Industrial equipment electromagnetic radiation covert communication detection data processing method
By constructing interference source coefficients and adjustment factors to adaptively adjust the detection benchmark threshold, the problem of high false judgment rate in the detection of covert communication electromagnetic radiation of industrial equipment is solved, and accurate detection in complex industrial environments is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-10
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies have a high false alarm rate in detecting covert electromagnetic radiation from industrial equipment and are unable to cope with the complex and ever-changing electromagnetic environment in industrial scenarios.
By acquiring the electromagnetic intensity, noise intensity, temperature, humidity, and equipment operating power and distance of the detection area, an interference source coefficient is constructed. An adjustment factor is calculated using environmental and monitoring data to adaptively adjust the detection benchmark threshold and reduce the false judgment rate.
It enables accurate detection of covert electromagnetic radiation communication in complex industrial environments, reduces the false alarm rate, and provides a more reliable detection basis.
Smart Images

Figure CN121815269A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication data processing technology, and in particular to a method for processing data related to covert electromagnetic radiation detection of industrial equipment. Background Technology
[0002] Covert electromagnetic radiation communication in industrial equipment is a communication method that utilizes the electromagnetic radiation generated by industrial equipment during normal operation as a carrier to achieve covert information transmission through specific technical means. Statistics show that global industrial control systems suffer over 120,000 electromagnetic interference attacks daily. Attackers may use covert communication techniques to steal industrial data or tamper with control commands. Therefore, effective and accurate data processing of electromagnetic radiation data generated by industrial equipment during normal operation is crucial for detecting covert electromagnetic radiation communication in industrial equipment.
[0003] Traditional methods for detecting covert communication via electromagnetic radiation from industrial equipment use energy detection based on RSSI (Received Signal Strength Indication). This method is simple to implement, low in cost, has low computational complexity, and is highly real-time. However, industrial environments are characterized by diverse equipment and strong environmental interference. Equipment start-up and shutdown, power changes, and alterations in environmental conditions all lead to changes in electromagnetic radiation in industrial settings. These changes occur frequently in industrial environments. Since energy detection algorithms use a single threshold for covert communication detection, they are prone to misjudging covert communication even when electromagnetic radiation conditions change, rather than when covert communication actually occurs. This results in a misjudgment rate as high as 47% in the complex and variable electromagnetic environment of industrial settings, making it difficult to cope with the complex and ever-changing electromagnetic radiation from industrial equipment.
[0004] Therefore, how to adaptively adjust and process electromagnetic radiation data during the operation of industrial equipment, so as to provide a reliable basis for more accurate detection of covert communication, has become a technical problem that urgently needs to be solved. Summary of the Invention
[0005] In view of this, the present invention provides a data processing method for detecting covert communication electromagnetic radiation of industrial equipment, in order to solve the technical problem that the current data processing method for electromagnetic radiation generated during the operation of industrial equipment is not reasonable enough, resulting in a high misjudgment rate for detecting covert communication electromagnetic radiation of industrial equipment.
[0006] The present invention provides a method for processing data related to covert communication detection of electromagnetic radiation from industrial equipment, comprising:
[0007] The electromagnetic intensity, noise intensity, temperature, humidity, and operating power of each device outside the detection area and its distance from the detection area are obtained. An interference source coefficient that is directly proportional to the operating power of each device and inversely proportional to the distance from the detection area is constructed. Temperature, humidity, and interference source coefficient are used as environmental data, and environmental data, electromagnetic intensity value, and noise intensity value are used as monitoring data.
[0008] Based on the similarity of the time series of noise intensity with the time series of each type of environmental data in historical monitoring data, the relative impact weight of each type of environmental data on noise is determined.
[0009] The analysis period is defined as the first time interval before the current moment. The analysis period is divided into sub-analysis segments by the standard deviation of electromagnetic intensity within the analysis period. The mean of each environmental data in the sub-analysis segment with the most stable electromagnetic intensity change is used as the benchmark value of the corresponding environmental data. The absolute value of the difference between the measured value of each environmental data and the benchmark value at the current moment is calculated. The adjustment factor is determined based on the absolute value of each difference and the relative influence weight.
[0010] The adaptive detection benchmark for completing the detection of covert electromagnetic radiation communication at the current moment is determined based on the adjustment factor.
[0011] Furthermore, the construction of the interference source coefficient, which is directly proportional to the operating power of each device and inversely proportional to the distance from the detection area, includes:
[0012] At any given moment, calculate the product of the reciprocal of the distance from any device outside the detection area to the monitoring area and the operating power of that device, and use the sum of all products as the interference source coefficient at that given moment.
[0013] Furthermore, determining the relative impact weight of each environmental data on noise based on the sequence variation similarity between the noise intensity time series and the time series of each environmental data includes:
[0014] The historical monitoring data is divided into a corresponding number of time periods using the second duration as the dividing length. The similarity between the noise data and each type of environmental data in each time period is determined. The time period with the highest similarity between the noise data and the current environmental data is selected from all time periods, and the monitoring data corresponding to all selected time periods are recorded as the weighted analysis dataset of the current environmental data. The relative influence weight of the current environmental data on noise is determined based on the weighted analysis dataset of the current environmental data.
[0015] Furthermore, determining the relative impact weight of the current environmental data on noise based on the weighted analysis dataset of the current environmental data includes:
[0016] Calculate the average noise intensity for each time period, take the time period with the lowest average noise intensity as the reference time period, calculate the average of each environmental data within the reference time period, take the average of each environmental data as the lower limit of the corresponding environmental data, and take the average noise intensity of the reference time period as the lower limit of the noise intensity.
[0017] In the weighted analysis dataset of the current environmental data, the difference between the measured value of the current environmental data and the lower limit value of the current environmental data at each time point is recorded as the first difference. The difference between the measured value of the noise intensity and the lower limit value of the noise intensity at each time point is recorded as the second difference. A coordinate graph of the current environmental data is constructed with the first difference as the x-axis and the second difference as the y-axis. A straight line is fitted to the coordinate graph of the current environmental data and the absolute value of the slope of the fitted line is determined. The ratio of the absolute value of the slope corresponding to the current environmental data to the sum of the absolute values of the slope corresponding to all environmental data is used as the relative influence weight of the current environmental data on the noise.
[0018] Furthermore, the step of dividing the analysis period into sub-analysis segments based on the standard deviation of electromagnetic intensity within the analysis period includes:
[0019] Calculate the change in electromagnetic intensity between any two adjacent moments within the analysis period, and divide the two adjacent moments whose change value is greater than the standard deviation of electromagnetic intensity within the analysis period into different sub-analysis segments.
[0020] Furthermore, the sub-analysis segment with the most stable electromagnetic intensity variation was identified, including:
[0021] Calculate the difference coefficient of the electromagnetic intensity time series within any sub-analysis segment. The ratio of the duration of any sub-analysis segment to the difference coefficient corresponding to that sub-analysis segment is taken as the stable value of the change of that sub-analysis segment. The sub-analysis segment with the largest stable value is taken as the sub-analysis segment with the most stable change in electromagnetic intensity.
[0022] Furthermore, the regulating factor is:
[0023] ,
[0024] in, Indicates the regulating factor. This represents the relative impact weight of the j-th type of environmental data on noise. This represents the measured value of the j-th type of environmental data. This represents the baseline value for the j-th type of environmental data. Indicates the number of types of environmental data. This indicates normalization.
[0025] Furthermore, based on the adjustment factor, an adaptive detection benchmark is determined to complete the detection of covert electromagnetic radiation communication at the current moment, including:
[0026] The upper and lower limits of the baseline model for the analysis period are adjusted according to the adjustment factor to obtain the corrected threshold range, and the corrected threshold range is used as the adaptive detection benchmark for completing the detection of electromagnetic radiation covert communication at the current moment.
[0027] Furthermore, the threshold upper and lower limits of the baseline model for the analysis period adjusted according to the adjustment factor include:
[0028] The upper limit of the threshold of the baseline model for the analysis period is increased by the adjustment factor, and the lower limit of the threshold of the baseline model for the analysis period is decreased by the adjustment factor.
[0029] The advantages of this invention compared to the prior art are:
[0030] This invention first compares the similarity between the changes in each type of environmental data and the changes in noise data to determine the relative impact weight of each type of environmental data on noise. Then, it selects recent data and determines the stable change period based on the electromagnetic intensity values of the recent data. Using the environmental data under the stable change period as the benchmark reference data, it compares the deviation of the current environmental data with the benchmark reference data and determines the adjustment factor based on the relative impact weight of each type of environmental data on noise. Then, based on the adjustment factor, it determines an adaptive detection threshold for detecting covert communication using electromagnetic radiation. The corrected threshold range can effectively eliminate the impact of noise changes caused by fluctuations in the current environmental state relative to the recent stable environmental state on the electromagnetic intensity signal detection quantity. This avoids false detection of covert communication in cases where the current environmental state fluctuates rather than actually having covert communication. Finally, through the improvement of the processing method for electromagnetic radiation data generated by the operation of industrial equipment, it provides a benchmark for more accurate detection of covert communication in industrial scenarios. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a flowchart illustrating a method for processing electromagnetic radiation covert communication detection data of industrial equipment, provided in Embodiment 1 of the present invention. Detailed Implementation
[0033] The overall concept of this invention is as follows:
[0034] This invention first compares the similarity between the changes in various environmental data sequences and the changes in noise intensity sequences within the entire historical monitoring data range to determine the relative impact weight of each environmental data on noise. Then, it selects a recent period backward from the current moment as the analysis period with a first duration of a smaller value. The values of each environmental data under the stable change sub-period of electromagnetic intensity within the analysis period are taken as the environmental values of the detection area under the recent stable state. Based on the deviation between the measured values of each environmental data at the current moment and the environmental values under the recent stable state, as well as the relative impact weight of each environmental data on noise, an adjustment factor applicable to the current moment is determined. The threshold range of the baseline model corresponding to the analysis period is widened and adjusted using the adjustment factor, so that the corrected threshold range includes the change corresponding to the fluctuation of the environmental state at the current moment relative to the stable environmental state of the recent period. This results in an appropriately processed adaptive detection benchmark. This improvement in the processing method of electromagnetic radiation data generated by industrial equipment operation avoids false detection of covert communication in cases where the environmental state fluctuates at the current moment rather than actually having covert communication. This provides an accurate basis for improving the accuracy of covert communication detection in industrial scenarios.
[0035] To further illustrate the technical solution of the present invention, specific embodiments are described below.
[0036] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of the invention include a particular feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. Furthermore, a particular feature, structure, or characteristic in one or more embodiments may be combined in any suitable form, and the terms "comprising," "including," "having," and variations thereof mean "including, but not limited to," unless otherwise specifically emphasized.
[0037] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0038] Method Implementation Examples:
[0039] See Figure 1 This is a flowchart illustrating a method for processing electromagnetic radiation covert communication detection data in industrial equipment, as provided in Embodiment 1 of the present invention. Figure 1 As shown, the method may include the following steps:
[0040] S101, acquire the electromagnetic intensity, noise intensity, temperature, humidity of the detection area, as well as the operating power of each device outside the detection area and the distance from the detection area, construct the interference source coefficient which is directly proportional to the operating power of each device and inversely proportional to the distance from the detection area, use temperature, humidity and interference source coefficient as environmental data, and use environmental data, electromagnetic intensity value and noise intensity value as monitoring data.
[0041] The detection of covert electromagnetic radiation in industrial environments requires first defining the detection area. This area can be the area where a class of devices works or the area where a single device works, and can be set by the operator according to the actual situation.
[0042] In the prior art, the method for detecting covert communication signals based on the energy detection method of RSSI (Received Signal Strength Indication) is to determine whether the detected signal strength deviates from the current corresponding baseline model threshold. However, as described in the overall concept of this application above, this application aims to determine the fluctuation of environmental noise that interferes with electromagnetic strength and adjust the threshold of the baseline model accordingly. Therefore, it is clear that the adjustment factor obtained in this application is adjusted around the baseline model.
[0043] Electromagnetic radiation in industrial environments mainly originates from various industrial equipment. The magnitude of electromagnetic radiation is affected by environmental noise, which is determined by the temperature and humidity in the industrial environment, as well as the operating power and distance of other equipment outside the detection area. Therefore, when using RSSI sensors to acquire electromagnetic signal strength, noise interference often causes the actual detected electromagnetic signal to deviate from the baseline model due to the influence of noise signals, resulting in false detections.
[0044] Therefore, based on the detection area, this embodiment acquires the electromagnetic intensity, noise intensity, temperature, and humidity of the detection area at a set sampling interval, while simultaneously acquiring the operating power and distance of other devices outside the detection area. The sampling interval can be set according to the actual industrial environment, such as several times per second. Electromagnetic intensity is preferably obtained by acquiring the average intensity fluctuation of electromagnetic signals at different locations within the detection area using an RSSI sensor. Noise intensity is acquired using a spectrum analyzer. By acquiring noise signals at different time periods using the spectrum analyzer, if the signal exhibits a continuous but irregular distribution on the spectrum, or covers the entire frequency band but lacks obvious frequency components, it can be identified as noise. The noise signal intensity is obtained through the noise measurement functions of the spectrum analyzer, such as noise marking and noise power density measurement. Specifically, the noise power density unit is converted from dBm / Hz to W / Hz, the total power is calculated by integration, and then converted back to dBm to obtain the noise intensity, where dBm represents signal strength and Hz represents bandwidth frequency. An infrared thermal imager and a humidity detector are placed at fixed locations within the detection area to acquire ambient temperature and humidity, respectively. Use a power analyzer to obtain the operating power of each device outside the detection area. Record the distance of each device from the center point of the detection area as the distance of each device from the detection area. This distance value can be obtained by consulting the factory equipment distribution manual or by direct measurement.
[0045] Since the overall size of an industrial setting is limited, and it is impossible to inspect an unlimited number of peripheral devices, the devices outside the inspection area can be determined by the type or operating power of other devices around the inspection area. High-power devices, such as industrial radios and high-power WiFi access points, have a wide signal coverage; low-power devices, such as Bluetooth beacons and Zigbee sensors, have fast signal attenuation and usually only affect RSSI values at close range (e.g., within a few meters). Therefore, the range of devices outside the inspection area can be limited according to their power levels. For example, if the remaining devices are mainly low-power devices, the maximum range can be limited to 10 meters, and if they are high-power devices, the maximum range can be limited to 20 meters.
[0046] In this embodiment, considering that the noise impact of other devices outside the detection area on the detection area is determined by their operating power and distance from the detection area, the operating power and distance from the detection area of other devices outside the detection area are calculated together to form the interference source coefficient:
[0047]
[0048] in, This represents the interference source coefficient at time t. This represents the operating power of the i-th device outside the detection area. This represents the distance of the i-th device outside the detection area from the center of the detection area, and N represents the number of devices outside the area. A higher operating power and a closer proximity to the detection area indicate greater interference intensity from that device, and thus a larger interference source coefficient.
[0049] By reconstructing the operating power of each device outside the detection area and its distance from the detection area into interference source coefficients, the types of current environmental data can be redefined as interference source coefficients, ambient temperature, and humidity. Adding electromagnetic intensity and noise intensity values then allows the generation of monitoring data for each monitoring time.
[0050] S102, in historical monitoring data, determine the relative impact weight of each environmental data on noise by using the similarity of the sequence changes between the noise intensity time series and the time series of each environmental data.
[0051] Since noise is mainly affected by several types of data, such as ambient temperature, humidity, and interference source coefficient, it is necessary to analyze the influence of changes in the above environmental data on changes in noise signal intensity. However, due to the large number of data types, it is difficult to obtain a definite relationship using the single control variable method. Nevertheless, the relative influence weight of each environmental data on noise can be constructed based on the relative similarity between the time series changes of each environmental data and the time series changes of noise intensity, so as to characterize the relative relationship between each environmental data and the change in noise signal.
[0052] To maximize the accuracy of the relative impact weight calculation, this embodiment preferably compares the similarity of the aforementioned time-series changes within the entire historical monitoring data set. The length of the historical monitoring data can be set by the operator based on the available computing power and required detection accuracy, such as one day. The similarity of the aforementioned time-series changes can be determined using any existing feasible method. This embodiment preferably employs the DTW (Dynamic Time Warping) algorithm to calculate the similarity value between the time-series environmental data and the noise intensity time-series, using the similarity value to determine the relative impact weight of each environmental data on the noise.
[0053] Furthermore, to obtain a more accurate relative impact weight, in a preferred embodiment, determining the relative impact weight of each environmental data on noise based on the sequence variation similarity between the noise intensity time series and the time series of each environmental data includes:
[0054] The historical monitoring data is divided into a corresponding number of time periods using the second duration as the dividing length. The similarity between the noise data and each type of environmental data in each time period is determined. The time period with the highest similarity between the noise data and the current environmental data is selected from all time periods, and the monitoring data corresponding to all selected time periods are recorded as the weighted analysis dataset of the current environmental data. The relative influence weight of the current environmental data on noise is determined based on the weighted analysis dataset of the current environmental data.
[0055] Specifically, the value of the second duration, i.e., the length of the divided time period, can be determined comprehensively based on the duration of historical monitoring data and the accuracy requirements for covert communication detection. In this embodiment, the second set duration is preferably 5 minutes. That is, the historical monitoring data is divided into a corresponding number of time periods according to the length of 5 minutes, and then the similarity between the noise data and each type of environmental data in each time period is determined. That is, the similarity between the noise data and temperature data, the similarity between the noise data and humidity data, and the similarity between the noise data and the interference source coefficient are determined. The calculation of the similarity can also use the DTW algorithm mentioned above.
[0056] Then, the time periods with the highest similarity values in each time period, corresponding to the same environmental data type, are considered as the same type of time period. For example, if the noise intensity and temperature data have the highest similarity in a certain time period, and the noise intensity and temperature data also have the highest similarity in another time period, then these two time periods are considered as the same type of time period and are used as the time period type of the corresponding environmental data type. The monitoring data corresponding to each time period type is recorded as the weighted analysis dataset of the corresponding environmental data to determine the relative impact weight of the current environmental data on noise.
[0057] The reason for grouping the time periods with the highest similarity among different time periods into the same category is that the monitoring data corresponding to the time periods of this category are most relevant to the environmental data types corresponding to the time periods of this category compared to other environmental data types. Therefore, they best represent the impact of this environmental type on noise, thereby improving the accuracy of the representation of the impact weight when using the weighted analysis dataset of the determined environmental data to obtain the impact weight.
[0058] Furthermore, to further improve the accuracy of influence weight acquisition, the step of determining the relative influence weight of the current environmental data on noise based on the weight analysis dataset of the current environmental data can be:
[0059] Calculate the average noise intensity for each time period, take the time period with the lowest average noise intensity as the reference time period, calculate the average of each environmental data within the reference time period, take the average of each environmental data as the lower limit of the corresponding environmental data, and take the average noise intensity of the reference time period as the lower limit of the noise intensity.
[0060] In the weighted analysis dataset of the current environmental data, the difference between the measured value of the current environmental data and the lower limit value of the current environmental data at each time point is recorded as the first difference. The difference between the measured value of the noise intensity and the lower limit value of the noise intensity at each time point is recorded as the second difference. A coordinate graph of the current environmental data is constructed with the first difference as the x-axis and the second difference as the y-axis. A straight line is fitted to the coordinate graph of the current environmental data and the absolute value of the slope of the fitted line is determined. The ratio of the absolute value of the slope corresponding to the current environmental data to the sum of the absolute values of the slope corresponding to all environmental data is used as the relative influence weight of the current environmental data on the noise.
[0061] Specifically, the time period with the lowest average noise signal intensity is chosen as the reference time period because it is generally a period with the fewest operating devices or a relatively stable environment. In this case, the environmental data can be considered to have no deviation. Therefore, the average value of each environmental data point within this time period can be used as the lower limit of the corresponding environmental data. This value can then be compared with the values of the corresponding environmental data at various times in the weighted analysis dataset to characterize the specific deviation trend or the deviation details at each moment in the weighted analysis dataset. Simultaneously, to obtain the corresponding noise deviation trend or the noise deviation details at each moment, the average noise intensity within the reference time period must also be calculated as the lower limit of the noise intensity.
[0062] Then, in the weighted analysis dataset of the current environmental data, the difference between the measured value of the current environmental data and the lower limit value of the current environmental data at each time point is calculated and recorded as the first difference. The difference between the measured value of the noise intensity and the lower limit value of the noise intensity at each time point is calculated and recorded as the second difference. Then, a relationship curve between the first difference and the second difference is constructed. To characterize the change in noise intensity by the steepness of the relationship curve, the first difference is chosen as the horizontal axis and the second difference as the vertical axis. Then, a straight line is fitted to the relationship curve between the first difference and the second difference, and the absolute value of the slope of the fitted line is determined. After obtaining the absolute value of the slope of the fitted line corresponding to each type of environmental data, the relative weight of the impact of each type of environmental data on the noise can be determined.
[0063]
[0064] in, This represents the relative impact weight of the j-th type of environmental data on noise. This represents the absolute value of the slope of the fitted line corresponding to the j-th type of environmental data, where M represents the type of environmental data. This represents the sum of the absolute slopes of the fitted lines corresponding to the M environmental data points. The larger the absolute slope of the fitted line, the closer the line is to the y-axis, the steeper the curve of the relationship between the first and second differences under the current environmental data, and the greater the relative weight of the current environmental data on the noise.
[0065] S103, the first time period before the current time is recorded as the analysis period. The analysis period is divided into sub-analysis segments by the standard deviation of electromagnetic intensity within the analysis period. The mean of each environmental data in the sub-analysis segment with the most stable change in electromagnetic intensity is used as the benchmark value of the corresponding environmental data. The absolute value of the difference between the measured value of each environmental data and the benchmark value at the current time is calculated. The adjustment factor is determined by the absolute value of each difference and the relative influence weight.
[0066] Specifically, the reason for selecting the first time period preceding the current moment as the analysis period is that industrial environments are highly variable, and the environment in earlier periods may differ from the recent environment. In this embodiment, the adjustment factor is determined by judging the deviation between the measured environmental value at the current moment and the stable value of the environmental data at the current moment. The stable value of the environmental data at the current moment can be determined through recent historical data. Therefore, compared to selecting historical monitoring data that includes earlier periods, selecting recent historical data for the first time period can more accurately represent this deviation and ensure the accuracy of the adjustment factor acquisition.
[0067] The value of the first duration can be the same as or different from the value of the second duration. In this embodiment, it is preferred that the value of the first duration is the same as the second duration, which is 5 minutes.
[0068] The reason for segmenting the analysis period into sub-analysis segments using the standard deviation of electromagnetic intensity within the analysis period is that existing energy detection methods based on RSSI (Received Signal Strength Indication) for covert communication detection compare the detected electromagnetic intensity with the detection threshold of a baseline model corresponding to the electromagnetic intensity data of a certain time period. The detection threshold of the baseline model is typically constructed by calculating the mean ± 3 times the standard deviation of the electromagnetic intensity data for that time period. Simultaneously, the standard deviation reflects the average deviation between data points and the mean. Through the standard deviation, the volatility, stability, or consistency of the data can be intuitively judged. The standard deviation can be used to identify stable segments and breakpoints in the data. If the difference in change between adjacent data points is greater than or equal to the standard deviation, it indicates a sharp change in the data, which may be a breakpoint indicating a data inflection point. Therefore, this embodiment preferably segments the analysis period into sub-analysis segments using the standard deviation of electromagnetic intensity within the analysis period. The method is as follows:
[0069] The change in electromagnetic intensity between any two adjacent moments within the analysis period is calculated, and two adjacent moments whose change is greater than the standard deviation of the electromagnetic intensity within the analysis period are divided into different sub-analysis segments. If the difference in change between adjacent data is less than the standard deviation, the adjacent data can be considered to change steadily and can be regarded as the same steady-state data segment, that is, the same sub-analysis segment.
[0070] For example, suppose the electromagnetic intensity data sequence corresponding to the current analysis period is (1,2,1,3,2,1,1,2,5,2,3,2,4,6,7,9,8). Using a standard deviation of 2.644 as the segmentation criterion, that is, when the difference between adjacent values is greater than or equal to 2.644, segmentation is performed. Then the above data sequence can be divided into three sub-analysis segments: (1,2,1,3,2,1,1,2), (5), and (2,3,2,4,6,7,9,8).
[0071] Furthermore, the reason for dividing the analysis period into multiple sub-analysis segments is to find sub-data segments that can characterize the stable state of the analysis period as much as possible. These sub-data segments that characterize the stable state of the analysis period represent the sub-analysis segments where the electromagnetic intensity changes are most stable. The method for this is as follows:
[0072] Calculate the difference coefficient of the electromagnetic intensity time series within any sub-analysis segment. The ratio of the duration of that sub-analysis segment to its corresponding difference coefficient is taken as the stable value of that sub-analysis segment. The sub-analysis segment with the largest stable value is considered the most stable in terms of electromagnetic intensity change. The formula is as follows:
[0073]
[0074] in, This indicates the stable value of the current sub-analysis segment. This represents the difference coefficient of the preceding sub-analysis segment. The coefficient of variation indicates the stability of the preceding sub-analysis segment; the larger the coefficient of variation, the lower the stability. The length of the preceding sub-analysis segment indicates the length of the data sequence. The longer the data sequence, the longer the stable duration, and the larger the stable value of the change.
[0075] Based on the stable value of the change, the most stable segment among all sub-analysis segments can be determined. Then, the mean value of each environmental data in this segment is used as the benchmark value of the corresponding environmental data to characterize the value of each environmental temperature under the recent stable environmental state.
[0076] Then, based on the degree of deviation of the measured value of each environmental data point from the baseline value at the current moment, and the relative influence weight of each environmental data point on the noise, the adjustment factor, which characterizes the degree of noise generation caused by the environmental deviation at the current moment, can be obtained:
[0077] ,
[0078] in, Indicates the regulating factor. This represents the relative impact weight of the j-th type of environmental data on noise. This represents the measured value of the j-th type of environmental data. This represents the baseline value for the j-th type of environmental data. Indicates the number of types of environmental data. This indicates normalization.
[0079] In addition, in a preferred embodiment, to avoid the measured value of the environmental data obtained at the current time deviating from the true value due to the detection deviation of the sensor when acquiring each type of environmental data at the current time, thereby causing deviation in the calculation of the adjustment factor, this preferred embodiment selects the average value of each type of environmental data within the third time period before the current time as the measured value of that type of environmental data at the current time, and participates in the above-mentioned adjustment factor calculation.
[0080] S104, Determine the adaptive detection benchmark for completing the electromagnetic radiation covert communication detection at the current moment based on the adjustment factor.
[0081] The adjustment factor effectively characterizes the degree to which the current environment deviates from a stable state. Therefore, the detection benchmark for detecting covert electromagnetic radiation at the current moment can be adaptively adjusted based on the obtained adjustment factor. The adaptively adjusted benchmark can provide a more reliable basis for subsequent detection, thereby improving the accuracy of subsequent detection. Specifically, determining the adaptive detection benchmark for detecting covert electromagnetic radiation at the current moment based on the adjustment factor includes:
[0082] The upper and lower limits of the baseline model for the analysis period are adjusted according to the adjustment factor to obtain the corrected threshold range, and the corrected threshold range is used as the adaptive detection benchmark for completing the detection of electromagnetic radiation covert communication at the current moment.
[0083] Since the environmental deviation from the current (or recent) stable state can be either upward or downward, we choose to increase the upper limit of the baseline model threshold for the analysis period using an adjustment factor, and decrease the lower limit of the baseline model threshold for the analysis period using an adjustment factor, to obtain the corrected threshold range, which is expressed as follows:
[0084]
[0085]
[0086] in, The lower limit of the threshold represents the range of the correction threshold. This represents the lower threshold of the baseline model for the analysis period. Indicates the regulating factor. This indicates the upper limit of the threshold range for correction. This indicates the upper limit of the baseline model for the analysis period.
[0087] This yields the adjusted threshold range. It is easy to understand that this adjusted threshold range is a dynamic threshold, which changes dynamically with changes in the environment.
[0088] After obtaining the corrected threshold range as described above, the real-time detected signal energy is compared with the corrected threshold range. Based on the improvement of the processing method of electromagnetic radiation data generated by the operation of industrial equipment, a prerequisite basis is provided for achieving more accurate covert communication detection.
[0089] The existing process of detecting covert communication by comparing the real-time detected signal energy with a corrected threshold range can be set as follows:
[0090] 1. Compare the real-time extracted signal energy value with a dynamic threshold. If the value is not within the threshold range, it is marked as a potential covert communication signal.
[0091] 2. Since covert signals cause small but continuous fluctuations in the signal, if the detected signal continues to deviate from the threshold range afterward, such as if the detected signal is marked 3 times in a row, then the signal can be considered a covert communication signal.
[0092] 3. Other characteristics (such as signal duration, periodicity, and spectral distribution) can also be combined to further verify whether the anomaly is caused by covert communication, thereby reducing the false alarm rate.
[0093] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for processing data related to covert communication detection of electromagnetic radiation from industrial equipment, characterized in that, include: The electromagnetic intensity, noise intensity, temperature, humidity, and operating power of each device outside the detection area and its distance from the detection area are obtained. An interference source coefficient that is directly proportional to the operating power of each device and inversely proportional to the distance from the detection area is constructed. Temperature, humidity, and interference source coefficient are used as environmental data, and environmental data, electromagnetic intensity value, and noise intensity value are used as monitoring data. Based on the similarity of the time series of noise intensity with the time series of each type of environmental data in historical monitoring data, the relative impact weight of each type of environmental data on noise is determined. The analysis period is defined as the first time interval before the current moment. The analysis period is divided into sub-analysis segments by the standard deviation of electromagnetic intensity within the analysis period. The mean of each environmental data in the sub-analysis segment with the most stable electromagnetic intensity change is used as the benchmark value of the corresponding environmental data. The absolute value of the difference between the measured value of each environmental data and the benchmark value at the current moment is calculated. The adjustment factor is determined based on the absolute value of each difference and the relative influence weight. The adaptive detection benchmark for completing the detection of covert electromagnetic radiation communication at the current moment is determined based on the adjustment factor.
2. The method for processing data of concealed communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, The interference source coefficient, which is directly proportional to the operating power of each device and inversely proportional to the distance from the detection area, includes: At any given moment, calculate the product of the reciprocal of the distance from any device outside the detection area to the monitoring area and the operating power of that device, and use the sum of all products as the interference source coefficient at that given moment.
3. The method for processing data related to covert communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, The method of determining the relative impact weight of each environmental data on noise based on the sequence variation similarity between the noise intensity time series and the time series of each environmental data includes: The historical monitoring data is divided into a corresponding number of time periods using the second duration as the dividing length. The similarity between the noise data and each type of environmental data in each time period is determined. The time period with the highest similarity between the noise data and the current environmental data is selected from all time periods, and the monitoring data corresponding to all selected time periods are recorded as the weighted analysis dataset of the current environmental data. The relative influence weight of the current environmental data on noise is determined based on the weighted analysis dataset of the current environmental data.
4. The method for processing data of concealed communication detection of electromagnetic radiation in industrial equipment according to claim 3, characterized in that, The step of determining the relative impact weight of the current environmental data on noise based on the weighted analysis dataset of the current environmental data includes: Calculate the average noise intensity for each time period, take the time period with the lowest average noise intensity as the reference time period, calculate the average of each environmental data within the reference time period, take the average of each environmental data as the lower limit of the corresponding environmental data, and take the average noise intensity of the reference time period as the lower limit of the noise intensity. In the weighted analysis dataset of the current environmental data, the difference between the measured value of the current environmental data and the lower limit value of the current environmental data at each time point is recorded as the first difference. The difference between the measured value of the noise intensity and the lower limit value of the noise intensity at each time point is recorded as the second difference. A coordinate graph of the current environmental data is constructed with the first difference as the x-axis and the second difference as the y-axis. A straight line is fitted to the coordinate graph of the current environmental data and the absolute value of the slope of the fitted line is determined. The ratio of the absolute value of the slope corresponding to the current environmental data to the sum of the absolute values of the slope corresponding to all environmental data is used as the relative influence weight of the current environmental data on the noise.
5. The method for processing data related to covert communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, The sub-analysis segments are obtained by dividing the analysis period into segments based on the standard deviation of electromagnetic intensity within the analysis period, including: Calculate the change in electromagnetic intensity between any two adjacent moments within the analysis period, and divide the two adjacent moments whose change value is greater than the standard deviation of electromagnetic intensity within the analysis period into different sub-analysis segments.
6. The method for processing data of concealed communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, Identify the sub-analysis segment where the electromagnetic intensity change is most stable, including: Calculate the difference coefficient of the electromagnetic intensity time series within any sub-analysis segment. The ratio of the duration of any sub-analysis segment to the difference coefficient corresponding to that sub-analysis segment is taken as the stable value of the change of that sub-analysis segment. The sub-analysis segment with the largest stable value is taken as the sub-analysis segment with the most stable change in electromagnetic intensity.
7. The method for processing data of concealed communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, The adjustment factor is: , in, Indicates the regulating factor. This represents the relative impact weight of the j-th type of environmental data on noise. This represents the measured value of the j-th type of environmental data. This represents the baseline value for the j-th type of environmental data. Indicates the number of types of environmental data. This indicates normalization.
8. The method for processing data of concealed communication detection of electromagnetic radiation from industrial equipment according to claim 1, characterized in that, The adaptive detection benchmark for completing the detection of covert electromagnetic radiation at the current moment is determined based on the adjustment factor, including: The upper and lower limits of the baseline model for the analysis period are adjusted according to the adjustment factor to obtain the corrected threshold range, and the corrected threshold range is used as the adaptive detection benchmark for completing the detection of electromagnetic radiation covert communication at the current moment.
9. The method for processing data related to covert communication detection of electromagnetic radiation from industrial equipment according to claim 8, characterized in that, The threshold upper and lower limits of the baseline model for the analysis period adjusted according to the adjustment factor include: The upper limit of the threshold of the baseline model for the analysis period is increased by the adjustment factor, and the lower limit of the threshold of the baseline model for the analysis period is decreased by the adjustment factor.