A method for protecting industrial control network security
By identifying attack behaviors, calculating privilege scores, fixing vulnerabilities, and generating reports through firewall intrusion detection and security policy modules, the problem of network security risks in industrial control systems has been solved, enabling real-time monitoring and efficient updates.
Patent Information
- Application Number
- CN202511187248.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-25
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-08-25
AI Technical Summary
Limited existing industrial equipment and system resources make it difficult to deploy comprehensive security measures, and the lack of timely vulnerability patches and security updates increases the cybersecurity risks of industrial control systems.
The firewall intrusion detection module monitors and filters data traffic, identifies potential attack behaviors, and implements access control; it calculates user and device permission scores, collects network status data to trigger alarms, fixes security vulnerabilities, and generates security protection reports to improve the network security index.
It enables real-time monitoring and early warning of anomalies in industrial control networks, timely patching of vulnerabilities, improved network security and system update efficiency, and reduced security risks.
Smart Images

Figure CN120785645B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control network security protection technology, specifically to an industrial control network security protection method. Background Technology
[0002] One method for protecting industrial control network security is a set of security measures specifically designed for industrial control systems. These measures aim to reduce the network threats and risks faced by industrial control systems and ensure the secure operation of industrial control networks. By isolating the industrial control network from the enterprise IT network, this method can reduce the impact of network threats on the industrial control system. This prevents malware from spreading from the IT network to the industrial control network, reducing the risk of network attacks. At the same time, it implements strict access control policies to restrict access to the industrial control network, allowing only authorized users and devices to access critical systems and equipment, reducing the risk of security vulnerabilities. Furthermore, it regularly updates system and equipment patches to fix known vulnerabilities, reducing the opportunity for potential attackers to exploit vulnerabilities and improving system security.
[0003] Currently, some industrial equipment and systems have limited resources, making it difficult to deploy comprehensive security measures and lacking timely vulnerability patches and security updates, which increases the security risks of industrial control networks. Summary of the Invention
[0004] (a) Technical problems to be solved
[0005] To address the shortcomings of existing technologies, this invention provides a method for protecting the network security of industrial control systems. This method monitors and filters data traffic entering and leaving the industrial control network via a firewall intrusion detection module, and collects network traffic data. including source address Destination address ,port and agreement And calculate the frequency of the flow. With traffic source To identify potential attack behaviors, the security policy module manages and enforces access control policies on the industrial control network based on the identified potential attack behaviors, ensuring that only authorized users access sensitive data and resources, and calculating user access permission scores. and device access permission rating To implement access control, when a user's identity fails to pass access verification by the security policy module, the network anomaly alarm module collects real-time status data of network devices and calculates network performance indicators. and network anomaly indicators This triggers an alarm and sends abnormal network data to the security vulnerability repair module. Upon receiving abnormal network data, the security vulnerability repair module identifies and repairs security vulnerabilities in the industrial control network, and promptly manages and updates the system with patches. After the security vulnerabilities in the industrial control network are repaired, the security detection module detects the entire industrial network and calculates the security risk index. This method is used to determine the network security compliance of industrial control networks and generate industrial control network security protection reports, which are then sent to the factory control network monitoring screen. By monitoring industrial control network anomalies through the above methods, timely warnings are issued to fix network vulnerabilities and update the system, thereby improving the security index of industrial control networks and solving the aforementioned problems.
[0006] (II) Technical Solution
[0007] To achieve the above objectives, the present invention provides the following technical solution: a method for protecting industrial control network security, comprising the following steps:
[0008] S1. Monitor and filter data traffic entering and leaving the industrial control network through the firewall intrusion detection module, and collect network traffic data. including source address Destination address ,port and Agreement And calculate the frequency of the flow. Traffic source To identify potential attack behaviors;
[0009] S2. Based on the potential attack behaviors identified in S1, manage and enforce access control policies for the industrial control network through the security policy module to ensure that only authorized users can access sensitive data and resources, and calculate user access permission scores. and device access permission rating To implement access control;
[0010] S3. When a user's identity fails to pass access verification by the security policy module, the network anomaly alarm module collects real-time status data of network devices, including the number of connections. Bandwidth utilization as well as Utilization And calculate network performance metrics and network anomaly indicators This triggers an alarm and sends abnormal network data to the security vulnerability remediation module;
[0011] S4. Upon receiving abnormal network data, the security vulnerability remediation module identifies and remediates security vulnerabilities in the industrial control network, promptly manages and updates patches to the system, and calculates the priority of vulnerability remediation. ;
[0012] S5. After the security vulnerabilities of the industrial control network are patched, the security detection module will detect the entire industrial network and calculate the security risk index. This is used to determine the compliance status of industrial control network security and generate an industrial control network security protection report, which is then sent to the factory control network monitoring screen.
[0013] Preferably, the S1 firewall intrusion detection module uses pre-defined attack detection rules to match and analyze traffic, identifying corresponding attack behaviors, including... attack, Injection and malware propagation.
[0014] Preferably, step S1 involves the firewall intrusion detection module calculating the traffic frequency based on the collected data. The calculation formula is as follows:
[0015]
[0016] In the formula, Indicates the frequency of flow. This indicates the number of data points in a time series. Indicates the first Traffic volume values at a given time point Indicates the first The time interval between each time point and the previous time point is obtained through system monitoring.
[0017] Preferably, step S1 calculates the traffic source based on the collected data by the firewall intrusion detection module. The calculation formula is as follows:
[0018]
[0019] In the formula, Indicates the source of traffic. Indicates the first Potential threat rating from each source. Indicates the first Data volume from various sources Indicates the first Transmission time from each source, Indicates the first The formula for the transmission frequency of each source takes into account factors such as threat score, data volume, transmission time and transmission frequency of each source to measure the complexity of different traffic sources. A higher traffic source value indicates that the source has a higher potential threat and a more complex transmission pattern.
[0020] Preferably, a user access permission score is calculated based on the potential attack behaviors identified in S1. The calculation formula is as follows:
[0021]
[0022] In the formula, This indicates the user's access permission rating. Indicates the quantity of each factor. Indicates the first The weights of each factor Indicates the first The system sets the scores for each factor, with the weights and scores defined above. In this formula, each factor is assigned a weight based on its importance, and the weights are multiplied by the corresponding scores and then summed. This comprehensive consideration of the impact of multiple factors on user access permissions yields the final access permission score. This score helps determine the user's access permission level in the system and, based on the score results, determines the resources and operations that the user can access.
[0023] Preferably, a device access permission score is calculated based on the potential attack behaviors identified in S1. The calculation formula is as follows:
[0024]
[0025] In the formula, This indicates a device access permission score. Indicates the number of factors involved in the overall analysis. Indicates the first The weight of each equipment control factor Indicates the first The score for each device control factor is set by the system. This formula multiplies the weight and score of each factor, sums them, and then divides by the sum of all weights to obtain the device access permission score. This method comprehensively considers the impact of different factors on device access permissions, determines the contribution of each factor to the final access permission score according to different weights, and determines the access permission level of the device based on the score, which helps to control access and manage security of devices.
[0026] Preferably, the S3 computes network performance metrics The calculation formula is as follows:
[0027]
[0028] In the formula, Indicates network performance metrics, Indicates network transmission rate. This indicates network bandwidth.
[0029] Preferably, the S3 calculates network anomaly indicators. The calculation formula is as follows:
[0030]
[0031] In the formula, Indicates network anomaly indicators. Indicates a normal network indicator. This represents the average value of network normality indicators. The standard deviation of the indicator is represented by the standard deviation of the indicator. The weights of network anomaly indicators are set by the system. The value of a network anomaly indicator is obtained by calculating the standardized difference between each network indicator and its average value, multiplying it by the corresponding weight, and then conducting a comprehensive evaluation.
[0032] Preferably, the priority of S4 computing vulnerability repair The calculation formula is as follows:
[0033]
[0034] In the formula, Indicates the priority of vulnerability remediation. Indicates the severity of the vulnerability. Indicates the difficulty of exploiting the vulnerability. Indicates the importance of the affected system. The values indicate the difficulty of fixing the vulnerability; these values are obtained from the vulnerability scoring table set in the system settings.
[0035] Preferably, S5 calculates the security risk index. The formula is shown below:
[0036]
[0037] In the formula, Indicates the safety risk index. Indicates the number of vulnerabilities. Indicates the severity of the vulnerability. Indicates the vulnerability remediation rate. This indicates the performance of the vulnerability tool.
[0038] Compared with existing technologies, the present invention provides a method for protecting industrial control network security, which has the following beneficial effects:
[0039] This invention monitors and filters data traffic entering and leaving the industrial control network through a firewall intrusion detection module, and collects network traffic data. including source address Destination address ,port and Agreement And calculate the frequency of the flow. Traffic source To identify potential attack behaviors, the security policy module manages and enforces access control policies on the industrial control network based on the identified potential attack behaviors, ensuring that only authorized users access sensitive data and resources, and calculating user access permission scores. and device access permission rating To implement access control, when a user's identity fails to pass access verification by the security policy module, the network anomaly alarm module collects real-time status data of network devices and calculates network performance indicators. and network anomaly indicators This triggers an alarm and sends abnormal network data to the security vulnerability repair module. Upon receiving abnormal network data, the security vulnerability repair module identifies and repairs security vulnerabilities in the industrial control network, and promptly manages and updates the system with patches. After the security vulnerabilities in the industrial control network are repaired, the security detection module detects the entire industrial network and calculates the security risk index. This method is used to determine the network security compliance of industrial control networks and generate industrial control network security protection reports, which are then sent to the factory control network monitoring screen. By monitoring industrial control network anomalies through the above methods, timely warnings are issued to fix network vulnerabilities and update the system, thereby improving the security index of industrial control networks. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the method steps of the present invention. Detailed Implementation
[0041] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0042] To address the issue that limited resources in some industrial equipment and systems make it difficult to deploy comprehensive security measures, and the lack of timely vulnerability patches and security updates increases the security risks of industrial control networks, this paper proposes a network security protection method for industrial control networks. Please refer to [link / reference]. Figure 1 The method includes the following steps:
[0043] S1. Monitor and filter data traffic entering and leaving the industrial control network through the firewall intrusion detection module, and collect network traffic data. including source address Destination address ,port and agreement And calculate the frequency of the flow. With traffic source To identify potential attack behaviors;
[0044] The firewall intrusion detection module uses pre-configured attack detection rules to match and analyze traffic, identifying corresponding attack behaviors, including... attack, Injection and malware propagation, the frequency of traffic is calculated using the following formula:
[0045]
[0046] By calculating the frequency of traffic, network data traffic can be monitored in real time. Real-time monitoring helps to promptly detect abnormal traffic patterns, such as network attacks and sudden surges in traffic, thereby improving network security. In the formula... Indicates the frequency of flow. This represents the number of data points in a time series. Indicates the first Traffic volume values at a given time point Indicates the first The time interval between each point in time and the previous point in time, as mentioned above, is obtained through system monitoring. By calculating the traffic frequency, traffic analysis and security auditing can be performed. By analyzing traffic data, potential security threats and abnormal behaviors can be identified, security incidents can be detected and responded to in a timely manner, and network security can be improved.
[0047] The formula for calculating traffic sources is as follows:
[0048]
[0049] By calculating traffic sources, potential sources of malicious traffic, such as malware and cyberattacks, can be identified in a timely manner, helping businesses take early security measures to ensure network security. The formula includes... Indicates the source of traffic. Indicates the first Potential threat rating from each source. Indicates the first Data volume from various sources Indicates the first Transmission time from each source, Indicates the first The formula takes into account factors such as threat score, data volume, transmission time and transmission frequency of each source to measure the complexity of different traffic sources. A higher traffic source value indicates that the source has a higher potential threat and a more complex transmission pattern.
[0050] S2. Based on the potential attack behaviors identified in S1, manage and enforce access control policies for the industrial control network through the security policy module to ensure that only authorized users can access sensitive data and resources, and calculate user access permission scores. and device access permission rating To implement access control;
[0051] The formula for calculating user access permission scores is as follows:
[0052]
[0053] By scoring user access permissions, more precise control over user access to system resources can be achieved. Based on the scoring results, access to sensitive data and critical systems can be restricted, reducing security risks and preventing unauthorized access and data leaks. The formula... This indicates the user's access permission rating. Indicates the quantity of each factor. Indicates the first The weights of each factor Indicates the first The scores for each factor are determined by the system. The weights and scores mentioned above are set by the system. In this formula, each factor is assigned a weight according to its importance and is multiplied by the corresponding score and then summed. This comprehensive consideration of the impact of multiple factors on user access rights yields the final access rights score. This score is used to help determine the user's access rights level in the system and to determine the resources and operations that the user can access based on the score results.
[0054] The formula for calculating device access permission scores is as follows:
[0055]
[0056] Device access permission scoring can be used to calculate scores based on device characteristics, security status, usage, and other information, enabling more accurate and personalized device access management. This helps reduce the risk of erroneous operations and device abuse, and protects system resources and data security. (The formula is missing from the original text.) This indicates a device access permission score. Indicates the number of factors involved in the overall analysis. Indicates the first The weight of each equipment control factor Indicates the first The score for each device control factor is set by the system. This formula multiplies the weight and score of each factor, sums them, and then divides by the sum of all weights to obtain the device access permission score. This method comprehensively considers the impact of different factors on device access permissions, determines the contribution of each factor to the final access permission score according to different weights, and determines the access permission level of the device based on the score, which helps to control access and manage security of the device.
[0057] S3. When a user's identity fails to pass access verification by the security policy module, the network anomaly alarm module collects real-time status data of network devices, including the number of connections. Bandwidth utilization as well as Utilization And calculate network performance metrics and network anomaly indicators This triggers an alarm and sends abnormal network data to the security vulnerability remediation module;
[0058] The formulas for calculating network performance metrics are as follows:
[0059]
[0060] By calculating network performance metrics, network performance can be monitored and evaluated in real time. System administrators can use these metrics to understand the network's operational status, promptly identify and resolve potential problems, and ensure the network operates normally and provides good service. In the formula... Indicates network performance metrics, Indicates network transmission rate. This indicates network bandwidth. Calculating network performance metrics can help with capacity planning and expansion. After analyzing metrics such as network load and data traffic, administrators can predict future needs, rationally plan network capacity and expansion schemes, and avoid network congestion and performance degradation.
[0061] The formula for calculating network anomaly indicators is as follows:
[0062]
[0063] By calculating network anomaly indicators, network problems can be predicted and managed in advance, reducing maintenance costs and troubleshooting time, and improving operational efficiency. The formula includes... Indicates network anomaly indicators. Indicates a normal network indicator. This represents the average value of network normality indicators. The standard deviation of the indicator is represented by the standard deviation of the indicator. The weights of network anomaly indicators are set by the system. The value of the network anomaly indicator is obtained by calculating the standardized difference between each network indicator and its average value, multiplying it by the corresponding weight, and then conducting a comprehensive evaluation.
[0064] S4. Upon receiving abnormal network data, the security vulnerability remediation module identifies and remediates security vulnerabilities in the industrial control network, promptly manages and updates patches to the system, and calculates the priority of vulnerability remediation. ;
[0065] The priority calculation formula for vulnerability remediation is as follows:
[0066]
[0067] Prioritizing high-priority vulnerabilities can improve the efficiency and speed of vulnerability remediation, reduce attack windows, and lower the likelihood of being attacked. (The formula...) Indicates the priority of vulnerability remediation. Indicates the severity of the vulnerability. Indicates the difficulty of exploiting the vulnerability. Indicates the importance of the affected system. The values indicate the difficulty of remediation. These values are obtained through the vulnerability scoring table set in the system. By determining the priority of vulnerability remediation, organizations and teams can more clearly understand which vulnerabilities are the most urgent and require the most attention, thereby improving security awareness and the level of importance attached to them.
[0068] S5. After the security vulnerabilities of the industrial control network are patched, the security detection module will detect the entire industrial network and calculate the security risk index. Used to determine the compliance status of industrial control network security and generate an industrial control network security protection report, which is then sent to the factory control network monitoring screen.
[0069] The formula for calculating the safety risk index is as follows:
[0070]
[0071] By calculating a security risk index, security risks can be quantified into numbers, facilitating the comparison and analysis of the risk levels of different security incidents or systems. This helps decision-makers better understand and manage security risks. The formula includes... Indicates the safety risk index. Indicates the number of vulnerabilities. Indicates the severity of the vulnerability. Indicates the vulnerability remediation rate. The performance of vulnerability tools and the security risk index can serve as a reference for decision-making, helping organizations to formulate security strategies and measures, optimize resource allocation, and improve the overall security level.
[0072] When the safety risk index A score greater than or equal to 80 indicates that the industrial control network security meets the standards. When the security risk index is... When the value is below 80, repeat steps S1-S5 until the risk to the system has been addressed and repaired.
[0073] By using the above methods, anomalies in the industrial control network can be monitored, and network vulnerabilities can be repaired and the system updated in a timely manner, thereby improving the security index of the industrial control network.
[0074] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for protecting industrial control network security, characterized in that: Includes the following steps: S1. Monitor and filter data traffic entering and leaving the industrial control network through the firewall intrusion detection module, and collect network traffic data. including source address Destination address ,port and Agreement And calculate the frequency of the flow. Traffic source To identify potential attack behaviors; S1 calculates the source of the traffic based on the collected data from the firewall intrusion detection module. The calculation formula is as follows: In the formula, Indicates the source of traffic. Indicates the first Potential threat rating from each source. Indicates the first Data volume from various sources Indicates the first Transmission time from each source, Indicates the first The formula takes into account the threat score, data volume, transmission time and transmission frequency of each source to measure the complexity of different traffic sources. A higher traffic source value indicates that the source has a higher potential threat and a more complex transmission pattern. S2. Based on the potential attack behaviors identified in S1, manage and enforce access control policies for the industrial control network through the security policy module to ensure that only authorized users can access sensitive data and resources, and calculate user access permission scores. and device access permission rating To implement access control; S3. When a user's identity fails to pass access verification by the security policy module, the network anomaly alarm module collects real-time status data of network devices, including the number of connections. Bandwidth utilization as well as Utilization And calculate network performance metrics and network anomaly indicators This triggers an alarm and sends abnormal network data to the security vulnerability remediation module; S4. Upon receiving abnormal network data, the security vulnerability remediation module identifies and remediates security vulnerabilities in the industrial control network, promptly manages and updates patches to the system, and calculates the priority of vulnerability remediation. ; S5. After the security vulnerabilities of the industrial control network are patched, the security detection module will detect the entire industrial network and calculate the security risk index. This is used to determine the compliance status of industrial control network security and generate an industrial control network security protection report, which is then sent to the factory control network monitoring screen.
2. The industrial control network security protection method according to claim 1, characterized in that: The S1 firewall intrusion detection module uses pre-defined attack detection rules to match and analyze traffic, identifying corresponding attack behaviors, including... attack, Injection and malware propagation.
3. The industrial control network security protection method according to claim 1, characterized in that: S1 calculates the traffic frequency based on the collected data from the firewall intrusion detection module. The calculation formula is as follows: In the formula, Indicates the frequency of flow. This indicates the number of data points in a time series. Indicates the first Traffic volume values at a given time point Indicates the first The time interval between each time point and the previous time point is obtained through system monitoring.
4. The industrial control network security protection method according to claim 1, characterized in that: Based on the potential attack behaviors identified in S1, a user access permission score is calculated. The calculation formula is as follows: In the formula, This indicates the user's access permission rating. Indicates the quantity of each factor. Indicates the first The weights of each factor Indicates the first The system sets the scores for each factor, with the weights and scores defined above. In this formula, each factor is assigned a weight based on its importance, and the weights are multiplied by the corresponding scores and then summed. This comprehensive consideration of the impact of multiple factors on user access permissions yields the final access permission score. This score helps determine the user's access permission level in the system and, based on the score results, determines the resources and operations that the user can access.
5. The industrial control network security protection method according to claim 4, characterized in that: Based on the potential attack behaviors identified in S1, a device access permission score is calculated. The calculation formula is as follows: In the formula, This indicates a device access permission score. Indicates the number of factors involved in the overall analysis. Indicates the first The weight of each equipment control factor Indicates the first The score for each device control factor is set by the system. This formula multiplies the weight and score of each factor, sums them, and then divides by the sum of all weights to obtain the device access permission score. This method comprehensively considers the impact of different factors on device access permissions, determines the contribution of each factor to the final access permission score according to different weights, and determines the access permission level of the device based on the score, which helps to control access and manage security of devices.
6. The industrial control network security protection method according to claim 5, characterized in that: The S3 computing network performance metrics The calculation formula is as follows: In the formula, Indicates network performance metrics, Indicates network transmission rate. This indicates network bandwidth.
7. The industrial control network security protection method according to claim 6, characterized in that: The S3 calculates network anomaly indicators. The calculation formula is as follows: In the formula, Indicates network anomaly indicators. Indicates a normal network indicator. This represents the average value of network normality indicators. The standard deviation of the indicator is represented by the standard deviation of the indicator. The weights of network anomaly indicators are set by the system. The value of a network anomaly indicator is obtained by calculating the standardized difference between each network indicator and its average value, multiplying it by the corresponding weight, and then conducting a comprehensive evaluation.
8. The industrial control network security protection method according to claim 7, characterized in that: The priority of S4 computing vulnerability remediation The calculation formula is as follows: In the formula, Indicates the priority of vulnerability remediation. Indicates the severity of the vulnerability. Indicates the difficulty of exploiting the vulnerability. Indicates the importance of the affected system. The values indicate the difficulty of fixing the vulnerability; these values are obtained from the vulnerability scoring table set in the system settings.
9. The industrial control network security protection method according to claim 8, characterized in that: The S5 calculates the security risk index. The formula is shown below: In the formula, Indicates the safety risk index. Indicates the number of vulnerabilities. Indicates the severity of the vulnerability. Indicates the vulnerability remediation rate. This indicates the performance of the vulnerability tool.
Citation Information
Patent Citations
Industrial control network security protection monitoring system
CN109474607A
Network attack and security vulnerability management framework platform based on big data analysis
CN116996286A