Construction method and device for dynamic attack and defense test environment of industrial control system
By using logic self-learning and AI agent mechanisms, a dynamic attack and defense test environment for industrial control systems is constructed, which solves the problems of long construction cycle, low simulation accuracy and weak dynamic response capability of traditional industrial control test environments. It realizes high-fidelity simulation and intelligent security drills, and improves the efficiency of security assessment and attack and defense verification of industrial control systems.
Patent Information
- Application Number
- CN202511059992.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-11-04
AI Technical Summary
Existing industrial control testing environments rely on physical equipment, have long construction cycles, low resource scheduling efficiency, lack accurate simulation of industrial control logic and processes, have insufficient simulation accuracy and dynamic response capabilities, and rely on manual setting for attack and defense simulation processes, making it impossible to achieve automated and intelligent evaluation.
By employing logic-based self-learning hardware system simulation technology, a virtual industrial control firmware model is constructed. A meta-aggregated data resource pool and an AI agent mechanism are introduced. Combined with causal reasoning and a numerical-model fusion model, intelligent scheduling and automated deployment of industrial control component resources are achieved. Spatiotemporal driving and data synchronization are supported, enabling automatic deduction of attack paths and adaptive optimization of defense strategies.
It improves the automation and simulation accuracy of security testing for industrial control systems, shortens the construction cycle, enhances dynamic response capabilities, and is suitable for dynamic attack and defense simulations and security capability training in complex industrial network environments.
Smart Images

Figure CN120893035A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial control system security testing, and in particular to a method and device for constructing an industrial control system dynamic attack and defense testing environment. BACKGROUND
[0002] The statements in this section merely provide background information related to the present application and do not necessarily constitute prior art.
[0003] With the rapid development of industrial internet and intelligent manufacturing, industrial control systems are gradually evolving towards digitization, networking and automation. However, the design of industrial control systems originally focuses on functionality and usability, and there are many deficiencies in security design, which makes them easy targets for cyber attacks. Attack events targeting industrial control systems occur frequently, such as ransomware intrusion, PLC hijacking, and industrial protocol vulnerability exploitation, which have become real threats. Therefore, the demand for network security capability building and attack and defense drills for industrial control systems is rising.
[0004] Existing industrial control security testing environments are mostly built on physical devices, which are diverse, costly to purchase, difficult to maintain and expand, and cannot meet the needs of dynamic drills and rapid iteration. Although some environments have introduced virtualization simulation methods, they lack high-fidelity simulation capabilities for industrial firmware, process flow and control logic, and are difficult to realistically reproduce complex industrial control scenarios. In addition, the simulation of attack paths and response strategy evaluation in current target range systems still mainly relies on manual design, lacks intelligent deduction and evaluation mechanisms, and is difficult to adapt to the drill needs of complex attack scenarios such as advanced persistent threats (APT).
[0005] In the actual construction process, the following technical problems exist: 1. The existing industrial control testing range has high dependence on hardware devices and firmware, low resource scheduling efficiency, and long construction period; 2. Lack of precise simulation mechanism for industrial control logic and process, insufficient simulation accuracy and dynamic response capability; 3. Attack and defense deduction process relies on manual path setting, making it difficult to achieve automated attack chain construction and intelligent defense strategy evaluation; 4. The current system has weak integration capabilities for AI intelligent agents and cannot complete complex and variable dynamic attack and defense training tasks. SUMMARY
[0006] In order to solve the technical problems of long construction period, low simulation accuracy, insufficient automation, weak dynamic response and the like of the existing industrial control test environment, the application provides a construction method and device of an industrial control system dynamic attack and defense test environment, and the application realizes virtual operation and behavior modeling of industrial control firmware through a hardware system simulation technology based on logical self-learning; a meta-aggregated data resource pool is constructed to realize intelligent scheduling and automatic deployment of industrial control component resources; when an abnormal behavior of an industrial equipment is detected, a deviation behavior data is completed based on a causal relationship reasoning mechanism and a simulation model is driven to adjust; a digital-analog fusion model supporting space-time driving and data synchronization is constructed to realize data consistency and linkage between a virtual environment and a real environment; an AI agent mechanism is introduced to automatically deduce an attack path, optimize a defense strategy and complete intelligent evaluation of a drill process; an interactive user interface is introduced to configure and control an attack and defense scene, and simulation and verification operations in a complex dynamic attack and defense environment are realized. High-fidelity simulation and intelligent safety drill of the industrial control system are realized, and the efficiency and intelligent level of safety evaluation and attack and defense verification of the industrial control system are improved.
[0007] In order to achieve the above-mentioned purpose, the application adopts the following technical solutions: The first aspect of the application provides a construction method of an industrial control system dynamic attack and defense test environment.
[0008] The construction method of the industrial control system dynamic attack and defense test environment comprises the following steps: System state modeling is performed on a key control hardware module, instruction sets, protocol behaviors and running logic are collected, and a dynamic simulation component is constructed; system states, instruction behaviors and protocol interaction processes of industrial firmware are separately modeled; a simulation platform is constructed based on a logical self-learning mechanism; Configuration information, firmware data and running states of various industrial control components are collected to construct a meta-aggregated data resource pool; An industrial equipment behavior data completion system based on a causal relationship reasoning mechanism is constructed; Time driving and event driving mechanisms are combined to set a data refreshing period and a triggering condition to synchronize physical equipment data to the simulation platform; running states of the physical equipment are mapped to logical variables in the simulation platform to drive state transition and response processes of the control logic, so as to construct a digital-analog fusion model supporting space-time driving and data synchronization; An AI agent mechanism module is introduced to automatically deduce an attack path, adaptively adjust a defense strategy and intelligently evaluate a drill effect; An industrial control target range management system for starting, stopping, resource monitoring and log recording operations of each module of the simulation platform is configured; A user interactive interface is configured.
[0009] Further, the meta-aggregated data resource pool includes hardware resource information, firmware version information, running state data and configuration parameters of various industrial control components, the hardware resource information including controllers, sensors, actuators and network communication modules; the meta-aggregated data resource pool realizes real-time collection, storage and management of industrial control component resources through a unified interface, supports dynamic updating and efficient calling of resources. Ensure that the industrial control component resources in the test environment are highly consistent with the real production environment, and improve the authenticity and effectiveness of the test environment.
[0010] Further, the causal relationship reasoning mechanism is to establish an industrial process knowledge base, which covers device operation rules, process flow and abnormal behavior patterns; use a graph model or a causal network to perform multi-dimensional analysis on industrial device behavior data to identify the root cause of behavior deviation; based on known device behavior rules and abnormal patterns, complete and correct the detected deviation behavior data. Thus, the accuracy and completeness of the simulation model are improved; and the knowledge base content is dynamically updated to adapt to changes in the industrial control system operating environment and new attack methods; further, the causal relationship reasoning result drives the adjustment of the simulation model to achieve high-fidelity simulation of industrial device behavior and real-time abnormal response.
[0011] Further, the digital-analog fusion model includes a space-time driving module and a data synchronization module, the space-time driving module being used to establish a mapping relationship between physical entities and simulation models based on device running time sequence and spatial deployment relationship, and drive the simulation process to dynamically evolve according to the predetermined process flow; the data synchronization module is used to interface real-time running data from the physical industrial control system, and to perform bidirectional alignment and comparison with simulation data in the virtual model. Ensure the data consistency and state synchronization between virtual and real, thereby enhancing the real-time response capability and simulation accuracy of the simulation system to the changes in device behavior, and improving the effectiveness of abnormal behavior identification and response in dynamic attack and defense testing.
[0012] Further, the AI agent mechanism module includes an attack deduction module, a defense optimization module and a drill evaluation module; the attack deduction module automatically generates a multi-path attack chain based on known vulnerability information, topology structure and system behavior pattern, using a path search algorithm and a simulated adversarial model; the defense optimization module dynamically adjusts security policies and resource configurations according to the AI model deduction result, to realize adaptive optimization of security protection schemes; the drill evaluation module collects and analyzes key indicators in the attack and defense interaction process, evaluates attack effectiveness, defense effectiveness and response timeliness, and based on the evaluation result, reversely trains and continuously optimizes the AI model. Thus, intelligent closed-loop management of complex attack and defense behaviors in the target range environment is realized.
[0013] Further, the industrial control target range management system comprises a task scheduling module, a resource management module, an operation monitoring module and a log analysis module, the task scheduling module supports a user to issue a one-key starting command through an interface, automatically pulls corresponding images and configurations according to a preset scene and deploys a simulation node; the resource management module dynamically allocates computing resources based on resource utilization and node load conditions, and realizes multi-scene concurrent simulation deployment; the operation monitoring module collects system operation indexes and container states, and generates a visual operation monitoring interface in real time; the log analysis module is used for log recording, and replays the whole process of the exercise according to a time axis, supports key event marking and traceability analysis, and provides data basis for attack chain verification, defense strategy review and AI model training.
[0014] Further, the user interaction interface is used for showing multiple attack and defense exercise scenes, and automatically deploying corresponding test configurations in response to user selection, so as to realize flexible calling and self-defined control of the target range environment.
[0015] The second aspect of the application provides a construction device of an industrial control system dynamic attack and defense test environment.
[0016] The construction device of the industrial control system dynamic attack and defense test environment comprises: A first unit is used for system state modeling of a key control hardware module, collecting instruction sets, protocol behaviors and operation logic, and constructing a dynamic simulation component; separating modeling of system states, instruction behaviors and protocol interaction processes of industrial firmware; and constructing a simulation platform based on a logic self-learning mechanism; A second unit is used for collecting configuration information, firmware data and operation states of multiple industrial control components, and constructing a meta-aggregated data resource pool; A third unit is used for constructing an industrial equipment behavior data completion system based on a causal relationship reasoning mechanism; A fourth unit is used for setting a data refreshing period and a trigger condition in combination with a time driving mechanism and an event driving mechanism, so as to synchronize physical equipment data to the simulation platform; mapping the operation state of the physical equipment to a logical variable in the simulation platform, driving state transition and response processes of the control logic, so as to construct a digital-analog fusion model supporting time and space driving and data synchronization; A fifth unit is used for introducing an AI agent mechanism module, so as to automatically deduce an attack path, adaptively adjust a defense strategy and intelligently evaluate an exercise effect; A sixth unit is used for configuring an industrial control target range management system for starting, stopping, resource monitoring and log recording operations of each module of the simulation platform; A seventh unit is used for configuring a user interaction interface.
[0017] The third aspect of the application provides a computer device, which comprises: a processor adapted to execute the computer program; The memory stores executable instructions, and the memory stores the computer program, and the computer program is executed by the processor to implement the steps in the construction method of the industrial control system dynamic attack and defense test environment according to the first aspect.
[0018] The fourth aspect of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is adapted to be loaded and executed by a processor to implement the steps in the construction method of the industrial control system dynamic attack and defense test environment according to the first aspect.
[0019] Compared with the prior art, the beneficial effects of the present application are: The present application adopts a firmware system state simulation technology based on logical self-learning, realizes the universality and scalability of industrial control firmware virtualization, constructs a metadata aggregation resource pool, realizes intelligent scheduling and automatic deployment of industrial control component resources, completes behavior data based on a causal relationship reasoning mechanism when detecting deviation of industrial equipment behavior from a preset knowledge base model, improves simulation accuracy, constructs a digital-analog fusion model supporting space-time driving and data synchronization, enhances consistency and real-time feedback capability in virtual-real interconnection process, and introduces an AI Agent collaboration mechanism when facing various threat simulation and response requirements, realizes automatic deduction of attack path, adaptive optimization of defense strategy and intelligent evaluation of the training process. The method effectively solves the problems of long construction period, insufficient simulation accuracy and weak dynamic response capability of the traditional industrial control test environment, and is suitable for the construction requirements of an AI-driven dynamic attack and defense deduction target range platform.
[0020] The present application effectively improves the automation degree, simulation accuracy and intelligent level of industrial control safety target range by integrating key technologies such as industrial control system simulation, AI attack and defense reasoning, causal data completion and digital-analog fusion. Compared with the traditional method, the present application significantly reduces the dependence on physical equipment and manual configuration, shortens the test environment construction period, improves the environment adaptation capability and training resource utilization rate; at the same time, through the introduction of AI Agent, the closed-loop linkage of attack chain generation, defense verification and effect evaluation is realized, which has good scalability and practical application value, and is suitable for dynamic attack and defense deduction, threat simulation and safety capability training in complex industrial network environment. BRIEF DESCRIPTION OF DRAWINGS
[0021] The drawings accompanying the specification of the present application form a part of the present application and serve to provide further understanding of the present application, and the illustrative embodiments of the present application and their descriptions serve to explain the present application, and do not constitute improper limitations on the present application.
[0022] Figure 1 is a flowchart of the construction method of the industrial control system dynamic attack and defense test environment according to the embodiment of the present application; Figure 2 is a structural diagram of an AI agent mechanism shown in an embodiment of the present application; Figure 3 is a structural diagram of a construction device of an industrial control system dynamic attack and defense test environment shown in an embodiment of the present application; Figure 4 is a structural diagram of a computer device shown in an embodiment of the present application. DETAILED DESCRIPTION
[0023] The present application will be further described below in conjunction with the accompanying drawings and embodiments.
[0024] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present application. Unless otherwise indicated, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application pertains.
[0025] It should be noted that the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit exemplary embodiments according to the present application. As used herein, the singular form is intended to include the plural form unless the context clearly indicates otherwise, and it should be further understood that when the terms "comprise" and / or "include" are used in the specification, there is a presence of a feature, step, operation, device, component, and / or combinations thereof.
[0026] Figure 1 is a flowchart of a construction method of an industrial control system dynamic attack and defense test environment shown in an embodiment of the present application; see Figure 1 , a flowchart of a construction method of an industrial control system dynamic attack and defense test environment shown in an embodiment of the present application. In this embodiment, the method may, for example, include the following steps: S101: Construct a firmware system state simulation platform based on a logic self-learning hardware system simulation technology, realize virtualized operation of industrial control hardware, have compatibility of multiple protocols and multiple architectures, and thus improve the versatility and expandability of the simulation platform.
[0027] Among them, the simulation platform performs system state modeling for key control hardware modules such as PLC, RTU, I / O module, communication interface card, etc., constructs a dynamic simulation component with behavior feature recognition and strategy adaptation capability by collecting its instruction set, protocol behavior and running logic.
[0028] The hardware system simulation technology of logical self-learning is: for different industrial control hardware architectures and firmware versions, collecting firmware execution trajectories and running data; based on the collected data, using machine learning algorithms to dynamically build and optimize the firmware simulation model; through the reinforcement learning mechanism to realize the adaptive adjustment of the simulation model, to improve the recognition ability of industrial control logic and abnormal behavior; support unified simulation interface of multi-protocol and multi-architecture industrial control equipment, ensure efficient virtualization and cross-platform compatibility of different types of industrial firmware.
[0029] The simulation model adopts modular and decoupled design, separates the system state, instruction behavior and protocol interaction process of industrial firmware, supports fast adaptation to different manufacturers and models of equipment, and has cross-platform and cross-protocol simulation capabilities. Device running logs, process flow rules and communication data can be introduced during model construction for semantic extraction and behavior modeling.
[0030] During operation, the simulation platform supports a logic self-learning mechanism, which can perform incremental rule learning and parameter optimization based on new interaction samples or abnormal behavior, and automatically feed the learning results back to the simulation model to continuously enhance the behavior expressiveness and accuracy of the model.
[0031] Unlike traditional static simulation methods based on hardware mapping, this system simulation platform does not rely on real firmware and physical hardware, supports cross-manufacturer and cross-architecture general industrial control device virtualization, and provides a high-fidelity and highly portable basic support environment for dynamic attack and defense testing.
[0032] S102: Build a meta-aggregated data resource pool, collect and aggregate configuration information, firmware data and running status of various industrial control components, and realize intelligent scheduling and automatic deployment of resources.
[0033] In this embodiment, the meta-aggregated data resource pool includes a resource collection module, a resource storage and management module, a resource index and retrieval module, an intelligent scheduling and automatic deployment module, and a resource dynamic update module, to realize unified collection, centralized management, rapid deployment and continuous update of industrial control resources.
[0034] The resource collection module can collect static configuration data of PLC, sensor, actuator, industrial gateway and other industrial control components, such as device model, firmware version and network topology, through a unified southbound communication interface compatible with multiple industrial protocol standards, such as Modbus, Profinet, EtherCAT and OPC UA. Meanwhile, in combination with the firmware mounting mechanism and image extraction tool, the system image file, file signature and verification information are extracted from each version of industrial control firmware to form a complete firmware raw data set. In addition, a lightweight data collection agent can be deployed in the target device or simulation node to periodically report the CPU usage, memory occupation, I / O load, network communication rate and abnormal log information of the device, ensuring the continuity and accuracy of the running state data.
[0035] The resource storage and management module uses a relational database (such as MySQL or PostgreSQL) to manage static configuration information and firmware metadata, and introduces a time series database (such as InfluxDB) to store device runtime indicators, meeting the high-concurrency read-write requirements and historical data tracking capabilities. This module builds a multi-dimensional metadata model covering hardware assets, firmware images, running indicators and configuration information, and standardizes the description of industrial control resource attributes and their logical relationships. To ensure environmental consistency, the module also introduces a hash comparison mechanism and consistency checking algorithm to periodically compare the resource states of the production environment and the simulation environment. If differences are found, the system can automatically trigger an alarm or repair process to ensure the consistency and reliability of resource images and configuration information.
[0036] The resource indexing and retrieval module is built based on the Elasticsearch technology framework and supports full-text indexing and multi-label classification. Users can perform combined retrieval based on device type, manufacturer, protocol standard, firmware version and running state, etc. to accurately locate the required industrial control resources. The search results support graphical display, including resource attributes, deployment history and real-time status, facilitating subsequent scheduling and deployment strategy formulation.
[0037] The intelligent scheduling and automated deployment module has multiple scheduling strategies built-in, including load balancing, minimum deployment delay, multi-node priority and other mechanisms. When receiving a task request, the system will automatically select the optimal resource node based on the scheduling strategy and complete the automatic creation, configuration and startup of containers or simulation nodes through platform interfaces such as Kubernetes and Docker Swarm. The module also supports one-key delivery of firmware images, configuration files and running state snapshots, enabling full-lifecycle deployment process management. The module also has version snapshot and one-key rollback capabilities to ensure that each simulation deployment can quickly revert to a known safe state in the event of an anomaly.
[0038] The resource dynamic updating module supports a subscription change monitoring mechanism, only synchronizing newly added or changed resource items, effectively reducing data synchronization bandwidth consumption. In the simulation node supporting hot updating, this module can realize online dynamic injection of firmware version and configuration parameters, without stopping the service to complete environment update and policy adjustment, enhancing the continuity and flexible adaptation ability of the environment.
[0039] S103: An industrial equipment behavior data completion system based on a causal relationship reasoning mechanism is constructed to improve the accuracy and real-time response capability of the industrial control system equipment behavior in the virtual simulation environment.
[0040] In this embodiment, the causal relationship reasoning mechanism includes three parts: an industrial process knowledge base, a graph model, and a causal network. The industrial process knowledge base collects the operation rules, process flow, and abnormal behavior patterns of the equipment, providing detailed data support for the reasoning mechanism. This knowledge base contains the regular operation procedures of the equipment, historical patterns of abnormal behavior, and fault warning information, which can provide comprehensive basic data for system reasoning analysis. The graph model and the causal network use these data to analyze the equipment behavior data in multiple dimensions, identify the deviation between the industrial equipment behavior and the preset knowledge base model, and then find the root cause of the behavior deviation.
[0041] Specifically, the graph model and the causal network establish a relationship graph between equipment operation and process flow to analyze the differences between equipment behavior and the preset model. Through the identification of deviation data, the system can complete and correct based on known equipment behavior rules and abnormal patterns, improving simulation accuracy. This process not only ensures high-fidelity simulation of equipment behavior in the simulation environment, but also significantly enhances the abnormal identification capability in dynamic attack and defense testing.
[0042] The synchronization control module combines the causal reasoning mechanism to ensure that when the system detects a behavior deviation, it can quickly complete the data and dynamically adjust the simulation model, enhancing the response capability of the simulation system to abnormal behavior. In addition, the system uses a reinforcement learning mechanism to adaptively adjust the simulation model, enabling it to more accurately simulate equipment behavior, especially when encountering unknown or complex abnormalities, the system can make more accurate adjustments and responses.
[0043] During the data completion and correction process, the causal relationship reasoning mechanism not only can detect and handle the deviation of equipment behavior data in real time, but also can dynamically update the industrial process knowledge base to adapt to changes in the equipment environment and new attack threats. Through this mechanism, the simulation system can efficiently respond to abnormalities and complete behavior when facing variable attack scenarios, thereby improving the authenticity and effectiveness of the entire attack and defense test.
[0044] In addition, the cause-effect reasoning mechanism supports the configuration of multiple synchronization modes, including periodic data updates and event-triggered modes, ensuring that the system can timely and accurately interact with the physical industrial control system. The data synchronization and state interaction between the virtual simulation system and the actual industrial control equipment remain highly consistent, improving the realism and accuracy of the test environment.
[0045] Finally, as the core unit in the dynamic attack and defense test environment, the cause-effect reasoning mechanism, combined with the intelligent decision-making ability of the AI Agent, provides a solid data foundation and decision support for the high-fidelity simulation and real-time abnormal response of industrial control systems, greatly improving the efficiency and accuracy of attack and defense testing.
[0046] S104: Build a digital-analog fusion model supporting time-space driving and data synchronization, which is used to realize data consistency, state synchronization and dynamic interaction between the virtual simulation environment and the physical industrial control system.
[0047] In this embodiment, the digital-analog fusion model includes a physical data acquisition module, a synchronization control module and a virtual mapping module. The physical data acquisition module acquires the running state parameters of PLC, sensors, actuators and other devices by interfacing with mainstream industrial communication protocols (such as Modbus, OPC UA, S7, etc.), including analog, digital and event code information.
[0048] The synchronization control module combines time driving and event driving mechanisms to set data refresh cycles and trigger conditions, ensuring that physical system data can be synchronized to the virtual simulation platform stably and timely. Time stamp alignment and buffer processing mechanisms are used to improve data synchronization accuracy and reduce transmission jitter.
[0049] The virtual mapping module maps the running state of the physical device to the logical variable in the simulation model, driving the state transition and response process of the control logic. For example, when a sensor analog value is detected to exceed a set threshold, the simulation platform can automatically trigger an alarm logic or control strategy, achieving consistent behavior response with the real industrial control system.
[0050] During data transmission, the system supports two synchronization modes: timed polling and event triggering. Time driving is used for periodic data updates, and event driving is used for immediate response to state changes, ensuring that the state interaction between the simulation model and the physical system has high real-time and accuracy.
[0051] It should be noted that the digital-analog fusion model supports bidirectional communication, and the control instructions generated in the virtual simulation can be written back to the physical device, realizing closed-loop control of the virtual-real system. At the same time, this model can be deployed in containerized simulation nodes or edge computing modules, with good scalability and portability.
[0052] In this embodiment, various data synchronization strategies can also be configured according to actual system requirements, including periodic collection, event subscription and alarm triggering modes, to adapt to different types of equipment and protocol differences in different industrial control environments. As the core supporting component of the dynamic attack and defense test environment, this model improves the response speed and simulation accuracy of virtual-real linkage, and provides a stable data foundation for the intelligent decision-making of the AI Agent.
[0053] S105: Introduce an AI agent mechanism to build an attack deduction module, a defense optimization module and an exercise evaluation module, realize automatic deduction of attack paths, adaptive adjustment of defense strategies and intelligent evaluation of exercise effects.
[0054] Figure 2 is the flowchart of the AI agent mechanism shown in the embodiment of the application; refer to Figure 2 In this embodiment, the AI agent mechanism realizes intelligent attack and defense deduction and evaluation by building a multi-module collaborative architecture. The attack deduction module includes an environment modeling module, an attack graph construction module, a path search module and an attack chain generation module, which work collaboratively in sequence. The environment modeling module analyzes the topology structure and device attributes of the industrial control system, and identifies attackable nodes and exploitation conditions in combination with the vulnerability knowledge base, as the basis for attack graph construction. The attack graph construction module uses graph neural network (GNN) to build an attack graph with nodes and their security associations as input, to express the potential attack paths between devices. The path search module uses Monte Carlo tree search (MCTS) algorithm to perform strategy traversal on the graph to find high feasibility attack paths. The attack chain generation module performs structured processing on the search results to output a complete path sequence containing attack behaviors at each stage. The four modules are connected in series to form a closed-loop process of “modeling→graph building→searching→generating”, supporting dynamic response and update to new topologies or vulnerability changes, and realizing attack deduction capabilities of automation, multiple paths and high restoration degree.
[0055] The defense optimization module includes an attack chain analysis module, a strategy matching module, a dynamic adjustment module and a linkage control module, which rely on a deep reinforcement learning (DRL) model for strategy optimization as a whole. The module receives the attack chain output by the attack deduction module, and extracts key attack nodes and weak links by the attack chain analysis module. The strategy matching module matches the corresponding access control, intrusion detection (IDS) and traffic filtering strategies based on the strategy library. The dynamic adjustment module evaluates the strategy effectiveness and response priority in combination with the DRL model to generate an optimal protection scheme in real time. The linkage control module sends defense actions to industrial firewalls, IPS and other systems to perform port isolation, whitelist control and other operations, realizing immediate response. The module supports closed-loop collaboration with the attack deduction module, and when the defense effect is fed back as insufficient by the exercise evaluation module, the result is input to the strategy optimization model in reverse, continuously iterating the protection strategy to improve the adaptive defense capability of the overall system The drill evaluation module includes an index collection module, a behavior analysis module, an effect evaluation module, and a feedback optimization module, and is used for realizing intelligent quantitative evaluation of the attack and defense process. The index collection module acquires multi-dimensional indexes such as attack success rate, defense response delay, and resource consumption in real time. The behavior analysis module models time series data based on a long short-term memory network (LSTM), and identifies attack and defense behavior patterns and response processes. The effect evaluation module combines a fuzzy comprehensive evaluation method, and quantitatively scores attack chain influence, defense strategy effectiveness, and system stability. The feedback optimization module feeds back the evaluation results to the attack deduction module and the defense optimization module respectively, the former is used for migrating learning to optimize attack path generation strategies, and the latter is used for adjusting protection strategy parameters, to realize closed-loop linkage of deduction, optimization, and evaluation. The module supports self-defined evaluation rules in different drill scenarios, and improves the pertinence and practical value of system security training.
[0056] It should be noted that the AI agent mechanism supports cross-platform deployment and module extension, and can be integrated into an edge computing node or a cloud target range platform through containerization technology. Data interaction is realized among the modules by using a message queue (MQ), to ensure real-time linkage of attack deduction, defense adjustment, and effect evaluation. Meanwhile, the mechanism has a model hot update interface built-in, which can dynamically upgrade a vulnerability knowledge base and a strategy rule base based on new attack samples, to adapt to the rapid evolution needs of industrial control system attack and defense scenarios, and to provide intelligent decision support for a dynamic attack and defense test environment.
[0057] S106: Develop and integrate an industrial control target range management system, to support starting, stopping, resource monitoring, and log recording operations on each module in the simulation environment, to improve management efficiency and test controllability.
[0058] In the embodiment, the industrial control target range management system is built by using a micro-service architecture, and is divided into a task scheduling module, a resource management module, a running monitoring module, and a log analysis module, which are respectively responsible for creation and scheduling of test tasks, node life cycle management, real-time monitoring of simulation environment running states, and collection and analysis of drill data.
[0059] The task scheduling module supports a user to issue a one-key starting command through an interface, to automatically pull corresponding images and configurations and deploy simulation nodes according to a preset scenario; the resource management module dynamically allocates computing resources based on resource usage and node load conditions, to realize multi-scenario concurrent simulation deployment; and the running monitoring module collects system running indexes such as CPU, memory, disk, and network, and container states, to generate a visual running monitoring interface in real time, to facilitate a user to master running conditions of each drill instance.
[0060] The log analysis module can record unified logs of user operations, attack processes, defense responses, etc., and replay the whole process on a timeline, support key event marking and trace analysis, and provide data basis for attack chain verification, defense strategy review, and AI model training. The system also supports Role-Based Access Control (RBAC) mechanism to ensure the security of operation permissions during the exercise process.
[0061] S107: Configure a user interaction interface to display multiple attack and defense exercise scenarios and automatically deploy the corresponding test configuration in response to user selection, enabling flexible invocation and custom control of the target range environment.
[0062] The user interaction interface is used for users to configure the exercise target through a graphical method, including selecting industrial control system types, target components, attack methods, exercise strategies, and expected evaluation indicators, and starting the corresponding exercise process through the operation interface to complete the full-process visual control from deployment to execution.
[0063] In this embodiment, the user interface supports graphical construction of attack chains by adding typical attack actions (such as information detection, password cracking, protocol injection, control hijacking, etc.) in a modular manner. The system automatically deploys corresponding container resources, loads firmware and configurations, and allocates simulation nodes based on user combinations, and dynamically feeds back the results to the interaction interface.
[0064] In this embodiment, the user interface includes an interactive configuration module and an exercise scenario deployment module. The interactive configuration module is used to show users multiple preset attack and defense scenarios, including different industrial control system types, attack methods, vulnerability types, and target assets, etc. parameter options, supporting users to flexibly combine attack chains and protection strategies based on simulation purposes. The exercise scenario deployment module automatically deploys corresponding firmware, industrial control component resources, network topology structures, and simulation data in the simulation environment based on the user-selected attack and defense combination configuration, and invokes AI Agent to perform deduction tasks. At the same time, the user interface supports real-time visual display and playback functions during the exercise process, facilitating users to interactively analyze and review the exercise process, attack path, defense response, etc.
[0065] The interaction interface further integrates real-time monitoring, attack playback, and result export functions, allowing users to view attack paths and system response states during execution. It supports exporting exercise logs, scoring results, and AI evaluation reports for teaching records and review analysis.
[0066] The real combat exercise includes penetration testing, vulnerability exploitation, attack chain construction, defense strategy verification, and traceability analysis, etc. The penetration testing is used for evaluating the accessibility and vulnerability of each key component in the industrial control system, the vulnerability exploitation simulates the attacker's intrusion path by reproducing typical security vulnerability behaviors, the attack chain construction forms a multi-step attack process under the guidance of the AI Agent, and is used for verifying the integrity of the system response mechanism, the defense strategy verification is used for testing the effectiveness and robustness of various security mechanisms under different attack paths, and the traceability analysis realizes attack source identification and attack process restoration through log recording and behavior traceability of the attack behavior chain, so that the security situation awareness and emergency response capability of the industrial control system in a complex dynamic environment are comprehensively improved. The user can quickly call the exercise template through the interface, and can also build a custom test path for new attack strategy verification or model training.
[0067] The user operation process is as follows: the user selects the exercise scene and configures the parameters through the Web console, the system schedules the simulation resources and deploys the corresponding nodes, returns the access interface and monitoring information of the controlled target machine, the user uses the attack tool to perform penetration operation, and the system automatically records the operation behavior and result state for scoring and evaluation.
[0068] The simulation target range environment constructed by the application supports multiple users to train online at the same time, all attack behaviors are executed in the controlled network space, the exercise process has "zero impact" on the external production environment, and a safe, real, and high-fidelity training platform is provided for industrial control security personnel.
[0069] It is worth noting that the system supports AI-assisted recommendation of exercise paths, the system automatically generates optimal attack path suggestions based on the user's past operation habits and target types, and simultaneously evaluates the difficulty and risk, thereby improving the training effect and personalized matching capability.
[0070] The interactive interface constructed by the application can be used for practical teaching, and can also serve multiple use scenarios such as target range competition, vulnerability reproduction, and strategy testing, and realizes complete closed-loop management from attack chain design, environment deployment, process evaluation to exercise review.
[0071] In summary, the application provides a construction method of an industrial control system dynamic attack and defense test environment, which can construct a high-fidelity, automatically deployable virtual simulation target range for a complex industrial control system, and has good intelligent deduction, real-time feedback, and strategy evaluation capability.
[0072] Compared with the existing industrial control target range technology, the application has the following advantages: Intelligentization: the AI Agent mechanism is introduced to realize attack path deduction, defense strategy optimization, and exercise evaluation automation, and to improve training efficiency and quality; High simulation: through digital-analog fusion and causal reasoning mechanism, the simulation environment has high fidelity and dynamic response ability; Easy to deploy: support automated deployment, fast initialization and container-level resource rollback, adapt to different training tasks; Flexibility: the target field supports multiple industrial protocols, components and topologies, and can cover common industrial control system attack and defense scenarios; High scalability: each module supports hot plug and heterogeneous extension, and can quickly integrate new protocols, new components and new threat samples to continuously update the simulation capability.
[0073] The above Figure 1 The construction method of the industrial control system dynamic attack and defense test environment provided by the embodiment of the application is introduced in detail, and next, the construction device of the industrial control system dynamic attack and defense test environment provided by the embodiment of the application will be introduced with reference to the drawings.
[0074] Figure 3 It is a structure diagram of the construction device of the industrial control system dynamic attack and defense test environment shown in the embodiment of the application, as Figure 3 shown, it is a specific embodiment of the construction device of the industrial control system dynamic attack and defense test environment. The device described in the embodiment, that is, the entity system for executing the method process described in the above embodiment. Its technical scheme is consistent with the above method embodiment in nature, and the related description in the above embodiment is also applicable to this embodiment. The device described in the embodiment includes the following multiple functional units: The first unit 201 is used for constructing a firmware system state simulation platform based on a logic self-learning hardware system simulation technology, realizing virtualization operation of industrial control hardware, having compatibility of multiple protocols and multiple architectures, thereby improving the universality and expansibility of the simulation platform; The second unit 202 is used for constructing a meta-aggregated data resource pool, used for collecting and converging configuration information, firmware data and running state of multiple industrial control components, realizing intelligent scheduling and automated deployment of resources; The third unit 203 is used for constructing an industrial equipment behavior data completion system based on a causal relationship reasoning mechanism, used for improving the accuracy and real-time response ability of industrial control system equipment behavior in the virtual simulation environment; The fourth unit 204 is used for constructing a digital-analog fusion model supporting space-time driving and data synchronization, used for realizing data consistency, state synchronization and dynamic linkage between the virtual simulation environment and the physical industrial control system; The fifth unit 205 is used for introducing an AI agent mechanism, constructing an attack deduction module, a defense optimization module and an exercise evaluation module, realizing automatic deduction of attack path, adaptive adjustment of defense strategy and intelligent evaluation of exercise effect; The sixth unit 206 is configured to develop and integrate an industrial control target range management system, support starting, stopping, resource monitoring and log recording operations on each module in the simulation environment, and improve management efficiency and test controllability. The seventh unit 207 is configured to configure a user interaction interface, display multiple attack and defense rehearsal scenes, and automatically deploy corresponding test configurations in response to user selection, to realize flexible calling and customized control of the target range environment.
[0075] Optionally, the first unit 201 is further configured to: By collecting the execution track, protocol interaction data and running log of the industrial control firmware, a device behavior model is constructed, and mode recognition and reinforcement learning methods are combined to dynamically optimize the simulation behavior, to support rapid adaptation and high-fidelity behavior reproduction of multiple manufacturer devices and multiple protocol stacks.
[0076] Optionally, the second unit 202 is further configured to: For the security testing requirements of the internal network, the service network and the external network respectively, corresponding Docker image resources are constructed, the image integrates typical industrial control system vulnerability environments and callable attack interfaces, and supports customized deployment of multiple versions of firmware and multiple types of protocol environments.
[0077] The internal network image includes components for simulating database system and middleware (such as MySQL, Redis, Apache, etc.) vulnerabilities; the service network image includes rehearsal environments integrating common Web service vulnerabilities (such as command injection, privilege bypass, directory traversal, etc.); and the external network image includes access components simulating user access points or attack entry points, for constructing a complete target range link structure.
[0078] Optionally, the third unit 203 is further configured to: Based on the causal graph, the industrial process knowledge base and the attack behavior model, the root cause of the detected behavior deviation is identified and abnormal correlation analysis is performed; the system can automatically complete the missing data and label the abnormal behavior, to ensure that the simulation process still has integrity and high simulation accuracy when dealing with unknown attack paths.
[0079] Optionally, the fourth unit 204 is further configured to: A space-time driving module and a real-time data synchronization mechanism are constructed to realize bidirectional driving and response linkage between the logical behavior of industrial devices and the physical system state; the synchronization mechanism supports real-time monitoring and aligned updating of physical data sources, to ensure consistency and synchronization between the virtual simulation model and the real device state.
[0080] Optionally, the fifth unit 205 is further configured to: The attack deduction module generates a multi-path attack chain based on a graph search algorithm and an attack and defense knowledge graph; the defense optimization module adaptively adjusts access control policies, firewall rules and security response mechanisms using a reinforcement learning strategy; the drill evaluation module collects key attack and defense indicators (such as attack success rate, response delay, protection coverage, etc.), automatically generates a multi-dimensional evaluation report, and provides targeted training feedback suggestions.
[0081] Optionally, the industrial control target range management system integrated by the sixth unit 206 has a monitoring module for monitoring the resource consumption and running state of each container node in real time; a log recording module is responsible for collecting and storing user operation logs, system events, attack behavior trajectories and defense response records and other key information, providing a basis for subsequent analysis and tracing.
[0082] Optionally, the seventh unit 207 is further configured to: configure an interactive graphical user interface to support users to select drill content according to drill targets by scene type, target system or attack method, and visually display the drill process in the form of a topology graph, a response state graph and a simulation data graph; After the user selects a specific vulnerability scenario, the system automatically completes the configuration and deployment of the matching container, divides it into internal network, service network and external network, and starts the relevant service components, generates target machine IP addresses and access portals, and supports users to carry out penetration testing and full-link attack and defense operations.
[0083] Referring to Figure 4 The computer device mainly includes a processor, a memory, a communication interface and an internal bus. The processor is responsible for executing various logical operations and control instructions to realize the core functions of the system. The memory includes a high-speed random access memory (RAM) and a non-volatile memory, used to store execution instructions, industrial control system firmware simulation models, knowledge base data and AI Agent algorithm models, etc.
[0084] The communication interface is used to connect the industrial control network environment, realize data exchange and synchronization with industrial equipment and external simulation resources, and support multi-protocol communication to adapt to diversified industrial control systems.
[0085] The components in the electronic device are interconnected through a high-speed bus to ensure the real-time and stability of data transmission. The processor drives the logic self-learning firmware simulation module by executing the program stored in the memory, realizes the virtualization of industrial control firmware and behavior modeling.
[0086] The system integrates a causal relationship reasoning module for analyzing and data completing the behavior deviation of industrial equipment, improving the accuracy and integrity of the simulation model. The digital-analog fusion module ensures the synchronization and consistency of the virtual simulation environment and the real industrial control system in the time and space and data layers.
[0087] The AI agent cooperation mechanism is embedded in the processor control logic to realize automatic deduction of attack paths, dynamic optimization of defense strategies, and intelligent evaluation of the exercise process, and support full-process automation and intelligentization of the dynamic attack and defense test environment.
[0088] The electronic device structure design has good expansibility and universality, can adapt to dynamic attack and defense test requirements of industrial control systems of different scales and complexities, and improves the response capability and test effect of the simulation environment.
[0089] The embodiment provides a computer readable storage medium (Memory), which is a memory device in a computer device, and is used for storing programs and data. It can be understood that the computer readable storage medium herein can include a built-in storage medium in the computer device, and of course can include an extended storage medium supported by the computer device. The computer readable storage medium provides a storage space, and the storage space stores a processing system of the computer device. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and the instructions can be one or more computer programs (including program codes). It should be noted that the computer readable storage medium herein can be a high-speed RAM memory, or a non-volatile memory such as at least one disk memory; optionally, the computer readable storage medium can also be at least one computer readable storage medium located away from the aforementioned processor.
[0090] In one embodiment, the computer readable storage medium stores one or more instructions; the processor loads and executes the one or more instructions stored in the computer readable storage medium to realize the corresponding steps in the embodiment of the method for constructing the dynamic attack and defense test environment of the industrial control system.
[0091] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage and optical storage) containing computer usable program code.
[0092] The embodiments of methods, apparatuses (systems) and computer program products according to the present application can be described in terms of flowcharts and / or block diagrams. It will be understood that each flow and / or block, and / or combinations of flows and / or blocks, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flows and / or blocks. Figure 1 one or more blocks or flows.
[0093] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flows and / or blocks. Figure 1 one or more blocks or flows.
[0094] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flows and / or block diagram block or blocks. Figure 1 one or more flows and / or blocks. Figure 1 one or more blocks or flows.
[0095] It can be understood by those skilled in the art that all or part of the above-mentioned embodiment methods can be implemented by computer program instructions to instruct related hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the flow of each method embodiment as described above. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM) or a random access memory (RAM), etc.
[0096] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for constructing a dynamic attack and defense testing environment for an industrial control system, characterized in that, include: System-state modeling of key control hardware modules is performed, instruction sets, protocol behavior and operational logic are collected, and dynamic simulation components are constructed. Separate modeling of system state, command behavior, and protocol interaction process in industrial firmware; A simulation platform is built based on a logic self-learning mechanism; Collect configuration information, firmware data, and operating status of various industrial control components to build a meta-aggregated data resource pool; Construct an industrial equipment behavior data completion system based on causal reasoning mechanism; By combining time-driven and event-driven mechanisms, data refresh cycles and trigger conditions are set to synchronize physical device data to the simulation platform; the operating state of the physical device is mapped to logical variables in the simulation platform to drive the state transition and response process of the control logic, so as to build a digital-analog fusion model that supports spatiotemporal driving and data synchronization. An AI agent mechanism module is introduced to automatically deduce attack paths, adaptively adjust defense strategies, and intelligently evaluate the effectiveness of drills. It also configures an industrial control range management system to start, stop, monitor resources, and log the various modules of the simulation platform; Configure the user interface.
2. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The meta-aggregated data resource pool includes hardware resource information, firmware version information, operating status data, and configuration parameters of various industrial control components. The hardware resource information includes controllers, sensors, actuators, and network communication modules. The meta-aggregated data resource pool realizes real-time acquisition, storage, and management of industrial control component resources through a unified interface, and supports dynamic updates and calls to resources.
3. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The causal reasoning mechanism is as follows: an industrial process knowledge base is established, which covers equipment operation rules, process flow and abnormal behavior patterns; multidimensional analysis of industrial equipment behavior data is performed using graph models or causal networks to identify the root causes of behavioral deviations; and the detected deviation behavior data is supplemented and corrected based on known equipment behavior patterns and abnormal patterns.
4. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The fusion model includes a spatiotemporal driving module and a data synchronization module. The spatiotemporal driving module is used to establish a mapping relationship between physical entities and simulation models based on the device runtime sequence and spatial deployment relationship, and drive the simulation process to evolve dynamically according to a predetermined process flow. The data synchronization module is used to interface with real-time operating data from the physical industrial control system and perform bidirectional alignment and comparison with the simulation data in the virtual model.
5. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The AI agent mechanism module includes an attack simulation module, a defense optimization module, and a drill evaluation module. The attack simulation module automatically generates multi-path attack chains based on known vulnerability information, topology, and system behavior patterns, using path search algorithms and simulated adversarial models. The defense optimization module dynamically adjusts security strategies and resource configurations based on the AI model simulation results to achieve adaptive optimization of the security protection scheme. The drill evaluation module collects and analyzes key indicators during the attack and defense interaction process, evaluates the attack effect, defense effectiveness, and response timeliness, and performs reverse training and continuous optimization of the AI model based on the evaluation results.
6. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The industrial control range management system includes a task scheduling module, a resource management module, an operation monitoring module, and a log analysis module. The task scheduling module allows users to issue one-click start commands via an interface, automatically pulling corresponding images and configurations and deploying simulation nodes according to preset scenarios. The resource management module dynamically allocates computing resources based on resource utilization and node load, enabling concurrent simulation deployment across multiple scenarios. The operation monitoring module collects system operation indicators and container status, generating a real-time visual operation monitoring interface. The log analysis module records logs and replays the entire exercise process along a timeline, supporting key event marking and source tracing analysis, providing data support for attack chain verification, defense strategy review, and AI model training.
7. The method for constructing a dynamic attack and defense testing environment for an industrial control system according to claim 1, characterized in that, The user interface is used to display various attack and defense drill scenarios and respond to user selections to automatically deploy corresponding test configurations, enabling flexible access and custom control of the test range environment.
8. A device for constructing a dynamic attack and defense testing environment for an industrial control system, characterized in that, include: The first unit is used to perform system-state modeling of key control hardware modules, collect instruction sets, protocol behavior and operating logic, and build dynamic simulation components. Separate modeling of system state, command behavior, and protocol interaction process in industrial firmware; A simulation platform is built based on a logic self-learning mechanism; The second unit is used to collect configuration information, firmware data and operating status of various industrial control components to build a meta-aggregated data resource pool; The third unit is used to build an industrial equipment behavior data completion system based on causal reasoning mechanism; The fourth unit is used to combine time-driven and event-driven mechanisms to set the data refresh cycle and trigger conditions to synchronize physical device data to the simulation platform; to map the operating state of the physical device to logical variables in the simulation platform, drive the state transition and response process of the control logic, and build a digital-analog fusion model that supports spatiotemporal driving and data synchronization. The fifth unit is used to introduce an AI agent mechanism module to automatically deduce attack paths, adaptively adjust defense strategies, and intelligently evaluate the effectiveness of drills. The sixth unit is used to configure and manage the industrial control range management system for starting, stopping, monitoring resources, and logging various modules of the simulation platform. Unit 7 is used to configure the user interface.
9. A computer device, characterized in that, A processor, adapted to execute computer programs; A memory storing executable instructions, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements the steps in the method for constructing a dynamic attack and defense test environment for an industrial control system as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded by a processor and execute the steps in the method for constructing a dynamic attack and defense test environment for an industrial control system as described in any one of claims 1-7.
Citation Information
Cited By
Network security attack and defense range system and method based on analogue simulation
CN121396651A
Virtual-real fusion large-scale network security simulation system and method
CN122268770A