Method and device for predicting information security threat risk path of oil and gas production system

By building a directed network of oil and gas production systems, assessing the recovery time and propagation time of nodes, simulating the failure propagation process of information threats, the problem of difficulty in risk path assessment in the existing technology is solved, targeted protection strategies are formulated, and resource waste is reduced.

CN120455292AActive Publication Date: 2025-08-08CHINA UNIV OF PETROLEUM (BEIJING)
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510586049.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-08
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The information layer connection of equipment in oil and gas production systems is too complex, resulting in complex attack methods and requiring a large number of security protection resources. However, the existing technology is difficult to effectively evaluate and predict risk paths, resulting in waste of resources.

Method used

By building a directed network of oil and gas production systems, the local aggregation coefficient of the nodes is obtained, the recovery time and propagation time of the nodes are determined, the failure propagation process of information threats is simulated, the disturbance risk level of the risk path is evaluated, and targeted protection strategies are formulated.

Benefits of technology

Quantitative evaluation and sorting of various risk paths in oil and gas production systems has been realized, reducing the waste of safety protection resources, and improving the effectiveness of targeted protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455292A_ABST
    Figure CN120455292A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an oil and gas production system information security threat risk path prediction method and device. According to the method, a directed network of an oil and gas production system is constructed, the propagation duration and the recovery duration of nodes in the directed network are obtained by extracting local aggregation coefficients of the nodes in the directed network, and then the dynamic failure propagation process of failure of the oil and gas production system caused by information threats is simulated according to the propagation duration and the recovery duration of the nodes. According to the method and the system provided by the invention, the risk levels of different risk paths can be quantitatively evaluated and sorted, and the security protection strategies of a plurality of risk paths can be formulated in a targeted manner, so that the propagation and expansion of information threats can be blocked in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the industrial field, and in particular to a method and device for predicting information security threat risk paths in oil and gas production systems. Background Art

[0002] In the industrial field, the supply security of oil and gas resources is usually achieved through the Oil and Gas Production-Cyber Physical System (OGP-CPS).

[0003] In related technologies, OGP-CPS collects, transmits and analyzes real-time data of equipment in the oil and gas production system at its information layer, and builds an information space twin corresponding to the equipment in the virtual information space. The information space twin can reflect the behavior and status of the equipment.

[0004] However, OGP-CPS connects multiple devices at the information layer, allowing originally relatively independent devices to be interconnected. This makes it possible to attack a device in the oil and gas production system and then attack other devices directly or indirectly connected to it. The excessive number of attack methods in the oil and gas production system leads to an overly complex risk path, requiring more security protection resources to be invested in the security protection of the oil and gas production system. Summary of the Invention

[0005] The embodiments of the present application provide a method and device for predicting information security threat risk paths of an oil and gas production system, which are used to determine the disturbance risk levels of multiple risk paths of the oil and gas production system, thereby achieving targeted security protection of the oil and gas production system and reducing waste of resources.

[0006] In a first aspect, an embodiment of the present application provides a method for predicting information security threat risk paths in an oil and gas production system, comprising:

[0007] Obtaining local clustering coefficients of a plurality of nodes, the plurality of nodes being nodes in a target directed network constructed based on the oil and gas generation system, the plurality of nodes corresponding to the plurality of devices;

[0008] Determining, based on the local clustering coefficients of the multiple nodes, recovery times of the multiple nodes and propagation times between every two nodes; the recovery time is the time required for the node to recover from a functional failure to become functionally valid, and the propagation time is the time required for the functional failure of one node to cause the functional failure of another node;

[0009] When perturbing at least one first node among the plurality of nodes, determining a failure propagation process based on the target directed network, the recovery time of the plurality of nodes, the propagation time between each two nodes, and the initial time of the perturbation, the failure propagation process including functional states of the plurality of nodes at the initial time, functional states at the end time, and functional states at a plurality of selected times between the initial time and the end time; the end time being the time when the target directed network returns to normal;

[0010] According to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one first node is determined, and the disturbance risk level is used to characterize the degree of harm to the oil and gas production system caused by the attack on at least one device corresponding to the at least one first node.

[0011] In a possible implementation, determining, according to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one first node includes:

[0012] Determining a plurality of target moments among the initial moment, the end moment, and the plurality of candidate moments;

[0013] Determining the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes;

[0014] The disturbance risk level is determined according to the instantaneous functional states at the multiple target moments.

[0015] In a possible implementation, the instantaneous functional state at the target moment satisfies the following formula 1:

[0016]

[0017] Among them, t k represents the target time, r(t k ) represents the instantaneous functional state corresponding to the target moment, N represents the total number of device types corresponding to the multiple nodes, α n Indicates the weight corresponding to type n, M n represents the total number of nodes corresponding to the type n in the plurality of nodes, S nm (t k ) represents the functional status of node m among the nodes corresponding to the type n at the target moment.

[0018] In a possible implementation, determining the disturbance risk level according to the instantaneous functional states at the multiple target moments includes:

[0019] Performing curve fitting processing on the instantaneous functional states at the multiple target moments to obtain a safety toughness change curve;

[0020] Determining a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the security resilience change curve;

[0021] The disturbance risk level is determined according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter.

[0022] In a possible implementation, the damage degree parameter S1 satisfies the following formula 2:

[0023]

[0024] Wherein, A represents the preset value associated with the end time and the initial time, t end represents the end time, t start represents the initial moment, R(t) represents the safety toughness change curve, ∫ represents the integral symbol, and dt represents the differential symbol;

[0025] The damage range parameter S2 satisfies the following formula 3:

[0026] S2=1 / R min Formula 3;

[0027] Among them, R min Indicates the minimum value of R(t), / indicates division operation;

[0028] The capability recovery parameter S3 satisfies the following formula 4:

[0029]

[0030] Wherein, P represents the number of at least one sub-curve, and the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include R min The corresponding target time, t end , and the R min The corresponding target time and t end The first curve is R(t) min The curve between the corresponding target time and the end time, K p represents the slope corresponding to the curve p in the at least one sub-curve.

[0031] In a possible implementation, determining the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter includes:

[0032] determining the product of the damage extent parameter and the damage range parameter;

[0033] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.

[0034] In a possible implementation, obtaining a local clustering coefficient of a node in the target directed network includes:

[0035] Determining a local clustering coefficient of the node according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point;

[0036] The local clustering coefficient C(i) of node i among the multiple nodes satisfies the following formula 5:

[0037]

[0038] Among them, k i represents the number of neighboring nodes of the node i, e i Indicates the number of edges between the adjacent points.

[0039] In a possible implementation, the recovery time T of node i among the multiple nodes is r (i) Satisfy the following formula 6:

[0040] T r (i)=C(i)·T rbase Formula 6;

[0041] Where C(i) represents the local clustering coefficient of the node i, T rbase Indicates the basic recovery time;

[0042] The propagation time T between node i and node j among the multiple nodes p (i, j) satisfies the following formula 7:

[0043]

[0044] Where C(j) represents the local clustering coefficient of the node j, T pbase Indicates the basic transmission time.

[0045] In one possible implementation, the method further includes:

[0046] constructing an initial directed network of the oil and gas generation system based on device information of the plurality of devices in the oil and gas generation system and connection relationships between the plurality of devices, the initial directed network comprising the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the directions of the edges indicating an information transmission direction or an oil and gas transmission direction between the devices corresponding to the nodes on the edges;

[0047] Determining an average path length and an average clustering coefficient of the initial directed network;

[0048] determining an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;

[0049] According to the optimal reconnection probability, edges between the multiple nodes in the initial directed network are adjusted to obtain the target directed network.

[0050] In a second aspect, an embodiment of the present application provides a safety simulation device for an oil and gas generation system, comprising:

[0051] an acquisition module, configured to acquire local clustering coefficients of a plurality of nodes, wherein the plurality of nodes are nodes in a target directed network constructed based on the oil and gas generation system, and the plurality of nodes correspond to the plurality of devices;

[0052] a determination module configured to determine, based on the local clustering coefficients of the multiple nodes, a recovery duration of the multiple nodes and a propagation duration between each two nodes; the recovery duration being the time required for the node to recover from a functional failure to become functionally valid, and the propagation duration being the time required for a functional failure of one node to cause a functional failure of another node;

[0053] The determination module is further configured to, when perturbing at least one of the plurality of nodes, determine a failure propagation process based on the target directed network, the recovery time of the plurality of nodes, the propagation time between each two nodes, and the initial time of the perturbation, wherein the failure propagation process includes functional states of the plurality of nodes at the initial time, functional states at the end time, and functional states at a plurality of selected times between the initial time and the end time; the end time being the time when the target directed network returns to normal;

[0054] The determination module is further used to determine the disturbance risk level of the risk path corresponding to the disturbance of the at least one node based on the failure propagation process, and the disturbance risk level is used to characterize the degree of harm to the oil and gas production system when at least one device corresponding to the at least one node is attacked.

[0055] In a possible implementation, the determining module is specifically configured to:

[0056] Determining a plurality of target moments among the initial moment, the end moment, and the plurality of candidate moments;

[0057] Determining the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes;

[0058] The disturbance risk level is determined according to the instantaneous functional states at the multiple target moments.

[0059] In a possible implementation, the instantaneous functional state at the target moment satisfies the following formula 1:

[0060]

[0061] Among them, t k represents the target time, r(t k ) represents the instantaneous functional state corresponding to the target moment, N represents the total number of device types corresponding to the multiple nodes, α n Indicates the weight corresponding to type n, M n represents the total number of nodes corresponding to the type n in the plurality of nodes, S nm (t k ) represents the functional status of node m among the nodes corresponding to the type n at the target moment.

[0062] In a possible implementation, the determining module is specifically configured to:

[0063] Performing curve fitting processing on the instantaneous functional states at the multiple target moments to obtain a safety toughness change curve;

[0064] Determining a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the security resilience change curve;

[0065] The disturbance risk level is determined according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter.

[0066] In a possible implementation, the damage degree parameter S1 satisfies the following formula 2:

[0067]

[0068] Wherein, A represents the preset value associated with the end time and the initial time, t end represents the end time, t startrepresents the initial moment, R(t) represents the safety toughness change curve, ∫ represents the integral symbol, and dt represents the differential symbol;

[0069] The damage range parameter S2 satisfies the following formula 3:

[0070] S2=1 / R min Formula 3;

[0071] Among them, R min Indicates the minimum value of R(t), / indicates division operation;

[0072] The capability recovery parameter S3 satisfies the following formula 4:

[0073]

[0074] Wherein, P represents the number of at least one sub-curve, and the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include R min The corresponding target time, t end , and the R min The corresponding target time and t end The first curve is R(t) min The curve between the corresponding target time and the end time, K p represents the slope corresponding to the curve p in the at least one sub-curve.

[0075] In a possible implementation, the determining module is specifically configured to:

[0076] determining the product of the damage extent parameter and the damage range parameter;

[0077] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.

[0078] In a possible implementation, the acquisition module is specifically configured to:

[0079] Determining a local clustering coefficient of the node according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point;

[0080] The local clustering coefficient C(i) of node i among the multiple nodes satisfies the following formula 5:

[0081]

[0082] Among them, k i represents the number of neighboring nodes of the node i, e i Indicates the number of edges between the adjacent points.

[0083] In a possible implementation, the recovery time T of node i among the multiple nodes is r (i) Satisfy the following formula 6:

[0084] T r (i)=C(i)·T rbase Formula 6;

[0085] Where C(i) represents the local clustering coefficient of the node i, T rbase Indicates the basic recovery time;

[0086] The propagation time T between node i and node j among the multiple nodes p (i, j) satisfies the following formula 7:

[0087]

[0088] Where C(j) represents the local clustering coefficient of the node j, T pbase Indicates the basic transmission time.

[0089] In a possible implementation, the determining module is further configured to:

[0090] constructing an initial directed network of the oil and gas generation system based on device information of the plurality of devices in the oil and gas generation system and connection relationships between the plurality of devices, the initial directed network comprising the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the directions of the edges indicating an information transmission direction or an oil and gas transmission direction between the devices corresponding to the nodes on the edges;

[0091] Determining an average path length and an average clustering coefficient of the initial directed network;

[0092] determining an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;

[0093] According to the optimal reconnection probability, edges between the multiple nodes in the initial directed network are adjusted to obtain the target directed network.

[0094] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor;

[0095] The memory stores computer-executable instructions;

[0096] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.

[0097] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.

[0098] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.

[0099] The embodiments of the present application provide a method and device for predicting information security threat risk paths in oil and gas production systems. Based on the local clustering coefficients of the multiple nodes, the method and device determine the recovery time of the multiple nodes and the propagation time between each two nodes. When disturbing at least one first node among the multiple nodes, the method and device determine the failure propagation process based on the target directed network, the recovery time of the multiple nodes, the propagation time between each two nodes, and the initial moment of the disturbance. Based on the failure propagation process, the disturbance risk level of the risk path corresponding to the disturbance of the at least one first node is determined, thereby achieving targeted formulation of security protection strategies for the multiple risk paths based on the disturbance risk levels of the multiple risk paths, so as to timely block the spread and expansion of information threats and reduce the waste of security protection resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0100] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0101] Figure 1 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 1 ;

[0102] Figure 2 A schematic diagram of the failure propagation process at a certain moment provided in an embodiment of the present application;

[0103] Figure 3 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 2 ;

[0104] Figure 4 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 3 ;

[0105] Figure 5 A schematic diagram of a security toughness change curve provided in an embodiment of the present application;

[0106] Figure 6 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 4 ;

[0107] Figure 7 A flowchart of a method for determining an optimal reconnection probability provided in an embodiment of the present application;

[0108] Figure 8 A schematic diagram of the structure of the device for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application;

[0109] Figure 9 A structural diagram of an electronic device provided in an embodiment of the present application.

[0110] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0111] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0112] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. For example, the first and second numerical values are merely used to distinguish different numerical values and do not limit their order. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity or execution order, and words such as "first" and "second" do not necessarily mean different.

[0113] It should be noted that in the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.

[0114] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item)" or similar expressions refer to any combination of these items, including any combination of single item(s) or plural item(s). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.

[0115] In the industrial field, ensuring the supply security of oil and gas resources is an important issue. In related technologies, the supply security of oil and gas resources is usually achieved through the cyber-physical system (Oil and Gas Production - Cyber Physical System, OGP-CPS) of the oil and gas production system.

[0116] OGP-CPS realizes constructing an information space twin corresponding to the device in the virtual information space by collecting, transmitting, and analyzing the real-time data of the physical entities of the devices in the oil and gas production system in its information layer. Through the information space twin, the behavior and state of the device can be reflected.

[0117] However, OGP-CPS connects multiple devices in the information layer, making the originally relatively independent devices connected to each other, resulting in the ability to attack other devices directly or indirectly connected to a certain device in the oil and gas production system by attacking a certain device in the oil and gas production system. There are too many attack means in the oil and gas production system, resulting in an overly complex risk path, and more security protection resources need to be invested in the security protection of the oil and gas production system.

[0118] In view of this, the present application proposes a method for predicting the risk path of information security threats in an oil and gas production system. This method determines the failure node by disturbing the first node, determines the recovery duration of multiple failure nodes by determining the local clustering coefficient, and then determines the disturbance risk level corresponding to the first node according to the recovery duration of multiple failure nodes and the propagation duration between multiple failure nodes. By disturbing the first node to determine the failure node, the risk path corresponding to the first node can be predicted, and then the security protection strategies for multiple risk paths can be formulated specifically according to the disturbance risk levels corresponding to multiple first nodes, reducing the waste of security protection resources.

[0119] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0120] Figure 1 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 1 ,like Figure 1 As shown, the method includes:

[0121] S101. Obtain local clustering coefficients of a plurality of nodes, where the plurality of nodes are nodes in a target directed network constructed based on an oil and gas generation system, and the plurality of nodes correspond to a plurality of devices in the oil and gas generation system.

[0122] Optionally, the executing entity of the embodiment of the present application is an electronic device, or it may be an oil and gas production system information security threat risk path prediction device set in the electronic device. The oil and gas production system information security threat risk path prediction device can be implemented through a combination of software and / or hardware.

[0123] The target directed network includes edges between multiple nodes, and the multiple nodes correspond to multiple devices. The edges indicate that the devices corresponding to the nodes on the edges are connected, and the directions of the edges indicate the information transmission direction or oil and gas transmission direction between the devices corresponding to the nodes on the edges.

[0124] Optionally, the plurality of devices include but are not limited to: pipes, pumps, valves, sensors, controllers, or actuators.

[0125] For example, if the devices corresponding to the nodes on an edge are a pipe and a pump, the edge indicates a connection between the pipe and the pump, and the direction of the edge indicates the direction of oil and gas transmission between the pipe and the pump. If the oil and gas transmission direction is paint flowing from the pipe into the pump, the direction of the edge between the pipe and the pump is from the node corresponding to the pipe to the node corresponding to the pump.

[0126] For example, when the devices corresponding to the nodes on an edge are sensors and controllers, the edge indicates a connection between the sensor and the controller, and the direction of the edge indicates the direction of information transmission between the sensor and the controller. For example, if a sensor is responsible for real-time monitoring of oil and gas pressure in a pipeline, and after detecting the oil and gas pressure data, the sensor transmits the pressure data to the controller, the direction of the edge between the sensor and the controller is from the node corresponding to the sensor to the node corresponding to the controller.

[0127] The local clustering coefficient of a node indicates the degree of connection between the node and other nodes. It can also be understood that the local clustering coefficient of a node indicates the degree of connection between the device corresponding to the node and other devices.

[0128] In one possible implementation, constructing a target directed network of the oil and gas generation system based on device information of multiple devices in the oil and gas generation system and connection relationships between the multiple devices includes:

[0129] Determine device information of a plurality of devices of an oil and gas production system, and determine a plurality of physical devices and a plurality of information devices;

[0130] Determining a plurality of nodes according to a plurality of physical devices and a plurality of information devices of an oil and gas production system, wherein the plurality of nodes includes a plurality of physical nodes and a plurality of information nodes;

[0131] Determine the connection relationship between multiple devices;

[0132] Determine multiple edges based on the connection relationship between multiple devices;

[0133] Build a basic network based on multiple physical nodes;

[0134] Constructing a cyber-physical control feedback substructure based on multiple information nodes and multiple edges;

[0135] A cyber-physical control feedback substructure is embedded in the basic network to construct a target directed network for the oil and gas generation system.

[0136] S102: Determine the recovery time of the multiple nodes and the propagation time between every two nodes according to the local clustering coefficients of the multiple nodes.

[0137] In one possible implementation, the embodiment of the present application defines three time parameters, namely, disturbance duration, propagation duration, and recovery duration, based on the Influence Propagation and Recovery Model (IRML) method, to characterize the dynamic behavior of the functional failure of the oil and gas production system after the oil and gas production system is attacked.

[0138] The perturbation duration is the duration that a node is perturbed, or the duration that the perturbation is applied to the node. It can also be considered the duration of the disruption caused by the sudden event. The perturbation duration is related to the sudden event itself and is a custom parameter.

[0139] The propagation time between each two nodes is the time required for the functional failure of one node to cause the functional failure of another node, or the time interval from the functional failure of one node to the functional failure of another node.

[0140] The node recovery time is the time required for the node to recover from functional failure to functional validity, or in other words, the time interval from the beginning of recovery to the complete restoration of function after the node fails. It is used to represent the difficulty of node function recovery.

[0141] The recovery time of a node can be understood as the recovery time of the device corresponding to the node.

[0142] The propagation time between each two nodes can be understood as the propagation time between the two devices corresponding to the two nodes.

[0143] The disturbance duration of a node can be understood as the disturbance duration of the device corresponding to the node.

[0144] The duration that a node is disturbed can be understood as the duration that the node is under attack.

[0145] Node function failure can be understood as abnormal operation of the device corresponding to the node.

[0146] The node function is valid, which can be understood as the device corresponding to the node is running normally.

[0147] S103. When disturbing at least one first node among the multiple nodes, determine a failure propagation process according to a target directed network, a recovery time of the multiple nodes, a propagation time between every two nodes, and an initial time of the disturbance.

[0148] The failure propagation process includes the functional states of multiple nodes at the initial moment, the functional states at the end moment, and the functional states at multiple selected moments between the initial moment and the end moment. The end moment is the moment when the target directed network returns to normal.

[0149] Optionally, the recovery time of multiple failed nodes, the propagation time between multiple failed nodes, and the initial time of disturbing the first node are added to determine the end time.

[0150] The target directed network returns to normal, which can be understood as the oil and gas production system corresponding to the target directed network is functioning effectively, or each node in the target directed network is functioning effectively.

[0151] In one possible implementation, determining a failure propagation process based on a target directed network, recovery times of multiple nodes, propagation time between each two nodes, and an initial time of a disturbance includes:

[0152] Determine, according to the target directed network, a plurality of failed nodes, where the failed nodes are nodes among the plurality of nodes that are functionally failed or may be functionally failed when the first node is disturbed;

[0153] The failure propagation process is determined based on the recovery time of multiple nodes, the propagation time between every two nodes, and the initial time of the disturbance.

[0154] The failed nodes include one or more of the following: failed nodes and failed nodes to be propagated. A failed node is a node with a functional failure among multiple nodes, and a failed node to be propagated is a node that may have a functional failure among multiple nodes.

[0155] The failed nodes include a first node, which may be referred to as an initial failed node.

[0156] The failure nodes to be propagated refer to other nodes in the target directed network that are directly or indirectly affected by the failure of the first node and thus fail in function.

[0157] According to the target directed network and the multiple failed nodes, normal operating nodes can also be determined. The normal operating nodes are other nodes in the target directed network except the multiple failed nodes.

[0158] Figure 2 A schematic diagram of the failure propagation process at a certain moment provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the target directed network includes multiple nodes, including G1, G2, G3, G4, G5, G6, G7, G8, G9, G10, G11, G12, G13, G14, G15, and G16.

[0159] Among them, the first node is G9, the failed nodes are G8 and G9, the failed nodes to be propagated include G6, G7, G10, G11, G12, G13, G14, G15, and G16, and the normally operating nodes include G1, G2, G3, G4, and G5.

[0160] G9 points to G8, indicating that the direction of the edge is from G9 to G8, the node connected to the starting point of the edge is G9, and the node connected to the end point of the edge is G8.

[0161] S104: Determine, according to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of at least one first node.

[0162] Specifically, based on the functional status of multiple nodes at the initial moment, the functional status at the end moment, and the functional status at multiple selected moments between the initial moment and the end moment, the disturbance risk level of the risk path corresponding to the disturbance of at least one first node is determined.

[0163] The disturbance risk level is used to represent the degree of damage to the oil and gas production system caused by an attack on a device corresponding to at least one first node.

[0164] Perturbing at least one first node corresponds to a risk path.

[0165] The higher the disturbance risk level, the greater the degree of harm to the oil and gas production system caused by the attack on the device corresponding to at least one first node.

[0166] exist Figure 1 In an embodiment, by determining the local clustering coefficients of multiple nodes in a target directed network, determining the recovery time of multiple nodes and the propagation time between every two nodes, and then determining the failure propagation process of disturbing at least one first node, and then determining the disturbance risk level of the risk path corresponding to the disturbance of at least one first node, it is achieved that according to the disturbance risk levels of multiple risk paths, targeted security protection strategies for multiple risk paths are formulated to reduce the waste of security protection resources.

[0167] Figure 3 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 2 ,like Figure 3 As shown, the method includes:

[0168] S301. Execute the above S101-S103.

[0169] S302: Determine multiple target moments among the initial moment, the end moment, and multiple candidate moments.

[0170] The multiple target moments include an initial moment, an end moment, and at least one moment selected from multiple candidate moments.

[0171] In a possible implementation, the at least one moment selected from the multiple candidate moments may be: at least one moment randomly selected from the multiple candidate moments.

[0172] S303: Determine the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes.

[0173] The functional status of a node includes function failure and function validity.

[0174] The functional status of a node can be represented by a numerical value. For example, a disabled function is represented by 0, and a valid function is represented by 1.

[0175] In one possible implementation, determining the instantaneous functional states at multiple target moments based on the functional states of the multiple nodes at multiple target moments and the device types corresponding to the multiple nodes includes:

[0176] Determine the N device types corresponding to multiple nodes

[0177] Based on experience, determine N weights corresponding to N device types;

[0178] Determine the functional status of multiple nodes at multiple target moments according to the failure propagation process;

[0179] According to the functional states of multiple nodes at multiple target moments and N weights, the instantaneous functional state at the target moment is determined.

[0180] In a possible implementation, the instantaneous functional state at the target moment satisfies the following formula 1:

[0181]

[0182] Among them, t k represents the target time, r(t k ) represents the instantaneous functional state corresponding to the target moment, N represents the total number of device types corresponding to multiple nodes, α n Indicates the weight corresponding to type n, n = 1, ..., N, M n Indicates the total number of nodes corresponding to type n in multiple nodes, S nm (t k ) represents the functional state of node m among the nodes corresponding to type n at the target time, m = 1,…,M.

[0183] The instantaneous functional state at the target moment can be understood as the instantaneous functional state of the oil and gas production system at the target moment.

[0184] S304: Determine the disturbance risk level according to the instantaneous functional states at multiple target moments.

[0185] exist Figure 3 In this embodiment, multiple target moments are determined from the initial moment, the end moment, and multiple candidate moments; the instantaneous functional states at the multiple target moments are determined based on the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes; and the disturbance risk level is determined based on the instantaneous functional states at the multiple target moments. By using the above method, the instantaneous functional states at multiple preset moments are determined based on the functional states of the multiple nodes during the failure propagation process, and the disturbance risk level corresponding to the first node is then determined, which allows for a more accurate determination of the disturbance risk level.

[0186] Figure 4 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 3 ,like Figure 4 As shown, the method includes:

[0187] S401, S301-S303.

[0188] S402: Perform curve fitting processing on the instantaneous functional states at multiple target moments to obtain a safety toughness change curve.

[0189] It is worth noting that the curve fitting process can be found in the related art and will not be described in detail here.

[0190] Figure 5 A schematic diagram of a security toughness change curve provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the horizontal axis represents time, the vertical axis represents instantaneous functional status, and the solid dots represent the instantaneous functional status at the target moment.

[0191] When the function is valid as 1 and the function is invalid as 0, the range of the instantaneous function status is between 0-1.

[0192] t end Indicates the end time, t start Indicates the initial time.

[0193] S403: Determine the damage degree parameter, damage range parameter, and capability recovery parameter of the target directed network according to the security resilience change curve.

[0194] In one possible implementation, the damage degree parameter S1 satisfies the following formula 2:

[0195]

[0196] Among them, A represents the preset value associated with the end time and the initial time, t end Indicates the end time, t start represents the initial moment, R(t) represents the safety toughness change curve, ∫ represents the integral symbol, and dt represents the differential symbol.

[0197] Exemplarily, when the function validity indication is 1, the preset value associated with the end time and the initial time is the absolute value of the end time minus the initial time.

[0198] In one possible implementation, the damage range parameter S2 satisfies the following formula 3:

[0199] S2=1 / R min Formula 3;

[0200] Among them, R min Indicates the minimum value of R(t), / indicates division operation;

[0201] In a possible implementation, the capability recovery parameter S3 satisfies the following formula 4:

[0202]

[0203] Wherein, P represents the number of at least one sub-curve, and at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include R min The corresponding target time, t end , and R min The corresponding target time and t end The first curve is R(t) in the target time. min The curve between the corresponding target time and the end time, K p Indicates the slope of curve p in at least one subcurve.

[0204] The slope corresponding to the curve p can be understood as the ratio of the absolute value of the difference between the two instantaneous functional states corresponding to the first moments corresponding to the curve p and the absolute value of the difference between the two first moments.

[0205] In R(t) min When the difference between the corresponding target time and the end time is less than a first preset value, P is equal to 1, indicating that the target directed network can be quickly restored to function effectively. The first preset value is, for example, 5 hours.

[0206] After perturbing at least one first node among the plurality of nodes, the target directed network can be restored to be functionally valid, and the capability recovery parameter satisfies The target directed network cannot be restored to function effectively, and the capability recovery parameter satisfies S3=0.

[0207] The target directed network is functionally effective, which can be understood as each node in the target directed network is functionally effective, the oil and gas production system is functionally effective, or each device in the oil and gas production system is functionally effective.

[0208] S404: Determine the disturbance risk level based on the damage degree parameter, the damage range parameter, and the capability recovery parameter.

[0209] In one possible implementation, determining the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capability recovery parameter includes:

[0210] Determine the product of the damage degree parameter and the damage range parameter;

[0211] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.

[0212] The damage degree parameter, damage range parameter, capability recovery parameter, and disturbance risk level satisfy the following formula 8:

[0213]

[0214] Among them, D iIndicates the disturbance risk level corresponding to the i-th first node.

[0215] exist Figure 4 In an embodiment, a curve fitting process is performed on the instantaneous functional states at multiple target moments to obtain a safety resilience change curve; based on the safety resilience change curve, the damage degree parameter, damage range parameter, and capacity recovery parameter of the target directed network are determined; and based on the damage degree parameter, damage range parameter, and capacity recovery parameter, the disturbance risk level is determined. In the above method, by performing curve fitting process on the instantaneous functional states at multiple target moments to obtain a safety resilience change curve, and then determining the damage degree parameter, damage range parameter, and capacity recovery parameter of the target directed network based on the safety resilience change curve, the influence of subjective factors on the process from the disturbance of the first node to the propagation until the oil and gas generation system resumes effective function can be reduced, thereby improving the accuracy of determining the disturbance risk level.

[0216] Figure 6 Schematic diagram of a process for predicting information security threat risk paths in oil and gas production systems provided in an embodiment of the present application Figure 4 ,like Figure 6 As shown, the method includes:

[0217] S601: Construct an initial directed network of the oil and gas generation system according to device information of multiple devices in the oil and gas generation system and connection relationships between the multiple devices. The initial directed network includes multiple nodes and edges between the multiple nodes.

[0218] The edge indicates that there is a connection between the devices corresponding to the nodes on the edge, and the direction of the edge indicates the information transmission direction or oil and gas transmission direction between the devices corresponding to the nodes on the edge.

[0219] In one possible implementation, constructing an initial directed network of the oil and gas generation system based on device information of multiple devices in the oil and gas generation system and connection relationships between the multiple devices includes:

[0220] Determine device information of a plurality of devices of an oil and gas production system, and determine a plurality of physical devices and a plurality of information devices;

[0221] Determining a plurality of nodes according to a plurality of physical devices and a plurality of information devices of an oil and gas production system, wherein the plurality of nodes includes a plurality of physical nodes and a plurality of information nodes;

[0222] Determine the connection relationship between multiple devices;

[0223] Determine multiple edges based on the connection relationship between multiple devices;

[0224] Build a basic network based on multiple physical nodes;

[0225] Constructing a cyber-physical control feedback substructure based on multiple information nodes and multiple edges;

[0226] The cyber-physical control feedback substructure is embedded in the basic network to construct the initial directed network of the oil and gas generation system.

[0227] S602: Determine the average path length and average clustering coefficient of the initial directed network.

[0228] In one possible implementation, determining the average path length and the average clustering coefficient of the initial directed network includes:

[0229] Determine the average path length of the initial directed network;

[0230] Determine the average clustering coefficient of the initial directed network.

[0231] In one possible implementation, determining the average path length of the initial directed network includes:

[0232] According to the initial directed network, determine the shortest path length between every two nodes;

[0233] The average path length is determined according to the shortest path length between every two nodes and the total number of the multiple nodes.

[0234] Optionally, the average path length of the initial directed network satisfies the following formula 9:

[0235]

[0236] Among them, L regular represents the average path length of the initial directed network, W represents the total number of nodes, and d(x,y) represents the shortest path length between node x and node y in the initial directed network.

[0237] In one possible implementation, determining the average clustering coefficient of the initial directed network includes:

[0238] Determine the local clustering coefficient of each node;

[0239] The average clustering coefficient is determined according to the local clustering coefficient of each node and the total number of multiple nodes.

[0240] Optionally, the local clustering coefficient of the initial directed network satisfies the following formula 10:

[0241]

[0242] Among them, C regular represents the average clustering coefficient of the initial directed network, and C(i) represents the local clustering coefficient of node i.

[0243] S603: Determine the optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient of the initial directed network.

[0244] In a possible implementation, a genetic algorithm is used to determine the optimal reconnection probability of the initial directed network based on the average path length and the average clustering coefficient of the initial directed network.

[0245] S604: Adjust the edges between multiple nodes in the initial directed network according to the optimal reconnection probability to obtain a target directed network.

[0246] In one possible implementation, adjusting edges between multiple nodes in an initial directed network according to an optimal reconnection probability to obtain a target directed network includes:

[0247] For an edge in the initial directed network, randomly generate a random number in the range [0,1];

[0248] When the random number is less than the optimal reconnection probability, the node connected to the starting point of the edge remains unchanged, and a new node is selected in the initial directed network as the node connected to the end point of the edge to establish a new edge; the new node is a node in the initial directed network other than the node connected to the starting point of the edge and the node originally connected to the end point of the edge.

[0249] When the random number is greater than or equal to the optimal reconnection probability, no edge adjustment is made;

[0250] Repeat the above operations for all edges in the initial directed network to obtain the target directed network.

[0251] S605 : Determine a local clustering coefficient of the node according to the number of at least one neighboring node of the node and the number of edges between at least one neighboring node, where the multiple nodes are nodes in the target directed network.

[0252] In a possible implementation, the local clustering coefficient C(i) of node i among the multiple nodes satisfies the following formula 5:

[0253]

[0254] Among them, k i represents the number of at least one neighboring node of node i, e i Indicates the number of edges between adjacent vertices.

[0255] The range of the local clustering coefficient is greater than or equal to 0 and less than or equal to 1. The closer it is to 1, the higher the degree of node neighbor clustering.

[0256] S606: Determine the recovery time of the multiple nodes and the propagation time between every two nodes according to the local clustering coefficients of the multiple nodes.

[0257] In a possible implementation, the recovery time T of node i among multiple nodes is r (i) Satisfy the following formula 6:

[0258] T r (i)=C(i)·T rbase Formula 6;

[0259] Where C(i) represents the local clustering coefficient of node i, T rbase Indicates the basic recovery time, the value is 1 day.

[0260] In a possible implementation, the propagation time T between node i and node j among multiple nodes is p (i, j) satisfies the following formula 7:

[0261]

[0262] Where C(j) represents the local clustering coefficient of node j, T pbase Indicates the basic transmission duration, which is 1 day.

[0263] The local clustering coefficient of a node characterizes the degree of clustering of the node in the target directed network. The higher the local clustering coefficient, the more adjacent nodes there are around the node, and the more likely a fault on the node will spread to other nodes. When the node recovers, according to the dynamic propagation rule, the node can only be recovered if all parent nodes of the node are functionally valid. The higher the local clustering coefficient, the more parent nodes there may be (the parent node refers to the node connected to the starting point of the edge directly connected to the node in the target directed network), and the node is more difficult to recover and recovers more slowly. In an embodiment of the present application, the local clustering coefficients of multiple nodes are combined with the basic recovery time and the basic propagation time to determine the recovery time of multiple nodes and the propagation time between each two nodes. This can take into account the impact of the degree of clustering of different nodes in the target directed network on the recovery time and propagation time, thereby obtaining a more accurate recovery time and propagation time.

[0264] S607. When disturbing at least one first node among multiple nodes, determine the failure propagation process based on the target directed network, the recovery time of multiple nodes, the propagation time between every two nodes, and the initial time of the disturbance. The failure propagation process includes the functional status of the multiple nodes at the initial time, the functional status at the end time, and the functional status at multiple selected times between the initial time and the end time.

[0265] It is worth noting that the execution method of S607 is the same as that of S103, which will not be repeated here.

[0266] S608: Determine multiple target moments from the initial moment, the end moment, and multiple candidate moments.

[0267] It is worth noting that the execution method of S608 is the same as that of S302, which will not be repeated here.

[0268] S609: Determine the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes.

[0269] It is worth noting that the execution method of S610 is the same as that of S303, which will not be repeated here.

[0270] S610: Perform curve fitting processing on the instantaneous functional states at multiple target moments to obtain a safety toughness change curve.

[0271] It is worth noting that the execution method of S611 is the same as that of S402, and will not be repeated here.

[0272] S611. Determine the damage degree parameter, damage range parameter, and capability recovery parameter of the target directed network based on the security resilience change curve.

[0273] It is worth noting that the execution method of S612 is the same as that of S403 and will not be repeated here.

[0274] S612. Determine the disturbance risk level based on the damage degree parameter, damage range parameter, and capability recovery parameter.

[0275] It is worth noting that the execution method of S613 is the same as that of S404, and will not be repeated here.

[0276] exist Figure 6 In one embodiment, an initial directed network of the oil and gas generation system is constructed based on device information of multiple devices in the oil and gas generation system and the connection relationships between the multiple devices; the average path length and average clustering coefficient of the initial directed network are determined; the optimal reconnection probability of the initial directed network is determined based on the average path length and average clustering coefficient; and based on the optimal reconnection probability, the edges between multiple nodes in the initial directed network are adjusted to obtain a target directed network. In this method, adjusting the initial directed network using the optimal reconnection probability to obtain the target directed network can produce a target directed network that better fits the oil and gas generation system, thereby improving the accuracy of determining the disturbance risk level.

[0277] The following combination Figure 7 , the process of determining the optimal reconnection probability of an initial directed network using a genetic algorithm is explained.

[0278] Figure 7 A flow chart of a method for determining an optimal reconnection probability provided in an embodiment of the present application is shown as follows: Figure 8 As shown, the method includes:

[0279] S701. Randomly generate multiple first individuals in the range of [0, 1] to construct an initial population. The initial population includes multiple first individuals, and the total number of the multiple first individuals is a.

[0280] For example, randomly generate a first individual in the range [0,1] to form the initial population A={A1,A2,…,A a}.

[0281] S702: Determine a fitness function formula based on the average path length and average clustering coefficient of the initial directed network.

[0282] In one possible implementation, a fitness function formula is determined based on the average path length and average clustering coefficient of the initial directed network, including:

[0283] Determine the expected average path length and the expected average clustering coefficient according to the average path length and the average clustering coefficient of the initial directed network;

[0284] The fitness function formula is determined based on the expected average clustering coefficient and the expected average path length.

[0285] Optionally, the average path length of the initial directed network and the expected average path length satisfy the following formula 11:

[0286] L g =a·log b (L regular W) + c Formula 11;

[0287] Among them, L g represents the expected average path length, L regular represents the average path length of the initial directed network, log represents the logarithmic function, a, b, and c represent parameters, which are selected based on experience, and W represents the total number of nodes in the initial directed network.

[0288] Optionally, the average clustering coefficient and the expected average clustering coefficient of the initial directed network satisfy the following formula 12:

[0289] C g =C regular (1-d) 3 Formula 12;

[0290] Among them, C g represents the expected average clustering coefficient, C regularrepresents the average path length of the initial directed network, and d represents a randomly generated random number in the range of [0, 1].

[0291] In one possible implementation, the fitness function formula satisfies the following formula 13:

[0292]

[0293] Among them, F(A a` ) represents individual A a` The fitness value, ω1, ω2 represent weight coefficients, L g represents the expected average path length, C g represents the expected average clustering coefficient, L regular (A a` ) represents individual A a` The corresponding average path length, C regular (A a` ) represents individual A a` The corresponding average clustering coefficient.

[0294] Optionally, ω1 and ω2 are determined based on experience, and ω2>ω1 is satisfied.

[0295] Individual A a` The corresponding average path length is: According to individual A a` The average path length of the process directed network is obtained by adjusting the edges between multiple nodes in the initial directed network.

[0296] Individual A a` The corresponding average clustering coefficient is: According to individual A a` The average clustering coefficient of the process directed network is obtained by adjusting the edges between multiple nodes in the initial directed network.

[0297] It is worth noting that “according to individual A a` The execution method of “adjusting the edges between the multiple nodes in the initial directed network to obtain the process directed network” is similar to the execution method of S604 and will not be repeated here.

[0298] S703: Substitute each individual in the initial population into the fitness function formula to determine the fitness vector corresponding to the initial population.

[0299] The fitness vector corresponding to the initial population includes the fitness value of each individual in the initial population.

[0300] S704. Using the tournament selection method, determine multiple second individuals based on the nth population. Initially, n=1, and the first population is the initial population.

[0301] The total number of the plurality of second individuals is equal to the total number of the plurality of first individuals.

[0302] It is worth noting that the specific implementation method of S704 can be found in the relevant technology and will not be described here in detail.

[0303] S705: Perform cross processing on every two individuals among the plurality of second individuals to determine a plurality of third individuals.

[0304] In a possible implementation, the following formula 14 is satisfied between the two second individuals and the third individual:

[0305] A new =α·A i +(1-α)·A j Formula 14;

[0306] Among them, A new Represents the third individual, A i ,A j represents the i-th second individual and the j-th second individual, α represents the cross-proportional coefficient, and the cross-proportional coefficient is randomly generated and ranges from [0, 1].

[0307] S706. Mutate the plurality of third individuals with a certain probability to determine a plurality of fourth individuals.

[0308] In a possible implementation, the relationship between a third individual and a fourth individual satisfies the following formula 15:

[0309] A mutated =A new +β rand(-1,1) Formula 15;

[0310] Among them, A mutated represents the fourth individual, β represents the variation amplitude, which is 0.3, and rand(-1,1) represents a random number greater than -1 and less than 1.

[0311] S707: Substitute the plurality of third individuals and the plurality of fourth individuals into the fitness function formula respectively to determine the fitness values of the plurality of third individuals and the plurality of fourth individuals.

[0312] S708. Sort the fitness values of the plurality of third individuals and the plurality of fourth individuals, and determine the first a individuals as the (n+1)th population.

[0313] S709: Substitute each individual in the (n+1)th population into the fitness function formula to determine the fitness vector corresponding to the (n+1)th population.

[0314] The fitness vector corresponding to the (n+1)th population includes the fitness value of each individual in the (n+1)th population.

[0315] S710: Determine whether the absolute value of the difference between the fitness vector corresponding to the (n+1)th population and the fitness vector corresponding to the nth population is less than a second preset value.

[0316] If so, execute S711; otherwise, execute S704.

[0317] In one possible implementation, the fitness vector corresponding to the (n+1)th population is subtracted from the fitness vector corresponding to the nth population, including:

[0318] Determine the first average value of the fitness vector corresponding to the (n+1)th population;

[0319] Determine the second average value of the fitness vector corresponding to the nth population;

[0320] The absolute value of the first average value minus the second average value is determined.

[0321] The second preset value is, for example, 0.1 or 0.01.

[0322] S711. Determine the best individual according to the fitness vector corresponding to the (n+1)th population.

[0323] In one implementation, determining the best individual according to the fitness vector corresponding to the (n+1)th population includes:

[0324] Sort all fitness values contained in the fitness vector corresponding to the (n+1)th population;

[0325] The individual with the highest fitness value after sorting is determined to be the best individual.

[0326] S712: Determine whether the average clustering coefficient corresponding to the best individual and the average path length corresponding to the best individual meet the determination conditions of the small-world network.

[0327] In a possible implementation, determining whether the average clustering coefficient corresponding to the best individual and the average path length corresponding to the best individual meet the determination conditions of a small-world network includes:

[0328] It is determined whether the absolute value of the difference between the average clustering coefficient corresponding to the best individual and the expected average clustering coefficient is less than a third preset value, and whether the absolute value of the difference between the average path length corresponding to the best individual and the expected average path length is less than a fourth preset value.

[0329] Optionally, the third preset value is, for example, 0.01, and the fourth preset value is, for example, 0.01.

[0330] If so, execute S713; otherwise, execute S701.

[0331] S713: Determine the best individual as the optimal reconnection probability.

[0332] Figure 8 A schematic diagram of the structure of the oil and gas production system information security threat risk path prediction device provided in the embodiment of the present application is shown as follows: Figure 8 As shown, the oil and gas production system information security threat risk path prediction device 80 provided in the embodiment of the present application includes:

[0333] An acquisition module 801 is configured to acquire local clustering coefficients of a plurality of nodes, wherein the plurality of nodes are nodes in a target directed network constructed based on the oil and gas generation system, and the plurality of nodes correspond to the plurality of devices;

[0334] Determination module 802 is configured to determine, based on the local clustering coefficients of the multiple nodes, a recovery duration of the multiple nodes and a propagation duration between each two nodes; the recovery duration is the time required for the node to recover from a functional failure to become functionally valid, and the propagation duration is the time required for the functional failure of one node to cause the functional failure of another node;

[0335] The determining module 802 is further configured to, when perturbing at least one of the plurality of nodes, determine a failure propagation process based on the target directed network, the recovery time of the plurality of nodes, the propagation time between each two nodes, and the initial time of the perturbation, wherein the failure propagation process includes functional states of the plurality of nodes at the initial time, functional states at the end time, and functional states at a plurality of selected times between the initial time and the end time; the end time being the time when the target directed network returns to normal;

[0336] The determination module 802 is further used to determine the disturbance risk level of the risk path corresponding to the disturbance of the at least one node based on the failure propagation process, and the disturbance risk level is used to characterize the degree of harm to the oil and gas production system when at least one device corresponding to the at least one node is attacked.

[0337] It should be noted here that the oil and gas production system information security threat risk path prediction device 80 provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.

[0338] In a possible implementation, the determining module 802 is specifically configured to:

[0339] Determining a plurality of target moments among the initial moment, the end moment, and the plurality of candidate moments;

[0340] Determining the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes;

[0341] The disturbance risk level is determined according to the instantaneous functional states at the multiple target moments.

[0342] In a possible implementation, the instantaneous functional state at the target moment satisfies the following formula 1:

[0343]

[0344] Among them, t k represents the target time, r(t k ) represents the instantaneous functional state corresponding to the target moment, N represents the total number of device types corresponding to the multiple nodes, α n Indicates the weight corresponding to type n, M n represents the total number of nodes corresponding to the type n in the plurality of nodes, S nm (t k ) represents the functional status of node m among the nodes corresponding to the type n at the target moment.

[0345] In a possible implementation, the determining module 802 is specifically configured to:

[0346] Performing curve fitting processing on the instantaneous functional states at the multiple target moments to obtain a safety toughness change curve;

[0347] Determining a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the security resilience change curve;

[0348] The disturbance risk level is determined according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter.

[0349] In a possible implementation, the damage degree parameter S1 satisfies the following formula 2:

[0350]

[0351] Wherein, A represents the preset value associated with the end time and the initial time, t end represents the end time, t start represents the initial moment, R(t) represents the safety toughness change curve, ∫ represents the integral symbol, and dt represents the differential symbol;

[0352] The damage range parameter S2 satisfies the following formula 3:

[0353] S2=1 / R min Formula 3;

[0354] Among them, R min Indicates the minimum value of R(t), / indicates division operation;

[0355] The capability recovery parameter S3 satisfies the following formula 4:

[0356]

[0357] Wherein, P represents the number of at least one sub-curve, and the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include R min The corresponding target time, t end , and the R min The corresponding target time and t end The first curve is R(t) min The curve between the corresponding target time and the end time, K p represents the slope corresponding to the curve p in the at least one sub-curve.

[0358] In a possible implementation, the determining module 802 is specifically configured to:

[0359] determining the product of the damage extent parameter and the damage range parameter;

[0360] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.

[0361] In a possible implementation, the acquisition module 801 is specifically configured to:

[0362] The local clustering coefficient of the node is determined according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point.

[0363] In a possible implementation, the local clustering coefficient C(i) of node i among the multiple nodes satisfies the following formula 5:

[0364]

[0365] Among them, k i represents the number of neighboring nodes of the node i, e i Indicates the number of edges between the adjacent points.

[0366] In a possible implementation, the recovery time T of node i among the multiple nodes is r (i) Satisfy the following formula 6:

[0367] T r (i)=C(i)·T rbase Formula 6;

[0368] Where C(i) represents the local clustering coefficient of the node i, T rbase Indicates the basic recovery time;

[0369] The propagation time T between node i and node j among the multiple nodes p (i, j) satisfies the following formula 7:

[0370]

[0371] Where C(j) represents the local clustering coefficient of the node j, T pbase Indicates the basic transmission time.

[0372] In a possible implementation, the determining module 802 is further configured to:

[0373] constructing an initial directed network of the oil and gas generation system based on device information of the plurality of devices in the oil and gas generation system and connection relationships between the plurality of devices, the initial directed network comprising the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the directions of the edges indicating an information transmission direction or an oil and gas transmission direction between the devices corresponding to the nodes on the edges;

[0374] Determining an average path length and an average clustering coefficient of the initial directed network;

[0375] determining an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;

[0376] According to the optimal reconnection probability, edges between the multiple nodes in the initial directed network are adjusted to obtain the target directed network.

[0377] It should be noted here that the oil and gas production system information security threat risk path prediction device 80 provided in the embodiment of the present application can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as the method embodiment will not be described in detail here.

[0378] It should be understood that the oil and gas production system information security threat risk path prediction device 80 is embodied in the form of a functional module. The term "module" herein may refer to an application-specific integrated circuit (ASIC), an electronic circuit, a processor (e.g., a shared processor, a dedicated processor, or a group processor, etc.) and memory for executing at least one software or firmware program, a combined logic circuit, and / or other suitable components that support the described functionality.

[0379] Figure 9 This is a structural diagram of an electronic device provided in an embodiment of the present application. Figure 9 As shown, the electronic device 90 includes a processor 901 and a memory 902. The processor 901 is in communication with the memory 902, and the memory 902 is used to store computer-executable instructions. The processor 901 is configured to execute the technical solution of any of the aforementioned method embodiments by executing the computer-executable instructions stored in the memory 902.

[0380] Optionally, the memory 902 may be independent or integrated with the processor 901. Optionally, when the memory 902 is a device independent of the processor 901, the electronic device 900 may further include a bus 903 for connecting the above devices.

[0381] The electronic device is used to execute the technical solution in any of the aforementioned method embodiments, and its implementation principles and technical effects are similar and will not be repeated here.

[0382] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules in the processor.

[0383] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.

[0384] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.

[0385] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0386] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.

[0387] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0388] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in a device as discrete components.

[0389] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.

[0390] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0391] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0392] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.

[0393] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0394] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.

Claims

1. A method for predicting information security threat risk paths in an oil and gas production system, wherein the oil and gas production system includes multiple devices, characterized in that: include: Obtaining local clustering coefficients of a plurality of nodes, the plurality of nodes being nodes in a target directed network constructed based on the oil and gas generation system, the plurality of nodes corresponding to the plurality of devices; Determining, based on the local clustering coefficients of the multiple nodes, the recovery duration of the multiple nodes and the propagation duration between every two nodes; The recovery duration is the time required for the node to recover from functional failure to functional validity, and the propagation duration is the time required for the functional failure of one node to cause the functional failure of another node; When perturbing at least one first node among the plurality of nodes, determining a failure propagation process based on the target directed network, the recovery time of the plurality of nodes, the propagation time between each two nodes, and the initial time of the perturbation, the failure propagation process including functional states of the plurality of nodes at the initial time, functional states at the end time, and functional states at a plurality of selected times between the initial time and the end time; the end time being the time when the target directed network returns to normal; According to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one first node is determined, and the disturbance risk level is used to characterize the degree of harm to the oil and gas production system caused by the attack on at least one device corresponding to the at least one first node.

2. The method according to claim 1, characterized in that The determining, according to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one first node includes: Determining a plurality of target moments among the initial moment, the end moment, and the plurality of candidate moments; Determining the instantaneous functional states of the multiple target moments according to the functional states of the multiple nodes at the multiple target moments and the device types corresponding to the multiple nodes; The disturbance risk level is determined according to the instantaneous functional states at the multiple target moments.

3. The method according to claim 2, characterized in that The instantaneous functional state at the target moment satisfies the following formula 1: Among them, t k represents the target time, r(t k ) represents the instantaneous functional state corresponding to the target moment, N represents the total number of device types corresponding to the multiple nodes, α n Indicates the weight corresponding to type n, M n represents the total number of nodes corresponding to the type n in the plurality of nodes, S nm (t k ) represents the functional status of node m among the nodes corresponding to the type n at the target moment.

4. The method according to claim 3, characterized in that The determining the disturbance risk level according to the instantaneous functional states at the multiple target moments includes: Performing curve fitting processing on the instantaneous functional states at the multiple target moments to obtain a safety toughness change curve; Determining a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the security resilience change curve; The disturbance risk level is determined according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter.

5. The method according to claim 4, characterized in that The damage degree parameter S1 satisfies the following formula 2: Wherein, A represents the preset value associated with the end time and the initial time, t end represents the end time, t start represents the initial moment, R(t) represents the safety toughness change curve, ∫ represents the integral symbol, and dt represents the differential symbol; The damage range parameter S2 satisfies the following formula 3: S2=1 / R min Formula 3; Among them, R min Indicates the minimum value of R(t), / indicates division operation; The capability recovery parameter S3 satisfies the following formula 4: Wherein, P represents the number of at least one sub-curve, and the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include R min The corresponding target time, t end , and the R min The corresponding target time and t end The first curve is R(t) min The curve between the corresponding target time and the end time, K p represents the slope corresponding to the curve p in the at least one sub-curve.

6. The method according to claim 4, characterized in that The determining the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capability recovery parameter includes: determining the product of the damage extent parameter and the damage range parameter; The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.

7. The method according to any one of claims 1 to 6, characterized in that Obtaining a local clustering coefficient of a node in the target directed network includes: Determining a local clustering coefficient of the node according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point; The local clustering coefficient C(i) of node i among the multiple nodes satisfies the following formula 5: Among them, k i represents the number of neighboring nodes of the node i, e i Indicates the number of edges between the adjacent points.

8. The method according to any one of claims 1 to 6, characterized in that The recovery time T of node i among the multiple nodes r (i) Satisfy the following formula 6: T r (i)=C(i)·T rbase Formula 6; Where C(i) represents the local clustering coefficient of the node i, T rbase Indicates the basic recovery time; The propagation time T between node i and node j among the multiple nodes p (i, j) satisfies the following formula 7: Where C(j) represents the local clustering coefficient of the node j, T pbase Indicates the basic propagation time.

9. The method according to any one of claims 1 to 6, characterized in that The method further comprises: constructing an initial directed network of the oil and gas generation system based on device information of the plurality of devices in the oil and gas generation system and connection relationships between the plurality of devices, the initial directed network comprising the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the directions of the edges indicating an information transmission direction or an oil and gas transmission direction between the devices corresponding to the nodes on the edges; Determining an average path length and an average clustering coefficient of the initial directed network; determining an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient; According to the optimal reconnection probability, edges between the multiple nodes in the initial directed network are adjusted to obtain the target directed network.

10. A device for predicting information security threat risk paths in an oil and gas production system, wherein the oil and gas production system comprises a plurality of devices, characterized in that: include: an acquisition module, configured to acquire local clustering coefficients of a plurality of nodes, wherein the plurality of nodes are nodes in a target directed network constructed based on the oil and gas generation system, and the plurality of nodes correspond to the plurality of devices; a determination module, configured to determine, based on the local clustering coefficients of the multiple nodes, the recovery duration of the multiple nodes and the propagation duration between every two nodes; The recovery duration is the time required for the node to recover from functional failure to functional validity, and the propagation duration is the time required for the functional failure of one node to cause the functional failure of another node; The determination module is further configured to, when perturbing at least one of the plurality of nodes, determine a failure propagation process based on the target directed network, the recovery time of the plurality of nodes, the propagation time between each two nodes, and the initial time of the perturbation, wherein the failure propagation process includes functional states of the plurality of nodes at the initial time, functional states at the end time, and functional states at a plurality of selected times between the initial time and the end time; the end time being the time when the target directed network returns to normal; The determination module is further used to determine the disturbance risk level of the risk path corresponding to the disturbance of the at least one node based on the failure propagation process, and the disturbance risk level is used to characterize the degree of harm to the oil and gas production system when at least one device corresponding to the at least one node is attacked.

Citation Information

Patent Citations

  • Oil and gas pipeline information physical safety intelligent risk identification method, device and equipment

    CN116066754A

  • Identifying multiple causal anomalies in power plant systems by modeling local propagations

    US20180307994A1

  • Artificial Intelligence-based Quantified Cyber Defense Control Model

    US20240314158A1