Industrial control safety technology based on time domain and value domain

Through the joint detection technology of time domain and value domain, combined with dynamic strategy management, the problem of inability to adapt to dynamic industrial control environments and complex abnormal behaviors in the existing technology is solved, and a high-precision and flexible safety detection of industrial control systems is achieved.

CN120353199APending Publication Date: 2025-07-22BEIJING SBR INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510455752.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing technology cannot flexibly adapt to the dynamic industrial control environment in industrial control systems, a single feature analysis method cannot capture complex anomalies across dimensions, and the machine learning method has a high false alarm rate in special operating modes.

Method used

Using industrial control security technology based on time domain and value domain, through data acquisition and preprocessing, time domain analysis, value domain analysis and time domain and value domain joint detection, combined with dynamic strategy management, a comprehensive detection model is built and the detection strategy is dynamically adjusted to deal with different operating scenarios.

Benefits of technology

It significantly improves the accuracy and reliability of abnormal detection, reduces false alarm rates, ensures the continuity and operation stability of the system, and enhances compatibility and detection flexibility for complex multi-protocol industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120353199A_ABST
    Figure CN120353199A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial safety protection, and discloses an industrial control safety technology based on a time domain and a value domain, which comprises the following steps: data acquisition and preprocessing: acquiring and cleaning industrial control protocol instruction data of an industrial control system in real time through a flow monitoring device; performing time domain analysis, and performing modeling and abnormal trend detection on the time sequence characteristics of the instruction data; value domain analysis: carrying out dynamic modeling and real-time verification on a parameter value domain range and a parameter association relationship of the industrial control instruction; carrying out time domain and value domain joint detection, constructing a comprehensive detection model based on time domain features and value domain features, and carrying out anomaly judgment; and dynamic strategy management: dynamically switching a detection strategy according to a maintenance time window and classifying response instruction risks. Through time domain and value domain conjoint analysis and dynamic strategy management, accurate detection and flexible adaptation of industrial control protocol instruction multi-dimensional abnormal behaviors are achieved, and the detection efficiency and the system safety are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial control system security protection, and particularly to an industrial control security technology based on time domain and value domain. Background Art

[0002] With the rapid development of intelligent manufacturing, industrial control systems (ICS) have been gradually widely applied in many key industries such as power, chemical industry, and manufacturing. These systems conduct real-time monitoring of equipment and issue commands through industrial control protocols, greatly improving production efficiency and resource utilization rate. However, the security of industrial control systems has become particularly important. Once the system is attacked or operates abnormally, it will not only cause production interruption, but may also lead to equipment damage or even safety accidents. Therefore, in order to ensure the stable operation of industrial control systems, it is necessary to design a technical means capable of dynamically detecting abnormal industrial control protocol commands to comprehensively improve the response ability and protection effect against potential threats.

[0003] In the instruction detection of industrial control systems, some solutions have been proposed in the prior art. For example, the rule-based detection method can quickly determine whether an instruction conforms to the set security range by statically matching preset rules. This technology is simple to implement and has high real-time performance. The statistical analysis method can capture the dynamic changes of system behavior to a certain extent by establishing a historical baseline, and has a certain detection ability for some abnormal behaviors that deviate from the baseline. The machine learning method uses a training model to learn the normal instruction pattern, has a high detection accuracy for known threats, and can adapt to complex dynamic environments to a certain extent.

[0004] Although the prior art has improved the instruction detection ability of industrial control systems to a certain extent, there are still significant deficiencies. On the one hand, due to the static nature of the rules, the rule-based detection cannot flexibly adapt to the dynamic changes of the industrial control environment. Especially in the maintenance mode or sudden working conditions, the scope of rule matching is limited, and it is difficult to detect unknown threats. On the other hand, the statistical analysis method usually relies on the modeling of a single feature (such as time interval or frequency), and has insufficient judgment ability for multi-parameter correlation anomalies, and is prone to missing complex cross-dimensional abnormal behaviors. In addition, although the machine learning method has advantages in detection accuracy, it has a high dependence on the data volume and training process, and it is difficult to adapt to complex industrial control systems with multiple scenarios and multiple protocols, especially in special operating modes (such as the maintenance mode). Summary of the Invention

[0005] Aiming at the deficiencies of the prior art, the present invention provides an industrial control security technology based on time domain and value domain, which solves the problems in the prior art that the static nature of the rules leads to the inability to adapt to the dynamic industrial control environment, the single feature analysis method cannot capture cross-dimensional complex abnormal behaviors, and the machine learning method has a high false alarm and missed detection rate in special operating modes.

[0006] To achieve the above object, the present invention is realized through the following technical solutions: An industrial control security technology based on time domain and value domain, comprising the following steps: Data acquisition and preprocessing, in which industrial control protocol instruction data of an industrial control system is collected and cleaned in real time through a traffic monitoring device; Time domain analysis, in which the time series characteristics of instruction data are modeled and abnormal trend detection is performed; Value domain analysis, in which the parameter value range and parameter correlation relationship of industrial control instructions are dynamically modeled and verified in real time; Joint detection of time domain and value domain, in which a comprehensive detection model is constructed based on time domain characteristics and value domain characteristics for abnormal determination; Dynamic policy management, in which the detection policy is dynamically switched according to the maintenance time window and the instruction risk is classified and responded to.

[0007] Preferably, the data acquisition and preprocessing includes: Using a traffic monitoring device to collect the industrial control protocol instruction traffic in real time, and the collected content includes time stamp, instruction type, parameter value and device identifier; Performing time synchronization on the collected instruction data to unify the time stamp to the standard time; Cleaning the collected data, removing duplicate data packets, and eliminating extreme outliers through statistical methods; Extracting the characteristics of industrial control instructions, including time interval, instruction frequency and parameter value range.

[0008] Preferably, the time domain analysis includes: Using a time series model to model the time characteristics of industrial control instruction traffic and constructing a prediction model; Calculating the deviation value between the real-time instruction traffic and the prediction model, and determining abnormality based on a preset threshold; Generating an alarm message and triggering a subsequent processing process when an abnormal trend appears.

[0009] Preferably, the time series modeling includes: Using a linear time series model to predict the short-term trend of industrial control instructions; Using a non-linear time series model to model the long-term trend and complex dependence relationship of industrial control instructions.

[0010] Preferably, the value domain analysis includes: Dynamically modeling the upper and lower limit value ranges of industrial control instruction parameters; Constructing a correlation model between industrial control parameters to describe the logical relationship between multiple parameters; Verifying the value range and parameter correlation of industrial control instructions in real time, and calculating the difference between the actual parameter correlation matrix and the reference correlation matrix.

[0011] Preferably, the parameter correlation modeling includes: Establishing the relationship between parameters using a multivariable linear regression model; Describing the joint distribution characteristics of parameters using a multivariable Gaussian distribution model, and determining whether there is an abnormal correlation based on the statistical deviation value.

[0012] Preferably, the joint time-domain and value-range detection includes: Fusing time-domain features and value-range features to construct a comprehensive detection model; Analyzing the fused features using a deep learning model; Classifying the risk levels of industrial control instructions according to the comprehensive detection model, including normal, low risk, and high risk.

[0013] Preferably, the comprehensive detection model includes: A deep learning model based on the attention mechanism, which is used to capture the correlation between time-domain features and value-range features; Assigning an anomaly score to each instruction and making a classification determination according to a preset risk level threshold.

[0014] Preferably, the dynamic policy management includes: Defining a maintenance time window, enabling the maintenance mode and adjusting the detection rules only within the allowed time range; Restoring strict detection rules when the time window is exceeded; Dynamically recording the risk determination results and operation information of all instructions.

[0015] Preferably, the classification of response instruction risks includes: When it is determined as a high-risk instruction, immediately blocking the instruction and triggering a real-time alarm; When it is determined as a low-risk instruction, recording the instruction information and prompting the operator; When it is determined as a normal instruction, directly allowing execution and storing the relevant operation logs.

[0016] The present invention provides an industrial control security technology based on the time domain and the value range. It has the following beneficial effects: 1. The present invention combines time-domain and value-range features, and through dynamic modeling and deep learning model for feature fusion, it can accurately capture multi-dimensional abnormal behaviors in the industrial control system. Compared with the existing single rule-based or baseline detection solutions, it overcomes the defect that they cannot adapt to the diverse instruction behaviors in a complex dynamic environment, and significantly improves the accuracy and reliability of abnormal detection.

[0017] 2. The present invention introduces a dynamic policy management module. By defining the maintenance time window in detail and dynamically switching rules, the system can flexibly respond to different operating scenarios. Compared with the static rule detection mode in the prior art, the present invention reduces false alarms when dealing with special states such as maintenance modes or sudden anomalies, ensuring the continuity and operational stability of the system.

[0018] 3. The present invention uses a multi-modal loss function to optimize the deep learning model, dynamically adjusting the weights of time-domain and parameter value-domain features, significantly enhancing the adaptability of the detection model in multi-scenario industrial control environments. Different from the design of fixed feature weights in the prior art, the present invention effectively improves the compatibility and detection flexibility for complex multi-protocol industrial control systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the specification of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0021] Please refer to the attached Figure 1 , the embodiments of the present invention provide an industrial control security technology based on time domain and value domain, including the following steps: S1. Data collection and preprocessing, in which the industrial control protocol instruction data of the industrial control system is collected and cleaned in real time through a traffic monitoring device; By comprehensively collecting and preprocessing the protocol instruction data in the industrial control system, not only can the temporal consistency of the data be ensured, but also noise data, redundant data can be removed, and key features can be extracted to support the accuracy and efficiency of the subsequent detection module.

[0022] Generally, data collection and preprocessing mainly involve traffic collection, time synchronization, data cleaning, and feature extraction. Through this process, a comprehensive capture and preliminary processing of the industrial control protocol instruction stream can be achieved, laying a foundation for subsequent time series modeling and dynamic value domain modeling.

[0023] In this embodiment, data collection is connected to the industrial control network in a bypass manner to avoid interfering with normal communication. The traffic monitoring device can be deployed at the core nodes of the network, such as switches and routers, and the specific location is determined by the network topology.

[0024] As an option, the collected data mainly includes the following fields of the industrial control protocol: A timestamp t, representing the time when the instruction data is generated; An instruction type C, used to distinguish different industrial control operations, such as read, write, control, etc.; A parameter value P, which is the key data for the actual execution operation; A device identifier D, used to identify the device that issues or receives the instruction.

[0025] In some embodiments, the collected protocols may include industrial protocols such as Modbus, OPCUA, and DNP3. Through parsers that support different protocols, the traffic collection device can capture data packets under multiple protocols, thus ensuring the generality and portability of the technology.

[0026] Generally, there may be deviations in the clocks of different devices in an industrial control system, which will lead to disorder in the time sequence of the collected data. To solve this problem, the collected timestamp is corrected through the Network Time Protocol (NTP), and the correction formula is as follows: t ′ = t + Δt sync Where: t ′ represents the corrected timestamp; t is the original timestamp; Δt sync represents the time offset, which is calculated from the difference between the current time of the device and the reference time.

[0027] In a possible implementation, the time synchronization operation is completed through a global time server. All devices will send synchronization requests to the time server during initial collection to obtain the accurate time offset.

[0028] The existence of duplicate data will interfere with subsequent analysis, so duplicate data needs to be removed after data collection. The judgment criterion for duplicate data can be that "device identifier D + timestamp t + instruction type C" are exactly the same. In this case, the earliest recorded instruction is retained, and other duplicate records are deleted.

[0029] For outlier detection, the interquartile range method (IQR) is used for processing. Specifically: First, calculate the first quartile Q1 and the third quartile Q3 of the data; Then calculate the interquartile range IQR, and the formula is: IQR = Q3 - Q1 Determine the outlier range according to the interquartile range: P low = Q1 - 1.5·IQR, P high = Q3 + 1.5·IQR Values outside the range [P low , P highThe parameter values will be regarded as anomalies and excluded; where: Q1: represents the value at the 25% position in the data; Q3: represents the value at the 75% position in the data; P low : represents the lower limit of acceptable parameter values; P high : represents the upper limit of acceptable parameter values.

[0030] By excluding extreme data through the above method, the interference of outliers on subsequent modeling can be effectively avoided, and the credibility of the data can be improved.

[0031] In the feature extraction stage, in this embodiment, key features related to time domain analysis and value domain analysis are extracted. Generally, time domain features include: Time interval Δt: the time difference between two consecutive instructions, and the calculation formula is: Δt = t i+1 -t i Instruction frequency f: represents the execution frequency of instructions, and the formula is: Value domain features include: Parameter value range P min and P max : the upper and lower limits of parameters obtained through historical data statistics; Parameter correlation matrix R: describes the correlation between multiple parameters In some embodiments, in order to adapt to different industrial control scenarios, the feature extraction module will be dynamically adjusted according to the protocol type. For example, for the Modbus protocol, the register address and function code can be additionally extracted; for the OPCUA protocol, the identifier and variable value of the data node can be extracted. This can provide customized feature support in different industrial control scenarios.

[0032] S2. Time domain analysis, modeling the time series features of instruction data and detecting abnormal trends; Through time domain analysis, sudden abnormal behaviors existing in the instruction stream can be effectively identified, such as sudden changes in the instruction execution frequency or abnormal time intervals between consecutive instructions. This module is closely connected to the aforementioned data acquisition and preprocessing module, using the preprocessed time series feature data as input to provide basic support for subsequent value domain analysis and joint detection.

[0033] Generally, time domain analysis adopts the method of time series modeling, combines short-term and long-term time dependencies, and accurately captures the time series patterns of instructions. In some embodiments, the time series can be analyzed in parallel through multiple models, including the autoregressive integrated moving average model (ARIMA) and the long short-term memory network model (LSTM), to meet the modeling requirements of linear and non-linear time series.

[0034] In this embodiment, first, a time series model is constructed based on the data of the instruction flow of the industrial control system to capture the time dynamic characteristics of normal instructions. Specifically, the autoregressive integrated moving average (ARIMA) model is used for linear modeling of short-term time series, and its prediction formula is as follows: y t = c + φ1y t-1 + φ2y t-2 + … + φ p y t-p + ∈ t - θ1∈ t-1 - … - θ q ∈ t-q Where: y t represents the instruction flow eigenvalue at the current time t; c is a constant term representing the baseline value of the time series; φ1, φ2, …, θ q are autoregressive coefficients representing the relationship between the current value and the previous p time points; ∈ t is a white noise term that follows a normal distribution with a mean of zero; θ1, …, θ q are moving average coefficients used to describe the correlation between the current value and the previous q noise terms.

[0035] As an option, for parts of the instruction sequence with obvious non-linear characteristics or long-term dependencies, a long short-term memory network (LSTM) is used for modeling. The LSTM model captures complex time series patterns through gated units, and its state update formula is: f t = σ(W f · [h t-1 , x t + b f ) i t = σ(W i · [h t-1 , x t + b i ), h t = o t - tanh(C t ), o t = σ(W o · [h t-1 , x t + b o ) Where: x t represents the input feature at time t; h t is the hidden state at the current time t, representing the output of the model; Ct is the state of the memory cell at the current moment; f t is the forget gate, used to control whether to retain the information from the previous moment; i t is the input gate, indicating the influence of the current input on the memory cell; o t is the output gate, determining the content output by the model; W f , W i , W C , W o are the model weight matrices, b f , b i , b C , b o are the bias terms; σ(·) is the Sigmoid activation function, and tanh(·) is the hyperbolic tangent function.

[0036] In a possible implementation, anomaly detection is performed by calculating the deviation between the real-time instruction stream and the predicted value of the time series model. The formula for calculating the deviation is: where: e t is the deviation, used to measure the gap between the actual value and the predicted value; y t represents the actual instruction feature value at time t; represents the predicted value of the time series model at time t.

[0037] Generally, when the deviation e t exceeds the preset threshold ασ e , it is determined that the instruction at this moment is abnormal. The formula for setting the threshold is: where: σ e is the standard deviation of the deviation; n represents the number of deviation samples; is the average value of the deviation; α is the sensitivity parameter, used to adjust the strictness of the detection.

[0038] As an extension, during the time-domain analysis process, the dynamic adjustment of the time window can be combined to adapt to different types of industrial control instruction streams. Specifically: For short-cycle high-frequency instructions, the time window should be set shorter to capture small timing changes; For long-term low-frequency instructions, the time window should be appropriately extended to avoid missing sudden anomalies.

[0039] In some embodiments, the length of the time window can be dynamically adjusted and optimized based on the statistical characteristics of the real-time instruction stream. The basis for adjustment includes the execution frequency of the instruction, the mean and variance of the time interval, etc.

[0040] S3. Range analysis: Dynamically model and perform real-time verification on the parameter value range and parameter correlation relationship of industrial control instructions. This module is closely connected to the aforementioned time-domain analysis module. Through the instruction timing anomalies determined by time-domain analysis, the rationality verification of parameter values can be further combined to improve the accuracy of anomaly detection. Generally, range analysis includes dynamic parameter value range modeling and parameter correlation verification, aiming to capture the characteristics of abnormal instructions from a numerical perspective.

[0041] In some embodiments, range analysis adopts multivariate modeling technology, not only validating the upper and lower limits of parameter values, but also modeling the dynamic correlation characteristics between parameters to achieve adaptability to complex industrial control environments. Through range analysis, the accurate detection ability for abnormal industrial control instructions can be significantly improved, providing key inputs for subsequent joint detection models.

[0042] In this embodiment, first, dynamically model the parameter value range of industrial control protocol instructions, and based on historical data and real-time data, dynamically update the upper and lower limit ranges of parameters. The range of parameter value ranges is usually calculated by statistical methods, and its upper and lower limits are defined as: P min = μ P - k·σ P , P max = μ P + k·σ P Where: P min and P max are the lower and upper limits of the parameter value respectively; μ P represents the mean of the parameter value; σ P represents the standard deviation of the parameter value; k is an adjustment coefficient used to flexibly control the value range.

[0043] Generally, the parameter value must satisfy the condition that P ∈ [P min , P max , otherwise it is determined as abnormal. In some embodiments, the selection of the adjustment coefficient k can be optimized according to the tolerance of the device. For example, for high-precision devices, the value of k is relatively small, while for devices with a higher error tolerance, the value of k can be appropriately increased; In a possible implementation, for the case where there is a strong correlation between parameters, model it through a multivariate regression model to capture the logical relationship between parameters. The expression of the multivariate regression model is: P j = w1P1 + w2P2 + … + w n-1 P n-1 + ∈ Where: P j is the target parameter; P1, P2, …, P n-1 are related parameters; w1, w2, …, wn-1 is the regression coefficient; ∈ is the error term, used to describe the residuals of model fitting.

[0044] Specifically, the regression coefficient w i can be estimated by the least squares method, and the formula is: W = (X T X) -1 X T Y where: X is the parameter matrix, with each column being a relevant parameter; Y is the target parameter value vector; W is the regression coefficient vector.

[0045] As an option, for the non - linear relationship between multiple parameters, the Gaussian distribution modeling method can be used to describe the joint distribution characteristics of the parameters. The probability density function of the Gaussian distribution model is: where: P is the parameter vector; μ is the parameter mean vector; ∑ is the parameter covariance matrix, describing the correlation between parameters; |∑| represents the determinant of the covariance matrix.

[0046] Generally, the Mahalanobis distance ΔP of the parameters is calculated to determine whether the parameter combination is abnormal, and its calculation formula is: ΔP = (P - μ) T Σ -1 (P - μ) where: ΔP is the deviation degree of the parameters; P - μ is the difference vector between the parameter vector and the mean value; ∑ -1 is the inverse matrix of the covariance matrix.

[0047] When the Mahalanobis distance ΔP exceeds the preset threshold, it is determined that the parameter combination is abnormal.

[0048] In the real - time analysis process, this embodiment dynamically verifies the parameter value range and parameter correlation matrix of the industrial control protocol instructions.

[0049] In the real - time analysis process, this embodiment dynamically verifies the parameter value range and parameter correlation matrix of the industrial control protocol instructions. Generally, the real - time correlation matrix is calculated by the following formula: where: R ij represents the correlation between parameter R i and R j ; Cov(P i , P j ) is the covariance of P i and P j ; and are the variances of P i and Pj Standard deviation

[0050] Specifically, calculate the real-time correlation matrix R t and compare it with the reference correlation matrix R baseline to quantify the degree of difference by calculating the Frobenius norm of the two matrices: ΔR = ||R t - R baseline || F where: ||·|| F represents the Frobenius norm of the matrix, defined as the square root of the sum of the squares of the elements of the matrix; ΔR is the deviation degree of the correlation matrix; R t represents the real-time correlation matrix of the industrial control protocol instruction parameters at the current moment t; R baseline represents the reference correlation matrix under normal operating conditions in the industrial control environment, which is a reference matrix calculated from historical data.

[0051] When ΔR exceeds the set threshold, it is determined that the correlation of the current instruction parameters is abnormal; As an extension, in some embodiments, the verification of the parameter value range and the correlation matrix can be optimized in combination with the specific characteristics of the industrial control protocol. For example, for the Modbus protocol, independent value range detection rules can be set for the legal range of register addresses; for the OPCUA protocol, the upper and lower limit ranges of parameters can be dynamically adjusted based on the type of data nodes. This protocol-aware dynamic adjustment mechanism can further improve the flexibility and adaptability of the value range analysis module.

[0052] Through the above value range analysis method, the present invention can not only accurately verify the single parameter value of the industrial control instruction, but also capture more complex abnormal features through the correlation analysis between multiple parameters.

[0053] S4. Joint detection in the time domain and value range, constructing a comprehensive detection model based on time domain features and value range features for anomaly determination; This module is seamlessly connected to the previous time domain analysis module and value range analysis module, and further makes a comprehensive determination of the abnormal behavior of the industrial control protocol instruction based on the detection results of the two. Generally, single-dimensional detection may miss complex behavior features, while this module improves the accuracy and robustness of anomaly detection through time-value joint analysis.

[0054] In some embodiments, the joint detection uses a deep learning model to perform feature fusion on time domain and value range features, and extracts potential feature correlations through a multi-layer structure, and finally realizes the comprehensive anomaly determination of the instruction. In this way, it can effectively cope with the dynamic behavior patterns in complex industrial control environments and improve the detection efficiency.

[0055] In this embodiment, first, time-domain features and value-domain features are extracted and normalized. The time-domain features include the time interval Δt and frequency f of the instruction, etc.; the value-domain features include the parameter value range P min , P max , the parameter correlation matrix R, etc. To achieve feature fusion, the above time-domain and value-domain features are combined to form a joint feature vector F, which is defined as: F = [T, P] where: F is the joint feature vector; T is the time-domain feature vector, including all time-related features, such as Δt, f; P is the value-domain feature vector, including features such as the parameter value range and the correlation matrix.

[0056] In a possible implementation, the joint feature F after feature fusion is input into a deep learning model for further analysis. Specifically, the model adopts a multi-layer network structure, where each layer is used to extract different levels of feature correlations. The core mechanism of the model is the attention mechanism, and its calculation formula is as follows: Output = AW V where: W Q , W K , W V are the weight matrices of query, key, and value respectively; d k is the dimension of the key vector, used for normalization; A is the attention weight matrix, indicating the correlation between features; Specifically, in this embodiment, the abnormal determination of the joint feature adopts a comprehensive score calculation method. By combining the feature correlation score output by the deep learning model with the individual scores of time-domain and value-domain detections, the comprehensive score S is calculated: S = λ1S T + λ2S P where: S is the comprehensive abnormal score; S T is the abnormal score of the time-domain feature; S P is the abnormal score of the value-domain feature; λ1, λ2 are weight parameters, satisfying λ1 + λ2 = 1.

[0057] Generally, when the comprehensive score S exceeds the preset threshold S threshold , the instruction is determined to be abnormal. This threshold can be adjusted according to the actual requirements of different industrial control environments. For example, in scenarios with high security requirements, the threshold can be appropriately reduced.

[0058] In a possible implementation, to improve the adaptability of joint detection, this embodiment introduces a multi-modal loss function to optimize the training effect of the model. The definition of the multi-modal loss function is as follows: L = αL T + βL P Where: L is the total loss; L T is the loss of time-domain features, representing the prediction error of the model for time features; L P is the loss of value-domain features, representing the prediction error of the model for parameter value features; α and β are weight coefficients, satisfying α + β = 1.

[0059] In some embodiments, the values of α and β can be dynamically adjusted according to the importance of time-domain and value-domain features. For example, when the industrial control system mainly uses periodic instructions, the weight of α can be increased, while for an environment with complex multi-parameter correlations, the weight of β can be increased; To further improve the detection efficiency, this embodiment also introduces a hierarchical detection mechanism. Generally, the hierarchical detection is divided into the following three layers: The first layer: preliminarily filter the joint feature vector F to eliminate obviously normal instructions and reduce the subsequent detection burden; The second layer: extract the potential correlation between time-domain and value-domain features through a deep learning model to generate a preliminary anomaly score; The third layer: make a final determination based on the comprehensive anomaly score S and output the instruction risk level.

[0060] In a specific application scenario, such as in a certain chemical control system, when the parameters of equipment temperature, pressure, and flow are simultaneously abnormal, the joint detection model can capture frequent operation instruction anomalies through time-domain features and at the same time discover that the parameter correlation is damaged through value-domain features. Finally, the model determination score SSS exceeds the threshold and an alarm is triggered; S5. Dynamic policy management, dynamically switch the detection policy according to the maintenance time window and classify and respond to instruction risks; Through dynamic policy management, it can ensure the flexible switching of the detection mechanism at different stages and in different environments during the operation of the system, while ensuring the accurate classification and processing of abnormal behaviors. Generally, dynamic policy management includes three parts: refined management of maintenance time, dynamic adjustment of detection rules, and risk classification and response, aiming to provide more intelligent and efficient security protection capabilities for industrial control systems.

[0061] In some embodiments, the dynamic policy management module is particularly suitable for complex production environments. For example, when the system enters the maintenance mode, certain non-conventional operations may be temporarily permitted, while when the system is in the normal production stage, all instructions must be executed strictly in accordance with the preset rules. This flexible policy adjustment mechanism can significantly reduce the false alarm rate while improving the recognition accuracy of abnormal instructions.

[0062] In this embodiment, first, the maintenance time window is refined and managed by the time control engine. Generally, the maintenance time window is defined as the time range during which non-conventional operations are allowed, and is described by the following formula: T window =[t start ,t end Where: T window is the maintenance time window; t start and t end are the start time and end time of the maintenance operation, respectively.

[0063] As an option, within the maintenance time window, the system will dynamically switch to the relaxed mode. At this time, some non-conventional instructions can be executed, such as calibration instructions for device parameters or adjustment instructions for system configuration. These instructions may not conform to the detection rules of normal production, but are necessary in the maintenance mode. Therefore, the detection rules will be temporarily relaxed while other rules still take effect.

[0064] In a possible implementation, when the time t exceeds T window , the system will automatically switch back to the strict mode. In the strict mode, all instructions must meet the detection standards in the time domain and value domain, otherwise they will be determined as abnormal and trigger blocking.

[0065] Specifically, in this embodiment, the dynamic adjustment of the detection rules adopts a modular design. The detection rules are divided into two parts: basic rules and extended rules: The basic rules cover the core detection standards in time domain analysis and value domain analysis, such as the rationality of the time interval Δt, the legality of the parameter value range P min ,P max , etc.

[0066] The extended rules are dynamically loaded according to specific scenarios, such as instruction parsing rules specific to certain protocols or special instruction processing rules in the device operating state.

[0067] The activation and deactivation of the extended rules are controlled by the following logic: Where: R active is the currently activated rule set; R base is the basic rule; R​i is the i-th extension rule; δ i is the activation status of the extension rule, where the value of 1 indicates activation and 0 indicates deactivation.

[0068] Generally, the value of δ i is determined by the current operating state of the system. For example, when the device enters a high-load operation, the extension rules related to high-frequency instructions may be activated; when the device enters a low-load or maintenance state, these rules are deactivated.

[0069] In this embodiment, the dynamic policy management further includes a risk classification and response mechanism. The risk classification is based on the comprehensive score S calculated by the joint detection module, and the specific classification logic is as follows: When S ≤ S normal , it is determined that the instruction is normal and directly allowed to pass; When S normal < S ≤ S low-risk , it is determined that the instruction is of low risk, and the log is recorded and the operator is prompted; When S > S low-risk , it is determined that the instruction is of high risk, and the block is immediately triggered and an alarm is sent.

[0070] The format of the log record includes the following content: Timestamp t, indicating the execution time of the instruction; Instruction type C, such as read instruction, write instruction, etc.; Parameter value P, such as the current operation parameters of the device; Risk level L, that is, normal, low risk or high risk.

[0071] In a possible implementation, in order to further improve the efficiency of exception handling, the log record also includes the hierarchical output of the detection module, such as the time-domain detection score S T , the value-range detection score S P , the comprehensive score S, etc. These data can be used for subsequent analysis and tracing.

[0072] In some embodiments, the dynamic policy management module can also be combined with an external event trigger mechanism. For example, when the system detects that the frequency of abnormal instructions exceeds a certain threshold, it can automatically switch to a more stringent detection mode to cope with potential network attacks or internal threats. Specifically, when the cumulative frequency f abnormal of abnormal instructions meets the following conditions, an upgrade is triggered: f abnormal ≥ f threshold where: f abnormal is the detection frequency of abnormal instructions; f threshold is the frequency threshold for triggering an upgrade.

[0073] After the upgrade is triggered, the system will enable a higher-level extension rule and send the detailed logs of all instructions to the remote security center for analysis.

[0074] Through the above dynamic policy management mechanism, the present invention realizes the intelligent adaptation to different operating states of the industrial control system.

[0075] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An industrial control security technology based on time domain and value domain, characterized in that, It includes the following steps: Data collection and preprocessing, where the industrial control protocol instruction data of the industrial control system is collected and cleaned in real time through a traffic monitoring device; Time-domain analysis, where the time series characteristics of the instruction data are modeled and abnormal trends are detected; Range analysis, where the parameter range and parameter correlation relationship of the industrial control instructions are dynamically modeled and verified in real time; Joint time-domain and range detection, where a comprehensive detection model is constructed based on time-domain characteristics and range characteristics for anomaly determination; Dynamic policy management, where the detection policy is dynamically switched according to the maintenance time window and the instruction risks are classified and responded to.

2. The industrial control security technology based on time domain and value domain according to claim 1 is characterized in that, The data collection and preprocessing include: Using a traffic monitoring device to collect the industrial control protocol instruction traffic in real time, and the collected content includes time stamps, instruction types, parameter values, and device identifiers; Performing time synchronization on the collected instruction data to unify the time stamps to the standard time; Cleaning the collected data, removing duplicate data packets, and eliminating extreme outliers through statistical methods; Extracting the characteristics of the industrial control instructions, including time intervals, instruction frequencies, and parameter value ranges.

3. The industrial control security technology based on time domain and value domain according to claim 1, characterized in that, The time-domain analysis includes: Using a time series model to model the time characteristics of the industrial control instruction traffic and constructing a prediction model; Calculating the deviation value between the real-time instruction traffic and the prediction model, and determining anomalies based on a preset threshold; Generating an alarm message and triggering the subsequent processing flow when an abnormal trend appears.

4. A kind of industrial control security technology based on time domain and value domain according to claim 3, characterized in that, The time series modeling includes: Using a linear time series model to predict the short-term trend of the industrial control instructions; Using a non-linear time series model to model the long-term trend and complex dependence relationship of the industrial control instructions.

5. A kind of industrial control security technology based on time domain and value domain according to claim 1, characterized in that, The range analysis includes: Dynamically modeling the upper and lower limit ranges of the industrial control instruction parameters; Constructing a correlation model between industrial control parameters to describe the logical relationship between multiple parameters; Verifying the range and parameter correlation of the industrial control instructions in real time, and calculating the difference between the actual parameter correlation matrix and the reference correlation matrix.

6. The industrial control security technology based on time domain and value domain according to claim 5, characterized in that, The parameter correlation modeling includes: Using a multi-variable linear regression model to establish the relationship between parameters; Using a multi-variable Gaussian distribution model to describe the joint distribution characteristics of parameters, and determining whether there is an abnormal correlation based on the statistical deviation value.

7. A kind of industrial control security technology based on time domain and value domain according to claim 1, characterized in that, The joint time-domain and range detection includes: Fusing the time-domain characteristics and range characteristics to construct a comprehensive detection model; Using a deep learning model to analyze the fused characteristics; Classifying the risk levels of the industrial control instructions according to the comprehensive detection model, including normal, low risk, and high risk.

8. An industrial control security technology based on time domain and value domain according to claim 7, characterized in that, The comprehensive detection model includes: A deep learning model based on the attention mechanism, which is used to capture the correlation between the time-domain characteristics and range characteristics; Assigning an anomaly score to each instruction and making a classification determination according to a preset risk level threshold.

9. A kind of industrial control security technology based on time domain and value domain according to claim 1, characterized in that, The dynamic policy management includes: Defining a maintenance time window, enabling the maintenance mode and adjusting the detection rules only within the allowed time range; Restoring strict detection rules when exceeding the time window; Dynamically recording the risk determination results and operation information of all instructions.

10. A kind of industrial control security technology based on time domain and value domain according to claim 1, characterized in that, The classified response to instruction risks includes: When a high-risk instruction is determined, immediately block the instruction and trigger a real-time alarm; When a low-risk instruction is determined, record the instruction information and prompt the operator; When it is determined to be a normal instruction, directly allow execution and store the relevant operation logs.

Citation Information

Patent Citations

  • Industrial control flow anomaly detection method and system based on convolution time sequence network

    CN112738014A

  • Industrial control system-oriented anomaly detection system and method

    CN115484102A

  • Industrial control system anomaly detection method and device based on production behaviors

    CN117370968A

  • Method for detecting abnormal operation of industrial control equipment based on industrial control protocol analysis

    CN119396062A

  • Method for monitoring time-series data, System for monitoring time-series data and Computer program for the same

    KR102011689B1