Industrial control asset full life cycle state management method and system based on situation awareness
By employing a situational awareness-based full lifecycle status management approach for industrial control assets, combined with proactive detection and passive monitoring, a dynamic asset management system is constructed. This solves the inaccuracy problem caused by static inventory management and enables precise risk assessment and security management of industrial control assets.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-03-13
AI Technical Summary
The reliance on static and isolated asset inventory management in existing technologies leads to inaccurate assessment of the accuracy of industrial control assets, which affects the management of security risks of industrial control assets.
By employing a situational awareness-based full lifecycle status management method for industrial control assets, a dynamic and precise asset management system is constructed using a combination of active detection and passive monitoring. Based on graph-structured network topology modeling, a trusted asset list is built using consistency confidence and fingerprint comparison results. Risk indicators are continuously collected, and situational prediction under a sliding window is used for full lifecycle status management.
It effectively improves the accuracy and security of industrial control asset management, ensures real-time updates of asset information, identifies potential risks, and enables continuous and dynamic risk assessment and management.
Smart Images

Figure CN121660449A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial control system technology, specifically to a method and system for full lifecycle status management of industrial control assets based on situational awareness. Background Technology
[0002] Currently, asset management in industrial control systems generally relies on static and isolated asset lists, typically generated manually or through periodic scanning. While these lists provide a basic identification of equipment within the industrial control system, frequent additions, replacements, and upgrades of industrial control assets lead to outdated and inaccurate asset information due to the failure to update these static lists in a timely manner. Particularly in complex industrial control environments, the diversity of equipment and dynamic changes in network topology render traditional asset identification methods inaccurate and prone to information silos, impacting subsequent security risk management and review. Because the focus of asset management is placed on the online operation phase, there is a lack of closed-loop management capabilities for the entire lifecycle of assets, from network entry to decommissioning. Especially as assets approach the end of their lifecycle, performance degradation and risk accumulation are often overlooked. The lack of intelligent decommissioning decision support based on multi-dimensional situational analysis makes it difficult to guarantee the accuracy and consistency of equipment identification, and risk assessment fails to achieve continuous, real-time dynamic monitoring, thus affecting the security risk assessment of industrial control assets.
[0003] In summary, existing technologies suffer from technical problems due to their reliance on static and isolated asset inventory management, which leads to inaccurate assessment of industrial control assets and further affects the management of industrial control asset security risks. Summary of the Invention
[0004] The purpose of this application is to provide a situational awareness-based method and system for full lifecycle status management of industrial control assets, in order to solve the technical problem in the prior art that the reliance on static and isolated asset list management leads to inaccurate assessment of the accuracy of industrial control assets, which in turn affects the security risk management of industrial control assets.
[0005] To achieve the above objectives, this application provides a method and system for managing the full lifecycle status of industrial control assets based on situational awareness.
[0006] Firstly, this application provides a situational awareness-based method for managing the full lifecycle status of industrial control assets. This method is implemented through a situational awareness-based industrial control asset lifecycle status management system. The method includes: performing parallel acquisition of active detection and passive monitoring using a preset scanning cycle; constructing an asset candidate vector set by adaptively weighting the active and passive result vectors; comparing the asset candidate vector set with a pre-built industrial control fingerprint database item by item to establish a primary identity vector for each candidate asset; and establishing a primary identity vector for each candidate asset based on the primary identity vector. A graph structure is established using vectors and network topology relationships. Nodes in the graph represent assets, and edges represent sessions or link interactions. Consistency confidence is calculated for each node based on node characteristics and neighbor aggregation information. A trusted asset list is constructed based on the consistency confidence calculation results and fingerprint comparison scores. Risk indicators for each asset are continuously collected based on the trusted asset list. These risk indicators include operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results. Situational prediction is performed under a sliding window based on the asset risk score. After the trusted asset list is identified using the situational prediction results, full lifecycle status management is performed.
[0007] Optionally, the active detection includes real-time port or protocol detection of each address segment in the industrial control network according to the hierarchical topology, and obtaining port response fingerprints, service banners, and handshake time characteristics. The passive monitoring includes continuous monitoring of local area network broadcasts and APP exchanges, and extracting source MAC, destination MAC, message templates, and time-series interaction events.
[0008] Optionally, the industrial control fingerprint database includes MAC-OUI, protocol feature templates, device signal signatures, firmware byte signatures, and a known service port matching table.
[0009] Optionally, the neighboring nodes of a node are determined according to the graph structure, and a message passing matrix is created; the neighbor information is weighted and aggregated within the message passing matrix according to the risk relevance, fingerprint matching confidence, and topological weight of the neighboring nodes to establish a local aggregation vector; the local aggregation vector is used to perform interactive consistency authentication on the node features to complete the consistency confidence calculation.
[0010] Optionally, within the period of each sliding window, a multidimensional risk time series tensor is constructed based on the asset risk score. The multidimensional risk time series tensor includes the asset risk score, risk volatility rate, risk correlation, and risk propagation coefficient of adjacent assets. The multidimensional risk time series tensor is input into a multi-layer temporal convolutional network to perform cross-window situation evolution modeling and output prediction results containing trend vectors and mutation vectors. The situation change potential energy is calculated based on the prediction results, and the situation prediction is completed using the situation change potential energy.
[0011] Optionally, based on the situation prediction results, the lifecycle end-of-life trigger identification of assets is performed, and a trigger identification result is established; the corresponding asset is identified as an end-of-life asset using the trigger identification result, and the end-of-life window range is determined based on the trend vector within the situation prediction results, and an enhanced monitoring mode is activated within the end-of-life window range; multi-source data collection is performed using the enhanced monitoring mode to establish a multi-source dataset; behavioral drift analysis is performed on the multi-source dataset, and the analysis results are input into the lifecycle end-of-life determination network to perform degradation rate fitting and abnormal morphology identification, establish an end-of-life health index, and lifecycle status management is performed based on the end-of-life health index.
[0012] Optionally, the following steps are taken: First, obtain the operation instruction sequence from the multi-source dataset. Second, perform time-series encoding on the historical instruction stream and the operation instruction sequence of the current period to establish an instruction embedding matrix. Third, perform time-series offset analysis on the instruction pattern vector of the current period and the historical stable pattern vector within the instruction embedding matrix to establish a time-series matching offset rate. Fourth, calculate the logical drift coefficient using the time-series matching offset rate to establish a first row of drift. Fifth, obtain the asset communication round-trip time series from the multi-source dataset. Sixth, obtain the delay drift index based on the asset communication round-trip time series and establish a second row of drift based on the delay drift index. Seventh, obtain power sample data from the multi-source dataset. Sixth, perform multi-scale wavelet decomposition based on the power sample data to establish high-frequency fluctuation components and low-frequency trends. Sixth, calculate the ratio of high-frequency fluctuation components to low-frequency trends to establish an energy consumption fluctuation rate. Seventh, use the energy consumption fluctuation rate, high-frequency fluctuation components, and low-frequency trends to detect energy consumption fluctuations and establish a third row of drift. Finally, complete the behavior drift analysis based on the first row of drift, the second row of drift, and the third row of drift.
[0013] Optionally, the business importance index of the terminal assets can be obtained; a joint risk assessment can be conducted based on the business importance index and the terminal health index to generate disposal recommendations for the terminal assets.
[0014] Optionally, early warning matching is performed based on the situation prediction results to establish an early warning signal; the early warning signal is then used for visualized early warning management.
[0015] Secondly, this application also provides a situational awareness-based industrial control asset lifecycle status management system for executing the situational awareness-based industrial control asset lifecycle status management method as described in the first aspect. The situational awareness-based industrial control asset lifecycle status management system includes: an asset scanning module, used to perform parallel acquisition of active detection and passive monitoring using a preset scanning cycle, and construct an asset candidate vector set by adaptively weighting the active result vectors and passive result vectors; an information comparison module, used to compare the asset candidate vector set with a pre-built industrial control fingerprint database item by item, and establish a primary identity vector for each candidate asset; and a graph structure construction module, used to construct a graph structure based on the primary identity vector and network topology. A graph structure is established, where nodes represent assets and edges represent sessions or links. Consistency confidence is calculated for each node based on node characteristics and neighbor aggregation information. A trusted asset list construction module constructs a trusted asset list based on the consistency confidence calculation results and fingerprint comparison scores. A risk collection module continuously collects risk indicators for each asset based on the trusted asset list, including operational health indicators, vulnerability exposure index, and compliance index, and establishes an asset risk score based on the continuous collection results. A situation prediction module performs situation prediction under a sliding window based on the asset risk score. After identifying the trusted asset list using the situation prediction results, full lifecycle status management is performed.
[0016] One or more technical solutions provided in this application have at least the following technical effects or advantages: By performing parallel collection of active probing and passive monitoring using a preset scanning cycle, the active and passive result vectors are used to construct an asset candidate vector set with adaptive weights. This asset candidate vector set is then compared item by item with a pre-built industrial control fingerprint database to establish a primary identity vector for each candidate asset. A graph structure is established based on the primary identity vectors and network topology, where nodes represent assets and edges represent sessions or link interactions. Consistency confidence is calculated for each node based on node characteristics and neighbor aggregation information. A trusted asset list is constructed based on the consistency confidence calculation results and fingerprint comparison scores. Risk indicators for each asset are continuously collected based on the trusted asset list, including operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results. Situational prediction is performed under a sliding window based on the asset risk score. After identifying the trusted asset list using the situational prediction results, full lifecycle status management is implemented. In other words, by combining active detection and passive monitoring, a dynamic and accurate asset management system is constructed. Based on graph-structured network topology modeling, a trusted asset list is built using consistency confidence and fingerprint comparison results. Risk indicators of various assets are continuously collected to assess the risk level of each asset. Full lifecycle status management is carried out through situation prediction under a sliding window, which effectively improves the accuracy and security of industrial control asset management.
[0017] The above description is merely an overview of the technical solution of this application. To better understand the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0019] Figure 1 This is a flowchart illustrating the situational awareness-based full lifecycle status management method for industrial control assets proposed in this application.
[0020] Figure 2 This is a schematic diagram of the structure of the situation awareness-based industrial control asset lifecycle status management system of this application.
[0021] Figure labeling: Asset scanning module 11, information comparison module 12, graph structure construction module 13, trusted list construction module 14, risk collection module 15, situation prediction module 16. Detailed Implementation
[0022] This application provides a situational awareness-based method and system for full lifecycle status management of industrial control assets. It addresses the technical problem in existing technologies where reliance on static, isolated asset lists leads to inaccurate assessments of industrial control assets, further impacting security risk management. By combining active detection and passive monitoring, a dynamic and precise asset management system is constructed. Based on graph-structured network topology modeling, a trusted asset list is built using consistency confidence and fingerprint comparison results. Risk indicators for various assets are continuously collected to assess the risk level of each asset. Full lifecycle status management is achieved through situational awareness prediction using a sliding window, effectively improving the accuracy and security of industrial control asset management.
[0023] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.
[0024] Example 1, please refer to the appendix. Figure 1 This application provides a situational awareness-based method for managing the full lifecycle status of industrial control assets. This method is applied to a situational awareness-based management system for the full lifecycle status of industrial control assets. The specific steps of this method are as follows: The system performs parallel acquisition of active detection and passive listening using a preset scanning cycle, and constructs an asset candidate vector set by adaptively weighting the active result vector and passive result vector.
[0025] Furthermore, this application also includes the following steps: the active detection includes real-time port or protocol detection of each address segment in the industrial control network according to the hierarchical topology, and obtaining port response fingerprints, service banners, and handshake time characteristics; the passive monitoring includes continuous monitoring of local area network broadcasts and APP exchanges, and extracting source MAC, destination MAC, message templates, and time-series interaction events.
[0026] Specifically, two threads, active probing and passive listening, are started in parallel, collecting data according to a preset scanning cycle. The preset scanning cycle is a pre-defined time interval for performing active probing. To avoid impacting industrial control applications with high real-time requirements, this cycle is usually relatively long and avoids peak business hours. For example, it is set to once every twelve hours.
[0027] Active probe is a technique that sends specific probe packets to target IP addresses and identifies assets based on their responses. Active probe threads scan each address range in the industrial control network according to a preset scanning cycle, performing port and protocol probes and encapsulating the results into an active result vector. This is achieved through port response fingerprints and service banners, while simultaneously measuring handshake time characteristics—the time delay when a device establishes a TCP connection. A port response fingerprint refers to the target port's response characteristics to probe packets, such as whether it is open, closed, or filtered. A service banner refers to the identification information actively returned by the server when connecting to certain service ports, typically including the service name and version number. The handshake time characteristic is the time required to establish a TCP connection with the target device; the time characteristics during transmission when a device or service establishes a connection can also serve as a unique identifier for the device.
[0028] A passive monitoring thread continuously analyzes network traffic, constructing a passive result vector depicting the actual network behavior of devices by parsing MAC addresses, industrial control protocol messages, and communication timing. Passive monitoring is a technology that discovers and identifies assets by listening to network traffic without actively interfering with the industrial control system or sending any probe messages. It monitors broadcast traffic in the local area network and communication data exchanged by applications. By listening to communication traffic between devices, it extracts source and destination MAC addresses, thereby identifying the interaction relationships and communication paths between devices. Source and destination MAC addresses are the hardware addresses of network data frames. The OUI prefix of the MAC address identifies the network card manufacturer and is an important clue for identifying industrial control equipment manufacturers. Simultaneously, it extracts message templates and time-series interaction events. Message templates are the structured characteristics of data packets for specific industrial control protocols. Deep packet analysis can extract protocol types, function codes, etc.; time-series interaction events represent the frequency, periodicity, and regularity of communication between devices.
[0029] By parsing MAC addresses, industrial control protocol messages, and communication timing, a passive result vector depicting the actual network behavior of devices is constructed. Adaptive weights are calculated based on factors such as current network load and data freshness; for example, during peak business hours, the passive weight is set to 0.8, and the active weight to 0.2; at night, it is adjusted to 0.5:0.5. The active and passive result vectors are then weighted and fused according to the adaptive weights to construct an asset candidate vector set, forming a candidate description for each asset. The asset candidate vector set includes all key assets identified in the operating environment and their detailed attribute information.
[0030] For example, in a simulated industrial control network consisting of a monitoring host A, a protocol gateway B, and a field controller C, active scanning tools and passive listening methods are deployed to comprehensively identify and discover all critical assets in the industrial control environment and collect their detailed attribute information. Active probing is performed to obtain active result vectors. A scan of monitoring host A (192.168.5.10) reveals open ports 80 and 443, identifies the web server as v2.0 from the service banner, with an average handshake time of 1.5ms, and generates active vector HMI1. A scan of protocol gateway B (192.168.5.20) reveals open port 102 and obtains the characteristic v1.5, with a handshake time of 4ms, generating active vector GW1. A scan of field controller C (192.168.5.30) shows no response on any port; this device is configured to drop all unexpected TCP packets, and active probing fails to discover it. Passive listening is then performed to obtain passive result vectors. Device S (IP 192.168.5.10, MAC AA-BB-CC-11-22-33) was detected communicating continuously with device B (IP 192.168.5.20) via a 100ms data transmission period, generating passive vector HMI2. Device B (IP 192.168.5.20, MAC DD-EE-FF-44-55-66) was detected communicating simultaneously with both 192.168.5.10 and 192.168.5.30, generating passive vector GW2. Device C (IP 192.168.5.30, MAC 12-34-56-78-9A-BC) was detected exchanging ultra-high frequency real-time data with 192.168.5.20 via the Profinet protocol at a period of 2ms. Passive vector PLC was generated, and passive monitoring successfully detected the critical controller C that had been missed by active probing.
[0031] The current time is determined to be 03:15, which is a low-load period. The fusion weights are set to: Active 0.6, Passive 0.4. For Gateway B, the active vectors GW1 and GW2 are fused to generate CGW: IP: 192.168.5.20, MAC: DD-EE-FF-44-55-66, Ports: 102, Protocols: OPC_UA / Profinet, Vendor: Manu_B, Cycle: 100ms / 2ms. For Controller C, since there is no active data, the candidate vectors are entirely composed of PLCs: IP: 192.168.5.30, MAC: 12-34-56-78-9A-BC, Ports: None (Passive), Protocols: Profinet, Vendor: Manu_C, Cycle: 2ms. Passive monitoring effectively compensates for the blind spots of active detection, and can discover key industrial control devices that are hidden by security policies or do not respond to general probes, completely eliminating shadow assets. Passive monitoring does not generate any additional network traffic, while active probing is strictly limited to periods and rates with low business impact, fundamentally eliminating potential risks to the real-time performance and stability of industrial control systems.
[0032] The candidate asset vector set is compared item by item with the pre-built industrial control fingerprint database to establish a primary identity vector for each candidate asset.
[0033] Furthermore, this application also includes the following steps: the industrial control fingerprint database includes MAC-OUI, protocol feature template, device signal signature, firmware byte signature, and known service port matching table.
[0034] Specifically, after receiving the asset candidate vector set from upstream, which represents all key assets already identified in the industrial control environment, an automated comparison process is initiated. For each asset in the asset candidate vector set, its various features are cross-compared with the industrial control fingerprint database at multiple levels. The industrial control fingerprint database is a pre-built knowledge base containing a large amount of characteristic information of industrial control equipment, and it is the core basis for accurate asset identification, used to accurately identify and verify industrial control assets.
[0035] The industrial control fingerprint database includes MAC-OUI, protocol feature templates, device signal signatures, firmware byte signatures, and a known service port matching table. MAC-OUI is the organization-unique identifier for a MAC address. The first three bytes of the MAC address, i.e., the first 24 bits of each network device's MAC address, are uniformly assigned by IEEE and used to identify the network device manufacturer. Protocol feature templates are a set of feature patterns defined using different protocols to describe the device's protocol characteristics; that is, the unique identification fields, data structures, and communication modes of various industrial control protocols in network packets. Device signal signatures are behavioral characteristics exhibited by the device during communication that uniquely identify its model or firmware version. Firmware byte signatures are specific byte sequences or strings containing firmware version information extracted from the device's response messages, used to identify the device's manufacturer and model. The known service port matching table is a mapping table that associates common industrial control devices and their services with default TCP / UDP port numbers, recording the port numbers used by common services to infer the type of service running based on the device's open ports.
[0036] By comparing the first 24 bits of the device's MAC address with vendor information in the fingerprint database using MAC-OUI, the range of possible vendors for the device can be quickly narrowed down. Using a known service port matching table and protocol feature templates, the open ports and communication protocols are verified to match the typical characteristics of devices from that vendor. Service banners or specific protocol response data obtained through proactive probing are matched against firmware byte signatures in the fingerprint database using regular expressions or hash values; simultaneously, network behavior is analyzed to ensure it matches device signal signatures in the database. All matching results are combined to generate a primary identity vector for each asset candidate vector, containing inferred device model, vendor, and firmware version information, and an initial confidence score is assigned to each inference.
[0037] For example, suppose a candidate vector CX is identified through active scanning and passive monitoring, describing a device with IP address 10.0.1.15. Its characteristics include MAC: 00-1C-1D-AA-BB-CC, OpenPorts: 44818, 2222, Protocol: CIP, and Banner: DeviceX-3000Firmwarev3.2.1. A fingerprint database is consulted, revealing that OUI00-1C-1D belongs to controller manufacturer C. The candidate asset vector shows port 44818 open, which the industrial control fingerprint database indicates is a commonly used EtherNet / IP protocol port for manufacturer C's devices. The open port 2222 is also marked in the industrial control fingerprint database as the engineer configuration port for manufacturer C's devices. Network traffic analysis confirms that the device is indeed using the CIP protocol to communicate with the scanner, and the packet structure fully conforms to the CIP protocol template definition in the fingerprint database. Key strings are extracted from the candidate vector's banner information, DeviceX-3000Firmwarev3.2.1. In the firmware byte signature section of the fingerprint database, an exact match was found, identified as "DeviceX-3000 series controller from manufacturer C, firmware version v3.2.1". A specific, non-destructive enumeration command was sent to the device. The data packet returned by the device contained a unique device serial number field and a hardware revision field, whose format and location were completely consistent with the DeviceX-3000 signal signature in the fingerprint database. Based on all the above successful matching evidence, a final primary identity vector (PX) was generated for this asset: IP is 10.0.1.15, MAC is 00-1C-1D-AA-BB-CC, identified model is DeviceX-3000, vendor is Manu_C, firmware version is v3.2.1, and confidence score is 95 / 100. The confidence score of 95 is composed of MAC-OUI match 15, port match 20, protocol verification 20, banner exact match 30, and signal signature match 10.
[0038] By comparing each item with the industrial control fingerprint database, the identity information of each device is confirmed, including manufacturer, model, and service type, effectively avoiding identification errors caused by similar device names or incomplete information. Through rapid and accurate asset identification, industrial control equipment is managed, especially during equipment updates, replacements, or additions, enabling real-time updates to the asset list and ensuring continuous monitoring and management of each device.
[0039] A graph structure is established based on the primary identity vector and network topology. Nodes in the graph structure represent assets, and edges represent sessions or link interactions. Consistency confidence of each node is calculated based on node characteristics and neighbor aggregation information.
[0040] Furthermore, this application also includes the following steps: determining the neighboring nodes of a node according to the graph structure and creating a message passing matrix; performing weighted aggregation of neighbor information within the message passing matrix based on the risk relevance, fingerprint matching confidence, and topological weight of the neighboring nodes to establish a local aggregation vector; and using the local aggregation vector to perform interactive consistency authentication on node features to complete the consistency confidence calculation.
[0041] Specifically, based on the primary identity vector of each asset and the network topology of devices in the system, the system constructs a graph structure. In the graph structure, nodes represent assets, and the characteristics of a node are determined by the asset's identity vector; edges represent sessions or links between assets, indicating the communication or data flow between assets. Network topology is the structural information of the physical or logical connections between assets in an industrial control system. For example, a monitoring host typically communicates directly with multiple programmable logic controllers (PLCs) on a specific network segment.
[0042] Based on the graph structure, each node in the graph determines its neighboring nodes, and a message passing matrix is initialized to manage the information flow between nodes. In the graph structure, the message passing matrix is a tool used to describe the information flow between nodes; rows and columns correspond to nodes, and matrix elements define the rules and weights for information passing between nodes. For each target node, all its neighboring nodes are traversed, and the risk relevance, fingerprint matching confidence, and topological weights of each neighbor's connection to the target node are determined. These are then weighted in the message passing matrix to generate a local aggregation vector representing its direct network environment. Risk relevance is a quantitative indicator used to measure the strength of the association between two adjacent nodes at the risk level. For example, if a PLC is identified as high-risk, the risk relevance of the HMI that communicates directly with it will also increase accordingly. Fingerprint matching confidence is extracted from the primary identity vector and represents the reliability of the node's own identity recognition result. For example, a device identified through precise banner matching has a confidence level of 95 / 100. Topological weights are weights assigned based on the connection type and business importance represented by the edges. For example, the weight of a periodic control communication link between a monitoring host and a programmable logic controller is much higher than that of a temporary, low-frequency diagnostic connection.
[0043] The target node aggregates weighted feature information from all its neighboring nodes using a message passing matrix, forming a local aggregation vector. This local aggregation vector is then used for interactive consistency authentication of node features, comparing the initial identity vector with the local aggregation vector. In simpler terms, it compares whether the target node's self-proclaimed identity is consistent with the identity reflected by its neighboring nodes. If the node's behavior is consistent with that of its neighboring nodes, the node's consistency confidence is high, indicating the reliability of its identity and the consistency of its state. If there are significant differences in information, the consistency confidence is low, potentially indicating that the asset is abnormal or has not been correctly identified.
[0044] For example, assuming a control network graph structure, the primary identity vector of target node A identifies it as a database server with a confidence level of 90; its neighboring node B is a monitoring host with a confidence level of 95, a risk correlation of 0.7 with A, and a topology weight of 0.9 due to its status as a primary data source; its neighboring node C is a programmable logic controller (PLC) with a confidence level of 98, a risk correlation of 0.8 with A, and a topology weight of 0.85 due to its status as a control terminal; and its neighboring node D is an engineering workstation with a confidence level of 92, a risk correlation of 0.3 with A, and a topology weight of 0.4 due to its status as a low-frequency management connection. A message passing matrix is created for node A, with rows and columns corresponding to A, B, C, and D. Based on the confidence levels of B, C, and D, their risk correlation with A, and their topology weights, a weighted aggregation is calculated. The resulting local aggregated vector strongly exhibits the characteristics of a server that closely interacts with the monitoring host and PLC of the control layer equipment. The self-proclaimed identity of node A as a database server is compared with the contextual identity reflected by the local aggregated vector, suggesting a possible real-time data server or control server. A standard database server typically does not establish high-frequency, high-priority direct data connections with the underlying PLC. This interaction pattern is seriously inconsistent with its self-proclaimed identity. Therefore, the interaction consistency authentication fails, and node A's final confidence score drops from the initial 90 points to 35 points, marking it as having a questionable identity.
[0045] By employing graph structure modeling and weighted information propagation, the consistency of asset identity is effectively identified. If a node's information is highly consistent with that of its neighboring nodes, the asset's identity is confirmed as trustworthy; otherwise, a warning is issued indicating potential anomalies. By weighted aggregation of neighboring node information, and by comprehensively considering risk relevance, fingerprint matching, and topological relationships, risk assessment becomes more comprehensive, enabling the timely detection of potential risks.
[0046] A list of trusted assets is constructed based on the consistency confidence score and fingerprint comparison score.
[0047] Specifically, a trusted asset list will be constructed by comparing fingerprint scores obtained through item-by-item comparisons with a working condition fingerprint database and calculating consistency confidence based on a graph structure. Appropriate weights will be assigned to the consistency confidence calculation result and the fingerprint comparison score; for example, the fingerprint score weight can be slightly higher in the initial stage, and the consistency confidence weight can be increased after the system stabilizes. A comprehensive trust score will be obtained by weighting the weights with their corresponding values, i.e., Comprehensive Trust Score = Consistency Confidence Calculation Result * Consistency Confidence Calculation Result Weight + Fingerprint Comparison Score * Fingerprint Comparison Score Weight.
[0048] An admission threshold is set. Only assets with a comprehensive score higher than this threshold will have their identity information (manufacturer, model, firmware version) and final score officially entered into the trusted asset list. Assets below the threshold are marked as pending review or suspicious assets, triggering alarms and requiring manual intervention from the administrator, thus ensuring the high trustworthiness of assets in the list. For example, asset P has a fingerprint comparison score of 95 and a consistency confidence score of 88, resulting in a comprehensive trustworthiness score of 95*0.5 + 88*0.5 = 91.5. Since the comprehensive score of 91.5 > 70, it is allowed to be included in the trusted asset list. Asset Q has a fingerprint comparison score of 85 and a consistency confidence score of 30, resulting in a comprehensive trustworthiness score of 57.5. Since the comprehensive score of 57.5 < 70, it is rejected from the trusted list and marked as a high-risk asset. By combining consistency confidence and fingerprint comparison scores, the identity and trustworthiness of assets are accurately confirmed, avoiding asset management problems caused by inconsistencies or errors in information.
[0049] Risk indicators for each asset are continuously collected based on the trusted asset list. These risk indicators include operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results.
[0050] Specifically, based on the trusted asset list, risk indicators are continuously collected for each asset, including operational health indicators, vulnerability exposure index, and compliance index. Operational health indicators reflect the normal operating status of the equipment, including equipment performance data such as CPU / memory utilization, network communication latency and packet loss rate, and abnormal process / service status; the vulnerability exposure index measures the degree of threat an asset is posed by known vulnerabilities, including CVSS basic score, vulnerability exploitability status, and vulnerability patching status; the compliance index measures whether the asset configuration complies with internal security policies or external requirements, including password policy compliance, network access control compliance, and audit log configuration.
[0051] Based on a trusted asset list, risk indicators are continuously collected for each asset on the list. Operational health indicators are periodically collected using various monitoring probes and scanners; vulnerability exposure indices are calculated by comparing data with a vulnerability database at regular intervals and considering the specific asset model and firmware version; and compliance indices are assessed by periodically performing compliance baseline checks.
[0052] The continuously collected operational health indicators, vulnerability exposure index, and compliance index are calculated, and different weights are assigned to different indicators. For example, operational health accounts for 30%, vulnerability exposure for 50%, and compliance for 20%. A weighted summation is then performed to output a final asset risk score ranging from 0 to 100. The asset risk score is based on the weighted summary of various risk indicators, representing the overall risk level of each asset. The asset risk score is usually dynamic, changing with changes in the risk indicators. A high-risk score indicates that the asset has significant security vulnerabilities and requires priority handling. For example, taking controller C in the trusted asset list as an example, its operational health indicators show a CPU utilization of 92%, a communication latency of 45ms with HMI_A, and the detection of an unknown process svchost_mod.exe running, resulting in a operational health sub-score of 25 / 100. Its vulnerability exposure index shows a high-risk vulnerability discovered during a vulnerability scan, with a base score of 9.0 for CVSSv3.1. This vulnerability already has publicly available exploit code and has not been patched, resulting in a vulnerability exposure index of 90 / 100. A compliance scan revealed that the device used the default engineer password admin:admin. Furthermore, its Telnet service violated the policy prohibiting the use of unencrypted management channels, resulting in a compliance index of 40 / 100. The risk calculation engine used weights including operational health (0.3), vulnerability exposure (0.5), and compliance (0.2). The asset risk score was calculated as (25*0.3 + 90*0.5) + 40*0.2 = 60.5. Since 0-30 represents low risk, 31-70 represents medium risk, and 71-100 represents high risk, this device was assessed as medium risk.
[0053] By continuously collecting and dynamically updating operational health metrics, vulnerability exposure indices, and compliance indices, the risk status of each asset is comprehensively assessed. Based on the asset's risk score, security managers can make more accurate decisions. For example, devices with high risk scores may require priority remediation or isolation to avoid potential security vulnerabilities.
[0054] Based on the asset risk score, a situation prediction is performed under a sliding window. After the situation prediction results are used to identify the trustworthy asset list, full lifecycle status management is performed.
[0055] Furthermore, this application also includes the following steps: within the period of each sliding window, constructing a multidimensional risk time series tensor based on the asset risk score, wherein the multidimensional risk time series tensor includes the asset risk score, risk volatility rate, risk correlation, and risk propagation coefficient of adjacent assets; inputting the multidimensional risk time series tensor into a multilayer temporal convolutional network, performing cross-window situation evolution modeling, and outputting prediction results including trend vectors and mutation vectors; calculating the situation change potential energy based on the prediction results, and using the situation change potential energy to complete situation prediction.
[0056] Specifically, within each sliding window period, a multidimensional risk time-series tensor is constructed for each asset. This tensor integrates the time series of its own risk, rate of change, associated risks, and network propagation characteristics. The multidimensional risk time-series tensor is a high-order data structure used to organize asset risk data within the sliding window, going beyond a single risk score. It includes asset risk score, risk volatility rate, risk correlation, and risk propagation coefficients of adjacent assets. The asset risk score is a static risk snapshot of the asset at each point in time, representing the risk level of each asset. The risk volatility rate is the rate of change of the risk score per unit of time, i.e., the first derivative, characterizing whether the risk is rapidly increasing, decreasing, or remaining stable. For example, if the score rises from 40 to 60 in one hour, the volatility rate is +20 / hour. Risk correlation is used to quantify the strength of risk associations between assets due to functional coupling or data flow dependencies. For example, an increase in the risk of a key controller will significantly increase the risk correlation of monitoring hosts that interact closely with it. The risk propagation coefficient of adjacent assets, based on graph structures, quantifies the ease and impact of risk spreading from one asset to its neighbors, reflecting the risk transmission effect between assets. For example, the failure of a firewall may have an extremely high risk propagation coefficient.
[0057] The multidimensional temporal tensors constructed within each time window are input into a multi-layer temporal convolutional network for analysis. A multi-layer temporal convolutional network is a deep learning model specifically designed for processing time-series data. Through its unique causal convolution and dilation structure, it effectively extracts long-term dependency patterns and complex features from historical data. A multi-layer temporal convolutional network means that the network contains multiple convolutional layers, enabling multi-level abstract learning of features at different time scales. By extracting and abstracting information from multiple levels within the network, the multi-layer temporal convolutional network performs cross-window situational evolution modeling, ultimately outputting two key results: a trend vector describing the long-term trend of risk and a mutation vector providing early warning of sudden risks. The trend vector is a quantitative description of the overall direction and intensity of asset risk changes over a future period, such as continuous increase, decrease, or stabilization; the mutation vector is a quantitative description of the probability and expected magnitude of a sudden jump in asset risk.
[0058] Based on the trend vector and mutation vector, the potential energy of the situation change is calculated. This potential energy reflects the intensity of risk changes and helps predict potential drastic risk fluctuations in the future. For example, potential energy = trend intensity * 0.7 + mutation intensity * 0.3. Assuming we analyze asset controller Z, with a sliding window of the past 24 hours and a step size of 1 hour, and considering its frequent communication with a database server Y that has a high-risk vulnerability, the correlation is 0.85 (out of 1.0). The analysis shows an upward trend vector with an intensity of 0.8, predicting a significant increase in risk over the next 12 hours. The mutation vector has a probability of 0.3 and an expected magnitude of 25, indicating a 30% probability that a potential chain reaction could cause a sharp increase of 25 risk points in the short term. Therefore, the potential energy of the situation change = 0.8 * 0.7 + (0.3 * 25 / 100) * 0.3 = 0.5825, which is considered a medium-to-high potential energy state. The situation prediction conclusion is that asset controller Z is in a high-risk upward trend over the next 12 hours, and there is a moderate probability that a sudden surge in risk may occur due to a problem with the associated asset database server Y. It is recommended to immediately check database server Y and strengthen monitoring of controller Z.
[0059] By combining sliding windows and temporal convolutional networks, the system can identify changing trends in asset risks in advance, helping managers predict the future safety status of assets. The trend vectors and mutation vectors in the measurement results provide in-depth analysis of risk changes, especially in detecting potential sudden risk events, helping to adjust safety strategies in a timely manner.
[0060] Furthermore, this application also includes the following steps: identifying the end-of-life trigger of an asset based on the situation prediction results, and establishing trigger identification results; using the trigger identification results to identify the corresponding asset as an end-of-life asset, determining the end-of-life window range based on the trend vector within the situation prediction results, and activating an enhanced monitoring mode within the end-of-life window range; using the enhanced monitoring mode to perform multi-source data collection and establish a multi-source dataset; performing behavior drift analysis on the multi-source dataset, inputting the analysis results into the end-of-life determination network, performing degradation rate fitting and abnormal morphology identification, establishing an end-of-life health index, and managing the life cycle status based on the end-of-life health index.
[0061] Furthermore, this application also includes the following steps: acquiring the operation instruction sequence from the multi-source dataset, performing time-series encoding on the historical instruction stream and the operation instruction sequence of the current period, and establishing an instruction embedding matrix; in the instruction embedding matrix, performing time-series offset analysis based on the instruction pattern vector of the current period and the historical stable pattern vector, and establishing a time-series matching offset rate; calculating the logical drift coefficient using the time-series matching offset rate, and establishing a first row of drift; acquiring the asset communication round-trip time series from the multi-source dataset, acquiring the delay drift index based on the asset communication round-trip time series, and establishing a second row of drift based on the delay drift index; acquiring power sample data from the multi-source dataset, performing multi-scale wavelet decomposition based on the power sample data, and establishing high-frequency fluctuation components and low-frequency trends; calculating the ratio of high-frequency fluctuation components to low-frequency trends, establishing an energy consumption fluctuation rate, and using the energy consumption fluctuation rate, high-frequency fluctuation components, and low-frequency trends to detect energy consumption fluctuation, and establishing a third row of drift; completing the behavior drift analysis based on the first row of drift, the second row of drift, and the third row of drift.
[0062] Specifically, the system identifies end-of-life triggers based on situational forecasts, meaning it identifies assets that are about to enter their final stage. End-of-life assets typically exhibit characteristics such as performance degradation and increased risk, indicating they have entered a phase requiring close monitoring and preparation for retirement. For example, when an asset's long-term risk trend vector is detected to be continuously upward with persistently high potential energy, or when its performance indicators show an irreversible downward trend, an automatic trigger identification result is established.
[0063] Based on the trigger identification results, the corresponding assets are marked as end-of-life assets. End-of-life assets are those that have entered the end of their life cycle, typically exhibiting characteristics such as equipment aging, performance degradation, and increased failure rates. In industrial control systems, these assets require special attention because they may pose higher safety and stability risks. The end-of-life window range is determined based on the trend vector within the situation prediction results; that is, the future period in which the asset may fail or the risk may increase sharply. For example, if the probability of a certain asset failing within the next 30 days is predicted to exceed 80%, then these 30 days are considered the end-of-life window.
[0064] Activating Enhanced Monitoring Mode within the end-stage monitoring window significantly increases the frequency and dimensionality of data collection, performing multi-source data acquisition to build a multi-source dataset. Enhanced Monitoring Mode is a high-frequency, multi-dimensional, and fine-grained data acquisition state initiated for end-stage assets, designed to capture more refined changes in health status. Within the end-stage monitoring window, the frequency of data acquisition is increased, the number of sensors involved is increased, and more health data about the equipment is obtained.
[0065] The process involves acquiring operation instruction sequences from multi-source datasets, i.e., control instructions in industrial control systems, used to control the state and behavior of equipment. Historical instruction streams refer to sequences of instructions executed in the past, while the current cycle instruction sequence refers to instructions executed within a specified time window. Temporal encoding is performed on both the historical instruction streams and the current cycle operation instruction sequences, transforming discrete operation instructions into numerical vectors that are processed by a computer model and retain their temporal relationships. The instruction embedding matrix is a matrix formed after temporal encoding, where each row represents the instruction feature vector at a time step. The entire matrix characterizes the deep patterns of instruction sequences over a period of time.
[0066] In the instruction embedding matrix, temporal offset analysis is performed by comparing the instruction pattern vector of the current period with the historical stable pattern vector to calculate the temporal matching offset rate. By calculating the temporal matching offset rate, the difference between the current period's instruction flow and historical behavior is assessed, thereby identifying whether there are behavioral anomalies or drifts, representing the degree of deviation of the current instruction sequence from the historical normal pattern. The logical drift coefficient is calculated using the temporal matching offset rate to establish the first-order drift amount, reflecting the degree of change in the instruction flow and indicating the extent to which asset behavior deviates from its normal pattern.
[0067] Obtain the asset communication round-trip time series from the multi-source dataset, which is the response time data series required for the asset to complete a full communication with the peer device. Obtain the latency drift index based on the asset communication round-trip time series, and establish the second row of drift based on this, which reflects the degradation of the asset's response speed.
[0068] Power sample data from multi-source datasets, specifically power consumption data of industrial control equipment, is acquired to reflect the equipment's energy consumption. High-frequency and low-frequency features of the signal are extracted through multi-scale wavelet decomposition. High-frequency fluctuation components represent instantaneous fluctuations during equipment operation, while low-frequency trends represent long-term operating trends. The ratio of high-frequency fluctuation components to low-frequency trends is calculated to establish an energy consumption volatility rate, used to measure the relative instability of the power signal. The energy consumption volatility rate, combined with high-frequency fluctuation components and low-frequency trends, is used to detect energy consumption fluctuations, further verifying equipment stability. A third line, drift, is established to reveal the asset's physiological health from an energy perspective. The first, second, and third lines of drift are quantified anomaly values from three dimensions: logical behavior (instructions), performance (latency), and physical characteristics (power consumption), respectively.
[0069] Behavioral drift analysis is performed based on the drift values in the first, second, and third rows to identify whether the asset exhibits abnormal behavior and whether further health checks or repairs are needed. By using drift values across these three dimensions, the main types of asset failures can be preliminarily determined, changes in equipment operation can be detected early, and the risk of equipment failure or performance degradation can be predicted based on the drift analysis results.
[0070] The results of behavioral drift analysis are input into the end-of-life assessment network, which simultaneously performs degradation rate fitting and abnormal morphology recognition, ultimately outputting an accurate end-of-life health index. The end-of-life assessment network is a specially trained deep learning model whose core task is to assess the overall health status of assets and predict remaining lifespan. The network performs degradation rate fitting and abnormal morphology recognition in parallel. The degradation rate fitting module analyzes drift data over nearly N periods, using linear or nonlinear regression models to calculate the deterioration trend and speed of various drift parameters and overall health status, i.e., the degradation rate. N is a positive integer greater than or equal to 1. The abnormal morphology recognition module acts as a powerful pattern classifier, matching the current behavioral drift pattern with various known end-of-life fault features in the knowledge base, such as thermal performance degradation patterns caused by fan failure or power fluctuation patterns caused by capacitor bulging, calculating the matching degree, i.e., the abnormal morphology probability. A terminal health index is established, calculated as: Terminal Health Index = Initial Health Score - (Degradation Rate * Remaining Time Weight) - (Abnormal Morphology Probability * Morphology Severity Coefficient). Lifecycle status management is based on this index; that is, corresponding operational strategies are automatically triggered according to the specific value and threshold of the terminal health index. The terminal health index is a quantitative indicator that integrates degradation rate and abnormal morphology, intuitively representing the remaining health level of an asset at the end of its lifecycle. The lower the terminal health index, the closer the asset is to functional failure. For example, with an initial health score of 100 and a degradation rate of -15 points / week (meaning the health index decreases by 15 points per week), if the current performance drift surge pattern highly matches the fault characteristics of main processor cache failure (match probability of 85%), and the preset severity coefficient is 40, the calculated terminal health index is 6. By combining behavioral drift analysis and a lifecycle end-of-life determination network, the system accurately determines whether a device has entered the end of its lifecycle, monitors the device's health status in real time, and formulates reasonable lifecycle management strategies based on this index.
[0071] Furthermore, this application also includes the following steps: obtaining business importance indicators for end-stage assets; conducting a joint risk assessment based on the business importance indicators and the end-stage health index, and generating disposal recommendations for end-stage assets.
[0072] Specifically, the business importance index of end-of-life assets obtained from the asset management system is an indicator used to measure the importance of an asset to overall business operations. It is typically composed of multiple factors, including the asset's business criticality, dependency, and impact on production lines or systems. A high business importance for an asset means that its failure could have a significant impact on production, service, or safety. The business importance index for each asset is calculated by analyzing multiple aspects such as equipment production efficiency, system dependency, and impact on workflows.
[0073] Joint risk assessment based on business importance indicators and end-of-life health indices is typically conducted using a pre-defined decision matrix. The vertical axis of this matrix represents business importance indicators, and the horizontal axis represents the end-of-life health index. Each cell in the matrix corresponds to a pre-defined disposal recommendation. Based on the specific values of an asset across these two dimensions, the corresponding cell in the matrix is located, automatically generating disposal recommendations for end-of-life assets. This ensures that assets with high business impact are given high priority even with slight declines in health, while less important assets are only replaced when their health deteriorates significantly. The disposal recommendations are specific and actionable instructions generated based on the joint risk assessment results, moving beyond simple technical judgments to a comprehensive decision incorporating business impact. For example, if the joint risk score is greater than 7.5, immediate retirement or replacement of the equipment is recommended to avoid production disruptions or safety issues; if the joint risk score is between 4 and 7.5, regular maintenance or enhanced monitoring of the equipment is recommended, with continued use until a more suitable retirement time; if the joint risk score is below 4, the equipment can continue operating, or minor maintenance is recommended. For example, suppose there is a device A in the industrial control system. Calculate the joint risk score: Device A has a terminal health index of 8.5 / 10 and a business importance index of 0.9 / 1. The weighting coefficients are 0.6 for the terminal health index and 0.4 for the business importance index. Then the joint risk score is 5.46, and it is recommended to carry out regular maintenance or strengthen monitoring of device A.
[0074] By jointly analyzing equipment health status and business importance, a comprehensive risk assessment is provided, effectively avoiding misjudgments caused by a single indicator and helping managers make more informed decisions when equipment is nearing retirement. Through proper assessment and management of equipment lifecycle status, it ensures that equipment is replaced or maintained at the appropriate time, avoiding resource waste and improving the operational efficiency of industrial control systems.
[0075] Furthermore, this application also includes the following steps: performing early warning matching based on the situation prediction results to establish an early warning signal; and using the early warning signal for visual early warning management.
[0076] Specifically, early warning matching is performed based on situational prediction results, which involves comparing the predicted results with pre-set early warning thresholds. These thresholds are typically based on historical equipment data, industry standards, or operator experience, defining warning lines for certain risk levels. For example, a health index drop exceeding 20% might trigger an alarm, or an alarm might be issued when the equipment's failure risk increases by more than 50%. Once data meeting the early warning criteria is detected, a pre-alarm signal is triggered, generating corresponding alarm information. The pre-alarm signal contains key information such as equipment ID, warning type, warning level, alarm time, and recommended actions.
[0077] Visualizing warning signals helps managers intuitively understand equipment status and potential risks. Common visualization methods include alarm panels, heatmaps, charts, and trend lines. Alarm panels display all triggered warning information, indicating the equipment, warning level, scope of impact, and recommended actions. Color coding, such as red for high risk, yellow for medium risk, and green for normal, allows users to quickly identify the most urgent risks. Trend charts display the health status of equipment and risk trends, helping managers predict potential future problems. Dashboards comprehensively display the real-time health status of the system, tracking equipment operating status and warning signals for timely intervention.
[0078] Through a visually appealing alert management interface, operators and managers can quickly identify which devices are malfunctioning and decide whether to take immediate action based on the alert level. Specifically, assets in different alert states are highlighted in different colors on the topology map; all alerts are displayed in detail in a list format, supporting filtering by level, asset type, time, etc.; based on the alert level, alarm information is automatically pushed via in-site messages, emails, SMS, instant messaging tools, and even voice calls; a handling work order is generated for each alert, clearly defining the responsible person, the handling deadline, and tracking the handling status until the alert is cleared after resolution, forming a closed management loop.
[0079] By predicting the situation and matching early warnings, potential equipment failures and performance degradation issues can be detected in advance, preventing sudden equipment downtime or major malfunctions. Through tiered early warning systems, operational resources can be allocated rationally. Emergency events receive immediate attention, important events are handled in a planned manner, and general events are resolved systematically, thereby improving the overall efficiency and responsiveness of the operations and maintenance team.
[0080] In summary, the situational awareness-based industrial control asset lifecycle status management method provided in this application has the following technical effects: By performing parallel collection of active probing and passive monitoring using a preset scanning cycle, the active and passive result vectors are used to construct an asset candidate vector set with adaptive weights. This asset candidate vector set is then compared item by item with a pre-built industrial control fingerprint database to establish a primary identity vector for each candidate asset. A graph structure is established based on the primary identity vectors and network topology, where nodes represent assets and edges represent sessions or link interactions. Consistency confidence is calculated for each node based on node characteristics and neighbor aggregation information. A trusted asset list is constructed based on the consistency confidence calculation results and fingerprint comparison scores. Risk indicators for each asset are continuously collected based on the trusted asset list, including operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results. Situational prediction is performed under a sliding window based on the asset risk score. After identifying the trusted asset list using the situational prediction results, full lifecycle status management is implemented. In other words, by combining active detection and passive monitoring, a dynamic and accurate asset management system is constructed. Based on graph-structured network topology modeling, a trusted asset list is built using consistency confidence and fingerprint comparison results. Risk indicators of various assets are continuously collected to assess the risk level of each asset. Full lifecycle status management is carried out through situation prediction under a sliding window, which effectively improves the accuracy and security of industrial control asset management.
[0081] Example 2: Based on the same inventive concept as the situational awareness-based industrial control asset lifecycle status management method in Example 1, this application also provides a situational awareness-based industrial control asset lifecycle status management system. Please refer to the appendix. Figure 2 The situational awareness-based industrial control asset lifecycle status management system includes: The asset scanning module 11 performs parallel collection of active detection and passive monitoring using a preset scanning cycle, constructing an asset candidate vector set by adaptively weighting the active and passive result vectors; the information comparison module 12 compares the asset candidate vector set with a pre-built industrial control fingerprint database item by item to establish a primary identity vector for each candidate asset; the graph structure construction module 13 constructs a graph structure based on the primary identity vector and network topology, where nodes represent assets and edges represent sessions or link interactions, and calculates the consistency confidence of each node based on node features and neighbor aggregation information; the trusted list construction module 14 constructs a trusted asset list based on the consistency confidence calculation results and fingerprint comparison scores; the risk collection module 15 continuously collects risk indicators for each asset based on the trusted asset list, including operational health indicators, vulnerability exposure index, and compliance index, and establishes an asset risk score based on the continuous collection results; the situation prediction module 16 performs situation prediction under a sliding window based on the asset risk score, identifies the trusted asset list using the situation prediction results, and performs full lifecycle status management.
[0082] Furthermore, the asset scanning module 11 in the situational awareness-based industrial control asset lifecycle status management system is also used for: the active detection includes real-time port or protocol detection of each address segment in the industrial control network according to the hierarchical topology, and obtaining port response fingerprints, service banners, and handshake time characteristics; the passive listening includes continuous listening to LAN broadcasts and APP exchanges, and extracting source MAC, destination MAC, message templates, and time-series interaction events.
[0083] Furthermore, the information comparison module 12 in the situational awareness-based industrial control asset lifecycle status management system is also used for: the industrial control fingerprint database includes MAC-OUI, protocol feature templates, device signal signatures, firmware byte signatures, and a known service port matching table.
[0084] Furthermore, the graph structure construction module 13 in the situational awareness-based industrial control asset lifecycle status management system is also used to: determine the neighboring nodes of a node according to the graph structure and create a message passing matrix; perform weighted aggregation of neighbor information within the message passing matrix according to the risk relevance, fingerprint matching confidence and topological weight of the neighboring nodes to establish a local aggregation vector; and use the local aggregation vector to perform interactive consistency authentication of node features to complete the consistency confidence calculation.
[0085] Furthermore, the situation prediction module 16 in the situation awareness-based industrial control asset lifecycle status management system is also used for: constructing a multidimensional risk time series tensor based on the asset risk score within each sliding window period, wherein the multidimensional risk time series tensor includes the asset risk score, risk fluctuation rate, risk correlation, and risk propagation coefficient of adjacent assets; inputting the multidimensional risk time series tensor into a multi-layer temporal convolutional network to perform cross-window situation evolution modeling, and outputting prediction results including trend vectors and mutation vectors; calculating the situation change potential energy based on the prediction results, and using the situation change potential energy to complete situation prediction.
[0086] Furthermore, the situation prediction module 16 in the situation awareness-based industrial control asset lifecycle status management system is also used for: identifying the end-of-lifecycle trigger of an asset based on the situation prediction result, and establishing a trigger identification result; using the trigger identification result to identify the corresponding asset as an end-of-life asset, and determining the end-of-life window range based on the trend vector in the situation prediction result, and activating an enhanced monitoring mode within the end-of-life window range; using the enhanced monitoring mode to perform multi-source data acquisition, and establishing a multi-source dataset; performing behavior drift analysis on the multi-source dataset, inputting the analysis results into the lifecycle end-of-life determination network, performing degradation rate fitting and abnormal morphology identification, establishing an end-of-life health index, and performing lifecycle status management based on the end-of-life health index.
[0087] Furthermore, the situation prediction module 16 in the situation awareness-based industrial control asset lifecycle status management system is also used for: acquiring the operation instruction sequence in the multi-source dataset, performing time-series encoding on the historical instruction stream and the operation instruction sequence of the current period, and establishing an instruction embedding matrix; in the instruction embedding matrix, performing time-series offset analysis based on the instruction pattern vector of the current period and the historical stable pattern vector, and establishing a time-series matching offset rate; calculating the logical drift coefficient using the time-series matching offset rate, and establishing a first row of drift; acquiring the asset communication round-trip time series in the multi-source dataset, acquiring the delay drift index based on the asset communication round-trip time series, and establishing a second row of drift based on the delay drift index; acquiring power sample data in the multi-source dataset, performing multi-scale wavelet decomposition based on the power sample data, and establishing high-frequency fluctuation components and low-frequency trends; calculating the ratio of high-frequency fluctuation components to low-frequency trends, establishing an energy consumption fluctuation rate, and using the energy consumption fluctuation rate, high-frequency fluctuation components, and low-frequency trends to detect energy consumption fluctuations, and establishing a third row of drift; and completing behavior drift analysis based on the first row of drift, the second row of drift, and the third row of drift.
[0088] Furthermore, the situation prediction module 16 in the situation awareness-based industrial control asset lifecycle status management system is also used to: obtain the business importance index of the end-stage asset; conduct a joint risk assessment based on the business importance index and the end-stage health index, and generate disposal recommendations for the end-stage asset.
[0089] Furthermore, the situation prediction module 16 in the situation awareness-based industrial control asset lifecycle status management system is also used for: performing early warning matching based on the situation prediction results, establishing early warning signal issuance signals; and using the early warning signal issuance signals for visualized early warning issuance management.
[0090] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Figure 1 The situational awareness-based industrial control asset lifecycle status management method and specific examples in Example 1 are also applicable to the situational awareness-based industrial control asset lifecycle status management system in this example. Through the foregoing detailed description of the situational awareness-based industrial control asset lifecycle status management method, those skilled in the art can clearly understand the situational awareness-based industrial control asset lifecycle status management system in this example. Therefore, for the sake of brevity, it will not be described in detail here.
[0091] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0092] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for full lifecycle status management of industrial control assets based on situational awareness, characterized in that, include: The system performs parallel acquisition of active detection and passive listening using a preset scanning cycle, and constructs an asset candidate vector set by adaptively weighting the active result vector and the passive result vector. The asset candidate vector set is compared item by item with the pre-built industrial control fingerprint database to establish a primary identity vector for each candidate asset. A graph structure is established based on the primary identity vector and network topology. The nodes of the graph structure represent assets, and the edges represent sessions or link interactions. The consistency confidence of each node is calculated based on node characteristics and neighbor aggregation information. A list of trusted assets is constructed based on the consistency confidence score calculation results and fingerprint comparison scores. Based on the trusted asset list, risk indicators for each asset are continuously collected. These risk indicators include operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results. Based on the asset risk score, a situation prediction is performed under a sliding window. After the situation prediction results are used to identify the trustworthy asset list, full lifecycle status management is performed.
2. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 1, characterized in that, Situational prediction under a sliding window based on the asset risk score includes: Within each sliding window period, a multidimensional risk time series tensor is constructed based on the asset risk score. The multidimensional risk time series tensor includes the asset risk score, risk volatility rate, risk correlation, and risk propagation coefficient of adjacent assets. The multidimensional risk temporal tensor is input into a multi-layer temporal convolutional network to perform cross-window situation evolution modeling and output prediction results containing trend vectors and mutation vectors. The potential energy of the situation change is calculated based on the prediction results, and the situation prediction is completed using the potential energy of the situation change.
3. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 2, characterized in that, After identifying the trusted asset list using situation prediction results, full lifecycle status management is performed, including: Based on the situation prediction results, identify the end-of-life triggers of assets and establish trigger identification results; The corresponding asset is identified as a terminal asset using the trigger identification result, and the terminal window range is determined according to the trend vector in the situation prediction result. The enhanced monitoring mode is then activated within the terminal window range. The enhanced monitoring mode is used to perform multi-source data acquisition and establish a multi-source dataset; Behavioral drift analysis is performed on the multi-source dataset, and the analysis results are input into the life cycle end-of-life determination network to perform degradation rate fitting and abnormal morphology recognition, establish a life cycle health index, and manage life cycle status based on the life cycle health index.
4. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 3, characterized in that, Life cycle status management based on the aforementioned end-stage health index includes: Obtain business importance metrics for end-stage assets; A joint risk assessment is conducted based on the aforementioned business importance indicators and the aforementioned end-stage health index to generate disposal recommendations for end-stage assets.
5. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 3, characterized in that, Behavioral drift analysis is performed on the multi-source dataset, including: Obtain the operation instruction sequence from the multi-source dataset, perform timing encoding on the historical instruction stream and the current cycle's operation instruction sequence, and establish an instruction embedding matrix; In the instruction embedding matrix, a time-series offset analysis is performed based on the instruction pattern vector of the current cycle and the historical stable pattern vector to establish a time-series matching offset rate; Calculate the logic drift coefficient using the timing matching offset rate, and establish the first row as the drift amount; Obtain the round-trip time series of asset communication from the multi-source dataset, obtain the delay drift index based on the asset communication round-trip time series, and establish the second row as the drift amount based on the delay drift index; Obtain power sample data from a multi-source dataset, perform multi-scale wavelet decomposition based on the power sample data, and establish high-frequency fluctuation components and low-frequency trends. Calculate the ratio of high-frequency fluctuation component to low-frequency trend to establish energy consumption fluctuation rate. Use the energy consumption fluctuation rate, high-frequency fluctuation component and low-frequency trend to detect energy consumption fluctuation amount and establish the third row as drift amount. Behavioral drift analysis is completed based on the drift amount of the first, second, and third rows.
6. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 1, characterized in that, The consistency confidence score for each node is calculated based on node characteristics and neighbor aggregation information, including: The adjacent nodes of a node are determined based on the graph structure, and a message passing matrix is created. Based on the risk relevance of adjacent nodes, fingerprint matching confidence, and topological weight, the neighbor information is weighted and aggregated within the message passing matrix to establish a local aggregation vector; The local aggregation vector is used to perform interactive consistency authentication on node features to complete the consistency confidence calculation.
7. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 1, characterized in that, The active detection includes real-time port or protocol detection of each address segment in the industrial control network according to the hierarchical topology, and obtaining port response fingerprints, service banners, and handshake time characteristics. The passive monitoring includes continuous monitoring of local area network broadcasts and APP exchanges, and extracting source MAC, destination MAC, message templates, and time-series interaction events.
8. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 1, characterized in that, The industrial control fingerprint database includes MAC-OUI, protocol feature templates, device signal signatures, firmware byte signatures, and a known service port matching table.
9. The method for full lifecycle status management of industrial control assets based on situational awareness as described in claim 1, characterized in that, After identifying the trusted asset list using situation prediction results, full lifecycle status management is performed, including: Based on the situation prediction results, early warning matching is performed, and an early warning issuance signal is established. Visualized early warning management is achieved using the aforementioned early warning signal.
10. A situational awareness-based industrial control asset lifecycle status management system, characterized in that, The steps for implementing the situation-aware-based industrial control asset lifecycle status management method according to any one of claims 1 to 9, wherein the situation-aware-based industrial control asset lifecycle status management system includes: The asset scanning module is used to perform parallel acquisition of active detection and passive listening using a preset scanning cycle, and construct an asset candidate vector set by adaptively weighting the active result vector and the passive result vector. The information comparison module is used to compare the asset candidate vector set with the pre-built industrial control fingerprint database item by item to establish the primary identity vector of each candidate asset. The graph structure construction module is used to build a graph structure based on the primary identity vector and network topology. The nodes of the graph structure represent assets, and the edges represent sessions or link interactions. The consistency confidence of each node is calculated based on node features and neighbor aggregation information. The trusted list construction module is used to construct a trusted asset list based on the consistency confidence calculation results and fingerprint comparison scores; The risk collection module is used to continuously collect risk indicators for each asset based on the trusted asset list. The risk indicators include operational health indicators, vulnerability exposure index, and compliance index. An asset risk score is established based on the continuous collection results. The situation prediction module is used to perform situation prediction under a sliding window based on the asset risk score. After identifying the trustworthy asset list using the situation prediction results, it performs full lifecycle status management.