PLC attack detection method based on register characteristic change

By analyzing the logical importance and dynamic state changes of PLC registers, register feature signatures are generated, which solves the accuracy and detection resistance of the existing PLC attack detection scheme, and realizes high-precision and low false alarm rate attack detection, which is suitable for complex industrial environments.

CN120276413APending Publication Date: 2025-07-08CHINA HYDROELECTRIC ENGINEERING CONSULTING GROUP CHENGDU RESEARCH HYDROELECTRIC INVESTIGATION DESIGN AND INSTITUTE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510424922.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing PLC attack detection scheme is difficult to detect subtle attacks, has high false alarm rate, weak detection resistance, and requires invasive modification of the PLC.

Method used

The PLC attack detection method based on register feature changes, establishes a static association between registers and application code, determines the logical importance, collects register status data in real time, generates and compares the register feature signatures, and detects attack behavior.

Benefits of technology

It realizes high-precision detection of subtle attacks, reduces false alarm rates, has strong detection resistance, and does not require intrusive modifications. It is suitable for complex industrial environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120276413A_ABST
    Figure CN120276413A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of industrial control security, and discloses a PLC attack detection method based on register feature change, which solves the problems of difficulty in detecting subtle attacks, high false alarm rate and weak detection resistance in the existing PLC attack detection scheme, and does not need to carry out invasive modification on a PLC. According to the scheme, firstly, static association between a register in the PLC and a current application code is established, and the logic importance degree of the register is determined; in the running process of the PLC, running state data of the register are collected in real time, and a dynamic snapshot sequence of the register is formed when the PLC runs; according to the logic importance of the register and the dynamic state and mapping condition of the register when the PLC normally operates, obtaining all possible register mapping characteristics of the PLC on the current application code, and generating a register characteristic signature when the PLC operates; and comparing the register feature signature during actual operation of the PLC with the register feature signature during normal operation of the PLC to detect whether an attack behavior exists or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control security, and particularly relates to a method for detecting PLC (Programmable Logic Controller) attacks based on register feature changes. Background Art

[0002] Industrial control systems are widely used in various critical infrastructures, such as power, oil, gas, manufacturing, etc. Among them, PLC is a core component responsible for automated process control and is used to ensure the normal operation of production. Even a minor attack on the PLC can cause a major blow to critical infrastructure, so the security of the PLC faces severe challenges.

[0003] In the prior art, the detection schemes for PLC attacks mainly rely on means such as network traffic analysis and behavior pattern monitoring. However, these methods have the following defects:

[0004] (1) It is difficult to detect subtle and low-frequency attack behaviors, especially when an attacker achieves a covert attack by modifying the internal code or data structure of the PLC.

[0005] (2) It is easily affected by normal operation fluctuations in a complex industrial environment, resulting in a high false alarm rate.

[0006] (3) An attacker can still bypass the existing detection system through technologies such as encrypted communication and traffic obfuscation, causing the detection system to fail, so the anti-detection ability of the existing detection scheme is weak.

[0007] (4) Some detection methods require invasive modification of the PLC or rely on specific hardware support, which is difficult to achieve in an actual industrial environment. Summary of the Invention

[0008] The technical problem to be solved by the present invention is: to propose a method for detecting PLC attacks based on register feature changes, solve the problems of existing detection schemes for PLC attacks, such as difficulty in detecting subtle attacks, high false alarm rate, weak anti-detection ability, and do not require invasive modification of the PLC.

[0009] The technical solution adopted by the present invention to solve the above technical problems is:

[0010] A method for detecting PLC attacks based on register feature changes, comprising the following steps:

[0011] S1. Establish a static association between the registers in the PLC and the current application code, and determine the logical importance of the registers;

[0012] S2. During the normal operation of the PLC, collect the running state data of the registers in real time to form a dynamic snapshot sequence of the registers when the PLC is running normally;

[0013] S3. Obtain all possible register mapping features of the PLC on the current application code according to the logical importance of the registers, the dynamic state of the registers during normal operation of the PLC, and the mapping conditions, and generate a register feature signature of the PLC on the current application code during normal operation;

[0014] S4. During the actual operation of the PLC, collect the operation status data of the registers in real time to form a dynamic snapshot sequence of the registers during the actual operation of the PLC;

[0015] S5. Obtain all possible register mapping features of the PLC on the current application code according to the logical importance of the registers, the dynamic state of the registers during the actual operation of the PLC, and the mapping conditions, and generate a register feature signature of the PLC on the current application code during the actual operation;

[0016] S6. Compare the register feature signature of the PLC on the current application code during the actual operation with the register feature signature of the PLC on the current application code during normal operation to detect whether there is an attack behavior.

[0017] Further, in step S1, establish a static association between the registers in the PLC and the application code, and determine the logical importance of the registers, including:

[0018] S11. Establish a list of core registers of the PLC, which consists of n core registers r, denoted as CRL = {r1, r2,..., r n} = {I, Q, M, T, C};

[0019] Among them, I represents a set composed of n1 input registers, that is, I = {i1, i2,..., i n1}; Q represents a set composed of n2 output registers, that is, Q = {q1, q2,..., q n2}; H represents a set composed of n3 holding registers, that is, H = {h1, h2,..., h n3}; T represents a set composed of n4 timers, T = {t1, t2,..., t n4}; C represents a set composed of n5 counters c, that is, C = {c1, c2,..., c n5}, n = n1 + n2 + n3 + n4 + n5;

[0020] S12. Obtain the current application code on the PLC, and divide the current application code into m functional sub-modules according to the functions to obtain all the functional sub-module sets P = {P1, P2,..., P m}, where P m represents the mth functional sub-module;

[0021] S13. Establish the indication functions of registers and functional sub - modules, and calculate the logical importance of registers:

[0022] Analyze the register module sets involved in each functional sub - module P k among them where l represents the number of registers involved in the functional sub - module P k ;

[0023] Define the indication functions of the register and functional sub - module sets

[0024]

[0025] where r ∈ CRL, R(P k ) is the register set involved in the functional sub - module P k ;

[0026] According to the occurrence of each register in the functional sub - module set, calculate the logical importance of each register r:

[0027]

[0028] where δ(r) is the logical importance of the register r.

[0029] Furthermore, in step S2, during the normal operation of the PLC, the running state data of the registers is collected in real - time to form a dynamic snapshot sequence of the registers during the normal operation of the PLC, including:

[0030] S21. During the normal operation of the PLC, collect the running state data of the registers in real - time through network data collection technology;

[0031] S22. Judge the dynamic state of the register at the current moment according to the real - time running state data of the register; the dynamic state is whether the register is active at the current moment;

[0032] S23. The dynamic snapshot sequence of the registers during the normal operation of the PLC is formed by the combination of the dynamic states of the registers at continuous different moments within a certain time period.

[0033] Furthermore, in step S22, the methods for judging the dynamic state of the register at the current moment include:

[0034] For input registers, that is, r ∈ I, if the sensor signal received by the register r is "high" or meets the trigger condition, it is determined that the register is active;

[0035] For output registers, that is, r ∈ Q, if the register r sends a control signal to the actuator, it is determined that the register is active;

[0036] For the holding registers, timers, and counters, i.e., r ∈ {M, T, C}, compare whether the value at the current moment is the same as that at the previous moment. If the value at the previous moment exists and the values at the current and previous moments are different, then determine that the register is active;

[0037] The dynamic state r of register r at time tt tt is represented by a binary value, where r tt = 0 indicates that the register is inactive, and r tt = 1 indicates that the register is active;

[0038] In step S23, within the time TT = {tt1, tt2,..., tt num_tt}, when the PLC is running normally, the dynamic snapshot sequence of the register is represented as:

[0039]

[0040] where, represents the dynamic snapshot of the register at tt num_tt moment, which is the set of the dynamic states of all registers at this moment, represents, is the dynamic state of the nth register at tt num_tt moment.

[0041] Furthermore, in step S3, according to the logical importance of the register, the dynamic state of the register when the PLC is running normally, and the mapping conditions, obtain all possible register mapping characteristics of the PLC on the current application code, and generate the register characteristic signature of the PLC on the current application code when it is running normally, including:

[0042] S31. Define the mapping characteristic function MF(r, P , tt, δ0) according to the logical importance δ(r) of register r, the indicator function tt and the dynamic state r k ;

[0043] S32. Analyze that there are num_s possible states when the PLC is running normally on the current application code, and obtain the corresponding num_s dynamic snapshots;

[0044] S33. For each obtained dynamic snapshot, form the mapping characteristic snapshot of the register in each functional sub-module, and obtain the global characteristic mapping corresponding to this state by aggregating the mapping characteristic snapshots of all functional sub-modules in the same state;

[0045] S34. Aggregate the num_s global characteristic mappings corresponding to each state to obtain the register characteristic signature of the PLC on the current application code when it is running normally.

[0046] Further, in step S31, the mapping feature function MF(r, P k , tt, δ0) is expressed as:

[0047]

[0048] where r ∈ CRL and δ0 is a preset threshold of logical importance.

[0049] Further, in step S33, for each obtained dynamic snapshot, a mapping feature snapshot of the register in each functional sub-module is formed, and by aggregating the mapping feature snapshots of all functional sub-modules in the same state, a global feature mapping corresponding to this state is obtained, including:

[0050] For state s, the dynamic snapshot obtained at time tt is expressed as: where is the dynamic state of the nth register corresponding to state s;

[0051] Form a mapping feature snapshot of the register on the functional sub-module P k :

[0052] where is the mapping feature of the nth register corresponding to state s on the functional sub-module P k ;

[0053] Aggregate the mapping feature snapshots on all sub-functional modules with the same number in state s to form the global feature mapping of the current state s where is the mapping feature of the register corresponding to state s on the functional sub-module P m ;

[0054] Further, in step S5, according to the logical importance of the register, the dynamic state of the register during the actual operation of the PLC, and the mapping conditions, all possible register mapping features that may occur on the current application code of the PLC are obtained, and a register feature signature during the actual operation of the PLC on the current application code is generated, including:

[0055] S51. Calculate the mapping feature of the register on each functional sub-module according to the logical importance and dynamic state of the register;

[0056] S52. According to the time within, the collected sequence of dynamic snapshots is used to form a mapping feature snapshot of the register in each functional sub-module at each moment tt where represents the mapping feature of the register on the functional sub-module P at time tt kMapping feature snapshot on;

[0057] S53. Aggregate the mapping feature snapshots on all sub - function modules at time tt with the same number to form the global feature mapping GFM at time tt tt , then obtain the register feature signature RFS of the PLC during actual operation on the current application code test , Among them, represents the global feature mapping at time tt num_tt .

[0058] Furthermore, in step S6, compare the register feature signature of the PLC during actual operation on the current application code with the register feature signature of the PLC during normal operation on the current application code to detect whether there is an attack behavior, including:

[0059] Based on the obtained register feature signature RFS of the PLC during actual operation on the current application code test , and the register feature signature RFS of the PLC during normal operation on the current application code baseline , RFS baseline = {GFM1, GFM2, …, GFM num_s} Among them, GFM num_s represents the global feature mapping of the num_s - th state;

[0060] Index RFS test and RFS baseline using a unified index and sort them according to the timestamp to obtain two ordered register feature signature sequences;

[0061] Compare the corresponding global feature mappings in the two ordered register feature signature sequences in turn. When the first corresponding global feature mapping is different in the two feature signature sequences, calculate the deviation. If the deviation is greater than the set threshold, it is determined as an attack behavior.

[0062] The beneficial effects of the present invention are:

[0063] By analyzing the logical importance and dynamic state changes of the registers in the PLC, the present invention generates a register feature signature, and by comparing the register feature signature during actual operation with the register feature signature during normal operation, the high - precision detection of attack behavior is realized. Compared with the prior art, the present invention has the following advantages:

[0064] (1) High - precision detection: It can accurately capture the minute abnormal changes in the PLC system and effectively identify subtle and low - frequency attack behaviors.

[0065] (2) Strong anti-detection ability: It is not affected by anti-detection technologies such as encrypted communication and traffic obfuscation, and has stronger anti-detection ability.

[0066] (3) Low false alarm rate: By comparing dynamic snapshots and feature signatures, it can effectively distinguish normal operation fluctuations and attack behaviors, and reduce the false alarm rate.

[0067] (4) Non-invasive: It does not require invasive modification of the PLC and is applicable to various industrial environments and PLC models.

[0068] (5) Strong real-time performance: It can collect the register status in real time and generate feature signatures to detect attack behaviors in a timely manner. Description of the Drawings

[0069] Figure 1 It is a flowchart of the PLC attack detection method based on register feature changes in the embodiments of the present invention. Detailed Embodiments

[0070] The present invention aims to provide a PLC attack detection method based on register feature changes, which solves the problems of difficult detection of subtle attacks, high false alarm rate, and weak anti-detection ability existing in the existing detection schemes for PLC attacks, and does not require invasive modification of the PLC. Its core idea is that the register, as the core data storage unit of the PLC operation, the change of its state can directly reflect the operation mode of the PLC and potential attack behaviors. This scheme generates register feature signatures by analyzing the logical importance and dynamic state changes of the registers in the PLC, and realizes high-precision detection of attack behaviors by comparing the register feature signatures in the actual operation process with those in the normal operation process. This method has the advantages of non-invasiveness, strong real-time performance, high anti-detection ability, and low false alarm rate. It can accurately capture the tiny abnormal changes in the PLC system, provide personalized detection schemes, and improve the overall security of the industrial control system, and is particularly suitable for complex and concealed attack scenarios.

[0071] The following further describes the solution of the present invention with reference to the drawings and embodiments.

[0072] Embodiment

[0073] The implementation process of the PLC attack detection method based on register feature changes provided in this embodiment is shown in Figure 1 and includes the following steps:

[0074] S1. Establish a static association between the registers in the PLC and the current application code to determine the logical importance of the registers;

[0075] In this step, to facilitate calculation, abstraction, and independence from PLC manufacturers and models, the register list in the actual PLC is simplified, focusing only on the main and commonly used registers, which are called "core registers". By establishing a static association between the registers and the application code, determining the logical importance of the registers can clarify the role and importance of each register in the PLC application. This provides the necessary basic information for subsequent creation of dynamic snapshots and generation of register feature signatures, enabling dynamic monitoring to more specifically capture abnormal behaviors. For example, it can more accurately capture abnormal changes in these key registers, thereby improving the accuracy of attack detection and also ignoring the interference caused by status changes of non-critical registers to reduce the false alarm rate.

[0076] In an exemplary implementation, the specific implementation sub-steps of this step are as follows:

[0077] S101. Establish the PLC core register list CRL:

[0078] The core registers in this embodiment consist of 10 core registers r, so the core register list CRL = {r1, r2,..., r8} = {I, Q, M, T, C}, where I represents a set composed of 2 input registers, that is, I = {i1, i2}; Q represents a set composed of 2 output registers, that is, Q = {q1, q2}; H represents a set composed of 2 holding registers, that is, H = {h1, h2}; T represents a set composed of 2 timers, T = {t1, t2}; C represents a set composed of 2 counters c, that is, C = {c1, c2}.

[0079] S102. Obtain the application code on the PLC and record the usage of registers in different code modules:

[0080] Obtain the code downloaded to the PLC through network data acquisition technology, that is, select a suitable communication protocol according to the PLC model and manufacturer, use the communication library, obtain the application code from the PLC and divide it into m functional sub-modules according to the functions, and obtain all the functional sub-module sets P = {P1, P2,..., P m}, where P m represents the mth functional sub-module.

[0081] The application pseudo-code obtained in this embodiment is as follows:

[0082] / / Conditional logic control

[0083] IF I1 = TRUE AND I2 = FALSE THEN / / I1 = TRUE means the current is at low water level, I2 = FALSE means it is not raining currently

[0084] Q1 := TRUE; / / Start the irrigation equipment

[0085] T1.IN := TRUE; / / Start the timer

[0086] ELSIF I2 = TRUE THEN

[0087] Q1 := FALSE; / / Stop the irrigation equipment when it rains

[0088] T1.IN := FALSE;

[0089] END_IF;

[0090] / / Alarm logic

[0091] IF T1.ET > T#10m THEN

[0092] Q2 := TRUE; / / Trigger the alarm

[0093] ELSE

[0094] Q2 := FALSE;

[0095] END_IF;

[0096] Accordingly, it can be divided into two functional sub - modules:

[0097] The conditional logic control module is P1, and the alarm logic module is P2.

[0098] S103. Establish the indicator functions of the registers and the functional sub - modules, and calculate the logical importance of the registers:

[0099] Analyze each functional sub - module P k the set of register modules involved in where l represents the number of registers involved in the functional sub - module P k involved.

[0100] R(P1) = {i1, i2, q1, t1}, R(P2) = {t1, q2}.

[0101] Define the indicator functions of the register and the functional sub - module set

[0102]

[0103] where r ∈ CRL, R(P k ) is the set of registers involved in the functional sub - module P k involved.

[0104]

[0105] The indication function values corresponding to the other registers in sub - modules P1 and P2 are 0.

[0106] According to the occurrence of the register in the set of functional sub - modules, calculate the logical importance δ(r) of the register r, and the formula is as follows:

[0107]

[0108] Then the logical importance of the register is shown in Table 1:

[0109] Table 1 Logical importance of registers

[0110] r <![CDATA[i1]]> <![CDATA[i2]]> <![CDATA[q1]]> <![CDATA[q2]]> <![CDATA[h1]]> <![CDATA[h2]]> <![CDATA[t1]]> <![CDATA[t2]]> <![CDATA[c1]]> <![CDATA[c2]]> δ(r) 1 1 1 1 0 0 2 0 0 0

[0111] S2. Create a dynamic snapshot of the register when the PLC is running normally:

[0112] In this step, the dynamic snapshot of the register can reflect the real - time behavior pattern of the register when the PLC is running, and it will be used as the data basis for calculating the register feature signature in the follow - up. In this step, during the normal operation of the PLC, the running state data of the register is collected in real - time to form a dynamic snapshot sequence of the register when the PLC is running normally.

[0113] In an exemplary implementation, the specific implementation sub - steps of this step are as follows:

[0114] S201. Obtain the running state of the register at the current moment from the normally running PLC through network data acquisition technology:

[0115] Select a suitable communication protocol according to the PLC model and manufacturer, configure the communication interface, and use the communication library to obtain the running state of the register at the current moment from the normally running PLC.

[0116] S202. Create a dynamic snapshot according to whether the register r ∈ CRL is active at the current moment:

[0117] For r ∈ I, if the sensor signal received by the register r is "high" or meets the trigger condition, then the register is considered active; for r ∈ Q, if the register r sends a control signal to the actuator, then the register is considered active; for r ∈ {M, T, C}, then compare whether the value at the current moment is the same as that at the previous moment. If the value at the previous moment exists and the values at the current moment and the previous moment are different, then the register is considered active.

[0118] The dynamic state r of the register r at time tt tt is represented by a binary value, where r tt = 0 indicates that the register is inactive, r tt = 1 indicates that the register is active. The dynamic snapshot DS at time tttt is the set of dynamic states of all registers, denoted by and is the dynamic state of the num_i-th register at time tt. DS tt = {0, 1, 0, 0, 0, 0, 0, 0, 0, 0} indicates that the second input register is active at time tt, and the other registers are inactive.

[0119] S203. During the time TT = {tt1, tt2, …, tt num_tt}, the collected dynamic snapshot sequence DSL is:

[0120]

[0121] S3. Calculate the register feature signature of the PLC on the current application code during normal operation:

[0122] In this step, according to the logical importance of the registers, the dynamic states of the registers during normal operation of the PLC, and the mapping conditions, all possible register mapping features that may appear on the current application code of the PLC are obtained, and the register feature signature of the PLC on the current application code during normal operation is generated; that is, the generation of the register feature signature of the PLC during normal operation is based on the logical importance, dynamic states, and mapping features of the functional sub-modules of the registers during normal operation of the PLC. It can comprehensively reflect the register behavior pattern of the PLC in the normal operation state, so as to be used for subsequent comparison with the register feature signature during actual operation to detect whether there is an attack.

[0123] In an exemplary implementation, the specific implementation sub-steps of this step are as follows:

[0124] S301. Define the mapping feature function:

[0125] According to the logical importance δ(r) of the register r, the indicator function and the dynamic state r tt to define the mapping feature function MF(r, P k , tt, δ0):

[0126]

[0127] where r ∈ CRL, δ0 is the threshold of the logical importance. δ(r) ≥ δ0 indicates that the register r has a high logical importance, and δ(r) < δ0 indicates that the register r has a low logical importance. The calculation formula of δ0 can be adjusted as needed. In this embodiment, δ0 is the average value of all logical importance values greater than 0, and δ0 = 1.2.

[0128] S302. Obtain the dynamic snapshots corresponding to all possible states when the PLC is running normally on the current code:

[0129] In this embodiment, there are 7 possible states when the PLC is running normally on the current application code, and the corresponding dynamic snapshots are shown in Table 2:

[0130] Table 2 Dynamic snapshots corresponding to 7 states when the PLC is running normally

[0131]

[0132] S303. According to the obtained dynamic snapshots, form the mapping feature snapshots of each register in the functional sub-module corresponding to each dynamic snapshot, so as to form the global feature mapping of the current state:

[0133] If there is a corresponding s state, the dynamic snapshot obtained at time tt is the dynamic state of the num_i-th register corresponding to the s state, and form the mapping feature snapshot of each register on the functional sub-module P k above is the mapping feature of the num_i-th register corresponding to the s state on the functional sub-module P k above

[0134] The mapping feature snapshots on all sub-functional modules are aggregated with the same number in the s state to form the global feature mapping of the current s state

[0135] In this embodiment, the global feature mapping obtained for each state is shown in Table 3:

[0136] Table 3 Global feature mapping of 7 states when the PLC is running normally

[0137]

[0138] Use RFS to represent the register feature signature of the PLC when it is running normally on the current application code baseline Then, in this embodiment, RFS baseline ={GFM s1 , GFM s2 , GFM s3 , GFM s4 , GFM s5 , GFM s6 , GFM s7}.

[0139] S304. Form the register feature signature of the PLC when it is running normally on the current application code:

[0140] By aggregating the global feature maps corresponding to num_s states that may occur in the current application code during the normal operation of the PLC, the register feature signature RFS of the PLC during normal operation on the current application code is obtained.

[0141] S4. Create a dynamic snapshot of the registers of the PLC during actual operation:

[0142] In this step, during the actual operation of the PLC, the running state data of the registers is collected in real time to form a dynamic snapshot sequence of the registers of the PLC during actual operation. For the specific implementation method, refer to the creation of the dynamic snapshot of the registers of the PLC during normal operation in step S2 above, which will not be elaborated here.

[0143] S5. Calculate the register feature signature of the PLC on the current application code during actual operation:

[0144] In this step, according to the logical importance of the registers, the dynamic state of the registers of the PLC during actual operation, and the mapping conditions, all possible register mapping features that may occur on the current application code of the PLC are obtained, and the register feature signature of the PLC on the current application code during actual operation is generated.

[0145] Among them, according to the logical importance and dynamic state of the registers in the same way as in step S303 above, calculate the mapping features of the registers on each functional sub-module; according to the dynamic snapshot sequence collected within the time, form the mapping feature snapshots of the registers on each functional sub-module at each moment tt Among them, represents the mapping feature snapshot of the register on the functional sub-module P at moment tt k ; then aggregate the mapping feature snapshots on all sub-functional modules with the same number at moment tt to form the global feature map GFM at moment tt tt , and then the register feature signature of the PLC on the current application code during actual operation is obtained Among them, represents num_tt the global feature map at moment tt.

[0146] In this embodiment, the environment where the PLC is located is always at a high water level and it is raining, and the signals of the input registers read periodically are always i1 = 0 and i2 = 1. Suppose an attacker tampers with the signal of t1, making the timer always in an active state, then the generated register feature signature RFS of the PLC during actual operation test is shown in Table 4:

[0147] Table 4 Register Feature Signature of the PLC during Actual Operation

[0148]

[0149] S6. Compare the register feature signatures of the PLC during actual operation on the current application code with those during normal operation on the current application code to detect attack behaviors:

[0150] In this step, compare the register feature signatures of the PLC during actual operation on the current application code with those during normal operation on the current application code to detect whether there are attack behaviors.

[0151] In an exemplary implementation, first perform duplicate removal on the RFS test individually, and perform indexing on the duplicate-removed RFS test and the RFS baseline with a unified index and sort them by timestamp to obtain RFS' baseline and RFS' test .

[0152] The unified index is shown in Table 5:

[0153] Table 5 Duplicate-removed RFS test and the RFS baseline unified index

[0154]

[0155]

[0156] That is:

[0157] RFS' baseline Sequence: {GFM2, GFM1, GFM3, GFM4, GFM5, GFM6, GFM7}

[0158] RFS' test Sequence: {GFM2, GFM8}

[0159] Then, compare the corresponding global feature mappings GFM in RFS' baseline and RFS' test in sequence, and calculate the deviation for the first non-identical global feature mapping GFM. The deviation Δ is initially 0. If the difference between the mapped features is greater than 4, then the deviation Δ = Δ + 2. If the difference between the mapped features is between 0 and 4, then the deviation Δ = Δ + 1. If the calculated deviation is greater than the threshold, it is regarded as an attack. In this embodiment, the threshold is 5. It is calculated that Δ = 6 > 5 in this embodiment, indicating that an attack is detected.

[0160] Finally, it should be noted that the above embodiments are only preferred embodiments and are not intended to limit the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the spirit and scope of the present invention as defined by the claims, several modifications, equivalent substitutions, improvements, etc. should all be included within the protection scope of the present invention.

Claims

1. A PLC attack detection method based on the change of register characteristics, characterized in that, Including the following steps: S1. Establish a static association between the registers in the PLC and the current application code, and determine the logical importance of the registers; S2. During the normal operation of the PLC, collect the running state data of the registers in real time to form a dynamic snapshot sequence of the registers during the normal operation of the PLC; S3. According to the logical importance of the registers, the dynamic state of the registers during the normal operation of the PLC, and the mapping conditions, obtain all possible register mapping characteristics of the PLC on the current application code, and generate a register feature signature of the PLC on the current application code during the normal operation; S4. During the actual operation of the PLC, collect the running state data of the registers in real time to form a dynamic snapshot sequence of the registers during the actual operation of the PLC; S5. According to the logical importance of the registers, the dynamic state of the registers during the actual operation of the PLC, and the mapping conditions, obtain all possible register mapping characteristics of the PLC on the current application code, and generate a register feature signature of the PLC on the current application code during the actual operation; S6. Compare the register feature signature of the PLC on the current application code during the actual operation with the register feature signature of the PLC on the current application code during the normal operation to detect whether there is an attack behavior.

2. The PLC attack detection method based on register feature change according to claim 1, characterized in that In step S1, establishing a static association between the registers in the PLC and the application code, and determining the logical importance of the registers includes: S11. Establish a core register list of the PLC, which consists of n core registers r, denoted as CRL = {r1, r2, …, r n} = {I, Q, M, T, C}; Among them, I represents a set composed of n1 input registers, that is, I = {i1, i2, …, i n1}; Q represents a set composed of n2 output registers, that is, Q = {q1, q2, …, q n2}; H represents a set composed of n3 holding registers, that is, H = {h1, h2, …, h n3}; T represents a set composed of n4 timers, T = {t1, t2, …, t n4}; C represents a set composed of n5 counters c, that is, C = {c1, c2, …, c n5}, and n = n1 + n2 + n3 + n4 + n5; S12. Obtain the current application code on the PLC, and divide the current application code into m functional sub-modules according to functions, to obtain all the sets of functional sub-modules P = {P1, P2, …, P m}, where P m represents the mth functional sub-module; S13. Establish an indication function between the registers and the functional sub-modules, and calculate the logical importance of the registers: Analyze each functional sub-module P k The set of register modules R(P k ) = {r k1 , r k2 , …, r kl}, where l represents the number of registers involved in the functional sub-module P k ; The indicating function Φ that defines the register and the set of functional sub-modules R(Pk) (r): where r ∈ CRL, R(P k ) is the set of registers involved in the functional sub-module P k ; According to the occurrence of each register in the set of functional sub-modules, calculate the logical importance of each register r: where δ(r) is the logical importance of register r.

3. The PLC attack detection method based on register feature change according to claim 2, characterized in that In step S2, during the normal operation of the PLC, collecting the running state data of the registers in real time to form a dynamic snapshot sequence of the registers during the normal operation of the PLC includes: S21. During the normal operation of the PLC, collect the running state data of the registers in real time through network data collection technology; S22. Judge the dynamic state of the register at the current moment according to the real-time running state data of the register; the dynamic state is whether the register is active at the current moment; S23. The dynamic snapshot sequence of the registers during the normal operation of the PLC is formed by combining the dynamic states of the registers at consecutive different moments in a certain time period.

4. The PLC attack detection method based on register feature change according to claim 3, characterized in that In step S22, the method for judging the dynamic state of the register at the current moment includes: For input registers, that is, r ∈ I, if the sensor signal received by register r is "high" or meets the trigger condition, it is determined that the register is active; For output registers, that is, r ∈ Q, if register r sends a control signal to the actuator, it is determined that the register is active; For the holding registers, timers, and counters, i.e., r ∈ {M, T, C}, compare whether the value at the current moment is the same as that at the previous moment. If the value at the previous moment exists and the values at the current and previous moments are different, then determine that the register is active; The dynamic state r of register r at time tt tt is represented by a binary value, where tt r = 0 indicates that the register is inactive, and tt r = 1 indicates that the register is active; In step S23, within the time TT = {tt1, tt2, …, tt num_tt}, the dynamic snapshot sequence of the register when the PLC is running normally is expressed as: Among them, DS ttnum_tt represents the dynamic snapshot of the time register at tt num_tt moment, which is the set of dynamic states of all registers at this moment, indicating that is the dynamic state of the nth register at tt num_tt moment.

5. The PLC attack detection method based on register feature changes according to claim 1, characterized in that, In step S3, according to the logical importance of the registers, the dynamic state of the registers during normal operation of the PLC, and the mapping conditions, obtain all possible register mapping features of the PLC on the current application code, and generate a register feature signature of the PLC on the current application code during normal operation, including: S31. Define the mapping feature function MF(r, P and the dynamic state r tt , tt, δ0) according to the logical importance δ(r) of the register r, the indicator function k ; S32. Analyze that there are num_s possible states when the PLC operates normally on the current application code, and obtain the corresponding num_s dynamic snapshots; S33. For each obtained dynamic snapshot, form a mapping feature snapshot of the registers in each functional sub-module, and obtain the global feature mapping corresponding to this state by aggregating the mapping feature snapshots of all functional sub-modules in the same state; S34. Aggregate the num_s global feature mappings corresponding to each state to obtain the register feature signature of the PLC on the current application code during normal operation.

6. The PLC attack detection method based on register feature changes according to claim 5, characterized in that, In step S31, the mapping feature function MF(r, P k , tt, δ0) is expressed as: where r ∈ CRL, and δ0 is a preset threshold for logical importance.

7. The PLC attack detection method based on register feature changes according to claim 5, characterized in that, In step S33, for each obtained dynamic snapshot, form a mapping feature snapshot of the registers in each functional sub-module, and obtain the global feature mapping corresponding to this state by aggregating the mapping feature snapshots of all functional sub-modules in the same state, including: For state s, the dynamic snapshot obtained at time tt is represented as: where is the dynamic state of the nth register corresponding to state s; Form a register's mapping feature snapshot on functional sub-module P k as follows: Among them, is the mapping feature of the s state corresponding to the nth register on the functional sub-module P k on. Aggregate the mapping feature snapshots on all sub - function modules with the same number in the s state to form the global feature mapping of the current s state Among them, is the mapping feature of the register corresponding to the s state on the functional sub - module P m ​ 8. The PLC attack detection method based on register feature changes according to claim 7, characterized in that, In step S5, according to the logical importance of the registers, the dynamic state of the registers during actual operation of the PLC, and the mapping conditions, obtain all possible register mapping features of the PLC on the current application code, and generate a register feature signature of the PLC on the current application code during actual operation, including: S51. Calculate the mapping features of the registers on each functional sub-module according to the logical importance and dynamic state of the registers; S52. According to time Within, the collected dynamic snapshot sequence forms a mapping feature snapshot of the register at each moment tt in each functional sub-module Among them, Indicates the mapping feature snapshot of the register at moment tt on the functional sub-module P k The mapping feature snapshot; S53. Aggregate the mapping feature snapshots on all sub - function modules with the same number at time tt to form the global feature map GFM at time tt tt , then obtain the register feature signature RFS of the PLC during actual operation on the current application code test , where represents the global feature map at time tt num_tt .

9. The PLC attack detection method based on register feature changes according to claim 8, characterized in that, In step S6, compare the register feature signature of the PLC on the current application code during actual operation with the register feature signature of the PLC on the current application code during normal operation to detect whether there is an attack behavior, including: Based on the register feature signature RFS of the PLC in the current application code during actual operation test , and the register feature signature RFS of the PLC in the current application code during normal operation baseline , RFS baseline = {GFM1, GFM2, …, GFM num_s}, where GFM num_s represents the global feature mapping of the num_s-th state; For RFS test and RFS baseline Index them using a unified index and sort them according to timestamps to obtain two ordered sequences of register feature signatures; Compare the corresponding global feature mappings in two ordered register feature signature sequences in sequence. When the first corresponding global feature mapping is different in the two feature signature sequences, calculate the deviation. If the deviation is greater than the set threshold, then determine it as an attack behavior.