Network attack identification method, device and equipment of oil and gas pipe network industrial control system and medium
By collecting and analyzing the flow fluctuations and connection request data of the oil and gas pipeline industrial control system, combining similarity analysis, data packet information is deeply analyzed, and the lack of identification of unknown or complex network attacks in the existing technology is solved, and comprehensive security monitoring and real-time identification of the oil and gas pipeline industrial control system is achieved.
Patent Information
- Application Number
- CN202510707896.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-08-08
AI Technical Summary
The existing oil and gas pipeline security monitoring methods mainly focus on the single detection of equipment and communication links, lack in-depth analysis of network behavior and traffic characteristics, and cannot effectively identify unknown or complex network attacks, especially at network characteristics such as traffic fluctuations and abnormal connection requests.
By collecting network transmission data of the industrial control system of the oil and gas pipeline network, including flow fluctuation data and connection request data, calculating the number of flow fluctuations and differences, building a connection request sequence, combining the similarity analysis of the historical request sequence, deeply analyzing the data packet information, marking the attack type and triggering warnings.
It realizes comprehensive monitoring and real-time identification of the network security of the oil and gas pipeline industrial control system, can identify traffic abnormalities and changes in connection request patterns, improves the ability to identify unknown or complex attacks, and reduces potential losses.
Smart Images

Figure CN120455123A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transmission technology, and in particular to a network attack identification method, device, equipment and medium for an oil and gas pipeline network industrial control system. Background Art
[0002] With the rapid development of information technology, digitalization and intelligentization have become key trends in modern oil and gas pipeline network operations. As core infrastructure for energy transmission and distribution, oil and gas pipeline networks bear the heavy responsibility of transporting oil, natural gas, and other critical resources. Their stability and security are directly related to the security of a nation's energy supply, sustainable economic development, and the public's quality of life. Oil and gas pipeline networks often rely on complex automated control systems, real-time data acquisition systems, and communication networks. This exposes them to a range of cybersecurity risks, including distributed denial of service (DDoS) attacks, data tampering, and unauthorized intrusions. In oil and gas pipeline networks, certain attacks can not only damage equipment and disrupt production, but can also trigger environmental disasters. Therefore, real-time network security monitoring and early warning are crucial. Therefore, ensuring network security and preventing external cyberattacks from compromising control systems, data flows, and monitoring facilities is a critical task in modern oil and gas pipeline network management.
[0003] With the continuous escalation of cyberattack methods, traditional oil and gas pipeline network security protection methods are no longer able to effectively address new cyber threats. Currently, the security protection of oil and gas pipeline networks mainly relies on traditional firewalls, intrusion detection and prevention systems (IDS / IPS), data encryption, and other security measures for key equipment and network links. However, these traditional protection measures generally focus on preventing direct intrusion from external attacks and fail to effectively identify potential attack behaviors, especially attacks at the level of network characteristics such as traffic fluctuations and abnormal connection requests. Therefore, how to combine multi-dimensional data such as network traffic, connection requests, and packet information in a complex and changing network environment to monitor and accurately identify network attack behaviors in real time has become a research hotspot in the current field of oil and gas pipeline network network security.
[0004] Furthermore, existing oil and gas pipeline network security monitoring and defense methods often focus on single-dimensional detection of equipment and communication links, lacking in-depth analysis of network behavior and traffic characteristics. Traditional attack detection methods often rely on static rules and known attack patterns, often failing to promptly detect and provide early warnings for unknown or complex attacks. Furthermore, existing technologies mostly focus on anomaly detection in a single dimension (such as traffic flow or ports), lacking the comprehensive analysis and dynamic judgment capabilities based on multi-dimensional data, and are unable to fully address diverse and complex network attack scenarios. Summary of the Invention
[0005] The present invention provides a network attack identification method, device, equipment and medium for an oil and gas pipeline network industrial control system, so as to realize comprehensive monitoring and real-time identification of network security of the oil and gas pipeline network industrial control system.
[0006] According to one aspect of the present invention, a method for identifying network attacks in an oil and gas pipeline network industrial control system is provided, comprising:
[0007] Collecting network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data;
[0008] Calculating the number of flow fluctuations and the difference in flow fluctuations per unit time based on the flow fluctuation data, and preliminarily determining whether the oil and gas pipeline network industrial control system is subject to a network attack based on the number of flow fluctuations and the difference in flow fluctuations;
[0009] If a preliminary determination is made that the oil and gas pipeline network industrial control system is under a network attack, constructing a connection request sequence corresponding to the connection request data based on the connection request data and a preset acquisition time sequence;
[0010] Determining the similarity between the connection request sequence and the historical request sequence, and determining again whether the oil and gas pipeline network industrial control system is subject to a network attack based on the similarity;
[0011] If the result of the second determination is that the oil and gas pipeline network industrial control system is under a network attack, the data packet information corresponding to the network transmission data is extracted, the data packet information is parsed, the attack type is marked and a warning is triggered.
[0012] According to another aspect of the present invention, a method for identifying network attacks in an oil and gas pipeline network industrial control system is provided, comprising:
[0013] Collecting network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data;
[0014] Calculating the number of flow fluctuations and the difference in flow fluctuations per unit time based on the flow fluctuation data, and preliminarily determining whether the oil and gas pipeline network industrial control system is subject to a network attack based on the number of flow fluctuations and the difference in flow fluctuations;
[0015] If a preliminary determination is made that the oil and gas pipeline network industrial control system is under a network attack, constructing a connection request sequence corresponding to the connection request data based on the connection request data and a preset acquisition time sequence;
[0016] Determining the similarity between the connection request sequence and the historical request sequence, and determining again whether the oil and gas pipeline network industrial control system is subject to a network attack based on the similarity;
[0017] If the result of the second determination is that the oil and gas pipeline network industrial control system is under a network attack, the data packet information corresponding to the network transmission data is extracted, the data packet information is parsed, the attack type is marked and a warning is triggered.
[0018] According to another aspect of the present invention, an electronic device is provided, comprising:
[0019] at least one processor;
[0020] and a memory communicatively connected to the at least one processor; wherein,
[0021] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network attack identification method for the oil and gas pipeline industrial control system described in any embodiment of the present invention.
[0022] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network attack identification method for the oil and gas pipeline industrial control system described in any embodiment of the present invention when executed.
[0023] The technical solution of the embodiment of the present invention is to collect network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data; calculate the number of flow fluctuations and the flow fluctuation difference per unit time according to the flow fluctuation data, and preliminarily judge whether the oil and gas pipeline network industrial control system is subject to a network attack according to the number of flow fluctuations and the flow fluctuation difference; when the preliminary judgment result is whether the oil and gas pipeline network industrial control system is subject to a network attack, construct a connection request sequence corresponding to the connection request data according to the connection request data and a preset collection time series; determine the similarity between the connection request sequence and the historical request sequence, and judge again whether the oil and gas pipeline network industrial control system is subject to a network attack according to the similarity; if the result of the second judgment is whether the oil and gas pipeline network industrial control system is subject to a network attack, extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type and trigger a warning. By combining multi-dimensional data, this technical solution can not only identify traffic anomalies, but also identify potential attack behaviors through changes in connection request patterns. It solves the problem that existing security monitoring methods mainly focus on single-dimensional detection, lack comprehensive multi-dimensional analysis, and cannot effectively identify unknown or complex attacks. It realizes comprehensive monitoring and real-time identification of network security of oil and gas pipeline industrial control systems.
[0024] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0026] Figure 1 A flowchart of a method for identifying network attacks on an oil and gas pipeline network industrial control system provided by an embodiment of the present invention;
[0027] Figure 2 A flowchart of another method for identifying network attacks on an oil and gas pipeline network industrial control system provided by an embodiment of the present invention;
[0028] Figure 3 A schematic structural diagram of a network attack identification device for an oil and gas pipeline network industrial control system provided by an embodiment of the present invention;
[0029] Figure 4 A schematic diagram of the structure of an electronic device for implementing the network attack identification method of the oil and gas pipeline network industrial control system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0030] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0032] Figure 1 A flowchart of a network attack identification method for an oil and gas pipeline industrial control system provided in an embodiment of the present invention is applicable to situations where network attacks are monitored and identified on an oil and gas pipeline industrial control system. The method can be executed by a network attack identification device for an oil and gas pipeline industrial control system. The device can be implemented in the form of hardware and / or software. The device can be configured in a server, and the server can be a network security server for monitoring and identification.
[0033] like Figure 1 As shown, the method specifically includes the following steps:
[0034] S110. Collect network transmission data corresponding to the oil and gas pipeline network industrial control system.
[0035] Among them, network transmission data includes traffic fluctuation data and connection request data.
[0036] It's understandable that in network security monitoring of oil and gas pipeline industrial control systems, network transmission data is collected to monitor system operating status in real time and identify potential threats. This data allows real-time monitoring of system operating status, rapid detection and response to potential threats, and ensures the safe and stable operation of industrial control systems.
[0037] Traffic fluctuation data refers to the dynamic changes in network communication traffic within industrial control systems, including changes over time in metrics such as packet transmission rate, bandwidth utilization, and data transmission volume. Connection request data refers to records of requests to establish network connections between devices or systems within industrial control systems, including information such as the source IP address, destination IP address, port number, protocol type, and request time.
[0038] In some embodiments, the collection of flow fluctuation data corresponding to the oil and gas pipeline network industrial control system includes: deploying flow monitoring equipment in the oil and gas pipeline network industrial control system to collect the flow fluctuation data of the oil and gas pipeline network industrial control system in real time; eliminating noise and invalid data in the flow fluctuation data, and formatting the flow fluctuation data according to unit time intervals to obtain the flow fluctuation data.
[0039] Specifically, flow monitoring devices or sensors can be deployed within the oil and gas pipeline network's industrial control system to collect real-time flow fluctuation data. This data is then filtered to remove noise and invalid data that may be generated during transmission, ensuring that the collected data reflects only actual flow fluctuations without interference from environmental factors or equipment failures, thereby improving data accuracy. Finally, valid flow fluctuation data is formatted according to unit time intervals to ensure that subsequent analysis and processing of the data follows a consistent time scale.
[0040] S120. Calculate the number of flow fluctuations and the flow fluctuation difference per unit time based on the flow fluctuation data, and preliminarily determine whether the oil and gas pipeline network industrial control system is under a network attack based on the number of flow fluctuations and the flow fluctuation difference.
[0041] Specifically, based on the collected flow fluctuation data, the number of flow fluctuations and the difference in flow fluctuations per unit time, such as per minute or per hour, can be calculated. This calculated number of flow fluctuations and difference in flow fluctuations can then be used to make a preliminary assessment of whether the oil and gas pipeline network's industrial control system has been compromised by a cyberattack.
[0042] In some embodiments, the calculation of the number of flow fluctuations and the flow fluctuation difference per unit time based on the flow fluctuation data includes: counting the number of fluctuations corresponding to the flow fluctuation data per unit time; calculating the difference between the maximum flow value and the minimum flow value corresponding to the flow fluctuation data per unit time as the flow fluctuation difference.
[0043] Specifically, the number of changes in flow data within a unit time can be counted. For example, if the flow rate rises, falls, or changes suddenly multiple times within a unit time, each change is counted as a fluctuation. The maximum and minimum flow data values within that unit time are then determined, and the difference between them is calculated. This difference reflects the magnitude of the change in flow rate within that unit time, i.e., the flow fluctuation difference.
[0044] In some embodiments, the preliminary judgment of whether the oil and gas pipeline network industrial control system is under a network attack based on the number of flow fluctuations and the flow fluctuation difference includes: determining whether the number of flow fluctuations is greater than a preset number of fluctuations, and determining whether the flow fluctuation difference is greater than a preset flow fluctuation difference; when the number of flow fluctuations is greater than the preset number of fluctuations and the flow fluctuation difference is greater than the preset flow fluctuation difference, a preliminary judgment of whether the oil and gas pipeline network industrial control system is under a network attack.
[0045] The preset number of fluctuations and the preset flow fluctuation difference may be a preset number of fluctuations and a preset flow fluctuation difference.
[0046] Specifically, the system determines whether the number of flow fluctuations exceeds a preset threshold, and whether the difference in flow fluctuations exceeds a preset threshold. If both the number of flow fluctuations and the difference in flow fluctuations meet these two conditions—that is, both exceed the preset number of fluctuations and the fluctuation difference—then it is preliminarily determined that the oil and gas pipeline network industrial control system may be under a cyber attack. If both the number of flow fluctuations and the fluctuation range are below the preset maximum values, the flow fluctuations are within a normal range, and it is preliminarily determined that the system is not under a cyber attack.
[0047] This has the beneficial effect of comprehensively reflecting abnormal changes in network traffic patterns by setting appropriate thresholds, providing an effective basis for further attack identification. This simple, real-time process is particularly suitable for real-time monitoring of large-scale oil and gas pipeline industrial control systems. It can help quickly identify potential network attacks such as DDoS attacks and data leaks, thereby improving the security protection capabilities of oil and gas pipeline industrial control systems and reducing potential risks and losses to them.
[0048] S130: When a preliminary determination is made that the oil and gas pipeline network industrial control system is under a network attack, a connection request sequence corresponding to the connection request data is constructed according to the connection request data and a preset acquisition time sequence.
[0049] The preset acquisition time sequence refers to a pre-set time sequence, which may include multiple time periods arranged in chronological order. The length of each time period may be the same, but preferably, the lengths of the time periods are different.
[0050] Specifically, when traffic fluctuation characteristics, such as the number of fluctuations and fluctuation differences, are used to initially determine that an oil and gas pipeline network industrial control system may be vulnerable to a cyberattack, a connection request sequence can be constructed by combining the connection request data with a preset acquisition time series to analyze the attack. This can be accomplished by determining the specific connection information of the industrial control computers within each time period based on the connection request data, and then combining the connection information from each time period to create a connection request sequence.
[0051] S140: Determine the similarity between the connection request sequence and the historical request sequence, and determine again whether the oil and gas pipeline network industrial control system is under a network attack based on the similarity.
[0052] The historical request sequence may be a connection request sequence of the industrial computer within a historical time period, and the acquisition method is the same as that of the connection request sequence, except that the historical request sequence is constructed based on the connection request data within the historical time period.
[0053] It's understandable that the historical request sequence reflects the regular changes in the IPC's connection requests in the past, while the connection request sequence reflects the regular changes in connection requests within the current cycle. By comparing the similarities between the two, we can determine the differences between current and historical connection behavior and further analyze whether the system is under attack.
[0054] By constructing this sequence, we can effectively track and identify regular changes in connection requests, thereby determining whether there are any unusual network behaviors. For example, frequent or sudden connection requests within a short period of time are often indicative of a network attack. Compared to simply monitoring traffic flow, connection request sequences provide more detailed information, making the identification of attack behavior more accurate and avoiding the potential misjudgment caused by single-dimensional analysis. Furthermore, this method is applicable to real-time, dynamic network environments, enabling the detection of potential threats in the early stages of an attack. It also provides foundational data for subsequent in-depth analysis and response, enhancing the security protection capabilities of oil and gas pipeline industrial control systems.
[0055] S150: If the result of the second determination is that the oil and gas pipeline network industrial control system is under a network attack, extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type and trigger a warning.
[0056] Specifically, if the attack is detected, the system can extract raw data packets directly related to the attack from previously collected network transmission data. The extracted data packets are then deeply analyzed to identify their protocol structure, payload content, and communication patterns. For example, this can include checking for the presence of malicious code, analyzing the attack target, and identifying the characteristics of the attack tool. Based on the analysis results, the attack is then categorized into specific types, such as intrusion or data theft. Finally, the attack is flagged, a security alert is generated, and security operations personnel are notified to take action.
[0057] For example, if a certain IP address was detected to be making a large number of unusual requests to an oil and gas pipeline network SCADA server within a short period of time, it was initially identified as an attack. After extracting the relevant data packets and analyzing them, it was discovered that the requests contained a payload exploiting a known Modbus protocol vulnerability. The system then flagged the attack as "Industrial Control Protocol Vulnerability Exploitation" and triggered a high-level alert, notifying the operations and maintenance team to take immediate action.
[0058] The technical solution of the embodiment of the present invention is to collect network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data; calculate the number of flow fluctuations and the flow fluctuation difference per unit time according to the flow fluctuation data, and preliminarily judge whether the oil and gas pipeline network industrial control system is subject to a network attack according to the number of flow fluctuations and the flow fluctuation difference; when the preliminary judgment result is whether the oil and gas pipeline network industrial control system is subject to a network attack, construct a connection request sequence corresponding to the connection request data according to the connection request data and a preset collection time series; determine the similarity between the connection request sequence and the historical request sequence, and judge again whether the oil and gas pipeline network industrial control system is subject to a network attack according to the similarity; if the result of the second judgment is whether the oil and gas pipeline network industrial control system is subject to a network attack, extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type and trigger a warning. By combining multi-dimensional data, this technical solution can not only identify traffic anomalies, but also identify potential attack behaviors through changes in connection request patterns. It solves the problem that existing security monitoring methods mainly focus on single-dimensional detection, lack comprehensive multi-dimensional analysis, and cannot effectively identify unknown or complex attacks. It realizes comprehensive monitoring and real-time identification of network security of oil and gas pipeline industrial control systems.
[0059] Figure 2 This is a flowchart of another network attack identification method for an oil and gas pipeline network industrial control system provided by an embodiment of the present invention. The similarity calculation process is further refined on the basis of the above embodiment. Its specific implementation method can be found in the technical solution of this embodiment. Among them, the technical terms that are the same or corresponding to the above embodiment are not repeated here. Figure 2 As shown, the method specifically includes the following steps:
[0060] S210: Collect network transmission data corresponding to the oil and gas pipeline network industrial control system.
[0061] S220. Calculate the number of flow fluctuations and the flow fluctuation difference per unit time based on the flow fluctuation data, and preliminarily determine whether the oil and gas pipeline network industrial control system is under a network attack based on the number of flow fluctuations and the flow fluctuation difference.
[0062] S230 , acquiring connection request data within each preset time period as pending request data corresponding to each preset time period; arranging the pending request data corresponding to all the preset time periods to obtain the connection request sequence.
[0063] The preset acquisition time series includes at least two preset time periods, for example, one time period per hour.
[0064] Specifically, the time is divided into a plurality of preset time periods, and all connection request data in each time period is extracted as the request data to be processed in the time period. Then, the request data to be processed in all time periods are arranged in chronological order to form a connection request sequence.
[0065] S240: For each of the preset time periods, determine a historical time period that matches the preset time period.
[0066] Specifically, one or more historical time periods are found for each preset time period, for example, the time period of 10:00-11:00 on the current Monday is matched with the time period of 10:00-11:00 on Mondays in the past few weeks.
[0067] S250: Calculate a first data volume value and a first connection number corresponding to the pending request data within the preset time period.
[0068] The first data volume value refers to the volume of request data to be processed within a preset period of time. The first number of connections refers to the total number of connection requests within the preset period of time.
[0069] S260: Calculate a second data volume value and a second connection number corresponding to the historical request data in the historical period.
[0070] The historical request sequence is obtained by arranging historical request data corresponding to at least two historical segments.
[0071] Similarly, the data volume of the historical request data in each historical period is determined as the second data volume value, and the total number of connection requests in the preset period is determined as the second connection number.
[0072] S270: Substitute the first data amount value, the first connection times, the second data amount value, and the second connection times into a similarity calculation formula to obtain a similarity value to be used corresponding to the preset time period.
[0073] The calculation formula for the similarity value to be used is:
[0074]
[0075] In the above formula, Si represents the similarity value to be used, t represents the first data amount value, ti represents the first data amount value, n represents the first connection number, and ni represents the second connection number.
[0076] S280 . Determine the similarity between the connection request sequence and the historical request sequence based on the to-be-used similarity values corresponding to the preset time periods, and determine again whether the oil and gas pipeline network industrial control system is under a network attack based on the similarity.
[0077] Specifically, the average of all similarity values to be used can be used as the similarity between the connection request sequence and the historical request sequence. Then, based on the similarity, it is determined again whether the oil and gas pipeline network industrial control system is under a network attack.
[0078] In some embodiments, judging again whether the oil and gas pipeline network industrial control system has been attacked by a network attack based on the similarity includes: setting a similarity threshold; if the similarity is less than the similarity threshold, judging whether the oil and gas pipeline network industrial control system has been attacked by a network attack; if the similarity is greater than or equal to the similarity threshold, judging that the oil and gas pipeline network has not been attacked by a network attack.
[0079] In the process of further judging whether the oil and gas pipeline network industrial control system is under a network attack based on the similarity analysis between the connection request sequence and the historical request sequence, a similarity threshold can be set as a judgment criterion.
[0080] The preset similarity threshold is usually determined based on historical data or expert experience.
[0081] If the calculated similarity between the connection request sequence and the historical request sequence is less than a preset similarity threshold, it indicates that the current connection request pattern is significantly different from the historical pattern. If this difference may be caused by a cyber attack, it is determined that the oil and gas pipeline network industrial control system may have been attacked by a cyber attack.
[0082] If the calculated similarity is greater than or equal to the preset similarity threshold, it indicates that the current connection request pattern is relatively close to the historical pattern. In this case, it is determined that the oil and gas pipeline network industrial control system has not been attacked by the network.
[0083] S290. If the result of the second determination is whether the oil and gas pipeline network industrial control system is under a network attack, extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type, and trigger a warning.
[0084] Compared with the prior art, the beneficial effect of the present invention is that the present invention realizes comprehensive monitoring and real-time identification of oil and gas pipeline network security by combining information from multiple dimensions of traffic fluctuation data and connection request data. First, the transmitted network data is collected, focusing on the changing characteristics of traffic fluctuations and connection requests. By calculating the number of traffic fluctuations and the fluctuation range value, a preliminary judgment is made as to whether a network attack has occurred. For example, frequent traffic fluctuations may indicate that the system has encountered an abnormal traffic attack such as a distributed denial of service (DDoS) attack. The connection request data is then used to analyze the connection request, and a connection request sequence is constructed and compared with the historical request sequence to further verify whether a network attack exists. If the connection request sequence changes significantly from the historical request sequence, it may indicate the presence of an abnormal connection request pattern or malicious activity.
[0085] Specifically, by combining multi-dimensional data, it is not only possible to identify traffic anomalies, but also to identify potential attack behaviors through changes in connection request patterns. Compared with traditional single detection methods, this solution provides a comprehensive and dynamic judgment method, making the identification of complex attack patterns more accurate. During the judgment process, the attack type is further determined through in-depth analysis of data packet information, and alarms are triggered in a timely manner to help operation and maintenance personnel respond quickly and reduce potential losses. This multi-level, multi-dimensional attack identification solution has higher fault tolerance and accuracy, can effectively enhance the security protection capabilities of oil and gas pipeline networks, and has important practical application value, especially in the face of increasingly complex network security threats.
[0086] Figure 3 The present invention provides a schematic diagram of a network attack identification device for an oil and gas pipeline network industrial control system. Figure 3 As shown, the device includes:
[0087] The data acquisition module 310 is used to collect network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data;
[0088] A preliminary judgment module 320 is configured to calculate the number of flow fluctuations and the flow fluctuation difference per unit time based on the flow fluctuation data, and to preliminarily judge whether the oil and gas pipeline network industrial control system is under a network attack based on the number of flow fluctuations and the flow fluctuation difference;
[0089] A sequence construction module 330 is configured to construct a connection request sequence corresponding to the connection request data based on the connection request data and a preset acquisition time sequence when a preliminary determination result indicates that the oil and gas pipeline network industrial control system is under a network attack;
[0090] A re-judgment module 340 is configured to determine the similarity between the connection request sequence and the historical request sequence, and to re-judgment whether the oil and gas pipeline network industrial control system is subject to a network attack based on the similarity;
[0091] The warning trigger module 350 is used to extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type and trigger a warning if the result of the second judgment is that the oil and gas pipeline network industrial control system is attacked by the network.
[0092] Optionally, the data acquisition module 310 is specifically configured to:
[0093] Deploy flow monitoring equipment in the oil and gas pipeline network industrial control system to collect flow fluctuation data of the oil and gas pipeline network industrial control system in real time;
[0094] Noise and invalid data in the flow fluctuation data are eliminated, and the flow fluctuation data is formatted according to a unit time interval to obtain the flow fluctuation data.
[0095] Optionally, the preliminary determination module 320 includes a statistical calculation submodule, specifically configured to:
[0096] Counting the number of fluctuations corresponding to the traffic fluctuation data within a unit time;
[0097] The difference between the maximum flow rate and the minimum flow rate corresponding to the flow fluctuation data within a unit time is calculated as the flow fluctuation difference.
[0098] Optionally, the preliminary judgment module 320 includes a preliminary judgment submodule, specifically configured to:
[0099] Determining whether the number of flow fluctuations is greater than a preset number of fluctuations, and determining whether the flow fluctuation difference is greater than a preset flow fluctuation difference;
[0100] When the number of flow fluctuations is greater than the preset number of fluctuations and the flow fluctuation difference is greater than the preset flow fluctuation difference, it is preliminarily determined that the oil and gas pipeline network industrial control system is under a network attack.
[0101] Optionally, the preset acquisition time sequence includes at least two preset time periods, and the sequence construction module 330 is specifically configured to:
[0102] Acquire the connection request data within each of the preset time periods as the request data to be processed corresponding to each of the preset time periods;
[0103] The request data to be processed corresponding to all the preset time periods are arranged to obtain the connection request sequence.
[0104] Optionally, the historical request sequence is obtained by arranging historical request data corresponding to at least two historical segments, and the re-judgment module 340 is specifically configured to:
[0105] For each of the preset time periods, determining a historical time period that matches the preset time period;
[0106] Calculating a first data volume value and a first connection number corresponding to the pending request data within the preset time period;
[0107] Calculate a second data volume value and a second connection number corresponding to the historical request data in the historical period;
[0108] Substituting the first data amount value, the first connection number, the second data amount value, and the second connection number into a similarity calculation formula to obtain a similarity value to be used corresponding to the preset time period;
[0109] Based on the to-be-used similarity values corresponding to the preset time periods, the similarity between the connection request sequence and the historical request sequence is determined.
[0110] Optionally, the re-judgment module 340 is further configured to:
[0111] Setting a similarity threshold, and if the similarity is less than the similarity threshold, determining that the oil and gas pipeline network industrial control system has been attacked by a network attack;
[0112] If the similarity is greater than or equal to the similarity threshold, it is determined that the oil and gas pipeline network has not been attacked by a network attack.
[0113] The network attack identification device for the oil and gas pipeline network industrial control system provided by the embodiment of the present invention can execute the network attack identification method for the oil and gas pipeline network industrial control system provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0114] Figure 4 A schematic diagram of the structure of an electronic device for implementing a network attack identification method for an oil and gas pipeline network industrial control system according to an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0115] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0116] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0117] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processors, controllers, microcontrollers, etc. Processor 11 executes the various methods and processes described above, such as the network attack identification method for oil and gas pipeline network industrial control systems.
[0118] In some embodiments, the network attack identification method for the oil and gas pipeline network industrial control system can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the network attack identification method for the oil and gas pipeline network industrial control system described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the network attack identification method for the oil and gas pipeline network industrial control system in any other appropriate manner (for example, by means of firmware).
[0119] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0120] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0121] In the context of the present invention, computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0122] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0123] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0124] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0125] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0126] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A network attack identification method for an oil and gas pipeline network industrial control system, characterized in that: include: Collecting network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data; Calculating the number of flow fluctuations and the difference in flow fluctuations per unit time based on the flow fluctuation data, and preliminarily determining whether the oil and gas pipeline network industrial control system is subject to a network attack based on the number of flow fluctuations and the difference in flow fluctuations; If a preliminary determination is made that the oil and gas pipeline network industrial control system is under a network attack, constructing a connection request sequence corresponding to the connection request data based on the connection request data and a preset acquisition time sequence; Determining the similarity between the connection request sequence and the historical request sequence, and determining again whether the oil and gas pipeline network industrial control system is subject to a network attack based on the similarity; If the result of the second determination is that the oil and gas pipeline network industrial control system is under a network attack, the data packet information corresponding to the network transmission data is extracted, the data packet information is parsed, the attack type is marked and a warning is triggered.
2. The method according to claim 1, characterized in that The acquisition of flow fluctuation data corresponding to the oil and gas pipeline network industrial control system includes: Deploy flow monitoring equipment in the oil and gas pipeline network industrial control system to collect flow fluctuation data of the oil and gas pipeline network industrial control system in real time; Noise and invalid data in the flow fluctuation data are eliminated, and the flow fluctuation data is formatted according to a unit time interval to obtain the flow fluctuation data.
3. The method according to claim 1, characterized in that The calculating of the number of flow fluctuations and the flow fluctuation difference per unit time according to the flow fluctuation data includes: Counting the number of fluctuations corresponding to the traffic fluctuation data within a unit time; The difference between the maximum flow rate and the minimum flow rate corresponding to the flow fluctuation data within a unit time is calculated as the flow fluctuation difference.
4. The method according to claim 1, wherein The preliminarily determining whether the oil and gas pipeline network industrial control system is under a network attack based on the number of flow fluctuations and the flow fluctuation difference includes: Determining whether the number of flow fluctuations is greater than a preset number of fluctuations, and determining whether the flow fluctuation difference is greater than a preset flow fluctuation difference; When the number of flow fluctuations is greater than the preset number of fluctuations and the flow fluctuation difference is greater than the preset flow fluctuation difference, it is preliminarily determined that the oil and gas pipeline network industrial control system is under a network attack.
5. The method according to claim 1, wherein The preset acquisition time sequence includes at least two preset time periods, and constructing a connection request sequence corresponding to the connection request data according to the connection request data and the preset acquisition time sequence includes: Acquire the connection request data within each of the preset time periods as the request data to be processed corresponding to each of the preset time periods; The request data to be processed corresponding to all the preset time periods are arranged to obtain the connection request sequence.
6. The method according to claim 5, characterized in that The historical request sequence is obtained by arranging historical request data corresponding to at least two historical segments, and determining the similarity between the connection request sequence and the historical request sequence includes: For each of the preset time periods, determining a historical time period that matches the preset time period; Calculating a first data volume value and a first connection number corresponding to the pending request data within the preset time period; Calculate a second data volume value and a second connection number corresponding to the historical request data in the historical period; Substituting the first data amount value, the first connection number, the second data amount value, and the second connection number into a similarity calculation formula to obtain a similarity value to be used corresponding to the preset time period; Based on the to-be-used similarity values corresponding to the preset time periods, the similarity between the connection request sequence and the historical request sequence is determined.
7. The method according to claim 1, characterized in that The determining again based on the similarity whether the oil and gas pipeline network industrial control system is subject to a network attack includes: Setting a similarity threshold, and if the similarity is less than the similarity threshold, determining that the oil and gas pipeline network industrial control system has been attacked by a network attack; If the similarity is greater than or equal to the similarity threshold, it is determined that the oil and gas pipeline network has not been attacked by a network attack.
8. A network attack identification device for an oil and gas pipeline network industrial control system, characterized in that: include: A data acquisition module, configured to acquire network transmission data corresponding to the oil and gas pipeline network industrial control system, wherein the network transmission data includes flow fluctuation data and connection request data; a preliminary judgment module, configured to calculate the number of flow fluctuations and the flow fluctuation difference per unit time based on the flow fluctuation data, and preliminarily judge whether the oil and gas pipeline network industrial control system is subject to a network attack based on the number of flow fluctuations and the flow fluctuation difference; a sequence construction module for constructing a connection request sequence corresponding to the connection request data based on the connection request data and a preset acquisition time sequence when a preliminary determination result indicates that the oil and gas pipeline network industrial control system is under a network attack; a re-judgment module, configured to determine the similarity between the connection request sequence and the historical request sequence, and re-judgment whether the oil and gas pipeline network industrial control system is subject to a network attack based on the similarity; The warning trigger module is used to extract the data packet information corresponding to the network transmission data, parse the data packet information, mark the attack type and trigger a warning if the result of the second judgment is that the oil and gas pipeline network industrial control system is under a network attack.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network attack identification method for the oil and gas pipeline industrial control system according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network attack identification method for the oil and gas pipeline network industrial control system according to any one of claims 1 to 7 when executed.