Method for monitoring an industrial network
By monitoring message transmission time in industrial networks, identifying subsequently added network nodes, and activating security modes, potential cybersecurity threats in industrial networks are addressed, improving the reliability and security of detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BECKHOFF AUTOMATION GMBH
- Filing Date
- 2023-12-15
- Publication Date
- 2026-05-08
AI Technical Summary
In industrial networks, subsequently added network nodes may pose a potential cybersecurity threat, tampering with or disrupting data traffic. Existing technologies struggle to reliably detect the addition of additional network nodes.
By monitoring message transmission time in the industrial network, the system can determine whether the transmission time of network nodes exceeds a predetermined threshold, thereby identifying subsequently added network nodes and activating a security mode to initiate protection measures.
It enables reliable detection of subsequently added network nodes, reduces the activation of erroneous security modes, and improves the reliability of monitoring network security threats.
Smart Images

Figure CN120303905B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for detecting changes in the topology of industrial networks. Background Technology
[0002] In industrial networks, network nodes added subsequently without network management knowledge pose a potential cybersecurity threat. For example, subsequently added network nodes may tamper with or disrupt data traffic. Therefore, after network configuration is complete, it is necessary to reliably detect whether any additional network nodes have been added. This applies both to ongoing operations and to operational disruptions during industrial network shutdowns. Summary of the Invention
[0003] The purpose of this invention is to provide improved protection for network nodes subsequently added in an industrial network.
[0004] The objective is achieved by the method according to claim 1. Preferred further developments are described in detail in the dependent claims.
[0005] In a method for detecting topology changes in an industrial network consisting of an arrangement of interconnected network nodes, the transmission time of messages in the industrial network is determined by at least one network node. If the determined transmission time or the change in transmission time exceeds a predetermined threshold, this is evaluated as an indication that a network node will subsequently be added to the network topology, and a security mode is activated.
[0006] By using transmission time monitoring in industrial networks, subsequently added network nodes can be reliably identified, and appropriate protection measures can be initiated by activating security mode.
[0007] A transmission time monitoring network node can be provided, which reads the determined transmission time from the network node and determines whether the read transmission time exceeds a predetermined threshold. The transmission time monitoring network node is preferably a control node in an industrial network, which determines the data transmission within the industrial network.
[0008] Monitoring of network security threats in industrial networks can be carried out centrally by monitoring network nodes based on transmission time, thus adapting to their respective network designs.
[0009] Furthermore, it can be stipulated that multiple network nodes perform transmission time measurements, and the transmission time monitoring network node correlates the transmission time measurements of each network node with each other to create a transmission time matrix. By appropriately evaluating the transmission time matrix generated in this manner, the transmission time monitoring network node can identify whether and where one or more additional network nodes have been added.
[0010] Safe mode can include warning messages that can be acknowledged to exit safe mode.
[0011] This ensures that operators are aware of the status of cybersecurity threats in the industrial network and can deactivate incorrect security mode activations, for example, if a required change in the network topology is perceived as a subsequent addition of a network node.
[0012] Thresholds can be correlated with environmental parameters, especially ambient temperature. Thresholds can also be correlated with operating parameters, especially operating time.
[0013] By correlating thresholds with environmental or operational parameters of industrial networks, the reliability of monitoring cybersecurity threats within these networks can be improved. In particular, it can ensure a reduction in the number of erroneous security mode activations.
[0014] The network node used to determine the transmission time can be the first network node that uses a precise time protocol to measure the transmission time of messages to the connected second network node.
[0015] This step allows for the continuous determination of transmission time between two adjacent network nodes. Variations in the determined transmission time caused by changing environmental factors, particularly ambient and component temperatures, typically remain below a threshold, signifying reliable monitoring.
[0016] To determine transmission time, network nodes can also measure the time between sending and receiving a message.
[0017] Here, the network node that measures the time between sending and returning a message can be the first network node after the control node in the network topology.
[0018] In addition, multiple network nodes can each measure the time between sending and returning a message, wherein the number of multiple network nodes is determined according to the operating conditions of the industrial network.
[0019] In industrial networks where messages are processed by network nodes during transmission, simplified time measurements can be performed, which can optimally match the corresponding network topology. Attached Figure Description
[0020] The invention will now be explained in more detail with reference to the accompanying drawings. In the drawings:
[0021] Figure 1 A schematic diagram of an Ethernet-based industrial network 1 is shown; and
[0022] Figure 2 Measurements were shown Figure 1 The method for transmitting time between two network nodes in the industrial network shown. Detailed Implementation
[0023] Industrial networks are used for production automation and process automation, where distributed devices such as I / O modules, measurement sensors, actuators, valves, and operator terminals communicate with automation, engineering, or visualization systems through powerful communication systems.
[0024] Active participants in an industrial network are automation, engineering, or visualization systems, hereinafter referred to as control nodes. They typically have network access authorization, send control or output data, and monitor data transmission and network status within the industrial network. Machine peripherals are the receivers of control data in the industrial network, hereinafter referred to as network nodes. They independently or upon request from control nodes acknowledge received messages and send messages containing sensor data and status data (also known as input data).
[0025] Automation technologies utilize industrial networks with various transmission rules. In a circular industrial network, data is transmitted periodically and continuously, regardless of whether it changes. On the other hand, in a non-circular industrial network, data is transmitted only when it changes or when a control node explicitly initiates data transmission.
[0026] There are also differences between site-oriented and message-oriented industrial networks. In site-oriented industrial networks, control nodes send messages to network nodes, which then acknowledge or respond to those messages. Message-oriented industrial networks, on the other hand, are characterized by control nodes sending unacknowledged messages, which can then be processed by all network nodes. Furthermore, bus-oriented industrial networks utilize messages to transmit all data from all connected network nodes, where the location of data for a given network node is determined by its position within the message block.
[0027] Because network connections in industrial environments are typically continuous from device to device, industrial networks are often implemented as a ring of network nodes starting from a control node. Industrial networks here usually have a bidirectional connection structure between network nodes, meaning that data transmission between two network nodes can occur in both directions.
[0028] Figure 1 A schematic diagram of an Ethernet-based industrial network 1 is shown as an example. The industrial network 1 is divided into multiple segments and has a first segment 10, a second segment 20, a third segment 30, and a fourth segment 40. Each segment includes multiple network nodes 100.
[0029] The first network segment 10 includes the first network node 111, the second network node 112, the third network node 113, the fourth network node 114, and the fifth network node 115.
[0030] The second network segment 20 has a sixth network node 121, a seventh network node 122, an eighth network node 123, and a ninth network node 124.
[0031] The third network segment 30 includes the tenth network node 131, the eleventh network node 132, and the twelfth network node 133.
[0032] The fourth network segment 40 has a thirteenth network node 141, a fourteenth network node 142, and a fifteenth network node 143.
[0033] Network nodes in different network segments are interconnected through a bidirectional connection structure. Each network node has at least two interfaces, also known as ports, and each interface is designed to combine data input and data output, also known as a transceiver.
[0034] The first network node 111 of the first network segment 10 is also designed as a first network distributor and connects the first network segment 10 to the second network segment 20. For this purpose, the first network node 111 has an additional third interface that connects the first network node 111 of the first network segment 10 to the sixth network node 121 of the second network segment 20.
[0035] The third network node 113 of the first network segment 10 is designed as a second network distributor, which connects the third network node 113 of the first network segment 10 to the thirteenth network node 141 of the fourth network segment 40 via an additional third interface.
[0036] The sixth network node 121 of the second network segment 20 is designed as a third network distributor. The third network distributor has another third interface, through which a connection is established between the sixth network node 121 of the second network segment 20 and the tenth network node 131 of the third network segment 30.
[0037] therefore, Figure 1 The network 1 shown has a structure in which the second network segment 20 and the fourth network segment 40 are connected to the first network segment 10 and are therefore located downstream of the first network segment 10. The third network segment 30 is connected to the second network segment 20 and is therefore located downstream of the second network segment 20.
[0038] In addition to the network nodes 100 arranged in the network segment, the industrial network 1 also has a control node 101, which is connected upstream of the network segment and to the first network node 111 designed as a first network distributor in the first network segment 10.
[0039] The entire industrial network can use a uniform transmission rate. However, network nodes 100 in different segments can also communicate with each other at different transmission rates.
[0040] In industrial networks, network topology—the physical order and arrangement of network nodes—is determined using configuration tools, manually by selecting network nodes from a list and adding them to their appropriate positions, or automatically by scanning an existing network. After determining the network topology, application-specific parameters for each network node are configured, process data (input and output data) is defined and linked to process variables of control nodes, and query frequency or cycle time is set.
[0041] Adding network nodes to an industrial network without prior knowledge of network management poses a potential cybersecurity threat. For example, these added nodes could tamper with or disrupt data traffic. Therefore, it is crucial to reliably detect any additional network nodes added after network configuration is complete. This applies both to ongoing operations and to operational disruptions during industrial network shutdowns.
[0042] Changes in network topology can be determined by network nodes determining the transmission time of messages in the industrial network. If the determined transmission time or the change in transmission time exceeds a predetermined threshold, it is evaluated as an indication to network nodes subsequently added to the network topology and a security mode is activated.
[0043] Safe mode can, for example, modify data traffic, such as restricting process data exchange, to prevent process data corruption. Safe mode may also include a warning message to the operator, which the operator can acknowledge to end safe mode if, for example, the operator determines that no additional network nodes have been added unnecessarily and therefore this is a false alarm.
[0044] In many industrial networks, messages sent by control nodes (typically as Ethernet frames, according to IEEE 802.3) are first received and parsed by each network node. The message is then forwarded by the network nodes.
[0045] In such industrial networks, transmission time measurements can be performed using timestamps in messages exchanged between network nodes. Here, the time of the event, read from a high-resolution system clock in the network node at the time of the event, is used as the timestamp. To determine the transmission time of messages between a network node and its neighboring nodes, the timestamps of sent and incoming messages are evaluated within the network node. For this purpose, the Precise Time Protocol (PTP) defined in the IEEE 1588 or IEC 61588 standards is specifically used, along with the IEEE protocol P802.1AS-Rev and its further developments derived for Time-Sensitive Networking (TSN).
[0046] There are two methods for measuring transmission time. If a network node can send a message at exactly the predetermined time using appropriate hardware and software, that time can be used as a timestamp in the corresponding message. Otherwise, the actual transmission time of the network node is determined by a transmission timestamp temporarily stored in the network node. The network node then sends the temporarily stored transmission timestamp in subsequent messages.
[0047] Figure 2 It shows Figure 1 The transmission time between the first network node 100A and the second network node 100B in the industrial network 1 shown is measured. In this network node design, each network node first receives a message, then parses it, and subsequently forwards it.
[0048] First network node 100A sends a first message N1 to second network node 100B at a first sending time t1, and second network node 100B receives the first message at a second receiving time t2. The first sending time t1 and the second receiving time t2 are determined by the corresponding first sending timestamp in first network node 100A and the second receiving timestamp in second network node 100B.
[0049] In response, the second network node 100B then sends the second message N2 back to the first network node 100A at the third occurrence time t3, and the first network node receives the second message N2 at the fourth reception time t4. The third transmission time t3 and the fourth reception time t4 are then determined by the corresponding third transmission timestamp in the second network node 100B and the fourth reception timestamp in the first network node 100A.
[0050] The second network node 100B can send the second reception time point t2 and the third transmission time point t3, or the time difference between the second reception time point t2, the third transmission time point t3, and the second reception time point t2, and the second message itself, or as an option, to the first network node 100A. Figure 1 The dashed line in the image indicates that another message, sent later, is sent to the first network node 100A.
[0051] Then, the first network node 100A determines the transmission time t_delay between the first network node 100A and the second network node 100B as follows:
[0052] t_delay=((t4-t1)-(t3-t2)) / 2.
[0053] The transmission time is determined here based on the following assumption: the outgoing path from the first network node 100A to the second network node 100B and the return path from the second network node 100B to the first network node 100A have the same average transmission time that changes only slowly. The transmission time here includes not only the transmission time on the link between the first network node 100A and the second network node 100B, but also the latency in the transceivers of the two network nodes; however, this latency can be assumed to be constant.
[0054] Another approach is to determine the transmission time in industrial networks, where network nodes process messages typically sent as Ethernet frames (according to IEEE 802.3) during transmission. While the message is passing through a network node, the node extracts output data from the received message, determined for the specific network node. Similarly, input data from the network node is added to the message during transmission. Here, the message is not fully received before processing; processing begins only after the control data within the message is received. Then, transmission is performed with a minimum offset of several bits of time.
[0055] In this type of industrial network, which is logically organized as a ring of network nodes, messages pass twice through each network node that is not connected to the end of the bidirectional connection structure.
[0056] exist Figure 1 The first network node 111 of the first network segment 10 shown is designed as a first network distributor, the third network node 113 of the first network segment 10 is designed as a second network distributor, and the sixth network node 121 of the second network segment 20 is designed as a third network distributor, such that the second network segment 20 and the fourth network segment 40 are connected to the first network segment 10 and downstream of the first network segment 1, and the third network segment 30 is connected to the second network segment 20 and downstream of the second network segment 20 in the industrial network 1, the following message transmission sequence is obtained.
[0057] Starting from control node 101, the message enters the first network segment 10 to the first network node 111, then enters the second network segment 20 to the sixth network node 121, the seventh network node 122, the eighth network node 123, and the ninth network node 124, then returns to the eighth network node 123, the seventh network node 122, the sixth network node 121, enters the third network segment 30, the tenth network node 131, the eleventh network node 132, the twelfth network node 133, then returns to the eleventh network node 132, the tenth network node 131, the sixth network node 121, and finally to the first network node 111. Node 111, then to the first network segment 10 to the second network node 112, to the third network node 113, then to the fourth network segment 40 to the thirteenth network node 141, to the fourteenth network node 142, to the fifteenth network node 143, back to the fourteenth network node 142, to the thirteenth network node 141, to the third network node 113, then further to the fourth network node 114, to the fifth network node 115, then back to the fourth network node 114, to the third network node 113, to the second network node 112, to the first network node 111, and then to the control node 101.
[0058] Each network node is typically able to measure the time between sending and receiving a message (hereinafter referred to as return time) with high precision at each port. This can be accomplished using the timestamp assigned to the message in the network node when it is sent or received. Here, the high-resolution system clock in the network node, which is read from the corresponding event time via hardware implementation, uses the time of sending or receiving the event as the timestamp.
[0059] exist Figure 1 In the industrial network shown, transmission time can be measured as follows: Network node 100 determines the return time of a specific message sent by control node 101 at all ports and inputs it into a storage register in the network node that can be read by the control node. After the message has circulated through the network segment, control node 101 reads the reception or return time from the storage register of the network node using another message, and can thereby determine the transmission time between the various network nodes 100.
[0060] For example, if Figure 1 In the industrial network 1 shown, the seventh network node 122 in the second network segment 20 determines the first reception time t1 on the outgoing route and the fourth reception time t4 on the return route. The eighth network node 123 in the second network segment 20 determines the second reception time t2 on the outgoing route and the third reception time t3 on the return route. Therefore, the control node 101 determines the transmission time t_delay between the seventh network node 122 and the eighth network node 123 as follows:
[0061] t_delay=((t4-t1)-(t3-t2)) / 2.
[0062] The transmission time determination is again based on the assumption that the outgoing path from the seventh network node 122 to the eighth network node 123 and the return path from the eighth network node 123 to the seventh network node 122 have the same average transmission time that changes only slowly. The transmission time here includes not only the transmission time on the link between the seventh network node 122 and the eighth network node 123, but also the transmission delay within the two network nodes; however, it can be assumed that this transmission delay is constant.
[0063] Because in Figure 1 In the industrial network 1 shown, as described above, all network nodes connected to the ports of the network nodes are through which messages pass, so the transmission time can be measured in such a way that all network nodes determine the return time through all downstream network nodes.
[0064] The first network node 111 receives a message from the control node 101 at its first port and forwards it to the second network segment 20 through its second port. The message returned from the second network segment 20 is forwarded to the first network segment 10 at the third port of the network node 111, and the message returned from the first network segment 10 is returned to the control node 101 through the first port.
[0065] Therefore, the return time at the second port of the first network node 111 corresponds to the transmission time from the first network node 111 through the sixth network node 121, the seventh network node 122, the eighth network node 123, the ninth network node 124, the eighth network node 123, the seventh network node 122, the sixth network node 121, the tenth network node 131, the eleventh network node 132, the twelfth network node 133, the eleventh network node 132, the tenth network node 131, and the sixth network node 121.
[0066] Therefore, the return time at the third port of the first network node 111 corresponds to the transmission time from the first network node 111 through the second network node 112, the fourth network node 113, the thirteenth network node 141, the fourteenth network node 142, the fifteenth network node 143, the fourteenth network node 142, the thirteenth network node 141, the third network node 113, the fourth network node 114, the fifth network node 115, the fourth network node 114, the third network node 113, and the second network node 112.
[0067] In industrial networks where messages are processed during transmission, transmission time is a purely hardware property, even across multiple network nodes. It depends on the length of the connection and the number and nature of the network nodes, but not on their specific tasks within a communication cycle. Whether a network node merely forwards messages or processes messages (i.e., reads output data from a message or writes input data into a message) is irrelevant to transmission time.
[0068] A transmission time monitoring network node can be provided in an industrial network. This node reads and stores the transmission time between network nodes in the network from each other, as well as from the individual network nodes performing transmission time measurements. The transmission time monitoring network node can be, for example... Figure 1 The control node 101 of the industrial network 1 shown.
[0069] If the transmission time between two adjacent network nodes is continuously determined, the variation in the determined transmission time due to changing environmental factors, particularly ambient and component temperatures, will generally remain below a threshold. On the other hand, network node switching may cause the threshold to be exceeded, thus issuing a warning. Therefore, network node switching must be acknowledged accordingly.
[0070] A threshold can be set such that it corresponds to the expected transmission time on the line between two adjacent network nodes, plus the transceiver delay in the two network nodes, and a tolerance value that takes into account possible variations in temperature and operating conditions. Any additional delay in transmission time caused by subsequent message processing and transmission in another network node added between the two network nodes (which is many times greater than the line transmission time and transceiver delay) will always exceed this threshold and will be detected.
[0071] In industrial networks where transmission time is determined by the return time of the first network node downstream of the control node, and in large networks with many network nodes, the exact number of network nodes cannot be directly determined due to component dispersion and the aging process of connected network nodes. Transmission time also varies during continuous operation due to environmental factors, particularly ambient and component temperatures. In large networks with many network nodes, these system-related variations in overall network return time often outweigh the impact of subsequently added additional network nodes.
[0072] Typical transmission delays at network nodes range from 1000 ns to 1500 ns (round trip), depending on the hardware version, and are affected by typical temperature-dependent variations within the range of 1-2%. Transmission times on the line are approximately 5 to 6 ns / m, depending on the cable design, and do not change significantly with temperature.
[0073] Therefore, measurements of a single network node downstream of the control node are typically sufficient only in small industrial networks with a limited number of nodes. In small networks, such as fewer than 20 nodes, the change in return time due to environmental factors, such as cooling during operational interruptions, is relatively small compared to the increase in transmission time caused by later additions of network nodes. In this case, monitoring the return time at the output interface of the first network node after the control node is sufficient.
[0074] In large industrial networks with, for example, more than 20 network nodes, return time must be monitored by multiple network nodes, such as every twenty network nodes in an industrial network.
[0075] In this network, the distributor can act as a network node to determine transmission time. Figure 1 In the industrial network 1 shown, in addition to the first network node 111 of the first network segment 10 acting as the first network distributor, the third network node 113 of the first network segment 10 can also act as the second network distributor, and the sixth network node 121 of the second network segment 20 acts as the third network distributor to measure the transmission time of messages in each network segment.
[0076] This method allows the transmission time measurements of individual network distributors to be correlated with each other to create a transmission time matrix. This can be accomplished by a transmission time monitoring network node, such as a control node, which reads the return times from network nodes performing time determination in the industrial network and forms the transmission time matrix. By properly evaluating the transmission time matrix generated in this way, the transmission time monitoring network node can identify whether and where one or more additional network nodes have been added.
[0077] This can be done by comparing a given transmission time with thresholds, each threshold indicating the maximum expected transmission time value for a transmission period. Alternatively, transmission time matrices generated one after another over time can be compared, with the maximum permissible variation in transmission time set as a threshold.
[0078] The number of network nodes that can measure the time between sending and receiving messages can be determined based on the network's operating conditions.
[0079] This step can also identify additional network nodes added at the end of a network segment or at unused interfaces of a network node. However, this is less relevant, as the addition is detected by the network node evaluating the connectivity status of the interface anyway. In protected environments, such as those triggered by the network node itself or by control nodes in an industrial network, the deactivation of unused interfaces can effectively prevent the unintended addition of network nodes.
[0080] To achieve improved monitoring, exceeding a threshold can be evaluated as an indication for subsequent insertion into the network topology of network nodes, which is correlated with environmental parameters such as ambient temperature and / or operational parameters such as transmission time in industrial networks. Therefore, as mentioned above, transmission delay at a network node, and thus transmission time, depends on temperature. This also applies to the wiring structure between network nodes. Operational interruptions also cause cooling, thus affecting transmission time measurements. By correlating with a threshold, false alarms can be prevented.
[0081] To perform improved monitoring, multiple transmission time measurements can be specified to be performed separately so that the average transmission time can be determined subsequently.
Claims
1. A method for detecting topology changes in an industrial network, said network consisting of an arrangement of interconnected network nodes. Multiple network nodes determine the transmission time of messages in the industrial network, measuring the time between sending and receiving a message. The number of these multiple network nodes is determined based on the network's operating conditions. If the determined transmission time or the change in transmission time exceeds a predetermined threshold, it is evaluated as an indication that a network node will be subsequently added to the network topology, and the security mode is activated.
2. The method according to claim 1, wherein, The transmission time monitoring network node reads the determined transmission time from the network node and determines whether the read transmission time exceeds a predetermined threshold.
3. The method according to claim 2, wherein, The transmission time monitoring network node is a control node in the industrial network, and the control node determines the data transmission in the industrial network.
4. The method according to claim 2, wherein, Multiple network nodes perform transmission time measurements, and the transmission time monitoring network node correlates the transmission time measurements of each network node with each other to create a transmission time matrix and identify whether and where one or more additional network nodes have been added by evaluating the transmission time matrix.
5. The method according to any one of claims 1 to 4, wherein, The security mode includes warning messages that can be acknowledged to terminate the security mode.
6. The method according to any one of claims 1 to 4, wherein, The threshold is associated with environmental parameters.
7. The method according to any one of claims 1 to 4, wherein, The threshold is the ambient temperature.
8. The method according to any one of claims 1 to 4, wherein, The threshold is associated with the operating parameters.
9. The method according to any one of claims 1 to 4, wherein, The threshold is associated with the operation time.
10. The method according to any one of claims 1 to 4, wherein, The network node used to determine the transmission time is the first network node that uses a precise time protocol to measure the transmission time of messages to the connected second network node.
11. The method according to any one of claims 1 to 4, wherein, The network node that measures the time between sending and returning a message is the first network node after the control node in the network topology.
Citation Information
Patent Citations
Method and node for the control of a connection in a communication network
CN101743724A
SDN (Software Defined Network) network abnormality monitoring method
CN107070714A