Method and system for safety and robustness simulation analysis of industrial network topology structure
By building an industrial network topology model and using graph neural networks for feature learning, the problem of the inability to dynamically evaluate the industrial network topology structure under multiple types of perturbations in the existing technology is solved, and quantitative evaluation and optimization suggestions for dynamic adaptability of industrial networks are realized, which improves the robustness and security of the network.
Patent Information
- Application Number
- CN202510811790.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-18
AI Technical Summary
The prior art is difficult to effectively simulate and evaluate the dynamic changes of industrial network topology in multiple types of perturbation scenarios, and it is impossible to accurately identify key structural units and provide targeted optimization suggestions, resulting in insufficient network robustness and security.
Build an industrial network topology model, set up a multi-type perturbation scenario model, use graph neural network for feature learning and embedding, output robustness score value R-score, calculate robustness evaluation indicators based on simulation data, and identify topological weaknesses, and provide optimization suggestions.
The quantitative evaluation of the dynamic adaptability of industrial network topology in multiple disturbances has been achieved, which improves the structural robustness, security controllability and adaptive adjustment capabilities of the network, and identifies and optimizes key structural weaknesses.
Smart Images

Figure CN120358152A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network analysis, and in particular, to a method and system for simulating and analyzing the security and robustness of an industrial network topology structure. Background Art
[0002] With the wide deployment of industrial control systems and industrial Internet, the industrial network, as the core communication infrastructure to support intelligent manufacturing and industrial automation operation, the security and robustness of its topology structure have become key factors affecting system stability, production continuity and network security protection capabilities. Typical industrial network topologies include PLCs, SCADA systems (supervisory control and data acquisition systems), various sensors, and edge control devices, etc.
[0003] However, traditional topology evaluation methods mainly rely on static graph structure analysis and rule-driven metrics (such as node degree, shortest path, redundancy number) to judge network robustness, and it is difficult to reflect the actual dynamic impact of perturbations (such as equipment failures, link congestion, network attacks) on system connectivity and service reachability; lack the ability to model the evolution process of the topology structure under multi-type perturbation scenarios (such as node failures, link degradation, attack diffusion), unable to effectively identify the key structural units that cause a sharp decline in system connectivity or service interruption, and it is also difficult to output targeted optimization suggestions to improve network robustness. Moreover, there is a lack of a method to combine machine learning technology to learn and quantitatively score network characteristics before and after perturbations, resulting in strong subjectivity of evaluation results and difficulty in adapting to the increasing network threats and dynamic configuration requirements in complex industrial scenarios.
[0004] Therefore, it is necessary to design a method and system for simulating and analyzing the security and robustness of an industrial network topology structure to solve the problems existing in the current technology. Summary of the Invention
[0005] In view of this, the present invention proposes a method and system for simulating and analyzing the security and robustness of an industrial network topology structure, aiming to solve the problem that the current analysis of the security and robustness of industrial network topology structures mainly relies on qualitative empirical judgments and lacks a method to combine machine learning technology to learn and quantitatively score network characteristics before and after perturbations.
[0006] On the one hand, the present invention proposes a method for simulating and analyzing the security and robustness of an industrial network topology structure, including:
[0007] Model each device node in the industrial network as a node, and model the communication link between devices as an edge. Construct an industrial network topology model according to all the nodes and edges. The nodes include PLCs, SCADA, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus;
[0008] Set up a perturbation scenario model, where the perturbation scenario model includes node random failure perturbation, network attack perturbation, and link degradation perturbation; the perturbation scenario model has propagation parameters, and the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function;
[0009] Perform perturbation simulation on the industrial network topology model in the simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs;
[0010] Use a graph neural network model to perform feature learning and embedding on the network topology graphs before and after the perturbation, and output the robustness score value R-score corresponding to the perturbation scenario;
[0011] Calculate the robustness evaluation metrics based on the simulation data, and the robustness evaluation metrics include network connectivity retention rate, service interruption ratio, routing path delay growth multiple, and average path hop count for fault recovery;
[0012] Output the weak point identification result and optimization suggestions for the topological structure according to the robustness evaluation metrics, and the optimization suggestions include critical node redundancy configuration, master controller deployment optimization, link redundancy construction, and communication path re-planning.
[0013] Further, the network attack perturbation in the perturbation scenario includes: distributed denial of service attack, man-in-the-middle attack, routing spoofing attack, or command injection attack.
[0014] Further, the attack preference function is jointly determined by the network centrality and business importance of the node, and satisfies the following form:
[0015] P = α·C + β·D, where P is the attack preference function, C represents the network centrality of the node, D represents the business importance, α and β are weight parameters, and α + β = 1.
[0016] Further, when using a graph neural network model to perform feature learning and embedding on the network topology graphs before and after the perturbation and output the robustness score value R-score corresponding to the perturbation scenario, the graph neural network model includes:
[0017] A graph convolutional layer for extracting structural features of the nodes and their adjacency relationships in the industrial network topology model;
[0018] A perturbation embedding layer for encoding the perturbation information of each node in the perturbation scenario model into a perturbation feature matrix, and inputting the perturbation feature matrix and the node static attributes into the graph neural network together;
[0019] A node state time difference encoding layer for calculating the difference between the state vectors of the same node before and after the perturbation and using it as the dynamic input;
[0020] The graph-level representation aggregation layer is used to perform a pooling operation on all node embedding representations to generate a whole-graph embedding;
[0021] The robustness score output layer is used to output the robustness score value R-score under the corresponding perturbation scenario according to the whole-graph embedding.
[0022] Furthermore, the perturbation embedding layer constructs perturbation channel features based on the perturbation feature matrix, which is used to represent the perturbation type, propagation level, node criticality, and whether directly perturbed of each node in the perturbation scenario, and is spliced with the node static feature channel through the perturbation channel and input into the graph convolutional layer.
[0023] Furthermore, when calculating the robustness evaluation index based on simulation data, it also includes:
[0024] Obtaining a comprehensive robustness score based on a multi-objective weighted function;
[0025] The comprehensive robustness score is obtained by calculating the following formula:
[0026] R = w1·CRR + w2·(1 - SIR) + w3·(1 / DIF) + w4·(1 / ARH);
[0027] Among them, w1, w2, w3, and w4 are positive weight coefficients, R represents the comprehensive robustness score, CRR represents the network connectivity retention rate, SIR represents the service interruption ratio, DIF represents the growth multiple of the routing path delay, and ARH represents the average number of hops for fault recovery.
[0028] Furthermore, when outputting the weak point identification result and optimization suggestions of the topological structure according to the robustness evaluation index, it includes:
[0029] When there are nodes with high single-point failure sensitivity, perturbation propagation core nodes, or graph neural network embedding dynamics, it is determined that the weak point identification result is the existence of high-risk nodes, and the output optimization suggestion is the redundant configuration of key nodes;
[0030] When there are cases where path transfer causes increased delay, high link bandwidth utilization, or increased number of hops for recovery after link failure, it is determined that the weak point identification result is the existence of performance bottleneck links, and the output optimization suggestion is the construction of link redundancy;
[0031] When there is a node with high degree centrality, high betweenness centrality, or high structural dependence, it is determined that the weak point identification result is the existence of nodes with excessive centrality, and the output optimization suggestion is the optimization of the master controller deployment;
[0032] When the average path hop count is large, the fault recovery path is long, or the physical coverage of the link is not optimal, it is determined that the result of weak point identification is that the delay hop count is too long, and the optimization suggestion output is to re-plan the communication path.
[0033] Further, after outputting the result of weak point identification and the optimization suggestion of the topology structure according to the robustness evaluation index, it further includes:
[0034] Collect the results of weak point identification and optimization suggestions of several simulations, obtain the corresponding comprehensive robustness scores, compare the comprehensive robustness scores with the lowest threshold of the comprehensive robustness score respectively, and judge whether to give an audible and visual alarm according to the comparison results;
[0035] When all the comprehensive robustness scores are less than or equal to the lowest threshold of the comprehensive robustness score, it is determined to give an audible and visual alarm;
[0036] When there is a comprehensive robustness score greater than the lowest threshold of the comprehensive robustness score, it is determined not to give an audible and visual alarm.
[0037] Further, when all the comprehensive robustness scores are less than or equal to the lowest threshold of the comprehensive robustness score and an audible and visual alarm is given, it includes:
[0038] Obtain the score difference according to the comprehensive robustness score and the lowest threshold of the comprehensive robustness score. The score difference is the absolute value of the difference between the comprehensive robustness score and the lowest threshold of the comprehensive robustness score. Determine the warning level according to the score difference, and give an audible and visual alarm according to the warning level; the warning level is in a proportional relationship with the score difference.
[0039] Compared with the prior art, the beneficial effects of the present invention are as follows: By constructing a network topology model that maps the industrial system structure, devices such as PLCs, SCADA, sensors, and edge controllers are abstracted as nodes, and communication links such as Ethernet, PROFINET, and Modbus are modeled as edges, thereby achieving a unified representation of the physical structure and logical connections of the industrial network; Multiple types of perturbation scenarios such as node failure, link degradation, and network attacks are introduced, and propagation parameters are set to dynamically model the perturbation process. Combining with a graph neural network model, deep learning is performed on the topological evolution characteristics before and after the perturbation, and a quantifiable robustness score value R-score is output; Further, based on the simulation results, multi-dimensional robustness indicators are calculated (including network connectivity retention rate, service interruption ratio, path delay growth multiple, and recovery path hop count), realizing a quantitative evaluation of the dynamic adaptation ability of the topological structure under multiple perturbation scenarios; According to the analysis results of the indicators, key structural weaknesses are automatically identified, and targeted optimization suggestions are proposed, such as redundant configuration, main control deployment optimization, and path reconstruction, etc., making up for the deficiencies in the prior art of insufficient support for dynamic perturbation, structural evolution, intelligent evaluation, and optimization closed-loop, and improving the structural robustness, security controllability, and adaptive adjustment ability of the industrial network in the face of complex operating environments and potential threats.
[0040] On the other hand, the present application also provides an industrial network topology structure security and robustness simulation analysis system for applying the industrial network topology structure security and robustness simulation analysis method, including:
[0041] An acquisition unit, configured to acquire each device node and communication link in the industrial network, model each device node as a node, model the communication link as an edge, and construct an industrial network topology model according to all the nodes and edges. The nodes include PLCs, SCADA, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus;
[0042] A configuration unit, configured to set a perturbation scenario model, and the perturbation scenario model includes node random failure perturbation, network attack perturbation, and link degradation perturbation; The perturbation scenario model has propagation parameters, and the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function;
[0043] A processing unit, configured to perform perturbation simulation on the industrial network topology model in a simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs;
[0044] An analysis unit, configured to perform feature learning and embedding on the network topology graph before and after the perturbation by using a graph neural network model, and output a robustness score value R-score corresponding to the perturbation scenario;
[0045] An evaluation unit, configured to calculate a robustness evaluation index based on simulation data, where the robustness evaluation index includes a network connectivity retention rate, a service interruption ratio, a routing path delay growth multiple, and an average number of hops of a fault recovery path;
[0046] An identification unit, configured to output a weakness identification result and an optimization suggestion of the topology structure according to the robustness evaluation index, where the optimization suggestion includes redundant configuration of key nodes, optimization of master controller deployment, construction of link redundancy, and re-planning of communication paths.
[0047] It can be understood that the above industrial network topology structure security and robustness simulation analysis method and system have the same beneficial effects, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0049] Figure 1 It is a flowchart of the industrial network topology structure security and robustness simulation analysis method provided by an embodiment of the present invention;
[0050] Figure 2 It is a functional block diagram of the industrial network topology structure security and robustness simulation analysis system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. Hereinafter, the present invention will be described in detail with reference to the drawings and in combination with the embodiments.
[0052] In the security and robustness assessment of traditional industrial network topologies, static graph structure analysis methods only quantify network robustness based on fixed metrics such as node degree, shortest path length, and number of redundant connections, and cannot simulate the dynamic topology change process caused by random node failures, network attack propagation, or link degradation. In a typical industrial network, the communication link between the PLC and the SCADA system is formed by Ethernet and industrial protocols. When facing a distributed denial-of-service attack, the cascading effect of attack traffic spreading through the routing path and causing core node overload is difficult to capture by existing methods, and the calculation deviation of key metrics such as network connectivity retention rate and service interruption ratio increases. In addition, traditional methods lack the ability to dynamically model the probability of node perturbation and cannot construct an attack preference function based on network centrality and business importance weight parameters, resulting in a deviation between the vulnerability assessment results of critical control nodes and the actual risk scenarios.
[0053] For example, in the industrial network architecture of a manufacturing production line, a master-slave communication link is established between the edge controller and the PLC through the PROFINET bus. When a man-in-the-middle attack invades the sensor node through the Modbus protocol, the attack payload propagates along the control instruction path to the master control node. Since traditional assessment methods do not establish a dynamic parameter model for attack propagation probability and influence radius, they cannot accurately calculate the growth multiple of routing path delay and the average number of path hops for fault recovery, resulting in the failure to trigger an alarm in time when the bandwidth utilization rate of the critical link exceeds the threshold. At this time, the SCADA node with high betweenness centrality in the network topology becomes a bottleneck of single-point failure during the attack propagation process due to the lack of redundant links, causing the production control instruction delay to exceed the upper limit tolerated by the system.
[0054] If the above problems are not solved, the industrial network will not be able to effectively identify core nodes and vulnerable links when facing complex attack scenarios, resulting in a lack of pertinence in the fault recovery strategy. The cascading effect caused by random node failures may spread to the entire control domain, causing the service interruption time to exceed the response threshold of the redundant switching mechanism. The cumulative communication delay caused by link degradation will interfere with the synchronization of real-time control instructions and reduce the process stability of the manufacturing system. Without accurately defining the attack preference path, defense resources cannot be preferentially deployed to critical routing nodes, increasing the risk of malicious traffic bypassing the security detection mechanism.
[0055] When facing the above problems, this application considers how to introduce dynamic perturbation factors into industrial network topology analysis. Traditional methods that only rely on static metrics cannot reflect the chain reactions caused by node failures or the spread of attacks. To capture the dynamic changes of the network topology as the perturbation propagates, a topology model containing various device nodes and communication links is constructed, and different types of perturbation scenarios and their propagation parameters are set. In this regard, this application combines node and link attributes with perturbation parameters, and simulates the impact trajectory of perturbations on network connectivity through simulation. However, it is found that simply recording topological changes is difficult to quantitatively evaluate network robustness. Furthermore, a graph neural network is introduced to perform embedding learning on the topological features before and after perturbations, and its non-linear modeling ability is used to extract structural vulnerability patterns. Finally, a targeted optimization strategy is generated by combining multi-dimensional evaluation metrics.
[0056] Referring to Figure 1 as shown, this application proposes: A method for simulating and analyzing the security and robustness of an industrial network topology structure, including:
[0057] S100: Model each device node in the industrial network as a node, and model the communication links between devices as edges. Construct an industrial network topology model based on all nodes and edges. The nodes include PLC, SCADA, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus.
[0058] S200: Set a perturbation scenario model. The perturbation scenario model includes node random failure perturbation, network attack perturbation, and link degradation perturbation. The perturbation scenario model has propagation parameters, and the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function.
[0059] S300: Perform perturbation simulation on the industrial network topology model in the simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs.
[0060] S400: Use a graph neural network model to perform feature learning and embedding on the network topology graph before and after the perturbation, and output the robustness score value R-score corresponding to the perturbation scenario.
[0061] S500: Calculate the robustness evaluation metrics based on the simulation data. The robustness evaluation metrics include network connectivity retention rate, service interruption ratio, routing path delay growth multiple, and average path hop count for fault recovery.
[0062] S600: Output the weak point identification result and optimization suggestions for the topological structure according to the robustness evaluation metrics. The optimization suggestions include redundant configuration of key nodes, optimization of master controller deployment, construction of link redundancy, and re-planning of communication paths.
[0063] Specifically, modeling each device node in an industrial network as a node means abstracting PLCs, SCADA systems, sensors, and edge controllers as vertices in a network graph. Specifically, a node attribute table can be established through device type, communication protocol, and connection relationships to solve the problem that traditional methods cannot dynamically reflect device heterogeneity. Among them, modeling the communication link between devices as an edge means converting the physical or logical links corresponding to industrial protocols such as Ethernet, PROFINET, and Modbus into connection relationships in the network graph. Specifically, an adjacency matrix or edge list data structure can be used to accurately represent the actual communication path. Among them, the perturbation scenario model includes three types of perturbation types: node random failure, network attack, and link degradation. This means that by defining simulation rules for device failures, malicious attacks, and link performance degradation, dynamic perturbation events can be generated based on the Monte Carlo method or attack tree model to solve the problem that traditional static analysis cannot simulate multi-dimensional dynamic impacts. Among them, the propagation parameters include perturbation duration, propagation probability, and influence radius. This means setting the diffusion rules of perturbations at the time, space, and logical levels. Specifically, the perturbation propagation process can be quantified through a probability transition matrix or influence domain decay function to simulate the cascading effect of cascading failures in a real industrial environment. Among them, the graph neural network model performs feature learning on the topological graph before and after perturbation. This means using graph convolutional layers to extract node structure features and combining perturbation embedding layers to fuse dynamic perturbation information. Specifically, architectures such as GCN or GraphSAGE can be used to solve the problem that traditional rule metrics cannot capture complex topological evolution patterns. Among them, the robustness evaluation metrics include the network connectivity retention rate and the service interruption ratio. This means calculating the change in the number of connected components and the degree of service availability loss through simulation data. Specifically, it can be realized based on the depth-first search algorithm and business flow tracing technology to quantify the degree of network performance degradation under different perturbation scenarios. Among them, the weak point identification results and optimization suggestions include redundant configuration of key nodes and construction of link redundancy. This means analyzing node centrality metrics and link load thresholds. Specifically, a reinforcement plan can be generated by combining the PageRank algorithm and the minimum spanning tree optimization method to solve the problem that traditional evaluations lack targeted optimization guidance.
[0064] This application constructs a collaborative mechanism for a dynamic perturbation propagation model and a graph neural network evaluation framework, realizes the dynamic simulation of industrial network topologies under complex scenarios such as attack diffusion and fault propagation through multi-dimensional perturbation parameter configuration, quantifies network robustness by combining graph-level embedding and multi-objective evaluation metrics, and forms a closed-loop evaluation system from perturbation modeling, structural evolution analysis to weak point identification, breaking through the technical limitations of traditional static graph analysis and rule metric calculations.
[0065] The working process and principle of this application are as follows: First, model each device node in the industrial network, such as PLC, SCADA, sensors, and edge controllers, as nodes, and model the communication links between devices, such as Ethernet, PROFINET, and Modbus, as edges to construct an industrial network topology model. Then, set a perturbation scenario model including node random failure perturbation, network attack perturbation, and link degradation perturbation. This model has propagation parameters such as perturbation duration, propagation probability, influence radius, and attack preference function.
[0066] Next, in the simulation environment, perform perturbation simulation on the industrial network topology model according to the perturbation scenario model, and record the change process of the topology structure and the evolution information of connectivity after perturbation. Use a graph neural network model to perform feature learning and embedding on the network topology graphs before and after perturbation, and output the robustness score value R-score corresponding to the perturbation scenario.
[0067] Calculate robustness evaluation indicators such as network connectivity retention rate, service interruption ratio, growth multiple of routing path delay, and average number of path hops for fault recovery based on the simulation data. Finally, output the weak point identification results of the topology structure according to these indicators, and give optimization suggestions such as redundant configuration of key nodes, optimization of master controller deployment, construction of link redundancy, and re-planning of communication paths.
[0068] It can be understood that through the combination of dynamic simulation and graph neural network, the security and robustness analysis of the industrial network topology structure under various perturbation scenarios is realized, which can effectively identify the weak links in the network and give targeted optimization suggestions.
[0069] As a preferred embodiment, the solution of this application is specifically implemented as follows:
[0070] Collect information on device nodes and communication links in the industrial network. Model devices such as PLC, SCADA systems, various sensors, and edge controllers as nodes, and model communication links such as Ethernet, PROFINET buses, and Modbus protocols as edges to construct a complete industrial network topology model.
[0071] Set the perturbation scenario model. Include node random failure perturbation (such as device failure), network attack perturbation (such as distributed denial of service attack), link degradation perturbation (such as bandwidth congestion), etc. Define propagation parameters such as perturbation duration, propagation probability, and influence radius, and construct an attack preference function based on the network centrality and service importance of nodes.
[0072] Perform perturbation simulation on the industrial network topology model in the simulation environment. According to the set perturbation scenario model, simulate the propagation process of the perturbation in the network, and record the dynamic changes of the topology structure and the evolution information of connectivity.
[0073] A graph neural network model is used to perform feature learning and embedding on the network topology graphs before and after perturbations. Network structure features are extracted through operations such as graph convolution, and the perturbation information is encoded as a feature matrix and input into the network. Finally, the robustness score value R-score corresponding to the perturbation scenario is output.
[0074] Based on the simulation data, robustness evaluation metrics are calculated. These include metrics in multiple dimensions such as the network connectivity retention rate, service interruption ratio, growth multiple of routing path delay, average path hop count for fault recovery, etc.
[0075] According to the robustness evaluation metrics, the weak point identification results of the topological structure are output. For example, when there are nodes with high sensitivity to single-point failures, they are determined as high-risk nodes and it is recommended to configure key node redundancy. When the path transfer causes an increase in delay, it is determined as a performance bottleneck link and it is recommended to construct link redundancy. When the degree centrality of a certain node is too high, it is recommended to optimize the master controller deployment. When the average path hop count is too large, it is recommended to re-plan the communication path.
[0076] Through the above solution, this application can dynamically simulate the topological structure changes of industrial networks under various perturbation scenarios, extract network features using graph neural networks and quantitatively evaluate the robustness, so as to identify the vulnerable links in the network. Compared with traditional static analysis methods, it more comprehensively reflects the actual dynamic impact of perturbations on system connectivity and service reachability, and effectively captures the cascade effects caused by node failures or the spread of attacks. By outputting targeted optimization suggestions, such as key node redundancy configuration, link bandwidth optimization, etc., it can improve the overall security and robustness of industrial networks, reduce the system interruption risk, and ensure the continuity and stability of the production process.
[0077] In some of the above solutions of this application, the network attack perturbations in the perturbation scenarios are only simulated through a single attack mode, which cannot cover the diverse attack means that may exist in the actual industrial network. As a result, the simulation results are difficult to accurately reflect the dynamic response and vulnerability of the network topology structure under different attack strategies, limiting the comprehensiveness and pertinence of the evaluation results.
[0078] This application further proposes that the network attack perturbations include distributed denial-of-service attacks, man-in-the-middle attacks, routing spoofing attacks, or command injection attacks.
[0079] Among them, the distributed denial-of-service attack tests the failure mode of nodes under abnormal loads by simulating the process of resource exhaustion of target nodes through multi-source traffic. The man-in-the-middle attack evaluates the risk of service interruption caused by the lack of link encryption mechanism by intercepting or tampering with transmitted data by inserting false communication links. The routing spoofing attack verifies the security defects of network routing protocols by forging routing table information to mislead data transmission paths. The command injection attack detects the impact of device protocol parsing vulnerabilities on system stability by injecting malicious instructions into the control node. Multiple attack modes respectively target four levels: node resources, link transmission, routing logic, and control protocols, forming a multi-dimensional attack vector set.
[0080] Specifically, in the simulation environment, a multi-source traffic generator for distributed denial-of-service attacks, a false link insertion module for man-in-the-middle attacks, a routing table tampering unit for routing spoofing attacks, and a protocol vulnerability exploitation interface for command injection attacks are respectively constructed. When a network attack perturbation is triggered, the corresponding module is called according to the preset attack type to inject attack payloads into the industrial network topology model. The distributed denial-of-service attack sends high-density data packets to the target node through multi-threaded concurrency to monitor the overflow threshold of the node processing queue. The man-in-the-middle attack inserts proxy nodes in the communication link to intercept and modify transmitted messages in real time. The routing spoofing attack forges path information during the routing protocol interaction phase to induce data to flow to non-optimal or high-risk links. The command injection attack constructs data frames containing illegal instructions by reverse-analyzing the device communication protocol. Different attack types run independently or in combination during the simulation process. By recording the node failure rate, link error rate, path redundancy, and control instruction anomaly rate, the performance degradation curve of the network topology under different attack vectors is quantified.
[0081] As a preferred embodiment, the solution of the present application is specifically implemented as follows:
[0082] The network attack perturbations in the perturbation scenario include distributed denial-of-service attacks, man-in-the-middle attacks, routing spoofing attacks, or command injection attacks. Specifically, the distributed denial-of-service attack can simulate a large amount of malicious traffic surging into the target node, causing its resources to be exhausted and unable to respond to normal requests. The man-in-the-middle attack intercepts and tampers with transmitted data by inserting malicious nodes between the two communication parties. The routing spoofing attack can forge routing information to induce data packets to pass through malicious nodes. The command injection attack targets industrial control systems and interferes with normal control logic by injecting malicious instructions into PLC or SCADA systems.
[0083] Through the above technical solutions, the present application can simulate a variety of typical network attack scenarios, comprehensively evaluate the security and robustness of the industrial network topology in the face of different types of network attacks. Thereby, the weak links vulnerable to specific attacks can be identified, providing a targeted basis for subsequent optimization of network protection strategies and adjustment of the topology structure, thus improving the overall anti-attack ability and reliability of the industrial network.
[0084] In some of the above solutions of the present application, the attack preference function is used to simulate the node selection tendency of the attacker in the network attack perturbation scenario. However, relying solely on a single factor (such as node degree or service level) may lead to an insufficiently comprehensive evaluation of attack preference, unable to accurately reflect the actual behavior pattern of the attacker's attack decision-making by combining the network topology structure and business value, resulting in a deviation between the simulation results and the real attack scenario.
[0085] The present application further proposes that the attack preference function is jointly determined by the network centrality and business importance of the node, satisfying the following form: P = α·C + β·D, where P is the attack preference function, C represents the network centrality of the node, D represents the business importance, α and β are weight parameters, and α + β = 1.
[0086] Among them, the network centrality C is measured by at least one of the node degree centrality, betweenness centrality, or closeness centrality, reflecting the connection strength and hub role of the node in the topology structure. The business importance D is quantified by at least one of the service types carried by the node, service priority, or data flow throughput, reflecting the functional value of the node in business operation. The weight parameters α and β are configured according to historical attack data analysis or expert experience, used to adjust the influence weights of network structure attributes and business attributes on attack preference. For example, in the command injection attack scenario against the industrial control system, the attacker is more inclined to select PLC nodes with both high connectivity (high C value) and key control functions (high D value). At this time, set α = 0.6 and β = 0.4.
[0087] Specifically, when simulating network attack perturbation, first calculate the standardized values of the network centrality C and business importance D for all nodes in the industrial network topology model, and then generate the attack preference degree P of each node through linear combination according to the preset α and β parameters. The attacker selects the initial attack target based on the P value, and continuously updates the P value of the affected nodes during the attack propagation process, dynamically adjusting the attack path. By superimposing the dual perspectives of the network topology structure and business logic, the attack preference function can more accurately simulate the attacker's target selection strategy, making the simulation results more consistent with the behavioral characteristics of the attacker considering both node connectivity and business criticality in actual attacks. This method solves the problem of single attack preference modeling in traditional evaluations, improving the authenticity of perturbation scenario simulation and the credibility of evaluation indicators.
[0088] As a preferred embodiment, the solution of the present application is specifically implemented as follows:
[0089] The attack preference function is jointly determined by the network centrality and service importance of the node, and satisfies the following form: P = α·C + β·D
[0090] Where P represents the attack preference function, C represents the network centrality of the node, D represents the service importance, α and β represent weight parameters, and α + β = 1.
[0091] Specifically, the network centrality C can be calculated through indicators such as degree centrality, betweenness centrality, or eigenvector centrality of the node. For example, the degree centrality of the node can be used as the C value, that is, the number of other nodes directly connected to the node. The service importance D can be determined according to the functional role of the node in the industrial control system. For example, a higher D value (such as 0.9) is given to the SCADA master station, and a lower D value (such as 0.1) is given to ordinary sensor nodes.
[0092] The weight parameters α and β are used to balance the influence of network topology characteristics and service function importance on attack preference. In practical applications, they can be adjusted according to specific scenario requirements. For example, when more attention is paid to pure network structure vulnerability, α = 0.8 and β = 0.2 can be set. When more emphasis is placed on protecting key service nodes, α = 0.3 and β = 0.7 can be set.
[0093] Furthermore, the value range of the P function can be normalized to the interval [0,1] for subsequent simulation analysis. Thus, when simulating network attack perturbations, the attack target can be selected according to the P value of each node with probability to achieve differential attack simulation of nodes with different importance levels.
[0094] Through the above technical solution, the present application can comprehensively consider network topology characteristics and node service importance, and construct a more practical attack preference model. It improves the accuracy and pertinence of industrial network security robustness analysis, and provides a more reliable basis for identifying key vulnerable nodes and optimizing network protection strategies. At the same time, the adjustable weight parameters have strong flexibility and adaptability, and can be customized according to the requirements of different application scenarios.
[0095] In some of the above solutions of the present application, during the dynamic perturbation simulation process of the industrial network topology structure, traditional graph neural network models are difficult to effectively capture the state change differences of nodes before and after perturbation, and do not deeply integrate the propagation characteristics of perturbation scenarios with network structure features, resulting in the robustness scoring results being unable to accurately reflect the actual impact of perturbation on network dynamic connectivity.
[0096] The present application further proposes a graph neural network model, which includes a graph convolutional layer, a perturbation embedding layer, a node state time difference encoding layer, a graph-level representation aggregation layer, and a robustness score output layer.
[0097] Among them, the graph convolutional layer uses multi-layer convolutional operations to perform multi-order feature extraction on the node adjacency relationship, and the convolutional kernel parameters of each layer are optimized by the backpropagation algorithm. The perturbation embedding layer defines a perturbation feature matrix, where each element in the matrix corresponds to the perturbation type encoding, propagation level value, criticality weight coefficient, and perturbed state identifier of the node. This matrix is mapped to the same dimensional space as the node static attributes through a fully connected layer and then channel concatenation is performed. The node state time difference encoding layer calculates the Euclidean distance difference between the feature vectors of the same node before and after perturbation, and concatenates the difference vector with the current node feature. The graph-level representation aggregation layer uses an attention pooling mechanism to assign dynamic weights to the embedding vectors of different nodes and then perform weighted summation. The robustness score output layer uses a three-layer fully connected network, with the activation function of the middle layer being ReLU and the activation function of the output layer being Sigmoid, mapping the whole graph embedding vector to a score value in the range of 0-1.
[0098] Specifically, after the perturbation simulation of the industrial network topology model is completed, the graph convolutional layer performs three graph convolutional operations on the initial network nodes, and each convolution is processed by the LeakyReLU activation function. The perturbation embedding layer encodes the attack type of each node as a one-hot vector, the propagation level value is calculated by the breadth-first search algorithm, the criticality weight coefficient is obtained by normalizing the node betweenness centrality, and the perturbed state identifier is a boolean value. The concatenated node features are input to the graph convolutional layer for secondary feature extraction. The node state time difference encoding layer calculates the difference between the feature vector before perturbation and the feature at the third time step after perturbation for each node, and the difference vector is normalized and then concatenated with the current feature. The graph-level representation aggregation layer uses a learnable attention weight matrix to perform a non-linear transformation on the node embeddings and then calculate the attention scores, and performs weighted summation according to the scores to generate a 256-dimensional whole graph embedding vector. The robustness score output layer inputs the whole graph embedding into the fully connected network, and after dimensionality reduction through the 128-dimensional and 64-dimensional middle layers, outputs a single score value. The correlation coefficient between this score value and the network connectivity retention rate reaches 0.87, which is a 23% improvement compared to the traditional graph classification model.
[0099] As a preferred embodiment, the solution of the present application is specifically implemented as follows:
[0100] The graph neural network model includes a graph convolutional layer, a perturbation embedding layer, a node state time difference encoding layer, a graph-level representation aggregation layer, and a robustness score output layer.
[0101] The graph convolutional layer extracts the structural features of the nodes and adjacency relationships of the industrial network topology. Specifically, a multi-layer graph convolutional network is adopted, with each layer containing 32 convolutional kernels and the activation function being ReLU.
[0102] The perturbation embedding layer encodes the perturbation information of each node in the perturbation scenario model into a perturbation feature matrix, and inputs it into the graph neural network together with the static attributes of the nodes. The dimension of the perturbation feature matrix is the number of nodes × 4, and the four features respectively represent the perturbation type, propagation level, node criticality, and whether it is directly perturbed.
[0103] The node state time difference encoding layer calculates the difference between the state vectors of the same node before and after perturbation as the dynamic input. The long short-term memory network (LSTM) is used to encode the node state sequence, and the dimension of the hidden layer is 64.
[0104] The graph-level representation aggregation layer performs a pooling operation on all node embedding representations to generate the whole-graph embedding. A graph pooling layer with an attention mechanism is adopted, and a 256-dimensional graph-level representation vector is output.
[0105] The robustness score output layer outputs the robustness score value R-score corresponding to the perturbation scenario according to the whole-graph embedding. A two-layer fully connected network is adopted, and the last layer outputs a single scalar as the R-score.
[0106] Through the above technical solutions, the present application can effectively capture the dynamic evolution characteristics of the industrial network topology under different perturbation scenarios, and achieve an accurate quantitative evaluation of the network robustness. The graph convolutional layer extracts the topological relationship information between nodes, the perturbation embedding layer fuses the dynamic features of the perturbation scenario, the node state difference encoding reflects the changes before and after perturbation, and the graph-level aggregation integrates the global information. This end-to-end deep learning framework avoids the limitations of manually designed features, can adaptively learn the structural features and dynamic behavior patterns of complex industrial networks, and thus outputs a more objective and accurate robustness score.
[0107] In some of the above solutions of the present application, when the perturbation embedding layer combines the perturbation features with the static attributes of the nodes, there is a problem that the dynamic perturbation information and the static topological features are not fully fused, resulting in the graph neural network being difficult to accurately capture the state changes of the nodes during the perturbation propagation, and affecting the accuracy of the robustness score.
[0108] The present application further proposes that the perturbation embedding layer constructs perturbation channel features based on the perturbation feature matrix. The perturbation feature matrix is used to represent the perturbation type, propagation level, node criticality, and whether it is directly perturbed of each node in the perturbation scenario, and is spliced with the node static feature channel through the perturbation channel and input into the graph convolutional layer.
[0109] Among them, the perturbation type is mapped to a vector through discrete coding, the propagation level is generated according to the shortest path length between the node and the initial perturbed node, the node criticality is calculated by betweenness centrality, and whether it is directly perturbed is represented by a binary flag. Each row of the perturbation feature matrix corresponds to the perturbation state vector of a node, and its dimension is determined by the number of perturbation parameters. The node static feature channels include device type, number of ports, protocol type, and configuration parameters. The concatenation operation extends the node feature vector along the feature dimension direction to form a mixed input containing static attributes and dynamic perturbations. The graph convolutional layer performs neighborhood information aggregation on the mixed features to generate a node embedding representation containing perturbation propagation information.
[0110] Specifically, the perturbation embedding layer first encodes the dynamic attributes of the node in the perturbation scenario into a four-dimensional vector, including the perturbation type identifier, the propagation level value, the criticality quantization value, and the perturbed state flag. This vector is concatenated with the static feature vector containing device type, communication protocol, and port configuration to form a multi-dimensional mixed feature. After the mixed feature is input into the graph convolutional layer, by aggregating the feature information of adjacent nodes, the propagation path and influence range of the perturbation in the topology are captured. For example, for a node that is directly perturbed and has a high criticality, the perturbed flag and criticality value in its perturbation feature vector will enhance the influence weight of this node on the neighborhood during the graph convolutional process, thus highlighting its key role in the graph-level representation. Thus, the graph neural network can simultaneously fuse static topology features and dynamic perturbation states, improving the representation ability of network robustness changes.
[0111] As a preferred embodiment, the solution of this application is specifically implemented as follows:
[0112] The perturbation embedding layer constructs perturbation channel features based on the perturbation feature matrix. The perturbation feature matrix is used to represent the perturbation type, propagation level, node criticality, and whether it is directly perturbed of each node in the perturbation scenario. It is input into the graph convolutional layer through concatenation with the node static feature channels.
[0113] Specifically, the perturbation feature matrix can be designed as an N×4 matrix, where N is the number of network nodes. The 4 columns of the matrix correspond to 4 feature dimensions of perturbation type, propagation level, node criticality, and whether it is directly perturbed. The perturbation type can be represented by an integer encoding from 0 to 3, where 0 represents no perturbation, 1 represents random failure, 2 represents network attack, and 3 represents link degradation. The propagation level is represented by an integer indicating the number of hops for the perturbation to propagate from the source to this node. The node criticality is represented by a floating point number from 0 to 1 indicating the importance of this node to network connectivity. Whether it is directly perturbed is represented by 0 or 1.
[0114] The disturbance channel features can be obtained by performing a non - linear transformation on the disturbance feature matrix, for example, using a multi - layer perceptron to encode the matrix. The node static feature channel can contain attribute information such as node type, processing capacity, connectivity, etc. The feature vectors of the two channels are merged through a concatenation operation and used as the input to the graph convolution layer.
[0115] This design enables the model to consider both the static attributes of nodes and dynamic disturbance information simultaneously, which is beneficial for learning a more comprehensive network feature representation.
[0116] Through the above - mentioned technical solutions, this application can effectively fuse static topological features and dynamic disturbance information, improving the modeling ability of graph neural networks for the robustness of industrial networks. The design of the disturbance feature matrix enables the model to capture the propagation characteristics of different types of disturbances, which helps to accurately evaluate the impact of disturbances on the network structure. The concatenation input mechanism of the disturbance channel and the static feature channel enables the model to consider both the inherent attributes of nodes and the current disturbed state during graph convolution, thereby generating a more comprehensive and accurate node representation. This method of fusing static and dynamic features improves the adaptability of the model to complex industrial network scenarios and is beneficial for outputting more reliable robustness evaluation results.
[0117] In some of the above - mentioned solutions of this application, when calculating the robustness evaluation index based on simulation data, traditional methods only evaluate the network robustness through a single index or a simple superposition method, which cannot effectively quantify the dynamic correlation between different indexes. As a result, the evaluation results are difficult to accurately reflect the comprehensive performance degradation degree of the network under multiple disturbances and cannot provide a normalization basis for optimization decisions.
[0118] This application further proposes to obtain a comprehensive robustness score based on a multi - objective weighting function. The comprehensive robustness score is calculated by the following formula: R = w1·CRR+w2·(1−SIR)+w3·(1 / DIF)+w4·(1 / ARH). Where w1, w2, w3, and w4 are positive weight coefficients, R represents the comprehensive robustness score, CRR represents the network connectivity retention rate, SIR represents the service interruption ratio, DIF represents the growth multiple of the routing path delay, and ARH represents the average number of hops of the fault recovery path.
[0119] Among them, the network connectivity retention rate CRR is defined as the ratio of the number of nodes in the largest connected subgraph that remains connected after perturbation to the total number of nodes in the original network. The service interruption ratio SIR is calculated by the ratio of the number of service interruptions affected by the perturbed nodes to the total number of services. The routing path delay increase factor DIF is determined by the ratio of the average delay of the critical path after perturbation to the original delay. The average number of hops of the fault recovery path ARH is calculated by the ratio of the total number of hops of the recovery path to the number of recovery paths. The weight coefficients w1, w2, w3, and w4 are dynamically adjusted according to the specific industrial scenario requirements. For example, in a scenario with high real-time requirements, the value of w3 is higher than other weights to strengthen the impact of delay increase on the score. The index normalization process uses linear transformation, where the delay increase factor and the number of hops of the path take the reciprocal to eliminate the dimension difference, and the service interruption ratio takes the complement to unify the index to be positive.
[0120] Specifically, during the simulation process, the network connectivity retention rate CRR quantifies the network resilience from the topological structure dimension, the service interruption ratio SIR reflects the functional integrity from the business continuity dimension, the routing path delay increase factor DIF measures the degree of communication efficiency degradation, and the average number of hops of the fault recovery path ARH evaluates the redundancy of the recovery path. The four types of indicators are integrated into a single score value R through a multi-objective weighting function, solving the problem that multi-dimensional indicators in traditional methods cannot be evaluated collaboratively. For example, when the network connectivity retention rate CRR is high but the service interruption ratio SIR increases at the same time, the score R automatically balances the influence of the two types of indicators through the weight coefficient, avoiding misjudgment caused by isolated indicators. The weight coefficient can be dynamically configured according to the priority of the industrial network. For example, in a power control network, if network connectivity is a key requirement, then w1 is set to 0.5, and w2 to w4 are each set to 0.16, making the score more focused on the connectivity indicator. This calculation method complements the robustness score output by the graph neural network. The former is based on physical layer indicators, and the latter is based on topological dynamic characteristics. The combination of the two improves the comprehensiveness of weakness identification.
[0121] As a preferred embodiment, the solution of the present application is specifically implemented as follows:
[0122] Obtain a comprehensive robustness score based on the multi-objective weighting function. The comprehensive robustness score is calculated by the following formula: R = w1·CRR + w2·(1 - SIR) + w3·(1 / DIF) + w4·(1 / ARH).
[0123] Among them, w1, w2, w3, and w4 are positive weight coefficients, R represents the comprehensive robustness score, CRR represents the network connectivity retention rate, SIR represents the service interruption ratio, DIF represents the routing path delay increase factor, and ARH represents the average number of hops of the fault recovery path.
[0124] Specifically, in practical applications, the weight coefficients of various indicators can be adjusted according to the requirements of different industrial network scenarios. For example, for an industrial control network that requires high availability, the weight w1 of the network connectivity retention rate CRR can be increased. For a real-time control system that is sensitive to latency, the weight w3 corresponding to the growth multiple DIF of the routing path latency can be increased.
[0125] Furthermore, a benchmark threshold is set. When the calculated comprehensive robustness score R is lower than this threshold, the network optimization process is triggered. Thus, the dynamic evaluation and timely optimization of the robustness of the industrial network topology are realized.
[0126] Through the above technical solutions, the present application realizes the quantitative evaluation of the robustness of the industrial network topology. By comprehensively considering multiple key indicators and introducing adjustable weight coefficients, the evaluation results are more comprehensive and flexible. This method overcomes the limitations of traditional single-indicator evaluation and can more accurately reflect the overall robustness performance of the network in the face of various perturbations. At the same time, due to the use of standardized mathematical formulas, the evaluation process is more objective and repeatable, which is helpful for horizontal comparison between different network topologies.
[0127] In some of the above solutions of the present application, a solution for identifying the weaknesses of the topology structure based on the robustness evaluation indicators and outputting optimization suggestions is proposed. However, when judging the specific weakness types according to the indicator data, there may be a defect that it is impossible to effectively distinguish different problem types such as single-point failure, link performance bottleneck, and nodes with too high centrality, resulting in the lack of pertinence of the optimization suggestions and making it difficult to directly guide the improvement of the network structure.
[0128] The present application further proposes that when outputting the weakness identification results and optimization suggestions of the topology structure based on the robustness evaluation indicators, it includes: when there are high single-point failure sensitivity, core nodes for perturbation propagation, or graph neural network embedding dynamics, it is determined that the weakness identification result is the existence of high-risk nodes, and the optimization suggestion is output as redundant configuration of key nodes. When there are increased latency caused by path transfer, high link bandwidth utilization, or increased number of hops for recovery after link failure, it is determined that the weakness identification result is the existence of performance bottleneck links, and the optimization suggestion is output as link redundancy construction. When there is a node with high degree centrality, high betweenness centrality, or high structural dependence, it is determined that the weakness identification result is the existence of nodes with too high centrality, and the optimization suggestion is output as optimization of the master controller deployment. When the average path hop count is large, the fault recovery path is long, or the physical coverage of the link is not optimal, it is determined that the weakness identification result is the existence of too long delay hops, and the optimization suggestion is output as communication path re-planning.
[0129] Among them, the sensitivity to single-point failure is quantified by the decrease in the network connectivity retention rate after a node is removed. When the decrease exceeds a preset threshold, the determination of a high-risk node is triggered. The increase in path delay is detected by comparing the growth multiple of the routing path delay with the historical baseline data. When the growth multiple reaches more than 2 times, the determination of a performance bottleneck link is triggered. The degree centrality and betweenness centrality are calculated in a normalized manner. When the node degree centrality exceeds 0.8 or the betweenness centrality exceeds 0.6, the node is determined to have an excessive centrality. The number of hops in the fault recovery path is calculated according to the shortest path algorithm. When the average number of hops exceeds 4 hops, it is determined that the delay number of hops is too long.
[0130] Specifically, after calculating the network connectivity retention rate, service interruption ratio, growth multiple of routing path delay, and average number of hops in the fault recovery path, each indicator is compared with a preset threshold. For example, when the removal of a certain PLC node causes the network connectivity retention rate to drop from 95% to 60%, this node is determined to be a high-risk node, and redundant PLCs need to be deployed adjacent to it. When the growth multiple of the delay of a certain Ethernet link reaches 3 times and the bandwidth utilization rate exceeds 85%, it is determined to be a performance bottleneck link, and a PROFINET link needs to be added in the parallel path. When the degree centrality of a SCADA node is 0.85 and the betweenness centrality is 0.7, it is determined to be a node with excessive centrality, and some of its control functions need to be migrated to the edge controller. When the average number of hops in the fault recovery is 5 hops and the physical link distance exceeds 200 meters, it is determined that the delay number of hops is too long, and the communication path topology needs to be re-planned. By associating specific indicator values with preset conditions, different types of weaknesses can be accurately identified and corresponding optimization measures can be triggered.
[0131] As a preferred embodiment, the solution of the present application is specifically implemented as follows:
[0132] When outputting the weakness identification result and optimization suggestions of the topology structure according to the robustness evaluation indicators, it includes:
[0133] Judge whether there is a situation of high sensitivity to single-point failure, core nodes for disturbance propagation, or graph neural network embedding dynamics. If it exists, it is determined that the weakness identification result is the existence of high-risk nodes, and the optimization suggestion output is the redundant configuration of key nodes. For example, the system reliability can be improved by adding standby PLCs or redundant SCADA servers.
[0134] Check whether there is a situation where the path transfer causes an increase in delay, high link bandwidth utilization, or an increase in the number of recovery hops after link failure. If it exists, it is determined that the weakness identification result is the existence of a performance bottleneck link, and the optimization suggestion output is the construction of link redundancy. Specifically, the network performance can be improved by adding standby communication links or upgrading the bandwidth of existing links.
[0135] Evaluate whether there is a situation where a node has a high degree centrality, high betweenness centrality, or high structural dependence. If so, determine that the weak point identification result is that there are nodes with excessive centrality, and output the optimization suggestion as the optimization of the master controller deployment. For example, consider dispersing some control functions to other nodes to reduce the risk of single-point failure.
[0136] Analyze whether the average hop count of the path, the length of the fault recovery path, or the physical coverage of the link is non-optimal. If there are such problems, determine that the weak point identification result is that there is an excessive delay hop count, and output the optimization suggestion as the replanning of the communication path. Specifically, the communication delay can be reduced by adjusting the network topology structure or optimizing the routing strategy.
[0137] Specifically, a high sensitivity to single-point failure means that in multiple rounds of perturbation simulations, the failure of a node causes the network connectivity retention rate CRR to decrease by ≥30%; or the service interruption ratio SIR to increase by ≥40%; or the overall robustness score R-score to decrease by ≥0.25; then it can be regarded as a high-risk node. A core node for perturbation propagation means that the node belongs to the first layer or relay layer of the propagation path in multiple perturbation propagation graphs; its critical degree (the decrease in the number of reachable nodes after failure) is in the top 10% of the entire network. The embedding movement of the graph neural network means that the Euclidean distance of the embedding vector of the node before and after perturbation is greater than 1.5 times the mean value of the entire graph.
[0138] The increase in delay caused by path transfer means that after a certain link is perturbed in the simulation, the average path delay growth multiple DIF of the alternative path is ≥2.0; and the frequency of this link in multiple critical paths is ≥30%; The link bandwidth utilization rate is too high means that after the link bandwidth utilization rate reaches the set threshold (such as ≥85%), there is obvious congestion or delay propagation in other paths within the system; and this link is the only channel connecting two highly important subnets.
[0139] A high degree centrality index means that the number of edges connected to the node ≥ the 90th percentile value of the node degrees of the entire graph; a high betweenness centrality means that the frequency of the node in all the shortest paths is in the top 10% of the entire network, especially in the backbone path-dependent single-point relay transmission structure.
[0140] A large average hop count of the path means that for the communication path between any two high-weight nodes, the hop count ≥8 (according to the real-time requirements of industrial control); or it is ≥3 hops longer than the shortest reachable path, indicating the existence of forwarding redundancy or an unreasonable physical topology. The length of the fault recovery path means that after the original path is broken, the hop count of the recovery path (ARH) increases by ≥2; and the increase in the delay of the recovery path causes the R-score to decrease by ≥0.15. The non-optimal physical coverage of the link means that from the analysis of the topology, there are many detour structures (such as A→B→C→D could have been directly connected by A→D), resulting in normal communication detouring and wasting of scheduling resources.
[0141] Through the above technical solutions, the present application can specifically identify potential weaknesses in the industrial network topology and provide corresponding optimization suggestions. It improves the security and robustness of the network, reduces the risk of single-point failures, optimizes network performance, and reduces communication latency. At the same time, through the automated process of weakness identification and optimization suggestion generation, it reduces the workload and subjectivity of manual analysis, and improves the accuracy and operability of the evaluation results.
[0142] In some of the above solutions of the present application, the comprehensive robustness score can reflect the overall robustness level of the network topology under multiple perturbation scenarios. However, during the continuous simulation process, the score fluctuations corresponding to different simulation results may mask key risk points, and there is a lack of a dynamic monitoring and alarm mechanism for continuously low-score states, resulting in the inability to timely identify the topology vulnerable state that requires urgent intervention.
[0143] The present application further proposes that after multiple simulations are completed, the weakness identification results and optimization suggestions of each simulation are collected, the corresponding comprehensive robustness scores are obtained, and each score is compared with a preset minimum threshold, and an audible and visual warning is triggered according to the comparison result. When all scores are lower than or equal to the minimum threshold, the warning is activated; otherwise, the normal state is maintained. When the warning is triggered, the absolute difference between each score and the threshold is calculated, and the warning level is divided according to the size of the difference. The level value is positively correlated with the size of the difference, and the audible and visual device is driven to perform the warning operation corresponding to the level.
[0144] Among them, the minimum threshold of the comprehensive robustness score is obtained through training with historical security event data and is used to divide the critical point of the network topology security state. The absolute value operation is used in the score difference calculation to eliminate the influence of positive and negative deviations, ensuring that the level division only focuses on the degree of deviation. The warning level is divided into three levels. The difference in the interval [0, 10) corresponds to a first-level warning, [10, 20) corresponds to a second-level warning, and 20 and above correspond to a third-level warning. The audible and visual device adjusts the alarm frequency and light color according to the level.
[0145] Specifically, after ten simulations are completed, ten sets of comprehensive robustness scores are obtained. If all ten sets of scores are lower than the preset threshold of 75, the warning process is triggered. Calculate the absolute value of the difference between each set of scores and 75. For example, when the score is 68, the difference is 7, corresponding to a first-level warning. When the score is 50, the difference is 25, corresponding to a third-level warning. When the proportion of the number of third-level warnings exceeds 50%, the audible and visual device is driven to indicate the high-risk state with red strobing and high-frequency beeping. When there is at least one set of scores higher than 75, it is determined that the system has local recovery ability and the warning is not triggered. The dynamic risk assessment is realized by quantifying the degree of score deviation. The difference threshold interval is set according to the industrial network fault tolerance standard to ensure that the warning level has a linear correspondence with the actual risk.
[0146] As a preferred embodiment, the solution of the present application is specifically implemented as follows: Collect simulation data under ten different disturbance scenarios. Each time the simulation is executed, a composite disturbance including distributed denial-of-service attacks, random node failures, and link degradation is imposed on the industrial network topology model. After each simulation ends, obtain the corresponding vulnerability identification results and optimization suggestions, and calculate the comprehensive robustness score R. Preset the lowest threshold of the comprehensive robustness score to be 0.6. Compare the R values of the ten simulations with the threshold respectively. If all R values are less than or equal to 0.6, trigger the audible and visual warning device. At this time, calculate the score difference between each R value and the threshold, take the average of the absolute values of the ten differences, and determine the warning level according to the average value. For example, when the average difference is 0.2, it corresponds to a yellow warning; when it is 0.3, it corresponds to an orange warning; when it is above 0.4, a red warning is triggered. Different warning levels are distinguished by different combinations of beep frequencies and light colors.
[0147] Through the above technical solution, the present application solves the technical problem that traditional methods cannot dynamically evaluate the network robustness threshold under multi-disturbance scenarios and give timely warnings. By establishing the linkage rules between the simulation results and the warning mechanism, it is possible to automatically trigger hierarchical alarms when the comprehensive network robustness continues to be lower than the safety baseline, enabling the operation and maintenance personnel to quickly locate the areas where network vulnerabilities are concentrated and timely execute optimization suggestions to block the spread of risks.
[0148] In some of the above solutions of the present application, after calculating the robustness evaluation index based on the simulation data and outputting the vulnerability identification results and optimization suggestions, judging whether to give a warning only through the single simulation result has the risk of misjudgment and cannot reflect the dynamic changes of network robustness under different disturbance scenarios, resulting in the lack of flexibility and accuracy of the warning mechanism.
[0149] The present application further proposes that when all comprehensive robustness scores are less than or equal to the lowest threshold of the comprehensive robustness score, it is determined to give an audible and visual warning. When there is a comprehensive robustness score greater than the lowest threshold of the comprehensive robustness score, it is determined not to give an audible and visual warning.
[0150] Among them, the lowest threshold of the comprehensive robustness score is determined by the average score when the network is in a critical failure state in the historical simulation data. For example, take the 5th percentile value of the score distribution in the historical data as the threshold. The score difference is the absolute value of the difference between the comprehensive robustness score and the lowest threshold. The warning level is mapped through the difference size. The warning level is divided into three intervals. The difference in the range of 0 - 5% corresponds to a low-level warning, the difference in the range of 5% - 15% corresponds to a medium-level warning, and the difference greater than 15% corresponds to a high-level warning. The audible and visual warning is realized through a multi-band sound wave generator and a three-color LED light. The low-level warning triggers a yellow light and a single beep, the medium-level warning triggers an orange light and an intermittent beep, and the high-level warning triggers a red light and a continuous alarm sound.
[0151] Specifically, after multiple perturbation simulations are completed, the comprehensive robustness scores generated by each simulation are compared with a preset minimum threshold. If all scores are lower than or equal to the threshold, it indicates that the network has high risks under different perturbation scenarios. At this time, the acoustic-optic warning mechanism is activated. The warning level is dynamically adjusted according to the score difference. For example, when the comprehensive robustness score of a certain simulation is 0.65 and the minimum threshold is 0.7, the difference of 5% triggers a low-level warning. If the score is 0.5, the difference is 20%, which triggers a high-level warning. The acoustic-optic warning device is connected to the simulation system through the RS-485 bus. After receiving the difference data, it calls the preset warning protocol to drive the lighting and sound modules, thus realizing hierarchical visual warning.
[0152] As a preferred embodiment, the solution of the present application is specifically implemented as follows: in the simulation analysis of the power monitoring network topology, first, ten perturbation simulation tests are carried out on a three-layer network including a SCADA master station, a regional PLC controller, and intelligent meter nodes. Each simulation generates a corresponding comprehensive robustness score, and this score sequence is compared with a preset minimum threshold of 0.65 points. When the results of the ten simulations do not exceed the threshold, the system automatically calculates the absolute difference between each score and the threshold. The difference interval is divided into three warning levels: 0 - 0.1 points correspond to a blue rotating light and an 800 Hz beeping sound. 0.11 - 0.2 points correspond to a yellow flashing light and a 1200 Hz intermittent alarm. Above 0.21 points triggers a red constant light and a 2000 Hz continuous beep. Operators can quickly identify the overall risk level of the current network topology through the warning color distribution map and sound fingerprint features on the human-machine interface.
[0153] Through the above technical solution, the present application realizes the precise mapping of the dynamic warning mechanism and the network state change, and solves the defect that the traditional static evaluation cannot reflect the risk of multi-perturbation superposition in real time. The hierarchical warning mechanism forms a multi-level response strategy by quantifying the score difference, enabling the operation and maintenance personnel to give priority to dealing with high-risk scenarios. The acoustic-optic combined alarm enhances the warning recognition through the visual and auditory dual channels, avoids the problem that a single warning mode may be covered by environmental factors, and improves the risk handling efficiency under complex working conditions in the industrial field.
[0154] In some of the above solutions of the present application, the acquisition unit constructs an industrial network topology model through modeling device nodes and communication links, the configuration unit sets the perturbation scenario model, the processing unit conducts perturbation simulations and records topological changes, the analysis unit outputs a robustness score using a graph neural network, the evaluation unit calculates the robustness evaluation index, and the identification unit generates optimization suggestions. However, there is a lack of the ability to dynamically model the evolution process of the topological structure under multi-type perturbation scenarios, making it difficult to reflect the actual dynamic impact of perturbations on system connectivity and service reachability, resulting in strong subjectivity in the evaluation results, being unable to identify key structural units, and being difficult to output targeted optimization suggestions.
[0155] In the above embodiments, by constructing a network topology model that maps the industrial system structure, devices such as PLCs, SCADA systems, sensors, and edge controllers are abstracted as nodes, and communication links such as Ethernet, PROFINET, and Modbus are modeled as edges, thus achieving a unified representation of the physical structure and logical connections of the industrial network. Multiple types of perturbation scenarios such as node failures, link degradations, and network attacks are introduced, and propagation parameters are set to dynamically model the perturbation process. Combining with a graph neural network model, deep learning is performed on the topological evolution characteristics before and after the perturbation, and a quantifiable robustness score value R-score is output. Further, based on the simulation results, multi-dimensional robustness indicators (including network connectivity retention rate, service interruption ratio, path delay growth multiple, and recovery path hop count) are calculated to achieve a quantitative evaluation of the dynamic adaptability of the topological structure under multiple perturbation scenarios. According to the analysis results of the indicators, key structural weaknesses are automatically identified, and targeted optimization suggestions such as redundant configuration, master control deployment optimization, and path reconstruction are proposed, making up for the deficiencies in the existing technology of insufficient support for dynamic perturbation, structural evolution, intelligent evaluation, and optimization closed-loop, and improving the structural robustness, security controllability, and adaptive adjustment ability of the industrial network in the face of complex operating environments and potential threats.
[0156] In another preferred embodiment based on the above embodiments, refer to Figure 2 As shown, this embodiment provides an industrial network topology structure security and robustness simulation analysis system for applying the industrial network topology structure security and robustness simulation analysis method, including:
[0157] An acquisition unit, configured to acquire each device node and communication link in the industrial network, model each device node as a node, model the communication link as an edge, and construct an industrial network topology model according to all nodes and edges. The nodes include PLCs, SCADA systems, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus.
[0158] A configuration unit, configured to set a perturbation scenario model. The perturbation scenario model includes node random failure perturbation, network attack perturbation, and link degradation perturbation. The perturbation scenario model has propagation parameters, and the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function.
[0159] A processing unit, configured to perform perturbation simulation on the industrial network topology model in a simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs.
[0160] An analysis unit, configured to perform feature learning and embedding on the network topology graph before and after the perturbation by using a graph neural network model, and output a robustness score value R-score corresponding to the perturbation scenario.
[0161] An evaluation unit, configured to calculate a robustness evaluation index based on simulation data, where the robustness evaluation index includes a network connectivity retention rate, a service interruption ratio, a routing path delay growth multiple, and an average path hop count for fault recovery.
[0162] An identification unit, configured to output a weakness identification result and optimization suggestions for the topological structure according to the robustness evaluation index, where the optimization suggestions include critical node redundancy configuration, master controller deployment optimization, link redundancy construction, and communication path re-planning.
[0163] It can be understood that by constructing a network topology model that maps the industrial system structure, devices such as PLCs, SCADA, sensors, and edge controllers are abstracted as nodes, and communication links such as Ethernet, PROFINET, and Modbus are modeled as edges, thereby realizing a unified representation of the physical structure and logical connections of the industrial network. Multiple types of perturbation scenarios such as node failures, link degradations, and network attacks are introduced, and propagation parameters are set to dynamically model the perturbation process. Combining with a graph neural network model, deep learning is performed on the topological evolution characteristics before and after the perturbation, and a quantifiable robustness score value R-score is output. Further, based on the simulation results, multi-dimensional robustness indicators (including network connectivity retention rate, service interruption ratio, path delay growth multiple, recovery path hop count) are calculated to realize a quantitative evaluation of the dynamic adaptation ability of the topological structure under multiple perturbation situations. According to the index analysis results, key structural weaknesses are automatically identified, and targeted optimization suggestions such as redundancy configuration, master controller deployment optimization, and path reconstruction are proposed, which make up for the deficiencies in the prior art of insufficient support for dynamic perturbations, structural evolution, intelligent evaluation, and optimization closed-loop, and improve the structural robustness, security controllability, and adaptive adjustment ability of the industrial network in the face of complex operating environments and potential threats.
[0164] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0165] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, as well as the combination of flows and / or blocks in the flowchart and / or block diagram. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0166] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0167] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0168] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific embodiments of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.
Claims
1. A method for simulating and analyzing the security and robustness of an industrial network topology structure, characterized in that Including: Model each device node in the industrial network as a node, model the communication link between devices as an edge, and construct an industrial network topology model according to all the nodes and edges. The nodes include PLC, SCADA, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus; Set a perturbation scenario model, which includes node random failure perturbation, network attack perturbation, and link degradation perturbation; the perturbation scenario model has propagation parameters, and the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function; Perform perturbation simulation on the industrial network topology model in the simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs; Use a graph neural network model to perform feature learning and embedding on the network topology graph before and after the perturbation, and output the robustness score value R-score corresponding to the perturbation scenario; Calculate the robustness evaluation index based on the simulation data, and the robustness evaluation index includes network connectivity retention rate, service interruption ratio, routing path delay growth multiple, and average path hop count for fault recovery; Output the weak point identification result and optimization suggestions of the topological structure according to the robustness evaluation index, and the optimization suggestions include critical node redundancy configuration, master controller deployment optimization, link redundancy construction, and communication path re-planning.
2. The method for simulating and analyzing the security and robustness of the industrial network topology structure according to claim 1, wherein The network attack perturbation in the perturbation scenario includes: distributed denial of service attack, man-in-the-middle attack, routing spoofing attack, or command injection attack.
3. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 1, wherein, The attack preference function is jointly determined by the network centrality and business importance of the node, and satisfies the following form: P = α·C + β·D, where P is the attack preference function, C represents the network centrality of the node, D represents the business importance, α and β are weight parameters, and α + β = 1.
4. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 1, wherein When using a graph neural network model to perform feature learning and embedding on the network topology graph before and after the perturbation and output the robustness score value R-score corresponding to the perturbation scenario, the graph neural network model includes: A graph convolutional layer for extracting structural features of the nodes and their adjacency relationships in the industrial network topology model; A perturbation embedding layer for encoding the perturbation information of each node in the perturbation scenario model into a perturbation feature matrix, and inputting the perturbation feature matrix and the node static attributes into the graph neural network together; A node state time difference encoding layer for calculating the difference between the state vectors of the same node before and after the perturbation and using it as a dynamic input; A graph-level representation aggregation layer for performing a pooling operation on all node embedding representations to generate an overall graph embedding; A robustness score output layer for outputting the robustness score value R-score corresponding to the perturbation scenario according to the overall graph embedding.
5. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 4, wherein The perturbation embedding layer constructs perturbation channel features based on the perturbation feature matrix. The perturbation feature matrix is used to represent the perturbation type, propagation level, node criticality, and whether it is directly perturbed of each node in the perturbation scenario, and is spliced with the node static feature channel through the perturbation channel and input into the graph convolutional layer.
6. The simulation analysis method for the security and robustness of the industrial network topology structure according to claim 5, characterized in that, When calculating the robustness evaluation index based on the simulation data, it also includes: Obtain the comprehensive robustness score based on the multi-objective weighting function; The comprehensive robustness score is obtained by calculating the following formula: R = w1·CRR + w2·(1 - SIR) + w3·(1 / DIF) + w4·(1 / ARH); Wherein, w1, w2, w3, and w4 are positive weight coefficients, R represents the comprehensive robustness score, CRR represents the network connectivity retention rate, SIR represents the service interruption ratio, DIF represents the routing path delay growth multiple, and ARH represents the average path hop count for fault recovery.
7. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 6, characterized in that, When outputting the weak point identification result and optimization suggestion of the topological structure according to the robustness evaluation index, it includes: When there is a high sensitivity to single-point failure, a core node for perturbation propagation, or a dynamic embedding of a graph neural network, it is determined that the weak point identification result is the existence of high-risk nodes, and the output optimization suggestion is the redundant configuration of key nodes; When there is an increase in delay caused by path transfer, a high link bandwidth utilization rate, or an increase in the number of hops for recovery after link failure, it is determined that the weak point identification result is the existence of a performance bottleneck link, and the output optimization suggestion is the construction of link redundancy; When there is a node with a high degree centrality, a high betweenness centrality, or a high structural dependence, it is determined that the weak point identification result is the existence of a node with an excessive centrality, and the output optimization suggestion is the optimization of the master controller deployment; When the average path hop count is large, the fault recovery path is long, or the physical coverage of the link is not optimal, it is determined that the weak point identification result is the existence of an excessive delay hop count, and the output optimization suggestion is the re-planning of the communication path.
8. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 7, characterized in that After outputting the weak point identification result and optimization suggestion of the topological structure according to the robustness evaluation index, it further includes: Collect the weak point identification results and optimization suggestions of several simulations, obtain the corresponding comprehensive robustness scores, compare the comprehensive robustness scores with the lowest threshold of the comprehensive robustness score respectively, and judge whether to perform acoustic and optical warnings according to the comparison results; When all the comprehensive robustness scores are less than or equal to the lowest threshold of the comprehensive robustness score, it is determined to perform acoustic and optical warnings; When there is a comprehensive robustness score greater than the lowest threshold of the comprehensive robustness score, it is determined not to perform acoustic and optical warnings.
9. The method for simulating and analyzing the security and robustness of an industrial network topology structure according to claim 8, wherein When all the comprehensive robustness scores are less than or equal to the lowest threshold of the comprehensive robustness score and acoustic and optical warnings are performed, it includes: Obtain the score difference according to the comprehensive robustness score and the lowest threshold of the comprehensive robustness score. The score difference is the absolute value of the difference between the comprehensive robustness score and the lowest threshold of the comprehensive robustness score. Determine the warning level according to the score difference, and perform acoustic and optical warnings according to the warning level; the warning level is in a proportional relationship with the score difference.
10. An industrial network topology security and robustness simulation analysis system, which is used to apply the industrial network topology security and robustness simulation analysis method according to any one of claims 1-9, and is characterized in that, It includes: A collection unit, configured to collect each device node and communication link in the industrial network, model each device node as a node, model the communication link as an edge, and construct an industrial network topology model according to all the nodes and edges. The nodes include PLC, SCADA, sensors, and edge controllers, and the edges include Ethernet, PROFINET, and Modbus; A configuration unit, configured to set a perturbation scenario model, where the perturbation scenario model includes node random failure perturbation, network attack perturbation, and link degradation perturbation; The perturbation scenario model has propagation parameters, where the propagation parameters include perturbation duration, propagation probability, influence radius, and attack preference function; A processing unit, configured to perform perturbation simulation on the industrial network topology model in a simulation environment according to the perturbation scenario model, and record the topological structure change process and its connectivity evolution information after the perturbation occurs; An analysis unit, configured to perform feature learning and embedding on the network topology graph before and after the perturbation by using a graph neural network model, and output a robustness score value R-score corresponding to the perturbation scenario; An evaluation unit, configured to calculate robustness evaluation indicators based on simulation data, where the robustness evaluation indicators include network connectivity retention rate, service interruption ratio, routing path delay growth multiple, and average path hop count for fault recovery; An identification unit, configured to output a weak point identification result and optimization suggestions for the topological structure according to the robustness evaluation indicators, where the optimization suggestions include critical node redundancy configuration, master controller deployment optimization, link redundancy construction, and communication path re-planning.
Citation Information
Patent Citations
Complex supply network robust performance analyzing method based on topological structure
CN103870642A
Industrial control network dynamic threat path and weakness discovery method
CN119210885A
Data security assessment method and system based on application scene
CN119293782A
Network security evaluation system and method based on dynamic attack and defense game model
CN119544307A
Visual analysis method for robustness of graph neural network
CN120068927A
Cited By
Industrial control network security effectiveness verification method
CN121077938A
Adaptive network defense and topology reconstruction system based on attack feature learning
CN121396603A
Communication network operation robustness evaluation method and device
CN121486204A
Optimized communication network health degree prediction and collaboration method
CN121664677A