Industrial internet security protection method and system

By analyzing the device click response time and historical data, combining multi-source fault type judgment and dynamic identity recognition, intelligent industrial Internet security protection is provided, and the problem of insufficient risk identification delay and accuracy in the existing technology is solved, and accurate classification and efficient protection of the equipment fault source types are achieved.

CN120301697AInactive Publication Date: 2025-07-11SHENZHEN BAILONG FISH CLOTHING TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510693727.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing industrial security protection systems lack dynamic understanding and in-depth analysis of the equipment behavior level, resulting in risk identification relies on abnormal instructions or network communication characteristics, resulting in insufficient delay and accuracy of risk identification, and it is impossible to effectively determine whether the equipment has superimposed failure risks.

Method used

By detecting the response time of the device interface, combining historical data to analyze the click response change characteristics, a two-layer convolutional neural network and shallow decision tree are used to detect potential hazards, count the number of risk items and the residence period, and combine the fault code matching and the proportion of network isolation sources to provide intelligent protection direction tips.

Benefits of technology

It enhances the comprehensive protection capability for network exceptions and identity exceptions, improves the security and intelligent response level of system operation, and improves the accuracy and processing efficiency of risk identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301697A_ABST
    Figure CN120301697A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial internet security protection method and system, relates to the technical field of industrial internet information security, is used for solving the problems that risk identification is delayed and whether equipment has a superimposed fault hidden danger or not cannot be judged, and determines click response change characteristics through click response time and historical data of an operation equipment interface. Selecting a corresponding potential risk detection method to carry out potential risk preprocessing on the equipment, obtaining a plurality of risk items according to a preprocessing result, combining the number of the risk items of the equipment and a retention period dominant value to analyze an equipment fault source type, selecting a corresponding processing method for a single-cause equipment fault source type, and selecting a corresponding processing method for a multi-cause equipment fault source type. The network isolation source proportion and the identity recognition source proportion are recorded, and the protection direction prompt is determined, so that the comprehensive protection capability for the network abnormity and the identity abnormity is enhanced, and the safety and the intelligent response level of system operation are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial Internet information security. More specifically, the present invention relates to an industrial Internet security protection method and system. Background Art

[0002] With the wide application of industrial Internet technology, more and more industrial terminal devices are connected to the network system, and the device functions are becoming increasingly complex and diverse. Although the existing industrial security protection systems can achieve basic intrusion detection and network isolation functions, most of the protection mechanisms still remain at the level of fixed policies or static feature matching, lacking dynamic understanding and in-depth analysis of the device behavior level.

[0003] The existing technologies have the following deficiencies: Currently, the risk identification of industrial devices mostly relies on abnormal instructions or network communication characteristics, and has not effectively utilized interaction behavior characteristics such as user click responses as the basis for risk precursors, resulting in delayed risk identification and insufficient accuracy, and unable to determine whether there are potential superimposed fault hazards in the devices. Therefore, an industrial Internet security protection method and system are proposed.

[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide an industrial Internet security protection method and system, which detect potential risks based on the device click response behavior characteristics, and combine risk item residence period analysis, multi-source fault type discrimination, and dynamic identity recognition abnormal modeling to solve the problems proposed in the above background art.

[0006] To achieve the above object, the present invention provides the following technical solutions. An industrial Internet security protection method and system includes S1: detecting the click response time of the device interface, analyzing its click response change characteristics in combination with historical data, and selecting a corresponding potential hazard detection method according to the click response change characteristics to perform risk preprocessing on the device; S2: identifying multiple risk items through preprocessing, counting the number of risk items and collecting their residence periods in the device, analyzing the dominant values of the residence periods, and classifying the device as a single cause fault source or a multiple fault source in combination with the number of risk items and the dominant values of the residence periods; S3: performing rule library retrieval processing based on fault codes on the single cause fault source, and for the multiple fault sources, setting a monitoring period, monitoring the status of the network isolation switch, recording the protection shutdown time and the protection shutdown frequency, and calculating the network isolation source ratio; S4: Set a time threshold to filter out low-frequency applications, count the device unlocking error rate and low-frequency application click rate during the monitoring period, calculate the proportion of identity recognition sources, and transmit the proportion of isolation sources and identity recognition sources to the user end to prompt the protection direction.

[0007] In a preferred embodiment, the click response time is obtained by recording the timestamp of the user click event and the timestamp of the device response completion, and subtracting the timestamp of the user click event from the timestamp of the device response completion; The historical data includes the average of historical click response time, which is obtained by selecting the time length of historical data, counting the historical click response time, accumulating the historical click response time and calculating the ratio of the statistical times; The difference between the historical click response time mean and the click response time is calculated to obtain the click response change characteristics.

[0008] In a preferred embodiment, the click response change feature is compared with the response threshold. If the click response change feature is greater than or equal to the response threshold, the double-layer convolutional neural network potential danger detection method is enabled. If the click response change feature is less than the response threshold, the shallow decision tree potential danger detection method is enabled. The double-layer convolutional neural network potential hazard detection method has a slow detection speed and high accuracy, while the shallow decision tree potential hazard detection method has a fast detection speed and slightly lower accuracy; According to the comparison results of the click response change characteristics and the response threshold, different potential danger detection methods are selected to pre-process the potential risks of the equipment.

[0009] In a preferred embodiment, the total number of risk items determined to be abnormal is counted through the risk marking results output by the potential hazard detection method to obtain the number of equipment risk items; By continuously tracking the status of each risk item, when the same risk item continues to exist in consecutive cycles, the system records the cycle number in which it first appears and the cycle number in which it finally does not appear again, and subtracts the cycle number in which it first appears from the cycle number in which it finally does not appear again to obtain the residence period of each risk item in the equipment.

[0010] In a preferred embodiment, all detected risk items are arranged in descending order from large to small according to their corresponding stay periods, the stay period is compared with a preset stay threshold, and short-term sporadic risk items whose stay period is lower than the preset stay threshold are eliminated to obtain a screening result; The screening results include the ranking results of risk items that meet the requirement that the stay period is not less than the preset stay threshold; According to the screening results, traverse all the remaining risk items, extract their corresponding maximum residence periods, sort them in descending order, and select the maximum residence period among all risk items as the explicit value of the residence period of the device; Based on the number of risk items obtained by screening and the explicit value of the residence period, combined with the classification judgment threshold, classify the fault source of the current device. If the number of risk items is less than or equal to the preset risk item number threshold, and the explicit value of the residence period is less than or equal to the preset explicit period threshold, it indicates that the device is of the single-cause fault source type; If the number of risk items is greater than the preset risk item number threshold, or the explicit value of the residence period is greater than the preset explicit period threshold, and any one of them is satisfied, it indicates that the device is of the multiple-fault source type.

[0011] In a preferred embodiment, for the single-cause fault source type, select the rule library retrieval method based on fault code matching as the fault handling method; The rule library retrieval method based on fault code matching determines the fault handling method by comparing the currently detected risk item features with the preset fault code rule library; When the device is of the multiple-fault source type, set the monitoring time, monitor the device network disconnector within the monitoring time, obtain the protection closing time and the protection closing frequency, and analyze the proportion of network isolation sources; Record the start timestamp when the disconnector switches from the "open" state to the "closed" state, and then record the end timestamp when it switches back to the "open" state. Calculate the difference between the end timestamp and the start timestamp to obtain the protection closing time; By continuously monitoring the state change of the network disconnector, whenever it is detected that the disconnector switches from "open" to "closed", it is counted as a protection closing event, and the frequency is accumulated to obtain the protection closing frequency.

[0012] In a preferred embodiment, standardize the protection closing time and the protection closing frequency, and substitute them into the logistic regression algorithm for calculation to obtain the proportion of network isolation sources.

[0013] In a preferred embodiment, obtain the usage duration of each application in the device, and calculate the ratio with the monitoring time duration to obtain the usage frequency of each application; Compare the usage frequency of each application with the preset time threshold. If the usage frequency of the application is greater than or equal to the preset time threshold, it indicates that the current application is of high usage frequency. If the usage frequency of the application is less than the preset time threshold, it indicates that the current application is of low usage frequency; Statistically analyze the identity recognition source features during the monitoring time. The identity recognition source features include the device unlocking error rate and the click-through rate of low-usage frequency applications; Standardize the device unlocking error rate and the click-through rate of low-usage frequency applications, and substitute them into the Beta-distribution function probability density evaluation model to determine the proportion of identity recognition sources.

[0014] In a preferred embodiment, adjust the parameters of the proportion of identity recognition sources and the proportion of network isolation sources respectively for normalization, and transmit the normalized proportion of identity recognition sources and the proportion of network isolation sources to the user side respectively to provide intelligent protection direction tips.

[0015] An industrial Internet security protection system includes a click response module, an evaluation and classification module, an isolation source analysis module, and a protection prompt module, and the modules are connected by signals. The click response module is used to detect the click response time of the operation device interface and analyze the click response change characteristics in combination with historical data, select different potential hazard detection methods according to the click response change characteristics to preprocess the potential risks of the device, and send the preliminary identification results of potential risk items to the evaluation and classification module. The evaluation and classification module is used to count the number of device risk items based on risk items, collect the residence cycle of each risk item in the device, screen each risk item, retain the dominant value of the residence cycle, classify the device as a single-cause failure source or a multiple-cause failure source in combination with the number of device risk items and the dominant value of the residence cycle, and send it to the isolation source analysis module. The isolation source analysis module is used to process the single-cause failure source type by using the rule base retrieval method based on fault code matching, set the monitoring time for the multiple-cause failure source type, monitor the device network isolation switch within the monitoring time, analyze the proportion of network isolation sources based on the protection shutdown time and the protection shutdown frequency, and send it to the protection prompt module. The protection prompt module is used to screen out low-usage frequency applications in the device by setting a time threshold, count the device unlocking error rate and the click-through rate of low-usage frequency applications within the monitoring time, comprehensively analyze the proportion of identity recognition sources based on the device unlocking error rate and the click-through rate of low-usage frequency applications, and transmit the proportion of the two types of failure sources to the user side for protection direction tips.

[0016] The technical effects and advantages of the present invention: 1. The present invention determines the click response change characteristics through the click response time of the operation device interface and historical data, selects the corresponding potential hazard detection method to preprocess the potential risks of the device, obtains multiple risk items based on the preprocessing results, analyzes the device failure source type in combination with the number of device risk items and the dominant value of the residence cycle, selects the corresponding processing method for the single-cause device failure source type, and records the proportion of network isolation sources and the proportion of identity recognition sources for the multiple-cause device failure source type to determine the protection direction tips, enhancing the comprehensive protection ability against network anomalies and identity anomalies, and effectively improving the security and intelligent response level of system operation. Brief Description of the Drawings

[0017] Figure 1 It is a method flow chart of a method for industrial Internet security protection according to the present invention.

[0018] Figure 2 It is a schematic diagram of modules of a system for industrial Internet security protection according to the present invention. Detailed Embodiments

[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0020] Embodiment 1 Please refer to Figure 1 , a method for industrial Internet security protection, and the specific operation process is as follows: S1: Detect the click response time of the operation device interface and combine historical data to analyze the click response change characteristics, and select different potential hazard detection methods according to the click response change characteristics to perform potential risk preprocessing on the device; The click response time refers to the time delay experienced by the user from operating the device interface (such as clicking a button or a control) to the device feedback (such as interface jump or function response), and the unit is usually milliseconds; Specifically, detecting the click response time of the device is to perform touch event monitoring through the application layer API in the human-computer interaction interface of the industrial device. When the device completes logical processing and triggers interface feedback (such as a new page loading completion, a pop-up window opening, a command execution completion, etc.), the response timestamp is recorded; The acquisition logic of the click response time is to record the timestamp of the user click event and the timestamp of the device response completion, and subtract the timestamp of the user click event from the timestamp of the device response completion to obtain the click response time; Historical data refers to the click response time information continuously collected and stored during the actual operation of the device. This information is stored in the historical record library, and the historical record library is used to record and manage the click response time data generated by the device in different time periods and different operation scenarios; Select the historical data time length, count the historical click response time, perform cumulative calculation on the historical click response time and calculate the ratio with the number of statistics to obtain the average historical click response time; It should be noted that the length of the historical data time selected is determined by the experimenter based on the equipment operation cycle and the user interaction frequency. The number of statistical times is the total number of historical click response times counted, which will not be elaborated here; Calculate the difference between the mean value of the historical click response time and the click response time to obtain the click response change feature; Compare the click response change feature with the response threshold. If the click response change feature is greater than or equal to the response threshold, it indicates that the equipment has potential complex risks, and then the double-layer convolutional neural network potential hazard detection method is enabled. If the click response change feature is less than the response threshold, it indicates that the equipment state changes slowly, and then the shallow decision tree potential hazard detection method is enabled; Specifically, the double-layer convolutional neural network potential hazard detection method is a deep learning model with slow detection speed and high accuracy, which is used for high-dimensional feature extraction and multi-level risk discrimination of complex patterns contained in equipment interaction behaviors, and can effectively identify potential security threats caused by multi-source factors. The shallow decision tree potential hazard detection method is a lightweight AI model with fast detection speed and slightly lower accuracy, which is used for rapid classification and preliminary screening of equipment click response features to achieve risk preprocessing under low resource consumption; Furthermore, according to the comparison result of the click response change feature and the response threshold, different potential hazard detection methods are selected to perform potential risk preprocessing on the equipment; S2: Obtain multiple risk items through potential risk preprocessing of the equipment, count the number of equipment risk items, collect the residence cycles of each risk item in the equipment, screen each risk item according to the residence cycle, analyze the residence cycle dominance value, and classify the equipment as a single-factor fault source or a multiple-factor fault source based on the number of equipment risk items and the residence cycle dominance value; The process of obtaining multiple risk items through potential risk preprocessing of the equipment includes the following steps: Input the click response time series, operation path sequence, and interface loading delay behavior characteristics of the equipment in the current cycle into the corresponding potential hazard detection method; Make a comprehensive judgment on the current input multi-dimensional interaction behavior to identify whether there are operation characteristics that deviate from normal behavior; Optionally, the comprehensive judgment can be based on threshold analysis or model decision probability output, etc., which is not limited here, but is specifically set by the experimenter and will not be elaborated here; When an operation feature that deviates from the normal behavior in any dimension feature of the equipment behavior is recognized, it is marked as an independent risk item. Each risk item has a unique number and is accompanied by structured information; Specifically, the structured information includes the risk item number, corresponding trigger conditions, risk types, detection confidence levels, etc., which will not be elaborated here; All detected risk items are aggregated to form a risk item set, and a risk item list is obtained; The logic for obtaining the number of equipment risk items is to obtain the number of equipment risk items by counting the total number of risk items that are judged to be abnormal based on the risk marking results output by the potential hazard detection method; The residence period of each risk item in the equipment refers to the length of time from the first detection of any risk item until the risk item is determined by the system to be eliminated (that is, the risk feature is not detected again in multiple consecutive monitoring cycles). The acquisition logic is to continuously track the status of each risk item. When the same risk item continues to exist in consecutive cycles, the system records the cycle number of its first appearance and the cycle number of the final non-recurrence, and subtracts the final non-recurrence cycle number from the first appearance cycle number to obtain the residence period of each risk item in the equipment; Among them, the cycle number is the cycle length set by the experimenter according to different time intervals. For each cycle, its time length is recorded and marked with a number. The specific total number of cycles and cycle length are obtained by the experimenter according to the equipment operation stability characteristics and risk change response rate, which will not be elaborated here; Arrange all detected risk items in descending order according to their corresponding stay periods, compare the stay period with the preset stay threshold, eliminate short-term sporadic risk items whose stay period is lower than the preset stay threshold, and obtain the screening results; The screening results include the ranking results of risk items that meet the requirement that the stay period is not less than the preset stay threshold; Specifically, the short-term sporadic risk item refers to a transient abnormal event whose stay period is less than a threshold within a set period range in a continuous monitoring period, so as to avoid mistaking a non-continuous fault as a fault source, which will not be elaborated here; According to the screening results, all the retained risk items are traversed, the corresponding maximum stay periods are extracted, and they are sorted from large to small, and the largest stay period among all the risk items is selected as the explicit value of the stay period of the equipment; According to the number of risk items and the explicit value of the dwell period obtained by screening, combined with the classification judgment threshold, the fault source of the current equipment is classified. The specific judgment logic is as follows: If the number of risk items is less than or equal to the preset risk item number threshold, and the dwell period explicit value is less than or equal to the preset explicit period threshold, it means that the device is a single-cause fault source type; Specifically, the single-cause fault source type indicates that the equipment risk items are concentrated and have low persistence, which may be caused by a single functional module failure or external interference, and will not be elaborated here; If the number of risk items is greater than the preset risk item number threshold, or the dwell period explicit value is greater than the preset explicit period threshold, if any one of the above conditions is met, it means that the device is of multiple fault source type; Specifically, the multiple fault source type indicates that multiple functional module failures or the superposition effects of multi-dimensional attack behaviors may exist inside the device; It should be noted that the risk item quantity threshold and the dominant period threshold are empirically set by the experimenters based on the device type, operation behavior model, and historical fault data, which will not be elaborated here; S3: For the single-cause fault source type, select the rule library retrieval method based on fault code matching for processing. When the device is of the multiple fault source type, set the monitoring time, monitor the device network disconnector within the monitoring time, record the protection shutdown time and the protection shutdown frequency, and analyze the proportion of network isolation sources; For the single-cause fault source type, select the rule library retrieval method based on fault code matching as the fault handling method; Specifically: The rule library retrieval method based on fault code matching quickly locates the fault source category and its corresponding processing strategy by comparing the currently detected main risk item features with the preset fault code rule library. The rule library stores typical fault codes, corresponding abnormal behavior descriptions, common causes, and disposal suggestions. The matching logic is as follows: ; In the formula, is the obtained processing solution, is the preset fault code rule library, is the currently identified main risk item; Among them, the preset fault code rule library is a structured fault information set constructed by the experimenters based on a large amount of historical fault data of industrial devices and typical abnormal events. The rule library is indexed by standardized fault codes and contains the triggering conditions, abnormal behavior characteristics, possible causes, and recommended processing solutions corresponding to each fault code, which is used to achieve rapid location and automated fault handling. The rule library can be dynamically extended and updated according to the device model and operating environment. The specific update method is not limited and will not be elaborated here; When the device is of the multiple fault source type, set the monitoring time, monitor the device network disconnector within the monitoring time, obtain the protection shutdown time and the protection shutdown frequency, and analyze the proportion of network isolation sources; Among them, the setting of the monitoring time can be based on the historical fault frequency of the device and the change trend of communication behavior, or the requirements of the operation and maintenance strategy and the risk level assessment result. The specific length of the monitoring time is not limited and will not be elaborated here; The acquisition logic of the protection shutdown time is to record the start timestamp when the disconnector switches from the "open" state to the "closed" state, and then record the end timestamp when it switches back to the "open" state, and calculate the difference between the end timestamp and the start timestamp to obtain the protection shutdown time; Among them, the disconnector is recorded by calling the underlying network service interface. Those skilled in the art can understand that the underlying network service interface includes, but is not limited to, the call of network device drivers, protocol stack status, or firewall control interfaces, which will not be elaborated here; The acquisition logic of the protection shutdown frequency is to continuously monitor the status change of the network disconnector. Whenever it is detected that the disconnector switches from "on" to "off", it is counted as a protection shutdown event, and the frequency is accumulated to obtain the protection shutdown frequency; The protection shutdown time and the protection shutdown frequency are standardized and substituted into the logistic regression algorithm for calculation to obtain the proportion of network isolation sources; It should be noted that the methods of standardization include, but are not limited to, standard linear transformation based on interval scaling, Z-Score standardization method based on statistics, or normalization method based on non-linear mapping function. The application methods of standardization will not be elaborated here; Among them, the calculation formula of the logistic regression algorithm is: ; In the formula, is the result of logistic regression calculation, that is, the proportion of network isolation sources, e is the natural base, y is the linear combination term of the logistic regression model. Specifically, y can be set as: ; In the formula, is the bias term, and are the regression coefficients of the protection shutdown time and the protection shutdown frequency respectively, is the protection shutdown time, is the protection shutdown frequency; Among them, when the protection shutdown time and the protection shutdown frequency are larger, the proportion of network isolation sources is lower, indicating that the device protection mechanism is more stable, the external intervention frequency is lower, and the impact of the network isolation sources relied on by the device on the overall security situation is smaller. On the contrary, it indicates that the network protection fails frequently, or the isolation control strategy fails to be effectively executed, indicating that the network isolation sources account for a relatively high proportion among multiple fault sources; S4: Screen out low-usage frequency applications in the device through a set time threshold, count the identity recognition source characteristics within the monitoring time, analyze the proportion of identity recognition sources by integrating the device unlocking error rate and the click-through rate of low-usage frequency applications, and transmit the proportion of the two types of fault sources to the user side for protection direction prompt; Obtain the usage duration of each application in the device, calculate the ratio with the monitored time duration to get the usage frequency of each application, compare the usage frequency of each application with a preset time threshold. If the usage frequency of the application is greater than or equal to the preset time threshold, it indicates that the current application has a high usage frequency; if the usage frequency of the application is less than the preset time threshold, it indicates that the current application has a low usage frequency; It should be noted that the time threshold is obtained by the experimenter based on the characteristics of the device's historical operation data and the risk level determination criteria, which will not be elaborated here; Specifically, the monitored time has been described in the above content and will not be elaborated here; Statistically analyze the identity recognition source features during the monitored time. The identity recognition source features include the device unlocking error rate and the click-through rate of low-usage-frequency applications; The acquisition logic of the device unlocking error rate is to count the total number of all unlocking behaviors at the device end within the set monitored time, and simultaneously record the number of unlocking failures. Calculate the ratio of the number of unlocking failures to the total number of unlocks to obtain the device unlocking error rate; The acquisition logic of the click-through rate of low-usage-frequency applications is to count the total number of clicks of low-usage-frequency applications during the monitored time, and then calculate the ratio with the total number of clicks of all applications during this monitored time to obtain the click-through rate of low-usage-frequency applications; Standardize the device unlocking error rate and the click-through rate of low-usage-frequency applications, and substitute them into the Beta - distribution function probability density evaluation model to determine the proportion of the identity recognition source; Specifically, denote the standardized device unlocking error rate as , and denote the click-through rate of low-usage-frequency applications as , and construct the joint Beta - distribution probability density function as follows: ; In the formula, represents the input variable, and are the shape parameters respectively, is the Beta function; Among them, the acquisition logic of the proportion of the identity recognition source is: substitute into the two independently constructed Beta distribution functions, calculate their probability density values respectively, and take the identity recognition source influence intensity represented by the distribution function corresponding to the maximum probability density value as the reference basis for the final proportion of the identity recognition source; It should be noted that the shape parameters are obtained by the experimenter through empirical fitting based on the device's historical behavior data, which will not be elaborated here; Add adjustment parameters to the proportion of the identity recognition source and the proportion of the network isolation source respectively for normalization processing; Specifically, the proportion expression after adding adjustment parameters is as follows: Let the proportion of the original identity recognition source be , and the proportion of the original network isolation source be ; Respectively introduce adjustable parameter weight terms and , satisfying , but do not require the sum value of and to be 1; Then the adjusted proportion value introduced is: ; Obviously, according to the above formula, there is: ; Among them, represents the degree of emphasis of the system on identity recognition - type risk factors, represents the sensitivity weight of the system to network isolation - type risk factors. The setting of the specific adjustable parameter weight terms can be flexibly set based on the usage scenario and user habits. For example, in a scenario with a higher data security level, can be set to enhance the influence of the network isolation fault source; Transmit the normalized proportion of the identity recognition source and the network isolation source to the user - end respectively to provide intelligent protection direction tips; The present invention determines the click - response change characteristics through the click - response time of the operation device interface and historical data, selects corresponding potential - danger detection methods to perform potential - risk pre - processing on the device, obtains multiple risk items based on the pre - processing results, analyzes the type of device fault source by combining the number of device risk items and the explicit value of the stay period. For single - cause device fault source types, corresponding processing methods are selected. For multi - cause device fault source types, record the proportion of the network isolation source and the identity recognition source, determine the protection direction tips, enhance the comprehensive protection ability against network anomalies and identity anomalies, and effectively improve the security and intelligent response level of the system operation; Embodiment 2 Please refer to Figure 2 , an industrial Internet security protection system, including a click - response module, an evaluation and classification module, an isolation - source analysis module, and a protection - prompt module, with signal connections between the modules; The click - response module is used to detect the click - response time of the operation device interface and analyze the click - response change characteristics in combination with historical data, select different potential - danger detection methods according to the click - response change characteristics to perform potential - risk pre - processing on the device, and send the preliminary recognition result of potential risk items to the evaluation and classification module; The evaluation and classification module is used to count the number of device risk items based on risk items, collect the residence cycle of each risk item in the device, screen each risk item, retain the explicit value of the residence cycle, classify the device as a single-fault source or a multiple-fault source based on the number of device risk items and the explicit value of the residence cycle, and send it to the isolation source analysis module; The isolation source analysis module is used to process the single-fault source type selection based on the rule library retrieval method of fault code matching, set the monitoring time for the multiple-fault source type, monitor the device network disconnector within the monitoring time, analyze the proportion of the network isolation source based on the protection shutdown time and the protection shutdown frequency, and send it to the protection prompt module; The protection prompt module is used to screen out low-usage frequency applications in the device by setting a time threshold, count the device unlocking error rate and the click-through rate of low-usage frequency applications within the monitoring time, analyze the proportion of the identity recognition source by integrating the device unlocking error rate and the click-through rate of low-usage frequency applications, and transmit the proportion of the two types of fault sources to the user side for protection direction prompt.

[0021] All the above formulas are dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0022] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0023] It should be understood that the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this text generally represents an "or" relationship between the preceding and following associated objects, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.

[0024] In this application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0025] It should be understood that in various embodiments of this application, the magnitude of the serial numbers of the above processes does not imply the sequence of execution. The execution sequence of each process should be determined by its function and internal logic, and should not impose any limitation on the implementation process of the embodiments of this application.

[0026] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this text can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0027] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0028] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other forms.

[0029] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0030] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0031] If the above function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0032] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An industrial Internet security protection method, characterized in that: include: S1: Detect the click response time of the device interface, and analyze the click response change characteristics in combination with historical data. According to the click response change characteristics, select the corresponding potential hazard detection method and perform risk preprocessing on the device; S2: Identify multiple risk items through preprocessing, count the number of risk items and collect their residence period in the equipment, analyze the explicit value of the residence period, and classify the equipment into a single cause fault source or multiple fault sources based on the number of risk items and the explicit value of the residence period; S3: For single-cause fault sources, a rule base search based on fault codes is used for processing. For multiple fault sources, a monitoring cycle is set to monitor the status of network isolation switches, record the protection shutdown time and frequency, and calculate the proportion of network isolation sources; S4: Set a time threshold to filter out low-frequency applications, count the device unlocking error rate and low-frequency application click rate during the monitoring period, calculate the proportion of identity recognition sources, and transmit the proportion of isolation sources and identity recognition sources to the user end to prompt the protection direction.

2. The industrial Internet security protection method according to claim 1, characterized in that: The click response time is obtained by recording the timestamp of the user's click event and the timestamp of the device's response completion, and subtracting the timestamp of the user's click event from the timestamp of the device's response completion. The historical data includes the average of historical click response time, which is obtained by selecting the time length of historical data, counting the historical click response time, accumulating the historical click response time and calculating the ratio of the statistical times; The difference between the historical click response time mean and the click response time is calculated to obtain the click response change characteristics.

3. The industrial Internet security protection method according to claim 2, characterized in that: Compare the click response change feature with the response threshold. If the click response change feature is greater than or equal to the response threshold, the double-layer convolutional neural network potential danger detection method is enabled. If the click response change feature is less than the response threshold, the shallow decision tree potential danger detection method is enabled. The double-layer convolutional neural network potential hazard detection method has a slow detection speed and high accuracy, while the shallow decision tree potential hazard detection method has a fast detection speed and slightly lower accuracy; According to the comparison results of the click response change characteristics and the response threshold, different potential danger detection methods are selected to pre-process the potential risks of the equipment.

4. The industrial Internet security protection method according to claim 3, wherein: The total number of risk items determined to be abnormal is counted through the risk marking results output by the potential hazard detection method to obtain the number of equipment risk items; By continuously tracking the status of each risk item, when the same risk item continues to exist in consecutive cycles, the system records the cycle number in which it first appears and the cycle number in which it finally does not appear again, and subtracts the cycle number in which it first appears from the cycle number in which it finally does not appear again to obtain the residence period of each risk item in the equipment.

5. The industrial Internet security protection method according to claim 4, wherein: Arrange all detected risk items in descending order according to their corresponding stay periods, compare the stay period with the preset stay threshold, eliminate short-term sporadic risk items whose stay period is lower than the preset stay threshold, and obtain the screening results; The screening results include the ranking results of risk items that meet the requirement that the stay period is not less than the preset stay threshold; According to the screening results, all the retained risk items are traversed, the corresponding maximum stay periods are extracted, and they are sorted from large to small, and the largest stay period among all the risk items is selected as the explicit value of the stay period of the equipment; Based on the number of risk items obtained through screening and the explicit value of the residence period, combined with the classification judgment threshold, classify the fault source of the current device. If the number of risk items is less than or equal to the preset risk item number threshold, and the explicit value of the residence period is less than or equal to the preset explicit period threshold, it indicates that the device is of the single-cause fault source type; If the number of risk items is greater than the preset risk item number threshold, or the explicit value of the residence period is greater than the preset explicit period threshold, and any one of them is satisfied, it indicates that the device is of the multiple-fault source type.

6. An industrial Internet security protection method according to claim 5, characterized in that: For the single-cause fault source type, select the rule library retrieval method based on fault code matching as the fault handling method; The rule library retrieval method based on fault code matching determines the fault handling method by comparing the currently detected risk item characteristics with the preset fault code rule library; When the device is of the multiple-fault source type, set the monitoring time, monitor the device network disconnector within the monitoring time, obtain the protection shutdown time and the protection shutdown frequency, and analyze the proportion of the network isolation source; Record the start timestamp when the disconnector switches from the "open" state to the "closed" state, and then record the end timestamp when it switches back to the "open" state. Calculate the difference between the end timestamp and the start timestamp to obtain the protection shutdown time; By continuously monitoring the state change of the network disconnector, each time it is detected that the disconnector switches from "open" to "closed", it is counted as a protection shutdown event, and the frequency is accumulated to obtain the protection shutdown frequency.

7. An industrial Internet security protection method according to claim 6, characterized in that: Standardize the protection shutdown time and the protection shutdown frequency, and substitute them into the logistic regression algorithm for calculation to obtain the proportion of the network isolation source.

8. The industrial Internet security protection method according to claim 1, characterized in that: Obtain the usage duration of each application in the device, and calculate the ratio with the monitoring time duration to obtain the usage frequency of each application; Compare the usage frequency of each application with the preset time threshold. If the application usage frequency is greater than or equal to the preset time threshold, it indicates that the current application is of high usage frequency. If the application usage frequency is less than the preset time threshold, it indicates that the current application is of low usage frequency; Statistically analyze the identity recognition source characteristics during the monitoring time. The identity recognition source characteristics include the device unlocking error rate and the click-through rate of low-usage-frequency applications; Standardize the device unlocking error rate and the click-through rate of low-usage-frequency applications, and substitute them into the Beta-distribution function probability density evaluation model to determine the proportion of the identity recognition source.

9. An industrial Internet security protection method according to claim 8, characterized in that: Add adjustment parameters to the proportion of the identity recognition source and the proportion of the network isolation source respectively for normalization processing, and transmit the normalized proportion of the identity recognition source and the proportion of the network isolation source to the user side respectively to provide intelligent protection direction tips.

10. An industrial Internet security protection system for implementing an industrial Internet security protection method according to any one of claims 1-9, characterized in that: It includes a click response module, an evaluation classification module, an isolation source analysis module, and a protection prompt module, and the signals between the modules are connected; The click response module is used to detect the click response time of operating the device interface, analyze the click response change characteristics in combination with historical data, select different potential hazard detection methods according to the click response change characteristics to perform potential risk preprocessing on the device, and send the preliminary identification result of potential risk items to the evaluation classification module; The evaluation and classification module is used to count the number of device risk items based on risk items, collect the residence cycle of each risk item in the device, screen each risk item, retain the explicit value of the residence cycle, classify the device as a single-fault source or a multiple-fault source based on the number of device risk items and the explicit value of the residence cycle, and send it to the isolation source analysis module; The isolation source analysis module is used to process the single-fault source type selection based on the rule library retrieval method of fault code matching. For the multiple-fault source type, set the monitoring time, monitor the device network disconnector within the monitoring time, analyze the proportion of the network isolation source based on the protection shutdown time and the protection shutdown frequency, and send it to the protection prompt module; The protection prompt module is used to screen out the applications with low usage frequency in the device by setting a time threshold, count the device unlocking error rate and the click-through rate of the applications with low usage frequency within the monitoring time, analyze the proportion of the identity recognition source by synthesizing the device unlocking error rate and the click-through rate of the applications with low usage frequency, and send the proportions of the two types of fault sources to the user side for protection direction prompt.