Common-mode fault modeling method for over-control protection system of chemical device under network attack
By constructing a simulation model of the over-control protection system of chemical equipment, analyzing the risk evolution under network attacks, the problem of failure to effectively analyze component coupling characteristics and common-mode failures in the existing technology is solved, and identification and effective defense of potential weak links are achieved.
Patent Information
- Application Number
- CN202510638769.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-08-08
AI Technical Summary
The prior art fails to effectively consider the component coupling characteristics and common-mode failure of chemical device over-control protection systems under network attacks, and lacks analysis methods for network attacks, resulting in high security risks.
Build a simulation model of the over-control protection system of chemical equipment, consider control logic, signal interaction and component coupling, simulate system response in different attack scenarios, analyze risk evolution mechanism, and formulate effective security strategies.
Through simulation models, accurately reflect the coupling characteristics of components, identify potential weak links, provide effective defense strategies, and reduce the risk of common-mode failure caused by cyber attacks.
Smart Images

Figure BDA0005407455890000021 
Figure BDA0005407455890000022 
Figure BDA0005407455890000031
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of chemical industry security, and in particular relates to a common mode fault modeling method for an overcontrol protection system of a chemical plant under network attacks. Background Art
[0002] With the continuous integration of next-generation information technology (IT), such as the Industrial Internet and artificial intelligence, and operational technology (OT), industrial process control and operations are becoming increasingly reliant on digital systems. Chemical plant process control and protection systems (PCPS) are gradually shifting from closed, isolated systems to open, interconnected systems, forming more digital and intelligent industrial cyber-physical systems (ICPS). These systems, such as sensors, controllers, and actuators, interconnect through communication networks, enabling the implementation of new operational methods such as remote operation and remote monitoring. These systems offer advantages such as high flexibility, simple installation, and ease of operation. However, while the introduction of network communications improves production efficiency, it also presents new security risks and challenges.
[0003] PCPSs bridge information systems and process systems, enabling basic process control and functional safety through specific communication technologies and protocols. These systems possess extensive dependencies and unique vulnerabilities, making them potential targets for cyberattacks. Unlike traditional information security (IS), the petrochemical industry's heavy reliance on communications and automated control systems, coupled with the inherent flammability, explosiveness, and toxicity of its production objects, poses a higher risk of cyber threats to process systems. Any cyber threat to process systems could potentially lead to unprecedented, large-scale failures, further damaging personnel, assets, and the environment, and even triggering serious consequences for national strategic security. Therefore, it is crucial to study the operation of over-the-counter protection systems under these new security risks.
[0004] Existing technologies for studying process control and protection system failures fail to consider the interdependencies between components at the subsystem level and under-consider cyberattacks, particularly the lack of analytical methods for attack-induced common-mode failures. Therefore, it is necessary to consider the potential cyberattack threats facing coupled systems during digital transformation and establish a system failure simulation model to simulate the development of common-mode failures in process systems under different cyberattack scenarios. This can help assess the impact of attack threats on system operations and provide optimal security deployment strategies for the system. Summary of the Invention
[0005] The purpose of the present invention is to address the above-mentioned problems and thus provide a scientific, reasonable and practical common-mode fault modeling method for the overcontrol protection system of a chemical plant under network attacks. Different module components are used to construct a simulation model that can accurately reflect the coupling characteristics of PCPS components, and by adjusting the model signal to simulate the system response under different attack scenarios, analyze the risk evolution mechanism of the overcontrol protection system under attack, and formulate an effective security defense strategy.
[0006] The technical solution of the present invention to solve the above technical problems is as follows:
[0007] A common mode fault modeling method for the overcontrol protection system of a chemical plant under network attack. The specific simulation steps are as follows:
[0008] S1. Simulation model construction. Comprehensively considering the control logic, signal interaction, and component coupling, a component modular modeling approach was used to construct the simulation model. Control logic encompasses the logical functions of the PLC controller. Signal interaction encompasses not only the interaction between the information layer and the operating system, but also the communication between the basic process control system and the safety instrumented system. Component coupling encompasses the interconnection between sensors, controllers, and actuators.
[0009] S2. Attack Scenario Simulation and Response. We establish attack expressions based on the risk evolution mechanism of the over-control protection system under attack. We then adjust the model signal to simulate different attack scenarios. This results in system responses under different types of attacks, further assessing system security and identifying potential weaknesses, providing a basis for developing effective defense strategies.
[0010] Preferably, the step S1 specifically includes:
[0011] S11. Delineate the target area. The chemical plant over-control protection system is subdivided into the information system (chemical plant network), the operating system (basic process control system, safety instrument system), and the production system (valves, reaction equipment). The production system is controlled by the operating system, and communication is completed by the information system. This provides a path for attackers to remotely tamper with the operating system and further affect the production system.
[0012] S12. System dynamic modeling. Based on the actual production process and the principle of chemical production process equilibrium, the dynamic relationship between state parameters and independent variables is derived under certain assumptions to obtain the system differential equation. Among them, the conservation relationship of parameter I is expressed as:
[0013]
[0014] Where, parameter I can be mass, energy, V i represents the rate of entry into system I, V e represents the rate of leaving system I.
[0015] S13. Model implementation and optimization. Based on the simulation results, evaluate the model's response to variable changes, adjust and optimize the model and its modules to ensure that the simulation model accurately reflects the operation of the actual system.
[0016] Preferably, the step S2 specifically includes:
[0017] The signal actually received by the system at time t under a general form of network attack can be expressed as:
[0018]
[0019] Where s i (t) represents the initial setting value of the system at time t, T represents the duration of the attack, a i (t) is the data manipulated by the attack.
[0020] According to the attack mechanism, the attack types are divided into three categories: signal shutdown attack, set value change attack and function reprogramming attack. Combined with the risk evolution mechanism of the over-control protection system under different attack scenarios, the attack manipulation data a are defined respectively. i (t) expression.
[0021] In a signal shutdown attack, the attacker interferes with the basic process control system communication link, preventing the controllers and actuators in the control system from receiving the latest signals, thus affecting the availability of the control system. i (t s ) represents the last signal received by the system before the attack begins, and its expression is:
[0022] a i (t) = s i (t s )=αs i (t) (3)
[0023] Where α represents the multiplication factor of the system signal change under attack.
[0024] In a setpoint change attack, the attacker obtains the device's key based on the basic process control system communication link and arbitrarily tampered with the real signal of the sensor or controller. The attack is completed by maliciously modifying the hidden value, causing the control system to execute incorrect instructions under the false signal, thereby compromising the system integrity. Its expression is:
[0025] a i (t) = s i (t)+βt (4)
[0026] Where β represents the additive factor of system change under attack.
[0027] In a functional reprogramming attack, the normal program of the PLC system is modified through the safety instrument system communication link, causing it to execute the logic preset by the attacker. Even if the system encounters an emergency, the safety interlock system will not operate and the emergency shut-off valve will remain open, threatening the safety of the system. The expression is:
[0028] a i (t)=1 (5)
[0029] Where, 1 indicates the emergency shut-off valve is open, and 0 indicates the emergency shut-off valve is closed.
[0030] This invention provides a common-mode fault modeling method for the overcontrol protection system of a chemical plant under cyberattacks. Compared with the existing technology, it has the following advantages:
[0031] The present invention constructs a PCPS system simulation model based on the Simulink platform. Combining the risk evolution mechanism of the overcontrol protection system under attack, the paper models various network abnormal conditions, such as signal shutdown attack, set value change attack, and function reprogramming attack. This method can analytically show the impact on the liquid level control loop and the temperature control loop, and demonstrates the risk of common-mode failure caused by communication coupling, thereby providing an effective security deployment strategy for the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.
[0033] Figure 1 This is a flowchart for modeling common mode faults of over-control protection systems in chemical plants under cyber attacks;
[0034] Figure 2 It is a schematic diagram of the over-control protection system of the continuous stirred tank reactor and heater;
[0035] Figure 3 is the response curve of the liquid level control loop of the continuous stirred tank reactor and heater;
[0036] Figure 4 is the temperature control loop response curve of the continuous stirred tank reactor and heater. DETAILED DESCRIPTION
[0037] The following will clearly and completely describe the technical solution of the present invention in conjunction with the embodiments and drawings of the present invention. Obviously, the present invention can be implemented in many other ways than those described herein, and those skilled in the art can make similar improvements without violating the connotation of the present invention, which are all within the scope of protection of the present invention.
[0038] like Figure 1 As shown, the specific implementation steps of the common mode fault modeling method of the overcontrol protection system of a chemical device under network attack provided by the embodiment of the present invention are as follows:
[0039] S1. Simulation model construction. Comprehensively considering the control logic, signal interaction, and component coupling, a component modular modeling approach was used to construct the simulation model. Control logic encompasses the logical functions of the PLC controller. Signal interaction encompasses not only the interaction between the information layer and the operating system, but also the communication between the basic process control system and the safety instrumented system. Component coupling encompasses the interconnection between sensors, controllers, and actuators.
[0040] S2. Attack Scenario Simulation and Response. We establish attack expressions based on the risk evolution mechanism of the over-control protection system under attack. We then adjust the model signal to simulate different attack scenarios. This results in system responses under different types of attacks, further assessing system security and identifying potential weaknesses, providing a basis for developing effective defense strategies.
[0041] by Figure 2 The modeling method of the present invention is further explained in detail using the over-control protection system for a continuous stirred tank reactor and heater as an example. This system comprises a temperature control loop and a liquid level control loop. Each loop consists of a sensor, a controller, and a regulating valve, communicating via a network to ensure proper operation. The detailed steps for constructing a simulation model for the over-control protection system for a continuous stirred tank reactor and heater are as follows.
[0042] S11. Define the target area. The over-control protection system of the stirred tank reactor and heater is subdivided into the information system (network), the operating system (basic process control system, safety instrument system) and the production system (valves, reaction devices). The basic process control system BPCS adjusts the opening of the control valve V3 according to the signal of the temperature sensor TT01 to effectively balance the heat released by the exothermic reaction in the reactor; while the liquid level control loop adjusts the inlet flow through the control valve V1 according to the signal of the liquid level sensor LT01 to keep the liquid level within the set range. In addition, a safety instrument system SIS is set up. When the liquid level sensor LT02 detects that the liquid level exceeds the interlock threshold, the emergency shut-off valve SDV cuts off the feed.
[0043] S12. System dynamic modeling. Based on the principle of chemical production process equilibrium and actual production processes, the dynamic relationship between state parameters and independent variables is derived under certain assumptions to obtain the system differential equations. Furthermore, in addition to considering the interconnectivity between components such as sensors, controllers, and actuators, it is also necessary to consider the communication between the basic process control system and the safety instrument system. A component modular modeling approach is then used to construct the simulation model.
[0044] Assuming that the reactor is uniform from top to bottom and ignoring the evaporation of liquid, the change in liquid level and the inlet and outlet flow rates satisfy the mass balance equation. Therefore, the differential equation describing the system liquid level is established based on the mass balance law:
[0045]
[0046] Assuming that the temperature in the reactor is equal everywhere, ignoring the influence of temperature on the density and mass heat capacity of the fluid, and applying the law of conservation of energy to the reactor and the cooling jacket, the differential equation describing the system temperature can be established as:
[0047]
[0048] In the formula, the meaning of each parameter and its specific value are shown in Table 1.
[0049] Table 1 Parameter meanings and specific values
[0050]
[0051] S13. Model implementation and optimization. Based on the simulation results, evaluate the model's response to variable changes, adjust and optimize the model and its modules to ensure that the simulation model accurately reflects the operation of the actual system.
[0052] Secondly, by adding ramp signal modules, step signal modules and their combination, we simulate Denial-of-Service (DoS) attacks, Deception (DCA) attacks and Control Logic Injection (CLI) attacks respectively, and obtain the system response under normal operation and different types of attacks, such as Figure 3 、 Figure 4 shown.
[0053] Figure 3 This is a comparison chart of the response of the liquid level control loop of the continuous stirred tank reactor and heater under normal operation and denial of service attack, spoofing attack and logic injection attack scenarios. Figure 4This chart compares the responses of the temperature control loops of a continuous stirred tank reactor and heater under normal operation, denial of service attacks, and spoofing attacks. Simulation results show that for a level control loop with dual defense layers of a basic process control system and a safety instrumented system, logic injection attacks can impact multiple defense layers and induce common-mode failures, significantly impacting the system. However, single denial of service and spoofing attacks have limited impact on the system's liquid level. Therefore, isolation measures should be established between defense layers to effectively mitigate the potential impact of coupling on process safety. For temperature control loops, denial of service attacks do not always result in overheating; the severity of the impact is determined by the duration of the attack and the last control signal state received by the system before the attack. In contrast, the system's response to spoofing attacks is more sensitive, and preventing these attacks should be a priority in temperature control loop security strategies.
[0054] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features therein can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A common mode fault modeling method for an overcontrol protection system of a chemical plant under a network attack, characterized in that: The steps include: S1. Simulation model construction. Comprehensively considering the control logic, signal interaction, and component coupling, a component modular modeling approach was used to construct the simulation model. Control logic encompasses the logical functions of the PLC controller. Signal interaction encompasses not only the interaction between the information layer and the operating system, but also the communication between the basic process control system and the safety instrumented system. Component coupling encompasses the interconnection between sensors, controllers, and actuators. S2. Attack Scenario Simulation and Response. We establish attack expressions based on the risk evolution mechanism of the over-control protection system under attack. We then adjust the model signal to simulate different attack scenarios. This results in system responses under different types of attacks, further assessing system security and identifying potential weaknesses, providing a basis for developing effective defense strategies.
2. The common mode fault modeling method for an overcontrol protection system of a chemical plant under a network attack according to claim 1 is characterized in that: The construction of the simulation model in step S1 includes: Assume that the container is uniform from top to bottom and ignore the evaporation of the liquid in the container; assume that the temperature in the container is equal everywhere and ignore the influence of temperature on the density and mass heat capacity of the fluid. The conservation relationship of the parameter I is expressed as: Where, parameter I can be mass, energy, V i represents the rate of entry into system I, V e represents the rate of leaving system I.
3. The common mode fault modeling method for an overcontrol protection system of a chemical plant under a network attack according to claim 1 is characterized in that: Step S2: attack scenario simulation and response, including: According to the attack mechanism, the attacks are divided into three categories: signal shutdown attack, set value change attack and function reprogramming attack. Combined with the risk evolution mechanism of the over-control protection system under different attack scenarios, the attack manipulation data a are defined respectively. i (t) expression. In a signal shutdown attack, the attacker interferes with the basic control system communication link, preventing the controllers and actuators in the control system from receiving the latest signals, thus affecting the availability of the control system. i (t s ) represents the last signal received by the system before the attack begins, and its expression is: a i (t)=s i (t s )=αs i (t) Where α represents the multiplication factor of the system signal change under attack. In a setpoint change attack, the attacker obtains the device's key based on the basic process control system communication link and arbitrarily tampered with the real signal of the sensor or controller. The attack is completed by maliciously modifying the hidden value, causing the control system to execute incorrect instructions under the false signal, thereby compromising the system integrity. Its expression is: a i (t)=s i (t)+βt Where β represents the additive factor of system change under attack. In a functional reprogramming attack, the normal program of the PLC system is modified through the safety instrument system communication link, causing it to execute the attacker's preset logic. Even if the system encounters an emergency, the safety interlock system will not operate and the emergency shut-off valve will remain open, threatening the safety of the system. The expression is: a i (t)=1。