Protocol sensing type intelligent penetration testing method and device for power generation industrial control system

By constructing a protocol knowledge base and an intelligent message generation module, combined with multi-dimensional anomaly monitoring and machine learning feedback mechanisms, the problem of insufficient protocol security in power generation industrial control systems has been solved, achieving efficient vulnerability discovery and in-depth testing.

CN121814447APending Publication Date: 2026-04-07HUANENG TONGCHUAN ZHAOJIN COAL POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-13
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

The industrial control protocol of the power generation industrial control system takes real-time performance and reliability into account during the design, but it lacks security, has a large number of security vulnerabilities, and faces Internet threats. Existing testing tools have poor protocol adaptability, insufficient testing depth, and high professional threshold.

Method used

A protocol knowledge base is constructed, and a semantically aware intelligent message generation and mutation module is adopted. Combined with multi-dimensional abnormal behavior monitoring and machine learning feedback mechanisms, targeted test cases are generated and test strategies are optimized to achieve in-depth and accurate testing of the power generation industrial control system.

Benefits of technology

It significantly improves the automation level of testing and the efficiency of vulnerability discovery, reduces the reliance on the professional background of testers, and enables in-depth and accurate testing of dedicated protocols for power generation industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121814447A_ABST
    Figure CN121814447A_ABST
Patent Text Reader

Abstract

The invention provides a protocol sensing type intelligent penetration test method and device for a power generation industrial control system, and the method comprises the steps: constructing a structured knowledge base which integrates protocol stipulations and historical vulnerability information, and employing a semantic sensing intelligent message generation and directional variation technology based on the structured knowledge base. In combination with multi-dimensional abnormal behavior monitoring of target equipment and a feedback learning mechanism based on machine learning, deep and accurate testing of a special protocol of the power generation industrial control system is realized, and the core pain points of poor protocol adaptability, insufficient testing depth, high professional threshold of manual testing and limited coverage of a general fuzzy testing tool are effectively overcome; therefore, the automation degree of testing and the efficiency and depth of vulnerability discovery are remarkably improved, and meanwhile, the dependence on the professional background of testers is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cybersecurity technology for industrial control systems, and in particular to a protocol-aware intelligent penetration testing method and apparatus for power generation industrial control systems. Background Technology

[0002] Industrial control systems (ICS) and supervisory control and data acquisition systems (SCADA) in the power generation industry widely adopt dedicated industrial control protocols, such as IEC 60870-5-104, Modbus TCP, DNP3, and OPC UA, to implement key functions such as generator control, substation automation, and power dispatching. These industrial control protocols are primarily designed for real-time performance and reliability, with insufficient consideration given to security, resulting in numerous security vulnerabilities and risks.

[0003] With the advancement of "smart grid" and "digital power plant" construction, the integration of power generation control systems with information networks is deepening, leading to increasingly severe security threats from the internet. Attackers may exploit vulnerabilities in industrial control protocols to remotely control power generation equipment, tamper with operating parameters, trigger system failures, and perform other malicious operations, posing a direct threat to power safety. Summary of the Invention

[0004] The first aspect of this disclosure provides a protocol-aware intelligent penetration testing method for power generation industrial control systems, comprising the following steps: S1: Construct a protocol knowledge base, which stores the specification information of at least one power generation industrial control system communication protocol in a structured manner. The specification information includes the protocol message structure, function code definition, data unit format, and legal value range. S2: Based on the protocol knowledge base, test cases for the target industrial control equipment are generated through the semantically aware intelligent message generation and mutation module, wherein the generation process includes targeted mutation of protocol fields; S3: Send the test cases to the target industrial control equipment, and monitor the response behavior of the target industrial control equipment in real time through the abnormal behavior monitoring module; S4: Based on monitoring results, dynamically adjust the test case generation strategy through the feedback learning module to optimize testing efficiency and vulnerability discovery capabilities.

[0005] In conjunction with the first aspect, the construction of the protocol knowledge base is based on protocol specification documents published by international standards organizations, and associates known historical vulnerability patterns related to specific function codes or data fields.

[0006] In conjunction with the first aspect, the intelligent message generation and mutation module employs a syntax tree-based protocol parsing technology and applies targeted mutation strategies for different types of fields, including: Replace the function code field with an undefined or high-risk function code; Generate excessively long or negative length data for the length field; Insert boundary values ​​into a numeric field; The attack payload involves inserting a format string into a string field.

[0007] In conjunction with the first aspect, the indicators monitored by the abnormal behavior monitoring module include at least one of the following: protocol response content, network connection status, system resource consumption, and service function performance.

[0008] In conjunction with the first aspect, the feedback learning module uses machine learning algorithms to analyze the correlation between test cases and abnormal behaviors, and adjusts subsequent mutation strategies accordingly.

[0009] A second aspect of this disclosure provides a protocol-aware intelligent penetration testing device, the device comprising: The protocol knowledge base module is used to store the specification information of the power generation industrial control system protocol; The intelligent message generation and mutation module is used to generate semantically aware test cases based on the protocol knowledge base. The abnormal behavior monitoring module is used to monitor abnormal responses of the target industrial control equipment; The feedback learning module is used to optimize test case generation strategies based on monitoring results.

[0010] In conjunction with the second aspect, the data structure of the protocol knowledge base module is configured to support the parsing and querying of protocol message structures, function code definitions, and data cell formats.

[0011] In conjunction with the second aspect, the intelligent message generation and mutation module is further configured to perform protocol syntax tree-based parsing and field-level targeted mutation, and the feedback learning module is further configured to dynamically optimize the test strategy through a machine learning model.

[0012] A third aspect of this disclosure provides an electronic device comprising: One or more processors; A storage unit is used to store one or more programs, which, when executed by one or more processors, enable the one or more processors to implement the protocol-aware intelligent penetration testing method for power generation industrial control systems.

[0013] A fourth aspect of this disclosure provides a computer-readable storage medium having a computer program stored thereon, characterized in that the computer program, when executed by a processor, can implement the protocol-aware intelligent penetration testing method for power generation control systems.

[0014] Beneficial Effects: This disclosure provides a protocol-aware intelligent penetration testing method and device for power generation industrial control systems. By constructing a structured knowledge base integrating protocol specifications and historical vulnerability information, and based on this, employing semantic-aware intelligent message generation and targeted mutation technology, combined with multi-dimensional abnormal behavior monitoring of target devices and a machine learning-based feedback learning mechanism, it achieves in-depth and accurate testing of dedicated protocols for power generation industrial control systems. This effectively overcomes the core pain points of general fuzzing tools, such as poor protocol adaptability and insufficient testing depth, as well as the high professional threshold and limited coverage of manual testing. Thus, it significantly improves the automation level of testing, the efficiency and depth of vulnerability discovery, and greatly reduces the dependence on the professional background of testers. Attached Figure Description

[0015] Figure 1 This is a flowchart illustrating a protocol-aware intelligent penetration testing method for power generation industrial control systems, according to an embodiment of this disclosure. Figure 2 This is a schematic diagram of the structure of a protocol-aware intelligent penetration testing device for power generation industrial control systems according to an embodiment of this disclosure; Figure 3 An electronic device according to an embodiment of this disclosure. Detailed Implementation

[0016] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those disclosed herein.

[0017] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. The singular forms “a,” “the,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0018] Figure 1 This is a flowchart illustrating a protocol-aware intelligent penetration testing method for power generation industrial control systems according to an embodiment of the present disclosure, including: S1: Construct a protocol knowledge base, which stores the specification information of at least one power generation industrial control system communication protocol in a structured manner. The specification information includes the protocol message structure, function code definition, data unit format, and legal value range. The protocol knowledge base is constructed based on protocol specification documents published by international standards organizations and associated with known historical vulnerability patterns related to specific function codes or data fields.

[0019] Specifically, based on official protocol specification documents published by standards organizations such as the International Electrotechnical Commission (IEC), the protocol rules described in these documents are structured, parsed, and stored using manual or automated scripts. For example, for the IEC 104 protocol, the knowledge base accurately records its message header length, APCI and ASDU structure, the data unit format corresponding to each type identifier (e.g., 45H represents single-point remote control), and the legal value range of each data field (e.g., 1 = split, 2 = combined). Furthermore, this knowledge base is linked to public vulnerability databases such as CVE, mapping known vulnerabilities to specific protocol function codes or fields, thus forming a comprehensive information database containing both protocol "syntactic" and "semantic" risks, providing precise targeted guidance for subsequent intelligent generation of test cases.

[0020] Furthermore, the protocol knowledge base adopts a hybrid storage architecture, specifically including: Relational database tables are used to store basic metadata of protocols, such as protocol name, version, standards publishing organization, and message infrastructure description. For example, a table structure for the Modbus TCP protocol might include fields such as Function_Code, Data_Unit_Type, Field_Name, Field_Type (e.g., UINT16, STRING), Min_Value, Max_Value (range of valid values), and Description (semantic description of the field).

[0021] Graph databases (Neo4j or similar): used to build a network of relationships between protocol elements and vulnerabilities. Node types include Protocol, FunctionCode, DataField, and Vulnerability (attributes include CVE-ID, CVSS score, and vulnerability type). Relationship types include HAS_FUNCTION (the protocol owns the function code), HAS_FIELD (the function code contains the field), and AFFECTS (the vulnerability affects a specific function code or field). This graph structure facilitates efficient queries of "which known vulnerabilities exist for a given function code" or "which protocol fields are affected by a given vulnerability."

[0022] Rule Engine Integration: The knowledge base has a built-in lightweight rule engine (such as Drools) for storing complex test heuristics based on expert experience. For example, a rule can be defined as: "IF Protocol == IEC 104 AND Function Code == 0x64 (Dual Point Remote Control) AND Field == QU (Qualifier) ​​THEN Recommended Mutation Strategy: Insert value 0x03 (Reserved Value) or 0xFF".

[0023] S2: Based on the protocol knowledge base, test cases for the target industrial control equipment are generated through the semantically aware intelligent message generation and mutation module, wherein the generation process includes targeted mutation of protocol fields; The intelligent message generation and mutation module employs a syntax tree-based protocol parsing technology and applies targeted mutation strategies for different types of fields, including: Replace the function code field with an undefined or high-risk function code; Generate excessively long or negative length data for the length field; Insert boundary values ​​into a numeric field; The attack payload involves inserting a format string into a string field.

[0024] Specifically, a protocol knowledge base built using S1 drives an intelligent message generation and mutation engine. This engine first uses syntax tree-based parsing technology to decompose the protocol message to be tested into a tree structure, with the root node representing the entire message and child nodes representing various fields (such as function codes, lengths, and data values). During mutation, instead of blindly and randomly flipping bits, a pre-defined targeted mutation strategy is applied based on the semantics of each field in the protocol. For example, for the "function code" field, the engine retrieves a list of all defined and undefined function codes from the knowledge base, prioritizing the replacement of undefined function codes or those known to be associated with high-risk operations (such as remote write commands). For the "length" field, it intentionally generates excessively long data or negative numbers exceeding the protocol's maximum value to trigger buffer overflows or logical errors. For numeric data fields, it systematically inserts boundary values ​​such as maximum, minimum, and zero. For string fields, it attempts to insert formatted strings (such as %s%s) and other attack payloads. This method ensures that the generated test cases both conform to the basic framework of the protocol and accurately target its vulnerable points.

[0025] Furthermore, the workflow and algorithm details of the intelligent message generation and mutation engine are as follows: Syntax Tree Construction Algorithm: The engine receives an initial message template that conforms to the specification (e.g., a valid IEC 104 general call command). Based on the ASN.1 description of the protocol in the knowledge base or a custom protocol description language (such as an XML-based protocol description file), it uses recursive descent parsing or the Earley parser to parse the message byte stream into an Abstract Syntax Tree (AST). Non-leaf nodes of the tree represent composite structures (such as APDU, ASDU), and leaf nodes represent basic fields (such as TypeId, COT, Address).

[0026] Mutation Policy Scheduler: It iterates through each leaf node of the AST, and based on its Field_Type and the associated vulnerability information retrieved from the knowledge base graph database, calls the corresponding mutation operator. The operator library includes: Enumeration Replacement Operator: For enumeration type fields such as function codes, retrieve all enumeration values ​​from the knowledge base and prioritize the replacement of undefined values, reserved values, or values ​​related to "write operation" or "system control".

[0027] Numeric boundary operators: For integer and floating-point number fields, generate values ​​such as MIN-1, MIN, MAX, MAX+1, 0, and -1. For signed length fields, additional negative values ​​(such as -1) are generated.

[0028] Buffer overflow operator: Generates data that far exceeds the defined length of a length field or the maximum allowed length of a message for a length or string field. For example, it generates a value of 65536 for the Modbus Quantity of Registers field (which exceeds the protocol-defined range of 1-125).

[0029] Format string operator: For string fields, insert format characters such as %n, %s, %x, etc., and combine them to generate attack payloads such as "%s%s%s" or long strings of "%n".

[0030] Timing and state mutation operators: generate message sequences that violate protocol state machine rules, such as sending application data before an application connection is established, or sending two consecutive "startup messages".

[0031] Test case encoding: The mutated AST is serialized back into a byte stream that conforms to the target protocol encoding rules (such as big-endian, BER encoding) to form a complete test case.

[0032] S3: Send the test cases to the target industrial control equipment, and monitor the response behavior of the target industrial control equipment in real time through the abnormal behavior monitoring module; The abnormal behavior monitoring module monitors at least one of the following indicators: protocol response content, network connection status, system resource consumption, and service function performance.

[0033] This is accomplished through a comprehensive abnormal behavior monitoring module. When the test cases generated by S2 are sent to the target industrial control equipment (such as a PLC or RTU), this monitoring module starts simultaneously, monitoring the equipment's response from multiple dimensions. It not only checks whether the protocol response messages returned by the equipment are abnormal (e.g., returning non-compliant responses, error codes, or no response at all), but also monitors the underlying network connection status (e.g., whether the connection is interrupted or reset), and the equipment's system-level metrics (e.g., whether CPU / memory usage spikes abnormally, or whether processes crash). More importantly, it works in conjunction with the industrial control system's monitoring interface (such as a SCADA human-machine interface) to observe whether the business functions of the tested equipment are affected, such as whether unexpected relay actions or telemetry data jumps occur. This multi-dimensional monitoring ensures that various deep-seated faults, from the protocol stack to the business logic, can be captured.

[0034] Furthermore, the specific implementation and monitoring rules of the abnormal behavior monitoring module are as follows: Protocol layer probe: The response parser parses the messages returned by the device in real time. The exception judgment rules include: a) response timeout (exceeding the protocol specification or preset threshold, such as 3 seconds); b) abnormal response code (such as Modbus exception function code 0x80 + original function code); c) incorrect response message structure (such as the length field does not match the actual length, CRC check error but is accepted by the device); d) abnormal response data (such as reading coil returning all 0xFF).

[0035] Protocol state machine monitors track session states (such as STARTDT and STOPDT states in IEC 104) and detects illegal state transitions.

[0036] System-level probes: Network traffic analysis captures all traffic entering and leaving the target device through port mirroring or proxies. It monitors connection interruptions (TCP RST), abnormal retransmissions, and sudden drops or surges in traffic.

[0037] Resource consumption monitoring: If the test environment allows (e.g., the device has a lightweight agent or supports SNMP), collect the device's CPU usage, memory consumption, and process list. Set a threshold (e.g., CPU continuously >95% for 10 seconds), and mark it as abnormal if exceeded.

[0038] Business layer probe: The SCADA / HMI interface listener reads key status values ​​from the monitoring system's interface via API or screen image analysis (OCR technology). For example, after sending a malformed "close" command, it monitors whether the circuit breaker status actually changes to "close," or whether related telemetry values ​​(such as current) undergo unexpected jumps.

[0039] Physical signal monitoring (in a closed-loop testbed) involves monitoring signal changes at the actual output terminals of the device using digital / analog input cards to verify whether the logic output is abnormal.

[0040] Association Analysis Engine: Receive data from all probes and perform correlation analysis using a rule engine. For example, a rule could be: "IF (protocol response timeout == TRUE) AND (network connection status == DISCONNECTED) AND (SCADA communication status == FAILED) THEN Anomaly level = CRITICAL, vulnerability type suspected = Denial of service (DoS)".

[0041] S4: Based on monitoring results, dynamically adjust the test case generation strategy through the feedback learning module to optimize testing efficiency and vulnerability discovery capabilities.

[0042] The feedback learning module uses machine learning algorithms to analyze the correlation between test cases and abnormal behavior, and adjusts subsequent mutation strategies accordingly.

[0043] Specifically, the "test case-monitoring result" data pairs recorded in step S3 are continuously collected, and machine learning algorithms (such as classification, regression, or reinforcement learning algorithms) are used to analyze and model this data. Through analysis, the model can learn which types of mutation strategies (e.g., mutations targeting the length field of a specific function code) are more likely to cause specific types of anomalies (e.g., process crashes), thereby identifying the most effective test vectors. Subsequently, this module dynamically adjusts the strategies and parameters for generating test cases in step S2, for example, increasing the selection probability of mutation types that have successfully triggered anomalies, or using new mutation combinations on specific fields. In this way, the entire testing system is no longer static and blind, but can continuously self-optimize as testing progresses, focusing computational resources on testing directions that are more likely to discover vulnerabilities, thereby continuously improving the efficiency and depth of testing.

[0044] Furthermore, the specific learning mechanism and optimization process of the feedback learning module are as follows: Feature engineering: Each test case is represented as a feature vector, with features including: protocol type, target function code, path of the mutated field (e.g., / APDU / ASDU / IOA), application mutation operator ID, and specific value of the injected mutation. Each monitoring result is represented as a label vector, including: whether an exception was triggered (Boolean value), exception type (e.g., protocol error, connection interruption, business exception), and exception severity level.

[0045] Model training and online learning: In the initial stage (cold start), prior weights generated based on historical vulnerability patterns in the knowledge base are used to assign initial probabilities to different mutation operators.

[0046] During the online learning phase, reinforcement learning models such as Contextual Bandit or Deep Q-Network (DQN) are employed. The testing environment is treated as a state space (including features of tested test cases and historical anomaly distribution), the selection of mutation policies is considered an action, and the severity of triggering anomalies (e.g., mapped according to CVSS baseline scores) is considered a reward. The model optimizes policy selection by continuously exploring (trying new policies) and leveraging (selecting historically high-reward policies).

[0047] Supervised learning is used to assist in training a Gradient Boosting Decision Tree (GBDT) classification model using the collected (feature, label) data. This model is then used to directly predict the probability that a particular test case might trigger an anomaly. The predictions from this model can be used as a priori for reinforcement learning models or to select batches of high-potential test cases.

[0048] Dynamic strategy adjustment: The learning model periodically (e.g., after every 1000 test cases) outputs policy update suggestions to the intelligent message generation and mutation module. The updates include: a) adjusting the selection probability distribution of each mutation operator; b) providing policy updates for specific "protocols". function code The "field" combination recommends new, model-generated variant values ​​(e.g., generating special message sequences that can cause state machine chaos through generative adversarial networks (GANs)); c) adjust the sending rate or order of test cases.

[0049] like Figure 2 The diagram shown is a schematic representation of a protocol-aware intelligent penetration testing device for power generation industrial control systems according to an embodiment of this disclosure, comprising: Protocol knowledge base module 210 is used to store the specification information of the power generation industrial control system protocol; The data structure of the protocol knowledge base module 210 is configured to support the parsing and querying of protocol message structures, function code definitions, and data cell formats.

[0050] The protocol knowledge base module 210 is the core data support of the device, specifically implemented as a structured database (such as a relational database or graph database). It internally contains sub-components such as a protocol parser, a protocol storage unit, and a vulnerability association engine. The protocol parser is responsible for processing the original protocol specification documents obtained from international standards organizations (such as the official standard text of IEC 60870-5-104), converting the natural language descriptions into machine-readable structured data through parsing. This data is stored in the protocol storage unit, forming a precise description of the protocol message structure, function code enumeration, data unit types, and the range of legal field values. For example, it explicitly records that "in the single-point remote control command (C_SC_NA_1) of the IEC 104 protocol, bits 0-1 of the QU field represent the execution qualifier, and the legal values ​​are 0-2." Meanwhile, the vulnerability association engine crawls known vulnerability information related to specific industrial control protocols from public vulnerability databases (such as CVE and NVD) and accurately maps it to the corresponding function codes or data fields in the knowledge base, thereby forming an intelligent knowledge system that includes both protocol "syntax" and "security semantics".

[0051] The intelligent message generation and mutation module 220 is used to generate semantically aware test cases based on the protocol knowledge base; The intelligent message generation and mutation module 220 is further configured to perform protocol syntax tree-based parsing and field-level targeted mutation, and the feedback learning module 240 is further configured to dynamically optimize the test strategy through a machine learning model.

[0052] This module is a message factory integrating a protocol syntax tree parser and a targeted mutation strategy engine. When test cases need to be generated, this module first retrieves the specification information of the target protocol from the protocol knowledge base module 210. Based on this specification, the syntax tree parser constructs a syntax tree in memory from a valid protocol message template. Each node in the tree corresponds to a field in the message (such as message header, function code, data length, data value, etc.). Subsequently, the targeted mutation strategy engine traverses this syntax tree and, based on the field type and semantics of each node, calls the corresponding strategy from a series of pre-built mutation algorithm libraries targeting the vulnerability characteristics of industrial control protocols. For example, for the "function code" node, it calls the "undefined code replacement algorithm"; for the "length field" node, it calls the "boundary overflow generation algorithm"; and for the "integer field" node, it calls the "extreme value insertion algorithm." This strategy scheduling based on syntax trees and semantics ensures that each generated malformed message is "targeted," passing the basic format verification of the protocol while precisely impacting the most vulnerable logical components of the protocol stack implementation.

[0053] Abnormal behavior monitoring module 230 is used to monitor abnormal responses of target industrial control equipment; This module is a comprehensive data acquisition and correlation analysis platform. It consists of multiple probes working collaboratively: the network protocol probe captures and analyzes the raw messages returned by the target device, checking their compliance with protocol specifications (e.g., whether the response type matches, whether the timing is abnormal); the system status probe monitors network connections (e.g., whether TCP connections are reset) and (where possible) obtains system logs and resource monitor data from the device to determine if there are process crashes, memory leaks, or abnormal spikes in CPU usage; the business logic probe interacts with the upper-level SCADA system or simulation test platform to monitor whether key business function indicators deviate, such as whether a remote control command caused an unexpected circuit breaker trip. All the multi-dimensional data collected by these probes is aggregated in real-time into a correlation analysis engine. This engine uses preset rules (e.g., "after receiving a malformed message, the device has no protocol response and SCADA shows a communication interruption") to comprehensively determine whether a test truly triggered valid "abnormal behavior," thus effectively filtering out meaningless noise interference.

[0054] Feedback learning module 240 is used to optimize test case generation strategies based on monitoring results.

[0055] This module is a data-driven optimizer based on machine learning. Internally, it maintains a test case library, continuously recording the characteristics of each test case from module 220 (e.g., "extreme value mutation of the QU field in the IEC 104 protocol single-point remote control command") and the corresponding monitoring results from module 230 (e.g., "target device service function abnormal, remote control execution failed"). This data is used as training samples and input into a machine learning model (e.g., using decision trees to identify feature combinations of effective mutations, or using reinforcement learning to build a "state-action-reward" model). Through offline training or online learning, the model gradually discovers potential correlation patterns between test case characteristics and triggering anomalies. Finally, based on the learned patterns, this module dynamically outputs optimization strategies to the intelligent message generation and mutation module 220, such as: "For the current test target, increase the boundary value mutation weight for enumeration type fields and decrease the random mutation weight for string fields." Through this closed-loop feedback, the entire device can rapidly evolve from a "broad-net" initial testing stage to a "precise-fishing" deep testing stage, thereby achieving self-evolution in testing efficiency and depth.

[0056] Electronic device 300 can be a desktop computer, laptop, handheld computer, cloud server, or other electronic device. Electronic device 300 may include, but is not limited to, processor 301 and memory 302. Those skilled in the art will understand that... Figure 3This is merely an example of electronic device 300 and does not constitute a limitation on electronic device 300. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device may also include input / output devices, network access devices, buses, etc.

[0057] Processor 301 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0058] The memory 302 can be an internal storage unit of the electronic device 300, such as a hard disk or RAM of the electronic device 300. The memory 302 can also be an external storage device of the electronic device 300, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the electronic device 300. Furthermore, the memory 302 can include both internal and external storage units of the electronic device 300. The memory 302 is used to store the computer program 303 and other programs and data required by the electronic device. The memory 302 can also be used to temporarily store data that has been output or will be output.

[0059] The above embodiments are only used to illustrate the technical solutions of this disclosure, and are not intended to limit it. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this disclosure, and should all be included within the protection scope of this disclosure.

Claims

1. A protocol-aware intelligent penetration testing method for power generation industrial control systems, characterized in that, Includes the following steps: A protocol knowledge base is constructed, wherein the protocol knowledge base stores the specification information of at least one power generation industrial control system communication protocol in a structured manner, and the specification information includes the protocol message structure, function code definition, data unit format and legal value range; Based on the protocol knowledge base, test cases for the target industrial control equipment are generated through a semantically aware intelligent message generation and mutation module, wherein the generation process includes targeted mutation of protocol fields; The test cases are sent to the target industrial control equipment, and the response behavior of the target industrial control equipment is monitored in real time through the abnormal behavior monitoring module. Based on the monitoring results, the test case generation strategy is dynamically adjusted through the feedback learning module to optimize testing efficiency and vulnerability discovery capabilities.

2. The method according to claim 1, characterized in that, The protocol knowledge base is constructed based on protocol specification documents published by international standards organizations and associated with known historical vulnerability patterns related to specific function codes or data fields.

3. The method according to claim 1, characterized in that, The intelligent message generation and mutation module employs a syntax tree-based protocol parsing technology and applies targeted mutation strategies for different types of fields, including: Replace the function code field with an undefined or high-risk function code; Generate excessively long or negative length data for the length field; Insert boundary values ​​into a numeric field; The attack payload involves inserting a format string into a string field.

4. The method according to claim 1, characterized in that, The abnormal behavior monitoring module monitors at least one of the following indicators: protocol response content, network connection status, system resource consumption, and service function performance.

5. The method according to claim 1, characterized in that, The feedback learning module uses machine learning algorithms to analyze the correlation between test cases and abnormal behavior, and adjusts subsequent mutation strategies accordingly.

6. A protocol-aware intelligent penetration testing device for implementing the method of any one of claims 1-5, characterized in that, include: The protocol knowledge base module is used to store the specification information of the power generation industrial control system protocol; The intelligent message generation and mutation module is used to generate semantically aware test cases based on the protocol knowledge base. The abnormal behavior monitoring module is used to monitor abnormal responses of the target industrial control equipment; The feedback learning module is used to optimize test case generation strategies based on monitoring results.

7. The apparatus according to claim 6, characterized in that, The data structure of the protocol knowledge base module is configured to support the parsing and querying of protocol message structures, function code definitions, and data cell formats.

8. The apparatus according to claim 6, characterized in that, The intelligent message generation and mutation module is further configured to perform protocol syntax tree-based parsing and field-level targeted mutation, and the feedback learning module is further configured to dynamically optimize the test strategy through a machine learning model.

9. An electronic device, characterized in that, include: One or more processors; A storage unit is used to store one or more programs, which, when executed by one or more processors, enable the one or more processors to implement the protocol-aware intelligent penetration testing method for power generation industrial control systems.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it can implement the protocol-aware intelligent penetration testing method for power generation industrial control systems.