Security assessment method and system for industrial control system of industrial computer
By conducting a comprehensive analysis and evaluation of the security protection information of industrial control systems, a security assessment report is generated, and protection strategies are matched and optimized. This resolves compatibility errors during system updates, improves security protection efficiency, and reduces costs.
Patent Information
- Application Number
- CN202511143114.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-11-21
AI Technical Summary
Because the industrial control system has not been updated for a long time, vulnerabilities exist in various aspects of the system. When it is updated again, compatibility errors and other problems are likely to occur, which means that the industrial control system needs to spend a lot of time and effort to complete the entire update.
This paper provides a security assessment method and system for industrial computer control systems. By acquiring enterprise security protection information, analyzing and evaluating it, generating a security assessment report, matching initial protection information, performing compatibility, protection balance and cost analysis, generating security protection strategies, and generating security protection upgrade information based on the target strategy selected by the enterprise.
It resolves vulnerabilities caused by long-term lack of updates to industrial control systems, reduces compatibility errors during the update process, improves the efficiency and accuracy of security protection, and reduces the time and effort costs of updates.
Smart Images

Figure CN120993886A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial control, and particularly relates to a safety evaluation method and system of an industrial computer industrial control system. BACKGROUND
[0002] Industrial control system (ICS) refers to a computer system and network used for monitoring and controlling production and industrial processes. ICS is an important part of national critical infrastructure and is widely used in energy, transportation, communication, water conservancy, environmental protection, military and other fields. It plays a crucial role in the country's economy, security and development. Ensuring the stable operation of ICS is of great importance to the development and security of the country. The functional safety and information safety of industrial control system are very important, because system failure or attack may cause production interruption, equipment damage or production safety accidents and other serious consequences. By conducting integrated risk assessment of functional safety and information safety, potential safety hazards and risks can be found, and timely measures can be taken to repair and strengthen, so as to ensure the safety of ICS, improve the robustness and reliability of ICS, reduce the operation cost of ICS, and enhance the competitiveness of enterprises in the market.
[0003] Due to the specific design and operation environment of ICS, the devices in ICS often operate according to the state at the first time of setting, and rarely update. With the improvement of network attack means, there are a large number of unpatched vulnerabilities in industrial control system, which may be exploited by attackers to launch attacks on devices. Due to the long-term non-update of industrial control system, there are vulnerabilities in various aspects of the system. When updating again, compatibility errors and other problems may occur, which may lead to the need for a large amount of time and effort to complete the entire update of the industrial control system to complete the protection settings to ensure system security. Meanwhile, in the ICS information layer, various devices or hosts are connected through communication networks, and cooperate and depend on each other to complete complex system functions. As the carrier of data interaction, communication network also becomes the way of attack propagation. Network attacks can be propagated within and between levels of the information layer through communication networks, increasing the security risk of the system.
[0004] Therefore, the present application provides a safety evaluation method and system of an industrial computer industrial control system to solve the above problems. SUMMARY
[0005] In view of the above, in order to overcome the defects of the prior art, the present application provides a safety evaluation method and system for an industrial computer control system, to solve the above problems that due to the long-term non-updating of the industrial control system, vulnerabilities exist in various aspects of the system, and when updating again, compatibility errors are prone to occur, thereby causing the industrial control system to need to spend a lot of time and effort to complete the entire updating.
[0006] In order to achieve the above-mentioned purpose, the technical scheme adopted by the present application is:
[0007] In a first aspect, the present application provides a safety evaluation method for an industrial computer control system, comprising: obtaining safety protection information of each module of an industrial control system of an enterprise; analyzing the safety protection information to obtain a safety evaluation report containing a list of safety protection problems of each module; matching a plurality of initial protection information according to the list of safety protection problems based on a preset safety protection graph; based on the safety protection information, analyzing the compatibility, protection balance and cost of each initial protection information to obtain a plurality of safety protection strategies for different modules in different cost intervals; obtaining a target safety protection strategy selected by the enterprise; matching corresponding protection measure information from the preset safety protection graph according to the target safety protection strategy; and generating corresponding safety protection upgrade information according to the protection measure information and the current safety protection information.
[0008] Preferably, the safety protection information of each module of the industrial control system of the enterprise is obtained, comprising: obtaining initial topology architecture information and interview information of process personnel of the safety protection of the industrial control system; obtaining firmware version information and communication link information of the industrial control system; and integrating the initial topology architecture information, the interview information, the firmware version information and the communication link information to obtain the safety protection information.
[0009] Preferably, the safety protection information is analyzed to obtain a safety evaluation report containing a list of safety protection problems of each module, comprising: obtaining a list of problems of the firmware version information and the communication link information from the corresponding manufacturer platform and / or professional exchange platform according to the firmware version information and the communication link information in the safety protection information, and generating a first safety analysis report; performing topology structure analysis on the safety protection information to determine a safety protection knowledge graph of the current industrial computer control system; comparing the preset safety protection graph and the safety protection knowledge graph to determine the security vulnerabilities lacking in the current industrial computer control system and the security vulnerabilities between layers, and obtaining a second safety analysis report; and integrating the first safety analysis report and the second safety analysis report to obtain the safety evaluation report containing the list of safety protection problems.
[0010] Preferably, the topology analysis of the security protection information determines the security protection knowledge graph of the current industrial computer system, comprising: optimizing the initial topology architecture information according to the interview information to obtain first topology architecture information; performing physical topology analysis, logical topology analysis, protocol level topology analysis, business function analysis and security domain division analysis on the first topology architecture information, and outputting the corresponding device distribution map with coordinates, cross-subnet communication relationship matrix, protocol dependency topology graph, control bribe calling topology graph and security partition compliance heat map; and fusing the device distribution map, cross-subnet communication relationship matrix, protocol dependency topology graph, control bribe calling topology graph and security partition compliance heat map to obtain the security protection knowledge graph.
[0011] Preferably, the comparison of the preset security protection graph and the security protection knowledge graph determines the security vulnerabilities lacking in the current industrial computer system and the security vulnerabilities between layers, and obtains a second security analysis report, comprising: superimposing and comparing the preset security protection graph and the security protection knowledge graph to obtain a difference protection graph; performing attack and defense simulation on the protection wall corresponding to the security protection knowledge graph based on a preset attack and defense simulation model to obtain a blocking analysis report; and using a hierarchical penetration testing method to penetrate and verify the horizontal and vertical interaction interfaces of the bus layer, control layer, monitoring layer and enterprise layer in the security protection knowledge graph to obtain a penetration verification result; and integrating the difference graph, the blocking analysis report and the penetration verification result to obtain the second security analysis report.
[0012] Preferably, the matching of the plurality of initial protection information according to the security protection problem list based on the preset security protection graph comprises: classifying the security problem list according to asset type, protocol type and vulnerability severity to obtain a first problem list classified according to type; and calling corresponding protection components from the preset security protection graph according to the problem type and the first problem list to obtain the plurality of initial protection information.
[0013] Preferably, the compatibility, protection balance and cost analysis of each initial protection information based on the security protection information obtains a plurality of security protection strategies for different modules in different cost intervals, comprising: compatibility matching of the security protection information and each initial protection information to screen out first protection information without interference; analyzing the protection balance of the first protection information to obtain second protection information sorted according to balance level; randomly collocating each second protection information based on the problem coverage principle to obtain an initial security protection strategy; and compatibility analysis and cost analysis of the initial security protection strategy to obtain security protection strategies in different cost intervals.
[0014] Preferably, the matching corresponding protection measure information from the preset security protection graph according to the target security protection strategy comprises: adopting a multi-relation traversal method based on a knowledge graph to match a protection measure node of the target security protection strategy; determining a plurality of initial target protection measure nodes according to a relationship between the protection measure node and a constraint condition; performing risk reduction degree, implementation complexity and maintenance cost analysis on the initial target protection measure nodes to obtain the initial target protection measure nodes in scoring order; adopting a greedy algorithm to process the initial target protection measure nodes in scoring order to determine a target protection measure node; and determining the protection measure information according to the target protection measure node.
[0015] Preferably, the generating corresponding security protection upgrade information according to the protection measure information and the current security protection information comprises: integrating the security protection information and the protection measure information to generate complete security protection information in a format matched with the security protection information; determining upgrade file information that needs to be supplemented in the security protection information according to a file difference between the complete security protection information and the security protection information; and generating corresponding security protection upgrade information according to the upgrade file information.
[0016] In a second aspect, the present application provides a security evaluation system of an industrial computer system, comprising: a security evaluation module, which acquires security protection information of each module of an industrial control system of an enterprise; analyzes the security protection information to obtain a security evaluation report containing a list of security protection problems of each module;
[0017] a strategy matching module, which matches a plurality of initial protection information according to the list of security protection problems based on a preset security protection graph; and performs compatibility, protection balance and cost analysis on each initial protection information based on the security protection information to obtain a plurality of security protection strategies for different modules in different cost intervals;
[0018] a protection upgrade module, which acquires a target security protection strategy selected by the enterprise; matches corresponding protection measure information from the preset security protection graph according to the target security protection strategy; and generates corresponding security protection upgrade information according to the protection measure information and the current security protection information.
[0019] The present application has the following beneficial effects:
[0020] 1、The present application can comprehensively analyze the security protection information of each module of the current industrial computer industrial control system of the enterprise, determine the problem list of the current industrial computer industrial control system, and then determine the initial security protection information for solving the problems in the problem list in combination with the preset security protection graph; the compatibility, protection balance and cost of each initial protection information are analyzed to obtain a plurality of security protection strategies for different modules in different cost intervals; finally, the target security protection strategy selected by the enterprise is obtained; according to the target security protection strategy, the security protection upgrade information of the current industrial computer industrial control system is generated, and the security protection upgrade of the industrial computer industrial control system is completed. Through the above-mentioned mode, the present application solves the problem that the industrial control system has not been updated for a long time, resulting in vulnerabilities in all aspects of the system, and when updating again, compatibility errors and other problems are prone to occur, and the industrial control system needs to spend a lot of time and effort to complete the entire update.
[0021] 2、The present application can comprehensively analyze the security protection information of the industrial control system, obtain a security evaluation report containing a security protection problem list of each module, evaluate the security protection problems of the current industrial computer industrial control system, and then repair the problems in the subsequent targeted repair to improve the security protection of the industrial computer.
[0022] 3、The present application can comprehensively and objectively analyze the topology structure of the security protection information, construct the security protection knowledge graph of the current industrial computer industrial control system, and facilitate the subsequent vulnerability analysis of the security protection knowledge graph, which is helpful for the subsequent targeted protection repair. BRIEF DESCRIPTION OF DRAWINGS
[0023] Figure 1 The present application is an industrial computer industrial control system security evaluation method.
[0024] Figure 2 The present application is an industrial computer industrial control system security evaluation system. DETAILED DESCRIPTION
[0025] The following will be described with reference to the accompanying drawings Figure 1 and the accompanying drawings Figure 2 The embodiments of the present application will be described in detail. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present application, and are not intended to limit the protection scope of the present application.
[0026] A security evaluation method for an industrial computer industrial control system, as shown in FIG. 1, includes the following steps: Figure 1
[0027] Step S11: Obtain the security protection information of each module of the industrial control system of the enterprise.
[0028] Preferably, each module refers to each module of the computer industrial control system of the enterprise, which is divided into a field device layer, a control layer, a monitoring layer, an enterprise layer, and a security management layer according to functions.
[0029] The protection setting information of the industrial control system of the enterprise in the security protection aspect is acquired, including a vulnerability scanning tool, a device scanner, a communication protocol of a device layer and a software layer, unencrypted plaintext transmission, a communication protection tool, configuration information of a device and a host, state information of an operating system, control logic, and the like, so as to facilitate subsequent comprehensive evaluation of the security protection information, discovery of system vulnerabilities of the industrial control system in the security protection aspect, and targeted repair according to the vulnerabilities.
[0030] Step S12: analyzing the security protection information to obtain a security evaluation report containing a security protection problem list of each module.
[0031] According to the control logic, the device model, the communication protocol, and the protection tool involved in the security protection information, the problems existing in the security protection information are acquired from manufacturers or professional analysis websites corresponding to the device model, the communication protocol, and the protection tool, and a first security analysis report is generated according to the protection information of the security protection information and the problems existing in the security protection information. The security protection information is subjected to type analysis and compatibility analysis to determine a security protection knowledge graph of the current industrial computer industrial control system; based on a preset security protection graph and a protection structure of the security protection knowledge graph of the current industrial computer industrial control system, security vulnerabilities and lacking security vulnerabilities between the layers of the current industrial computer industrial control system are determined, and a second security analysis report is obtained; the first security analysis report and the second security analysis report are de-duplicated and integrated to obtain a security evaluation report containing a security protection problem list.
[0032] Step S13: based on the preset security protection graph, matching a plurality of initial protection information according to the security protection problem list;
[0033] The preset security protection graph is established based on the most comprehensive and objective security protection technical means and tools possessed by each aspect; according to the problems existing in the security protection problem list, technical tools, communication protection protocols, and / or permission setting methods for solving the problems are matched from the preset security protection graph.
[0034] Step S14: based on the security protection information, performing compatibility, protection balance, and cost analysis on each initial protection information to obtain a plurality of security protection strategies for different modules in different cost intervals;
[0035] On the basis of the security protection information of the current industrial computer system, the first batch of first protection information meeting the compatibility condition is selected from the initial protection information according to the compatibility matching of the security protection information and the initial protection information; then, the initial security protection strategy is obtained by randomly matching the first protection information according to the rule that all problems in the list of security protection problems can be solved under the premise of compatibility matching between the first protection information; the cost analysis is carried out according to the tools, communication protection protocols and the like in the initial security protection strategy, and the module matching of the initial security protection strategy is carried out according to the modules of the current industrial computer system, so as to obtain a plurality of security protection strategies for different modules in different cost intervals.
[0036] Step S15: obtaining the target security protection strategy selected by the enterprise; and matching the corresponding protection measure information from the preset security protection graph according to the target security protection strategy.
[0037] After the enterprise is shown the security protection strategies in different cost intervals, the enterprise selects the acceptable cost interval according to its own situation, determines the target security protection strategy selected by the customer, and then matches the corresponding protection measure information from the preset security protection graph according to the target security protection strategy, including the corresponding configuration file information, code information and equipment information of the technical tools, communication protection protocols and permission setting methods.
[0038] Step S16: generating the corresponding security protection upgrade information according to the protection measure information and the current security protection information, so as to complete the security protection upgrade of the industrial computer system.
[0039] According to the current security protection information and the protection measure information, the complete security protection information matching the format of the current security protection information is generated; then, the upgrade file information needed to be supplemented by the current security protection information is determined according to the file difference between the complete security protection information and the current security protection information; the corresponding security protection upgrade information is generated according to the upgrade file information, so as to complete the security protection upgrade of the industrial computer system.
[0040] Specifically, the present application can comprehensively analyze the security protection information of each module of the current industrial computer system of the enterprise, determine the problem list of the current industrial computer system, and then determine the initial security protection information for solving the problems in the problem list in combination with the preset security protection map. The compatibility, protection balance and cost of each initial protection information are analyzed to obtain a plurality of security protection strategies for different modules in different cost intervals. Finally, the target security protection strategy selected by the enterprise is obtained. According to the target security protection strategy, the security protection upgrade information of the current industrial computer system is generated, and the security protection upgrade of the industrial computer system is completed. Through the above method, the present application solves the problem that the industrial control system has not been updated for a long time, resulting in vulnerabilities in all aspects of the system. When updating again, compatibility errors and other problems are prone to occur, which further leads to the problem that the industrial control system needs to spend a lot of time and effort to complete the entire update.
[0041] In an embodiment of the present application, the security protection information of each module of the industrial control system of the enterprise is obtained, including: obtaining the initial topology architecture information and the interview information of the process personnel of the industrial control system security protection; obtaining the firmware version information and the communication link information of the industrial control system; integrating the initial topology architecture information, the interview information, the firmware version information and the communication link information to obtain the security protection information.
[0042] The protection setting information of the industrial control system of the enterprise in the aspect of security protection includes a vulnerability scanning tool, a device scanner, a device layer and a software layer communication protocol, an unencrypted plaintext transmission, a communication protection tool, configuration information of devices and hosts, state information of an operating system, control logic, etc., which facilitates subsequent comprehensive evaluation of these security protection information, discovery of system vulnerabilities of the industrial control system in the aspect of security protection, and targeted repair according to the vulnerabilities.
[0043] Specifically, Zeek or Suricata is used to analyze the traffic metadata of the industrial control system, draw a real communication link, and obtain the communication link information. The initial topology architecture information is the topology architecture information when the industrial control system is initialized, which is the final version before formal use. Checksum comparison tool is used to identify the version information of the firmware. The interview information of the process personnel is obtained to understand the priority of the attack surface and the main framework information of the industrial control system. Finally, the security protection information is obtained by integrating the above information.
[0044] Through the above embodiments, the present application can comprehensively and objectively obtain the security protection information of each module of the industrial control system, providing a data basis for subsequent security evaluation and targeted data update.
[0045] In an embodiment of the present application, the security protection information is analyzed to obtain a security evaluation report containing a security protection problem list of each module, including: according to the firmware version information and the communication link information in the security protection information, obtaining a problem list of the firmware version information and the communication link information from a corresponding manufacturer platform and / or a professional exchange platform, and generating a first security analysis report; performing topology analysis on the security protection information to determine a security protection knowledge graph of the current industrial computer system; comparing the preset security protection graph and the security protection knowledge graph to determine security vulnerabilities lacking in the current industrial computer system and security vulnerabilities between layers, and obtaining a second security analysis report; and integrating the first security analysis report and the second security analysis report to obtain the security evaluation report containing the security protection problem list.
[0046] Preferably, the firmware version information includes a device model, a protection tool, etc. The communication link information includes a communication protocol, a communication control logic, etc.
[0047] Specifically, according to the control logic, the device model, the communication protocol, and the protection tool involved in the security protection information, the problems existing in these security protection information are obtained from the manufacturers or professional analysis websites corresponding to the device model, the communication protocol, and the protection tool, and the first security analysis report is generated according to the protection information of these security protection information and the problems existing in these security protection information. The security protection information is analyzed to determine a security protection knowledge graph of the current industrial computer system; based on the protection structure of the preset security protection graph and the security protection knowledge graph of the current industrial computer system, the security vulnerabilities between layers and the security vulnerabilities lacking in the current industrial computer system are determined, and a second security analysis report is obtained; and the first security analysis report and the second security analysis report are de-duplicated and integrated to obtain the security evaluation report containing the security protection problem list.
[0048] Through the setting mode of the embodiment, the security protection information of the industrial computer system can be analyzed in all directions, the security evaluation report containing the security protection problem list of each module is obtained, the security protection problems of the current industrial computer system are evaluated, and subsequent targeted repair can be performed for these problems to improve the security protection of the industrial computer.
[0049] In an embodiment of the present application, the security protection information is subjected to topology analysis to determine a security protection knowledge graph of the current industrial computer system, including: optimizing initial topology architecture information according to interview information to obtain first topology architecture information; performing physical topology analysis, logical topology analysis, protocol level topology analysis, business function analysis and security domain division analysis on the first topology architecture information to output corresponding device distribution map with coordinates, cross-subnet communication relationship matrix, protocol dependency relationship topology map, control loop call topology map and security partition compliance heat map; and fusing the device distribution map, cross-subnet communication relationship matrix, protocol dependency relationship topology map, control loop call topology map and security partition compliance heat map to obtain the security protection knowledge graph.
[0050] For example, the SolarWinds NPM tool is used to collect the switch ARP table + LLDP / CDP adjacency relationship + port mirroring traffic to output the device distribution map with coordinates; the Zeek+Splunk ES tool is used to analyze the NetFlow / sFlow log and establish an IP-MAC-port mapping table, and the IP-MAC-port mapping table is processed to finally output the cross-subnet communication relationship matrix. The Wireshark+Scapy script tool is used for deep packet analysis to extract the master-slave relationship chain of Modbus / PROFINET / DNP3 protocols to output the protocol dependency relationship topology map; the MATLAB Stateflow tool is used to analyze the business function of the first topology architecture information, and the process DCS system SAMA graph reverse engineering and HMI operation sequence tracking method are used to output the control loop call topology map; the Palo Alto Panorama tool is used to reversely analyze the existing firewall strategy and compare with the VLAN configuration table to output the security partition compliance heat map. Then, the device distribution map, cross-subnet communication relationship matrix, protocol dependency relationship topology map, control loop call topology map and security partition compliance heat map are subjected to multi-dimensional topology fusion to obtain the security protection knowledge graph.
[0051] Through the above embodiments, the present application can comprehensively and objectively analyze the security protection information, construct the security protection knowledge graph of the current industrial computer system, facilitate subsequent vulnerability analysis of the security protection knowledge graph, and help subsequent targeted protection repair.
[0052] In an embodiment of the present application, the preset security protection graph and the security protection knowledge graph are compared to determine the security vulnerabilities that the current industrial computer system lacks and the security vulnerabilities between layers, and a second security analysis report is obtained, including: superimposing and comparing the preset security protection graph and the security protection knowledge graph to obtain a difference protection graph; performing attack and defense simulation on the protection wall corresponding to the security protection knowledge graph based on the preset attack and defense simulation model to obtain a blocking analysis report; and using a hierarchical penetration testing method to penetrate and verify the horizontal and vertical interaction interfaces of the bus layer, the control layer, the monitoring layer and the enterprise layer in the security protection knowledge graph to obtain a penetration verification result; and integrating the difference graph, the blocking analysis report and the penetration verification result to obtain the second security analysis report.
[0053] Specifically, the ideal preset security protection graph and the actual security protection knowledge graph of the industrial control system are subjected to ternary group difference analysis of nodes-edges-attributes to obtain a difference protection graph; and a preset attack and defense simulation model based on current attack means and simulation technology is used to simulate the attack and defense of the protection means corresponding to the security protection knowledge graph to obtain a blocking analysis report of the actual security protection knowledge graph, deduce potential attack chains based on real topology, and verify the blocking ability of existing protection measures. The horizontal and vertical interaction interfaces of the field bus layer, the control layer, the monitoring layer and the enterprise layer are subjected to penetration verification. The difference graph, the blocking analysis report and the penetration verification result are integrated to obtain the second security analysis report.
[0054] In the above manner, the present application can find multiple vulnerabilities of the industrial control system, for example, multiple PLCs (S7-1500 / 1200 series) are directly exposed to the factory local area network; the main switch has no HA backup, and a single point failure can cause the entire network to be paralyzed; a certain engineer station accesses the Internet in violation of regulations and does not deploy USB peripheral control; some PLCs still use the factory password (such as "siemens") and do not have a mandatory modification policy; the engineer station can directly access the safety controller (Safety Controller), which violates the "least privilege" principle; the clock deviation of some devices exceeds 5 seconds, resulting in invalid log auditing, etc.
[0055] In an embodiment of the present application, based on the preset security protection graph, a plurality of initial protection information is matched according to the security protection problem list, including: classifying the security problem list according to asset type, protocol type and vulnerability severity to obtain a first problem list classified according to type; and calling corresponding protection components from the preset security protection graph according to the problem type and the first problem list to obtain a plurality of initial protection information.
[0056] Specifically, first, the problems in the problem list are classified according to asset types, agreement types and vulnerability severity; then, corresponding protection components are matched for the problems from the preset security protection graph; wherein, the protection components corresponding to technical measures include: encrypted communication module, agreement whitelist, access control list, etc.; the protection components corresponding to management measures include: minimum authority matrix, firmware upgrade process, log audit strategy, etc.; the protection components corresponding to physical measures include: network isolation device, optical coupling isolator, lightning surge protector, etc. After the matching of all the protection components in the first problem list and the preset security protection graph is completed, the initial matching multiple initial protection information is obtained.
[0057] In the above manner, the preset security protection graph is established based on the most comprehensive and objective security protection technical means and tools, and the technical tools, communication protection agreements and / or permission setting methods, etc. that solve the problems in the security protection problem list are matched from the preset security protection graph, which helps to determine the most suitable protection components for subsequent full-range upgrading of the security protection of the current industrial computer system used by the enterprise.
[0058] In an embodiment of the present application, based on the security protection information, the compatibility, protection balance and cost of each initial protection information are analyzed to obtain multiple security protection strategies for different modules in different cost intervals, including: the compatibility of the security protection information and each initial protection information is matched to screen out the first protection information without interference; the protection balance of the first protection information is analyzed to obtain the second protection information sorted according to the balance level; each second protection information is randomly arranged based on the problem coverage principle to obtain the initial security protection strategy; the initial security protection strategy is analyzed for compatibility and cost to obtain the security protection strategy in different cost intervals.
[0059] Specifically, based on the security protection information of the current industrial computer system, the compatibility of the security protection information and each initial protection information is matched to screen out the first batch of first protection information that meets the compatibility without interference condition from each initial protection information; then, the protection balance of the first protection information is analyzed to obtain the second protection information sorted according to the balance level according to the rating standards of whether covering all links of the attack kill chain and whether having cross-level cascading defense capability; then, each first protection information is randomly arranged according to the rule of being able to solve all problems in the security protection problem list to obtain the initial security protection strategy; under the premise that the compatibility between each first protection information is without interference or with low interference, the cost of each tool, communication protection agreement, etc. in the initial security protection strategy is analyzed, and the initial security protection strategy is matched according to the module of the current industrial computer system to obtain multiple security protection strategies for different modules in different cost intervals.
[0060] Through the above manner, the application can analyze the compatibility, protection balance and cost of each initial protection information based on the security protection information, obtain security protection strategies for different modules in different cost intervals, and intuitively see the cost required for updating the industrial control system, the corresponding security protection strategy, so as to facilitate the enterprise to determine the final target security protection strategy.
[0061] In an embodiment of the application, according to the target security protection strategy, the corresponding protection measure information is matched from the preset security protection graph, including: using a multi-relation traversal method based on a knowledge graph to match the protection measure node of the target security protection strategy; determining a plurality of initial target protection measure nodes according to the relationship between the protection measure node and the constraint condition; performing risk reduction degree, implementation complexity and maintenance cost analysis on the initial target protection measure node to obtain the initial target protection measure node sorted according to the score; using a greedy algorithm to process the initial target protection measure node sorted according to the score to determine the target protection measure node; and determining the protection measure information according to the target protection measure node.
[0062] Specifically, after the enterprise selects an acceptable cost interval according to its own situation after the enterprise is shown the security protection strategies in each cost interval, the target security protection strategy selected by the customer is determined; and then the corresponding protection measure information is matched from the preset security protection graph according to the target security protection strategy, including the corresponding configuration file information, code information and device information of the technical tool, communication protection protocol and permission setting method.
[0063] Specifically, the multi-relation traversal method based on the knowledge graph is used to match the protection measure node of the target security protection strategy, including: determining a plurality of initial target protection measure nodes according to the relationship between the protection measure node and the constraint condition; performing risk reduction degree, implementation complexity and maintenance cost analysis on the initial target protection measure node, using a weighted average method to determine the comprehensive score of the initial target protection measure node, and then obtaining the initial target protection measure node sorted according to the score; then using a greedy algorithm to process the initial target protection measure node sorted according to the score to generate a Pareto optimal solution set and provide the best solution, thereby obtaining the corresponding target protection measure node; and determining the corresponding protection measure information according to the target protection measure node.
[0064] Through the above manner, the application can match the optimal protection measure information from the preset security protection graph according to the target security protection strategy, which meets the actual needs of the enterprise.
[0065] In one embodiment of the present application, the corresponding security protection upgrade information is generated according to the protection measure information and the current security protection information, including: integrating the security protection information and the protection measure information to generate complete security protection information matching the format of the security protection information; determining the upgrade file information that needs to be supplemented for the security protection information according to the file difference between the complete security protection information and the security protection information; and generating the corresponding security protection upgrade information according to the upgrade file information.
[0066] Specifically, the complete security protection information matching the format of the current security protection information is generated by integrating the current security protection information and the protection measure information; then the upgrade file information that needs to be supplemented for the current security protection information is determined according to the file difference between the complete security protection information and the current security protection information; and the corresponding security protection upgrade information is generated according to the upgrade file information, so as to complete the security protection upgrade of the industrial computer system.
[0067] In one embodiment of the present application, the present application further provides a security evaluation system of an industrial computer system, including:
[0068] The security evaluation module acquires the security protection information of each module of the industrial control system of the enterprise; analyzes the security protection information to obtain a security evaluation report containing a list of security protection problems of each module;
[0069] The strategy matching module matches a plurality of initial protection information according to the list of security protection problems based on a preset security protection graph; and performs compatibility, protection balance and cost analysis on each initial protection information based on the security protection information to obtain a plurality of security protection strategies for different modules in different cost intervals;
[0070] The protection upgrade module acquires the target security protection strategy selected by the enterprise; matches the corresponding protection measure information from the preset security protection graph according to the target security protection strategy; and generates the corresponding security protection upgrade information according to the protection measure information and the current security protection information.
[0071] Through mutual cooperation between the above modules, the application can comprehensively analyze the security protection information of each module of the current industrial computer work system of the enterprise, determine the problem list of the current industrial computer work system, and then determine the initial security protection information for solving the problems in the problem list in combination with the preset security protection graph. The initial protection information is analyzed for compatibility, protection balance and cost, and a plurality of security protection strategies for different modules in different cost intervals are obtained. Finally, the target security protection strategy selected by the enterprise is obtained. According to the target security protection strategy, the security protection upgrade information of the current industrial computer work system is generated, and the security protection upgrade of the industrial computer work system is completed. Through the above manner, the application solves the problem that the industrial control system has not been updated for a long time, resulting in vulnerabilities in all aspects of the system, and when updating again, compatibility errors and other problems are prone to occur, thereby causing the industrial control system to spend a lot of time and effort to complete the entire update.
[0072] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0073] It should be noted that in the description of the present application, the terms "first", "second", "third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.
[0074] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, so that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program codes can be executed entirely on a machine, partially on a machine, partially on a machine as a separate software package, and partially on a remote machine or server.
[0075] In the context of this disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0076] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0077] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0078] The computer system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server can be a cloud server, a server of a distributed system, or a server combined with a blockchain.
[0079] So far, the technical solutions of the present application have been described in combination with the preferred embodiments shown in the drawings, but it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without departing from the principles of the present application, and the technical solutions after these changes or replacements will all fall within the protection scope of the present application.
Claims
1. A method of security assessment of an industrial computer system, characterized in that, The method comprises the following steps: obtaining security protection information of each module of an industrial control system of an enterprise; analyzing the security protection information to obtain a security assessment report containing a list of security protection problems of each module; based on a preset security protection map, matching a plurality of initial protection information according to the list of security protection problems; based on the security protection information, analyzing the compatibility, protection balance and cost of each initial protection information to obtain a plurality of security protection strategies for different modules in different cost intervals; obtaining a target security protection strategy selected by the enterprise; and matching corresponding protection measure information from the preset security protection map according to the target security protection strategy; generating corresponding security protection upgrade information according to the protection measure information and the current security protection information.
2. The security evaluation method according to claim 1, characterized by, The method comprises the following steps:
3. The security evaluation method according to claim 2, characterized by, obtaining security protection information of each module of an industrial control system of an enterprise; 4. The security evaluation method according to claim 3, characterized by, analyzing the security protection information to obtain a security assessment report containing a list of security protection problems of each module; based on a preset security protection map, matching a plurality of initial protection information according to the list of security protection problems; based on the security protection information, analyzing the compatibility, protection balance and cost of each initial protection information to obtain a plurality of security protection strategies for different modules in different cost intervals; obtaining a target security protection strategy selected by the enterprise; and matching corresponding protection measure information from the preset security protection map according to the target security protection strategy; generating corresponding security protection upgrade information according to the protection measure information and the current security protection information. The method comprises the following steps: obtaining security protection information of each module of an industrial control system of an enterprise; analyzing the security protection information to obtain a security assessment report containing a list of security protection problems of each module; based on a preset security protection map, matching a plurality of initial protection information according to the list of security protection problems; based on the security protection information, analyzing the compatibility, protection balance and cost of each initial protection information to obtain a plurality of security protection strategies for different modules in different cost intervals; obtaining a target security protection strategy selected by the enterprise; and matching corresponding protection measure information from the preset security protection map according to the target security protection strategy; generating corresponding security protection upgrade information according to the protection measure information and the current security protection information. The method comprises the following steps: obtaining security protection information of each module of an industrial control system of an enterprise; analyzing the security protection information to obtain a security assessment report containing a list of security protection problems of each module; based on a preset security protection map, matching a plurality of initial protection information according to the list of security protection problems; based on the security protection information, analyzing the compatibility, protection balance and cost of each initial protection information to obtain a plurality of security protection strategies for different modules in different cost intervals; obtaining a target security protection strategy selected by the enterprise; and matching corresponding protection measure information from the preset security protection map according to the target security protection strategy; generating corresponding security protection upgrade information according to the protection measure information and the current security protection information.
5. The security evaluation method according to claim 3, characterized by, The preset security protection graph and the security protection knowledge graph are compared, security vulnerabilities lacking in the current industrial computer industrial control system and security vulnerabilities between layers are determined, and a second security analysis report is obtained, including: superimposing and comparing the preset security protection graph and the security protection knowledge graph to obtain a difference protection graph; performing attack and defense simulation on the protection wall corresponding to the security protection knowledge graph based on the preset attack and defense simulation model to obtain a blocking analysis report; and using a hierarchical penetration testing method to penetrate and verify the horizontal and vertical interaction interfaces of the bus layer, the control layer, the monitoring layer and the enterprise layer in the security protection knowledge graph to obtain a penetration verification result; integrating the difference graph, the blocking analysis report and the penetration verification result to obtain the second security analysis report.
6. The security evaluation method according to claim 1, characterized by, The preset security protection graph is used to match multiple initial protection information according to the security protection problem list, including: classifying the security problem list according to asset type, protocol type and vulnerability severity to obtain a first problem list classified according to type; calling corresponding protection components from the preset security protection graph according to the problem type and the first problem list to obtain multiple initial protection information.
7. The security evaluation method according to claim 1, characterized by, The security protection information is used to analyze the compatibility, protection balance and cost of each initial protection information to obtain multiple security protection strategies for different modules in different cost intervals, including: matching the compatibility of the security protection information and each initial protection information to filter out the first protection information without interference; analyzing the protection balance of the first protection information to obtain second protection information sorted according to the balance level; randomly arranging each second protection information based on the problem coverage principle to obtain an initial security protection strategy; performing compatibility analysis and cost analysis on the initial security protection strategy to obtain security protection strategies in different cost intervals.
8. The method of claim 1, wherein, The target security protection strategy is used to match corresponding protection measure information from the preset security protection graph, including: using a knowledge graph-based multi-relation traversal method to match the target security protection strategy with a protection measure node; determining multiple initial target protection measure nodes according to the relationship between the protection measure node and the constraint condition; performing risk reduction degree, implementation complexity and maintenance cost analysis on the initial target protection measure node to obtain an initial target protection measure node sorted according to the score; using a greedy algorithm to process the initial target protection measure node sorted according to the score to determine a target protection measure node; determining the protection measure information according to the target protection measure node.
9. The method of claim 1, wherein, The protection measure information and the current security protection information are used to generate corresponding security protection upgrade information, including: integrating the security protection information and the protection measure information to generate complete security protection information in the format of matching security protection information; determining the upgrade file information that needs to be supplemented in the security protection information according to the file difference between the complete security protection information and the security protection information; generating corresponding security protection upgrade information according to the upgrade file information.
10. A security assessment system for an industrial computer control system, characterized in that, The security evaluation module obtains the security protection information of each module of the industrial control system of the enterprise. The security evaluation module obtains the security protection information of each module of the industrial control system of the enterprise. The security protection information is analyzed to obtain a security evaluation report of a list of security protection problems contained in each module; The policy matching module matches a plurality of initial protection information according to the list of security protection problems based on the preset security protection graph; and performs compatibility, protection balance and cost analysis on each initial protection information based on the security protection information to obtain a plurality of security protection strategies for different modules in different cost intervals; The protection upgrade module acquires a target security protection strategy selected by the enterprise; matches corresponding protection measure information from the preset security protection graph according to the target security protection strategy; and generates corresponding security protection upgrade information according to the protection measure information and the current security protection information.
Citation Information
Patent Citations
Method and a system for performing safety protection by utilizing a multilayer safety protection system
CN109492901A
Industrial information security guarantee system construction method
CN110033174A
Industrial control network monitoring device and method
CN110221581A
Industrial control system network security simulation test platform and computer equipment
CN114157493A
Industrial control security protection system, software updating method, device and equipment thereof and medium
CN116048585A