Oil and gas pipe network risk assessment method

By simulating compound attacks and combining historical attack data with real-time network status to calculate the risk assessment value of the oil and gas pipeline network, the problem of inaccurate assessment in existing technologies is solved, a more accurate and timely risk assessment is achieved, and the security protection capability of the oil and gas pipeline network is enhanced.

CN120675740APending Publication Date: 2025-09-19PIPECHINA SOUTH CHINA CO +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510667348.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies make it difficult to accurately assess the risk level of oil and gas pipeline networks under complex attacks, and lack dynamic reflection of historical attack data and real-time network status, resulting in inaccurate and intime assessment results.

Method used

By simulating composite attacks on network layer data, the initial risk assessment value is calculated based on the historical attack deviation index and real-time network status characteristic value, and then adjusted through correction and compensation coefficients to obtain the final risk assessment level.

Benefits of technology

It improves the accuracy and real-time performance of oil and gas pipeline network risk assessment, can better reflect the potential impact of complex attacks, and provides a scientific basis for the security protection of oil and gas pipeline networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675740A_ABST
    Figure CN120675740A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of risk quantitative assessment, and discloses an oil and gas pipe network risk assessment method, which comprises the following steps: acquiring network layer data, historical network layer attack records and post-attack network state data of a to-be-assessed oil and gas pipe network; calculating an initial risk assessment value of the to-be-assessed oil and gas pipe network based on an attack result of the attack simulation; under the condition that the historical attack deviation index is greater than or equal to a historical attack deviation index threshold value, correcting the initial risk assessment value based on a preset correction coefficient to obtain a corrected risk assessment value; under the condition that the at least one post-attack network state characteristic value is greater than the corresponding network state standard value, compensating the corrected risk assessment value based on a preset compensation coefficient to obtain a compensated risk assessment value; and determining the risk assessment level of the to-be-assessed oil and gas pipe network according to the compensation risk assessment value. The method not only improves the accuracy of risk assessment of the oil and gas pipe network, but also enhances the ability to cope with security threats of the oil and gas pipe network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of risk quantification assessment, and in particular to a method for risk assessment of oil and gas pipeline networks. Background Art

[0002] A complex attack combines multiple attack techniques and methods within a network, leveraging multiple attack nodes, multiple attack paths, and multiple attack vectors to achieve a comprehensive attack and intrusion into the target network. This attack typically consists of multiple components, including a master control node, attack nodes, and attack vectors. Complex attacks can be carried out in a variety of ways, including port scanning, DDoS attacks, vulnerability exploitation, and password cracking. From the master control node, the attacker directs attack nodes to scan the target network for potential weaknesses and vulnerabilities, then exploits attack vectors to deliver the attack payload or execute attack code. The attack payload can be malicious code, viruses, worms, or other malware that infects the target device, taking control of it, or stealing sensitive information.

[0003] Since oil and gas pipeline systems usually contain a large number of critical infrastructures, such as oil pipelines, storage tanks and refineries, once these facilities are attacked, they will not only cause serious damage to the environment, but may also cause major safety accidents and even threaten public safety. Summary of the Invention

[0004] In view of this, this application proposes an oil and gas pipeline network risk assessment method, which aims to improve the accuracy of oil and gas pipeline network risk assessment results.

[0005] The present application proposes a risk assessment method for an oil and gas pipeline network, comprising the following steps: obtaining network layer data, historical network layer attack records, and post-attack network status data of the oil and gas pipeline network to be assessed; wherein the network layer data includes network traffic data, network protocol data, device status data, and log data; and the post-attack network status data is the network status data of the oil and gas pipeline network to be assessed after a composite attack; performing attack simulation on a test set to be assessed corresponding to the network layer data by simulating a composite attack to obtain attack results, and calculating an initial risk assessment value for the oil and gas pipeline network to be assessed based on the attack results; determining a historical attack deviation index for the oil and gas pipeline network to be assessed based on the historical network layer attack records, and, if the historical attack deviation index is greater than or equal to a historical attack deviation index threshold, correcting the initial risk assessment value based on a preset correction coefficient to obtain a corrected risk assessment value; determining multiple post-attack network status characteristic values ​​of the oil and gas pipeline network to be assessed based on the post-attack network status data, and, if at least one post-attack network status characteristic value is greater than a corresponding network status standard value, compensating the corrected risk assessment value based on a preset compensation coefficient to obtain a compensated risk assessment value; and determining a risk assessment level for the oil and gas pipeline network to be assessed based on the compensated risk assessment value.

[0006] In some embodiments, an attack simulation is performed on the test set to be evaluated corresponding to the network layer data by simulating a composite attack to obtain an attack result, including: establishing a test set to be evaluated based on the network layer data; performing denial of service attack simulation, distributed denial of service attack simulation and man-in-the-middle attack simulation on the network traffic data in the test set to be evaluated to obtain traffic attack simulation results; wherein the traffic attack simulation results include attack traffic intensity, request response failure rate and resource occupancy rate; performing forged packet attack simulation and session hijacking attack simulation on the network protocol data in the test set to be evaluated to obtain protocol attack simulation results; wherein the protocol attack simulation results include the number of forged packets, session hijacking success rate and protocol anomaly rate; performing configuration error simulation attack simulation and privilege escalation attack simulation on the device status data in the test set to obtain status attack simulation results; wherein the status attack simulation results include the number of configuration errors, privilege escalation success rate and device anomaly rate; performing log tampering attack simulation and log forgery attack simulation on the log data in the test set to be evaluated to obtain log attack simulation results; wherein the log attack simulation results include the number of tampered logs, the number of forged logs and the log anomaly rate.

[0007] In some embodiments, an initial risk assessment value of the oil and gas pipeline network to be assessed is calculated based on the attack results, including: the attack results include flow attack simulation results, protocol attack simulation results, state attack simulation results, and log attack simulation results; the initial risk assessment value of the oil and gas pipeline network to be assessed is calculated based on the flow attack simulation results, protocol attack simulation results, state attack simulation results, and log attack simulation results; the initial risk assessment value is obtained by the following formula:

[0008]

[0009] Where Rinitial represents the initial risk assessment value; ωi represents the weight coefficient of the i-th attack simulation result; ni represents the number of indicators in the i-th attack simulation result; ωij represents the weight coefficient of the j-th indicator of the i-th attack simulation result; Xij represents the normalized value of the j-th indicator of the i-th attack simulation result.

[0010] In some embodiments, based on historical network layer attack records, determining a historical attack deviation index of the oil and gas pipeline network to be evaluated includes: analyzing the historical network layer attack records to obtain a first attack behavior and a second attack behavior; the first attack behavior is used to represent an attack behavior whose occurrence frequency is greater than a first frequency threshold and whose risk coefficient is less than the first risk threshold; the second attack behavior is used to represent an attack behavior whose occurrence frequency is less than a second frequency threshold and whose risk coefficient is greater than the second risk threshold; determining an attack severity factor corresponding to each first attack behavior and an attack severity factor corresponding to each second attack behavior, respectively, and constructing an attack severity factor sequence; counting the number of first attack behaviors, recorded as a first number; counting the number of second attack behaviors, recorded as a second number; and calculating the historical attack deviation index of the oil and gas pipeline network to be evaluated based on the attack severity factor sequence, the first number, and the second number; wherein the historical attack deviation index is obtained by the following formula:

[0011]

[0012] Where Ihistory represents the historical attack deviation index; a represents the first quantity; b represents the second quantity; Sk represents the attack severity factor of the k-th first attack behavior; Ck represents the number of the k-th first attack behavior; Hl represents the attack severity factor of the l-th second attack behavior, and Rl represents the number of the l-th second attack behavior.

[0013] In some embodiments, the method further includes: when the historical attack deviation index is less than a historical attack deviation index threshold, keeping the initial risk assessment value unchanged.

[0014] In some embodiments, correcting the initial risk assessment value based on a preset correction coefficient includes: obtaining a preset correction coefficient, wherein the preset correction coefficient includes a first correction coefficient, a second correction coefficient, and a third correction coefficient; the first correction coefficient is less than the second correction coefficient, and the second correction coefficient is less than the third correction coefficient; calculating a ratio of a historical attack deviation index to a historical attack deviation index threshold, recorded as an attack deviation ratio; when the attack deviation ratio is less than or equal to a first attack deviation ratio threshold, selecting the first correction coefficient as the correction coefficient corresponding to the initial risk assessment value, and taking the product of the first correction coefficient and the initial risk assessment value as the corrected risk assessment value; when the attack deviation ratio is greater than the first attack deviation ratio threshold and less than or equal to a second attack deviation ratio threshold, selecting the second correction coefficient as the correction coefficient corresponding to the initial risk assessment value, and taking the product of the second correction coefficient and the initial risk assessment value as the corrected risk assessment value; the first attack deviation ratio threshold is less than the second attack deviation ratio threshold; when the attack deviation ratio is greater than the second attack deviation ratio threshold, selecting the third correction coefficient as the correction coefficient corresponding to the initial risk assessment value, and taking the product of the third correction coefficient and the initial risk assessment value as the corrected risk assessment value.

[0015] In some embodiments, based on the post-attack network status data, multiple post-attack network status characteristic values ​​of the oil and gas pipeline network to be evaluated are determined, including: feature extraction of the post-attack network status data to obtain multiple post-attack network status characteristic values ​​corresponding to the post-attack network status data; the multiple post-attack network status characteristic values ​​include traffic anomaly rate, equipment load rate and network delay time; the method also includes: when the multiple post-attack network status characteristic values ​​are all less than or equal to the corresponding network status standard values, keeping the modified risk assessment value unchanged.

[0016] In some embodiments, compensating the modified risk assessment value based on a preset compensation coefficient includes: determining a post-attack network state characteristic value greater than a network state standard value as a target network state characteristic value, and calculating a difference value between each target network state characteristic value and the network state standard value; generating a first difference value set based on all difference values ​​less than or equal to a preset difference value; generating a second difference value set based on all difference values ​​greater than the preset difference value; calculating a first average difference value of the first difference value set, and calculating a second average difference value of the second difference value set; and calculating a real-time behavior index of the oil and gas pipeline network to be evaluated based on the first average difference value and the second average difference value; wherein the real-time behavior index is obtained by the following formula:

[0017] RBI = Δ1 × α + Δ2 × β;

[0018] Among them, RBI represents the real-time behavior index, Δ1 represents the first average difference value; α represents the first influence coefficient; Δ2 represents the second average difference value; β represents the second influence coefficient; based on the preset compensation coefficient and the real-time behavior index, the modified risk assessment value is compensated.

[0019] In some embodiments, the modified risk assessment value is compensated based on a preset compensation coefficient and a real-time behavior index, including: obtaining a preset compensation coefficient, wherein the preset compensation coefficient includes a first compensation coefficient, a second compensation coefficient, and a third compensation coefficient; the first compensation coefficient is less than the second compensation coefficient, and the second compensation coefficient is less than the third compensation coefficient; comparing the real-time behavior index with a first behavior index threshold and a second behavior index threshold, and determining a compensation coefficient corresponding to the modified risk assessment value based on the comparison result; wherein the first behavior index threshold is less than the second behavior index threshold; when the real-time behavior index is less than or equal to the first behavior index threshold, the first compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the first compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value; when the real-time behavior index is greater than the first behavior index threshold and less than or equal to the second behavior index threshold, the second compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the second compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value; when the real-time behavior index is greater than the second behavior index threshold, the third compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the third compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value.

[0020] In some embodiments, the risk assessment level of the oil and gas pipeline network to be assessed is determined based on the compensated risk assessment value, including: comparing the compensated risk assessment value with the compensated risk assessment threshold, and determining the risk assessment level of the oil and gas pipeline network to be assessed based on the comparison result; when the compensated risk assessment value is less than or equal to the compensated risk assessment threshold, the risk assessment level of the oil and gas pipeline network to be assessed is determined to be the first level; when the compensated risk assessment value is greater than the compensated risk assessment threshold, the risk assessment level of the oil and gas pipeline network to be assessed is determined to be the second level; wherein the first level is lower than the second level.

[0021] Compared with the existing technology, the beneficial effects of the present application are: the oil and gas pipeline network risk assessment method provided by the present application comprehensively considers the impact of multiple attack types on the oil and gas pipeline network, is not limited to the traditional single attack mode, but simulates a composite attack scenario, so that the risk level of the oil and gas pipeline network when it is attacked can be more accurately assessed; the present application also considers the impact of historical attack data on the current risk assessment, and by calculating the historical attack deviation index, it can reflect the potential impact of historical attack behavior on the current network status, thereby making necessary corrections to the initial risk assessment value, so that the assessment result is closer to the actual risk level; the present application also introduces the analysis of real-time network layer data, and through the calculation of the real-time behavior index, it can dynamically reflect the real-time status of the oil and gas pipeline network after being attacked, further improving the accuracy and real-time nature of the risk assessment; by setting the compensation coefficient, the present application can compensate the corrected risk assessment value according to the real-time behavior index, ensuring that the assessment result can timely reflect the safety status of the oil and gas pipeline network, and provide a scientific basis for the safety protection of the oil and gas pipeline network. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present application. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:

[0023] Figure 1 A flow chart of a method for oil and gas pipeline network risk assessment provided in an embodiment of the present application. DETAILED DESCRIPTION

[0024] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, unless there is a conflict, the embodiments in this application and the features described in the embodiments may be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.

[0025] See Figure 1 As shown, in some embodiments of the present application, this embodiment provides an oil and gas pipeline network risk assessment method, including the following steps:

[0026] S100: Obtain network layer data of the oil and gas pipeline network to be assessed, historical network layer attack records, and post-attack network status data.

[0027] The network layer data, historical network layer attack records, and post-attack network status data of the oil and gas pipeline network to be assessed, namely, the network layer data, historical network layer attack records, and post-attack network status data of the network platform corresponding to the oil and gas pipeline network to be assessed. Network layer data includes network traffic data, network protocol data, device status data, and log data. Post-attack network status data refers to the network status data of the oil and gas pipeline network to be assessed after a complex attack.

[0028] S200: Perform attack simulation on the test set to be evaluated corresponding to the network layer data by simulating a composite attack, obtain attack results, and calculate an initial risk assessment value of the oil and gas pipeline network to be evaluated based on the attack results.

[0029] S300: Based on historical network layer attack records, determine the historical attack deviation index of the oil and gas pipeline network to be assessed, and when the historical attack deviation index is greater than or equal to the historical attack deviation index threshold, correct the initial risk assessment value based on a preset correction coefficient.

[0030] S400: Based on the post-attack network status data, multiple post-attack network status characteristic values ​​of the oil and gas pipeline network to be evaluated are determined, and when at least one post-attack network status characteristic value is greater than the corresponding network status standard value, the corrected risk assessment value is compensated based on a preset compensation coefficient to obtain a compensated risk assessment value.

[0031] S500: Determine a risk assessment level of the oil and gas pipeline network to be assessed according to the compensated risk assessment value.

[0032] It is understood that the oil and gas pipeline network risk assessment method provided in this embodiment comprehensively considers the impact of multiple attack types on the oil and gas pipeline network. It is not limited to traditional single attack modes, but rather simulates complex attack scenarios, thereby more accurately assessing the risk level of the oil and gas pipeline network when it is attacked. This embodiment also considers the impact of historical attack data on the current risk assessment. By calculating the historical attack deviation index, it can reflect the potential impact of historical attack behavior on the current network status, thereby making necessary corrections to the initial risk assessment value, making the assessment result more closely aligned with the actual risk level. This embodiment also incorporates the analysis of real-time network layer data. By calculating the real-time behavior index, it can dynamically reflect the real-time status of the oil and gas pipeline network after an attack, further improving the accuracy and real-time nature of the risk assessment. By setting a compensation coefficient, this embodiment can compensate the revised risk assessment value based on the real-time behavior index, ensuring that the assessment result can timely reflect the safety status of the oil and gas pipeline network and provide a scientific basis for oil and gas pipeline network security protection.

[0033] It can be understood that this embodiment not only improves the accuracy of oil and gas pipeline network risk assessment, but also enhances the ability to respond to oil and gas pipeline network security threats, which helps the oil and gas industry to take more effective protective measures in the face of increasingly complex network attacks and ensure the safe and stable operation of oil and gas pipeline networks.

[0034] Specifically, the attack simulation is performed on the test set to be evaluated corresponding to the network layer data by simulating a composite attack, and the attack results obtained include:

[0035] Based on the network layer data, a test set to be evaluated is established.

[0036] Conduct denial of service attack simulations, distributed denial of service attack simulations, and man-in-the-middle attack simulations on the network traffic data in the evaluation test set to obtain traffic attack simulation results. The traffic attack simulation results include attack traffic intensity, request response failure rate, and resource occupancy rate.

[0037] Perform forged packet attack simulation and session hijacking attack simulation on the network protocol data in the evaluation test set to obtain protocol attack simulation results. The protocol attack simulation results include the number of forged packets, session hijacking success rate, and protocol anomaly rate.

[0038] The device status data in the evaluation test set is simulated for configuration error attacks and privilege escalation attacks to obtain status attack simulation results. The status attack simulation results include the number of configuration errors, privilege escalation success rate, and device abnormality rate.

[0039] Perform log tampering attack simulations and log forgery attack simulations on the log data in the evaluation test set to obtain log attack simulation results. The log attack simulation results include the number of tampered logs, the number of forged logs, and the log anomaly rate.

[0040] As you can understand, attack traffic intensity refers to the number of attack packets sent per unit time during the attack simulation, reflecting the intensity and potential damage of the attack. The request response failure rate refers to the ratio of the number of times the attacked device failed to respond to requests during the attack simulation to the total number of requests. This metric reveals the impact of the attack on network service availability. The resource utilization rate reflects the attack's utilization of network resources, including the utilization of key resources such as CPU and memory, and indicates the potential impact of the attack on network performance. The number of forged packets refers to the total number of forged packets sent during the attack simulation, revealing the attacker's level of control over network protocols. The session hijacking success rate refers to the ratio of the number of successful attempts to take over legitimate user sessions to the total number of attempts. This metric measures the attacker's ability to control network sessions. The number of configuration errors refers to the number of device misconfigurations discovered during the simulated attack, reflecting network device security vulnerabilities. The privilege escalation success rate refers to the ratio of the number of successful privilege escalation attempts to the total number of attempts. This metric measures the attacker's ability to control system permissions. The number of tampered logs refers to the number of log entries tampered with during the attack simulation, which reveals the extent of the attacker's interference with log records. The number of forged logs refers to the number of false log entries added during the attack simulation, which measures the extent of the attacker's damage to log integrity. The log anomaly rate refers to the proportion of log anomalies found during the attack simulation, which indicates the impact of the attack on the normal functioning of the logging system.

[0041] As you can see, these detailed simulation results provide a comprehensive understanding of the oil and gas pipeline network's response and vulnerability to different types of attacks. This not only helps assess the risk level of the oil and gas pipeline network under complex attacks, but also provides a basis for developing appropriate security measures, thereby improving the overall security of the oil and gas pipeline network.

[0042] Specifically, when calculating the initial risk assessment value of the oil and gas pipeline network to be assessed based on the attack results, it includes:

[0043] The attack results include traffic attack simulation results, protocol attack simulation results, state attack simulation results, and log attack simulation results.

[0044] The initial risk assessment value of the oil and gas pipeline network to be assessed is calculated based on the traffic attack simulation results, protocol attack simulation results, state attack simulation results, and log attack simulation results.

[0045] The initial risk assessment value is obtained by the following formula:

[0046]

[0047] Where Rinitial represents the initial risk assessment value. ωi represents the weight coefficient of the i-th attack simulation result. ni represents the number of indicators in the i-th attack simulation result. ωij represents the weight coefficient of the j-th indicator in the i-th attack simulation result. Xij represents the normalized value of the j-th indicator in the i-th attack simulation result.

[0048] It is understandable that to calculate the initial risk assessment value, it is first necessary to determine the weight coefficients ωi for each type of attack simulation result. Assume that the weight coefficients assigned to the denial of service attack simulation, distributed denial of service attack simulation, man-in-the-middle attack simulation, forged packet attack simulation, session hijacking attack simulation, configuration error simulation attack simulation, privilege escalation attack simulation, log tampering attack simulation, and log forgery attack simulation are ω1 to ω9, respectively. Next, assign a weight coefficient ωij to each indicator. For example, for the traffic attack simulation results, the weight coefficients for attack traffic intensity, request response failure rate, and resource occupancy are ω11, ω12, and ω13, respectively. Similarly, assign corresponding weight coefficients to each indicator in the protocol attack simulation results, state attack simulation results, and log attack simulation results.

[0049] Specifically, assume that in a certain evaluation, the normalized values ​​of the various attack simulation results obtained through simulated attacks are as follows: Traffic attack simulation results: The normalized value of attack traffic intensity is X11 = 0.8, the normalized value of request-response failure rate is X12 = 0.6, and the normalized value of resource occupancy is X13 = 0.7. Protocol attack simulation results: The normalized value of the number of forged packets is X21 = 0.5, the normalized value of the session hijacking success rate is X22 = 0.3, and the normalized value of the protocol anomaly rate is X23 = 0.4. State attack simulation results: The normalized value of the number of configuration errors is X31 = 0.2, the normalized value of the privilege escalation success rate is X32 = 0.1, and the normalized value of the device anomaly rate is X33 = 0.5. Log attack simulation results: The normalized value of the number of tampered logs is X41 = 0.6, the normalized value of the number of forged logs is X42 = 0.2, and the normalized value of the log anomaly rate is X43 = 0.3. Assume that the weight coefficients ω1 to ω9 are 0.15, 0.1, 0.1, 0.15, 0.1, 0.1, 0.1, 0.1, 0.1, and 0.1, respectively, and the indicator weight coefficient ωij of each attack simulation result is 1 / ni, that is, the weight coefficient of each indicator is equal, then:

[0050] Rinitial=0.15×(0.8×1 / 3+0.6×1 / 3+0.7×1 / 3)+0.1×(0.5×1 / 3+0.3×1 / 3+0.4×1 / 3)+ 0.1×(0.2×1 / 3+0.1×1 / 3+0.5×1 / 3)+0.15×(0.6×1 / 3+0.2×1 / 3+0.3×1 / 3)=0.223895.

[0051] Therefore, through the above calculations, we obtained the initial risk assessment value Rinitial of 0.223895, which provides basic data for subsequent risk quantification assessment.

[0052] It should be noted that the above calculation is only an example. In actual applications, the determination of the weight coefficients ωi and ωij needs to be adjusted according to the specific conditions of the oil and gas pipeline network and historical attack data to ensure the accuracy and applicability of the evaluation results.

[0053] Specifically, based on historical network layer attack records, the historical attack deviation index of the oil and gas pipeline network to be assessed is determined, including:

[0054] Analyze historical network-layer attack records to obtain first and second attack behaviors. First attack behaviors are defined as those with a frequency greater than a first frequency threshold and a risk factor less than the first risk threshold. Second attack behaviors are defined as those with a frequency less than a second frequency threshold and a risk factor greater than the second risk threshold. The risk factor indicates the extent of damage to the oil and gas pipeline network to be assessed when the attack occurs. The higher the risk factor of the attack, the greater the extent of damage to the oil and gas pipeline network to be assessed.

[0055] An attack severity factor corresponding to each first attack behavior and an attack severity factor corresponding to each second attack behavior are determined respectively, and an attack severity factor sequence is constructed.

[0056] The number of the first attack behaviors is counted and recorded as the first number. The number of the second attack behaviors is counted and recorded as the second number.

[0057] The historical attack deviation index of the oil and gas pipeline network to be evaluated is calculated based on the attack severity factor sequence, the first quantity, and the second quantity. The historical attack deviation index is obtained by the following formula:

[0058]

[0059] Where Ihistory represents the historical attack deviation index. a represents the first quantity. b represents the second quantity. Sk represents the attack severity factor of the kth first attack behavior. Ck represents the number of the kth first attack behaviors. Hl represents the attack severity factor of the lth second attack behavior. Rl represents the number of the lth second attack behaviors.

[0060] Understandably, in order to more accurately reflect the impact of historical attacks on the current network status, in-depth analysis of historical attack records is required. By statistically analyzing the frequency of various attack behaviors in historical records, we can identify which attack behaviors are frequent and which pose a higher risk. Primary attack behaviors typically refer to attacks that occur frequently but are likely to cause relatively little damage, while secondary attack behaviors refer to attacks that occur less frequently but could potentially cause severe damage to the oil and gas pipeline network. After determining primary and secondary attack behaviors, each attack behavior is then assigned an attack severity factor. This factor reflects the potential damage the attack behavior could cause to the oil and gas pipeline network. For example, a denial of service attack might have a low attack severity factor because it might not cause direct damage to physical equipment in the oil and gas pipeline network, but it would temporarily disrupt service. Conversely, a successful privilege escalation attack might have a high attack severity factor because it could allow the attacker to gain control of critical systems, posing a direct threat to the security of the oil and gas pipeline network. By calculating the historical attack deviation index and the real-time behavior index, this embodiment can not only correct the initial risk assessment value, but also dynamically reflect the real-time status of the oil and gas pipeline network after being attacked, thereby providing more timely and accurate assessment results for the security protection of the oil and gas pipeline network.

[0061] In some embodiments, the oil and gas pipeline network risk assessment method provided in the embodiments of the present application further includes:

[0062] When the historical attack deviation index is less than the historical attack deviation index threshold, the initial risk assessment value remains unchanged.

[0063] Specifically, the historical attack deviation index can be compared with the historical attack deviation index threshold, and the comparison result can be used to determine whether to revise the initial risk assessment value. If the historical attack deviation index is greater than or equal to the historical attack deviation index threshold, the initial risk assessment value is revised. If the historical attack deviation index is less than the historical attack deviation index threshold, the initial risk assessment value is not revised.

[0064] Specifically, when revising the initial risk assessment value based on the preset correction factor, it includes:

[0065] A preset coefficient interval is obtained, wherein the preset coefficient interval includes a first correction coefficient, a second correction coefficient, and a third correction coefficient. The first correction coefficient is smaller than the second correction coefficient, and the second correction coefficient is smaller than the third correction coefficient.

[0066] Calculate the ratio of the historical attack deviation index to the historical attack deviation index threshold, and record it as the attack deviation ratio.

[0067] The attack deviation ratio is compared with a first attack deviation ratio threshold and a second attack deviation ratio threshold, and a correction coefficient corresponding to the initial risk assessment value is determined based on the comparison results, wherein the first attack deviation ratio threshold is less than the second attack deviation ratio threshold.

[0068] When the attack deviation ratio is less than or equal to the first attack deviation ratio threshold, the first correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the first correction coefficient and the initial risk assessment value is used as the corrected risk assessment value.

[0069] When the attack deviation ratio is greater than the first attack deviation ratio threshold and less than or equal to the second attack deviation ratio threshold, the second correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the second correction coefficient and the initial risk assessment value is used as the corrected risk assessment value.

[0070] When the attack deviation ratio is greater than the second attack deviation ratio threshold, the third correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the third correction coefficient and the initial risk assessment value is used as the corrected risk assessment value.

[0071] As you can see, the above steps yield an initial risk assessment value that's corrected based on historical attack data, making the assessment more consistent with the current security status of the oil and gas pipeline network. The correction factor takes into account the relationship between the historical attack deviation index and the threshold, ensuring the dynamic and adaptable nature of the risk assessment. In practice, the correction factor range can be adjusted based on the specific conditions and security requirements of the oil and gas pipeline network to achieve optimal risk assessment results.

[0072] Specifically, based on the post-attack network status data, multiple post-attack network status characteristic values ​​of the oil and gas pipeline network to be assessed are determined, including:

[0073] Feature extraction is performed on the post-attack network status data to obtain multiple post-attack network status feature values ​​corresponding to the post-attack network status data. The multiple post-attack network status feature values ​​include traffic anomaly rate, device load rate, and network delay time.

[0074] In some embodiments, the oil and gas pipeline network risk assessment method provided in the embodiments of the present application further includes:

[0075] When multiple post-attack network status characteristic values ​​are all less than or equal to the corresponding network status standard values, the modified risk assessment value remains unchanged.

[0076] Based on this, this application can support feature extraction of all real-time network layer data and obtain the post-attack network status feature values ​​corresponding to all real-time network layer data.

[0077] Determine the network status standard value corresponding to each post-attack network status characteristic value.

[0078] When all post-attack network state characteristic values ​​are less than or equal to the corresponding network state standard values, it is determined that no compensation is required for the modified risk assessment value.

[0079] When one or more post-attack network state characteristic values ​​are greater than corresponding network state standard values, it is determined that the modified risk assessment value needs to be compensated.

[0080] It's understood that post-attack network status characteristic values ​​include key indicators such as traffic anomaly rate, device load rate, and network latency. These indicators reflect the network's current operating status and potential security risks. Real-time monitoring of these characteristic values ​​can promptly detect anomalies. The network status standard values ​​are set based on the normal operating parameters of the oil and gas pipeline network and historical security incident data. These standard values ​​provide a benchmark for assessing whether post-attack network status characteristic values ​​are abnormal. If post-attack network status characteristic values ​​exceed the standard range, this indicates a possible security incident and requires further analysis and action. For example, if real-time network traffic suddenly increases, exceeding the set standard value, a deeper network inspection may be necessary to determine whether a denial-of-service attack is occurring.

[0081] Specifically, when compensating the revised risk assessment value based on the preset compensation coefficient, it includes:

[0082] The post-attack network state characteristic value greater than the network state standard value is determined as the target network state characteristic value, and the difference between each target network state characteristic value and the network state standard value is calculated.

[0083] A first difference value set is generated according to all difference values ​​that are less than or equal to a preset difference value.

[0084] A second difference value set is generated according to all difference values ​​greater than a preset difference value.

[0085] A first average difference value of the first difference value set is calculated, and a second average difference value of the second difference value set is calculated.

[0086] A real-time behavior index of the oil and gas pipeline network to be evaluated is calculated based on the first average difference value and the second average difference value.

[0087] The real-time behavior index is obtained by the following formula:

[0088] RBI=Δ1×α+Δ2×β.

[0089] Where RBI represents the real-time behavior index, Δ1 represents the first average difference value, α represents the first impact coefficient, Δ2 represents the second average difference value, and β represents the second impact coefficient.

[0090] The modified risk assessment value is compensated based on the preset compensation coefficient and the real-time behavior index.

[0091] It is understood that the calculation of the Real-time Behavior Index (RBI) is to quantify the degree of deviation between the current network state and the normal operating state. By analyzing the difference between the characteristic value of the network state after the attack and the standard value of the network state, the first average difference value can be obtained. and the second mean difference The first mean difference It reflects the fluctuation of network characteristic values ​​within the normal range, while the second average difference value The first impact coefficient α and the second impact coefficient β are set to take into account the impact of different difference values ​​on the overall network status, ensuring that the real-time behavior index can accurately reflect the real-time security status of the network.

[0092] Specifically, based on the preset compensation coefficient and the real-time behavior index, the compensation for the modified risk assessment value includes:

[0093] A preset compensation coefficient is set, wherein the preset compensation coefficient includes a first compensation coefficient, a second compensation coefficient, and a third compensation coefficient, wherein the first compensation coefficient is smaller than the second compensation coefficient, and the second compensation coefficient is smaller than the third compensation coefficient.

[0094] The real-time behavior index is compared with a first behavior index threshold and a second behavior index threshold, and a compensation coefficient corresponding to the revised risk assessment value is determined based on the comparison result, wherein the first behavior index threshold is less than the second behavior index threshold.

[0095] When the real-time behavior index is less than or equal to the first behavior index threshold, the first compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the first compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value.

[0096] When the real-time behavior index is greater than the first behavior index threshold and less than or equal to the second behavior index threshold, the second compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the second compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value.

[0097] When the real-time behavior index is greater than the second behavior index threshold, the third compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product of the third compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value.

[0098] As can be understood, the above steps yield a corrected risk assessment value, modified by the real-time behavior index, making the assessment more consistent with the current safety status of the oil and gas pipeline network. The compensation coefficient is set by taking into account the relationship between the real-time behavior index and the threshold, ensuring the dynamic and adaptable nature of the risk assessment. In practical applications, the compensation coefficient range can be adjusted based on the specific conditions and safety requirements of the oil and gas pipeline network to achieve optimal risk assessment results.

[0099] Specifically, when determining the risk assessment level of the oil and gas pipeline network to be assessed based on the compensated risk assessment value, it includes:

[0100] The compensation risk assessment value is compared with the compensation risk assessment threshold, and the risk assessment level of the oil and gas pipeline network to be assessed is determined based on the comparison result.

[0101] When the compensation risk assessment value is less than or equal to the compensation risk assessment threshold, the risk assessment level of the oil and gas pipeline network to be assessed is determined to be the first level.

[0102] When the compensation risk assessment value is greater than the compensation risk assessment threshold, the risk assessment level of the oil and gas pipeline network to be assessed is determined to be the second level.

[0103] Among them, the first level is smaller than the second level.

[0104] As you can see, the above steps can be used to categorize the risk assessment of oil and gas pipeline networks into different levels, providing safety managers with a clear indication of the risk status. This categorization of risk assessment levels helps to quickly identify and respond to potential security threats, ensuring the stable operation of the oil and gas pipeline network.

[0105] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or a combination of software and hardware embodiments. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] The present application is described with reference to the flowcharts of the methods according to the embodiments of the present application. It should be understood that each process in the flowchart, as well as the combination of processes in the flowchart, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate the instructions for implementing the processes in the flowchart. Figure 1 A device that specifies functions in a process or multiple processes.

[0107] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A function specified in a process or multiple processes.

[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 The steps of a specified function in a process or multiple processes.

[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and not to limit them. Although the present application has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present application can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present application should be included in the scope of protection of the claims of the present application.

Claims

1. A method for risk assessment of oil and gas pipeline networks, characterized in that: include: Obtain network layer data, historical network layer attack records, and post-attack network status data of the oil and gas pipeline network to be assessed; wherein the network layer data includes network traffic data, network protocol data, device status data, and log data; the post-attack network status data is the network status data of the oil and gas pipeline network to be assessed after the composite attack; Performing attack simulation on the test set to be evaluated corresponding to the network layer data by simulating a composite attack to obtain attack results, and calculating an initial risk assessment value of the oil and gas pipeline network to be evaluated based on the attack results; Based on the historical network layer attack records, determining a historical attack deviation index of the oil and gas pipeline network to be assessed, and, if the historical attack deviation index is greater than or equal to a historical attack deviation index threshold, correcting the initial risk assessment value based on a preset correction coefficient to obtain a corrected risk assessment value; Determining, based on the post-attack network state data, a plurality of post-attack network state characteristic values ​​of the oil and gas pipeline network to be assessed, and compensating the modified risk assessment value based on a preset compensation coefficient when at least one of the post-attack network state characteristic values ​​is greater than a corresponding network state standard value to obtain a compensated risk assessment value; The risk assessment level of the oil and gas pipeline network to be assessed is determined according to the compensated risk assessment value.

2. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: The step of performing attack simulation on the test set to be evaluated corresponding to the network layer data by simulating a composite attack to obtain an attack result includes: Establishing a test set to be evaluated based on the network layer data; Performing denial of service attack simulation, distributed denial of service attack simulation, and man-in-the-middle attack simulation on the network traffic data in the test set to be evaluated to obtain traffic attack simulation results; wherein the traffic attack simulation results include attack traffic intensity, request response failure rate, and resource occupancy rate; Perform forged data packet attack simulation and session hijacking attack simulation on the network protocol data in the test set to be evaluated to obtain protocol attack simulation results; wherein the protocol attack simulation results include the number of forged data packets, session hijacking success rate and protocol anomaly rate; Performing configuration error simulation attack simulation and privilege escalation attack simulation on the device status data in the test set to be evaluated to obtain status attack simulation results; wherein the status attack simulation results include the number of configuration errors, privilege escalation success rate, and device abnormality rate; Perform log tampering attack simulation and log forgery attack simulation on the log data in the test set to be evaluated to obtain log attack simulation results; wherein the log attack simulation results include the number of tampered logs, the number of forged logs and the log anomaly rate.

3. The oil and gas pipeline network risk assessment method according to claim 2, characterized in that: Calculating the initial risk assessment value of the oil and gas pipeline network to be assessed based on the attack result includes: The attack results include the traffic attack simulation result, the protocol attack simulation result, the state attack simulation result and the log attack simulation result; Calculating an initial risk assessment value of the oil and gas pipeline network to be assessed based on the traffic attack simulation results, the protocol attack simulation results, the state attack simulation results, and the log attack simulation results; The initial risk assessment value is obtained by the following formula: Where Rinitial represents the initial risk assessment value; ωi represents the weight coefficient of the i-th attack simulation result; ni represents the number of indicators in the i-th attack simulation result; ωij represents the weight coefficient of the j-th indicator of the i-th attack simulation result; Xij represents the normalized value of the j-th indicator of the i-th attack simulation result.

4. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: Determining the historical attack deviation index of the oil and gas pipeline network to be evaluated based on the historical network layer attack records includes: Analyzing the historical network layer attack records to obtain a first attack behavior and a second attack behavior; the first attack behavior is used to represent an attack behavior whose occurrence frequency is greater than a first frequency threshold and whose risk coefficient is less than the first risk threshold; the second attack behavior is used to represent an attack behavior whose occurrence frequency is less than a second frequency threshold and whose risk coefficient is greater than the second risk threshold; Determining the attack severity factor corresponding to each first attack behavior and the attack severity factor corresponding to each second attack behavior, respectively, and constructing an attack severity factor sequence; Counting the number of the first attack behaviors, which is recorded as a first number; counting the number of the second attack behaviors, which is recorded as a second number; The historical attack deviation index of the oil and gas pipeline network to be evaluated is calculated according to the attack severity factor sequence, the first quantity, and the second quantity; wherein the historical attack deviation index is obtained by the following formula: Where Ihistory represents the historical attack deviation index; a represents the first quantity; b represents the second quantity; Sk represents the attack severity factor of the k-th first attack behavior; Ck represents the number of the k-th first attack behavior; Hl represents the attack severity factor of the l-th second attack behavior, and Rl represents the number of the l-th second attack behavior.

5. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: Also includes: When the historical attack deviation index is less than the historical attack deviation index threshold, the initial risk assessment value is kept unchanged.

6. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: The correcting the initial risk assessment value based on a preset correction coefficient includes: Obtaining the preset correction coefficient, wherein the preset correction coefficient includes a first correction coefficient, a second correction coefficient, and a third correction coefficient; the first correction coefficient is smaller than the second correction coefficient, and the second correction coefficient is smaller than the third correction coefficient; Calculating a ratio of the historical attack deviation index to the historical attack deviation index threshold, and recording the ratio as an attack deviation ratio; When the attack deviation ratio is less than or equal to a first attack deviation ratio threshold, the first correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the first correction coefficient and the initial risk assessment value is used as the corrected risk assessment value; When the attack deviation ratio is greater than the first attack deviation ratio threshold and less than or equal to the second attack deviation ratio threshold, the second correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the second correction coefficient and the initial risk assessment value is used as the corrected risk assessment value; the first attack deviation ratio threshold is less than the second attack deviation ratio threshold; When the attack deviation ratio is greater than the second attack deviation ratio threshold, the third correction coefficient is selected as the correction coefficient corresponding to the initial risk assessment value, and the product of the third correction coefficient and the initial risk assessment value is used as the corrected risk assessment value.

7. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: The determining, based on the post-attack network status data, a plurality of post-attack network status characteristic values ​​of the oil and gas pipeline network to be evaluated includes: Performing feature extraction on the post-attack network state data to obtain a plurality of post-attack network state feature values ​​corresponding to the post-attack network state data; the plurality of post-attack network state feature values ​​including a traffic anomaly rate, a device load rate, and a network delay time; The method further comprises: In a case where the plurality of post-attack network state characteristic values ​​are all less than or equal to corresponding network state standard values, the modified risk assessment value is maintained unchanged.

8. The oil and gas pipeline network risk assessment method according to claim 7, characterized in that: The compensating the modified risk assessment value based on a preset compensation coefficient includes: Determining a post-attack network state characteristic value greater than the network state standard value as a target network state characteristic value, and calculating a difference between each target network state characteristic value and the network state standard value; generating a first difference value set according to all the difference values ​​that are less than or equal to a preset difference value; generating a second difference value set according to all the difference values ​​greater than a preset difference value; calculating a first average difference value of the first difference value set, and calculating a second average difference value of the second difference value set; Calculating a real-time behavior index of the oil and gas pipeline network to be evaluated based on the first average difference value and the second average difference value; The real-time behavior index is obtained by the following formula: RBI = Δ1 × α + Δ2 × β; Wherein, RBI represents the real-time behavior index, Δ1 represents the first average difference value; α represents the first impact coefficient; Δ2 represents the second average difference value; β represents the second impact coefficient; The modified risk assessment value is compensated based on the preset compensation coefficient and the real-time behavior index.

9. The oil and gas pipeline network risk assessment method according to claim 8, characterized in that: The compensating the modified risk assessment value based on the preset compensation coefficient and the real-time behavior index includes: Obtaining the preset compensation coefficient, wherein the preset compensation coefficient includes a first compensation coefficient, a second compensation coefficient, and a third compensation coefficient; the first compensation coefficient is smaller than the second compensation coefficient, and the second compensation coefficient is smaller than the third compensation coefficient; Comparing the real-time behavior index with a first behavior index threshold and a second behavior index threshold, and determining a compensation coefficient corresponding to the modified risk assessment value according to the comparison result; wherein the first behavior index threshold is less than the second behavior index threshold; When the real-time behavior index is less than or equal to the first behavior index threshold, the first compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product of the first compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value; When the real-time behavior index is greater than the first behavior index threshold and less than or equal to the second behavior index threshold, the second compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product of the second compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value; When the real-time behavior index is greater than the second behavior index threshold, the third compensation coefficient is selected as the compensation coefficient corresponding to the modified risk assessment value, and the product value of the third compensation coefficient and the modified risk assessment value is used as the compensated risk assessment value.

10. The oil and gas pipeline network risk assessment method according to claim 1, characterized in that: Determining the risk assessment level of the oil and gas pipeline network to be assessed according to the compensated risk assessment value includes: Comparing the compensation risk assessment value with the compensation risk assessment threshold, and determining the risk assessment level of the oil and gas pipeline network to be assessed according to the comparison result; When the compensation risk assessment value is less than or equal to the compensation risk assessment threshold, determining that the risk assessment level of the oil and gas pipeline network to be assessed is the first level; When the compensation risk assessment value is greater than the compensation risk assessment threshold, determining that the risk assessment level of the oil and gas pipeline network to be assessed is the second level; The first level is smaller than the second level.