Industrial control system safety assessment method based on multi-source heterogeneous data fusion
Through the multi-source heterogeneous data fusion method, the industrial control system is evaluated using PCA, DeepSeek v3 0324 and TGNN-CA models, which solves the problem of multi-source heterogeneous data fusion, and realizes a comprehensive and accurate assessment of the system security situation, and quantitative analysis is carried out in combination with business impact to support accurate security management and operation and maintenance.
Patent Information
- Application Number
- CN202510738483.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-08-12
AI Technical Summary
The prior art cannot effectively integrate multi-source heterogeneous data for comprehensive and accurate industrial control system security assessment, and lacks a comprehensive assessment of security and business performance, making it difficult to deal with dynamically changing attack patterns and system operation status.
The multi-source heterogeneous data fusion method is used to reduce the dimensionality through principal component analysis PCA, and combined with the DeepSeek v3 0324 model and the timing diagram neural network TGNN-CA, the system log and network traffic data are security assessment, and the fusion analysis is carried out to generate an accurate security situation evaluation report.
It significantly improves the comprehensiveness and accuracy of industrial control system security assessment, can respond to system changes and complex attack modes, provide accurate security status assessment, and conduct quantitative analysis based on business impact, supporting more accurate security management and operation and maintenance.
Smart Images

Figure CN120474800A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial control systems, and in particular to an industrial control system security assessment method based on multi-source heterogeneous data fusion. Background Art
[0002] The security of industrial control systems (ICS) has become a critical issue due to the increasing convergence of industry and information technology and the rise of cyber threats targeting critical infrastructure. ICS, which include systems such as supervisory control and data acquisition (SCADA), distributed control systems (DCS), and programmable logic controllers (PLC), are at the heart of industries such as energy, manufacturing, transportation, and utilities. Cyberattacks against ICS can have far-reaching consequences, including physical damage to equipment, operational disruptions, and even loss of life.
[0003] In 2018, in the paper "IIoT Cybersecurity Risk Modeling for SCADA Systems," authors Gregory Falco et al. focused on risk assessment of SCADA systems, specifically targeting SCADA vulnerabilities and their potential exploitation in critical infrastructure. The study demonstrated that a data-driven approach can more accurately assess the security risks of SCADA systems, providing strong guidance for future SCADA security research. The study also proposed technical SCADA IIoT design recommendations to help mitigate the risk of future system exploitation. Given the central role of SCADA systems in society's operations, the study emphasized the importance of a data-driven prioritization approach to identifying security vulnerabilities specific to SCADA software subclasses, which is crucial for ensuring the security of critical infrastructure. While the study emphasized the importance of data-driven security assessments, it focused solely on SCADA systems.
[0004] In the 2022 paper "QualSec: An Automated Quality-Driven Approach for Security Risk Identification in Cyber-Physical Production Systems," Matthias Eckhart et al. proposed an automated approach, called QualSec, for automatically identifying security risks associated with industrial control systems in the industrial sector and analyzing potential attack paths and their impact on product quality. This approach leverages semantic engineering knowledge representation, enabling efficient reuse of engineering models from AutomationML artifacts to identify cascading effects. QualSec also employs Petri net analysis to provide in-depth analysis of security risks and cascading effects, providing information on possible attack paths, how attackers can conceal malicious behavior, and the consequences of attacks on product quality. This research innovatively moves beyond analyzing security risks to linking them to the consequences of attacks on product quality. However, QualSec relies on the engineering data exchange format (AML), which limits its analytical power in the context of multi-source heterogeneous data sources.
[0005] In 2019, patent CN201911021420.7, "A Method and System for Assessing Information Security Attack Risks in Industrial Control Systems," proposed a simulation method for assessing information security attack risks in industrial control systems. This method, applied to an information security attack risk simulation device comprised of multiple components, such as a main controller, a water tank, an overflow valve, a solenoid valve, and a liquid level sensor, simulates the liquid level control process of a control system. The method first acquires risk assessment indicator data, which includes four categories: controlled object status data, control algorithm parameters, attack type data, and control environment status data. Each data category includes multiple parameter values, such as the water tank level, solenoid valve opening, control algorithm parameters, and attack type. By determining whether a risk signal is generated and calculating a risk value based on each data type, the information security attack risk value is ultimately determined, and the risk level is determined. The control error is calculated by comparing the difference between the actual liquid level and the set value. This is an early method that uses multiple data sets to comprehensively assess risk levels, but it is limited to risk assessment of the liquid level control process of the control system, which has significant limitations.
[0006] In 2022, patent CN202111402855.3, "Quantitative Assessment Method for Functional Safety of Industrial Control Systems Based on Digital Twin Technology," proposed a method for quantitative assessment of functional safety of industrial control systems. First, by establishing a digital twin model, the operation of the equipment under different operating conditions is simulated, fault data is generated, and a fault identification model is trained. Then, the degree of equipment failure is quantified by calculating offsets, and future offset trends are predicted. Finally, the functional safety risk value of each operating device is calculated by combining current and future offsets, and the functional safety risk value of the entire system is weighted. This method can provide early warning of faults and quantify safety risks, supporting the safety management of industrial control systems. However, this method is based on simulation and does not leverage the real data captured by industrial equipment in the real world.
[0007] In 2022, patent CN202111345538.2, "A One-Way Security Detection and Multi-Factor Weighted Assessment System for Industrial Control Terminal Devices," proposed a one-way security detection and multi-factor weighted assessment system for industrial control terminal devices. The system comprises multiple modules. The indicator assessment system construction module constructs a risk assessment indicator system for terminal devices and analyzes correlations between indicators. The industrial control security data acquisition module collects data based on the risk assessment indicator system. The secure one-way communication module implements one-way communication with the secure data one-way communication hardware, ensuring unidirectional data transmission after Layer 2 data processing. The secure data one-way communication hardware filters the received data for external networks and forwards it to the multi-factor weighted assessment module. This module scores each indicator data type and, in combination with timeliness factors, detection time factors, user security requirements factors, and indicator correlations, comprehensively weights the terminal device's security to determine a final security score. This system leverages data from different modules and uses a weighted algorithm to derive an overall device security score. However, the weighted data used by this system only considers the industrial control terminal device and does not encompass the entire industrial control system, resulting in a partial security score.
[0008] Clearly, the aforementioned methods cannot be effectively applied to complete industrial control system security assessments. This is primarily due to the fact that industrial control systems consist of multiple modules and contain data with diverse structures. Industrial control data is characterized by its heterogeneity and multi-source nature, often underpinned by strong temporal sequences. Assessing the entire industrial control system requires the integration of this heterogeneous data. Furthermore, existing security assessments are typically conducted separately from business assessments, lacking a comprehensive evaluation of security and business performance. This independence can lead to overlooking the overall business impact of the system when optimizing performance, and vice versa. Furthermore, traditional security assessment methods often rely on static rules or manually defined rule bases, making them difficult to adapt to dynamically changing attack patterns or system operating conditions. This also makes it difficult for current industrial control system security assessments to capture real-time or emerging security threats. Summary of the Invention
[0009] The purpose of the present invention is to design an industrial control system security assessment method based on multi-source heterogeneous data fusion in order to solve the above problems.
[0010] The present invention achieves the above-mentioned purpose through the following technical solutions:
[0011] Industrial control system security assessment method based on multi-source heterogeneous data fusion, including:
[0012] S1. Obtain relevant data of industrial control systems and network traffic data and pre-process them;
[0013] S2. Use principal component analysis (PCA) to reduce the dimension of the processed data;
[0014] S3. Perform security assessment on the relevant data of the industrial control system and the network traffic data after dimensionality reduction, and obtain a first assessment result and a second assessment result respectively;
[0015] The security assessment of the industrial control system after dimensionality reduction is performed to obtain the first assessment results, specifically:
[0016] (1) Use the DeepSeek v3 0324 model to conduct a preliminary evaluation and analysis of the relevant data of the industrial control system after dimensionality reduction. The analysis results include anomaly identification results, risk levels, and recommended repair actions;
[0017] (2) Associating the analysis results with the industrial safety knowledge graph to generate the first evaluation results;
[0018] Perform security assessment on the network traffic data after dimensionality reduction to obtain the second assessment result, specifically:
[0019] 1) Perform spatiotemporal feature alignment on the network data after dimensionality reduction;
[0020] 2) Use the time series graph neural network (TGNN-CA) to perform time series analysis and security assessment on the aligned network data to obtain the second assessment result;
[0021] S4. Fusing the first evaluation result and the second evaluation result to obtain an evaluation result;
[0022] S5. Classify and grade the risk impact based on the assessment results;
[0023] S6. Output evaluation report based on risk classification.
[0024] The beneficial effects of the present invention are: by separately processing system logs and network traffic data from multi-source heterogeneous data, the comprehensiveness and accuracy of industrial control system security assessments are significantly improved. DeepSeek v3 0324 is used to conduct security assessments on system logs, and a time-series graph neural network is used to analyze network traffic data. Ultimately, the assessment results of the two are integrated to provide a more comprehensive security situation. This method can effectively respond to changes in system operation and complex attack patterns, providing accurate security status assessments for industrial control systems. This method of independent evaluation of multi-source data avoids the limitations of traditional methods that cannot fully reflect the system security situation, and provides more accurate security management and operation and maintenance support. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is a flow chart of the industrial control system security assessment method based on multi-source heterogeneous data fusion of the present invention;
[0026] Figure 2 This is a flowchart of the security assessment based on DeepSeek v3 0324 and the temporal graph neural network;
[0027] Figure 3 It is a flowchart of the triple adversarial training mechanism flow chart. DETAILED DESCRIPTION
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more apparent, the technical solutions of the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present invention. It should be understood that the described embodiments are only a portion of the embodiments of the present invention, not all of them. Generally, the components of the embodiments of the present invention described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations.
[0029] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.
[0030] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0031] In the description of the present invention, it should be understood that the terms "upper", "lower", "inside", "outside", "left", "right", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, or are the orientations or positional relationships in which the inventive product is conventionally placed when in use, or are the orientations or positional relationships conventionally understood by those skilled in the art. These are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or component referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present invention.
[0032] Furthermore, the terms “first”, “second”, etc. are merely used for distinguishing descriptions and should not be understood as indicating or implying relative importance.
[0033] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, terms such as "disposed" and "connected" should be understood in a broad sense. For example, "connected" can mean a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can also mean internal communication between two components. Those skilled in the art will be able to understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0034] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0035] Industrial control system security assessment method based on multi-source heterogeneous data fusion, including:
[0036] S1. Obtain relevant data from the industrial control system and network traffic data and preprocess them. The preprocessing includes:
[0037] 1. Use filtering to remove noise from industrial control system data and network traffic data, retaining the key components of the data. The relevant data is system logs. In industrial control systems, sensor or system failures can cause noise in collected log or traffic data. Log data also requires preliminary processing, namely deserialization and extraction of key data fields.
[0038] The filtering method eliminates these irrelevant signal components by setting a threshold, thereby improving the quality of the data and the accuracy of subsequent analysis. The weighted moving average method (WMA) is used for data denoising. It is based on the weighted average of past data points, giving higher weights to the most recent observations, so as to better capture trends rather than short-term noise. The calculation formula of WMA is: ,in is the data value after filtering, For past data points, is the weight of each data point. In this way, the filtering method can effectively remove noise from the data and improve the smoothness of the data, which is helpful for subsequent analysis and decision-making.
[0039] ② Use Z-score standardization to convert the filtered data into standardized data. Z-score standardization converts the data into a standard normal distribution (mean 0, standard deviation 1), so that each feature in the data can be compared at the same scale. Standardization is very important for reliable and fast processing of multi-source data, especially when the data comes from different sensors or measurement devices. Using a unified standard can eliminate scale differences between different data and prevent certain features from taking too much weight in the analysis process. The formula for Z-score standardization is: Among them, A is the original data, is the mean of the data, Where, where is the standard deviation of the data, and Z is the Z-score normalized value. In industrial control systems, if multiple modules transmit data, without normalization, the data may be difficult to directly compare due to varying units of measurement. Using Z-score normalization, all data is converted to dimensionless, standardized values, making subsequent multi-source data processing, analysis, and fusion evaluation easier and more accurate.
[0040] ③. Use interpolation to interpolate the standardized data, fill in the missing values, and obtain the relevant data and network traffic data of the filled industrial control system. The interpolation method infers the possible values of the missing values based on the trends and changes of the data, thereby maintaining the continuity and integrity of the data. In industrial control systems, some data points may occasionally be lost during data transmission due to failures or communication problems. The use of linear interpolation can effectively fill these missing values. The linear interpolation method is based on the linear relationship between the known data points at both ends. The calculation formula is: ,in, Fill the missing values in the result, and are the known data points before and after the missing value, and is the corresponding time point, is the time point of the missing value, is the missing value after filling. Through interpolation, missing values can be effectively filled to ensure the integrity and continuity of the data, thereby providing stable data support for subsequent analysis.
[0041] S2. Use principal component analysis (PCA) to reduce the dimensionality of the processed data. PCA aims to map high-dimensional data to a low-dimensional space while preserving the variance information of the original data as much as possible. PCA transforms multiple original variables into a few principal components through linear transformation, thereby reducing the dimensionality of the data, simplifying the data structure, improving computational efficiency, and reducing subsequent computational complexity, thereby achieving more efficient data analysis and fusion. Specifically, it includes:
[0042] S21. Calculate the covariance matrix to measure the linear relationship between different features, expressed as: , where X is the standardized data matrix, n is the number of samples, is a matrix The transpose of , C is the covariance matrix;
[0043] S22. Perform eigenvalue decomposition on the covariance matrix to obtain eigenvalues and eigenvectors, where the eigenvectors represent the main component directions of the data, and the eigenvalues represent the data variance in that direction;
[0044] S23. Select the first k principal components from largest to smallest according to the size of the eigenvalues;
[0045] S24. Project the unselected principal components with large eigenvalues onto the selected principal components to obtain the data after dimensionality reduction, which is expressed as: , where B is the original data matrix, D is the eigenvector matrix, For data after dimensionality reduction, dimensionality reduction can retain the principal components with larger eigenvalues and effectively reduce information loss.
[0046] S2', based on the statistical distribution detection of dynamic thresholds, automatically removes outliers that deviate from the normal mode by more than 3 standard deviations; at the same time, a multimodal verifier is used to verify the consistency across data sources to obtain cleaned data.
[0047] S3. Perform security assessment on the relevant data of the industrial control system and the network traffic data after dimensionality reduction, and obtain a first assessment result and a second assessment result respectively;
[0048] The security assessment of the industrial control system after dimensionality reduction is performed to obtain the first assessment results, specifically:
[0049] The Fluentd log collection tool further standardizes heterogeneous logs of industrial control systems (such as PLC operation logs, server audit logs, and equipment alarm logs) and converts them into a unified JSON format to achieve field mapping and format alignment. Regular expressions and semantic analysis are also used to desensitize sensitive information.
[0050] (1) The DeepSeek v3 0324 model was used to conduct a preliminary evaluation and analysis of the relevant data of the industrial control system after dimensionality reduction. The analysis results included anomaly identification results, risk levels, and recommended repair actions; specifically:
[0051] Log feature engineering: Device topology relationships (such as the communication link between PLCs and SCADA) and asset importance tags (such as P0-level critical equipment) are injected into log entries to enhance the model's understanding of industrial scenarios. spaCy is then used to extract entities (such as device numbers and error codes) and action verbs (such as "restart" and "overload") from the logs, constructing structured feature vectors to extract key data.
[0052] Model reasoning and threat identification: Use prompt word engineering and knowledge base to enhance the recognition ability of large models; design domain-specific prompt templates to guide the model to focus on the security assessment objectives of industrial control systems. Reference prompt word templates are:
[0053] As an industrial security expert, analyze the following logs:
[0054] [Device ID]{device_id}
[0055] [Log content]{message}
[0056] Please execute:
[0057] 1. Determine the type of anomaly (hardware failure / configuration error / malicious attack)
[0058] 2. Assess risk level (Critical / High / Medium / Low)
[0059] 3. Recommended remediation actions (such as firmware upgrades and access control policy adjustments)
[0060] (2) Associate the analysis results with the industrial safety knowledge graph to generate the first evaluation result; inject the analysis results in the form of vectors to improve the accuracy of diagnosis. The reference template is:
[0061] Known vulnerability: CVE-2025-1234 (Siemens PLC firmware buffer overflow)
[0062] Current log: PLC-001 memory usage continues to exceed 90%
[0063] Reasoning requirements:
[0064] 1. Determine whether it is a sign of vulnerability exploitation
[0065] 2. If there is a risk, recommend the patch number and operation manual section
[0066] Perform security assessment on the network traffic data after dimensionality reduction to obtain the second assessment result, specifically:
[0067] 1) Perform spatiotemporal feature alignment on the network data after dimensionality reduction; design dynamic topology time window , divide the time series data into processing units with spatiotemporal correlation features: the basic time window length is set to be adaptively adjustable by ±20%; a dynamic device communication graph is synchronously constructed within each time window , expressed as: ,in, Indicates the active device nodes during period t, It is a communication connection. , is the threshold value of communication frequency, is the threshold value of delay. The spatiotemporal joint feature matrix is expressed as: ,in Represents the tensor concatenation operation of graph features and time series features.
[0068] 2) Use the time series graph neural network (TGNN-CA) to perform time series analysis and security assessment on the aligned network data to obtain the second assessment result;
[0069] The temporal graph neural network TGNN-CA includes a spatiotemporal embedding layer, a causal attention layer, a multi-scale convolutional layer, and a dynamic causal evaluation layer from input to output;
[0070] Spatiotemporal Embedding Layer:
[0071] The input data dimension is (batch_size, T, N, F), where:
[0072] N: Number of dynamic device nodes (range 50-5000)
[0073] F: Node feature dimension (including 8-dimensional features such as traffic intensity and protocol type)
[0074] T: time window length (default Δt=10s)
[0075] Build device communication graphs in real time , edge feature matrix Include: ;in, : packet frequency, : Communication delay, : information entropy;
[0076] Causal attention layer: Captures the attack propagation path based on the differentiable causal mask mechanism. The node-level attention is expressed as: ,in, : The attention weight of node i to node j, Q, K: query vector (Query), key vector (Key), : causal mask matrix, : Key vector dimension (scaling factor).
[0077] The causal mask matrix Mcausal is learned through prior knowledge and runtime communication patterns;
[0078] Multi-scale convolution layer: used to fuse dilated convolution and residual connection, that is, parallel convolution path and feature fusion formula, expressed as: ;in, : fusion feature matrix, , : convolution weight matrix, : Output features of the attention layer, , : Output features of different convolution paths.
[0079] Dynamic causal assessment layer: The causal impact strength is analyzed as the second assessment result based on the industrial business-oriented assessment mechanism. The causal impact strength is expressed as: , where S node It is the node status aggregation. : causal influence strength, : The hidden state of node u.
[0080] A meta-learning optimizer is used to dynamically adjust the graph learning rate (initial η = 5e-4), and an adversarial training strategy (PGD attack + defense) is introduced to improve model robustness. PGD stands for projected gradient descent (an adversarial training method).
[0081] S4. Adopting the adversarial meta-learning dual-drive architecture to build an industrial-grade efficient fusion system, fuse the first evaluation result and the second evaluation result to obtain the evaluation result;
[0082] Three-stage dynamic fusion mechanism
[0083] Phase 1: Adversarial feature enhancement, building dual feature space adversarial optimization: ,in : adversarial loss function, θ: model parameters, δ: adversarial perturbation, Δ: delay-sensitive perturbation space (constrained by TSN protocol), x: input data.
[0084] Phase 2: Meta-learning dynamic gating, designing an LSTM-based meta-controller to achieve millisecond-level weight updates: ,in, : Fusion weight at time t, : weight matrix, : The hidden state at the last moment, : Real-time protocol feature vector, : Bias term.
[0085] Phase 3: Anti-interference fusion decision-making, innovative time-domain robust aggregation function:
[0086] , where y: fusion result, : the weight of the k-th input, : the kth input feature, : Protocol sensitivity attenuation coefficient ( =0.7), : Gradient of the loss function with respect to the input.
[0087] Protocol Adaptation Enhancement
[0088] Developing Adaptive Meta-Update Strategies for Industrial Protocols: ; Achieve 8-hour rapid adaptation under OPC U A over TSN protocol. : updated model parameters, : current model parameters, : learning rate, : meta-learning update coefficient, : loss function, : Support set data, : query set data, : Temporary model parameters.
[0089] Through the weighted fusion technology of multi-source heterogeneous data, we obtained the evaluation fusion results from different modules and different environments of the industrial control system, which provides unified and concise data input for subsequent business impact evaluation and policy response.
[0090] S5. Classify and grade the risk impact based on the assessment results; specifically:
[0091] S51. Establish risk impact assessment indicators, including equipment availability, output impact, safety impact, and economic losses. Equipment availability refers to whether a failure or anomaly causes the equipment to stop working; output impact refers to whether a failure causes a reduction or stagnation in production capacity; safety impact refers to whether there are risks to personnel or the environment; and economic losses refer to direct economic losses caused by business interruption or failure.
[0092] S52. Analyze the dependencies between various subsystems and business functions in industrial control systems, including how equipment failures affect production line operations and how network security incidents (such as denial of service attacks) affect data collection and monitoring. Construct a correlation matrix to represent the corresponding relationship between security risks and business functions of industrial control systems.
[0093] Each indicator is assigned a weight to reflect its impact on the overall business of the industrial system. This paper tentatively sets equipment availability at 40%, output impact at 30%, security impact at 20%, and economic loss at 10%. The business impact factor settings can be adjusted based on the specific industrial control system scenario.
[0094] S53. Based on the industrial control system security assessment results, map the risk score to a business impact indicator. Specifically, based on the industrial control system security assessment results, map the risk score to a business impact indicator. Low risk corresponds to an impact score of 0-2, medium risk corresponds to an impact score of 3-5, and high risk corresponds to an impact score of 6-10.
[0095] S54. Calculate the business impact score using a weighted assessment method and map it to a business impact level. The business impact score is expressed as: , where W is the weight of each indicator, , , , The corresponding quantitative score is mapped to the business impact level as follows: the calculated comprehensive business impact score is mapped to the business impact level, where 0-2 indicates slight business impact (normal operation), 3-5 indicates moderate business impact (some functions are restricted), and 6-10 indicates severe business impact (critical functions are interrupted).
[0096] S6. Output an evaluation report based on risk classification. The content of the evaluation report includes: the current risk status of the industrial control system, analysis of the specific impact of various risks on business functions, quantitative estimation of business stagnation or production capacity loss, and security response recommendations and optimization measures.
[0097] Conduct security response and business optimization based on optimization measures. Trigger security response: Different levels of security response are triggered based on the business impact. Minor impacts require ongoing monitoring without emergency intervention. Moderate impacts require preventive maintenance or system configuration optimization. Severe impacts require immediate downtime for inspection and implementation of emergency response measures. Business recovery and optimization: Based on expert knowledge, optimize solutions for restoring business functions are developed to mitigate the impact of system risks on business continuity. Long-term optimization recommendations are also provided, such as strengthening network security protection and updating device configurations.
[0098] Through the above steps, this invention combines the security assessment results of industrial control systems with the impact on industrial business, forming a quantitative business impact evaluation system. Through indicator weighting, quantitative scoring, and visual display, it accurately assesses the specific impact of security risks on the business, guides security response and business optimization, and thus ensures the stable operation of industrial systems and business continuity.
[0099] The present invention significantly improves the comprehensiveness and accuracy of industrial control system security assessments by separately processing system logs and network traffic data from multi-source heterogeneous data. Unlike traditional single data source assessment methods, the present invention uses DeepSeek v3 0324 to perform security assessments on system logs, uses a time series graph neural network to analyze network traffic data, and ultimately merges the assessment results of the two to provide a more comprehensive security situation. Through data preprocessing and noise data removal technology, high-quality data input is ensured, the scale of heterogeneous data is unified, and the reliability of the assessment results is enhanced. In addition, combined with a deep learning model for dynamic analysis, this method can effectively respond to system operation changes and complex attack patterns, providing accurate security status assessments for industrial control systems. This method of independent assessment of multi-source data avoids the limitation of traditional methods that cannot fully reflect the system security situation, and provides more accurate security management and operation and maintenance support.
[0100] The present invention not only focuses on the assessment of security status, but also introduces a correlation analysis mechanism between security assessment and industrial business impact, significantly enhancing the business practicality of the assessment. By establishing a correlation model between security status and business functions, this method quantifies the specific impact of security risks on equipment availability, production capacity, safety and economic costs, and clearly demonstrates the degree of interference of security risks on business through an assessment matrix and comprehensive scoring. Unlike traditional methods that simply focus on technical security, the present invention fully considers business continuity and operational efficiency in the assessment process, helping managers make a reasonable trade-off between security risks and business impact. This method can provide management of industrial control systems with a more business-valuable decision-making basis.
[0101] The technical solution of the present invention is not limited to the above-mentioned specific embodiments. Any technical variations made according to the technical solution of the present invention fall within the protection scope of the present invention.
Claims
1. An industrial control system security assessment method based on multi-source heterogeneous data fusion, characterized by: include: S1. Obtain relevant data of industrial control systems and network traffic data and pre-process them; S2. Use principal component analysis (PCA) to reduce the dimension of the processed data; S3. Perform security assessment on the relevant data of the industrial control system and the network traffic data after dimensionality reduction, and obtain a first assessment result and a second assessment result respectively; The security assessment of the industrial control system after dimensionality reduction is performed to obtain the first assessment results, specifically: (1) Use the DeepSeek v3 0324 model to conduct a preliminary evaluation and analysis of the relevant data of the industrial control system after dimensionality reduction. The analysis results include anomaly identification results, risk levels, and recommended repair actions; (2) Associating the analysis results with the industrial safety knowledge graph to generate the first evaluation results; Perform security assessment on the network traffic data after dimensionality reduction to obtain the second assessment result, specifically: 1) Perform spatiotemporal feature alignment on the network data after dimensionality reduction; 2) Use the time series graph neural network (TGNN-CA) to perform time series analysis and security assessment on the aligned network data to obtain the second assessment result; S4. Fusing the first evaluation result and the second evaluation result to obtain an evaluation result; S5. Classify and grade the risk impact based on the assessment results; S6. Output evaluation report based on risk classification.
2. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 1 is characterized in that: Preprocessing in S1 includes: ① Use filtering method to remove noise from relevant data of industrial control system and network traffic data; ②, Use Z-score standardization to convert the filtered data into standardized data; ③. Use the interpolation method to perform interpolation calculations on the standardized data, fill in the missing values, and obtain the relevant data of the industrial control system and network traffic data after filling.
3. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 1 is characterized in that: Included in S2: S21. Calculate the covariance matrix C, expressed as: ,in, is the standardized data matrix, n is the number of samples, is a matrix The transpose of S22. Perform eigenvalue decomposition on the covariance matrix to obtain eigenvalues and eigenvectors; S23. Select the first k principal components from largest to smallest according to the size of the eigenvalues; S24. Project the unselected principal components with large eigenvalues onto the selected principal components to obtain the data after dimensionality reduction, which is expressed as: , where B is the original data matrix, D is the eigenvector matrix, is the data after dimensionality reduction.
4. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 1 is characterized in that: Between S2 and S3, S2' is also included. Statistical distribution detection based on dynamic thresholds automatically removes outliers that deviate from the normal mode by more than 3 standard deviations. At the same time, a multimodal verifier is used to verify consistency across data sources to obtain cleaned data.
5. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 4 is characterized in that: Specifically in 1) it is: Designing dynamic topology time windows , the time series data is divided into processing units with spatiotemporal correlation features: the basic time window length is set to be adaptively adjustable by ±20%; Synchronously build a dynamic device communication graph within each time window , expressed as: ,in, Indicates the active device nodes during period t, It is a communication connection. , is the threshold value of communication frequency, is the threshold value of delay, and the spatiotemporal joint feature matrix is expressed as: ,in Represents the tensor concatenation operation of graph features and time series features.
6. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 5 is characterized in that: The temporal graph neural network TGNN-CA includes a spatiotemporal embedding layer, a causal attention layer, a multi-scale convolutional layer, and a dynamic causal evaluation layer from input to output. The spatiotemporal embedding layer is used to construct a device communication graph in real time. , edge feature matrix Expressed as: ;in, is the packet frequency, is the communication delay, is the information entropy; the causal attention layer captures the attack propagation path according to the differentiable causal mask mechanism, and the node-level attention is expressed as: ,in, is the attention weight of node i to node j, Q and K are query vector (Query) and key vector (Key), respectively. is the causal mask matrix, is the key vector dimension (scaling factor); the causal mask matrix Mcausal is learned through prior knowledge and runtime communication mode; the multi-scale convolution layer is used to fuse the void convolution and residual connection, which is expressed as: ;in, is the fusion feature matrix, 、 are the convolution weight matrices, is the output feature of the attention layer, 、 are the output features of different convolution paths respectively; the dynamic causal evaluation layer analyzes the causal impact strength as the second evaluation result based on the industrial business-oriented evaluation mechanism; the causal impact strength is expressed as: , where S node is the node status aggregation function, where: is the causal influence strength, is the hidden state of node u.
7. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 1 is characterized in that: In S4, the adversarial meta-learning dual-drive architecture is used to build an industrial-grade efficient fusion system. The industrial-grade efficient fusion system fuses the first evaluation result and the second evaluation result to obtain the evaluation result.
8. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 7 is characterized in that: The industrial-grade efficient fusion system uses a three-stage dynamic fusion mechanism for fusion. Stage 1: Enhance the adversarial features and build a dual feature space adversarial optimization. ,in is the adversarial loss function, θ is the model parameter, δ is the adversarial perturbation, Δ is the delay-sensitive perturbation space, and x is the input data; Phase 2: Meta-learning dynamic gating, designing an LSTM-based meta-controller to achieve millisecond-level weight updates, expressed as: ,in is the fusion weight at time t, is the weight matrix, is the hidden state at the last moment, is the real-time protocol feature vector, is the bias term; Stage 3: Anti-interference fusion decision, innovative time domain robust aggregation function, expressed as: , where y is the fusion result, is the weight of the kth input, is the kth input feature, is the protocol sensitivity attenuation coefficient ( =0.7), is the gradient of the loss function with respect to the input.
9. The industrial control system security assessment method based on multi-source heterogeneous data fusion according to claim 1 is characterized in that: Included in S5: S51. Establish risk impact assessment indicators, including equipment availability, output impact, safety impact, and economic losses; S52. Analyze the dependencies between various subsystems and business functions in the industrial control system and construct a correlation matrix; S53. Based on the industrial control system security assessment results, map the risk score to a business impact indicator; S54. Calculate the business impact score using a weighted assessment method and map it to a business impact level. The business impact score is expressed as: , where W is the weight of each indicator, 、 、 and is the corresponding quantitative score.
Citation Information
Patent Citations
Industrial control system information security attack risk assessment method and system
CN110703712A
A one-way security detection and multi-factor weighted evaluation system for industrial control terminal equipment
CN114117337B
Quantitative evaluation method of functional safety of industrial control systems based on digital twin technology
CN114118777B
Cited By
Database security situation awareness method and system based on multi-source data fusion
CN121167747A