An autonomously controllable ship lock industrial control network security protection system and method

CN121690665BActive Publication Date: 2026-09-08南通市港航事业发展中心 +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511694855.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-18
Publication Date
2026-09-08
Estimated Expiration
2045-11-18

AI Technical Summary

Technical Problem

[0004]然而,上述技术虽然能够实现工业控制网络的安全防护,但网络安全防护机制主要集中于静态的特征归类与策略匹配,缺乏对工控设备实际运行状态或动态异常行为的感知与分析能力,难以及时发现源于控制层或网络层的实时异常;并且,上述方法侧重于网络连接权限与安全验证策略的配置,缺乏对异常事件发生后的传播路径分析、溯源机制与响应决策过程的设计,难以形成有效的安全事件处置闭环

Benefits of technology

通过构建设备行为基线模型并实时监测各控制设备的运行参数,能够全面感知船闸控制系统的运行状态,及时准确地发现设备异常行为,为后续的异常分析提供可靠依据;采用预建的设备网络关联模型,对比异常设备和网络异常的时序特征以及模式特征,可以准确判断设备异常是否源于网络攻击或通信故障,确保事故原因的准确定位;基于网络通信依赖分析,能够深入溯源网络异常引发的设备异常,精准定位异常来源和影响范围,为采取针对性的防护措施奠定基础;结合预先建立的安全运维知识库,动态生成包括紧急缓解措施和短期修复方案在内的分层次响应策略,既能快速遏制安全事故,又能有效修复系统并排查隐患,大幅提升船闸工业控制网络的自动化防护和自愈能力;实现对船闸工业控制网络安全状况的全方位感知和自主防控,形成有效的安全事件处置闭环,具有显著的安全性、可靠性和自适应性,对保障关键基础设施的稳定运行具有重要意义。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690665B_ABST
    Figure CN121690665B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of industrial control network security, and discloses an autonomously controllable ship lock industrial control network security protection system and method; comprising: constructing a behavior baseline model, and collecting device operation parameters in real time to comprehensively monitor each ship lock control device for abnormalities and identify abnormal control devices; acquiring network abnormal conditions, and comparing the network abnormal conditions and the abnormal control devices in multiple levels to determine whether the abnormal reasons of the abnormal control devices originate from the network abnormality; constructing a network communication dependency graph to determine the abnormal source and influence range of the abnormal control devices caused by the network abnormality; and based on a pre-established security operation knowledge base and in combination with the abnormal source and influence range, dynamically generating a hierarchical response strategy; the application realizes all-around perception and autonomous prevention and control of the security situation of the ship lock industrial control network, forms an effective security event disposal closed loop, and has remarkable security, reliability and self-adaptability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control network security technology, and more specifically, to an autonomous and controllable industrial control network security protection system and method for ship locks. Background Technology

[0002] With the deep integration of information technology and industrial control systems, ship locks, as an important component of water transport hubs, increasingly rely on automated control systems, sensor networks, and remote communication technologies for their operation. Ship lock control systems typically include programmable logic controllers (PLCs), human-machine interfaces (HMIs), industrial switches, and remote terminal equipment, forming a typical industrial control network. However, current industrial control networks generally suffer from the following security vulnerabilities: due to the extensive use of proprietary protocols and closed architectures, it is difficult to detect and prevent network attacks in a timely manner; once an industrial control system is intruded upon or damaged, it can easily lead to equipment malfunction, waterway blockage, or even accidents; especially in critical infrastructure such as ship locks, network attacks can cause control logic to be tampered with and system paralysis to occur, seriously threatening national water transport security. Therefore, there is an urgent need for an intelligent industrial control network security protection system to achieve intelligent identification, rapid response, and traceability of network security incidents.

[0003] Patent CN114019933B discloses a network security control method and device for an industrial control system. The method includes: receiving network connection requests from multiple first industrial control terminals and their corresponding functional characteristic parameters; establishing a virtual protection network based on the functional characteristic parameters and determining the node terminals within the virtual protection network; sending protection policies to the node terminals and initiating network connections between the industrial control server and the node terminals, as well as network connections between the node terminals and second industrial control terminals within the virtual protection network. This invention groups industrial control terminals with the same or similar functional characteristic parameters into the same virtual protection network and uses a unified security verification standard to perform security verification on the message data within the virtual protection network, avoiding inappropriate network security protection for the industrial control terminals and improving network security protection efficiency.

[0004] However, while the aforementioned technologies can achieve security protection for industrial control networks, the network security protection mechanisms mainly focus on static feature classification and policy matching, lacking the ability to perceive and analyze the actual operating status or dynamic abnormal behavior of industrial control equipment, making it difficult to detect real-time anomalies originating from the control layer or network layer in a timely manner. Furthermore, the aforementioned methods emphasize the configuration of network connection permissions and security verification policies, lacking the design of propagation path analysis, source tracing mechanisms, and response decision-making processes after abnormal events occur, making it difficult to form an effective closed loop for security incident handling.

[0005] In view of this, the present invention proposes an autonomous and controllable network security protection system and method for the industrial control of ship locks to solve the above problems. Summary of the Invention

[0006] To overcome the aforementioned deficiencies of the prior art and achieve the above objectives, the present invention provides the following technical solution: a self-controllable network security protection method for ship lock industrial control systems, comprising: A corresponding behavioral baseline model is constructed for each lock control device, and the equipment operation parameters of each lock control device are collected in real time. Based on the behavioral baseline model and the equipment operation parameters, comprehensive anomaly monitoring is carried out on each lock control device to identify abnormal control devices. The system acquires network anomalies and uses a pre-built device network association model to perform multi-level feature comparison between network anomalies and anomaly control devices. By comparing the temporal correlation and pattern consistency between the anomaly control devices and network anomalies, it determines whether the anomaly of the anomaly control devices originates from network anomalies. Construct a network communication dependency graph, and based on the network communication dependency graph, conduct in-depth source tracing analysis and propagation path prediction of the anomaly control equipment caused by network anomalies, and determine the source and scope of impact of the anomalies; Based on a pre-established security operations and maintenance knowledge base, and combined with the source and scope of the anomaly, a hierarchical response strategy is dynamically generated. The hierarchical response strategy includes emergency mitigation measures and short-term repair solutions.

[0007] Furthermore, methods for identifying abnormal control devices include: Each behavior baseline model includes the average value and standard deviation of each device's operating parameter. A preset threshold multiple is used to calculate the product of each standard deviation and the threshold multiple in each normal behavior baseline model, obtaining the deviation tolerance. Based on the average value and deviation tolerance of each normal behavior model, the interval threshold for each device's operating parameter for each lock control device is calculated, and the corresponding fluctuation interval is constructed. Each device's operating parameter for each lock control device is compared with its corresponding fluctuation interval. Lock control devices with operating parameters exceeding the corresponding fluctuation interval are marked as abnormal control devices, while lock control devices with all operating parameters within the fluctuation interval are not marked.

[0008] Furthermore, the device network association model includes historical latency relationships and historical pattern relationships. The historical latency relationship includes the time interval between the network anomaly time and the device anomaly time when the cause of the abnormal control device's anomaly in a historical moment was a network anomaly. The network anomaly time is the time corresponding to the acquisition of the network anomaly situation, and the device anomaly time is the time corresponding to the identification of the abnormal control device. The historical pattern relationship includes the pattern combination when the cause of the abnormal control device's anomaly in a historical moment was a network anomaly. The pattern combination includes the abnormal pattern of the abnormal control device and the abnormal pattern of the network anomaly situation. Methods for determining whether a malfunction in a control device stems from a network anomaly include: If there is both temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be the network anomaly; if there is no simultaneous temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be the network anomaly. Methods for comparing the time-series correlation between abnormal control devices and network anomalies include: The system acquires real-time device time and real-time network time. Real-time device time refers to the time of device anomalies acquired in real time, and real-time network time refers to the time of network anomalies acquired in real time. A unified time protocol is used to align the real-time device time and real-time network time. Historical latency relationships are obtained based on the device-network correlation model, and all time intervals in the historical latency relationships are averaged to obtain the average interval. A tolerance coefficient is preset, and a time window is constructed starting from the real-time device time and extending forward based on the average time and the tolerance coefficient. The length of the time window is the sum of the average time and the tolerance coefficient. The real-time network time and the time window are analyzed. If the real-time network time is within the time window, there is a temporal correlation between the anomaly control device and the network anomaly; if the real-time network time is outside the time window, there is no temporal correlation between the anomaly control device and the network anomaly.

[0009] Furthermore, methods for comparing the consistency of patterns between abnormal control devices and network anomalies include: Acquire historical feature data, which includes historical device data and historical network data. Historical device data is device feature data obtained from abnormal control devices at historical moments, and historical network data is network feature data obtained from network anomalies at historical moments. K-means clustering algorithm was used to cluster historical device data and historical network data respectively, dividing the historical device data into... Each device mode category categorizes historical network data into Network mode categories, and All values ​​are integers greater than 1; For each device mode category and network mode category, a corresponding abnormal mode is set; real-time feature data is obtained, including real-time device data and real-time network data. Real-time device data is device feature data obtained in real time from the abnormal control device, and real-time network data is network feature data obtained in real time from network abnormal situations; the similarity between real-time device data and each device mode category is calculated, and the abnormal mode corresponding to the device mode category with the highest similarity is taken as the real-time device mode corresponding to the real-time device data; the similarity between real-time network data and each network mode category is calculated, and the abnormal mode corresponding to the network mode category with the highest similarity is taken as the real-time network mode corresponding to the real-time network data. The real-time device mode and the real-time network mode are combined to generate a real-time combination. Historical mode relationships are obtained based on the device-network association model, and the real-time ratio is obtained based on the historical mode relationships. The real-time ratio is the ratio between the number of times the real-time combination appears in the historical mode relationships and the total number of times all mode combinations appear in the historical mode relationships. A preset ratio threshold is set, and the real-time ratio is compared with the ratio threshold. If the real-time ratio is greater than or equal to the ratio threshold, there is mode consistency between the abnormal control device and the network abnormality. If the real-time ratio is less than the ratio threshold, there is no mode consistency between the abnormal control device and the network abnormality.

[0010] Furthermore, methods for constructing network communication dependency graphs include: Obtain network communication records, which include communication metrics between various devices; these metrics include source IP address, destination IP address, number of data packets, and communication frequency. All devices in the communication records are treated as nodes. Directed edges are established between nodes that communicate, based on the source and destination IP addresses in the records. The direction of the directed edges points from the initiating device to the receiving device. Two nodes with a directed edge are grouped into a node set. Communication feature data, including the number of data packets and communication frequency, is obtained for each node set based on the communication records. The communication feature data for each node set is standardized to obtain standard communication data. A pre-defined ratio set is used, containing proportional coefficients corresponding to the number of data packets and communication frequency. The communication feature data for each node set is weighted and summed according to the ratio set to obtain the communication weight for each node set, which is then used as the communication weight for the corresponding directed edge. A network communication dependency graph is constructed based on the nodes, directed edges, and communication weights.

[0011] Furthermore, the steps to determine the source of the anomaly include: Step S101: Mark the abnormal control device caused by the network abnormality as a network abnormal device, and mark the node corresponding to the network abnormal device as the current node; Step S102: From the network communication dependency graph, obtain the communication weights corresponding to all directed edges pointing to the current node, and mark them as the current weights; Step S103: Obtain the standard network communication dependency graph and mark all communication weights in the standard network communication dependency graph as standard weights; Step S104: Subtract the corresponding standard weight from each current weight and take the absolute value to obtain the weight variable; Step S105: Compare each weight variable with a preset variable threshold, mark the directed edges whose weight variables are greater than the variable threshold as candidate edges, and do not mark the directed edges whose weight variables are less than or equal to the variable threshold. Step S106: If there is a candidate edge in step S105, proceed to step S107; if there is no candidate edge in step S105, proceed to step S108. Step S107: Compare the weight variables of all candidate edges, mark the candidate edge with the largest weight variable as the source edge, update the current node to the node connected to the current node through the source edge, and return to step S102; Step S108: Designate the device corresponding to the current node as the source of the anomaly.

[0012] Furthermore, the steps to determine the scope of impact include: Step S201: Set corresponding numerical labels for all nodes in the network communication dependency graph and mark them as node labels; use all node labels that are marked as the node corresponding to the current node as a node label set; use all weight variables corresponding to the source edges as a variable set, and use the variable set and the node label set as an influence set; Step S202: Mark the node corresponding to the network malfunctioning device as the current node; Step S203: From the network communication dependency graph, obtain all directed edges originating from the current node and mark them as current edges; obtain the node pointed to by each current edge and mark it as the target node; combine the communication weight corresponding to each current edge, the node label of the corresponding target node, and the influence set as a prediction set. Step S204: Input each set of predictions into the trained variable prediction model to predict the weight variable corresponding to each current edge and mark it as the prediction variable. The variable prediction model is a deep neural network model. Step S205: Compare each predicted variable with the variable threshold, mark the current edge where the predicted variable is greater than the variable threshold as an influencing edge, and do not mark the current edge where the weight variable is less than or equal to the variable threshold. Step S206: If there is an influencing edge in step S205, proceed to step S207; if there is no influencing edge in step S205, proceed to step S208. Step S207: Add all predicted variables and node labels of the target nodes corresponding to all affected edges to the affected set, and take all target nodes corresponding to all affected edges as the current nodes, then return to step S203. Step S208: Use the affected set as the scope of influence.

[0013] Furthermore, the security operations and maintenance knowledge base includes emergency mitigation measures and short-term repair plans corresponding to different anomaly levels, including severe anomalies, high-level anomalies, medium-level anomalies, and low-level anomalies. Methods for dynamically generating hierarchical response strategies include: The number of node tags within the affected area is counted and used as the impact quantity; based on all weighted variables and the impact quantity within the affected area, the anomaly level is determined; based on the anomaly level, corresponding emergency mitigation measures and short-term remediation plans are selected from the security operations and maintenance knowledge base; the selected emergency mitigation measures are combined to obtain... Group measures combination; combining the selected short-term remediation plans to obtain Group scheme combination, and All are integers greater than 1; Group measures combination and Group the schemes and then combine them again to obtain Group strategy combination; Different numerical labels are assigned to different emergency mitigation measures and short-term repair solutions, and these labels are marked as strategy labels. The emergency mitigation measures and short-term repair solutions in each strategy combination are replaced with the corresponding strategy labels. Each strategy combination is input into a trained effect prediction model to predict the corresponding security protection effect. The effect prediction model is a deep neural network model. The security protection effects of each strategy combination are compared, and the strategy combination with the highest security protection effect is taken as the hierarchical response strategy.

[0014] Furthermore, the steps for determining the anomaly level include: Step S301: Calculate the mean and variance of all weighted variables within the scope of influence to obtain the variable mean and variable variance; Step S302: Construct multiple fuzzy sets for the quantity of influence, the mean of the variable, and the variance of the variable, respectively; Step S303: Convert the quantity of influence, the mean of the variable, and the variance of the variable into the membership degree of each corresponding fuzzy set using fuzzification technology; Step S304: Define fuzzy rules; Step S305: Match the fuzzy influence quantity, variable mean, and variable variance with the fuzzy rules respectively, and use the fuzzy inference method to perform fuzzy inference to obtain the fuzzy inference result, which is the membership degree of each anomaly level; Step S306: Compare the membership degree of each anomaly level and obtain the anomaly level with the highest membership degree.

[0015] A self-controllable network security protection system for the industrial control of ship locks, implementing the aforementioned self-controllable network security protection method for the industrial control of ship locks, includes: The equipment monitoring module is used to build corresponding behavioral baseline models for each lock control device and collect the equipment operation parameters of each lock control device in real time. Based on the behavioral baseline models and equipment operation parameters, it performs comprehensive anomaly monitoring on each lock control device and identifies abnormal control devices. The anomaly detection module is used to obtain network anomalies and use a pre-built device network association model to perform multi-level feature comparison between network anomalies and anomaly control devices. By comparing the temporal correlation and pattern consistency between the anomaly control devices and network anomalies, it determines whether the anomaly of the anomaly control devices originates from network anomalies. The anomaly tracing module is used to construct a network communication dependency graph. Based on the network communication dependency graph, it performs in-depth source tracing analysis and propagation path prediction on the anomaly control devices caused by network anomalies, and determines the source and scope of impact of the anomalies. The operations and maintenance response module is used to dynamically generate tiered response strategies based on a pre-established security operations and maintenance knowledge base and in combination with the source and scope of the anomaly. The tiered response strategies include emergency mitigation measures and short-term repair solutions.

[0016] The technical effects and advantages of this invention, a self-controllable industrial control network security protection system and method for ship locks, are as follows: By constructing a baseline model of equipment behavior and monitoring the operating parameters of each control device in real time, the operating status of the lock control system can be comprehensively perceived, and abnormal equipment behavior can be detected in a timely and accurate manner, providing a reliable basis for subsequent anomaly analysis. By using a pre-built equipment network association model and comparing the temporal and pattern characteristics of abnormal equipment and network anomalies, it is possible to accurately determine whether the equipment anomaly originates from a network attack or communication failure, ensuring accurate location of the cause of the incident. Based on network communication dependency analysis, it is possible to deeply trace the equipment anomalies caused by network anomalies, accurately locate the source and scope of the anomalies, and lay the foundation for taking targeted protective measures. Combined with a pre-established security operation and maintenance knowledge base, a hierarchical response strategy, including emergency mitigation measures and short-term repair solutions, can be dynamically generated. This can not only quickly contain security incidents but also effectively repair the system and investigate hidden dangers, significantly improving the automated protection and self-healing capabilities of the lock industrial control network. It achieves comprehensive perception and autonomous control of the network security status of the lock industrial control network, forming an effective closed loop for security incident handling. It has significant security, reliability, and adaptability, which is of great significance for ensuring the stable operation of critical infrastructure. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of an autonomous and controllable ship lock industrial control network security protection system according to Embodiment 1 of the present invention; Figure 2 This is a flowchart of a self-controllable and controllable network security protection method for industrial control of ship locks, according to Embodiment 2 of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example 1 Please see Figure 1 As shown in this embodiment, an autonomous and controllable industrial control network security protection system for ship locks includes an equipment monitoring module, an anomaly determination module, an anomaly tracing module, and an operation and maintenance response module. The modules are connected via wired and / or wireless means to realize data transmission between the modules.

[0020] The equipment monitoring module is used to build corresponding behavioral baseline models for each lock control device and collect the equipment operation parameters of each lock control device in real time. Based on the behavioral baseline models and equipment operation parameters, it performs comprehensive anomaly monitoring on each lock control device and identifies abnormal control devices.

[0021] Lock control equipment refers to automated execution equipment involved in the opening and closing of locks and water level regulation, including but not limited to electric hoists, hydraulic cylinders, and valves. A behavioral baseline model refers to modeling the patterns of the operating parameters of each lock control device under normal and abnormal conditions, forming a standard reference model reflecting the normal operating characteristics of the lock control equipment. Equipment operating parameters are various technical indicators reflecting the working status of the lock control equipment, such as current, voltage, and temperature for electric hoists, hydraulic oil pressure and piston movement speed for hydraulic cylinders, and opening degree and flow rate for valves. These operating parameters are collected by various sensors installed on each lock control device, such as current sensors and temperature sensors installed inside electric hoists, pressure sensors installed on hydraulic system pipelines, and angle sensors and flow meters installed on valves. Each behavioral baseline model includes the mean value and standard deviation of each device's operating parameter. The mean value is the average value of the corresponding device's operating parameter under historical normal conditions, and the standard deviation is the degree of dispersion of the corresponding device's operating parameter under historical normal conditions. The behavioral baseline models are all established by those skilled in the art by collecting the device operating parameters of different lock control devices at different times under historical normal conditions and performing statistical analysis and calculation.

[0022] Methods for identifying abnormal control devices include: A preset threshold multiple is used, which is set by those skilled in the art based on actual conditions, typically 2 or 3. The product of each standard deviation in each normal behavior baseline model and the threshold multiple is calculated to obtain the deviation tolerance. Based on the average value and deviation tolerance corresponding to each normal behavior model, the interval threshold for each operating parameter of each lock control device is calculated, and the corresponding fluctuation interval is constructed. The interval threshold includes an upper threshold and a lower threshold; the upper threshold is the sum of the average value and the deviation tolerance, and the lower threshold is the difference between the average value and the deviation tolerance. Each operating parameter of each lock control device is compared with its corresponding fluctuation interval. Lock control devices whose operating parameters exceed the corresponding fluctuation interval are marked as abnormal control devices, while lock control devices whose operating parameters are all within the fluctuation interval are not marked.

[0023] The anomaly detection module is used to acquire network anomalies and use a pre-built device network association model to perform multi-level feature comparison between network anomalies and anomaly control devices. By comparing the temporal correlation and pattern consistency between the anomaly control devices and network anomalies, it determines whether the anomaly of the anomaly control devices originates from network anomalies.

[0024] Network anomalies refer to various abnormal phenomena in the industrial control network of a ship lock that are caused by network attacks or potential malicious acts and affect the stability and real-time performance of equipment communication. Network anomalies typically interfere with data interaction between the ship lock control equipment and the host computer, control center, or other equipment, leading to the tampering, interruption, or delay of control commands. This can cause equipment malfunctions, response failures, abnormal lock operation, and other problems, resulting in shipping delays, economic losses, and even safety risks to personnel and vessels. Network anomalies include, but are not limited to, distributed denial-of-service attacks (causing network congestion and equipment communication interruptions), man-in-the-middle attacks or ARP spoofing and other data hijacking behaviors (causing abnormal equipment status or incorrect control), malicious data injection or command tampering (causing equipment malfunctions), and brute-force attacks (damaging communication links or obtaining unauthorized access rights). Network anomalies are detected in real time through communication monitoring modules, security detection equipment (including intrusion detection systems, intrusion prevention systems, firewalls, security gateways, etc.) or edge nodes deployed in the lock industrial control network. By continuously analyzing network status data (i.e., various indicators related to network operation, such as network bandwidth usage, latency, jitter, packet loss rate, etc.), communication behavior logs (i.e., detailed records of historical communication between lock control devices, such as command issuance and response timestamps, communication data content summaries, communication frequency and duration, etc.), and intrusion characteristics (i.e., abnormal patterns or data characteristics summarized based on known network attack methods, such as a large number of access requests from abnormal IPs or ports, repeated illegal login attempts, and the appearance of unauthorized protocols or commands in the industrial control network, etc.), accurate perception and rapid response to communication anomalies caused by various security threats can be achieved.

[0025] The device network association model includes historical delay relationships and historical pattern relationships. Historical delay relationships include the time interval between the network anomaly time and the device anomaly time when the cause of the abnormal control device's anomaly stemmed from a network anomaly in a historical moment. The network anomaly time is the time corresponding to the acquisition of the network anomaly situation, and the device anomaly time is the time corresponding to the identification of the abnormal control device. Historical pattern relationships include combinations of patterns when the cause of the abnormal control device's anomaly stemmed from a network anomaly in a historical moment. These combinations include the abnormal patterns of the abnormal control device and the abnormal patterns of the network anomaly situation. An abnormal pattern refers to a structured pattern reflecting the characteristics of anomalies, formed by acquiring and combining anomaly-related characteristic data (such as indicator mutations, behavioral sequences, response delays, etc.) when an anomaly occurs in the network or device. This pattern describes the typical characteristic form of anomaly occurrence. Examples of abnormal patterns corresponding to abnormal control devices include control response failure, position control anomaly, and illegal operation response. Examples of abnormal patterns corresponding to network anomalies include denial-of-service attacks, ARP spoofing attacks, and data injection. The device network model is constructed by those skilled in the art based on the anomaly event log database built into the security event management system of the lock industrial control network, by acquiring historical delay relationships and historical pattern relationships.

[0026] Methods for comparing the temporal correlation between abnormal control devices and network anomalies include: The system acquires real-time device time and real-time network time. Real-time device time is the time of device anomaly acquired in real time, and real-time network time is the time of network anomaly acquired in real time. A unified time protocol (network time protocol or precise time protocol) is used to align the real-time device time and real-time network time. Based on the device network association model, the system obtains historical latency relationships and averages all time intervals in the historical latency relationships to obtain the average interval. A preset tolerance coefficient is established, which is pre-set by those skilled in the art based on actual conditions. Taking the real-time device time as the starting point, a time window is constructed by extending forward based on the average time and the tolerance coefficient. The length of the time window is the sum of the average time and the tolerance coefficient. The real-time network time and the time window are analyzed. If the real-time network time is within the time window, there is a temporal correlation between the abnormal control device and the network anomaly. If the real-time network time is outside the time window, there is no temporal correlation between the abnormal control device and the network anomaly.

[0027] Methods for comparing the consistency of patterns between abnormal control devices and network anomalies include: Historical feature data is acquired, including historical device data and historical network data. Historical device data consists of device feature data obtained from abnormal control devices at historical moments, while historical network data consists of network feature data obtained from network anomalies at historical moments. This historical feature data is also obtained through the built-in abnormal event log database in the security event management system of the lock industrial control network. Device feature data includes various key indicators and parameters reflecting abnormal behavior of lock control devices, such as device response time and abnormal parameters (i.e., the operating parameters of devices whose abnormal control devices exceed the corresponding fluctuation range). Network feature data includes indicators and behavioral characteristics reflecting the communication status and security situation of the lock industrial control network, such as the number of unauthorized access requests, abnormal login attempts, network bandwidth utilization, and packet loss rate. K-means clustering algorithm was used to cluster historical device data and historical network data respectively, dividing the historical device data into... Each device mode category categorizes historical network data into Network mode categories, and All values ​​are integers greater than 1; the K-means clustering algorithm is existing technology, and its specific process will not be elaborated here; those skilled in the art set corresponding abnormal modes for each device mode category and network mode category based on practical experience; real-time feature data is obtained, which includes real-time device data and real-time network data. Real-time device data is device feature data obtained in real time from abnormal control devices, and real-time network data is network feature data obtained in real time from network abnormal situations; the similarity between real-time device data and each device mode category is calculated, and the abnormal mode corresponding to the device mode category with the highest similarity is taken as the real-time device mode corresponding to the real-time device data; the similarity between real-time network data and each network mode category is calculated, and the abnormal mode corresponding to the network mode category with the highest similarity is taken as the real-time network mode corresponding to the real-time network data; The similarity between real-time device data and device pattern categories is calculated as follows: the Euclidean distance between the corresponding cluster centers of real-time device data and device pattern categories is calculated, and the reciprocal of the Euclidean distance is taken as the similarity. The calculation method of Euclidean distance is existing technology, and the specific calculation process will not be elaborated here. The calculation method of the similarity between real-time network data and network pattern categories is the same as that of the calculation method of the similarity between real-time device data and device pattern categories. The real-time device mode and the real-time network mode are combined to generate a real-time combination; historical mode relationships are obtained based on the device-network association model, and the real-time ratio is obtained based on the historical mode relationships; the real-time ratio is the ratio between the number of times the real-time combination appears in the historical mode relationships and the total number of times all mode combinations appear in the historical mode relationships; a preset ratio threshold is set by those skilled in the art based on the actual situation; the real-time ratio is compared with the ratio threshold. If the real-time ratio is greater than or equal to the ratio threshold, there is mode consistency between the abnormal control device and the network abnormal situation; if the real-time ratio is less than the ratio threshold, there is no mode consistency between the abnormal control device and the network abnormal situation.

[0028] Methods for determining whether the malfunction of a faulty control device stems from a network anomaly include: If both temporal correlation and pattern consistency exist between the abnormal control device and the network anomaly, the cause of the abnormal control device's anomaly is determined to be a network anomaly; if neither temporal correlation nor pattern consistency exists between the abnormal control device and the network anomaly, the cause of the abnormal control device's anomaly is determined to be a network anomaly.

[0029] It should be noted that when determining whether an anomaly in a control device originates from a network anomaly, both temporal correlation and pattern consistency must be satisfied simultaneously. This is because: First, temporal correlation ensures the temporal relevance of the anomaly events. If the occurrence times of the device anomaly and the network anomaly do not match, even if their characteristic patterns are similar, it is difficult to conclude that the network anomaly is the direct cause of the device anomaly. Temporal consistency is a fundamental condition for inferring causal relationships. Second, pattern consistency ensures the behavioral relevance of the anomaly events. If the manifestations of device anomalies (such as control response failure) and network anomalies (such as denial-of-service attacks) frequently appear simultaneously in the device-network correlation model, it indicates that they share typical common characteristics. If their anomaly patterns do not match, even if the times coincide, it may be due to accidental events or different causes. Therefore, only when both temporal correlation and pattern consistency are satisfied can the anomaly in a control device be accurately determined to originate from a network anomaly, avoiding misjudgments or omissions.

[0030] The anomaly tracing module is used to construct a network communication dependency graph. Based on the network communication dependency graph, it performs in-depth source tracing analysis and propagation path prediction for anomalies caused by network anomalies, and determines the source and scope of impact of the anomalies.

[0031] Methods for constructing network communication dependency graphs include: Network communication records are obtained from data sources such as communication logs, flow monitoring systems, and abnormal time logs in the ship lock industrial control network. These records include communication indicators when various devices communicate with each other. The devices include ship lock control equipment, sensors, and other communication devices (such as industrial control firewalls, gateways, and switches). The communication indicators include source IP address, destination IP address, number of data packets, and communication frequency. All devices in the communication records are treated as nodes. Directed edges are established between nodes that communicate, based on the source and destination IP addresses in the communication records. The direction of the directed edges points from the initiating device to the receiving device, representing the communication dependency between devices. Two nodes with a directed edge are treated as a set of nodes. Based on the communication records, communication feature data corresponding to each set of nodes is obtained, including the number of data packets and the communication frequency. The communication feature data corresponding to each set of nodes is standardized (e.g., Z-score standardization, Min-Max standardization, etc.) to obtain standard communication data. A preset ratio set is established, including the ratio coefficients corresponding to the number of data packets and the communication frequency. This ratio set is preset by those skilled in the art based on actual conditions. The communication feature data corresponding to each set of nodes is weighted and summed according to the ratio set to obtain the communication weight of each set of nodes, which is then used as the communication weight of the corresponding directed edge. A network communication dependency graph is constructed based on the nodes, directed edges, and communication weights.

[0032] The steps to determine the source of the anomaly include: Step S101: Mark the abnormal control device caused by the network abnormality as a network abnormal device, and mark the node corresponding to the network abnormal device as the current node; Step S102: From the network communication dependency graph, obtain the communication weights corresponding to all directed edges pointing to the current node, and mark them as the current weights; Step S103: Obtain the standard network communication dependency graph and mark all communication weights in the standard network communication dependency graph as standard weights; the standard network communication dependency graph is constructed by those skilled in the art based on the obtained network communication records when the network is in a normal historical state. Step S104: Subtract the corresponding standard weight from each current weight and take the absolute value to obtain the weight variable; Step S105: Compare each weight variable with a preset variable threshold, mark the directed edges whose weight variables are greater than the variable threshold as candidate edges, and do not mark the directed edges whose weight variables are less than or equal to the variable threshold. Step S106: If there is a candidate edge in step S105, proceed to step S107; if there is no candidate edge in step S105, proceed to step S108. Step S107: Compare the weight variables of all candidate edges, mark the candidate edge with the largest weight variable as the source edge, update the current node to the node connected to the current node through the source edge, and return to step S102; Step S108: Designate the device corresponding to the current node as the source of the anomaly.

[0033] The steps to determine the scope of impact include: Step S201: Set corresponding numerical labels for all nodes in the network communication dependency graph and mark them as node labels; use all node labels that are marked as the node corresponding to the current node as a node label set; use all weight variables corresponding to the source edges as a variable set, and use the variable set and the node label set as an influence set; Step S202: Mark the node corresponding to the network malfunctioning device as the current node; Step S203: From the network communication dependency graph, obtain all directed edges originating from the current node and mark them as current edges; obtain the node pointed to by each current edge and mark it as the target node; combine the communication weight corresponding to each current edge, the node label of the corresponding target node, and the influence set as a prediction set, that is, the prediction set corresponds one-to-one with the current edge. Step S204: Input each set of predictions into the trained variable prediction model to predict the weight variable corresponding to each current edge and mark it as the predicted variable; the variable prediction model is a deep neural network model, which is an existing technology, and the specific training process will not be described in detail here. Step S205: Compare each predicted variable with the variable threshold, mark the current edge where the predicted variable is greater than the variable threshold as an influencing edge, and do not mark the current edge where the weight variable is less than or equal to the variable threshold. Step S206: If there is an influencing edge in step S205, proceed to step S207; if there is no influencing edge in step S205, proceed to step S208. Step S207: Add all predicted variables and node labels of the target nodes corresponding to all affected edges to the affected set, and take all target nodes corresponding to all affected edges as the current nodes, then return to step S203. Step S208: Use the affected set as the scope of influence.

[0034] The operations and maintenance response module is used to dynamically generate hierarchical response strategies based on a pre-established security operations and maintenance knowledge base and in combination with the source and scope of the anomaly. The hierarchical response strategies include emergency mitigation measures and short-term repair solutions.

[0035] The security operations and maintenance knowledge base includes emergency mitigation measures and short-term repair solutions corresponding to different anomaly levels, including severe anomalies, high-level anomalies, medium-level anomalies, and low-level anomalies. This knowledge base is systematically pre-built by those skilled in the art, combining general strategies for industrial control network security protection, communication structure models, and internationally accepted security standards, using engineering analysis methods, graph modeling techniques, and strategy deduction mechanisms. Emergency mitigation measures and short-term repair solutions represent two different levels and objectives of emergency response. Emergency mitigation measures aim to quickly contain problems and prevent the security incident from spreading further or causing more serious consequences; examples include automatically isolating abnormal control devices, cutting off abnormal communication paths, downgrading operation, and activating backup control units. Short-term repair solutions aim to restore the core functions of the system in a short time and investigate and address the root cause of the problem; examples include reconfiguring security policies, updating patches or firmware on affected devices, and changing the source of the anomaly. By organically combining emergency mitigation measures and short-term repair solutions, a hierarchical security protection strategy can be formed that enables rapid response, precise location, and step-by-step repair, comprehensively improving the security, stability, and recovery capabilities of the ship lock industrial control network.

[0036] Methods for dynamically generating hierarchical response strategies include: The number of node tags within the affected area is counted and used as the impact quantity; based on all weighted variables and the impact quantity within the affected area, the anomaly level is determined; based on the anomaly level, corresponding emergency mitigation measures and short-term remediation plans are selected from the security operations and maintenance knowledge base; the selected emergency mitigation measures are combined to obtain... Group measures combination; combining the selected short-term remediation plans to obtain Group scheme combination, and All are integers greater than 1; among them, a combination of measures includes at least one emergency mitigation measure, and a combination of solutions includes at least one short-term repair solution; Group measures combination and Group the schemes and then combine them again to obtain Group strategy combination, ; Different numerical labels are assigned to different emergency mitigation measures and short-term repair solutions, and these labels are marked as strategy labels. The emergency mitigation measures and short-term repair solutions in each strategy combination are replaced with the corresponding strategy labels. Each strategy combination is input into a trained effect prediction model to predict the corresponding security protection effect. The effect prediction model is a deep neural network model. The security protection effects of each strategy combination are compared, and the strategy combination with the highest security protection effect is taken as the hierarchical response strategy.

[0037] The steps to determine the anomaly level include: Step S301: Calculate the mean and variance of all weighted variables within the scope of influence to obtain the variable mean and variable variance; Step S302: Construct multiple fuzzy sets for the quantity of influence, the mean of the variable, and the variance of the variable; for example, the fuzzy set corresponding to the quantity of influence is large quantity, medium quantity, small quantity, etc., the fuzzy set corresponding to the mean of the variable is large mean, medium mean, small mean, etc., and the fuzzy set corresponding to the variance of the variable is large variance, medium variance, small variance, etc. Step S303: Convert the number of influences, the mean of the variables, and the variance of the variables into the membership degrees of each corresponding fuzzy set using fuzzification techniques. Fuzzification is the process of converting precise numerical values ​​into the membership degrees of fuzzy sets. Examples of fuzzification techniques include triangular membership functions and trapezoidal membership functions. For example, if the numerical value of the number of influences is high, it is inferred that the membership degree of the large number of influences is 0.8, the membership degree of the medium number of influences is 0.4, and the membership degree of the small number of influences is 0. Step S304: Define fuzzy rules. Fuzzy rules are defined based on expert knowledge or relevant literature. For example, if the fuzzy set has a large number of elements, a large mean, and a small variance, then the anomaly level is inferred to be a high degree of membership for severe anomalies. If the fuzzy set has a small number of elements, a small mean, and a small variance, then the anomaly level is inferred to be a high degree of membership for low-level anomalies. Step S305: Match the fuzzified number of influences, variable mean, and variable variance with the fuzzy rules respectively, and perform fuzzy inference using fuzzy inference methods (such as the Mamdani fuzzy inference model, Sugeno fuzzy inference model, etc.) to obtain the fuzzy inference results. The fuzzy inference results are the membership degrees of each anomaly level; for example, the membership degree of severe anomalies is 0.6, the membership degree of high-level anomalies is 0.8, the membership degree of medium-level anomalies is 0.4, and the membership degree of low-level anomalies is 0.1. Step S306: Compare the membership degree of each anomaly level and obtain the anomaly level with the highest membership degree.

[0038] This embodiment, by constructing a baseline model of equipment behavior and monitoring the operating parameters of each control device in real time, can comprehensively perceive the operating status of the lock control system, promptly and accurately detect abnormal equipment behavior, and provide a reliable basis for subsequent anomaly analysis. Using a pre-built equipment network association model, comparing the temporal and pattern characteristics of abnormal equipment and network anomalies can accurately determine whether equipment anomalies originate from network attacks or communication failures, ensuring accurate location of the cause of the incident. Based on network communication dependency analysis, it can deeply trace the source of equipment anomalies caused by network anomalies, accurately locate the source and scope of impact, and lay the foundation for taking targeted protective measures. Combined with a pre-established security operation and maintenance knowledge base, it dynamically generates a hierarchical response strategy, including emergency mitigation measures and short-term repair solutions, which can quickly contain security incidents, effectively repair the system, and identify hidden dangers, significantly improving the automated protection and self-healing capabilities of the lock industrial control network. It achieves comprehensive perception and autonomous control of the lock industrial control network network security status, forming an effective closed loop for security incident handling, with significant security, reliability, and adaptability, which is of great significance for ensuring the stable operation of critical infrastructure.

[0039] Example 2 Please see Figure 2 As shown, the parts not described in detail in this embodiment are described in Embodiment 1. This embodiment provides an autonomous and controllable network security protection method for ship lock industrial control systems. The method includes: A corresponding behavioral baseline model is constructed for each lock control device, and the equipment operation parameters of each lock control device are collected in real time. Based on the behavioral baseline model and the equipment operation parameters, comprehensive anomaly monitoring is carried out on each lock control device to identify abnormal control devices. The system acquires network anomalies and uses a pre-built device network association model to perform multi-level feature comparison between network anomalies and anomaly control devices. By comparing the temporal correlation and pattern consistency between the anomaly control devices and network anomalies, it determines whether the anomaly of the anomaly control devices originates from network anomalies. Construct a network communication dependency graph, and based on the network communication dependency graph, conduct in-depth source tracing analysis and propagation path prediction of the anomaly control equipment caused by network anomalies, and determine the source and scope of impact of the anomalies; Based on a pre-established security operations and maintenance knowledge base, and combined with the source and scope of the anomaly, a hierarchical response strategy is dynamically generated. The hierarchical response strategy includes emergency mitigation measures and short-term repair solutions.

[0040] Example 3 This application also provides an electronic device. The electronic device may include one or more processors and one or more memories. The memories store computer-readable code, which, when executed by the one or more processors, can perform the autonomous and controllable lock industrial control network security protection method described above.

[0041] The method or system according to the embodiments of this application can also be implemented using the architecture of the electronic device shown in this application. The electronic device may include a bus, one or more CPUs, ROM, RAM, a communication port connected to a network, input / output, a hard disk, etc. The storage device in the electronic device, such as a ROM or hard disk, may store the autonomous and controllable lock industrial control network security protection method provided in this application. Furthermore, the electronic device may also include a user interface. Of course, the architecture shown in this application is merely exemplary; when implementing different devices, one or more components in the electronic device shown in this application may be omitted according to actual needs.

[0042] Example 4 One embodiment of this application discloses a computer-readable storage medium. The computer-readable storage medium stores computer-readable instructions. When the computer-readable instructions are executed by a processor, a self-controllable network security protection method for ship lock industrial control systems according to an embodiment of this application, as described with reference to the above figures, can be performed. The storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0043] Furthermore, according to embodiments of this application, the processes described in the above-referenced flowcharts can be implemented as computer software programs. For example, this application provides a non-transitory machine-readable storage medium storing machine-readable instructions that can be executed by a processor to perform instructions corresponding to the method steps provided in this application, such as an autonomous and controllable method for protecting the network security of a ship lock industrial control system. When this computer program is executed by a central processing unit (CPU), it performs the functions defined in the method of this application.

[0044] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0045] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0046] In the description of this invention, it should be understood that the terms "first," "second," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance.

[0047] In the description of this invention, unless otherwise stated, "a plurality of" means two or more.

[0048] In the description of this invention, "several" means one or more, and "a large number" means two or more.

[0049] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0050] All formulas in this manual are dimensionless and calculated numerically. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.

[0051] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

Claims

1. A self-controllable network security protection method for ship lock industrial control systems, characterized in that, include: A corresponding behavioral baseline model is constructed for each lock control device, and the equipment operation parameters of each lock control device are collected in real time. Based on the behavioral baseline model and the equipment operation parameters, comprehensive anomaly monitoring is carried out on each lock control device to identify abnormal control devices. Methods for identifying abnormal control devices include: Each behavioral baseline model includes the average value and standard deviation of each device's operating parameter. A preset threshold multiple is used to calculate the product of each standard deviation and the threshold multiple in each behavioral baseline model, obtaining the deviation tolerance. Based on the average value and deviation tolerance of each behavioral baseline model, the interval threshold for each operating parameter of each lock control device is calculated, and the corresponding fluctuation interval is constructed. Each operating parameter of each lock control device is compared with its corresponding fluctuation interval. Lock control devices with operating parameters exceeding the corresponding fluctuation interval are marked as abnormal control devices, while lock control devices with all operating parameters within the fluctuation interval are not marked. The system acquires network anomalies and uses a pre-built device-network association model to perform multi-level feature comparisons between network anomalies and anomalous control devices. By comparing the temporal correlation and pattern consistency between the anomalous control devices and network anomalies, it determines whether the anomaly of the anomalous control devices originates from network anomalies. Methods for determining whether the anomaly of the anomalous control devices originates from network anomalies include: If there is both temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be a network anomaly; if there is no simultaneous temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be not a network anomaly. Construct a network communication dependency graph, and based on the network communication dependency graph, conduct in-depth source tracing analysis and propagation path prediction of the anomaly control equipment caused by network anomalies, and determine the source and scope of impact of the anomalies; Based on a pre-established security operations and maintenance knowledge base, and combined with the source and scope of the anomaly, a hierarchical response strategy is dynamically generated. The hierarchical response strategy includes emergency mitigation measures and short-term repair solutions.

2. The autonomous and controllable network security protection method for ship lock industrial control systems according to claim 1, characterized in that, The device network association model includes historical latency relationships and historical pattern relationships. The historical latency relationship includes the time interval between the network anomaly time and the device anomaly time when the cause of the abnormal control device's anomaly in the past was a network anomaly. The network anomaly time is the time corresponding to the acquisition of the network anomaly situation, and the device anomaly time is the time corresponding to the identification of the abnormal control device. The historical pattern relationship includes the pattern combination when the cause of the abnormal control device's anomaly in the past was a network anomaly. The pattern combination includes the abnormal pattern of the abnormal control device and the abnormal pattern of the network anomaly situation. Methods for comparing the temporal correlation between abnormal control devices and network anomalies include: The system acquires real-time device time and real-time network time. Real-time device time refers to the time of device anomalies acquired in real time, and real-time network time refers to the time of network anomalies acquired in real time. A unified time protocol is used to align the real-time device time and real-time network time. Historical latency relationships are obtained based on the device-network correlation model, and all time intervals in the historical latency relationships are averaged to obtain the average interval. A tolerance coefficient is preset, and a time window is constructed starting from the real-time device time and extending forward based on the average interval and the tolerance coefficient. The length of the time window is the sum of the average interval and the tolerance coefficient. The real-time network time and the time window are analyzed. If the real-time network time is within the time window, there is a temporal correlation between the anomaly control device and the network anomaly; if the real-time network time is outside the time window, there is no temporal correlation between the anomaly control device and the network anomaly.

3. The autonomous and controllable network security protection method for ship lock industrial control systems according to claim 2, characterized in that, Methods for comparing the consistency of patterns between abnormal control devices and network anomalies include: Acquire historical feature data, which includes historical device data and historical network data. Historical device data is device feature data obtained from abnormal control devices at historical times, and historical network data is network feature data obtained from network anomalies at historical times. K-means clustering algorithm was used to cluster historical device data and historical network data respectively, dividing the historical device data into... Each device mode category categorizes historical network data into Network mode categories, and All values ​​are integers greater than 1; For each device mode category and network mode category, a corresponding abnormal mode is set; real-time feature data is obtained, including real-time device data and real-time network data. Real-time device data is device feature data obtained in real time from the abnormal control device, and real-time network data is network feature data obtained in real time from network abnormal situations; the similarity between real-time device data and each device mode category is calculated, and the abnormal mode corresponding to the device mode category with the highest similarity is taken as the real-time device mode corresponding to the real-time device data; the similarity between real-time network data and each network mode category is calculated, and the abnormal mode corresponding to the network mode category with the highest similarity is taken as the real-time network mode corresponding to the real-time network data. The real-time device mode and the real-time network mode are combined to generate a real-time combination. Historical mode relationships are obtained based on the device-network association model, and the real-time ratio is obtained based on the historical mode relationships. The real-time ratio is the ratio between the number of times the real-time combination appears in the historical mode relationships and the total number of times all mode combinations appear in the historical mode relationships. A preset ratio threshold is set, and the real-time ratio is compared with the ratio threshold. If the real-time ratio is greater than or equal to the ratio threshold, there is mode consistency between the abnormal control device and the network abnormality. If the real-time ratio is less than the ratio threshold, there is no mode consistency between the abnormal control device and the network abnormality.

4. The autonomous and controllable network security protection method for ship lock industrial control systems according to claim 3, characterized in that, Methods for constructing network communication dependency graphs include: Obtain network communication records, which include communication metrics between various devices; these metrics include source IP address, destination IP address, number of data packets, and communication frequency. All devices in the communication records are treated as nodes. Directed edges are established between nodes that communicate, based on the source and destination IP addresses in the records. The direction of the directed edges points from the initiating device to the receiving device. Two nodes with a directed edge are grouped into a node set. Communication feature data, including the number of data packets and communication frequency, is obtained for each node set based on the communication records. The communication feature data for each node set is standardized to obtain standard communication data. A pre-defined ratio set is used, containing proportional coefficients corresponding to the number of data packets and communication frequency. The standard communication data for each node set is weighted and summed according to the ratio set to obtain the communication weight for each node set, which is then used as the communication weight for the corresponding directed edge. A network communication dependency graph is constructed based on the nodes, directed edges, and communication weights.

5. A method for protecting the network security of an autonomous and controllable ship lock industrial control system according to claim 4, characterized in that, The steps to determine the source of the anomaly include: Step S101: Mark the abnormal control device caused by the network abnormality as a network abnormal device, and mark the node corresponding to the network abnormal device as the current node; Step S102: From the network communication dependency graph, obtain the communication weights corresponding to all directed edges pointing to the current node, and mark them as the current weights; Step S103: Obtain the standard network communication dependency graph and mark all communication weights in the standard network communication dependency graph as standard weights; Step S104: Subtract the corresponding standard weight from each current weight and take the absolute value to obtain the weight variable; Step S105: Compare each weight variable with a preset variable threshold, mark the directed edges whose weight variables are greater than the variable threshold as candidate edges, and do not mark the directed edges whose weight variables are less than or equal to the variable threshold. Step S106: If there is a candidate edge in step S105, proceed to step S107; if there is no candidate edge in step S105, proceed to step S108. Step S107: Compare the weight variables of all candidate edges, mark the candidate edge with the largest weight variable as the source edge, update the current node to the node connected to the current node through the source edge, and return to step S102; Step S108: Designate the device corresponding to the current node as the source of the anomaly.

6. A method for protecting the network security of an autonomous and controllable ship lock industrial control system according to claim 5, characterized in that, The steps to determine the scope of impact include: Step S201: Set corresponding numerical labels for all nodes in the network communication dependency graph and mark them as node labels; use all node labels that are marked as the node corresponding to the current node as a node label set; use all weight variables corresponding to the source edges as a variable set, and use the variable set and the node label set as an influence set; Step S202: Mark the node corresponding to the network malfunctioning device as the current node; Step S203: From the network communication dependency graph, obtain all directed edges originating from the current node and mark them as current edges; obtain the node pointed to by each current edge and mark it as the target node; combine the communication weight corresponding to each current edge, the node label of the corresponding target node, and the influence set as a prediction set. Step S204: Input each set of predictions into the trained variable prediction model to predict the weight variable corresponding to each current edge and mark it as the prediction variable. The variable prediction model is a deep neural network model. Step S205: Compare each predicted variable with the variable threshold, mark the current edge where the predicted variable is greater than the variable threshold as an influencing edge, and do not mark the current edge where the predicted variable is less than or equal to the variable threshold. Step S206: If there is an influencing edge in step S205, proceed to step S207; if there is no influencing edge in step S205, proceed to step S208. Step S207: Add all predicted variables and node labels of the target nodes corresponding to all affected edges to the affected set, and take all target nodes corresponding to all affected edges as the current nodes, then return to step S203. Step S208: Use the affected set as the scope of influence.

7. A method for protecting the network security of an autonomous and controllable ship lock industrial control system according to claim 6, characterized in that, The security operations and maintenance knowledge base includes emergency mitigation measures and short-term repair plans corresponding to different anomaly levels, including severe anomalies, high-level anomalies, medium-level anomalies, and low-level anomalies. Methods for dynamically generating hierarchical response strategies include: The number of node tags within the affected area is counted and used as the impact quantity; based on all weighted variables and the impact quantity within the affected area, the anomaly level is determined; based on the anomaly level, corresponding emergency mitigation measures and short-term remediation plans are selected from the security operations and maintenance knowledge base; the selected emergency mitigation measures are combined to obtain... Group measures combination; combining the selected short-term remediation plans to obtain Group scheme combination, and All are integers greater than 1; Group measures combination and Group the schemes and then combine them again to obtain Group strategy combination; Different numerical labels are assigned to different emergency mitigation measures and short-term repair solutions, and these labels are marked as strategy labels. The emergency mitigation measures and short-term repair solutions in each strategy combination are replaced with the corresponding strategy labels. Each strategy combination is input into a trained effect prediction model to predict the corresponding security protection effect. The effect prediction model is a deep neural network model. The security protection effects of each strategy combination are compared, and the strategy combination with the highest security protection effect is taken as the hierarchical response strategy.

8. A method for protecting the network security of an autonomous and controllable ship lock industrial control system according to claim 7, characterized in that, The steps to determine the anomaly level include: Step S301: Calculate the mean and variance of all weighted variables within the scope of influence to obtain the variable mean and variable variance; Step S302: Construct multiple fuzzy sets for the quantity of influence, the mean of the variable, and the variance of the variable, respectively; Step S303: Convert the number of influences, the mean of the variables, and the variance of the variables into the membership degree of each corresponding fuzzy set using fuzzification technology; Step S304: Define fuzzy rules; Step S305: Match the fuzzy influence quantity, variable mean, and variable variance with the fuzzy rules respectively, and use the fuzzy inference method to perform fuzzy inference to obtain the fuzzy inference result. The fuzzy inference result is the membership degree of each anomaly level. Step S306: Compare the membership degree of each anomaly level and obtain the anomaly level with the highest membership degree.

9. A self-controllable network security protection system for the industrial control of ship locks, implementing the self-controllable network security protection method for the industrial control of ship locks as described in any one of claims 1-8, characterized in that, include: The equipment monitoring module is used to build a corresponding behavioral baseline model for each lock control device and collect the equipment operation parameters of each lock control device in real time. Based on the behavioral baseline model and the equipment operation parameters, it performs comprehensive anomaly monitoring on each lock control device and identifies abnormal control devices. Methods for identifying abnormal control devices include: Each behavioral baseline model includes the average value and standard deviation of each device's operating parameter. A preset threshold multiple is used to calculate the product of each standard deviation and the threshold multiple in each behavioral baseline model, obtaining the deviation tolerance. Based on the average value and deviation tolerance of each behavioral baseline model, the interval threshold for each operating parameter of each lock control device is calculated, and the corresponding fluctuation interval is constructed. Each operating parameter of each lock control device is compared with its corresponding fluctuation interval. Lock control devices with operating parameters exceeding the corresponding fluctuation interval are marked as abnormal control devices, while lock control devices with all operating parameters within the fluctuation interval are not marked. The anomaly detection module is used to acquire network anomalies and perform multi-level feature comparison between network anomalies and abnormal control devices using a pre-built device network association model. By comparing the temporal correlation and pattern consistency between the abnormal control devices and network anomalies, it determines whether the anomaly of the abnormal control devices originates from network anomalies. The methods for determining whether the anomaly of the abnormal control devices originates from network anomalies include: If there is both temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be a network anomaly; if there is no simultaneous temporal correlation and pattern consistency between the abnormal control device and the network anomaly, the cause of the abnormal control device is determined to be not a network anomaly. The anomaly tracing module is used to construct a network communication dependency graph. Based on the network communication dependency graph, it performs in-depth source tracing analysis and propagation path prediction on the anomaly control devices caused by network anomalies, and determines the source and scope of impact of the anomalies. The operations and maintenance response module is used to dynamically generate tiered response strategies based on a pre-established security operations and maintenance knowledge base and in combination with the source and scope of the anomaly. The tiered response strategies include emergency mitigation measures and short-term repair solutions.

Citation Information

Patent Citations

  • A network security control method and device for an industrial control system

    CN114019933B

  • Industrial control safety monitoring method and system

    CN120582966A

  • Method for anomaly classification of industrial control system communication network

    US20220269258A1