A network security policy optimization method and system
By identifying and evaluating communication patterns with reduced detection sensitivity in adaptive network security systems, and combining industrial production processes and logic verification, potential risks are simulated, and security strategies are adjusted. This solves the problem of insufficient identification of covert penetration by adaptive network security systems and improves the network security protection capabilities of industrial control systems.
Patent Information
- Application Number
- CN202511416633.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2045-09-30
AI Technical Summary
When faced with attackers using their 'optimization' logic for covert penetration, adaptive network security systems are unable to effectively identify and block threats, and may instead 'give the green light' to attacks, leading to production accidents and data breaches.
By acquiring the detection sensitivity adjustment records of the adaptive network security system, we can identify communication patterns with continuously decreasing detection sensitivity, conduct multi-dimensional risk reassessment, verify the rationality of the communication patterns by combining industrial production processes and operational logic, and simulate potential risks using an industrial control logic inference engine to adjust security policies and generate alerts.
Effectively identify and block covert infiltration activities, avoid production accidents and data leaks, improve network security protection levels, and ensure production continuity and equipment lifespan.
Smart Images

Figure CN120896790B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of network security, and specifically to a network security strategy optimization method and system. Background Technology
[0002] In modern industrial production, especially in critical manufacturing plants, the production network carries all control commands and data flow. To ensure production continuity and data integrity, many factories have introduced adaptive network security systems. These systems can analyze network communication data in real time, profile normal behavior, and flag and respond to deviations, such as isolating devices or adjusting firewall rules. In the initial stages of system deployment, they have demonstrated excellent performance in identifying and blocking unauthorized access and malicious data injection, significantly improving the factory's network security protection level.
[0003] However, attackers discovered that when faced with a large amount of "harmless" background noise or sporadic, non-critical anomalies, the adaptive network security system tends to optimize its alerts to lower their priority and avoid false alarms. Attackers exploited this characteristic by controlling external jump servers to send a series of seemingly random but carefully crafted "probing" packets to the factory network. These packets had weak characteristics, were strictly controlled below the single-event alert threshold, and contained no known malicious payloads. When the system detected these sporadic, low-intensity anomalies, it initially labeled them as "low-risk events." However, because they recurred repeatedly and did not escalate into a real threat, the system gradually categorized them as "background noise" or "sporadic network jitter."
[0004] Such covert infiltration can have serious consequences, such as leading to decreased product quality, shortened equipment lifespan, or even production accidents through small, gradual parameter modifications. Meanwhile, stolen data leaks slowly through these seemingly harmless channels in extremely low-frequency, fragmented forms, making data breaches difficult to detect. The factory's adaptive security system, due to its "optimization" logic, ironically becomes a blind spot for attackers, continuously misjudging genuine threats as harmless background activity, or even actively "giving the green light" to attackers' infiltration activities, causing the factory to suffer huge potential losses without its knowledge.
[0005] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention
[0006] This application discloses a network security strategy optimization method and system, which aims to solve the problem that adaptive network security systems cannot effectively identify and block threats when attackers use their "optimization" logic to conduct covert penetration, and may instead "give the green light" to attack behavior.
[0007] The technical solution of this application is as follows:
[0008] Firstly, this application discloses a method for optimizing network security strategies, including:
[0009] The system acquires the detection sensitivity adjustment records of the adaptive network security system during the process of adjusting network communication modes, and identifies communication modes with continuously decreasing detection sensitivity based on these records.
[0010] A multi-dimensional risk reassessment is conducted on the communication mode to obtain the multi-dimensional risk reassessment results. The multi-dimensional risk reassessment includes correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system based on the current state and operation logic to obtain rationality verification information.
[0011] Based on the results of the multi-dimensional risk reassessment, the security strategy of the adaptive network security system is adjusted and optimized, and alarm information is generated and issued.
[0012] Through this technical solution, this application can proactively identify and re-evaluate communication patterns that are misjudged as "harmless" by the adaptive security system, thereby effectively discovering potential covert penetration behaviors, preventing the system from becoming a blind spot for attackers due to "optimization" logic, and significantly improving the network security protection capabilities of industrial control systems.
[0013] Furthermore, by combining the current state and operational logic, the rationality of the communication mode in the industrial control system is verified. The steps to obtain rationality verification information include:
[0014] The system identifies whether the communication mode includes modifications to non-functional parameters in the industrial control system, and determines whether the current industrial production line is in an abnormal processing flow or a flexible production mode, thus obtaining modification identification results and state mode judgment results.
[0015] When the modification identification result indicates that the communication mode contains a modification operation, and the status mode judgment result indicates that the current industrial production line is in an abnormal processing flow or flexible production mode, a temporary system status copy is generated based on the real-time operating status of the current industrial control system and the new values of non-functional parameters contained in the communication mode.
[0016] From the preset industrial disturbance event library, based on the type and function of the non-functional parameters modified by the communication mode, select disturbance events with a correlation degree reaching a preset threshold, and add the simulation effect of the disturbance events to the temporary system state copy;
[0017] Using a pre-set industrial control logic simulation engine, the behavior evolution of a temporary system state replica under the influence of disturbance events is simulated. Based on the behavior evolution, it is determined whether an unexpected chain reaction is triggered, and a potential risk score is calculated.
[0018] If the potential risk score exceeds the preset risk threshold, it indicates that there is a potential risk, and the internal attention level of the communication mode is increased to prevent the detection sensitivity of the communication mode from decreasing.
[0019] Through this technical solution, this application can deeply assess the potential risks of non-functional parameter modifications in communication modes by simulating the impact of industrial disturbance events on system state replicas. This allows for the early detection and prevention of malicious behaviors that may lead to unexpected chain reactions without affecting actual production, effectively avoiding production accidents or quality problems caused by parameter fine-tuning.
[0020] Based on the above, the steps of selecting disturbance events with a correlation reaching a preset threshold from a pre-set industrial disturbance event library, according to the type and effect of the non-functional parameters modified by the communication mode, and adding the simulation effect of the disturbance events to the temporary system state copy include:
[0021] Identify the type and function of non-functional parameters in the communication mode;
[0022] Obtain the real-time operating status and historical operating data of the current industrial production line;
[0023] Analyze the historical anomaly correlations between non-functional parameters and sensor readings, actuator responses, or network communication modes to obtain historical anomaly correlation information;
[0024] Monitor the environmental conditions and equipment aging status of the current industrial production line to obtain information on environmental conditions and equipment aging status.
[0025] Based on the type and function of non-functional parameters, the real-time operating status of the current industrial production line, historical operating data, environmental conditions, equipment aging information, and historical anomaly correlation information, several basic disturbance events are constructed to form a composite disturbance event.
[0026] Add the simulated effects of the composite disturbance event to the temporary system state copy.
[0027] Through this technical solution, this application can comprehensively consider multiple factors to construct composite perturbation events, making risk assessment more comprehensive and accurate, avoiding the limitations of single perturbation event assessment, and thus more effectively identifying potential threats in complex attack scenarios.
[0028] Furthermore, by utilizing a pre-defined industrial control logic simulation engine, the behavior evolution of a temporary system state replica under the influence of disturbance events is simulated. Based on this behavioral evolution, the steps to determine whether an unexpected chain reaction is triggered and to calculate a potential risk score include:
[0029] Identify modifications to non-functional parameters in communication modes, as well as the instantaneous impact of disturbance events on industrial production line equipment or industrial control logic;
[0030] Based on the modification and instantaneous impact of non-functional parameters, a multi-dimensional impact path is constructed; the multi-dimensional impact path includes parameter change path, device state transition path, and network communication behavior path;
[0031] Monitor key indicators along each multi-dimensional impact path; key indicators include the extent to which parameters deviate from safe ranges, unexpected indicators of device state transitions, and abnormal fluctuations in network communication traffic or latency;
[0032] Set a cumulative risk threshold;
[0033] When any key indicator on the multi-dimensional influence path reaches the preset instantaneous anomaly threshold, or when the cumulative effect of the key indicators on the multi-dimensional influence path at different time points causes the comprehensive cumulative value to exceed the cumulative risk threshold, the identification of unexpected chain reactions is triggered.
[0034] A potential risk score is calculated based on the potential impact of unintended chain reactions on production continuity, product quality, and equipment lifespan, as well as the probability of such unintended chain reactions occurring.
[0035] Through this technical solution, this application can construct multi-dimensional impact paths and monitor key indicators to analyze the chain reactions that disturbance events may trigger in more detail, and comprehensively consider their impact and probability of occurrence, thereby providing a more accurate potential risk score and a more reliable basis for adjusting security strategies.
[0036] In some preferred implementations, the steps for monitoring key metrics along each multidimensional impact path include:
[0037] When changes are detected in the operating status, product type, or equipment configuration of an industrial production line, the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration is obtained.
[0038] Obtain actual operating data of the current industrial production line;
[0039] Based on actual operational data, the deviation and trend of key indicators are compared with the expected safe range or normal behavior baseline.
[0040] The anomaly detection thresholds for key indicators are dynamically adjusted based on the degree and trend of deviation.
[0041] Through this technical solution, this application can adjust the anomaly judgment threshold of key indicators in real time according to the dynamic changes of industrial production lines, thereby avoiding false alarms or missed alarms that may be caused by fixed thresholds, and improving the accuracy and adaptability of anomaly detection.
[0042] As an optional approach, when changes are detected in the operating status, product type, or equipment configuration of an industrial production line, the steps to obtain the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration include:
[0043] Identify the production parameters, equipment types, and process flows involved when the operating status, product type, or equipment configuration of an industrial production line changes.
[0044] Based on production parameters, equipment type, and process flow, several corresponding basic baseline units are obtained from the preset baseline unit library;
[0045] Based on the relationships and combination logic of the basic baseline units, construct composite baselines;
[0046] Based on the composite baseline, obtain the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration.
[0047] Through this technical solution, this application can construct a composite baseline by combining basic baseline units, which can flexibly adapt to the complex changes in industrial production lines, ensure that the expected safe range of key indicators or normal behavior baselines always match the actual production situation, and improve the efficiency and accuracy of baseline management.
[0048] Based on this, and according to the relationships and combination logic of the basic baseline units, the steps for constructing a composite baseline include:
[0049] Based on the logical dependencies between basic baseline units and the temporal relationships in the production process, construct a combined sequence;
[0050] Based on the combined sequence, the behavioral evolution of the combined sequence under normal operating conditions is simulated to obtain simulated behavioral data;
[0051] Based on the simulated behavioral data, a composite baseline corresponding to the combined pattern is generated.
[0052] Through this technical solution, this application can generate composite baselines by simulating the behavioral evolution of combined sequences, making the baselines closer to actual operating conditions, improving the accuracy and reliability of the baselines, and thus better supporting the anomaly judgment of key indicators.
[0053] Furthermore, based on the logical dependencies between the basic baseline units and the temporal relationships in the production process, the steps for constructing the combined sequence include:
[0054] When new equipment is introduced into an industrial production line, the interface specifications and control protocols of the new equipment are analyzed to obtain interface specification and control protocol information.
[0055] When a new production process is detected in an industrial production line, the input-output relationship and operation sequence of each production link in the new process are analyzed to obtain information on the input-output relationship and operation sequence.
[0056] Based on interface specifications, control protocol information, input / output relationships, and operation sequence information, identify novel logical dependencies and timing relationships between basic baseline units;
[0057] Integrate novel logical dependencies and temporal relationships into the construction rules of combined sequences.
[0058] Through this technical solution, this application can promptly identify and integrate the logical dependencies and temporal relationships brought about by new equipment and new processes, ensuring the real-time updating and adaptability of baseline construction rules, thereby effectively responding to the rapid changes in industrial production lines.
[0059] In one implementation, the step of constructing a combined sequence based on the logical dependencies between basic baseline units and the temporal relationships in the production process includes:
[0060] When industrial production lines adopt new production processes, based on the corresponding new logical dependencies and temporal relationships, the conflict points with the existing combination sequence construction rules are identified.
[0061] Analyze the conflict types at the conflict points; conflict types include logical contradictions, timing misalignments, or overlapping parameter ranges.
[0062] Based on the conflict type, select the corresponding resolution strategy from the preset conflict resolution strategy library; resolution strategies include priority adjustment, rule merging, or parameter range refinement;
[0063] Apply the solution strategy to adjust the existing rules for constructing combined sequences;
[0064] Logical consistency verification is performed on the adjusted combination sequence construction rules to eliminate logical vulnerabilities in the adjusted combination sequence construction rules and generate verified baseline unit combination sequence construction rules.
[0065] Construct a combined sequence according to the baseline unit combined sequence construction rules.
[0066] Through this technical solution, this application can effectively identify and resolve baseline construction rule conflicts that may be caused by the introduction of new processes, ensure the logical consistency and accuracy of baseline rules, and thus avoid misjudgment or omission caused by rule conflicts.
[0067] Secondly, this application also discloses a network security policy optimization system for performing network security policy optimization, including:
[0068] The communication pattern recognition module is used to acquire the detection sensitivity adjustment records of the adaptive network security system during the process of adjusting and managing network communication patterns, and to identify communication patterns with continuously decreasing detection sensitivity based on the detection sensitivity adjustment records.
[0069] The multidimensional risk assessment module is used to reassess the communication mode from multiple dimensions and obtain the multidimensional risk reassessment results. The multidimensional risk reassessment includes: performing correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system by combining the current state and operation logic to obtain rationality verification information.
[0070] The network policy optimization module is used to adjust and optimize the security policy of the adaptive network security system based on the results of multi-dimensional risk reassessment, and to generate and issue alarm information.
[0071] This technical solution provides an integrated system that, through modular design, enables automated optimization of network security strategies, effectively enhancing the ability of industrial control systems to respond to covert penetration attacks and ensuring the continuity and security of production.
[0072] Beneficial Effects: The network security strategy optimization method disclosed in this application proactively discovers potential threats that might be misjudged as "harmless" by the system by acquiring the sensitivity adjustment records of network communication patterns detected by the adaptive network security system and identifying communication patterns with continuously decreasing detection sensitivity. Based on this, a multi-dimensional risk reassessment is conducted on these communication patterns. This not only correlates the communication patterns with preset abnormal behaviors but also deeply verifies the rationality of the communication patterns in the industrial control system by combining the current state and operational logic of the industrial production process. This comprehensive assessment mechanism can effectively identify covert penetration behaviors by attackers using the system's "optimization" logic, such as through minor, gradual parameter modifications or low-frequency data theft. Finally, based on the results of the multi-dimensional risk reassessment, the security strategy of the adaptive network security system is adjusted and optimized, and alarm information is generated. This avoids the system becoming a blind spot for attackers due to "optimization" logic, effectively solving the problem in existing technologies where adaptive security systems cannot effectively identify and block threats when facing carefully designed covert attacks, or even actively "give the green light" to attacks. The technical solution of this application significantly improves the network security protection level of industrial control systems, ensures the continuity of production, product quality and equipment life, and avoids potential huge losses. Attached Figure Description
[0073] Figure 1 This is a flowchart of a network security strategy optimization method in one embodiment of the present invention;
[0074] Figure 2 This is a flowchart of a network security strategy optimization method according to another embodiment of the present invention;
[0075] Figure 3 This is a system block diagram of a network security policy optimization system according to another embodiment of the present invention;
[0076] Explanation of reference numerals in the attached figures:
[0077] 1. Network security policy optimization system; 11. Communication pattern recognition module; 12. Multi-dimensional risk assessment module; 13. Network policy optimization module. Detailed Implementation
[0078] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0079] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0080] This application proposes a network security strategy optimization method, combining... Figure 1 As shown, it includes:
[0081] S1, acquire the detection sensitivity adjustment record of the adaptive network security system in the process of adjusting network communication mode, and identify the communication mode with continuously decreasing detection sensitivity based on the detection sensitivity adjustment record;
[0082] S2, conduct a multi-dimensional risk reassessment of the communication mode to obtain the multi-dimensional risk reassessment results; the multi-dimensional risk reassessment includes correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system by combining the current state and operation logic to obtain rationality verification information.
[0083] S3 adjusts and optimizes the security policy of the adaptive network security system based on the results of multi-dimensional risk reassessment, and generates and issues alert information.
[0084] The "adaptive network security system" mentioned in this application refers to a system capable of dynamically adjusting its security strategies and detection mechanisms based on changes in the network environment, threat landscape, and its own operational status. This system typically includes modules such as traffic monitoring, behavior analysis, threat intelligence integration, and a policy engine, aiming to achieve real-time perception, intelligent analysis, and proactive defense against network threats. Its core lies in learning normal network behavior patterns through machine learning or artificial intelligence algorithms and identifying abnormal behaviors that deviate from these patterns. "Detection sensitivity adjustment records" refer to the historical records of modifications made to the internal detection rules, thresholds, or algorithm parameters of the adaptive network security system during operation. These adjustments may be to reduce false alarms, improve detection efficiency, or adapt to new network environments. This application utilizes these records to track the changing trends in the system's sensitivity to specific communication patterns. "Communication pattern" refers to a specific behavioral pattern of data transmission in the network, such as the use of specific protocols, packet size, transmission frequency, source IP address, destination IP address, port number, etc. In industrial control systems, communication patterns are often associated with specific production operations or equipment states. "Multi-dimensional risk reassessment" refers to a more comprehensive and in-depth risk analysis process for identified communication patterns. It not only relies on traditional cybersecurity indicators but also incorporates the unique attributes of industrial control systems, such as the current state and operational logic of industrial production processes, to provide more accurate risk assessments. "The current state and operational logic of industrial production processes" refers to the operational phase of an industrial control system at a specific point in time (e.g., startup, normal operation, shutdown, maintenance, etc.) and the pre-defined logical rules used to control production equipment and processes. This information is crucial for determining the appropriateness of network communication patterns in an industrial environment.
[0085] Specifically, in the step of acquiring the detection sensitivity adjustment records of the adaptive network security system during the process of adjusting network communication modes, and identifying communication modes with continuously decreasing detection sensitivity based on these records, the following approach can be used:
[0086] One implementation involves an adaptive network security system periodically uploading its detection sensitivity adjustment logs to a central log server. This log server can be configured with a data analysis module programmed to periodically scan these logs and identify records where detection sensitivity has decreased for specific communication patterns. For example, if the system has adjusted its detection threshold from high risk to medium risk and then back to low risk three consecutive times within the past month for Modbus TCP communication with source IP address A and destination port B, the module would mark this as a communication pattern with continuously decreasing detection sensitivity.
[0087] Another implementation approach is for the adaptive network security system to incorporate a sensitivity trend analysis component. This component is configured to monitor policy adjustment events within the system in real time. When it detects a decrease in the detection sensitivity of a certain communication pattern, the component records the time, magnitude, and characteristics of the relevant communication pattern. If the sensitivity of this communication pattern is decreased multiple times within a preset time window (e.g., 24 hours, one week, or one month), or if the cumulative decrease in sensitivity exceeds a preset threshold, the component will immediately identify this communication pattern as one with continuously decreasing detection sensitivity.
[0088] Specifically, in the step of correlating communication patterns with preset abnormal behaviors to obtain correlation analysis information, the following methods can be used:
[0089] One implementation involves the system maintaining a pre-defined database of anomalous behaviors, which includes known attack patterns on industrial control systems, characteristics of malware behavior, and communication pattern fingerprints of historical anomalous events. When a communication pattern with continuously decreasing detection sensitivity is identified, the system performs feature matching and correlation analysis against the anomalous behaviors in the database. For example, if the characteristics of a communication pattern (such as packet size, frequency, or specific field values) are highly similar to the anomalous behavior patterns of "slow data leakage" or "parameter tampering attempts" recorded in the database, the system generates corresponding correlation analysis information, indicating that the communication pattern may be associated with a certain anomalous behavior.
[0090] Another approach is for the system to utilize a behavioral analysis engine to perform deep learning on historical network traffic data, constructing a baseline for normal communication patterns. When a communication pattern with continuously decreasing detection sensitivity is identified, the system compares it to the normal baseline and analyzes the degree and manner of deviation. Simultaneously, the system integrates with a threat intelligence platform to query the IP addresses, domain names, or file hashes involved in the communication pattern for known malicious records. Through the fusion analysis of this multi-source information, the system can obtain more comprehensive correlation analysis information to determine whether the communication pattern is associated with potential abnormal behavior.
[0091] The following methods can be used to obtain the current state and operational logic of an industrial production process:
[0092] One implementation approach is to integrate the system with an Industrial Control System (ICS) SCADA (Supervisory and Data Acquisition) system or DCS (Distributed Control System). Through this integration, the system can acquire real-time data on the production line's operating status recorded in the SCADA / DCS (e.g., equipment start / stop status, valve opening / closing, motor speed, temperature, pressure, and other sensor readings) and the currently executing process stage. Simultaneously, the system can access the control logic program stored in a PLC (Programmable Logic Controller) or RTU (Remote Terminal Unit) to parse out the logical relationships between devices, such as the operating sequence, conditional judgments, and parameter settings.
[0093] Another approach is to deploy the system within an industrial network, using passive listening or active querying to parse real-time status information of production equipment from industrial protocols (such as Modbus, EtherNet / IP, PROFINET, etc.). For operational logic, the system can pre-import process flow diagrams, operation manuals, or automation scripts from industrial production and convert them into a machine-readable logic rule base. During runtime, the system matches and identifies the currently executing production stage and its corresponding operational logic based on the actual operating data of the production line.
[0094] In the step of verifying the rationality of the communication mode in the industrial control system by combining the current state and operational logic, and obtaining rationality verification information, the following methods can be used:
[0095] One implementation involves the system comparing identified communication patterns with continuously decreasing detection sensitivity with the real-time status and operational logic of the current industrial production process. For example, if a communication pattern involves an instruction to open a valve, but the current production process indicates that the valve should be closed at this stage, or if the timing of the instruction does not match the valve operation time specified in the operational logic, the system will determine that the communication pattern is unreasonable and generate corresponding reasonableness verification information.
[0096] Another approach is for the system to construct an industrial control system behavior model that includes the expected behaviors of all legal operations and communication patterns. When a communication pattern with continuously decreasing detection sensitivity is received, the system inputs it into the behavior model for simulation. The model predicts the potential consequences of this communication pattern based on the current production status and operational logic. If the simulation results show that the communication pattern will lead to unexpected equipment status changes, process interruptions, or safety risks, the system will determine it as unreasonable and generate reasonableness verification information. For example, if a communication pattern attempts to modify the operating parameters of a piece of equipment, but based on the current production process and equipment load, the modification of these parameters exceeds the safe range, then the communication pattern will be judged as unreasonable.
[0097] The steps of adjusting and optimizing the security policy of the adaptive network security system based on the results of multi-dimensional risk reassessment, and generating and issuing alert information, can be achieved in the following ways:
[0098] One implementation involves the system calculating a comprehensive risk score for the communication pattern based on multi-dimensional risk reassessment results (including correlation analysis information and rationality verification information). If this comprehensive risk score exceeds a preset risk threshold, the system immediately sends an instruction to the adaptive network security system, requesting it to increase its detection sensitivity for that communication pattern. For example, it could remove the communication pattern from the "whitelist" or raise its detection threshold to the highest level. Simultaneously, the system generates and issues an alert to notify security operations personnel of the potential threat's existence. The alert may include detailed characteristics of the communication pattern, the risk score, correlation analysis results, and reasons for the rationality verification.
[0099] Another approach is for the system to dynamically generate or modify security policy rules for the adaptive network security system based on the results of multi-dimensional risk reassessment. For example, if a communication pattern is deemed high-risk and unreasonable, the system can generate a new firewall rule to directly block the transmission of that communication pattern; or it can generate an intrusion detection rule to perform deep packet inspection and behavioral analysis on that communication pattern. Simultaneously, the system will issue alerts through various channels (such as email, SMS, and SCADA system alarm interfaces), along with suggested response measures, such as isolating affected devices, forcibly modifying relevant parameters, or initiating emergency response procedures.
[0100] Optional, combined Figure 2 As shown, the steps in step S2, which combine the current state and operational logic to verify the rationality of the communication mode in the industrial control system and obtain rationality verification information, include:
[0101] S21, identify whether the communication mode includes modification operations on non-functional parameters in the industrial control system, and determine whether the current industrial production line is in an abnormal processing flow or flexible production mode, and obtain the modification identification result and the state mode judgment result.
[0102] S22, when the modification identification result indicates that the communication mode contains a modification operation, and the state mode judgment result indicates that the current industrial production line is in an abnormal processing flow or flexible production mode, a temporary system state copy is generated based on the real-time operating status of the current industrial control system and the new values of non-functional parameters contained in the communication mode.
[0103] S23, from the preset industrial disturbance event library, select disturbance events with a correlation degree reaching a preset threshold according to the type and function of the non-functional parameters modified by the communication mode, and add the simulation effect of the disturbance events to the temporary system state copy;
[0104] S24 uses a pre-set industrial control logic deduction engine to simulate the behavior evolution of a temporary system state replica under the influence of disturbance events, determines whether an unexpected chain reaction is triggered based on the behavior evolution, and calculates a potential risk score.
[0105] S25. If the potential risk score exceeds the preset risk threshold, it indicates that there is a potential risk and the internal attention level of the communication mode is increased to prevent the detection sensitivity of the communication mode from decreasing.
[0106] Specifically, identifying whether a communication mode includes modifications to non-functional parameters in the industrial control system involves parsing the data packet content, protocol fields, or instruction sequences of the communication mode to determine if there are any instructions or data modifying non-functional parameters within the industrial control system. Non-functional parameters can be understood as parameters that do not directly affect the physical output of the production process but are crucial to the system's operational stability, safety, performance, or maintainability. Examples include the programmable logic controller (PLC)'s log level, communication timeout threshold, buffer size, diagnostic information switch, firmware update instructions, security authentication configuration, network topology configuration, data acquisition frequency, alarm threshold range, and system clock synchronization settings. Determining whether the current industrial production line is in an abnormal handling process or a flexible production mode involves monitoring the industrial control system's operating status, production plan, equipment alarm information, or operator instructions to determine if the production line is in a non-standard or unexpected operating state. Abnormal handling processes can include equipment failure maintenance, emergency shutdown, system recovery, and safety drills; flexible production modes can include product model switching, small-batch customized production, and dynamic adjustment of process parameters. From this, modification identification results and status mode judgment results can be obtained.
[0107] When the modification identification result indicates that the communication mode involves modification operations, and the status mode judgment result indicates that the current industrial production line is in an abnormal handling process or flexible production mode, a deeper risk assessment is required. At this point, a temporary system state copy is generated based on the real-time operating status of the current industrial control system and the new values of non-functional parameters contained in the communication mode. The temporary system state copy can be understood as a virtualized or simulated snapshot of the current operating state of the industrial control system, containing parameters of all critical equipment, sensor readings, actuator status, network connection information, and the internal logic state of the controller. The generation of this copy aims to provide an isolated and controllable environment for simulating and testing potential risks without affecting actual production operations.
[0108] Furthermore, from a pre-defined industrial disturbance event library, based on the type and effect of the non-functional parameters modified by the communication mode, disturbance events with a correlation reaching a preset threshold are selected, and the simulated effects of these disturbance events are added to a temporary system state copy. The industrial disturbance event library is a pre-built database containing various events that may affect the operation of industrial control systems, such as common network attacks (e.g., denial-of-service attacks, parameter tampering attacks), equipment failures (e.g., sensor drift, actuator jamming), environmental anomalies (e.g., sudden temperature rise, power fluctuations), operational errors, or software vulnerabilities. Selecting disturbance events with a correlation reaching the preset threshold means that the system intelligently filters out events most relevant to the non-functional parameters modified by the current communication mode and most likely to cause risks. For example, if the communication mode modifies the PLC's log level, attack or failure events related to the log system may be selected. Adding the simulated effects of the disturbance events to the temporary system state copy means simulating the occurrence of these disturbance events in a virtual environment, for example, by injecting simulated malicious data packets, changing virtual sensor readings, simulating equipment failure states, etc., to observe the system's behavior under these combined conditions.
[0109] Subsequently, using a pre-set industrial control logic simulation engine, the behavior evolution of a temporary system state replica under the influence of disturbance events is simulated. Based on this behavioral evolution, it is determined whether unexpected chain reactions are triggered, and a potential risk score is calculated. The industrial control logic simulation engine is a simulation platform capable of simulating the internal logic, equipment behavior, and network communication of industrial control systems. This engine can deduce the dynamic response of the system under specific inputs and disturbances based on pre-set control logic and physical models. Unexpected chain reactions refer to behaviors that exceed normal expectations or safety limits during the simulation process, such as production line shutdowns, product quality degradation, equipment damage, safety interlock failures, data transmission interruptions, or abnormal alarms. The potential risk score is the result of a quantitative assessment of the severity and probability of these unexpected chain reactions.
[0110] Ultimately, if the potential risk score exceeds a preset risk threshold, it indicates a potential risk and raises the internal attention level of the communication pattern, preventing a decrease in the detection sensitivity of the communication pattern. This means that even if the communication pattern appears legitimate on the surface, the system will remain highly vigilant and take appropriate security measures because it may trigger a high-risk chain reaction under certain conditions. Raising the internal attention level can include marking it as high-risk communication, triggering a manual review process, increasing the granularity of logging, or initiating additional monitoring mechanisms. Preventing a decrease in detection sensitivity ensures that the adaptive network security system will not misjudge the frequent occurrence of the communication pattern as normal behavior, thereby avoiding the underreporting of future potential threats.
[0111] Optionally, the step of selecting disturbance events with a correlation reaching a preset threshold from a preset industrial disturbance event library, based on the type and effect of the non-functional parameters modified by the communication mode, and adding the simulated effect of the disturbance events to the temporary system state copy includes:
[0112] Identify the type and function of non-functional parameters in the communication mode;
[0113] Obtain the real-time operating status and historical operating data of the current industrial production line;
[0114] Analyze the historical anomaly correlations between non-functional parameters and sensor readings, actuator responses, or network communication modes to obtain historical anomaly correlation information;
[0115] Monitor the environmental conditions and equipment aging status of the current industrial production line to obtain information on environmental conditions and equipment aging status.
[0116] Based on the type and function of non-functional parameters, the real-time operating status of the current industrial production line, historical operating data, environmental conditions, equipment aging information, and historical anomaly correlation information, several basic disturbance events are constructed to form a composite disturbance event.
[0117] Add the simulated effects of the composite disturbance event to the temporary system state copy.
[0118] Specifically, in verifying the rationality of communication modes, the first step is to identify the type and function of non-functional parameters within the communication mode. For example, these non-functional parameters might involve temperature setpoints, pressure thresholds, flow limits, and equipment operating mode switching commands, and their functions might include adjusting process parameters, controlling equipment start-up and shutdown, and adjusting network bandwidth. Accurately identifying this information is fundamental to subsequently constructing disturbance events.
[0119] Furthermore, it is necessary to acquire the real-time operating status and historical operating data of the current industrial production line. Real-time operating status can include instantaneous data such as sensor readings, actuator positions, and controller outputs of the current equipment, while historical operating data covers long-term operating records, maintenance logs, and fault reports of the production line under different operating conditions. This data provides a comprehensive insight into the current health status and past behavior patterns of the production line.
[0120] Furthermore, to gain a deeper understanding of the potential impact of modifications to non-functional parameters, it is necessary to analyze historical anomalies in relation to these parameters and sensor readings, actuator responses, or network communication patterns. This will yield information on these historical anomaly correlations. For example, has a historical modification of a specific non-functional parameter ever caused abnormal fluctuations in sensor readings, actuator response delays, or sudden increases in network communication traffic? This correlation analysis helps reveal the potential causal relationship between parameter modifications and system anomalies.
[0121] In addition, it is necessary to monitor the environmental conditions and equipment aging status of the current industrial production line to obtain information on these factors. Environmental conditions may include ambient temperature, humidity, vibration, etc., which can affect the performance and stability of the equipment. The degree of equipment aging can be assessed through the equipment's operating time, wear and tear, maintenance records, etc. Aging equipment may exhibit different response characteristics when faced with parameter changes or external disturbances.
[0122] Based on the identified types and functions of non-functional parameters, the real-time operating status of the current industrial production line, historical operating data, environmental conditions, equipment aging information, and historical anomaly correlation information, several basic disturbance events can be constructed and combined to form a composite disturbance event. A basic disturbance event can simulate a single factor (such as a sensor malfunction, an actuator jamming, or a network link congestion), while a composite disturbance event combines multiple related basic disturbance events according to specific logic and timing relationships to more realistically simulate chain reactions or multi-point failures that may occur in complex industrial scenarios. For example, a composite disturbance event might simulate a scenario where "a key parameter is modified under conditions of equipment aging and excessively high ambient temperature, accompanied by increased network communication latency."
[0123] Finally, the simulated effects of the composite disturbance event are added to the temporary system state copy. This means that before verifying the rationality of the communication mode, the temporary system state copy not only includes the new values of non-functional parameters after the communication mode modification, but also superimposes the impact of the composite disturbance event constructed from the above multi-dimensional information, thus providing a more realistic and challenging simulation environment for subsequent industrial control logic deduction.
[0124] Optionally, the steps of using a pre-defined industrial control logic simulation engine to simulate the behavioral evolution of a temporary system state replica under the influence of a disturbance event, determining whether an unexpected chain reaction is triggered based on the behavioral evolution, and calculating a potential risk score include:
[0125] Identify modifications to non-functional parameters in communication modes, as well as the instantaneous impact of disturbance events on industrial production line equipment or industrial control logic;
[0126] Based on the modification and instantaneous impact of non-functional parameters, a multi-dimensional impact path is constructed; the multi-dimensional impact path includes parameter change path, device state transition path, and network communication behavior path;
[0127] Monitor key indicators along each multi-dimensional impact path; key indicators include the extent to which parameters deviate from safe ranges, unexpected indicators of device state transitions, and abnormal fluctuations in network communication traffic or latency;
[0128] Set a cumulative risk threshold;
[0129] When any key indicator on the multi-dimensional influence path reaches the preset instantaneous anomaly threshold, or when the cumulative effect of the key indicators on the multi-dimensional influence path at different time points causes the comprehensive cumulative value to exceed the cumulative risk threshold, the identification of unexpected chain reactions is triggered.
[0130] A potential risk score is calculated based on the potential impact of unintended chain reactions on production continuity, product quality, and equipment lifespan, as well as the probability of such unintended chain reactions occurring.
[0131] Specifically, when verifying the rationality of communication modes, the first step is to identify modifications to non-functional parameters within the communication mode, as well as the instantaneous impact of disturbance events on industrial production line equipment or industrial control logic. Modifications to non-functional parameters can refer to adjustments to parameters that do not directly affect the production process, such as equipment configuration, system settings, and communication protocol parameters. The instantaneous impact of disturbance events refers to the direct and immediate effect on industrial production line equipment (e.g., sensors, actuators, controllers) or industrial control logic (e.g., PLC programs, SCADA system configurations) immediately after the disturbance event occurs. For example, a modification to the equipment firmware version number (a non-functional parameter) may cause a delay in the equipment's response under specific operating conditions (an instantaneous impact).
[0132] Based on this, a multi-dimensional impact path is constructed according to the modification and instantaneous effects of non-functional parameters. This multi-dimensional impact path aims to comprehensively depict the propagation and evolution of potential risks within the industrial control system. Specifically, the parameter change path refers to how the modification of non-functional parameters leads to a chain reaction of changes in other related parameters (whether functional or non-functional); the device state transition path refers to the unexpected transitions that may occur in the operating state (e.g., normal, warning, fault, offline, etc.) of a device after being affected by parameter modifications or disturbance events; and the network communication behavior path refers to the abnormal fluctuations that may occur in communication patterns such as network communication traffic, protocol behavior, latency, and packet loss rate within or outside the system. For example, modifying the MTU value of a network device (parameter change) may cause abnormal packet fragmentation behavior of a specific protocol (network communication behavior), thereby affecting the status report of devices that rely on that protocol (device state transition).
[0133] Furthermore, key indicators are monitored along each multi-dimensional impact path. Key indicators are measures used to quantify and assess the degree of anomalies along each impact path. Specifically, the magnitude of parameter deviation from the safe range refers to the degree of deviation between the modified or affected parameter value and the preset safe operating range; the unexpectedness indicator of equipment state transition refers to whether the equipment state transition conforms to the expected operating logic or whether it has entered an abnormal state; abnormal fluctuations in network communication traffic or latency refer to a significant increase or decrease in network traffic or communication latency compared to the normal baseline. For example, monitoring a PID parameter of a control loop deviating from its safe operating range by 15% (parameter deviation magnitude), or a key sensor suddenly changing from an "operating" state to an "unknown" state (unexpected equipment state transition), or a sudden increase of 200 milliseconds in real-time data packet latency on the control network (abnormal fluctuations in network communication).
[0134] To more accurately identify potential risks, a cumulative risk threshold is set. This threshold is used to determine whether the accumulation of multiple minor anomalies constitutes a significant risk. When any key indicator on a multi-dimensional influence path reaches a preset instantaneous anomaly threshold, it indicates the existence of an immediate risk. Furthermore, and more importantly, when the cumulative effect of key indicators on a multi-dimensional influence path at different time points causes the overall cumulative value to exceed the cumulative risk threshold, the identification of unexpected chain reactions should also be triggered. This means that even if the anomaly of a single indicator is insufficient to trigger an instantaneous alert, the cumulative effect of multiple indicators' persistent minor anomalies or interactions on different paths may indicate a potentially significant risk.
[0135] Therefore, once an unexpected chain reaction is identified, a potential risk score is calculated based on the potential impact of the unexpected chain reaction on production continuity, product quality, and equipment lifespan, as well as the probability of the unexpected chain reaction occurring. The impact on production continuity can be quantified as downtime, output loss, etc.; the impact on product quality can be quantified as scrap rate, rework rate, etc.; and the impact on equipment lifespan can be quantified as accelerated wear, increased failure rate, etc. The probability of an unexpected chain reaction occurring can be assessed using historical data, expert experience, or simulation results. The final potential risk score is a comprehensive indicator used to quantify the overall risk level that this communication mode may bring.
[0136] Optionally, the steps for monitoring key metrics along each multi-dimensional impact path include:
[0137] When changes are detected in the operating status, product type, or equipment configuration of an industrial production line, the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration is obtained.
[0138] Obtain actual operating data of the current industrial production line;
[0139] Based on actual operational data, the deviation and trend of key indicators are compared with the expected safe range or normal behavior baseline.
[0140] The anomaly detection thresholds for key indicators are dynamically adjusted based on the degree and trend of deviation.
[0141] Specifically, when the operating status, product type, or equipment configuration of an industrial production line changes—for example, when the production line switches from producing product A to producing product B, or when equipment is upgraded—the system monitors these changes in real time. Once such a change is detected, the system proactively acquires the expected safety range or normal behavior baseline of key indicators (KPIs) that matches the current new production status, product type, or equipment configuration. These baselines can be pre-stored in a database or dynamically generated using machine learning models based on historical data and the current configuration. The expected safety range refers to the numerical range that KPIs should maintain under normal operating conditions; the normal behavior baseline refers to the typical behavioral pattern or statistical distribution of KPIs under a specific production mode.
[0142] Subsequently, the system acquires the actual operating data of the current industrial production line. This data includes, but is not limited to, real-time data related to multi-dimensional influence paths, such as sensor readings, actuator status, network traffic, latency, and CPU utilization.
[0143] Next, the acquired actual operational data is compared with the expected safe range or normal behavioral baseline of the aforementioned matched key indicators. This comparison allows for the calculation of the degree of deviation from the key indicators, such as the distance between the actual value and the expected range boundary, or the similarity between the actual behavioral pattern and the baseline pattern. Furthermore, the trend of deviation can be analyzed, such as whether it is a continuous deviation, a periodic deviation, or a momentary deviation.
[0144] Finally, based on the calculated degree and trend of deviation, the system dynamically adjusts the anomaly detection thresholds for key indicators. For example, if the deviation is small and the trend is stable, the threshold can be appropriately relaxed; if the deviation is large or the trend shows signs of aggravation, the threshold will be tightened to increase sensitivity to potential risks. This dynamic adjustment ensures the accuracy and adaptability of anomaly detection, avoiding misjudgments or omissions caused by changes in the production environment.
[0145] Optionally, when changes are detected in the operating status, product type, or equipment configuration of an industrial production line, it is necessary to obtain the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration. Specifically, this step may include the following operations:
[0146] Identify the production parameters, equipment types, and process flows involved when the operating status, product type, or equipment configuration of an industrial production line changes.
[0147] Based on production parameters, equipment type, and process flow, several corresponding basic baseline units are obtained from the preset baseline unit library;
[0148] Based on the relationships and combination logic of the basic baseline units, construct composite baselines;
[0149] Based on the composite baseline, obtain the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration.
[0150] Specifically, identifying changes in the operating status, product type, or equipment configuration of an industrial production line, including changes in production parameters, equipment types, and processes, refers to the system's ability to automatically or manually identify the specific operating conditions of the current industrial production line. For example, when a production line switches from producing product A to producing product B, the system will recognize the change in product type and further identify specific production parameters related to product B production (such as temperature, pressure, and speed setpoints), the types of equipment used (such as specific models of processing equipment and sensors), and the corresponding process flow (such as the sequence and duration of heating, cooling, and mixing). This information forms the basis for building an accurate baseline.
[0151] Based on production parameters, equipment type, and process flow, the system retrieves several corresponding basic baseline units from a pre-defined baseline unit library. This can be understood as the system maintaining a database containing various predefined "basic baseline units." Each basic baseline unit represents the behavior pattern or safe range of a specific production parameter, equipment type, or process flow segment under normal operating conditions. For example, a basic baseline unit might define the normal vibration range of a specific pump model at a specific flow rate, or the expected reading range of a sensor at a specific temperature. Upon recognizing the current operating condition, the system retrieves and selects the basic baseline unit from this library that best matches or is most relevant to the current operating condition.
[0152] In practical applications, constructing a composite baseline based on the relationships and combination logic of basic baseline units refers to combining multiple acquired basic baseline units according to their logical dependencies and temporal relationships in the actual production process. For example, if a process includes two steps, "heating" and "cooling," and the completion of the heating step is a prerequisite for the start of the cooling step, then the basic baseline units corresponding to these two steps will be combined according to this temporal and logical relationship to form a composite baseline representing the entire "heating-cooling" process. This combination logic can be constructed based on predefined rules, expert knowledge, or machine learning models to ensure that the composite baseline accurately reflects the overall behavior of complex production processes.
[0153] Optionally, based on the relationships and combination logic of the basic baseline units, the steps for constructing a composite baseline include:
[0154] Based on the logical dependencies between basic baseline units and the temporal relationships in the production process, construct a combined sequence;
[0155] Based on the combined sequence, the behavioral evolution of the combined sequence under normal operating conditions is simulated to obtain simulated behavioral data;
[0156] Based on the simulated behavioral data, a composite baseline corresponding to the combined pattern is generated.
[0157] Specifically, the logical dependencies between basic baseline units can refer to the data flow, control signals, or physical connections between different devices or process stages. For example, data from one sensor might be the input condition for the operation of another actuator. The temporal relationships in the production process refer to the order and time intervals of various operations or events; for example, material filling can only proceed after a valve is opened. By analyzing these relationships, one or more combined sequences can be constructed, each representing the path of basic baseline units working collaboratively according to predetermined logic and timing under a specific production mode. Simulating the behavioral evolution of the combined sequence under normal operating conditions refers to reproducing the production process represented by the combined sequence in a simulated environment using simulation tools or digital twin technology. Normal operating conditions refer to the operating parameters, equipment responses, and network communication modes that an industrial production line should have under fault-free, abnormal disturbance-free, and conforming design specifications and operating procedures. Through simulation, a series of simulated behavioral data can be obtained, including the changing trends of various parameters, equipment state transitions, and network communication traffic and latency under these normal conditions. In practical applications, generating a composite baseline corresponding to a combination pattern based on simulated behavioral data refers to extracting and solidifying information such as the normal range, fluctuation characteristics, and correlation patterns of various key indicators obtained during the simulation process into a composite baseline under that specific combination pattern. For example, the average value, standard deviation, maximum and minimum values of each parameter, as well as the correlation between different parameters, can be calculated based on the simulation data, thereby forming a multi-dimensional and dynamic normal behavioral baseline model.
[0158] Optionally, based on the logical dependencies between the basic baseline units and the temporal relationships in the production process, the steps for constructing the combined sequence include:
[0159] When new equipment is introduced into an industrial production line, the interface specifications and control protocols of the new equipment are analyzed to obtain interface specification and control protocol information.
[0160] When a new production process is detected in an industrial production line, the input-output relationship and operation sequence of each production link in the new process are analyzed to obtain information on the input-output relationship and operation sequence.
[0161] Based on interface specifications, control protocol information, input / output relationships, and operation sequence information, identify novel logical dependencies and timing relationships between basic baseline units;
[0162] Integrate novel logical dependencies and temporal relationships into the construction rules of combined sequences.
[0163] Specifically, when new equipment is introduced into an industrial production line, such as robots with autonomous decision-making capabilities, IoT sensors, or advanced control units, a thorough analysis of their interface specifications and control protocols is necessary. Interface specifications refer to the rules governing data exchange and command transmission between devices, such as industrial communication protocols like Modbus TCP, EtherNet / IP, and OPC UA. Control protocols define how devices respond to commands, report status, and collaborate with other devices. By analyzing this information, a comprehensive understanding of the new equipment's behavior patterns and potential impact on the industrial control system can be achieved.
[0164] Simultaneously, when industrial production lines adopt new production processes, such as transitioning from mass production to flexible manufacturing or introducing new processing steps, a detailed analysis of the input-output relationships and operational sequences of each production stage in the new process flow is required. Input-output relationships refer to the inputs required for each production stage (such as raw materials, energy, and control signals) and the outputs generated (such as semi-finished products, data, and waste). Operational sequences define the execution order and parallel relationships that these stages must follow. By analyzing this information, the impact of the new process on existing production processes and equipment interactions can be clearly identified.
[0165] Furthermore, based on the acquired interface specifications, control protocol information, input / output relationships, and operation sequence information, new logical dependencies and timing relationships between basic baseline units can be identified. New logical dependencies refer to the previously unidentified mutual constraints and influences between equipment or processes arising from the introduction of new equipment or new production processes. Timing relationships refer to the temporal order, concurrency, or synchronization requirements of these new dependencies. Examples include the communication timing between a new robot and an existing programmable logic controller (PLC), and the data transmission dependencies between different workstations in a new process.
[0166] Therefore, the identified novel logical dependencies and temporal relationships are integrated into the rules for constructing composite sequences. This means updating and expanding existing rules for constructing composite sequences to accurately reflect the actual operational logic and behavioral patterns of industrial production lines after the introduction of new equipment or processes. This integration ensures that subsequently generated composite sequences can more accurately simulate the actual production environment, thus providing a more reliable foundation for the generation of composite baselines.
[0167] Optionally, based on the logical dependencies between the basic baseline units and the temporal relationships in the production process, the steps for constructing the combined sequence include:
[0168] When industrial production lines adopt new production processes, based on the corresponding new logical dependencies and temporal relationships, the conflict points with the existing combination sequence construction rules are identified.
[0169] Analyze the conflict types at the conflict points; conflict types include logical contradictions, timing misalignments, or overlapping parameter ranges.
[0170] Based on the conflict type, select the corresponding resolution strategy from the preset conflict resolution strategy library; resolution strategies include priority adjustment, rule merging, or parameter range refinement;
[0171] Apply the solution strategy to adjust the existing rules for constructing combined sequences;
[0172] Logical consistency verification is performed on the adjusted combination sequence construction rules to eliminate logical vulnerabilities in the adjusted combination sequence construction rules and generate verified baseline unit combination sequence construction rules.
[0173] Construct a combined sequence according to the baseline unit combined sequence construction rules.
[0174] Specifically, when new production processes are introduced into an industrial production line—for example, new automated equipment, new production steps, or new material handling methods—these new processes bring about new operational logic, data flow, and equipment interaction patterns, thus forming new logical dependencies and temporal relationships. The system then compares these new relationships with existing rules used to construct combinatorial sequences to identify inconsistencies or contradictions, i.e., conflict points.
[0175] The conflict types at conflict points can be understood as the specific manifestations that cause inconsistencies between existing rules and new process requirements. For example, logical contradictions refer to situations where the preconditions or results of an operation in the existing rules contradict the actual logic of the new process; temporal misalignments refer to situations where the execution order of operations in the existing rules does not match the actual order required by the new process, which may lead to deadlocks or inefficiency; and parameter range overlaps refer to situations where the effective range of a parameter in the new process overlaps with the range defined in the existing rules, but their meanings or effects are different, which may lead to misjudgments or improper operations.
[0176] In practical applications, based on the identified conflict type, the system selects the most suitable resolution strategy from a pre-set conflict resolution strategy library. For example, for logical contradictions, a priority adjustment strategy can be used to clarify that the new process rule has a higher priority than the old rule; for timing misalignments, a rule merging strategy can be used to integrate the related timing logic in the new and old rules to form new, more comprehensive timing rules; for overlapping parameter ranges, a parameter range refinement strategy can be used to more accurately divide the effective range of parameters and define different processing logic for different ranges.
[0177] After selecting and applying the appropriate solution strategy, the existing combination sequence construction rules will be adjusted accordingly. To ensure the correctness and accuracy of the adjusted rules, logical consistency verification is required. This verification process aims to check for new logical loopholes, circular dependencies, or inconsistencies in the adjusted rules, for example, by using formal verification methods or simulation tests to identify and eliminate these problems. Ultimately, a set of rigorously verified baseline unit combination sequence construction rules that accurately reflects the current state and process flow of the industrial production line is generated.
[0178] This application also discloses a network security policy optimization system for performing network security policy optimization, combined with... Figure 3 As shown, the network security policy optimization system 1 includes:
[0179] The communication pattern recognition module 11 is used to acquire the detection sensitivity adjustment record of the adaptive network security system in the process of adjusting and managing network communication patterns, and to identify the communication patterns with continuously decreasing detection sensitivity based on the detection sensitivity adjustment record.
[0180] The multidimensional risk assessment module 12 is used to reassess the communication mode in multiple dimensions and obtain the multidimensional risk reassessment results. The multidimensional risk reassessment includes correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system by combining the current state and operation logic to obtain rationality verification information.
[0181] The network policy optimization module 13 is used to adjust and optimize the security policy of the adaptive network security system based on the results of multi-dimensional risk reassessment, and generate and issue alarm information.
[0182] Specifically, the communication pattern recognition module can be implemented as a standalone software service or as a sub-module integrated into an existing network security management platform. This module is configured to continuously monitor policy adjustment events within the adaptive network security system and acquire sensitivity adjustment records of its management process for adjusting network communication patterns. Based on these records, the communication pattern recognition module can identify communication patterns with continuously decreasing sensitivity. The specific implementation methods for acquiring sensitivity adjustment records and identifying communication patterns have already been described in the above embodiments and will not be repeated here. It is important to emphasize that the implementation methods of the communication pattern recognition module can include, but are not limited to: periodically pulling log data from the adaptive network security system's log server for offline analysis, or acquiring sensitivity adjustment events and processing them immediately by subscribing to the adaptive network security system's internal event bus. For example, this module can simply scan log files via a scheduled task to find specific keywords or patterns to identify records with decreasing sensitivity, without requiring complex machine learning models for trend prediction.
[0183] The multi-dimensional risk assessment module can be implemented as an independent risk analysis engine or as a post-processing unit of the communication pattern recognition module. This module is configured to perform multi-dimensional risk reassessment on the communication patterns identified by the communication pattern recognition module to obtain multi-dimensional risk reassessment results. The specific implementation methods of multi-dimensional risk reassessment have been described in the above embodiments, including correlation analysis between communication patterns and preset abnormal behaviors to obtain correlation analysis information, and obtaining the current state and operational logic of the industrial production process and combining it to verify the rationality of the communication patterns in the industrial control system to obtain rationality verification information, which will not be elaborated further here. It should be emphasized that the implementation methods of the multi-dimensional risk assessment module may include, but are not limited to: performing correlation analysis by calling external threat intelligence databases and behavioral analysis models, and obtaining production status and operational logic through real-time data interaction with the data interface of the industrial control system, and using preset rule engines or expert systems for rationality verification. For example, this module can simply perform risk assessment using a preset static rule set without the ability to dynamically adjust the assessment logic.
[0184] The network policy optimization module can be implemented as a policy management and execution unit, interfaced with the adaptive network security system. This module is configured to adjust and optimize the security policies of the adaptive network security system based on the multi-dimensional risk reassessment results provided by the multi-dimensional risk assessment module, and generate and issue alert information. The specific implementation methods for adjusting security policies and issuing alert information based on multi-dimensional risk reassessment results have been described in the above embodiments and will not be repeated here. It is important to emphasize that the implementation methods of the network policy optimization module may include, but are not limited to: sending policy update instructions to the adaptive network security system via API interface, such as increasing the detection sensitivity of specific communication patterns or adding new blocking rules; simultaneously, issuing alerts to relevant operations and maintenance personnel through various communication channels (such as email, SMS, SCADA system alarm interface), and providing detailed risk reports and suggested response measures. For example, this module may only support the selection and application of predefined policy templates, and may not support refined, adaptive policy generation based on specific risk scenarios.
[0185] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for optimizing network security strategies, characterized in that, include: The system acquires the detection sensitivity adjustment records of the adaptive network security system during the process of adjusting network communication modes, and identifies communication modes with continuously decreasing detection sensitivity based on the detection sensitivity adjustment records. A multi-dimensional risk reassessment is performed on the communication mode to obtain the multi-dimensional risk reassessment result; the multi-dimensional risk reassessment includes correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system in combination with the current state and operation logic to obtain rationality verification information. Based on the results of the multi-dimensional risk reassessment, the security strategy of the adaptive network security system is adjusted and optimized, and alarm information is generated and issued. The step of verifying the rationality of the communication mode in the industrial control system by combining the current state and the operation logic, and obtaining rationality verification information, includes: The system identifies whether the communication mode includes modifications to non-functional parameters in the industrial control system, and determines whether the current industrial production line is in an abnormal processing flow or a flexible production mode, thereby obtaining modification identification results and state mode judgment results. When the modification identification result indicates that the communication mode includes the modification operation, and the state mode judgment result indicates that the current industrial production line is in an abnormal processing flow or flexible production mode, a temporary system state copy is generated based on the real-time operating status of the current industrial control system and the new values of non-functional parameters included in the communication mode. From the preset industrial disturbance event library, based on the type and function of the non-functional parameters modified by the communication mode, disturbance events with a correlation degree reaching a preset threshold are selected, and the simulated effect of the disturbance events is added to the temporary system state copy. Using a pre-set industrial control logic deduction engine, the behavior evolution of the temporary system state replica under the influence of the disturbance event is simulated. Based on the behavior evolution, it is determined whether an unexpected chain reaction is triggered, and a potential risk score is calculated. If the potential risk score exceeds a preset risk threshold, it indicates the existence of a potential risk, and the internal attention level of the communication mode is increased to prevent the detection sensitivity of the communication mode from decreasing.
2. The network security strategy optimization method according to claim 1, characterized in that, The process involves selecting events from a pre-set industrial disturbance event database based on the type and function of the non-functional parameters modified by the communication mode, and then selecting events with a correlation degree of [insert correlation here]. The steps of handling disturbance events with preset thresholds and adding the simulated effects of the disturbance events to the temporary system state copy include: Identify the type and function of non-functional parameters in the communication mode; Obtain the real-time operating status and historical operating data of the current industrial production line; Analyze the historical anomaly correlations between non-functional parameters and sensor readings, actuator responses, or network communication modes to obtain historical anomaly correlation information; Monitor the environmental conditions and equipment aging status of the current industrial production line to obtain information on environmental conditions and equipment aging status. Based on the type and function of non-functional parameters, the real-time operating status of the current industrial production line, historical operating data, environmental conditions, equipment aging information, and historical anomaly correlation information, several basic disturbance events are constructed to form a composite disturbance event. The simulated effects of the composite disturbance event are added to the temporary system state copy.
3. The network security strategy optimization method according to claim 1, characterized in that, The steps of using a preset industrial control logic simulation engine to simulate the behavioral evolution of the temporary system state replica under the influence of the disturbance event, determining whether an unexpected chain reaction is triggered based on the behavioral evolution, and calculating a potential risk score include: Identify modifications to non-functional parameters in the communication mode, as well as the instantaneous impact of the disturbance event on industrial production line equipment or industrial control logic; Based on the modification of non-functional parameters and the instantaneous impact, a multi-dimensional impact path is constructed; the multi-dimensional impact path The paths include parameter change paths, device state transition paths, and network communication behavior paths; Monitor key indicators along each multi-dimensional impact path; these key indicators include the magnitude of parameter deviation from the safe range, unexpected indicators of device state transitions, and abnormal fluctuations in network communication traffic or latency. Set a cumulative risk threshold; When any key indicator on the multi-dimensional influence path reaches the preset instantaneous anomaly threshold, or when the cumulative effect of the key indicators on the multi-dimensional influence path at different time points causes the comprehensive cumulative value to exceed the cumulative risk threshold, the identification of unexpected chain reactions is triggered. A potential risk score is calculated based on the potential impact of unintended chain reactions on production continuity, product quality, and equipment lifespan, as well as the probability of such unintended chain reactions occurring.
4. The network security strategy optimization method according to claim 3, characterized in that, The steps for monitoring key indicators along each multi-dimensional influence path include: When changes are detected in the operating status, product type, or equipment configuration of an industrial production line, the expected safety range or normal behavior baseline of key indicators that match the current changed production status, product type, or equipment configuration is obtained. Obtain actual operating data of the current industrial production line; Based on the actual operating data, the deviation and trend of the key indicators are compared with the expected safe range or normal behavior baseline. Based on the degree and trend of deviation, the anomaly judgment threshold of key indicators is dynamically adjusted.
5. The network security strategy optimization method according to claim 4, characterized in that, The step of obtaining the expected safety range or normal behavior baseline of key indicators that matches the current changed production status, product type, or equipment configuration when changes are detected in the operating status, product type, or equipment configuration of the industrial production line includes: Identify the production parameters, equipment types, and process flows involved when the operating status, product type, or equipment configuration of an industrial production line changes. Based on the production parameters, equipment type, and process flow, several corresponding basic baseline units are obtained from the preset baseline unit library; Based on the association and combination logic of the basic baseline units, a composite baseline is constructed; Based on the composite baseline, obtain the expected safety range or normal behavior baseline of key indicators that matches the current changed production status, product type, or equipment configuration.
6. The network security strategy optimization method according to claim 5, characterized in that, The step of constructing a composite baseline based on the association and combination logic of the basic baseline units includes: Based on the logical dependencies between the basic baseline units and the temporal relationships in the production process, a combined sequence is constructed; Based on the combined sequence, the behavioral evolution of the combined sequence under normal operating conditions is simulated to obtain simulated behavioral data; Based on the simulated behavior data, a composite baseline corresponding to the combined pattern is generated.
7. A network security strategy optimization method according to claim 6, characterized in that, The step of constructing the combined sequence based on the logical dependencies between the basic baseline units and the temporal relationships in the production process includes: When new equipment is introduced into an industrial production line, the interface specifications and control protocols of the new equipment are analyzed to obtain interface specification and control protocol information. When a new production process is detected in an industrial production line, the input-output relationship and operation sequence of each production link in the new process are analyzed to obtain information on the input-output relationship and operation sequence. Based on the interface specifications and control protocol information, as well as the input-output relationship and operation sequence information, identify novel logical dependencies and timing relationships among the basic baseline units; The novel logical dependencies and temporal relationships are integrated into the construction rules of the combined sequence.
8. A network security strategy optimization method according to claim 6, characterized in that, The step of constructing the combined sequence based on the logical dependencies between the basic baseline units and the temporal relationships in the production process includes: When industrial production lines adopt new production processes, based on the corresponding new logical dependencies and temporal relationships, the conflict points with the existing combination sequence construction rules are identified. Analyze the conflict type of the conflict point; the conflict type includes logical contradiction, timing misalignment, or overlapping parameter ranges. Based on the conflict type, select the corresponding resolution strategy from the preset conflict resolution strategy library; The solutions include priority adjustment, rule merging, or parameter range refinement; The aforementioned solution strategy is applied to adjust the existing rules for constructing combined sequences; Logical consistency verification is performed on the adjusted combination sequence construction rules to eliminate logical vulnerabilities in the adjusted combination sequence construction rules and generate verified baseline unit combination sequence construction rules. A combined sequence is constructed according to the baseline unit combined sequence construction rules.
9. A network security policy optimization system, used to perform network security policy optimization, characterized in that, include: The communication pattern recognition module is used to acquire the detection sensitivity adjustment record of the adaptive network security system in the process of adjusting and managing network communication patterns, and to identify the communication patterns with continuously decreasing detection sensitivity based on the detection sensitivity adjustment record. A multi-dimensional risk assessment module is used to perform multi-dimensional risk reassessment on the communication mode and obtain multi-dimensional risk reassessment results. The multi-dimensional risk reassessment includes: performing correlation analysis between the communication mode and preset abnormal behaviors to obtain correlation analysis information; obtaining the current state and operation logic of the industrial production process; and verifying the rationality of the communication mode in the industrial control system by combining the current state and operation logic to obtain rationality verification information. The network policy optimization module is used to adjust and optimize the security policy of the adaptive network security system based on the multi-dimensional risk reassessment results, and generate and issue alarm information. The multidimensional risk assessment module is also used for: The system identifies whether the communication mode includes modifications to non-functional parameters in the industrial control system, and determines whether the current industrial production line is in an abnormal processing flow or a flexible production mode, thereby obtaining modification identification results and state mode judgment results. When the modification identification result indicates that the communication mode includes the modification operation, and the state mode judgment result indicates that the current industrial production line is in an abnormal processing flow or flexible production mode, a temporary system state copy is generated based on the real-time operating status of the current industrial control system and the new values of non-functional parameters included in the communication mode. From the preset industrial disturbance event library, based on the type and function of the non-functional parameters modified by the communication mode, disturbance events with a correlation degree reaching a preset threshold are selected, and the simulated effect of the disturbance events is added to the temporary system state copy. Using a pre-set industrial control logic deduction engine, the behavior evolution of the temporary system state replica under the influence of the disturbance event is simulated. Based on the behavior evolution, it is determined whether an unexpected chain reaction is triggered, and a potential risk score is calculated. If the potential risk score exceeds a preset risk threshold, it indicates the existence of a potential risk, and the internal attention level of the communication mode is increased to prevent the detection sensitivity of the communication mode from decreasing.
Citation Information
Patent Citations
Sensitive data anomaly cross-border detection method and system based on flow analysis
CN119341846A