Cps attack path reconstruction method and system based on kill chain model clustering
By using a clustering method based on the kill chain model, network traffic and electrical measurement data of cyber-physical systems are processed and analyzed in a unified manner, solving the problem of cross-layer attack path reconstruction, realizing accurate identification and tracing of cross-layer attack paths, and improving the security defense capabilities of CPS systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-10
AI Technical Summary
Existing technologies struggle to achieve unified modeling and data fusion of cross-layer attack paths in cyber-physical systems (CPS), making it difficult to identify and trace cross-layer attacks, especially in the case of multi-stage, chain-like attacks where there is a lack of effective detection and defense methods.
A clustering method based on the kill chain model is adopted to perform unified time alignment and windowing processing on information layer network traffic data and physical layer electrical measurement data, construct cross-layer coupling features, and identify and reconstruct attack paths through semantic grouping and clustering analysis, thereby realizing cross-layer correlation between information layer behavior and physical layer response.
It achieves accurate reconstruction of cross-layer attack paths, improves attack identification capabilities, enhances threat understanding and tracing accuracy, solves the challenges of cross-layer data fusion and path reconstruction, and ensures that the restored attack path closely matches the actual attack logic.
Smart Images

Figure CN121462314B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a CPS attack path reconstruction method and system based on a kill chain model clustering. BACKGROUND
[0002] The statements in this section merely provide background technology related to the present application and do not necessarily constitute prior art.
[0003] With the evolution of Cyber Physical System (CPS) towards high digitalization and intelligence, while supporting intelligent scheduling, flexible control and adaptive operation, it also faces increasingly severe network attack risks. Especially in the context of multi-source heterogeneous devices, virtual-real fusion communication architecture and cross-domain interaction control, attackers can take advantage of the complexity and coupling of the system to launch a multi-stage, chain-propelled attack process, penetrating from the information layer to the control layer and the physical layer, ultimately endangering the safe and stable operation of the system. Such cross-layer attacks often have stage, continuity and concealment, making it difficult for traditional single-point, single-domain detection and defense methods to timely perceive and effectively block.
[0004] At the information layer, attackers usually rely on means such as vulnerability exploitation, phishing emails, and horizontal penetration to gradually break through the boundary protection, control SCADA servers, workstations or key communication nodes, and form a continuous chain of malicious behavior within the system. At the control layer, attackers can further manipulate key devices such as Local Controller, IED, RTU, etc., by intervening in the control process through disguised control commands or abnormal operation logic. At the physical layer, attack behavior may manifest itself in ways such as false measurement injection, scheduling instruction tampering, and device operating parameter manipulation, causing abnormal changes in physical side data, and even triggering local oscillation or large-scale cascading failures. Due to the complex coupling structure within CPS, the interweaving of signals and control links, the propagation relationship of cross-layer attacks often presents stage jumping and coupled nonlinearity, making the actual abnormal alarms present characteristics such as fragmentation, weak association and time sequence confusion, greatly increasing the difficulty of attack identification and tracing.
[0005] Existing tracing methods mostly focus on single-domain processing at the network or physical side: at the information layer, intrusion detection system alerts, log anomalies, network traffic fluctuations, etc. are used for attack identification; at the physical layer, emphasis is placed on state quantity deviation, operating index overrun and device behavior anomaly detection. Although these methods can capture local anomalies, they still have significant shortcomings when faced with cross-layer, multi-stage attacks:
[0006] (1) Limited static correlation capability: Most methods rely on static rules or simple time correlation, which cannot capture the stage continuity and strategy evolution of attack behavior, making it difficult to identify multi-stage chain attacks;
[0007] (2) Lack of unified cross-layer modeling framework: Information layer, control layer and physical layer usually adopt decentralized model, lack of unified semantics and causal description, and cannot systematically present the complete chain of attack transmission from information layer to physical layer.
[0008] (3) Multi-source heterogeneous data is difficult to unify: Network traffic, system logs, control instructions and physical measurements, etc. Data has significant differences in format structure, time accuracy, sampling characteristics and semantic expression, and lacks unified data description and alignment mechanism. Existing methods are difficult to establish consistent association between multi-layer data, which leads to ineffective integration of cross-layer information, thereby affecting the complete reconstruction and traceability analysis of attack chain. SUMMARY
[0009] In order to solve the problem of the prior art, the present application provides a CPS attack path reconstruction method and system based on kill chain model clustering, which realizes the complete attack chain inference from information reconnaissance penetration to physical impact, can output the cross-layer attack path reflecting how the information layer behavior drives the physical layer response, and realizes unified modeling, efficient data fusion and whole process link type traceability through innovative attack recognition method and association coupling strategy, which significantly improves the threat understanding ability and attack tracking precision of CPS.
[0010] In order to achieve the above purpose, the present application adopts the following technical scheme:
[0011] In the first aspect, the present application provides a CPS attack path reconstruction method based on kill chain model clustering.
[0012] A CPS attack path reconstruction method based on kill chain model clustering, comprising the following processes:
[0013] The network traffic data of the information layer and the electrical measurement data of the physical layer are aligned and windowed according to a unified time, the two types of windowed data are standardized, and the two types of standardized data are cross-layer coupled to obtain a fusion time sequence;
[0014] The fusion time sequence is semantically grouped to obtain four feature subspaces, each feature subspace corresponding to a stage of a kill chain model;
[0015] In each feature subspace, the fusion samples of each time window are mapped to the corresponding semantic coordinates, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and after mapping, clustering is performed, and each feature subspace corresponds to obtain a plurality of candidate clusters;
[0016] The credibility evaluation unit is configured to calculate a phase credibility score for each candidate cluster in each feature subspace respectively, and obtain a corresponding candidate phase cluster for each feature subspace according to the phase credibility score.
[0017] Based on the global time sequence, the candidate phase clusters corresponding to each feature subspace are sorted according to the occurrence time to form a preliminary phase sequence, the causal relationship of any adjacent candidate phase clusters in the preliminary phase sequence is determined, each phase of the kill chain model is taken as a trunk structure, each obtained candidate phase cluster is mapped to a corresponding phase node, and after the candidate phase clusters with incorrect phase sequences and without causal relationships are removed, a final network attack chain link is obtained.
[0018] In a second aspect, the present application provides a CPS attack path reconstruction system based on kill chain model clustering.
[0019] A CPS attack path reconstruction system based on kill chain model clustering includes:
[0020] The cross-layer coupling processing unit is configured to align and window the network traffic data of the information layer and the electrical measurement data of the physical layer according to a uniform time, perform standardization processing on the two types of data after the windowing processing, perform cross-layer coupling on the two types of data after the standardization processing, and obtain a fusion time sequence.
[0021] The feature semantic grouping unit is configured to perform semantic grouping on the fusion time sequence to obtain four feature subspace, each of which corresponds to a phase of a kill chain model.
[0022] The feature subspace clustering unit is configured to map the fusion samples of each time window to the corresponding semantic coordinates in each feature subspace, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and after the mapping, clustering is performed, so that each feature subspace corresponds to a plurality of candidate clusters.
[0023] The credibility evaluation unit is configured to calculate a phase credibility score for each candidate cluster in each feature subspace respectively, and obtain a corresponding candidate phase cluster for each feature subspace according to the phase credibility score.
[0024] The attack chain link generation unit is configured to sort the candidate phase clusters corresponding to each feature subspace according to the occurrence time based on the global time sequence to form a preliminary phase sequence, determine the causal relationship of any adjacent candidate phase clusters in the preliminary phase sequence, take each phase of the kill chain model as a trunk structure, map each obtained candidate phase cluster to a corresponding phase node, remove the candidate phase clusters with incorrect phase sequences and without causal relationships, and obtain a final network attack chain link.
[0025] In a third aspect, the present application provides a computer device, comprising: a processor and a computer readable storage medium;
[0026] a processor, adapted to execute the computer program;
[0027] the computer readable storage medium, wherein the computer program is stored in the computer readable storage medium, and when executed by the processor, the computer program implements the CPS attack path reconstruction method based on kill chain model clustering of the first aspect of the present application.
[0028] In a fourth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is adapted to be loaded and executed by a processor to implement the CPS attack path reconstruction method based on kill chain model clustering of the first aspect of the present application.
[0029] In a fifth aspect, the present application provides a computer program product, comprising a computer program, and when executed by a processor, the computer program implements the CPS attack path reconstruction method based on kill chain model clustering of the first aspect of the present application.
[0030] Compared with the prior art, the present application has the following beneficial effects:
[0031] The present application realizes unified correlation analysis of information layer and physical layer, breaks through the limitation of traditional method difficult to trace across layers, and through establishing unified time sequence reference and behavior characteristic expression mode, communication behavior, control operation and physical response are included in the same analysis framework, effectively solving the problem that information layer and physical layer data are difficult to directly fuse, providing a technical foundation for overall identification of cross-layer security events; the present application introduces a phased kill chain characteristic space and combines clustering to infer attack stages, significantly improves the cross-stage attack identification capability, constructs a multi-stage kill chain model suitable for CPS scene, decomposes complex attack behavior into identifiable stage characteristic subspaces, and automatically classifies homologous behaviors through unsupervised clustering, which can reveal the trajectory of attack promotion from massive mixed data, avoiding the omission of multi-stage chain attacks by traditional static correlation methods.
[0032] This invention aligns and windowes network traffic data from the information layer and electrical measurement data from the physical layer according to a unified time frame, and obtains a fused time series through standardization and cross-layer coupling. Semantic grouping of the fused time series yields feature subspaces corresponding to the four stages of the kill chain. Samples are mapped within these subspaces and clustered to obtain candidate clusters. Credibility scores are calculated to filter candidate stage clusters, which are then sorted by time and mapped to kill chain stages based on causal relationships. Erroneous clusters are eliminated to obtain the final attack chain. This invention solves the problems of existing methods, such as difficulty in integrating CPS cross-layer data and insufficient accuracy in attack path reconstruction. It overcomes the shortcomings of traditional methods, such as separating information layer and physical layer data and lacking semantic association and causal judgment. It breaks the limitations of single-dimensional data analysis, improves the accuracy of attack stage division and path reconstruction, and makes attack path reconstruction more consistent with the actual attack evolution logic. It avoids path omissions or misjudgments caused by single-dimensional analysis and avoids invalid path interference caused by the lack of standards for stage cluster selection, providing a more reliable basis for attack tracing and defense strategy formulation.
[0033] This invention slices multi-source data into fixed-length time windows, constructing a fused feature vector for each time window that includes physical layer operational characteristics, information layer network behavior characteristics, cross-layer coupling characteristics, and data quality markers. All feature vectors are arranged chronologically to form a fused time series. This solves the problem of inconsistent formats and asynchronous timing of multi-source data across layers in CPS, making feature integration difficult. It overcomes the shortcomings of traditional data processing, such as isolated cross-layer data and chaotic temporal dimensions, achieving unification of multi-source data in both time and feature dimensions. This improves the orderliness and consistency of cross-layer data fusion, providing a more structured foundation for subsequent feature subspace partitioning and clustering analysis. It avoids feature failure caused by time misalignment or format differences, prevents stage division deviations due to chaotic temporal logic, and avoids the problems of scattered clustering results and inability to correspond to attack stages caused by disordered data, ensuring the smooth progress of subsequent analysis.
[0034] This invention calculates a stage credibility score for each candidate cluster within a feature subspace using a weighted average of temporal concentration and behavioral intensity scores, with the weights corresponding to the temporal concentration and behavioral intensity scores, respectively. This addresses the lack of quantitative standards in candidate cluster selection and the inability to distinguish between effective attack clusters and noisy clusters. It overcomes the shortcomings of traditional cluster selection based on subjective judgment, establishing objective quantitative selection criteria, improving the reliability of candidate stage clusters, ensuring that the selected clusters better match the characteristics of actual attack stages, reducing interference from non-attack clusters, avoiding path redundancy caused by invalid clusters, preventing stage misjudgments due to subjective selection, and avoiding inconsistencies in path reconstruction results caused by inconsistent cluster selection standards. This provides a high-quality stage cluster foundation for subsequent causal relationship analysis and attack path construction.
[0035] The time concentration score of the application is calculated based on the relationship between the standard deviation of the timestamps of samples in a cluster and the maximum time standard deviation of all clusters, and the behavior intensity score is obtained by averaging the distance of samples in a cluster from the mean vector of the normal operation of the system, solving the problem that the phase reliability score lacks specific and landable quantitative calculation method, overcoming the shortcomings of previous scoring standards being vague and unable to accurately measure the attack-related characteristics of clusters, filling the gap in the details of the scoring calculation link, improving the accuracy and objectivity of the phase reliability score, making the score of each candidate cluster more accurately reflect its attack characteristics in terms of time aggregation and behavior abnormality, and making the basis for screening candidate clusters more solid. Avoid cluster screening bias caused by vague scoring standards, prevent the situation that effective attack clusters are mis-screened due to inaccurate scoring or noise clusters are retained due to ambiguous scoring, and provide more accurate quantitative support for the determination of subsequent candidate phase clusters.
[0036] The application determines the causal relationship of adjacent candidate phase clusters through time proximity constraint and cross-layer causal correlation, the time proximity constraint requires that the time interval of the cluster is within the maximum acceptable threshold, and the cross-layer causal correlation requires that the information layer and the physical layer feature sequence are positively correlated, solving the problem that the causal relationship of adjacent candidate phase clusters is difficult to accurately determine, especially the problem that the causal relationship is not clear in the CPS cross-layer scenario, overcoming the defects of traditional causal determination which only relies on time sequence and ignores the cross-layer association of information layer and physical layer, taking into account the timing logic and cross-layer behavior driving relationship, improving the accuracy and rationality of causal relationship determination, making the timing association of phase clusters more consistent with the characteristics that information layer behavior drives physical layer response in CPS attacks, avoiding false causal relationship caused by only relying on time sequence, preventing clusters with cross-layer behavior disconnection from being incorrectly associated, ensuring the logical coherence of the attack path, and making the reconstructed attack path closer to the real attack process.
[0037] Advantages of the additional aspects of the application will be partially given in the following description, partially will become apparent from the following description, or will be learned by the practice of the application. BRIEF DESCRIPTION OF DRAWINGS
[0038] The accompanying drawings, which form a part of this application, are included to provide a further understanding of the application, and are incorporated in and constitute a part of this application. The embodiments of the application illustrated in the drawings, and their description, are presented to explain the application and not to limit or define the application.
[0039] Figure 1 A flowchart of a CPS attack path reconstruction method based on a kill chain model cluster is provided for an exemplary embodiment of the application;
[0040] Figure 2 A power information physical system scenario is provided for an exemplary embodiment of the application;
[0041] Figure 3A schematic diagram of clustering results of an attack phase provided for an exemplary embodiment of the present application, wherein the horizontal coordinate values and the vertical coordinate values represent the projection values of samples in two virtual feature dimensions after being compressed into a two-dimensional space;
[0042] Figure 4 A schematic diagram of a principle of a CPS attack path reconstruction system based on clustering of a kill chain model provided for an exemplary embodiment of the present application;
[0043] Figure 5 A schematic diagram of a computer device provided for an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0044] The present application will be further described below in conjunction with the accompanying drawings and embodiments.
[0045] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.
[0046] The present implementation proposes a CPS attack path reconstruction method based on clustering of a kill chain model, as shown in Figure 1 After the data of the information layer and the physical layer are fused and processed, and the relevant feature definitions are clear, the feature subspaces corresponding to the stages of reconnaissance penetration, privilege escalation, control tampering, and physical impact are divided, and then the clustering operation is performed on the data according to the CPS kill chain model to obtain candidate clusters, and then the stage candidate identification is performed through stage constraint and stage mapping, and finally the time-cause path reconstruction is completed to realize the CPS cross-layer attack tracing. Specifically, the following processes are included:
[0047] S1: Align the network traffic data of the information layer and the electrical measurement data of the physical layer according to a unified time window, extract and standardize the respective statistical and event features, and at the same time construct joint features reflecting the time sequence and topological coupling between the two layers, and output the fusion time sequence vector sequence that can be used for analysis;
[0048] S2: According to the attack process definition of the CPS, a number of semantically clear stages are defined, and the fusion features are grouped according to the stage semantics to form a feature subspace dedicated to each stage to guide subsequent analysis;
[0049] S3: In each stage feature subspace, unsupervised clustering is performed on the fusion time sequence samples, and a number of cluster structures are formed according to the similarity of the information layer and the physical layer feature mode, so as to distinguish different types of behavior fragments and reveal possible stage abnormal patterns;
[0050] S4: Based on the time distribution and behavior intensity of the clustering results, construct a stage credibility assessment model, screen stage candidates for each cluster, and finally retain only high credibility clusters that may represent the real attack stage;
[0051] S5: Reconstruct the selected candidate stage clusters according to time sequence and causal dependencies, establish a cross-layer causal graph, realize the inference of the complete attack chain from reconnaissance to physical impact, and output the cross-layer attack path that reflects how the behavior of the information layer drives the response of the physical layer.
[0052] In step S1 of this implementation, the network traffic characteristics of the information layer and the electrical measurement characteristics of the physical layer are integrated into a consistent time series, providing a foundation for subsequent clustering analysis and cross-layer tracing based on the kill chain stage. The two types of data originally come from different sources, have different formats, different time resolutions, and significant differences in semantic levels. Therefore, a unified fusion process is needed to achieve the alignment, compression, standardization, and correlated representation of the cross-layer data.
[0053] S1-1: Time alignment and windowing.
[0054] This invention aligns two types of data using a time windowing approach. Specifically, a fixed time interval is used as a window to aggregate all physical measurements (such as voltage, current, phase angle, and changes in device status) and all network traffic records falling within that time window (including traffic volume, number of connections, protocol type, and changes in communication behavior). Each window ultimately forms a comprehensive record that includes both physical changes and network communication behavior within that time period. If a window contains only data from one layer, this invention retains a "missing data flag" to prevent misjudgment due to missing data from both layers.
[0055] like Figure 2 The diagram shows a scenario of a power information physical system. The system is divided into a monitoring layer, a field layer, and an enterprise management layer. The monitoring layer integrates historical databases, real-time databases, data acquisition servers, and operator stations through a "control network," undertaking the functions of data storage, acquisition, and operational control. The field layer comprises two areas, each equipped with a remote terminal unit (RTU), intelligent electronic device (IED), and control station (CS), all connected to a programmable logic controller (PLC). Secure network connections are established between the two areas of the field layer, between the field layer and the monitoring layer, and between the monitoring layer and the enterprise management layer (which deploys ERP / MES / MIS systems). This ensures data interaction between layers and enhances the network security of the architecture.
[0056] In this implementation, the information layer data adopts CICAPT-IIoT dataset, which is a multi-modal APT attack dataset for industrial Internet of Things scenarios, containing 168 hours of data such as network traffic, system audit logs and complete attack stage labels, which can be used to study attack chain identification, cross-stage behavior analysis and tracing. Its characteristics are real attack process, clear stage division, and can be used as a benchmark dataset for information layer APT detection and causal path reconstruction. The physical layer data adopts PowerSystem Intrusion Dataset (PSID) dataset, which is a comprehensive attack and defense experiment dataset for power information physical system, which is constructed by a research team in the field of power system security based on a real power system simulation platform, an industrial control network environment and a typical attack scenario.
[0057] S1-2: Semantic compression and standardization.
[0058] The present application uniformly compresses and standardizes two types of data. In the physical layer, the continuously changing signals (such as voltage, current, phase angle) will extract their average value, change amplitude, fluctuation degree, etc. in each window; state information (such as switch displacement, device log event) is converted into whether it occurs, the number of occurrences or the event level, etc. While the traffic data of the information layer, from the original record, extracts network load, connection behavior change, protocol distribution, communication direction characteristics, communication frequency change, network session activity, etc. Through this way, two completely different original data are transformed into a set of general numerical indicators that can be compared and used for machine learning algorithms.
[0059] S1-3: Cross-layer coupling feature construction.
[0060] The present application constructs cross-layer association features, that is, it mines the potential coupling relationship between the network layer and the physical layer in multiple ways, typical methods include:
[0061] (1) Time correlation: if a device suddenly appears abnormal change in the physical layer, and the network traffic corresponding to the device appears significant increase or decrease in the same window, it is considered as synchronous abnormal behavior of information layer and physical layer;
[0062] (2) Topological correlation: using the mapping relationship between devices and network addresses, it is determined whether a network communication is directed to a specific physical device, and the influence degree of the communication behavior on the measurement value of the device is quantified;
[0063] (3) Joint abnormality: the abnormality degree of the information layer and the abnormality degree of the physical layer are calculated respectively, and then combined into a comprehensive index, which is used to identify suspicious windows of "network abnormality driving physical abnormality".
[0064] Through the association processing, the application does not simply splice the two types of data together, but expresses the possible cause-effect relationship between the information layer and the physical layer, so that the subsequent clustering algorithm can naturally find the cross-layer chain mode of attack behavior.
[0065] The application constructs a fixed-length time window The multi-source data is sliced, and each time window A fusion feature vector is constructed:
[0066] (1);
[0067] wherein, represents the physical layer operation features (such as voltage, current, phasor and steady-state offset statistics) in the time window; represents the network behavior features of the information layer (such as traffic statistics, connection mode, protocol usage features, etc.); represents the cross-layer coupling features, which are used to describe the association relationship between the information layer behavior and the physical layer response; represents the data quality label, including missing, retransmission, noise suppression and other meta-information.
[0068] The feature vectors of all time windows are arranged in time sequence to form a fusion time sequence for subsequent analysis:
[0069] (2);
[0070] wherein, respectively represent the fusion feature vectors of the first and second time windows, represents the fusion feature vector of the nth time window.
[0071] Through the above fusion process, the application realizes the natural docking between the information layer network traffic data and the physical layer electrical force measurement data, and converts the two from completely different data systems into a unified continuous time sequence that is computable, comparable and can be used for phased modeling, thereby laying a data foundation for cross-layer attack tracing.
[0072] After completing the unified fusion of information-physical data, the application further constructs a customized kill chain model suitable for the attack scenario of the power grid information-physical system in step S2, and performs phased feature subspace division on the fused data according to the attack features and system behavior differences of each phase. The core role of this step is to provide clear "behavior semantic guidance" for subsequent clustering analysis, ensuring that the clustering results can correspond to different phases in the attack process, thereby establishing a clear logical structure for cross-layer tracing.
[0073] S2-1: Construct a kill chain model.
[0074] The kill chain model constructed in this invention comprises four core stages, namely:
[0075] (1) Reconnaissance and penetration stage: Attackers enter the information layer through network probing, weak password attempts, scanning behavior, etc.; (2) Lateral movement and control acquisition stage: Attackers expand control permissions in the internal network and try to approach the core of the control system; (3) Command tampering stage: Attackers inject abnormal control commands or modify parameters through the control system or field controller; (4) Physical impact stage: Due to the tampered commands or data taking effect, abnormal changes occur in power equipment, electrical parameters or operating status.
[0076] S2-2: Divide the feature subspace.
[0077] To enable the clustering process to automatically distinguish between different stages, this invention semantically groups the fused cross-layer features, dividing them into four feature subspaces. Each subspace corresponds to a typical feature pattern of a certain stage. This invention divides the attack process into four stages. and define a feature subspace for each stage. :
[0078] (3);
[0079] in, Represents the d-dimensional real space; Representing the The feature subspace corresponding to each stage of the kill chain consists of the feature dimensions most relevant to the semantics of that stage.
[0080] In the feature subspace of the reconnaissance and penetration phase, this invention focuses on selecting features that reflect high-frequency network probing, connection attempts, protocol changes, and abnormal request behavior, while also including device-independent background behavioral indicators. The main objective of this subspace is to capture the behavioral patterns of attackers "probing the system," thus placing greater emphasis on the communication characteristics of the information layer, while the physical layer contributes less or remains stable.
[0081] In the feature subspace of the lateral movement and control acquisition phase, this invention selects features that reflect changes in the internal network communication structure, increased device access depth, enhanced communication with key control nodes, and increased traffic directed to sensitive devices. It also considers subtle but anomalous parameter fluctuations in the physical layer (e.g., slight changes in controller state or abnormal sampling delays) to indicate that an attacker has approached or begun to influence the control link.
[0082] In the feature subspace of the instruction tampering stage, the application focuses on extracting features such as device state changes, parameter mutations, device log abnormalities, and correlating them with behaviors such as instruction issuance, control signal changes, and device response differences in the information layer. This stage is a key link in the attack of the formal intervention control link.
[0083] In the feature subspace of the physical impact stage, the application mainly focuses on abnormal changes in electrical quantities, device load transfer, running deviation expansion, protection action abnormalities, and system state mutations. The contribution of the information layer is relatively weak, but it is used to provide event-dependent clues.
[0084] Specifically, as shown in Table 1.
[0085] Table 1: Features corresponding to each stage
[0086]
[0087] Through the above phased feature subspace construction, the application organizes the originally complex and high-dimensional fusion features according to attack semantics, enabling clustering algorithms to operate under more explicit behavior semantic constraints. The feature subspace corresponding to each stage is both distinctive and logically continuous, and can express the chain evolution path of attack behaviors in information-physical systems from the information layer to the physical layer through the adjacent relationship between stages.
[0088] In step S3 of the present embodiment, specifically, it includes:
[0089] S3-1: Multi-modal clustering based on stage feature space.
[0090] The core goal of this step is to automatically discover the behavior patterns of data in the fusion feature space and divide them into the most likely corresponding cluster structure of the damage chain stage, serving as the basis for subsequent candidate stage screening and attack path reconstruction.
[0091] Based on the four types of stage feature subspaces defined in step S2, this invention maps the fused samples of each time window to corresponding semantic coordinates, enabling the distance between samples to accurately reflect their similarity in network and physical behaviors. After mapping, the system first uses the density-based clustering algorithm DBSCAN to initially partition the samples. By identifying dense regions and outliers in the feature space, the overall data is decomposed into several coarse-grained behavioral regions, while automatically separating extreme anomalous samples. Subsequently, to further improve the granularity of stage partitioning, this invention introduces the distance-based clustering algorithm K-means within each dense region to further refine the grouping of the initially aggregated samples, allowing similar behavioral patterns to be distinguished in a more compact local space. Throughout the clustering process, the system simultaneously considers the communication change patterns of the information layer and the operational fluctuation trends of the physical layer, incorporating both types of behavior into the clustering process through a unified distance metric, thereby obtaining a joint cluster structure that reflects both network actions and physical influences.
[0092] S3-2: Candidate cluster screening.
[0093] The clustering results are divided into three categories, such as Figure 3 As shown: one type is the large, stable cluster of "main clusters," representing typical, recurring normal behavior of the system under non-attack conditions; another type is the loosely distributed "edge clusters," usually corresponding to suspicious but not entirely anomalous transitional behaviors, such as low-frequency probes by attackers or short-term disturbances to the system; finally, there are isolated, very few "anomaly clusters," where data points often exhibit both drastic shifts in communication patterns and anomalous responses in physical characteristics, highly consistent with typical characteristics of a certain stage of the kill chain. This invention analyzes the statistical characteristics, density structure, and position of each cluster in the stage feature space to classify "anomaly clusters" into... "The most likely stage category is labeled. Through this process, a preliminary set of attack samples in different stages is formed, laying the data foundation for the next step of candidate stage identification and cross-layer path reconstruction."
[0094] (4) ;
[0095] in, Indicates the first Each stage of the kill chain The set of candidate clusters; Representing the One stage of the kill chain; Representing the The feature subspace corresponding to each stage of the kill chain; Representing the The first candidate cluster in the kill chain stage; Representing the The second candidate cluster in the kill chain phase; representing the first candidate cluster of the first kill chain phase; total number of candidate clusters representing the first kill chain phase.
[0096] In step S4 of the present implementation, the phase candidate identification, specifically, includes:
[0097] After obtaining various clusters in the clustering phase, the present application enters the candidate phase identification step, the main task of which is to find out those clusters that are most likely to represent the real attack phase from all clustering clusters, and to provide the basis for the sequence of the final attack path reconstruction. Specifically, the present application evaluates the phase credibility of each clustering cluster according to its performance in the dimensions of time distribution, behavior intensity, cross-layer consistency, etc. In order to further improve the identification accuracy, the present application constructs a screening mechanism based on the logical sequence of the phase, and uses the forward and backward promotion relationship of the kill chain to constrain the cluster.
[0098] If a clustering cluster simultaneously shows obvious information layer communication anomaly and corresponding physical layer operation disturbance, it is considered to have higher attack phase characteristics; and those clusters that only show slight changes in a layer or are scattered in time axis and lack of behavior dependence between the front and back are considered to be candidate clusters with lower credibility.
[0099] The phase credibility score of each clustering cluster is defined as:
[0100] (5);
[0101] wherein, is the weight of the time concentration score; is the weight of the behavior intensity score, is the time concentration score, which measures the clustering degree of samples in the cluster on the time axis. A real attack phase usually presents intensive behavior in a period of time, while normal disturbance or noise is usually scattered and discontinuous. The more concentrated the time is, the more likely it is that the attacker is performing a phased operation, and the more dispersed the time is, the more likely it is that it is random noise or normal fluctuation.
[0102] (6);
[0103] wherein, represents the standard deviation of the timestamp of the samples in the cluster, the maximum time standard deviation among all clusters.
[0104] is the behavior intensity score, the attack behavior will produce obvious deviation from the normal operation mode change, whether in the information layer or the physical layer, these abnormal actions are usually more far from the normal mode than the data under normal operation, so the abnormal amplitude can be measured by calculating the distance between the sample and the mean value of the normal operation data.
[0105] (7);
[0106] wherein, represents the number of data samples in the cluster , represents each sample point in the cluster, represents the mean vector under normal operation state, represents the distance between and .
[0107] By screening by the above credibility score, a small number of high reliability candidate attack phase clusters can be extracted from complex multi-modal clustering results, and automatically arranged into one or more candidate phase sequences in the order of kill chain. These sequences will be further integrated into a complete cross-layer attack chain in the next step of time-cause path reconstruction.
[0108] In step S5 of the present implementation, the time-cause path reconstruction specifically includes:
[0109] After obtaining the high-credibility candidate phase cluster, the present application enters the final step of time-cause path reconstruction. The core goal of this step is to reorganize the information layer and physical layer behavior events scattered on the time axis according to the causal relationship, and restore the complete cross-layer attack chain from intrusion to physical impact of the attacker.
[0110] (1) Time sorting: based on the global time sequence, the candidate phase clusters are sorted according to the occurrence time to form a preliminary phase sequence:
[0111] (8);
[0112] (9);
[0113] wherein, represents the candidate phase cluster sequence sorted by occurrence time, represents the total number of candidate phase clusters participating in sorting; represents the occurrence time of the first candidate phase cluster after sorting; represents the occurrence time of the second candidate phase cluster after sorting; represents the occurrence time of the third candidate phase cluster Candidate stage clusters The time of occurrence.
[0114] (2) Causal relationship judgment: for any adjacent clusters and Determine whether they have a causal relationship:
[0115] (10);
[0116] in, express and There is a causal relationship between them.
[0117] The conditions for establishment include two items:
[0118] (2-1) Temporal proximity constraint:
[0119] (11);
[0120] in, It is the maximum acceptable time interval threshold, the value of which depends on the sum of system communication latency, controller processing time, and physical response time; Representative cluster with cluster The time interval; Representative cluster Start time; Representative cluster The start time is determined. If the difference is too large, the causal relationship is rejected; that is, a cluster existing alone without any preceding or following clusters is likely noise. If semantically reasonable clusters can be found before and after it, it is more likely to be an effective attack phase. All phases must conform to the kill chain progression rules to ensure that the identification results match the actual attack process.
[0121] (2-2) Cross-level causal correlation:
[0122] (12);
[0123] in These represent the behavioral feature sequences of the information layer and the physical layer, respectively. This represents the Pearson correlation coefficient. CPS attacks are characterized by cyber-physical processes. For example, during the control tampering phase, abnormal operations at the communication layer often lead to changes in current, voltage, and power angle. Therefore, it is necessary to measure the correlation between the two layers; if the correlation is negative or close to zero, it is considered that there is no causal link.
[0124] Based on this, the present invention constructs a cross-layer causal graph, takes the kill chain logic as the main structure, and maps each candidate cluster to the corresponding stage node.
[0125] (13);
[0126] (14)
[0127] (15)
[0128] (16);
[0129] wherein, represents the first stage of the kill chain, i.e., the reconnaissance and infiltration stage; represents the second stage of the kill chain, i.e., the lateral movement and control acquisition stage; represents the third stage of the kill chain, i.e., the command tampering stage; represents the fourth stage of the kill chain, i.e., the physical impact stage; represents a stage advancing symbol; represents a cross-layer causal graph; represents a node set of the causal graph (the node is a screened candidate stage cluster); represents an edge set of the causal graph (the edge is a causal correlation between candidate stage clusters); represents a screened candidate stage cluster (each node corresponds to a high-confidence candidate stage cluster); represents a cluster and a cluster have a causal relationship. As shown in Table 2, an example of an attack event cross-layer path is shown.
[0130] Table 2: Example of attack event cross-layer path
[0131]
[0132] By topological structure constraints, the stage sequence error and false causality (not meeting the relevance or time constraints) are eliminated, and the finally generated path not only reflects the advancing process of the attacker, but also shows how the information layer behavior drives the physical layer response, and realizes the complete reconstruction of the cross-layer association and stage evolution.
[0133] Through this mechanism, the invention effectively filters out isolated events and random fluctuations, so that the result only retains attack links with continuity, logicality and verifiability. The reconstructed path finally output provides interpretable cross-layer traceability evidence for the system, which can clearly show the attack source, advancing method and impact on the physical system, and provides a reliable basis for subsequent evidence collection and defense deployment.
[0134] The CPS cross-layer attack tracing method based on the kill chain model clustering provided by the application can extract stage features in multi-source data of the information layer and the physical layer and complete cross-layer clustering association, effectively compressing the complexity of the original data and significantly improving the analysis efficiency. Through candidate stage identification and time-cause path reconstruction, the application can accurately restore the complete promotion link of the attack from intrusion to physical impact, realize fine description of the attack process and cross-layer association, and provide more reliable and more interpretable basis for system anomaly detection, accurate positioning and tracing.
[0135] Figure 4 A CPS attack path reconstruction system based on kill chain model clustering is shown, comprising:
[0136] The cross-layer coupling processing unit 401 is configured to align and window the network traffic data of the information layer and the electrical measurement data of the physical layer according to a unified time, standardize the two types of data after windowing processing, and couple the two types of data after standardization to obtain a fusion time sequence.
[0137] The feature semantic grouping unit 402 is configured to perform semantic grouping on the fusion time sequence to obtain four feature subspaces, each corresponding to a stage of a kill chain model.
[0138] The feature subspace clustering unit 403 is configured to map the fusion samples of each time window to the corresponding semantic coordinates in each feature subspace, so that the distance between the fusion samples can accurately reflect their similarity in network behavior and physical behavior, and then perform clustering, so that each feature subspace corresponds to a plurality of candidate clusters.
[0139] The credibility evaluation unit 404 is configured to calculate a stage credibility score for each candidate cluster in each feature subspace, and obtain a candidate stage cluster corresponding to each feature subspace according to the stage credibility score.
[0140] The attack link generation unit 405 is configured to sort the candidate stage clusters corresponding to each feature subspace according to the occurrence time based on the global time sequence to form a preliminary stage sequence, determine the cause-effect relationship between any adjacent candidate stage clusters in the preliminary stage sequence, take each stage of the kill chain model as a backbone structure, map each candidate stage cluster obtained to the corresponding stage node, and after eliminating candidate stage clusters with incorrect stage order and no cause-effect relationship, obtain the final network attack link.
[0141] It can be understood that the above-mentioned units can be combined into one or several other units respectively or entirely, or some of the units can be further split into a plurality of units with smaller functions to implement the same operation without affecting the implementation of the technical effects of the embodiments of the present application. The above-mentioned units are divided based on logical functions. In actual application, the function of one unit can also be implemented by a plurality of units, or the functions of a plurality of units are implemented by one unit. In other embodiments of the present application, the system can also include other units. In actual application, these functions can also be assisted by other units, and can be implemented by a plurality of units in cooperation.
[0142] According to another embodiment of the present application, the system of the present embodiment can be constructed by running a computer program (including program codes) capable of performing each step involved in the corresponding method of the present application on a general computing device such as a computer including processing elements and storage elements such as a Central Processing Unit (CPU), a Random Access Memory (RAM), a Read Only Memory (ROM), etc., the computer program can be recorded on a computer readable recording medium, and loaded into the above-mentioned computing device through the computer readable recording medium and run therein.
[0143] Figure 5 A computer device is shown, which includes a processor 501, a communication interface 502, and a computer readable storage medium 503. Wherein the processor 501, the communication interface 502 and the computer readable storage medium 503 can be connected through a bus or other means.
[0144] Wherein, the communication interface 502 is used for receiving and sending data, the computer readable storage medium 503 can be stored in the memory of the electronic device, the computer readable storage medium 503 is used for storing computer programs, the computer programs include program instructions, and the processor 501 is used for executing the program instructions stored in the computer readable storage medium 503.
[0145] The processor 501 is the computing core and control core of the electronic device, which is suitable for implementing one or more instructions, and is particularly suitable for loading and executing one or more instructions to implement a corresponding method flow or a corresponding function.
[0146] The processor 501 is configured to perform the following process:
[0147] The network traffic data of the information layer and the electrical measurement data of the physical layer are aligned and windowed in a uniform time, the two types of data after windowing are standardized, and the two types of data after standardization are cross-layer coupled to obtain a fusion time sequence;
[0148] The fusion time sequence is semantically grouped to obtain four feature subspaces, each of which corresponds to a stage of a kill chain model;
[0149] In each feature subspace, the fusion sample of each time window is mapped to the corresponding semantic coordinate, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and clustering is performed after mapping, so that each feature subspace corresponds to multiple candidate clusters;
[0150] The stage credibility score of each candidate cluster in each feature subspace is calculated, and the candidate stage cluster corresponding to each feature subspace is obtained according to the stage credibility score;
[0151] Based on the global time sequence, the candidate stage clusters corresponding to each feature subspace are sorted according to the occurrence time to form a preliminary stage sequence, the causal relationship between any adjacent candidate stage clusters in the preliminary stage sequence is determined, each stage of the kill chain model is taken as a trunk structure, each candidate stage cluster obtained is mapped to the corresponding stage node, and after eliminating the candidate stage clusters with incorrect stage order and without causal relationship, the final network attack link is obtained.
[0152] The application also provides a computer readable storage medium, which is a memory device in an electronic device and is used for storing programs and data.
[0153] In addition, one or more instructions suitable for being loaded and executed by the processor are stored in the storage space, and the instructions can be one or more computer programs (including program codes).
[0154] In one embodiment, the computer readable storage medium stores one or more instructions; the processor loads and executes the one or more instructions stored in the computer readable storage medium to implement the following process:
[0155] align and window the network traffic data of the information layer and the electrical measurement data of the physical layer according to uniform time, standardize the two types of data after the windowing processing, and cross-layer coupling the two types of data after the standardization processing to obtain a fusion time sequence;
[0156] perform semantic grouping on the fusion time sequence to obtain four feature subspaces, and each feature subspace corresponds to a stage of a kill chain model;
[0157] In each feature subspace, the fusion samples of each time window are mapped to corresponding semantic coordinates, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and clustering is performed after the mapping, and each feature subspace corresponds to obtain a plurality of candidate clusters;
[0158] The stage credibility score of each candidate cluster in each feature subspace is calculated, and the candidate stage cluster corresponding to each feature subspace is obtained according to the stage credibility score;
[0159] Based on the global time sequence, the candidate stage clusters corresponding to each feature subspace are sorted according to the occurrence time to form a preliminary stage sequence, the causal relationship of any adjacent candidate stage clusters in the preliminary stage sequence is determined, each stage of the kill chain model is taken as a trunk structure, each candidate stage cluster obtained is mapped to the corresponding stage node, and after eliminating the candidate stage clusters with incorrect stage order and without causal relationship, a final network attack chain is obtained.
[0160] The application also provides a computer program product or a computer program, which comprises computer instructions stored in a computer readable storage medium. The processor of the electronic device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to make the electronic device execute the following processes:
[0161] align and window the network traffic data of the information layer and the electrical measurement data of the physical layer according to uniform time, standardize the two types of data after the windowing processing, and cross-layer coupling the two types of data after the standardization processing to obtain a fusion time sequence;
[0162] perform semantic grouping on the fusion time sequence to obtain four feature subspaces, and each feature subspace corresponds to a stage of a kill chain model;
[0163] In each feature subspace, the fusion samples of each time window are mapped to corresponding semantic coordinates, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and clustering is performed after the mapping, and each feature subspace corresponds to obtain a plurality of candidate clusters;
[0164] Calculate a stage credibility score for each candidate cluster in each feature subspace, and obtain a candidate stage cluster corresponding to each feature subspace according to the stage credibility score;
[0165] Sort the candidate stage clusters corresponding to each feature subspace according to the occurrence time based on the global time sequence, form a preliminary stage sequence, determine the causal relationship between any adjacent candidate stage clusters in the preliminary stage sequence, take each stage of the kill chain model as a trunk structure, map each obtained candidate stage cluster to a corresponding stage node, and after eliminating candidate stage clusters with incorrect stage order and without causal relationship, obtain a final network attack chain link.
[0166] Those skilled in the art can appreciate that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0167] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, all or part can be realized in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. Computer instructions can be stored in a computer-readable storage medium or transmitted by a computer-readable storage medium. Computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (e.g., coaxial cable, optical fiber, digital line) or wireless (e.g., infrared, wireless, microwave, etc.) methods. The computer-readable storage medium can be any available medium that the computer can access or a data processing device such as a server, data center, etc. integrated with one or more available media. The available media can be magnetic media (e.g., floppy disk, hard disk, magnetic tape), optical media (e.g., DVD), or semiconductor media (e.g., solid state disk), etc.
[0168] The above is only a preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A CPS attack path reconstruction method based on a kill chain model clustering, characterized in that, The method comprises the following processes: aligning and windowing network traffic data of an information layer and electrical measurement data of a physical layer according to uniform time, standardizing the two types of data after windowing, cross-layer coupling the two types of data after standardization, and obtaining a fusion time sequence; performing semantic grouping on the fusion time sequence to obtain four feature subspaces, each of which corresponds to a stage of a kill chain model; in each feature subspace, mapping fusion samples of each time window to corresponding semantic coordinates so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and clustering after the mapping is completed, so that each feature subspace corresponds to multiple candidate clusters; calculating stage credibility scores of the candidate clusters in each feature subspace respectively, and obtaining candidate stage clusters corresponding to each feature subspace according to the stage credibility scores; based on a global time sequence, sorting the candidate stage clusters corresponding to each feature subspace according to occurrence time to form a preliminary stage sequence, determining the causal relationship between any adjacent candidate stage clusters in the preliminary stage sequence, taking each stage of the kill chain model as a trunk structure, mapping each obtained candidate stage cluster to a corresponding stage node, and after eliminating candidate stage clusters with incorrect stage order and without causal relationship, obtaining a final network attack chain link.
2. The CPS attack path reconstruction method based on kill chain model clustering according to claim 1, wherein the standardization of the two types of data after windowing and the cross-layer coupling of the two types of data after standardization comprise: The multi-source data is sliced with a fixed length time window, and a fusion feature vector is constructed for each time window: wherein, represents a physical layer running feature in the i-th time window; represents a network behavior feature of an information layer in the i-th time window; represents a cross-layer coupling feature in the i-th time window; represents a cross-layer coupling feature in the i-th time window; represents a data quality label in the i-th time window, and the feature vectors of all time windows are arranged in time sequence to form a fusion time sequence for subsequent analysis . . 3. The CPS attack path reconstruction method based on kill chain model clustering according to claim 1, wherein the stages of the kill chain model comprise: a reconnaissance and penetration stage, a lateral movement and control acquisition stage, an instruction tampering stage, and a physical impact stage.
4. The CPS attack path reconstruction method based on kill chain model clustering according to claim 1, wherein the calculation of the stage credibility scores of the candidate clusters in each feature subspace respectively comprises: ; wherein, is a time concentration score; is a behavior intensity score; is a weight for the time concentration score; is a weight for the behavior intensity score.
5. The CPS attack path reconstruction method based on kill chain model clustering according to claim 4, wherein Time Concentration Score for: ,in, Cluster Standard deviation of internal sample timestamps This represents the largest time standard deviation among all clusters; behavior intensity score is: wherein denotes a cluster of data samples, denotes each sample point in the cluster, denotes the mean vector in normal operating state, represents the distance between and 6. The CPS attack path reconstruction method based on kill chain model clustering according to any one of claims 1-4, wherein the causal relationship between any adjacent candidate stage clusters in the preliminary stage sequence is determined through time proximity constraints and cross-layer causal correlation; Temporal proximity constraints include: ,in, It is the maximum acceptable time interval threshold. Representative cluster The start time, Representative cluster End time; Cross-layer causal correlations, including: wherein, represents a sequence of features of the information layer, represents a sequence of features of the behavior of the physical layer, represents a Pearson correlation coefficient. 7.A CPS attack path reconstruction system based on a kill chain model clustering, characterized in that, comprise: a cross-layer coupling processing unit configured to align and window network traffic data of an information layer and electrical measurement data of a physical layer according to uniform time, standardize the two types of data after windowing, cross-layer couple the two types of data after standardization, and obtain a fusion time sequence; a feature semantic grouping unit configured to perform semantic grouping on the fusion time sequence to obtain four feature subspaces, each of which corresponds to a stage of a kill chain model; The characteristic subspace clustering unit is configured to: map the fusion samples of each time window to the corresponding semantic coordinates in each characteristic subspace, so that the distance between the fusion samples can accurately reflect the similarity in network behavior and physical behavior, and perform clustering after the mapping; and each characteristic subspace corresponds to a plurality of candidate clusters. The credibility evaluation unit is configured to: calculate a stage credibility score for each candidate cluster in each characteristic subspace, and obtain a candidate stage cluster corresponding to each characteristic subspace according to the stage credibility score. The attack link generation unit is configured to: sort the candidate stage clusters corresponding to each characteristic subspace according to the occurrence time based on the global time sequence to form a preliminary stage sequence, determine the causal relationship between any adjacent candidate stage clusters in the preliminary stage sequence, take each stage of the kill chain model as a backbone structure, map each obtained candidate stage cluster to the corresponding stage node, and obtain a final network attack link after eliminating candidate stage clusters with incorrect stage order and without causal relationship.
8. A computer device, comprising: It comprises: a processor and a computer readable storage medium; a processor adapted to execute a computer program; a computer readable storage medium having a computer program stored therein, wherein the computer program is executed by the processor to implement the CPS attack path reconstruction method based on kill chain model clustering according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is adapted to be loaded and executed by the processor to implement the CPS attack path reconstruction method based on kill chain model clustering according to any one of claims 1 to 6.
10. A computer program product, characterised in that, The computer program product comprises a computer program, and the computer program is executed by the processor to implement the CPS attack path reconstruction method based on kill chain model clustering according to any one of claims 1 to 6.
Citation Information
Patent Citations
APT attack path reconstruction method based on time sequence diagram comparison clustering and medium
CN120474829A
APT attack detection method, device and equipment
CN120979783A