Network security protection method and equipment for oil-gas pipe network control system and storage medium
By acquiring multi-dimensional safety data and dynamically adjusting the acquisition cycle, the timeliness and accuracy of data acquisition in the oil and gas pipeline control system are solved, accurate safety situation assessment and flexible protection measures are achieved, and the system's response capabilities and efficiency are improved.
Patent Information
- Application Number
- CN202510708378.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-08-08
AI Technical Summary
The existing oil and gas pipeline control system lacks dynamic adjustment capabilities and is unable to respond to network attacks, equipment failures or environmental changes in a timely manner, resulting in low timeliness and accuracy of data collection, and lacks the comprehensive processing capabilities of multi-dimensional data, making it difficult to provide accurate security situation assessment.
By acquiring multi-dimensional security data, including network traffic data, log data and environmental sensor data, the historical security data threshold is determined, and the data acquisition period is dynamically adjusted according to the duration of the attack, and the attack level is identified by combining the trend slope and clustering algorithm to achieve dynamic adjustment of the acquisition period and comprehensive data processing.
Optimize the timeliness and accuracy of data acquisition, improve the accuracy of security situation evaluation, can timely identify and respond to attacks of different levels, reduce delay problems in traditional systems, and smoothly adjust the acquisition cycle in the recovery state, avoiding system burden.
Smart Images

Figure CN120455124A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security protection method, device and storage medium for an oil and gas pipeline network control system. Background Art
[0002] As global energy demand grows, oil and gas pipeline networks, as crucial infrastructure for energy transportation, shoulder a massive transportation burden. Currently, the scale of oil and gas pipeline construction continues to expand, and operational technology is becoming increasingly digital and intelligent. Widely distributed control networks and Industrial Internet of Things technologies are being adopted to achieve intelligent management of the entire process, from oil and gas collection and transportation to end users. This modern development has greatly improved the efficiency and reliability of pipeline operations.
[0003] However, most security systems still rely on regular manual inspections and fixed data collection cycles, failing to dynamically adjust to actual threats. This results in inaccurate and time-sensitive data collection. For example, in the face of cyberattacks, equipment failures, or environmental changes, traditional systems fail to respond promptly, missing the optimal opportunity for defense. Furthermore, existing security systems generally lack the ability to comprehensively process multidimensional data, making it difficult to provide accurate security situation assessments through multi-level, multi-angle data analysis. Summary of the Invention
[0004] The present invention provides a network security protection method, device and storage medium for an oil and gas pipeline network control system, so as to realize dynamic adjustment of acquisition cycle, comprehensive processing of multi-dimensional data, accurate identification of attack status and classification of attack levels.
[0005] According to one aspect of the present invention, a network security protection method for an oil and gas pipeline network control system is provided, comprising:
[0006] Acquiring multidimensional security data corresponding to the control system based on an initial acquisition period, wherein the multidimensional security data includes at least one of network traffic data, log data, device status data, and environmental sensor data;
[0007] determining historical security data of the control system, determining a security data threshold based on the historical security data, and determining whether the control system is under attack based on the multi-dimensional security data and the security data threshold;
[0008] In the case where the oil and gas pipeline network is attacked, the duration of the attack is determined, and the initial collection period is adjusted to a target collection period based on the duration of the attack.
[0009] According to another aspect of the present invention, a network security protection device for an oil and gas pipeline network control system is provided, comprising:
[0010] a data acquisition module, configured to acquire multi-dimensional security data corresponding to the control system based on an initial acquisition period, wherein the multi-dimensional security data includes at least one of network traffic data, log data, device status data, and environmental sensor data;
[0011] a threshold determination module, configured to determine historical security data of the control system, determine a security data threshold based on the historical security data, and determine whether the control system is under attack based on the multi-dimensional security data and the security data threshold;
[0012] The period updating module is used to determine the duration of the attack when the oil and gas pipeline network is attacked, and adjust the initial collection period to a target collection period based on the duration of the attack.
[0013] According to another aspect of the present invention, an electronic device is provided, comprising:
[0014] at least one processor;
[0015] and a memory communicatively connected to the at least one processor; wherein,
[0016] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network security protection method for the oil and gas pipeline control system described in any embodiment of the present invention.
[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, which stores computer instructions, and the computer instructions are used to enable a processor to implement the network security protection method for the oil and gas pipeline network control system described in any embodiment of the present invention when executed.
[0018] The technical solution of the embodiments of the present invention dynamically adjusts the data collection cycle based on the duration of the attack. This allows for timely capture of changes in security threats in the face of different types of attacks, optimizing the timeliness and accuracy of data collection and avoiding the potential delays caused by the fixed collection cycle of traditional systems. By comprehensively collecting and processing multidimensional data such as network traffic, log data, device status data, and environmental sensor data, not only does the comprehensiveness of data collection improve, but also the comprehensive analysis of this multidimensional data provides a more accurate security posture assessment, contributing to a deeper understanding of the system's overall security status.
[0019] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0021] Figure 1 A flowchart of a network security protection method for an oil and gas pipeline network control system provided by an embodiment of the present invention;
[0022] Figure 2 A flowchart of another network security protection method for an oil and gas pipeline network control system provided by an embodiment of the present invention;
[0023] Figure 3 A schematic structural diagram of a network security protection device for an oil and gas pipeline network control system provided by an embodiment of the present invention;
[0024] Figure 4 A schematic diagram of the structure of an electronic device for implementing the network security protection method for the oil and gas pipeline network control system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0026] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0027] Figure 1This is a flowchart of a network security protection method for an oil and gas pipeline network control system provided by an embodiment of the present invention. This embodiment is applicable to situations where there is no network security protection for an oil and gas pipeline network control system. This method can be executed by a network security protection device for an oil and gas pipeline network control system. The device can be implemented in the form of hardware and / or software and can be configured in a computer device. Figure 1 As shown, the method specifically includes the following steps:
[0028] S110 . Acquire multi-dimensional safety data corresponding to the control system based on the initial acquisition cycle.
[0029] Among them, the initial collection cycle refers to the cycle for obtaining multi-dimensional security data of the control system; the control system refers to the control system when the oil and gas pipeline network is in operation, which controls the normal operation of the oil and gas pipeline network to transport oil and gas resources; the multi-dimensional security data includes at least one of network traffic data, log data, equipment status data and environmental sensor data.
[0030] Specifically, the initial collection periods of network traffic data, log data, device status data, and environmental sensor data are calculated using the following formulas:
[0031]
[0032] Among them, T net Indicates the initial collection period of network traffic data; B avail Indicates available bandwidth, unit: bit / second; η bandwidth represents the bandwidth efficiency coefficient, which is the ratio of effective data in network traffic; D avg Indicates the average size of each data packet, unit: bytes; network data packet transmission frequency coefficient, α net Indicates the traffic update rate of network transmission, unit: data packet / second; F net Indicates the number of flow changes per unit time; β net represents the packet loss rate; δ net Indicates the degree to which data collection is affected by network delay, unit: second; T logs Indicates the initial collection period of log data; S avail Indicates the available space of system storage, unit: byte; η storage Indicates the effective space ratio of log storage, 0<η storage <1;L avg Indicates the average size of a log entry, in bytes; α logs Indicates the frequency of log record generation, unit: number of log entries generated per second; F logs Indicates the log record generation speed, unit: number of records generated per second; T device Indicates the collection period of equipment status data; Pdevice Indicates the processing capacity of the device, unit: data points / second; ΔS device Indicates the rate of change of device status data, unit: data points / second; F device Indicates the workload factor of the equipment operation, 0<F device <1; T sensor Indicates the collection period of environmental sensor data;
[0033] S sensor is the sampling rate of the sensor, unit: samples / second; η sensor Represents the sensor sampling efficiency coefficient, 0<η sensor <1;ΔE sensor Indicates the rate of environmental change, unit: change / second.
[0034] It should be noted that the sensor sampling efficiency coefficient is the theoretical minimum sampling interval divided by the actual sampling interval. The initial collection period for network traffic data is primarily determined by factors such as available bandwidth, bandwidth efficiency coefficient, average packet size, network packet transmission frequency coefficient, traffic fluctuation frequency, packet loss rate, and the impact of network latency, ensuring that the data collection period is appropriate for network conditions. The initial collection period for log data is influenced by factors such as available system storage space, the effective space percentage of log storage, average log entry size, log record generation frequency, and log record generation speed, ensuring that the system can record log data in a timely manner and avoid storage overload. The collection period for device status data is closely related to the device's processing capacity, the rate of change of device status data, and the device's operating load factor, ensuring that the device's operating status is reflected promptly. The collection period for environmental sensor data is primarily determined by the sensor's sampling rate, sampling efficiency coefficient, and the rate of environmental change, ensuring that the data reflects environmental changes. By comprehensively considering these factors, the data collection module can determine an appropriate initial collection period for different data types, optimizing data collection efficiency, reducing system burden, and ensuring real-time and accurate data.
[0035] In an embodiment of the present invention, comprehensive collection and processing of multi-dimensional data such as network traffic data, log data, device status data, and environmental sensor data not only improves the comprehensiveness of data collection, but also provides a more accurate security situation assessment through comprehensive analysis of these multi-dimensional data, which helps to deeply understand the overall security status of the control system.
[0036] S120 , determining historical security data of the control system, determining a security data threshold based on the historical security data, and judging whether the control system is under attack based on the multi-dimensional security data and the security data threshold.
[0037] Historical security data refers to the control system's network traffic data, log data, device status data, and environmental sensor data over a historical period. Security data thresholds can be understood as threshold ranges determined based on historical security data. These thresholds can be used to determine whether the control system is under attack. For example, determining whether multidimensional security data falls within a security threshold can be used to determine whether the control system is under attack.
[0038] S130: When the oil and gas pipeline network is attacked, determine the duration of the attack, and adjust the initial collection period to the target collection period based on the duration of the attack.
[0039] Understandably, most security systems still rely on regular manual inspections and fixed data collection cycles, failing to dynamically adjust to actual threats. This results in inaccurate and time-sensitive data collection. For example, when faced with cyberattacks, equipment failures, or environmental changes, traditional systems fail to respond promptly, missing the optimal opportunity for defense.
[0040] In an embodiment of the present invention, the data collection period can be adjusted in real time according to the duration of the attack, that is, the initial collection period is adjusted to the target period. This can timely capture changes in security threats when facing different types of attacks, optimize the timeliness and accuracy of data collection, and avoid the delay problem that may be caused by the fixed collection period of the traditional system.
[0041] In some embodiments, the multidimensional security data may be analyzed based on a time series to determine a trend slope corresponding to the multidimensional security data; the attack level of the control system may be determined based on the trend slope, and an alarm may be issued according to the attack level.
[0042] In other embodiments, the trend slope is calculated using the following formula:
[0043]
[0044] Where Slope represents the trend slope; t m is the acquisition time of the mth sampling value in the multi-dimensional security data, x m is the mth sampling value, is the time mean of all selected sample values in the multidimensional security data; is the mean of all selected sampling values; w is the fixed window set for trend analysis.
[0045] Specifically, if the absolute value of the trend slope is greater than 0.3, it is determined to be in an attacked state. Furthermore, the attack level is divided according to the trend slope. When Slope>0.7, the attack level is classified as a severe attack; when 0.5<Slope≤0.7, the attack level is classified as a moderate attack; when 0.3<Slope≤0.5, the attack level is classified as a slight attack; if the duration is greater than t th , it will go up one level.
[0046] Based on the above embodiment, the alarm can be issued based on the attack level: when the attack level is severe, an alarm signal is immediately issued; when the attack level is mild or moderate, the user is asked to enable remote control. It should be noted that if the attack level is already severe, the current level will not be increased.
[0047] As you can see, by categorizing attacks into different levels, we can accurately assess their severity. This categorization facilitates the implementation of appropriate response measures based on the severity of the attack. When a severe attack is detected, an immediate alarm is issued, ensuring that relevant personnel can intervene and address the situation as quickly as possible. For moderate and minor attacks, the user can be requested to enable remote control, allowing for a more intensive intervention based on the actual situation. By setting the attack level to stop escalating once it reaches severe, the system can prevent excessive adjustments to the attack level due to continuous detection, ensuring stable operation and preventing excessive alarm frequency from disrupting normal operations. Furthermore, continuous attack monitoring and timely feedback enable protective measures to be implemented early during an attack, preventing prolonged exposure to risk. The categorization and alarm mechanism automatically adjusts protection based on the severity of the attack. For severe attacks, alarms are prioritized and an emergency response is initiated. For minor attacks, remote control requests are made, reducing system burden while ensuring that lower-level threats are addressed.
[0048] In some preferred embodiments, historical abnormal data may be obtained, and the multi-dimensional security data and the historical abnormal data may be clustered with a clustering algorithm to obtain a clustering result; and the attack type corresponding to the control system may be determined based on the clustering result.
[0049] Among them, historical abnormal data refers to the data corresponding to when the control system is attacked. Different attack types can correspond to different historical abnormal data; the attack type is any one or more of network traffic tampering, log tampering, device control command injection and environmental data interference.
[0050] Specifically, the multidimensional security data and the historical abnormal data are clustered, for example, using a k-means clustering algorithm or a DBSCAN algorithm. After clustering is completed, the historical abnormal data to which the multidimensional security data belongs is determined, and the attack type corresponding to the historical abnormal data is used as the attack type of the control system.
[0051] Figure 2 This is a flowchart of another network security protection method for an oil and gas pipeline network control system provided by an embodiment of the present invention. This embodiment can also adjust and call back the initial collection cycle to improve the real-time response capability to attacks. Figure 2 As shown, the method specifically includes the following steps:
[0052] S210 . Acquire multi-dimensional safety data corresponding to the control system based on the initial acquisition cycle.
[0053] S220: Determine historical safety data of the control system, and determine a safety data threshold based on the historical safety data.
[0054] S230. Determine whether the multi-dimensional security data is between a lower threshold and an upper threshold; if so, determine that the control system is attacked; if not, determine that the control system is not attacked.
[0055] In some embodiments, the safety data threshold includes a lower threshold and an upper threshold, which are calculated by the following formulas:
[0056]
[0057] Among them, U min is the lower limit of the threshold, U max is the upper threshold limit; N is the number of historical security data samples; i represents the type of multi-dimensional security data, namely network traffic data, log data, device status data and environmental sensor data; represents the jth sampling value; k represents the threshold tolerance coefficient, 1≤k≤3.
[0058] It should be noted that by selecting the latest multi-dimensional security data of the same type and performing statistics based on the number of historical data samples, it is possible to ensure that the threshold setting is more accurate. The lower and upper threshold limits can be dynamically adjusted based on the actual collected data to ensure that security detection in different environments is more in line with the actual operating status. The introduction of the threshold tolerance coefficient k (1≤k≤3) provides flexibility in threshold setting. The threshold range can be adjusted according to specific needs to avoid misjudgment or missed judgment. Different tolerance coefficients enable the threshold range to adapt to different data fluctuations, thereby improving the penetration test module's ability to respond to security threats.
[0059] In this embodiment, the latest data is selected by collection time, which can reflect the current security status of the control system in real time. By continuously updating the threshold, it can effectively respond to environmental changes and potential security threats, ensuring that efficient monitoring and protection capabilities are maintained under constantly changing conditions.
[0060] S240. When the oil and gas pipeline network is attacked, determine the duration of the attack.
[0061] S250: Calculate a weight factor according to the attack duration and a preset time threshold, and determine a target collection period according to the weight factor.
[0062] The target acquisition period is calculated by the following formula:
[0063]
[0064] T = T0·(1-p·l);
[0065] Among them, l is the weight factor; t d is the duration; t th is the time threshold; T is the target acquisition period; T0 is the initial acquisition period; p is the shrinkage coefficient, which is used to control the shrinkage ratio of the acquisition period.
[0066] Specifically, by calculating a weighting factor based on the attack duration and a preset time threshold, the data collection cycle can be flexibly adjusted. As the attack persists, the data collection cycle is automatically shortened to monitor potential threats more frequently and improve the system's real-time response capabilities to attacks. The introduction of this contraction factor allows for precise control over changes in the collection cycle, ensuring that adjustments to the collection cycle align with the actual attack scenario.
[0067] S260: Adjust the initial collection period to the target collection period.
[0068] In some embodiments, the method further includes: if it is detected that the control system is restored to a non-attacked state, determining a collection period to be corrected; and correcting the target collection period based on the collection period to be corrected to restore the target collection period to the initial collection period.
[0069] The acquisition period to be corrected is calculated using the following formula:
[0070] T new =min[T new , T + β·(T0-T)];
[0071] Among them, T new is the acquisition period to be corrected; β is the callback coefficient, which is used to control the recovery speed of the acquisition period; T is the target acquisition period; T0 is the initial acquisition period.
[0072] Specifically, after returning to a safe state, the initial collection period is not immediately restored. Instead, the collection period is gradually adjusted to avoid monitoring loopholes caused by a too-rapid recovery. The introduction of a callback coefficient makes the recovery process smoother, ensuring that effective monitoring can continue even in a safe state.
[0073] The technical solution of the present invention has at least the following beneficial effects:
[0074] By dynamically adjusting the data collection cycle based on the duration of the attack, it is possible to promptly capture changes in security threats when facing different types of attacks, optimize the timeliness and accuracy of data collection, and avoid the delays that may be caused by the fixed collection cycle of traditional systems.
[0075] By comprehensively collecting and processing multi-dimensional data such as network traffic data, log data, device status data, and environmental sensor data, not only the comprehensiveness of data collection is improved, but also a more accurate security situation assessment is provided through comprehensive analysis of these multi-dimensional data, which helps to deeply understand the overall security status of the system.
[0076] By combining historical data with thresholds, it can accurately determine whether an attack is underway, improving early warning capabilities for potential security threats and enabling rapid identification and response when they occur. By analyzing the duration of an attack, it can categorize the severity of the attack, helping decision-makers implement targeted protective measures for varying severity levels. When the attack level reaches a certain threshold, an alert is issued promptly, and remote control options are provided for moderate or minor attacks, effectively providing users with flexible protection solutions and enhancing responsiveness to varying threat levels.
[0077] Furthermore, when a safe state is detected, the collection period can be gradually restored to its initial value, avoiding excessively extended data collection periods and improving system efficiency during recovery. This mechanism ensures balanced data collection and avoids unnecessary system burden.
[0078] Figure 3 This is a schematic diagram of the structure of a network security protection device for an oil and gas pipeline network control system provided by an embodiment of the present invention. Figure 3 As shown, the device includes:
[0079] a data acquisition module 310 for acquiring multi-dimensional security data corresponding to the control system based on an initial acquisition period, wherein the multi-dimensional security data includes at least one of network traffic data, log data, device status data, and environmental sensor data;
[0080] a threshold determination module 320 for determining historical security data of the control system, determining a security data threshold based on the historical security data, and determining whether the control system is under attack based on the multi-dimensional security data and the security data threshold;
[0081] The period updating module 330 is configured to determine the duration of an attack when the oil and gas pipeline network is attacked, and adjust the initial collection period to a target collection period based on the duration of the attack.
[0082] In some embodiments, the network security protection device of the oil and gas pipeline network control system further includes a classification and alarm module, specifically configured to:
[0083] Analyzing the multidimensional safety data based on a time series to determine a trend slope corresponding to the multidimensional safety data;
[0084] An attack level of the control system is determined based on the trend slope, and an alarm is performed according to the attack level.
[0085] In some embodiments, the trend slope is calculated by the following formula:
[0086]
[0087] Where Slope represents the trend slope; t m is the acquisition time of the mth sampling value in the multi-dimensional security data, x m is the mth sampling value, is the time mean of all selected sample values in the multidimensional security data; is the mean of all selected sampling values; w is the fixed window set for trend analysis.
[0088] In some embodiments, the network security protection device of the oil and gas pipeline network control system further includes an attack type determination module, specifically configured to:
[0089] Acquire historical abnormal data, and cluster the multidimensional safety data and the historical abnormal data using a clustering algorithm to obtain a clustering result;
[0090] The attack type corresponding to the control system is determined based on the clustering result.
[0091] In some embodiments, the safety data threshold includes a lower threshold and an upper threshold, which are calculated by the following formulas:
[0092]
[0093] Among them, U min is the lower limit of the threshold, U maxis the upper threshold limit; N is the number of historical security data samples; i represents the type of multi-dimensional security data, namely network traffic data, log data, device status data and environmental sensor data; represents the jth sampling value; k represents the threshold tolerance coefficient, 1≤k≤3.
[0094] In some embodiments, the threshold determination module 320 is specifically configured to:
[0095] determining whether the multi-dimensional security data is between the lower threshold and the upper threshold;
[0096] If so, it is determined that the control system is attacked;
[0097] If not, it is determined that the control system has not been attacked.
[0098] In some embodiments, the periodic update module 330 is specifically configured to:
[0099] Calculating a weight factor based on the duration of the attack and a pre-set time threshold, and determining a target collection period based on the weight factor;
[0100] The initial acquisition period is adjusted to the target acquisition period; wherein the target acquisition period is calculated by the following formula:
[0101]
[0102] T = T0·(1-p·l);
[0103] Among them, l is the weight factor; t d is the duration; t th is the time threshold; T is the target acquisition period; T0 is the initial acquisition period; p is the shrinkage coefficient, which is used to control the shrinkage ratio of the acquisition period.
[0104] In some embodiments, a callback module is further included, specifically configured to:
[0105] If it is detected that the control system has recovered to a state where it has not been attacked, then determining the acquisition period to be corrected;
[0106] Correcting the target acquisition cycle based on the acquisition cycle to be corrected to restore the target acquisition cycle to the initial acquisition cycle;
[0107] The acquisition period to be corrected is calculated using the following formula:
[0108] T new =min[T new , T + β·(T0-T)];
[0109] Among them, Tnew is the acquisition period to be corrected; β is the callback coefficient, which is used to control the recovery speed of the acquisition period; T is the target acquisition period; T0 is the initial acquisition period.
[0110] The network security protection device for the oil and gas pipeline network control system provided in the embodiment of the present invention can execute the network security protection method for the oil and gas pipeline network control system provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0111] Figure 4 A schematic diagram of the structure of an electronic device for implementing the network security protection method of the oil and gas pipeline network control system according to an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0112] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12, and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0113] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0114] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processors, controllers, microcontrollers, etc. Processor 11 executes the various methods and processes described above, such as the network security protection method for an oil and gas pipeline network control system.
[0115] In some embodiments, the network security protection method for the oil and gas pipeline network control system can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the network security protection method for the oil and gas pipeline network control system described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the network security protection method for the oil and gas pipeline network control system in any other appropriate manner (for example, by means of firmware).
[0116] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0117] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0118] In the context of the present invention, computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0119] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0120] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0121] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0122] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0123] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A network security protection method for an oil and gas pipeline network control system, characterized in that: include: Acquiring multi-dimensional security data corresponding to the control system based on an initial acquisition period, wherein the multi-dimensional security data includes at least one of network traffic data, log data, device status data, and environmental sensor data; determining historical security data of the control system, determining a security data threshold based on the historical security data, and determining whether the control system is under attack based on the multi-dimensional security data and the security data threshold; In the case where the oil and gas pipeline network is attacked, the duration of the attack is determined, and the initial collection period is adjusted to a target collection period based on the duration of the attack.
2. The method according to claim 1, characterized in that Also includes: Analyzing the multidimensional safety data based on a time series to determine a trend slope corresponding to the multidimensional safety data; An attack level of the control system is determined based on the trend slope, and an alarm is performed according to the attack level.
3. The method according to claim 2, characterized in that The trend slope is calculated by the following formula: Where Slope represents the trend slope; t m is the acquisition time of the mth sampling value in the multi-dimensional security data, x m is the mth sampling value, is the time mean of all selected sample values in the multidimensional security data; is the mean of all selected sampling values; w is the fixed window set for trend analysis.
4. The method according to claim 1, wherein The method further comprises: Acquire historical abnormal data, and cluster the multidimensional safety data and the historical abnormal data using a clustering algorithm to obtain a clustering result; The attack type corresponding to the control system is determined based on the clustering result.
5. The method according to claim 1, wherein The safety data threshold includes a lower threshold and an upper threshold, which are calculated using the following formulas: Among them, U min is the lower limit of the threshold, U max is the upper threshold limit; N is the number of historical security data samples; i represents the type of multi-dimensional security data, namely network traffic data, log data, device status data and environmental sensor data; represents the jth sampling value; k represents the threshold tolerance coefficient, 1≤k≤3.
6. The method according to claim 5, characterized in that The determining whether the control system is attacked based on the multi-dimensional security data and the security data threshold includes: determining whether the multi-dimensional security data is between the lower threshold and the upper threshold; If so, it is determined that the control system is attacked; If not, it is determined that the control system has not been attacked.
7. The method according to claim 1, characterized in that The adjusting the initial collection period to a target collection period based on the attack duration includes: Calculating a weight factor based on the duration of the attack and a pre-set time threshold, and determining a target collection period based on the weight factor; The initial acquisition period is adjusted to the target acquisition period; wherein the target acquisition period is calculated by the following formula: T = T0·(1-p·l); Where l is the weight factor; t d is the duration; t th is the time threshold; T is the target acquisition period; T0 is the initial acquisition period; p is the shrinkage coefficient, which is used to control the shrinkage ratio of the acquisition period.
8. The method according to claim 7, characterized in that Also includes: If it is detected that the control system has recovered to a state where it has not been attacked, then determining the acquisition period to be corrected; Correcting the target acquisition cycle based on the acquisition cycle to be corrected to restore the target acquisition cycle to the initial acquisition cycle; The acquisition period to be corrected is calculated using the following formula: T new =min[T new ,T+β·(T0-T)]; Among them, T new is the acquisition period to be corrected; β is the callback coefficient, which is used to control the recovery speed of the acquisition period; T is the target acquisition period; T0 is the initial acquisition period.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the network security protection method for the oil and gas pipeline network control system according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network security protection method for the oil and gas pipeline network control system according to any one of claims 1 to 8 when executed.