Industrial control system anomaly detection method based on behavior causal chain

By introducing a behavioral causal chain model into industrial control systems and integrating multi-source heterogeneous data for anomaly detection, the shortcomings of existing methods in detecting complex threat scenarios are solved, achieving efficient and accurate anomaly detection and result interpretation.

CN121792141APending Publication Date: 2026-04-03XIDIAN UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-17
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing methods for detecting anomalies in industrial control systems are ill-suited to complex threat scenarios, such as varying data distributions and unknown attack patterns. They also suffer from insufficient interpretability of detection results, high computational complexity, and difficulty in operating efficiently in real-time and resource-constrained industrial environments.

Method used

A behavior-based causal chain detection method is adopted. By fusing network, physical and time-frequency domain features, a causal chain model is constructed. Combined with time window features of multiple time scales and a comprehensive anomaly scoring function, real-time anomaly detection of industrial control systems is achieved.

Benefits of technology

It improves the accuracy and interpretability of detection, reduces false alarms and false negatives, enhances the real-time performance and efficiency of the system in resource-constrained environments, and can clearly reveal the generation mechanism and propagation pattern of abnormal behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792141A_ABST
    Figure CN121792141A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial control system anomaly detection method based on a behavior causal chain. The method comprises the steps of collecting a network layer feature vector, a physical feature vector and a time-frequency domain feature vector of an industrial control system; carrying out feature fusion to obtain a joint feature vector; obtaining a plurality of time window features of different time scales according to a plurality of preset time windows of different time scales and the joint feature vector; constructing an input vector according to the joint feature vector and a plurality of time window features of different time scales; inputting the input vector into a pre-constructed behavior causal chain model to obtain a causal chain; calculating the score of the comprehensive abnormal scoring function according to the causal chain and the reference causal chain; and when the score of the comprehensive anomaly scoring function is greater than a preset global anomaly judgment threshold, judging that an abnormal event exists. The method has relatively high detection accuracy, calculation efficiency and system adaptability, and can realize anomaly detection in a complex industrial control environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of time-triggered Ethernet, specifically relating to an anomaly detection method for industrial control systems based on behavioral causal chains. Background Technology

[0002] Industrial Control Systems (ICS) are critical infrastructure supporting modern industrial automation and intelligent manufacturing. They are widely used in important sectors such as power, petrochemicals, transportation, water treatment, and manufacturing, serving as a vital support system for national economic operation and social production. The deep integration of information technology and industrial control technology has driven the networking and intelligentization of these systems, resulting in more complex system structures, increasingly interconnected devices, and frequent interactions of business data and control commands across multi-layered networks. Their security directly impacts the stability of industrial processes and production safety.

[0003] However, the openness and interconnectivity brought about by networking have exposed industrial control systems to a wider range of cyber threats. Attacks have evolved from traditional single-point penetration to complex, multi-stage, multi-source coordinated attacks, exhibiting characteristics such as high concealment, rapid propagation, and wide-ranging impact. Faced with increasingly complex threat forms, anomaly detection, as a core component of industrial control system security protection, plays a crucial role in identifying abnormal behavior, discovering potential attacks, and supporting emergency response.

[0004] Existing methods for detecting anomalies in industrial control systems still have significant limitations in practical applications. On the one hand, methods based on machine learning or temporal causal analysis are highly dependent on training data and fixed models, making it difficult to adapt to changes in data distribution and unknown attack methods in industrial scenarios. Furthermore, these methods often remain at the statistical or temporal level, lacking a deep understanding of control logic and the semantics of device behavior, resulting in insufficient interpretability of detection results. On the other hand, causal analysis methods for multi-device collaborative scenarios have high computational complexity and long update cycles during modeling and inference, making it difficult to operate efficiently in industrial environments where real-time performance and resource constraints coexist. These problems make it difficult for existing solutions to achieve a balance between detection accuracy, computational efficiency, and system adaptability, limiting their actual protective effectiveness in complex industrial control environments. Summary of the Invention

[0005] To address the aforementioned problems in the existing technology, this invention provides an anomaly detection method for industrial control systems based on behavioral causal chains.

[0006] The technical problem to be solved by this invention is achieved through the following technical solution: In a first aspect, the present invention provides an anomaly detection method for industrial control systems based on behavioral causal chains, the method comprising: The industrial control system is subjected to network space acquisition, physical space acquisition and electromagnetic space acquisition respectively to obtain network layer feature vector, physical feature vector and time-frequency domain feature vector; The network layer feature vector, the physical feature vector, and the time-frequency domain feature vector are fused to obtain a joint feature vector. Multiple time window features at different time scales are obtained based on multiple preset time windows at different time scales and the joint feature vector; An input vector is constructed based on the joint feature vector and the time window features of multiple different time scales; The input vector is input into a pre-constructed behavioral causal chain model to obtain a causal chain; wherein, the behavioral causal chain model is constructed according to the behavioral causal chain defined in the form of a graph structure. The score of the comprehensive anomaly scoring function is calculated based on the causal chain and the benchmark causal chain; wherein the benchmark causal chain is obtained based on a pre-constructed benchmark causal chain model; the benchmark causal chain model is obtained based on the typical causal relationships of the industrial control system under steady-state conditions; An abnormal event is determined to exist when the score of the comprehensive anomaly scoring function is greater than the preset global anomaly determination threshold.

[0007] Optionally, the step of performing network space acquisition, physical space acquisition, and electromagnetic space acquisition on the industrial control system to obtain network layer feature vectors, physical feature vectors, and time-frequency domain feature vectors includes: Collect the response messages of the industrial control system and parse the response messages to obtain the operation semantics; The request and response message in the same communication channel are matched according to the timestamp to obtain the control transaction unit; The network layer feature vector is obtained based on the operational semantics, the response message, and the control transaction unit. Acquire the set of physical state variables of sensors and actuators through edge data acquisition devices; The control response delay and time consistency indicators are obtained from the control transaction unit, and the physical feature vector is obtained from the physical state variable set. The electromagnetic signal sequence generated during system operation is obtained, and the time-frequency domain feature vector of the electromagnetic signal sequence is extracted.

[0008] Optionally, the joint feature vector is represented as follows: ; in, Indicates the sampling time The joint eigenvectors, Indicates the sampling time The network layer feature vectors, Indicates the sampling time The physical feature vector, Indicates the sampling time The time-frequency domain eigenvectors.

[0009] Optionally, the multiple time windows with different time scales are represented as follows: ; in, This refers to the multiple time windows with different time scales. This represents a short window used to detect sudden anomalies. The middle window represents the detection period perturbation. This represents a long window for detecting latent changes.

[0010] Optionally, the time window features of the multiple different time scales are represented as follows: ; in, Indicates the sampling time The time window features of the multiple different time scales. Indicates the sampling time Mean shift within the window, Indicates the sampling time variance shift, Indicates the sampling time The rate of change of signal energy.

[0011] Optionally, the construction process of the baseline causal chain model includes: The baseline edge weights are obtained based on the set of steady-state causal chains generated by the industrial control system within multiple steady-state time windows under steady-state conditions. Construct a baseline causal structure based on the baseline edge weights; A confidence index is defined based on the instantaneous edge weights and the baseline edge weights; The causal dependencies of the steady-state causal chain are adjusted according to the confidence index to obtain the adjusted causal dependencies; The baseline causal chain model is obtained based on the adjusted causal dependencies.

[0012] Optionally, the comprehensive anomaly scoring function is represented as follows: ; in, Indicates time The comprehensive anomaly scoring function, Causal path deviation The weighting coefficients, Represents the causal chain generated at time t. , Represents the baseline causal chain, To control the deviation The weighting coefficients, Time drift The weighting coefficients, For cross-space consistency deviation The weighting coefficients.

[0013] Optionally, after determining that an abnormal event exists when the score of the comprehensive anomaly scoring function is greater than a preset global anomaly determination threshold, the method further includes: The dominant deviation factor is obtained based on the deviation that contributes most to the causal path deviation, the control deviation, the time drift, and the cross-spatial consistency deviation.

[0014] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: In the above technical solution, this invention introduces a causal chain model to realize an incremental graph structure, enabling the rapid construction of causal chains during real-time detection. This allows for continuous updating of causal dependencies between devices in a multi-device collaborative industrial control environment, ensuring efficient operation under resource constraints and improving the real-time performance and efficiency of the detection system. Furthermore, by employing a joint modeling method using multi-source heterogeneous data, integrating network layer feature vectors, physical feature vectors, and time-frequency domain feature vectors, and through protocol semantic parsing and causal chain modeling, the system's semantic understanding of control logic and device behavior is effectively enhanced, improving the accuracy of anomaly detection and strengthening the interpretability of detection results. This allows the detection process to clearly reveal the generation mechanism and propagation rules of abnormal behavior, thereby reducing false alarms and false negatives. Finally, this invention addresses the problems of complex multi-device causal modeling and insufficient system adaptability.

[0015] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0016] Figure 1 This is a flowchart of an anomaly detection method for an industrial control system based on behavioral causal chains provided in an embodiment of the present invention; Figure 2 This is a flowchart of an anomaly detection process provided by an embodiment of the present invention. Detailed Implementation

[0017] The present invention will be further described in detail below with reference to specific embodiments, but the implementation of the present invention is not limited thereto.

[0018] Figure 1 This is a flowchart of an anomaly detection method for an industrial control system based on behavioral causal chains provided by an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps: S101. Perform network space acquisition, physical space acquisition and electromagnetic space acquisition on the industrial control system to obtain network layer feature vector, physical feature vector and time-frequency domain feature vector.

[0019] Optionally, S101 may include: Collect response messages from industrial control systems and parse the response messages to obtain operational semantics; The request and response messages in the same communication channel are matched based on the timestamp to obtain the control transaction unit; The network layer feature vectors are obtained based on the operational semantics, response messages, and control transaction units. Acquire the set of physical state variables of sensors and actuators through edge data acquisition devices; The control response delay and time consistency indicators are obtained from the control transaction unit, and the physical feature vector is obtained from the physical state variable set. Obtain the electromagnetic signal sequence generated during system operation and extract the time-frequency domain feature vector of the electromagnetic signal sequence.

[0020] Understandable, Figure 2 This is a flowchart illustrating an anomaly detection process provided in an embodiment of the present invention, such as... Figure 2 As shown, by configuring a mirror port on the industrial control system, the response messages between various nodes can be copied to the acquisition terminal. The acquisition terminal runs a data capture program based on tshark to collect the response messages in real time and extract the operation semantics through protocol parsing.

[0021] Set in the time interval Internally collected message set for: ; in, In response to the sampling time of the message, For the message set Message, The first The source and destination addresses of each message. For the first The industrial control protocol type of the message. For the first The message payload of each message, For the first The timestamp of the message collection This indicates the total number of messages collected within this time interval.

[0022] Based on the structured characteristics of the response messages, protocol parsing is used to perform field-by-field parsing and semantic reconstruction of the collected response messages. First, based on each message... Industrial control protocol types ,from Extract the function code, register address, and data value fields to construct the first... Protocol field triples of the message: ; in, Indicates the first The function code of the message (operation type, such as read / write / control). Indicates the first The register address or function object of the message. Indicates the first The data value or transmission parameters of the message.

[0023] Since the response message only reflects bit-level functional flags and lacks understandable business semantics, this invention introduces a semantic mapping function: ; in, For the first The semantics of operations mapped from the protocol field triples of a message. This is a protocol semantic mapping function used to map protocol field triples to readable operational semantics, such as "write valve 1 opening = 70%" or "read pump station pressure value". This mapping function is automatically generated based on the industrial protocol function table and device I / O register configuration file. By establishing a correspondence between function codes and device operational semantics, it achieves the conversion from underlying communication fields to control behavior semantics.

[0024] Industrial control systems typically employ a master-slave communication structure, where the upper-level monitoring terminal periodically issues control commands, and the lower-level devices execute the operations and return feedback results. Because a single response message in a request-response model cannot fully reflect the system's behavioral logic, analyzing only one-way communication can easily lead to semantic fragmentation, making it difficult to reconstruct the complete "control triggering-execution feedback" process, thus affecting the accuracy and interpretability of the detection.

[0025] Therefore, after protocol parsing and semantic mapping, this invention designs a transaction aggregation and response association mechanism to restore the true control transaction relationship at the message level. This mechanism uses timestamps and session identifiers as its core, identifying a complete control interaction by matching request and response messages in the same communication channel. The system distinguishes different sessions based on protocol identifiers such as TCP (Transmission Control Protocol) session number, Modbus transaction ID, or DNP3 (Distributed Network Protocol 3) sequence number, and selects the response message closest to the request time within a set time window to ensure logical correspondence.

[0026] Therefore, the control transaction unit is defined as: ; in, and The first The request and response semantic events obtained by a transaction during the protocol resolution phase. This represents the network communication latency between the request and response of the i-th transaction. When the same transaction occurs within a predefined time window... If no corresponding response is detected, the system automatically marks it as an abnormal transaction.

[0027] After the transaction set is constructed, this invention further extracts network layer features based on the transaction layer to achieve quantitative modeling and comparable expression of communication behavior.

[0028] The core objective of feature extraction is to control the unit of transaction. Transforming it into a measurable vectorized representation enables the system to track the evolution trend of communication features in the time series dimension.

[0029] Based on this, the feature vector of the network layer is defined as follows: ; in, Let be the communication frequency of the i-th transaction. Let be the failure rate of the i-th transaction. The first four features are a subset of local features, used to characterize the behavioral semantics and response characteristics of a single transaction; while and The number of occurrences of the same session transaction and the number of exceptions (no response or timeout) within the fixed time window are determined respectively.

[0030] The physical space acquisition module reflects the actual execution results of control commands at the device level, acquiring dynamic changes in process variables in real time through sensor and actuator interfaces. The system deploys edge data acquisition devices on PLCs (Programmable Logic Controllers) or industrial control units to periodically read output signals from field sensors and actuators. The acquired data is synchronized with timestamps and device identifiers to achieve time alignment with network transaction data.

[0031] Set in the time interval The set of physical state variables collected internally is as follows: ; in, Indicates the first A sensor or actuator at the sampling time The output of .

[0032] To measure the time relationship between control command execution and device response, the control response delay is further defined as follows: ; in, For the first The physical response time for each transaction. For the first The request time for each transaction. If ( If the preset response threshold is used, the device response is marked as "hysteresis anomaly".

[0033] For each physical variable, calculate its rate of change, mean, and variance within the time window to form the final physical feature vector: ; in, Representing physical variables At sampling time The rate of change at a given point is used to characterize the trend of a variable over time. For physical variables The steady-state mean within this time window is used to describe its average level; For physical variables The variance of the fluctuation within this time window is used to measure its stability and degree of volatility.

[0034] The system deploys non-contact electromagnetic detection sensors (such as broadband magnetic probes or electric field probes) around key control equipment, and synchronously collects and records the raw signals through a high-speed sampling card, thereby reflecting the implicit relationship between control actions and equipment operating status from the energy characteristics level.

[0035] Set in the time interval The electromagnetic signal sequence acquired internally is as follows: ; in, Indicates the first Each measuring point at the sampling time Electromagnetic signals. Electromagnetic signals After bandpass filtering and frame preprocessing, time-frequency domain features are extracted. : ; in, Main frequency, For signal bandwidth, For power spectral density, For the first Signal envelope energy at each measurement point For the rising time, Duration.

[0036] In addition, to verify the synchronization between electromagnetic events and network commands, a time consistency index is defined: ; in, For the first The electromagnetic response time corresponding to each transaction, when ( When the threshold for time consistency is set (preset), it is determined that there may be a forgery or replay attack. This indicator will be used as one of the edge weights in subsequent causal chain modeling.

[0037] After completing data acquisition and feature extraction in the network, physical, and electromagnetic domains, the system obtained three types of feature sequences that respectively reflect control intent, process response, and energy behavior: ; ; ; Since the sampling frequencies and response delays differ across spaces, direct joint analysis can lead to temporal offset and semantic mismatch issues. To address this, this invention proposes a multi-dimensional feature fusion and temporal modeling method. Based on time synchronization, scale partitioning, and feature reconstruction, a unified high-dimensional behavioral feature vector is formed for subsequent causal chain modeling and anomaly detection.

[0038] S102. Perform feature fusion on the network layer feature vector, physical feature vector, and time-frequency domain feature vector to obtain a joint feature vector.

[0039] It is understandable that the spatial data of industrial control systems are temporally correlated. To achieve consistent fusion of spatial features, this invention introduces a feature fusion mechanism based on timestamp synchronization. A unified reference time axis is established in the system. The spatial feature sequences are interpolated and resampled using a function. Map to a uniform time step to give them the same time resolution: ; At each sampling time The system can obtain synchronization features in three spaces, and the joint feature vector constructed based on these features is as follows: ; Indicates the sampling time The joint eigenvectors, Indicates the sampling time The network layer feature vectors, Indicates the sampling time The physical feature vector, Indicates the sampling time The time-frequency domain eigenvectors.

[0040] Through this mechanism, the system obtains a complete spatially consistent description at each time step, enabling different types of behavioral information to be modeled uniformly under the same semantic coordinates.

[0041] S103. Based on multiple preset time windows at different time scales and joint feature vectors, obtain time window features at multiple time scales.

[0042] It is understandable that, such as Figure 2 As shown, anomalies in industrial processes exhibit multi-timescale characteristics, such as sudden control anomalies (milliseconds), periodic disturbances (seconds), and slowly changing instability (minutes), making it difficult for a single time window to simultaneously capture different dynamic patterns. This invention further introduces a multi-scale sliding window set based on a unified time axis: ; in, This represents multiple time windows with different time scales. This represents a short window used to detect sudden anomalies. The middle window represents the detection period perturbation. This represents a long window for detecting latent changes.

[0043] For each type of window Feature sequences within Statistical offsets and dynamic indices at different time scales are calculated to jointly reflect changes in system state stability and energy fluctuation trends. Specifically, the characteristics of multiple time windows at different time scales are defined as follows: ; in, Indicates the sampling time The time window features at multiple different time scales Indicates the sampling time Mean shift within the window, Indicates the sampling time variance shift, Indicates the sampling time The rate of change of signal energy.

[0044] S104. Construct an input vector based on the joint feature vector and time window features at multiple different time scales.

[0045] To form a unified input for causal analysis, spatial fusion features are combined with time window features at three scales to construct the final input vector: ; in, , , These represent the temporal variation characteristics under short, medium, and long windows, respectively.

[0046] S105. Input the input vector into the pre-constructed behavioral causal chain model to obtain the causal chain; wherein, the behavioral causal chain model is constructed according to the behavioral causal chain defined in the form of a graph structure.

[0047] It is understandable that, such as Figure 2 As shown, after obtaining the input vector Subsequently, a behavioral causal chain model is constructed to characterize the directed dependency relationship of "operator – control command – equipment response" in industrial control systems, thereby achieving causal explanation and anomaly identification of system behavior. The behavioral logic of industrial control systems naturally possesses causal chain characteristics, namely: upper-level operation commands trigger intermediate control logic, ultimately manifesting as state or energy responses at the equipment level. Therefore, this invention defines the behavioral causal chain in the form of a graph structure: ; in, For a set of nodes, each node This represents the time corresponding to that moment. input vector , is used to represent a system behavior event; A set of directed edges used to describe the causal triggering relationships between events, i.e., events Regarding the event The causal effect; This is a set of edge weights, representing the time delay weight, control deviation weight, and cross-space consistency weight, respectively. Specifically, the time delay weight... Reflecting the timing dependencies of event triggering: ; in, The time decay coefficient, , The timestamp of the corresponding event; Control deviation rights This indicates the degree of magnitude deviation between the operational output and the physical response: ; in, This is the physical layer response value. Standard amplitude; Cross-space consistency rights Derived from the electromagnetic-network synchronization index defined above: .

[0048] S106. Calculate the score of the comprehensive anomaly scoring function based on the causal chain and the baseline causal chain; wherein, the baseline causal chain is obtained based on the pre-constructed baseline causal chain model; the baseline causal chain model is obtained based on the typical causal relationships of the industrial control system under steady-state conditions.

[0049] Optionally, the process of constructing the baseline causal chain model includes: The baseline edge weights are obtained based on the set of steady-state causal chains generated within multiple steady-state time windows under steady-state conditions of the industrial control system. Construct a baseline causal structure based on the baseline edge weights; Confidence indices are defined based on instantaneous edge weights and baseline edge weights; The causal dependencies of the steady-state causal chain are adjusted based on the confidence index to obtain the adjusted causal dependencies; The baseline causal chain model is obtained based on the adjusted causal dependencies.

[0050] Understandably, in order to achieve quantifiable determination of anomaly detection, this invention establishes a baseline causal chain model during the normal operation phase of the system under steady-state conditions. This is used to characterize the typical causal dependencies of a system under steady-state conditions. Specifically, in the baseline construction phase, the system is based on a set of causal chains generated within multiple normal time windows: ; Perform statistical aggregation on node relationships and edge weight parameters. For any node pair... If a relationship co-occurs in more than a set proportion of causal chains (i.e., a triggering relationship exists under most normal operating conditions), then that relationship is included in the baseline causal chain. Baseline Edge Weight The calculation uses a weighted expectation form: ; in, , and These are represented as the average values ​​of the time delay weight, the control deviation weight, and the cross-space consistency weight, respectively. , and These are the weighting coefficients for the three types of weights, used to balance the contributions of different types of information.

[0051] Based on this, the baseline causal structure of the system under steady-state conditions for: ; in, The union of all event nodes that occurred within all normal time windows during the baseline construction phase. This refers to the causal relationship of events that occur continuously within a normal time window. This is the weighted expected value of the consistency of all edges in the benchmark, i.e. .

[0052] Once the real-time monitoring phase begins, considering fluctuations in operating conditions, task switching, and changes in equipment parameters, the causal chain structure needs to have adaptive update capabilities. Therefore, this invention introduces a confidence assessment mechanism based on edge weight consistency, building upon the baseline causal structure, to quantify the reliability of real-time causal relationships.

[0053] For any candidate relation Its instantaneous edge weight at the current moment is defined as: ; To measure the relationship against the average edge weight in the benchmark model Consistency, the confidence index is defined as: ; in, To prevent small constants with a denominator of zero, the system at each time step... Generate the current causal chain and compared with the benchmark model Perform a structural comparison. If a new node or edge is detected (e.g., a new control command, device status, or energy signal), then perform a confidence index comparison. Adjusting causal dependencies: ; in, Let be the set of causal relationships at the current time t. The set of causal relationships updated in the next moment. This represents the confidence threshold. If a causal relationship remains unobserved for an extended period, a decay update is performed. ; This is to ensure that the model can adapt to long-term evolution and dynamic changes in new scenarios.

[0054] Through this incremental learning mechanism, the system can continuously optimize the causal dependency structure, achieve "adaptive evolution" of the causal chain, and maintain the stability of detection for new operating conditions.

[0055] During the real-time detection phase, the system generates a causal chain based on the current time t. Reference causal chain under normal operating conditions A comparison is made. By analyzing the existence changes in event relationships and the degree of edge weight deviation, the comprehensive anomaly scoring function is expressed as follows: ; in, Indicates time The comprehensive anomaly scoring function, Causal path deviation The weighting coefficients, Represents the causal chain generated at time t. , Represents the baseline causal chain, To control the deviation The weighting coefficients, Time drift The weighting coefficients, For cross-space consistency deviation The weighting coefficients satisfy .

[0056] The specific calculation methods for the four types of deviation indicators are as follows: ① Causal path deviation : Causal path deviation This is used to measure changes in the order of event triggering or dependency structure. The system compares the adjacency matrix of the current causal chain with that of the baseline causal chain. and Calculate based on differences: ; in, The matrix element differences, representing the number of edges in the baseline causal chain, reflect the addition or absence of causal relationships. This metric quantifies the degree of change at the structural level; when events deviate from the baseline causal chain in the system, The value increased significantly.

[0057] ② Control deviation : Control deviation Used to evaluate the magnitude deviation of command execution results. For each event pair Calculate the deviation of the control component of the current edge weight from the baseline value: ; in, The control deviation weight at the current time step. This applies when the deviation between the device's execution result and the control command increases (e.g., output value drift, response error). It will rise significantly.

[0058] ③Time drift : Time drift Used to reflect the dynamic changes in system response latency. For each event pair Define time drift: ; in, For the current transaction response delay, This is the baseline average latency. This value increases significantly when the communication network experiences congestion, periodic tasks malfunction, or the response process slows down.

[0059] ④ Cross-spatial consistency deviation : Used to measure changes in the synchronicity of electromagnetic and network events across the time and energy dimensions. Based on the synchronicity index defined above. We can obtain: ; in, This is the baseline synchronization index average. If spurious responses, signal interference, or replay attacks occur, cross-space synchronization will decrease. Significant increase.

[0060] During the baseline construction phase, the system addresses each deviation. Establish a normal distribution model: .

[0061] S107. When the score of the comprehensive anomaly scoring function is greater than the preset global anomaly judgment threshold, it is determined that an anomaly event exists.

[0062] Optionally, after S107, the method also includes: The dominant deviation factor is obtained by considering the deviation that contributes most to causal path deviation, control deviation, time drift, and cross-spatial consistency deviation.

[0063] Understandably, the system defines a global anomaly detection threshold: ; in, and The mean and variance of the comprehensive score during the normal phase are given. This is the confidence interval coefficient (usually taken as 2 to 3).

[0064] when When an abnormal event occurs, the system determines that an abnormal event exists at that moment and obtains the dominant deviation factor based on the deviation that contributes the most among the causal path deviation, control deviation, time drift, and cross-space consistency deviation. This factor may be "time delay anomaly" or "cross-space inconsistency anomaly" to enhance the interpretability of the detection results.

[0065] In the above technical solution, this invention introduces a causal chain model and a dynamic update mechanism to achieve an incremental graph structure. This enables the causal chain to be rapidly constructed and adaptively updated during real-time detection, continuously updating the causal dependencies between devices in a multi-device collaborative industrial control environment. This ensures efficient operation under resource constraints, improving the real-time performance and efficiency of the detection system. Furthermore, by employing a joint modeling method using multi-source heterogeneous data, integrating network layer feature vectors, physical feature vectors, and time-frequency domain feature vectors, and through protocol semantic parsing and causal chain modeling, the system's semantic understanding of control logic and device behavior is effectively enhanced, improving... The accuracy of anomaly detection is improved, and the interpretability of the detection results is enhanced, enabling the detection process to clearly reveal the generation mechanism and propagation law of abnormal behavior, thereby reducing the false alarm and false negative rates. To address the problems of complex multi-device causal modeling and insufficient system adaptability, a lightweight causal chain modeling and incremental graph structure framework is designed to effectively reduce computational overhead and improve system adaptability. By calculating the consistency and confidence of edge weights between devices in the causal chain in real time, the continuous updating and precise adjustment of the causal chain structure in multi-device collaboration and dynamic environments are ensured, enabling the system to efficiently and flexibly respond to different attack modes and operating condition changes in complex scenarios.

[0066] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, those skilled in the art can combine and integrate the different embodiments or examples described in this specification.

[0067] Although the invention has been described herein in conjunction with various embodiments, those skilled in the art will understand and implement other variations of the disclosed embodiments by reviewing the accompanying drawings and the disclosure in carrying out the claimed invention. In the description of the invention, the word "comprising" does not exclude other components or steps, "a" or "an" does not exclude a plurality, and "a plurality" means two or more, unless otherwise explicitly specified. Furthermore, while different embodiments may describe certain measures, this does not mean that these measures cannot be combined to produce good results.

[0068] The above description, in conjunction with specific preferred embodiments, provides a further detailed explanation of the present invention. It should not be construed that the specific implementation of the present invention is limited to these descriptions. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of the present invention, and all such modifications and substitutions should be considered within the scope of protection of the present invention.

Claims

1. An anomaly detection method for industrial control systems based on behavioral causal chains, characterized in that, The method includes: The industrial control system is subjected to network space acquisition, physical space acquisition and electromagnetic space acquisition respectively to obtain network layer feature vector, physical feature vector and time-frequency domain feature vector; The network layer feature vector, the physical feature vector, and the time-frequency domain feature vector are fused to obtain a joint feature vector. Multiple time window features at different time scales are obtained based on multiple preset time windows at different time scales and the joint feature vector; An input vector is constructed based on the joint feature vector and the time window features of multiple different time scales; The input vector is input into a pre-constructed behavioral causal chain model to obtain a causal chain; wherein, the behavioral causal chain model is constructed according to the behavioral causal chain defined in the form of a graph structure. The score of the comprehensive anomaly scoring function is calculated based on the causal chain and the benchmark causal chain; wherein the benchmark causal chain is obtained based on a pre-constructed benchmark causal chain model; the benchmark causal chain model is obtained based on the typical causal relationships of the industrial control system under steady-state conditions; An abnormal event is determined to exist when the score of the comprehensive anomaly scoring function is greater than the preset global anomaly determination threshold.

2. The industrial control system anomaly detection method based on behavioral causal chain according to claim 1, characterized in that, The process of acquiring network space, physical space, and electromagnetic space data from the industrial control system to obtain network layer feature vectors, physical feature vectors, and time-frequency domain feature vectors includes: Collect the response messages of the industrial control system and parse the response messages to obtain the operation semantics; The request and response message in the same communication channel are matched according to the timestamp to obtain the control transaction unit; The network layer feature vector is obtained based on the operational semantics, the response message, and the control transaction unit. Acquire the set of physical state variables of sensors and actuators through edge data acquisition devices; The control response delay and time consistency indicators are obtained from the control transaction unit, and the physical feature vector is obtained from the physical state variable set. The electromagnetic signal sequence generated during system operation is obtained, and the time-frequency domain feature vector of the electromagnetic signal sequence is extracted.

3. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 1, characterized in that, The joint feature vector is represented as follows: ; in, Indicates the sampling time The joint eigenvectors, Indicates the sampling time The network layer feature vectors, Indicates the sampling time The physical feature vector, Indicates the sampling time The time-frequency domain eigenvectors.

4. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 1, characterized in that, The multiple time windows with different time scales are represented as follows: ; in, This refers to the multiple time windows with different time scales. This represents a short window used to detect sudden anomalies. The middle window represents the detection period perturbation. This represents a long window for detecting latent changes.

5. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 1, characterized in that, The time window features at multiple different time scales are represented as follows: ; in, Indicates the sampling time The time window features of the multiple different time scales. Indicates the sampling time Mean shift within the window, Indicates the sampling time variance shift, Indicates the sampling time The rate of change of signal energy.

6. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 1, characterized in that, The construction process of the baseline causal chain model includes: The baseline edge weights are obtained based on the set of steady-state causal chains generated by the industrial control system within multiple steady-state time windows under steady-state conditions. Construct a baseline causal structure based on the baseline edge weights; A confidence index is defined based on the instantaneous edge weights and the baseline edge weights; The causal dependencies of the steady-state causal chain are adjusted according to the confidence index to obtain the adjusted causal dependencies; The baseline causal chain model is obtained based on the adjusted causal dependencies.

7. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 1, characterized in that, The comprehensive anomaly scoring function is expressed as follows: ; in, Indicates time The comprehensive anomaly scoring function, Causal path deviation The weighting coefficients, Represents the causal chain generated at time t. , Represents the baseline causal chain, To control the deviation The weighting coefficients, Time drift The weighting coefficients, For cross-space consistency deviation The weighting coefficients.

8. The anomaly detection method for industrial control systems based on behavioral causal chains according to claim 7, characterized in that, After determining that an abnormal event exists when the score of the comprehensive anomaly scoring function is greater than a preset global anomaly determination threshold, the method further includes: The dominant deviation factor is obtained based on the deviation that contributes most to the causal path deviation, the control deviation, the time drift, and the cross-spatial consistency deviation.