Industrial firewall device based on time sequence graph detection

By constructing an industrial firewall device with time-series graph detection, the problem of insufficient detection of covert time-series attacks in industrial firewalls is solved. It achieves accurate identification and rapid protection of industrial protocol communications, adapts to multi-protocol scenarios, reduces hardware costs, and improves operation and maintenance efficiency.

CN121125333APending Publication Date: 2025-12-12BEIJING CATHAY INTERNET INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511561757.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-29
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Existing industrial firewalls struggle to detect covert timing attacks by attackers that alter packet intervals and disrupt response sequences, and in resource-constrained environments, they cannot rely on complex computations, resulting in inadequate protection.

Method used

An industrial firewall device based on time-series graph detection is adopted. Through data acquisition, feature extraction, graph modeling, detection analysis and protection response modules, it constructs and detects the time-series characteristics of industrial protocols in real time, so as to achieve accurate identification and rapid protection against abnormal behavior.

Benefits of technology

It accurately identifies covert timing attacks, reduces hardware costs, adapts to multi-protocol scenarios, ensures real-time response, provides tiered protection and visual traceability, and improves the security and operational efficiency of industrial control networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125333A_ABST
    Figure CN121125333A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial firewall device based on time sequence atlas detection, which relates to the technical field of industrial control network security and comprises the steps of protocol identification, feature extraction, time sequence atlas construction, baseline modeling, online detection and response protection. Extracting time sequence characteristics such as a request-response relationship, a time interval and an event sequence, and converting the time sequence characteristics into a time sequence graph on which nodes correspond to communication events and edges correspond to time sequences; and generating a baseline map based on normal data, comparing the deviation between the current map and the baseline map in real-time communication, and executing a protection action after judging abnormality. The device for realizing the method comprises a data acquisition module, a feature extraction module, an atlas modeling module, a detection analysis module, a protection response module, a man-machine interaction module and a wide-voltage power supply module which are electrically connected in sequence. According to the method and the device, hidden time sequence attacks can be accurately identified, multiple industrial protocols are supported, and the adaptive resource-limited industrial equipment is designed in a lightweight manner.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial control network security, and particularly relates to an industrial firewall device based on time sequence graph detection. BACKGROUND

[0002] Existing industrial firewalls are mainly based on static rule matching or deep packet inspection (DPI) mechanisms, and the core thereof is to perform legality verification and simple policy filtering on protocol fields. This kind of method has certain protection effect on abnormal fields and illegal instructions, but has obvious deficiencies in the following cases: Time sequence abnormal attack: the communication of an industrial control system (ICS) has stability, periodicity and order, for example, an IEC104 master station initiates a total call periodically, the response order of a slave station is fixed, Modbus is periodically queried, and OPCUA is subscribed and updated. An attacker can not modify the protocol field, but can realize hidden attack by changing the message interval and disturbing the response order.

[0003] Detection avoidance means: an attacker uses the legality of the protocol stack to cover abnormal behavior, and a traditional firewall is difficult to find problems through rule or field verification.

[0004] Resource-limited environment: industrial field devices (such as isolation devices and firewalls) usually have limited hardware resources, and cannot rely on complex deep learning or mass storage.

[0005] In summary, there is an urgent need for a protection method that can model the time sequence characteristics of industrial protocol communication and detect abnormal behavior in real time under limited hardware conditions.

[0006] Therefore, the person skilled in the art provides an industrial firewall device based on time sequence graph detection to solve the problems in the background art. SUMMARY

[0007] The purpose of the present application is to provide an industrial firewall device based on time sequence graph detection to solve the problems in the background art.

[0008] To achieve the above purpose, the present application provides the following technical scheme: An industrial firewall device based on time sequence graph detection, comprising a data acquisition module, a feature extraction module, a graph modeling module, a detection analysis module, a protection response module, a man-machine interaction module for visual management and a wide voltage power supply module for powering each module, which are electrically connected in sequence; the data acquisition module adopts a gigabit Ethernet interface, integrates a message capture chip and a multi-protocol identification unit, can capture all industrial network traffic and automatically identify mainstream industrial protocols, ensures accurate traffic analysis and no loss of key data; the feature extraction module takes an FPGA chip as the core and carries a time sequence feature extraction engine, which can extract key time sequence features such as time interval, request-response matching relationship and event trigger sequence from message sequences, and filter invalid messages to reduce interference; the graph modeling module carries an industrial-grade processor, which can convert time sequence features into time sequence graphs (nodes correspond to communication events, and edges correspond to time sequence dependencies between events), and store baseline graphs generated based on normal communication data, and support baseline incremental update; the detection analysis module can construct a current communication time sequence graph in real time, determine time sequence anomalies by comparing the deviation between the real-time graph and the baseline graph, and ensure timely abnormality discovery; the protection response module pre-stores multiple protection strategies, and can execute alarm, block or isolation actions according to abnormal conditions; the man-machine interaction module supports visual viewing and parameter adjustment of time sequence graphs and abnormal logs; and the wide voltage power supply module is adapted to voltage fluctuation in industrial field, integrates overvoltage, overcurrent and short circuit protection functions, and ensures stable operation of the device.

[0009] As a further scheme of the present application: the multi-protocol identification unit of the data acquisition module can automatically identify IEC104, Modbus, OPCUA and other mainstream industrial protocols, accurately identify through protocol exclusive fields (such as IEC104 APCI field and Modbus function code), has low analysis process delay, and can automatically filter invalid messages such as broadcast storm and device heartbeat packet, and only retains valid traffic for subsequent processing.

[0010] As a further scheme of the present application: the time sequence feature extraction engine of the feature extraction module can accurately calculate the time interval of continuous communication messages, match the request frame and response frame between master and slave devices, and record the fixed trigger sequence of communication events, so as to ensure that the extracted time sequence features can completely reflect the periodicity and sequence regularity of industrial communication.

[0011] As a further scheme of the present application: the graph modeling module generates a baseline time sequence graph based on communication data in the normal operation stage of the industrial field, the baseline graph can be incrementally updated according to subsequent newly added normal communication modes, and a real-time time sequence graph is generated at a high frequency, so as to ensure that the real-time graph can dynamically reflect the current communication state.

[0012] As a further scheme of the present application: the detection analysis module determines whether there is a timing anomaly by comparing the edge weight difference (i.e., time interval deviation) and node order difference (i.e., event order deviation) of the real-time graph and the baseline graph, and the anomaly determination standard can be flexibly adjusted through the man-machine interaction module to adapt to different industrial control scene requirements.

[0013] As a further scheme of the present application: the protection strategy of the protection response module includes sound and light alarm prompt, cutting off suspicious communication connection, guiding abnormal traffic to an independent network segment for isolation, etc., and a single strategy or a combined strategy can be selected according to the safety requirements of the industrial control scene, and the protection action is executed quickly to avoid the spread of abnormal influence.

[0014] As a further scheme of the present application: the man-machine interaction module is equipped with a touch display screen, which can visually display the baseline timing graph, real-time timing graph and abnormal log details, and also supports adjusting the abnormal determination standard through a remote management interface and exporting historical abnormal records, facilitating the abnormal tracing and device management of operation and maintenance personnel.

[0015] As a further scheme of the present application: the wide voltage power supply module supports the wide range of voltage input commonly seen in industrial sites, and outputs stable voltage for power supply of each module, and the overvoltage, overcurrent and short circuit protection functions respond in time, which can effectively cope with power supply fluctuations in industrial sites and ensure the continuous and stable work of the device in complex environments.

[0016] Compared with the prior art, the present application has the following advantages: 1. Accurate identification of hidden timing attack, filling the protection gap: Breakthrough the limitation of traditional industrial firewall relying only on protocol field verification, by constructing timing graph to model the time interval, request-response relationship and event order characteristics of industrial communication, it can accurately detect hidden timing attacks initiated by attackers through "changing message interval and disturbing response order" (such as IEC104 master station total calling interval anomaly and slave station response order disorder), avoid industrial control system failure caused by timing anomaly, and greatly improve the comprehensiveness of industrial network security protection; 2. Flexible adaptation of multiple protocols, reducing deployment cost: The device is built-in with a protocol recognition unit, which can automatically identify IEC104, Modbus, OPCUA and other mainstream industrial protocols, without the need to replace hardware or additional modules, it can adapt to multiple protocol industrial networks in different scenes such as intelligent manufacturing and energy control. Compared with the traditional scheme of using multiple firewalls to adapt to a single protocol, the present device reduces the number of equipment deployment, and reduces the hardware procurement and operation and maintenance cost; 3. Lightweight design adaptation to industrial resources, ensuring real-time response: Adopting the "FPGA + industrial-grade processor" architecture, the feature extraction and atlas comparison process is lightweight, and does not need to rely on a large amount of computing resources, and can be stably run on resource-limited devices such as industrial field firewalls, isolation devices, etc. At the same time, from real-time atlas construction, anomaly determination to protection action execution, the whole process is time-consuming, and can complete the response within the millisecond level time required by the industrial control system, avoiding the safety risk caused by detection lag; 4. Baseline dynamic update, adapt to network changes: The baseline time series atlas supports incremental update based on new normal communication mode, without the need to re-collect all normal data when the industrial control network topology changes (such as adding slave stations, adjusting communication links), greatly reducing the operation and maintenance workload in dynamic network environment. At the same time, the abnormal judgment standard can be flexibly adjusted through the man-machine interaction module, adapting to the differences in communication rules of different industrial scenes; 5. Hierarchical protection and visualized traceability, improving operation and maintenance efficiency: The protection response module pre-stores hierarchical protection strategies such as alarm, block, isolation, which can be flexibly selected according to the scene safety requirements, avoiding excessive protection affecting normal business, and at the same time, timely containing abnormal expansion. In addition, the device automatically records abnormal logs, and visualizes abnormal details (time, equipment, deviation type) through the touch screen and remote management interface, which facilitates operation and maintenance personnel to quickly trace the cause and optimize the protection strategy, reducing the difficulty of fault troubleshooting. BRIEF DESCRIPTION OF DRAWINGS

[0017] Fig. 1 It is an overall architecture diagram of an industrial firewall system.

[0018] Fig. 2 It is an example diagram of time series atlas construction in an industrial firewall device based on time series atlas detection.

[0019] Fig. 3 It is a flowchart of time series anomaly detection and protection in an industrial firewall device based on time series atlas detection. DETAILED DESCRIPTION

[0020] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.

[0021] Reference Figs. 1-3The embodiment provides an industrial firewall device based on timing graph detection, which is suitable for intelligent manufacturing, energy management and other industrial control systems carrying IEC104, Modbus, OPCUA and other industrial protocols. Through the coherent process of "protocol identification-feature extraction-graph modeling-online detection-protection response", accurate identification and rapid protection of industrial communication timing abnormal attack are realized. The following will be described in detail in combination with the protection scene of the IEC104 protocol industrial control network.

[0022] The industrial firewall device adopts a rack-type hardware structure, and the shell is made of cold-rolled steel plate material and is subjected to anti-static spraying treatment on the surface. It can withstand the complex environment such as high and low temperature and dust commonly seen in industrial sites, and ensure long-term stable operation. The back of the device is provided with four gigabit Ethernet interfaces (two WAN ports for connecting industrial control network core equipment, two LAN ports for connecting terminal equipment), one RS485 debugging interface and one power supply interface; the front panel is provided with four status indicator lights (green for normal operation, yellow for baseline establishment, red for abnormal alarm, and blue for protection action execution) and two operation buttons ("start baseline" button and "manual reset" button); the internal integrated data acquisition chip, FPGA feature extraction module, industrial-grade processor and storage unit, and each component realizes efficient data interaction through an industrial-grade mainboard, ensuring stable signal transmission and low delay.

[0023] When the industrial firewall device accesses the industrial control network, it is first connected to the factory industrial control network core switch through the back WAN port 1, the WAN port 2 is standby, the LAN port 1 is connected to the IEC104 master station (such as the dispatch center server), and the LAN port 2 is connected to the IEC104 slave station cluster (such as the field measurement and control device), so as to ensure that all communication flows between the master station and the slave station pass through the device; after accessing the industrial power supply, the front green "normal operation" indicator light is always on, and the device enters the initial standby state.

[0024] I. Normal communication baseline establishment process Press the front "start baseline" button, and the device switches to the baseline establishment state, and the yellow "baseline establishment" indicator light flashes. At this time, the data acquisition module is started, and the normal communication flow between the IEC104 master and slave stations is captured according to the preset parameters, and during this period, the master and slave stations are kept in normal business operation (such as the master station periodically initiating a total call, and the slave station replying data in order), so as to ensure that the collected flow can cover the complete normal communication period. The data acquisition module simultaneously starts the protocol identification function, automatically identifies the message type through the APCI field (such as the start character and the length field) special for the IEC104 protocol, filters out invalid messages such as switch broadcast packets and device heartbeat detection packets, and only keeps valid business messages such as master station total call, slave station confirmation, slave station measurement value reporting and slave station end frame.

[0025] The feature extraction module receives the valid packets output by the data acquisition module, and deeply processes the packet interaction sequence: extracts the time interval of the master station initiating the total call and the slave station replying the confirmation, the time interval of the slave station confirming to sending the measurement value, and the time interval of the measurement value to the end frame; matches each time the master station request corresponding slave station response frame, establishes the "request-response" corresponding relationship; records the fixed trigger sequence of the communication event (such as "master station total call→slave station confirmation→slave station measurement value→slave station end frame"), and forms a complete timing feature set.

[0026] The atlas modeling module converts the extracted timing features into a baseline timing atlas: taking the communication events such as "master station total call", "slave station confirmation", "slave station measurement value", and "slave station end frame" as atlas nodes, and taking the time interval between events as the edge weight of the connected nodes, the timing dependency relationship of the edge (such as the "master station total call" node pointing to the "slave station confirmation" node, and the normal time interval range marked on the edge) is labeled, a baseline timing atlas reflecting the normal communication rule is generated, and stored in the internal storage unit. If a new normal communication mode is added to the subsequent industrial control network (such as normal interaction after adding a slave station device), the baseline atlas can be automatically updated incrementally, without the need to re-collect all normal data.

[0027] II. Real-time timing anomaly detection process After the baseline atlas is established, the device automatically switches back to the normal operation state, the yellow indicator light is extinguished, the green indicator light is always on, and enters the real-time monitoring mode. The data acquisition module continuously captures the communication traffic of the IEC104 master-slave station, and transmits it to the feature extraction module in real time; the feature extraction module extracts the time interval, request-response matching relationship and event sequence characteristics of the current communication according to the same logic as in the baseline establishment stage, to ensure that the dimensions of the real-time features and the baseline features are consistent.

[0028] The atlas modeling module dynamically constructs the real-time timing atlas of the current communication according to the real-time timing features, and the atlas structure is consistent with the baseline timing atlas (the node type and the dependency relationship of the edge are the same), only the edge weight (time interval) and the node appearance order change with the real-time communication. The detection and analysis module compares the real-time timing atlas with the baseline timing atlas node by node and edge by edge: if the time interval of the real-time communication exceeds the normal range of the corresponding interval of the baseline (such as the interval of the master station total call and the slave station confirmation far exceeds the baseline setting range), or the trigger sequence of the communication event is inconsistent with the baseline sequence (such as the slave station first sends the measurement value and then sends the confirmation), it is determined that the timing is abnormal.

[0029] III. Abnormal protection response process When the detection analysis module determines that there is a timing anomaly, an anomaly signal is immediately sent to the protection response module, the front-end red "anomaly alarm" indicator light flashes, the buzzer emits intermittent prompt sound, and the man-machine interface (equipped with a touch screen) reports the alarm information, including the time of anomaly occurrence, the master and slave station device identifiers involved, and the anomaly type (time interval anomaly or sequence anomaly).

[0030] The protection response module pre-stores three types of protection strategies, which can be selected for execution according to the industrial control scene requirements: if the "alarm priority" strategy is selected, only the sound and light alarm is continuously sent, and the operation and maintenance personnel manually handle; if the "automatic blocking" strategy is selected, after the alarm is triggered, if there is no manual intervention within the preset time, the device automatically cuts off the abnormal communication connection (such as closing the TCP session between the abnormal master and slave stations), preventing the spread of abnormal traffic, at this time the front-end blue "protection action in execution" indicator light is lit; if the "isolation and shunting" strategy is selected, the device guides the abnormal traffic to an independent isolation network segment, without affecting the communication of other normal devices.

[0031] After the protection action is executed, the device automatically records the anomaly log, including anomaly details, executed protection action, action execution time, and other information, the log can be viewed through the touch screen, or exported through the RS485 debugging interface or the remote management interface (access address: 192.168.1.1), which is convenient for subsequent operation and maintenance personnel to trace the anomaly cause and optimize the protection strategy.

[0032] Four, multi-protocol scene adaptation verification Adjust the device parameter configuration to recognize the Modbus protocol, repeat the above baseline establishment and real-time monitoring process: the data acquisition module automatically recognizes the message through the function code of the Modbus protocol (such as read register function code 03, write register function code 06), the feature extraction module extracts the time interval of the master station query and the slave station response under the Modbus protocol, the request-response matching relationship, the atlas modeling module generates the corresponding baseline and real-time timing atlas, the detection analysis module accurately recognizes the timing anomaly under the Modbus protocol (such as shortened query interval anomaly, disordered response sequence), the protection response module executes the alarm and blocking action according to the preset strategy, verifies the adaptability of the device in the multi-protocol scene, and meets the safety protection needs of different industrial protocols without replacing the hardware.

[0033] It will be obvious to a person skilled in the art that the application is not limited to the details of the foregoing exemplary embodiments and can be implemented in other concrete forms without departing from the spirit or essential characteristics of the application. The embodiments are therefore to be considered in all respects as illustrative and not restrictive, the scope of the application being indicated by the appended claims rather than by the foregoing description, and all changes which come within the meaning and range of equivalency of the claims are therefore intended to be embraced therein. No reference signs in the claims should be considered as limiting the scope of the claims to the identity of the reference signs therein.

[0034] Furthermore, it should be understood that although the description is made on the basis of the embodiments, not every embodiment contains only one independent technical solution, and the description of the specification is only for the sake of clarity, and those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that those skilled in the art can understand.

Claims

1. An industrial firewall device based on time-series graph detection, characterized in that, The system comprises a data acquisition module, a feature extraction module, a graph modeling module, a detection and analysis module, and a protection and response module, all electrically connected in sequence. It also includes a human-machine interface module for visual management and a wide-voltage power supply module to power each module. The data acquisition module uses a gigabit Ethernet interface and integrates a packet capture chip and a multi-protocol identification unit. It can capture the full traffic of the industrial control network and automatically identify mainstream industrial protocols, ensuring accurate traffic parsing without losing critical data. The feature extraction module uses an FPGA chip as its core and is equipped with a time-series feature extraction engine. It can extract key time-series features such as time intervals, request-response matching relationships, and event triggering sequences from the packet sequence, while filtering invalid packets to reduce interference. The graph modeling module is equipped with an industrial-grade processor, which can convert time-series features into a time-series graph (nodes correspond to communication events, and edges correspond to time-series dependencies between events) and store a baseline graph generated based on normal communication data, supporting incremental baseline updates. The detection and analysis module can construct the current communication timing graph in real time, and determine timing anomalies by comparing the deviation between the real-time graph and the baseline graph, ensuring timely detection of anomalies; the protection and response module pre-stores multiple protection strategies and can execute alarm, blocking, or isolation actions according to abnormal situations; the human-machine interaction module supports visual viewing and parameter adjustment of timing graphs and anomaly logs; the wide-voltage power supply module adapts to voltage fluctuations in industrial sites and integrates overvoltage, overcurrent, and short-circuit protection functions to ensure stable operation of the device.

2. The industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The multi-protocol identification unit of the data acquisition module can automatically identify mainstream industrial protocols such as IEC104, Modbus, and OPCUA. It achieves accurate identification through protocol-specific fields (such as the APCI field of IEC104 and the function code of Modbus). The parsing process has low latency and can automatically filter invalid messages such as broadcast storms and device heartbeat packets, retaining only valid business traffic for subsequent processing.

3. The industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The temporal feature extraction engine of the feature extraction module can accurately calculate the time interval of continuous communication messages, match request frames and response frames between master and slave devices, and record the fixed triggering order of communication events, ensuring that the extracted temporal features can fully reflect the periodicity and sequentiality of industrial communication.

4. The industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The graph modeling module generates a baseline time series graph based on communication data during normal operation of the industrial site. The baseline graph can be incrementally updated according to newly added normal communication modes. At the same time, it generates a real-time time series graph at a high frequency to ensure that the real-time graph can dynamically reflect the current communication status.

5. An industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The detection and analysis module comprehensively determines whether there is a timing anomaly by comparing the edge weight difference (i.e., time interval deviation) and node sequence difference (i.e., event sequence deviation) between the real-time graph and the baseline graph. The anomaly judgment criteria can be flexibly adjusted through the human-computer interaction module to adapt to the needs of different industrial control scenarios.

6. An industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The protection strategies of the protection response module include audible and visual alarm prompts, cutting off suspicious communication connections, and diverting abnormal traffic to isolated independent network segments. Single or combined strategies can be selected according to the security requirements of industrial control scenarios, and the protection actions are executed quickly to prevent the spread of abnormal impacts.

7. An industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The human-machine interaction module is equipped with a touch screen display, which can intuitively display the baseline time series graph, real-time time series graph and anomaly log details. It also supports adjusting the anomaly judgment criteria and exporting historical anomaly records through the remote management interface, which facilitates anomaly tracing and device management by operation and maintenance personnel.

8. An industrial firewall device based on time-series graph detection according to claim 1, characterized in that, The wide-voltage power supply module supports a wide range of voltage inputs common in industrial settings, outputs a stable voltage to power each module, and has timely overvoltage, overcurrent, and short-circuit protection functions. It can effectively cope with power supply fluctuations in industrial settings and ensure that the device can work continuously and stably in complex environments.

Citation Information

Cited By

  • Protocol conversion method of Internet of Things water information heterogeneous data transmission protocol gateway

    CN121462677A