Industrial control honey pot defense system and method based on mirror image simulation

By building a high-simulation industrial control honeypot network and deploying authentication nodes, generating access identification verification codes and encrypted communication data, the problems of low simulation accuracy and inaccurate visitor identity recognition in the existing technology are solved, and the defense capability and production stability of the industrial network are improved.

CN120358100AActive Publication Date: 2025-07-22南京迅集科技有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510847730.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

In the existing industrial network defense, the simulation accuracy is low and is easily seen by the attacker, causing the attacker to ignore the simulation network and attack the real network, resulting in wasting computing resources and degradation of defense capabilities, and failing to accurately identify the visitor's identity, which may misjudgment of normal access as an exception, affecting production progress.

Method used

Based on the mirror simulation industrial control honeypot defense system, a high-simulation honeypot network is built by identifying industrial control network data, and the authentication node is deployed to generate access identification verification codes and encrypt communication data. It uses a two-dimensional array of simulated communication behavior data keys for encryption and decryption to determine the identity of the visitor.

Benefits of technology

It improves the defense capabilities of industrial control networks, accurately recognizes normal visitors and attackers, ensures normal production progress, and enhances the accuracy and defense capabilities of access recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358100A_ABST
    Figure CN120358100A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of industrial network defense, and discloses an industrial control honey pot defense system and method based on mirror image simulation. Comprising the following steps: identifying an industrial control network in a factory to obtain equipment information data, an industrial protocol, an equipment topological structure and communication behavior data in the industrial control network; constructing a simulation industrial control honeypot network according to the obtained data; deploying an identification node in the simulation industrial control honeypot network, generating a corresponding access identification check code through the identification node according to simulation communication behavior data in the simulation industrial control honeypot network, and encrypting the simulation communication behavior data to obtain encrypted simulation communication behavior data; checking an access identification check code obtained by decrypting the encrypted simulation communication behavior data by the visitor, judging whether the access is normal or not according to a check result, and making a corresponding response; and the defense capability of the industrial control network in the factory is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial network defense, and more specifically, to an industrial control honeypot defense system and method based on mirror simulation. Background Art

[0002] The patent application with the publication number CN116436653A discloses a honeypot dynamic configuration method, device, honeypot intrusion detection system and storage medium, including: determining the distribution of at least one honeypot in the industrial control device network based on the industrial control device network; generating a description file of the honeypot based on a pre-determined honeypot defense strategy; generating corresponding honeypots in the industrial control device network based on the description file and the distribution; dynamically configuring the at least one honeypot based on an access request to the industrial control device network, and timely adjusting the configuration of the honeypot or honeynet according to the change of the access request, improving the accuracy and efficiency of intrusion detection and trap attacks, and solving the problem that industrial control network attacks in related technologies change the attack method to avoid intrusion detection according to the honeypot recognition situation.

[0003] However, in the process of traditional industrial network defense, the simulation accuracy of the industrial control network is relatively low, which is easy to be recognized by attackers. As a result, attackers will not attack the simulated industrial control network, but look for the real industrial control network to attack, reducing the role of the simulated industrial control network, wasting computing and communication resources, directly attacking the real industrial control network, reducing the defense of the industrial control network, increasing the risk of intrusion of the industrial control network, and not identifying the identity of visitors, which may misjudge normal access as abnormal access and defend normal visitors, so that normal visitors cannot obtain the communication data of the device, and thus cannot normally analyze the devices in the industrial control network, which may cause abnormal operation of the devices in the industrial control network, affecting the production progress of the factory and reducing the factory's revenue.

[0004] In view of this, the present invention provides an industrial control honeypot defense system and method based on mirror simulation to solve the above problems. Summary of the Invention

[0005] To overcome the above defects of the prior art and to achieve the above object, the present invention provides the following technical solution: An industrial control honeypot defense system based on mirror simulation, including a defense center, which is communicatively connected to an industrial control environment recognition component, a simulation honeypot environment construction component, a security defense deployment component, and a behavior monitoring and response component; The industrial control environment recognition component is responsible for recognizing the industrial control network in the factory to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; The simulation honeypot environment construction component is responsible for constructing a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structure, and communication behavior data in the industrial control network; The security defense deployment component is responsible for deploying authentication nodes in the simulated industrial control honeypot network, and through the authentication nodes, generating corresponding access recognition verification codes according to the simulated communication behavior data in the simulated industrial control honeypot network, generating a simulated communication behavior data key, converting the simulated communication behavior data key into a two-dimensional array of simulated communication behavior data keys, and encrypting the simulated communication behavior data through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data; The behavior monitoring and response component is responsible for verifying the access recognition verification code obtained by the visitor decrypting the encrypted simulated communication behavior data, and judging whether it is a normal access according to the verification result, and making corresponding responses according to the judgment result.

[0006] Further, the device information data includes the models, IP addresses, open port numbers, and communication behavior characteristic tables of all devices in the industrial control network; The communication behavior data includes periodic communication data, event-driven communication data, broadcast behavior data, control instruction data, response data, and retry behavior data.

[0007] Further, the method for constructing a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structure, and communication behavior data in the industrial control network includes: Based on the device information data, construct simulated device units using Docker. At the same time, use Docker to configure and allocate a unique virtual IP address for each simulated device unit, and configure the same open port number and communication behavior characteristic table as the corresponding real device for each simulated device unit; Interconnect the corresponding simulated device units according to the device topology structure, and construct simulated PLC nodes based on the open source communication library of Python. Generate simulated communication behavior data according to the communication behavior data in the industrial control network. During the monitoring time period, through the simulated PLC nodes, control the communication between the simulated device units according to the corresponding industrial protocols and simulated communication behavior data to obtain a simulated industrial control honeypot network.

[0008] Further, the method for deploying authentication nodes in the simulated industrial control honeypot network and generating corresponding access recognition verification codes through the authentication nodes according to the simulated communication behavior data in the simulated industrial control honeypot network includes: Deploy an authentication node in each simulated device unit in the simulated industrial control honeypot network; Divide the monitoring time period into For each monitoring sub - time period, convert the simulation communication behavior data transmitted to the simulation device unit within the monitoring sub - time period into English representation, convert each character after conversion into the corresponding ASCII code representation, convert the ASCII code of each character into an eight - bit binary representation, and combine the binary representations of all characters to form a simulation communication behavior data stream; Divide the simulation communication behavior data stream into simulation communication behavior data segments, specifically including: Obtain the lengths of the simulation communication behavior data stream and the simulation communication behavior data segments. Divide the length of the simulation communication behavior data stream by the length of the simulation communication behavior data segment to obtain the division result. Determine whether to pad the simulation communication behavior data stream based on the division result. If the division result is an integer, do not pad the simulation communication behavior data stream. If the division result is not an integer, pad the simulation communication behavior data stream; The process of padding the simulation communication behavior data stream includes: Obtain the remainder of dividing the length of the simulation communication behavior data stream by the length of the simulation communication behavior data segment. Subtract the remainder of dividing the length of the simulation communication behavior data stream by the length of the simulation communication behavior data segment from the length of the simulation communication behavior data segment to obtain the subtraction result ; Add binary digits at the end of the simulation communication behavior data stream; Divide the simulation communication behavior data stream once every bits to obtain simulation communication behavior data segments, where is the length of the simulation communication behavior data segment ; ; Label the simulation communication behavior data segments, denoted as

[0009] Further, the method for generating the simulation communication behavior data key includes: Randomly generate random values, set a random value threshold. When the random value is greater than or equal to the random value threshold, replace the random value with ; when the random value is less than the random value threshold, replace the random value with ; pool all the replaced random values to obtain the simulation communication behavior data key.

[0010] Further, the method for converting the simulation communication behavior data key into a two-dimensional array of simulation communication behavior data keys includes: Construct a two-dimensional array , , and , map the first bits of the binary of the simulation communication behavior data key to the first row of the two-dimensional array , map the th to th bits of the binary of the simulation communication behavior data key to the second row of the two-dimensional array , map the th to th bits of the binary of the simulation communication behavior data key to the third row of the two-dimensional array , ……, map the th to th bits of the binary of the simulation communication behavior data key to the th row of the two-dimensional array to obtain a two-dimensional array of simulation communication behavior data keys.

[0011] Further, the method for encrypting the simulation communication behavior data with the two-dimensional array of simulation communication behavior data keys to obtain the encrypted simulation communication behavior data includes: Adopt the same method as converting the simulation communication behavior data key into a two-dimensional array of simulation communication behavior data keys to convert the simulation communication behavior data segment into a two-dimensional array of simulation communication behavior data segments; Obtain the start time of the monitored sub-time period, and perform an exclusive OR operation on the elements in the two-dimensional array of simulation communication behavior data keys and the elements in the two-dimensional array of simulation communication behavior data segments according to the start time of the monitored sub-time period to obtain an encrypted two-dimensional array of simulation communication behavior data segments; Convert the encrypted two-dimensional array of simulation communication behavior data segments into an encrypted simulation communication behavior data segment, and merge the encrypted simulation communication behavior data segments in the splitting order to obtain the encrypted simulation communication behavior data.

[0012] Further, the method for converting the encrypted two-dimensional array of simulation communication behavior data segments into an encrypted simulation communication behavior data segment includes: Take the elements in the first row of the encrypted two-dimensional array of simulation communication behavior data segments as the first bits of the binary of the encrypted simulation communication behavior data segment, take the elements in the second row of the encrypted two-dimensional array of simulation communication behavior data segments as the th to th bits of the binary of the encrypted simulation communication behavior data segment, take the elements in the third row of the encrypted two-dimensional array of simulation communication behavior data segments as the th to bit binary, ……, take the elements within the row of the two-dimensional array of encrypted simulation communication behavior data segments as the to bit binary of the encrypted simulation communication behavior data segment.

[0013] Furthermore, the method for verifying the access identification verification code obtained by the visitor decrypting the encrypted simulation communication behavior data and judging whether it is a normal access according to the verification result and making corresponding responses according to the judgment result includes: When a visitor accesses the simulation device unit, first enter the authentication node in the simulation device unit, obtain the time when the visitor accesses the simulation device unit, and then obtain the monitoring sub-time period to which the time when the visitor accesses the simulation device unit belongs, and record it as the access monitoring sub-time period; The authentication node provides the encrypted simulation communication behavior data of the simulation device unit and the corresponding two-dimensional array of simulation communication behavior data keys within the previous monitoring sub-time period of the access monitoring sub-time period and the start time of the previous monitoring sub-time period to the visitor. The visitor decrypts the encrypted simulation communication behavior data to obtain the corresponding access identification verification code, and inputs the access identification verification code into the authentication node. The authentication node verifies the input access identification verification code; If the input access identification verification code is correct, it is a normal access, and the IP address of the industrial control network in the factory is given to the visitor. If the times of input access identification verification codes are incorrect, it is an abnormal access, and the visitor is permanently banned.

[0014] The industrial control honeypot defense method based on mirror simulation includes: Step S1: Identify the industrial control network in the factory to obtain the device information data, industrial protocols, device topology structure, and communication behavior data in the industrial control network; Step S2: Construct a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structure, and communication behavior data in the industrial control network; Step S3: Deploy an authentication node in the simulated industrial control honeypot network, and generate a corresponding access identification verification code according to the simulated communication behavior data in the simulated industrial control honeypot network, and encrypt the simulated communication behavior data to obtain encrypted simulated communication behavior data; Step S4: Verify the access identification verification code obtained by the visitor decrypting the encrypted simulated communication behavior data, and judge whether it is a normal access according to the verification result and make corresponding responses.

[0015] The technical effects and advantages of the industrial control honeypot defense system and method based on mirror simulation of the present invention: 1. The industrial control network within the factory is identified to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network. Based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network, a simulated industrial control honeypot network is constructed. The simulated industrial control honeypot network has high simulation accuracy and is not easily detected by attackers, attracting attackers to access the simulated industrial control honeypot network, thereby enhancing the defense ability of the industrial control network. 2. Authentication nodes are deployed in the simulated industrial control honeypot network. The authentication nodes generate corresponding access identification verification codes according to the simulated communication behavior data in the simulated industrial control honeypot network, and generate a simulated communication behavior data key. The simulated communication behavior data key is converted into a two-dimensional array of simulated communication behavior data keys, and the simulated communication behavior data is encrypted through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data. The visitor needs to decrypt the encrypted simulated communication behavior data to obtain the access identification verification code, and judge whether it is a normal access or an abnormal access according to the access identification verification code, accurately distinguishing normal visitors and attackers, enabling attackers to be defended and normal visitors to access normally, thus ensuring the normal production progress of the factory, enhancing the defense ability of the industrial control network, and the access identification verification code is dynamic, further improving the accuracy of judging whether it is a normal access or an abnormal access. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 Schematic diagram of the industrial control honeypot defense system based on mirror simulation of the present invention; Figure 2 Schematic diagram of the industrial control honeypot defense method based on mirror simulation of the present invention; Figure 3 Flow chart of constructing the simulated industrial control honeypot network of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0018] Embodiment 1 Please refer to Figure 1 and Figure 3As shown in the figure, the industrial control honeypot defense system based on mirror simulation in this embodiment includes a defense center, which is communicatively connected to an industrial control environment recognition component, a simulation honeypot environment construction component, a security defense deployment component, and a behavior monitoring and response component; The industrial control environment recognition component is responsible for recognizing the industrial control network in the factory to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; The simulation honeypot environment construction component is responsible for constructing a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; The security defense deployment component is responsible for deploying authentication nodes in the simulated industrial control honeypot network, and generating corresponding access recognition verification codes according to the simulated communication behavior data in the simulated industrial control honeypot network through the authentication nodes, and generating a simulated communication behavior data key, converting the simulated communication behavior data key into a two-dimensional array of simulated communication behavior data keys, and encrypting the simulated communication behavior data through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data; The behavior monitoring and response component is responsible for verifying the access recognition verification code obtained by the visitor decrypting the encrypted simulated communication behavior data, and judging whether it is a normal access according to the verification result, and making corresponding responses according to the judgment result.

[0019] The process of recognizing the industrial control network in the factory to obtain device information data, industrial protocols, device topology structures, and communication behavior data includes: The device information data includes basic information such as the models, IP addresses, open port numbers, and communication behavior characteristic tables of all devices in the industrial control network. The communication behavior characteristic table includes parameters such as device response delay, periodic communication interval, and error code return rules. The industrial protocols include all industrial protocols used in the industrial control network. The communication behavior data includes periodic communication data, event-driven communication data, broadcast behavior data, control instruction data, response data, and retry behavior data; The periodic communication data includes data regularly uploaded or requested by PLCs, RTUs, sensors, etc. For example, Modbus periodically reads coil status, etc.; The event-driven communication data includes communication data triggered by alarms, switch state changes, etc. For example, SCADA receives an alarm trigger response command, etc.; The broadcast behavior data includes network discovery and synchronization communication behavior data. For example, ARP, mDNS, DCP, S7Comm discovery requests, etc.; The control instruction data includes control instruction data issued by an operator or an automatic device. For example, writing to a PLC register, controlling the start and stop of a pump, etc.; The response data includes reply data to a controller request, etc. For example, reading a temperature feedback value, confirming the device status, etc.; The retry behavior data includes characteristic behavior data such as device anomalies, timeouts, retransmissions, etc. For example, resending a message after a communication failure, etc.; Set up a data acquisition terminal, configure the data acquisition terminal to generate a configuration channel, and through the generated configuration channel, link to the factory's server. The data acquisition terminal obtains device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network within the factory's server through the configuration channel; The process of configuring the data acquisition terminal includes: Pre-configure the IP address and communication port of the factory server in the configuration file of the data acquisition terminal, and configure the timeout for connecting to the factory server and the number of times and intervals for reconnecting when the connection fails in the configuration file.

[0020] The process of constructing a simulated industrial control honeypot network based on device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network includes: Build simulated device units based on Docker according to the device information data. Each simulated device unit is encapsulated as an independent container. At the same time, configure and assign a unique virtual IP address to each simulated device unit through Docker, and configure the same open port number and communication behavior characteristic table as the corresponding real device for each simulated device unit to enhance the behavior credibility and deception ability of the simulated device unit. Connect the corresponding simulated device units according to the device topology structure, and build a simulated PLC node based on the open source communication library of Python. Generate simulated communication behavior data according to the communication behavior data in the industrial control network. During the monitoring time period, control the communication between the simulated device units through the simulated PLC node according to the corresponding industrial protocol and simulated communication behavior data to obtain a simulated industrial control honeypot network; It should be noted that in the process of traditional industrial network defense, the simulation accuracy of the industrial control network is relatively low, which is easily detected by attackers. As a result, attackers will not attack the simulated industrial control network, but search for the real industrial control network to attack. This reduces the role of the simulated industrial control network and wastes computing and communication resources. Directly attacking the real industrial control network reduces the defense of the industrial control network and increases the risk of the industrial control network being invaded. Therefore, the present invention constructs a simulated industrial control honeypot network with high simulation accuracy, which is not easily detected by attackers and attracts attackers to access the simulated industrial control honeypot network, thereby increasing the defense ability of the industrial control network.

[0021] The process of deploying authentication nodes in the simulated industrial control honeypot network and generating corresponding access recognition verification codes by the authentication nodes according to the simulated communication behavior data in the simulated industrial control honeypot network includes: Deploy an authentication node in each simulated device unit in the simulated industrial control honeypot network; Divide the monitoring time period into monitoring sub-time periods, The value of can be set through experimental data analysis or experience; For example, the monitoring time period is from 07:00:00 on February 18, 2025 to 08:00:00 on February 18, 2025. Set to 6. Then, the time period from 07:00:00 to 07:10:00 is a monitoring sub-time period, the time period from 07:10:01 to 07:20:00 is a monitoring sub-time period, the time period from 07:20:01 to 07:30:00 is a monitoring sub-time period, the time period from 07:30:01 to 07:40:00 is a monitoring sub-time period, the time period from 07:40:01 to 07:50:00 is a monitoring sub-time period, and the time period from 07:50:01 to 08:00:00 is a monitoring sub-time period; Convert the simulated communication behavior data transmitted to the simulated device unit within the monitoring sub-time period into English representation, convert each character after conversion into the corresponding ASCII code representation, convert the ASCII code of each character into an eight-bit binary representation, and combine the binary representations of all characters to form a simulated communication behavior data stream; It should be noted that simulation communication behavior data is transmitted to the simulation device unit during each monitoring sub - time period. An authentication node encrypts the simulation communication behavior data transmitted to the simulation device unit. For example, if there are two simulation device units, there are two authentication nodes. One authentication node is responsible for one simulation device unit and encrypts the simulation communication behavior data transmitted to this simulation device unit during each monitoring sub - time period, obtaining the encrypted simulation communication behavior data corresponding to the simulation communication behavior data transmitted to this simulation device unit during each monitoring sub - time period. That is, several encrypted simulation communication behavior data are obtained according to the number of monitoring sub - time periods. The other authentication node works on the same principle; The simulation communication behavior data stream is segmented into simulation communication behavior data segments, specifically including: Obtain the lengths of the simulation communication behavior data stream and the simulation communication behavior data segment. Divide the length of the simulation communication behavior data stream by the length of the simulation communication behavior data segment to obtain the division result. Determine whether to pad the simulation communication behavior data stream according to the division result. If the division result is an integer, do not pad the simulation communication behavior data stream. If the division result is not an integer, pad the simulation communication behavior data stream; The process of padding the simulation communication behavior data stream includes: Obtain the remainder of the length of the simulation communication behavior data stream divided by the length of the simulation communication behavior data segment. Subtract the remainder of the length of the simulation communication behavior data stream divided by the length of the simulation communication behavior data segment from the length of the simulation communication behavior data segment to obtain the subtraction result ; Add binary digits at the end of the simulation communication behavior data stream; Every bits, segment the simulation communication behavior data stream once to obtain the simulation communication behavior data segment, which is the length of the simulation communication behavior data segment; Label the simulation communication behavior data segments, denoted as , , , where is the number of simulation communication behavior data segments; The process of generating the simulation communication behavior data key includes: Generate A random value, and the random value generation formula is: ; Among them, is the random value generated by the random value generation formula, is a randomly varying value and ; represents randomly generating a to floating value, represents randomly generating a to floating value; It should be explained that this item sets the independent variable of the sine function to , introduces a rapidly increasing frequency and a slowly increasing logarithmic perturbation, making the fluctuation complex and unstable; this item takes the square root of the absolute value of plus the periodic term , making the result regular but difficult to predict; this item The output range of the sine function is [-1, 1]. After putting it into the exponential function, the output is between , that is, [0.367, 2.718]. This is an amplifier with periodic perturbation; this item increases steadily, used to scale the exponential result to prevent explosive growth; this item The high-order cosine introduces extremely high-frequency rapid changes; this overall item is well controlled, not too large, but the change pattern is very complex, generating irregular and high-frequency change fluctuations; this item slightly perturbs the denominator with sine, and tends to be stable as increases, providing a slight noise fluctuation. When is small, this part has a greater impact. When is large, this part can be almost ignored; Set the random value threshold. The random value threshold can be set through experimental data analysis or experience. When the random value is greater than or equal to the random value threshold, replace the random value with , and when the random value is less than the random value threshold, replace the random value with . Collect all the replaced random values to obtain the simulation communication behavior data key; Convert the simulation communication behavior data key into a two-dimensional array of simulation communication behavior data keys, specifically including: Construct a two-dimensional array , , and , map the first binary digits of the simulation communication behavior data key to the two-dimensional array In the first row of to bits of the simulation communication behavior data key are mapped to the second row of the two-dimensional array In the second row of to bits of the simulation communication behavior data key are mapped to the two-dimensional array In the third row of to bits of the simulation communication behavior data key are mapped to the two-dimensional array In the row of as the elements in the row, a two-dimensional array of the simulation communication behavior data key is obtained; The process of encrypting the simulation communication behavior data with the two-dimensional array of the simulation communication behavior data key to obtain the encrypted simulation communication behavior data includes: Using the same method as converting the simulation communication behavior data key to the two-dimensional array of the simulation communication behavior data key, the simulation communication behavior data segment is converted into a two-dimensional array of the simulation communication behavior data segment; Obtain the start time of the monitoring sub-time period, and perform an exclusive NOR operation on the elements in the two-dimensional array of the simulation communication behavior data key and the elements in the two-dimensional array of the simulation communication behavior data segment according to the start time of the monitoring sub-time period to obtain a two-dimensional array of the encrypted simulation communication behavior data segment; For example: The start time of the monitoring sub-time period is 07:00:00 on February 18, 2025, and the corresponding number is 20250218070000. Replace 0 with 1, and the corresponding number is 21251218171111; If the first two digits of the number corresponding to the start time of the monitored sub - time period are 2 and 1, then perform an exclusive - NOR operation on the elements in the second row of the two - dimensional array of simulation communication behavior data keys and the elements in the first row of the two - dimensional array of simulation communication behavior data segments, and replace the elements in the first row of the two - dimensional array of simulation communication behavior data segments with the result of the exclusive - NOR operation. If the third and fourth digits of the number corresponding to the start time of the monitored sub - time period are 2 and 5 respectively, then perform an exclusive - NOR operation on the elements in the second row of the two - dimensional array of simulation communication behavior data keys and the elements in the fifth row of the two - dimensional array of simulation communication behavior data segments, and replace the elements in the fifth row of the two - dimensional array of simulation communication behavior data segments with the result of the exclusive - NOR operation,... If the penultimate and last digits of the number corresponding to the start time of the monitored sub - time period are 1 and 1, then perform an exclusive - NOR operation on the elements in the first row of the two - dimensional array of simulation communication behavior data keys and the elements in the first row of the two - dimensional array of simulation communication behavior data segments, and replace the elements in the first row of the two - dimensional array of simulation communication behavior data segments with the result of the exclusive - NOR operation, to obtain an encrypted two - dimensional array of simulation communication behavior data segments; Convert the encrypted two - dimensional array of simulation communication behavior data segments into an encrypted simulation communication behavior data segment, specifically including: Take the elements in the first row of the encrypted two - dimensional array of simulation communication behavior data segments as the first bits of binary of the encrypted simulation communication behavior data segment, take the elements in the second row of the encrypted two - dimensional array of simulation communication behavior data segments as the to bits of binary of the encrypted simulation communication behavior data segment, take the elements in the third row of the encrypted two - dimensional array of simulation communication behavior data segments as the to bits of binary of the encrypted simulation communication behavior data segment,... take the elements in the th row of the encrypted two - dimensional array of simulation communication behavior data segments as the to bits of binary; Merge the encrypted simulation communication behavior data segments in the splitting order to obtain the encrypted simulation communication behavior data; It should be noted that the traditional method does not identify the identity of visitors, which may misjudge normal access as abnormal access and defend against normal visitors, resulting in normal visitors being unable to obtain the communication data of the device, and thus unable to conduct normal analysis on the devices in the industrial control network. This may cause problems such as abnormal operation of the devices in the industrial control network, affecting the production progress of the factory and reducing the factory's revenue. Therefore, in the present invention, an authentication node is deployed in the simulated industrial control honeypot network. The authentication node generates corresponding access identification verification codes based on the simulated communication behavior data in the simulated industrial control honeypot network, generates a simulated communication behavior data key, converts the simulated communication behavior data key into a two-dimensional array of simulated communication behavior data keys, encrypts the simulated communication behavior data through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data. The visitor needs to decrypt the encrypted simulated communication behavior data to obtain the access identification verification code, and determines whether it is normal access or abnormal access based on the access identification verification code, accurately distinguishing normal visitors and attackers, defending against attackers, and allowing normal visitors to access normally, thus ensuring the normal production progress of the factory, improving the defense ability of the industrial control network, and the access identification verification code is dynamic, further improving the accuracy of determining normal access or abnormal access.

[0022] The process of verifying the access identification verification code obtained by the visitor decrypting the encrypted simulated communication behavior data and determining whether it is normal access based on the verification result and making corresponding responses according to the judgment result includes: When a visitor accesses the simulated device unit, first enter the authentication node in the simulated device unit, obtain the time when the visitor accesses the simulated device unit, and then obtain the monitoring sub-time period to which the time when the visitor accesses the simulated device unit belongs, and record it as the access monitoring sub-time period. The authentication node provides the encrypted simulated communication behavior data of the simulated device unit and the corresponding two-dimensional array of simulated communication behavior data keys in the previous monitoring sub-time period and the start time of the previous monitoring sub-time period to the visitor. The visitor decrypts the encrypted simulated communication behavior data to obtain the corresponding access identification verification code and inputs the access identification verification code into the authentication node. The authentication node verifies the input access identification verification code. If the input access identification verification code is correct, it is normal access, and the visitor is given the IP address of the industrial control network in the factory. If the access identification verification codes input consecutively times are incorrect, it is abnormal access, and the visitor is permanently banned. It should be noted that the access permission of the simulated device unit is opened starting from the second monitoring sub-time period. Generally, is set to 3.

[0023] In this embodiment, the industrial control network in the factory is identified to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network. A simulated industrial control honeypot network is constructed based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network. The simulated industrial control honeypot network has high simulation accuracy and is not easily detected by attackers, attracting attackers to access the simulated industrial control honeypot network, thereby increasing the defense ability of the industrial control network. A discrimination node is deployed in the simulated industrial control honeypot network, and the discrimination node generates corresponding access identification verification codes according to the simulated communication behavior data in the simulated industrial control honeypot network, and generates a simulated communication behavior data key. The simulated communication behavior data key is converted into a two-dimensional array of simulated communication behavior data keys, and the simulated communication behavior data is encrypted through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data. The visitor needs to decrypt the encrypted simulated communication behavior data to obtain the access identification verification code, and judges whether it is a normal access or an abnormal access according to the access identification verification code, accurately distinguishing normal visitors and attackers, so that attackers are defended and normal visitors can access normally, thus ensuring the normal production progress of the factory, improving the defense ability of the industrial control network, and the access identification verification code is dynamic, further improving the accuracy of judging whether it is a normal access or an abnormal access.

[0024] Embodiment 2 Please refer to Figure 2 As shown, for the parts not described in detail in this embodiment, please refer to the description in Embodiment 1. A defense method for industrial control honeypots based on mirror simulation is provided, including: Step S1: Identify the industrial control network in the factory to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; Step S2: Construct a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; Step S3: Deploy a discrimination node in the simulated industrial control honeypot network, and the discrimination node generates corresponding access identification verification codes according to the simulated communication behavior data in the simulated industrial control honeypot network, and encrypts the simulated communication behavior data to obtain encrypted simulated communication behavior data; Step S4: Verify the access identification verification code obtained by the visitor decrypting the encrypted simulated communication behavior data, and judge whether it is a normal access according to the verification result, and make corresponding responses.

[0025] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0026] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only one way, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0027] As mentioned above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention.

[0028] Finally: The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should all be included in the protection scope of the present invention.

Claims

1. An industrial control honeypot defense system based on mirror simulation, including a defense center, characterized in that It also includes the following components communicatively connected to the defense center: An industrial control environment identification component, responsible for identifying the industrial control network in the factory to obtain device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; A simulation honeypot environment construction component, responsible for constructing a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network; A security defense deployment component, responsible for deploying authentication nodes in the simulated industrial control honeypot network, and generating corresponding access identification verification codes through the authentication nodes according to the simulated communication behavior data in the simulated industrial control honeypot network, and generating a simulated communication behavior data key, converting the simulated communication behavior data key into a two-dimensional array of simulated communication behavior data keys, and encrypting the simulated communication behavior data through the two-dimensional array of simulated communication behavior data keys to obtain encrypted simulated communication behavior data; A behavior monitoring and response component, responsible for verifying the access identification verification code obtained by decrypting the encrypted simulated communication behavior data by the visitor, and judging whether it is a normal access according to the verification result, and making corresponding responses according to the judgment result.

2. The industrial control honeypot defense system based on mirror simulation according to claim 1, characterized in that The device information data includes the models, IP addresses, open port numbers, and communication behavior characteristic tables of all devices in the industrial control network; The communication behavior data includes periodic communication data, event-driven communication data, broadcast behavior data, control instruction data, response data, and retry behavior data.

3. The industrial control honeypot defense system based on mirror simulation according to claim 2, wherein, The method for constructing a simulated industrial control honeypot network based on the device information data, industrial protocols, device topology structures, and communication behavior data in the industrial control network includes: Constructing simulated device units based on Docker according to the device information data, and at the same time configuring and allocating a unique virtual IP address for each simulated device unit through Docker, and configuring the same open port number and communication behavior characteristic table as the corresponding real device for each simulated device unit; Interconnecting the corresponding simulated device units according to the device topology structure, constructing simulated PLC nodes based on the open source communication library of Python, generating simulated communication behavior data according to the communication behavior data in the industrial control network, and within the monitoring time period, controlling the communication between the simulated device units through the simulated PLC nodes according to the corresponding industrial protocols and simulated communication behavior data to obtain a simulated industrial control honeypot network.

4. The industrial control honeypot defense system based on mirror simulation according to claim 3, characterized in that, The method for deploying authentication nodes in the simulated industrial control honeypot network and generating corresponding access identification verification codes through the authentication nodes according to the simulated communication behavior data in the simulated industrial control honeypot network includes: Deploying an authentication node in each simulated device unit in the simulated industrial control honeypot network; Divide the monitoring time period into monitoring sub-time periods, convert the simulation communication behavior data transmitted to the simulation device unit within the monitoring sub-time periods into English representation, convert each character after conversion into the corresponding ASCII code representation, convert the ASCII code of each character into an eight-bit binary representation, and combine the binary representations of all characters to form a simulation communication behavior data stream; The data stream of the simulated communication behavior is segmented into data segments of the simulated communication behavior, and the data segments of the simulated communication behavior are numbered, denoted as , , is the number of data segments of the simulated communication behavior; Obtaining the first binary digit of each segment of the simulated communication behavior data, and combining the obtained binaries in the label order of the segments of the simulated communication behavior data to obtain the access identification verification code corresponding to the monitoring sub-time period.

5. The industrial control honeypot defense system based on mirror simulation according to claim 4, characterized in that, The method for generating the simulated communication behavior data key includes: Randomly generate random values, which is the length of the simulation communication behavior data segment. Set a random value threshold. When the random value is greater than or equal to the random value threshold, replace the random value with ; when the random value is less than the random value threshold, replace the random value with . Aggregate all the replaced random values to obtain the simulation communication behavior data key.

6. The industrial control honeypot defense system based on mirror simulation according to claim 5, wherein The method for converting the simulated communication behavior data key into a two-dimensional array of simulated communication behavior data keys includes: Construct a two-dimensional array , , and , map the first bits of the simulation communication behavior data key to the first row of the two-dimensional array . Map the th to th bits of the simulation communication behavior data key to the second row of the two-dimensional array . Map the th to th bits of the simulation communication behavior data key to the third row of the two-dimensional array . …… Map the th to th bits of the simulation communication behavior data key to the th row of the two-dimensional array to obtain the two-dimensional array of the simulation communication behavior data key.

7. The industrial control honeypot defense system based on mirror simulation according to claim 6, characterized in that, The method for encrypting simulation communication behavior data by using the two-dimensional array of simulation communication behavior data keys to obtain encrypted simulation communication behavior data includes: Using the same method as converting the simulation communication behavior data key into a two-dimensional array of simulation communication behavior data keys, converting the simulation communication behavior data segment into a two-dimensional array of simulation communication behavior data segments; Obtaining the start time of the monitored sub-time period, and performing an exclusive NOR operation on the elements in the two-dimensional array of simulation communication behavior data keys and the elements in the two-dimensional array of simulation communication behavior data segments according to the start time of the monitored sub-time period to obtain a two-dimensional array of encrypted simulation communication behavior data segments; Converting the two-dimensional array of encrypted simulation communication behavior data segments into an encrypted simulation communication behavior data segment, and merging the encrypted simulation communication behavior data segments in the splitting order to obtain encrypted simulation communication behavior data.

8. The industrial control honeypot defense system based on mirror simulation according to claim 7, characterized in that, The method for converting the two-dimensional array of encrypted simulation communication behavior data segments into an encrypted simulation communication behavior data segment includes: Take the elements in the first row of the two-dimensional array of encrypted simulation communication behavior data segments as the first bit binary digits, take the elements in the second row of the two-dimensional array of encrypted simulation communication behavior data segments as the to bit binary digits, take the elements in the third row of the two-dimensional array of encrypted simulation communication behavior data segments as the to bit binary digits, ……, take the elements in the th row of the two-dimensional array of encrypted simulation communication behavior data segments as the to bit binary digits.

9. The industrial control honeypot defense system based on mirror simulation according to claim 8, characterized in that, The method for verifying the access identification verification code obtained by decrypting the encrypted simulation communication behavior data by the visitor, judging whether it is a normal access according to the verification result, and making corresponding responses according to the judgment result includes: When a visitor accesses the simulation device unit, first enter the authentication node in the simulation device unit, obtain the time when the visitor accesses the simulation device unit, and then obtain the monitored sub-time period to which the time when the visitor accesses the simulation device unit belongs, and record it as the access monitored sub-time period; The authentication node provides the encrypted simulation communication behavior data of the simulation device unit in the previous monitored sub-time period of the access monitored sub-time period, the corresponding two-dimensional array of simulation communication behavior data keys, and the start time of the previous monitored sub-time period to the visitor. The visitor decrypts the encrypted simulation communication behavior data to obtain the corresponding access identification verification code, and inputs the access identification verification code into the authentication node. The authentication node verifies the input access identification verification code; If the input access identification verification code is correct, it is a normal access, and the IP address of the industrial control network in the factory is given to the visitor. If the access identification verification code input is incorrect for consecutive times, it is an abnormal access, and the visitor will be permanently banned.

10. An industrial control honeypot defense method based on mirror simulation, which is used to implement the industrial control honeypot defense system according to any one of claims 1 to 9, and is characterized in that, Including: Step S1: Identify the industrial control network in the factory to obtain the device information data, industrial protocol, device topology structure, and communication behavior data in the industrial control network; Step S2: Construct a simulation industrial control honeypot network based on the device information data, industrial protocol, device topology structure, and communication behavior data in the industrial control network; Step S3: Deploy an authentication node in the simulation industrial control honeypot network, and generate a corresponding access identification verification code according to the simulation communication behavior data in the simulation industrial control honeypot network through the authentication node, and encrypt the simulation communication behavior data to obtain encrypted simulation communication behavior data; Step S4: Verify the access identification verification code obtained by decrypting the encrypted simulation communication behavior data by the visitor, judge whether it is a normal access according to the verification result, and make corresponding responses.

Citation Information

Patent Citations

  • Honeypot dynamic configuration method and device, honeypot intrusion detection system and medium

    CN116436653A

  • Honeynet cluster deployment method for industrial control system

    CN115913632A

  • Conpot-based industrial control system deception defense system construction method and system

    CN119892454A

  • Industrial field network security honeypot simulation and threat trapping system

    CN120165922A

  • In-band asymmetric protocol simulator

    US20170353492A1