Oil and gas production system information security threat risk path prediction method and device
By analyzing the local clustering coefficient and propagation time of nodes in the oil and gas production system, calculating the disturbance risk level, and formulating targeted security protection strategies, the problem of complex attack paths caused by equipment interconnection was solved, and efficient resource utilization and effective risk control were achieved.
Patent Information
- Application Number
- CN202510586049.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-05-07
AI Technical Summary
The interconnectedness of cyber-physical systems in oil and gas production systems leads to overly complex attack paths, requiring substantial security resources.
By obtaining the local clustering coefficients of multiple nodes, the node recovery time and propagation time are determined, the failure propagation process is analyzed, the disturbance risk level is calculated, and targeted security protection strategies are formulated.
It reduces the waste of security resources, improves the effectiveness of targeted protection, and reduces the risk of the spread and diffusion of information threats.
Smart Images

Figure CN120455292B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the industrial field, and in particular to an oil and gas production system information security threat risk path prediction method and device. BACKGROUND
[0002] In the industrial field, the supply safety of oil and gas resources is usually realized through an oil and gas production system - cyber physical system (OGP-CPS).
[0003] In the related art, the OGP-CPS realizes the construction of a device corresponding information space twin through the collection, transmission and analysis of real-time data of devices in the oil and gas production system in the information layer thereof, and through the information space twin, the behavior and state of the device can be reflected.
[0004] However, the OGP-CPS connects multiple devices in the information layer, so that the originally relatively independent devices are connected with each other, resulting in that an attack on a certain device of the oil and gas production system can realize an attack on other devices directly or indirectly connected therewith, the attack means of the oil and gas production system is too much, resulting in that the risk path is too complex, and more security protection resources need to be invested for the security protection of the oil and gas production system. SUMMARY
[0005] The embodiments of the present application provide an oil and gas production system information security threat risk path prediction method and device to determine the disturbance risk level of multiple risk paths of the oil and gas production system, and to realize the targeted security protection of the oil and gas production system and reduce the waste of resources.
[0006] In a first aspect, the embodiments of the present application provide an oil and gas production system information security threat risk path prediction method, comprising:
[0007] Obtaining local clustering coefficients of multiple nodes, the multiple nodes being nodes in a target directed network constructed based on the oil and gas production system, the multiple nodes corresponding to the multiple devices;
[0008] According to the local clustering coefficients of the multiple nodes, determining a recovery time length of the multiple nodes and a propagation time length between each two nodes; the recovery time length being a time length required for the node to recover from functional failure to functional validity, and the propagation time length being a time length required for the functional failure of one node to cause the functional failure of another node;
[0009] determine, according to the target directed network, the recovery time length of the plurality of nodes, the propagation time length between each two nodes, and an initial time of the perturbation, a failure propagation process including the functional state of the plurality of nodes at the initial time, the functional state at an ending time, and the functional state of the plurality of candidate times between the initial time and the ending time; the ending time is the time when the target directed network recovers to normal;
[0010] According to the failure propagation process, determine the perturbation risk level of the risk path corresponding to the perturbation of the at least one first node, the perturbation risk level is used to represent the damage degree of the at least one device corresponding to the at least one first node being attacked to the oil and gas production system.
[0011] In a possible implementation, the determining, according to the failure propagation process, the perturbation risk level of the risk path corresponding to the perturbation of the at least one first node includes:
[0012] Among the initial time, the ending time and the plurality of candidate times, a plurality of target times are determined;
[0013] According to the functional state of the plurality of nodes at the plurality of target times and the device type corresponding to the plurality of nodes, determine the instantaneous functional state of the plurality of target times;
[0014] According to the instantaneous functional state of the plurality of target times, determine the perturbation risk level.
[0015] In a possible implementation, the instantaneous functional state of the target time satisfies the following formula 1:
[0016] Formula 1;
[0017] Wherein, t represents the target time, f (t) represents the instantaneous functional state corresponding to the target time t, N represents the total number of device types corresponding to the plurality of nodes, N represents the type corresponding weight, N represents the total number of nodes of the type corresponding to the plurality of nodes, N represents the node of the type corresponding to the plurality of nodes, at the target time.
[0018] In a possible implementation, the determining the disturbance risk level according to the instantaneous function states of the plurality of target time instants comprises:
[0019] performing curve fitting processing on the instantaneous function states of the plurality of target time instants to obtain a safety resilience change curve;
[0020] determining a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the safety resilience change curve;
[0021] determining the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capability recovery parameter.
[0022] In a possible implementation, the damage degree parameter satisfies the following formula 2:
[0023] Formula 2
[0024] wherein, denotes a preset value associated with the end time instant and the initial time instant, denotes the end time instant, denotes the initial time instant, denotes the safety resilience change curve, and ∫ denotes an integral sign, denotes a differential sign.
[0025] The damage range parameter satisfies the following formula 3:
[0026] Formula 3
[0027] wherein, denotes a minimum value of , and / denotes a division operation.
[0028] The capability recovery parameter satisfies the following formula 4:
[0029] Formula 4
[0030] wherein, denotes a number of at least one sub-curve, the at least one sub-curve being a curve obtained by dividing a first curve according to at least two first time instants, the at least two first time instants including a corresponding target time instant, , and a target time instant between the corresponding target time instant and , the first curve being in the safety resilience change curve. The curve between the corresponding target time and the end time, represents a curve in the at least one sub-curve The corresponding slope.
[0031] In a possible implementation, determining the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capacity recovery parameter includes:
[0032] determining the product of the damage extent parameter and the damage range parameter;
[0033] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.
[0034] In a possible implementation, obtaining a local clustering coefficient of a node in the target directed network includes:
[0035] Determining a local clustering coefficient of the node according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point;
[0036] a node among the plurality of nodes The local clustering coefficient Satisfies the following formula 5:
[0037] Formula 5;
[0038] in, Represents the node The number of neighbors of Indicates the number of edges between the adjacent points.
[0039] In a possible implementation manner, a node among the multiple nodes Recovery time Satisfies the following formula 6:
[0040] Formula 6;
[0041] in, Represents the node The local clustering coefficient, Indicates the basic recovery time;
[0042] a node among the plurality of nodes The propagation time between node j The following formula 7 is satisfied:
[0043] Formula 7;
[0044] in, a local clustering coefficient of the node representing a basic propagation duration.
[0045] In a possible implementation, the method further includes:
[0046] constructing an initial directed network of the oil and gas production system according to device information of the plurality of devices and a connection relationship between the plurality of devices, the initial directed network including the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between devices corresponding to a pair of nodes on the edge, and a direction of the edge indicating a direction of information transmission or oil and gas transmission between the devices corresponding to the pair of nodes on the edge;
[0047] determining an average path length and an average clustering coefficient of the initial directed network;
[0048] determining an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;
[0049] adjusting the edges between the plurality of nodes in the initial directed network according to the optimal reconnection probability to obtain the target directed network.
[0050] In a second aspect, an embodiment of the present application provides a safety simulation device of an oil and gas production system, including:
[0051] an obtaining module configured to obtain local clustering coefficients of a plurality of nodes, the plurality of nodes being nodes in a target directed network constructed based on the oil and gas production system, and the plurality of nodes corresponding to the plurality of devices;
[0052] a determining module configured to determine, according to the local clustering coefficients of the plurality of nodes, a recovery duration of the plurality of nodes and a propagation duration between each pair of nodes, the recovery duration being a duration required for a node to recover from functional failure to functional validity, and the propagation duration being a duration required for functional failure of one node to lead to functional failure of another node;
[0053] the determining module is further configured to, when at least one node in the plurality of nodes is disturbed, determine, according to the target directed network, the recovery duration of the plurality of nodes, the propagation duration between each pair of nodes, and an initial time of the disturbance, a failure propagation process, the failure propagation process including functional states of the plurality of nodes at the initial time, at an end time, and at a plurality of candidate times between the initial time and the end time; and the end time being a time when the target directed network recovers to normal.
[0054] The determining module is further configured to determine, according to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one node, the disturbance risk level being used to represent a degree of harm to the oil and gas production system caused by an attack on at least one device corresponding to the at least one node.
[0055] In a possible implementation, the determining module is specifically configured to:
[0056] determine a plurality of target time points from among the initial time point, the end time point, and the plurality of candidate time points;
[0057] determine, according to the functional states of the plurality of nodes at the plurality of target time points and the device types corresponding to the plurality of nodes, instantaneous functional states of the plurality of target time points;
[0058] determine the disturbance risk level according to the instantaneous functional states of the plurality of target time points.
[0059] In a possible implementation, the instantaneous functional state of the target time point satisfies the following formula 1:
[0060] Formula 1
[0061] wherein, t represents the target time point, f(t) represents the instantaneous functional state of the target time point, N represents a total number of the device types corresponding to the plurality of nodes, Nt represents a type corresponding weight, Nn represents a total number of nodes of the type corresponding to the plurality of nodes, Nn represents a node of the type corresponding node at the target time point.
[0062] In a possible implementation, the determining module is specifically configured to:
[0063] perform curve fitting processing on the instantaneous functional states of the plurality of target time points to obtain a security resilience change curve;
[0064] determine, according to the security resilience change curve, a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network;
[0065] determine the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capability recovery parameter.
[0066] In one possible implementation, the damage degree parameter Satisfies the following formula 2:
[0067] Formula 2;
[0068] in, represents a preset value associated with the end time and the initial time, represents the end time, represents the initial time, represents the safety toughness change curve, ∫ represents the integral symbol, represents the differential symbol;
[0069] The damage range parameters Satisfies the following formula 3:
[0070] Formula 3;
[0071] in, express The minimum value of , / represents the division operation;
[0072] The capability recovery parameter Satisfies the following formula 4:
[0073] Formula 4;
[0074] in, represents the number of at least one sub-curve, wherein the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, wherein the at least two first moments include The corresponding target time, , and the The corresponding target time and The first curve is middle The curve between the corresponding target time and the end time, represents a curve in the at least one sub-curve The corresponding slope.
[0075] In a possible implementation, the determining module is specifically configured to:
[0076] determining the product of the damage extent parameter and the damage range parameter;
[0077] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.
[0078] In a possible implementation, the acquisition module is specifically configured to:
[0079] Determining a local clustering coefficient of the node according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point;
[0080] a node among the plurality of nodes The local clustering coefficient Satisfies the following formula 5:
[0081] Formula 5;
[0082] in, Represents the node The number of neighbors of Indicates the number of edges between the adjacent points.
[0083] In a possible implementation manner, a node among the multiple nodes Recovery time Satisfies the following formula 6:
[0084] Formula 6;
[0085] in, Represents the node The local clustering coefficient, Indicates the basic recovery time;
[0086] a node among the plurality of nodes The propagation time between node j The following formula 7 is satisfied:
[0087] Formula 7;
[0088] in, Represents the node The local clustering coefficient, Indicates the basic transmission time.
[0089] In a possible implementation, the determining module is further configured to:
[0090] constructing an initial directed network of the oil and gas production system based on the device information of the plurality of devices in the oil and gas production system and the connection relationships between the plurality of devices, the initial directed network including the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the directions of the edges indicating the direction of information transmission or oil and gas transmission between the devices corresponding to the nodes on the edges;
[0091] determine an average path length and an average clustering coefficient of the initial directed network;
[0092] determine an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;
[0093] adjust edges between the plurality of nodes in the initial directed network according to the optimal reconnection probability, to obtain the target directed network.
[0094] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory, a processor;
[0095] The memory stores computer-executable instructions.
[0096] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.
[0097] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.
[0098] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.
[0099] The oil and gas production system information security threat risk path prediction method and device provided by the embodiments of the present application determine the recovery duration of the plurality of nodes and the propagation duration between each two nodes according to the local clustering coefficients of the plurality of nodes, determine the failure propagation process according to the target directed network, the recovery duration of the plurality of nodes, the propagation duration between each two nodes, and the initial time of the disturbance when at least one first node in the plurality of nodes is disturbed, determine the disturbance risk level of the risk path corresponding to the disturbance of the at least one first node according to the failure propagation process, and then implement the security protection strategy of the plurality of risk paths according to the disturbance risk levels of the plurality of risk paths, so as to timely block the propagation and expansion of information threats and reduce the waste of security protection resources. BRIEF DESCRIPTION OF DRAWINGS
[0100] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and serve to explain the principles of the present application together with the specification.
[0101] Figure 1A flowchart of a method for predicting a security threat risk path of an oil and gas production system according to an embodiment of the present application Figure One ;
[0102] Figure 2 A schematic diagram of a failure propagation process at a certain moment according to an embodiment of the present application
[0103] Figure 3 A flowchart of a method for predicting a security threat risk path of an oil and gas production system according to an embodiment of the present application Figure Two ;
[0104] Figure 4 A flowchart of a method for predicting a security threat risk path of an oil and gas production system according to an embodiment of the present application Figure Three ;
[0105] Figure 5 A schematic diagram of a security resilience change curve according to an embodiment of the present application
[0106] Figure 6 A flowchart of a method for predicting a security threat risk path of an oil and gas production system according to an embodiment of the present application Figure Four ;
[0107] Figure 7 A flowchart of a method for determining an optimal reconnection probability according to an embodiment of the present application
[0108] Figure 8 A schematic diagram of a device for predicting a security threat risk path of an oil and gas production system according to an embodiment of the present application
[0109] Figure 9 A structural diagram of an electronic device according to an embodiment of the present application
[0110] The specific embodiments of the present application have been shown by the above-described drawings, and will be described in more detail hereinafter. These drawings and written descriptions are not intended to limit the scope of the present application concept in any way, but to illustrate the present application concept to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0111] The exemplary embodiments will be described in detail herein below with reference to the drawings. In the following description, the same drawings reference numbers are used to denote like or similar elements. The embodiments described in the following exemplary embodiments are not representative of all embodiments consistent with the present application. Rather, they are merely examples of devices and methods consistent with some aspects of the present application, as detailed in the appended claims.
[0112] In the embodiments of the present application, the same items or similar items with basically the same functions and effects are distinguished by using "first", "second", and the like. For example, the first value and the second value are only used to distinguish different values, and the order is not limited. Those skilled in the art can understand that "first", "second", and the like do not limit the quantity and execution order, and "first", "second", and the like do not necessarily mean different.
[0113] It should be noted that in the embodiments of the present application, the words "exemplarily" or "for example" are used to represent an example, illustration or description. Any embodiment or design scheme described as "exemplarily" or "for example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the words "exemplarily" or "for example" are intended to present the relevant concept in a specific manner.
[0114] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character "or" generally represents an "or" relationship between the associated objects. "At least one" or the like means any combination of these items, including single item or any combination of multiple items. For example, at least one of a, b, or c can represent a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple.
[0115] In the related art, the supply safety of oil and gas resources is generally realized through an oil and gas production-cyber physical system (OGP-CPS) of an oil and gas production system.
[0116] The OGP-CPS realizes the construction of an information space twin of a device corresponding to a physical entity of the device in a virtual information space by collecting, transmitting, and analyzing real-time data of the physical entity of the device in the information layer of the OGP-CPS, and the behavior and state of the device can be reflected through the information space twin.
[0117] However, the OGP-CPS connects multiple devices in the information layer, so that the originally relatively independent devices are connected with each other, which causes that an attack on a certain device of the oil and gas production system can realize an attack on other devices directly or indirectly connected with the certain device, the attack means of the oil and gas production system is too much, which causes that the risk path is too complex, and more security protection resources need to be invested for the security protection of the oil and gas production system.
[0118] In view of this, the present application provides an oil and gas production system information security threat risk path prediction method. The method determines the failure nodes by perturbing the first node, determines the recovery time of the multiple failure nodes by determining the local clustering coefficient, and then determines the perturbation risk level corresponding to the first node according to the recovery time of the multiple failure nodes and the propagation time between the multiple failure nodes. The risk path corresponding to the first node can be predicted by determining the failure nodes by perturbing the first node, and then the security protection strategy of the multiple risk paths can be formulated according to the perturbation risk level corresponding to the multiple first nodes, thereby reducing the waste of security protection resources.
[0119] The technical solutions of the present application and how the technical solutions solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0120] Figure 1 The flowchart of an oil and gas production system information security threat risk path prediction method provided by the embodiments of the present application Figure One As shown in Figure 1 , the method comprises:
[0121] S101, obtain the local clustering coefficient of multiple nodes, the multiple nodes are nodes in a target directed network constructed based on an oil and gas production system, and the multiple nodes correspond to multiple devices in the oil and gas production system.
[0122] Optionally, the execution subject of the embodiments of the present application is an electronic device, or an oil and gas production system information security threat risk path prediction device provided in the electronic device. The oil and gas production system information security threat risk path prediction device can be realized by the combination of software and / or hardware.
[0123] The target directed network comprises edges between multiple nodes, the multiple nodes correspond to multiple devices, the edge indicates that the devices corresponding to the nodes on the edge are connected, and the direction of the edge indicates the information transmission direction or the oil and gas transmission direction between the devices corresponding to the nodes on the edge.
[0124] Optionally, the multiple devices include but are not limited to: pipelines, pumps, valves, sensors, controllers, or actuators, etc.
[0125] For example, when the devices corresponding to the nodes on the edge are a pipeline and a pump, the edge indicates that the pipeline and the pump are connected, and the direction of the edge indicates the oil and gas transmission direction between the pipeline and the pump. If the oil and gas transmission direction is that the oil paint flows from the pipeline into the pump, then the direction of the edge between the pipeline and the pump is from the node corresponding to the pipeline to the node corresponding to the pump.
[0126] For example, when the devices corresponding to the pair of nodes on the edge are a sensor and a controller, the edge indicates that there is a connection between the sensor and the controller, and the direction of the edge indicates the direction of information transmission between the sensor and the controller. If the sensor is responsible for real-time monitoring of the oil and gas pressure in the pipeline, after the sensor detects the pressure data of the oil and gas pressure, the pressure data is transmitted to the controller, at this time, the direction of the edge between the sensor and the controller is from the node corresponding to the sensor to the node corresponding to the controller.
[0127] The local clustering coefficient of a node indicates the tightness of the connection of the node with other nodes, and can also be understood as indicating the tightness of the connection between the device corresponding to the node and other devices.
[0128] In a possible implementation, a target directed network of an oil and gas production system is constructed according to device information of a plurality of devices in the oil and gas production system and a connection relationship between the plurality of devices, and includes the following steps.
[0129] Device information of a plurality of devices of the oil and gas production system is determined, and a plurality of physical devices and a plurality of information devices are determined.
[0130] According to the plurality of physical devices and the plurality of information devices of the oil and gas production system, a plurality of nodes are determined, and the plurality of nodes include a plurality of physical nodes and a plurality of information nodes.
[0131] A connection relationship between the plurality of devices is determined.
[0132] A plurality of edges are determined according to the connection relationship between the plurality of devices.
[0133] A basic network is constructed according to the plurality of physical nodes.
[0134] An information-physical control feedback substructure is constructed according to the plurality of information nodes and the plurality of edges.
[0135] The information-physical control feedback substructure is embedded in the basic network to construct a target directed network of the oil and gas production system.
[0136] S102, according to the local clustering coefficient of the plurality of nodes, determining the recovery time length of the plurality of nodes and the propagation time length between each two nodes.
[0137] In a possible implementation, the embodiments of the present application define three time parameters of disturbance time length, propagation time length and recovery time length based on the Influence Propagation and Recovery Model (IRML) method, which are used to represent the dynamic behavior of the functional failure of the oil and gas production system after the oil and gas production system is attacked.
[0138] The disturbance duration is the duration of the disturbance of the node, or the duration of the disturbance applied to the node, or the duration of the disturbance of the node by the incident.
[0139] The propagation duration between each two nodes is the duration required for the functional failure of one node to cause the functional failure of another node, or the time interval from the functional failure of one node to the functional failure of another node.
[0140] The recovery duration of the node is the duration required for the node to recover from the functional failure to the functional validity, or the time interval from the start of recovery to the complete recovery of the function after the functional failure of the node, which is used to characterize the difficulty of the functional recovery of the node.
[0141] The recovery duration of the node can be understood as the recovery duration of the device corresponding to the node.
[0142] The propagation duration between each two nodes can be understood as the propagation duration between the two devices corresponding to the two nodes.
[0143] The disturbance duration of the node can be understood as the disturbance duration of the device corresponding to the node.
[0144] The duration of the disturbance of the node can be understood as the duration of the attack on the node.
[0145] The functional failure of the node can be understood as the abnormal operation of the device corresponding to the node.
[0146] The functional validity of the node can be understood as the normal operation of the device corresponding to the node.
[0147] S103, when the at least one first node in the plurality of nodes is disturbed, determining a failure propagation process according to the target directed network, the recovery duration of the plurality of nodes, the propagation duration between each two nodes, and the initial time of the disturbance.
[0148] The failure propagation process includes the functional state of the plurality of nodes at the initial time, the functional state at the end time, and the functional state at the plurality of selected time points between the initial time and the end time, and the end time is the time when the target directed network recovers to normal.
[0149] Optionally, the recovery duration of the plurality of failed nodes, the propagation duration between the plurality of failed nodes, and the initial time of the disturbance of the first node are added to determine the end time.
[0150] The recovery of the target directed network to normal can be understood as the functional validity of the oil and gas production system corresponding to the target directed network, or the functional validity of each node in the target directed network.
[0151] In a possible implementation, the failure propagation process is determined according to the target directed network, the recovery time length of the plurality of nodes, the propagation time length between each two nodes, and the initial time of the disturbance, and includes:
[0152] According to the target directed network, a plurality of failure nodes are determined, the failure nodes being nodes that are functionally failed or possibly functionally failed in the plurality of nodes when the first node is disturbed;
[0153] The failure propagation process is determined according to the recovery time length of the plurality of nodes, the propagation time length between each two nodes, and the initial time of the disturbance.
[0154] The failure nodes include one or more of the following: failed nodes and to-be-propagated failure nodes. The failed nodes are nodes that are functionally failed in the plurality of nodes, and the to-be-propagated failure nodes are nodes that are possibly functionally failed in the plurality of nodes.
[0155] The failed nodes include the first node. The first node can be referred to as an initial failure node.
[0156] The to-be-propagated failure nodes refer to other nodes that are directly or indirectly affected by the functional failure of the first node and then functionally failed in the target directed network.
[0157] According to the target directed network and the plurality of failure nodes, a normally operating node can also be determined. The normally operating node is a node other than the plurality of failure nodes in the target directed network.
[0158] Figure 2 A schematic diagram of a failure propagation process at a certain moment provided by an embodiment of the present application is shown in FIG. 1. Figure 2 As shown in FIG. 1, the target directed network includes a plurality of nodes, including G1, G2, G3, G4, G5, G6, G7, G8, G9, G10, G11, G12, G13, G14, G15, and G16.
[0159] The first node is G9, the failed nodes are G8 and G9, the to-be-propagated failure nodes include G6, G7, G10, G11, G12, G13, G14, G15, and G16, and the normally operating nodes include G1, G2, G3, G4, and G5.
[0160] G9 points to G8, indicating that the direction of the edge is from G9 to G8, the node connected to the starting point of the edge is G9, and the node connected to the terminal point of the edge is G8.
[0161] In S104, a disturbance risk level of a risk path corresponding to the disturbance on the at least one first node is determined according to the failure propagation process.
[0162] Specifically, the disturbance risk level of the risk path corresponding to the disturbance of the at least one first node is determined according to the functional state of the plurality of nodes at the initial time, the functional state of the plurality of nodes at the end time, and the functional state of the plurality of nodes at a plurality of candidate times between the initial time and the end time.
[0163] The disturbance risk level is used to represent the degree of harm of the attack on the equipment corresponding to the at least one first node to the oil and gas production system.
[0164] The disturbance of the at least one first node corresponds to a risk path.
[0165] The higher the disturbance risk level is, the greater the degree of harm of the attack on the equipment corresponding to the at least one first node to the oil and gas production system.
[0166] In Figure 1 In an embodiment, by determining the local clustering coefficient of the plurality of nodes in the target directed network, determining the recovery time length of the plurality of nodes and the propagation time length between each two nodes, and then determining the failure propagation process of disturbing the at least one first node, and further determining the disturbance risk level of the risk path corresponding to the disturbance of the at least one first node, the security protection strategy of the plurality of risk paths is formulated according to the disturbance risk levels of the plurality of risk paths, and the waste of security protection resources is reduced.
[0167] Figure 3 A flowchart of an oil and gas production system information security threat risk path prediction method provided by an embodiment of the present application Figure Two As Figure 3 shown, the method comprises:
[0168] S301, performing S101-S103.
[0169] S302, determining a plurality of target times at an initial time, an end time and a plurality of candidate times.
[0170] The plurality of target times includes the initial time, the end time, and at least one time selected from the plurality of candidate times.
[0171] In a possible implementation, the at least one time selected from the plurality of candidate times can be at least one time randomly selected from the plurality of candidate times.
[0172] S303, determining the instantaneous functional state of the plurality of target times according to the functional state of the plurality of nodes at the plurality of target times and the device type corresponding to the plurality of nodes.
[0173] The functional state of the node includes functional failure and functional validity.
[0174] The functional state of a node can be represented by a numerical value. For example, a functional failure is represented by 0, and a functional validity is represented by 1.
[0175] In one possible implementation, the instantaneous functional state of a target time is determined according to the functional states of the plurality of nodes at the plurality of target times and the device types corresponding to the plurality of nodes.
[0176] The device types corresponding to the plurality of nodes are determined according to the device types of the plurality of nodes. The device types corresponding to the plurality of nodes are determined according to the device types of the plurality of nodes.
[0177] The weights corresponding to the plurality of device types are determined according to experience. The weights corresponding to the plurality of device types are determined according to experience. The weights corresponding to the plurality of device types are determined according to experience.
[0178] The functional states of the plurality of nodes at the plurality of target times are determined according to the failure propagation process.
[0179] The instantaneous functional state of the target time is determined according to the functional states of the plurality of nodes at the plurality of target times and the plurality of weights. The instantaneous functional state of the target time is determined according to the functional states of the plurality of nodes at the plurality of target times and the plurality of weights.
[0180] In one possible implementation, the instantaneous functional state of the target time satisfies the following formula 1:
[0181] Formula 1;
[0182] Wherein, The target time is represented by t. The instantaneous functional state corresponding to the target time is represented by S(t). The total number of device types corresponding to the plurality of nodes is represented by N. The weight corresponding to the type is represented by w. The total number of nodes corresponding to the type in the plurality of nodes is represented by n. The node in the type corresponding to the node in the plurality of nodes is represented by i. The functional state of the node at the target time is represented by S(t, i). The functional state of the node at the target time is represented by S(t, i). The functional state of the node at the target time is represented by S(t, i). The functional state of the node at the target time is represented by S(t, i). The functional state of the node at the target time is represented by S(t, i). .
[0183] The instantaneous functional state of the target time can be understood as the instantaneous functional state of the oil and gas production system at the target time.
[0184] S304, the disturbance risk level is determined according to the instantaneous functional state of the plurality of target times.
[0185] In Figure 3In the embodiment, the plurality of target moments are determined at an initial moment, an ending moment and a plurality of candidate moments; the instantaneous function states of the plurality of target moments are determined according to the function states of the plurality of nodes at the plurality of target moments and the device types corresponding to the plurality of nodes; and the disturbance risk level is determined according to the instantaneous function states of the plurality of target moments. In this way, the instantaneous function states of the plurality of preset moments are determined according to the function states of the plurality of nodes in the failure propagation process, and then the disturbance risk level corresponding to the first node is determined, so that the disturbance risk level can be determined more accurately.
[0186] Figure 4 A flowchart of an oil and gas production system information security threat risk path prediction method provided by an embodiment of the present application Figure Three As shown in Figure 4 , the method comprises:
[0187] S401, S301-S303.
[0188] S402, the instantaneous function states of the plurality of target moments are subjected to curve fitting processing to obtain a security resilience change curve.
[0189] It is worth noting that the curve fitting processing is described in related technologies, which will not be repeated here.
[0190] Figure 5 A schematic diagram of a security resilience change curve provided by an embodiment of the present application is shown in Figure 5 , in which the horizontal axis represents time, the vertical axis represents the instantaneous function state, and the solid circle represents the instantaneous function state of the target moment.
[0191] When the function is effective and represented as 1 and the function failure is represented as 0, the range of the instantaneous function state is between 0 and 1.
[0192] The ending moment is represented by Tend. The initial moment is represented by Tini.
[0193] S403, according to the security resilience change curve, the damage degree parameter, the damage range parameter and the ability recovery parameter of the target directed network are determined.
[0194] In one possible implementation, the damage degree parameter satisfies the following formula 2:
[0195] Formula 2;
[0196] wherein, Tini represents a preset value associated with the ending moment and the initial moment, Tend represents the ending moment, Tini represents the initial moment, represents the safety toughness change curve, ∫ represents the integral symbol, Represents the differential symbol.
[0197] Exemplarily, when the function validity indication is 1, the preset value associated with the end time and the initial time is the absolute value of the end time minus the initial time.
[0198] In one possible implementation, the destruction range parameter Satisfies the following formula 3:
[0199] Formula 3;
[0200] in, express The minimum value of , / represents the division operation;
[0201] In one possible implementation, the capability recovery parameter Satisfies the following formula 4:
[0202] Formula 4;
[0203] in, Indicates the number of at least one sub-curve, where at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, and the at least two first moments include The corresponding target time, ,as well as The corresponding target time and The target time between the first curve is middle The corresponding curve between the target time and the end time, Indicates a curve in at least one subcurve The corresponding slope.
[0204] curve The corresponding slope can be understood as the curve The ratio of the absolute value of the difference between the instantaneous functional states corresponding to the two first moments to the absolute value of the difference between the two first moments.
[0205] exist middle When the difference between the corresponding target time and the end time is less than a first preset value, P is equal to 1, indicating that the target directed network can be quickly restored to function effectively. The first preset value is, for example, 5 hours.
[0206] After perturbing at least one first node among the plurality of nodes, the target directed network can be restored to be functionally valid, and the capability recovery parameter satisfies The target directed network cannot be restored to be functionally valid, and the capability recovery parameter is satisfied .
[0207] The target directed network is functionally valid, which can be understood as that each node in the target directed network is functionally valid, the oil and gas production system is functionally valid, or each device in the oil and gas production system is functionally valid.
[0208] S404, determining the disturbance risk level according to the damage degree parameter, the damage range parameter and the capability recovery parameter.
[0209] In a possible implementation, the disturbance risk level is determined according to the damage degree parameter, the damage range parameter and the capability recovery parameter, including:
[0210] determining a product of the damage degree parameter and the damage range parameter;
[0211] determining a ratio of the product to the capability recovery parameter as the disturbance risk level.
[0212] The damage degree parameter, the damage range parameter, the capability recovery parameter and the disturbance risk level satisfy the following formula 8:
[0213] Formula 3;
[0214] wherein, represents the disturbance risk level corresponding to the i th first node.
[0215] In Figure 4 Embodiments, the instantaneous function states of the plurality of target moments are curve fitting processed to obtain a safety resilience change curve; the damage degree parameter, the damage range parameter and the capability recovery parameter of the target directed network are determined according to the safety resilience change curve; and the disturbance risk level is determined according to the damage degree parameter, the damage range parameter and the capability recovery parameter. In the above manner, by curve fitting processing the instantaneous function states of the plurality of target moments to obtain a safety resilience change curve, and then determining the damage degree parameter, the damage range parameter and the capability recovery parameter of the target directed network according to the safety resilience change curve, the influence of subjective factors on the process of disturbing the first node to propagation until the oil and gas production system is restored to be functionally valid can be reduced, and the accuracy of determining the disturbance risk level can be improved.
[0216] Figure 6 A flowchart of an oil and gas production system information security threat risk path prediction method provided by an embodiment of the present application Figure Four As Figure 6 shown, the method includes:
[0217] S601, constructing an initial directed network of the oil and gas production system according to device information of a plurality of devices in the oil and gas production system and a connection relationship between the plurality of devices, the initial directed network including a plurality of nodes and edges between the plurality of nodes.
[0218] The edge indicates that there is a connection between devices corresponding to the nodes on the edge, and the direction of the edge indicates a direction of information transmission or oil and gas transmission between the devices corresponding to the nodes on the edge.
[0219] In a possible implementation, constructing an initial directed network of the oil and gas production system according to device information of a plurality of devices in the oil and gas production system and a connection relationship between the plurality of devices includes:
[0220] Determining device information of a plurality of devices of the oil and gas production system, determining a plurality of physical devices and a plurality of information devices;
[0221] According to the plurality of physical devices and the plurality of information devices of the oil and gas production system, determining a plurality of nodes, the plurality of nodes including a plurality of physical nodes and a plurality of information nodes;
[0222] Determining a connection relationship between the plurality of devices;
[0223] According to the connection relationship between the plurality of devices, determining a plurality of edges;
[0224] According to the plurality of physical nodes, constructing a base network;
[0225] According to the plurality of information nodes and the plurality of edges, constructing an information-physical control feedback substructure;
[0226] Embedding the information-physical control feedback substructure in the base network to construct the initial directed network of the oil and gas production system.
[0227] S602, determining an average path length and an average clustering coefficient of the initial directed network.
[0228] In a possible implementation, determining an average path length and an average clustering coefficient of the initial directed network includes:
[0229] Determining the average path length of the initial directed network;
[0230] Determining the average clustering coefficient of the initial directed network.
[0231] In a possible implementation, determining the average path length of the initial directed network includes:
[0232] According to the initial directed network, determining a shortest path length between each two nodes;
[0233] According to the shortest path length between each two nodes and a total number of the plurality of nodes, determining the average path length.
[0234] Optionally, the average path length of the initial directed network satisfies the following formula 9:
[0235] Formula 9;
[0236] wherein, denotes the average path length of the initial directed network, denotes the total number of the plurality of nodes, denotes the shortest path length between the node and the node in the initial directed network.
[0237] In a possible implementation, determining the average clustering coefficient of the initial directed network comprises:
[0238] determining the local clustering coefficient of each node;
[0239] determining the average clustering coefficient according to the local clustering coefficient of each node and the total number of the plurality of nodes.
[0240] Optionally, the local clustering coefficient of the initial directed network satisfies the following formula 10:
[0241] Formula 10;
[0242] wherein, denotes the average clustering coefficient of the initial directed network, denotes the local clustering coefficient of the node .
[0243] S603, determining the optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient of the initial directed network.
[0244] In a possible implementation, the optimal reconnection probability of the initial directed network is determined according to the average path length and the average clustering coefficient of the initial directed network by using a genetic algorithm.
[0245] S604, adjusting the edges between the plurality of nodes in the initial directed network according to the optimal reconnection probability to obtain a target directed network.
[0246] In a possible implementation, the target directed network is obtained by adjusting the edges between the plurality of nodes in the initial directed network according to the optimal reconnection probability, comprising:
[0247] generating a random number ranging from 0 to 1 for an edge in the initial directed network;
[0248] When the random number is less than the optimal reconnection probability, the node connected to the starting point of the edge remains unchanged, and a new node is selected in the initial directed network as the node connected to the end point of the edge to establish a new edge; the new node is a node in the initial directed network other than the node connected to the starting point of the edge and the node originally connected to the end point of the edge.
[0249] When the random number is greater than or equal to the optimal reconnection probability, no edge adjustment is made;
[0250] Repeat the above operations for all edges in the initial directed network to obtain the target directed network.
[0251] S605 : Determine a local clustering coefficient of the node according to the number of at least one neighboring node of the node and the number of edges between at least one neighboring node, where the multiple nodes are nodes in the target directed network.
[0252] In one possible implementation, a node among the multiple nodes The local clustering coefficient Satisfies the following formula 5:
[0253] Formula 5;
[0254] in, Representation node The number of at least one adjacent point of Indicates the number of edges between adjacent vertices.
[0255] The range of the local clustering coefficient is greater than or equal to 0 and less than or equal to 1. The closer it is to 1, the higher the degree of node neighbor clustering.
[0256] S606: Determine the recovery time of the multiple nodes and the propagation time between every two nodes according to the local clustering coefficients of the multiple nodes.
[0257] In one possible implementation, a node among the multiple nodes Recovery time Satisfies the following formula 6:
[0258] Formula 6;
[0259] in, Representation node The local clustering coefficient, Indicates the basic recovery time, the value is 1 day.
[0260] In one possible implementation, a node among the multiple nodes The propagation time between node j Satisfies the following formula 7:
[0261] Formula 7;
[0262] wherein, denotes the local clustering coefficient of a node denotes the local clustering coefficient of a node denotes the basic propagation duration, and the value is 1 day.
[0263] The local clustering coefficient of a node represents the clustering degree of the node in the target directed network. The higher the local clustering coefficient, the more adjacent nodes exist around the node, and the failure of the node is more likely to propagate to other nodes. When the node is recovered, according to the dynamic propagation rule, the node can be recovered only if all parent nodes of the node are functional. The higher the local clustering coefficient, the more parent nodes (the parent node refers to a node connected to the starting point of an edge directly connected to the node in the target directed network) that exist, and the more difficult and slower the node is recovered. In the embodiments of the present application, the local clustering coefficients of multiple nodes are combined with the basic recovery duration and the basic propagation duration to determine the recovery duration of the multiple nodes and the propagation duration between each two nodes, which can consider the influence of the clustering degree of different nodes in the target directed network on the recovery duration and the propagation duration, and further obtain more accurate recovery duration and propagation duration.
[0264] S607, when at least one first node in the multiple nodes is disturbed, determining a failure propagation process according to the target directed network, the recovery duration of the multiple nodes, the propagation duration between each two nodes, and an initial time of the disturbance, the failure propagation process including the functional state of the multiple nodes at the initial time, the functional state at an end time, and the functional state of the multiple nodes at multiple candidate times between the initial time and the end time.
[0265] It is worth noting that the execution method of S607 is the same as that of S103, which will not be repeated here.
[0266] S608, determining multiple target times in the initial time, the end time and the multiple candidate times.
[0267] It is worth noting that the execution method of S608 is the same as that of S302, which will not be repeated here.
[0268] S609, determining the instantaneous functional state of the multiple target times according to the functional state of the multiple nodes at the multiple target times and the device types corresponding to the multiple nodes.
[0269] It is worth noting that the execution method of S610 is the same as that of S303, which will not be repeated here.
[0270] S610, performing curve fitting processing on the instantaneous functional state of the multiple target times to obtain a security resilience change curve.
[0271] It is worth noting that S611 has the same execution method as S402, which will not be repeated here.
[0272] S611, according to the security resilience curve, determine the damage degree parameter, damage range parameter, and capacity recovery parameter of the target directed network.
[0273] It is worth noting that S612 has the same execution method as S403, which will not be repeated here.
[0274] S612, according to the damage degree parameter, damage range parameter and capacity recovery parameter, determine the disturbance risk level.
[0275] It is worth noting that S613 has the same execution method as S404, which will not be repeated here.
[0276] In Figure 6 In an embodiment, according to the device information of the plurality of devices in the oil and gas production system and the connection relationship between the plurality of devices, an initial directed network of the oil and gas production system is constructed; the average path length and the average clustering coefficient of the initial directed network are determined; according to the average path length and the average clustering coefficient, the optimal reconnection probability of the initial directed network is determined; according to the optimal reconnection probability, the edges between the plurality of nodes in the initial directed network are adjusted to obtain a target directed network. In the above manner, the initial directed network is adjusted by the optimal reconnection probability to obtain the target directed network, which can obtain a target directed network that is more suitable for the oil and gas production system, thereby improving the accuracy of determining the disturbance risk level.
[0277] The following will be combined Figure 7 with the process of determining the optimal reconnection probability of the initial directed network by using the genetic algorithm.
[0278] Figure 7 The flowchart of a method for determining the optimal reconnection probability provided by the embodiments of the present application is shown in Figure 8 , and the method comprises:
[0279] S701, randomly generate a plurality of first individuals in the range of [0, 1] to construct an initial population, the initial population includes a plurality of first individuals, and the total number of the plurality of first individuals is a.
[0280] For example, a plurality of first individuals in the range of [0, 1] are randomly generated to form an initial population .
[0281] S702, according to the average path length and the average clustering coefficient of the initial directed network, determine the fitness function formula.
[0282] In one possible implementation, a fitness function formula is determined based on the average path length and average clustering coefficient of the initial directed network, including:
[0283] Determine the expected average path length and the expected average clustering coefficient according to the average path length and the average clustering coefficient of the initial directed network;
[0284] The fitness function formula is determined based on the expected average clustering coefficient and the expected average path length.
[0285] Optionally, the average path length of the initial directed network and the expected average path length satisfy the following formula 11:
[0286] Formula 11;
[0287] in, represents the expected average path length, represents the average path length of the initial directed network, represents the logarithmic function, 、 、 Indicates a parameter, which is determined based on experience. Represents the total number of nodes in the initial directed network.
[0288] Optionally, the average clustering coefficient and the expected average clustering coefficient of the initial directed network satisfy the following formula 12:
[0289] Formula 12;
[0290] in, represents the expected average clustering coefficient, represents the average path length of the initial directed network, Indicates a randomly generated random number in the range [0, 1].
[0291] In one possible implementation, the fitness function formula satisfies the following formula 13:
[0292] Formula 13;
[0293] in, Represents an individual The fitness value of 、 represents the weight coefficient, represents the expected average path length, represents the expected average clustering coefficient, Represents an individual The corresponding average path length is Represents an individual the corresponding average clustering coefficient.
[0294] Optionally, , The value is determined empirically and satisfies .
[0295] The individual The corresponding average path length is: according to the individual Adjusting the edges between the plurality of nodes in the initial directed network, the average path length of the process directed network obtained.
[0296] The individual The corresponding average clustering coefficient is: according to the individual Adjusting the edges between the plurality of nodes in the initial directed network, the average clustering coefficient of the process directed network obtained.
[0297] It is worth noting that the execution method of "adjusting the edges between the plurality of nodes in the initial directed network, the process directed network obtained" is similar to the execution method of S604, which will not be repeated here.
[0298] S703, respectively, each individual in the initial population is substituted into the fitness function formula, and the fitness vector corresponding to the initial population is determined.
[0299] The fitness vector corresponding to the initial population includes the fitness value of each individual in the initial population.
[0300] S704, using tournament selection (Tournament Selection), a plurality of second individuals are determined according to the nth population, initially, n=1, and the first population is the initial population.
[0301] The total number of the plurality of second individuals is equal to the total number of the plurality of first individuals.
[0302] It is worth noting that the specific implementation method of S704 is described in the related art, which will not be repeated here.
[0303] S705, each two individuals in the plurality of second individuals are cross-processed to determine a plurality of third individuals.
[0304] In one possible implementation, the two second individuals and a third individual satisfy the following formula 14:
[0305] Formula 14;
[0306] Wherein, Indicates the third individual, denotes the ith second individual and the jth second individual, denotes a cross-proportionality coefficient, the cross-proportionality coefficient is randomly generated and ranges from [0, 1].
[0307] S706, mutating the plurality of third individuals with a certain probability to determine a plurality of fourth individuals.
[0308] In a possible implementation, a third individual and a fourth individual satisfy the following formula 15:
[0309] Formula 15;
[0310] wherein, denotes the fourth individual, denotes a mutation range, the mutation range is 0.3, denotes a random number greater than -1 and less than 1.
[0311] S707, respectively bringing the plurality of third individuals and the plurality of fourth individuals into a fitness function formula to determine respective fitness values of the plurality of third individuals and the plurality of fourth individuals.
[0312] S708, sorting the respective fitness values of the plurality of third individuals and the plurality of fourth individuals to determine the first a individuals as the (n+1)th population.
[0313] S709, respectively substituting each individual in the (n+1)th population into the fitness function formula to determine a fitness vector corresponding to the (n+1)th population.
[0314] The fitness vector corresponding to the (n+1)th population includes respective fitness values of each individual in the (n+1)th population.
[0315] S710, determining whether an absolute value of a difference between the fitness vector corresponding to the (n+1)th population and the fitness vector corresponding to the nth population is less than a second preset value.
[0316] If yes, S711 is executed, otherwise, S704 is executed.
[0317] In a possible implementation, the difference between the fitness vector corresponding to the (n+1)th population and the fitness vector corresponding to the nth population includes:
[0318] determining a first average value of the fitness vector corresponding to the (n+1)th population;
[0319] determining a second average value of the fitness vector corresponding to the nth population;
[0320] determining an absolute value of a difference between the first average value and the second average value.
[0321] The second preset value is, for example, 0.1 or 0.01.
[0322] S711, determining the optimal individual according to the fitness vector corresponding to the (n+1)th population.
[0323] In an implementation manner, the determining the optimal individual according to the fitness vector corresponding to the (n+1)th population comprises:
[0324] sorting all fitness values contained in the fitness vector corresponding to the (n+1)th population;
[0325] determining the individual corresponding to the highest fitness value after the sorting as the optimal individual.
[0326] S712, judging whether the average clustering coefficient corresponding to the optimal individual and the average path length corresponding to the optimal individual satisfy the determination condition of the small-world network.
[0327] In a possible implementation manner, the judging whether the average clustering coefficient corresponding to the optimal individual and the average path length corresponding to the optimal individual satisfy the determination condition of the small-world network comprises:
[0328] judging whether the absolute value of the difference between the average clustering coefficient corresponding to the optimal individual and the expected average clustering coefficient is less than a third preset value, and whether the absolute value of the difference between the average path length corresponding to the optimal individual and the expected average path length is less than a fourth preset value.
[0329] Optionally, the third preset value is, for example, 0.01, and the fourth preset value is, for example, 0.01.
[0330] If yes, performing S713, otherwise, performing S701.
[0331] S713, determining the optimal individual as the optimal reconnection probability.
[0332] Figure 8 A structural schematic diagram of an oil and gas production system information security threat risk path prediction device provided by an embodiment of the present application is shown in FIG. 8. As shown in FIG. 8, the oil and gas production system information security threat risk path prediction device 80 provided by the embodiment of the present application comprises: Figure 8 An acquisition module 801 is configured to acquire local clustering coefficients of a plurality of nodes, the plurality of nodes being nodes in a target directed network constructed based on the oil and gas production system, and the plurality of nodes corresponding to the plurality of devices.
[0333]
[0334] The determination module 802 is configured to determine a recovery time length of the plurality of nodes and a propagation time length between each two nodes according to a local clustering coefficient of the plurality of nodes, the recovery time length being a time length required for the node to recover from a functional failure to a functional validity, and the propagation time length being a time length required for a functional failure of one node to cause a functional failure of another node.
[0335] The determination module 802 is further configured to determine a failure propagation process including functional states of the plurality of nodes at an initial time, at an ending time, and at a plurality of candidate times between the initial time and the ending time, when a disturbance is performed on at least one node in the plurality of nodes, according to the target directed network, the recovery time length of the plurality of nodes, the propagation time length between each two nodes, and the initial time of the disturbance, the ending time being a time when the target directed network recovers to normal.
[0336] The determination module 802 is further configured to determine a disturbance risk level of a risk path corresponding to the disturbance performed on the at least one node according to the failure propagation process, the disturbance risk level being used to represent a degree of harm to the oil and gas production system caused by an attack on at least one device corresponding to the at least one node.
[0337] It should be noted that the oil and gas production system information security threat risk path prediction apparatus 80 provided by the embodiments of the present application can realize all the method steps realized by the method embodiments and achieve the same technical effects, and thus the same parts and beneficial effects as the method embodiments will not be described in detail herein.
[0338] In a possible implementation, the determination module 802 is specifically configured to:
[0339] determine a plurality of target times among the initial time, the ending time and the plurality of candidate times;
[0340] determine an instantaneous functional state of the plurality of target times according to the functional states of the plurality of nodes at the plurality of target times and the device types corresponding to the plurality of nodes;
[0341] determine the disturbance risk level according to the instantaneous functional state of the plurality of target times.
[0342] In a possible implementation, the instantaneous functional state of the target time satisfies the following formula 1:
[0343] Formula 1
[0344] wherein, t represents the target time, representing an instantaneous function state corresponding to the target moment, representing a total number of device types corresponding to the plurality of nodes, representing a type corresponding weight, representing a total number of nodes of the type in the plurality of nodes, representing a type a node in the corresponding node a function state at the target moment.
[0345] In a possible implementation, the determining module 802 is specifically configured to:
[0346] perform curve fitting processing on the instantaneous function states of the plurality of target moments to obtain a security resilience change curve;
[0347] determine a damage degree parameter, a damage range parameter, and a capability recovery parameter of the target directed network according to the security resilience change curve;
[0348] determine the disturbance risk level according to the damage degree parameter, the damage range parameter, and the capability recovery parameter.
[0349] In a possible implementation, the damage degree parameter satisfies the following formula 2:
[0350] Formula 2;
[0351] wherein, represents a preset value associated with the end moment and the initial moment, represents the end moment, represents the initial moment, represents the security resilience change curve, and ∫ represents an integral sign, represents a differential sign;
[0352] the damage range parameter satisfies the following formula 3:
[0353] Formula 3;
[0354] wherein, represents a minimum value of , and / represents a division operation;
[0355] the capability recovery parameter satisfies the following formula 4:
[0356] Formula 4;
[0357] in, represents the number of at least one sub-curve, wherein the at least one sub-curve is a curve obtained by dividing the first curve according to at least two first moments, wherein the at least two first moments include The corresponding target time, , and the The corresponding target time and The first curve is middle The curve between the corresponding target time and the end time, represents a curve in the at least one sub-curve The corresponding slope.
[0358] In a possible implementation, the determining module 802 is specifically configured to:
[0359] determining the product of the damage extent parameter and the damage range parameter;
[0360] The ratio of the product to the capacity recovery parameter is determined as the disturbance risk level.
[0361] In a possible implementation, the acquisition module 801 is specifically configured to:
[0362] The local clustering coefficient of the node is determined according to the number of at least one neighboring point of the node and the number of edges between the at least one neighboring point.
[0363] In a possible implementation manner, a node among the multiple nodes The local clustering coefficient Satisfies the following formula 5:
[0364] Formula 5;
[0365] in, Represents the node The number of neighboring points, Indicates the number of edges between the adjacent points.
[0366] In a possible implementation manner, a node among the multiple nodes Recovery time Satisfies the following formula 6:
[0367] Formula 6;
[0368] in, Represents the node a local clustering coefficient of the node, denotes a basic recovery time length;
[0369] a node in the plurality of nodes a propagation time length between the node i and the node j satisfies the following formula 7:
[0370] formula 7;
[0371] wherein, denotes the node a local clustering coefficient of the node, denotes a basic propagation time length.
[0372] In a possible implementation, the determining module 802 is further configured to:
[0373] construct an initial directed network of the oil and gas production system according to device information of the plurality of devices in the oil and gas production system and a connection relationship between the plurality of devices, the initial directed network including the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between devices corresponding to a node pair on the edge, and a direction of the edge indicating a direction of information transmission or oil and gas transmission between the devices corresponding to the node pair on the edge;
[0374] determine an average path length and an average clustering coefficient of the initial directed network;
[0375] determine an optimal reconnection probability of the initial directed network according to the average path length and the average clustering coefficient;
[0376] adjust the edges between the plurality of nodes in the initial directed network according to the optimal reconnection probability to obtain the target directed network.
[0377] It should be noted that the oil and gas production system information security threat risk path prediction apparatus 80 provided by the embodiments of the present application can realize all the method steps realized by the method embodiments and can achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0378] It should be understood that the oil and gas production system information security threat risk path prediction apparatus 80 is embodied in the form of functional modules. The term "module" herein can refer to an Application-Specific Integrated Circuit (ASIC), an electronic circuit, a processor (for example, a shared processor, a dedicated processor, or a group processor, etc.) and a memory for executing at least one software or firmware program, a combination of logic circuitry and / or other suitable components that support the described functionality.
[0379] Figure 9 A structural diagram of an electronic device is provided for an embodiment of the present application. As shown in the figure, the electronic device 90 includes a processor 901 and a memory 902. Among them, the processor 901 is in communication connection with the memory 902, and the memory 902 is used to store computer execution instructions; the processor 901 is configured to execute the technical solutions in any of the preceding method embodiments via the computer execution instructions stored in the memory 902. Figure 9
[0380] Optionally, the memory 902 can be independent or integrated with the processor 901. Optionally, when the memory 902 is a device independent of the processor 901, the electronic device 900 can further include a bus 903 for connecting the above-mentioned devices.
[0381] The electronic device is used to execute the technical solutions in any of the preceding method embodiments, and the implementation principles and technical effects are similar, which will not be repeated here.
[0382] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), and can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the application can be directly embodied as execution completed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0383] The memory can include a Random Access Memory (RAM), and can also include a Non-volatile Memory (NVM), for example, at least one disk memory.
[0384] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0385] The present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the method described above.
[0386] The present application also provides a computer readable storage medium, which stores computer execution instructions, and when a processor executes the computer execution instructions, the method described above is implemented.
[0387] The readable storage medium described above can be realized by any type of volatile or non-volatile storage device or their combination, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special purpose computer.
[0388] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium, and can write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.
[0389] The division of units is only a logical functional division, and in actual implementation, there can be another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0390] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0391] In addition, each functional unit in various embodiments of the application can be integrated into one processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.
[0392] If the function is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the various embodiment methods of the application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0393] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The aforementioned program can be stored in a computer readable storage medium. The program executes to perform the steps of the above-mentioned method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, and various program code storage media.
[0394] Finally, it should be noted that those skilled in the art, after considering the specification and practicing the application disclosed herein, will easily think of other embodiments of the application. The application is intended to cover any variations, uses or adaptations of the application that follow the general principles of the application and include known or customary technical means in the art that are not disclosed by the application, and is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the application is only limited by the appended claims.
Claims
1. A method for predicting an information security threat risk path of an oil and gas production system, the oil and gas production system comprising a plurality of devices, the method comprising: The method comprises: obtaining local clustering coefficients of a plurality of nodes, the plurality of nodes being nodes in a target directed network constructed based on the oil and gas production system, the plurality of nodes corresponding to the plurality of devices; determining, according to the local clustering coefficients of the plurality of nodes, recovery time lengths of the plurality of nodes and propagation time lengths between each two nodes; the recovery time length being a time length required for the node to recover from functional failure to functional validity, and the propagation time length being a time length required for functional failure of one node to cause functional failure of another node; when at least one first node in the plurality of nodes is disturbed, determining, according to the target directed network, the recovery time lengths of the plurality of nodes, the propagation time lengths between each two nodes, and an initial time of disturbance, a failure propagation process, the failure propagation process comprising functional states of the plurality of nodes at an initial time, at an end time, and at a plurality of candidate times between the initial time and the end time; the end time being a time when the target directed network returns to normal; determining, according to the failure propagation process, a disturbance risk level of a risk path corresponding to the disturbance of the at least one first node, the disturbance risk level being used to represent a degree of harm of at least one device corresponding to the at least one first node being attacked to the oil and gas production system; the determining, according to the failure propagation process, the disturbance risk level of the risk path corresponding to the disturbance of the at least one first node comprises: determining a plurality of target times among the initial time, the end time and the plurality of candidate times; determining instantaneous functional states of the plurality of target times according to the functional states of the plurality of nodes at the plurality of target times and device types corresponding to the plurality of nodes; determining the disturbance risk level according to the instantaneous functional states of the plurality of target times; the determining the disturbance risk level according to the instantaneous functional states of the plurality of target times comprises: performing curve fitting processing on the instantaneous functional states of the plurality of target times to obtain a security resilience change curve; determining a damage degree parameter, a damage range parameter and a capability recovery parameter of the target directed network according to the security resilience change curve; determining the disturbance risk level according to the damage degree parameter, the damage range parameter and the capability recovery parameter.
2. The method of claim 1, wherein, The instantaneous functional state of the target time satisfies the following formula 1: Formula 1 ; wherein, denotes the target time instant, denotes the instantaneous functional state corresponding to the target time instant, denotes the total number of device types corresponding to the plurality of nodes, denotes the type corresponding weight, denotes the total number of nodes of the type corresponding to the plurality of nodes, denotes the type corresponding node functional state at the target time instant.
3. The method of claim 1, wherein, the degree of damage parameter satisfies the following equation 2: Formula 2; wherein denotes a preset value associated with the end time and the initial time, denotes the end time, denotes the initial time, denotes the security resilience change curve, ∫ denotes the integral sign, denotes the differential sign; The destruction range parameter satisfies the following equation 3: Formula 3; wherein represents the minimum value of / denotes a division operation; the capability recovery parameter satisfies the following equation 4: Formula 4; wherein denotes the number of at least one sub-curve, the at least one sub-curve being a curve resulting from a division of the first curve by at least two first time instants, the at least two first time instants comprising a corresponding target time instant, , and the corresponding target time instant and target time instant between the corresponding target time instant and the end time instant, the first curve being in the curve between the corresponding target time instant and the end time instant, denotes the slope of the curve corresponding to the at least one sub-curve.
4. The method of claim 1, wherein, the determining the disturbance risk level according to the damage degree parameter, the damage range parameter and the capability recovery parameter comprises: determining a product of the damage degree parameter and the damage range parameter; determining the disturbance risk level as a ratio of the product to the capability recovery parameter.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: obtaining a local clustering coefficient of a node in the target directed network comprises: a node of the plurality of nodes a local clustering coefficient satisfies the following equation 5: Formula 5; in, Represents the node The number of neighboring points, Indicates the number of edges between the adjacent points.
6. The method according to any one of claims 1 to 4, characterized in that, a node of the plurality of nodes a recovery duration satisfies the following equation 6: Formula 6; wherein, denotes the local clustering coefficient of the node denotes the local clustering coefficient of the node denotes the basic recovery duration; a node of the plurality of nodes a propagation time length between the node j and the node i satisfies the following equation 7: Formula 7; wherein, denotes the local clustering coefficient of the node denotes the local clustering coefficient of the node denotes the basic propagation duration.
7. The method according to any one of claims 1 to 4, characterized in that, determining the local clustering coefficient of the node according to a number of at least one adjacent point of the node and a number of edges between the at least one adjacent point; According to the device information of the plurality of devices in the oil and gas production system and the connection relationship between the plurality of devices, an initial directed network of the oil and gas production system is constructed, the initial directed network comprising the plurality of nodes and edges between the plurality of nodes, the edges indicating that there is a connection between the devices corresponding to the nodes on the edges, and the direction of the edges indicating the direction of information transmission or oil and gas transmission between the devices corresponding to the nodes on the edges; determining the average path length and the average clustering coefficient of the initial directed network; According to the average path length and the average clustering coefficient, the optimal reconnection probability of the initial directed network is determined; According to the optimal reconnection probability, the edges between the plurality of nodes in the initial directed network are adjusted to obtain the target directed network.
8. An oil and gas production system information security threat risk path prediction apparatus, the oil and gas production system comprising a plurality of devices, characterized by, Comprising: The acquisition module is used for acquiring the local clustering coefficient of the plurality of nodes, the plurality of nodes being the nodes in the target directed network constructed based on the oil and gas production system, and the plurality of nodes corresponding to the plurality of devices; The determination module is used for determining the recovery time length of the plurality of nodes and the propagation time length between each two nodes according to the local clustering coefficient of the plurality of nodes; The recovery time length is the time length required for the node to recover from functional failure to functional validity, and the propagation time length is the time length required for the functional failure of one node to cause the functional failure of another node; The determination module is also used for determining a failure propagation process according to the target directed network, the recovery time length of the plurality of nodes, the propagation time length between each two nodes, and the initial time of disturbance when at least one node in the plurality of nodes is disturbed, the failure propagation process comprising the functional state of the plurality of nodes at the initial time, the functional state at the end time, and the functional state at a plurality of candidate times between the initial time and the end time; and the end time is the time when the target directed network recovers to normal; The determination module is also used for determining the disturbance risk level of the risk path corresponding to the disturbance of the at least one node according to the failure propagation process, the disturbance risk level being used to represent the degree of harm to the oil and gas production system caused by the attack on the at least one device corresponding to the at least one node; The determination module is specifically used for determining a plurality of target times among the initial time, the end time and the plurality of candidate times, and determining the instantaneous functional state of the plurality of target times according to the functional state of the plurality of nodes at the plurality of target times and the device type corresponding to the plurality of nodes; The determination module is specifically used for performing curve fitting processing on the instantaneous functional state of the plurality of target times to obtain a security resilience change curve, determining a damage degree parameter, a damage range parameter and a capability recovery parameter of the target directed network according to the security resilience change curve, and determining the disturbance risk level according to the damage degree parameter, the damage range parameter and the capability recovery parameter.
Citation Information
Patent Citations
Identifying multiple causal anomalies in power plant systems by modeling local propagations
US20180307994A1
Artificial Intelligence-based Quantified Cyber Defense Control Model
US20240314158A1