A security control method, device, equipment and medium of an industrial network

By constructing a digital twin of the smelting production line and generating attack traffic using the PPO algorithm, the problem of insufficient countermeasure capabilities in traditional industrial network security defense systems has been solved, and the optimization and autonomous evolution of the defense system have been achieved.

CN120750650BActive Publication Date: 2025-12-26BENXI IRON & STEEL (GROUP) INFORMATION AUTOMATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511212511.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-28
Publication Date
2025-12-26
Estimated Expiration
2045-08-28

AI Technical Summary

Technical Problem

Traditional industrial network security defense systems lack high-quality attack data training, making it difficult to improve the system's adversarial capabilities. Furthermore, existing attack testing tools cannot effectively identify highly covert attacks that can cause cumulative damage, resulting in defense measures lagging behind attack evolution.

Method used

A digital twin of the smelting production line is constructed, a mapping table of attack commands and attack damage is established, and the PPO algorithm is used to generate attack traffic that is both destructive and covert. The digital twin is used to simulate and verify the countermeasure capabilities of the defense system, and the attack traffic is optimized through the reward function, forming a closed-loop evolution of attack and defense exercises.

Benefits of technology

It achieves deep integration of attack traffic and smelting scenarios, optimizes the defense performance of the defense system, discovers defense vulnerabilities, and continuously iterates and optimizes the defense system, thereby improving the real-time response and autonomous evolution capabilities of the defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750650B_ABST
    Figure CN120750650B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of industrial network security, and discloses a security control method, device and equipment of an industrial network and a medium, the method comprising: acquiring production line data to construct a digital twin of a smelting production line; acquiring historical attack data, establishing a mapping table of attack instructions-attack damage, and forming an attack database according to the ICS Matrix framework; constructing an attack agent based on a PPO algorithm and calling the attack database to output attack traffic; executing the attack traffic on the digital twin to obtain the attack success rate, attack damage, attack concealment and attack cost of the attack traffic; for attack traffic with an attack success rate greater than a first threshold, calculating a reward function of the PPO algorithm and generating optimized attack traffic through the reward function to iterate the defense system of the smelting production line. The present application builds an attack database by itself, enables the attack agent to continuously optimize attack traffic, and uses the digital twin to realize the iterative optimization of the defense system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial network security, and in particular to a security control method, device and equipment of an industrial network and a medium. BACKGROUND

[0002] With the deep application of the industrial internet in the smelting field, the intelligent degree of the smelting production line is significantly improved, but at the same time, it also faces increasingly complex network attack threats. The traditional industrial security defense adopts a static rule base or a general penetration testing technology, which has the following limitations: 1. The existing attack testing tool lacks dynamic perception ability for process characteristics, and the generated attack instructions are easy to be filtered by normal production logic or trigger device safety interlocking to cause attack failure; 2. Ordinary attack strategies often have difficulty in balancing between destructiveness and concealment, for example, direct over-limit attack is strong in destructiveness but easy to be detected, while low-intensity exploratory attack is high in concealment but difficult to cause substantial damage, resulting in that the defense system cannot verify the real countermeasures; 3. The lack of training data makes the attack simulation and defense evolution lack high-quality data support.

[0003] Therefore, the rule base relying on historical attack patterns is difficult to cope with new customized attacks, and the defense measures are updated behind the attack evolution, especially for attack instructions with high concealment and causing cumulative damage, which are difficult for the existing defense system to identify and cope with. In addition, testing attack traffic directly on the entity production line may cause production accidents, and offline simulation cannot accurately restore the dynamic characteristics of the process. SUMMARY

[0004] The purpose of the present application is to: for the security defense of the traditional industrial network, lack of high-quality attack data for training, there are problems such as difficult to improve the countermeasures of the defense system, provide a security control method, device, equipment and medium of industrial network, can be deeply integrated with smelting scene, constantly optimize production high-quality attack traffic, ensure the concealment and destructiveness of attack traffic in smelting scene, so as to facilitate the verification of the countermeasures of the defense system, in order to promote the iterative upgrade of the defense system.

[0005] In order to achieve the above object, in a first aspect of the present application, a security control method of an industrial network is provided, comprising: S1, obtaining production line data to construct a digital twin of a smelting production line; S2, obtaining historical attack data, establishing a mapping table of attack instructions-attack damage, and forming an attack database according to an ICS Matrix framework; S3, constructing an attack agent based on a PPO algorithm, and calling the attack database to output attack traffic, wherein the attack agent receives simulation data of the digital twin in real time, obtains parameter limits and process sensitive periods of an attack target, to determine an action space of the attack agent, and generates attack traffic under the constraint of the action space; S4, performing attack traffic on the digital twin to obtain attack success rate, attack damage, attack concealment and attack cost of the attack traffic; S5, for attack traffic with an attack success rate greater than a first threshold, calculating a reward function of the PPO algorithm according to the attack damage, the attack concealment and the attack cost, and generating optimized attack traffic through the reward function; and S6, iteratively optimizing a defense system of the smelting production line based on the optimized attack traffic.

[0006] In a second aspect of the present application, a security control device of an industrial network is provided, comprising: a twin module configured to obtain production line data to construct a digital twin of a smelting production line; a database module configured to obtain historical attack data, establish a mapping table of attack instructions-attack damage, and form an attack database according to an ICS Matrix framework; an attack module configured to construct an attack agent based on a PPO algorithm, and call the attack database to output attack traffic, wherein the attack agent receives simulation data of the digital twin in real time, obtains parameter limits and process sensitive periods of an attack target, to determine an action space of the attack agent, and generates attack traffic under the constraint of the action space; a simulation module configured to perform attack traffic on the digital twin to obtain attack success rate, attack damage, attack concealment and attack cost of the attack traffic; an optimization module configured to, for attack traffic with an attack success rate greater than a first threshold, calculate a reward function of the PPO algorithm according to the attack damage, the attack concealment and the attack cost, and generate optimized attack traffic through the reward function; and a defense module configured to iteratively optimize a defense system of the smelting production line based on the optimized attack traffic.

[0007] In a third aspect of the present application, an electronic device is provided, comprising a memory and a processor coupled to the memory, the processor being configured to execute the method of the first aspect based on instructions stored in the memory.

[0008] In a fourth aspect of the present application, a computer readable storage medium is provided, having a computer program stored thereon, the computer program being executed by a processor to implement the method of the first aspect.

[0009] The technical scheme of the present application is that the TTPs data of the attack database is self-built through historical attack data, and the parameter limit and process sensitive period of the smelting equipment are obtained in real time by using the digital twin, the action space is set, the attack agent can intelligently generate attack traffic with destructive and concealed properties based on the PPO algorithm, invalid attack instructions or low-quality attack traffic are avoided, after the attack simulation of the digital twin, the attack traffic is deeply integrated with the smelting scene through the design calculation of the reward function, the attack traffic is continuously optimized, based on the continuously optimized attack traffic, the simulation training of the digital twin is carried out, not only the defense performance of the existing smelting production line defense system can be verified, but also the defense vulnerabilities can be found, the defense system is continuously iteratively optimized, and the closed-loop evolution of attack and defense exercises is formed in the digital twin. BRIEF DESCRIPTION OF DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0011] Figure 1 is a flow chart of the security control method of the industrial network described in the embodiment.

[0012] Figure 2 is an optimization flow chart of the defense system described in the embodiment.

[0013] Figure 3 is a structural schematic diagram of the security control device of the industrial network described in the embodiment.

[0014] Figure 4 is a structural schematic diagram of the electronic device described in the embodiment. DETAILED DESCRIPTION

[0015] The technical solutions in the embodiments of the present application will be described clearly and completely in the embodiments of the present application in combination with the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0016] The present application will be described below in combination with the drawings and specific embodiments.

[0017] As Figure 1As shown, the security control method of the industrial network in the embodiment includes: S1, acquiring production line data to construct a digital twin of a smelting production line; S2, acquiring historical attack data, establishing a mapping table of attack instructions-attack damage, and forming an attack database according to the ICS Matrix framework; S3, constructing an attack agent based on the PPO algorithm, calling the attack database to output attack traffic, wherein the attack agent receives simulation data of the digital twin in real time, obtains parameter limits and process sensitive periods of the attack target, to determine the action space of the attack agent, and generates attack traffic under the constraint of the action space; S4, performing attack traffic on the digital twin to obtain the attack success rate, attack damage, attack concealment, and attack cost of the attack traffic; S5, for attack traffic with an attack success rate greater than a first threshold, calculating a reward function of the PPO algorithm according to the attack damage, attack concealment, and attack cost, and generating optimized attack traffic through the reward function; and S6, iterating the defense system of the smelting production line based on the optimized attack traffic.

[0018] The production line data can include device body data, process data, dynamic environment data, time sequence data of PLC controllers and sensors, and the like, that is, digital twins are formed for the field control layer and the field device layer in the real industrial network to form a high-fidelity digital twin that can simulate the smelting production line and support fault prediction and process optimization.

[0019] ICS Matrix (Industrial Control System Matrix) is a knowledge framework specially constructed for security threats in industrial control environments, which maps the tactics and techniques of attackers to scenarios specific to industrial control systems, providing structured guidance for protection, and is also a vertical application of the ATT&CK framework in the field of industrial control systems. ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is an existing attack model framework. ICS Matrix completely follows the TTPs (Tactics, Techniques, and Procedures) data format of ATT&CK, and based on the ICS Matrix framework, the historical attack data of the smelting production line is sorted out to construct an attack database that can deeply couple the ATT&CK tactics with the digital twin, and then construct a dedicated attack database for the smelting scene, thereby improving the effectiveness and practicality of the attack traffic output by the subsequent attack agent.

[0020] Meanwhile, the mapping table based on historical attack data is established to make up for the shortcomings of the ICS Matrix framework, such as supplementing a specific physical damage model on a smelting production line to the attack database, quantifying attack damage that may be caused by attack instructions (such as modifying temperature parameters) to equipment damage and product defects, thereby providing a quantitative basis for the calculation of attack damage, assisting the calculation of reward functions and risk scores, and serving as reference data for generating attack traffic.

[0021] When establishing the mapping table of attack instructions-attack damage, first, the attack instructions need to be associated with the ATT&CK framework to ensure standardized attack classification, then the attack objects and attack parameters are determined, and finally the corresponding attack damage is determined, which may be determined by expert experience, may be obtained by detecting historical events, or may be calculated by some quantitative formula. For example, in a smelting scenario, part of the mapping table can be formed as shown in the following table:

[0022]

[0023] PPO (Proximal Policy Optimization) is a reinforcement learning algorithm that mainly limits the update amplitude through the action space to prevent the generated attack traffic from deviating too much, realizes the moderate improvement of the attack traffic, and uses the reward function to evaluate the relatively good and bad of the generated attack traffic, thereby continuously optimizing and updating the strategy and gradually generating more dangerous and effective attack traffic.

[0024] When the attack agent calls the attack database, the corresponding TTPs data and framework are extracted and arranged, that is, the tactical targets, technical means and operation processes required for the attack are taken as input data, and the corresponding mapping table information and action space are also taken as input data, and then the reinforcement learning outputs the attack traffic. The attack traffic refers to multiple attack instructions output by the attack agent, wherein the multiple attack instructions can be independent attack instructions or attack instruction chains.

[0025] It should be noted that the action space is determined based on the real-time simulation information of the digital twin, and further determined by the parameter limit and process sensitive period of the attack target. The parameter limit and process sensitive period are updated in real time according to the field working condition. The parameter limit refers to the physical limit of the attack target controlled under the current working condition or the theoretical range of tampering. The process sensitive period refers to the key smelting step under the working condition, which is usually the stage of key monitoring. That is, some attack targets in some smelting steps will be obviously prohibited from operating. If attack traffic related to the operation is generated at this time, it is easy to be identified and shielded.

[0026] For example, when the attack target is the oxygen lance height controller, if the information that the oxygen lance is at the lowest moving point is obtained in the simulation data, it can be determined that the control of the oxygen lance height movement cannot continue to move downward, that is, the current parameter limit of the oxygen lance height controller is greater than 0 (less than 0 represents that the oxygen lance height is controlled to descend), and then the attack agent is prohibited from generating an attack instruction to control the oxygen lance to descend at this time. Therefore, the parameter greater than 0 of the oxygen lance height controller is a constraint condition of the current attack flow, which belongs to the constraint formed by the corresponding parameter limit. For another example, it is obtained that the current smelting production line is in the process sensitive period of the tapping stage, and at this time the ladle car is obviously in a state of being unable to move. Therefore, the attack agent is prohibited from generating an attack flow to move the ladle car, that is, the tapping stage prohibits the generation of the movement of the ladle car as a constraint condition of the current attack flow, which belongs to the constraint formed by the corresponding process sensitive period. In this way, based on multiple attack targets on the smelting production line and the constraints of various parameter limits and various process sensitive periods, the action space of the attack flow can be combined to constrain the generation of the attack flow, so as to avoid generating invalid attack instructions or attack instructions that can be easily identified and shielded, that is, to avoid generating attack instructions with extremely low attack success rate and wasting limited attack cost, thereby effectively promoting the attack agent to generate high-quality attack flow.

[0027] After generating the attack flow, the attack simulation can be performed in the digital twin to verify the attack effect and the countermeasures of the defense system, and to obtain the required simulation data. The attack success rate, attack damage, attack concealment and attack cost can be determined according to the actual working condition, for example, can be collected through the digital twin or can be calculated based on the historical data with appropriate weights.

[0028] For example, the attack success rate is the probability of successfully triggering the expected damage. The attack success rate can be calculated by combining the historical data and the process sensitive period, that is, the attack success rate P = a * b * 100%, wherein a is the historical success rate, which can be obtained based on the ratio of the historical success number to the total attack number of the same type of attack instruction in the attack database, and b is the process sensitive period coefficient, which is 1.0-1.5, 1 in the non-process sensitive period and 1.5 in the process sensitive period. Since the key stage is more sensitive to parameter fluctuation and has a higher attack success probability, the weight correction can more accurately reflect the actual risk.

[0029] The attack damage can be obtained by simulating the damage in real time through the digital twin, and in order to reduce the simulation cost, the attack damage can also be estimated directly based on the established mapping table. Specifically, the attack damage can be calculated by combining the equipment loss and the quality loss, that is, the attack damage D=c+d, wherein c is the equipment loss, such as repair cost, downtime cost, etc., and d is the quality loss, such as product scrap cost or order breach cost, etc.

[0030] The attack concealment is the probability of being detected by the detection system, which can be obtained based on the security detection module in the digital twin. Specifically, the frequency of attack traffic triggering an alarm is counted to determine the size of the attack concealment. The attack concealment can also be indirectly calculated based on the traffic feature anomaly degree e1, the behavior pattern anomaly degree e2, and the log tampering possibility e3, such as attack concealment G=1-(0.5e1+0.3e2+0.2e3). Since the industrial network traffic is regular and easy to detect anomalies, the weight of e1 is set to 0.5. Since log tampering usually requires higher permissions, the weight of e3 is set to 0.2.

[0031] The attack cost T can be calculated by the network resource cost consumed by the attack and the time cost, that is, T=f+g, wherein f is the network resource cost, such as the cost of zombie devices, the byte cost of attack traffic, etc., and g is the time cost, such as the attack time cost (which can be obtained through the simulation data of the digital twin), the preparation time cost of the attack, etc.

[0032] The first threshold value can be set according to actual needs. For example, attack traffic with an attack success rate of less than 30% can be eliminated, that is, only attack traffic with an attack success rate greater than 30% can be calculated by the reward function, so as to guide the attack agent to only optimize and update attack traffic with an attack success rate greater than 30%.

[0033] The present application builds the TTPs data of the attack database through the historical attack data, and uses the digital twin to obtain the parameter limit and process sensitive period of the smelting equipment in real time, completes the establishment of the action space, so that the attack agent can intelligently generate attack traffic with destructive and concealment based on the PPO algorithm, while avoiding the generation of invalid attack instructions or low-quality attack traffic. After the attack simulation of the digital twin and the design calculation of the reward function, the attack traffic can be deeply integrated with the smelting scene, and the attack traffic can be continuously optimized. Based on the continuously optimized attack traffic, through the simulation training of the digital twin, not only the defense performance of the existing smelting production line defense system can be verified, but also the defense vulnerabilities can be found, and the defense system can be continuously iterated and optimized, forming a closed-loop evolution of attack and defense in the digital twin.

[0034] In some optional embodiments, the defense measures of the smelting production line are iteratively refined based on the optimized attack traffic, including: S61, calculating a risk score according to the attack success rate, attack damage, and attack concealment of the attack traffic; and S62, implementing hierarchical access control on the attack targets of the digital twin according to the risk score, and optimizing the access control based on the simulation data of the digital twin.

[0035] As one of the important defense means of the industrial defense system, the access control can block the access of the attack traffic in real time, thereby isolating the harm of the attack traffic in time, and the risk score can be used to assess the threat of the attack traffic and facilitate risk grading. Based on the access optimization of the digital twin, the defense effect of different process stages can be simulated, intelligent mapping of attack features to access control is realized, the problem of lagging of traditional static defense rules is solved, the defense system is promoted to evolve autonomously, and the defense system of the smelting production line has the ability to co-evolve with the attack agent.

[0036] In some optional embodiments, the hierarchical access control on the attack targets of the digital twin according to the risk score includes: sequentially dividing the attack targets into core targets, important targets, and auxiliary targets according to the smelting process, and sequentially increasing the risk scores required for corresponding access control, and when the risk score is greater than a second threshold, immediately isolating the core targets, intensifying the identity verification for the important targets, and performing instruction auditing for the auxiliary targets.

[0037] The hierarchical smelting equipment can be classified according to the size of the impact on product quality, or classified in combination with the severity of safety hazards. Specifically, the on-site working conditions can be selected, for example, in the smelting process, the failure of the converter and its oxygen lance equipment will directly affect the product quality and is prone to cause serious harm to people or equipment, so it can be classified as core equipment. Similarly, the harm of the continuous casting machine is relatively small, and it can be classified as important equipment. For example, the smoke purification equipment does not directly affect the product quality, and the possibility of causing serious casualties in the control process is low, and it can be classified as auxiliary equipment.

[0038] The risk score required for access control increases in turn, that is, the risk scores required for core targets, important targets and auxiliary targets to start access control are different. For example, for core targets, when the risk score is 20 points, the access control is triggered to be strengthened, and for auxiliary targets, the risk score needs to reach 40 points to trigger the strengthening of access control. The second threshold is a higher risk score, which can be determined according to the working condition, and when the core target, the important target and the auxiliary target are in the same high risk, there will also be differences in access control. For core targets, operation safety needs to be strictly guaranteed, so access isolation is performed to completely block the damage of attack instructions. For important targets, identity verification is enhanced, such as requiring double authentication of operation permission level and dynamic token to access control, to reserve space for normal process operation. For auxiliary targets, instructions are recorded and audited, such as comparing with standard threshold to implement over-limit interception and reduce excessive intervention on process flow.

[0039] Based on the hierarchical adjustment of the smelting equipment, the granularity of access control can be improved, which is beneficial to balance safety and production.

[0040] In some optional embodiments, the risk score J = w1*P + w2*g*D + w3*G, wherein w1, w2, w3 are weight coefficients, and w1 + w2 + w3 = 1, g is a target coefficient, P is an attack success rate, D is an attack loss, and G is an attack concealment.

[0041] The attack success rate, attack damage and attack concealment can be normalized, and the weight of each can be set according to the working condition requirements. For example, when high destructive attacks are usually prioritized, the weight of attack damage can be set to 0.5. In addition, through the setting of the target coefficient, the risk assessment of the smelting production line can be more in line with the smelting production line. The attack damage of the core target can obtain additional weighting, such as the target coefficients of the core target, the important target and the auxiliary target can be set to 1.5, 1.2 and 1 respectively.

[0042] In some optional embodiments, in step S5, the reward function K = r1*D + r2*G - r3*T, wherein r1 ≥ 0.3, r2 ≥ 0.5, and r1 + r2 + r3 = 1, D is an attack loss, G is an attack concealment, and T is an attack cost.

[0043] By limiting the weight coefficient of the reward function, the optimization direction of the PPO algorithm can be constrained, so that the attack agent can iterate attack traffic mainly based on attack concealment, and then consider a certain attack damage, so as to facilitate the generation of slow and concealed attacks in the later stage, and realize implicit damage through damage accumulation, make up for the lack of current research on slow and concealed attacks, and facilitate the development of targeted defense measures.

[0044] In some optional embodiments, the iterative smelting production line defense based on the optimized attack traffic also includes: S63, constructing a defense agent, inputting the attack traffic and the risk score, outputting a repair strategy, injecting the repair strategy into the digital twin, and performing the attack traffic on the digital twin again to form an attack-defense iterative cycle.

[0045] The defense agent is used to convert the attack traffic (such as high-frequency attack paths and exploit methods) optimized by the attack agent into a proactive defense repair strategy, that is, the repair strategy is used to reduce the attack success rate of the attack traffic, such as targeted modification of firewall rules, authentication strategies, etc., thereby forming an attack-defense closed loop, and the proactive defense repair strategy is injected into the digital twin, and the corresponding attack traffic is restarted, which can detect the defense effect of the repair strategy, and further promote the attack agent to continuously optimize the attack traffic, forming an attack generation-defense iterative closed loop mechanism.

[0046] As shown in Figure 2 The defense agent and the admission control have a complementary relationship, which can meet the dual protection of real-time requirements (admission control) and systematic protection (defense agent) in industrial scenarios, that is, the admission control is used to intercept attacks in real time, and the defense agent is used to eliminate system vulnerabilities based on generated attack traffic to reduce the success rate of attack traffic, thereby forming a complete closed loop of attack simulation, risk assessment, real-time blocking, and long-term reinforcement.

[0047] In some optional embodiments, the input attack traffic and the risk score are used to output a repair strategy, which includes: outputting a repair strategy based on process continuity requirements and sensor redundancy mechanisms.

[0048] In the smelting field, the repair strategy for attack traffic needs to avoid interruptions in the smelting production line. For example, if the parameters of the furnace temperature sensor are tampered with, restarting the furnace temperature sensor directly may cause production interruptions due to the lack of key parameters of the furnace temperature in the automation system. Therefore, the repair strategy needs to reconstruct the true value through redundant sensors, and further limiting the action space of the repair strategy can better fit the defense system of the smelting production line and generate effective repair strategies to ensure smooth production.

[0049] The repair strategy generated by the defense agent through the attack traffic can enhance the resistance of the industrial network to the attack traffic, and reduce the system vulnerability. For example, if the attack traffic frequently uses a certain attack path, the corresponding ACL strategy can be automatically deployed in the controller based on the key nodes in the attack path to block the lateral movement. For example, for some attack instructions that can cause high damage, custom Snort rules can be embedded in the industrial firewall to detect specific types of malicious instructions. In addition, the network structure of the defense agent can be constructed according to the existing model.

[0050] Next, a security control device of an industrial network provided by an embodiment of the present application is described. The device described below can be referred to in correspondence with the method described above. Based on the above embodiment, Figure 3 is a structural schematic diagram of a security control device of an industrial network provided by the present embodiment.

[0051] As Figure 3 shown, a security control device of an industrial network includes: a twin module 10 for obtaining production line data to construct a digital twin of a smelting production line; a database module 20 for obtaining historical attack data, establishing an attack instruction-attack damage mapping table, and forming an attack database according to the ICS Matrix framework; an attack module 30 for constructing an attack agent based on a PPO algorithm and calling the attack database to output attack traffic. The attack agent receives simulation data of the digital twin in real time, obtains parameter limits and process sensitive periods of the attack target to determine the action space of the attack agent, and generates attack traffic under the constraint of the action space; a simulation module 40 for executing attack traffic on the digital twin to obtain attack success rate, attack damage, attack concealment, and attack cost of the attack traffic; an optimization module 50 for attack traffic with an attack success rate greater than a first threshold, calculating a reward function of the PPO algorithm according to the attack damage, attack concealment, and attack cost, and generating optimized attack traffic through the reward function; and a defense module 60 for iterating the defense system of the smelting production line based on the optimized attack traffic.

[0052] Based on the above method embodiment, please refer to Figure 4 , Figure 4 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. An electronic device 300 provided by an embodiment of the present application includes a processor 301 and a memory 302. The memory 302 stores machine-readable instructions executable by the processor 301. The machine-readable instructions are executed by the processor 301 to perform the method described above. The electronic device can be a physical device.

[0053] Based on the method embodiments, a computer readable storage medium is also provided, which stores a computer program. The computer program is executed by a processor to implement the steps of the method in any one of the above embodiments.

[0054] Those skilled in the art understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0055] The present application is described with reference to flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.

[0056] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.

[0057] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.

[0058] In a typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memories.

[0059] Memory can include non-persistent memory, Random Access Memory (RAM), and / or non-volatile memory such as read only memory (ROM) or flash memory, etc. in a computer readable medium. Memory is an example of computer readable media.

[0060] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer readable media does not include transitory media such as modulated data signals and carrier waves.

[0061] It should also be noted that the terms "comprising", "comprises", "including", "includes" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article or apparatus. Without limitation, an element preceded by "comprises a" does not, without more constraints, foreclose the existence of additional identical elements in the process, method, article or apparatus that includes the element.

[0062] Those skilled in the art will understand that embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product embodied in one or more computer-usable storage media (including, but not limited to, disk memory, CD-ROM, optical storage etc.) having computer usable program code contained therein.

[0063] The above merely provides an example of the present application and is not intended to limit the present application. The present application can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.

Claims

1. A security control method of an industrial network, characterized by, Comprise: S1, obtain the production line data to construct the digital twin of the smelting production line; S2, obtain historical attack data, establish an attack instruction-attack damage mapping table, and form an attack database according to the ICS Matrix framework; S3, construct an attack agent based on the PPO algorithm, call the attack database to output attack traffic, wherein the attack agent receives the simulation data of the digital twin in real time, obtains the parameter limit and process sensitive period of multiple attack targets on the smelting production line, forms the action space of the attack agent based on the constraint combination of the parameter limit and the process sensitive period, and generates attack traffic under the constraint of the action space; S4, execute the attack traffic on the digital twin to obtain the attack success rate, attack damage, attack concealment, and attack cost of the attack traffic; S5, for attack traffic with an attack success rate greater than a first threshold, calculate a reward function of the PPO algorithm according to the attack damage, attack concealment, and attack cost, and generate optimized attack traffic through the reward function; S6, based on the optimized attack traffic, iterate the defense system of the smelting production line.

2. The security control method of an industrial network according to claim 1, characterized by, Based on the optimized attack traffic, iterate the defense system of the smelting production line, comprising: S61, calculate a risk score according to the attack success rate, attack damage, and attack concealment of the attack traffic; S62, implement hierarchical access control on the attack targets of the digital twin according to the risk score, and optimize the access control based on the simulation data of the digital twin.

3. The security control method of an industrial network according to claim 2, characterized by, Implementing hierarchical access control on the attack targets of the digital twin according to the risk score comprises: According to the smelting process, the attack targets are sequentially divided into core targets, important targets, and auxiliary targets, and the risk scores required for corresponding access control are sequentially increased, and when the risk score is greater than a second threshold, the core targets are immediately isolated, the important targets are strengthened for identity verification, and the auxiliary targets are subjected to instruction auditing.

4. The security control method of an industrial network according to claim 3, characterized by, The risk score J = w1*P + w2*g*D + w3*G, wherein w1, w2, and w3 are weight coefficients, and w1 + w2 + w3 = 1, g is a target coefficient, P is the attack success rate, D is the attack loss, and G is the attack concealment.

5. The security control method of an industrial network according to claim 1, characterized by, In step S5, the reward function K = r1*D + r2*G - r3*T, wherein r1 ≥ 0.3, r2 ≥ 0.5, and r1 + r2 + r3 = 1, D is the attack loss, G is the attack concealment, and T is the attack cost.

6. The security control method of an industrial network according to any one of claims 2 to 5, characterized by, Based on the optimized attack traffic, iterate the defense system of the smelting production line, further comprising: S63, construct a defense agent, input the attack traffic and the risk score to output a repair strategy, inject the repair strategy into the digital twin, and execute the attack traffic on the digital twin again to form an attack-defense iteration cycle.

7. The security control method of an industrial network according to claim 6, wherein Inputting the attack traffic and the risk score to output the repair strategy comprises: outputting the repair strategy based on the process continuity requirement and the sensor redundancy mechanism.

8. A security control device of an industrial network, characterized by comprising: Comprise: A twin module for obtaining production line data to construct a digital twin of a smelting production line; A database module for obtaining historical attack data, establishing an attack instruction-attack damage mapping table, and forming an attack database according to the ICS Matrix framework; A twin module for obtaining production line data to construct a digital twin of a smelting production line; The attack module is configured to construct an attack agent based on the PPO algorithm, and to call an attack database to output attack traffic, wherein the attack agent is configured to receive simulation data of the digital twin in real time, to obtain parameter limits and process sensitive periods of a plurality of attack targets on the smelting production line, to form an action space of the attack agent based on a constraint combination of the parameter limits and the process sensitive periods, and to generate the attack traffic under the constraint of the action space; The simulation module is configured to execute the attack traffic on the digital twin to obtain an attack success rate, an attack damage, an attack concealment, and an attack cost of the attack traffic. The optimization module is configured to, for attack traffic with an attack success rate greater than a first threshold, calculate a reward function of the PPO algorithm according to the attack damage, the attack concealment, and the attack cost, and to generate optimized attack traffic through the reward function. The defense module is configured to iterate a defense system of the smelting production line based on the optimized attack traffic.

9. An electronic device, comprising: A processor coupled to the memory, the processor configured to execute a method according to any one of claims 1 to 7 based on instructions stored in the memory.

10. A computer-readable storage medium, characterized in that, A computer program stored thereon, the computer program being executed by a processor to implement a method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Moving target defense method and device based on reinforcement learning and storage medium

    CN115694904A

  • Industrial control system security threat response processing method based on digital twinning

    CN116545656A