Industrial control safety target range construction method and system based on digital twinborn technology
By constructing an industrial control security test range based on digital twin technology, the problem of existing platforms lacking access interfaces for attack simulation tools and state management mechanisms has been solved. This has enabled efficient test range state management and automated recovery, improved testing efficiency and result reliability, and supported in-depth simulation and verification of complex network attacks.
Patent Information
- Application Number
- CN202511115113.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-18
AI Technical Summary
Existing digital twin platforms lack standardized access interfaces for attack simulation tools and efficient range status management mechanisms, resulting in tedious and time-consuming environment cleanup and configuration recovery work after complex attack and defense tests, which hinders high-frequency, iterative vulnerability verification and defense strategy optimization.
We construct an industrial control security test range based on digital twin technology. By defining interactive interfaces and establishing an automated test range reset mechanism, we adopt physical system modeling, communication network modeling, and collaborative simulation modeling to realize the conversion and feedback of attack commands. We also provide standardized interfaces and efficient state management by backing up and restoring the simulation environment state through a snapshot mechanism.
It improves testing efficiency, enhances the reliability and consistency of test results, lowers the technical threshold, supports high-frequency iterative security verification, and promotes in-depth simulation and verification of physical world cascading failures caused by complex network attacks.
Smart Images

Figure CN120979716A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network security simulation, and particularly relates to an industrial control security target field construction method and system based on digital twinning technology. BACKGROUND
[0002] Industrial control system (ICS) is the "central nervous system" of key infrastructures such as energy, manufacturing and transportation, and its safe and stable operation is of great importance. In order to effectively evaluate and improve the security protection capability of industrial control system, the industry generally adopts the method of constructing a simulation test platform or a security target field to carry out attack and defense drills and security verification, and digital twinning technology emerges as the times require.
[0003] Digital twinning technology aims to create a high-fidelity dynamic virtual model for a physical entity, and realizes virtual-real integration through real-time data interaction, which has shown great potential in the fields of industrial design, state monitoring and predictive maintenance. The patent application with publication number CN119168699A realizes quantitative evaluation and dynamic prediction of market subject monopoly situation by constructing a monopoly behavior data target field using a generative adversarial network (GAN) and combining a data-driven digital twinning model. The patent application with publication number CN115811472A realizes diversified and high-fidelity power network security scene training by automatically deploying a topology structure containing a power system digital twin, and supporting a drill module for attack and defense deduction and multi-dimensional index evaluation. The patent application with publication number CN115544672A proposes a data-driven digital twinning scene construction method, which collects static data (device parameters) and dynamic data (operation data) of a physical test device, and generates a data model and a three-dimensional geometric model in sequence, and finally matches and drives the geometric model with the dynamic data, realizing high-fidelity virtual mapping of the real test device and its operation process, thereby significantly reducing the verification cost of large-scale physical tests.
[0004] Most existing digital twinning platforms are not designed for security testing, and generally lack standardized attack simulation tool access interfaces, and more importantly, they lack efficient target field state management mechanisms. After completing a complex attack and defense test, the cleaning, configuration recovery and scene resetting workflow of the target field environment is tedious and time-consuming, and this efficiency bottleneck has become a key obstacle to using digital twinning technology for high-frequency, iterative vulnerability verification and defense strategy optimization. SUMMARY
[0005] To solve the problems in the prior art, the application provides a method and system for constructing an industrial control safety target field based on digital twin technology, which considers multiple stages including a simulation tool access interface, target field environment cleaning, configuration recovery and scene resetting, and constructs an efficient target field state management mechanism.
[0006] The first aspect of the application discloses a method for constructing an industrial control safety target field based on digital twin technology, which adopts the following technical solution:
[0007] A digital twin simulation environment is constructed for an actual industrial scene, including physical system modeling, communication network modeling and collaborative simulation modeling.
[0008] An interaction interface between the simulation environment and external tools is defined, including selecting a communication mode according to data exchange requirements, defining a logical communication channel based on the selected communication mode and standardizing a data exchange format.
[0009] Through the interaction interface, an attack instruction initiated by an external tool is converted into a simulation operation instruction in the simulation environment, and a physical state change caused by the simulation operation instruction is fed back to the external tool.
[0010] An automated target field resetting mechanism is established to backup and restore the state of the simulation environment through a snapshot mechanism.
[0011] Further, the physical system modeling simulates the physical behavior of hardware devices in the actual industrial scene through a physical system simulator; the communication network modeling simulates data exchange and network communication between hardware devices through a communication network simulator model.
[0012] The collaborative simulation modeling is used for cross-domain data events between the physical system simulator and the communication network simulator; the physical system simulator and the communication network simulator publish physical states and communication data as key values to a joint simulation coordinator, and both of them obtain real-time corresponding values by subscribing to the keys of the other party in the joint simulation coordinator.
[0013] Further, the selection of the communication mode according to the data exchange requirements includes:
[0014] For a data exchange scene with more than T 数据传输 times of data transmission per second and a response time requirement within Δt, an asynchronous message queue mode is selected; in the asynchronous message queue mode, different data flow topics are defined as logical communication channels.
[0015] For an instruction interaction scene with single operation response and immediate confirmation requirement, a synchronous RESTful mode is adopted; in the synchronous RESTful mode, an operation endpoint is defined as a logical communication channel.
[0016] Further, the process of converting the attack instruction into the simulation operation instruction comprises:
[0017] The joint simulation coordinator accepts the attack instruction data issued by the external tool and checks it, including format and syntax checking, semantics and state checking; the attack instruction data that passes the checking will be parsed into structured attack instruction information;
[0018] Through the attack-physical effect mapping library built in the simulation environment, the simulation operation instruction corresponding to the structured attack instruction information is extracted;
[0019] The simulation operation instruction is dispatched to the target physical system simulator and executed at the next synchronization time step, and after executing the simulation operation instruction, the physical system state is updated;
[0020] The joint simulation coordinator captures the updated physical state data, encapsulates it according to the defined standardized data exchange format, and publishes it to the corresponding logical communication channel to feed back to the external tool.
[0021] Further, the state of the simulation environment is represented by a complete set of range state, and the complete set of range state S env Comprises:
[0022] S env ={S phy ,S net ,S coord};
[0023] Among them, S phy represents the state set of the physical system simulator, including the parameters of all physical model objects in the memory of the physical system simulator; S net is the state set of the communication network simulator, including the state of the network topology, node configuration and internal event queue; S coord is the state set of the joint simulation coordinator, including the simulation timestamp, the to-be-processed cross-domain event queue.
[0024] Further, the state of the simulation environment is backed up through a snapshot mechanism, including:
[0025] When receiving the backup instruction, the joint simulation coordinator broadcasts a synchronous pause instruction to all simulators, so that the state of all simulators is paused at the same simulation time point t';
[0026] Each simulator exports its state set S phy (t') and S net (t') at the simulation time point t', and the joint simulation coordinator exports its state set S coord (t') at the simulation time point t';
[0027] S phy(t') and S net (t') and S coord The state data file (t') and the S are compressed and stored as a history state snapshot compressed package together with the metadata file.
[0028] Further, the state of the simulation environment is restored through a snapshot mechanism;
[0029] When the recovery instruction is received, the current simulation process is terminated; for the history state snapshot compressed package Snap(k) at time k, after decompression, the hash value stored in Snap(k) is used to perform integrity checking on all files;
[0030] If the checking passes, the physical state simulator, the communication network simulator, and the joint simulation coordinator restore the state set at time k to the corresponding modules.
[0031] A second aspect of the present application discloses an industrial control security target range construction system based on digital twin technology, which adopts the technical scheme of the industrial control security target range construction method provided in the first aspect of the present application. The system comprises:
[0032] A digital twin simulation module is configured to construct a digital twin simulation environment for an actual industrial scene, including physical system modeling, communication network modeling, and collaborative simulation modeling;
[0033] An interface management module is configured to define an interaction interface between the simulation environment and external tools, including selecting a communication mode according to data exchange requirements, defining a logical communication channel based on the selected communication mode, and standardizing a data exchange format;
[0034] A real-time interaction module is configured to convert an attack instruction initiated by an external tool into a simulation operation instruction in the simulation environment through the interaction interface, and feed back a physical state change caused by the simulation operation instruction to the external tool;
[0035] A state recovery module is configured to establish an automated target range reset mechanism, and backup and restore the state of the simulation environment through a snapshot mechanism
[0036] Compared with the prior art, the present application is not limited to constructing a static and high-fidelity digital twin simulation model, but creatively proposes and implements an automated target range state management system specially designed for high-frequency and iterative attack and defense drills, which contains fine strategy management and high-reliability fault tolerance mechanism. The prior art focuses on the top-level architecture design or data-driven modeling process of the target range, but generally lacks effective solutions to the core engineering pain points of "target range use efficiency" and "test scene rapid reset". The present application addresses this technical gap and has the following beneficial effects:
[0037] 1、The application has made significant improvement in test efficiency. Its unique automatic state backup and recovery mechanism can realize efficient automatic "one-key" recovery by reducing the manual scene configuration, cleaning and resetting time in traditional target range, which is counted by hours. This efficiency improvement makes it possible to verify security vulnerabilities with high frequency and iteration, thereby effectively accelerating the vulnerability analysis and defense strategy optimization process.
[0038] 2、The application effectively enhances the reliability and consistency of test results. Through the integrity check based on SHA256 hash value and transactional error handling capability, it can ensure that each drill starts from an accurate and uncontaminated baseline state, which helps to eliminate configuration drift and inconsistency that may be introduced by manual resetting, thereby improving the reliability and comparability of test results.
[0039] 3、The architecture of the application reduces the technical threshold for conducting complex security research. The combination of standardized access interface and efficient state management creates favorable conditions for "plug and play" type of joint testing of external security tools. Researchers can focus more on attack or defense algorithms themselves rather than spending time on the construction and maintenance of the target range, which reduces the time cost of complex network attack and defense experiments and helps to promote the rapid verification and iteration of security strategies.
[0040] 4、The application provides a technical basis for simulating and verifying the cascading effect of cyber-physical systems. By deeply integrating industrial physical system simulation and communication network simulation and establishing an accurate mapping from network attack to physical effect, the application builds a high-fidelity digital twin environment. On this basis, the efficient state management function makes it have important application value in studying the physical world cascading failures caused by complex network attacks. BRIEF DESCRIPTION OF DRAWINGS
[0041] Figure 1 is a process schematic diagram of the industrial control security target range construction method based on digital twin technology. DETAILED DESCRIPTION
[0042] In order to make the purpose, technical scheme and advantages of the present application clearer, the technical scheme of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. The embodiments described in the present application are only a part of the embodiments of the present application, not all embodiments. Based on the spirit of the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.
[0043] Embodiment one
[0044] As Figure 1As shown, the embodiment proposes a construction method of an industrial control safety target range based on digital twin technology, which includes the following steps:
[0045] Step 1, create a simulation environment; for specific industrial scenarios, build a digital twin simulation environment, including physical system simulation model and communication network simulation model. This embodiment takes the smart distribution grid scenario as an example, and its specific implementation process is as follows.
[0046] 1.1: Physical system modeling; simulate the physical behavior of hardware devices through a physical system simulator. This embodiment selects the open-source power grid simulation platform GridLAB-D, and loads the GLM model (GridLAB-D Model) file of the IEEE 13-node standard test distribution network. The GLM model defines the electrical properties and connection relationships of physical objects such as transformers, line impedances, switch states, and user-side physical loads, to reproduce the real power flow and voltage distribution.
[0047] 1.2: Communication network modeling; simulate data exchange and network communication between hardware devices through a network communication simulator. This embodiment uses the discrete event network simulation software NS-3 to create corresponding network nodes for each user-side physical, which simulate the functions of smart meters for collecting and transmitting data. The CSMA / CA protocol is used to simulate LAN communication, and each node is assigned a unique IP address; through network communication simulation, a user-side communication network topology is constructed to realize data transmission and exchange between devices.
[0048] 1.3: Joint simulation coordinator introduction; introduce a joint simulation coordinator as middleware to manage the co-simulation of physical system simulation and network communication simulation. In this embodiment, the open-source joint simulation framework FNCS (Framework for Network Co-Simulation) is used as the coordinator. The core function of FNCS is its cross-domain data interaction mechanism and unified time management mechanism. Its cross-domain data interaction mechanism is based on the publish-subscribe model, and GridLAB-D can publish its internal node voltage, line power, and other physical states as specific key-value pairs to the FNCS agent, while the nodes in NS-3 can subscribe to these specific keys to obtain the physical state data they are interested in in real time, and vice versa, thereby breaking down the data barriers between the information domain and the physical domain. At the same time, its unified time management mechanism requires all simulators (GridLAB-D, NS-3) to obtain authorization from FNCS before entering the next simulation time step, ensuring strict synchronization and behavior consistency in the time sequence of the entire digital twin environment. An example is given below.
[0049] Assume that at a certain time of the simulation, GridLAB-D simulates the voltage of the smart meter node A in the distribution network as 220V, and the line power from node A to node B as 150kW. GridLAB-D packages these data into key-value pairs and publishes them to the agent of FNCS, as shown in Table 1.
[0050] Table 1: Key-value pair example
[0051] Key: A_node_voltage Value: 220V Key: A_to_B_line_power Value: 150kW
[0052] Assume that the smart meter node B needs to know the voltage of node A to evaluate the impact of load changes. Node B subscribes to the key of“A_node_voltage” through the subscription mechanism in NS-3. When GridLAB-D publishes the data of this key, node B in NS-3 can obtain the voltage value of 220V in real time. Conversely, assume that node B finds that the grid load exceeds the threshold in the simulation, and publishes this information as the value data of the load key to FNCS. GridLAB-D can obtain the load status by subscribing to the load key, and adjust the power distribution or other parameters of the distribution network according to the load status.
[0053] Assume that the current simulation time compensation is 1 second, and the voltage and power calculated by GridLAB-D will change within this second. However, the smart meter node in NS-3 also has its own simulation step different from GridLAB-D. In order to ensure data synchronization, the time management mechanism of FNCS requires that both GridLAB-D and NS-3 must perform calculations within the same time step. For example, after GridLAB-D publishes the voltage data, the smart meter node in NS-3 must wait until FNCS authorizes it to enter the next time step, obtain the updated voltage data, and respond.
[0054] Step 2: Design a modular attack and defense tool access interface. The purpose of this step is to provide a target range with an open, standard, and extensible access layer, breaking down the barriers between the simulation environment and various external security tools, and enabling them to easily perform plug-and-play joint testing. Specifically:
[0055] 2.1: Establish a communication specification. To effectively decouple the core engine of the target range from external tools, this step establishes a unified communication specification for exchanging data between the simulation system and external tools, and selects different communication modes according to actual needs.
[0056] Step 2.1.1: Select the communication mode according to the real-time performance and data coupling degree of the interaction scenario;
[0057] For state feedback data stream that requires continuous, high-frequency interaction and should avoid blocking (e.g. physical simulator publishes real-time voltage of all nodes externally), this embodiment sets the transmission data more than 1000 times per second, preferably using asynchronous decoupled Message Queue (MQ) mode, such as using RabbitMQ or ZeroMQ;
[0058] For instruction-based interaction that requires immediate confirmation and independent operation (e.g. external tool initiates a specific attack or requests a target state snapshot), it is preferred to use synchronous RESTful API mode.
[0059] Step 2.1.2, define specific logical communication channels according to the selected communication mode;
[0060] As in the MQ mode, topics such as sim.feedback.voltage (feedback voltage) and sim.control.attack (control attack) can be defined, and in the API mode, endpoints such as / api / attack / execute (execute attack) can be defined, to process attack instructions and state feedback data streams respectively.
[0061] 2.2: Standardized data exchange format, to ensure that the data exchanged between different tools can be correctly parsed, this step defines a set of unified data payload format.
[0062] Step 2.2.1, select data format and optimize for different communication channel characteristics;
[0063] For high-throughput state feedback channels (e.g. more than 10MB of data transmitted per second), it is preferred to use binary serialization formats such as Protocol Buffers (Protobuf), which has the advantage of small data volume, high encoding and decoding efficiency, and can significantly reduce network overhead and processing delay;
[0064] For instruction control channels, JSON format with good universality and human readability can be selected.
[0065] Step 2.2.2, Designing the Data Structure Design: Take an attack instruction as an example, its JSON structure can be defined as follows: a unique identifier attack_id of string type; an attack name attack_type of enumeration type, such as "CHANNEL_INTERFERENCE" (corresponding to channel interference attack); an attack target identifier target_id of string type, such as "Node_671"; an attack parameter parameters of object type, whose internal fields vary dynamically according to attack_type, such as {"delay_ms": 100, "packet_loss_rate": 0.1}; and an attack schedule schedule of object type, containing start_time and end_time fields.
[0066] 2.3: Establishing a Security Mechanism: To ensure the security of the open access layer, a complete security mechanism is established in this step:
[0067] At the authentication level, all external tools accessing the target API or message queue must provide a pre-assigned API key (API Key) or authentication token (Token) for identity verification.
[0068] At the authorization level, the target implements Role-Based Access Control (RBAC) internally, binding different operation permissions to different API keys or user roles, for example, a certain key only has the permission to subscribe to status data, but not to execute attack instructions.
[0069] At the transmission level, all communication channels are forced to use TLS1.2 and above protocols for end-to-end encryption to ensure the confidentiality and integrity of data during transmission.
[0070] At the same time, the gateway layer of the interface performs strict legality verification and input purification on all received data packets, such as checking whether attack_type is in the allowed enumeration list and whether delay_ms and other parameters are valid values, to prevent format errors or malicious payloads from damaging the target simulation engine itself.
[0071] Step 3: Establishing Real-time Mapping of Attacks to Physical Effects and State Feedback Mechanism; The core of this step is to establish a bridge connecting the network information domain and the industrial physical domain, accurately and in real time converting abstract attack instructions initiated by external tools into physical effects in the simulation environment, and being able to feedback the consequences of the physical effects as data, thus forming a causal response and data verification loop between attack behavior and its physical consequences; Specifically:
[0072] 3.1: Subscription and Legitimacy Verification of Attack Instructions;
[0073] The attack instruction issued by the external tool is received by the joint simulation coordinator and is verified;
[0074] Step 3.1.1, the joint simulation coordinator (such as FNCS) continuously listens to and subscribes to the logical communication channel (such as API endpoint / api / attack / execute) defined in step 2.1.2.
[0075] Step 3.1.2, when receiving attack instruction data, the coordinator does not immediately resolve, but first performs a strict legality verification process, including:
[0076] (1) Format and syntax verification; verify whether the attack instruction data conforms to the data format (such as JSON or Protobuf) defined in step 2.2;
[0077] (2) Semantic and state verification; that is, verify the validity of the instruction content, for example, check whether the attack target ID (such as "Node_671") in the instruction exists in the current physical system simulation model (such as GridLAB-D), and whether the attack type (such as "LOAD_INJECTION") is supported by the mapping library. Only instructions that pass double verification are considered legal instructions and their structured information is extracted for subsequent conversion.
[0078] 3.2: Instruction conversion based on mapping library; for the structured attack instruction information parsed in step 3.1, through the preset "attack-physical effect mapping library", the abstract network attack instruction in it is converted into specific operation instructions that can be recognized and executed by the physical system simulator.
[0079] In the simulation environment constructed in step 1, an "attack-physical effect mapping library" is built in. The mapping library is a set of key-value pairs that records the mapping rules of different types of attacks to physical simulation operations. Among them, the "key" is the attack type (attack_type) in the external attack instruction, and the "value" is an object that defines detailed conversion rules. Preferably, the mapping library is stored in the form of a JSON or YAML file.
[0080] Taking an "evil injection of false load" attack as an example, an entry in the mapping library can be defined as follows:
[0081] "LOAD_INJECTION":{"target_simulator":"GridLAB-D","target_function":"set_power_value","parameter_map":{"target_id":"object_name","power_change_kw":"value"}}
[0082] This entry is interpreted as: when an attack of type LOAD_INJECTION is received, a function named set_power_value in the simulator named GridLAB-D should be invoked, and the value of the target_id field in the attack instruction should be mapped to the object_name parameter of this function, and the value of the power_change_kw field should be mapped to the value parameter.
[0083] In this way, the mapping library specifies the equivalent operation in the physical world for each type of network attack behavior, including channel jamming, message replay, injection attacks, and other attack types. This conversion process can be formally represented as:
[0084] A sim = F map (C attack );
[0085] where A sim is the converted simulation operation instruction that can be executed in the physical simulator, F map represents the conversion function corresponding to the attack instruction in the mapping library, and C attack is the structured attack instruction information parsed in step 3.1. A sim preferably includes the identification of the target simulator, the specific function or method name to be invoked, and the parameters required to execute the operation.
[0086] 3.3: Scheduling and execution of physical effects; the simulation operation instruction A sim is assigned to the target physical system simulator, and the simulator executes this simulation operation instruction at the next synchronization time step and updates the physical system state.
[0087] Step 3.3.1, after completing the instruction conversion, the coordinator immediately assigns the simulation operation instruction to the target physical system simulator (such as GridLAB-D) according to the target simulator identifier contained in A sim .
[0088] Step 3.3.2, after receiving the instruction, the physical system simulator executes the simulation operation at the next synchronization time step, thereby changing the state of one or more physical models within it.
[0089] The state set here represents the set of all internal parameters of all physical objects (such as lines, loads, transformers, etc.) being modeled in the physical system simulator at time step t. The state update process can be represented as:
[0090] S t+1 = f exec (S t , A sim );
[0091] Where S t and S t+1 represent the state set of the physical model at the current time step t and the updated next time step respectively. f exec () represents the function of the physical system simulator executing A sim .
[0092] 3.4: Capture and publish of physical state; Capture the state change of the physical system and feed the state change to external tools through standardized format.
[0093] Step 3.4.1, after the simulation operation instruction is executed and the system state is updated to S t+1 , the co-simulation coordinator immediately queries the virtual sensor state change associated with the affected device from the physical system model.
[0094] The "virtual sensor state change" here specifically refers to the numerical change of the key state parameters inside the physical model, for example, in the power distribution network scenario, it may represent the node voltage changing from 7200V to 6900V, or the line active power changing from 3200kW to 4000kW. The co-simulation coordinator captures and needs to package the latest, absolute state data (i.e. 6900V or 4000kW) after the attack occurs, rather than the state change amount (-300V or +800kW), because the absolute state data is more complete and reliable.
[0095] Step 3.4.2, the coordinator encapsulates these captured latest state data according to the standard data format defined in step 2.2, and publishes it to the designated state feedback communication channel (such as the sim.feedback.voltage topic of MQ). External attack or defense tools can understand the physical consequences caused by their behavior in real time by subscribing to this channel, providing data basis for the next step of decision making, thus completing the complete transaction flow from instruction issuance to effect observation.
[0096] Step 4, establish an automated backup and recovery mechanism; Establish an automated target range reset mechanism to completely save and restore the state of the entire simulation environment
[0097] 4.1: Define the complete set of target field states and snapshot mechanism
[0098] Define the target field states that need to be saved and restored, and capture the states through the snapshot mechanism. Specifically:
[0099] 4.1.1: Complete set of target field states S env composed of the states of individual core components of the simulation environment:
[0100] S env = {S phy , S net , S coord};
[0101] where S phy represents the state set of the physical system simulator (such as GridLAB-D), specifically the complete parameters of all physical model objects in the simulator memory; S net is the state set of the communication network simulator (such as NS-3), which includes the network topology, node configuration, and internal event queue state; S coord is the state set of the joint simulation coordinator (such as FNCS), including the current global simulation timestamp and the cross-domain event queue to be processed.
[0102] Step 4.1.2, establish snapshot mechanism
[0103] Define snapshot function F snapshot : When receiving a backup instruction, the joint simulation coordinator broadcasts a "synchronous pause" instruction to the simulators (including the physical system simulator and the communication network simulator), causing all simulators to pause at the same simulation time point t'.
[0104] Then call the built-in state export interface of each simulator to export the state data files of S phy and S net of the simulator; at the same time, export the S coord state data file of the coordinator itself;
[0105] Finally, compress the state data files of S phy , S net and S coord along with a metadata file into a historical state snapshot compressed package (such as snap_timestamp.tar.gz). The metadata file contains the timestamp, description information, and SHA256 hash value for integrity verification.
[0106] As an optional step in this embodiment, it also supports formulating and executing business-associated backup strategies; trigger backup operations according to different business scenarios and coordinate backup strategy priorities;
[0107] Backup strategies include event-triggered strategies, periodic strategies, and manual triggering strategies, among which:
[0108] Event triggering strategy: Monitor the logical communication channel defined in step 2. When a preset triggering event E associated with a specific business scenario occurs... trigger When detected, a snapshot backup will be automatically executed.
[0109] Periodic strategy: Automatically perform snapshot backups according to the set time period for disaster recovery and progress preservation;
[0110] Users can manually trigger backup operations to meet specific needs.
[0111] The priority order of this backup strategy is manual triggering, event triggering, and periodic triggering. To prevent excessively frequent backups, the backup strategy in this embodiment also employs a mutex mechanism: when any snapshot task (regardless of the triggering strategy) begins execution, a mutex is activated, temporarily blocking other new, lower-priority backup requests until the current task is completed and a preset "cooldown time" (e.g., 5 minutes) has elapsed, in order to avoid high-frequency snapshot operations impacting system resources.
[0112] As an optional step in this embodiment, a recovery management function is also provided, allowing users to independently select any snapshot from the historical state snapshot set for recovery. This recovery process is performed by a recovery function F that includes a fault-tolerant mechanism. recover Automated execution;
[0113] When a recovery command is received, all current simulation processes are terminated;
[0114] Decompress the snapshot file Snap(k) at the specified time k, and verify the integrity of all decompressed files using the SHA256 hash value stored in the snapshot file. If the verification fails, the recovery process is immediately aborted and the user is notified that the snapshot file is corrupted, thus avoiding recovery from a corrupted data source. If the verification passes, F... recover According to the complete set S of the target range state at snapshot time k env The definition of (k) calls the state import interfaces of each simulator and coordinator respectively, and imports S phy (k), S net (k) and S coord The state of (k) is restored to the corresponding module. If any step in the recovery process fails, the recovery process is terminated, and the loaded partial state is cleaned up to prevent the range from entering an inconsistent "half-recovery" state.
[0115] After the recovery is completed, the entire target environment will be accurately returned to the state at time k, and the simulation can continue from this time point.
[0116] Embodiment Two
[0117] The embodiment provides an industrial control security target field construction system based on a digital twin technology, and uses a specific implementation of the industrial control security target field construction method described in Embodiment One. The system includes a digital twin simulation module, an interface management module, a real-time interaction module, and a state recovery module.
[0118] The digital twin simulation module is used to construct a digital twin simulation environment for an actual industrial scene, including physical system modeling, communication network modeling, and collaborative simulation modeling. This module constructs a high-fidelity simulation environment that integrates industrial physical system models and communication network models.
[0119] The interface management module is used to define the interaction interface between the simulation environment and external tools, including selecting a communication mode according to data exchange requirements, defining a logical communication channel based on the selected communication mode, and standardizing the data exchange format. This module provides a standardized access interface to enable the docking of external attack simulation tools or security defense tools with the simulation environment.
[0120] The real-time interaction module is used to convert attack instructions initiated by external tools into simulation operation instructions in the simulation environment through the interaction interface, and to feed back the physical state changes caused by the simulation operation instructions to the external tools. This module is used to establish real-time mapping and closed-loop interaction between network attack behavior and physical effects in the simulation environment.
[0121] The state recovery module is used to establish an automated target field reset mechanism to backup and restore the state of the simulation environment through a snapshot mechanism. This module is used to perform automated state backup and recovery operations on the simulation environment to achieve rapid resetting of the test scene.
[0122] The present application solves the problems of low simulation degree and closed tool ecosystem of existing target fields by constructing a high-fidelity digital twin simulation environment and combining standardized modular access interfaces. At the same time, its unique automated state backup and recovery mechanism greatly improves the test efficiency of attack and defense drills, shortening the scene reset time from several hours to minutes, which helps to achieve high-frequency and iterative automated security verification of complex industrial control systems in a safe, controllable, and low-cost environment.
[0123] It should be pointed out finally that the above embodiments are only used to illustrate the technical solutions of the present application but not to limit it, and although the present application has been described in detail with reference to the above embodiments, it should be understood by those skilled in the art that the specific embodiments of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. A method for constructing an industrial control safety target range based on digital twin technology, characterized in that, Comprise: Constructing a digital twin simulation environment for actual industrial scenarios, including physical system modeling, communication network modeling, and collaborative simulation modeling; Defining the interaction interface between the simulation environment and external tools, including selecting a communication mode according to data exchange requirements, defining a logical communication channel based on the selected communication mode, and standardizing the data exchange format; Through the interaction interface, convert the attack instruction initiated by the external tool into a simulation operation instruction in the simulation environment, and feed back the physical state change caused by the simulation operation instruction to the external tool; Establish an automated target range reset mechanism to backup and restore the state of the simulation environment through the snapshot mechanism.
2. The industrial control security target range construction method based on digital twin technology according to claim 1, characterized in that: The physical system modeling simulates the physical behavior of hardware devices in the actual industrial scenario through a physical system simulator; the communication network modeling simulates the data exchange and network communication between hardware devices through a communication network simulator model; The collaborative simulation modeling is used to coordinate the cross-domain data events between the physical system simulator and the communication network simulator; the physical system simulator and the communication network simulator publish the physical state and communication data as key values to the joint simulation coordinator, and both of them obtain the real-time corresponding values by subscribing to the keys of the other party in the joint simulation coordinator.
3. The construction method of the industrial control safety target range based on the digital twin technology according to claim 1, characterized in that, Select a communication mode according to data exchange requirements, including: For the data exchange scene that the data transmission is more than T 数据传输 per second and the response time requirement is within Δt, the asynchronous message queue mode is selected; in the asynchronous message queue mode, different data flow topics are defined as logical communication channels; For instruction interaction scenarios that respond to single operations and require immediate confirmation, use the synchronous RESTful mode; in the synchronous RESTful mode, define operation endpoints as logical communication channels.
4. The construction method of the industrial control safety target range based on the digital twin technology according to claim 1, characterized in that, The process of converting attack instructions into simulation operation instructions includes: The joint simulation coordinator accepts attack instruction data issued by the external tool and performs verification, including format and syntax verification, semantic and state verification; attack instruction data that passes the verification will be parsed into structured attack instruction information; Through the built-in attack-physical effect mapping library in the simulation environment, extract the simulation operation instruction corresponding to the structured attack instruction information; Dispatch the simulation operation instruction to the target physical system simulator and execute it at the next synchronization time step; after executing the simulation operation instruction, update the physical system state; The joint simulation coordinator captures the updated physical state data, encapsulates it according to the defined standardized data exchange format, and publishes it to the corresponding logical communication channel to feed back to the external tool.
5. The industrial control security target range construction method based on digital twin technology according to claim 1, characterized in that: The state of the simulation environment is represented by a complete set of range states, S env comprises: S env = {S phy , S net , S coord}; where S phy represents the state set of the physical system simulator, including the parameters of all physical model objects in the physical system simulator memory; S net represents the state set of the communication network simulator, including the state of network topology, node configuration and internal event queue; S coord represents the state set of the joint simulation coordinator, including the simulation timestamp and the to-be-processed cross-domain event queue.
6. The construction method of the industrial control safety target range based on the digital twin technology according to claim 1, characterized in that, Backup the state of the simulation environment through the snapshot mechanism, including: When receiving the backup instruction, the joint simulation coordinator broadcasts a synchronization pause instruction to all simulators, so that the state of all simulators is paused at the same simulation time point t'; Each simulator derives a state set S of itself at simulation time point t' phy (t') and S net (t'), the joint simulation coordinator derives a state set S of itself at simulation time point t' coord (t'); S phy (t'), S net (t') and S coord (t') are compressed and stored as a history state snapshot package together with the metadata file.
7. The construction method of the industrial control safety target range based on the digital twin technology according to claim 1, characterized in that, Restore the state of the simulation environment through the snapshot mechanism; When receiving the recovery instruction, terminate the current simulation process; for the historical state snapshot compression package Snap(k) at time k, perform integrity verification on all files using the hash value stored in Snap(k) after decompression; If the check passes, the physical state simulator, the communication network simulator and the joint simulation coordinator restore the state set of the corresponding module to the state set at time k.
8. An industrial control safety range construction system based on digital twin technology, calling the industrial control safety range construction method according to any one of claims 1-7, characterized in that, The system comprises: a digital twin simulation module for constructing a digital twin simulation environment for an actual industrial scene, including physical system modeling, communication network modeling and collaborative simulation modeling; an interface management module for defining an interaction interface between the simulation environment and external tools, including selecting a communication mode according to data exchange requirements, defining a logical communication channel based on the selected communication mode and standardizing data exchange formats; a real-time interaction module for converting attack instructions initiated by external tools into simulation operation instructions in the simulation environment through the interaction interface, and feeding back physical state changes caused by the simulation operation instructions to the external tools; a state recovery module for establishing an automated target range reset mechanism to back up and restore the state of the simulation environment through a snapshot mechanism.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The computer program, when loaded into a processor, implements the industrial control security target range construction method according to any one of claims 1-7.
10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1-9. The computer program, when executed by a processor, implements the industrial control security target range construction method according to any one of claims 1-7.
Citation Information
Patent Citations
Digital twin simulation method, system, device and server
CN115544672A
Network security target range construction system and method of power system
CN115811472A
Digital twinning-based monopoly situation prediction method and device
CN119168699A
Cited By
Road traffic network safety target range construction method based on MCP protocol
CN121309185A
Ship network security target range simulation device based on digital twinning and experimental platform
CN121690732A