A method for verifying security effectiveness of an industrial control network

By constructing a security potential energy field mapping and real-time entropy change monitoring system for industrial control networks, the problems of accuracy and real-time verification of industrial control network security are solved, enabling accurate real-time security status assessment and dynamic risk identification of industrial control networks.

CN121077938BActive Publication Date: 2026-01-13GUANGZHOU SHIBEIYUN BIG DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511589726.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-03
Publication Date
2026-01-13
Estimated Expiration
2045-11-03

AI Technical Summary

Technical Problem

Existing industrial control network security verification methods are insufficient to meet the requirements of accuracy and real-time monitoring, failing to accurately identify potential risk nodes and monitor network status changes in real time.

Method used

By constructing a security potential energy field mapping based on the industrial control network topology, quantifying the security potential energy coefficient and generating a network effectiveness baseline map, and combining it with the real-time data stream of the entropy verification threshold monitoring node, accurate and real-time verification of the industrial control network can be achieved.

Benefits of technology

It improves the accuracy and real-time performance of industrial control system network security situation assessment, enabling real-time detection of dynamic risks and enhancing the real-time nature and relevance of security status judgment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077938B_ABST
    Figure CN121077938B_ABST
Patent Text Reader

Abstract

The application discloses a kind of verification methods of industrial control network security effectiveness, it is related to digital information transmission technical field.The method includes: determining the industrial control network topology based on target industrial control network, by conducting security potential field mapping, construct network effectiveness baseline chart, wherein, by the security effectiveness of industrial control network is quantified as security potential coefficient, the network effectiveness baseline chart is composed of contour potential graph based on invariance industrial control network topology and security elasticity coefficient based on industrial control network topology fine adjustment test;By locating the risk control verification node in the network effectiveness baseline chart, additional entropy verification threshold, the entropy change monitoring of node real-time data flow is executed, and the node real-time verification result is determined;By coupling the network effectiveness baseline chart and the node real-time verification result, as the effectiveness verification result of industrial control network and carry out target industrial control network operation and maintenance management.The application effectively improves the accuracy and real-time performance of industrial control network security effectiveness verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of digital information transmission technology, and more specifically to a method for verifying the effectiveness of industrial control network security. Background Technology

[0002] Industrial control network (ICS) is a communication network specifically designed to connect and automate the control of various physical devices in an industrial environment. Its goal is to ensure the safe, reliable, accurate, and efficient operation of industrial production processes. Currently, the field of ICS network security verification has developed a multi-dimensional protection system, providing fundamental safeguards for ICS system security.

[0003] Existing methods focus on static mapping of network assets and structures. While they provide a clear architectural baseline, they are difficult to accurately quantify and resiliently assess the security posture, resulting in inaccurate identification of potential risk nodes. At the same time, due to the lack of a continuous monitoring mechanism for the real-time operation of the network, they cannot effectively capture instantaneous risks caused by configuration fine-tuning or internal traffic anomalies, resulting in a significant lag in the real-time performance of security verification and making it difficult to support proactive and adaptive security operation and maintenance decisions. Summary of the Invention

[0004] This application provides a method for verifying the effectiveness of industrial control network security, aiming to solve the technical problem that existing technologies cannot meet the requirements of industrial control networks for accurate and real-time security verification.

[0005] In view of the above problems, this application provides a method for verifying the effectiveness of industrial control system network security, including:

[0006] The topology of the industrial control network based on the target industrial control network is determined, and a network effectiveness baseline map is constructed by performing a safety potential energy field mapping. The safety effectiveness of the industrial control network is quantified into a safety potential energy coefficient. The network effectiveness baseline map is composed of a contour potential energy map based on the invariant industrial control network topology and a safety elasticity coefficient based on the industrial control network topology fine-tuning test.

[0007] By locating risk control verification nodes in the network effectiveness baseline diagram, adding an entropy verification threshold, and performing entropy change monitoring of the node's real-time data stream, the real-time verification result of the node is determined.

[0008] By coupling the network validity baseline map with the real-time verification results of the nodes, the validity verification results of the industrial control network are used as the target industrial control network operation and maintenance management.

[0009] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0010] This application provides a method for verifying the network effectiveness of industrial control system (ICS) networks. By quantifying security effectiveness as a potential energy coefficient, a network effectiveness baseline integrating topology invariance and elastic fine-tuning is constructed, improving the accuracy of security situation assessment. Furthermore, by locating key nodes in the baseline and monitoring the entropy change of their data flows, real-time perception and verification of dynamic risks are achieved, thereby enhancing the real-time performance of security status judgment. This method effectively improves the accuracy and real-time performance of ICS network effectiveness verification. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 A flowchart illustrating a method for verifying the effectiveness of industrial control network security, provided in an embodiment of this application;

[0013] Figure 2 This is a schematic diagram of the security resilience coefficient step in the industrial control network topology fine-tuning test, which is part of a verification method for the effectiveness of industrial control network security provided in this application embodiment. Detailed Implementation

[0014] This application provides a method for verifying the effectiveness of industrial control network security, which addresses the technical problem that existing technologies cannot meet the requirements of industrial control networks for accurate and real-time security verification.

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0016] It should be noted that the terms "comprising" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to these processes, methods, products, or devices.

[0017] Examples, such as Figure 1 As shown, this application provides a method for verifying the effectiveness of industrial control system network security, the method comprising:

[0018] S100: Determine the industrial control network topology based on the target industrial control network, and construct a network effectiveness baseline map by performing a safety potential energy field mapping. The safety effectiveness of the industrial control network is quantified into a safety potential energy coefficient. The network effectiveness baseline map is composed of a contour potential energy map based on the invariant industrial control network topology and a safety elasticity coefficient based on the industrial control network topology fine-tuning test.

[0019] In this embodiment, the topology of the industrial control network (ICS) based on the target ICS network is determined. A network effectiveness baseline map is constructed by performing security potential energy field mapping. The security effectiveness of the ICS network is quantified into security potential energy coefficients. The network effectiveness baseline map consists of a contour potential energy map based on the invariant ICS network topology and security elasticity coefficients based on ICS network topology fine-tuning tests. By determining the ICS network topology and conducting security potential energy field mapping, abstract security effectiveness can be transformed into quantifiable security potential energy coefficient indicators. Combining the static security characteristics of the invariant topology with the dynamic elasticity of the fine-tuning scenario, a comprehensive network effectiveness baseline map is constructed. This provides a standardized benchmark for subsequent accurate location of risk control nodes and real-time security verification, addressing the problems of fuzzy security status assessment and insufficient dynamic adaptability.

[0020] First, determine the industrial control network topology based on the target industrial control network. Industrial control network topology refers to the overall diagram of the physical connections and logical communication architecture of various devices in the industrial control network, such as terminals, controllers, and network devices. Network topology discovery tools are used to collect the device connection relationships and communication link information of the target industrial control network, clarify the node hierarchy structure, and form a complete topology diagram. For example, for the industrial control network of an automotive parts production line, SNMP scanning tools are used to collect the IP addresses, port mapping relationships, and communication protocol types of devices such as PLC controllers, industrial switches, and robot terminals, and a three-level topology structure of controller-switch-terminal is drawn.

[0021] Secondly, a network effectiveness baseline map is constructed by mapping the security potential energy field. The security effectiveness of the industrial control network is quantified into a security potential energy coefficient. The network effectiveness baseline map is composed of a contour potential energy map based on the invariant industrial control network topology and a security elasticity coefficient based on the industrial control network topology fine-tuning test.

[0022] The method provided in this application, "contour potential energy map based on invariant industrial control network topology", includes:

[0023] Generate a data probe, wherein the data probe is a set of industrial control data packets that do not carry malicious payloads;

[0024] The data probe is input into any node of the industrial control network topology and randomly walks through the target industrial control network to quantify the safety potential coefficient of the industrial control verification node.

[0025] Based on the industrial control network topology, the safety potential energy coefficient is topologically integrated to generate the contour potential energy map.

[0026] First, data probes are generated, which are a set of industrial control data packets without malicious payloads. Data probes are standard communication data packets specifically designed for industrial control protocols, carrying no malicious payloads. Their purpose is to traverse the network non-destructively, triggering and recording the security responses of each node, thereby assessing its security behavior under normal conditions. Based on the mainstream communication protocols of the target industrial control network, a set of data packets that do not contain malicious code and conform to protocol specifications is constructed to ensure that the data probes can penetrate the network normally without affecting equipment operation. For example, for the Modbus protocol of an industrial control network for an automotive parts production line, data packets containing reading coil status and reading holding registers are generated. The data segments within the data packets are filled with normal values ​​simulating the production environment, forming 10 sets of data probes.

[0027] Secondly, the data probe is input into any node of the industrial control network topology and randomly walks through the target industrial control network to quantify the safety potential coefficient of the industrial control verification node.

[0028] The method provided in this application embodiment includes the following steps before "the safety potential coefficient of the quantitative chemical control verification node":

[0029] Identify industrial control verification nodes, wherein the industrial control verification nodes include at least key terminals, network devices, and controllers;

[0030] Define the quantitative elements of the security potential coefficient, wherein the quantitative elements include at least the density of defense measures, the strength of the strategy, the value of industrial control, the purity of the behavioral baseline, and the security coupling degree of the node.

[0031] First, industrial control system (ICS) verification nodes are identified. These verification nodes include at least key terminals, network devices, and controllers. ICS verification nodes refer to the main equipment in the ICS network that has a critical impact on business operations and requires focused monitoring of its safety status; they are the primary objects for safety potential quantification. Based on the importance of the ICS network's business processes, nodes that play a crucial role in production continuity are selected, covering the three main types of equipment: key terminals, network devices, and controllers. For example, in the aforementioned automotive production line ICS network, the following ICS verification nodes are selected: Key Terminal: The robot terminal responsible for processing engine cylinder blocks; Network Device: The core industrial switch connecting the controller and the terminal; Controller: The PLC controller controlling the cycle time of the entire production line; a total of 8 ICS verification nodes are selected.

[0032] Secondly, the quantitative elements of the security potential coefficient are defined. These quantitative elements include at least the density of defensive measures, the strength of strategies, the value of industrial control systems, the purity of behavioral baselines, and the security coupling degree of nodes. The security potential coefficient is a numerical indicator reflecting the security status of industrial control nodes, obtained through a comprehensive evaluation of multiple quantitative elements. The quantitative elements refer to the main evaluation dimensions used to calculate the security potential coefficient and are the basis for quantifying the security status. Each element is assigned a quantitative scoring standard of 0-10. The density of defensive measures reflects the number of security protection devices deployed on the node; the strength of strategies reflects the strictness of security strategies; the value of industrial control systems measures the importance of the node to the business; the purity of behavioral baselines indicates the degree of conformity between the node's behavior and the normal baseline; and the security coupling degree of nodes reflects the close security relationship between the node and other nodes. For example, quantitative standard elements are set for the above 8 industrial control verification nodes: Defense measure density: 8 points for deploying a firewall, 3 points for not having a firewall; Policy strength: 10 points for whitelist policy, 6 points for ordinary ACL policy; Industrial control value: 10 points for key controllers, 5 points for ordinary terminals; Behavioral baseline purity: 10 points for behavior conformity of 95% or more, 7 points for 80%-95%; Node security coupling: 9 points for connecting more than 5 key nodes, 6 points for connecting 2-4 nodes.

[0033] Then, the data probe is input into any node of the industrial control network topology, and randomly walks within the target industrial control network to quantify the safety potential coefficient of the industrial control verification node. The data probe is input into any node of the industrial control network topology, and does not follow a fixed path within the industrial control network. Through a protocol forwarding mechanism, the probe randomly walks within the network, collecting response data from each industrial control verification node. Combined with a preset quantitative element scoring standard, the safety potential coefficient of each node is calculated. For example, the above 10 sets of Modbus protocol data probes are input into an industrial switch, and the probes are forwarded by the switch to each robot terminal and PLC controller. The response data collected from a certain PLC controller meets the normal standard, and its quantitative element score is: defense measure density 8 points, strategy strength 10 points, industrial control value 10 points, behavioral baseline purity 10 points, and node security coupling degree 9 points; weighted summation, with each element having a weight of 0.2, yields a safety potential coefficient = (8 + 10 + 10 + 10 + 9) × 0.2 = 9.4 points. A typical terminal, having only deployed a basic firewall, has a defense density of only 3 points and a security potential coefficient of (3+6+5+8+6)×0.2=5.6 points.

[0034] Finally, based on the industrial control network topology, the safety potential energy coefficients are topologically integrated to generate the contour potential energy map. Using the established industrial control network topology as the basic framework, the safety potential energy coefficient of each industrial control verification node is mapped to its corresponding topological location. An interpolation algorithm is used to supplement the potential energy estimates of non-verification nodes, resulting in a visual map representing the potential energy distribution using contour lines. A contour potential energy map is a visual chart that uses contour lines to intuitively display the distribution of safety potential energy coefficients in different areas, based on the industrial control network topology. It can quickly identify high-safety-level and low-safety-level areas. For example, using the three-level topology of an automotive production line industrial control network as the basis, the safety potential energy coefficients of the eight verification nodes are marked at their corresponding equipment locations. The area around the PLC controller has a high security level, and data probes approaching it will be recorded by the firewall, reviewed by the sandbox, and monitored by the IDS, resulting in a security potential energy coefficient of 9.4 points. This forms a steep potential energy cliff in the map, marked with dense red contour lines. A certain ordinary terminal has weak defenses, and data can reach it without resistance, resulting in a potential energy coefficient of 5.6 points, marked with sparse blue contour lines. The potential energy estimates of other auxiliary nodes are calculated using a linear interpolation algorithm to complete the contour potential energy map.

[0035] In the method provided in this application embodiment, "the security resilience coefficient based on industrial control network topology fine-tuning test" is, for example... Figure 2 As shown, it includes:

[0036] A potential field adjustment mode is set, and the industrial control network topology is locally fine-tuned based on quantization elements according to the first potential field adjustment mode to determine the first body fine-tuning network topology.

[0037] The first test potential energy map is determined by quantizing the random walk and safety potential energy coefficient based on the data probe;

[0038] Based on the first test potential energy diagram, a first safety elastic coefficient is generated;

[0039] Combine the first potential field adjustment mode with the first safety elasticity coefficient, and add an effectiveness verification database.

[0040] First, a potential field adjustment mode is set. Based on the first potential field adjustment mode, the industrial control network topology is locally fine-tuned based on quantitative elements to determine the first-body fine-tuned network topology. The potential field adjustment mode refers to a specific method for locally adjusting the industrial control network topology, set to test network security resilience. Local fine-tuning refers to making slight, temporary adjustments to security parameters only for specific nodes or areas in the industrial control network, without changing the overall topology architecture, used to simulate controllable defense weakening scenarios. Multiple potential field adjustment modes are defined, such as adjusting the IDS confidence threshold and disabling a single defense device. For specific nodes in the industrial control network topology, slight, temporary local parameter adjustments are made based on quantitative elements to form the fine-tuned topology structure, ensuring that the adjustment process is controllable and does not affect normal network operation. For example, the first potential field adjustment mode is set: temporarily increasing the IDS confidence threshold of a certain PLC controller, adjusting the original 80% threshold of that node to 90%, simulating slight defense weakening; selecting the aforementioned PLC controller for fine-tuning forms the corresponding first-body fine-tuned network topology.

[0041] Secondly, a first test potential energy map is determined based on the random walk and security potential energy coefficient quantization of the data probe. The data probe is subjected to a random walk in the first-body fine-tuning network topology. For example, after the data probe is subjected to a random walk in the first-body fine-tuning network topology, the security potential energy coefficient of the chemical control verification node is requantified to generate the first test potential energy map.

[0042] Furthermore, based on the first test potential energy diagram, a first security resilience coefficient is generated. The security resilience coefficient refers to the ability of the defense system to restore balance or maintain stability after local fine-tuning of the industrial control network topology.

[0043] In the method provided in this application embodiment, if the first test potential energy map is a potential energy self-healing state based on local fine-tuning, the speed and efficiency of restoring balance after adjustment are elastically quantified and used as the first safety elastic coefficient. The self-healing state is the stable state of the defense system under topological cooperation where local potential energy flows to the weakened point to replenish it.

[0044] For example, consider a PLC controller in the industrial control network of an automotive parts production line. Its original safety potential coefficient was 9.4. A potential field adjustment mode was used to temporarily increase the IDS confidence threshold, raising it from 80% to 90% to simulate a slight weakening of defenses and conduct resilience testing. Data probes randomly walked through the fine-tuned topology and collected data showing that the PLC controller's safety potential coefficient temporarily dropped to 8.2. Due to the reduced IDS alarm sensitivity, the strategy strength score decreased from 10 to 8. At this time, three robot terminals communicating with the PLC controller, with original safety potential coefficients of 8.5, 8.3, and 8.0 respectively, detected the weakening defenses through a topology collaboration mechanism. They automatically increased their own safety strategy strength, lowering the IDS confidence threshold from 80% to 75%, resulting in corresponding increases in safety potential coefficients of 8.8, 8.6, and 8.3 respectively. The potential energy of surrounding nodes flows to replenish the weakened point, and the overall network potential energy distribution recovers to the stable level before fine-tuning within 1.5 minutes, forming a potential energy self-healing state. The recovery speed weight is set at 0.3, and the recovery efficiency weight at 0.7. The recovery speed scoring criteria are: 5 points for within 1 minute, 3.5 points for 1-2 minutes, and 2 points for more than 2 minutes; the recovery efficiency scoring criteria are: 9-10 points for a recovery rate ≥95%, 7-8 points for 90%-94%, and less than 5 points for less than 90%. A recovery speed of 1.5 minutes corresponds to a score of 3.5 points; the recovery efficiency is calculated as the percentage of potential energy recovery. In this case, the network recovered to 98% of its original stable level, corresponding to a score of 9.2 points. The final first safety elasticity coefficient is (3.5 × 0.3) + (9.2 × 0.7) = 1.05 + 6.44 = 7.49 points.

[0045] In the method provided in this application embodiment, if the first test potential energy map is a potential energy weakening state based on local fine-tuning, the zero value is used as the first safety elasticity coefficient. The potential energy weakening state is the unbalanced state of the defense system under topological isolation where the local potential energy has no response and the potential energy at the weakening point decreases.

[0046] For example, considering a typical terminal in the aforementioned industrial control network with an original security potential coefficient of 5.6, a potential field adjustment mode with basic firewall rules temporarily disabled was used to simulate a local protection gap and conduct a resilience test. Data probes randomly walked through the fine-tuned topology and collected data showing that the security potential coefficient of this typical terminal rapidly dropped to 3.0. Due to the firewall rules being disabled, the defense measure density score dropped from 3 to 1. Observation revealed that the industrial switches and other terminals connected to this typical terminal did not respond at all; they neither increased their own security policy strength nor replenished the potential energy to the weakened point. The potential energy of this typical terminal continued to deplete, forming a topological isolation state with surrounding nodes. The overall defense system exhibited an unbalanced state, resulting in a weakened potential energy state. Since this local fine-tuning caused a decrease in the potential energy of the weakened point without any topological collaborative response, it met the definition of a weakened potential energy state. Therefore, the first security resilience coefficient was set to zero.

[0047] Finally, the first potential field adjustment mode and the first safety elasticity coefficient are combined and added to the validity verification database. For all industrial control verification nodes, multiple rounds of repeated testing are conducted using different potential field adjustment modes. The adjustment parameters, test potential energy diagram status, and safety elasticity coefficient are recorded for each round of testing. All related data are then bound and added to the validity verification database to form a complete elasticity assessment dataset. For example, for the above 8 verification nodes, three adjustment modes—adjusting the IDS threshold, disabling a single defense device, and modifying the ACL policy—are used, with 3 rounds of testing for each, resulting in a total of 72 sets of test data. The adjustment mode parameters, safety elasticity coefficient, and status description in each set of data are bound and added to the validity verification database of the automotive production line industrial control network, recording the detailed test process and results.

[0048] The method provided in this application embodiment, "constructing a network effectiveness baseline map", includes:

[0049] Based on the contour potential energy map and the safety elasticity coefficient, a network effectiveness baseline map is generated, wherein the industrial control verification node and the safety elasticity coefficient are in one-to-one correspondence.

[0050] Nodes with a security resilience coefficient of zero or below a preset resilience threshold in the network effectiveness baseline graph are identified as risk control verification nodes.

[0051] First, a network effectiveness baseline map is generated based on the contour potential energy map and security resilience coefficients, where each industrial control system (ICS) verification node corresponds one-to-one with a security resilience coefficient. The contour potential energy map is then fused with the average security resilience coefficients from multiple rounds of testing at each node to form a network effectiveness baseline map that includes static security potential energy and dynamic resilience capabilities. Each ICS verification node corresponds one-to-one with its corresponding average security resilience coefficient. For example, the network effectiveness baseline map is generated by fusion of the contour potential energy map with the average security resilience coefficients from eight verification nodes. The network effectiveness baseline map is a comprehensive map integrating security potential energy distribution and security resilience coefficients from multiple rounds of testing, serving as a benchmark for evaluating the network effectiveness of industrial control systems (ICS) networks.

[0052] Secondly, nodes with a security resilience coefficient of zero or below a preset resilience threshold in the network effectiveness baseline graph are identified as risk control verification nodes. An resilience threshold is set, and nodes with a security resilience coefficient of zero or below the set threshold are identified as risk control verification nodes. For example, if the preset resilience threshold is set to 4.0, then the ordinary terminal with a coefficient of 0 in Mode 2 testing, and two other nodes with average security resilience coefficients of 3.6 and 3.8, are identified as risk control verification nodes; the remaining nodes with security resilience coefficients higher than the threshold are not identified.

[0053] In this embodiment, by quantifying the security potential energy coefficient and visualizing the contour potential energy map, combined with the potential energy cliff characteristics of key nodes, a precise characterization of the static security state of the industrial control network is achieved. Based on multiple rounds of resilience testing and security resilience coefficient calculation, the collaborative capability and self-recovery capability of the defense system are comprehensively evaluated. The network effectiveness baseline map constructed by integrating static potential energy and dynamic resilience data provides a more comprehensive benchmark for subsequent security verification. By accurately identifying risk control verification nodes, the key objects of operation and maintenance management are clarified, significantly improving the pertinence and foresight of security protection.

[0054] S200: By locating the risk control verification node in the network validity baseline map, adding an entropy verification threshold, performing entropy change monitoring of the node's real-time data stream, and determining the node's real-time verification result.

[0055] In this embodiment, risk control verification nodes are located in the network validity baseline map, an entropy verification threshold is added, and entropy change monitoring of the node's real-time data stream is performed to determine the node's real-time verification result. By adding an entropy verification threshold based on node security characteristics and implementing real-time data stream entropy change monitoring for risk control verification nodes, dynamic perception of node security status can be achieved, risks caused by disordered data stream mutations can be accurately identified, real-time data support for industrial control network security validity verification can be provided, and the accuracy and real-time performance of verification can be further improved.

[0056] First, risk control verification nodes are located in the network effectiveness baseline map. Based on the network effectiveness baseline map generated by S100, nodes with a safety resilience coefficient of zero or below a preset resilience threshold are extracted to form a list of risk control verification nodes that need to be monitored in key areas, thus clarifying the objects to be monitored in real time. For example, in the effectiveness baseline map of the industrial control network of an automotive parts production line, three nodes are selected as risk control verification nodes: a regular terminal with a safety resilience coefficient of 0, a robot terminal with a coefficient of 3.6, and an industrial switch with a coefficient of 3.8, numbered T01, R03, and S02, respectively.

[0057] Secondly, an entropy verification threshold is added to monitor the entropy change of the real-time data stream of the execution node and determine the real-time verification result of the node.

[0058] The method provided in this application embodiment, which "adds an entropy verification threshold, performs entropy change monitoring of the node's real-time data stream, and determines the node's real-time verification result", includes:

[0059] As the industrial control network operates, network data flow monitoring is performed on the risk control verification nodes, and the data is encapsulated into node data packets;

[0060] Set an entropy verification threshold, and generate real-time node verification results by performing entropy change verification on node data packets based on risk control verification nodes.

[0061] First, as the industrial control network operates, network data flow monitoring is performed on the risk control verification nodes, and the data is encapsulated into node data packets. Multi-dimensional data acquisition tools are deployed to capture network traffic, process behavior, control command sequences, and associated physical data of the risk control verification nodes in real time. Various types of data are parsed according to standardized formats and integrated and encapsulated into node data packets containing complete status information. Control command sequences refer to the set of commands transmitted between industrial control nodes to implement equipment control functions; physical data refers to entity parameter data related to the operating status of industrial control equipment, such as temperature, pressure, and rotational speed; node data packets refer to standardized data units formed after integrating multi-dimensional real-time data, providing a complete data source for entropy change verification. Continuing the previous example, acquisition tools are deployed on nodes T01, R03, and S02 to acquire Modbus protocol network traffic, equipment process operation logs, PLC control command sequences, and the robotic arm operating temperature data corresponding to R03 in real time. Fifteen data entries from T01 for a certain period are encapsulated into node data packets in the format of [data type + timestamp + content summary], covering normal control commands, regular process lists, and temperature data.

[0062] Secondly, an entropy verification threshold is set, and real-time node verification results are generated by performing entropy change verification on node data packets based on risk control verification nodes.

[0063] The method provided in this application embodiment, "setting an entropy verification threshold and performing entropy change verification based on node data packets of risk control verification nodes," includes:

[0064] Based on the quantitative elements of the safety potential energy coefficient, the defensive entropy reduction behavior of the industrial control verification node is quantified to determine the node entropy change baseline.

[0065] If there is entropy increase and no regression, or if the entropy increase regression does not meet the node entropy change baseline, an attack risk will be used as the node's real-time verification result.

[0066] If there is no entropy increase, or if there is entropy increase and the entropy increase regression satisfies the node entropy change baseline, the industrial control safety status will be used as the node's real-time verification result.

[0067] First, based on the quantitative elements of the security potential coefficient, the defensive entropy reduction behavior of the industrial control verification node is quantified to determine the node entropy change baseline. The node entropy change baseline refers to the entropy value reference standard determined based on the node's defense capability and historical normal data. It serves as the basis for judging whether the entropy change is abnormal and whether the defense is effective. Based on the quantitative elements of the security potential coefficient in S100, such as defense measure density and strategy strength, the defensive entropy reduction effect of the risk control verification node is quantified, that is, the ability of defense measures to resist attacks and maintain entropy value stability. Combining the entropy statistics of multi-dimensional data under historical normal conditions, the node entropy change baseline is set, including the normal entropy value range, the abnormal entropy value threshold, and the entropy value regression time limit. For example, for the T01 terminal, with defense measure density of 1 point, strategy strength of 6 points, industrial control value of 5 points, behavioral baseline purity of 8 points, and node security coupling of 6 points, its defensive entropy reduction effect score is (1+6+5+8+6)×0.2=5.2 points. The information entropy value under normal conditions over the past 7 days ranged from 1.8 to 2.5. An entropy baseline was set: normal entropy range 1.8-2.5, abnormal entropy increase threshold 3.0, abnormal entropy decrease threshold 1.2, and entropy return time limit 30 seconds. This means that after defensive measures take effect, the abnormal entropy value must be brought back to the baseline range within 30 seconds. Abnormal entropy increase refers to a state where node data disorder increases due to attack behaviors such as scanning, penetration, and data leakage, resulting in an entropy value exceeding the normal range. Abnormal entropy decrease refers to a state where data is forcibly ordered due to covert attacks such as ransomware encryption, resulting in an abnormally low entropy value.

[0068] Secondly, if entropy increase exists without regression, or if the entropy increase regression does not meet the node entropy change baseline, an attack risk is identified as the node's real-time verification result. If the entropy value increases abnormally (exceeding the abnormal entropy increase threshold and failing to regress within the regression time limit), or decreases abnormally (below the abnormal entropy decrease threshold) without a reasonable cause, it is determined to be an entropy value anomaly caused by an attack, and the node's real-time verification result is: an attack risk exists. For example, when monitoring the T01 terminal, a large number of port scanning data packets were found in the network traffic during a certain period, the real-time entropy value suddenly increased from 2.2 to 3.9, and did not regress for 40 seconds. At the same time, an unknown process appeared in the process behavior, which was determined to be: an attack risk exists.

[0069] Furthermore, if there is no entropy increase, or if there is entropy increase and the entropy change returns to the node's entropy change baseline, the industrial control system (ICS) security status is used as the node's real-time verification result. If the entropy value is within the normal range, or if it quickly returns to the baseline after an anomaly due to the effectiveness of defensive measures, it is determined that the defense entropy reduction effect is effective, and the node's real-time verification result is: ICS security status. When monitoring the R03 terminal, an illegal control command attempting to access was captured, and the entropy value briefly rose to 3.2. At this time, the IPS deployed on the node immediately intercepted the command, and the entropy value dropped back to 2.1 within 25 seconds, which meets the expectation of the defense entropy reduction effect, and it is determined to be: ICS security status.

[0070] In this embodiment, a multi-dimensional data information entropy quantification method is adopted, breaking through the limitations of traditional single-dimensional monitoring. It can identify both abnormal entropy increases caused by attacks and abnormal entropy decreases caused by covert attacks, significantly improving the comprehensiveness and accuracy of risk identification. The quantification of the defense entropy reduction effect is integrated into the entropy change baseline setting. By monitoring the entire process of entropy value from anomaly to regression, dynamic evaluation of the actual effectiveness of defense measures is achieved, making security verification not only focus on risk identification but also consider the judgment of defense effectiveness. Real-time entropy change monitoring of risk control verification nodes enables rapid response to potential attacks, providing dynamic and accurate risk basis for operation and maintenance management, further enhancing the real-time and targeted nature of industrial control network security verification, and providing strong support for subsequent operation and maintenance decisions.

[0071] S300: By coupling the network validity baseline map with the real-time verification results of the nodes, the validity verification results of the industrial control network are used as the target industrial control network operation and maintenance management.

[0072] In this embodiment, the network validity baseline map and the real-time node verification results are coupled to serve as the validity verification results of the industrial control network and are used for the operation and maintenance management of the target industrial control network. The network validity baseline map reflects the intrinsic security state based on the configuration and is a static benchmark; the real-time node verification results reflect the dynamic security state of the risk control verification nodes. Both have limitations when used alone: ​​relying solely on the baseline map cannot capture the state changes caused by real-time attacks, and relying solely on the real-time results lacks a reference framework for the overall security situation. By coupling the two layers of verification data, the global perspective of the static baseline and the real-time details of dynamic monitoring can be integrated to form a validity verification result that is both comprehensive and timely. This provides accurate and complete decision-making basis for the operation and maintenance management of the industrial control network and solves the one-sidedness problem of single-dimensional verification.

[0073] In the method provided in this application embodiment, a first verification layer is constructed based on the network validity baseline map, and a second verification layer is updated based on the real-time verification results of the nodes. By coupling the first verification layer and the second verification layer, the validity verification result of the target industrial control network is obtained.

[0074] First, a first verification layer is constructed based on the network validity baseline diagram. Using the network validity baseline diagram generated by S100 as a foundation, the safety potential coefficient, safety resilience coefficient, and risk control verification node identifiers of each node in the diagram are retained to form a first verification layer covering the global intrinsic security state of the industrial control network, serving as a benchmark reference framework for security validity. For example, the first verification layer of an industrial control network for an automotive parts production line includes 8 industrial control verification nodes with safety potential coefficients ranging from 5.6 to 9.4 and safety resilience coefficients ranging from 0 to 5.0. Three risk control verification nodes are marked in red, visually presenting the intrinsic security level and resilience capabilities of each node. The first verification layer, using the network validity baseline diagram as its carrier, is a static verification framework reflecting the configuration-based intrinsic security state of the industrial control network.

[0075] Secondly, the second verification layer is updated based on the real-time verification results of the nodes. Based on the real-time verification results of the S200 nodes, the real-time security status and entropy change data of the risk control verification nodes are extracted to form a dynamically updated second verification layer, focusing on the real-time changes of risk nodes. For example, the second verification layer data for the above three risk control verification nodes are as follows: Terminal T01 is at risk of attack, with an entropy value of 3.9 for 40 seconds; Terminal R03 is in an industrial control security state, with the entropy value briefly rising to 3.2 before returning to 2.1 after 25 seconds; Switch S02 is at risk of attack, with the entropy value plummeting to 1.0; the data is updated every 10 seconds. The second verification layer, with the real-time verification results of the nodes as its core, is a real-time verification framework reflecting the dynamic security status and entropy change characteristics of the risk control verification nodes.

[0076] Furthermore, by coupling the first verification layer and the second verification layer, the validity verification result of the target industrial control network is obtained. Real-time data from the second verification layer is overlaid onto the baseline graph of the first verification layer. Color coding is used to associate the intrinsic and real-time states of the risk control verification nodes; for example, [Attack Risk Exists] is marked with a flashing orange indicator, and [Industrial Control Security Status] is marked with green. Baseline information is retained for non-risk control nodes, forming a validity verification result that integrates static benchmarks and dynamic changes. For example, in the baseline graph of the first verification layer, terminal T01 is overlaid with a flashing orange indicator and a note: [Entropy value 3.9, lasting 40 seconds, attack risk exists]; terminal R03 is overlaid with a green indicator and a note: [Entropy value 2.1, effective entropy reduction defense]; switch S02 is overlaid with a flashing orange indicator and a note: [Entropy value 1.0, abnormal entropy reduction]; the remaining non-risk control nodes retain their original baseline colors and coefficient labels, forming a complete validity verification result.

[0077] Finally, the target industrial control network is managed and maintained based on the effective verification results. According to the coupled verification results, targeted measures are taken for nodes in different states: for nodes with attack risks, real-time defense responses are triggered, such as blocking abnormal traffic, isolating nodes, and tracing the attack source; for risk-controlled nodes in an industrial control security state, their entropy change trends are continuously monitored; for non-risk-controlled nodes, configuration checks are periodically performed against the baseline to ensure the stability of the intrinsic security state. For example, for the attack risk result of the T01 terminal, the firewall is automatically triggered to block abnormal scanning traffic, and maintenance personnel remotely log in to check unknown processes; for the R03 terminal, entropy changes are continuously monitored to confirm the effectiveness of defense measures; for non-risk-controlled PLC controllers, the IDS policy and firewall configuration are checked against the baseline weekly to ensure that the intrinsic security state does not deviate from the baseline.

[0078] In this embodiment, by coupling static baselines with dynamic real-time data, the limitations of single-dimensional verification are overcome, enabling the validity verification results to encompass both the global intrinsic security situation and reflect the real-time state changes of risk nodes, thereby improving the comprehensiveness and accuracy of the verification. Targeted operation and maintenance management measures are formulated based on the precise results after coupling, avoiding blind operations and improving the speed of risk response and the utilization efficiency of defense resources. By continuously linking baselines and real-time data, a closed-loop management mechanism of benchmark-monitoring-response-optimization is formed, effectively improving the dynamic optimization and long-term stable operation of industrial control network security status.

[0079] The embodiments of this application, through the specific implementation methods described above, achieve the following technical effects:

[0080] This application provides a method for verifying the effectiveness of industrial control system (ICS) network security. By constructing a network effectiveness baseline map, the intrinsic security state of the ICS network is accurately quantified. Combined with multi-dimensional assessments of security potential coefficients and security resilience coefficients, the overall security posture and the distribution of high-risk nodes are clearly depicted. Through multi-dimensional real-time data flow entropy change monitoring of risk control verification nodes, both abnormal entropy increases caused by attacks and abnormal entropy decreases caused by covert attacks can be captured, effectively improving the comprehensiveness and accuracy of risk identification. By coupling the global perspective of the static baseline with the real-time details of dynamic monitoring, a comprehensive and timely effectiveness verification result is formed, providing accurate decision-making basis for operation and maintenance management. Targeted defense response and closed-loop management measures significantly improve the efficiency of risk handling and defense resource utilization, contributing to the dynamic optimization of the ICS network security status, ensuring its long-term stable operation, and comprehensively improving the accuracy and real-time performance of ICS network security effectiveness verification.

[0081] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0082] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0083] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A method for verifying the effectiveness of industrial control system network security, characterized in that, The method includes: The topology of the industrial control network based on the target industrial control network is determined, and a network effectiveness baseline map is constructed by performing a safety potential energy field mapping. The safety effectiveness of the industrial control network is quantified into a safety potential energy coefficient. The network effectiveness baseline map is composed of a contour potential energy map based on the invariant industrial control network topology and a safety elasticity coefficient based on the industrial control network topology fine-tuning test. By locating risk control verification nodes in the network effectiveness baseline diagram, adding an entropy verification threshold, and performing entropy change monitoring of the node's real-time data stream, the real-time verification result of the node is determined. By coupling the network validity baseline map with the real-time verification results of the nodes, the validity verification results of the industrial control network are used as the target industrial control network operation and maintenance management; Among them, the contour potential energy map based on the invariant industrial control network topology includes: Generate a data probe, wherein the data probe is a set of industrial control data packets that do not carry malicious payloads; The data probe is input into any node of the industrial control network topology and randomly walks through the target industrial control network to quantify the safety potential coefficient of the industrial control verification node. Based on the industrial control network topology, the safety potential energy coefficient is topologically integrated to generate the contour potential energy map.

2. The method for verifying the effectiveness of industrial control system network security as described in claim 1, characterized in that, Before the safety potential coefficient of the quantitative chemical control verification node, it includes: Identify industrial control verification nodes, wherein the industrial control verification nodes include at least key terminals, network devices, and controllers; Define the quantitative elements of the security potential coefficient, wherein the quantitative elements include at least the density of defense measures, the strength of the strategy, the value of industrial control, the purity of the behavioral baseline, and the security coupling degree of the node.

3. The method for verifying the effectiveness of industrial control network security as described in claim 2, characterized in that, The security resilience coefficient based on industrial control network topology fine-tuning test includes: A potential field adjustment mode is set, and the industrial control network topology is locally fine-tuned based on quantization elements according to the first potential field adjustment mode to determine the first body fine-tuning network topology. The first test potential energy map is determined by quantizing the random walk and safety potential energy coefficient based on the data probe; Based on the first test potential energy diagram, a first safety elastic coefficient is generated; Combine the first potential field adjustment mode with the first safety elasticity coefficient, and add an effectiveness verification database.

4. The method for verifying the effectiveness of industrial control network security as described in claim 3, characterized in that, If the first test potential energy map is a potential energy self-healing state based on local fine-tuning, the speed and efficiency of restoring balance after adjustment are elastically quantified and used as the first safety elastic coefficient. Here, the self-healing state is the stable state of the defense system under topological cooperation where local potential energy flows to the weakened point to replenish it.

5. The method for verifying the effectiveness of industrial control network security as described in claim 4, characterized in that, If the first test potential energy map is a potential energy weakening state based on local fine-tuning, the zero value is taken as the first safety elasticity coefficient. The potential energy weakening state is the unbalanced state of the defense system under topological isolation where the local potential energy has no response and the potential energy at the weakening point decreases.

6. The method for verifying the effectiveness of industrial control network security as described in claim 5, characterized in that, Construct a network effectiveness baseline diagram, including: Based on the contour potential energy map and the safety elasticity coefficient, a network effectiveness baseline map is generated, wherein the industrial control verification node and the safety elasticity coefficient are in one-to-one correspondence. Nodes with a security resilience coefficient of zero or below a preset resilience threshold in the network effectiveness baseline graph are identified as risk control verification nodes.

7. The method for verifying the effectiveness of industrial control network security as described in claim 1, characterized in that, Add an entropy verification threshold, perform entropy change monitoring of real-time data streams from nodes, and determine the real-time verification results of nodes, including: As the industrial control network operates, network data flow monitoring is performed on the risk control verification nodes, and the data is encapsulated into node data packets; Set an entropy verification threshold, and generate real-time node verification results by performing entropy change verification on node data packets based on risk control verification nodes.

8. The method for verifying the effectiveness of industrial control network security as described in claim 7, characterized in that, Set an entropy verification threshold and perform entropy change verification on node data packets based on the risk control verification node, including: Based on the quantitative elements of the safety potential energy coefficient, the defensive entropy reduction behavior of the industrial control verification node is quantified to determine the node entropy change baseline. If there is entropy increase and no regression, or if the entropy increase regression does not meet the node entropy change baseline, an attack risk will be used as the node's real-time verification result. If there is no entropy increase, or if there is entropy increase and the entropy increase regression satisfies the node entropy change baseline, the industrial control safety status will be used as the node's real-time verification result.

9. The method for verifying the effectiveness of industrial control network security as described in claim 1, characterized in that, A first verification layer is constructed based on the network validity baseline map, and a second verification layer is updated based on the real-time verification results of the nodes. By coupling the first verification layer and the second verification layer, the validity verification results of the target industrial control network are obtained.

Citation Information

Patent Citations

  • Method and system for monitoring network security of power grid industrial control system

    CN114172702A

  • Industrial field network security online monitoring system

    CN120050104A