Industrial control network security analysis method and system based on knowledge graph, and medium

By using a knowledge graph-based industrial control system (ICS) network security analysis method, we can mine the security invariants of ICS components and construct a ternary graph, deploy ICS thresholds, solve the problem of difficult identification of ICS network security risks, and realize full-process security management of ICS systems.

CN121000513BActive Publication Date: 2026-02-13北京珞安科技有限责任公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511499854.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-02-13
Estimated Expiration
2045-10-21

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to identify industrial control system network security risks in a timely manner and there is a lack of effective protection decision-making mechanisms. Traditional methods are unable to fully depict the operating logic and potential security risks of industrial control systems, and there is a lack of protection decision-making mechanisms oriented towards the business logic level, resulting in insufficient system protection capabilities.

Method used

The knowledge graph-based industrial control network security analysis method models the control logic by mining the security invariants of industrial control components, constructs a trusted computing base, and combines industrial control protocol parsing, slow attack and physical consequence perception to establish a ternary graph, deploys industrial control thresholds and embeds security thresholds in the front-end peripheral interface of the controller to achieve two-level threshold decision-making.

Benefits of technology

It enhances the comprehensiveness and credibility of industrial control system network security analysis, strengthens the protection against potential attacks, and realizes full-process security threshold management of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000513B_ABST
    Figure CN121000513B_ABST
Patent Text Reader

Abstract

The application discloses a knowledge graph-based industrial control network security analysis method and system and a medium, and relates to the technical field of industrial control network security.The method comprises the following steps: for an industrial control scene, an industrial control component-component industrial control element is used to mine security invariants and perform control logic modeling, and a trusted computing base is built; an industrial control knowledge graph is determined; a first industrial control threshold is deployed based on the trusted computing base, a second industrial control threshold is established based on the industrial control knowledge graph, an industrial control security threshold is embedded in a peripheral interface in front of a controller, and with the interaction of a first industrial control task instruction, an industrial control security threshold is added to perform two-level threshold decision and industrial control security threshold management.The technical problem that the existing industrial control network security risks are difficult to identify in a timely manner and lack effective protection decision mechanisms is solved, the technical effect of improving the comprehensiveness and credibility of industrial control network security analysis and enhancing the protection capability of an industrial control system against potential attack behaviors is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of industrial control network security, and in particular to an industrial control network security analysis method and system based on a knowledge graph and a medium. BACKGROUND

[0002] With the gradual development of industrial control systems in the direction of networking and intelligentization, the application of the industrial control systems in key infrastructures such as power, petrochemical industry, transportation and manufacturing is continuously expanding. However, the industrial control network environment often has characteristics such as protocol closure, component complexity and strong heterogeneity, so that network attack means show a diversification and concealment trend, and traditional security measures based on feature matching or a single protection boundary are difficult to discover potential risks in time. On the one hand, existing security analysis methods mostly rely on static rules or single-point detection, and are difficult to comprehensively depict the running logic and potential security risks of the industrial control system; on the other hand, there is a lack of effective protection decision mechanism for the business logic layer, which leads to insufficient system protection capability when facing slow attacks, cross-layer penetration and physical consequence correlation risks. SUMMARY

[0003] The application provides an industrial control network security analysis method, system and medium based on a knowledge graph, and solves the technical problem that industrial control network security risks are difficult to be identified in time and lack effective protection decision mechanisms in the prior art.

[0004] In a first aspect, the application provides an industrial control network security analysis method based on a knowledge graph, which comprises the following steps:

[0005] For the industrial control scene, security invariants are mined and control logic modeling is performed on the industrial control components-component industrial control elements, a trusted computing base is built, a ternary graph is constructed through industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, an industrial control knowledge graph is determined, a first industrial control threshold is deployed based on the trusted computing base, a second industrial control threshold is established based on the industrial control knowledge graph, an industrial control security threshold is embedded in the peripheral interface in front of the controller, with the interaction of the first industrial control task instruction, the industrial control security threshold is added to perform two-level threshold decision, and industrial control security threshold management is performed.

[0006] In a second aspect, the application provides an industrial control network security analysis system based on a knowledge graph, which comprises the following steps:

[0007] A trusted computing base building module: for the industrial control scene, the security invariant is mined and the control logic modeling is performed for the industrial control component-component industrial control element, and the trusted computing base is built; a graph construction module: the ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, and the industrial control knowledge graph is determined; a management module: the first industrial control threshold is deployed by the trusted computing base, the second industrial control threshold is established by the industrial control knowledge graph, the industrial control security threshold is embedded in the peripheral interface in front of the controller, the two-level threshold decision is performed by the added industrial control security threshold with the interaction of the first industrial control task instruction, and the industrial control security threshold management is performed.

[0008] In a third aspect, the present application provides a computer readable storage medium storing a computer program, which, when executed by a processor, implements the knowledge graph-based industrial control network security analysis method provided by the present application.

[0009] The one or more technical solutions provided in the present application have at least the following technical effects or advantages:

[0010] First, for the industrial control scene, the security invariant is mined and the control logic modeling is performed for the industrial control component-component industrial control element, and the trusted computing base is built. Then, the ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, and the industrial control knowledge graph is determined. Finally, the first industrial control threshold is deployed by the trusted computing base, the second industrial control threshold is established by the industrial control knowledge graph, the industrial control security threshold is embedded in the peripheral interface in front of the controller, the two-level threshold decision is performed by the added industrial control security threshold with the interaction of the first industrial control task instruction, and the industrial control security threshold management is performed. The technical problem that the industrial control network security risk is difficult to identify in time and lacks effective protection decision mechanism in the prior art is solved, the technical effect of improving the comprehensiveness and credibility of industrial control network security analysis and enhancing the protection capability of industrial control system to potential attack behavior is achieved. BRIEF DESCRIPTION OF DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0012] Figure 1 The flowchart of the knowledge graph-based industrial control network security analysis method provided by the embodiments of the present application is shown.

[0013] Figure 2 The structure diagram of the knowledge graph-based industrial control network security analysis system provided by the embodiments of the present application is shown.

[0014] Figure labeling: Trusted computing base construction module 11, graph construction module 12, management module 13. Detailed Implementation

[0015] This application provides a knowledge graph-based method, system, and medium for industrial control system network security analysis, which solves the technical problems in the prior art of the difficulty in timely identification of industrial control system network security risks and the lack of an effective protection decision-making mechanism.

[0016] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0017] It should be noted that the terms "comprising" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to these processes, methods, products, or devices.

[0018] Example 1, as Figure 1 As shown, this application provides a knowledge graph-based method for industrial control system network security analysis, wherein the method includes:

[0019] For industrial control scenarios, security invariants are extracted from industrial control components and industrial control elements, and control logic is modeled to build a trusted computing base.

[0020] Furthermore, building a trusted computing base includes:

[0021] For the industrial control scenario, the industrial control array is determined by regularizing the industrial control components and their industrial control elements; the industrial control array is traversed, and industrial control filtering is performed based on security invariants with rigid security conditions to determine invariant elements; the invariant elements are then logically formally reconstructed and integrated to build the trusted computing base.

[0022] First, for the industrial control scene, the industrial control components in the industrial control system, such as controllers, sensors, actuators, network communication modules, etc., are extracted and regularized. The input parameters, control instructions, running state quantities and output feedbacks corresponding to each component are taken as industrial control elements, the correspondence between the components and the elements is established, and the industrial control array is generated in the preset logical order. Then, the industrial control array is traversed, the value range, state transition rule and causal dependence of each industrial control element under the condition of normal system operation are analyzed, and combined with the filtering mechanism based on the rigid safety condition (such as the safety threshold not exceeding the boundary, the state transition satisfying uniqueness, and the logical instruction maintaining consistency), the elements meeting the stability and consistency are extracted as invariant elements. Further, the invariant elements are logically formalized and reconstructed, including converting the invariant elements into formal logic constraint expressions, Boolean algebra relationships or temporal logic formulas, and combining the industrial control process to form a complete set of control logic expressions. Finally, the logical formalization result is integrated to build a trusted computing base.

[0023] A ternary graph is constructed by analyzing the industrial control protocol, slow attack within the baseline range and physical consequence perception, to determine the industrial control knowledge graph.

[0024] The mainstream protocols used in the industrial control network are analyzed, the protocol message format, field semantics, transmission rules and compliance conditions are extracted, the semantic analysis results of the protocol layer are formed, and the protocol consistency graph is constructed. Secondly, based on the operation records and communication logs of the industrial control scene, slow attack behaviors existing within the baseline range are retrieved, such as low-frequency command insertion, intermittent data packet delay, fine-grained parameter tampering, etc., the evolution process and potential attack sequence are analyzed, and a slow attack graph is established. Then, the physical consequences that the industrial control system may produce under the influence of attacks are perceived and modeled, including running efficiency decline, device overload, production process anomaly or security boundary breakthrough, etc. By monitoring the changes of running parameters and process indicators, a physical consequence perception graph is formed. Finally, the protocol layer analysis graph, slow attack graph and physical consequence perception graph are modeled in a ternary association according to the logical chain of cause-process-result, a unified industrial control knowledge graph is established, and the knowledge expression and multi-dimensional reasoning of the industrial control network security situation are realized.

[0025] Further, the ternary graph is constructed by analyzing the industrial control protocol, slow attack within the baseline range and physical consequence perception, including:

[0026] The industrial control protocol of the industrial control scene is retrieved, the first detection deployment is performed from the protocol level, and a one-layer graph is constructed, wherein the protocol level is the protocol compliance based on the industrial control protocol; the second detection deployment is performed from the semantic level, and a two-layer graph is constructed, wherein the semantic level is the introduction of malicious semantics under protocol compliance; the one-layer graph and the two-layer graph are cascaded as a first knowledge graph.

[0027] Specifically, the set of industrial control protocols actually used in the industrial control scene is invoked, the frame structure, field rules, transmission timing and response mechanism of the industrial control protocol are decoded and analyzed, and on this basis, protocol compliance verification conditions are set, including field legality, field value range, check bit correctness and message timing integrity, the first verification deployment at the protocol level is completed, and a one-layer protocol compliance graph is established according to the verification result, which is used to represent the normal communication logic and compliance boundary of the industrial control protocol. Secondly, on the basis of protocol compliance, further introduce the verification deployment of the semantic layer, that is, the semantic analysis of the communication message conforming to the protocol format, identify the business meaning and context relationship of the instruction, and combine the attack corpus or abnormal behavior library to detect the malicious semantic instructions that may be carried in the compliant communication, such as abnormal parameter injection, hidden command execution, and unauthorized operation triggering, etc., thereby constructing a two-layer semantic graph for representing potential malicious behavior under protocol compliance. Finally, the one-layer protocol compliance graph and the two-layer semantic graph are cascaded to establish a corresponding relationship between cause and level, forming a first knowledge graph to realize cross-level security association modeling from the protocol level to the semantic level.

[0028] Further, ternary graph construction is performed based on industrial control protocol analysis, slow attack within baseline range, and physical consequence perception, including:

[0029] For the industrial control scene, industrial control records homologous to the industrial control scene are retrieved; for the industrial control records, slow industrial control attack sequences are mined by targeting slow attacks within the baseline range; and a second knowledge graph is constructed according to the slow industrial control attack sequences.

[0030] Specifically, for the industrial control scene, homologous industrial control records are invoked, which include communication logs, device running logs, task scheduling data, historical alarm information, etc.; in the industrial control records, communication segments with characteristics such as abnormal delay, low-frequency repetition, and segmented insertion are filtered out by referring to the baseline range, and are used as potential slow attack candidate events; further, pattern recognition and timing aggregation are performed on the candidate events, event chains that meet the attack behavior characteristics are extracted, and slow industrial control attack sequences are formed. Finally, according to the slow industrial control attack sequences, a mapping relationship of event-process-result is established, a ternary representation of attack causes, attack means and attack consequences is defined, and a second knowledge graph is constructed to reveal the potential evolution path and risk chain of slow attacks in the industrial control scene.

[0031] Further, ternary graph construction is performed based on industrial control protocol analysis, slow attack within baseline range, and physical consequence perception, including:

[0032] Determine the first industrial control incentive in the network dimension, the first industrial control consequence in the control logic dimension, and the second industrial control consequence in the physical response dimension to determine the graph architecture, wherein the first industrial control incentive is derived from the trusted computing base, the first knowledge graph, or the second knowledge graph; based on the graph architecture, based on the industrial control record, directional mining is performed to generate a third knowledge graph.

[0033] In the industrial control scenario, potential abnormal trigger conditions are extracted as the first industrial control incentive from the network communication dimension, wherein the first industrial control incentive includes abnormal data packet injection, illegal session establishment, abnormal traffic fluctuation, etc., and its source can be provided by the invariant check result in the trusted computing base, the protocol and semantic verification result in the first knowledge graph, or the slow attack sequence in the second knowledge graph.

[0034] In the control logic dimension, the execution path and state transition process of the industrial control task instruction are modeled, and the logic deviation or illegal instruction execution caused by abnormal incentive triggering is identified as the first industrial control consequence.

[0035] In the physical response dimension, the change trend of the industrial control system running parameters (such as pressure, temperature, speed, current, etc.) is monitored, the physical deviation or device damage caused by abnormal control logic is identified, and it is taken as the second industrial control consequence.

[0036] Based on the first industrial control incentive, the first industrial control consequence and the second industrial control consequence, a graph architecture is established, and the industrial control record is directionally mined to extract the instantiation data of the incentive, the consequence and the causal chain, which is stored in a triple form, to generate a third knowledge graph for multidimensional reasoning and cross-level security situation awareness.

[0037] The first industrial control threshold is deployed based on the trusted computing base, the second industrial control threshold is established based on the industrial control knowledge graph, and the industrial control security threshold is embedded in the peripheral interface in front of the controller. With the interaction of the first industrial control task instruction, the industrial control security threshold is added to perform two-level threshold decision and industrial control security threshold management.

[0038] A first industrial control threshold is deployed on a trusted computing base, and a correspondence between the industrial control component and the security invariant is taken as a threshold condition for consistency comparison and security verification of task instructions entering the industrial control network. Secondly, a second industrial control threshold is established based on the industrial control knowledge graph, and protocol compliance, semantic detection, slow attack sequence and physical consequence perception results are taken as judgment criteria for further security reasoning of the task instructions passing through the first industrial control threshold. Then, a peripheral interface is set at the data receiving end of the controller, and an industrial control security threshold module is embedded in the interface, so that it can be triggered in real time before the task instruction enters the controller. Finally, as the first industrial control task instruction is transmitted in the industrial control network, the industrial control security threshold module automatically calls the cascaded logic of the first industrial control threshold and the second industrial control threshold to perform two-level threshold decision: if it is determined to be a safe instruction, it is released to the controller, if it is determined to be an abnormal instruction, it is partially or completely isolated, and an alarm management is triggered, thereby realizing the whole-process security threshold management of the industrial control task instruction.

[0039] Further, the industrial control security threshold embedded in the peripheral interface in front of the controller includes:

[0040] For the industrial control network, a peripheral interface is deployed at the data receiving front end of the controller; the cascaded decision logic based on the first industrial control threshold and the second industrial control threshold is set, and the industrial control security threshold is generated by supervised training to convergence; the industrial control security threshold is embedded and deployed in the peripheral interface, wherein the industrial control security threshold is triggered along with the data flow of the industrial control network thread.

[0041] For the industrial control network, a peripheral interface is deployed at the data receiving front end of the controller, which serves as a security check entrance for industrial control task instructions entering the controller. Secondly, the cascaded decision logic based on the first industrial control threshold and the second industrial control threshold is set, wherein the first industrial control threshold is used to verify the consistency of the instruction and the invariant elements in the trusted computing base, and the second industrial control threshold is used to make reasoning and judgment on protocol compliance, semantic anomaly and slow attack sequence based on the industrial control knowledge graph. Further, the two-level threshold logic is input into a supervised learning model for training, and the classifier converges by iteratively training historical industrial control records and labeled attack samples, generating an industrial control security threshold model that meets the recognition accuracy requirements. Finally, the industrial control security threshold model is embedded and deployed in the controller peripheral interface, so that it can be triggered in real time when the data of the industrial control network thread flows through, realizing online security filtering and dynamic decision of the task instruction, thereby improving the front-end protection capability of the industrial control system without changing the original logic of the controller.

[0042] Further, the two-level threshold decision includes:

[0043] The industrial control source end generates a first industrial control task instruction, and performs communication control from the industrial control source end to the controller. With the transmission of the first industrial control task instruction in the industrial control network, the industrial control security threshold embedded in the peripheral interface in front of the controller is triggered in real time. Secondly, the industrial control security threshold calls the cascaded decision logic based on the first industrial control threshold and the second industrial control threshold to perform two-level threshold decision: the first industrial control threshold is used to check the consistency of the instruction and the security invariant in the trusted computing base; the second industrial control threshold is based on the industrial control knowledge graph to check the protocol compliance of the instruction, identify semantic anomalies, and reason the potential slow attack mode. If the results of the two-level threshold decision are both safe, the system allows the first industrial control task instruction to continue to be transmitted to the controller and executed; if the result of any level threshold decision is abnormal, the one-way isolation of the task instruction is performed. The one-way isolation mode includes partial isolation and complete isolation: partial isolation is used to block only abnormal fields or abnormal parameters while retaining the safe part of the instruction, and complete isolation is used to block the entire instruction stream and trigger a safety alarm.

[0044] The industrial control source end generates a first industrial control task instruction, and performs communication control from the industrial control source end to the controller. With the transmission of the first industrial control task instruction in the industrial control network, the industrial control security threshold embedded in the peripheral interface in front of the controller is triggered in real time. Secondly, the industrial control security threshold calls the cascaded decision logic based on the first industrial control threshold and the second industrial control threshold to perform two-level threshold decision: the first industrial control threshold is used to check the consistency of the instruction and the security invariant in the trusted computing base; the second industrial control threshold is based on the industrial control knowledge graph to check the protocol compliance of the instruction, identify semantic anomalies, and reason the potential slow attack mode. If the results of the two-level threshold decision are both safe, the system allows the first industrial control task instruction to continue to be transmitted to the controller and executed; if the result of any level threshold decision is abnormal, the one-way isolation of the task instruction is performed. The one-way isolation mode includes partial isolation and complete isolation: partial isolation is used to block only abnormal fields or abnormal parameters while retaining the safe part of the instruction, and complete isolation is used to block the entire instruction stream and trigger a safety alarm.

[0045] Further, the execution of the industrial control security cascaded decision based on the first industrial control threshold and the second industrial control threshold includes:

[0046] The first industrial control threshold is triggered to match the first industrial control task instruction in the trusted computing base to determine the first invariant element. The first industrial control task instruction is compared and arbitrated in the form of reconstruction logic based on the first invariant element to determine the first industrial control security state, wherein the first industrial control security state includes an arbitration consistent part and an arbitration inconsistent part. The arbitration inconsistent part is one-way isolated, and the arbitration consistent part is passed by the first industrial control threshold and imported into the second industrial control threshold. The first knowledge graph is used to perform hierarchical decision at the protocol level and the semantic level to determine the first graph result. The second knowledge graph is triggered to perform graph decision based on the slow industrial control attack sequence to determine the second graph result. If the first graph result and the second graph result are completely safe, the arbitration consistent part is transmitted to the controller. If it is not completely safe, the safe part is passed by the second industrial control threshold, and the unsafe part triggers the third knowledge graph to locate the industrial control consequences. The arbitration inconsistent part and the industrial control consequences are used to perform industrial control alarm management.

[0047] Specifically, the first industrial control threshold is triggered, the first industrial control task instruction is matched with the security invariant elements in the trusted computing base one by one, and the invariant elements corresponding to the instruction are extracted. Secondly, for the invariant elements, the task instruction is compared and arbitrated based on the logical reconstruction form, it is judged whether the instruction meets the safety constraint condition, and the first industrial control safety state is obtained. The first industrial control safety state includes an arbitration consistent part and an arbitration inconsistent part: the arbitration consistent part represents the instruction segment that conforms to the invariant logic, and the arbitration inconsistent part represents the instruction segment that violates the invariant logic. For the arbitration inconsistent part, one-way isolation is performed to block its continuous transmission; for the arbitration consistent part, it passes through the first industrial control threshold and is imported into the second industrial control threshold. Further, in the second industrial control threshold, the hierarchical decision at the protocol level and the semantic level is performed based on the first knowledge graph to obtain a first graph result; at the same time, the second knowledge graph is triggered, and the graph determination based on the slow industrial control attack sequence is performed to obtain a second graph result. If the first graph result and the second graph result are both determined as completely safe, the arbitration consistent part is allowed to be transmitted to the controller; if any result is determined as not completely safe, the safe part thereof is executed through the second industrial control threshold, and the unsafe part triggers the third knowledge graph to further locate the physical industrial control consequences that may be caused by the instruction. Finally, combined with the arbitration inconsistent part and the industrial control consequences, the industrial control alarm management is performed, including generating an alarm event, updating a security log and notifying an operation and maintenance terminal, so as to realize the safety protection closed loop of the industrial control system under the support of the multi-layer knowledge graph.

[0048] To sum up, the embodiments of the present application have at least the following technical effects:

[0049] Firstly, for the industrial control scene, the security invariants are mined and the control logic is modeled based on the industrial control components-component industrial control elements, and the trusted computing base is built. Then, the industrial control knowledge graph is determined by constructing a ternary graph based on industrial control protocol analysis, slow attack in the baseline range and physical consequence perception. Finally, the first industrial control threshold is deployed based on the trusted computing base, the second industrial control threshold is established based on the industrial control knowledge graph, and the industrial control safety threshold is embedded in the peripheral interface in front of the controller. With the interaction of the first industrial control task instruction, the two-level threshold decision of the industrial control safety threshold is added, and the industrial control safety threshold management is performed. The technical problem that the industrial control network security risk is difficult to identify in time and lacks effective protection decision mechanism in the prior art is solved, and the technical effects of improving the comprehensiveness and credibility of industrial control network security analysis and enhancing the protection capability of industrial control system to potential attack behavior are achieved.

[0050] Embodiment two, based on the same inventive concept as the knowledge graph-based industrial control network security analysis method in the foregoing embodiments, as shown in Figure 2 The present application provides a knowledge graph-based industrial control network security analysis system, wherein the system comprises:

[0051] The trusted computing base building module 11: for the industrial control scene, mining security invariants and control logic modeling of industrial control components-component industrial control elements, building a trusted computing base; the graph construction module 12: with industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception ternary graph construction, determine the industrial control knowledge graph; the management module 13: with the first industrial control threshold deployed by the trusted computing base, the second industrial control threshold is established by the industrial control knowledge graph, the industrial control security threshold is embedded in the peripheral interface in front of the controller, with the interaction of the first industrial control task instruction, the industrial control security threshold is added to the two-level threshold decision, and the industrial control security threshold management is carried out.

[0052] Further, the trusted computing base building module 11 is used to execute the following method:

[0053] For the industrial control scene, the industrial control components-component industrial control elements are regularized, and the industrial control array is determined; the industrial control array is traversed, the security invariants based on rigid security conditions are used for industrial control filtering, and the invariant elements are determined; for the invariant elements, logical formalization reconstruction is carried out, and the trusted computing base is integrated and built.

[0054] Further, the graph construction module 12 is used to execute the following method:

[0055] The industrial control protocol of the industrial control scene is called, the first detection deployment is carried out from the protocol level, and a one-layer graph is constructed, wherein the protocol level is based on the protocol compliance of the industrial control protocol; the second detection deployment is carried out from the semantic level, and a two-layer graph is constructed, wherein the semantic level is the introduction of malicious semantics under protocol compliance; the one-layer graph and the two-layer graph are cascaded as a first knowledge graph.

[0056] Further, the graph construction module 12 is used to execute the following method:

[0057] For the industrial control scene, the industrial control records homologous to the industrial control scene are retrieved; for the industrial control records, the slow industrial control attack sequence is mined with the slow attack in the baseline range as the target; according to the slow industrial control attack sequence, a second knowledge graph is constructed.

[0058] Further, the graph construction module 12 is used to execute the following method:

[0059] Determine the graph architecture with the first industrial control inducement in the network dimension, the first industrial control consequence in the control logic dimension, and the second industrial control consequence in the physical response, wherein the first industrial control inducement is derived from the trusted computing base, the first knowledge graph or the second knowledge graph; based on the graph architecture, the third knowledge graph is generated based on the directed mining of the industrial control records.

[0060] Further, the management module 13 is used to execute the following method:

[0061] For industrial control networks, a peripheral interface is deployed at the data receiving front end of the controller; a cascaded decision logic based on a first industrial control threshold and a second industrial control threshold is set, and the industrial control safety threshold is generated through supervised training until convergence; the industrial control safety threshold is embedded in the peripheral interface, wherein the industrial control safety threshold is triggered as the data flow of the industrial control network thread passes through.

[0062] Furthermore, the management module 13 is used to perform the following methods:

[0063] The industrial control signal source generates a first industrial control task instruction and executes communication control from the industrial control signal source to the controller. As the first industrial control task instruction is transmitted in the industrial control network, the industrial control security threshold is triggered, and an industrial control security cascade decision based on the first industrial control threshold and the second industrial control threshold is executed. If it is a safe instruction, the first industrial control task instruction is allowed to pass; if it is an abnormal instruction, the first industrial control task instruction is unidirectionally isolated. The isolation mode includes partial isolation and complete isolation.

[0064] Furthermore, the management module 13 is used to perform the following methods:

[0065] The first industrial control threshold is triggered, and the first industrial control task instruction is matched in the trusted computing base to determine the first invariant element. For the first invariant element, the first industrial control task instruction is compared and arbitrated in a reconstructed logical form to determine the first industrial control security state, wherein the first industrial control security state includes an arbitrated consistent part and an arbitrated inconsistent part. The arbitrated inconsistent part is unidirectionally isolated, and the arbitrated consistent part passes the first industrial control threshold, then is imported into the second industrial control threshold. A hierarchical decision is made at the protocol and semantic levels based on the first knowledge graph to determine the first graph result. The second knowledge graph is triggered, and a graph decision based on a slow industrial control attack sequence is executed to determine the second graph result. If the first graph result and the second graph result are completely secure, the arbitrated consistent part is transmitted to the controller. If they are not completely secure, the secure part passes the second industrial control threshold, and the insecure part is triggered by the third knowledge graph to locate the industrial control consequences. Industrial control alarm management is performed based on the arbitrated inconsistent part and the industrial control consequences.

[0066] Embodiment three, based on the same inventive concept as the knowledge graph-based industrial control network security analysis method in the foregoing embodiments, this embodiment provides a computer readable storage medium, which can be used to store software programs, computer executable programs and modules, such as the program instructions / modules corresponding to the knowledge graph-based industrial control network security analysis method in the embodiments of the present application. The processor executes the software programs, instructions and modules stored in the memory, thereby performing various functional applications and data processing of the computer device, i.e. implementing the knowledge graph-based industrial control network security analysis method described above.

[0067] It should be noted that the above sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. And the above describes specific embodiments of the present application. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.

[0068] The above is only the preferred embodiment of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0069] The specification and drawings of the present application are only exemplary descriptions of the present application, and are considered to cover any and all modifications, changes, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various modifications and changes to the present application without departing from the scope of the present application. Thus, if these modifications and changes of the present application belong to the scope of the present application and its equivalent technology, the present application intends to include these modifications and changes.

Claims

1. An industrial control network security analysis method based on a knowledge graph, characterized in that, The method comprises: For the industrial control scene, the security invariants of the industrial control component-component industrial control elements are mined and the control logic is modeled, and a trusted computing base is built; An industrial control knowledge graph is determined by constructing a ternary graph with industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception; A first industrial control threshold is deployed based on the trusted computing base, and a second industrial control threshold is established based on the industrial control knowledge graph, the industrial control security threshold is embedded in the peripheral interface in front of the controller, and the two-level threshold decision is added by the interaction of the first industrial control task instruction, and the industrial control security threshold management is performed; Wherein, embedding the industrial control security threshold in the peripheral interface in front of the controller comprises: For the industrial control network, a peripheral interface is deployed in front of the data receiving of the controller; The cascade decision logic based on the first industrial control threshold and the second industrial control threshold is set, and the industrial control security threshold is generated by supervised training to convergence; The industrial control security threshold is embedded and deployed in the peripheral interface, wherein the industrial control security threshold is triggered by the data flow of the industrial control network thread; Wherein, performing two-level threshold decision comprises: The industrial control source end generates a first industrial control task instruction, and performs communication control from the industrial control source end to the controller; With the transmission of the first industrial control task instruction in the industrial control network, the industrial control security threshold is triggered, the industrial control security cascade decision based on the first industrial control threshold and the second industrial control threshold is executed, if it is a safe instruction, the first industrial control task instruction is passed; If it is an abnormal instruction, the first industrial control task instruction is executed in one-way isolation, wherein the isolation mode includes partial isolation and complete isolation; Wherein, performing industrial control security cascade decision based on the first industrial control threshold and the second industrial control threshold comprises: Trigger the first industrial control threshold, match the first industrial control task instruction in the trusted computing base, and determine the first invariant element; For the first invariant element, the first industrial control task instruction is compared and arbitrated in the form of reconfiguration logic to determine the first industrial control security state, wherein the first industrial control security state includes an arbitration consistent part and an arbitration inconsistent part; The arbitration inconsistent part is isolated in one direction, and the arbitration consistent part is passed through the first industrial control threshold and imported into the second industrial control threshold; According to the first knowledge graph, the hierarchical decision of the protocol level and the semantic level is executed to determine the first graph result; Trigger the second knowledge graph to execute the graph decision based on the slow industrial control attack sequence to determine the second graph result; If the first graph result and the second graph result are completely safe, the arbitration consistent part is transmitted to the controller; If it is not completely safe, the safe part is passed through the second industrial control threshold, and the unsafe part is triggered by the third knowledge graph to locate the industrial control consequence; According to the arbitration inconsistent part and the industrial control consequence, the industrial control alarm management is performed. 2.The knowledge graph based industrial control network security analysis method of claim 1, wherein, Building a trusted computing base comprises: For the industrial control scene, the industrial control elements of the industrial control component-component are regularized to determine the industrial control array; The industrial control array is traversed to filter the industrial control based on the security invariants of the rigid security conditions to determine the invariant elements; For the invariant elements, the logic is formalized and reconstructed to integrate and build the trusted computing base. 3.The knowledge graph based industrial control network security analysis method of claim 1, wherein, The ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, including: The industrial control protocol of the industrial control scene is called, and the first detection deployment is performed from the protocol level to construct a one-layer graph, wherein the protocol level is protocol compliance based on the industrial control protocol; The second detection deployment is performed from the semantic level to construct a two-layer graph, wherein the semantic level is the introduction of malicious semantics under protocol compliance; The one-layer graph and the two-layer graph are cascaded as a first knowledge graph. 4.The knowledge graph based industrial control network security analysis method of claim 3, wherein, The ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, including: For the industrial control scene, the industrial control records homologous to the industrial control scene are retrieved; For the industrial control records, slow industrial control attack sequences are mined with slow attacks in the baseline range as the target; According to the slow industrial control attack sequence, a second knowledge graph is constructed. 5.The knowledge graph based industrial control network security analysis method of claim 4, wherein, The ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception, including: Determine the graph architecture by determining the first industrial control inducement in the network dimension, the first industrial control consequence in the control logic dimension, and the second industrial control consequence in the physical response, wherein the first industrial control inducement is derived from the trusted computing base, the first knowledge graph or the second knowledge graph; Based on the graph architecture, the third knowledge graph is generated by directional mining based on the industrial control records.

6. The industrial control network security analysis system based on a knowledge graph, characterized in that, The system for implementing the knowledge graph-based industrial control network security analysis method of any one of claims 1-5, the system comprising: A trusted computing base building module: for the industrial control scene, the security invariant of the industrial control component-component industrial control element is mined and the control logic modeling is performed to build the trusted computing base; A graph construction module: the ternary graph is constructed by industrial control protocol analysis, industrial control baseline range slow attack and physical consequence perception to determine the industrial control knowledge graph; A management module: the first industrial control threshold is deployed based on the trusted computing base, the second industrial control threshold is established based on the industrial control knowledge graph, the industrial control security threshold is embedded in the peripheral interface in front of the controller, and the two-level threshold decision is performed by adding the industrial control security threshold execution with the interaction of the first industrial control task instruction to perform the industrial control security threshold management.

7. A computer-readable storage medium having stored thereon a computer program, characterized in that, The program is executed by the processor to realize the knowledge graph-based industrial control network security analysis method of any one of claims 1-5.

Citation Information

Patent Citations

  • Industrial network information security monitoring and protection system

    CN114567463A

  • Industrial control network security feature analysis method and system applying knowledge graph

    CN117040926A