Industrial internet security monitoring control system
Through the network security monitoring, control logic monitoring and traceability analysis modules, the security monitoring and control problems of interconnection and cooperation among devices in the industrial Internet are solved, real-time detection and hierarchical early warning of network attacks and control logic tampering is realized, and the security and production continuity of the system are guaranteed.
Patent Information
- Application Number
- CN202510748359.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
The existing technology has failed to effectively solve the security monitoring and control problems of interconnection and cooperation among devices in the industrial Internet, and there are security risks such as data leakage, malicious intrusion and production process disorders.
The network security monitoring module, control logic monitoring module and traceability analysis module are adopted to identify external attacks and tampering behaviors by analyzing industrial equipment communication network traffic data, and multi-dimensional traceability analysis is carried out in combination with the decision tree algorithm to trigger differentiated hierarchical warnings.
It realizes comprehensive monitoring of network security, promptly discovers control logic tampering, clarifys the root cause of the problem, and improves the security of the system and production continuity.
Smart Images

Figure CN120281572A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial Internet security monitoring, and relates to an industrial Internet security monitoring and control system. Background Art
[0002] The industrial Internet is a technical architecture and industrial development model that deeply integrates Internet technology into the industrial field to realize the intelligentization, high efficiency, and networking of industrial production systems. Among them, in connecting industrial equipment and systems, the industrial Internet connects various devices, machines, sensors, control systems, etc. in industrial production through various communication technologies, such as the Internet of Things, wired networks, wireless networks, etc., to achieve interconnection and data sharing between devices, enabling devices to work together efficiently, stably, and securely.
[0003] However, due to the characteristics of non-uniform protocols, strong device heterogeneity, and complex network architectures in the industrial Internet, security risks such as data leakage, malicious intrusion, and production instruction tampering are likely to occur due to communication protocol vulnerabilities, device authentication defects, or unencrypted data transmission. At the same time, the weak cooperation mechanism between heterogeneous devices may lead to production process disorders or physical damage. Therefore, it is necessary to conduct full-link control over the interconnection and cooperation process between devices by real-time monitoring the data flow of the process, establishing dynamic access control strategies, and deploying abnormal behavior analysis systems to identify and block attack paths to ensure the security of cross-system cooperation and production continuity.
[0004] The existing technologies have obvious deficiencies in the security monitoring and control of the interconnection and cooperation between industrial devices.
[0005] For example, the existing Chinese patent with the authorized announcement number CN115826539B discloses a device cooperation control method and system based on industrial Internet identification. Its core lies in grouping and identifying multiple devices through industrial Internet identification, and then realizing the cooperation control of the devices. The specific steps include: obtaining device information and dividing device groups, assigning industrial Internet identifiers to each device group and device, and finally performing cooperation control based on these identifiers. This method focuses on the identification management and cooperation operations between devices, but does not involve the security monitoring and control of the interconnection and cooperation between devices.
[0006] Another example is that the existing Chinese patent with the authorized announcement number CN114755993B discloses a cooperation control method, system, and related devices applied to the industrial Internet. It determines the data priority and target processing device by analyzing the data type, generation time, and processing device status of the operation data in the industrial production process, and finally selects the optimal processing device to execute the task. This method focuses on improving data processing efficiency and industrial control efficiency and also does not involve the security issues of the interconnection and cooperation between devices. Summary of the Invention
[0007] In view of the above problems, the present invention proposes an industrial Internet security monitoring and control system to realize the function of industrial Internet security monitoring.
[0008] The technical solution adopted by the present invention to solve its technical problems is as follows: The present invention provides an industrial Internet security monitoring and control system, including: a network security monitoring module: analyzing and identifying external network attack behaviors and illegal access requests based on the traffic data of the industrial device communication network collected, and analyzing the risk level based on parameters such as attack type, attack frequency, influence range, access times, and the number of access devices.
[0009] A control logic monitoring module: identifying whether the control logic between devices has been tampered with through the collected operation status data of industrial devices, and triggering a verification alarm when a logic anomaly is detected.
[0010] A traceability analysis module: After receiving the verification alarm, retrieving operation logs, behavior trajectories, and version update records for multi-dimensional analysis, and using a decision tree algorithm to determine whether the cause of the tampering belongs to one or more combinations of misoperation, malicious tampering, or system download and update.
[0011] An early warning execution module: triggering differentiated hierarchical early warnings according to the risk level and the classification of the cause of the tampering.
[0012] Compared with the prior art, the industrial Internet security monitoring and control system described in the present invention has the following beneficial effects: 1. Network security monitoring: The present invention realizes comprehensive monitoring of network security by analyzing the traffic data of the industrial device communication network in real time, identifying external network attack behaviors and illegal access requests, and evaluating the risk level in combination with multi-dimensional parameters such as attack type, frequency, and influence range.
[0013] 2. Detection of control logic tampering: The present invention detects anomalies in the execution sequence, content, and cycle of the control logic by comparing the operation status data of the device with the standard control logic, and thus timely discovers control logic tampering behaviors to ensure the normal operation of industrial devices.
[0014] 3. Multi-dimensional traceability analysis: The present invention combines operation logs, behavior trajectories, and version update records, and uses a decision tree algorithm to distinguish control logic anomalies caused by misoperation, malicious tampering, and system updates, which can clarify the root cause of the problem and facilitate targeted handling. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 This is the connection diagram of the system modules of the present invention.
[0017] Figure 2 This is the composition diagram of the network security monitoring module of the present invention.
[0018] Figure 3 This is the composition diagram of the traceability analysis module of the present invention. Specific embodiments
[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] Please refer to Figure 1 As shown, the present invention provides an industrial Internet security monitoring and control system, including a network security monitoring module, a control logic monitoring module, a traceability analysis module, and an early warning execution module.
[0021] The control logic monitoring module is connected to the traceability analysis module, and the early warning execution module is respectively connected to the network security monitoring module and the traceability analysis module.
[0022] The network security monitoring module analyzes and identifies external network attack behaviors and illegal access requests based on the traffic data of the industrial device communication network collected, and analyzes the risk level based on parameters such as attack type, attack frequency, influence range, number of access times, and number of access devices.
[0023] Further, referring to Figure 2 As shown, the network security monitoring module includes a traffic data collection unit, an external network attack monitoring unit, and an illegal access monitoring unit. The specific working process of the traffic data collection unit is as follows: Set listening ports on each key node device in the industrial device communication network to mirror its network traffic, copy the data packets flowing through these devices, and send them to the traffic analysis system to obtain the traffic data of each key node device in the communication network during the monitoring period.
[0024] As a preferred solution, the key node device refers to a device that is in a key position in the industrial device communication network and plays a crucial role in the normal operation, data transmission, and security guarantee of the network. In a specific embodiment, the key node devices include, but are not limited to: routers, switches, firewalls, intrusion detection systems / intrusion prevention systems, servers, load balancers, network access devices, core network devices, etc.
[0025] In another specific embodiment, professional traffic collection tools such as Wireshark, tcpdump, etc. are used to capture raw data packets on each network interface of the industrial device communication network, save them as files or directly perform real-time analysis, and thus obtain traffic data.
[0026] Furthermore, the specific working process of the external network attack monitoring unit includes: obtaining the average traffic, peak traffic, and port traffic distribution of each key node device in the communication network at different time periods by using the traffic patterns of normal network activities of the industrial device communication network stored in the database, and thus establishing the traffic baselines of each key node device in the communication network.
[0027] Compare the traffic data of each key node device in the communication network during the monitoring period with its traffic baseline to obtain the deviations of the average traffic, peak traffic, and port traffic distribution relative to the traffic baseline, and input the deviations into a preset traffic data relative baseline deviation - traffic anomaly coefficient relationship model to output the traffic anomaly coefficients of each key node device. The relationship model includes the quantitative mapping relationship between the traffic data relative baseline deviation and the traffic anomaly coefficient.
[0028] If the traffic anomaly coefficient of a certain key node device in the communication network is greater than the set threshold, it is determined that there is an external network attack behavior in the communication network, and this key node device is recorded as an abnormal node device, and the number of abnormal node devices is counted.
[0029] It should be noted that in a feasible simulation process, assume that there are three key node devices: Device A, Device B, and Device C. The traffic baselines and actual traffic data of the three key node devices during the monitoring period are respectively referred to in Table 1 and Table 2. Based on the traffic data relative baseline deviation - traffic anomaly coefficient relationship model, the traffic anomaly coefficients of each key node device can be analyzed and obtained, specifically referred to in Table 3.
[0030] Table 1. Baseline data of key node devices
[0031]
[0032] Table 2. Actual traffic data of key node devices
[0033]
[0034] Table 3. Analysis results of traffic anomaly coefficients of key node devices
[0035]
[0036] Among them, the model rules are as follows: (1) Average traffic anomaly coefficient = |Percentage deviation of average traffic| × 0.1; (2) Peak traffic anomaly coefficient = |Percentage deviation of peak traffic| × 0.15; (3) Port distribution anomaly coefficient = Total port distribution deviation (sum of absolute values of percentage changes of each port) × 0.05; (4) Total traffic anomaly coefficient is the sum of the three anomaly coefficients.
[0037] Furthermore, the specific working process of the external network attack monitoring unit further includes: extracting the attack traffic characteristics of each abnormal node device from the traffic data, comparing them with the traffic characteristics of various network attacks stored in the database, matching the corresponding network attack types of each abnormal node device, and classifying and statistically obtaining the set of attack types of external network attacks on the communication network.
[0038] As a preferred solution, the attack types of external network attacks include DDoS attacks, SQL injections, XSS, man-in-the-middle attacks, port scans, malware propagation, phishing attacks, zero-day vulnerability exploits, brute force attacks, DNS hijacking, etc. The traffic characteristics of each attack include packet size, frequency, protocol usage, abnormal behaviors, etc.
[0039] Obtain the attack frequencies corresponding to each abnormal node device, and perform maximum and minimum value calculations to obtain the attack frequencies of external network attacks on the communication network.
[0040] As a preferred solution, the network attack frequency refers to the number of occurrences or rate of attack behaviors initiated against a specific target, system, or network within a certain time range.
[0041] Substitute the number of abnormal node devices in the communication network into the corresponding relationship between the number of abnormal node devices and the impact scope level preset, and match to obtain the impact scope level of external network attacks on the communication network.
[0042] Input the set of attack types, attack frequencies, and impact scope levels of external network attacks on the communication network into the evaluation model of the set network attack risk level to obtain the network attack risk level of the communication network.
[0043] It should be noted that the evaluation model of the network attack risk level includes the quantitative mapping relationship between the set of attack types, attack frequencies, impact scope levels, and network attack risk levels.
[0044] It should be noted that for a feasible simulation process, as shown in Tables 4, 5, and 6, the specific process of analyzing the network attack risk level of the communication network is as follows: Set the risk factors corresponding to each attack type, screen out the risk factors corresponding to each attack in the set of attack types of external network attacks on the communication network, and accumulate them to obtain the attack type risk factors of external network attacks on the communication network.
[0045] Set the risk factors corresponding to each attack frequency range and each influence range level, and respectively screen out the attack frequency risk factor and the influence range risk factor of the external network attack of the communication network.
[0046] Calculate the weighted average of the attack type risk factor, the attack frequency risk factor, and the influence range risk factor of the external network attack of the communication network to obtain the comprehensive risk factor of the external network attack of the communication network, and substitute the calculation result into the corresponding relationship between the set comprehensive risk factor and the network attack risk level to obtain the network attack risk level of the communication network.
[0047] Table 4. Definition of risk factors and weight comparison table
[0048]
[0049] Table 5. Risk level mapping table
[0050]
[0051] Table 6. Evaluation results of network attack risk level
[0052]
[0053] It should be noted that based on dynamic traffic data, the present invention uses traffic baseline comparison and abnormal coefficient calculation to accurately detect external network attack behaviors and quantify the risk level, thereby improving the accuracy and pertinence of detection and realizing real-time monitoring and risk analysis of network attack behaviors.
[0054] Furthermore, the specific working process of the illegal access monitoring unit is as follows: According to the traffic data of each key node device in the communication network within the monitoring period, extract the characteristics of each access request of each key node device in the communication network within the monitoring period. The characteristics include traffic frequency, access time, IP home location, number of failed connection attempts, protocol-port combination, and compare with the corresponding characteristics of illegal access stored in the database to determine whether it is an illegal access request.
[0055] Further obtain the cumulative number of illegal access requests of key node devices in the communication network and the cumulative number of key node devices with illegal access, record them as the number of access requests and the number of access devices of the illegal access of the communication network, and substitute them into the evaluation model of the preset illegal access risk level to obtain the illegal access risk level of the communication network.
[0056] It should be noted that a feasible simulation process, the specific process of determining whether it is an illegal access request is as follows: According to the characteristics corresponding to illegal access stored in the database, obtain the traffic frequency range, access time period, IP home location blacklist, number of failed connection attempts range, protocol-port combination library corresponding to illegal access.
[0057] Set matching factors for traffic frequencies that belong to and do not belong to the illegal access corresponding traffic frequency range, and screen out the matching factors between the traffic frequencies of each access request of each key node device in the communication network and illegal access, and denote them as , indicating the number of the th key node device, , indicating the number of the th access request. Similarly, obtain the matching factors between the access time, IP ownership, number of failed connection attempts, protocol - port combination of each access request of each key node device in the communication network and illegal access, and denote them as respectively. .
[0058] By analyzing the formula , obtain the illegal access tendency degree of each access request of each key node device in the communication network , where respectively represent the preset weights of traffic frequency, access time, IP ownership, number of failed connection attempts, and protocol - port combination. .
[0059] Compare the illegal access tendency degree of each access request of each key node device in the communication network with the preset illegal access tendency degree threshold. If the illegal access tendency degree of a certain key node device's certain access request is greater than the threshold, it is determined as an illegal access request.
[0060] It should be noted that for a feasible simulation process, according to the number of access requests and the number of access devices of the communication network's illegal access requests, obtain the communication network illegal access risk level assessment result based on the illegal access risk level assessment model. For details, refer to Table 7.
[0061] Table 7. Illegal Access Risk Level Assessment Result
[0062]
[0063] It should be noted that the present invention extracts access features, calculates based on multi - feature comparison and illegal access tendency degree, efficiently identifies illegal access requests and evaluates the risk level, realizes the identification and risk classification of illegal access requests, and enhances the system's defense ability.
[0064] The control logic monitoring module identifies whether the control logic between devices is tampered with through the collected industrial device operation status data, and triggers a verification alarm when detecting a logic anomaly.
[0065] Furthermore, the specific working process of the control logic monitoring module is as follows: collect real-time data on the operating status of industrial equipment, obtain the execution sequence, execution content, and execution cycle of control instructions between industrial equipment, and compare them with the standard execution sequence, standard execution content, and execution cycle threshold of control instructions between industrial equipment stored in the database.
[0066] Set the abnormal factors corresponding to inconsistent execution sequence, different execution content, and exceeding the execution cycle threshold respectively, match the abnormal factors corresponding to the execution sequence, content, and cycle of control instructions between industrial equipment, accumulate them to obtain the abnormal coefficient of the control logic between industrial equipment, and compare the result with the set threshold. If it is greater than the threshold, the control logic between industrial equipment is abnormal and has been tampered with.
[0067] It should be noted that the execution sequence, execution content, and execution cycle of control instructions between industrial equipment are the core of the control logic. Among them, the execution sequence is the timing skeleton of the control logic, the execution content is the behavior definition of the control logic, and the execution cycle is the timing constraint of the control logic. The sequence, content, and cycle jointly encode the complete rule chain of "when → what to do → how long to last", and these three jointly define the core rules for the system to operate, ensuring that the equipment completes collaborative tasks at the correct time and in the correct way.
[0068] It should be noted that it is reasonable to determine logical tampering by monitoring the execution sequence, execution content, and execution cycle of industrial equipment control instructions, because the normal operation of the industrial control system depends on the strict timing, parameter consistency, and periodic law of the predefined logic. If an attacker tampers with the control logic, it will inevitably lead to the instruction sequence violating the established process flow (such as wrong step sequence), the execution parameters deviating from the safety threshold (such as abnormal numerical injection), or unexpected fluctuations in the operation interval (such as cycle compression / extension). These features have quantifiable differences from the legal behavior patterns in the baseline model. By comparing the characteristic parameters of the actual instruction flow with the standard logic in real time and combining with the anomaly detection algorithm, it is possible to effectively identify hidden logical tampering behaviors. Its essence is to construct an abnormal behavior fingerprint using the deterministic characteristics of the control system, which conforms to the double verification principle of "whitelist + behavior analysis" in industrial security defense.
[0069] It should be noted that by comparing the equipment operation status data with the standard logic, this invention detects abnormalities in the execution sequence, content, or cycle of the control logic, and thus discovers control logic tampering behaviors in a timely manner to ensure the normal operation of industrial equipment.
[0070] After receiving the verification alarm, the traceability analysis module retrieves the operation logs, behavior trajectories, and version update records for multi-dimensional analysis, and uses the decision tree algorithm to determine that the reason for tampering belongs to one or more combinations of misoperation, malicious tampering, or system download and update.
[0071] Further, referring to Figure 3 as shown, the traceability analysis module includes a misoperation analysis unit, a malicious tampering analysis unit, and a system download and update analysis unit. The specific working process of the misoperation analysis unit is as follows: retrieve the operation log of the industrial device, obtain the modification time point of the control logic program code of the industrial device and the text before and after the modification. If the modification time point of the program code is during normal working hours or error-prone hours and the conversion of the text before and after the modification conforms to common input errors, it is determined that the reason for the tampering of the control logic between industrial devices is misoperation.
[0072] As a preferred solution, the error-prone hours include shift change, fatigue period, etc.
[0073] As a preferred solution, the common input errors include space, deletion, copying, swapping positions, etc.
[0074] Further, the specific working process of the malicious tampering analysis unit is as follows: obtain the behavior trajectory of the operation of the industrial device personnel, identify whether there are set malicious tampering behavior characteristics. If so, it is determined that the reason for the tampering of the control logic between industrial devices is malicious tampering. The malicious tampering behavior characteristics include operation mode avoiding normal processes, time distribution during non-working hours, deliberately hiding behavior, target selectivity, and no subsequent corrective attempt behavior.
[0075] As a preferred solution, the deliberately hiding behavior includes deleting logs or using others' credentials, etc.
[0076] As a preferred solution, the target selectivity means that the modification of the control logic program code is targeted at specific key parameters or processes.
[0077] Further, the specific working process of the system download and update analysis unit is as follows: obtain the version update record of the industrial device. If the modification time point of the control logic program code of the industrial device coincides with the version update time point, the version update mentions the modification of the control logic, and the control logic can be restored to normal by rolling back to the version before the update, it is determined that the reason for the tampering of the control logic between industrial devices is system download and update.
[0078] It should be noted that the present invention combines operation logs, behavior trajectories, and version update records, and uses decision tree algorithms to distinguish control logic anomalies caused by misoperations, malicious tampering, and system updates, which can clarify the root cause of the problem and facilitate targeted handling.
[0079] The warning execution module triggers differential graded warnings according to the risk level and the classification of the tampering reason.
[0080] Further, the specific working process of the early warning execution module is as follows: Set the mapping relationships between the network attack risk level, illegal access risk level of the communication network, and the reasons for tampering with the control logic between devices and the early warning levels. According to the risk levels and the reasons for tampering, filter out the corresponding early warning levels and trigger an early warning.
[0081] It should be noted that for a feasible simulation process, obtain the early warning level evaluation results based on the network attack risk level, illegal access risk level of the communication network, and the reasons for tampering with the control logic between devices. For specific data, refer to Table 8.
[0082] Table 8. Partial evaluation results of early warning levels
[0083]
[0084] It should be noted that the present invention classifies based on the network attack risk level, illegal access risk level, and reasons for tampering, triggers hierarchical early warnings, and further ensures that the response measures match the risk levels, realizes a differential hierarchical early warning mechanism, and improves the accuracy and efficiency of early warnings.
[0085] The above content is only an example and illustration of the concept of the present invention. Those skilled in the art of the present technology can make various modifications or supplements to the described specific embodiments or use similar methods for substitution, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should fall within the protection scope of the present invention.
Claims
1. An industrial Internet security monitoring and control system, characterized in that, Including: Network security monitoring module: Analyze and identify external network attack behaviors and illegal access requests based on the traffic data of the industrial equipment communication network collected, and analyze the risk level based on parameters such as attack type, attack frequency, influence range, access times, and the number of access devices; Control logic monitoring module: Identify whether the control logic between devices is tampered with through the operation status data of the industrial equipment collected, and trigger a verification alarm when logical anomalies are detected; Traceability analysis module: After receiving the verification alarm, retrieve the operation logs, behavior tracks, and version update records for multi-dimensional analysis, and use the decision tree algorithm to determine that the reason for the tampering belongs to one or more combinations of misoperation, malicious tampering, or system download and update; Early warning execution module: Trigger differential graded early warnings according to the risk level and the classification of the tampering reasons.
2. The industrial Internet security monitoring and control system according to claim 1, characterized in that: The network security monitoring module includes a traffic data collection unit, an external network attack monitoring unit, and an illegal access monitoring unit. The specific working process of the traffic data collection unit is as follows: Set listening ports on each key node device in the industrial equipment communication network to mirror its network traffic, copy the data packets flowing through these devices, and send them to the traffic analysis system to obtain the traffic data of each key node device in the communication network during the monitoring period.
3. An industrial Internet security monitoring and control system according to claim 2, characterized in that: The specific working process of the external network attack monitoring unit includes: Establish traffic baselines for each key node device in the communication network; Use the traffic patterns of normal network activities of the industrial equipment communication network stored in the database to obtain the average traffic, peak traffic, and port traffic distribution of each key node device in the communication network at different time periods; Compare the traffic data of each key node device in the communication network during the monitoring period with its traffic baseline to obtain the deviation of the average traffic, peak traffic, and port traffic distribution relative to the traffic baseline, and input this deviation into the preset relative baseline deviation of traffic data - traffic anomaly coefficient relationship model to output the traffic anomaly coefficient of each key node device. The relationship model contains the quantitative mapping relationship between the relative baseline deviation of traffic data and the traffic anomaly coefficient; If the traffic anomaly coefficient of a certain key node device in the communication network is greater than the set threshold, it is determined that there is an external network attack behavior in the communication network, and this key node device is recorded as an abnormal node device, and the number of abnormal node devices is counted.
4. The industrial Internet security monitoring and control system according to claim 3, wherein: The specific working process of the external network attack monitoring unit further includes: Extract the attack traffic characteristics of each abnormal node device from the traffic data, compare them with the traffic characteristics of various network attacks stored in the database, match the network attack types corresponding to each abnormal node device, and classify and count to obtain the set of attack types of the external network attacks in the communication network; Obtain the network attack frequency corresponding to each abnormal node device, and perform maximum and minimum value calculations to obtain the network attack frequency of the external network attacks in the communication network; Substitute the number of abnormal node devices in the communication network into the corresponding relationship between the number of abnormal node devices and the influence range level preset, and match to obtain the influence range level of the external network attacks in the communication network; Input the set of attack types, attack frequencies, and impact scope levels of external network attacks on the communication network into the evaluation model of the preset network attack risk level to obtain the network attack risk level of the communication network.
5. An industrial Internet security monitoring and control system according to claim 2, wherein: The specific working process of the illegal access monitoring unit is as follows: According to the traffic data of each key node device in the communication network within the monitoring period, extract the characteristics of each access request of each key node device in the communication network within the monitoring period. The characteristics include traffic frequency, access time, IP ownership, number of failed connection attempts, protocol-port combination, and compare them with the corresponding characteristics of illegal access stored in the database to determine whether it is an illegal access request. Further obtain the cumulative number of illegal access requests and the cumulative number of key node devices with illegal access in the communication network, record them as the number of access requests and the number of access devices of illegal access in the communication network, and substitute them into the evaluation model of the preset illegal access risk level to obtain the illegal access risk level of the communication network.
6. The industrial Internet security monitoring and control system according to claim 1, characterized in that: The specific working process of the control logic monitoring module is as follows: Collect real-time data on the operating status of industrial equipment, obtain the execution sequence, execution content, and execution cycle of control instructions between industrial equipment, and compare them with the standard execution sequence, standard execution content, and execution cycle threshold of control instructions between industrial equipment stored in the database. Set abnormal factors corresponding to inconsistent execution sequences, different execution contents, and exceeding the execution cycle threshold respectively, match the abnormal factors corresponding to the execution sequence, content, and cycle of control instructions between industrial equipment, accumulate them to obtain the abnormal coefficient of the control logic between industrial equipment, and compare this result with the set threshold. If it is greater than the threshold, the control logic between industrial equipment is abnormal and has been tampered with.
7. An industrial Internet security monitoring and control system according to claim 1, characterized in that: The traceability analysis module includes a misoperation analysis unit, a malicious tampering analysis unit, and a system download and update analysis unit. The specific working process of the misoperation analysis unit is as follows: Retrieve the operation log of the industrial equipment to obtain the modification time point of the control logic program code of the industrial equipment and the text before and after the modification. If the modification time point of the program code is during normal working hours or error-prone hours and the conversion of the text before and after the modification conforms to common input errors, it is determined that the reason for the tampering of the control logic between industrial equipment is misoperation.
8. An industrial Internet security monitoring and control system according to claim 7, characterized in that: The specific working process of the malicious tampering analysis unit is as follows: Obtain the behavior track of the operation of industrial equipment personnel, and identify whether there are set malicious tampering behavior characteristics. If so, it is determined that the reason for the tampering of the control logic between industrial equipment is malicious tampering. The malicious tampering behavior characteristics include operating mode to avoid normal processes, time distribution during non-working hours, deliberately hiding behavior, target selectivity, and no subsequent corrective attempt behavior.
9. An industrial Internet security monitoring and control system according to claim 7, characterized in that: The specific working process of the system download and update analysis unit is as follows: Obtain the version update record of the industrial equipment. If the modification time point of the control logic program code of the industrial equipment coincides with the version update time point, the version update mentions the modification of the control logic, and the control logic can be restored to normal by rolling back to the version before the update, it is determined that the reason for the tampering of the control logic between industrial equipment is system download and update.
10. The industrial Internet security monitoring and control system according to claim 1, characterized in that: The specific working process of the early warning execution module is as follows: Set the mapping relationship between the network attack risk level, illegal access risk level of the communication network, and the reasons for the tampering of the control logic between devices and the warning level. According to the risk level and the reasons for tampering, filter out the corresponding warning level and trigger a warning.
Citation Information
Patent Citations
Collaborative control methods, systems and related equipment applied to the Industrial Internet
CN114755993B
A method and system for collaborative device control based on industrial internet identification
CN115826539B
Trusted security gateway implementation method based on total element network identifier
CN116633693A
Information security monitoring method and system based on industrial internet
CN118509214A
Security protection system for cloud side end collaborative interaction of power distribution Internet of Things
CN119402235A
Cited By
Frequency converter remote monitoring method and system based on Internet of Things
CN120972647A
A method and system for remote monitoring of a frequency converter based on the Internet of Things
CN120972647B
Industrial internet security operation and maintenance risk assessment method and system
CN121690707A