An industrial control network security service security guarantee system based on behavior analysis

The industrial control network security system, through multi-source data fusion, dynamic behavior modeling, and federated learning, solves the static and single-dimensional analysis problems of traditional industrial control security systems, and achieves real-time and precise defense against advanced threats and business continuity assurance.

CN120474776BActive Publication Date: 2026-01-27CPI NORTHEAST ENERGY SAVING TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510607332.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2026-01-27
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

Existing industrial control network security systems rely on static rules and lack multi-dimensional analysis, resulting in weak threat tracing capabilities, high false alarm rates, delayed responses, and a high risk of production disruptions.

Method used

By employing a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federated learning analysis cluster, an attack chain prediction module, and an adaptive protection policy executor, combined with a software-defined security architecture and a model evolution feedback loop, real-time and accurate protection policy delivery and threat prediction are achieved.

Benefits of technology

It significantly enhances the proactive defense capabilities against advanced persistent threats and zero-day attacks, reduces false alarm rates, ensures the continuity and security of industrial control services, and adapts to the dynamic changes in the industrial control environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474776B_ABST
    Figure CN120474776B_ABST
Patent Text Reader

Abstract

The application provides an industrial control network security service security guarantee system based on behavior analysis, and belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, an adaptive protection strategy executor and a model evolution feedback loop, wherein: the multi-source data fusion acquisition module synchronously acquires industrial control network traffic (containing OPC UA / Modbus / DNP3 protocol analysis), device operation logs, user operation behavior fingerprints and physical interface state data, wherein the physical interface state data comprises USB / network interface electrical characteristic fluctuation monitoring. Through multi-technology fusion and closed-loop design, the scheme effectively solves the problems of static nature, single-dimensional analysis defects and response lag of traditional industrial control security schemes, constructs a comprehensive protection system with dynamic modeling, intelligent decision-making, privacy protection and continuous optimization, and significantly improves the security and business reliability of the industrial control network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control network security technology, specifically to an industrial control network security business security assurance system based on behavior analysis. Background Technology

[0002] The Industrial Control System (ICS) Network Security Assurance System is a security protection system specifically designed for industrial control systems. It aims to defend against threats such as cyberattacks and malicious operations, ensuring stable industrial production and business continuity. Its core function is to guarantee the secure and controllable operation of industrial control systems, preventing production losses or data leaks due to security risks. However, existing ICS network security assurance systems still have the following shortcomings:

[0003] 1. Static rule dependency: Traditional solutions mainly rely on predefined rule bases or single risk assessment models, which are difficult to adapt to dynamically changing industrial control environments and new attack patterns;

[0004] 2. Insufficient single-dimensional analysis: The lack of multi-dimensional correlation analysis of user behavior, device status, and network traffic results in weak threat tracing capabilities;

[0005] 3. Response lag and high false alarm rate: The inadequacy of dynamic baseline modeling and adaptive strategies leads to a high false alarm rate and low efficiency in the execution of protection strategies.

[0006] Technological development needs:

[0007] Balancing data privacy and model generalization: Industrial control nodes have high data privacy requirements, and collaborative model training needs to be achieved while protecting data.

[0008] Improved real-time performance and accuracy: Industrial control systems have stringent real-time requirements, necessitating millisecond-level protection strategy delivery and high-precision attack prediction;

[0009] Business continuity assurance: Traditional solutions are prone to production interruptions due to accidental blocking, and protection logic needs to be optimized by combining virtual verification and policy conflict resolution.

[0010] To address this, a business security assurance system for industrial control network security based on behavioral analysis is proposed. Summary of the Invention

[0011] The present invention aims to solve the problems mentioned in the background art by providing a network security assurance system for industrial control systems based on behavior analysis.

[0012] The specific technical solution is as follows:

[0013] A network security assurance system for industrial control systems based on behavior analysis, comprising:

[0014] The multi-source data fusion acquisition module simultaneously acquires industrial control network traffic (including OPC UA / Modbus / DNP3 protocol parsing), equipment operation logs, user operation behavior fingerprints, and physical interface status data, including monitoring of electrical characteristic fluctuations of USB / network interfaces.

[0015] The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode equipment status data (PLC register values, sensor sampling rates) and user behavior data (operation command sequences, permission change records) respectively, and then fuses them through a spatiotemporal attention mechanism to generate a three-dimensional behavior baseline model.

[0016] The federated learning analytics cluster consists of edge computing units deployed on various industrial control nodes. It uses differential privacy technology to encrypt local behavioral features, achieves cross-domain model aggregation through a parameter server, and outputs a global abnormal behavior map.

[0017] The attack chain prediction module integrates Hidden Markov Model (HMM) and Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identifiers (reconnaissance, lateral movement, data infiltration).

[0018] The adaptive protection policy executor dynamically reconstructs access control rules based on the software-defined security (SDS) architecture, supports millisecond-level issuance and rollback of protection policies, and includes a triple protection mechanism of traffic rate limiting, port isolation, and command whitelisting.

[0019] The model evolution feedback loop optimizes the aggregated weights of federated learning through reinforcement learning, and employs adversarial example generation techniques to enhance the robustness of the baseline model against zero-day attacks.

[0020] The aforementioned industrial control network security assurance system based on behavior analysis includes a multi-source data fusion acquisition module that connects to the industrial control network in parallel via an industrial bus (such as PROFINET) and a mirror port, with its output connected to the heterogeneous data input interface of the dynamic behavior modeling engine.

[0021] The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and at the same time provides behavior deviation indicators to the attack chain prediction module.

[0022] Each edge computing unit of the federated learning analytics cluster is interconnected with the central parameter server through a time-sensitive network (TSN), and its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API.

[0023] The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and global anomaly graph from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via message queue (MQTT).

[0024] The adaptive protection strategy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, wherein:

[0025] The protection policy distribution interface is synchronized in real time with the SDN controller in the industrial control network;

[0026] The strategy execution effect data is collected by the data plane agent and sent back to the model evolution feedback loop;

[0027] The model evolution feedback loop establishes bidirectional data channels with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

[0028] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the multi-source data fusion and acquisition module includes:

[0029] The physical interface security protection unit adopts a composite structure of Y-shaped metal limit bar and piezoelectric sensor. When an unauthorized plugging and unplugging operation is detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously.

[0030] The protocol deep parsing unit supports instruction-level reassembly of industrial control protocols transmitted on non-standard ports and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

[0031] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the dynamic behavior modeling engine includes:

[0032] The equipment profile generation unit constructs differentiated behavioral evaluation indicators based on equipment type (PLC / RTU / HMI), with the PLC controller having an added register write frequency weighting factor.

[0033] The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions (operator / administrator / third party) and implements dual behavior verification for high-risk operations (such as firmware upgrades and clock synchronization).

[0034] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the federated learning analysis cluster adopts:

[0035] The gradient obfuscation mechanism injects Gaussian noise during local model training to ensure that the original data features cannot be restored during parameter updates.

[0036] The dynamic participation node selection algorithm dynamically adjusts the participating nodes in federated learning based on the online status of devices, remaining computing resources, and security status scores.

[0037] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the attack chain prediction module implements:

[0038] Multi-stage attack correlation analysis performs causal reasoning between abnormal device states (such as sudden changes in temperature sensor data) and network behaviors (such as abnormal external connections of SCADA servers), generating an attack stage assessment report mapped by the MITRE ATT&CK framework.

[0039] The risk quantification decision matrix uses the Analytic Hierarchy Process (AHP) to calculate the threat value for each attack path:

[0040]

[0041] Where w i S represents the weight of the attack phase. i denoted as the current behavior deviation, k as the situation sensitivity coefficient, and S0 as the baseline deviation threshold.

[0042] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the adaptive protection policy executor includes:

[0043] The digital twin verification sandbox virtually executes suspicious control commands and confirms attack behavior by comparing the state deviation value (Δ>15%) between the actual device and the digital twin.

[0044] The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive (such as when isolation and mirroring are triggered simultaneously).

[0045] The aforementioned industrial control network security assurance system based on behavior analysis includes a model evolution feedback loop implementation:

[0046] The adversarial example evolution mechanism uses Wasserstein GAN to generate adversarial examples that conform to industrial control physical constraints, thereby enhancing the model's ability to identify covert attacks.

[0047] The incremental learning scheduler automatically triggers local retraining of the model based on the device firmware upgrade record, maintaining the consistency between the behavioral baseline model and the version of the physical device.

[0048] The aforementioned industrial control network security assurance system based on behavior analysis, wherein the physical interface security protection unit integrates:

[0049] The multimodal authentication module needs to simultaneously verify the digital certificate (SM2 algorithm) and the physical key (NFC chip) when making a physical connection. If the authentication fails, the self-destruct fuse circuit is activated.

[0050] The electromagnetic fingerprint acquisition unit establishes a unique identifier database for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

[0051] The aforementioned industrial control network security assurance system based on behavior analysis includes a user behavior baseline database implemented as follows:

[0052] Two-factor behavior verification couples user biometrics (finger vein recognition) with operation timing patterns (click intervals, command combinations) for verification.

[0053] Context-aware correction automatically adjusts the allowed operation time window based on changes in the production plan, and implements the "four-eyes principle" approval for high-risk operations outside the planned period;

[0054] The aforementioned industrial control network security assurance system based on behavioral analysis incorporates the following risk quantification decision matrix:

[0055] Business impact factors are dynamically adjusted based on the process importance of the protected equipment (e.g., reactor pressure control vs. environmental monitoring) to calculate risk weights.

[0056] The situation propagation model calculates the probability of cascading failures that may be caused by a single point of failure based on the industrial control network topology.

[0057] The present invention has the following beneficial effects:

[0058] 1. Full-chain collaborative protection: By integrating multi-source data collection, dynamic behavior modeling, federated learning analysis, attack chain prediction, adaptive protection and model evolution feedback modules, a closed-loop protection system covering the entire process of "data collection-analysis-decision-execution-optimization" is constructed, which significantly improves the proactive defense capability against advanced persistent threats (APT) and zero-day attacks.

[0059] 2. Multi-dimensional security protection:

[0060] Physical layer defense: Effectively prevents hardware spoofing attacks through physical interface security protection units and unauthorized operation detection;

[0061] Protocol layer deep inspection: Supports non-standard port protocol reassembly and abnormal payload identification, improving the detection accuracy of protocol spoofing attacks;

[0062] Dynamic modeling at the behavioral level: Differentiated device profiles and user behavior baseline libraries enhance the ability to distinguish between legitimate operations and abnormal behaviors, reducing the risk of misjudgment.

[0063] 3. Intelligent decision-making and adaptive optimization:

[0064] Based on the privacy protection mechanism of federated learning, cross-node collaborative analysis is achieved, ensuring the generalization ability of the model while protecting data privacy.

[0065] By using digital twin sandbox verification and policy conflict resolution, the false blocking rate is reduced, ensuring the continuity of industrial control business.

[0066] Combining dynamic sensitivity coefficients with risk quantification models enhances the responsiveness to sudden attacks.

[0067] 4. Improved system robustness:

[0068] The model evolution feedback loop continuously optimizes the baseline model through adversarial example generation and incremental learning, adapting to firmware upgrades of industrial control equipment and new attack patterns;

[0069] Risk assessment based on business impact factors and situation propagation models can proactively prevent abnormal behaviors that may trigger cascading failures. Attached Figure Description

[0070] Figure 1 A schematic diagram of the architecture of an industrial control network security business security assurance system based on behavior analysis provided in an embodiment of the present invention;

[0071] Figure 2 A diagram illustrating the impact of the dynamic sensitivity coefficient k on the response time of the industrial control network security business security assurance system based on behavior analysis provided in this embodiment of the invention.

[0072] Figure 3 Error comparison chart of the improved normalization method for the industrial control network security business security assurance system based on behavior analysis provided in the embodiments of the present invention;

[0073] Figure 4 A comparison chart of attack identification accuracy of the industrial control network security protection system based on behavior analysis provided in this embodiment of the invention;

[0074] Figure 5 A comparison chart of false blocking rates of the industrial control network security protection system based on behavior analysis provided in this embodiment of the invention. Detailed Implementation

[0075] The technical solution of the present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0076] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual images. They should not be construed as limiting the scope of this patent. To better illustrate the embodiments of the present invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual dimensions of the product. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.

[0077] In the accompanying drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components. In the description of the present invention, it should be understood that if terms such as "upper," "lower," "left," "right," "inner," and "outer" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting the present patent. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.

[0078] In the description of this invention, unless otherwise explicitly specified and limited, the term "connection" or similar designation indicating a connection between components should be interpreted broadly. For example, it can refer to a fixed connection, a detachable connection, or an integral part; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can refer to the internal communication between two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0079] The industrial control network security protection system based on behavior analysis provided in this embodiment, such as... Figures 1-5 As shown, where Figure 2 The graph shows the impact of the dynamic sensitivity coefficient k on the response time, illustrating the effect of introducing the dynamic sensitivity coefficient k on the system's response time. Assuming the industry average response time is 100ms, this system, by dynamically adjusting the sensitivity coefficient k, reduces the response time to 1 / 5 of the industry average, significantly improving the system's response speed. Figure 3 To improve the error comparison of normalization methods, a comparison chart was created. The error performance of the traditional Min-Max normalization method and the improved Tanh normalization method was compared under data distribution offset scenarios. Assuming the traditional method has an error of 15%, the improved method, by optimizing the normalization process, reduces the error to 5%, significantly improving the accuracy of data processing. Figure 4The chart showing the attack identification accuracy comparison demonstrates the difference in attack identification accuracy between the traditional solution and our system in the StealthyFDI attack scenario. The traditional solution achieves an accuracy rate of 89.2%, while our system achieves an accuracy rate as high as 98.7%, significantly improving the accuracy of attack identification. Figure 5 The chart shows a comparison of false blocking rates, comparing the performance of our system with the industry benchmark. The industry benchmark has a false blocking rate of 9.1%, while our system, through algorithm optimization, reduces the false blocking rate to 2.3%, significantly reducing the occurrence of erroneous operations.

[0080] This industrial control network security assurance system based on behavior analysis includes: a multi-source data fusion and acquisition module, a dynamic behavior modeling engine, a federated learning analysis cluster, an attack chain prediction module, an adaptive protection strategy executor, and a model evolution feedback loop, wherein:

[0081] The multi-source data fusion acquisition module simultaneously acquires industrial control network traffic (including OPC UA / Modbus / DNP3 protocol parsing), equipment operation logs, user operation behavior fingerprints, and physical interface status data, including monitoring of electrical characteristic fluctuations of USB / network interfaces.

[0082] The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode equipment status data (PLC register values, sensor sampling rates) and user behavior data (operation command sequences, permission change records) respectively, and then fuses them through a spatiotemporal attention mechanism to generate a three-dimensional behavior baseline model.

[0083] The federated learning analytics cluster consists of edge computing units deployed on various industrial control nodes. It uses differential privacy technology to encrypt local behavioral features, achieves cross-domain model aggregation through a parameter server, and outputs a global abnormal behavior map.

[0084] The attack chain prediction module integrates Hidden Markov Model (HMM) and Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identifiers (reconnaissance, lateral movement, data infiltration).

[0085] The adaptive protection policy executor dynamically reconstructs access control rules based on the software-defined security (SDS) architecture, supports millisecond-level issuance and rollback of protection policies, and includes a triple protection mechanism of traffic rate limiting, port isolation, and command whitelisting.

[0086] The model evolution feedback loop optimizes the aggregated weights of federated learning through reinforcement learning, and employs adversarial example generation techniques to enhance the robustness of the baseline model against zero-day attacks.

[0087] The industrial control system network security business security assurance system based on behavior analysis, which adopts the above technical solution, integrates multi-source data collection, dynamic modeling, federated learning, attack prediction, adaptive protection and feedback optimization modules to build a collaborative protection system covering the entire chain, thereby improving the industrial control system's proactive defense capabilities against complex attacks and ensuring business continuity.

[0088] Specifically, in this embodiment, the multi-source data fusion acquisition module is connected to the industrial control network in parallel through an industrial bus (such as PROFINET) and a mirror port, and its output is connected to the heterogeneous data input interface of the dynamic behavior modeling engine.

[0089] The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and at the same time provides behavior deviation indicators to the attack chain prediction module.

[0090] Each edge computing unit of the federated learning analytics cluster is interconnected with the central parameter server through a time-sensitive network (TSN), and its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API.

[0091] The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and global anomaly graph from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via message queue (MQTT).

[0092] The adaptive protection strategy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, wherein:

[0093] The protection policy distribution interface is synchronized in real time with the SDN controller in the industrial control network;

[0094] The strategy execution effect data is collected by the data plane agent and sent back to the model evolution feedback loop;

[0095] The model evolution feedback loop establishes bidirectional data channels with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

[0096] By adopting the above technical solution, through parallel access of industrial bus and mirror port, time-sensitive network transmission and cross-layer feedback mechanism, efficient collaboration between various modules of the system is ensured, and real-time closed-loop response of data acquisition, analysis and decision-making and strategy execution is achieved.

[0097] Specifically, in this embodiment, the multi-source data fusion acquisition module includes:

[0098] The physical interface security protection unit adopts a composite structure of Y-shaped metal limit bar and piezoelectric sensor. When an unauthorized plugging and unplugging operation is detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously.

[0099] The protocol deep parsing unit supports instruction-level reassembly of industrial control protocols transmitted on non-standard ports and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

[0100] By adopting the above technical solutions, the physical layer security protection capability is enhanced, unauthorized devices are effectively prevented from accessing the network, the detection accuracy of protocol spoofing attacks is improved, and abnormal commands are prevented from penetrating the industrial control network.

[0101] Specifically, in this embodiment, the dynamic behavior modeling engine includes:

[0102] The equipment profile generation unit constructs differentiated behavioral evaluation indicators based on equipment type (PLC / RTU / HMI), with the PLC controller having an added register write frequency weighting factor.

[0103] The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions (operator / administrator / third party) and implements dual behavior verification for high-risk operations (such as firmware upgrades and clock synchronization).

[0104] By adopting the above technical solutions, we can achieve differentiated modeling of device behavior profiles and fine-grained control of user operations, improve the adaptability of the baseline model to device types and role permissions, and reduce the risk of misjudgment.

[0105] Specifically, in this embodiment, the federated learning analytics cluster adopts:

[0106] The gradient obfuscation mechanism injects Gaussian noise during local model training to ensure that the original data features cannot be restored during parameter updates.

[0107] The dynamic participation node selection algorithm dynamically adjusts the participating nodes in federated learning based on the online status of devices, remaining computing resources, and security status scores.

[0108] By adopting the above technical solution, the efficiency of federated learning is optimized while protecting data privacy, and the participating nodes are dynamically adjusted to adapt to changes in the industrial control environment, ensuring the security of model training and the utilization rate of resources.

[0109] Specifically, in this embodiment, the attack chain prediction module implements:

[0110] Multi-stage attack correlation analysis performs causal reasoning between abnormal device states (such as sudden changes in temperature sensor data) and network behaviors (such as abnormal external connections of SCADA servers), generating an attack stage assessment report mapped by the MITRE ATT&CK framework.

[0111] The risk quantification decision matrix uses the Analytic Hierarchy Process (AHP) to calculate the threat value for each attack path:

[0112]

[0113] Where w i S represents the weight of the attack phase. i denoted as the current behavior deviation, k as the situation sensitivity coefficient, and S0 as the baseline deviation threshold.

[0114] By adopting the above technical solution, multi-dimensional anomaly characteristics and attack framework knowledge are integrated to enhance the predictive ability of multi-stage attack chains and realize the quantitative assessment and priority classification of risk threats.

[0115] The parameters of the risk quantification decision matrix are defined as follows:

[0116] 1. Attack phase weight w i :

[0117] Technical definition: Based on the attack phases (reconnaissance, weaponization, lateral movement, etc.) divided by the MITRE ATT&CK framework, the judgment matrix is ​​calculated using the Analytic Hierarchy Process (AHP). The scale value of the judgment matrix comes from the device criticality score (CVE vulnerability level × business impact factor).

[0118] Dynamic adjustment mechanism:

[0119] Initial values: Preset baseline weights based on equipment type (PLC controller weight range [0.3, 0.6], HMI human-machine interface [0.1, 0.3]);

[0120] Runtime correction: Calculates a sliding average based on the attack pattern heat updated every 24 hours by a threat intelligence subscription service (such as the MISP platform);

[0121] 2. Current behavior deviation S i :

[0122] Computational model:

[0123]

[0124] Where V current Real-time behavioral feature vector V baseline For the baseline model output, σ historical The standard deviation of historical data, = 1e -5 Prevent division by zero errors;

[0125] Normalization: A modified Tanh function is used to normalize S. i Mapping to the [0,1] interval:

[0126]

[0127] 3. Situation sensitivity coefficient k:

[0128] Dynamic calculation equation:

[0129]

[0130] k base : Basic sensitivity (default value 2.5, configurable range [1.0, 5.0]);

[0131] α: Environmental threat coefficient (obtained through real-time threat intelligence interface, value range [0.1, 0.9])

[0132] N alert : The number of alarms triggered in the current attack chain;

[0133] N total : The total number of stages in the attack chain;

[0134] Mechanism of action: When the completion degree of the attack chain exceeds 30%, the kk value is automatically increased by 1.8 times to enhance the risk perception sensitivity.

[0135] 4. Baseline deviation threshold S0:

[0136] Generation method:

[0137] Offline stage: Calculate the upper bound of the 95% confidence interval of the historical normal data distribution through kernel density estimation (KDE);

[0138] Online stage: Update using exponential weighted moving average (EWMA):

[0139]

[0140] Among them, the smoothing factor λ = 0.85 (configurable range [0.7, 0.95]);

[0141] Abnormal reset: When S i > 2S0 for 3 consecutive times, trigger the emergency reconstruction process of the baseline model;

[0142] 5. Nonlinear transformation function:

[0143] Technical effect: Using the sigmoid function to replace the traditional linear superposition to solve the following problems:

[0144] The inhibitory effect on low-deviation attacks (S i < S0) (output value < 0.5);

[0145] The saturation characteristic of high-deviation attacks (S i > 2S0) (output value approaches 1);

[0146] Engineering optimization: Linear interpolation is used in the S0±0.2 interval to avoid strategy oscillation caused by sudden changes in inflection points.

[0147] This scheme combines AHP weights with real-time threat intelligence, significantly improving the APT attack detection rate; the introduction of a dynamic sensitivity coefficient k greatly shortens the response time to sudden attacks from the industry average; the improved Tanh normalization method significantly reduces errors in scenarios with data distribution deviations compared to the traditional Min-Max normalization; and the EWMA threshold update mechanism significantly reduces the false alarm rate compared to the fixed threshold scheme.

[0148] Technical effectiveness verification: Tested on the OPC UA testbed, this parameter system performs well under Stealthy FDI attack scenarios:

[0149] Attack identification accuracy: 98.7% (compared to 89.2% for traditional solutions);

[0150] False blocking rate: 2.3% (compared to industry benchmark of 9.1%);

[0151] It meets the enhanced requirements of SR 3.8 (anomaly detection) and SR 3.10 (risk assessment) in the IEC 62443-3-3 standard.

[0152] Specifically, in this embodiment, the adaptive protection strategy executor includes:

[0153] The digital twin verification sandbox virtually executes suspicious control commands and confirms attack behavior by comparing the state deviation value (Δ>15%) between the actual device and the digital twin.

[0154] The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive (such as when isolation and mirroring are triggered simultaneously).

[0155] By adopting the above technical solution, the effectiveness of the strategy is verified through virtual execution, and strategy conflicts are intelligently resolved, so as to maintain the normal operation of industrial control business to the greatest extent while ensuring security protection.

[0156] Specifically, in this embodiment, the model evolution feedback loop is implemented as follows:

[0157] The adversarial example evolution mechanism uses Wasserstein GAN to generate adversarial examples that conform to industrial control physical constraints, thereby enhancing the model's ability to identify covert attacks.

[0158] The incremental learning scheduler automatically triggers local retraining of the model based on the device firmware upgrade record, maintaining the consistency between the behavioral baseline model and the version of the physical device.

[0159] By adopting the above technical solutions, the model's ability to generalize to new attack patterns is improved, and the dynamic synchronization between the baseline model and the device firmware version is ensured, thus avoiding protection failure due to system upgrades.

[0160] Specifically, in this embodiment, the physical interface security protection unit integrates:

[0161] The multimodal authentication module needs to simultaneously verify the digital certificate (SM2 algorithm) and the physical key (NFC chip) when making a physical connection. If the authentication fails, the self-destruct fuse circuit is activated.

[0162] The electromagnetic fingerprint acquisition unit establishes a unique identifier database for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

[0163] By adopting the above technical solutions, multi-factor authentication and hardware uniqueness identification of physical interfaces are strengthened, effectively defending against physical layer spoofing attacks and improving the traceability of interface operations.

[0164] Specifically, in this embodiment, the user behavior baseline library is implemented as follows:

[0165] Two-factor behavior verification couples user biometrics (finger vein recognition) with operation timing patterns (click intervals, command combinations) for verification.

[0166] Context-aware correction automatically adjusts the allowed operation time window based on changes in the production plan, and implements the "four-eyes principle" for approval of high-risk operations outside the planned period.

[0167] By adopting the above technical solution, and combining biometrics and operational behavior for dual verification, the system can dynamically adapt to changes in the production environment, thereby achieving precise control and audit tracking of high-risk operations.

[0168] Specifically, in this embodiment, a risk quantification decision matrix is ​​introduced:

[0169] Business impact factors are dynamically adjusted based on the process importance of the protected equipment (e.g., reactor pressure control vs. environmental monitoring) to calculate risk weights.

[0170] The situation propagation model calculates the probability of cascading failures that may be caused by a single point of failure based on the industrial control network topology.

[0171] By adopting the above technical solution and introducing business logic and network topology correlation analysis, the risk assessment can be more in line with actual production needs, and abnormal behaviors that may cause cascading failures can be blocked in advance.

[0172] Among them, the spatiotemporal attention mechanism achieves multidimensional data fusion through the spatiotemporal anomaly perception fusion weight equation (STAFW), which is as follows:

[0173]

[0174] in:

[0175] A i,j This represents the fusion weight of device i within time window j, used to dynamically adjust the contribution of device behavior features to the baseline model;

[0176] ΔT i The standard deviation of the device state sequence is calculated using a sliding window as a time dynamic factor.

[0177] Φ i,j The spatial correlation factor is calculated based on the reciprocal of the shortest path hop count between devices in the industrial control network topology.

[0178] The anomaly factor represents the real-time feature vector V. i Compared with baseline model output The Euclidean distance;

[0179] σ i The standard deviation of historical data for device i;

[0180] λ t , λ s , λ a These are configurable hyperparameters that control the weights of the time, space, and anomaly dimensions, respectively (default value: λ). t =0.4,λ s =0.3,λ a =0.3).

[0181] τ and η are normalization coefficients used to balance the differences in the dimensions of each factor and prevent numerical overflow (τ = 10ms, η = 5).

[0182] For example, in a dynamic behavior modeling engine, suppose a PLC controller detects a sudden change in register value (ΔT) within a time window j=5. i =8.2), the logical distance to the SCADA server is 2 hops (Φ i,j =0.6), and the real-time features deviate from the baseline. Substitute into the equation to calculate:

[0183]

[0184] The results showed that the device's features were given high weight during fusion, triggering deep anomaly analysis.

[0185] Technical effects:

[0186] Dynamic weight allocation: By combining spatiotemporal factors and abnormal factors, it accurately captures sudden and related abnormal behaviors in industrial control systems.

[0187] Reduced false positive rate: Compared with the traditional mean fusion method, the false positive rate is significantly reduced in the StealthyFDI attack scenario.

[0188] Real-time optimization: The normalization coefficient design keeps the computational complexity at O(N), meeting the millisecond-level response requirements of industrial control systems.

[0189] The spatiotemporal attention mechanism implements a multidimensional data fusion workflow through the Spatiotemporal Anomaly Awareness Fusion Weight Equation (STAFW):

[0190] 1. Data preprocessing: Real-time acquisition of device status (such as PLC register values) and network topology data;

[0191] 2. Factor calculation:

[0192] Time dynamic factor ΔT i Calculate the standard deviation of the state sequence using a sliding window (e.g., 1 second);

[0193] Spatial correlation factor Φ i,j Calculate the reciprocal of the shortest path between devices based on the network topology graph (e.g., Φ). i,j =1 / number of jumps);

[0194] Anomaly factor: Real-time comparison of the deviation between the feature vector and the baseline model.

[0195] 3. Weighted Fusion: Substitute each factor into the STAFW equation to generate a weighted behavioral feature vector.

[0196] 4. Baseline Model Update: The spatiotemporal attention mechanism dynamically adjusts the generation process of the 3D behavioral baseline based on weights. By incorporating network topology correlation into the fusion weights, it addresses the problem of traditional methods neglecting logical dependencies between devices, using historical standard deviation σ. i Dynamically normalized anomalies avoid misjudgments caused by inherent equipment fluctuations. Hyperparameter λ t , λ s , λ a It allows maintenance personnel to flexibly adjust the detection sensitivity according to business needs.

[0197] In summary, the industrial control network security assurance system based on behavior analysis provided in this embodiment has the following advantages:

[0198] 1. Full-chain collaborative protection: By integrating multi-source data collection, dynamic behavior modeling, federated learning analysis, attack chain prediction, adaptive protection and model evolution feedback modules, a closed-loop protection system covering the entire process of "data collection-analysis-decision-execution-optimization" is constructed, which significantly improves the proactive defense capability against advanced persistent threats (APT) and zero-day attacks.

[0199] 2. Multi-dimensional security protection:

[0200] Physical layer defense: Effectively prevents hardware spoofing attacks through physical interface security protection units and unauthorized operation detection;

[0201] Protocol layer deep inspection: Supports non-standard port protocol reassembly and abnormal payload identification, improving the detection accuracy of protocol spoofing attacks;

[0202] Dynamic modeling at the behavioral level: Differentiated device profiles and user behavior baseline libraries enhance the ability to distinguish between legitimate operations and abnormal behaviors, reducing the risk of misjudgment.

[0203] 3. Intelligent decision-making and adaptive optimization:

[0204] Based on the privacy protection mechanism of federated learning, cross-node collaborative analysis is achieved, ensuring the generalization ability of the model while protecting data privacy.

[0205] By using digital twin sandbox verification and policy conflict resolution, the false blocking rate is reduced, ensuring the continuity of industrial control business.

[0206] Combining dynamic sensitivity coefficients with risk quantification models enhances the responsiveness to sudden attacks.

[0207] 4. Improved system robustness:

[0208] The model evolution feedback loop continuously optimizes the baseline model through adversarial example generation and incremental learning, adapting to firmware upgrades of industrial control equipment and new attack patterns;

[0209] Risk assessment based on business impact factors and situation propagation models can proactively prevent abnormal behaviors that may trigger cascading failures.

[0210] The specific workflow is as follows:

[0211] 1. Data Acquisition and Fusion:

[0212] The system can access the industrial control network in parallel via industrial buses (such as PROFINET) and mirror ports to capture multi-source data (network traffic, device logs, user operations, physical interface status) in real time.

[0213] The physical interface security protection unit synchronously monitors illegal plugging and unplugging behavior, and the protocol parsing unit reassembles the industrial control commands transmitted through non-standard ports.

[0214] 2. Dynamic Behavior Modeling:

[0215] Heterogeneous data processing pipelines encode device status (such as PLC register values) and user behavior (such as operation instruction sequences) respectively;

[0216] The spatiotemporal attention mechanism integrates multidimensional data to generate a three-dimensional behavioral baseline model.

[0217] 3. Federated Learning and Threat Prediction:

[0218] Edge computing nodes use differential privacy technology to encrypt local features and aggregate global anomaly maps through Time-Sensitive Network (TSN);

[0219] The attack chain prediction module combines HMM and GNN to analyze the correlation between abnormal device states and network behavior, and generate an attack phase assessment report.

[0220] 4. Adaptive protection execution:

[0221] Dynamically deploy protection policies (such as traffic rate limiting and port isolation) based on software-defined security (SDS);

[0222] A digital twin sandbox virtually executes suspicious commands, and the authenticity of the attack is verified through state deviation.

[0223] The strategy conflict resolver selects the optimal execution plan based on business priorities.

[0224] 5. Closed-loop optimization and evolution:

[0225] The model evolution feedback loop optimizes federated learning weights through reinforcement learning and enhances model robustness by utilizing adversarial examples.

[0226] The incremental learning scheduler triggers local model retraining based on device firmware upgrade records to maintain dynamic system synchronization.

[0227] This solution effectively addresses the static nature, single-dimensional analysis deficiencies, and delayed response issues of traditional industrial control security solutions through multi-technology integration and closed-loop design. It constructs a comprehensive protection system with dynamic modeling, intelligent decision-making, privacy protection, and continuous optimization, significantly improving the security and business reliability of industrial control networks.

[0228] The above are merely preferred embodiments of the present invention and are not intended to limit the implementation methods and protection scope of the present invention. Those skilled in the art should recognize that any equivalent substitutions and obvious changes made based on the description and illustrations of the present invention should be included within the protection scope of the present invention.

Claims

1. A network security assurance system for industrial control systems based on behavioral analysis, characterized in that, include: The multi-source data fusion acquisition module simultaneously acquires industrial control network traffic, equipment operation logs, user operation behavior fingerprints, and physical interface status data, including physical interface status data such as monitoring of electrical characteristic fluctuations of USB / network interfaces. The dynamic behavior modeling engine uses a heterogeneous data processing pipeline to encode device status data and user behavior data respectively, and then uses a spatiotemporal attention mechanism to fuse and generate a three-dimensional behavior baseline model. The federated learning analytics cluster consists of edge computing units deployed on various industrial control nodes. It uses differential privacy technology to encrypt local behavioral features, achieves cross-domain model aggregation through a parameter server, and outputs a global abnormal behavior map. The attack chain prediction module integrates Hidden Markov Model (HMM) and Graph Neural Network (GNN) to predict potential attack paths based on real-time behavioral deviations and generate threat intelligence including attack stage identifiers. The adaptive protection policy executor dynamically reconstructs access control rules based on the software-defined security (SDS) architecture, supports millisecond-level issuance and rollback of protection policies, and includes a triple protection mechanism of traffic rate limiting, port isolation, and command whitelisting. The model evolution feedback loop optimizes the aggregated weights of federated learning through reinforcement learning, and employs adversarial example generation techniques to enhance the robustness of the baseline model against zero-day attacks.

2. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The multi-source data fusion acquisition module is connected to the industrial control network in parallel through the industrial bus and mirror port, and its output is connected to the heterogeneous data input interface of the dynamic behavior modeling engine. The dynamic behavior modeling engine receives real-time data streams from the multi-source data fusion acquisition module. Its baseline model output is connected to the local model upload interface of the federated learning analysis cluster via the OPC UA protocol, and at the same time provides behavior deviation indicators to the attack chain prediction module. Each edge computing unit of the federated learning analytics cluster is interconnected with the central parameter server through a time-sensitive network (TSN). Its global anomaly graph generation end is connected to the threat intelligence fusion layer of the attack chain prediction module via a RESTful API. The attack chain prediction module receives real-time deviation data from the dynamic behavior modeling engine and the global anomaly map from the federated learning analysis cluster. Its attack path prediction results are pushed to the policy decision engine of the adaptive protection policy executor via the message queue MQTT. The adaptive protection strategy executor includes an OpenFlow interface directly connected to the control plane switch and an execution result feedback channel, wherein: The protection policy distribution interface is synchronized in real time with the SDN controller in the industrial control network; The strategy execution effect data is collected by the data plane agent and sent back to the model evolution feedback loop; The model evolution feedback loop establishes bidirectional data channels with the weight adjustment interface of the dynamic behavior modeling engine and the aggregation algorithm update interface of the federated learning analysis cluster through a cross-layer feedback bus, forming a closed-loop optimization mechanism.

3. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The multi-source data fusion acquisition module includes: The physical interface security protection unit adopts a composite structure of Y-shaped metal limit bar and piezoelectric sensor. When an unauthorized plugging and unplugging operation is detected, the physical locking mechanism and digital certificate revocation are triggered simultaneously. The protocol deep parsing unit supports instruction-level reassembly of industrial control protocols transmitted on non-standard ports and identifies abnormal payloads disguised as legitimate protocols through syntax tree comparison.

4. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The dynamic behavior modeling engine includes: The equipment profile generation unit constructs differentiated behavioral evaluation indicators based on equipment type (PLC / RTU / HMI), with the PLC controller having an added register write frequency weighting factor. The user behavior baseline library establishes a multi-level operation sequence Markov chain based on role permissions, and implements dual behavior verification for high-risk operations.

5. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The federated learning analytics cluster adopts: The gradient obfuscation mechanism injects Gaussian noise during local model training to ensure that the original data features cannot be restored during parameter updates. The dynamic participation node selection algorithm dynamically adjusts the participating nodes in federated learning based on the online status of devices, remaining computing resources, and security status scores.

6. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The attack chain prediction module implements: Multi-stage attack correlation analysis performs causal reasoning between abnormal device states and network behavior, generating an attack stage assessment report mapped by the MITRE ATT&CK framework. The risk quantification decision matrix uses the Analytic Hierarchy Process (AHP) to calculate the threat value for each attack path: Where w i S represents the weight of the attack phase. i denoted as the current behavior deviation, k as the situation sensitivity coefficient, and S0 as the baseline deviation threshold.

7. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The adaptive protection strategy executor includes: The digital twin verification sandbox virtually executes suspicious control commands and confirms attack behavior by comparing the state deviation value Δ between the actual device and the digital twin, which is greater than 15%. The policy conflict resolver automatically selects the optimal execution plan based on business continuity priority when multiple protection policies are mutually exclusive.

8. The industrial control network security assurance system based on behavior analysis according to claim 1, characterized in that, The model evolution feedback loop is implemented as follows: The adversarial example evolution mechanism uses Wasserstein GAN to generate adversarial examples that conform to industrial control physical constraints, thereby enhancing the model's ability to identify covert attacks. The incremental learning scheduler automatically triggers local retraining of the model based on the device firmware upgrade record, maintaining the consistency between the behavioral baseline model and the version of the physical device.

9. The industrial control network security assurance system based on behavior analysis according to claim 3, characterized in that, The physical interface security protection unit integrates: The multimodal authentication module needs to simultaneously verify the digital certificate and physical key when making a physical connection. If the authentication fails, the self-destruct fuse circuit is activated. The electromagnetic fingerprint acquisition unit establishes a unique identifier database for the device hardware by monitoring the electromagnetic radiation characteristics when the interface is connected.

10. The industrial control network security assurance system based on behavior analysis according to claim 4, characterized in that, The user behavior baseline library is implemented as follows: Two-factor behavioral verification couples user biometrics with operation timing patterns for verification; Context-aware correction automatically adjusts the allowed operation time window based on changes in the production plan, and implements the "four-eyes principle" for approval of high-risk operations outside the planned period.

Citation Information

Patent Citations

  • An industrial host network security operation and maintenance monitoring system

    CN119766482A

  • Information security risk assessment whole-process management system

    CN119939591A