Industrial internet operating system security risk prediction method and system based on knowledge graph
By building a security risk knowledge graph for the industrial Internet operating system and training prediction models, the problem of difficult security risks in the industrial Internet is solved, real-time prediction and early warning of security risks is achieved, and security prevention capabilities are improved.
Patent Information
- Application Number
- CN202510231145.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-06-20
AI Technical Summary
Complex and changeable threats and attacks in the industrial Internet environment are difficult to effectively predict and prevent security incidents before they occur. Traditional security protection measures mainly focus on post-event detection and response.
The security risk prediction method of industrial Internet operating system based on knowledge graph is adopted, and security risk knowledge graph is constructed by collecting and preprocessing security risk data, and a security risk prediction model based on knowledge graph is trained to predict real-time data and generate security risk prediction reports.
Real-time prediction and early warning of security risks in industrial Internet operating systems, improve the prediction accuracy and prevention capabilities of security incidents, and reduce false alarms and missed reports.
Smart Images

Figure CN120180441A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of industrial Internet security, and in particular to a method and system for predicting security risks of an industrial Internet operating system based on a knowledge graph. Background Art
[0002] The industrial Internet has a crucial impact on the manufacturing industry. It not only promotes the deep integration of manufacturing processes and information technology but also accelerates the digital and intelligent transformation of the manufacturing industry, significantly improving production efficiency and quality and enhancing industry competitiveness. However, the widespread application of the industrial Internet has also triggered unprecedented network security risks. The industrial Internet involves the interconnection and interaction of a large number of industrial control systems, sensors, actuators, and other devices. The huge datasets generated by these devices require real-time transmission and processing. Given the openness and complexity of the industrial Internet environment, sensitive data privacy issues such as data leakage and data tampering are likely to occur. In addition, the industrial Internet also faces external attacks and internal threats that may occur during system operation. External attacks mainly come from means such as hacker attacks, malware, and phishing. These attackers attempt to steal sensitive data, damage production systems, or create chaos. Internal threats may come from security incidents caused by system operation errors, losses caused by untimely emergency responses, etc. Facing the complex and changing threats and attacks in the industrial Internet environment, traditional security protection measures mainly focus on post-detection and response and are difficult to effectively predict and prevent security incidents before they occur. Summary of the Invention
[0003] The purpose of the present invention is to overcome the defects of the above-mentioned existing technologies and provide a method and system for predicting security risks of an industrial Internet operating system based on a knowledge graph.
[0004] The purpose of the present invention can be achieved through the following technical solutions:
[0005] A method for predicting security risks of an industrial Internet operating system based on a knowledge graph, the steps including:
[0006] Collect security risk data of the industrial Internet operating system and preprocess the data;
[0007] Based on the preprocessed security risk data, construct a security risk knowledge graph of the industrial Internet operating system;
[0008] Construct and train an industrial Internet security risk prediction model based on the knowledge graph;
[0009] Use the trained industrial Internet security risk prediction model based on the knowledge graph to predict the real-time data of the industrial Internet operating system, determine whether there is a risk of a security incident occurring in the system, and generate a security risk prediction report according to the prediction result.
[0010] 1. A method for predicting security risks of an industrial Internet operating system based on a knowledge graph, characterized in that the steps include:
[0011] Collect security risk data of the industrial Internet operating system and preprocess the data;
[0012] Based on the preprocessed security risk data, construct a security risk knowledge graph of the industrial Internet operating system;
[0013] Construct and train an industrial Internet security risk prediction model based on the security risk knowledge graph;
[0014] Use the trained industrial Internet security risk prediction model to predict the real-time data of the industrial Internet operating system, judge whether there is a risk of security incidents in the system, and generate a security risk prediction report according to the prediction results.
[0015] As a preferred technical solution, the key entities in the construction of the security risk knowledge graph of the industrial Internet operating system include:
[0016] Devices: sensors, controllers, servers;
[0017] Operating systems: industrial-specific operating systems, general operating systems;
[0018] Users: administrators, operators, visitors;
[0019] Application programs: industrial control software, office software, data analysis software;
[0020] Security vulnerabilities: operating system vulnerabilities, application program vulnerabilities, network protocol vulnerabilities;
[0021] Security threats: malware, network attacks, internal threats;
[0022] Network environments: enterprise internal networks, external networks;
[0023] Security incident response strategies: access control strategies, data encryption strategies, intrusion detection strategies.
[0024] As a preferred technical solution, the relationship types between entities in the construction of the security risk knowledge graph of the industrial Internet operating system include:
[0025] The running relationship between devices and operating systems, the communication relationship between devices;
[0026] The operation relationship between users and devices, the usage relationship between users and operating systems, the usage relationship between users and application programs;
[0027] the operational relationship between applications and the operating system;
[0028] The connection relationship between the network environment and the equipment, and the propagation relationship between the network environment and security threats;
[0029] The relationship between security vulnerabilities and operating systems, and the relationship between security vulnerabilities and applications;
[0030] The exploitation relationship between security threats and security vulnerabilities, the attack relationship between security threats and devices, the attack relationship between security threats and operating systems, and the attack relationship between security threats and applications;
[0031] The application relationship between security incident response strategy and devices, the application relationship between security incident response strategy and operating system, and the application relationship between security incident response strategy and application programs.
[0032] As a preferred technical solution, the industrial Internet security risk prediction model based on knowledge graph adopts a knowledge graph embedding model based on pairwise relationship vectors. The model training process is as follows:
[0033] According to the knowledge graph of industrial Internet operating system security risks, a given training triple (h, r, t) is obtained, where h is the head entity, r is the relationship, and t is the tail entity. Negative samples are generated by randomly replacing the head entity or the tail entity.
[0034] Initialize the model and initialize the embedding of entities and relations. The entity embedding sets the L2 norm of the entity to 1, i.e. ‖h‖ 2 =‖t‖ 2 =1; the relation embedding represents the relation as a pair of vectors [r H ,r T ],r H and r T Project the head entity h and the tail entity t into the Euclidean space respectively; use the L1 norm between the head entity projection vector and the tail entity projection vector as the scoring function;
[0035] Set the model's hyperparameters and train the industrial Internet security risk prediction model;
[0036] During the model testing phase, for a given head entity and relationship, the scoring function values of all possible tail entities are calculated and sorted according to the scoring function values. The entities with the highest rankings are the predicted linked entities, thereby realizing link prediction of the knowledge graph.
[0037] As a preferred technical solution, the performance evaluation indicators used in the model training process include average reciprocal rank and Hit@k;
[0038] The average reciprocal rank is the average of the reciprocal ranks of the correct entities. If the correct entity is ranked nth in the list, its reciprocal rank is 1 / n;
[0039] Hit@k is used to measure the proportion of hitting the correct entity among the top k prediction results. Count the number n of triples in the top k prediction results that contain the correct tail entity in all the prediction results of the test set, and divide it by the total number N of triples in the test set, that is, Hit@k = n / N.
[0040] As a preferred technical solution, the loss function adopted for training the industrial Internet security risk prediction model is specifically as follows:
[0041]
[0042] Among them,
[0043]
[0044] In the formula, (h, r, t) is a triple, h is the head entity, r is the relationship, and t is the tail entity; f r (h, t) is the scoring function; G and G ′ are the sets of positive samples and negative samples respectively.
[0045] As a preferred technical solution, the generation of the security risk prediction report according to the prediction results is specifically as follows:
[0046] Extract the key entities involved from the prediction results of the knowledge graph, and infer the types of security events that occurred based on the extracted entity and relationship information, combined with the knowledge and experience in the field of industrial Internet security;
[0047] Trace the network connection paths of the devices related to the risk, determine the other devices that communicate directly or indirectly with the devices related to the risk, as well as the roles and interdependencies of these devices in the industrial production process, and analyze the network scope and device set affected by the security event;
[0048] Comprehensively consider multiple factors, including the harm degree of vulnerabilities, the importance of affected devices, the probability of occurrence of security events, and the possible scope of business impact, set reasonable weights for each factor, and determine the final security risk level through weighted calculation.
[0049] As a preferred technical solution, the judgment of whether there is a risk of security events in the system specifically includes:
[0050] For the associated prediction of devices and applications, locate potential security hazards between devices and applications, and predict the likelihood of device failures or data leaks caused by application vulnerabilities. When risks are discovered, update the application patches to fix the vulnerabilities. If immediate repair is not possible, restrict the functions of the application on the device or deactivate it, and at the same time back up the critical data of the device.
[0051] For the associated prediction of devices and operating systems, predict the impact of operating system vulnerabilities on the running stability and security of devices. For risks, upgrade the operating system patches. If the risks are caused by compatibility issues, adjust the device drivers or system configurations. If there are attack risks, strengthen the access control between the device and the system, and deploy an intrusion detection system to monitor abnormal traffic in real time.
[0052] For the associated prediction of devices and users, analyze the impact of user operations on device security and predict the risks of malicious or incorrect operations. When abnormal operation risks are detected, warn the user and record them. For users suspected of malicious operations, restrict or freeze their accounts and conduct security audits. For users with frequent incorrect operations, provide operation training and guidance.
[0053] For the associated prediction of devices and network environments, evaluate the impact of network environment threats on devices and predict the risks of network attacks. When attack risks are predicted, adjust the firewall rules to block suspicious network traffic. Isolate critical devices from the network. Deploy a honeypot system to trap attackers and collect attack information.
[0054] As a preferred technical solution, determining whether there is a risk of a security incident occurring in the system specifically includes:
[0055] For the associated prediction of applications and operating systems, identify security issues in the interaction between applications and operating systems, and predict the risk of application vulnerabilities exploiting system vulnerabilities. If risks are discovered, update the application and system patches. Strengthen the permission management of the application in the system and restrict unnecessary permissions. If the risks are severe, temporarily deactivate the application and notify the user.
[0056] For the associated prediction of applications and users, understand the security risks when users use applications, and predict the possibility of user data leakage or being attacked by malware. If risks are discovered, prompt the user to update the application version or strengthen the account security settings. For high-risk applications, guide the user to uninstall or replace them. If the user data has been leaked, notify the user and assist in handling it.
[0057] For the associated prediction of applications and network environments, evaluate the impact of the network environment on the security of applications, and predict the risk of network attacks damaging the functions and data of applications. For risks, optimize the application network architecture and add network security protection devices. Encrypt the transmission and storage of application data. If attacked, restore the application service and investigate the source of the attack.
[0058] As a preferred technical solution, determining whether there is a risk of a security incident in the system specifically includes:
[0059] For the associated prediction of the operating system and the user, analyze the impact of user operations on the security of the operating system, and predict the risk of system failures caused by abuse or misoperation of user permissions; if a risk is found, adjust the user permissions; for users at risk of misoperation, provide system operation guides; if the system has been damaged, repair and restore the data;
[0060] For the associated prediction of the operating system and the network environment, predict the risk of attacks on the operating system by threats in the network environment; if an attack risk is predicted, update the system security policy and patches; strengthen the network boundary protection; if the system is attacked, isolate the infected system and conduct emergency response and data recovery;
[0061] For the associated prediction of the user and the network environment, evaluate the security risks of the user in different network environments, and predict the risks of the user being phished or infected by malware; if a risk is found, send a security reminder to the user; for high-risk network environments, restrict the user's network access; if the user has been attacked, assist the user in restoring the security of the account and data.
[0062] Compared with the prior art, the present invention has the following beneficial effects:
[0063] 1) Based on the knowledge graph of the security risks of the industrial Internet operating system, the present invention trains through a link prediction model based on embedding to obtain a security risk prediction model, determines whether there is a risk of a security incident in the system, generates a security risk prediction report according to the prediction result, issues a warning message at the corresponding level, and initiates the corresponding security risk emergency response plan.
[0064] 2) By constructing a knowledge graph of the security risks of the industrial Internet operating system, the present invention integrates multi-source heterogeneous data such as devices, users, application programs, vulnerabilities, and security incident response strategies, and fully explores their complex relationships. Compared with traditional security risk prediction technologies based on a single data source or simple rules, it can more comprehensively and deeply grasp the system security situation. Using the PairRE model for link prediction training, the pairwise relationship vectors in the model can adaptively handle complex relationships, and in the complex environment of the industrial Internet, it can capture the relationships between entities more accurately than traditional knowledge graph link prediction models, thereby improving the risk prediction accuracy and reducing false positives and false negatives. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 It is a flowchart of the method for predicting the security risks of the industrial Internet operating system based on the knowledge graph of the present invention;
[0066] Figure 2This is a process diagram for training an industrial Internet of Things security risk prediction model based on a knowledge graph according to the present invention. Specific implementation mode
[0067] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives detailed implementation modes and specific operation processes, but the protection scope of the present invention is not limited to the following embodiments.
[0068] Embodiment 1
[0069] The purpose of the present invention is to provide an industrial Internet of Things operating system security risk prediction system based on a knowledge graph. Aiming at the problem that the existing industrial Internet of Things faces various internal and external threats resulting in poor security, it predicts possible security events and provides more reliable security guarantees for industrial production, so as to solve the problems raised in the above background technology.
[0070] To achieve the above purpose, the present invention provides the following technical solution: An industrial Internet of Things operating system security risk prediction method based on a knowledge graph, as Figure 1 shown, the method steps include:
[0071] Collection and preprocessing of industrial Internet of Things operating system security risk data, collecting various types of device information, user information, security risks and other relevant data of the industrial Internet of Things operating system, and preprocessing the collected data.
[0072] Construction of an industrial Internet of Things operating system security risk knowledge graph, constructing the preprocessed data into an industrial Internet of Things operating system security risk knowledge graph.
[0073] Training of an industrial Internet of Things security risk prediction model based on a knowledge graph, training through an embedding-based link prediction model to obtain a security risk prediction model.
[0074] Industrial Internet of Things security risk warning and response based on a knowledge graph, judging whether there is a risk of a security event in the system through a security risk prediction model, generating a security risk prediction report according to the prediction result, sending out warning information at the corresponding level, and starting the corresponding security risk emergency response plan.
[0075] Furthermore, the collected industrial Internet operating system security risk dataset includes basic device data such as the hardware models of each device, the device system version, system configuration information, and installed applications. It focuses on collecting device operation data such as device running time, IP address, geographical location, network traffic data, and user operation logs, as well as the latest vulnerability information in external databases such as the existing vulnerability list, the harm levels corresponding to each vulnerability, and the national vulnerability database, and security risk-related data such as security incident response strategies. The collected data is preprocessed, including data cleaning and data format conversion. Through data cleaning, invalid data packets in network traffic data are filtered out, and noise data or error data such as abnormal or incomplete records in the logs are deleted. Through data format conversion, data from different sources is uniformly converted into a common JSON format.
[0076] Furthermore, for the construction of the industrial Internet operating system security risk knowledge graph, a knowledge graph of industrial Internet operating system security risks is constructed based on the preprocessed data. First, entity recognition is carried out to determine the key entities in the knowledge graph, including devices (sensors, controllers, servers, etc.), operating systems (industrial-specific operating systems, general operating systems, etc.), users (administrators, operators, visitors, etc.), application programs (industrial control software, office software, data analysis software, etc.), security vulnerabilities (operating system vulnerabilities, application program vulnerabilities, network protocol vulnerabilities, etc.), security threats (malware, network attacks, internal threats, etc.), network environments (enterprise internal networks, external networks, etc.), security incident response strategies (access control strategies, data encryption strategies, intrusion detection strategies, etc.), etc. Then, relationship extraction is carried out to determine the relationship types between entities, including the running relationship between devices and operating systems, the communication relationship between devices, the operation relationship between users and devices, the usage relationship between users and operating systems, the usage relationship between users and application programs, the running relationship between application programs and operating systems, the connection relationship between network environments and devices, the propagation relationship between network environments and security threats, the interaction relationship between security vulnerabilities and operating systems, the interaction relationship between security vulnerabilities and application programs, the exploitation relationship between security threats and security vulnerabilities, the attack relationship between security threats and devices, the attack relationship between security threats and operating systems, the attack relationship between security threats and application programs, the application relationship between security incident response strategies and devices, the application relationship between security incident response strategies and operating systems, the application relationship between security incident response strategies and application programs, etc. Finally, the entities and relationships are stored in the graph database Neo4j to construct the industrial Internet operating system security risk knowledge graph. Constructing each entity and extracting the relationships between entities can comprehensively describe and understand the industrial Internet system, which helps to accurately identify security threats and vulnerabilities using the knowledge graph in the follow-up and achieve security risk prediction and early warning.
[0077] Furthermore, for the training of the industrial Internet security risk prediction model based on the knowledge graph, the specific training process is as follows Figure 2 as shown. Use the knowledge graph embedding model PairRE based on pairwise relation vectors for training, which is divided into three steps: data preparation, model initialization, and model training.
[0078] First, perform data preparation. A large number of given training triples (h, r, t) are obtained from the constructed industrial Internet operating system security risk knowledge graph, where h is the head entity, r is the relation, and t is the tail entity. For example, (Device A, has vulnerability, Vulnerability C), (Device B, is vulnerable to attack, Malware D), (Device C, suffers an attack, Cyber attack E), (Device D, spreads threat, Malicious traffic F), (Application X, has vulnerability, Vulnerability Y), (Application Z, is vulnerable to attack, Malware W), (Application P, suffers an attack, Phishing attack Q), (Application R, spreads threat, Malicious code S), (Device E, runs, Application F), (Operating system A, has vulnerability, Vulnerability C), (Operating system B, is vulnerable to attack, Malware D), (User X, performs high-risk operation, Security event Y), (User Z, accesses abnormal network, Phishing attack E), (Internal network, is exposed to, External attack F), (External network, spreads, Malicious traffic G), etc. To increase the diversity of the dataset to avoid model overfitting, a large number of negative samples are generated by randomly replacing the head entity or the tail entity. Combine all positive and negative samples to form the dataset, and divide the dataset into a training set, a validation set, and a test set.
[0079] Then, perform model initialization. Initialize the embeddings of entities and relations. For entity embeddings, set the L2 norm of the entity to 1, i.e., ‖h‖ 2 = ‖t‖ 2 = 1. For relation embeddings, represent the relation as a pair of vectors [r H , r t , where r H and r T project the head entity h and the tail entity t into the Euclidean space respectively. Use the L1 norm to measure the distance between the two projected vectors, and this distance is used as a measure of the rationality of the triple. That is, when (h, r, t) holds, it should satisfy Otherwise should be far from Therefore, the scoring function is defined as follows:
[0080]
[0081] where d represents the dimension of the entity embedding vector.
[0082] Finally, the model is trained. Set the hyperparameters of the model, including the embedding vector dimension, the maximum number of training rounds, the model performance evaluation index, etc. In this embodiment, the embedding dimension is set to 512, the maximum number of training rounds is set to 1000, and the model performance evaluation index is set to the mean reciprocal rank (MRR) and Hit@k. If the correct entity ranks nth in the list, its reciprocal rank is 1 / n, and MRR is the average of the reciprocal ranks of the correct entities. Hit@k is used to measure the proportion of correct entities hit in the first k prediction results. The number of triplets n in the first k prediction results of all test sets containing the correct tail entity (or head entity) is counted, and it is divided by the total number of triplets n in the test set, that is, Hit@k = n / N.
[0083] To optimize the model, the following loss function is used to optimize the model as the training objective:
[0084]
[0085] in,
[0086]
[0087] G and G ′ are the sets of positive samples and negative samples respectively.
[0088] In the model testing phase, for a given head entity and relationship (or tail entity and relationship), the scoring function values of all possible tail entities (or head entities) are calculated, and the entities with the highest ranking are ranked according to the scoring function values. The predicted link entities are then used to achieve link prediction of the knowledge graph. In the Industrial Internet Operating System Security Risk Knowledge Graph, when predicting a security vulnerability or security threat (tail entity) with a specific affected relationship with a device, application, operating system, user, or network environment (head entity), the model calculates the scores of all vulnerability entities and uses the security vulnerability or security threat with a high score as the prediction result that may be associated with the device. This scoring-based sorting method can screen out the most likely entity combination in the complex knowledge graph relationship, providing important clues for security risk prediction.
[0089] Furthermore, for the security risk early warning and response of the industrial Internet based on the knowledge graph, the trained model is used to predict the real-time operation data of the industrial Internet operating system to determine whether there is a risk of security incidents occurring in the system. A security risk prediction report is generated according to the prediction results, which includes information such as the predicted security incident type, occurrence probability, possible affected scope, and security risk level. First, extract the key entities involved from the prediction results of the knowledge graph, such as devices, users, applications, security vulnerabilities, etc., and their association relationships. According to the extracted entity and relationship information, combined with the knowledge and experience in the field of industrial Internet security, infer the possible types of security incidents. Secondly, use statistical analysis methods to quantitatively analyze factors such as the strength and frequency of entity relationships in the prediction results to evaluate the occurrence probability of security incidents. Thirdly, trace the network connection paths of devices related to the risk, determine other devices that communicate directly or indirectly with them, and the roles and interdependencies of these devices in the industrial production process, and analyze the network scope and device set that may be affected by security incidents. Finally, comprehensively consider multiple factors, including the harm degree of vulnerabilities, the importance of affected devices, the occurrence probability of security incidents, and the possible scope of business impact, set reasonable weights for each factor, and determine the final security risk level through weighted calculation. Send warning information at the corresponding level according to the security risk level in the prediction report. The warning levels are divided into three levels: low, medium, and high, corresponding to different degrees of security risks. According to the warning level and the predicted security incident type, initiate the corresponding security risk emergency response plan, including a series of predefined measures, such as isolating threatened devices, restricting the operation permissions of suspicious users, starting the backup system, updating firewall rules, and fixing vulnerabilities.
[0090] Among them, for the association prediction of devices and applications, accurately locate the security hazards between devices and applications, predict the possibility of device failures or data leaks caused by application vulnerabilities, be aware of the risks in advance, and gain time for security protection. When risks are discovered, update the application patches in a timely manner to fix the vulnerabilities; if they cannot be repaired immediately, restrict the functions of the application on the device or disable it; at the same time, back up the key data of the device to reduce the risk of data loss.
[0091] Among them, for the association prediction of devices and operating systems, predict the impact of operating system vulnerabilities on the running stability and security of devices, discover system-device compatibility issues and potential attack points in advance, and ensure the stable operation of devices. For the risks, upgrade the operating system patches; if compatibility issues cause risks, adjust the device drivers or system configurations; if there are attack risks, strengthen the access control between devices and systems and deploy intrusion detection systems to monitor abnormal traffic in real time.
[0092] Among them, for the association prediction of devices and users, analyze the impact of user operations on device security, predict the risks of malicious or incorrect operations, regulate user behavior, and reduce the risk of device damage. When detecting abnormal operation risks, warn users in a timely manner and record them; for users suspected of malicious operations, restrict or freeze their accounts and conduct security audits; for users with frequent incorrect operations, provide operation training and guidance.
[0093] Among them, for the association prediction of devices and network environments, evaluate the impact of network environment threats on devices, predict the risks of network attacks, and ensure the security of devices in complex network environments. When predicting attack risks, adjust firewall rules to block suspicious network traffic; isolate key devices from the network; deploy a honeypot system to trap attackers and collect attack information.
[0094] Among them, for the association prediction of application programs and operating systems, clarify the security issues in the interaction between application programs and operating systems, predict the risk of application vulnerabilities exploiting system vulnerabilities, and ensure the secure operation of systems and applications. When discovering risks, update application and system patches simultaneously; strengthen the permission management of applications in the system and restrict unnecessary permissions; if the risks are serious, temporarily disable the application and notify users.
[0095] Among them, for the association prediction of application programs and users, understand the security risks when users use application programs, predict the possibility of user data leakage or being attacked by malware, and protect user data security. When discovering risks, prompt users to update the application version or strengthen account security settings; for high-risk applications, guide users to uninstall or replace them; if user data has been leaked, notify users in a timely manner and assist in handling it.
[0096] Among them, for the association prediction of application programs and network environments, evaluate the impact of network environments on the security of application programs, predict the risk of network attacks damaging the functions and data of application programs, and ensure the normal operation of application programs in the network. For risks, optimize the application network architecture and add network security protection devices; encrypt the transmission and storage of application data; if attacked, promptly restore the application service and investigate the source of the attack.
[0097] Among them, for the association prediction of operating systems and users, analyze the impact of user operations on the security of operating systems, predict the risk of system failures caused by user privilege abuse or incorrect operations, and maintain the stability and security of operating systems. When discovering risks, adjust user permissions; for users at risk of incorrect operations, provide system operation guides; if the system has been damaged, repair it in a timely manner and restore the data.
[0098] Among them, for the correlation prediction of the operating system and the network environment, the attack risk of the threats in the network environment to the operating system is predicted, the security weaknesses of the system in the network are discovered in advance, and the security of the operating system in the network environment is guaranteed. When the attack risk is predicted, the system security policy and patches are updated; the network boundary protection is strengthened; if the system is attacked, the infected system is isolated in time, and emergency response and data recovery are carried out.
[0099] Among them, for the correlation prediction of the user and the network environment, the security risks of the user in different network environments are evaluated, the risks of the user being phished, infected with malware, etc. are predicted, and the security of the user in the network environment is protected. When a risk is discovered, a security reminder is sent to the user; for high-risk network environments, the user's network access is restricted; if the user has been attacked, assist the user in restoring the security of the account and data.
[0100] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative work. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field of the present invention based on the concept of the present invention through logical analysis, reasoning or limited experiments on the basis of the prior art should be within the protection scope determined by the claims.
Claims
1. A method for predicting security risks of industrial Internet operating systems based on knowledge graph, characterized in that the steps include: Collect industrial Internet operating system security risk data and pre-process the data; Based on the pre-processed security risk data, a knowledge graph of security risks of industrial Internet operating systems is constructed; Build and train an industrial Internet security risk prediction model based on the security risk knowledge graph; Use the trained industrial Internet security risk prediction model to predict the real-time data of the industrial Internet operating system, determine whether the system is at risk of a security incident, and generate a security risk prediction report based on the prediction results.
2. According to the method for predicting security risks of industrial Internet operating systems based on knowledge graphs according to claim 1, it is characterized in that: The key entities in constructing the industrial Internet operating system security risk knowledge graph include: Equipment: sensors, controllers, servers; Operating system: industrial-specific operating system, general-purpose operating system; Users: Administrator, Operator, Guest; Applications: industrial control software, office software, data analysis software; Security vulnerabilities: operating system vulnerabilities, application vulnerabilities, network protocol vulnerabilities; Security threats: malware, cyberattacks, insider threats; Network environment: enterprise internal network, external network; Security incident response strategy: access control strategy, data encryption strategy, and intrusion detection strategy.
3. According to the method for predicting security risks of industrial Internet operating systems based on knowledge graphs according to claim 2, it is characterized in that: The types of relationships between entities in constructing the industrial Internet operating system security risk knowledge graph include: The operating relationship between the device and the operating system, and the communication relationship between devices; The operational relationship between the user and the device, the usage relationship between the user and the operating system, and the usage relationship between the user and the application; the operational relationship between applications and the operating system; The connection relationship between the network environment and the equipment, and the propagation relationship between the network environment and security threats; The relationship between security vulnerabilities and operating systems, and the relationship between security vulnerabilities and applications; The exploitation relationship between security threats and security vulnerabilities, the attack relationship between security threats and devices, the attack relationship between security threats and operating systems, and the attack relationship between security threats and applications; The application relationship between security incident response strategy and devices, the application relationship between security incident response strategy and operating system, and the application relationship between security incident response strategy and application programs.
4. According to the method for predicting security risks of industrial Internet operating systems based on knowledge graphs according to claim 1, it is characterized in that: The industrial Internet security risk prediction model based on knowledge graph adopts a knowledge graph embedding model based on pairwise relationship vectors. The model training process is as follows: According to the knowledge graph of industrial Internet operating system security risks, a given training triple (h, r, t) is obtained, where h is the head entity, r is the relationship, and t is the tail entity. Negative samples are generated by randomly replacing the head entity or the tail entity. Initialize the model and initialize the embedding of entities and relations. The entity embedding sets the L2 norm of the entity to 1, i.e. ‖h‖ 2 =‖t‖ 2 =1; the relation embedding represents the relation as a pair of vectors [r H ,r T ],r H and r T Project the head entity h and the tail entity t into the Euclidean space respectively; use the L1 norm between the head entity projection vector and the tail entity projection vector as the scoring function; Set the model's hyperparameters and train the industrial Internet security risk prediction model; During the model testing phase, for a given head entity and relationship, the scoring function values of all possible tail entities are calculated and sorted according to the scoring function values. The top-ranked entities are the predicted linked entities, thereby realizing link prediction of the knowledge graph.
5. According to claim 4, a method for predicting security risks of industrial Internet operating systems based on knowledge graphs is characterized in that: The performance evaluation indicators used in the model training process include average reciprocal rank and Hit@k; The average reciprocal rank is the average of the reciprocal ranks of the correct entities. If the correct entity is ranked nth in the list, its reciprocal rank is 1 / n; Hit@k is used to measure the proportion of correct entities hit in the first k prediction results. The number of triplets n containing the correct tail entity in the first k prediction results of all test sets is counted, and divided by the total number of triplets in the test set N, to obtain Hit@k = n / N.
6. According to the method for predicting security risks of industrial Internet operating systems based on knowledge graphs according to claim 4, it is characterized in that: The loss function used in the training of the industrial Internet security risk prediction model is as follows: in, In the formula, (h, r, t) is a triple, h is the head entity, r is the relationship, and t is the tail entity; f r (h, t) is the scoring function; G and G ′ are the sets of positive samples and negative samples respectively.
7. The method for predicting security risks of industrial Internet operating systems based on knowledge graph according to claim 3 is characterized in that: The security risk prediction report is generated according to the prediction results, as follows: Extract the key entities involved from the prediction results of the knowledge graph, and infer the type of security incident that occurred based on the extracted entity and relationship information, combined with knowledge and experience in the field of industrial Internet security; Trace the network connection paths of risk-related devices, identify other devices that communicate directly or indirectly with risk-related devices, as well as the roles and interdependencies of these devices in the industrial production process, and analyze the network scope and device collection affected by security incidents; Taking into account multiple factors, including the severity of the vulnerability, the importance of the affected equipment, the probability of a security incident, and the scope of possible business impact, reasonable weights are set for each factor, and the final security risk level is determined through weighted calculation.
8. The method for predicting security risks of industrial Internet operating systems based on knowledge graph according to claim 7 is characterized in that: The determining whether the system has a risk of a security incident specifically includes: Predict the association between devices and applications, locate security risks between devices and applications, and predict the possibility of device failure or data leakage caused by application vulnerabilities; when risks are found, update application patches to fix vulnerabilities; if they cannot be fixed immediately, limit the function of the application on the device or disable it, and back up key device data; Predict the association between devices and operating systems, and predict situations where operating system vulnerabilities affect the stability and security of device operations; upgrade operating system patches based on risks; if risks are caused by compatibility issues, adjust device drivers or system configurations; if there are attack risks, strengthen access control between devices and systems, and deploy intrusion detection systems to monitor abnormal traffic in real time; Predict the association between devices and users, analyze the impact of user operations on device security, and predict the risk of malicious or erroneous operations; if abnormal operation risks are detected, warn the user and record them; restrict or freeze the account of users suspected of malicious operations, and conduct security audits; provide operation training and guidance for users who frequently make erroneous operations; Predict the association between devices and network environment, evaluate the impact of network environment threats on devices, and predict network attack risks; when attack risks are predicted, adjust firewall rules to block suspicious network traffic; isolate key devices from the network; deploy honeypot systems to entrap attackers and collect attack information.
9. The method for predicting security risks of industrial Internet operating systems based on knowledge graph according to claim 7 is characterized in that: The determining whether the system has a risk of a security incident specifically includes: Predict the association between applications and operating systems, identify security issues in the interaction between applications and operating systems, and predict the risk of application vulnerabilities exploiting system vulnerabilities; if risks are found, update applications and system patches; strengthen the permission management of applications in the system and restrict unnecessary permissions; if the risk is serious, temporarily disable the application and notify the user; Predict the association between applications and users, understand the security risks when users use applications, and predict the possibility of user data leakage or malware attacks; if risks are found, prompt users to update the application version or strengthen account security settings; for high-risk applications, guide users to uninstall or replace them; if user data has been leaked, notify users and assist in handling; Predict the correlation between applications and network environments, evaluate the impact of network environments on application security, and predict the risk of network attacks damaging application functions and data; optimize application network architecture and add network security protection equipment to address risks; encrypt application data for transmission and storage; and if attacked, restore application services and investigate the source of the attack.
10. The method for predicting security risks of industrial Internet operating systems based on knowledge graph according to claim 7 is characterized in that: The determining whether the system has a risk of a security incident specifically includes: Predict the association between the operating system and users, analyze the impact of user operations on the security of the operating system, and predict the risk of system failure caused by user privilege abuse or misoperation; if risks are found, adjust user privileges; provide system operation guides for users at risk of misoperation; if the system is damaged, repair and restore data; Predict the correlation between the operating system and the network environment, and predict the attack risk of threats in the network environment to the operating system; if the attack risk is predicted, update the system security policy and patches; strengthen the network boundary protection; if the system is attacked, isolate the infected system, conduct emergency response and data recovery; It predicts the association between users and network environments, evaluates users' security risks in different network environments, and predicts users' risks of being infected by phishing and malware. If risks are found, it sends security alerts to users. For high-risk network environments, it restricts users' network access. If users have been attacked, it assists users in restoring their accounts and data security.
Citation Information
Cited By
Industrial internet security risk knowledge graph construction method
CN122088649A
A Method for Constructing a Knowledge Graph of Industrial Internet Security Risks
CN122088649B