Intelligent operation and maintenance method and system for industrial control equipment based on large model

By constructing a distributed monitoring architecture based on a large model and cross-channel collaborative analysis, the problem of insufficient early warning in industrial control equipment monitoring systems has been solved, enabling real-time status tracking and automated operation and maintenance of industrial control equipment, thereby improving safety response capabilities and system stability.

CN120956542BActive Publication Date: 2026-02-13北京珞安科技有限责任公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511493029.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-02-13
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Existing industrial control equipment monitoring systems rely on traditional rules and static thresholds, resulting in insufficient early warning capabilities for complex security events, inability to respond to potential threats in a timely manner, and impact on the safe operation of the system.

Method used

A distributed monitoring architecture based on a large model is constructed. Network situation monitoring nodes collect real-time network situation awareness time-series data of industrial control equipment. Cross-channel collaborative analysis is performed using long and short time-series feature prediction channels and network security event identification channels to generate a network security event risk index. When the threshold is reached, operation and maintenance instructions are automatically issued for management.

Benefits of technology

It enables real-time, continuous status tracking and in-depth analysis of industrial control equipment, improving response speed and operation and maintenance efficiency, reducing manual intervention, and ensuring the stability and security of equipment and networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956542B_ABST
    Figure CN120956542B_ABST
Patent Text Reader

Abstract

The application provides an intelligent operation and maintenance method and system for industrial control equipment based on a large model, relates to the technical field of network monitoring, and comprises the following steps: deploying monitoring nodes according to industrial control equipment distribution information, and obtaining a distributed industrial control equipment monitoring architecture; collecting P pieces of network situation awareness time sequence data in the process of networking communication of the P pieces of industrial control equipment; inputting an industrial control equipment network security event prediction model for cross-channel collaborative analysis, and generating P pieces of industrial control equipment network security event prediction results; and when the risk index of any network security event reaches a network security event risk index threshold, issuing an operation and maintenance instruction and executing operation and maintenance management. The application solves the technical problem that the existing industrial control equipment monitoring usually relies on traditional rule-based monitoring and static threshold setting, which leads to insufficient early warning capability for complex security events, and further leads to the fact that the industrial control equipment cannot respond in time when encountering potential threats, thereby affecting the safe operation of the entire system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network monitoring, in particular to an intelligent operation and maintenance method and system for industrial control equipment based on a large model. BACKGROUND

[0002] In modern industrial environments, more and more industrial control equipment is connected to enterprise networks, and the security of these industrial control equipment is crucial because any security attack on industrial control equipment can have a serious impact on production processes, data flow, and the stability of the overall system. However, existing industrial control equipment monitoring systems usually rely on traditional rule-based monitoring and static threshold settings, such as setting alarms when network traffic is too high or delay is too long. However, this method relies on manual threshold setting and is difficult to effectively capture the interrelationships between devices and complex security events. The limitations of existing technology result in insufficient early warning capabilities for complex security events, which in turn leads to the inability of industrial control equipment to respond in a timely manner when encountering potential threats, which can cause device failure or the spread of network attacks, and even affect the safe operation of the entire production system. SUMMARY

[0003] The present application provides an intelligent operation and maintenance method and system for industrial control equipment based on a large model, aiming to solve the technical problem that existing industrial control equipment monitoring usually relies on traditional rule-based monitoring and static threshold settings, resulting in insufficient early warning capabilities for complex security events, which in turn leads to the inability of industrial control equipment to respond in a timely manner when encountering potential threats, affecting the safe operation of the entire system.

[0004] The first aspect of the present application provides an intelligent operation and maintenance method for industrial control equipment based on a large model, the method comprising: deploying monitoring nodes according to industrial control equipment distribution information to obtain a distributed industrial control equipment monitoring architecture, the distributed industrial control equipment monitoring architecture comprising P network situation monitoring nodes of P industrial control equipment, P being a positive integer; during the networking communication process of the P industrial control equipment, based on the P network situation monitoring nodes, collecting P network situation awareness time series data according to a preset monitoring window; inputting the P network situation awareness time series data into an industrial control equipment network security event prediction model for cross-channel collaborative analysis to generate P industrial control equipment network security event prediction results, the industrial control equipment network security event prediction model comprising a long-short time series feature prediction channel and a network security event identification channel, and each industrial control equipment network security event prediction result comprising a network security event risk index; when any network security event risk index of any industrial control equipment reaches a network security event risk index threshold, issuing an operation and maintenance instruction, and performing operation and maintenance management of the any industrial control equipment based on the operation and maintenance instruction.

[0005] In a second aspect, the application discloses an intelligent operation and maintenance system for industrial control equipment based on a large model, which is used for the method and comprises a monitoring architecture establishment module, a perception data acquisition module, a cross-channel collaborative analysis module, and an operation and maintenance management module.

[0006] The one or more technical solutions provided in the application have at least the following beneficial effects:

[0007] The monitoring nodes are deployed according to the distribution information of the industrial control equipment to build a distributed monitoring architecture, which has strong scalability and can flexibly add monitoring nodes according to actual needs to comprehensively cover all industrial control equipment connected to the enterprise network. Each monitoring node independently monitors one device or a group of devices, and collects and processes related data in real time. The network situation awareness time series data of the P industrial control equipment is collected based on the monitoring nodes, which can track the status of each industrial control equipment in real time and continuously. The time series data reflects the real-time running status of the equipment and provides important information of the network security situation. The collected time series data is input into the industrial control equipment network security event prediction model for cross-channel collaborative analysis, from which the long-short time series features and security event identification features of the equipment are extracted to generate the network security event risk index of the equipment. This process realizes the deep analysis and prediction of the equipment status through the long-short memory network and the recurrent neural network. When the network security event risk index of a certain industrial control equipment reaches the preset risk index threshold, an operation and maintenance instruction is automatically sent out to perform the corresponding operation and maintenance management operation to repair the equipment fault or alleviate the security risk. The automatic operation and maintenance management mechanism significantly reduces the need for manual intervention, improves the response speed and operation and maintenance efficiency, and can quickly respond when the equipment is abnormal, avoiding the expansion of security events to other equipment or systems, and ensuring the stability and security of the equipment and network.

[0008] The above description is only a summary of the technical solutions of the present application. In order to enable the technical means of the present application to be more clearly understood, and to be implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the present application to be more apparent and easy to understand, the following specific embodiments of the present application are provided. BRIEF DESCRIPTION OF DRAWINGS

[0009] Figure 1 A large model-based intelligent operation and maintenance method for industrial control equipment is provided.

[0010] Figure 2 A large model-based intelligent operation and maintenance system structure diagram for industrial control equipment is provided.

[0011] The following table explains the reference signs: monitoring architecture establishment module 10, perception data acquisition module 20, cross-channel collaborative analysis module 30, operation and maintenance management module 40. DETAILED DESCRIPTION

[0012] The embodiments of the present application provide a large model-based intelligent operation and maintenance method and system for industrial control equipment, which solves the technical problem that the existing industrial control equipment monitoring usually relies on traditional rule-based monitoring and static threshold setting, resulting in insufficient early warning capability for complex security incidents, and further resulting in the inability of industrial control equipment to respond in time when encountering potential threats, affecting the safe operation of the entire system.

[0013] After introducing the basic principles of the present application, the various non-limiting embodiments of the present application will be specifically introduced in combination with the drawings of the specification. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.

[0014] Embodiment one, as shown in the figure, the embodiments of the present application provide a large model-based intelligent operation and maintenance method for industrial control equipment, the method comprises: Figure 1 According to the distribution information of the industrial control equipment, the monitoring node is deployed, and the distributed industrial control equipment monitoring architecture is obtained, the distributed industrial control equipment monitoring architecture comprises P network situation monitoring nodes of P industrial control equipment, P is a positive integer.

[0015]

[0016] ​According to the geographical distribution and work requirements of the industrial control equipment, the distribution information of the industrial control equipment refers to the position, connection mode and functional requirements of the industrial control equipment in the entire industrial environment. These industrial control equipment are located in different areas or working environments, so when deploying the monitoring nodes, the mutual connection between the industrial control equipment, the communication path, the data flow and other factors need to be considered comprehensively. In this process, the monitoring requirements of each industrial control equipment are evaluated, and effective monitoring node deployment is carried out according to its specific task to determine the number, position and communication path of the monitoring nodes.

[0017] The distributed industrial control equipment monitoring architecture is a networked system that contains multiple monitoring nodes for continuously tracking and monitoring the status of industrial control equipment. This architecture is distributed, meaning it is composed of multiple independent but cooperative nodes that are connected through a network, share data and information, and each node is responsible for monitoring different devices or different areas. The architecture contains P network situation monitoring nodes for P industrial control equipment, where P is a positive integer representing the number of devices to be monitored. Each industrial control equipment obtains real-time network situation awareness data such as device status, data traffic, anomaly detection, etc. through the monitoring nodes to analyze and monitor the overall network security.

[0018] During the networking communication process of the P industrial control equipment, P network situation awareness time series data is collected according to the preset monitoring window based on the P network situation monitoring nodes.

[0019] When these industrial control equipment communicate through the network, they exchange a large amount of data, which includes the running status of the equipment, warning signals, abnormal data, etc. During networking, each industrial control equipment exchanges data with the monitoring nodes. Each monitoring node continuously collects network situation data according to the preset monitoring window. The preset monitoring window refers to a time window, measured in seconds, minutes or hours, to set the frequency of data collection. Network situation awareness time series data refers to the network status data of industrial control equipment captured in time series, including device running status, network delay, traffic changes, error warnings, load and other parameters. These data help to monitor the health status of the equipment in real time and identify potential network security risks. During data collection, the monitoring nodes monitor the network data of each industrial control equipment in real time and capture various types of time series data related to the equipment. These data have continuity in the time dimension, so they can reflect the running changes of the equipment and the dynamic characteristics of the system status.

[0020] The P network situation awareness time series data are input into an industrial control device network security event prediction model for cross-channel collaborative analysis, P industrial control device network security event prediction results are generated, the industrial control device network security event prediction model includes a long-short time series feature prediction channel and a network security event identification channel, and each industrial control device network security event prediction result includes a network security event risk index.

[0021] The P network situation awareness time series data collected are input as input data into an industrial control device network security event prediction model, and the purpose of the prediction model is to analyze the time series data and predict possible network security events, especially the potential risks of devices. The long-short time series feature prediction channel aims to capture the behavior patterns and state changes of devices by analyzing the long-short term features of the data, including the traffic trend of devices in different time windows, the high-low fluctuation of device load, etc. By using time series analysis methods, the model can identify the potential rules of device behavior; the network security event identification channel mainly focuses on the identification of network security events, and detects potential security events by analyzing abnormal patterns in the data, such as sharp fluctuations in network traffic, abnormal communication between devices, etc. which can be used as an indication of network security events. This channel uses machine learning algorithms to identify abnormal events and assign corresponding labels to each security event.

[0022] After the above analysis, the model generates network security event prediction results for each industrial control device, which include the network security event risk index of each industrial control device. This index is a quantitative value that represents the likelihood and severity of a device being subjected to a security event. For example, if the risk index of a device is high, it means that the device is in a potential risk state and may face network attacks, data breaches or other security threats.

[0023] When the network security event risk index of any industrial control device reaches the network security event risk index threshold, an operation and maintenance instruction is issued, and operation and maintenance management of the industrial control device is performed based on the operation and maintenance instruction.

[0024] A network security event risk index threshold is set, and if the risk index of a device exceeds the threshold, it is considered that the device is facing a security event and needs to be handled in a timely manner. For example, the threshold is set to 0.8, which means that when the risk index of a device exceeds 0.8, the device needs to be further checked or handled. The setting of the threshold is based on historical data, the security level of the device and the overall security requirements of the network.

[0025] When the risk index of a certain device exceeds the threshold, an operation and maintenance instruction is automatically issued, which is a direct operation instruction for the device, such as closing a certain port, starting a security repair program, adjusting the device configuration, etc. The issuance of the operation and maintenance instruction is automated and can dynamically respond to changes in the risk index without human intervention, ensuring that potential security threats are handled in a timely manner. After receiving the operation and maintenance instruction, the target industrial control device is subjected to corresponding operation and maintenance management operations according to the operation and maintenance instruction. Through this series of operations, the network security state of the industrial control device can be monitored in real time, and automatic response measures can be taken when potential security threats are discovered, ensuring the safety of the entire industrial environment.

[0026] Further, the method for constructing the network security event prediction model of the industrial control device comprises:

[0027] According to the preset monitoring window, the P industrial control devices are subjected to network situation awareness data backtracking to obtain P historical network situation awareness time series data sets. Based on a predetermined long-short time feature analysis scale, the P historical network situation awareness time series data sets are subjected to long-short time feature capture to obtain P long-short time sample groups. According to a long-short time memory network, the P long-short time sample groups are subjected to supervised training, and when the training loss function converges to a predetermined threshold, the long-short time sequence feature prediction channel is generated. According to the P long-short time sample groups, a network security event sample group and a network state normal sample group are extracted. According to a recurrent neural network, the network security event sample group and the network state normal sample group are subjected to supervised training, and when the training loss function converges to a predetermined threshold, the network security event identification channel is generated. The long-short time sequence feature prediction channel and the network security event identification channel are subjected to multi-channel collaborative fusion to generate the network security event prediction model of the industrial control device.

[0028] The network situation awareness data backtracked according to the preset monitoring window is used to understand the past running state and network behavior of the device by using historical data. These data include the communication records, traffic data, system load, error warnings, etc. of the device. By backtracking these data, P historical network situation awareness time series data sets are obtained, which contain the network states of each industrial control device at different time points, forming a complete time series data set.

[0029] The predetermined long-short time feature analysis scale refers to extracting features at different time scales. Short-term features can reflect the instantaneous state changes of the device, while long-term features can reflect the long-term running trends and behavior patterns of the device. These features can include short-term fluctuations in device load, long-term trends in traffic changes, device response time, etc. Through this analysis, P long-short time sample groups are obtained, each of which corresponds to the long-short time features of an industrial control device in historical data. These sample groups provide basic data for subsequent model training.

[0030] Long short-term memory networks are used to process and predict time series data, which can effectively capture long-term dependencies in time series data and solve the gradient vanishing problem that ordinary neural networks may encounter in long sequence data training. In this step, P long short-term sample groups are used for supervised training of long short-term memory networks. Supervised training means training using labeled data, which has already labeled the past safety status and risk situation of the device. The goal of training is to let the model learn the operation rules of the device and the probability of network security events under certain conditions through these historical data.

[0031] During training, the goal is to minimize the loss function, that is, to reduce the prediction error of the model. The loss function is calculated according to the difference between the predicted results and the actual labels. Training continues until the value of the loss function converges to a predetermined threshold, which means that the model has learned the potential rules of the data, and the prediction error has reached an acceptable range. When the loss function converges, the training is completed and a long short-term sequence feature prediction channel is generated, which is specifically used to predict the long short-term sequence features of the device from new time series data and provide the basis for subsequent security event prediction.

[0032] The network security event sample group contains time series data of industrial control devices when a network security event occurs. The data contains abnormal patterns, attack behaviors (such as DDoS attacks, malware, unauthorized access, etc.) and their performance in time series data; The normal network state sample group contains the time series data of the industrial control device when it is running normally, reflecting the normal behavior and network state of the device without security events. By classifying these sample groups, it can be identified which time series data corresponds to network security events and which time series data represents normal network status.

[0033] A recurrent neural network is a type of neural network architecture that is well-suited for handling time series data, as it can capture dependencies in the time series. The recurrent neural network can learn patterns in the time series data that change over time, making it particularly suitable for processing network state data from industrial control devices, which have temporal dependencies. The network security event sample set and the network state normal sample set are input into the recurrent neural network for supervised training. Supervised training means that the model is trained using labeled data (i.e., labels for security events and normal states), with the goal of teaching the model to distinguish between the two types of data. During training, the recurrent neural network optimizes its weights to minimize a loss function that measures the difference between the model's predictions and the actual labels. When the value of the loss function converges to a predetermined threshold, it means that the model has learned the patterns in the data and can accurately classify network security events and normal states. After training is complete, a network security event recognition channel is generated. This channel can extract features of network security events from input time series data and make classification predictions, such as identifying whether an attack, device failure, or other abnormal behavior is present.

[0034] The long-short time series feature prediction channel and the network security event recognition channel are combined in a multi-channel collaborative fusion, which means that the output results of the two channels are combined to form a comprehensive prediction model. This model can simultaneously extract long-short time series features and recognize network security events. After the output results of the two channels are collaboratively fused, an industrial control device network security event prediction model is generated. This model can predict the network security status of the device based on input time series data and provide accurate risk indices and prediction results for operational decision-making.

[0035] Furthermore, the network security event sample set includes a first long-short time series feature set of the industrial control device when a network security event occurs, and the first long-short time series feature set has a network security event label. The network state normal sample set includes a second long-short time series feature set of the industrial control device when the network state is normal, and the second long-short time series feature set has a network state normal label.

[0036] The network security event sample set is extracted from time series data of the industrial control device when a network security event occurs. These data contain network posture features of the device when it encounters attacks or other security issues. The first long-short time series feature set captures the dynamic behavior of the device when a network security event occurs. By analyzing these data, abnormal patterns can be identified, such as sudden increases or decreases in network traffic, delays or abnormal fluctuations in device response time, etc. These features are extracted from time series data, including both short-term features (such as instantaneous traffic changes, device state fluctuations) and long-term features (such as long-term patterns of device behavior). For example, when a device is under attack, it may experience sudden abnormal fluctuations, but also gradual decline over a long period of time.

[0037] The first long short-term feature set has a network security event label, which is manually or automatically labeled, indicating whether the data sample belongs to a certain specific network security event, such as network attack, data leakage or other anomalies.

[0038] The network state normal sample group is extracted from the time series data of the industrial control device in the normal working state, which contains the normal running state of the device without network security events. The second long short-term feature set mainly describes the behavior pattern of the device without any security event, such as the normal fluctuation range of network traffic, normal device response time and load. The second long short-term feature set has a network state normal label, which indicates that these time series data belong to the normal state of the device without network security events. The label tells the model that these data do not contain any security threat and are normal behavior of the device. This normal state data sample helps the model learn the normal behavior of the device in the healthy state and distinguish it from the features of abnormal events.

[0039] Further, generating the network security event identification channel further includes:

[0040] Extracting a network security event type set of the industrial control device in the network security event sample group when the network security event occurs; and performing incremental training on the network security event identification channel according to the network security event type set and the first long short-term feature set.

[0041] The network security event type set specifically refers to different security event types extracted in the sample group. These types can be: attack types such as DDoS attack, virus propagation, Trojan intrusion, etc.; device failure types such as hardware failure, network connection interruption, etc.; abnormal behavior types such as data leakage, identity theft, illegal access, etc. Each network security event sample has a label indicating that the event belongs to a certain specific security event type. Therefore, the network security event type set is a category set extracted from these labeled data to represent different types of network security events.

[0042] Incremental training refers to continuously updating and optimizing the model based on the existing model through newly added features, rather than retraining the model from scratch. This way, the model can still maintain high accuracy when facing new event types or different security scenarios. In this process, the network security event type set and the first long-short feature set are used together to perform incremental training on the network security event identification channel. During the incremental training process, the model continuously adjusts and optimizes its internal parameters based on new network security event types and corresponding long-short feature information. The training process is to let the model learn how to better identify new security events and improve the identification accuracy by learning different types of event patterns. Incremental training enables the model to continuously learn these new event types and distinguish them from existing security event types, thereby improving the model's identification ability.

[0043] Further, the method comprises:

[0044] Based on the P sets of historical network situation awareness time series data, network security event extraction and same type aggregation are performed to obtain Q sets of same type network security event data, Q being a positive integer. Based on the Q sets of same type network security event data, same type network security event duration extraction is performed to obtain Q sets of same type network security event duration. Time duration distribution analysis is performed on the Q sets of same type network security event duration, and the predetermined long-short feature analysis scale is generated according to the analysis result.

[0045] Network security events are extracted from P sets of historical network situation awareness time series data. These time series data contain the state information of each industrial control device at different time points. By analyzing these data, the occurring security events can be identified. Same type aggregation is to gather similar security events together to form a same type network security event data set. This can further analyze the common features of these network security events, avoid excessive dispersion of data, and improve the effectiveness of event analysis. Through aggregation, Q sets of same type network security event data are finally obtained, where Q is a positive integer representing the number of event categories, and each category contains multiple similar security event samples.

[0046] The duration of each event category is extracted from Q sets of same type network security event data. Duration refers to the time interval from the start of the event to the end. For example, for device failure, the duration is the time from the start of device failure to the recovery of the device.

[0047] The time length distribution analysis is performed on the set of Q same network security event duration, the time length distribution analysis is to analyze the duration of different categories of events in time distribution, can use statistical methods, such as histogram, probability distribution, quantile analysis, etc., to obtain the distribution characteristics of the duration, through these analyses, the common mode of the duration of different types of events can be identified. The predetermined long-short time feature analysis scale refers to the time window set during the analysis process according to the characteristics of the time length distribution, which is used for subsequent feature extraction and model training. This scale helps to model and predict events according to the length of time.

[0048] Further, the P network situation awareness time series data collected according to the preset monitoring window further includes:

[0049] The P network situation awareness time series data is subjected to abnormal perception data identification, wherein the abnormal perception includes data missing, data noise, and data repetition; the abnormal perception data is subjected to abnormal mode analysis, when the abnormal mode analysis result is a repairable abnormality, the abnormal perception data is subjected to data correction, when the abnormal mode analysis result is an unrepairable abnormality, the abnormal perception data is subjected to elimination, and the data cleaning of the P network situation awareness time series data is completed.

[0050] Abnormal perception data identification is to identify various abnormal conditions existing in time series data, such as data missing, data noise, data repetition, and data abnormal fluctuation. These abnormal data will affect the accuracy and effect of subsequent analysis, so they need to be identified and processed. Data missing refers to the fact that no valid data is collected at some time points or data segments, which is usually caused by equipment failure, network interruption, or data transmission loss; data noise refers to random fluctuations or errors in data, which usually do not represent real network situation changes, but are caused by external interference, sensor error, or unstable factors in the data collection process; data repetition refers to the same value or data point appearing at the same time or time period, which is usually caused by errors in the data collection system or network synchronization problems.

[0051] The abnormal pattern analysis is performed on the abnormal perception data to determine whether the abnormal data can be restored to the normal state by correction means or whether it needs to be directly removed. Some abnormalities are caused by small errors or temporary problems, such as data noise or temporary network fluctuations. For these abnormalities, interpolation, smoothing algorithm or other correction methods can be used for processing. Common repair methods include interpolation, mean substitution, and data filling before and after. The repaired data will be restored to the original data as much as possible. Some abnormalities may be caused by serious faults, attacks or data damage, etc. These abnormal data cannot be repaired and may mislead the analysis results, so they need to be removed from the data set to ensure the quality of the remaining data and the accuracy of the analysis. Data cleaning refers to repairing repairable abnormal data and removing unrepairable abnormal data to obtain clean and reliable P network situation perception time series data. The data after cleaning can be better used for subsequent model training, prediction and analysis to avoid negative effects of abnormal data on the results.

[0052] Further, the method further comprises:

[0053] When the network security event risk index of multiple industrial control devices reaches the network security event risk index threshold, multi-device joint analysis is performed, a linkage response strategy is generated, and global operation and maintenance management is performed based on the linkage response strategy.

[0054] When the network security event risk index of multiple industrial control devices reaches the network security event risk index threshold, multi-device joint analysis is performed. The purpose of this analysis is to examine the synergy between devices from a global perspective, identify possible mutual influences or linkage effects between devices, for example, security events of some devices may affect the operating status of other devices, or when multiple devices are simultaneously attacked, it may cause the collapse or serious failure of the entire industrial system. Based on the mutual relationship between multiple devices, multi-device joint analysis is performed, including network connection between devices, shared resources and cooperative tasks, time correlation, etc. Based on the multi-device joint analysis result, a linkage response strategy is generated. The goal is to coordinate the operation and maintenance behavior of multiple devices to reduce the overall network security risk and ensure the stability and security of the devices. For example, if multiple devices are attacked by the same type of attack or abnormal event, coordinate the repair process of these devices to ensure that they are restored to normal operation in the shortest time. Global operation and maintenance management is performed according to the linkage response strategy. Global operation and maintenance management involves coordinating the operation and maintenance work of multiple devices in the entire industrial control system to ensure that each device can be effectively responded to in a timely manner when a network security event occurs.

[0055] Further, the operation and maintenance management of the arbitrary industrial control device based on the operation and maintenance instruction further comprises:

[0056] The operation and maintenance instruction is used to call a basic industrial control device operation and maintenance scheme, and the operation and maintenance management is performed on the arbitrary industrial control device based on the preset monitoring window, and an arbitrary industrial control device operation and maintenance effect index set is obtained; the feedback optimization of the basic industrial control device operation and maintenance scheme is performed according to the arbitrary industrial control device operation and maintenance effect index set, and a target industrial control device operation and maintenance scheme is generated.

[0057] When performing operation and maintenance management, first, the operation and maintenance instruction is used to call a basic industrial control device operation and maintenance scheme. The basic industrial control device operation and maintenance scheme is a preset response measure for different types of devices, different fault modes or security events, including device repair, state monitoring, fault elimination, etc. For example, for a device under attack, it is isolated from the system by network isolation, communication restriction, etc. to prevent the spread of attacks. Based on the basic industrial control device operation and maintenance scheme, the operation and maintenance management is performed on the arbitrary industrial control device, and in the operation and maintenance management process, the device is analyzed based on the preset monitoring window after operation and maintenance. Various indicators, including device recovery time, fault repair effectiveness, system performance improvement, etc. At the end of each monitoring window, operation and maintenance effect indicators are collected. These indicators are used to measure the success or failure of operation and maintenance, including recovery time, fault detection rate, etc.

[0058] The feedback optimization process means that according to the collected operation and maintenance effect data, the existing basic operation and maintenance scheme is adjusted and optimized. If the effect of some operation and maintenance measures is not ideal, it is improved according to the index result. For example, if the repair step in the basic operation and maintenance scheme is not efficient, or the device recovery time is too long, it is adjusted to propose a new repair strategy or improvement measure. The target industrial control device operation and maintenance scheme is the scheme after feedback optimization, which aims to provide more efficient and more accurate operation and maintenance operations. This scheme is individually adjusted according to the specific needs and running environment of each device to ensure the best operation and maintenance effect.

[0059] Further, the method comprises:

[0060] In any preset monitoring window, the operation and maintenance effect of the network situation awareness data after operation and maintenance is evaluated based on an operation and maintenance effect evaluation function to generate an arbitrary industrial control device operation and maintenance effect index. The operation and maintenance effect evaluation includes network state stability evaluation, network anomaly detection rate evaluation, and operation response time evaluation. When the arbitrary industrial control device operation and maintenance effect index does not meet the operation and maintenance effect constraint, the scheme feedback optimization of this period is performed. When the arbitrary industrial control device operation and maintenance effect index meets the operation and maintenance effect constraint, the tracking evaluation of the next period is entered.

[0061] In any preset monitoring window, the network situational awareness data after operation and maintenance is evaluated based on an operation and maintenance effect evaluation function. The operation and maintenance effect evaluation function is used to measure the recovery of the device and the network security state after the operation and maintenance operation. The purpose of the operation and maintenance effect evaluation function is to quantify the improvement degree of the device in the operation and maintenance process and provide a basis for subsequent decision-making. The industrial control device operation and maintenance effect indicators are generated according to the operation and maintenance effect evaluation result. These indicators are used to measure whether the device returns to the normal working state after completing the operation and maintenance, or whether the operation and maintenance measures are effective. Among them, the network state stability evaluation measures the network state stability of the device after the operation and maintenance, for example, whether the device can return to the normal working state, whether the network can run stably, whether there are network fluctuations, disconnection and other problems; the network anomaly detection rate refers to whether all abnormal behaviors or potential threats in the network can be successfully detected after the operation and maintenance, for example, whether network attacks, device failures or other security events can be identified in time; the operation response time reflects the ability to quickly take countermeasures when problems or abnormalities occur. This indicator evaluates how quickly the system can start repair and protection measures after discovering problems. A good operation and maintenance scheme should be able to respond quickly and reduce system downtime or loss.

[0062] If any industrial control device operation and maintenance effect indicator does not meet the operation and maintenance effect constraint, that is, the performance of the device does not meet the set standard, the scheme feedback optimization is started. The operation and maintenance effect constraint can be that the network stability needs to reach a certain standard, such as the delay time being lower than a certain value and the packet loss rate being lower than a certain proportion; the anomaly detection rate should be higher than a certain threshold; the response time needs to meet the rapid recovery requirement, for example, the response time is less than 5 minutes.

[0063] In the feedback optimization process, the current operation and maintenance scheme is optimized according to the evaluation result. The purpose of feedback optimization is to improve the repair and recovery ability of the device by adjusting and improving the operation and maintenance strategy. For example, if the device recovery time is too long, adjust the repair strategy and adopt more effective repair methods or tools; if the anomaly detection rate is insufficient, increase more monitoring indicators or adjust the existing monitoring rules to improve the detection accuracy; if the operation response time is too long, optimize resource allocation, such as speeding up the response process, increasing more resources, etc.

[0064] If any industrial control device operation and maintenance effect indicator meets the operation and maintenance effect constraint, it means that the operation and maintenance measures successfully restore the normal operation of the device and reach the predetermined standard. In this case, enter the tracking evaluation of the next cycle, which means that the device has been successfully restored and can enter the next stage of regular tracking to continue monitoring the device state and operation and maintenance effect. Periodic evaluation is the monitoring of the continuous health status of the device to ensure that the device can run stably in different periods and potential problems can be found in time.

[0065] Embodiment two, based on the same inventive concept as the intelligent operation and maintenance method of industrial control equipment based on a large model in the preceding embodiments, as Figure 2 As shown in the figure, the embodiment of the present application provides an intelligent operation and maintenance system of industrial control equipment based on a large model, which comprises:

[0066] A monitoring architecture establishment module 10 is configured to deploy monitoring nodes according to industrial control equipment distribution information, and obtain a distributed industrial control equipment monitoring architecture, wherein the distributed industrial control equipment monitoring architecture comprises P network situation monitoring nodes of P industrial control equipment, and P is a positive integer; a perception data acquisition module 20 is configured to acquire P network situation awareness time series data according to a preset monitoring window based on the P network situation monitoring nodes during the networking communication process of the P industrial control equipment; a cross-channel collaborative analysis module 30 is configured to input the P network situation awareness time series data into an industrial control equipment network security event prediction model for cross-channel collaborative analysis, and generate P industrial control equipment network security event prediction results, wherein the industrial control equipment network security event prediction model comprises a long-short time sequence feature prediction channel and a network security event identification channel, and each industrial control equipment network security event prediction result comprises a network security event risk index; and an operation and maintenance management module 40 is configured to issue an operation and maintenance instruction when any network security event risk index of any industrial control equipment reaches a network security event risk index threshold value, and perform operation and maintenance management of the any industrial control equipment based on the operation and maintenance instruction.

[0067] Further, the cross-channel collaborative analysis module 30 is configured to perform the following operation steps:

[0068] According to the preset monitoring window, the P industrial control equipment is subjected to network situation awareness data backtracking to obtain a P historical network situation awareness time series data set; based on a predetermined long-short time feature analysis scale, the P historical network situation awareness time series data set is subjected to long-short time feature capturing to obtain P long-short time sample groups; according to a long-short time memory network, the P long-short time sample groups are subjected to supervised training, and when a training loss function converges to a predetermined threshold value, the long-short time sequence feature prediction channel is generated; according to the P long-short time sample groups, a network security event sample group and a network state normal sample group are extracted; according to a recurrent neural network, the network security event sample group and the network state normal sample group are subjected to supervised training, and when a training loss function converges to a predetermined threshold value, the network security event identification channel is generated; and the long-short time sequence feature prediction channel and the network security event identification channel are subjected to multi-channel collaborative fusion to generate the industrial control equipment network security event prediction model.

[0069] Further, the network security event sample set comprises a first long-short time feature set of the industrial control equipment when the network security event occurs, and the first long-short time feature set has a network security event label; the network state normal sample set comprises a second long-short time feature set of the industrial control equipment when the network state is normal, and the second long-short time feature set has a network state normal label.

[0070] Further, the cross-channel collaborative analysis module 30 is configured to perform the following operation steps:

[0071] extract a network security event type set of the industrial control equipment when the network security event occurs in the network security event sample set; and perform incremental training on the network security event identification channel according to the network security event type set and the first long-short time feature set.

[0072] Further, the cross-channel collaborative analysis module 30 is configured to perform the following operation steps:

[0073] perform network security event extraction and same-type aggregation based on the P sets of historical network situation awareness time series data to obtain Q sets of same-type network security event data, Q being a positive integer; perform same-type network security event duration extraction based on the Q sets of same-type network security event data to obtain Q sets of same-type network security event duration; and perform duration distribution analysis on the Q sets of same-type network security event duration to generate the predetermined long-short time feature analysis scale according to the analysis result.

[0074] Further, the perception data collection module 20 is configured to perform the following operation steps:

[0075] perform abnormal perception data identification on the P sets of network situation awareness time series data, wherein the abnormal perception includes data loss, data noise, and data duplication; perform abnormal mode analysis on the abnormal perception data, when the abnormal mode analysis result is a repairable abnormality, perform data correction on the abnormal perception data, when the abnormal mode analysis result is an unrepairable abnormality, perform elimination on the abnormal perception data, and complete data cleaning of the P sets of network situation awareness time series data.

[0076] Further, the operation and maintenance module 40 is configured to perform the following operation steps:

[0077] when the network security event risk indexes of the multiple industrial control equipment all reach the network security event risk index threshold, perform multi-device joint analysis to generate a linkage response strategy, and perform global operation and maintenance based on the linkage response strategy.

[0078] Further, the operation and maintenance module 40 is configured to perform the following operation steps:

[0079] Based on the operation and maintenance instructions, the operation and maintenance plan of the basic industrial control equipment is retrieved, and the operation and maintenance management of the arbitrary industrial control equipment is carried out. The system performs periodic tracking and evaluation based on the preset monitoring window to obtain a set of operation and maintenance effect indicators for the arbitrary industrial control equipment. Based on the set of operation and maintenance effect indicators for the arbitrary industrial control equipment, the operation and maintenance plan of the basic industrial control equipment is optimized to generate a target industrial control equipment operation and maintenance plan.

[0080] Furthermore, the operation and maintenance management module 40 is used to perform the following operation steps:

[0081] Within any preset monitoring window, based on the operation and maintenance effect evaluation function, the network situational awareness data after operation and maintenance is evaluated to generate operation and maintenance effect indicators for any industrial control equipment. The operation and maintenance effect evaluation includes network status stability evaluation, network anomaly detection rate evaluation, and operation response time evaluation. When the operation and maintenance effect indicators of any industrial control equipment do not meet the operation and maintenance effect constraints, the scheme feedback optimization for this cycle is performed. When the operation and maintenance effect indicators of any industrial control equipment meet the operation and maintenance effect constraints, the tracking evaluation for the next cycle begins.

[0082] Through the foregoing detailed description of the intelligent operation and maintenance method for industrial control equipment based on a large model, those skilled in the art can clearly understand the intelligent operation and maintenance system for industrial control equipment based on a large model in this embodiment. Since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and relevant parts can be referred to the method section.

[0083] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for intelligent operation and maintenance of industrial control equipment based on a large model, characterized in that, The method includes: Based on the distribution information of industrial control equipment, monitoring nodes are deployed to obtain a distributed industrial control equipment monitoring architecture, which includes P network status monitoring nodes for P industrial control equipment, where P is a positive integer. During the networking communication process of the P industrial control devices, P network situation awareness time-series data are collected and acquired according to a preset monitoring window based on the P network situation monitoring nodes. The P network situational awareness time-series data are input into the industrial control equipment network security event prediction model for cross-channel collaborative analysis to generate P industrial control equipment network security event prediction results. The industrial control equipment network security event prediction model includes a long and short time-series feature prediction channel and a network security event identification channel. Each industrial control equipment network security event prediction result includes a network security event risk index. The method for constructing the network security event prediction model for the industrial control equipment includes: According to the preset monitoring window, network situational awareness data backtracking is performed on the P industrial control devices to obtain P sets of historical network situational awareness time series data. Based on a predetermined long and short time feature analysis scale, long and short time features are captured on the P sets of historical network situational awareness time series data to obtain P long and short time sample groups. The P long and short time sample groups are trained under supervision using a long short time memory network. When the training loss function converges to a predetermined threshold, the long and short time series feature prediction channel is generated. Based on the P long and short time sample groups, extract network security event sample groups and normal network status sample groups; The network security event sample group and the network normal status sample group are trained under supervision using a recurrent neural network. When the training loss function converges to a predetermined threshold, the network security event identification channel is generated. The long and short time-series feature prediction channels and the network security event identification channels are fused together to generate the network security event prediction model for the industrial control equipment. When the network security event risk index of any industrial control device reaches the network security event risk index threshold, an operation and maintenance instruction is issued, and the operation and maintenance management of the arbitrary industrial control device is executed based on the operation and maintenance instruction.

2. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 1, characterized in that, The network security incident sample group includes a first set of long and short-term features of industrial control equipment when a network security incident occurs, and the first set of long and short-term features has a network security incident label. The network status normal sample group includes a second set of long and short-term features of industrial control equipment when the network status is normal, and the second set of long and short-term features has a network status normal label.

3. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 2, characterized in that, Generating the network security event identification channel also includes: Extract the set of network security event types for industrial control equipment in the network security event sample group when a network security event occurs; Incremental training is performed on the network security event identification channel based on the set of network security event types and the first set of long and short time features.

4. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 3, characterized in that, The method includes: Based on the P sets of historical network situational awareness time-series data, network security events are extracted and aggregated to obtain Q sets of network security event data of the same type, where Q is a positive integer. Based on the Q sets of similar network security event data, the duration of similar network security events is extracted to obtain a set of Q durations of similar network security events. A duration distribution analysis is performed on the set of Q similar network security events, and the predetermined short-term characteristic analysis scale is generated based on the analysis results.

5. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 1, characterized in that, The step of collecting P network situational awareness time-series data according to a preset monitoring window also includes: Anomaly detection data identification is performed on the P network situational awareness time-series data, wherein anomaly detection includes data missing, data noise, and data duplication; Anomaly pattern analysis is performed on the abnormal perception data. When the anomaly pattern analysis result is a repairable anomaly, the abnormal perception data is corrected. When the anomaly pattern analysis result is an unrepairable anomaly, the abnormal perception data is removed, thus completing the data cleaning of the P network situational awareness time series data.

6. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 1, characterized in that, The method further includes: When the network security incident risk index of multiple industrial control devices reaches the network security incident risk index threshold, multi-device joint analysis is performed to generate a linkage response strategy, and global operation and maintenance management is carried out based on the linkage response strategy.

7. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 1, characterized in that, The step of executing the operation and maintenance management of the arbitrary industrial control equipment based on the operation and maintenance instructions also includes: Based on the operation and maintenance instructions, the operation and maintenance plan of the basic industrial control equipment is invoked, and the operation and maintenance management of the arbitrary industrial control equipment is carried out. Based on the preset monitoring window, periodic tracking and evaluation are performed to obtain a set of operation and maintenance effect indicators for the arbitrary industrial control equipment. Based on the set of operation and maintenance performance indicators for any industrial control equipment, the operation and maintenance plan for the basic industrial control equipment is optimized through feedback, and the operation and maintenance plan for the target industrial control equipment is generated.

8. The intelligent operation and maintenance method for industrial control equipment based on a large model as described in claim 7, characterized in that, The method includes: Within any preset monitoring window, based on the operation and maintenance effect evaluation function, the operation and maintenance effect evaluation is performed on the network situation awareness data after operation and maintenance, and an operation and maintenance effect index for any industrial control equipment is generated. The operation and maintenance effect evaluation includes network status stability evaluation, network anomaly detection rate evaluation, and operation response time evaluation. When the operation and maintenance performance indicators of any industrial control equipment do not meet the operation and maintenance performance constraints, the solution feedback optimization for this cycle will be performed. When the operation and maintenance performance indicators of any industrial control equipment meet the operation and maintenance performance constraints, the next cycle of tracking and evaluation will begin.

9. An intelligent operation and maintenance system for industrial control equipment based on a large model, characterized in that: The system is used to implement the intelligent operation and maintenance method for industrial control equipment based on a large model as described in any one of claims 1-8, the system comprising: The monitoring architecture establishment module is used to deploy monitoring nodes according to the distribution information of industrial control equipment and obtain a distributed industrial control equipment monitoring architecture. The distributed industrial control equipment monitoring architecture includes P network status monitoring nodes for P industrial control equipment, where P is a positive integer. The sensing data acquisition module is used to acquire P network situation sensing time-series data based on the P network situation monitoring nodes according to a preset monitoring window during the network communication process of the P industrial control devices. The cross-channel collaborative analysis module is used to input the P network situational awareness time-series data into the industrial control equipment network security event prediction model for cross-channel collaborative analysis, generating P industrial control equipment network security event prediction results. The industrial control equipment network security event prediction model includes long and short time-series feature prediction channels and network security event identification channels. Each industrial control equipment network security event prediction result includes a network security event risk index. The operation and maintenance management module is used to issue operation and maintenance instructions when the network security event risk index of any industrial control equipment reaches the network security event risk index threshold, and to execute the operation and maintenance management of the arbitrary industrial control equipment based on the operation and maintenance instructions.

Citation Information

Patent Citations

  • Network security dynamic early warning method and system based on knowledge graph

    CN119788344A

  • Dynamic detection architecture, strategy, system and method for attack variants

    CN120433964A