Technological process alarm method, device and system and electronic equipment
By analyzing and judging the flow data of process parameters in the industrial network security audit server, the problem that process parameters are easily tampered with in the network transmission in traditional MES systems is solved, real-time monitoring and alarm of process parameters is realized, and the reliability of the industrial control system is improved.
Patent Information
- Application Number
- CN202510212659.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-24
AI Technical Summary
In traditional MES systems, process parameters are easily tampered with during network transmission, resulting in the MES system being unable to trigger alarms and unable to monitor the process flow in real time.
By applying a process flow alarm method in an industrial network security audit server, the process parameter alarm threshold input by the user and the switch traffic data are obtained, the traffic data is analyzed to obtain the target process parameters, and the alarm threshold is determined whether it exceeds the alarm threshold. If it exceeds it, an alarm information is generated and sent to the production management terminal.
It effectively avoids tampering with process parameters during network transmission, enhances the alarm capability of the MES system, and improves the monitoring accuracy and reliability of the industrial control system.
Smart Images

Figure CN120196058A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of process monitoring and alarm, and particularly relates to a process flow alarm method, device, system and electronic device. Background Art
[0002] In industries such as petroleum, chemical, and power, in the MES system (production management system) generally, equipment alarms, process alarms, quality alarms, environmental alarms, and operation alarms are monitored and alarmed. These classifications can help enterprises better manage and monitor the production process. For example, equipment alarms mainly target the operating status of machinery and equipment. When the equipment fails or the operating parameters exceed the set range, the system will automatically send an alarm notification to remind relevant personnel to handle it in time to avoid production stagnation or product quality problems. This classification method can effectively improve production efficiency, reduce downtime, and ensure the stability of product quality.
[0003] Process alarms are mainly used to monitor various parameters in the production process to ensure that the process flow operates within the set range. Such alarms include abnormal monitoring of process parameters such as temperature, pressure, flow rate, and concentration. By strictly controlling process parameters, process alarms can effectively ensure product consistency and quality.
[0004] As Figure 1 shown, in the traditional MES system, the acquisition of process alarm parameters is mainly achieved through sensors. The sensors are responsible for real-time acquisition of various parameters in the process, such as temperature, pressure, flow rate, etc., and transmit these parameters to the MES system. The monitoring module in the MES system is responsible for receiving these data and performing further processing and analysis. The generated alarms are pushed to the monitoring large screen and displayed in real time.
[0005] If the process parameters collected by the collector are tampered with during the transmission process, the monitoring module of the MES system cannot trigger an alarm, and the purpose of real-time monitoring of the process flow cannot be achieved. Summary of the Invention
[0006] In order to solve the above problems, a process flow alarm method, device, system and electronic device of the present invention can avoid the tampering of process parameters during network transmission, supplement the alarm ability of the MES system, and improve the accuracy and reliability of industrial control system monitoring.
[0007] In a first aspect, a process flow alarm method provided by the present invention is applied to an industrial network security audit server, and the industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module; the method includes:
[0008] Obtain the process parameter alarm threshold input by the user;
[0009] Obtain the traffic data of the switch; wherein, the traffic data is the data sent by the process parameter acquisition module to the switch;
[0010] Analyze the traffic data to obtain the target process parameters;
[0011] Determine whether the target process parameters exceed the process parameter alarm threshold; if so, generate an alarm message and send the alarm message to the production management terminal; otherwise, return to the step of obtaining the traffic data of the switch and continue to execute.
[0012] In an alternative embodiment, the process parameter acquisition module includes a controller and at least one process parameter acquisition sensor, the at least one process parameter acquisition sensor is connected to the controller, and the controller is connected to the switch.
[0013] In an alternative embodiment, the analyzing the traffic data to obtain the target process parameters includes:
[0014] Analyze the traffic data to obtain the protocol type and protocol data;
[0015] Determine whether the protocol type is the target communication protocol; if so, continue to the next step; otherwise, return to the step of obtaining the traffic data of the switch and execute again; wherein, the target communication protocol is the communication protocol between the controller and the switch;
[0016] Analyze the protocol data according to a pre-established parsing library to determine the target process parameters, wherein the parsing library is established according to the target communication protocol.
[0017] In an alternative embodiment, the analyzing the traffic data to obtain the protocol type and protocol data includes:
[0018] Perform MAC layer parsing on the traffic data to obtain the source MAC address and the destination MAC address;
[0019] Perform network layer parsing on the traffic data to obtain the source IP address and the destination IP address;
[0020] Perform transport layer parsing on the traffic data to obtain the source port, the destination port, and the transport layer protocol;
[0021] Perform application layer parsing on the traffic data to obtain industrial protocol data;
[0022] Use a pre-established protocol matching engine to match and identify the industrial protocol data, determine the protocol type, and extract the protocol data.
[0023] In an alternative embodiment, the protocol matching engine performs matching using one or more of the definition of protocol fields, data format, protocol features, and a predetermined rule library; wherein, the data format includes the length of the data packet, the order of fields in the data packet, and the arrangement of fields in the data packet.
[0024] In an alternative embodiment, the method further includes:
[0025] Performing security analysis based on one or more of the source MAC address, destination MAC address, source IP address, destination IP address, source port, destination port, transport layer protocol, and industrial protocol to determine the attack source and attack target.
[0026] In an alternative embodiment, the parsing of the protocol data according to a pre-established parsing library to determine the target process parameters includes:
[0027] Obtaining a pre-established list of point templates; wherein, the items in the list of point templates include tag number items, item number items, data area items, offset items, data length items, value items, and value type items; wherein, the tag number item represents the unique identifier of the point, the item number item represents the data name, the data area item represents the area number where the data is stored, and the offset item represents the starting position of the data in the data area;
[0028] Obtaining key fields from the protocol data, the key fields including function code, data area, offset, and data length; wherein, the function code represents the operation type, and the operation type includes read and write;
[0029] Determining the target monitoring points according to the data area, offset, and length in the key fields;
[0030] Traversing the list of point templates according to the target monitoring points to determine the point information matching the target monitoring points;
[0031] Parsing the point information to obtain the target process parameters.
[0032] In a second aspect, a device for warning of a process flow provided by the present invention, the industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module; the device includes:
[0033] A threshold acquisition module, configured to acquire a process parameter warning threshold input by a user;
[0034] A traffic capture module, configured to acquire traffic data of the switch; wherein, the traffic data is data sent by the process parameter acquisition module to the switch;
[0035] A traffic analysis module, configured to analyze the traffic data to obtain target process parameters;
[0036] A comparison module, configured to determine whether the target process parameters exceed the process parameter warning threshold; if so, generate a warning message and send the warning message to the production management terminal; otherwise, return to the step of obtaining the traffic data of the switch and continue to execute.
[0037] In a third aspect, an industrial control system provided by the present invention includes a switch, and at least one process parameter acquisition module, an industrial network security audit server, and a production management terminal respectively connected to the switch;
[0038] The process parameter acquisition module is configured to acquire process parameters in the industrial production link and send the process parameters to the switch;
[0039] The industrial network security audit server is configured to obtain traffic data from the switch, process the traffic data by using the process flow warning method according to any one of the first aspects, obtain a warning message, and send the warning message to the production management terminal.
[0040] In a fourth aspect, an electronic device provided by the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the method according to any one of the foregoing first aspects are implemented.
[0041] In a fifth aspect, a computer-readable medium having non-volatile program code executable by a processor is provided, and the program code causes the processor to execute the method according to any one of the foregoing first aspects.
[0042] The beneficial effects brought by the technical solution provided by the embodiments of the present invention are as follows: The process flow alarm method, device, system and electronic device of the present invention are applied to an industrial network security audit server. First, the process parameter alarm threshold input by the user and the traffic data of the switch are obtained; the traffic data here is the data sent by the process parameter acquisition module to the switch; then, the traffic data is parsed to obtain the target process parameter; finally, it is judged whether the target process parameter exceeds the process parameter alarm threshold; if so, an alarm message is generated and sent to the production management terminal; otherwise, the step of obtaining the traffic data of the switch is returned to continue; since the network audit server directly obtains the traffic data from the switch in the production manufacturing layer to obtain the process parameters, the transmission of process data in the network is avoided, thus completely eliminating the possibility of the process parameters being tampered with during network transmission; the present invention can avoid the process parameters being tampered with during network transmission, supplement the alarm ability of the MES system, and improve the accuracy and reliability of industrial control system monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 Generate a process alarm flow chart for the current MES system;
[0044] Figure 2 Schematic flow chart of the process flow alarm method provided by the embodiments of the present invention;
[0045] Figure 3 Another schematic flow chart of the process flow alarm method provided by the embodiments of the present invention;
[0046] Figure 4 MES system process alarm flow chart provided by the embodiments of the present invention;
[0047] Figure 5 Another schematic flow chart of the process flow alarm method provided by the embodiments of the present invention, aiming to reflect the traffic analysis process;
[0048] Figure 6 Schematic system diagram of the process flow alarm device provided by the embodiments of the present invention;
[0049] Figure 7 Schematic system diagram of the industrial control system provided by the embodiments of the present invention;
[0050] Figure 8 Schematic system diagram of the electronic device provided by the embodiments of the present invention.
[0051] In the figure: 100 - Threshold acquisition module; 200 - Traffic capture module; 300 - Traffic analysis module; 400 - Comparison module; 710 - Switch; 720 - Process parameter acquisition module; 730 - Industrial network security audit server; 740 - Production management terminal; 1000 - Electronic device; 1001 - Communication interface; 1002 - Processor; 1003 - Memory; 1004 - Bus. Detailed implementation mode
[0052] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0053] The process flow alarm method provided in this embodiment is applied to an industrial network security audit server. The industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module.
[0054] Here, a network audit system (also known as an industrial network security audit system) is installed in the industrial network security audit server. This system is specifically used to monitor, analyze, and audit security activities in the industrial control network, such as protocol identification and asset management, traffic audit and anomaly detection, intrusion behavior and attack detection, operation behavior recording and traceability, and audit record and log storage. As Figure 2 shown, the switch acquires process parameters from the process parameter acquisition modules in each process flow. The data of the switch is sent to the office network through an isolation network gateway. There is a production management terminal in the office network, and an MES system is configured in this production management terminal.
[0055] Preferably, the process parameter acquisition module includes a controller and at least one process parameter acquisition sensor. At least one process parameter acquisition sensor is connected to the controller, and the controller is connected to the switch. That is, the process parameters are acquired through the process parameter acquisition sensors. These process parameter acquisition sensors can be one or more of a temperature sensor, a pressure sensor, a flow sensor, a liquid level sensor, a gas sensor, an infrared sensor, a Hall sensor, an acceleration sensor, a displacement sensor, an angle sensor, a humidity sensor, a photoelectric sensor, a magnetoresistive sensor, a microwave sensor, a ultrasonic sensor, a capacitance sensor, an inductance sensor, a resistance sensor, an image sensor, a fiber optic sensor, etc. The acquired process parameters include one or more of temperature data, pressure data, flow data, liquid level data, gas data, infrared data, Hall data, acceleration data, displacement data, angle data, humidity data, photoelectric data, magnetoresistive data, microwave data, ultrasonic data, capacitance data, inductance data, resistance data, image data, and fiber optic data.
[0056] See Figure 2 , the method of this embodiment includes the following steps S100 to step S400.
[0057] Step S100, obtain the alarm threshold of the process parameters input by the user.
[0058] Specifically, the user (administrator) configures the alarm threshold of at least one process parameter in the key process flow in the industrial network security audit system, such as the alarm point values of the aforementioned temperature data, pressure data, flow data, liquid level data, gas data, infrared data, Hall data, acceleration data, displacement data, angle data, humidity data, optoelectronic data, magnetoresistive data, microwave data, ultrasonic data, capacitance data, inductance data, resistance data, image data, and optical fiber data.
[0059] Step S200, obtain the flow data of the switch; wherein, the flow data is the data sent by the process parameter acquisition module to the switch.
[0060] Here, the process parameters collected by the process parameter acquisition sensor are sent to the switch, and the industrial network security audit server grabs these data from the switch.
[0061] Step S300, parse the flow data to obtain the target process parameters. That is, parse the flow data to obtain the real-time process parameters of the key engineering process. Preferably, step S300 includes the following steps S310 to S330.
[0062] Step S310, parse the flow data to obtain the protocol type and protocol data. The protocol type is the protocol name, and the extracted protocol data is saved for use in subsequent steps. Specifically, in implementation, the steps corresponding to step S310 can be integrated into an engine, called a protocol recognition engine. Specifically, step S310 includes the following steps S311 to S315.
[0063] Step S311, perform MAC layer parsing on the flow data to obtain the source MAC address and the destination MAC address.
[0064] Step S312, perform network layer parsing on the flow data to obtain the source IP address and the destination IP address.
[0065] Step S313, perform transport layer parsing on the flow data to obtain the source port, the destination port, and the transport layer protocol.
[0066] Step S314, perform application layer parsing on the flow data to obtain the industrial protocol data.
[0067] Step S315, use the pre-established protocol matching engine to perform matching recognition on the industrial protocol data, determine the protocol type, and extract the protocol data.
[0068] Specifically, as Figure 5As shown in the figure, the protocol recognition engine first parses the header of the traffic data, that is, performs MAC L1 layer parsing, extracts the source MAC address and the destination MAC address; then parses the IP header of the data packet, extracts the source IP address and the destination IP address; parses the transport layer to identify the protocol type of data transmission; parses the application layer to identify the industrial protocol type.
[0069] Preferably, the protocol matching engine performs matching by using one or more of the protocol field definitions, data formats, protocol features, and a pre-determined rule library; among them, the data format includes the length of the data packet, the order of fields in the data packet, and the arrangement of fields in the data packet. Here, for protocol features, some protocols may use specific encoding methods, compression algorithms, or encryption technologies when transmitting data, and these features can be used as the basis for protocol matching.
[0070] Step S320, determine whether the protocol type is the target communication protocol. If so, continue to the next step; otherwise, return to step S200 and execute again; where the target communication protocol is the communication protocol between the controller and the switch.
[0071] The controller in this embodiment is described by taking M6 / M7 (indicating M6 or M7) as an example, and the target communication protocol is the M6 / M7 protocol. This step determines whether the protocol type is the M6 / M7 protocol. If so, continue to execute; otherwise, return to step S200 to capture real-time traffic data again, and then continue to parse the captured real-time traffic data.
[0072] Step S330, parse the protocol data according to the pre-established parsing library to determine the target process parameters, where the parsing library is established according to the target communication protocol.
[0073] In specific implementation, the content corresponding to steps S320 to S330 can be integrated into an engine, called the traffic parsing engine.
[0074] Specifically, the parsing library is established based on the M6 / M7 protocol. The traffic parsing engine calls the M6 / M7 parsing library to parse the protocol data.
[0075] Step S330 includes the following steps S331 to S335.
[0076] Step S331, obtain the pre-established list of point templates; among them, the items in the list of point templates include tag number item, item number item, data area item, offset item, data length item, value item, and value type item; as shown in Table 1, where the tag number item represents the unique identifier of the point (e.g., A1), the item number item represents the data name (e.g., AV), the data area item represents the area number where the data is stored (e.g., 1), and the offset item represents the starting position of the data in the data area (e.g., 12345). In addition, there are also the length item (i.e., the byte length of the data, e.g., 4), the value item (e.g., - indicates unparsed), and the value type item (e.g., float indicates floating point number).
[0077] Table 1
[0078] Item number Item number Data area Offset Length Value Value type A1 AV 1 12345 4 - float
[0079] Step S332, obtain the key fields from the protocol data, and the key fields include function code, data area, offset, and data length; among them, the function code represents the operation type, and the operation types include read and write. The data area is similar to the aforementioned data area item and represents the area number where the data is stored.
[0080] Step S333, determine the target monitoring point according to the data area, offset, and length in the key fields. For example, determine the corresponding target monitoring point according to the data area 1 and the offset 12345.
[0081] Step S334, traverse the list of point templates according to the target monitoring point to determine the point information that matches the target monitoring point. When traversing, the matching conditions can include data area, offset, and data length. Finally, determine the point information corresponding to the target monitoring point, such as tag number, item number, value, value type, etc.
[0082] Step S335, parse the point information to obtain the target process parameter. According to the matching point information, parse the original value in the protocol data to obtain the target process parameter. For example, according to the value type float, convert the original data into the actual process parameter value, such as 20.0A, and verify whether the process parameter value is within a reasonable range. If so, determine 20.0A as the target process parameter.
[0083] Step S400, determine whether the target process parameter exceeds the process parameter alarm threshold; if so, generate an alarm message and send the alarm message to the production management terminal; otherwise, return to the step of obtaining the traffic data of the switch and continue to execute.
[0084] As Figure 4As shown, the target process parameters are compared with the alarm thresholds configured in step S100, and an alarm is generated for the comparison result and pushed to the MES system of the production management terminal through a dedicated interface. The MES system generates an alarm push based on this alarm information and displays the alarm push to the user through a display module. In some other embodiments, the alarm information can be directly displayed to the user on the industrial network security management server side, or sent to the user's handheld terminal (such as a mobile phone, a tablet computer, etc.) through a mobile network to achieve timely and reliable alarms.
[0085] In some embodiments, the source and destination of the traffic data are identified through step S311, and the usage of physical addresses in the network is detected. The routing and addressing processes in the data packet are understood through step S312, and the usage of IP addresses in the network is detected. The protocol type (TCP / UDP) of the data transmission is identified through step S313, and the reliability and integrity of the data transmission are detected. The data transmission content and behavior of the application program are understood through step S314, and potential network security threats are detected. Therefore, further, the method of this embodiment further includes: performing security analysis based on one or more of the source MAC address, destination MAC address, source IP address, destination IP address, source port, destination port, transport layer protocol, and industrial protocol to determine the attack source and attack target. By parsing the traffic captured from the switch layer by layer in this embodiment, the composition and behavior of the network traffic are deeply understood, which helps to optimize the network performance, ensure network security, and provide strong decision-making support for network administrators.
[0086] Specifically in implementation, taking xx Chemical Plant as an example, process parameter monitoring is implemented in the MES system. The process parameter acquisition sensors on the control network transmit the acquired process parameters to the MES system on the office network through the network. The MES system gives an early warning for the process flow parameters according to the pre-configured alarm thresholds. If a network attack occurs on the office network and a hacker tampers with the process flow parameters transmitted from the control network to the office network, at this time, the alarm subsystem of the MES system cannot give a real-time alarm for the process flow parameters. At this time, the industrial network security audit system, as a basic network security device deployed on the control network, can parse the traffic data on the control network switch and parse out the process flow parameters at different points of the controller. Generating an alarm for the process flow parameters in the industrial network security audit system can avoid the transmission of the process flow parameters between the control network and the office network. The alarm information generated by the industrial network security audit system can be directly sent to the MES system of the production management terminal through a dedicated interface to ensure the security and reliability of the system.
[0087] In some possible embodiments, such as Figure 3As shown in the figure, the method steps of this embodiment can be in sequence: traffic parsing, M6 / M7 protocol identification, M6 / M7 library call, point value template query, reporting point value data, and comparing the point value with the alarm threshold (the user pre-configures the point value alarm threshold); determining whether it is within the threshold range, if so, returning to the traffic parsing step, otherwise giving an alarm.
[0088] In the method of this embodiment, the user configures the alarm threshold of the key process flow in the industrial network security management system. The industrial network security management system grabs traffic from the switch layer, parses the process parameters, and compares them with the configured alarm threshold, generates an alarm according to the comparison result and pushes it to the administrator of the MES system. This embodiment directly grabs traffic at the controller layer switch and parses out the process point values, avoiding the risk of tampering during the data transmission process. This embodiment deeply analyzes industrial protocols (such as M6 / M7), extracts key process parameters, and improves the accuracy and pertinence of the parsing. This embodiment can also implement real-time alarms in the network security audit system, without relying on the data transmission of the MES system, ensuring the timeliness and reliability of the alarms. This embodiment quickly parses out the process point values by querying the point value template, improving the efficiency and scalability of the system.
[0089] In summary, the method of this embodiment directly obtains the process point values from the production manufacturing layer switch, avoiding the transmission of the process point value parameters in the network; completely eliminating the possibility of the process flow parameters being tampered with during the network transmission process, improving the real-time performance and reliability of the process parameter monitoring, and effectively preventing the impact of network attacks on the process flow. The process point value alarm of the network audit product in this embodiment is a supplement to the alarm of the MES system.
[0090] The method of this embodiment is applicable to multiple industrial control systems in the fields of chemical industry, electric power, manufacturing, etc., for real-time monitoring of process flow parameters and preventing the parameters from being tampered with during the transmission process. The method of this embodiment is suitable for large-scale promotion and use. The above embodiment is described by taking the M6 / M7 industrial protocol as an example, and this embodiment can also be compatible with multiple industrial protocols, including but not limited to the MODBUS protocol and the SMB protocol.
[0091] See Figure 6 , the process flow alarm device provided in this embodiment is applied to an industrial network security audit server. The industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module; the device of this embodiment includes a threshold acquisition module 100, a traffic capture module 200, a traffic parsing module 300, and a comparison module 400.
[0092] The threshold acquisition module 100 is used to acquire the alarm threshold of the process parameters input by the user. The traffic capture module 200 is used to acquire the traffic data of the switch; wherein, the traffic data is the data sent by the process parameter acquisition module to the switch. The traffic analysis module 300 is used to analyze the traffic data to obtain the target process parameters. The comparison module 400 is used to determine whether the target process parameters exceed the alarm threshold of the process parameters; if so, an alarm message is generated and sent to the production management terminal; otherwise, the step of acquiring the traffic data of the switch is returned and executed continuously.
[0093] In an alternative embodiment, the process parameter acquisition module includes a controller and at least one process parameter acquisition sensor, the at least one process parameter acquisition sensor is connected to the controller, and the controller is connected to the switch.
[0094] In an alternative embodiment, the traffic analysis module 300 includes a protocol identification module, a protocol judgment module, and a traffic analysis module. The protocol identification module is used to analyze the traffic data to obtain the protocol type and protocol data. The protocol judgment module is used to judge whether the protocol type is the target communication protocol, if so, the next step is continued; otherwise, the step of acquiring the traffic data of the switch is returned and executed again; wherein, the target communication protocol is the communication protocol between the controller and the switch. The traffic analysis module is used to analyze the protocol data according to the pre-established analysis library to determine the target process parameters, wherein, the analysis library is established according to the target communication protocol.
[0095] In an alternative embodiment, the protocol identification module includes a MAC layer analysis module, a network layer analysis module, a transport layer analysis module, an application layer analysis module, and a protocol matching module. The MAC layer analysis module is used to perform MAC layer analysis on the traffic data to obtain the source MAC address and the destination MAC address. The network layer analysis module is used to perform network layer analysis on the traffic data to obtain the source IP address and the destination IP address. The transport layer analysis module is used to perform transport layer analysis on the traffic data to obtain the source port, the destination port, and the transport layer protocol. The application layer analysis module is used to perform application layer analysis on the traffic data to obtain industrial protocol data. The protocol matching module is used to perform matching identification on the industrial protocol data by using the pre-established protocol matching engine to determine the protocol type and extract the protocol data.
[0096] In an alternative embodiment, the protocol matching engine performs matching by using one or more of the definition of protocol fields, data format, protocol features, and a pre-determined rule library; wherein, the data format includes the length of the data packet, the order of fields in the data packet, and the arrangement manner of fields in the data packet.
[0097] In an alternative embodiment, the device further includes a security analysis module configured to perform security analysis based on one or more of the source MAC address, destination MAC address, source IP address, destination IP address, source port, destination port, transport layer protocol, and industrial protocol to determine the attack source and attack target.
[0098] In an alternative embodiment, the traffic analysis module includes a template acquisition module, a key field extraction module, a target monitoring point determination module, a traversal module, and a parsed point information module. The template acquisition module is configured to acquire a pre-established list of point templates; wherein, the items in the list of point templates include a tag number item, an item number item, a data area item, an offset item, a data length item, a value item, and a value type item; wherein, the tag number item represents the unique identifier of the point, the item number item represents the data name, the data area item represents the area number where the data is stored, and the offset item represents the starting position of the data in the data area. The key field extraction module is configured to obtain key fields from the protocol data, the key fields including a function code, a data area, an offset, and a data length; wherein, the function code represents the operation type, and the operation type includes read and write. The target monitoring point determination module is configured to determine the target monitoring point according to the data area, offset, and length in the key fields. The traversal module is configured to traverse the list of point templates according to the target monitoring point to determine the point information that matches the target monitoring point. The parsed point information module is configured to parse the point information to obtain the target process parameters.
[0099] By using the device provided in the embodiment of the present application, since the device has the same inventive concept as the above-mentioned method provided in the embodiment of the present application, on the premise that the method can solve the technical problem, the device can also solve the technical problem, and details are not described herein again.
[0100] See Figure 7 , the industrial control system 700 provided in this embodiment includes a switch 710 and at least one process parameter acquisition module 720, an industrial network security audit server 730, and a production management terminal 740 respectively connected to the switch 710. The process parameter acquisition module 720 is configured to acquire process parameters in the industrial production link and send the process parameters to the switch 710. The industrial network security audit server 730 is configured to obtain traffic data from the switch 710, process the traffic data by using the foregoing process flow warning method to obtain warning information, and send the warning information to the production management terminal 740. Here, the warning information is sent to the production management terminal 740 through a dedicated interface.
[0101] By using the system provided in the embodiments of the present application, since the system has the same inventive concept as the above-mentioned method provided in the embodiments of the present application, on the premise that the method can solve technical problems, the device can also solve technical problems, and details are not described herein again.
[0102] Referring to Figure 8 , an embodiment of the present invention further provides an electronic device 1000, including a communication interface 1001, a processor 1002, a memory 1003, and a bus 1004. The processor 1002, the communication interface 1001, and the memory 1003 are connected through the bus 1004; the above-mentioned memory 1003 is used to store a computer program that supports the processor 1002 to execute the above-mentioned process flow warning method, and the above-mentioned processor 1002 is configured to execute the program stored in the memory 1003.
[0103] Optionally, an embodiment of the present invention further provides a computer-readable medium having non-volatile program code executable by the processor 1002, and the program code causes the processor 1002 to execute the process flow warning method in the above-mentioned embodiment.
[0104] As is known by technical common sense, the present invention can be implemented by other embodiments that do not depart from its spirit or essential features. Therefore, the above-disclosed embodiments are illustrative in all aspects and not exclusive. All changes within the scope of the present invention or equivalent to the present invention are encompassed by the present invention.
Claims
1. A process flow alarm method, characterized in that: Applied to an industrial network security audit server, the industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module; the method includes: Obtain the process parameter alarm threshold value input by the user; Acquire flow data of the switch; wherein the flow data is data sent by the process parameter acquisition module to the switch; Analyzing the flow data to obtain target process parameters; Determine whether the target process parameter exceeds the process parameter alarm threshold; if so, generate an alarm message and send the alarm message to the production management terminal; otherwise, return to the step of obtaining the flow data of the switch and continue to execute.
2. The process flow alarm method according to claim 1, characterized in that: The process parameter acquisition module includes a controller and at least one process parameter acquisition sensor, the at least one process parameter acquisition sensor is connected to the controller, and the controller is connected to the switch.
3. The process flow alarm method according to claim 2, characterized in that: The flow data is analyzed to obtain target process parameters, including: Parsing the traffic data to obtain a protocol type and protocol data; Determine whether the protocol type is the target communication protocol, if yes, proceed to the next step; otherwise, return to the step of obtaining the flow data of the switch and re-execute; wherein the target communication protocol is the communication protocol between the controller and the switch; The protocol data is parsed according to a pre-established parsing library to determine the target process parameters, wherein the parsing library is established according to the target communication protocol.
4. The process flow alarm method according to claim 3, characterized in that: The parsing of the traffic data to obtain the protocol type and protocol data includes: Perform MAC layer analysis on the traffic data to obtain a source MAC address and a destination MAC address; Performing network layer analysis on the traffic data to obtain a source IP address and a destination IP address; Performing transport layer analysis on the traffic data to obtain a source port, a destination port and a transport layer protocol; Performing application layer analysis on the flow data to obtain industrial protocol data; The industrial protocol data is matched and identified using a pre-established protocol matching engine, the protocol type is determined, and the protocol data is extracted.
5. The process flow alarm method according to claim 4, characterized in that: The protocol matching engine uses one or more of the definition of protocol fields, data formats, protocol features and a predetermined rule base for matching; wherein the data format includes the length of the data packet, the order of fields in the data packet, and the arrangement of fields in the data packet.
6. The process flow alarm method according to claim 4, characterized in that: The method further comprises: Security analysis is performed based on one or more of the source MAC address, destination MAC address, source IP address, destination IP address, source port, destination port, transport layer protocol and industrial protocol to determine the attack source and attack target.
7. The process flow alarm method according to claim 3, characterized in that: The step of parsing the protocol data according to a pre-established parsing library to determine the target process parameters includes: Obtain a pre-established point template list; wherein the items in the point template list include a bit number item, an item number item, a data area item, an offset item, a data length item, a value item, and a value type item; wherein the bit number item represents a unique identifier of the point, the item number item represents a data name, the data area item represents an area number for data storage, and the offset item represents a starting position of the data in the data area; Acquire key fields from the protocol data, the key fields including function code, data area, offset and data length; wherein the function code represents an operation type, and the operation type includes read and write; Determine the target monitoring point according to the data area, offset and length in the key field; Traversing the point template list according to the target monitoring point, determining the point information matching the target monitoring point; The point information is analyzed to obtain the target process parameters.
8. A process flow alarm device, characterized in that: Applied to an industrial network security audit server, the industrial network security audit server is connected to a switch, and the switch is respectively connected to a production management terminal and at least one process parameter acquisition module; the device comprises: A threshold acquisition module is used to obtain the process parameter alarm threshold input by the user; A flow capture module, used to obtain flow data of the switch; wherein the flow data is the data sent by the process parameter acquisition module to the switch; A flow analysis module, used to analyze the flow data to obtain target process parameters; The comparison module is used to determine whether the target process parameter exceeds the process parameter alarm threshold; if so, generate an alarm message and send the alarm message to the production management terminal; otherwise, return to the step of obtaining the flow data of the switch to continue execution.
9. An industrial control system, characterized in that: It includes a switch and at least one process parameter acquisition module, an industrial network security audit server and a production management terminal respectively connected to the switch; The process parameter collection module is used to collect process parameters in the industrial production process and send the process parameters to the switch; The industrial network security audit server is used to obtain flow data from the switch, and process the flow data using the process flow alarm method described in any one of claims 1-7 to obtain alarm information, and send the alarm information to the production management terminal.
10. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of claims 1 to 7 when executing the computer program.