Monitoring method of industrial network

By monitoring the message transmission time in the industrial network, identifying subsequent added network nodes and activating the security mode, the security threat problem caused by the addition of network nodes in the industrial network is solved, and the monitoring reliability of network security threats is improved.

CN120303905AActive Publication Date: 2025-07-11BECKHOFF AUTOMATION GMBH
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202380085917.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-22
Filing Date
2023-12-15
Publication Date
2025-07-11
Estimated Expiration
2043-12-15

Smart Images

  • Figure CN120303905A_ABST
    Figure CN120303905A_ABST
Patent Text Reader

Abstract

The invention relates to a method for detecting a topology change in an industrial network, said network consisting of an arrangement of network nodes connected to one another, at least one network node determining a transmission time of a message in the industrial network, said network node detecting a change in topology if the determined transmission time or a change in transmission time exceeds a predetermined threshold value. If so, an indication of a network node subsequently added to the network topology is evaluated and a security mode is activated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for detecting changes in an industrial network topology. Background Art

[0002] In an industrial network, network nodes subsequently added without knowledge of network management knowledge pose potential network security threats. For example, subsequently added network nodes may tamper with or disrupt data traffic. Therefore, after network configuration is completed, it is necessary to reliably detect whether additional network nodes have been added. This applies both to ongoing operations and to operation interruptions during the shutdown of the industrial network. Summary of the Invention

[0003] The object of the present invention is to provide improved protection against subsequently added network nodes in an industrial network.

[0004] The object is achieved by the method according to claim 1. Preferred further developments are detailed in the dependent claims.

[0005] In a method for detecting changes in the topology of an industrial network consisting of an arrangement of network nodes connected to each other, the transmission time of messages in the industrial network is determined by at least one network node. If the determined transmission time or the change in the transmission time exceeds a predetermined threshold, this is evaluated as an indication that a network node has been subsequently added to the network topology, and a security mode is activated.

[0006] By means of transmission time monitoring in the industrial network, subsequently added network nodes can be reliably identified, and appropriate protective measures can be initiated by activating the security mode.

[0007] A transmission time monitoring network node can be provided, which reads the determined transmission time from the network node and determines whether the read transmission time exceeds a predetermined threshold. The transmission time monitoring network node is preferably a control node in the industrial network, which determines data transmission in the industrial network.

[0008] Monitoring of network security threats in the industrial network can be carried out centrally by the transmission time monitoring network node, thus adapting to the respective network design.

[0009] Furthermore, it can be provided that a plurality of network nodes perform transmission time measurements, and the transmission time monitoring network node correlates the transmission time measurements of the respective network nodes with each other in order to create a transmission time matrix. By appropriately evaluating the transmission time matrix generated in this way, the transmission time monitoring network node can identify whether and where one or more additional network nodes have been added.

[0010] The security mode can include a warning message that can be acknowledged to exit the security mode.

[0011] This ensures that the operator is aware of the status of cybersecurity threats in the industrial network and can deactivate incorrect security mode activations again, for example, if required changes in the network topology are considered subsequent to the addition of network nodes.

[0012] The threshold can be associated with environmental parameters, in particular the ambient temperature. The threshold can also be associated with operating parameters, in particular the operating time.

[0013] By associating the threshold with the environmental or operating parameters of the industrial network, the reliability of monitoring cybersecurity threats in the industrial network can be improved. In particular, the number of incorrect security mode activations can be guaranteed to be reduced.

[0014] The network node for determining the transmission time can be the first network node that measures the transmission time of a message to a connected second network node using the Precision Time Protocol.

[0015] Through this step, the transmission time between two adjacent network nodes can be continuously determined. The variations in the determined transmission time caused by changing environmental influencing factors, in particular the ambient temperature and component temperature, generally remain below the threshold, which means reliable monitoring is achieved.

[0016] To determine the transmission time, the network node can also measure the time between sending a message and the message being returned.

[0017] Here, the network node that measures the time between sending a message and the message being returned can be the first network node after the control node in the network topology.

[0018] In addition, multiple network nodes can each measure the time between sending a message and the message being returned, where the number of the multiple network nodes is determined according to the operating conditions of the industrial network.

[0019] In an industrial network where the sent message is processed by network nodes during transmission, a simplified time measurement can be performed, which can optimally match the corresponding network topology. Description of the Drawings

[0020] The present invention will be explained in more detail below with reference to the drawings. In the drawings:

[0021] Figure 1 A schematic diagram of an Ethernet-based industrial network 1 is shown; and Figure 2 Shows the measurement Figure 1 A method for measuring the transmission time between two network nodes in the shown industrial network. Detailed Description of the Invention

[0022] Industrial networks are used for production automation and process automation, where decentralized devices of machine peripherals, such as I / O modules, measurement sensors, drives, valves, and operator terminals, communicate with automation systems, engineering systems, or visualization systems via a powerful communication system.

[0023] The active participants in an industrial network are automation systems, engineering systems, or visualization systems, hereinafter referred to as control nodes. They usually have network access authorization, send control data or output data, and monitor data transmission and network status in the industrial network. Machine peripherals are the receivers of control data in the industrial network, hereinafter referred to as network nodes. They independently or upon request from the control node confirm received messages and send messages with sensor data and status data (also referred to as input data).

[0024] Industrial networks with various transmission rules are used in automation technology. In a cyclic industrial network, data is transmitted regularly and continuously regardless of whether the data has changed. On the other hand, in an acyclic industrial network, data is transmitted only when the data changes or when the control node explicitly initiates data transmission.

[0025] There is also a distinction between site-oriented industrial networks and message-oriented industrial networks. In site-oriented industrial networks, the control node sends a message to the network node, and then the network node confirms or responds to the message. Message-oriented industrial networks are characterized in that the control node issues unacknowledged messages, which can then be processed by all network nodes. In addition, bus-oriented industrial networks are used, where the control node uses messages to transmit all data of all connected network nodes, and the location of the data of the corresponding network node is determined by its position in the message block.

[0026] Since in an industrial environment, network connections are usually continuous from device to device, industrial networks are usually implemented as a ring of network nodes starting from the control node. Industrial networks usually have a two-way connection structure between network nodes here, which means that data transmission between two network nodes can be carried out in both directions.

[0027] Figure 1 A schematic diagram of an Ethernet-based industrial network 1 is shown as an example. Industrial network 1 is divided into multiple network segments here and has a first network segment 10, a second network segment 20, a third network segment 30, and a fourth network segment 40. Each network segment includes multiple network nodes 100.

[0028] The first network segment 10 includes a first network node 111, a second network node 112, a third network node 113, a fourth network node 114, and a fifth network node 115.

[0029] The second network segment 20 has a sixth network node 121, a seventh network node 122, an eighth network node 123, and a ninth network node 124.

[0030] The third network segment 30 includes a tenth network node 131, an eleventh network node 132, and a twelfth network node 133.

[0031] The fourth network segment 40 has a thirteenth network node 141, a fourteenth network node 142, and a fifteenth network node 143.

[0032] The network nodes in different network segments are all interconnected through a bidirectional connection structure. Each network node has at least two interfaces, also known as ports, and each interface is designed for combined data input and data output, also known as a transceiver.

[0033] The first network node 111 of the first network segment 10 is also designed as a first network distributor and connects the first network segment 10 to the second network segment 20. For this purpose, the first network node 111 has an additional third interface, which connects the first network node 111 of the first network segment 10 to the sixth network node 121 of the second network segment 20.

[0034] The third network node 113 of the first network segment 10 is designed as a second network distributor, which connects the third network node 113 of the first network segment 10 to the thirteenth network node 141 of the fourth network segment 40 via an additional third interface.

[0035] The sixth network node 121 of the second network segment 20 is designed as a third network distributor. The third network distributor has another third interface, through which a connection is established between the sixth network node 121 of the second network segment 20 and the tenth network node 131 of the third network segment 30.

[0036] Therefore, Figure 1 The shown network 1 has a structure in which the second network segment 20 and the fourth network segment 40 are connected to the first network segment 10 and thus are located downstream of the first network segment 10. The third network segment 30 is connected to the second network segment 20 and thus is located downstream of the second network segment 20.

[0037] In addition to the network nodes 100 arranged in the network segments, the industrial network 1 also has a control node 101, which is connected upstream of the network segments and is connected to the first network node 111 of the first network segment 10 designed as a first network distributor.

[0038] The entire industrial network can use a unified transmission rate. However, the network nodes 100 in different network segments can also communicate with each other at different transmission rates respectively.

[0039] In an industrial network, the network topology, i.e., the physical order and arrangement of network nodes in the network, is determined using a configuration tool, or manually by selecting network nodes from a list and then adding them to the corresponding positions, or automatically by scanning an already existing network. After determining the network topology, application-specific parameters of each network node are configured, process data, i.e., input data and output data, is determined and linked to the process variables of the control node, and the query frequency or cycle time is set.

[0040] Subsequent network nodes added to the industrial network without knowledge of network management represent a potential network security threat. For example, a subsequently added network node may tamper with or disrupt data traffic. Therefore, after network configuration is completed, it is necessary to reliably detect whether additional network nodes have been added. This applies both to ongoing operations and to operation interruptions during the shutdown of the industrial network.

[0041] A change in the network topology can be determined by having network nodes determine the transmission time of messages in the industrial network, where if the determined transmission time or change in transmission time exceeds a predetermined threshold, it is evaluated as an indication of a network node subsequently added to the network topology and the security mode is activated.

[0042] The security mode can be, for example, a changed data traffic, such as a restricted process data exchange, in order to prevent process data from being damaged. The security mode can also include a warning message to the operator, and if, for example, the operator determines that no additional network nodes have been added undesirably and thus this is a false alarm, the operator can confirm the warning message to end the security mode.

[0043] In many industrial networks, messages sent by the control node (usually as Ethernet frames (according to IEEE 802.3)) are first received by each network node and then parsed. Then the message is forwarded by the network node.

[0044] In such industrial networks, timestamps in messages exchanged between network nodes can be used to perform transmission time measurements. Here, the high-resolution system clock in the network node at the time of the event read through hardware is used as the timestamp for the event. To determine the transmission time of a message between a network node and an adjacent network node, the timestamps of the sent and incoming messages are evaluated in the network node. For this purpose, the Precision Time Protocol (PTP) defined in the IEEE 1588 or IEC 61588 standard and the IEEE protocol P802.1AS-Rev and its further developments derived in Time-Sensitive Networking (TSN) are particularly used.

[0045] There are two method steps for measuring the transmission time here. If the network node can send a message at exactly a predetermined time point using appropriate hardware and software, the sending time point can be sent as a timestamp in the corresponding message. Otherwise, the actual transmission time of the network node is determined by the transmission timestamp temporarily stored in the network node. Then the network node sends the transmission timestamp temporarily stored in the network node in a subsequent message.

[0046] Figure 2 shows Figure 1 the measurement of the transmission time between the first network node 100A and the second network node 100B in the industrial network 1 shown. Here, the network nodes are designed such that each network node first receives a message, then parses it and subsequently forwards it.

[0047] The first network node 100A sends a first message N1 to the second network node 100B at a first sending time point t1, and the second network node receives the first message at a second receiving time point t2. The first sending time point t1 and the second receiving time point t2 are determined by the first sending timestamp in the corresponding first network node 100A and the second receiving timestamp in the second network node 100B.

[0048] In response, the second network node 100B then sends a second message N2 back to the first network node 100A at a third sending time point t3, and the first network node receives the second message N2 at a fourth receiving time point t4. The third sending time point t3 and the fourth receiving time point t4 are in turn determined by the corresponding third sending timestamp in the second network node 100B and the fourth receiving timestamp in the first network node 100A.

[0049] The second network node 100B can here send the second receiving time point t2 and the third sending time point t3 or the second receiving time point t2 and the time difference between the third sending time point t3 and the second receiving time point t2 together with the second message itself to the first network node 100A, or as an option as Figure 1 shown by the dashed line in

[0050] Then, the first network node 100A determines the transmission time t_delay between the first network node 100A and the second network node 100B as follows: t_delay = ((t4 - t1) - (t3 - t2)) / 2.

[0051] The transmission time is determined herein based on the following assumption: the forward path from the first network node 100A to the second network node 100B and the return path from the second network node 100B to the first network node 100A have the same average transmission time that only changes slowly. The transmission time herein includes not only the transmission time on the link between the first network node 100A and the second network node 100B, but also the delays in the transceivers of the two network nodes. However, it can be assumed that this delay is constant.

[0052] In another way, the transmission time can be determined in an industrial network, in which network nodes process messages that are usually sent as Ethernet frames (in accordance with IEEE 802.3) during transmission. During the passage of the message through the network node, the network node obtains the output data determined for the corresponding network node from the received message. Similarly, the input data from the network node is added to the message during transmission. Here, the message is not fully received before processing, but processing starts only after the control data in the message is received. Then, the transmission is performed with a minimum offset of several bit times respectively.

[0053] In such an industrial network logically organized as a ring of network nodes, the message passes through each network node that is not connected to the end of the bidirectional connection structure twice.

[0054] In Figure 1 In the industrial network 1 shown, the first network node 111 of the first network segment 10 is designed as the first network distributor, the third network node 113 of the first network segment 10 is designed as the second network distributor, and the sixth network node 121 of the second network segment 20 is designed as the third network distributor, such that the second network segment 20 and the fourth network segment 40 are connected to the first network segment 10 and downstream of the first network segment 10, and the third network segment 30 is connected to the second network segment 20 and downstream of the second network segment 20, the following transmission sequence of the message is obtained.

[0055] Starting from the control node 101, the message enters the first network segment 10 to the first network node 111, then enters the second network segment 20 to the sixth network node 121, to the seventh network node 122, to the eighth network node 123, to the ninth network node 124, returns to the eighth network node 123, to the seventh network node 122, to the sixth network node 121, enters the third network segment 30, to the tenth network node 131, to the eleventh network node 132, to the twelfth network node 133, returns to the eleventh network node 132, to the tenth network node 131, to the sixth network node 121, to the first network node 111, and then in the first network segment 10 to the second network node 112, to the third network node 113, and then enters the fourth network segment 40 to the thirteenth network node 141, to the fourteenth network node 142, to the fifteenth network node 143, returns to the fourteenth network node 142, to the thirteenth network node 141, to the third network node 113, and then further to the fourth network node 114, to the fifth network node 115, and then returns to the fourth network node 114, to the third network node 113, to the second network node 112, to the first network node 111, and then to the control node 101.

[0056] Each network node can generally measure the time (hereinafter referred to as the return time) between the sent and returned messages with high precision at each port. This can be done by means of the timestamps assigned to the messages in the network nodes when sending or receiving messages. The high-resolution system clock in the network node that reads the corresponding event time through hardware here uses the time point of the sending event or receiving event as the timestamp.

[0057] In Figure 1 In the industrial network shown, the transmission time measurement can be carried out in the following way: The network node 100 determines the return time of the special message sent by the control node 101 at all ports and inputs it into the storage register in the network node that can be read by the control node. After the message has circulated through the network segment, the control node 101 reads the reception time or return time from the storage register of the network node by means of another message, and can thereby determine the transmission time between the individual network nodes 100.

[0058] For example, if Figure 1 the seventh network node 122 in the second network segment 20 in the industrial network 1 shown determines the first reception time t1 on the way there and the fourth reception time t4 on the way back, and the eighth network node 123 in the second network segment 20 determines the second reception time t2 on the way there and the third reception time t3 on the way back, then the control node 101 determines the transmission time t_delay between the seventh network node 122 and the eighth network node 123 as follows: t_delay = ((t4 - t1) - (t3 - t2)) / 2。

[0059] The determination of the transmission time is again based on the assumption that the forward path from the seventh network node 122 to the eighth network node 123 and the return path from the eighth network node 123 to the seventh network node 122 have the same average transmission time that only changes slowly. The transmission time here includes not only the transmission time on the link between the seventh network node 122 and the eighth network node 123, but also the transmission delays in the two network nodes. However, it can be assumed that this transmission delay is constant.

[0060] Since in Figure 1 the industrial network 1 shown, as described above, all the network nodes connected to the ports of the network nodes are traversed by the message, the transmission time measurement can be performed in such a way that all network nodes determine the return times through all downstream network nodes.

[0061] The first network node 111 receives a message from the control node 101 at its first port and forwards it through its second port to the second network segment 20. The message returned from the second network segment 20 is forwarded to the first network segment 10 at the third port of the network node 111, and the message returned from the first network segment 10 is returned to the control node 101 through the first port.

[0062] Therefore, the return time at the second port of the first network node 111 corresponds to the transmission time from the first network node 111 through the sixth network node 121, the seventh network node 122, the eighth network node 123, the ninth network node 124, the eighth network node 123, the seventh network node 122, the sixth network node 121, the tenth network node 131, the eleventh network node 132, the twelfth network node 133, the eleventh network node 132, the tenth network node 131, and the sixth network node 121.

[0063] Therefore, the return time at the third port of the first network node 111 corresponds to the transmission time from the first network node 111 through the second network node 112, the fourth network node 113, the thirteenth network node 141, the fourteenth network node 142, the fifteenth network node 143, the fourteenth network node 142, the thirteenth network node 141, the third network node 113, the fourth network node 114, the fifth network node 115, the fourth network node 114, the third network node 113, and the second network node 112.

[0064] In an industrial network where messages are processed during transmission, the transmission time is a purely hardware property. Even when spanning multiple network nodes, it depends on the length of the connection line as well as the number and nature of the network nodes, but not on specific tasks within their communication cycles. Whether a network node only forwards messages or whether a network node processes messages (i.e., reads output data from the message or writes input data into the message) has no bearing on the transmission time.

[0065] A transmission time monitoring network node can be provided in the industrial network, which reads and stores the transmission time between network nodes in the network from each network node that performs transmission time measurement. The transmission time monitoring network node can be, for example Figure 1 the control node 101 of the industrial network 1 shown.

[0066] If the transmission time between two adjacent network nodes is continuously determined, the variation in the determined transmission time due to changing environmental influencing factors, especially the ambient temperature and component temperature, usually remains below the threshold. On the other hand, network node exchanges may cause the threshold to be exceeded, thus issuing a warning. Therefore, network node exchanges must be confirmed accordingly.

[0067] The threshold can be set such that the threshold corresponds to the expected transmission time on the line between two adjacent network nodes as well as the transceiver delays in the two network nodes plus a tolerance value that takes into account possible changes in temperature conditions and operating conditions. The additional extension of the transmission time due to message processing and message transmission in another network node added subsequently between the two network nodes (which is many times higher than the line transmission time and transceiver delays) will always exceed such a threshold and will be detected.

[0068] In an industrial network where the transmission time is determined by the return time of the first network node downstream of the control node, in a large network with many network nodes, due to component dispersion and the aging process of the connected network nodes, the exact number of network nodes cannot be directly obtained. Due to environmental influencing factors, especially the ambient and component temperature, the transmission time also changes during continuous operation. In a large network with many network nodes, the variations in the overall network return time related to the system tend to be greater than the impact of subsequently added additional network nodes.

[0069] The typical transmission delay of network nodes ranges from 1000 ns to 1500 ns (round trip direction), depending on the hardware version, and is affected by typical temperature-related variations in the range of 1 - 2%. The transmission time on the line is approximately 5 to 6 ns / m, depending on the cable design, and does not change significantly with temperature.

[0070] Therefore, the measurement of individual network nodes downstream of the control node is usually sufficient only in small industrial networks with a small number of network nodes. In a small network, for example, fewer than 20 network nodes, due to environmental impact changes, such as changes in the return time due to cooling during an operation interruption, are relatively small compared to the increase in transmission time caused by subsequently added network nodes. Here, it is sufficient to monitor the return time at the output interface of the first network node after the control node.

[0071] In large industrial networks with, for example, more than 20 network nodes, the return time must be monitored by multiple network nodes, for example, every twentieth network node in the industrial network.

[0072] Here, the network distributor can be used as a network node to determine the transmission time. In Figure 1 the industrial network 1 shown, in addition to the first network node 111 of the first network segment 10 as the first network distributor, the third network node 113 of the first network segment 10 can also be used as the second network distributor, and the sixth network node 121 of the second network segment 20 as the third network distributor for measuring the transmission time of respective network segment messages.

[0073] By this method step, the transmission time measurements of the respective network distributors can be correlated with each other to create a transmission time matrix. This can be done by a transmission time monitoring network node, such as a control node, which reads the return time from the network nodes in the industrial network that perform time determination and forms a transmission time matrix. By appropriately evaluating the transmission time matrix generated in this way, the transmission time monitoring network node can identify whether and where one or more additional network nodes have been added.

[0074] This can be done by comparing the determined transmission time with a threshold value, each threshold value indicating the maximum transmission time value expected for the transmission time period. The transmission time matrices generated one after another in time can also be compared with each other, and the maximum allowable change in the transmission time can be set as the threshold value.

[0075] The number of network nodes that measure the time between the sent message and the returned message can be determined according to the operating conditions of the network.

[0076] By this step, additional network nodes added at the end of the network segment or at unused interfaces of the network nodes can also be identified. However, this is less relevant because in any case, the addition is detected by network nodes that evaluate the connection status of the interfaces. In a protected environment, for example, the deactivation of unused interfaces triggered by the network nodes themselves or by the control nodes in the industrial network can effectively prevent network nodes from being added unexpectedly.

[0077] For improved monitoring, exceeding a threshold can be evaluated as an indication of a network node subsequently inserted into the network topology, which is associated with environmental parameters such as ambient temperature and / or operating parameters such as the transmission time of an industrial network. Thus, as described above, the transmission delay and thus the transmission time at the network node depend on the temperature. This also applies to the line structure between network nodes. An operating interruption also causes cooling, which affects the transmission time measurement. By associating with a threshold, false alarms can be prevented.

[0078] For performing improved monitoring, it can also be provided to perform a plurality of transmission time measurements separately in order to subsequently determine an average transmission time.

Claims

1. A method for detecting topological changes in an industrial network, the network consisting of an arrangement of network nodes connected to each other, wherein at least one network node determines the transmission time of messages in the industrial network, wherein if the determined transmission time or change in transmission time exceeds a predetermined threshold, it is evaluated as an indication of a network node to be subsequently added to the network topology and a security mode is activated.

2. The method according to claim 1, wherein The transmission time monitoring network node reads the determined transmission time from the network node and determines whether the read transmission time exceeds a predetermined threshold.

3. The method according to claim 2, wherein, The transmission time monitoring network node is a control node in the industrial network, and the control node determines data transfer in the industrial network.

4. The method according to claim 2 or 3, wherein Multiple network nodes perform transmission time measurements, and the transmission time monitoring network node correlates the transmission time measurements of the individual network nodes with each other in order to create a transmission time matrix and identify whether and where one or more additional network nodes have been added by evaluating the transmission time matrix.

5. The method according to any one of claims 1 to 4, wherein The security mode includes a warning message that can be acknowledged to terminate the security mode.

6. The method according to any one of claims 1 to 5, wherein The threshold is associated with environmental parameters, in particular the environmental temperature.

7. The method according to any one of claims 1 to 6, wherein, The threshold is associated with operating parameters, in particular the operating time.

8. The method according to any one of claims 1 to 7, wherein, The network node for determining the transmission time is the first network node that measures the transmission time of a message to a connected second network node using the Precision Time Protocol.

9. The method according to any one of claims 1 to 7, wherein The network node measures the time between sending a message and the message returning to determine the transmission time.

10. The method according to claim 9, wherein, The network node that measures the time between sending a message and the message returning is the first network node after the control node in the network topology.

11. The method according to claim 9 or 10, wherein Multiple network nodes each measure the time between sending a message and the message returning, wherein the number of the multiple network nodes is determined according to the operating conditions of the network.

Citation Information

Patent Citations

  • Method and node for the control of a connection in a communication network

    CN101743724A

  • SDN (Software Defined Network) network abnormality monitoring method

    CN107070714A

  • Automatic network topology detection and fraud detection

    US20130278437A1

  • Network security assessment using a network traffic parameter

    US20190173899A1

  • Attack detection on computer systems

    WO2020221533A1