An ai security agent automated defense system and method
The AI-powered security intelligent agent automated defense system utilizes real-time data analysis and attack behavior knowledge graphs to generate scenario-based defense strategies, resolving the conflict between production continuity and security defense in industrial control systems, and achieving efficient and intelligent defense operations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING HUAQING XINAN TECH CO LTD
- Filing Date
- 2026-01-13
- Publication Date
- 2026-04-24
AI Technical Summary
Existing industrial control system security defense technologies lack the ability to dynamically adapt to the production scenarios of industrial control systems. They cannot achieve accurate and efficient automated defense while ensuring production continuity, resulting in a disconnect between defense operations and production needs, which can easily lead to production interruptions or safety hazards.
The AI-powered security intelligent agent automated defense system acquires real-time multi-dimensional data from the industrial control system through the perception layer, parses it into structured and effective data, identifies attack types and intentions by combining attack behavior knowledge graphs, generates scenario-based defense strategies based on asset classification and risk matrix methods, and coordinates security devices to execute defense operations.
It enables the accurate identification of attack threats and the generation of defense strategies adapted to production scenarios while ensuring the continuity of industrial control system production. This improves the intelligence and timeliness of security protection, avoids interference with production during defense operations, and solves the problem that traditional defense technologies cannot balance security and production.
Smart Images

Figure CN121509114B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automated defense for AI security agents, and more particularly to an automated defense system for AI security agents. Background Technology
[0002] With the deep integration of the Industrial Internet and intelligent manufacturing, industrial control systems are gradually breaking away from the traditional closed architecture and moving towards networking and intelligent transformation. In this process, the network attack risks faced by the system are also continuously increasing. Attack targets have shifted from traditional information leakage to precise strikes such as industrial control protocol tampering, business process disruption, and core equipment paralysis. Attack methods are becoming more covert and professional, such as vulnerability exploitation attacks against mainstream industrial control protocols such as Modbus and OPCUA, and targeted penetration attacks combined with industrial control business logic. This places stringent requirements on the automation, intelligence, and scenario adaptability of industrial control security defense technologies.
[0003] Existing industrial control system (ICS) security defense technologies have evolved from passive protection to partially automated defense. In the early stages, they mainly relied on boundary protection devices such as industrial firewalls and intrusion detection systems, which depended on preset rules to intercept known attack characteristics. In recent years, although some technologies have attempted to combine artificial intelligence algorithms to achieve anomaly detection and attack identification, improving the ability to perceive unknown attacks, these technologies still have significant limitations: existing defense technologies generally lack the ability to dynamically adapt to the production scenarios of ICS, and fail to fully take into account the core requirement of "production continuity first" for ICS and the effectiveness of security defense. When formulating defense strategies, existing technologies often generate standardized defense operations based solely on attack types or vulnerability levels. This fails to consider the differentiated needs of the current production phase of the industrial control system (such as the core production phase and the downtime maintenance phase), nor does it fully link the dynamic matching of asset importance classification and attack risk level. This leads to a disconnect between defense operations and production operation needs. If defense operations such as equipment restart and business switching are performed during the core production phase, it can easily cause production interruption and economic losses. On the other hand, if only lightweight defense measures are adopted during the downtime maintenance phase, it is impossible to completely fix vulnerabilities and eliminate security risks. Ultimately, this leads to a dilemma where "overly strong defense affects production, while underly weak defense cannot protect security." It is difficult to achieve accurate, efficient, and automated defense while ensuring the continuity of industrial control system production. Summary of the Invention
[0004] This application provides an AI security intelligent agent automated defense method and system, which realizes accurate and efficient automated defense while ensuring the production continuity of industrial control systems.
[0005] Firstly, this application provides an automated defense system for AI security agents, the system comprising:
[0006] The perception layer is used to acquire real-time multi-dimensional data from the industrial control system. Based on the industrial control protocol, it parses the real-time multi-dimensional data to obtain structured effective data, calculates the deviation of the structured effective data from the preset baseline model, and obtains abnormal data.
[0007] The cognitive layer is used to input the abnormal data into a preset attack behavior knowledge graph to identify attack behavior, obtain attack type, and infer attack intent based on the attack type and industrial control business logic. At the same time, it identifies industrial control system equipment assets through a combination of active scanning and passive discovery, and establishes an association mapping between the equipment assets and network topology, business processes, and security vulnerabilities to obtain asset classification results.
[0008] The decision-making layer is used to determine the degree of attack impact based on the attack type and attack intent, determine the probability of attack occurrence by combining the asset classification results and equipment vulnerability exposure, and use a preset risk matrix method to cross-evaluate the degree of attack impact and the probability of attack occurrence to obtain the attack risk level. Based on the attack risk level, the initial defense strategy is generated by integrating the industrial control system operation status. Then, the operation type of the initial defense strategy is screened and the strength is adjusted based on the production stage to obtain a scenario-based defense strategy.
[0009] The execution layer is used to coordinate security devices and industrial control devices to perform defense operations based on the scenario-based defense strategy.
[0010] In the above technical solution, the perception layer acquires real-time multi-dimensional data from the industrial control system, which is then parsed by the industrial control protocol and converted into structured and valid data. Abnormal data is then accurately screened out by calculating the deviation of the structured and valid data from the preset baseline model. This process ensures the comprehensiveness of data acquisition and the standardization of parsing, and also achieves accurate identification of abnormal data by referring to the baseline model. This provides high-quality data support for the subsequent assessment of attack threats and avoids the problem of inaccurate defense caused by data disorder or abnormal misjudgment. Building upon this foundation, the cognitive layer inputs abnormal data into a pre-defined attack behavior knowledge graph to accurately identify attack types. It then uses this information to infer attack intent through in-depth reasoning based on industrial control business logic. Simultaneously, it comprehensively identifies industrial control system equipment assets through a combination of proactive scanning and reactive discovery. Based on these assets, it establishes a mapping relationship with network topology, business processes, and security vulnerabilities, ultimately generating an asset classification result. This step not only achieves accurate characterization of attack threats and clarifies the specific types and core intents of attacks, but also clearly defines the importance of different equipment assets through asset classification. This provides crucial support for the rational allocation of subsequent defense resources and the precise formulation of defense strategies, resolving the problem of insufficient defense targeting caused by ambiguous attack threats and unclear asset priorities in traditional defense methods. As the core decision-making hub of the system, the decision-making layer first scientifically determines the impact of an attack based on its attack type and intent. Then, it objectively assesses the probability of an attack by combining asset classification results and equipment vulnerability exposure. Through a pre-set risk matrix method, it cross-evaluates the attack impact and probability of attack to accurately classify the attack risk level. Subsequently, it integrates the industrial control system's operating status to generate an initial defense strategy. Further, based on the production stage, it filters the operation types and adjusts the strength of the initial defense strategy to ultimately form a scenario-based defense strategy. This process not only achieves quantitative assessment of attack risk through the risk matrix method, ensuring accurate matching between the defense strategy and the risk level, but also effectively avoids the problem of standardized strategies being out of touch with production scenarios in traditional defenses by integrating differentiated adaptations of the industrial control system's operating status and production stages. Lightweight defense operations can be retained and operations that affect production continuity can be eliminated during the core production stage, while comprehensive defense operations can be implemented during downtime maintenance. Thus, while ensuring the effectiveness of defense, it maximizes the maintenance of the industrial control system's production continuity, achieving a synergistic unity between security and production.The execution layer, based on scenario-based defense strategies, coordinates security devices and industrial control equipment to precisely execute defense operations. This enables the defense plans formed in the early stages of perception, cognition, and decision-making to be implemented efficiently. It ensures the targeting and timeliness of defense operations and achieves seamless integration between security protection and industrial control equipment operation through device linkage, avoiding conflicts between defense operations and equipment operation. Ultimately, the entire system, through the progressive and efficient collaboration of the perception, cognition, decision-making, and execution layers, achieves automated, intelligent, and scenario-based defense against attack threats to industrial control systems, significantly improving the security protection capabilities of industrial control systems. At the same time, it always adheres to the core requirement of prioritizing production continuity, completely solving the problem that traditional defense technologies cannot balance the effectiveness of security defense with production continuity.
[0011] A second aspect of this application provides an automated defense method for AI security intelligent agents. The method includes: acquiring real-time multi-dimensional data from an industrial control system; parsing the real-time multi-dimensional data based on the industrial control protocol to obtain structured effective data; calculating the deviation of the structured effective data from a preset baseline model to obtain abnormal data.
[0012] The abnormal data is input into a preset attack behavior knowledge graph for attack behavior identification to obtain the attack type. Based on the attack type and the industrial control business logic, the attack intent is deduced. At the same time, the industrial control system equipment assets are identified through a combination of active scanning and passive discovery. Based on the equipment assets, an association mapping is established with network topology, business processes, and security vulnerabilities to obtain asset classification results.
[0013] The degree of attack impact is determined based on the attack type and attack intent. The probability of attack occurrence is determined by combining the asset classification results and equipment vulnerability exposure. The attack risk level is obtained by cross-evaluating the degree of attack impact and the probability of attack occurrence using a preset risk matrix method. An initial defense strategy is generated by integrating the attack risk level into the industrial control system operation status. The operation type and intensity of the initial defense strategy are then screened and adjusted based on the production stage to obtain a scenario-based defense strategy.
[0014] Based on the aforementioned scenario-based defense strategy, security devices and industrial control devices work together to perform defense operations.
[0015] In the above technical solution, by acquiring real-time multi-dimensional data from the industrial control system, it is possible to comprehensively cover various key data dimensions during the operation of the industrial control system, providing a complete data foundation for subsequent security analysis. Then, based on the industrial control protocol parsing, the real-time multi-dimensional data is processed separately, which can transform heterogeneous and messy raw data into standardized structured and effective data, avoiding analysis obstacles caused by inconsistent data formats. Subsequently, by calculating the deviation between the structured and effective data and the preset baseline model, abnormal data that deviates from the normal operating state can be accurately captured, ensuring that early signals of attack threats are not missed, and laying a solid data foundation for subsequent attack analysis. The aforementioned abnormal data is input into a pre-defined attack behavior knowledge graph. By leveraging the relationships between nodes in the knowledge graph, precise matching and identification of attack behaviors can be achieved, thereby clarifying the attack type. Based on this attack type and combined with industrial control business logic, deep reasoning can be performed to accurately uncover the attack intent behind the attack. At the same time, by combining active scanning with passive discovery, comprehensive and thorough identification of industrial control system equipment assets can be achieved, avoiding asset omissions caused by a single identification method. Furthermore, based on equipment assets, a mapping relationship is established between network topology, business processes, and security vulnerabilities, clearly clarifying the relationship between assets and various elements of the system. The final asset classification results clarify the importance of different assets, providing a key basis for the precise allocation of defense resources. Based on the identified attack types and intents, the potential impact of an attack on an industrial control system (ICS) can be scientifically determined. Combined with asset classification results and equipment vulnerability exposure, the actual likelihood of an attack occurring, i.e., the probability of attack occurrence, can be objectively assessed. By cross-evaluating the attack impact and probability of attack using a pre-set risk matrix method, a precise attack risk level can be quantified, avoiding risk misjudgment caused by subjective judgment. Subsequently, based on this attack risk level, an initial defense strategy is generated by integrating it into the ICS operating status, ensuring that the defense strategy is adapted to the real-time operation of the system. Then, based on the production stage, the initial defense strategy undergoes operation type screening and intensity adjustment. The final scenario-based defense strategy not only ensures the targeting of defense operations but also effectively avoids interference with production continuity caused by defense actions, achieving a dynamic balance between security defense and production operation. Finally, based on the scenario-based defense strategy, security devices and industrial control equipment work together to perform defense operations. This allows the defense plan generated through multi-stage analysis to be quickly implemented, ensuring that attack threats are contained in a timely and effective manner. The entire process, through the layered connection and synergy of the technical features of each stage, forms a fully automated defense closed loop from data perception, threat assessment, strategy generation to operation execution. This not only significantly improves the accuracy, timeliness, and intelligence of industrial control system security defense, but also, through key designs such as asset classification and scenario-based strategy adaptation, maximizes the production continuity of industrial control systems while efficiently resisting attack threats, completely solving the problem of balancing security and production in traditional defense models.
[0016] In summary, one or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0017] 1. Accurate and efficient data perception and anomaly identification: By acquiring real-time multi-dimensional data from the industrial control system, comprehensively covering key data dimensions such as network traffic, equipment operation logs, and control command flow, and then converting it into standardized structured and effective data through industrial control protocol parsing, the analysis interference caused by heterogeneous data is avoided. Subsequently, by calculating the deviation between the structured and effective data and the preset baseline model, abnormal data that deviates from the normal operating state can be accurately captured, providing high-quality and highly reliable data support for attack threat assessment and effectively reducing the probability of false or missed anomaly detection.
[0018] 2. Clear and explicit threat perception and asset management: Abnormal data is input into a pre-defined attack behavior knowledge graph. By leveraging the relationships between nodes such as attack sources and vulnerability types in the graph, accurate identification of attack types is achieved. This is then combined with industrial control system business logic reasoning to deduce attack intent, making the essence of the attack threat clearly discernible. Simultaneously, a comprehensive identification of industrial control system equipment assets is achieved through a combination of proactive scanning and reactive discovery. Based on equipment assets, a mapping is established between network topology, business processes, and security vulnerabilities, ultimately forming an asset classification result. This clarifies the boundaries between core assets, important assets, and general assets, solving the problems of ambiguous attack threats and unclear asset priorities in traditional defense, and providing a precise basis for subsequent defense decisions.
[0019] 3. Highly adaptable defense strategy generation: The attack impact is determined based on the attack type and intent. The probability of attack occurrence is determined by combining asset classification results and equipment vulnerability exposure. The precise attack risk level is obtained through cross-evaluation using a preset risk matrix method, ensuring that the defense strategy is accurately matched with the risk level. The initial defense strategy is then generated by integrating the industrial control system's operating status. Based on the production stage, the operation type of the initial defense strategy is screened and the intensity is adjusted to form a scenario-based defense strategy. This avoids defense operations that affect production continuity during the core production stage and achieves comprehensive protection during downtime maintenance, completely solving the problem of the disconnect between traditional standardized defense and production scenarios.
[0020] 5. Full-chain defense closed loop ensures security and production collaboration: By linking security equipment and industrial control equipment to execute scenario-based defense operations, the defense plan formed in the early perception, cognition, and decision-making stages can be quickly implemented, realizing a full-chain automated defense closed loop from data collection, threat identification, strategy generation to operation execution. The entire process not only greatly improves the intelligence, timeliness, and targeting of industrial control system security defense, but also maximizes production continuity through the collaborative design of each link, truly achieving the synergistic unity of security defense effectiveness and production continuity, and providing a reliable guarantee for the stable and safe operation of industrial control systems. Attached Figure Description
[0021] Figure 1 This application provides an architectural diagram of an AI security agent automated defense system as an embodiment of the present application.
[0022] Figure 2 A schematic diagram of the decision layer architecture provided in the embodiments of this application;
[0023] Figure 3 This is a schematic diagram of an execution layer architecture provided in an embodiment of this application. Detailed Implementation
[0024] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0025] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.
[0026] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0027] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0028] Based on the aforementioned background technology, further please refer to... Figure 1 , Figure 1This application provides an architecture diagram of an automated defense system for AI security agents. This system can be implemented using a computer program or run as a standalone utility application. Specifically, in this application embodiment, the method can be applied to a server, but it can also be applied to electronic devices such as servers. An automated defense system for AI security agents includes:
[0029] The perception layer is used to acquire real-time multi-dimensional data from the industrial control system. Based on the industrial control protocol, it parses the real-time multi-dimensional data to obtain structured effective data, calculates the deviation of the structured effective data from the preset baseline model, and obtains abnormal data.
[0030] In the specific implementation, to comprehensively capture the operating status and potential attack traces of the industrial control system, avoid information loss and delays caused by a single data dimension or acquisition method, and transform unstructured raw data into analyzable data to establish normal operation benchmarks for accurate anomaly identification, the perception layer performs operations according to the following logic: First, data acquisition is carried out through multi-source data acquisition modules, adopting a distributed acquisition architecture. This architecture can adapt to the characteristics of dispersed and diverse devices in the industrial control system, effectively avoiding the bottleneck of single-point acquisition and the risk of data loss. Specifically, network traffic data is collected through the mirror port of the industrial switch, PLC device operation logs and RTU device operation logs are collected through the device serial port, SCADA system operation records and industrial control command streams are collected through the SCADA system API interface, and physical layer sensor data is collected at the same time. These data together constitute real-time multi-dimensional data covering device operation, network transmission, business operation, and other dimensions. The acquisition frequency is set differently according to the importance of the device. The PLC device, as the core control device, has an acquisition frequency of 100 milliseconds per acquisition, the SCADA server has an acquisition frequency of 500 milliseconds per acquisition, and the sensor has an acquisition frequency of 1 second per acquisition. A circular buffer mechanism is used to cache data to ensure the real-time performance of high-priority data and that no data is lost. Next, the industrial control protocol parsing module processes the real-time multidimensional data. Industrial control protocols are standardized rules for communication between industrial control devices. The mainstream Modbus, OPCUA, IEC61850, S7, and DNP3 protocols each have specific data formats. Based on the format characteristics of these protocols, the parsing module extracts key fields such as operation codes, data addresses, device identifiers, and control commands, transforming the originally messy raw data into structured and meaningful effective data, providing a standardized foundation for subsequent analysis. Finally, a preset baseline model is constructed through the anomaly detection module. The baseline model is a quantitative benchmark for the normal operation of the industrial control system. The module uses the STL time-series decomposition algorithm to process historical structured effective data. This algorithm can separate trend items, periodic items, and random items in the data. Trend items correspond to long-term changes such as performance degradation caused by the accumulation of equipment operating time. Periodic items correspond to periodic changes such as flow fluctuations caused by production shifts. Random items are irregular and accidental fluctuations. By separating the three types of data, a multi-dimensional baseline model is constructed. Then, the deviation between the real-time structured effective data and the baseline model is calculated. The deviation threshold is calibrated differently according to industry and equipment type. The threshold for PLC equipment in the power industry is ±15%, the threshold for SCADA servers in the petrochemical industry is ±10%, and the threshold for sensors in the intelligent manufacturing industry is ±20%. When the deviation of real-time data exceeds the corresponding threshold, it is determined to be abnormal data.Through the above operations, the multi-source data acquisition module realizes comprehensive, real-time, and lossless acquisition of multi-dimensional data from the industrial control system; the industrial control protocol parsing module completes the transformation of raw data into structured and effective data; and the anomaly detection module achieves accurate identification of abnormal data by virtue of its precise baseline model and differentiated thresholds. The final output of abnormal data can accurately reflect the abnormal behavior of the industrial control system, providing reliable and accurate input data for the cognitive layer to carry out attack type identification.
[0031] Based on the above embodiments, as an optional embodiment, the sensing layer includes:
[0032] The multi-source data acquisition module is used to acquire real-time multi-dimensional data, consisting of network traffic data, PLC device operation logs, RTU device operation logs, SCADA system operation records, industrial control command streams, and physical layer sensor data, through a distributed acquisition architecture via industrial switch mirror ports, device serial ports, and SCADA system API interfaces.
[0033] In specific embodiments, in order to comprehensively capture the operating status and potential attack traces of the industrial control system, avoid information loss and collection bottlenecks caused by a single collection method or data dimension, and provide a complete and real-time data source for subsequent industrial control protocol parsing and anomaly detection, the multi-source data acquisition module performs operations according to the following logic: First, a distributed acquisition architecture is adopted. This architecture can adapt to the deployment characteristics of dispersed and diverse devices in the industrial control system, effectively avoid the performance bottlenecks and data loss risks caused by single-point acquisition, and ensure that the acquisition process does not affect the normal operation of the industrial control system. The module acquires data through three core acquisition interfaces: First, it collects network traffic data via the mirror port of an industrial switch. This port can replicate all communication data in the network without interfering with normal business transmission, and completely captures network interaction traces between devices. Second, it directly connects to PLC and RTU devices via device serial ports to collect PLC and RTU device operation logs. The device serial port is a standard physical interface for industrial control equipment, capable of directly reading core operational information such as CPU usage, memory usage, and instruction execution status. Third, it utilizes the SCADA system API interface, an open data interaction channel for the SCADA system, to securely acquire SCADA system operation records and industrial control command streams. Simultaneously, it collects physical layer sensor data, covering key data reflecting the physical state of the production site, such as temperature, pressure, and flow. These six types of data together constitute real-time multidimensional data, achieving full-dimensional coverage of the industrial control system's network, equipment, business, and physical environment. During the data acquisition process, the module sets different acquisition frequencies according to the importance of each device: PLC devices, as core control devices, are acquired every 100 milliseconds; SCADA servers are acquired every 500 milliseconds; and sensors are acquired every 1 second. This ensures the real-time performance of data from core devices while preventing excessive acquisition of resources from non-core devices. A circular buffer mechanism is also used for data caching. This mechanism ensures that high-priority data is not lost by cyclically overwriting old data, meeting the requirements for continuous acquisition. Through these operations, the multi-source data acquisition module achieves comprehensive, efficient, and lossless real-time multi-dimensional data acquisition from the industrial control system. The acquired data covers key dimensions such as network transmission, equipment operation, business operations, and the physical environment. This provides a complete and reliable foundation for the subsequent industrial control protocol parsing module to extract structured and effective data, and for the anomaly detection module to build baseline models and identify abnormal data. This ensures that no attack traces are missed and lays a data foundation for the accurate operation of the entire defense system.
[0034] The industrial control protocol parsing module is used to parse the real-time multidimensional data based on mainstream industrial control protocols such as Modbus, OPCUA, IEC61850, S7, and DNP3, and extract key fields of operation codes, data addresses, device identifiers, and control commands from the protocols to obtain structured and valid data.
[0035] Specifically, in order to transform the messy and unstandardized real-time multidimensional data acquired by the multi-source data acquisition module into standardized data that can be directly used for anomaly detection, and to solve the problem of data that cannot be directly analyzed due to differences in the formats of different industrial control protocols, the industrial control protocol parsing module operates according to the following logic: The module uses five mainstream industrial control protocols—Modbus, OPCUA, IEC61850, S7, and DNP3—as the core basis for parsing. These protocols are standardized rules for data communication and command interaction between devices in industrial control systems. Although different protocols are adapted to different industrial control scenarios and device types, they all contain core fields describing device operation and data transmission. The module performs targeted adaptation and parsing for the field definitions and data encoding formats of each protocol to avoid parsing deviations or omissions of key information due to protocol differences. During the parsing process, the module accurately extracts four key fields from real-time multidimensional data: operation code, data address, device identifier, and control command. The operation code clarifies the specific operation type performed by the device; the data address indicates the specific location of the data in the device's storage unit; the device identifier uniquely distinguishes different industrial control devices; and the control command is the core instruction information that drives the device to complete specific actions. Through the targeted extraction and standardization of these four key fields, the original, diverse formats of raw network traffic data, device operation logs, and control command streams are transformed into structured, meaningful, and directly usable structured data for subsequent analysis. Through this process, the industrial control protocol parsing module successfully breaks down the format barriers between different industrial control protocols, achieving standardized processing of real-time multidimensional data. The output structured and effective data possesses uniformity and usability, providing accurate and standardized input support for the subsequent anomaly detection module to build a baseline model of the industrial control scenario based on historical structured and effective data and to calculate the deviation between the real-time structured and effective data and the baseline model. This ensures that the anomaly detection process can accurately identify abnormal data.
[0036] The anomaly detection module is used to process historical structured valid data based on the STL time series decomposition algorithm, separate trend items, periodic items and random items, construct a preset multi-dimensional baseline model, calculate the deviation between real-time structured valid data and the baseline model, and obtain abnormal data when the deviation exceeds a preset threshold.
[0037] Specifically, to accurately filter anomalies from the structured and valid data output by the industrial control protocol parsing module, and to address the issues of susceptibility to normal fluctuations and high false alarm rates when directly relying on raw data for judgment, thus providing reliable input for the cognitive layer, the anomaly detection module operates according to the following logic: The module uses the STL time-series decomposition algorithm as its core tool. This algorithm is a technology specifically designed to decompose time-series data components, capable of removing irrelevant interference factors. It first processes historical structured and valid data, separating it into trend items, periodic items, and random items. Trend items correspond to the performance degradation patterns of equipment over long-term operation; periodic items are periodic fluctuations caused by production shifts; and random items are irregular and accidental changes. Based on these three types of components, a preset multi-dimensional baseline model is constructed. This model is a quantitative standard for the normal operation of the industrial control system, covering multiple data dimensions. Subsequently, the module receives real-time structured and valid data, calculates its deviation from the corresponding dimensions of the multi-dimensional baseline model. The deviation is a quantitative value of the difference between the real-time data and the normal baseline. Simultaneously, a preset threshold, differentiated by industry and equipment type, is used. When the deviation exceeds this threshold, the data is identified as abnormal. Through the above operations, the STL time series decomposition algorithm achieves accurate splitting of historical data, the multi-dimensional baseline model fits the actual operating state, and the combination of deviation and threshold accurately identifies anomalies, effectively reducing the false alarm rate and false negative rate. The output anomaly data provides accurate and reliable core evidence for the identification of cognitive layer attacks.
[0038] The cognitive layer is used to input the abnormal data into a preset attack behavior knowledge graph to identify attack behavior, obtain attack type, and infer attack intent based on the attack type and industrial control business logic. At the same time, it identifies industrial control system equipment assets through a combination of active scanning and passive discovery, and establishes an association mapping between the equipment assets and network topology, business processes, and security vulnerabilities to obtain asset classification results.
[0039] In the specific implementation, in order to transform the abnormal data output by the perception layer into attack-related information and asset risk information that can be directly used by the decision-making layer, and to avoid the problems of incomplete attack analysis and inaccurate asset value judgment caused by isolated abnormal data, the cognition layer performs operations in an orderly manner according to the following logic: First, attack type identification is carried out through the attack feature graph construction module. The preset attack behavior knowledge graph is a structured model that integrates the relationship between attack-related elements. Its nodes include attack source, vulnerability type, attack tool, target device, operation behavior, and impact consequences. The edges represent the causal and correlation relationships between each node. The module first integrates the known attack feature library (collecting the set of previously confirmed attack features) to construct this knowledge graph, and the knowledge graph supports dynamic updates to adapt to new attacks. Then, abnormal data is input into this knowledge graph for matching and identification. By comparing the operation behavior, target device identification, and other information in the abnormal data with the features of the nodes in the knowledge graph, the corresponding attack type is accurately located. Next, the attack intent reasoning module infers the attack intent. The industrial control business logic is the functional division of each device in the industrial control system, the sequence of production processes, and the path to achieve business objectives. Based on the identified attack types, combined with the target device type (such as PLC devices responsible for core control and SCADA servers responsible for data monitoring), the operational behavior characteristics in abnormal data (such as illegal data reading and control command tampering), and the stages of the industrial control business process (such as raw material processing and finished product assembly), the module clearly infers four attack intents: data theft, business interruption, equipment damage, and production process tampering, ensuring that no core attack objective is overlooked. Simultaneously, the industrial control asset mapping and classification module performs asset-related operations, employing a combination of active scanning and passive discovery to identify industrial control system equipment assets. Active scanning involves sending probe commands to the network to obtain device response information, while passive discovery involves monitoring network traffic and device communication data to extract asset identifiers. Ultimately, this accurately identifies equipment assets such as PLC devices, RTU devices, SCADA servers, and industrial switches. Based on these equipment assets, a mapping is established with network topology (physical connections and communication paths between devices), business processes (the specific responsibilities and collaboration order of devices in the production process), and security vulnerabilities (the exploitable defects inherent in the devices themselves), clearly presenting the network location, business value, and security shortcomings of the assets. Furthermore, based on the asset's criticality to production (whether it affects core production functions), the magnitude of business interruption losses (losses from production stoppages caused by asset failures), and the scope of impact of equipment damage (other devices and businesses affected by asset failures), assets are classified into three categories: core assets, important assets, and general assets.Through the above operations, the attack feature graph construction module achieves accurate identification of attack types with the help of structured knowledge graphs, the attack intent reasoning module clarifies the core target of the attack by combining industrial control business logic, and the industrial control asset mapping and classification module fully grasps the status, relationship and value level of industrial control system equipment assets. The attack type, attack intent and asset classification results output by the three modules form a complete attack and asset risk profile, providing comprehensive, accurate and structured input basis for decision-makers to conduct risk assessment and generate defense strategies.
[0040] Based on the above embodiments, as an optional embodiment, the cognitive layer includes:
[0041] The attack feature graph construction module is used to integrate the known attack feature library in the MITREATT&CK-ICS attack framework to construct a preset attack behavior knowledge graph. The nodes of the preset attack behavior knowledge graph include attack source, vulnerability type, attack tool, target device, operation behavior, and impact consequences. The edges represent the relationship between each node. The abnormal data is input into the preset attack behavior knowledge graph for matching and identification to obtain the attack type.
[0042] The attack intent reasoning module is used to reason out four attack intents—data theft, business interruption, equipment damage, and production process tampering—based on the attack type and in conjunction with the industrial control business logic.
[0043] The industrial control asset mapping and classification module is used to identify equipment assets in the industrial control system through a combination of active scanning and passive discovery. Based on the equipment assets, it establishes an association mapping relationship with network topology, business processes, and security vulnerabilities. Then, according to the criticality of the asset to production, the magnitude of business interruption losses, and the scope of impact of equipment damage, the assets are classified into three categories: core assets, important assets, and general assets.
[0044] The decision-making layer is used to determine the degree of attack impact based on the attack type and attack intent, determine the probability of attack occurrence by combining the asset classification results and equipment vulnerability exposure, and use a preset risk matrix method to cross-evaluate the degree of attack impact and the probability of attack occurrence to obtain the attack risk level. Based on the attack risk level, the initial defense strategy is generated by integrating the industrial control system operation status. Then, the operation type of the initial defense strategy is screened and the strength is adjusted based on the production stage to obtain a scenario-based defense strategy.
[0045] In practical implementation, in order to generate defense strategies that are accurately adapted to industrial control scenarios based on the attack types, attack intentions, asset classification results, and equipment vulnerability exposure information output by the cognitive layer, and to avoid the problems of rigidity in traditional decision-making mechanisms and conflicts between protection and production, the decision-making layer executes operations in an orderly manner according to the following logic: First, the attack impact degree determination module is used to make a judgment. The attack impact degree is a quantitative assessment of the potential losses caused by the attack. The module executes according to clear rules: if the attack intention is to cause business interruption or equipment damage and is related to core assets, or if the attack intention is to tamper with the production process and is related to important assets or above, it is judged as severe; if the attack intention is to steal data and is related to core assets, or if the attack intention is to cause business interruption and is related to important assets, it is judged as moderate; and other situations are judged as minor. By binding the importance of assets with the attack intention, it is ensured that the loss assessment is consistent with the actual industrial control production. Next, the attack probability determination module determines the probability. The attack probability is an assessment of the likelihood of an attack occurring. This module combines a pre-set industry attack statistics database, which synchronizes in real time with attack event data released by the National Industrial Control System Security Vulnerability Database and industry security monitoring platforms. The database is categorized and stored by industry, attack type, and device type. It supports real-time query and statistics of attack frequency, and calculates the frequency of similar attacks in the same industry and similar scenarios within the past three months. At the same time, it correlates the asset classification results and corresponding device vulnerability information: if a device vulnerability is exposed and associated with core or important assets, or if the same type of attack occurs three or more times, it is determined to be of high probability; if a device vulnerability is exposed but only associated with general assets, or if the same type of attack occurs once or twice, it is determined to be of medium probability; if the device has no exposed vulnerabilities and the same type of attack has occurred zero times, it is determined to be of low probability. By combining objective data with asset vulnerability status, the probability determination is ensured to be accurate and reliable. Then, the risk assessment module employs a pre-defined risk matrix method. This method quantifies risk through a two-dimensional cross-mapping of attack impact and probability of occurrence. It cross-maps severe, moderate, and minor attack impact with high, medium, and low attack probability to obtain four attack risk levels: extremely high, high, medium, and low. This provides a clear basis for subsequent strategy generation. Next, the defense strategy generation module generates an initial defense strategy. This module incorporates the real-time operating status of the industrial control system, i.e., production load and key process stages. A decision model is constructed using a deep reinforcement learning algorithm. The model's state space includes the industrial control system's operating status, attack type, asset classification results, and defense resource occupancy rate. The action space covers isolation and blocking, vulnerability repair, traffic scrubbing, and process termination. The reward function uses attack handling success rate, production impact, and defense resource consumption rate as core parameters. The initial defense strategy is generated by maximizing cumulative rewards, ensuring that the strategy balances defense effectiveness and resource efficiency.Finally, the strategy adaptation module performs the adaptation. This module adjusts the initial defense strategy based on the current production stage of the industrial control system, either the core production stage or the shutdown / maintenance stage: in the core production stage, operations affecting production continuity, such as equipment restarts and business switching, are removed, while lightweight defense operations like traffic isolation and temporary patch loading are retained; in the shutdown / maintenance stage, comprehensive defense operations such as deep scanning and thorough vulnerability patching are added, increasing the scope of port blocking and isolation, resulting in a scenario-based defense strategy. Through these operations, the attack impact determination module and the attack probability determination module provide accurate input for risk assessment. The risk assessment module quantifies the attack risk level, the defense strategy generation module generates an initial strategy that fits the system state, and the strategy adaptation module achieves deep adaptation between the strategy and the production scenario. The final output scenario-based defense strategy possesses targeted defense capabilities while avoiding impact on production continuity, providing accurate and reliable instruction basis for the execution layer to link security devices and industrial control devices to perform defense operations.
[0046] Based on the above embodiments, as an optional embodiment, please refer to... Figure 2 The decision-making layer includes:
[0047] The attack impact severity assessment module is used to determine the degree of attack impact according to the following rules: if the attack intent is to interrupt business or damage equipment and is related to core assets, or if the attack intent is to tamper with production processes and is related to important assets or above, it is judged as severe; if the attack intent is to steal data and is related to core assets, or if the attack intent is to interrupt business and is related to important assets, it is judged as moderate; all other cases are judged as minor.
[0048] The attack probability determination module combines a pre-set industry attack statistics database to calculate the frequency of similar attacks in the same industry and similar scenarios within the past three months. It also correlates with asset classification results and corresponding device vulnerability information: if a device vulnerability is exposed and associated with core or important assets, or if similar attacks occur three or more times, it is classified as high probability; if a device vulnerability is exposed but only associated with general assets, or if similar attacks occur once or twice, it is classified as medium probability; if no vulnerabilities are exposed and similar attacks occur zero times, it is classified as low probability. The risk assessment module uses a pre-set risk matrix method to cross-map the impact of severe, moderate, and minor attacks with high, medium, and low attack probabilities to obtain four attack risk levels: extremely high, high, medium, and low.
[0049] The defense strategy generation module is used to generate an initial defense strategy that includes isolation and blocking, vulnerability repair, traffic cleaning, and process termination, based on the attack risk level and the real-time operating status of the industrial control system, i.e., production load and key process stages, and to build a decision model through deep reinforcement learning algorithm.
[0050] The strategy adaptation module is used to adapt the initial defense strategy based on the current production stage of the industrial control system, namely the core production stage or the shutdown and maintenance stage: in the core production stage, operations that affect production continuity are removed, and lightweight defense operations such as traffic isolation and temporary patch loading are retained; in the shutdown and maintenance stage, comprehensive defense operations such as deep scanning and thorough vulnerability repair are added to improve the port blocking scope of isolation and blocking, so as to obtain a scenario-based defense strategy.
[0051] Specifically, in order to transform the attack types, attack intentions, asset classification results, and equipment vulnerability information output by the cognitive layer into defense strategies that are precisely adapted to industrial control production scenarios, and to solve the problems of traditional decision-making mechanisms lacking quantitative basis and strategies being out of touch with production needs, the decision-making layer coordinates and executes operations in an orderly manner through five modules: First, the attack impact degree judgment module is activated. The attack impact degree is a quantitative assessment of the production losses that an attack may cause. The module strictly follows preset rules to make judgments. An attack intention that is to cause business interruption or equipment damage and is related to core assets, or an attack intention that is to tamper with production processes and is related to important assets or above, is judged as severe; an attack intention that is to steal data and is related to core assets, or an attack intention that is to cause business interruption and is related to important assets, is judged as moderate; and other situations are judged as minor. By binding the attack intention with the asset classification results, it is ensured that the loss assessment is in line with the core production requirements of the industrial control system. Next, the attack probability determination module is activated. The attack probability is a quantified value of the likelihood of the same type of attack occurring in similar scenarios within the same industry. The module combines a pre-set industry attack statistics database, which synchronizes in real time with attack event data released by the National Industrial Control System Security Vulnerability Database and industry security monitoring platforms. The database is categorized and stored by industry, attack type, and device type, and supports real-time query and statistics of attack frequency. It calculates the frequency of similar attacks in the same industry and similar scenarios within the past three months, while also linking asset classification results and corresponding device vulnerability information: if a device vulnerability is exposed and associated with core or important assets, or if the same type of attack occurs three or more times, it is determined to be of high probability; if a device vulnerability is exposed but only associated with general assets, or if the same type of attack occurs one or two times, it is determined to be of medium probability; if a device has no exposed vulnerabilities and the same type of attack has occurred zero times, it is determined to be of low probability. By combining objective data with asset vulnerability status, the probability determination is ensured to be accurate and reliable. The risk assessment module is then activated, employing a pre-defined risk matrix method. This method quantifies risk by cross-mapping the attack impact level with the attack probability. It cross-maps severe, moderate, and minor attack impact levels with high, medium, and low attack probabilities, resulting in four attack risk levels: extremely high, high, medium, and low. This provides a clear priority basis for subsequent defense strategy generation. Next, the defense strategy generation module is activated. Based on the obtained attack risk levels, this module incorporates the real-time operating status of the industrial control system (ICS), i.e., production load and key process stages. A decision model is constructed using a deep reinforcement learning algorithm. The model's state space encompasses the ICS operating status, attack type, asset classification results, and defense resource occupancy rate. The action space includes four core defense operations: isolation and blocking, vulnerability repair, traffic scrubbing, and process termination. The reward function uses attack handling success rate, production impact, and defense resource consumption rate as core parameters. By maximizing the cumulative reward, an initial defense strategy incorporating the above four operations is generated, ensuring that the strategy balances defense effectiveness and resource efficiency.Finally, the strategy adaptation module is activated. This module adapts the initial defense strategy based on the current production stage of the industrial control system, either the core production stage or the shutdown / maintenance stage. During the core production stage, ensuring production continuity is the primary principle, eliminating operations that impact production, such as equipment restarts and business switching, while retaining lightweight defense operations like traffic isolation and temporary patch loading. During the shutdown / maintenance stage, where production interruption is not a concern, comprehensive defense operations such as deep scanning and thorough vulnerability patching are added, while the scope of port blocking is expanded, ultimately resulting in a scenario-based defense strategy. Through the above operations, the attack impact determination module and the attack probability determination module provide accurate quantitative input for risk assessment. The risk assessment module clarifies the attack risk level, the defense strategy generation module outputs an initial strategy that fits the risk level and system state, and the strategy adaptation module achieves deep integration between the strategy and the production stage. The resulting scenario-based defense strategy possesses both targeted attack resistance capabilities and strict adaptation to the operational needs of different production stages, effectively avoiding over- or under-defense issues. This provides a clear and feasible core basis for the execution layer to coordinate security devices and industrial control equipment to perform defense operations.
[0052] The execution layer is used to coordinate security devices and industrial control devices to perform defense operations based on the scenario-based defense strategy.
[0053] For specific embodiments, please refer to Figure 3To accurately translate the scenario-based defense strategies output by the decision-making level into actual defense actions, and to address the problems of poor coordination between security devices and industrial control equipment, reliance on manual operation leading to delayed responses, and potential disruptions to production continuity in traditional defense execution processes, the execution layer, with strategy at its core, achieves automated and production-friendly defense operations through module collaboration. First, the security control module is activated. The scenario-based defense strategy clearly defines the requirements for isolating and blocking attack traffic and cleaning traffic. As the core unit for coordinating security devices, the security control module establishes communication with three types of core security devices: industrial firewalls, intrusion prevention systems, and network access control systems. Industrial firewalls isolate attack traffic from normal business traffic, intrusion prevention systems precisely intercept attack behavior, and network access control systems restrict unauthorized access permissions. The module dynamically distributes firewall rules, protection policies, and access control lists through API interfaces (standardized data exchange interfaces between devices), directly instructing security devices to perform precise handling of attack source IPs, abnormal ports, or illegal traffic, ensuring that attack traffic is blocked in real time at the network layer and does not spread to core industrial control equipment. Next, the device linkage module is activated. Addressing the device operation requirements for vulnerability repair and process termination in the scenario-based defense strategy, the module interacts with three core industrial control devices: PLC devices, RTU devices, and SCADA servers. It employs common industrial control system communication protocols such as Modbus and OPCUA to ensure the compatibility and stability of command transmission. It performs temporary vulnerability repairs (such as closing vulnerable ports and loading temporary patches), terminates suspicious processes, and resets device status. Before all repair operations, it automatically backs up the current device configuration. If device malfunctions after the operation, a rollback mechanism can be configured to restore the device to its original operating state, eliminating security risks at the device level and preventing negative impacts on production operations. When an attack causes a core business interruption, the emergency response module simultaneously triggers a preset business self-healing process. This process is based on an emergency recovery plan pre-set according to industrial control business logic and core production needs. It quickly restores core production functions by activating backup devices to replace faulty devices, switching business links to bypass the attacked link, and restoring key production parameters to normal values. Through the above operations, the security control module achieves precise network-level blocking of attack traffic, the device linkage module eliminates security risks of industrial control equipment and ensures equipment stability, and the emergency response module ensures uninterrupted core business operations. All three strictly adhere to the requirements of scenario-based defense strategies, achieving adaptation of defense operations to the production stage. Attack handling latency is less than 1000ms, completely eliminating the lag of manual intervention. At the same time, backup rollback and business self-healing mechanisms are configured to ensure production continuity, ultimately achieving efficient implementation of the defense strategy, effectively resisting attacks without affecting the normal production operation of the industrial control system.
[0054] Based on the above embodiments, as an optional embodiment, the execution layer includes:
[0055] The security control module is used for isolation and blocking, and traffic scrubbing operations based on scenario-based defense strategies. It works in conjunction with three types of security devices: industrial firewalls, intrusion prevention systems, and network access control systems. It dynamically distributes firewall rules, protection policies, and access control lists through API interfaces to achieve real-time isolation and blocking of attack traffic.
[0056] The device linkage module is used for vulnerability repair and process termination operations based on scenario-based defense strategies. It interacts with three types of industrial control devices: PLC devices, RTU devices, and SCADA servers, to perform temporary vulnerability repair, suspicious process termination, and device status reset operations. It automatically backs up the current device configuration before repair and supports configuration rollback. The emergency response module is used to trigger a preset business self-healing process when an attack causes core business interruption. It quickly restores core production functions through three operations: backup device activation, business link switching, and key parameter recovery.
[0057] Specifically, in order to accurately translate the scenario-based defense strategies output by the decision-making level into actual defense actions, and to solve the problems of poor linkage between security equipment and industrial control equipment in the traditional execution stage, reliance on manual operation leading to delayed response and potential disruption to production continuity, the execution layer implements defense operations through three modules in a coordinated manner: First, the security control module is activated. The isolation and blocking and traffic scrubbing operations explicitly defined in the scenario-based defense strategy are the core means to resist the spread of attack traffic. As the core unit for linking security equipment, the security control module establishes communication with three core security devices: industrial firewalls, intrusion prevention systems, and network access control systems. Industrial firewalls are used to physically isolate attack traffic from normal business traffic, intrusion prevention systems are used to accurately intercept known attack behaviors, and network access control systems are used to restrict the access permissions of unauthorized entities. The module dynamically issues firewall rules, protection policies, and access control lists through API interfaces (standardized data exchange channels between devices), directly instructing the three types of security devices to perform targeted processing on attack source IPs, abnormal ports, or illegal data packets, ensuring that attack traffic is isolated and blocked in real time at the network level and does not spread to core industrial control equipment. Next, the device linkage module is activated. Addressing the device-side operational requirements for vulnerability repair and process termination in the scenario-based defense strategy, the module interacts with three core industrial control devices: PLC devices, RTU devices, and SCADA servers. It employs common industrial control system communication protocols such as Modbus and OPCUA to ensure the compatibility and stability of command transmission. It performs temporary vulnerability repairs (e.g., closing vulnerable ports, loading temporary security patches), terminating suspicious processes, and resetting device status. Before all repair operations, it automatically backs up the current device configuration. This configuration backup is a complete preservation of device operating parameters and program instructions. If device malfunctions after a repair operation, a rollback mechanism can be used to restore the device to its original operating state, eliminating security risks at the device level and preventing negative impacts on production operations. When an attack breaches network and device protection, causing core business interruption, the emergency response module simultaneously triggers a pre-set business self-healing process. This process is based on an emergency recovery plan pre-set according to industrial control business logic and core production needs. It quickly restores core production functions through three operations: backup device activation (activating redundant devices to replace faulty devices), business link switching (bypassing the attacked communication link and activating the backup link), and key parameter restoration (resetting core production parameters to normal operating values). Through the above operations, the security control module achieves precise network-level blocking of attack traffic, the device linkage module eliminates security risks of industrial control equipment and ensures equipment stability, and the emergency response module ensures uninterrupted core business operations. All three strictly adhere to the requirements of scenario-based defense strategies, achieving adaptation of defense operations to the production stage. Attack handling latency is less than 1000 milliseconds, completely eliminating the lag of manual intervention. At the same time, backup rollback and business self-healing mechanisms are configured to ensure production continuity, ultimately achieving efficient implementation of the defense strategy, effectively resisting attacks without affecting the normal production operation of the industrial control system.
[0058] Based on the above embodiments, as an optional embodiment, a self-optimization layer is used to obtain an attack tracing report by reconstructing the attack process through traffic tracing and log tracing based on the defense operation execution results of the execution layer and the industrial control system operation status data. Based on the tracing report, the defense strategy library is optimized, and the anomaly detection model and attack identification model are updated through a federated learning mechanism while ensuring data privacy.
[0059] Specifically, to enable the entire defense system to continuously evolve and address the issues of rigid strategies, inability to adapt to new attacks, and insufficient model generalization capabilities in traditional defense systems, while also mitigating the risk of privacy leaks caused by centralized data sharing, the self-optimization layer executes operations in an orderly manner according to the following logic: The self-optimization layer first receives the defense operation execution results and industrial control system operation status data transmitted by the execution layer. The defense operation execution results include key information such as whether the attack was successfully blocked, whether the vulnerability was properly patched, and whether production was affected. The industrial control system operation status data covers data such as equipment operating parameters, network traffic changes, and business process stability. These data are the core basis for subsequent optimization. Next, the attack process is reconstructed by combining traffic tracing and log tracing. Traffic tracing analyzes the communication characteristics and data interaction paths of network traffic related to the attack to locate the attack source IP, attack link, and transmitted malicious data. Log tracing analyzes the operation logs of industrial control equipment, alarm logs of security equipment, and system operation logs to extract key information such as the attack time, the type of vulnerability exploited, and the malicious operations performed. The results of these two types of tracing are integrated to form an attack tracing report that includes the attack source, attack path, attack steps, exploited vulnerability, and scope of impact. This report clearly presents the full picture of the attack and provides precise direction for subsequent optimization. Based on the attack tracing report, the defense strategy library is optimized. The defense strategy library is a collection of defense operations corresponding to various attacks. For the shortcomings of existing strategies found in the tracing report (such as insufficient isolation port range for a certain attack or incomplete vulnerability remediation steps), the operational details of the corresponding defense strategies are adjusted, and dedicated defense processes for new types of attacks are added to make the defense strategy library more closely match actual attack scenarios. Subsequently, the anomaly detection model and attack identification model are updated through a federated learning mechanism. Federated learning is a distributed model training method where self-optimizing layers from multiple industrial control scenarios act as federated nodes. These nodes retain original attack data and runtime status data locally, avoiding privacy leaks caused by centralized data transmission. Only model parameters are extracted to update gradients, which are then encrypted using homomorphic encryption. Homomorphic encryption ensures that gradient data is not cracked during transmission, protecting data privacy. The encrypted gradient data is then uploaded to the federated server, which aggregates the gradient data from all nodes to generate global model parameters, which are then distributed to each node to update the anomaly detection model and attack identification model. This allows the model to accurately identify new and mutated attacks. Through these operations, the attack attribution report provides a clear basis for optimization, and the optimized defense strategy library becomes more targeted. The federated learning mechanism achieves collaborative model updates while ensuring data privacy, ultimately enabling the self-optimizing layer to have continuous iteration capabilities. This allows the entire defense system to dynamically adapt to attack changes, maintaining an attack identification accuracy rate consistently above 98%, while avoiding data privacy leaks. This forms a closed-loop evolution of "defense-feedback-optimization," fundamentally improving the long-term security level of the industrial control system.
[0060] On the other hand, the present invention also provides an automated defense method for AI security agents, the method comprising:
[0061] S101, acquire real-time multidimensional data from the industrial control system, parse the real-time multidimensional data according to the industrial control protocol to obtain structured effective data, calculate the deviation of the structured effective data from the preset baseline model, and obtain abnormal data;
[0062] S102, the abnormal data is input into a preset attack behavior knowledge graph to identify attack behavior, obtain attack type, and obtain attack intent based on the attack type and industrial control business logic. At the same time, industrial control system equipment assets are identified by a combination of active scanning and passive discovery. Based on the equipment assets, an association mapping is established with network topology, business process and security vulnerability to obtain asset classification results.
[0063] S103, based on the attack type and attack intent, determine the degree of attack impact, combine the asset classification results and equipment vulnerability exposure to determine the probability of attack occurrence, use a preset risk matrix method to cross-evaluate the degree of attack impact and the probability of attack occurrence to obtain the attack risk level, and integrate the attack risk level into the industrial control system operation status to generate an initial defense strategy, and then filter the operation type and adjust the intensity of the initial defense strategy based on the production stage to obtain a scenario-based defense strategy.
[0064] S104, based on the scenario-based defense strategy, the security equipment and industrial control equipment work together to perform defense operations.
[0065] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Other embodiments of this disclosure will be readily apparent to those skilled in the art upon consideration of the specification and the disclosure of practical truths.
[0066] This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.
Claims
1. An AI-powered automated defense system for security agents, characterized in that, The system includes: The perception layer is used to acquire real-time multi-dimensional data from the industrial control system, parse the real-time multi-dimensional data based on the industrial control protocol to obtain structured effective data, calculate the deviation of the structured effective data from the preset baseline model, and obtain abnormal data. The perception layer includes an anomaly detection module, which processes historical structured effective data based on the STL time series decomposition algorithm, separates trend items, periodic items and random items, constructs a preset multi-dimensional baseline model, calculates the deviation between real-time structured effective data and the baseline model, and obtains abnormal data when the deviation exceeds a preset threshold. The cognitive layer is used to input the abnormal data into a preset attack behavior knowledge graph for attack behavior identification, obtain the attack type, and infer the attack intent based on the attack type and industrial control business logic. Simultaneously, it identifies industrial control system equipment assets through a combination of active scanning and passive discovery, and establishes an association mapping between these equipment assets and network topology, business processes, and security vulnerabilities to obtain asset classification results. The cognitive layer includes: The attack feature graph construction module is used to integrate the known attack feature library in the MITREATT&CK-ICS attack framework to construct a preset attack behavior knowledge graph. The nodes of the preset attack behavior knowledge graph include attack source, vulnerability type, attack tool, target device, operation behavior, and impact consequences. The edges represent the relationship between each node. The abnormal data is input into the preset attack behavior knowledge graph for matching and identification to obtain the attack type. The attack intent reasoning module is used to infer four attack intents—data theft, business interruption, equipment damage, and production process tampering—based on the attack type and combined with the industrial control business logic. The industrial control asset mapping and classification module is used to identify equipment assets in the industrial control system through a combination of active scanning and passive discovery. Based on the equipment assets, it establishes an association mapping relationship with network topology, business processes, and security vulnerabilities. Then, according to the criticality of the asset to production, the magnitude of business interruption loss, and the scope of impact of equipment damage, the assets are classified into three categories: core assets, important assets, and general assets. The decision-making layer is used to determine the degree of attack impact based on the attack type and attack intent, determine the probability of attack occurrence by combining the asset classification results and equipment vulnerability exposure, and obtain an attack risk level by cross-evaluating the degree of attack impact and the probability of attack occurrence using a preset risk matrix method. Based on the attack risk level, an initial defense strategy is generated by integrating the industrial control system's operating status. Then, based on the production stage, the initial defense strategy is subjected to operation type screening and strength adjustment to obtain a scenario-based defense strategy. The decision-making layer includes: The attack impact severity assessment module is used to determine the degree of attack impact according to the following rules: if the attack intent is to interrupt business or damage equipment and is related to core assets, or if the attack intent is to tamper with production processes and is related to important assets or above, it is judged as severe; if the attack intent is to steal data and is related to core assets, or if the attack intent is to interrupt business and is related to important assets, it is judged as moderate; all other cases are judged as minor. The attack probability determination module combines a pre-set industry attack statistics database to calculate the frequency of similar attacks in the same industry and similar scenarios within the past three months. It also correlates with asset classification results and corresponding device vulnerability information: if a device vulnerability is exposed and associated with core or important assets, or if similar attacks occur three or more times, it is classified as high probability; if a device vulnerability is exposed but only associated with general assets, or if similar attacks occur once or twice, it is classified as medium probability; if no vulnerabilities are exposed and similar attacks occur zero times, it is classified as low probability. The risk assessment module uses a pre-set risk matrix method to cross-map the impact of severe, moderate, and minor attacks with high, medium, and low attack probabilities to obtain four attack risk levels: extremely high, high, medium, and low. The defense strategy generation module is used to generate an initial defense strategy that includes isolation and blocking, vulnerability repair, traffic cleaning, and process termination, based on the attack risk level and the real-time operating status of the industrial control system, i.e., production load and key process stages, and to build a decision model through deep reinforcement learning algorithm. The strategy adaptation module is used to adapt the initial defense strategy based on the current production stage of the industrial control system, namely the core production stage or the shutdown and maintenance stage: in the core production stage, operations that affect production continuity are removed, and lightweight defense operations such as traffic isolation and temporary patch loading are retained; in the shutdown and maintenance stage, comprehensive defense operations such as deep scanning and thorough vulnerability repair are added to improve the port blocking scope of isolation and blocking, so as to obtain a scenario-based defense strategy. The execution layer is used to coordinate security devices and industrial control devices to perform defense operations based on the scenario-based defense strategy.
2. The system according to claim 1, characterized in that, The perception layer also includes: The multi-source data acquisition module is used to acquire real-time multi-dimensional data, consisting of network traffic data, PLC device operation logs, RTU device operation logs, SCADA system operation records, industrial control command streams, and physical layer sensor data, through a distributed acquisition architecture via industrial switch mirror ports, device serial ports, and SCADA system API interfaces. The industrial control protocol parsing module is used to parse the real-time multidimensional data based on mainstream industrial control protocols such as Modbus, OPCUA, IEC61850, S7, and DNP3, and extract key fields of operation codes, data addresses, device identifiers, and control commands from the protocols to obtain structured and valid data.
3. The system according to claim 1, characterized in that, The execution layer includes: a security control module and a device linkage module; The security control module is used for isolation and blocking, and traffic scrubbing operations based on scenario-based defense strategies. It works in conjunction with three types of security devices: industrial firewalls, intrusion prevention systems, and network access control systems. It dynamically distributes firewall rules, protection policies, and access control lists through API interfaces to achieve real-time isolation and blocking of attack traffic. The device linkage module is used for vulnerability repair and process termination operations based on the scenario-based defense strategy. It interacts with three types of industrial control devices: PLC devices, RTU devices, and SCADA servers, and performs temporary vulnerability repair, suspicious process termination, and device status reset operations. It automatically backs up the current device configuration before repair and supports configuration rollback. The emergency response module is used to trigger a preset business self-healing process when an attack causes a core business interruption. It quickly restores core production functions through three operations: backup device activation, business link switching, and key parameter recovery.
4. The system according to claim 1, characterized in that, It also includes a self-optimization layer, which is used to reconstruct the attack process and obtain an attack source report based on the execution results of the defense operation of the execution layer and the operating status data of the industrial control system through traffic source tracing and log source tracing. Based on the source tracing report, the defense strategy library is optimized, and the anomaly detection model and attack identification model are updated through a federated learning mechanism while ensuring data privacy.
5. The system according to claim 2, characterized in that, The acquisition frequency of the multi-source data acquisition module is set differently according to the device type: the acquisition frequency of PLC devices is 100 milliseconds per acquisition, the acquisition frequency of SCADA servers is 500 milliseconds per acquisition, and the acquisition frequency of sensors is 1 second per acquisition. A circular buffer mechanism is used to cache data to avoid data loss.
6. The system according to claim 1, characterized in that, The deviation threshold of the anomaly detection module is calibrated differently according to industry and equipment type.
7. The system according to claim 1, characterized in that, The industry attack statistics database synchronizes in real time with the national industrial control system security vulnerability database and attack event data released by the industry security monitoring platform. It is categorized and stored by industry, attack type, and device type, and supports real-time query and statistics of attack frequency.
8. An automated defense method for AI security intelligent agents in the field of industrial control, based on the system described in any one of claims 1-7, characterized in that, Includes the following steps: Acquire real-time multidimensional data from the industrial control system, parse the real-time multidimensional data based on the industrial control protocol to obtain structured effective data, calculate the deviation of the structured effective data from the preset baseline model, and obtain abnormal data; The abnormal data is input into a preset attack behavior knowledge graph for attack behavior identification to obtain the attack type. Based on the attack type and the industrial control business logic, the attack intent is deduced. At the same time, the industrial control system equipment assets are identified through a combination of active scanning and passive discovery. Based on the equipment assets, an association mapping is established with network topology, business processes, and security vulnerabilities to obtain asset classification results. The degree of attack impact is determined based on the attack type and attack intent. The probability of attack occurrence is determined by combining the asset classification results and equipment vulnerability exposure. The attack risk level is obtained by cross-evaluating the degree of attack impact and the probability of attack occurrence using a preset risk matrix method. An initial defense strategy is generated by integrating the attack risk level into the industrial control system operation status. The operation type and intensity of the initial defense strategy are then screened and adjusted based on the production stage to obtain a scenario-based defense strategy. Based on the aforementioned scenario-based defense strategy, security devices and industrial control devices work together to perform defense operations.
Citation Information
Patent Citations
Power system network space precision linkage defense control method and device
CN120342668A
Network security protection management system and method based on big data
CN120455088A
Network security threat research and judgment method, system and equipment and storage medium
CN120880765A