Big data-based intelligent factory safety information management system
By constructing a digital twin model and dynamically optimizing defense strategies, the smart factory security information management system solves the problems of slow response and rigid strategies in traditional systems, and realizes real-time precise defense and adaptive management of smart factories.
Patent Information
- Application Number
- CN202511315906.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-09-16
AI Technical Summary
Traditional factory safety management systems struggle to detect new types of attacks in real time and lack dynamic adaptability, resulting in delayed defense responses that impact production safety and efficiency.
The smart factory safety information management system based on big data obtains factory characteristic information through the protocol analysis module, builds a digital twin model, and combines an attack scenario library and a defense strategy library to simulate attack and defense scenarios in real time and dynamically optimize defense strategies.
It enables real-time and accurate identification of attacks on smart factories, improves defense response speed and strategy adaptability, and ensures safe and stable production operation.
Smart Images

Figure CN120825340B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of factory safety management, in particular to a smart factory safety information management system based on big data. BACKGROUND
[0002] With the automation and informatization of production processes in smart factories through a large number of intelligent devices and industrial networks, the highly interconnected nature of industrial control systems faces increasingly complex security threats, from malicious instruction tampering, data theft to system paralysis and other attack incidents. Traditional factory safety management relies on manual experience and static defense strategies, which are difficult to cope with the dynamic changes of new attack methods, and a real-time sensing and intelligent decision-making safety information management system is needed to ensure production continuity and data security.
[0003] In the prior art, some factory safety management systems only detect and defend attacks based on a pre-set rule library, lack dynamic adaptability to complex attack scenarios, and are difficult to accurately identify zero-day vulnerability attacks. At the same time, most systems use static defense strategies and cannot optimize strategies according to actual production environments, device operating states and attack characteristics, which has obvious shortcomings in balancing safety protection and production efficiency, leading to problems such as over-protection affecting production or insufficient protection causing safety accidents when attacks occur. SUMMARY
[0004] The present application provides a smart factory safety information management system based on big data to solve the problems of defense response lag and poor dynamic adaptability of defense strategies in the prior art.
[0005] In order to achieve the above object, the embodiment of the present application provides a smart factory safety information management system based on big data, which comprises: a protocol analysis module, which is used to obtain interactive instructions between factory feature information and factory equipment, and analyze the interactive instructions to generate interactive data; a sandbox simulation module, which comprises a feature mirroring unit, a defense deployment unit and an attack deployment unit, the feature mirroring unit is used to generate a digital twin model of the factory according to the factory feature information; the attack deployment unit is configured with an attack scenario library, the attack scenario library stores a plurality of attack scenarios, each attack scenario comprises a plurality of attack response sequences, and the attack response sequence comprises a plurality of attack instructions; the defense deployment unit is configured with a defense response strategy library, the defense response strategy library stores a plurality of defense strategies, the defense deployment unit generates a defense clue according to the factory feature information, and configures the corresponding defense strategy from the defense response strategy library to the corresponding position according to the defense clue to generate a defense strategy group; an attack simulation module, which is used to determine attack instructions according to the interactive data generated by the protocol analysis module and the equipment operation data simulated by the digital twin model, and determine an attack scenario according to the determined attack instructions and the attack scenario library; a defense evaluation module, which is configured with a defense evaluation algorithm to evaluate the defense response deviation of each defense strategy; the defense strategies in the defense strategy library form an association relationship, each association relationship corresponds to an associated replacement data; a strategy correction module, which retrieves each defense strategy associated with the defense strategy to generate a plurality of defense update plans through the defense response deviation, calculates the response value of each defense update plan according to the replacement association data through a preset correction contention algorithm, and selects the defense update plan with the highest response value to update the corresponding defense strategy group.
[0006] Optionally, the factory feature information comprises the geometric structure, physical characteristics and operation data of the factory equipment, and the protocol analysis module comprises a three-dimensional laser scanning device and an embedded sensor arranged in the factory.
[0007] Optionally, the protocol analysis module is configured to: scan the factory equipment through the three-dimensional laser scanning device to obtain point cloud data and spatial position information of the factory equipment, and generate the geometric structure of the factory equipment; monitor the physical response data of the factory equipment through the embedded sensor to obtain the physical characteristics of the factory equipment; and analyze the industrial Internet of Things gateway data of the factory to extract real-time operation parameters of the factory equipment and obtain the operation data of the factory equipment.
[0008] Optionally, the feature mirroring unit is configured to: based on the factory feature information, call corresponding virtual deployment features from a preset virtual feature library, the virtual deployment features including device three-dimensional model parameters, physical property matrices and behavior logic scripts; embed the virtual deployment features into a pre-constructed reference communication model to generate the digital twin model; and optimize parameters of the digital twin model according to historical running data of the factory equipment.
[0009] Optionally, the defense deployment unit includes: a vulnerability point and sensitive node extraction unit configured to extract vulnerability points and sensitive nodes of the factory equipment according to the factory feature information; a potential attack path generation unit configured to associate and match the extracted vulnerability points and sensitive nodes with the attack scene to generate a potential attack path including an attack success rate and an influence range, and determine a high-risk path; and a defense clue generation unit configured to establish a mapping relationship between the determined high-risk path and basic actions in the defense response strategy library to generate a defense clue.
[0010] Optionally, the attack simulation module includes: an instruction information analysis unit configured to compare interaction data in a preset normal instruction library with the interaction data generated by the protocol analysis module to identify an abnormal operation sequence; and a physical state analysis unit configured to compare running parameters obtained by the protocol analysis module with device running data simulated after the digital twin model executes the interaction instruction to identify an abnormal deviation.
[0011] Optionally, the attack simulation module further includes: an attack scene judgment unit configured to, when the abnormal operation sequence and the abnormal deviation are identified, determine that an instruction corresponding to the instruction data is an attack instruction, and determine an attack scene corresponding to the attack instruction; and an influence range and severity evaluation unit configured to evaluate an influence range and severity caused by the attack according to attack targets and potential harm information included in the selected attack scene.
[0012] Optionally, the defense evaluation algorithm is configured to: for each defense strategy, simulate a device state parameter after defense execution by the digital twin model, the device state parameter including device running data, production process data and safety state data; compare the generated device state parameter with an actual device state parameter in multiple dimensions to generate a multi-dimensional deviation, the multi-dimensional deviation including a device parameter deviation, a process timing deviation and a risk control deviation; and perform standardization processing on the deviations in each dimension to generate a single-quantized defense response deviation value.
[0013] Optionally, the defense strategy associated with each defense strategy is retrieved by the defense response bias to generate several defense update plans, comprising: when there is a defense response bias value corresponding to the defense strategy exceeds a preset threshold, based on the association relationship formed between the defense strategies, retrieving the candidate defense strategies associated with the current defense strategy; for each of the candidate defense strategies, calculate the association strength value with the current defense strategy, and select the several defense strategies with the highest association strength; according to the selected defense strategies, several defense update plans are combined and generated.
[0014] Optionally, the modified contention algorithm is configured to: for each defense update plan, simulate the corresponding replacement association data through the digital twin model to obtain a multi-dimensional index reflecting the execution effect of the defense update plan; based on the multi-dimensional index and the preset ideal value, through a preset mapping rule, obtain the corresponding standardized score; the standardized score is weighted and aggregated to generate the response value of the defense update plan.
[0015] The safety information management system of the intelligent factory based on big data provided by the application obtains factory feature information and device interaction instructions in real time through a protocol analysis module, provides a comprehensive data basis for safety defense; a sandbox simulation module constructs a digital twin model and generates a defense strategy group and an attack scene library with the help of a feature mirror unit, a defense deployment unit and an attack deployment unit, realizes accurate simulation of the safety situation of the factory; the attack simulation module determines the attack instruction and judges the attack scene in combination with the interaction data and the device operation data; the defense evaluation module and the strategy correction module realize dynamic optimization of the defense strategy by quantifying the defense response bias, generating defense update plans and selecting the optimal scheme, the modules of the system cooperate with each other, form a complete closed loop from data collection, attack identification to defense optimization, effectively solve the problems of lagging response of traditional intelligent factory safety defense and static strategy configuration, and significantly improve the real-time performance, accuracy and self-adaptability of safety protection. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor. In the drawings:
[0017] Figure 1 is the framework diagram of the safety information management system of the intelligent factory based on big data provided by the embodiment of the present application;
[0018] Figure 2 is the feature information collection flowchart provided by the embodiment of the present application;
[0019] Figure 3 is a digital twin model construction flowchart provided by an embodiment of the present application;
[0020] Figure 4 is a defense clue generation flowchart provided by an embodiment of the present application;
[0021] Figure 5 is an attack scenario matching flowchart provided by an embodiment of the present application;
[0022] Figure 6 is a defense strategy effect evaluation flowchart provided by an embodiment of the present application;
[0023] Figure 7 is a defense update plan generation flowchart provided by an embodiment of the present application. DETAILED DESCRIPTION
[0024] The specific embodiments of the embodiments of the present application are described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the embodiments of the present application, and are not used to limit the embodiments of the present application.
[0025] It should be noted that the acquisition, transmission, storage, use, processing and the like of data in the technical solutions of the present application comply with the relevant provisions of national laws and regulations. In the embodiments of the present application, some industry existing solutions such as software, components, models and the like may be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility of the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0026] As described above, with the deep integration of industrial control systems and networks, the network attack means faced by smart factories is increasingly complex and concealed, and traditional security protection technologies are difficult to accurately identify new attacks in real time, and also cannot dynamically adapt to production scenarios to adjust defense strategies, resulting in a difficult balance between security protection and production efficiency. Therefore, it is extremely important to develop a more effective factory security information management system.
[0027] To solve this problem, the present application provides a smart factory security information management system based on big data, which collects factory equipment operation data and interaction instructions, constructs a digital twin model to simulate attack and defense scenarios, quickly identifies abnormal instructions to determine attack types, timely deploys defense strategies and dynamically optimizes the scheme according to the defense effect, forms a whole-process closed-loop management, effectively improves the defense response speed and strategy adaptive ability of the smart factory, and ensures the safe and stable operation of production.
[0028] The present application will be described in detail below. Figures 1-7 The present application is described in detail.
[0029] Figure 1Figure 1 is a framework diagram of a smart factory security information management system based on big data provided by an embodiment of the present application. Figure 1 As shown in Figure 1, the present embodiment provides a smart factory security information management system based on big data, which comprises: a protocol analysis module for acquiring interaction instructions between factory feature information and factory equipment and analyzing the interaction instructions to generate interaction data; a sandbox simulation module comprising a feature mirroring unit, a defense deployment unit and an attack deployment unit, the feature mirroring unit being configured to generate a digital twin model of the factory according to the factory feature information; the attack deployment unit being configured with an attack scenario library, the attack scenario library storing a plurality of attack scenarios, each attack scenario comprising a plurality of attack response sequences, the attack response sequence comprising a plurality of attack instructions; the defense deployment unit being configured with a defense response strategy library, the defense response strategy library storing a plurality of defense strategies, the defense deployment unit generating a defense clue according to the factory feature information and configuring a corresponding defense strategy from the defense response strategy library to a corresponding position to generate a defense strategy group according to the defense clue; an attack simulation module for determining attack instructions according to the interaction data generated by the protocol analysis module and the equipment operation data simulated by the digital twin model, and determining an attack scenario according to the determined attack instructions and the attack scenario library; a defense evaluation module configured with a defense evaluation algorithm to evaluate the defense response deviation of each defense strategy; the defense strategies in the defense strategy library being associated with each other, each association having an associated replacement data; a strategy correction module for retrieving each defense strategy associated with the defense strategy to generate a plurality of defense update plans through the defense response deviation, calculating the response value of each defense update plan according to the replacement association data through a preset correction contention algorithm, and selecting the defense update plan with the highest response value to update the corresponding defense strategy group.
[0030] The smart factory security information management system based on big data provided by the present embodiment realizes full-process closed-loop management of security defense through the cooperative operation of multiple modules. The protocol analysis module collects factory features and interaction data in real time to provide accurate basis for defense decision; the sandbox simulation module constructs a digital twin model, combines the attack scenario library and the defense strategy library, and simulates and generates a defense strategy group in advance; the attack simulation module identifies abnormal instructions and attack scenarios in a timely manner; the defense evaluation and strategy correction module continuously optimizes the defense strategy through quantitative deviation and dynamic update plan. The modules of the system work closely together to effectively solve the problems of response lag and strategy rigidity of traditional security systems, and significantly improve the timeliness, accuracy and self-adaptability of the security defense of the smart factory.
[0031] As shown in Figure 1, the present embodiment provides a smart factory security information management system based on big data, which comprises: a protocol analysis module for acquiring interaction instructions between factory feature information and factory equipment and analyzing the interaction instructions to generate interaction data; a sandbox simulation module comprising a feature mirroring unit, a defense deployment unit and an attack deployment unit, the feature mirroring unit being configured to generate a digital twin model of the factory according to the factory feature information; the attack deployment unit being configured with an attack scenario library, the attack scenario library storing a plurality of attack scenarios, each attack scenario comprising a plurality of attack response sequences, the attack response sequence comprising a plurality of attack instructions; the defense deployment unit being configured with a defense response strategy library, the defense response strategy library storing a plurality of defense strategies, the defense deployment unit generating a defense clue according to the factory feature information and configuring a corresponding defense strategy from the defense response strategy library to a corresponding position to generate a defense strategy group according to the defense clue; an attack simulation module for determining attack instructions according to the interaction data generated by the protocol analysis module and the equipment operation data simulated by the digital twin model, and determining an attack scenario according to the determined attack instructions and the attack scenario library; a defense evaluation module configured with a defense evaluation algorithm to evaluate the defense response deviation of each defense strategy; the defense strategies in the defense strategy library being associated with each other, each association having an associated replacement data; a strategy correction module for retrieving each defense strategy associated with the defense strategy to generate a plurality of defense update plans through the defense response deviation, calculating the response value of each defense update plan according to the replacement association data through a preset correction contention algorithm, and selecting the defense update plan with the highest response value to update the corresponding defense strategy group. Figure 2As shown, preferably, the factory feature information includes the geometric structure, physical characteristics and operating data of the factory equipment, and the protocol analysis module includes a three-dimensional laser scanning device and embedded sensors deployed in the factory.
[0032] More preferably, the protocol analysis module is configured to: scan the factory equipment using the 3D laser scanning device to obtain point cloud data and spatial location information of the factory equipment, and generate the geometric structure of the factory equipment; monitor the physical response data of the factory equipment using the embedded sensor to obtain the physical characteristics of the factory equipment; and extract the real-time operating parameters of the factory equipment by parsing the industrial IoT gateway data of the factory to obtain the operating data of the factory equipment.
[0033] In a preferred embodiment of the invention, the protocol analysis module acquires the geometric structure, physical characteristics, and operational data of factory equipment through multiple channels, including a 3D laser scanning device, embedded sensors, and an industrial IoT gateway. The 3D laser scanning device scans the factory equipment, acquiring point cloud data and spatial location information to generate precise geometric structure data, providing a foundation for equipment modeling and spatial layout analysis. Embedded sensors monitor the equipment's physical response data in real time, understanding its material properties and other physical characteristics. Data from the industrial IoT gateway is parsed to extract real-time operating parameters, including temperature and pressure. This combination of data acquisition methods comprehensively and accurately obtains multi-dimensional characteristic information of the factory equipment, providing reliable data support for subsequent construction of digital twin models, analysis of equipment vulnerabilities, and formulation of defense strategies. This effectively improves the data accuracy and completeness of the smart factory safety information management system, thereby enhancing the system's ability to perceive and respond to equipment safety risks.
[0034] like Figure 3 As shown, preferably, the feature mirroring unit is configured to: retrieve corresponding virtual deployment features from a preset virtual feature library based on the factory feature information, the virtual deployment features including equipment 3D model parameters, physical attribute matrix and behavioral logic script; embed the virtual deployment features into a pre-built benchmark communication model to generate the digital twin model; and optimize the parameters of the digital twin model according to the historical operating data of the factory equipment.
[0035] In the preferred embodiment of the present application, the feature mirroring unit first retrieves device three-dimensional model parameters, physical property matrices, and behavior logic scripts, etc. from the virtual feature library based on the geometric structure, physical characteristics, and operation data of the factory equipment, and then embeds these virtual features into the reference communication model to construct a digital twin model. Finally, the model parameters are optimized according to the historical operation data of the factory equipment. This technical solution has many advantages: first, by retrieving data from the virtual feature library, the factory equipment can be quickly digitized and modeled, greatly reducing the time and labor costs of manual modeling; second, the digital twin model can achieve 1:1 virtual mapping of the factory equipment operating state, which is convenient for simulating various attack scenarios in a virtual environment at low cost and high efficiency, discovering potential security risks in advance, and reflecting changes in device operation in real time to provide accurate data support for defense deployment and improve the dynamic response capability and risk prevention and control level of the intelligent factory security information management system.
[0036] As shown in Figure 4 Preferably, the defense deployment unit generates defense clues by extracting vulnerable points and sensitive nodes of the factory equipment according to the factory feature information, associating and matching the extracted vulnerable points and sensitive nodes with the attack scenarios to generate potential attack paths containing attack success rates and impact ranges, and determining high-risk paths, and establishing a mapping relationship between the determined high-risk paths and the basic actions in the defense response strategy library to generate defense clues.
[0037] In the preferred embodiment of the present application, the process of the defense deployment unit generating defense clues is described in detail. The advantages and technical effects of this scheme are outstanding: first, by accurately positioning vulnerable points and sensitive nodes, the security threats faced by the factory equipment can be identified specifically, avoiding blind deployment of defense resources; second, by determining high-risk paths based on attack success rates and impact ranges, the defense work can focus on threats that may cause significant losses, improving defense efficiency; third, by mapping high-risk paths with the defense strategy library, the automatic association of defense strategies is realized, which shortens the security response time, enhances the ability of the intelligent factory to resist attacks, and effectively safeguards the production safety of the factory. In addition, defense clues are the basis for generating defense strategy groups, and the automatic generation of defense strategy groups can greatly shorten the defense response cycle and reduce the risk of human error compared to manually developing strategies.
[0038] For example, in a certain smart factory, the protocol analysis module discovers through three-dimensional laser scanning that the stamping equipment has a fragile point of structural stress concentration, and the embedded sensor monitors sensitive nodes with data transmission delay in the control system communication interface. The defense deployment unit associates these information with the attack scenario library, determines that hackers may use the transmission delay vulnerability to implant malicious instructions, causing abnormal stamping of the equipment, and this attack path has high success rate, wide influence range, and is listed as a high-risk path. Subsequently, the system establishes a mapping relationship between the high-risk path and the basic actions in the defense response strategy library, generates defense clues containing specific measures such as "deploying real-time data encryption and abnormal traffic monitoring at the communication interface" and "increasing high-frequency structural detection at the stress concentration position of the equipment". Finally, according to the defense clues, the corresponding defense strategy is retrieved from the defense response strategy library, the data encryption and real-time monitoring program is deployed at the communication interface, the inspection scheme is formulated for the stress position of the equipment, and finally the complete defense strategy group is generated to effectively prevent potential attacks.
[0039] As shown in Figure 5 Preferably, the attack simulation module includes: an instruction information analysis unit that compares the interaction data in the preset normal instruction library according to the interaction data generated by the protocol analysis module to identify abnormal operation sequences; and a physical state analysis unit that compares the running parameters obtained by the protocol analysis module according to the equipment running data simulated after the interaction instructions are executed by the digital twin model to identify abnormal deviations.
[0040] Further preferably, the attack simulation module further includes an attack scenario judgment unit configured to: when abnormal operation sequences and abnormal deviations are identified, determine that the instruction data corresponding to the instructions are attack instructions, and determine the attack scene corresponding to the attack instructions; and according to the attack target and potential harm information contained in the selected attack scene, evaluate the influence range and severity caused by this attack.
[0041] In the preferred embodiment of the present application, the attack simulation module comprises an instruction information analysis unit, a physical state analysis unit, and an attack scene judgment unit. The abnormal operation sequence comprises a plurality of instruction data, the instruction information analysis unit compares the instruction data obtained by the protocol analysis module with the preset normal instruction mode library to identify the abnormal operation sequence; the physical state analysis unit finds out the abnormal deviation by comparing the device running parameters predicted by the digital twin model with the actually collected parameters; the attack scene judgment unit determines the attack instruction when detecting the abnormal operation sequence and the deviation, determines the attack scene according to the attack scene library, and evaluates the attack influence range and severity. This design verifies the attack behavior from two dimensions of instruction logic and device running state through the cooperation of multiple units, avoids the misjudgment risk of single-dimensional detection, can quickly and accurately locate the attack source and type, provides key data support for the formulation of subsequent defense strategies, greatly improves the detection accuracy and response efficiency of the system to the security threats of the smart factory, and effectively safeguards the safe and stable operation of the factory production.
[0042] For example, the mechanical arm of a production line in a smart factory is performing a material handling task, and the protocol analysis module collects the mechanical arm control instructions and running data and transmits them to the attack simulation module. The instruction information analysis unit finds that the data of a control instruction is different from the data in the normal instruction mode library, and an abnormal operation sequence occurs; at the same time, the physical state analysis unit compares the mechanical arm running trajectory predicted by the digital twin model with the actually collected trajectory data, and finds that the actual running angle of the mechanical arm deviates abnormally. At this time, the attack scene judgment unit determines that the instruction is an attack instruction, and matches it with the attack instruction sequence of "malicious tampering of device running parameters" in the attack scene library, determines that the current attack scene is "device parameter tampering attack", and further evaluates that this attack may cause the mechanical arm to collide with the device, resulting in production line downtime and device damage.
[0043] As shown in Figure 6 Preferably, the defense evaluation algorithm is configured to: for each defense strategy, simulate the device state parameters after defense execution through the digital twin model, the device state parameters comprising device running data, production process data, and safety state data; based on the generated device state parameters, compare with the actual device state parameters in multiple dimensions to generate multi-dimensional deviations, the multi-dimensional deviations comprising device parameter deviations, process timing deviations, and risk control deviations; and perform standardization processing on each dimension deviation to generate a single quantitative defense response deviation value.
[0044] Specifically, the standardization processing process can be represented as: first, calculate the weighted geometric mean value of each dimension deviation :
[0045] (1)
[0046] Subsequently, the standard deviation is calculated , which is used to measure the dispersion degree of each dimension deviation relative to the weighted average value:
[0047] (2)
[0048] Finally, the geometric mean value is combined with the standard deviation to generate the defense response deviation value D:
[0049] (3)
[0050] wherein, , , respectively represent the equipment parameter deviation, the process timing deviation, and the risk control deviation, and the corresponding weights are , , , and represent the adjustment coefficients.
[0051] In the preferred embodiment of the present application, the defense evaluation algorithm adopts an aggregation formula combining weighted geometric mean and standard deviation to realize the deep quantitative evaluation of the defense strategy. The algorithm first generates the equipment state parameters after the defense execution through the digital twin model, compares them with the actual parameters to obtain the multi-dimensional deviation values of the equipment parameters, process timing, risk control, etc.; then, the synergistic effect of each dimension deviation is calculated using the weighted geometric mean formula (1) to highlight the comprehensive effect between the deviations, and the dispersion degree of the deviations is measured using the standard deviation formula (2) to reflect the data fluctuation; finally, the two are combined through formula (3) to output a single quantitative defense response deviation value. This technical solution has obvious advantages: first, the weighted geometric mean avoids the weakening of extreme deviations by simple arithmetic mean, and accurately reflects the overall effectiveness of the defense strategy; second, the standard deviation introduces fluctuation analysis, which can identify unstable factors in the defense process, such as strategy vulnerabilities under intermittent abnormal attacks; third, the dynamic adjustment coefficient supports scenario-based customization, such as increasing the fluctuation weight in high-risk production links to enhance the evaluation relevance.
[0052] For example, taking the evaluation of the production line defense strategy of a smart factory as an example, the defense evaluation module uses the defense evaluation algorithm for quantitative analysis. After the digital twin model simulates the defense execution, the equipment parameter deviation = 0.15, the process timing deviation = 0.25, the risk control deviation = 3, and the weight distribution is = 0.4, = 0.3, = 0.3, and the adjustment coefficient = 0.7, =0.3. First, calculate the weighted geometric mean using equation (1). ≈0.21, then calculate the standard deviation using equation (2). ≈0.065, and finally, substituting into equation (3), we calculate the defense response deviation value D=0.1665.
[0053] like Figure 7 As shown, preferably, the step of retrieving the defense strategies associated with each defense strategy through the defense response deviation to generate several defense update plans includes: when the defense response deviation value corresponding to a defense strategy exceeds a preset threshold, retrieving candidate defense strategies that are associated with the current defense strategy based on the association relationship formed between the defense strategies; for each candidate defense strategy, calculating the association strength value with the current defense strategy, and selecting several defense strategies with the highest association strength; and combining the selected defense strategies to generate several defense update plans.
[0054] Specifically, the process of calculating the correlation strength value can be as follows: evaluate the matching degree between the candidate defense strategy and the current strategy from three dimensions: function, historical collaboration, and resource adaptation. Sum the scores of each dimension according to preset weights to obtain a correlation strength value between 0 and 1. The higher the value, the more suitable it is to combine with the current strategy to optimize the defense system.
[0055] In a preferred embodiment of the present invention, the generation process of the defense update plan is described in detail. When the defense response deviation value output by the defense evaluation algorithm exceeds a preset threshold, the system generates a defense update plan in three steps based on the correlation between defense strategies: First, it retrieves candidate defense strategies associated with the current strategy; second, it uses a correlation strength calculation model to evaluate the fit between each candidate strategy and the current strategy, and selects the strategy with the highest correlation strength; finally, it combines the selected strategies. This scheme has significant advantages: First, automated correction greatly shortens the strategy optimization cycle. For example, in network attack scenarios, the strategy adjustment time can be reduced from several hours of manual processing to minutes. Second, accurate correlation screening is based on historical data and algorithm evaluation of strategy correlation strength, avoiding blind replacement, improving the effectiveness of new strategies, and reducing the risk of strategy conflicts. Third, combined updates compensate for the limitations of a single strategy through multi-strategy collaboration. For example, combining access control and traffic monitoring strategies to deal with complex attacks significantly improves the overall resilience and adaptability of the smart factory security defense system.
[0056] For example, after a simulated network attack test, the defense evaluation module calculates that the response deviation value of the current defense strategy is 0.65, which exceeds the preset threshold (for example, 0.5). The system immediately retrieves 5 candidate defense strategies such as "traffic anomaly blocking", "key data encryption" and "intrusion behavior tracing" related to the current strategy from the defense response strategy library based on the correlation between defense strategies; then, the system evaluates from three dimensions of function, historical synergy and resource adaptation: analyzes the coincidence degree of each candidate defense strategy and the current strategy on the defense target, counts the success rate of jointly defending similar attacks in history, judges whether the demand for computing resources and network bandwidth conflicts when deployed, and weights the scores of each dimension according to the preset weight to obtain the correlation strength value of each candidate strategy. Filter out the "traffic anomaly blocking" and "key data encryption" strategies with the highest correlation strength; finally, combine these two strategies with the current strategy to generate a new defense update plan. After this plan is put into use, when the same type of attack is simulated again, the defense response deviation value drops to 0.2, successfully resisting the attack, which reflects the efficiency and accuracy of the scheme in quickly optimizing the defense strategy in practical application.
[0057] Preferably, the modified contention algorithm is configured to: for each defense update plan, simulate the corresponding replacement correlation data through the digital twin model to obtain a multi-dimensional index reflecting the execution effect of the defense update plan; based on the multi-dimensional index and the preset ideal value, obtain the corresponding standardized score through the preset mapping rule; aggregate the standardized scores by weighting to generate the response value of the defense update plan; select the defense update plan with the highest response value to update the corresponding defense strategy group.
[0058] Specifically, the multi-dimensional index can include attack interception rate, production efficiency, data leakage risk and the like. The mapping rule can be represented as: for positive indicators (such as attack interception rate, production efficiency): the ratio of the multi-dimensional index to the ideal value is taken as the original evaluation value, and if the result exceeds 1, it is taken as 1. For negative indicators (such as data leakage risk value): subtract the actual value of the multi-dimensional index after replacement from 1 to get the ratio of the ideal value, and the result is taken as the original evaluation value. Then, the original evaluation value is uniformly mapped to the 0-1 interval, and if the original evaluation value exceeds the range, the boundary value (1 for greater than 1 and 0 for less than 0) is taken, to obtain the standardized score; finally, the standardized score is adjusted to a reasonable range combined with the weight of each dimension to obtain the response value of the corresponding defense update plan.
[0059] In the preferred embodiment of the present application, a verification system for defense update plan is constructed, the execution effect of the defense update plan is simulated through the digital twin model, multi-dimensional indexes such as attack interception rate, production efficiency, data leakage risk, etc. are obtained, and they are compared with the preset ideal value, the original evaluation value is calculated according to the ratio of actual value to ideal value of positive index and the ratio of actual value to ideal value of negative index minus 1, and the original evaluation value is mapped to the interval of 0-1, and finally the response value of the defense update plan is generated based on the weight aggregation standardization score of each dimension, so as to accurately judge the effectiveness of the defense update plan, and ensure that only the plan meeting the preset standard can be put into actual deployment, effectively improving the scientificity and reliability of the safety defense strategy of the intelligent factory.
[0060] For example, in a certain intelligent factory, the system generates three defense update plans. For one of the defense update plans, the system simulates the plan through the digital twin model and obtains multi-dimensional indexes such as attack interception rate of 88% (ideal value is for example 95%), production efficiency of 92% (ideal value is for example 90%), data leakage risk value of 6 (ideal value is for example 5), etc. According to the mapping rule, the attack interception rate is a positive index, and the original evaluation value is 88% ÷ 95% ≈ 0.926; the production efficiency original evaluation value is 92% ÷ 90% ≈ 1.02, and 1 is taken as the standardization score; the data leakage risk value is a negative index, and the original evaluation value is 1-6 ÷ 5 = 0.8. Combined with the attack interception rate weight (for example, 0.5), the production efficiency weight (for example, 0.3), and the data leakage risk value weight (for example, 0.2), the final response value of the plan is 0.926 × 0.5 + 1 × 0.3 + 0.8 × 0.2 = 0.923. At the same time, the system calculates the response values of the other two defense update plans as 0.75 and 0.821 respectively, so the defense update plan is selected to update the corresponding defense strategy group.
[0061] The intelligent factory safety information management system based on big data provided by the present application acquires the characteristic information of the factory equipment, constructs a digital twin model to simulate attack scenarios and defense strategy execution effect, and simulates and generates defense strategy groups in advance, accurately identifies abnormal instructions and judges attack scenarios based on attack simulation, evaluates defense effect through multi-dimensional comparison after executing defense strategy, generates an update plan according to the strategy correlation relationship when the defense response deviation exceeds the threshold, selects the optimal scheme to update the defense strategy through simulation calculation of multi-dimensional indexes, standardization score and weighted aggregation response value. This scheme realizes the whole-process closed-loop management from data acquisition, risk prediction, defense implementation to strategy optimization, significantly improves the automation and intelligence level of intelligent factory safety protection, reduces safety risk, and ensures stable production operation.
[0062] It should be understood that, in the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. It should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0063] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in a general manner. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0064] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0065] Those skilled in the art can clearly understand the present application by the description of the above embodiments. The present application can be implemented in hardware, or in firmware, or in a combination thereof. When implemented in software, the functions can be stored in or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. Storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. Disk and disc, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray® disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0066] In conclusion, the above description is only the preferred embodiment of the technical scheme of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A smart factory safety information management system based on big data, characterized in that, The smart factory safety information management system includes: The protocol analysis module is used to acquire factory feature information and interaction instructions between factory equipment, and parse the interaction instructions to generate interaction data; The sandbox simulation module includes a feature mirroring unit, a defense deployment unit, and an attack deployment unit. The feature mirroring unit generates a digital twin model of the factory based on the factory's feature information. The attack deployment unit is configured with an attack scenario library, which stores several attack scenarios. Each attack scenario includes several attack response sequences, and each attack response sequence includes several attack instructions. The defense deployment unit is configured with a defense response strategy library, which stores several defense strategies. The defense deployment unit generates defense clues based on the factory's feature information and retrieves the corresponding defense strategies from the defense response strategy library based on the defense clues, configuring them in the corresponding positions to generate a defense strategy group. An attack simulation module is used to determine attack instructions based on the interaction data generated by the protocol analysis module and the device operation data simulated by the digital twin model, and to determine attack scenarios based on the determined attack instructions and the attack scenario library. The defense evaluation module is equipped with a defense evaluation algorithm to evaluate the defense response deviation of each defense strategy; the defense strategies in the defense strategy library are associated with each other, and each association corresponds to an associated replacement data. The strategy correction module retrieves the defense strategies associated with each defense strategy based on the defense response deviation to generate several defense update plans. It calculates the response value of each defense update plan based on the replacement associated data using a preset correction contention algorithm, and selects the defense update plan with the highest response value to update the corresponding defense strategy group.
2. The smart factory safety information management system according to claim 1, characterized in that, The factory feature information includes the geometric structure, physical characteristics and operating data of the factory equipment, and the protocol analysis module includes a 3D laser scanning device and embedded sensors deployed in the factory.
3. The smart factory safety information management system according to claim 2, characterized in that, The protocol analysis module is configured as follows: The factory equipment is scanned using the 3D laser scanning device to obtain point cloud data and spatial location information of the factory equipment, and to generate the geometric structure of the factory equipment. By using the embedded sensors to monitor the physical response data of the factory equipment, the physical characteristics of the factory equipment can be obtained. By analyzing the industrial IoT gateway data of the factory, the real-time operating parameters of the factory equipment can be extracted to obtain the operating data of the factory equipment.
4. The intelligent factory safety information management system according to claim 1, characterized in that, The feature mirror unit is configured as follows: Based on the factory feature information, the corresponding virtual deployment features are retrieved from the preset virtual feature library. The virtual deployment features include equipment 3D model parameters, physical attribute matrix and behavioral logic script. The virtual deployment features are embedded into a pre-built baseline communication model to generate the digital twin model; The parameters of the digital twin model are optimized based on historical operating data of the factory equipment.
5. The smart factory safety information management system according to claim 1, characterized in that, The defense deployment unit generates defense clues including: Based on the factory feature information, extract the vulnerability points and sensitive nodes of the factory equipment; The extracted vulnerabilities and sensitive nodes are matched with the attack scenarios to generate potential attack paths that include attack success rate and scope of impact, and high-risk paths are identified. Based on the identified high-risk paths, a mapping relationship is established with the basic actions in the defense response strategy library to generate defense clues.
6. The smart factory safety information management system according to claim 1, characterized in that, The attack simulation module includes: The instruction information analysis unit identifies abnormal operation sequences by comparing the interaction data generated by the protocol analysis module with the interaction data in the preset normal instruction library. The physical state analysis unit compares the simulated device operation data obtained by the protocol analysis module with the operating parameters obtained by the protocol analysis module based on the digital twin model after executing the interactive instructions to identify abnormal deviations.
7. The smart factory safety information management system according to claim 6, characterized in that, The attack simulation module further includes an attack scenario determination unit, which is configured to: When abnormal operation sequences and abnormal deviations are detected, the instruction corresponding to the instruction data is determined to be an attack instruction, and the attack scenario corresponding to the attack instruction is determined. Based on the attack targets and potential harm information contained in the selected attack scenario, assess the scope and severity of the impact of this attack.
8. The smart factory safety information management system according to claim 1, characterized in that, The defense evaluation algorithm is configured as follows: For each defense strategy, a digital twin model is used to simulate and generate equipment status parameters after the defense is executed. These equipment status parameters include equipment operation data, production process data, and safety status data. Based on the generated equipment status parameters, a multi-dimensional comparison is made with the actual equipment status parameters to generate multi-dimensional deviations, including equipment parameter deviations, process timing deviations, and risk control deviations. The deviations in each dimension are standardized to generate a single, quantified defense response deviation value.
9. The smart factory safety information management system according to claim 8, characterized in that, The process of retrieving the defense strategy associated with each defense strategy through defense response deviation to generate several defense update plans includes: When the defense response deviation value corresponding to a defense strategy exceeds a preset threshold, candidate defense strategies that are associated with the current defense strategy are retrieved based on the correlation between the defense strategies. For each candidate defense strategy, calculate the correlation strength value with the current defense strategy, and select the defense strategies with the highest correlation strength. Based on the selected defense strategies, several defense update plans are generated.
10. The smart factory safety information management system according to claim 1, characterized in that, The modified contention algorithm is configured as follows: For each defense update plan, the corresponding replacement data will be simulated using the digital twin model to obtain multi-dimensional indicators reflecting the effectiveness of the defense update plan. Based on the multidimensional indicators and preset ideal values, a corresponding standardized score is obtained through preset mapping rules; The standardized scores are weighted and aggregated to generate the response value of the defense update plan; Select the defense update plan with the highest response value and update the corresponding defense strategy group.
Citation Information
Patent Citations
Network attack and defense decision support method and system based on artificial intelligence
CN119155099A
Smart factory management method based on digital twinning
CN120215451A