Network security PLC system
Optimizing the PLC network security strategy through gene editing algorithms solves the problem of lack of intelligence and adaptability in the existing technology, and realizes dynamic optimization of PLC network security strategy and higher security protection capabilities.
Patent Information
- Application Number
- CN202510301653.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-20
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing PLC network security protection methods lack intelligence and adaptability, making it difficult to deal with complex and changeable network security threats.
Gene editing algorithm is used to optimize PLC network security strategies, and by obtaining current security status information and real-time data transmission delays, the gene editing algorithm is used to dynamically adjust protective measures, including firewall rules, intrusion detection system settings and data encryption methods.
It realizes dynamic optimization of PLC network security policies, improves the overall security protection capabilities of the system, can continuously adapt to changes in the network environment, and effectively deal with various network security threats.
Smart Images

Figure CN120185875A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of PLC, and more specifically, it relates to a PLC system with network security. Background Art
[0002] With the development of the networking and intelligentization of industrial control systems, programmable logic controllers (PLCs) have been widely used in various industries. PLCs achieve interconnection with other devices through the network and realize automatic control of the industrial production process through programming. However, the network environment in which PLCs are located is becoming increasingly complex, and network security issues are becoming increasingly prominent.
[0003] Traditional PLC network security protection measures mainly include:
[0004] Setting up a firewall to restrict illegal access. By setting up a firewall between the PLC and the external network and configuring strict access control policies, illegal intrusion can be prevented to a certain extent.
[0005] Updating system patches in a timely manner. By regularly scanning the PLC system for vulnerabilities and installing patches in a timely manner, known security vulnerabilities can be repaired and the system security can be improved.
[0006] Strengthening identity authentication and permission management. By strictly authenticating PLC users and assigning corresponding operation permissions according to user roles, illegal operations can be prevented from the source.
[0007] Applying secure communication protocols. By adopting a secure industrial Ethernet protocol or applying secure communication protocols such as VPN and SSL on the communication link, data eavesdropping and tampering can be prevented.
[0008] Deploying an intrusion detection system. By deploying an intrusion detection system in the PLC system, network traffic can be monitored in real time, suspicious behaviors can be detected and alarmed in a timely manner, so as to take corresponding measures in a timely manner.
[0009] However, the above traditional protection measures are often static and pre-configured, lacking intelligence and adaptability, and are difficult to cope with the increasingly complex and changeable network security threats. In addition, the network environment in which PLCs are located usually includes a variety of heterogeneous devices, uses different communication protocols, and the network conditions (such as latency, jitter, etc.) also change dynamically over time. These factors all pose greater challenges to PLC network security protection. Summary of the Invention
[0010] The present invention provides a PLC system with network security, which solves the technical problem that the protection measures lacking intelligence and adaptability in the related art are difficult to cope with the increasingly complex and changeable network security threats.
[0011] The present invention provides a network security PLC system, including:
[0012] A WAN port for connecting to a wide area network;
[0013] A LAN port for connecting to a local area network;
[0014] A network security module, connected to the WAN port and the LAN port, for obtaining the current security status information of the PLC network and the real-time data transmission delay information of the PLC network, and optimizing the PLC network security policy using a gene editing algorithm according to the parameter settings related to the gene editing algorithm;
[0015] A CPU for executing the gene editing algorithm of the network security module;
[0016] A PLC logic module for updating the PLC network security configuration according to the optimized network security policy.
[0017] Further, the network security module is used to perform the following steps:
[0018] Obtain the current security status information of the PLC network and the real-time data transmission delay information of the PLC network;
[0019] Perform original encoding on the security status information according to the encoding rule, and introduce a delay adjustment factor, a device availability factor, and a connection stability factor according to the obtained real-time data transmission delay information of the PLC network to correct the result of the original encoding, obtaining a corrected gene sequence;
[0020] Limit the mutation amplitude according to the delay adjustment factor, the device availability factor, and the connection stability factor, and perform a mutation operation on the corrected gene sequence to obtain a mutated gene sequence;
[0021] Introduce a collaborative security factor, a remote connection stability factor, and a remote connection security factor, and evaluate the mutated gene sequence using a fitness function;
[0022] According to the fitness value, select a gene sequence with a higher fitness from the population of mutated gene sequences using a selection algorithm;
[0023] Decode and restore the selected gene sequence to the optimized network security policy.
[0024] Further, the expression of the delay adjustment factor is:
[0025] , where is the maximum acceptable delay time, is the data transmission delay time corresponding to the i-th policy parameter;
[0026] Device availability factor The expression is:
[0027] , where is the mean time between failures;
[0028] Connection stability factor The expression is:
[0029] , where is the duration with delay lower than the threshold, is the total duration for transmitting the security status information once.
[0030] Furthermore, the delay impact factor The expression is: ;
[0031] Collaborative security factor The expression is:
[0032] , where is the number of device pairs with consistent policies, is the total number of devices;
[0033] Connection security factor The expression is:
[0034] , where is the number of known security vulnerabilities in the current PLC system, is the total number of security vulnerabilities in the same type of PLC system.
[0035] Furthermore, the fitness function is:
[0036]
[0037] where represents the security index value of the network under the network security policy implemented based on the gene sequence , represents the corresponding resource consumption value, , , , , and are the first, second, third, fourth, fifth, and sixth weight coefficients.
[0038] Furthermore, the restricted mutation amplitude according to the delay adjustment factor, device availability factor, and connection stability factor is:
[0039] , where ;
[0040] ;
[0041] is a set mutation range adjustment value, and the policy parameter is encoded into gene bits according to the original coding rule .
[0042] Further, a mutation amplitude upper limit is set during the mutation operation.
[0043] Further, a minimum time interval for the mutation operation is set during the mutation operation.
[0044] Further, a hierarchical coding mechanism is used during the original coding:
[0045] First, the devices connected to the PLC system are classified according to their types, and a unique class code is assigned to each class, which is represented by a fixed-length binary code;
[0046] For each type of device, its specific parameters are encoded again.
[0047] Further, for the IP address coding of the device during the original coding, first determine the subnet where the device is located, encode the subnet address using a conventional coding method, and then for each device within the subnet, only encode its relative address within the subnet, represent the relative address with an 8-bit binary number, and combine the subnet address coding and the device relative address coding to obtain the IP address coding part of the device.
[0048] The beneficial effects of the present invention are as follows:
[0049] It can dynamically optimize the PLC network security policy according to the real-time data transmission delay situation of the PLC network and other network environment changes. The firewall rules, intrusion detection system settings, data encryption situation, etc. have all been adjusted more reasonably according to the optimization process, making it more adaptable to the actual network environment and security requirements.
[0050] Through the improved gene coding, mutation, and fitness evaluation methods, it can more comprehensively and accurately evaluate the advantages and disadvantages of the network security policy. The new fitness function takes into account the impact of data transmission delay on the implementation effect of the network security policy, making the selected policy combination more in line with the actual situation and improving the overall security protection ability of the PLC system.
[0051] As the network environment continues to change, this technical solution can continuously optimize the PLC network security policy and effectively respond to various network security threats. When the network latency changes or new security threats emerge, by repeating the above process, the system can timely adjust the network security policy to ensure the safe and stable operation of the PLC system. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 is a schematic diagram of the modules of the network-secure PLC system of the present invention;
[0053] Figure 2 is an example diagram of the initial device connection and security status information;
[0054] Figure 3 is an example diagram of the initial PLC network real-time data transmission delay situation information;
[0055] Figure 4 is a schematic diagram of the network security policy before and after the application of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0056] Now, the subject matter described herein will be discussed with reference to example embodiments. It should be understood that discussing these embodiments is only to enable those skilled in the art to better understand and thus implement the subject matter described herein. Without departing from the scope of protection of the content of this specification, changes can be made to the functions and arrangements of the elements discussed. Each example can omit, substitute, or add various processes or components as needed. Additionally, the features described in some examples can also be combined in other examples.
[0057] The present invention provides a network-secure PLC system based on the following technical solution:
[0058] As Figure 1 shown, a network-secure PLC system includes: a WAN port, a LAN port, a network security module, a CPU, and a PLC logic module. Among them, the network security module is used to obtain the current security status information of the PLC network and the real-time data transmission delay situation information of the PLC network, and according to the parameter settings related to the gene editing algorithm, use the gene editing algorithm to optimize the PLC network security policy; the CPU is used to execute the optimization program of the network security module; the PLC logic module is used to update the PLC network security configuration according to the optimized network security policy;
[0059] The WAN port and the LAN port are necessary network interfaces for connecting to the wide area network and the local area network.
[0060] The specific process of using the gene editing algorithm to optimize the PLC network security policy is as follows:
[0061] Step 1: Encoding of security status information considering data transmission delay;
[0062] First, the network security module obtains the current security status information of the PLC network and the real-time data transmission delay situation information of the PLC network (the delay time series , 、 、 、 represent the data transmission delay times at the 1st, 2nd, 3rd, and mth moments respectively).
[0063] The security status information includes the policy parameters of the PLC itself and all devices connected to the PLC;
[0064] There are corresponding timestamp marks for the recording of policy parameters and the monitoring of data transmission delay times, and the alignment of gene bits and the delay time series is achieved through timestamps.
[0065] Then, the network security module introduces the following adjustment factors according to the obtained real-time data transmission delay situation information of the PLC network :
[0066] Delay adjustment factor , and its specific form can be determined through experiments according to the actual situation. For example , where is the maximum acceptable delay time, is the data transmission delay time corresponding to the ith policy parameter.
[0067] Device availability factor , which is used to measure the impact of the current delay level on device availability, and is set to , where is the mean time between failures.
[0068] Connection stability factor , which is used to measure the impact of the current delay level on network connection stability, and is set to , where is the duration with delay below the threshold, is the total duration for transmitting the security status information once.
[0069] Encode the security status information according to the encoding rule, and the security status information is expressed as:
[0070] , 、 、 、 represent the 1st, 2nd, 3rd, and mth policy parameters respectively.
[0071] First, each policy parameter is encoded into a gene bit according to the original encoding rule , and then it is corrected according to the delay adjustment factor, device availability factor, and connection stability factor to obtain the finally encoded gene bit . Finally, all the corrected gene bits are combined into a gene sequence .
[0072] When recording the i-th policy parameter and performing gene encoding on it to obtain a gene bit, the corresponding timestamp of this operation will be recorded at the same time. In the delay time series, each sequence unit's corresponding delay time data also has its corresponding timestamp. By matching the timestamp recorded by the gene bit with the timestamps of each unit in the delay time series, the delay time series unit corresponding to the gene bit in time can be found
[0073] The original encoding rule includes
[0074] Hierarchical encoding mechanism
[0075] First, the devices connected to the PLC system are classified according to their types, such as different categories like temperature sensors, pressure sensors, actuators, etc. A unique category code is assigned to each category, represented by a fixed-length binary code. For example, an 8-bit binary number is used to represent the category code
[0076] For each type of device, its specific parameters are encoded. Taking the temperature sensor as an example, its accuracy (represented by 3-bit binary numbers for different accuracy levels), sampling frequency (represented by 5-bit binary numbers for different frequency ranges), and other parameters are encoded respectively. The category code and the specific parameter encoding are combined to form the complete gene encoding of the device
[0077] To a certain extent, it simplifies the encoding process and improves the encoding efficiency
[0078] IP address encoding combined with subnet mask
[0079] For the IP address encoding of a large number of devices, first determine the subnet where the device is located. The subnet address is encoded using a conventional encoding method. For example, a 16-bit binary number is used to represent the subnet address
[0080] Then for each device within the subnet, only its relative address within the subnet needs to be encoded, represented by an 8-bit binary number. The subnet address encoding and the device relative address encoding are combined to obtain the IP address encoding part of the device, thereby reducing the length and complexity of the gene encoding
[0081] Step 2: Improved mutation operation
[0082] For each gene bit in the gene sequence , with a probability When performing mutations, the mutation range needs to be restricted according to the delay adjustment factor, device availability factor, and connection stability factor. The original mutation range randomly changes its value within a reasonable range (such as the to change under binary coding), and now the value range after mutation becomes , where:
[0083] ;
[0084] , is the mutation range adjustment value set according to the specific situation.
[0085] For devices with different protocols, different mutation strategies are adopted. For example, for industrial Ethernet devices, the mutation range can be appropriately relaxed and a larger mutation range adjustment value can be set; while for Modbus devices, more cautious mutation operations are adopted, and both the mutation range and probability are relatively small.
[0086] The mutation operation needs to balance security and real-time performance. To avoid the mutated security policy being too radical and affecting system stability, a mutation amplitude upper limit can be set. At the same time, to ensure that the mutated security policy can take effect in a timely manner, a minimum time interval for the mutation operation can be set.
[0087] The mutated gene sequence is denoted as . The mutation operation can be expressed as:
[0088]
[0089] where represents the improved mutation function, which generates the mutated gene sequence
[0090] based on the input gene sequence
[0090] Furthermore, an interoperability check module is added.
[0091] Considering the interoperability between heterogeneous networks, the mutation operation should also ensure that the mutated network security policy does not cause communication interruptions or compatibility issues between devices with different network protocols. Immediately after the mutation operation, check whether the mutated policy affects the normal communication between devices. If there are problems, make appropriate adjustments. For example, if the mutated Wi-Fi device cannot communicate normally with the wired network device, adjust the mutated policy (such as restoring some access control rules or encryption methods) to ensure normal communication between devices.
[0092] Step 3: Re-evaluate the fitness
[0093] Fitness function In addition to considering network security metrics and resource consumption, the following factors also need to be considered:
[0094] Delay impact factor , which is used to measure the impact of delay on the effectiveness of the security policy, and is set to .
[0095] Collaborative security factor , which is used to measure the collaboration of security policies between different devices, and is set to , where is the number of pairs of devices with consistent policies, is the total number of device pairs.
[0096] Connection stability factor , which has been introduced previously.
[0097] Connection security factor , and its specific calculation method can be set according to the actual situation. For example: , where is the current number of known security vulnerabilities, is the total number of security vulnerabilities of the same type of PLC system.
[0098] The fitness function is:
[0099]
[0100] where represents the network security metric value under the network security policy implemented based on the gene sequence , represents the corresponding resource consumption value, , , , , and are weight coefficients re-set according to importance ( , , , , , )。
[0101] The evaluation of the security index value of the network is as follows:
[0102] Value of equipment assets:
[0103] Value of the PLC core module: The core hardware components such as the processor and memory of the PLC itself play a crucial role in the entire control system. Its value can be determined according to the procurement cost of the equipment, its importance in the industrial production process (for example, the PLC controlling key production links has a higher value), and the difficulty of replacement, denoted as 。
[0104] Value of connected devices: Various devices connected to the PLC, such as sensors and actuators, are assigned value scores according to factors such as their functional importance in the production process, their impact on production continuity, and the cost of the devices themselves. For example, sensors monitoring key production parameters have relatively high values, depending on the specific device type.
[0105] Then the total value of the PLC network equipment assets is 。
[0106] Value of data assets:
[0107] Value of control program data: The control program stored in the PLC is crucial for the orderly operation of the entire industrial production process. Its value depends on factors such as the development cost of the program, its ability to precisely control the production process, and the production losses that may occur due to program errors, denoted as 。
[0108] Value of production data: Various data (such as parameter data of temperature, pressure, flow, etc.) in the production process collected and processed by the PLC are determined value scores according to their importance for production monitoring, quality control, and subsequent analysis, denoted as 。
[0109] Then the total value of the PLC network data assets is 。
[0110] Comprehensively, the total asset value of the PLC network is 。
[0111] Evaluation of the threat possibility of the PLC network:
[0112] Possibility of external threats:
[0113] Network intrusion threat: When considering a PLC connected to an external network (such as a corporate local area network, the Internet, etc.), evaluate the possibility of network intrusion threats such as hacker attacks and malware invasions. This can be evaluated based on the network security protection level of the enterprise where the PLC is located (such as firewall configuration, effectiveness of intrusion detection systems, etc.), historical data on network intrusions of PLCs in the industry, and the current network security situation, denoted as 。
[0114] Physical attack threat: Evaluate the possibility of physical attacks such as physical damage and tampering of the PLC device by external personnel. This can be determined based on the installation location of the PLC device (whether it is vulnerable to external access), on-site security measures (such as whether there are surveillance cameras, access control, etc.), denoted as 。
[0115] Possibility of internal threat:
[0116] Threat of incorrect operation: Problems such as production interruption or data errors may be caused by incorrect operation of the PLC device or its control program by the operator. The possibility of such incorrect operation can be determined based on the training level of the operator, the standardization degree of the operation process, and the complexity of the device operation, denoted as 。
[0117] Threat of malicious operation: Consider the possibility of malicious tampering and destruction of the PLC by internal personnel for certain purposes (such as economic benefits, revenge, etc.). This can be evaluated based on the internal personnel management mechanism of the enterprise (such as permission settings, personnel background checks, etc.) and the occurrence frequency of previous internal personnel violation incidents, denoted as 。
[0118] Then the overall threat possibility of the PLC network facing all threats is calculated as follows:
[0119] 。
[0120] III. PLC network vulnerability assessment:
[0121] Device vulnerability:
[0122] PLC hardware vulnerability: Check the hardware of the PLC device itself, such as the processor, memory, communication interface, etc., for known security vulnerabilities. Assign a score to the hardware vulnerability of the PLC according to the severity of the vulnerability (for example, vulnerabilities that can cause device out-of-control, data leakage and other serious consequences are rated as high severity, and vulnerabilities that may only cause temporary device failures are rated as medium or low severity), denoted as 。
[0123] Vulnerability of connected devices: Similarly, conduct hardware vulnerability checks on devices such as sensors and actuators connected to the PLC, and assign scores according to their hardware vulnerability situations, denoted as etc., which specifically depend on the device type.
[0124] Then the total vulnerability of the PLC network devices is , expressed as follows:
[0125] .
[0126] Software vulnerability:
[0127] Vulnerability of the PLC operating system: Analyze whether there are security risks in the operating system adopted by the PLC, and set scores for the vulnerability of the PLC operating system according to the scope of influence and severity of the operating system vulnerabilities, denoted as .
[0128] Vulnerability of the control program: Check whether there are code vulnerabilities, logical errors, etc. in the control program stored inside the PLC, and determine scores for the vulnerability of the control program according to the scope of influence and severity of these vulnerabilities, denoted as .
[0129] Then the total vulnerability of the PLC network software is .
[0130] Overall, the overall vulnerability of the network inside the PLC can be obtained as , expressed as follows:
[0131] .
[0132] Evaluation of the effectiveness of PLC network security control
[0133] Effectiveness of the firewall: If a firewall is set up in the PLC network, assign a score to the effectiveness of the firewall according to factors such as whether the firewall rule configuration is reasonable and whether it can effectively prevent unauthorized access, denoted as .
[0134] Effectiveness of the intrusion detection system: If there is an intrusion detection system, consider the detection accuracy rate, false alarm rate of the intrusion detection system, and whether it can timely detect and report potential security threats, etc., to determine the effectiveness score of the intrusion detection system, denoted as .
[0135] Effectiveness of encryption technology: Check aspects such as the strength of the encryption algorithm adopted by the PLC network and the security of key management, and set scores for the effectiveness of the encryption technology, denoted as .
[0136] Comprehensively evaluate the overall effectiveness of all security control measures in the PLC network It is expressed as follows:
[0137] .
[0138] Calculate the PLC network security index value
[0139] According to the above evaluation results, use a suitable formula to calculate the security index value. It is expressed as follows:
[0140]
[0141] The meaning of this formula is: the higher the effectiveness of network security control, the higher the security index value; while the greater the asset value, the higher the threat possibility, and the stronger the vulnerability, the lower the security index value.
[0142] Step 4: Optimization selection operation
[0143] The network security module performs a selection operation according to the fitness value obtained from the re-evaluation and the selection pressure coefficient When using common selection algorithms such as roulette wheel selection, it is necessary to calculate the probability of each gene sequence being selected according to the new fitness value.
[0144] Let the gene sequence retained after the selection operation be , and the selection operation can be expressed as:
[0145]
[0146] where represents the optimized selection function, which selects gene sequences with higher fitness according to the input population of mutated gene sequences , the selection pressure coefficient and the information on the real-time data transmission delay situation of the PLC network .
[0147]
[0147] Step 5: Update the PLC network security system
[0148] The network security module decodes and restores the selected gene sequence into a network security policy and applies it to the PLC network security system to update and optimize the existing network security policies, configurations, etc. The PLC logic module makes corresponding adjustments to the access control rules, intrusion detection system settings, data encryption methods, etc. of the PLC network according to the updated network security policy, so as to improve the ability of the PLC system to cope with network security threats.
[0149] The method of the present invention improves gene encoding and mutation operations by introducing a delay adjustment factor, and considers the impact of data transmission delay on the effectiveness of security policies in the fitness function, enabling the gene editing algorithm to dynamically optimize network security policies according to the real-time delay situation of the PLC network. At the same time, the updated security policy can be applied to the PLC network security system in a timely manner, effectively improving the security protection level of the PLC system. Compared with the prior art, the present invention can overcome technical obstacles such as the conflict between the real-time requirements of the gene editing algorithm and the data transmission delay of the PLC network, the difficult accurate establishment of the complex mapping relationship between gene encoding and PLC network security policies, and the difficulty of comprehensively and accurately measuring the advantages and disadvantages of network security policies by the fitness function, and realizes an effective method that can dynamically adapt to changes in the network environment and continuously optimize the PLC network security policy.
[0150] The following is an embodiment based on the above technical solution;
[0151] There is an automated production workshop in a factory, which contains various types of equipment controlled and managed through a PLC system, and involves remote maintenance and monitoring operations. There is a heterogeneous network environment in the workshop, some equipment is connected through a wired network, some equipment is connected through a Wi-Fi network, and there are also some mobile devices (such as inspection robots), which will switch between different networks (Wi-Fi and cellular networks). In addition, in order to ensure the continuity of production and the security of equipment, it is necessary to continuously optimize the network security policy of the PLC system.
[0152] As Figure 2 shown is an example of the initial device connection and security status information.
[0153] As Figure 3 shown is an example of the initial PLC network real-time data transmission delay situation information.
[0154] The process of encoding security status information considering data transmission delay is as follows:
[0155] Application of the hierarchical encoding mechanism:
[0156] Taking the temperature sensor (TS1) as an example, the device type is encoded as "00000010" (the temperature sensor category code is 2), the accuracy is encoded as "010" (corresponding to medium accuracy), and the sampling frequency is encoded as "10100" (corresponding to a certain sampling frequency range), which are combined to form part of the gene encoding of the device.
[0157] For IP address encoding, the subnet address "192.168.1.0" is encoded as "11000000101010000000000100000000", and the relative address "10" of the device within the subnet is encoded as "00001010", which are combined to obtain the complete IP address encoding part.
[0158] The final gene encoding of TS1 (partially shown):
[0159] "00000010010101001100000010101000000000010000000000001010…"
[0160] Encoding information related to remote connection (for the inspection robot PR1):
[0161] The VPN encryption algorithm is AES-256, encoded as "00000001" (corresponding to the encoding rule), the authentication method is username / password, encoded as "0000000001" (corresponding to the encoding rule), and the permission level is intermediate (encoded as "010").
[0162] Calculation of connection stability factor: (The total number of connections per month is 10 times), encoded as "10000" (corresponding to the encoding rule).
[0163] Combined to form the complete gene encoding of PR1 (partially shown):
[0164] "00000001000000000101010000000000000000000000000000000000000000000000000010000…"
[0165] The process of the improved mutation operation is as follows:
[0166] Adjustment of mutation parameters based on device importance:
[0167] For the actuator (ACT1), a critical device, the mutation probability , the adjustment value of the mutation range is set to 5% of the original value range of each gene bit.
[0168] For the temperature sensor (TS1), an important device, the mutation probability , the adjustment value of the mutation range is set to 10% of the original value range of each gene bit.
[0169] For the pressure sensor (PS1), an ordinary device, the mutation probability , the adjustment value of the mutation range Set to 15% of the original value range of each gene locus.
[0170] For the patrol robot (PR1), which is an important device and involves remote connection, the mutation probability , and the mutation range can be set to change parameters such as the VPN encryption algorithm (e.g., from AES-256 to AES-512), authentication method (e.g., from username / password to two-factor authentication), etc. within a reasonable range.
[0171] The process of performing the mutation operation is as follows:
[0172] After the mutation operation, the gene sequences of each device are as follows (partially shown):
[0173] The gene sequence of TS1 becomes :
[0174] "00000010011101101100000010101000000000010000000000001011…"
[0175] The gene sequence of PS1 becomes :
[0176] "00000001010101001100000010101000000000010000000000001010…"
[0177] The gene sequence of ACT1 becomes :
[0178] "00000011010101001100000010101000000000010000000000001010…"
[0179] The gene sequence of PR1 becomes :
[0180] "000000010000000011010100000000000000000000000000000000000000000010001…"
[0181] The process of re-evaluating the fitness is as follows:
[0182] Fitness function calculation (taking TS1 as an example):
[0183] Let the security index value of the network (under the network security policy implemented based on the mutated gene sequence TS1') be 0.8 (the value obtained through evaluation, which can be determined according to actual attack simulations, etc.), and the resource consumption situation value is 0.2 (the value obtained through evaluation, which can be determined according to the actual resource monitoring), and the equipment availability factor (the total number of monthly operations is 10 times).
[0184] Weight coefficient setting: , , , .
[0185] Calculation of the new fitness function value:
[0186]
[0187] Similarly, calculate the fitness function values of other devices:
[0188] For PS1, obtain (the specific calculation process is omitted).
[0189] For ACT1, obtain (the specific calculation process is omitted).
[0190] For PR1, obtain (the specific calculation process is omitted).
[0191] The process of the optimized selection operation is as follows:
[0192] Selection pressure coefficient setting: The selection pressure coefficient .
[0193] Execution of the selection operation:
[0194] Calculate the probability of each gene sequence being selected according to the new fitness value. For example, for TS1, the probability of being selected (where represents all devices).
[0195] After the selection operation, the retained gene sequence is (here is the gene sequence of ACT1’, only for example).
[0196] The process of updating the PLC network security system is as follows:
[0197] Decode and restore the network security policy (taking ACT1’ as an example). The network security policies before and after application are as Figure 4 shown.
[0198] The embodiments of the present invention have been described above. However, these embodiments are not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of these embodiments, those of ordinary skill in the art can also make more equivalent embodiments in various forms, all of which fall within the protection scope of these embodiments.
Claims
1. A network-secure PLC system, characterized in that: include: WAN port, used to connect to the wide area network; LAN port, used to connect to the local area network; The network security module is connected to the WAN port and the LAN port, and is used to obtain the current security status information of the PLC network and the real-time data transmission delay information of the PLC network, and optimize the PLC network security strategy using the gene editing algorithm according to the parameter settings related to the gene editing algorithm; CPU, used to execute the gene editing algorithm of the network security module; The PLC logic module is used to update the PLC network security configuration according to the optimized network security strategy.
2. A network secure PLC system according to claim 1, characterized in that: The network security module is used to perform the following steps: Obtain the current safety status information of the PLC network and the real-time data transmission delay information of the PLC network; The safety status information is originally encoded according to the encoding rules, and according to the acquired PLC network real-time data transmission delay information, a delay adjustment factor, a device availability factor and a connection stability factor are introduced to correct the original encoding result to obtain a corrected gene sequence; The variation range is limited according to the delay adjustment factor, the equipment availability factor and the connection stability factor, and a variation operation is performed on the corrected gene sequence to obtain a mutated gene sequence; The collaborative safety factor, remote connection stability factor and remote connection safety factor are introduced, and the fitness function is used to evaluate the mutated gene sequence; According to the fitness value, a selection algorithm is used to select a gene sequence with higher fitness from the mutated gene sequence population; The selected gene sequences are decoded and restored into optimized network security strategies.
3. A network secure PLC system according to claim 1, characterized in that: Delay Adjustment Factor The expression is: ,in is the maximum acceptable delay time, is the data transmission delay time corresponding to the i-th strategy parameter; Equipment availability factor The expression is: ,in is the mean time between failures; Connection Stability Factor The expression is: ,in is the duration of time the delay is below the threshold, The total time it takes to transmit a security status message.
4. A network secure PLC system according to claim 1, characterized in that: Delay Impact Factor The expression is: ; Synergistic safety factor The expression is: ,in is the number of device pairs with consistent policies, is the total number of device pairs; Connection security factor The expression is: ,in is the number of known security vulnerabilities in the current PLC system, is the total number of security vulnerabilities of the same type of PLC systems.
5. A network secure PLC system according to claim 4, characterized in that: The fitness function is: ; in Based on gene sequence The security index value of the network under the implemented network security strategy, Indicates the corresponding resource consumption value. , , , , and are the first, second, third, fourth, fifth, and sixth weight coefficients.
6. A network secure PLC system according to claim 1, characterized in that: The variation range is limited according to the delay adjustment factor, equipment availability factor and connection stability factor: ,in ; ; is the set variation range adjustment value, and the strategy parameters are encoded as gene positions according to the original encoding rules. .
7. A network secure PLC system according to claim 1, characterized in that: Set an upper limit for the mutation range during the mutation operation.
8. A network secure PLC system according to claim 1, characterized in that: Set the minimum time interval for a mutation operation.
9. A network secure PLC system according to claim 1, characterized in that: The original encoding uses a layered encoding mechanism: First, the devices connected to the PLC system are classified by type, and each category is assigned a unique category code, which is represented by a fixed-length binary code; For each type of equipment, its specific parameters are encoded.
10. A network secure PLC system according to claim 1, characterized in that: When encoding the IP address of the device in the original encoding, first determine the subnet where the device is located, and encode the subnet address using a conventional encoding method. Then, for each device in the subnet, only its relative address in the subnet needs to be encoded, and the relative address is represented by an 8-bit binary number. The subnet address code and the device relative address code are combined to obtain the IP address code portion of the device.