Security isolation method based on automated wharf plc network
By deploying traffic acquisition equipment in the automated terminal PLC network for identity authentication and feature analysis, the problem that traditional security devices cannot effectively authenticate and release PLC traffic is solved, and accurate security isolation and real-time protection of the PLC network are achieved, ensuring the security and reliability of the network.
Patent Information
- Application Number
- CN202510792742.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-08-15
AI Technical Summary
Existing traditional security equipment cannot effectively authenticate, identify and release traffic from the automated terminal PLC network, and cannot meet the requirements of high security and high reliability, making it difficult to protect security threats such as network attacks and illegal intrusions.
By deploying traffic acquisition devices between the PLC network and the external network, PLC traffic is obtained in real time and identity authentication and feature analysis is performed, legal device information database and communication rules are used to match, illegal or abnormal traffic is identified and intercepted, and fast hashing algorithms and protocol analysis algorithms are used for accurate authentication and release.
It realizes accurate security isolation of PLC network, prevents network attacks and illegal intrusions, ensures the security and reliability of PLC network, improves the real-time and effectiveness of security protection, and provides abnormal traffic recording and analysis support.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automated terminal network security, and in particular to a security isolation method based on an automated terminal PLC network. Background Art
[0002] With the continuous improvement of port automation, programmable logic controllers (PLCs) are widely used in automated terminals for equipment control and process management. As the core control system of automated terminals, the security of PLC networks is of paramount importance. However, existing automated terminal PLC networks face many security threats, such as cyber attacks, illegal intrusions, and malware propagation. Once the PLC network is attacked, it may cause terminal equipment failure, operational process interruption, and even cause serious safety accidents and economic losses.
[0003] Currently, traditional network security measures, such as firewalls and intrusion detection systems, can provide network security protection to a certain extent. However, they are difficult to achieve accurate security isolation and protection for the unique communication protocols and traffic characteristics of PLC networks. PLC network communication is characterized by strong real-time performance, small data volumes, and strong protocol specificity. Traditional security equipment cannot effectively authenticate, identify, and release PLC traffic, and cannot meet the high security and high reliability requirements of automated terminal PLC networks. Therefore, a security isolation method and device for automated terminal PLC networks is urgently needed to address the problems existing in the existing technology. Summary of the Invention
[0004] In response to the shortcomings of the existing technology, the present invention provides a security isolation method based on the PLC network of an automated terminal, which solves the problem proposed in the above background technology that the traditional security equipment cannot effectively authenticate, identify and release control PLC traffic, and cannot meet the high security and high reliability requirements of the PLC network of the automated terminal.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: a safety isolation method based on an automated terminal PLC network, comprising the following steps:
[0006] Traffic collection: The equipment collects traffic data in the automated terminal PLC network and obtains all PLC traffic passing through in real time;
[0007] Identity authentication: The collected PLC traffic is authenticated and compared with the pre-set legal device information database. If the device information in the traffic matches the information in the legal device information database, the traffic is considered to be from a legal device and the next step of identification is entered; if not, the traffic is determined to be illegal and directly discarded;
[0008] Traffic identification: For PLC traffic that has passed identity authentication, further analyze its characteristics and determine whether the traffic conforms to the normal PLC communication mode based on the pre-set PLC communication rules and security policies. If it conforms, it is considered normal traffic; if not, it is considered abnormal traffic.
[0009] Traffic release: For normal traffic, it is allowed to pass through the device and continue to be transmitted in the PLC network; for abnormal traffic, it is blocked from passing through the device and the relevant information of the abnormal traffic is recorded for subsequent security analysis and processing.
[0010] Furthermore, the traffic collection equipment is deployed in the communication link between the PLC network and the external network.
[0011] Furthermore, the source address, destination address, and port information in the traffic are extracted during identity authentication.
[0012] Furthermore, the features further analyzed in traffic identification include communication protocol, data format, and data content.
[0013] Furthermore, the relevant information of abnormal traffic in traffic release includes source address, destination address, and abnormal characteristics.
[0014] Furthermore, during identity authentication, a fast hash algorithm is used to compare device information with a valid device information database.
[0015] Furthermore, in traffic identification, protocol parsing algorithms and pattern matching algorithms are used to analyze the communication protocol, data format, and data content characteristics of PLC traffic.
[0016] Furthermore, during traffic release, normal traffic is released and abnormal traffic is blocked by controlling the switch status of the network interface.
[0017] The present invention provides a security isolation method based on the PLC network of an automated terminal, which has the following beneficial effects: the security isolation method based on the PLC network of an automated terminal can effectively identify and intercept illegal traffic and abnormal traffic through a strict identity authentication and traffic identification mechanism, prevent network attacks, illegal intrusions and other security threats, and ensure the security of the PLC network of the automated terminal; it is designed according to the special communication protocol and traffic characteristics of the PLC network, and can achieve accurate authentication, identification and release of PLC traffic, ensuring that only traffic that meets security requirements can be transmitted in the PLC network without affecting the normal operation of the PLC network; it can collect and process PLC traffic data in real time, promptly discover and deal with safety hazards, and improve the timeliness and effectiveness of safety protection of the PLC network of the automated terminal; by recording abnormal traffic information, it is convenient for security management personnel to conduct security analysis and processing, and it is also convenient for maintenance and optimization of safety isolation devices. DETAILED DESCRIPTION
[0018] The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0019] The present invention provides a technical solution: a safety isolation method based on an automated terminal PLC network, comprising the following steps:
[0020] Traffic collection: In the network architecture of the automated terminal, equipment with high-speed data collection capabilities is deployed at key nodes in the communication link between the PLC network and the external network. Specifically, the equipment can be deployed on the mirror port of the switch connecting the PLC network and the external network. Through the mirroring function of the switch, a copy of all traffic data transmitted in the PLC network is transmitted to the collection device; or it can be deployed in series in the communication link, so that the PLC traffic flows directly through the collection device.
[0021] The device is equipped with a high-performance network data acquisition chip that can monitor the data transmission status in the communication link in real time. When PLC traffic passes through, the chip captures the traffic data at an extremely high sampling frequency to ensure that no data packet is missed. For example, in the actual application scenario of a large-scale automated terminal, the acquisition device can complete the acquisition of a standard PLC data packet in a very short time (such as 1 millisecond), and preliminarily encapsulate the collected raw traffic data. Then, through the high-speed data transmission interface, the complete traffic data is transmitted in real time to the subsequent identity authentication module for processing.
[0022] Identity authentication: The identity authentication module pre-establishes and maintains a legal device information database, which stores detailed information on all legal PLC devices in the automated terminal, including but not limited to the device's source address, destination address, and corresponding port information. The database uses an efficient data storage structure, such as a hash table or database, to facilitate rapid data query and comparison operations.
[0023] When the identity authentication module receives the PLC flow data transmitted by the flow collection module, it first parses the data to extract the source address, destination address and port information in the flow. Then, it uses the fast hash algorithm to process the extracted device information and compares the processed hash value with the hash value of the corresponding device information in the legal device information database. Since the fast hash algorithm has the characteristics of fast calculation speed and low collision probability, it can complete the comparison of a large amount of device information in a very short time.
[0024] If the comparison result shows that the extracted device information hash value completely matches the hash value of a legitimate device record in the information database, the traffic is deemed to come from a legitimate device, marked as legitimate traffic, and passed to the subsequent traffic identification module for further analysis; if no matching record is found after the comparison, the traffic is determined to be illegal traffic, the identity authentication module immediately discards it, and records the relevant information of the illegal traffic in the system log, including the discarding time, source address, etc., so that security management personnel can conduct subsequent audits and analysis.
[0025] Traffic identification: The traffic identification module has a built-in detailed and complete PLC communication rules and security policy library. The rules and policies in this library are formulated based on the actual communication needs of the automated terminal PLC network, equipment operating characteristics, and industry safety standards. They cover many aspects such as specific communication protocol format requirements between PLC devices, normal data transmission frequency range settings, and data content restrictions.
[0026] When the traffic identification module receives legitimate PLC traffic that has passed identity authentication, it starts the protocol parsing algorithm and pattern matching algorithm to conduct an in-depth analysis of the traffic. The protocol parsing algorithm can accurately identify the type of communication protocol used by the traffic, and decode and parse the traffic data according to the specifications of the corresponding protocol to obtain key information; the pattern matching algorithm compares and matches the characteristics of the parsed traffic data in terms of communication protocol, data format, data content, etc. according to the pre-set normal communication mode rules.
[0027] For example, if it is found that the data transmission frequency of a certain PLC traffic is significantly higher than the normal range, or the data content contains instruction codes that do not comply with regulations, the pattern matching algorithm will determine that the traffic does not conform to the normal PLC communication mode and identify it as abnormal traffic; conversely, if the traffic characteristics in all aspects meet the preset rules, it will be judged as normal traffic and the judgment result will be passed to the traffic release module.
[0028] Traffic release: The traffic release module mainly realizes the release and blocking operations of PLC traffic by controlling the switch status of the network interface. The module integrates a high-precision network interface control unit, which can control the network interface quickly and accurately according to the judgment results transmitted by the traffic identification module.
[0029] For PLC data that is judged to be normal traffic, the network interface control unit keeps the corresponding network interface open, allowing the traffic to pass through the equipment smoothly and continue to be transmitted in the PLC network, ensuring that the normal operation process of the automated terminal is not affected; for data that is determined to be abnormal traffic, the network interface control unit immediately closes the corresponding network interface to prevent the abnormal traffic from entering the PLC network, thereby effectively preventing the spread of potential security threats.
[0030] The traffic release module also features a logging function. When abnormal traffic is detected, it promptly records relevant information, including the source address, destination address, and specific abnormal characteristics, in a system log file. Security managers can review these logs to conduct in-depth analysis of the source and attack methods of abnormal traffic, allowing them to implement targeted security measures, such as blocking illegal devices and optimizing existing PLC communication rules and security policies, to continuously enhance the security capabilities of the automated terminal PLC network.
[0031] The embodiments of the present invention are presented for purposes of illustration and description and are not intended to be exhaustive or to limit the invention to the disclosed forms. Many modifications and variations will be apparent to those skilled in the art. The embodiments are chosen and described in order to better illustrate the principles of the invention and its practical application and to enable those skilled in the art to understand the invention and design various embodiments with various modifications as suited for specific applications.
Claims
1. A safety isolation method based on automated terminal PLC network, characterized in that: The following steps are involved: Traffic collection: The equipment collects traffic data in the automated terminal PLC network and obtains all PLC traffic passing through in real time; Identity authentication: The collected PLC traffic is authenticated and compared with the pre-set legal device information database. If the device information in the traffic matches the information in the legal device information database, the traffic is considered to be from a legal device and the next step of identification is entered; if not, the traffic is determined to be illegal and directly discarded; Traffic identification: For PLC traffic that has passed identity authentication, further analyze its characteristics and determine whether the traffic conforms to the normal PLC communication mode based on the pre-set PLC communication rules and security policies. If it conforms, it is considered normal traffic; if not, it is considered abnormal traffic. Traffic release: For normal traffic, it is allowed to pass through the device and continue to be transmitted in the PLC network; for abnormal traffic, it is blocked from passing through the device and the relevant information of the abnormal traffic is recorded for subsequent security analysis and processing.
2. A safety isolation method based on an automated terminal PLC network according to claim 1, characterized in that: The equipment used in traffic collection is deployed in the communication link between the PLC network and the external network.
3. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized in that: Extract the source address, destination address, and port information from the traffic during identity authentication.
4. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized in that: The features that are further analyzed in traffic identification include communication protocol, data format, and data content.
5. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized in that: The relevant information of abnormal traffic in traffic release includes source address, destination address, and abnormal characteristics.
6. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized by: During identity authentication, a fast hash algorithm is used to compare device information with the legitimate device information database.
7. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized in that: In traffic identification, protocol parsing algorithm and pattern matching algorithm are used to analyze the communication protocol, data format, and data content characteristics of PLC traffic.
8. The safety isolation method based on the automated terminal PLC network according to claim 1 is characterized in that: During traffic release, normal traffic is released and abnormal traffic is blocked by controlling the switch status of the network interface.