for the prediction information transmitted from node to node , the external network attack can be specifically modeled as: (6); where the random variable follows a Bernoulli distribution, indicating whether the node is attacked when transmitting data to node . When , this communication channel is under external attack at time; when , the situation is the opposite. At the same time, represents the probability of an attack occurring on this channel, and the random vector and the positive semi - definite matrix denotes the offset injected by an external attacker and satisfies , where is a finite constant.
[0077] For any sensor node, consider node at time for the security detection of the data in the predicted data packet transmitted by node . Design the real-time data attack detector as: (7); where the attack detector metric indicates that the data may be under an external network attack, and indicates that it is trusted data. is the detection threshold of the pre-given real-time detector.
[0078] Step 2: Design the suspicious information retransmission rule and the retransmission data security detector: Considering that when , it is determined that the predicted information transmitted by neighbor node to node may be under an external network attack and data tampering. The receiving node actively requests the neighbor node to retransmit this suspicious data packet, and design the following data retransmission metric set: (8); Issued by node at time to node , indicating that node requests node to retransmit the data packet sent at time . Since the data retransmission metric set contains a small amount of data and has a low requirement for real-time performance, it is easier to be protected by a symmetric encryption algorithm. Therefore, it can be considered that it will not be injected with malicious signals or tampered with by an attacker during transmission. To distinguish the retransmitted data from the real-time data, define the retransmitted data packet as , where represents the retransmitted data at time that has been tampered with by an external attacker. Considering the data security detection of the retransmitted signal, when node receives the data retransmitted by node again, design the retransmission data attack detector as: (9); where the attack detector metric indicates the detection node For the detection node The retransmitted Detection result of the data at the moment, Indicates that it is determined that this data may have been tampered with by an external network attack, Indicates that it is considered to be trustworthy data. Parameter Is a pre-given retransmission detection threshold and satisfies . For the detection node , construct at The register that can store the previous Step information, and the register Is expressed as: (10); Where . To ensure the effective use of storage space and computing performance, all real-time data detected as suspicious by the detector (7) is retransmitted at most once.
[0079] In particular, in the attack detector for retransmitted data , define the threshold Can reduce the false alarm rate of the detector. Is a threshold with a relatively small value, set according to the noise level, and can detect attacks with a large amplitude; but when the prediction deviation between sensors is large, at this time, even without an attack, the residual may exceed the threshold And alarm. Therefore, the data that does not exceed the threshold () And the real-time and retransmitted equal data are also retained and applied to the next iteration, which can effectively reduce the false alarm rate.
[0080] It should be noted that different from the timeout retransmission mechanism in the field of network communication, the data retransmission rule in the present invention is an active retransmission of suspicious data.
[0081] Step 3: Design a distributed secure state estimator with a data retransmission term added: In the first and second steps, the real-time data detector (7) and the retransmitted data detector (9) are designed respectively. Considering the dual attack detectors comprehensively and adding the retransmission information term, design a distributed secure state estimator based on the retransmission of suspicious data and express it as: (11); Where Is the estimated value of the state of the system At the moment by the sensor node, Is the gain matrix of the secure estimator, Is the prediction of the measurement value of the system By the node At the moment, is the measurement value of the detection node i, Representation Node exist The set of neighbors that are determined to transmit suspicious information at any time, and . Scaling factor is a predetermined constant whose value is in the interval In which Indicates the number of neighbors of the sensor node with the most neighbors. exist The system state estimation error at time t is , then for any node , the state estimation error covariance matrix can be expressed as: (12); in represents the transpose of all terms on the right side of the equation.
[0082] Considering that (12) contains the cross terms obtained by multiplying the estimated errors between nodes, it is impossible to solve it directly. Therefore, the upper bound matrix of the state estimation error covariance is defined as: (13); in ,and is the upper bound of the state estimation error covariance matrix. For any sensor node , the parameters in the covariance matrix Defined as: (14); in is any finite positive constant. Since The sum of the diagonal elements is an upper bound on the sum of squares of the estimation error, so by solving the partial derivatives , we can get the gain matrix in the estimator (13) for: (15); At this point, the design of the safety estimator of the present invention is completed. The comprehensive prediction process formulas (3), (4), the estimator gain (15) and the update process formulas (11), (14) are given. and Under these conditions, the distributed security state estimation of industrial control systems under network attacks can be realized.
[0083] The verification phases are as follows: In order to verify the effectiveness of the distributed collaborative fusion estimator based on suspicious information retransmission proposed in this invention, this section gives an implementation example of an industrial control temperature measurement system in a production workshop. The workshop area to be measured is divided into For a grid where the temperature within each grid is a state component, a -dimensional temperature vector can be defined from the lower left to the upper right. The temperature heat conduction can be linearly modeled as: ; where is the temperature vector, is the average temperature value of the grid at time , is the Gaussian process noise, is the system matrix, and its specific form can be given by the following iterative relationship: ; where is the fusion speed factor, is the length of each grid area.
[0084] Assume that there are randomly distributed industrial temperature sensors in the area to be measured in the production workshop to measure the temperature of the points to be measured. Its measurement equation can be modeled as ; where is the measurement value of the sensor at time , is the measurement noise, is the measurement matrix, and its specific form can be given by the following iterative relationship: ; where is the global coordinate of the sensor in the entire area (the origin is at the lower left corner of the area).
[0085] The following specifically describes the estimation process of the distributed collaborative fusion estimator.
[0086] The first step: For each sensor node , design a real-time data attack detector as: ; where is the predicted temperature value of node at time , is the possibly attacked temperature prediction value passed from node at time to node .
[0087] The second step: For each sensor node , design a retransmission data attack detector as: ; wherein is the node for the retransmission value of the predicted temperature at the moment, the register is constructed as: ; Step 3: For each sensor node , the iterative process of the distributed estimator is: ; ; ; ; ; wherein , the parameter is the same as formula (14).
[0088] In the Python environment, a simulation experiment is carried out for the implementation case (Section 5.2), and the simulation process is as follows: Parameter setting: Parameters of the area to be measured in the production workshop and the initial state of temperature:
[0089]
[0090] For all sensor nodes , the initial state and parameter settings of the estimator are as follows:
[0091] In addition, the communication relationship between industrial sensors is as Figure 3 shown.
[0092] (2) Result analysis The simulation results are as Figures 4 - 6 shown.
[0093] The analysis results show that under the multi-sensor distributed security state estimation framework of the industrial control system, the distributed state estimation method based on suspicious data retransmission proposed by the present invention can effectively realize the estimation of the real-time state of the industrial control system, and at the same time effectively compensate for the impact of attacks on the estimation performance. Figure 4 A thermal comparison graph of the measured real temperature and the estimated temperature by the algorithm in the production workshop at the 60th step is given, and the temperature range is from 24°C to 34°C; Figure 5It is a curve graph showing the variation of temperature estimation errors of 20 industrial temperature sensors (each industrial temperature sensor is deployed on the corresponding detection node, and the detection node is responsible for communication and calculation) over 60 time steps. The curves at different depths represent the curves of the estimation errors of different sensor nodes varying with time; Figure 6 It is a curve graph showing the variation of the average temperature estimation errors of the temperature sensors corresponding to 20 detection nodes over 60 time steps.
[0094] According to Figure 3 and Figure 4 it can be seen that even if the transmitted data may be tampered with by external attackers, the temperature within the region can be effectively estimated by the designed attack detector and state estimator. According to Figure 3 and Figure 5 it can be seen that the temperature sensors corresponding to the 20 detection nodes can respectively achieve bounded estimation of the regional temperature, and the estimation error initially decreases exponentially and then is limited within a finite bound. Figure 6 The estimation error of the centralized estimation method without attack (the dotted line in the figure) is compared, and it can be seen that the average estimation error of the designed distributed security estimator under attack is close to the optimal estimation.
[0095] As Figure 7 shown, the second aspect of the present invention also proposes a distributed security estimation device for any detection node in a distributed multi-sensor system, including: The first data confirmation module 1 is used to determine the first detection data of the detection node and the second detection data of the adjacent node, and determine the first difference data according to the first detection data and the second detection data; The second data confirmation module 2 is used to, if the first difference data meets the first preset condition, obtain the third detection data of the adjacent node by a predetermined method, and determine the second difference data according to the first detection data and the third detection data; The security estimation module 3 is used to, if the second difference data meets the second preset condition, determine the security estimation data of the system according to the first detection data and the third detection data.
[0096] As Figure 8 shown, Figure 8 shows a structural block diagram of a computing device 800 provided according to an embodiment of the present invention. The components of the computing device 800 include but are not limited to a memory 810 and a processor 820. The processor 820 is connected to the memory 810 through a bus 830, and a database 850 is used to store data.
[0097] The computing device 800 also includes an access device 840, which enables the computing device 800 to communicate via one or more networks 860. Examples of such networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 540 may include one or more of any type of wired or wireless network interface (e.g., a network interface controller (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface.
[0098] In one embodiment of the present invention, the above components of the computing device 800, as well as Figure 8 other components not shown, may also be connected to each other, for example, via a bus. It should be understood that Figure 8 the block diagram of the computing device shown is for illustrative purposes only and is not a limitation on the scope of the present invention. Those skilled in the art can add or replace other components as needed.
[0099] The computing device 800 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a Personal Computer (PC). The computing device 800 can also be a mobile or stationary server.
[0100] Among them, the processor 820 is used to execute the following computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned distributed security estimation method are implemented. The above is a schematic solution of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above-mentioned distributed security estimation method belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above-mentioned distributed security estimation method.
[0101] An embodiment of the present invention also provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned distributed security estimation method are implemented.
[0102] The above is a schematic solution of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above-mentioned distributed security estimation method belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above-mentioned distributed security estimation method.
[0103] An embodiment of the present invention also provides a computer program. Among them, when the computer program is executed on a computer, the computer is made to execute the steps of the above-mentioned distributed security estimation method.
[0104] The above is a schematic solution of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the above-mentioned distributed security estimation method belong to the same concept. For the details not described in detail in the technical solution of the computer program, reference can be made to the description of the technical solution of the above-mentioned distributed security estimation method.
[0105] The specific embodiments of the present invention are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0106] Computer instructions include computer program code, which can be in the form of source code, object code, executable files, or some intermediate forms, etc. Computer-readable media can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, mobile hard disks, magnetic disks, optical discs, computer memories, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in computer-readable media can be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0107] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the described order of actions, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential for the embodiments of the present invention.
[0108] In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0109] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The optional embodiments do not elaborate on all the details, nor do they limit the invention to only the specific implementation manners. Obviously, according to the content of the embodiments of the present invention, many modifications and variations can be made. The present invention selects and specifically describes these embodiments to better explain the principles and practical applications of the embodiments of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A distributed security estimation method, used for any detection node in a distributed multi-sensor system, characterized in that: include: Determine first detection data of the detection node and second detection data of an adjacent node, and determine first difference data according to the first detection data and the second detection data; If the first difference data satisfies a first preset condition, obtaining third detection data of the adjacent node in a predetermined manner, and determining second difference data according to the first detection data and the third detection data; If the second difference data satisfies a second preset condition, safety estimation data of the system is determined according to the first detection data and the third detection data.
2. The method according to claim 1, characterized in that The method further comprises: If the first difference data does not satisfy the first preset condition, safety estimation data of the system is determined by using the first detection data and the second detection data.
3. The method according to claim 1, characterized in that The method further comprises: Acquire a plurality of fourth detection data of the adjacent node in the predetermined manner, wherein the fourth detection data is detection data of the adjacent node within a predetermined time before the third detection data; Safety estimation data of the system is determined based on the first detection data, the third detection data and a plurality of the fourth detection data.
4. The method according to claim 1, characterized in that: The method further comprises: If the number of the adjacent nodes is greater than a predetermined value, obtaining second detection data of each adjacent node, and determining first difference data corresponding to each adjacent node according to the second detection data of each adjacent node and the first detection data; If the first difference data of the adjacent nodes does not meet the first preset condition, the adjacent nodes are classified into a first classification set, If the first difference data of the adjacent nodes meets the first preset condition, classifying the adjacent nodes into a second classification set; Constructing a second detection data set based on the second detection data of all the adjacent nodes in the first classification set; Acquire the third detection data of all adjacent nodes in the second classification set in the predetermined manner to construct a third detection data set; Safety estimation data for the system is determined based on the first detection data set, the second detection data set, and the third detection data set.
5. The method according to claim 4, characterized in that The step of acquiring the third detection data of all adjacent nodes in the second classification set in the predetermined manner to construct a third detection data set includes: Acquire the third detection data of each adjacent node in the second classification set by the predetermined method; Determine second difference data of adjacent nodes in the second classification set according to the third detection data and the first detection data; If the second difference data meets the second preset condition, the third detection data of the adjacent nodes in the second classification set are added to the third detection data set.
6. The method according to claim 1, characterized in that The determining the first detection data of the detection node includes: Determining historical safety estimation data of the detection node and a system matrix of the system; State prediction data of the system is determined based on the historical safety estimation data and the system matrix data, and the state prediction data is used as the first detection data.
7. The method according to claim 6, characterized in that The method further comprises: Determining the measurement data and measurement matrix of the detection node sensor; Determining measurement prediction data based on the state prediction data and the measurement matrix; Determining a difference between the measured data and the measured predicted data; The safety estimate data is determined based on the difference and the state prediction data.
8. A distributed safety estimation device, used for any detection node in a distributed multi-sensor system, characterized in that: include: A first data confirmation module, used to determine first detection data of the detection node and second detection data of an adjacent node, and determine first difference data according to the first detection data and the second detection data; a second data confirmation module, configured to obtain the third detection data of the adjacent node in a predetermined manner if the first difference data satisfies a first preset condition, and determine the second difference data according to the first detection data and the third detection data; A safety estimation module is used to determine safety estimation data of the system according to the first detection data and the third detection data if the second difference data meets a second preset condition.
9. A computing device, characterized in that include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of a distributed security assessment method described in any one of claims 1 to 5 are implemented.
10. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the steps of a distributed security assessment method according to any one of claims 1 to 5.