An industrial Internet security control method for complex attacks
By analyzing the risk equipment rate and risk impact values in the production process, setting and dynamically updating security control strategies, the shortcomings of traditional security defense methods in the face of complex attacks are solved, and targeted and dynamic defense of the industrial Internet is achieved.
Patent Information
- Application Number
- CN202510749254.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Traditional security defense methods are difficult to achieve effective defense and dynamic regulation when facing complex attacks from unknown software vulnerabilities and new malware, and cannot effectively control the industrial Internet.
By analyzing the risk equipment rate and risk impact values of the production links connected to the industrial Internet, setting corresponding security control policies and dynamically updates based on the attack situation, including calculation of risk equipment rate, historical intrusion analysis, dynamic adjustment of security control policies and real-time monitoring.
It realizes targeted defense and dynamic defense of the industrial Internet, and can conduct intelligent analysis and dynamic regulation when facing complex attacks, improving the pertinence and effectiveness of security defense.
Smart Images

Figure CN120263564B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of industrial Internet technology, and specifically is an industrial Internet security control method oriented towards complex attacks. Background Art
[0002] The Industrial Internet has entered a new stage of large-scale development. Its infrastructure continues to strengthen, its technological innovation capabilities steadily increase, and its industry scale continues to expand, driving its development and becoming increasingly prominent. However, with the rapid development of the Industrial Internet, security issues are also becoming increasingly prominent. Traditional security defenses are often ineffective against new and complex attacks, and the security of the Industrial Internet faces severe challenges.
[0003] In existing technologies, when facing complex attacks from unknown software vulnerabilities and new malware, the Industrial Internet has deployed multiple security protection systems such as firewalls, intrusion detection systems, and antivirus gateways. However, due to the unified security control methods set up in the numerous generation links connected to the Industrial Internet, traditional security control methods are unable to effectively and specifically defend against complex attacks. At the same time, traditional security control methods are also unable to dynamically adjust their own defenses.
[0004] To this end, the present invention proposes an industrial Internet security control method oriented to complex attacks. Summary of the Invention
[0005] The purpose of the present invention is to provide an industrial Internet security control method resistant to complex attacks in order to address the deficiencies in the prior art.
[0006] The technical problems to be solved by the present invention are:
[0007] How to achieve targeted and dynamic defense of the Industrial Internet in the face of complex attacks.
[0008] In order to achieve the above object, the present invention adopts the following technical solutions:
[0009] An industrial Internet security control method for complex attacks, the method comprising:
[0010] Step S1: Analyze the network connection risk of the production link connected to the industrial Internet to obtain the risk equipment rate of the production link;
[0011] Step S2: Analyze the historical intrusion situation of the production links connected to the industrial Internet and obtain the risk impact value of the production links;
[0012] Step S3: Setting corresponding security control policies for production links connected to the industrial Internet based on the risk equipment rate and risk impact value;
[0013] Step S4: Dynamically update the security control strategy of the production links connected to the industrial Internet based on the attack situation.
[0014] Furthermore, the step S1 includes the following sub-steps:
[0015] Step S11: Obtain the production equipment data corresponding to the production process connected to the industrial Internet, and obtain the number of networked devices in the production process and the commissioning time, maintenance number and safety protection level of each networked device;
[0016] Production equipment data includes the number of networked devices in the production process connected to the Industrial Internet, as well as the commissioning time, maintenance times, and safety protection level of each networked device. The safety protection level includes the first safety protection level, the second safety protection level, and the third safety protection level. The protection effect of the first safety protection level is higher than that of the second safety protection level, and the protection effect of the second safety protection level is higher than that of the third safety protection level.
[0017] Step S12: Calculate the risk equipment rate of the production process based on the production equipment data.
[0018] Furthermore, the calculation process of the risk equipment rate includes:
[0019] Step S121: Subtract the time of use from the current time to obtain the usage time STiu of each network-connected device in the production link, where i is the number of the production link and u is the number of the network-connected device;
[0020] Step S122: Mark the maintenance times of each network-connected device in the production process as WCiu, and obtain the safety protection coefficient FXiu of each network-connected device in the production process according to the safety protection level; wherein the safety protection level is proportional to the safety protection coefficient;
[0021] Step S123, calculate the network connection risk value Fiu of each network-connected device in the production process by using the formula, which is as follows:
[0022] Fiu = (STiu / ST + WCiu / WC) / (FXiu / FX); where ST is the standard value corresponding to the service life, WC is the standard value corresponding to the number of maintenance times, and FX is the standard value corresponding to the safety protection factor.
[0023] Step S124: The network access risk value is compared with the network access risk threshold. If the network access risk value is greater than or equal to the network access risk threshold, the corresponding network access device is marked as a risky network access device. If the network access risk value is less than the network access risk threshold, no operation is performed.
[0024] Step S125, counting the number of risky network access devices and recording it as the number of risky network access devices;
[0025] Step S126, obtaining the number of networked devices in the production process, and comparing the number of risky networked devices with the number of networked devices to obtain the risky device rate of the production process.
[0026] Furthermore, step S2 includes the following sub-steps:
[0027] Step S21, obtaining network intrusion data corresponding to the production link connected to the industrial Internet;
[0028] Network intrusion data includes the number of network intrusions in production links connected to the Industrial Internet, as well as the number of network-connected devices in the production link that were paralyzed due to each network intrusion, the duration of the equipment paralysis, and the production progress delays caused by each network intrusion;
[0029] Step S22, marking the number of network intrusions in the production link connected to the industrial Internet as RQi;
[0030] Step S23, marking the number of devices paralyzed in the production link caused by each network intrusion as THi, and marking the duration of the device paralysis caused by each network intrusion as TTi;
[0031] Step S24, each time a network intrusion causes a production delay, the production progress is marked as DWi;
[0032] In step S25, the risk impact value FYi of the networked device connected to the Industrial Internet is calculated by the formula, which is as follows:
[0033] FYi=[(RQi / RQ)×a1+(THi / TH)×a2+(TTi / TT)×a3]×DWi;
[0034] In the above formula, RQ is the standard value of the number of network intrusions, TH is the standard value of the number of device paralysis, TT is the standard value of the device paralysis duration, and a1, a2, and a3 are proportional coefficients.
[0035] Furthermore, when the number of products in stalled production is [X1, X2], the production delay progress is S1;
[0036] When the number of products in stagnant production is (X2, X3], the production delay progress is S2;
[0037] When the number of products in stagnant production is (X3, X4], the production delay progress is S3;
[0038] When the number of products in stagnant production is (X4, ∞), the production delay progress is S4; among them, X1, X2, X3 and X4 are all positive integers, 0<X1<X2<X3<X4, 0<S1<S2<S3<S4.
[0039] Furthermore, step S3 includes the following sub-steps:
[0040] Step S31, obtaining the risk equipment rate FLi and risk impact value FYi of the production link;
[0041] Step S32, calculating the risk value Fi of the production link connected to the industrial Internet by the formula Fi = FLi × FYi;
[0042] Step S33: If the risk value is less than or equal to the first risk threshold, the production link connected to the industrial Internet executes the third security control strategy;
[0043] If the risk value is greater than the first risk threshold and less than or equal to the second risk threshold, the production link connected to the industrial Internet will execute the second security control strategy;
[0044] If the risk value is greater than the second risk threshold, the production link connected to the industrial Internet will execute the first security control strategy; wherein, the second risk threshold is greater than the first risk threshold.
[0045] Furthermore, the security strength of the first security control strategy is higher than the security strength of the second security control strategy, and the security strength of the second security control strategy is higher than the security strength of the third security control strategy.
[0046] Furthermore, step S4 includes the following sub-steps:
[0047] Step S41, setting a virtual folder for a networked device in a production link connected to the industrial Internet, wherein the virtual folder contains a specified number of test files;
[0048] Step S42: When it is detected that the industrial Internet is facing a network attack, an integrity check and a file attribute check are performed on the test file in the virtual folder;
[0049] Step S43: If the integrity check and the file attribute check of the test file both pass, the test file is recorded as the original file; if either the integrity check or the file attribute check of the test file fails, the test file is recorded as a tampered file;
[0050] Step S44 , counting the number of tampered files and recording it as the number of tampered files, comparing the number of tampered files with the total number of test files, and obtaining the tampering rate of test files in the virtual folders corresponding to different production links.
[0051] Furthermore, the step S4 further includes the following sub-steps:
[0052] Step S45: Obtain the preset tampering rate corresponding to the production link according to the executed security control strategy, specifically:
[0053] If it is the third security control strategy, the preset tampering rate is Y3;
[0054] If it is the second security control strategy, the preset tampering rate is Y2;
[0055] If it is the first security control strategy, the preset tampering rate is Y1; wherein Y1<Y2<Y3;
[0056] Step S46, comparing the tampering rate of the test file in the virtual folder with the preset tampering rate corresponding to the production process;
[0057] Step S47: If the tampering rate is less than or equal to the preset tampering rate, no operation is performed;
[0058] If the tampering rate is greater than the preset tampering rate, the corresponding security control strategy will be set in the production process for upgrading.
[0059] Furthermore, the verification process of integrity check is:
[0060] Calculate and save the hash value of the test file in advance. When a network attack occurs, calculate the hash value of the test file again and compare it with the previously saved hash value.
[0061] If the two calculated hash values are consistent, the integrity of the test file is not compromised;
[0062] If the two calculated hash values are inconsistent, it means that the integrity of the test file is destroyed.
[0063] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:
[0064] 1. The present invention analyzes the network connection risk of the production links connected to the Industrial Internet, obtains the risk equipment rate of the production links through analysis, and realizes intelligent analysis of the network connection risk of the corresponding production links connected to the Industrial Internet;
[0065] 2. The present invention analyzes the historical intrusion situations of the production links connected to the Industrial Internet, obtains the risk impact value of the production links through analysis, and realizes the analysis and judgment of the historical intrusion situations of the corresponding production links connected to the Industrial Internet;
[0066] 3. This invention combines the risk equipment rate and risk impact value to set corresponding security control strategies for the production links connected to the Industrial Internet, thus achieving targeted defense against the Industrial Internet in the face of complex attacks;
[0067] 4. When facing complex attacks, the present invention dynamically updates the security control strategy of the production links connected to the industrial Internet according to the attack situation, and can dynamically adjust the corresponding defense system of the industrial Internet to achieve dynamic defense. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 is a flow chart of the steps of the present invention;
[0069] Figure 2 This is a flowchart of the sub-steps corresponding to step S1 in the present invention;
[0070] Figure 3 Flow chart of the steps corresponding to the sub-steps of step S2 in the present invention;
[0071] Figure 4 Flow chart of the steps corresponding to the sub-steps of step S3 in the present invention;
[0072] Figure 5 Flow chart of the steps corresponding to the sub-steps of step S4 in the present invention;
[0073] Figure 6 Flow chart of the steps corresponding to the sub-steps of step S6 in the present invention;
[0074] Figure 7 It is a structural schematic diagram of the electronic device in the present invention. DETAILED DESCRIPTION
[0075] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0076] Example 1: Please refer to Figures 1-6 As shown, the technical solution provided by the present invention is: an industrial Internet security control method for complex attacks, mainly used for security control of various production links in smart factories, and realizing network control of industrial equipment used in various production links through the industrial Internet. The method includes:
[0077] Step S1: Analyze the network connection risk of the production link connected to the industrial Internet to obtain the risk equipment rate of the production link;
[0078] For example, the production process may include product material screening, product material processing, product packaging, etc., which are not specifically limited here;
[0079] In this embodiment, step S1 includes the following sub-steps:
[0080] Step S11: Obtain the production equipment data corresponding to the production process connected to the industrial Internet, and obtain the number of networked devices in the production process and the commissioning time, maintenance number and safety protection level of each networked device;
[0081] It should be specified that the production equipment data refers to the number of networked devices in the production process connected to the Industrial Internet, as well as the commissioning time, maintenance times, and safety protection level of each networked device. The safety protection level is obtained from the nameplate on the production equipment. The safety protection level includes the first safety protection level, the second safety protection level, and the third safety protection level. The protection effect of the first safety protection level is higher than that of the second safety protection level, and the protection effect of the second safety protection level is higher than that of the third safety protection level.
[0082] Step S12: Calculate the risk equipment rate of the production process based on the production equipment data. The specific calculation process of the risk equipment rate is as follows:
[0083] Step S121: Subtract the time of use from the current time to obtain the usage time STiu of each network-connected device in the production link, where i is the number of the production link and u is the number of the network-connected device;
[0084] Step S122: Mark the maintenance times of each network-connected device in the production link as WCiu, and obtain the safety protection coefficient FXiu of each network-connected device in the production link according to the safety protection level; wherein the safety protection level is proportional to the safety protection coefficient, that is, the better the protection effect of the safety protection level, the larger the value of the safety protection coefficient. For example, the safety protection coefficient corresponding to the first safety protection level is 1.3, the safety protection coefficient corresponding to the second safety protection level is 1.2, and the safety protection coefficient corresponding to the third safety protection level is 1.1;
[0085] Step S123, calculate the network connection risk value Fiu of each network-connected device in the production process by using the formula, which is as follows:
[0086] Fiu = (STiu / ST + WCiu / WC) / (FXiu / FX); where ST is the standard value corresponding to the service life, WC is the standard value corresponding to the number of maintenance times, and FX is the standard value corresponding to the safety protection factor. The standard values are used to remove the units of each parameter.
[0087] Step S124: The network access risk value is compared with the network access risk threshold. If the network access risk value is greater than or equal to the network access risk threshold, the corresponding network access device is marked as a risky network access device. If the network access risk value is less than the network access risk threshold, no operation is performed.
[0088] Step S125, counting the number of risky network access devices and recording it as the number of risky network access devices;
[0089] Step S126, obtaining the number of networked devices in the production process, and comparing the number of risky networked devices with the number of networked devices to obtain the risky device rate of the production process.
[0090] Step S2: Analyze the historical intrusion situation of the production links connected to the industrial Internet and obtain the risk impact value of the production links;
[0091] In this embodiment, step S2 includes the following sub-steps:
[0092] Step S21, obtaining network intrusion data corresponding to the production link connected to the industrial Internet;
[0093] It should be specified that the network intrusion data refers to the number of network intrusions in the production process connected to the Industrial Internet, as well as the number of network-connected devices in the production process that were paralyzed due to each network intrusion, the duration of the equipment paralysis, and the production progress delays caused by each network intrusion. The equipment paralysis duration is the maximum duration of paralysis of network-connected devices, and the production delay progress is calculated as the number of products whose production was halted due to paralysis of network-connected devices due to network intrusions.
[0094] Specifically, when the number of products in stalled production is [X1, X2], the production delay progress is S1;
[0095] When the number of products in stagnant production is (X2, X3], the production delay progress is S2;
[0096] When the number of products in stagnant production is (X3, X4], the production delay progress is S3;
[0097] When the number of products that are stalled is (X4,∞), the production delay is S4; where X1, X2, X3 and X4 are all positive integers, 0<X1<X2<X3<X4, 0<S1<S2<S3<S4;
[0098] Step S22, marking the number of network intrusions in the production link connected to the industrial Internet as RQi;
[0099] Step S23, marking the number of devices paralyzed in the production link caused by each network intrusion as THi, and marking the duration of the device paralysis caused by each network intrusion as TTi;
[0100] Step S24, each time a network intrusion causes a production delay, the production progress is marked as DWi;
[0101] In step S25, the risk impact value FYi of the networked device connected to the Industrial Internet is calculated by the formula, which is as follows:
[0102] FYi=[(RQi / RQ)×a1+(THi / TH)×a2+(TTi / TT)×a3]×DWi;
[0103] In the above formula, RQ is the standard value of the number of network intrusions, TH is the standard value of the number of device paralysis, TT is the standard value of the device paralysis duration, and a1, a2, and a3 are proportional coefficients.
[0104] Step S3: Setting corresponding security control policies for production links connected to the industrial Internet based on the risk equipment rate and risk impact value;
[0105] In this embodiment, step S3 includes the following sub-steps:
[0106] Step S31, obtaining the risk equipment rate FLi and risk impact value FYi of the production link obtained by the above calculation;
[0107] Step S32, calculating the risk value Fi of the production link connected to the industrial Internet by the formula Fi = FLi × FYi;
[0108] Step S33: Compare the risk value with the risk threshold to determine whether the production link connected to the industrial Internet should implement the corresponding security control strategy, specifically:
[0109] If the risk value is less than or equal to the first risk threshold, the production link connected to the industrial Internet will execute the third security control strategy;
[0110] If the risk value is greater than the first risk threshold and less than or equal to the second risk threshold, the production link connected to the industrial Internet will execute the second security control strategy;
[0111] If the risk value is greater than the second risk threshold, the first security control strategy is executed in the production link connected to the industrial Internet; wherein the second risk threshold is greater than the first risk threshold, the security strength of the first security control strategy is greater than the security strength of the second security control strategy, and the security strength of the second security control strategy is greater than the security strength of the third security control strategy;
[0112] In this embodiment, the security control strategy refers to a multi-layered defense system for the production process. The defense system of the first security control strategy includes network layer security protection, system layer security protection, and data layer security protection. The defense system of the second security control strategy includes system layer security protection and data layer security protection. The defense system of the third security control strategy includes data layer security protection.
[0113] Among them, network layer security protection adopts advanced network security technologies, such as industrial firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), etc., to monitor and filter network traffic in real time to prevent the intrusion of malicious traffic; system layer security protection is to strengthen the security of operating systems, databases, application software, etc. in industrial Internet systems to prevent vulnerabilities from being exploited. At the same time, security auditing and log analysis technologies are used to record and analyze system operations to detect abnormal behaviors in a timely manner; data layer security protection adopts data encryption, data backup, data recovery and other technologies to ensure the confidentiality, integrity and availability of data. At the same time, a data access control mechanism is established to strictly control data access rights.
[0114] Step S4, dynamically updating the security control strategy of the production link connected to the industrial Internet based on the attack situation;
[0115] In this embodiment, step S4 includes the following sub-steps:
[0116] Step S41: Setting a virtual folder for a networked device in a production link connected to the Industrial Internet, wherein a specified number of test files are stored in the virtual folder; wherein no security control policy is set for the virtual folder or the test files;
[0117] Step S42: When it is detected that the industrial Internet is facing a network attack, an integrity check and a file attribute check are performed on the test file in the virtual folder;
[0118] In specific implementation, integrity verification can be achieved through hash value verification, check code verification, digital signature verification, etc. In this embodiment, it is preferred to determine whether the test file has been tampered with by hash value verification; file attribute inspection can be achieved by file size change, file name garbled characters, content garbled characters, etc.
[0119] The hash value verification is as follows: the hash value of the test file is calculated and saved in advance. When a network attack occurs, the hash value of the test file is calculated again and compared with the previously saved hash value. If the two calculated results are consistent, it means that the integrity of the test file has not been damaged. If they are inconsistent, it means that the integrity of the test file has been damaged.
[0120] Step S43: If the integrity check and the file attribute check of the test file both pass, the test file is recorded as the original file; if either the integrity check or the file attribute check of the test file fails, the test file is recorded as a tampered file;
[0121] Step S44, counting the number of tampered files and recording it as the number of tampered files, comparing the number of tampered files with the total number of test files, and obtaining the tampering rate of test files in the virtual folders corresponding to different production links;
[0122] Step S45: Obtain the preset tampering rate corresponding to the production link according to the executed security control strategy, specifically:
[0123] If it is the third security control strategy, the preset tampering rate is Y3;
[0124] If it is the second security control strategy, the preset tampering rate is Y2;
[0125] If it is the first security control strategy, the preset tampering rate is Y1; wherein Y1<Y2<Y3;
[0126] Step S46, comparing the tampering rate of the test file in the virtual folder with the preset tampering rate corresponding to the production process;
[0127] Step S47: If the tampering rate is less than or equal to the preset tampering rate, no operation is performed;
[0128] If the tampering rate is greater than the preset tampering rate, the corresponding security control strategy set in the production link will be upgraded;
[0129] In this embodiment, upgrading means: when the tampering rate is greater than the preset tampering rate, if the security control strategy of the production link is the second security control strategy, the security control strategy of the production link is dynamically updated to the first security control strategy; when the tampering rate is greater than the preset tampering rate, if the security control strategy of the production link is the first security control strategy, the defense system in the security control strategy corresponding to the production link is added on the basis of the first security control strategy.
[0130] As a further solution of this embodiment, when the tampering rate is greater than a preset tampering rate, each networked device in the production link connected to the industrial Internet is monitored, and the industrial Internet security control method further includes:
[0131] Step S5, obtaining real-time device data of networked devices in the production process connected to the Industrial Internet;
[0132] Among them, the real-time device data is the real-time download speed and real-time upload speed of the networked device at different time points;
[0133] Step S6: Perform security monitoring on networked devices in the production process connected to the Industrial Internet based on real-time device data;
[0134] In this embodiment, step S6 includes the following sub-steps:
[0135] Step S61, setting the monitoring duration of the networked device and setting multiple time points within the monitoring duration;
[0136] Step S62, obtaining the real-time download speed and real-time upload speed of the network access device at different time points;
[0137] Step S63: Calculate the difference in real-time download speed between adjacent time points and take the absolute value to obtain the download speed fluctuation value. Similarly, calculate the difference in real-time download speed between adjacent time points and take the absolute value to obtain the upload speed fluctuation value.
[0138] Step S64: If the download speed fluctuation value between any adjacent time points is greater than the download speed fluctuation threshold or the upload speed fluctuation value between any adjacent time points is greater than the upload speed fluctuation threshold, a device abnormality signal is generated;
[0139] Step S65: If the download speed fluctuation value between all adjacent time points is less than or equal to the download speed fluctuation threshold, and the upload speed fluctuation value between all adjacent time points is less than or equal to the upload speed fluctuation threshold, then a device normal signal is generated;
[0140] In fact, when an abnormal device signal is generated, the corresponding network-connected device will be shut down and disconnected from the industrial Internet.
[0141] In this application, if a corresponding calculation formula appears, the above calculation formula is dimensionless and its numerical calculation is performed. The weight coefficient, proportional coefficient and other coefficients in the formula are set to a result value obtained by quantifying each parameter. Regarding the size of the weight coefficient and the proportional coefficient, as long as it does not affect the proportional relationship between the parameter and the result value, it is acceptable.
[0142] Example 2: Figure 7 As shown, this embodiment provides an electronic device, which may include: a processor, a communication interface, a memory, and a system bus, wherein the processor, the communication interface, and the memory communicate with each other through the system bus. The processor can call the logic instructions in the memory to execute an industrial Internet security control method for complex attacks, the method comprising: analyzing the network access risk of the production link connected to the industrial Internet, and analyzing to obtain the risk device rate of the production link; analyzing the historical intrusion situation of the production link connected to the industrial Internet, and analyzing to obtain the risk impact value of the production link; setting a corresponding security control strategy for the production link connected to the industrial Internet based on the risk device rate and the risk impact value; dynamically updating the security control strategy of the production link connected to the industrial Internet according to the attack situation; obtaining real-time device data of the networked devices in the production link connected to the industrial Internet; and performing security monitoring on the networked devices in the production link connected to the industrial Internet based on the real-time device data.
[0143] In addition, the logical instructions in the above-mentioned memory can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0144] Example 3: The present application also provides a computer program product, which includes a computer program stored on a computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute an industrial Internet security control method for complex attacks provided by the above methods, the method including: analyzing the network connection risk situation of the production link connected to the industrial Internet, and analyzing to obtain the risk equipment rate of the production link; analyzing the historical intrusion situation of the production link connected to the industrial Internet, and analyzing to obtain the risk impact value of the production link; setting corresponding security control strategies for the production link connected to the industrial Internet based on the risk equipment rate and the risk impact value; dynamically updating the security control strategies of the production link connected to the industrial Internet according to the attack situation; obtaining real-time device data of network-connected devices in the production link connected to the industrial Internet; and performing security monitoring of network-connected devices in the production link connected to the industrial Internet based on the real-time device data.
[0145] Example 4: The present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the above-mentioned industrial Internet security control method for complex attacks, the method comprising: analyzing the network connection risk situation of the production link connected to the industrial Internet, and obtaining the risk equipment rate of the production link through analysis; analyzing the historical intrusion situation of the production link connected to the industrial Internet, and obtaining the risk impact value of the production link through analysis; setting a corresponding security control strategy for the production link connected to the industrial Internet based on the risk equipment rate and the risk impact value; dynamically updating the security control strategy of the production link connected to the industrial Internet according to the attack situation; obtaining real-time device data of networked devices in the production link connected to the industrial Internet; and performing security monitoring of networked devices in the production link connected to the industrial Internet based on the real-time device data.
[0146] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0147] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0148] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An industrial Internet security control method for complex attacks, characterized by: The specific steps are as follows: Step S1: Analyze the network connection risk of the production link connected to the industrial Internet to obtain the risk equipment rate of the production link; Step S2: Analyze the historical intrusion situation of the production links connected to the industrial Internet and obtain the risk impact value of the production links; Step S3: Setting corresponding security control policies for production links connected to the industrial Internet based on the risk equipment rate and risk impact value; Step S4, dynamically updating the security control strategy of the production link connected to the industrial Internet based on the attack situation; Wherein, step S2 includes the following sub-steps: Step S21, obtaining network intrusion data corresponding to the production link connected to the industrial Internet; Network intrusion data includes the number of network intrusions in production links connected to the Industrial Internet, the number of network-connected devices in the production link that were paralyzed due to each network intrusion, the duration of the paralysis, and the delay in production progress caused by each network intrusion; Step S22, marking the number of network intrusions in the production link connected to the industrial Internet as RQi; Step S23, marking the number of devices paralyzed in the production link caused by each network intrusion as THi, and marking the duration of the device paralysis caused by each network intrusion as TTi; Step S24, each time a network intrusion causes a production delay, the production progress is marked as DWi; In step S25, the risk impact value FYi of the networked device connected to the Industrial Internet is calculated by the formula, which is as follows: FYi=[(RQi / RQ)×a1+(THi / TH)×a2+(TTi / TT)×a3]×DWi; where RQ is the standard value of the number of network intrusions, TH is the standard value of the number of device paralysis, TT is the standard value of the device paralysis duration, and a1, a2, and a3 are proportional coefficients. Wherein, step S3 includes the following sub-steps: Step S31, obtaining the risk equipment rate FLi and risk impact value FYi of the production link; Step S32, calculating the risk value Fi of the production link connected to the industrial Internet by the formula Fi = FLi × FYi; Step S33: If the risk value is less than or equal to the first risk threshold, the production link connected to the industrial Internet executes the third security control strategy; If the risk value is greater than the first risk threshold and less than or equal to the second risk threshold, the production link connected to the industrial Internet will execute the second security control strategy; If the risk value is greater than a second risk threshold, the production link connected to the industrial Internet executes the first security control strategy; wherein the second risk threshold is greater than the first risk threshold; The security strength of the first security control strategy is higher than that of the second security control strategy, and the security strength of the second security control strategy is higher than that of the third security control strategy.
2. The industrial Internet security control method for complex attacks according to claim 1 is characterized in that: Step S1 includes the following sub-steps: Step S11: Obtain the production equipment data corresponding to the production process connected to the industrial Internet, and obtain the number of networked devices in the production process and the commissioning time, maintenance number and safety protection level of each networked device; Production equipment data includes the number of networked devices in the production process connected to the Industrial Internet, as well as the commissioning time, maintenance times, and safety protection level of each networked device. The safety protection level includes the first safety protection level, the second safety protection level, and the third safety protection level. The protection effect of the first safety protection level is higher than that of the second safety protection level, and the protection effect of the second safety protection level is higher than that of the third safety protection level. Step S12: Calculate the risk equipment rate of the production process based on the production equipment data.
3. The industrial Internet security control method for complex attacks according to claim 2 is characterized in that: The calculation process of risk equipment rate includes: Step S121: Subtract the time of use from the current time to obtain the usage time STiu of each network-connected device in the production link, where i is the number of the production link and u is the number of the network-connected device; Step S122: Mark the maintenance times of each network-connected device in the production process as WCiu, and obtain the safety protection coefficient FXiu of each network-connected device in the production process according to the safety protection level; wherein the safety protection level is proportional to the safety protection coefficient; Step S123, calculate the network connection risk value Fiu of each network-connected device in the production process through the formula, the specific formula is as follows: Fiu = (STiu / ST + WCiu / WC) / (FXiu / FX); where ST is the standard value corresponding to the service life, WC is the standard value corresponding to the number of maintenance times, and FX is the standard value corresponding to the safety protection factor. Step S124: The network access risk value is compared with the network access risk threshold. If the network access risk value is greater than or equal to the network access risk threshold, the corresponding network access device is marked as a risky network access device. If the network access risk value is less than the network access risk threshold, no operation is performed. Step S125, counting the number of risky network access devices and recording it as the number of risky network access devices; Step S126, obtaining the number of networked devices in the production process, and comparing the number of risky networked devices with the number of networked devices to obtain the risky device rate of the production process.
4. The industrial Internet security control method for complex attacks according to claim 3 is characterized in that: When the number of products in stagnant production is [X1, X2], the production delay progress is S1; When the number of products in stagnant production is (X2, X3], the production delay progress is S2; When the number of products in stagnant production is (X3, X4], the production delay progress is S3; When the number of products in stagnant production is (X4, ∞), the production delay progress is S4; among them, X1, X2, X3 and X4 are all positive integers, 0<X1<X2<X3<X4, 0<S1<S2<S3<S4.
5. The industrial Internet security control method for complex attacks according to claim 4 is characterized in that: Step S4 includes the following sub-steps: Step S41, setting a virtual folder for a network-accessible device in a production link connected to the Industrial Internet, wherein the virtual folder contains a specified number of test files; Step S42: When it is detected that the industrial Internet is facing a network attack, an integrity check and a file attribute check are performed on the test file in the virtual folder; Step S43: If the integrity check and the file attribute check of the test file both pass, the test file is recorded as the original file; if either the integrity check or the file attribute check of the test file fails, the test file is recorded as a tampered file; Step S44 , counting the number of tampered files and recording it as the number of tampered files, comparing the number of tampered files with the total number of test files, and obtaining the tampering rate of test files in the virtual folders corresponding to different production links.
6. The industrial Internet security control method for complex attacks according to claim 5 is characterized in that: Step S4 also includes the following sub-steps: Step S45: Obtain the preset tampering rate corresponding to the production link according to the executed security control strategy, specifically: If it is the third security control strategy, the preset tampering rate is Y3; If it is the second security control strategy, the preset tampering rate is Y2; If it is the first security control strategy, the preset tampering rate is Y1; wherein Y1<Y2<Y3; Step S46, comparing the tampering rate of the test file in the virtual folder with the preset tampering rate corresponding to the production process; Step S47: If the tampering rate is less than or equal to the preset tampering rate, no operation is performed; If the tampering rate is greater than the preset tampering rate, the corresponding security control strategy will be set in the production process for upgrading.
7. The industrial Internet security control method for complex attacks according to claim 6 is characterized in that: The verification process of integrity check is: Calculate and save the hash value of the test file in advance. When a network attack occurs, calculate the hash value of the test file again and compare it with the previously saved hash value. If the two calculated hash values are consistent, the integrity of the test file is not compromised; If the two calculated hash values are inconsistent, it means that the integrity of the test file is destroyed.
Citation Information
Patent Citations
Network security protection system, method and device based on active defense strategy
CN116471064A
Industrial internet security protection system and method
CN117201044A