Host security fine management and control system of industrial control system

By constructing an enhanced host agent client and a multi-engine collaborative architecture, several shortcomings in the host-level security protection of Emerson industrial control systems were addressed. This resulted in comprehensive and efficient log collection, refined baseline verification, precise account management, and accurate alarms, thereby improving the system's security incident response efficiency and protection capabilities.

CN121864358APending Publication Date: 2026-04-14浙江浙能数字科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-02
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

The existing security protection of Emerson industrial control systems at the host level suffers from problems such as limited log collection scope, data redundancy, insufficient baseline verification, rough account status management, numerous false alarms, and lack of third-party linkage mechanisms, resulting in low efficiency in responding to security incidents.

Method used

An enhanced host agent client and a multi-engine collaborative architecture are built to achieve comprehensive log collection, efficient data processing, refined baseline verification, precise account control, and intelligent alarm filtering. This includes a security dashboard, log analysis unit, security alarm unit, peripheral management unit, log aggregation engine, security baseline verification engine, user status management engine, and alarm optimization engine. It supports multi-protocol transmission and third-party log forwarding. The enhanced host agent client is compatible with the original Emerson Host Security Guard.

Benefits of technology

It enhances host security protection capabilities, boasts strong compatibility, comprehensive and efficient log collection, refined baseline verification, good security ecosystem linkage, precise account management, and high alarm accuracy, thereby reducing the burden of operation and maintenance and improving the efficiency of security incident handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864358A_ABST
    Figure CN121864358A_ABST
Patent Text Reader

Abstract

The invention discloses a host security fine management and control system of an industrial control system, which comprises an application layer, a data transmission and analysis layer and an acquisition and terminal protection layer, and is characterized in that the application layer comprises a security instrument panel, a log analysis unit, a security alarm unit and a peripheral management unit; the data transmission and analysis layer comprises a log centralized convergence engine, a security baseline check engine, a user state management engine and an alarm optimization engine; and the acquisition and terminal protection layer comprises enhanced host Agent clients deployed at the industrial control nodes. According to the host security fine management and control system of the industrial control system disclosed by the invention, by constructing the enhanced host Agent client and a multi-engine collaborative architecture, log collection comprehensiveness, data processing high efficiency, baseline check refinement, account management and control precision and alarm filtering intellectualization are realized, and the host security protection capability of the Eimeson industrial control system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of industrial control system security protection technology, specifically relating to a host security fine control system for industrial control systems. Background Technology

[0002] With the widespread application of industrial control systems and the increasing complexity of the network threat environment, host-level security has become crucial for ensuring the stable operation of industrial production. Emerson Industrial Control Systems, as one of the most widely used industrial control systems, has seen its native host detection client gradually reveal several shortcomings in practical applications: limited log collection scope, failing to meet comprehensive threat detection data requirements; serious data redundancy issues during large-scale log collection, consuming significant bandwidth and storage resources and impacting security incident response efficiency; insufficient detail in baseline verification configuration display, making it difficult for security administrators to quickly grasp the actual status and make accurate rectifications; lack of effective linkage mechanisms with third-party security platforms, resulting in insufficient security ecosystem collaboration capabilities; coarse-grained account status control, making it difficult to effectively identify abnormal account activity; and a high number of false alarms, increasing the burden on operations and maintenance. Summary of the Invention

[0003] The main objective of this invention is to provide a fine-grained host security management system for industrial control systems. By constructing an enhanced host agent client and a multi-engine collaborative architecture, it achieves comprehensive log collection, efficient data processing, refined baseline verification, precise account management, and intelligent alarm filtering, thereby enhancing the host security protection capabilities of Emerson industrial control systems.

[0004] To achieve the above objectives, this invention provides a host security fine-grained control system for industrial control systems, comprising an application layer, a data transmission and analysis layer, and a data acquisition and terminal protection layer, wherein: The application layer includes a security dashboard, a log analysis unit, a security alarm unit, and a peripheral management unit; The data transmission and analysis layer includes a log aggregation engine, a security baseline verification engine, a user status management engine, and an alarm optimization engine. The log aggregation engine supports multiple protocols, third-party log forwarding, and has log aggregation algorithms. The security baseline verification engine is used for fine-grained display of baseline status, real-time detection of baseline compliance, and detailed visualization of configuration parameters. The user status management engine is used for managing the enabled / disabled status of all users, user permissions and groups, user login history, and password status. The alarm optimization engine is used for accurate filtering of alarm information and accurate identification and filtering of anomalies in the original Emerson Host Security Guard whitelist. The data collection and terminal protection layer includes an enhanced host agent client deployed on each industrial control node. The enhanced host agent client is compatible with the original Emerson Host Security Guard and is used for incremental log collection, real-time collection of account information and configuration, and real-time collection of security policies.

[0005] As a further preferred technical solution to the above technical solution, for incremental data collection, operating system logs, system event logs, security event logs and application logs are collected, and the collected logs are transmitted to the log aggregation engine.

[0006] As a further preferred technical solution to the above technical solution, the log aggregation algorithm automatically identifies and removes duplicate log information, while supporting multi-protocol transmission and third-party log forwarding.

[0007] As a further preferred technical solution to the above technical solution, the configuration parameters are detailed and visible, including account policies, audit policies and password complexity configurations.

[0008] As a further preferred technical solution to the above technical solution, the multi-protocol includes UDP protocol and TCP protocol.

[0009] The beneficial effects of this invention are as follows: 1. Strong compatibility: The enhanced host agent client is seamlessly compatible with the original Emerson Host Security Guard, without requiring large-scale modifications to the original system, thus ensuring the stability of system operation.

[0010] 2. Comprehensive and efficient log collection: The scope of log collection has been expanded, and combined with efficient log aggregation algorithms, it not only ensures the richness of threat detection data, but also solves the problem of data redundancy and improves data processing efficiency.

[0011] 3. Refined baseline verification: Provides detailed baseline configuration information display and real-time compliance detection, helping security administrators accurately grasp the system security status and quickly complete rectification.

[0012] 4. Excellent security ecosystem integration: It supports multi-protocol third-party log forwarding, realizes real-time integration with third-party security platforms, and improves the collaborative capabilities of security protection.

[0013] 5. Precise account management: It achieves refined management of account status, permissions, login history and other dimensions, effectively preventing internal threats.

[0014] 6. High alarm accuracy: Through a precise false alarm filtering mechanism, the number of false alarms is significantly reduced, alleviating the workload of operation and maintenance personnel and improving the efficiency of security incident handling. Attached Figure Description

[0015] Figure 1 This is a schematic diagram of the present invention.

[0016] Figure 2 This is the running interface of the enhanced host agent client of the present invention.

[0017] Figure 3 This is the running interface of the enhanced host agent client of the present invention. Detailed Implementation

[0018] The following description is intended to disclose the present invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art. The basic principles of the invention defined in the following description can be applied to other embodiments, modifications, improvements, equivalents, and other technical solutions that do not depart from the spirit and scope of the invention.

[0019] In the preferred embodiments of the present invention, those skilled in the art should note that the Emerson industrial control system and the like involved in the present invention can be considered as prior art.

[0020] Preferred embodiment.

[0021] like Figure 1-3 As shown, this invention discloses a host security fine-grained control system for industrial control systems, comprising an application layer, a data transmission and analysis layer, and a data acquisition and terminal protection layer, wherein: The application layer includes a security dashboard, a log analysis unit, a security alarm unit, and a peripheral management unit; The data transmission and analysis layer includes a log aggregation engine, a security baseline verification engine, a user status management engine, and an alarm optimization engine. The log aggregation engine supports multiple protocols, third-party log forwarding, and has a log aggregation algorithm (for accurate deduplication and noise reduction). The security baseline verification engine is used for fine-grained display of baseline status, real-time detection of baseline compliance, and detailed visualization of configuration parameters. The user status management engine is used for managing the enabled / disabled status of all users, user permissions and groups, user login history, and password status. The alarm optimization engine is used for accurate filtering of alarm information and accurate identification and filtering of anomalies in the original Emerson Host Security Guard whitelist. The data collection and terminal protection layer includes an enhanced host agent client deployed on each industrial control node. The enhanced host agent client is compatible with the original Emerson Host Security Guard and is used for incremental log collection, real-time collection of account information and configuration, and real-time collection of security policies.

[0022] Specifically, for incremental data collection, operating system logs, system event logs, security event logs, and application logs are collected and transmitted to the log aggregation engine.

[0023] More specifically, for log aggregation algorithms, duplicate log information is automatically identified and removed, while supporting multi-protocol transmission and third-party log forwarding.

[0024] Furthermore, detailed and visible configuration parameters are provided, including account policies, audit policies, and password complexity configurations (enabling security administrators to quickly grasp the actual situation and make precise rectifications).

[0025] Furthermore, the multi-protocol includes both UDP and TCP protocols.

[0026] This invention not only fully inherits the advantages of the original Emerson Host Security Guard, but also adds operating system log collection, efficient log aggregation algorithms, fine-grained account management, and precise false alarm filtering mechanisms, forming a more comprehensive, accurate, and efficient security management platform, thus building a solid security protection foundation for Emerson industrial control environments.

[0027] It is worth mentioning that the technical features of Emerson industrial control systems and other technologies involved in this patent application should be regarded as prior art. The specific structure, working principle, and possible control methods and spatial arrangement of these technical features can be adopted using conventional choices in the field, and should not be regarded as the inventive point of this patent. This patent will not be further elaborated in detail.

[0028] For those skilled in the art, modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this invention should be included within the protection scope of this invention.

Claims

1. A host safety precision control system for an industrial control system, characterized in that, It includes the application layer, data transmission and analysis layer, and data acquisition and terminal protection layer, among which: The application layer includes a security dashboard, a log analysis unit, a security alarm unit, and a peripheral management unit; The data transmission and analysis layer includes a log aggregation engine, a security baseline verification engine, a user status management engine, and an alarm optimization engine. The log aggregation engine supports multiple protocols, third-party log forwarding, and has log aggregation algorithms. The security baseline verification engine is used for fine-grained display of baseline status, real-time detection of baseline compliance, and detailed visualization of configuration parameters. The user status management engine is used for managing the enabled / disabled status of all users, user permissions and groups, user login history, and password status. The alarm optimization engine is used for accurate filtering of alarm information and accurate identification and filtering of anomalies in the original Emerson Host Security Guard whitelist. The data collection and terminal protection layer includes an enhanced host agent client deployed on each industrial control node. The enhanced host agent client is compatible with the original Emerson Host Security Guard and is used for incremental log collection, real-time collection of account information and configuration, and real-time collection of security policies.

2. The host safety precision control system for an industrial control system according to claim 1, characterized in that, For incremental data collection, operating system logs, system event logs, security event logs, and application logs are collected and transmitted to the log aggregation engine.

3. The host safety precision control system for an industrial control system according to claim 2, characterized in that, For log aggregation algorithms, duplicate log information is automatically identified and removed, while supporting multi-protocol transmission and third-party log forwarding.

4. The host safety precision control system for an industrial control system according to claim 3, characterized in that, The configuration parameters are detailed and visible, including account policies, audit policies, and password complexity configurations.

5. The host safety precision control system for an industrial control system according to claim 3, characterized in that, The multiple protocols include UDP and TCP.