Password security management method applied to industrial security

By building an isolated simulation test platform in the industrial control system and using traffic mirroring and script recording to generate test cases, the issues of test case validity and compatibility were resolved. This enabled efficient and accurate cryptographic strategy testing and remediation suggestion generation, avoiding production interruptions.

CN121309367AActive Publication Date: 2026-01-09TAIRUI (BEIJING) TECH SERVICE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511852441.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-10
Publication Date
2026-01-09
Estimated Expiration
2045-12-10

AI Technical Summary

Technical Problem

Existing technologies are insufficient for effectively testing the compatibility and impact of changes in cryptographic policies within industrial control systems, leading to serious consequences such as production line shutdowns and data loss. Furthermore, the effectiveness of test cases lacks a scientific verification mechanism.

Method used

Build an isolated simulation test platform that corresponds to the real production environment. Generate test cases covering real scenarios through traffic mirroring, script recording and template library. Combined with self-verification mechanism and priority scheduling, monitor system response data to obtain test results and automatically generate targeted repair suggestions.

Benefits of technology

It enables precise replication of HMI/PLC/DCS controllers and network structures in industrial control systems, avoiding test interruptions, ensuring the comprehensiveness and effectiveness of test cases, improving test efficiency, and providing accurate problem localization and repair guidance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309367A_ABST
    Figure CN121309367A_ABST
Patent Text Reader

Abstract

The invention particularly relates to a password security management method applied to industrial security, which relates to the technical field of industrial control system security, and comprises the following steps of: deploying password strategies in batches in an arranged controlled simulation environment, triggering test case execution according to priorities, and monitoring system response data to obtain a test result; wherein in the test case execution process, whether the obtained execution success rate is correct or not needs to be judged through the verification error coefficient obtained through analysis. According to the invention, an isolation simulation test platform highly consistent with a real production environment is established, an HMI / operator station, a PLC / DCS controller and an industrial network structure are accurately duplicated in combination with a digital twinning technology, and a test process and the production environment are completely isolated; serious consequences, such as automatic process interruption and production line stop, possibly caused by password strategy change testing are avoided from the source.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of industrial control system security, in particular to a password security management method applied to industrial security. BACKGROUND

[0002] Industrial control systems, as the core infrastructure of industrial production, need to run continuously for 24 hours, and their stability is directly related to production safety and efficiency.

[0003] In industrial control systems, in addition to operator accounts, a large number of service accounts and machine accounts support key automation processes such as data collection, instruction transmission, and report generation. The update and iteration of password policies are necessary means to ensure system security, but directly deploying new policies in a production environment may cause automation processes that have not been updated in time to be interrupted, resulting in serious consequences such as production downtime, data loss, and quality accidents. Therefore, industrial systems have very low tolerance for trial and error of password policy changes.

[0004] Existing testing methods are mostly for general IT environments and do not fully adapt to the special nature of industrial systems, making it difficult to replicate the device interaction logic of industrial control networks and the dependency relationship of automation processes, resulting in test results that cannot be effectively migrated to production environments. At the same time, the effectiveness of test cases lacks a scientific verification mechanism, making it difficult to ensure the comprehensiveness of test coverage and the authenticity of results, and unable to accurately locate compatibility issues and the scope of influence caused by password policy changes, lacking targeted repair guidance, ultimately leading to uncontrollable risks of policy deployment.

[0005] Therefore, a password security management method applied to industrial security is proposed to address the above problems. SUMMARY

[0006] The purpose of the present application is to solve the above problems by proposing a password security management method applied to industrial security.

[0007] To achieve the above purpose, the present application adopts the following technical solutions: The password security management method applied to industrial security comprises: Building an isolated simulation test platform corresponding to the real production environment; Deploying the password policy to be tested, and generating test cases covering real scenarios through traffic mirroring, script recording, and template library; Deploying the password policy in batches in the controlled simulation environment, triggering test case execution according to priority, monitoring system response data to obtain test results; wherein the execution success rate obtained during test case execution needs to be judged for correctness by analyzing the verification error coefficient obtained; Analyze test data to determine compliance and compatibility, locate problem root causes, assess impact scope, automatically generate targeted repair suggestions and comprehensive test reports.

[0008] Preferably, the construction of an isolated simulation test platform corresponding to the real production environment, specifically comprising: By configuring the target IP network segment, subnet mask, limiting the scanning range to industrial control network; The scanning results are matched with the field import data of the asset management system and CMDB; Create a virtual machine, restore the system based on the snapshot file of the production environment HMI, restore the disk partition structure, registry configuration, and driver version; Use the Hash check tool to verify the consistency of the key files of the cloned system with the production environment; Manually configure the virtual machine IP address, subnet mask, gateway, DNS, to ensure consistency with the production environment HMI network parameters; copy the production network VLAN ID, VLAN name, trunk link configuration, and configure static routing or OSPF routing protocol; Import the security policy of the production environment into the simulation firewall, including source and destination addresses, service ports, actions, and log enable state; Simulate the delay and packet loss rate of the industrial network; Scan the authentication port of the simulation component to verify that the port is in an open state; write a test tool to send a standard protocol request to the authentication port.

[0009] Preferably, the deployment of the password policy to be tested, and the generation of test cases covering real scenarios through traffic mirroring, script recording, and template library, specifically comprising: The graphical interface provides a Web-based management interface; The configuration policy also includes password complexity support for custom settings, password management settings, and account security management settings; Built-in policy conflict rule library, when the configured policy items contradict each other, the system automatically prompts the conflict point and provides modification suggestions.

[0010] Preferably, the generation and recording of automated test cases are also included: Configure port mirroring on the core switch of the production network to mirror authentication-related traffic to the collection server; retain the authentication protocol traffic and store it as a pcap format file, named by timestamp; Replay the pcap file in the simulation environment with configured replay rate and number of times; The administrator logs in to the policy management platform, enters the script recording module, inputs the recording name, target device IP, recording duration, and clicks Start Recording; Capture all network requests, system calls, process start / termination events when the administrator executes the automation process in the production environment; After recording, the captured behavior is converted into a Python or Shell script; Execute the recorded script in the simulation environment, verify that the script can completely reproduce the original process, and the execution success rate must meet the preset standard, and the execution success rate obtained at the same time completes self-verification, that is, whether the execution success rate is correct is judged by analyzing the verification error coefficient, otherwise, the failure node is prompted and re-recording is allowed.

[0011] Preferably, the verification error coefficient acquisition process comprises: Extract the timestamp sequence of script execution, including the start time and end time of each step, respectively denoted as single-step start time and single-step end time; And the real step start time and real step end time corresponding to the production environment; Calculate the time difference between the single-step start time and the real step start time to obtain the start deviation duration; calculate the time difference between the single-step end time and the real step end time to obtain the end deviation duration; Sum the start deviation duration and the end deviation duration to obtain the total single-step deviation duration; Get the duration between single-step start time and single-step end time, denoted as single-step process duration; get the duration between real step start time and real step end time, denoted as real step process duration; Get the time difference between the single-step process duration and the real step process duration, denoted as process time deviation; Take the total single-step deviation duration and the process time deviation as the base and the height perpendicular to the base of the triangle respectively, construct a triangle, and calculate the area of the triangle, denoted as the initial error coefficient; Get the initial error coefficient corresponding to each step in the script execution process, and arrange it in descending order according to the numerical value to obtain the initial error coefficient descending order set; Extract the largest three initial error coefficients from the set, and calculate the mean value to obtain the verification error coefficient; Match the verification error coefficient with the corresponding decay rate, subtract the decay rate from the obtained execution success rate, and if the obtained execution success rate still meets the preset execution success rate requirement, perform self-verification of the execution success rate.

[0012] Preferably, the password policy is deployed in batches in the laid controlled simulation environment, the test case execution is triggered according to priority, and the system response data is monitored to obtain the test result, specifically comprising: Create a test domain in the simulation version of the policy management server, add all simulated devices and virtual machines in the simulation environment to the test domain, and ensure that the devices are networked with the domain controller; Deploy in batches according to equipment type, prioritizing non-core equipment, and then deploying core control equipment; After deployment, the system automatically logs into each device, verifies whether the policy has been successfully applied via command line, generates a deployment verification report, and marks devices that failed to apply the policy and the reasons therefor.

[0013] Preferably, the method further includes triggering the test execution: Test case scheduling configuration: Supports prioritizing test cases, with higher priority cases executed first; supports parallel execution; Execution triggering methods: Supports manual triggering, timed triggering, and event triggering; When a test case fails to execute, the system automatically analyzes the reason for the failure. If it is a temporary problem, it automatically retryes the execution; if it is a permanent problem, it stops retrying and marks the failure status. It displays the execution status of test cases in real time, showing the number of executed test cases, the number of remaining test cases, and the success rate. It also supports manually pausing / resumpting test execution.

[0014] Preferably, the method also includes comprehensive monitoring and data acquisition: Logs were collected and key fields were extracted. Configure packet capture ports on the core routers and switches of the simulated network, set packet capture filtering rules, and split the packet capture files by hour; Parse the packet capture file to extract the protocol type, source port, destination port, sequence number, acknowledgment number, username, password encryption method, authentication result, and response time; Performance monitoring includes monitoring response time, error rate, and resource utilization; Install a monitoring agent on the simulation equipment to collect performance metrics in real time.

[0015] Preferably, the analysis of test data is used to determine compliance and compatibility, locate the root cause of problems, assess the scope of impact, and automatically generate targeted remediation suggestions and a comprehensive test report with visualization elements, specifically including: Built-in compliance checklist; supports custom compliance rules, and administrators can add internal enterprise password management standards; For each account, verify whether it meets all compliance rules one by one. If all rules are met, it is deemed compliant; otherwise, it is deemed non-compliant, and the specific non-compliant items are marked. Set compatibility grading standards; conduct correlation analysis on root cause localization and impact scope assessment from time, account, device, and protocol dimensions; classify failure root causes, with each category containing specific sub-causes; The quantitative assessment of the scope of impact analyzes the impact on business, equipment, and accounts. The dependency relationship is represented by generating a topology graph, with devices / systems represented by nodes and dependency relationships represented by lines, highlighting problematic nodes and dependency paths, and marking the scope of influence.

[0016] Preferably, the method further comprises: Based on the root cause analysis results and the built-in repair scheme knowledge base, the corresponding repair suggestions are matched to ensure the pertinence and operability of the suggestions. The repair suggestions are analyzed from the account level, device level, software level and policy level: According to the repair urgency, high-priority suggestions are displayed first, and the time, resources and technical difficulty required for repair are marked. For each suggestion, the effect after implementation is predicted to help administrators make decisions, and a comprehensive test report is generated.

[0017] As described above, due to the adoption of the above technical solutions, the beneficial effects of the present application are: 1. The present application builds an isolated simulation test platform highly consistent with the real production environment, combines digital twin technology to accurately reproduce HMI / operator station, PLC / DCS controller and industrial network structure, completely isolates the test process from the production environment, and avoids serious consequences such as automation process interruption and production downtime caused by password policy change test from the root cause.

[0018] 2. The present application realizes the automatic generation of test cases through flow mirroring, script recording and template library, combines the execution success rate self-verification mechanism to ensure the comprehensiveness, authenticity and effectiveness of the test cases, greatly reduces the cost of manual writing and verification; the priority scheduling, parallel execution and failure retry mechanism in the test execution stage further improves the test efficiency; in the result analysis link, multi-dimensional correlation analysis realizes accurate positioning of the problem root cause, hierarchical classification of repair suggestions and visual comprehensive report, which provides clear guidance for rectification and reduces the difficulty of problem solving. BRIEF DESCRIPTION OF DRAWINGS

[0019] In the following description of exemplary embodiments in conjunction with the accompanying drawings, more details, features and advantages of the present application are disclosed, in which: Figure 1 The method flowchart of the present application. DETAILED DESCRIPTION

[0020] Several embodiments of the present application will be described in more detail below with reference to the accompanying drawings so as to enable those skilled in the art to implement the present application. The present application can be embodied in many different forms and purposes and should not be limited to the embodiments described herein. These embodiments are provided to make the present application comprehensive and complete, and to fully convey the scope of the present application to those skilled in the art. The embodiments do not limit the present application.

[0021] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and the present disclosure and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein. Embodiments

[0022] DETAILED DESCRIPTION Figure 1 is made to the drawings.

[0023] APPENDIX Figure 1 The password security management method flowchart for industrial safety provided by the embodiments of the present application shows the complete steps from building an isolated simulation test platform corresponding to a real production environment to automatically generating targeted repair suggestions and a comprehensive test report.

[0024] In the present embodiment, it comprises: Building an isolated simulation test platform corresponding to a real production environment provides real scene support for subsequent testing, ensuring the effectiveness and migratability of the test results; Specifically, it comprises: By configuring the target IP network segment and subnet mask, the scanning range is limited to the industrial control network, avoiding scanning of unrelated office networks; The scanning mode includes active detection using ICMP ping and TCP SYN scanning (to avoid interference to production equipment caused by full connection scanning), and passive listening through mirroring of industrial switch ports to capture device communication messages; The scanning results are matched with the asset management system and CMDB import data in the field (with device IP and host name as the unique identifier), automatically removing duplicate entries and supplementing missing fields (such as the production line to which the device belongs and the contact information of the person in charge); CMDB is the abbreviation of Configuration Management Database, the core of which is to store detailed information of IT assets (such as devices, software, and network components) and the dependency relationship between assets, providing unified data support for IT management and decision-making; The inventory export supports multiple formats such as CSV, JSON, and Excel, and the fields include device IP address, host name, MAC address, device type, model, firmware version, operating system version, installed software list, network partition to which it belongs, authentication protocol type, and information of the person in charge; Legacy device identification rule: built-in industrial device compatibility database containing authentication capability parameters of common industrial device models, through comparing device model and firmware version, marking legacy devices that do not support SHA-256 encryption, password length limit ≤8 bits, etc.

[0025] Scan permission control: using read-only permission account to perform scan operation, scan frequency can be configured (default 1 time per week), avoiding high-frequency scan occupying network bandwidth.

[0026] The establishment process of the digital twin model includes: HMI / operator station modeling: Create a virtual machine through VMware vSphere or Hyper-V, restore the system based on the snapshot file of the production environment HMI, restore the disk partition structure, registry configuration, and driver version; Use the Hash check tool to verify the consistency of the key files (such as configuration software executable files, project configuration files) of the cloned system with the production environment, and the pass rate must meet the preset standard; Manually configure the virtual machine IP address, subnet mask, gateway, DNS to ensure consistency with the network parameters of the production environment HMI, and close unnecessary network services; PLC / DCS controller modeling: Hardware simulator configuration: for Siemens S7 series PLC, use S7-PLCSIMAdvanced to create a virtual controller consistent with the production PLC model, import the PLC program (.awl format) of the production environment, configure CPU model, memory size, I / O module quantity, etc.

[0027] Stake module development standard: for old PLC that cannot be simulated, develop a stake module using C++, simulate the PLC authentication interface based on TCP / IP protocol, support receiving login request, parsing username and password, returning preset response (success / failure), and response delay control consistent with the real PLC.

[0028] Program logic consistency: virtual controller or stake module needs to restore the authentication logic of production PLC, including password storage encryption method (such as AES-256), login permission verification rule (such as administrator / operator permission distinction).

[0029] Network structure modeling: VLAN and routing configuration: in Cisco IOS or Huawei VRP system, replicate the VLAN ID, VLAN name, trunk link configuration of the production network, configure static routing or OSPF routing protocol, ensure that the network topology of the simulation environment is consistent with the production environment; Firewall and ACL rules: Import the security policy of the production environment into the simulation firewall, including source and destination addresses, service ports, actions (allow / deny), and log status, to ensure that the network access control during testing is consistent with the production environment. Network delay simulation: Simulate the delay and packet loss rate of the industrial network using the NetEm tool to restore the real transmission characteristics of the production network. Interface state detection: Use the Nmap tool to scan the authentication port of the simulation component to verify that the port is in an open state, excluding the case where the port is intercepted by the firewall or the service is not started. Interface compatibility verification: Write a test tool through Socket programming to send a standard protocol request to the authentication port and verify that the interface can correctly return a response message. Multi-protocol support: Support common authentication interfaces in industrial scenarios, including RDP (3389 port), SSH (22 port), Telnet (23 port), database ports (MySQL 3306, SQL Server 1433), PLC dedicated ports (Siemens 102 port, Modbus 502 port), OPCUA port (4840 / 4841).

[0030] Deploy the password policy to be tested and generate test cases that cover real scenarios through traffic mirroring, script recording, and template library to ensure comprehensiveness, relevance, and repeatability. During the execution of the test cases, the success rate of execution needs to be judged by analyzing the verification error coefficient to determine whether the execution success rate is correct. Specifically, it includes: The graphical interface provides a Web-based management interface that supports drag-and-drop policy configuration, real-time preview of policy effects, and fields such as policy name, applicable scope, effective time, configuration items, and notes. The configuration policy also includes password complexity, password management settings, and account security management settings. Password complexity: Supports custom character sets, prohibits consecutive repeated characters, and prohibits keyboard sequences. Password management: Supports password minimum usage period (e.g., 1 day to prevent frequent changes), password reset reminders (7 days before expiration via email / sms), and mandatory password history record number (configurable from 1 to 20 times). Account security: Supports account lockout time (configurable from 1 to 1440 minutes), lockout unlocking method (manual unlocking / automatic unlocking), and idle account hibernation (e.g., 90 days of inactivity automatically hibernates). Built-in policy conflict rule library: When the configured policy items conflict with each other (e.g., setting the password maximum usage period to 90 days and the password to be permanently valid), the system automatically prompts the conflict point and provides modification suggestions.

[0031] Also includes the generation and recording of automated test cases: Configure port mirroring (SPAN) on the core switch of the production network, mirror authentication-related traffic (such as TCP 3389, 1433 port traffic) to the collection server; Use Wireshark to filter out irrelevant traffic, only keep Kerberos, LDAP, RDP, SQLServer authentication protocol traffic, store as pcap format file, name by timestamp; Use Tcpreplay tool to replay pcap file in simulation environment, configure replay rate (default 1:1 restore real traffic rate), replay times (can be configured 1-10 times), support to intercept part of the traffic replay according to time range; The administrator logs in to the policy management platform, enters the script recording module, enters the recording name (such as production line B database collection process), target device IP, recording duration, and clicks start recording; Capture all network requests (including TCP connections, UDP messages, application layer protocol interactions), system calls, process start / termination events of the administrator executing the automation process in the production environment; After recording is complete, the system automatically converts the captured behavior into Python or Shell script, removes redundant operations (such as repeated mouse clicks), replaces fixed parameters (such as IP address, username) with variables, and supports manual editing of scripts to adjust logic; Execute the recorded script in a simulation environment to verify that the script can completely reproduce the original process, and the execution success rate must meet the preset standard (success rate must be above 95%), and the execution success rate is also self-verified, that is, by analyzing the verification error coefficient to determine whether the execution success rate is correct, otherwise prompt the failure node and allow re-recording; Template script library: Scenario coverage: built-in 20+ common industrial automation scenario templates, including OPCDA / UA data collection, MES system and PLC communication, database backup, HMI picture switching, report automatic generation, device remote maintenance, etc. Template parameter configuration: each template provides a visual parameter configuration interface, key parameters to be filled in include target device IP, port number, username, password, operation frequency, data transmission format, expected result, etc. Script customization extension: support users to modify script logic based on templates, add custom assertions (such as judging whether the returned data meets the expected format), loop structure, exception handling mechanism (such as connection timeout retry).

[0032] The process of obtaining the verification error coefficient includes: extracting a timestamp sequence of the script execution, including the start time and the end time of each step, respectively denoted as single-step start time and single-step end time; extracting a historical timestamp sequence of the same flow in the production environment, and recording the start time and the end time of each step, respectively denoted as real-step start time and real-step end time; calculating the difference between the single-step start time and the real-step start time, and taking the absolute value to obtain the start deviation duration; calculating the difference between the single-step end time and the real-step end time, and taking the absolute value to obtain the end deviation duration; summing the start deviation duration and the end deviation duration to obtain the single-step deviation total duration; obtaining the duration between the single-step start time and the single-step end time, denoted as single-step process duration; obtaining the duration between the real-step start time and the real-step end time, denoted as real-step process duration; obtaining the time difference between the single-step process duration and the real-step process duration, denoted as process time deviation; taking the single-step deviation total duration and the process time deviation as the base and the height perpendicular to the base of a triangle respectively, constructing the triangle and calculating the area of the triangle, denoted as initial error coefficient; obtaining the initial error coefficients corresponding to each step in the script execution process, and arranging them in descending order according to the numerical value to obtain an initial error coefficient descending order set; extracting the three largest initial error coefficients from the set, and calculating the mean value to obtain a verification error coefficient; matching the verification error coefficient with the corresponding decay rate, subtracting the decay rate from the obtained execution success rate, and if the execution success rate still meets the preset execution success rate requirement, verifying the execution success rate.

[0033] matching the verification error coefficient with the corresponding decay rate, the process includes: presetting the value range of three groups of thresholds, each group of threshold value range corresponding to a decay rate, matching the verification error coefficient with the value range of the three groups of thresholds to obtain the decay rate corresponding to the verification error coefficient; The verification logic can comprehensively capture the timing risk of industrial script execution, by synchronously considering the step time point deviation (start deviation, end deviation) and the execution time deviation (process time deviation), and quantifying the superimposed influence of the two in the form of a triangle area, making the severity of timing deviation more intuitive and perceptible.

[0034] At the same time, the average of the three largest initial error coefficients is selected as the verification error coefficient, which highlights the deviation weight of the key step and avoids the interference of single extreme value on the overall judgment, making the error quantization result better reflect the real timing state of the industrial process.

[0035] The verification error coefficient-decay rate-success rate standard process constructed by it deeply binds the timing consistency performance and the execution success rate, ensuring that the final success rate not only meets the surface numerical standard, but also has adaptability to the production environment.

[0036] It can accurately screen out effective test cases that meet the actual industrial production at the timing level, providing a reliable premise for subsequent compliance and compatibility testing of password policies, fully meeting the core requirements of industrial security scenarios for process stability and result authenticity.

[0037] In the controlled simulation environment, deploy password policies in batches, trigger test case execution (including failure retry) according to priority, and monitor system response data to obtain test results; Specifically, it includes: Create a test domain (such as test.industrial.com) in the simulation version of the policy management server, and add all simulated devices and virtual machines in the simulation environment to the test domain to ensure network connectivity between devices and domain controllers; Support two push modes: manual push (administrator clicks immediately to trigger) and timed push (configure deployment time, such as 2 am, to avoid testing peak); Deploy by device type in batches, prioritize non-core devices (such as report servers), then deploy core control devices (such as PLCs and HMIs), and interval each batch deployment by 30 minutes to facilitate monitoring of deployment effects; After deployment, the system automatically logs into each device and verifies whether the policy has been successfully applied through command line (such as Windows gpresult command, Linux pam-config command), generates a deployment verification report, and marks devices that have not been successfully applied and the reasons (such as network failure, insufficient permissions); If the device is detected offline during deployment, the system will record the offline time and automatically retry the deployment when the device is online, with a maximum of 3 retries, and if it still fails, an alarm will be sent to the administrator.

[0038] It also includes the trigger of test execution: Case scheduling configuration: support sorting test cases by priority (high / medium / low), with high-priority cases (such as PLC control process testing) executed first; support parallel execution (default maximum of 10 cases executed simultaneously), with configurable parallel number to avoid high resource occupation; Execution trigger mode: support manual trigger (administrator clicks start test), timing trigger (configure test time), event trigger (such as automatically triggered after policy deployment is completed); When the test case execution fails, the system automatically analyzes the failure reason. If it is a temporary problem such as network fluctuation or service temporary non-start, it will automatically retry execution (up to 3 times); If it is a permanent problem such as authentication failure or script error, stop retrying and mark the failure state; Real-time display of test case execution status (waiting for execution / execution in progress / success / failure), display of the number of executed test cases, the number of remaining test cases, and success rate, support for manual pause / resume of test execution.

[0039] It also includes comprehensive monitoring and data collection: System log monitoring: Log collection tool: use ELKStack (Elasticsearch, Logstash, Kibana) or Fluentd to collect logs, support WindowsEventLog, LinuxSyslog, application custom log formats, etc. Log field extraction: extract key fields from logs, including event time, event ID, event type, username, source IP, target IP, event description, error code, etc. Standardize log format for easy analysis; Log storage period: default storage period is 90 days, support for configuring storage period, can export log file backup; Network packet capture: Packet capture configuration: configure packet capture ports on core routers and switches in the simulation network, set packet capture filtering rules (only capture authentication protocol related traffic), and packet capture files are segmented by hour; Packet analysis field: use Wireshark to analyze packet capture files, extract protocol type, source port, destination port, sequence number, acknowledgment number, username, password encryption method, authentication result, response time, etc. Performance monitoring, including: Monitoring index definition: Response time: total time from sending authentication request to receiving response, unit ms; Error rate: the number of errors during test case execution as a percentage of the total number of executions; Resource utilization: CPU usage, memory usage, disk I / O, network bandwidth occupancy; Install monitoring agent (such as PrometheusNodeExporter) on simulation devices to collect performance indicators in real time, and the collection frequency can be configured; Set thresholds for performance indicators (such as response time threshold 500ms, CPU usage threshold 80%), trigger alarms when thresholds are exceeded, notify administrators through email, SMS.

[0040] Assign a unique test ID to each test execution, all monitoring data (logs, packet capture files, performance indicators) are associated with the test ID, making it easy to query complete data by test ID later.

[0041] Preserve all original monitoring data, support downloading original log files, packet capture files, facilitate administrators to conduct secondary analysis.

[0042] Analyze test data to determine compliance and compatibility, locate problem root causes, assess impact scope, automatically generate targeted repair recommendations and comprehensive test reports with visual elements, provide decision-making basis for strategy online; Specifically includes: Built-in compliance check list, corresponding to NIST SP800-63B, ISO / IEC27001, GB / T22239, etc. Standard requirements, check items include password length, complexity, validity period, history record, account lock, etc.

[0043] Support custom compliance rules, administrators can add enterprise internal password management specifications (such as prohibiting using enterprise name, device model as password); For each account, check whether it meets all compliance rules one by one, if all meet, it is determined to be compliant, otherwise it is determined to be non-compliant, mark specific non-compliant items (such as password length is only 8 bits, does not meet the minimum 12 bits requirement); Compatibility analysis dimensions: Device hardware compatibility: Check if the device firmware version supports the new password policy (such as whether it supports long password, strong encryption algorithm).

[0044] Software compatibility: Check if the operating system, configuration software, database, etc. Can correctly parse and execute the new password policy.

[0045] Protocol compatibility: Check if the authentication protocol (such as Kerberos, LDAP) is compatible with the new password policy, if there is a protocol version that does not support the situation.

[0046] Compatibility classification standards: First-level incompatible: The device cannot support the new policy at all, resulting in authentication function failure (such as old PLC does not support password length>8 bits); Second-level incompatible: The device partially supports the new policy, with functional abnormalities (such as supporting long password but response time significantly increases); Third-level incompatible: The device supports the new policy, but needs to modify the configuration or upgrade the component (such as the operating system needs to install patches); Root cause positioning and impact range assessment, including correlation analysis from time dimension, account dimension, device dimension and protocol dimension; Time dimension: correlate logs, packet capture data, performance indicators within the same time period, and locate authentication failure problems that occur at a certain time.

[0047] Account dimension: analyze the authentication of the same account on different devices and at different times to determine whether it is an account problem (such as password error).

[0048] Device dimension: statistics of all accounts on the same device authentication results, to determine whether it is a device configuration or compatibility problem.

[0049] Protocol dimension: analyze all interaction data of the same authentication protocol to determine whether it is a protocol incompatibility or configuration error.

[0050] Common failure root causes are divided into 6 categories, including password non-compliance, account lockout, device compatibility, protocol incompatibility, network failure, and software failure, each category contains specific sub-reasons (such as password non-compliance includes insufficient length, insufficient complexity, and not changing expired password, etc.); Impact range quantification assessment analyzes business impact, device impact and account impact; Business impact: statistics of the number of affected business systems and key business processes, and assessment of business interruption risk level (high / medium / low).

[0051] Device impact: statistics of the number of affected devices and device type distribution, and assessment of device rectification cost.

[0052] Account impact: statistics of the number of affected accounts and account type (operator account / service account) distribution, and assessment of account rectification workload.

[0053] Dependency relationship is represented by generating a topology graph with nodes representing devices / systems and lines representing dependency relationships, highlighting problem nodes and dependency paths, and marking impact range.

[0054] Automatic generation of repair suggestions: Based on root cause analysis results and built-in repair scheme knowledge base, matching corresponding repair suggestions to ensure the pertinence and operability of the suggestions; Repair suggestions are analyzed from account level, device level, software level and policy level: Account level: such as modifying account svc_data password to ensure length ≥ 12 characters, containing uppercase and lowercase letters, numbers and special characters, converting service account to group managed service account (gMSA) for automatic password management.

[0055] Device level: such as upgrading PLC-01 firmware to V4.5 version, supporting long password function, deploying authentication agent gateway for Old_PLC_01, proxy processing authentication request.

[0056] Software level: such as installing KB2992611 patch for WindowsServer2012 server, supporting SHA-256 encryption, restructuring backup.bat script, getting password from HashiCorpVault security vault.

[0057] Policy level: such as adjusting the maximum password lifetime to 180 days, reducing the password change frequency of service accounts, configuring a lenient password policy for legacy devices, and applying a strong password policy for the rest of the devices.

[0058] According to the urgency of repair (high / medium / low), high priority suggestions (such as core PLC authentication failure repair) are displayed first, with the required time, resources, and technical difficulty marked; For each suggestion, the effect after implementation is predicted (such as account svc_dat' will comply with the password policy after implementation, and the data collection process will run normally), helping administrators make decisions; And generate a comprehensive test report: Report structure and content: Executive summary: test purpose, test scope, test time, total number of test cases, success rate, core conclusion (such as there are 3 high-risk points in the new password policy, which need to be rectified before going online).

[0059] Detailed findings: list all problems by risk level (high risk, medium risk, low risk), each problem contains problem description, affected object, root cause analysis, risk explanation.

[0060] Risk level definition: High risk: problems that will cause core business interruption, production line stop (such as PLC authentication failure).

[0061] Medium risk: problems that will affect non-core business and cause functional abnormalities (such as report generation failure).

[0062] Low risk: problems that have little impact on business and can be optimized later (such as some account password complexity is close to the threshold).

[0063] Affected business system list: list the names of affected business systems, departments, business types, impact levels, and recovery suggestion times.

[0064] Repair operation guide: provide detailed repair steps according to problem classification, including operation subject, operation steps, verification method, precautions, and relevant tool download link, command example.

[0065] Appendix: Test case list, monitoring raw data screenshot, topology diagram, compliance check list.

[0066] Report visualization elements: include test success rate pie chart, risk level distribution column chart, affected device type statistics chart, repair priority radar chart, intuitive display of test results.

[0067] Report export format: support PDF, Word, HTML format export, PDF format support encryption protection (set open password), prevent report leakage.

[0068] The above formulas are dimensionless values calculated, and the formulas are obtained by collecting a large amount of data to simulate a formula of the latest real situation, and the preset parameters in the formula are set by the person skilled in the art according to the actual situation.

[0069] The above only describes some exemplary embodiments of the application by way of illustration, and it is needless to say that those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the application. Therefore, the above drawings and descriptions are illustrative in nature and should not be understood as limiting the scope of protection of the claims of the application.

[0070] It should be noted that in this paper, if there are relationship terms such as first and second, they are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or equipment including the element.

[0071] It should be understood that in various embodiments of the present application, the size of the sequence number of each process described above does not mean the order of execution, and the execution order of each process should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0072] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0073] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.

[0074] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. they can be located in one place or distributed on multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiment according to actual needs.

[0075] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0076] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any skilled person in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0077] The above only describes some exemplary embodiments of the present application by way of illustration, and it is needless to say that those skilled in the art can modify the described embodiments in various ways without deviating from the spirit and scope of the present application. Therefore, the above figures and descriptions are illustrative in nature and should not be understood as limiting the scope of protection of the claims of the present application.

Claims

1. A password security management method applied to industrial security, characterized by, The method comprises the following steps: Building an isolated simulation test platform corresponding to the real production environment; Deploying the password policy to be tested, and generating test cases covering real scenarios through traffic mirroring, script recording, and template library; Deploying the password policy in batches in the controlled simulation environment, triggering test case execution according to priority, and monitoring system response data to obtain test results; During the execution of the test case, the success rate of execution is determined by analyzing the verification error coefficient to determine whether the success rate of execution is correct; Analyze test data to determine compliance and compatibility, locate problem root causes, assess impact scope, automatically generate targeted repair suggestions, and generate comprehensive test reports.

2. The password security management method for industrial security according to claim 1, wherein Building an isolated simulation test platform corresponding to the real production environment, specifically including: Limiting the scanning range to the industrial control network by configuring the target IP network segment and subnet mask; Field matching of scanning results with asset management system and CMDB import data; Creating a virtual machine, restoring system disk partition structure, registry configuration, and driver version based on the snapshot file of the production environment HMI; Using a Hash check tool to verify the consistency of key files in the cloned system with the production environment; Manually configuring the virtual machine IP address, subnet mask, gateway, and DNS to ensure consistency with the production environment HMI network parameters; copying the production network VLAN ID, VLAN name, trunk link configuration, and configuring static routing or OSPF routing protocol; Importing the security policy of the production environment into the simulation firewall, including source and destination addresses, service ports, actions, and log enable state; Simulating the delay and packet loss rate of the industrial network; Scanning the authentication port of the simulation component to verify that the port is in an open state; writing a test tool to send a standard protocol request to the authentication port.

3. The password security management method for industrial security according to claim 1, wherein Deploying the password policy to be tested, and generating test cases covering real scenarios through traffic mirroring, script recording, and template library, specifically including: Providing a Web-based management interface through a graphical interface; The configuration policy also includes custom password complexity settings, password management settings, and account security management settings; Built-in policy conflict rule library, when the configured policy items contradict each other, the system automatically prompts the conflict point and provides modification suggestions.

4. The password security management method for industrial security according to claim 3, wherein Also includes the generation and recording of automated test cases: Configure port mirroring on the core switch of the production network to mirror authentication-related traffic to the collection server; Preserve the authentication protocol traffic and store it as a pcap format file named by timestamp; Replay the pcap file in the simulation environment, configure the replay rate and number of replays; The administrator logs in to the policy management platform and enters the script recording module, enters the recording name, target device IP, and recording duration, and clicks Start Recording; Capture all network requests, system calls, and process start / termination events when the administrator executes the automated process in the production environment; After recording is complete, convert the captured behavior into a Python or Shell script; The recorded script is executed in a simulation environment to verify that the script can completely reproduce the original process, and the execution success rate needs to reach a preset standard, and the execution success rate obtained is simultaneously completed self-verification, that is, whether the execution success rate is correct is judged by analyzing the obtained verification error coefficient, otherwise, a failure node is prompted and re-recording is allowed.

5. The password security management method for industrial security according to claim 4, wherein The process of obtaining the verification error coefficient includes: extracting the timestamp sequence of script execution, including the start time and end time of each step, respectively denoted as single-step start time and single-step end time; and the real step start time and real step end time corresponding to the production environment; calculate the time difference between the single-step start time and the real step start time to obtain the start deviation duration; calculate the time difference between the single-step end time and the real step end time to obtain the end deviation duration; sum the start deviation duration and the end deviation duration to obtain the single-step deviation total duration; obtain the duration between the single-step start time and the single-step end time, denoted as single-step process duration; obtain the duration between the real step start time and the real step end time, denoted as real step process duration; obtain the time difference between the single-step process duration and the real step process duration, denoted as process time deviation; the single-step deviation total duration and the process time deviation are respectively taken as the base and the height perpendicular to the base of the triangle, and the area of the triangle is calculated after the triangle is constructed, denoted as the initial error coefficient; obtain the initial error coefficient corresponding to each step in the script execution process, and arrange it in descending order according to the numerical value to obtain the initial error coefficient descending order set; extract the largest three initial error coefficients from the set, and obtain the verification error coefficient after mean value calculation; match the corresponding decay rate to the verification error coefficient, and subtract the decay rate from the obtained execution success rate, if the obtained execution success rate still meets the preset execution success rate requirement, then the execution success rate is self-verified.

6. The password security management method for industrial security according to claim 1, wherein In the laid controlled simulation environment, deploy the password strategy in batches, trigger the test case execution according to the priority, monitor the system response data to obtain the test result, specifically including: create a test domain in the simulation version of the policy management server, add all simulated devices and virtual machines in the simulation environment to the test domain, and ensure that the devices and domain controllers are networked; deploy by device type in batches, preferentially deploy non-core devices, and then deploy core control devices; after deployment, the system automatically logs into each device, verifies whether the policy is successfully applied through the command line, generates a deployment verification report, and marks the devices that are not successfully applied and the reasons.

7. The password security management method for industrial security according to claim 6, wherein It also includes the trigger of test execution: case scheduling configuration: support sorting test cases by priority, high-priority cases are executed first; support parallel execution; execution trigger mode: support manual trigger, timing trigger, and event trigger; when the test case execution fails, the system automatically analyzes the failure reason, if it is a temporary problem, it automatically retries the execution; if it is a permanent problem, it stops retrying and marks the failure state; real-time display of the execution status of the test case, display the number of executed cases, the number of remaining cases, and the success rate, support manual pause / resume of test execution.

8. The password security management method for industrial security according to claim 7, wherein It also includes comprehensive monitoring and data collection: log collection and extraction of key fields; Configure the packet capture port on the core router and switch of the simulation network, set the packet capture filter rule, and split the packet capture file by hour; Parse the packet capture file, extract the protocol type, source port, destination port, sequence number, acknowledgment number, username, password encryption method, authentication result, and response time; Performance monitoring, including monitoring response time, error rate, and resource utilization; Install the monitoring agent on the simulation device to collect performance indicators in real time.

9. The password security management method for industrial security according to claim 1, wherein, Analyze test data to determine compliance and compatibility, locate problem root causes, assess impact scope, automatically generate targeted repair recommendations and comprehensive test reports with visual elements, including: Built-in compliance check list; support custom compliance rules, administrators can add enterprise internal password management specifications; For each account, check whether it meets all compliance rules one by one. If all rules are met, it is determined to be compliant, otherwise it is determined to be non-compliant, and the specific non-compliant items are marked; Set compatibility grading standards; root cause positioning and impact scope assessment are analyzed from the time dimension, account dimension, device dimension, and protocol dimension; classify failure root causes, each class contains specific sub-reasons; Impact scope quantitative assessment analyzes business impact, device impact, and account impact; Dependency relationship is represented by a topology graph with nodes representing devices / systems and lines representing dependency relationships. Highlight the nodes and dependency paths with problems and mark the impact scope.

10. The password security management method for industrial security according to claim 9, wherein Also includes: Based on the root cause analysis results and the built-in repair solution knowledge base, match the corresponding repair recommendations to ensure the pertinence and operability of the recommendations; Repair recommendations are analyzed from the account level, device level, software level, and policy level: Sort by repair urgency, high-priority recommendations are displayed first, and mark the time, resources, and technical difficulty required for repair; For each recommendation, predict the effect after implementation to help administrators make decisions; and generate a comprehensive test report.

Citation Information

Cited By

  • A method and system for determining a database verification password based on a driver

    CN122346841A