Industrial information security emergency disposal method, terminal and system based on cloud threat resource pool

By utilizing the emergency response method of the cloud threat resource pool, which automatically analyzes and matches response templates and combines them with cloud data, the problems of low efficiency and resource lag in industrial information security emergency response are solved, achieving high efficiency and accuracy in emergency response. The emergency response tools are dynamically adjusted, thereby improving emergency response capabilities.

CN121907472APending Publication Date: 2026-04-21NAT IND INFORMATION SECURITY DEV RES CENT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-09-19
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies for emergency response to industrial information security issues suffer from problems such as low efficiency, difficulty in tool selection, inconsistent operating procedures, and lagging resource updates, making it difficult to effectively cope with complex and ever-changing network threats and emergencies.

Method used

An emergency response method based on a cloud threat resource pool is adopted. By collecting on-site information and event symptoms, prior knowledge features are used to automatically analyze and match response templates. Emergency response operations are carried out in conjunction with threat data from the cloud threat resource pool. New threat data is uploaded in real time, and source tracing and response documents are compiled and shared to the cloud.

Benefits of technology

It has improved the efficiency and accuracy of emergency response, enabled real-time sharing and updating of threat data, dynamically adjusted emergency response tools, solved the problems of lag in emergency response and the dilemma of individual combat, and improved emergency response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907472A_ABST
    Figure CN121907472A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial information security emergency disposal method, terminal and system based on a cloud threat resource pool. The industrial information safety emergency disposal method comprises the following steps: acquiring a field condition and an event symptom; matching a corresponding disposal template for the emergency disposal by utilizing priori knowledge based on a field condition and an event symptom; on the basis of the disposal template, according to the threat data in the local threat resource pool, in combination with assistance of the threat data in the cloud threat resource pool, completing the emergency disposal operation; collecting novel threat data found in the emergency disposal operation and uploading the novel threat data to a cloud threat resource pool in real time; and arranging the traceability disposal document of the emergency disposal and sharing the traceability disposal document to a cloud threat resource pool. A side cloud cooperation mode of a cloud system platform and a field emergency disposal tool is adopted, the tool box is remotely updated, positioned and configured, dynamic upgrading of the emergency disposal tool capacity is guaranteed in real time, the emergency disposal efficiency is improved, and the defect of the emergency disposal capacity of an industrial enterprise is overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of emergency response technology, and in particular to an industrial information security emergency response method, terminal, and system based on a cloud threat resource pool. Background Technology

[0002] Threat resource pools are information security technologies used to collect, analyze, and share cyber threats. Based on this, potential cyber threats can be effectively analyzed, identified, managed, and predicted, helping enterprises improve their emergency response capabilities. The industrial sector exhibits the following characteristics:

[0003] Industrial threats are complex and ever-changing. Enterprises have a wide variety of network devices, and industrial equipment is outdated and difficult to update in a timely manner. This results in complex and ever-changing network threats, covering a wide range of fields. When faced with specific situations, emergency response personnel often find it difficult to accurately identify the entry point, which seriously affects the speed of emergency response and greatly raises the threshold for emergency response personnel.

[0004] Secondly, there are numerous industrial detection tools available. Furthermore, for different cyber threats, emergency responders often need to select the appropriate tools from among many available options based on the specific circumstances. This requires not only proficiency with the tools but also tool management skills, enabling them to quickly select suitable tools and provide solutions for specific situations.

[0005] The industrial emergency response process is often disorganized. Finally, after an emergency response is completed, follow-up work such as recovery, summarization, rectification, and tracking is often required. However, there are no unified standards for this in the current technology, and it often depends on the individual judgment of the emergency response personnel, leading to problems such as difficulty in ensuring remedial measures, unstable response efficiency, and difficulty in retrospection.

[0006] Fourth, emergency resource updates are lagging behind. Current emergency response technologies are often concentrated in resource pools with established models. Once determined, they are difficult to change, maintain, or upgrade remotely. There is a lack of real-time updates and linkage based on cloud-based threat resource pools, resulting in a lag and limitations in responding to emergencies and making it difficult to keep up with the latest developments.

[0007] With the gradual integration of industrialization and informatization, emergency response has never been more urgent. Industrial network threats have evolved from widespread infiltration to precise attacks. Furthermore, information networks also face severe threats; cyber threats remain a persistent problem, profoundly impacting every enterprise.

[0008] As we all know, industrial network information security is not something that can be achieved overnight; it requires both prevention and remedial action. However, existing technologies mainly focus on the protection and analysis of network security incidents, with little research on emergency response in the field of industrial information security. The operational process can be roughly divided into three stages: incident response, incident handling, and incident management. During incident response and handling, auxiliary tools, cloud databases, and expert knowledge bases are used for processing. However, these processes are often handled manually, lacking systematic guidance, heavily influenced by human factors, and lacking standardized operational procedures. Furthermore, the limited technology available is mainly focused on integrating tools within established models, failing to effectively utilize threat resource pools for real-time tool updates. This results in delays, limitations, and a heavy reliance on application scenarios, making it difficult to cover most current emergencies. Moreover, there is no specific archiving and preservation method for post-incident recovery, tracking, and tracing, making it difficult to create a valuable resource library. Summary of the Invention

[0009] This invention provides an industrial information security emergency response method, terminal, and system based on a cloud threat resource pool, to address the problem of low emergency response efficiency in existing technologies.

[0010] The industrial information security emergency response method based on a cloud threat resource pool according to embodiments of the present invention includes:

[0011] Collect on-site information and event symptoms; the on-site information includes: the degree of damage to system applications, the degree of damage to system data, and the scope of impact on system data; the event symptoms include: phenomena directly observed on-site, phenomena found during preliminary inspection, symptoms found through questioning, and comprehensive phenomena;

[0012] Based on the on-site situation and the event symptoms, prior knowledge features are used to automatically analyze and match the corresponding handling template from the terminal threat resources of the industrial information security emergency response tool; the terminal threat resources of the industrial information security emergency response tool contain a variety of handling templates, and each handling template has a different handling strategy;

[0013] Based on the aforementioned handling template, and with the assistance of threat data from the terminal threat resources of the industrial information security emergency response tool, combined with threat data from the cloud threat resource pool, the emergency response operation is completed. The cloud threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners.

[0014] Analyze the new threat data discovered during this emergency response operation and upload it to the cloud-based threat resource pool in real time;

[0015] Compile the source tracing and handling documents for this emergency response and share them to the cloud-based threat resource pool.

[0016] Corresponding to the above method, this embodiment of the invention also proposes a computer-readable storage medium storing an information transmission implementation program. When the program is executed by a processor, it implements the steps of the industrial information security emergency response method based on a cloud threat resource pool as described above.

[0017] This invention also proposes an industrial information security emergency response tool terminal, comprising:

[0018] The threat resources include threat data and various handling templates, each with a different handling strategy.

[0019] The data acquisition and analysis module is remotely connected to the cloud-based threat resource pool. The data acquisition and analysis module is used to sort out the on-site records and newly discovered threat data during this emergency response operation and upload them to the cloud-based threat resource pool in real time.

[0020] The template configuration module is communicatively connected to the threat resources. This module is used to determine the on-site situation and event symptoms, and based on the on-site situation and event symptoms, automatically analyzes and matches the corresponding emergency response template from the threat resources using prior knowledge features. The on-site situation includes: the degree of system application damage, the degree of system data damage, and the scope of system data impact. The event symptoms include: directly observed phenomena on-site, phenomena discovered during preliminary inspection, symptoms discovered through questioning, and comprehensive phenomena.

[0021] The emergency response module is communicatively connected to both the template configuration module and the threat resources, and is also remotely connected to the cloud-based threat resource pool. The emergency response module is used to complete the emergency response operation based on the response template, the threat data in the threat resources, and the threat data from the cloud-based threat resource pool. The cloud-based threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners.

[0022] The summary and archiving module is remotely connected to the cloud-based threat resource pool. The summary and archiving module is used to organize the source tracing and handling documents of this emergency response and share them to the cloud-based threat resource pool.

[0023] This invention also proposes an industrial information security emergency response system, comprising:

[0024] The cloud threat resource pool collects threat data at least through abnormal traffic collection, malware sample collection, and network scanners;

[0025] Remote support system;

[0026] The industrial information security emergency response tool terminal described above is communicatively connected to both the cloud threat resource pool and the remote support system.

[0027] By employing the embodiments of the present invention, threat data is shared and updated in real time through a cloud-based threat resource pool. The threat data can provide enterprises with an integrated industrial information security incident emergency response tool that combines remote and on-site capabilities, as well as remote expert support, to guide on-site operators in completing each process of industrial information security emergency response. This can improve emergency response efficiency and address the shortcomings in the emergency response capabilities of industrial enterprises.

[0028] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description

[0029] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of the embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. In the drawings:

[0030] Figure 1 This is a flowchart of an industrial information security emergency response method based on a threat resource pool, according to an embodiment of the present invention.

[0031] Figure 2 This is a schematic diagram of emergency diagnosis in an embodiment of the present invention;

[0032] Figure 3 This is a schematic diagram of the diagnostic results in an embodiment of the present invention;

[0033] Figure 4 This is a schematic diagram of an industrial information security emergency response system according to an embodiment of the present invention. Detailed Implementation

[0034] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the invention and to fully convey the scope of the invention to those skilled in the art. Furthermore, in some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0035] Existing emergency response boxes often operate in an isolated mode of single - soldier combat. Once an emergency response box is formed, it is difficult to change, and it cannot respond to new threats in a timely manner. For emergencies, only the inherent mode can be used for guidance and handling, and it cannot coordinate and mobilize emergency response resources well during on - site disposal. There is a serious lag in dealing with new types of emergency threats. The information volume in the threat resource library is small and outdated, lacking real - time update and linkage of the cloud threat resource pool, making it difficult to keep up with the frontiers and not being able to adapt well to the current development of industrial information security.

[0036] Referring to Figure 1 As shown, the industrial information security emergency response method based on a threat resource pool according to an embodiment of the present invention includes:

[0037] Collect on - site situations and event symptoms; the on - site situations include: the degree of damage to system applications, the degree of damage to system data, and the scope of influence of system data; the event symptoms include four categories: directly observed phenomena on - site, phenomena found through preliminary inspections, symptoms found through inquiries, and comprehensive phenomena. Specifically, the event symptoms can be symptoms such as a blue screen, inability to open a website, inability to open a file, inability to start the system, and slow running speed, and can refer to Figure 2 .

[0038] Based on the on - site situation and the event symptoms, automatically analyze and match the corresponding disposal template for this emergency response event from the threat resources of the industrial information security emergency response tool terminal using prior knowledge features; there are various disposal templates in the threat resources of the industrial information security emergency response tool terminal, and the disposal strategies of each disposal template are different; the embodiment of the present invention sets up more than 30 disposal templates including a mining virus disposal template, a ransomware virus disposal template, a worm virus disposal template, an information theft event disposal template, etc.

[0039] Based on the disposal template, according to the threat data in the threat resources of the industrial information security emergency response tool terminal, and with the assistance of the threat data in the cloud threat resource pool, complete this emergency response operation; the cloud threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners to ensure that all current threat data is basically covered in the cloud threat resource pool. For resources not available in the threat resources of the industrial information security emergency response tool terminal, each step of the disposal operation is assisted by the cloud threat resource pool; through interaction with the cloud threat resource pool, the emergency response box can master a large amount of threat data and keep consistent with the cloud threat resource pool. The threat data provides a reference basis for operators to perform emergency handling.

[0040] Analyze the new threat data discovered during this emergency response operation and upload it to the cloud threat resource pool in real time; for example, new threat data collected on-site can be updated to the cloud threat resource pool in real time using 5G, wireless, wired, or other methods.

[0041] Compile the source tracing and handling documents for this emergency response and share them to the cloud-based threat resource pool.

[0042] This invention achieves real-time sharing and updating of threat data through a cloud-based threat resource pool, solving the problem of delayed threat information in the emergency response kit. It can synchronize information on emerging new threat events from the cloud to the emergency response kit to improve emergency response capabilities and accuracy, while also uploading on-site threat information to the cloud-based threat resource pool to ensure the timeliness and reliability of the cloud-based threat resource pool.

[0043] By employing the embodiments of the present invention, threat data is shared and updated in real time through a cloud-based threat resource pool. The threat data can guide operators in completing various emergency response procedures, thereby improving both the efficiency and effectiveness of emergency response.

[0044] Based on the above embodiments, further variant embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in each variant embodiment.

[0045] According to some embodiments of the present invention, each of the treatment templates corresponds to a feature calculation formula, and at least one of the elements and the weights of the elements in the feature calculation formulas of different treatment templates is different, wherein the elements correspond to the on-site situation and the event symptoms;

[0046] The process of automatically analyzing and matching the corresponding handling template for this emergency response event from the terminal threat resources of industrial information security emergency response tools, based on the on-site situation and the event symptoms, and utilizing prior knowledge features, includes:

[0047] Based on the on-site situation and the event symptoms, calculations are performed according to the feature calculation formulas corresponding to the various handling templates contained in the terminal threat resources of the industrial information security emergency response tool, to obtain multiple feature calculation results.

[0048] The handling template corresponding to the feature calculation result with the largest value among the multiple feature calculation results is selected as the handling template for this emergency response. The source tracing and handling document is a comprehensive report, which can be understood as a database of solution case studies.

[0049] In this embodiment of the invention, the matching process for handling templates utilizes pre-set knowledge feature weights for automatic analysis and matching. Weights are assigned to N features within each dimension, considering both the on-site situation and the event symptoms. Based on historical data and experience, a feature calculation formula for each type of handling template is formed. Then, the system iterates through various built-in feature calculations based on the selected event symptoms, selecting the most probable suspicious cause of the event to form the available handling template for the current event. For example, the feature calculation formula for the mining virus handling template is: Event Symptom 1 Weight + Event Symptom 2 Weight + Event Symptom 35 Weight + Event Symptom 36 Weight + Event Symptom 38 Weight = Current Feature Calculation Result.

[0050] Reference Figure 3 As shown, according to some embodiments of the present invention, the step of matching a corresponding handling template for this emergency response from the terminal threat resources of the industrial information security emergency response tool based on the on-site situation and the event symptoms includes:

[0051] Based on the on-site situation and the symptoms of the event, a diagnostic result is automatically generated; the diagnostic result includes: suspected cause of the threat event, security event level, and security event type;

[0052] Match the corresponding treatment template based on the diagnosis results.

[0053] Furthermore, after automatically analyzing and generating diagnostic results, users can adjust these results to produce the final diagnosis. This allows for adaptive adjustments based on user experience, enhancing dynamism and intelligence, and making the diagnostic results more reliable.

[0054] Furthermore, each treatment template corresponds to a feature calculation formula, and at least one of the elements and the weights of the elements in the feature calculation formulas of different treatment templates is different, and the elements correspond to each element in the diagnostic results;

[0055] The treatment templates matched based on the diagnostic results include:

[0056] Based on the diagnostic results, calculations are performed according to the feature calculation formulas corresponding to the various handling templates contained in the terminal threat resources of the industrial information security emergency response tool, to obtain multiple feature calculation results.

[0057] The handling template corresponding to the feature calculation result with the largest value among the multiple feature calculation results is used as the handling template for this emergency response.

[0058] According to some embodiments of the present invention, the step of completing the emergency response operation based on the handling template, using threat data from the terminal threat resources of the industrial information security emergency response tool, and with the assistance of threat data from the cloud threat resource pool, includes:

[0059] Establish information communication channels with remote support systems through cloud-based collaboration to build a joint emergency response system;

[0060] Using the industrial information security emergency response system, based on the response template, and with the assistance of threat data from the terminal threat resources of the industrial information security emergency response tool and the threat data from the cloud threat resource pool, the emergency response operation is completed.

[0061] Furthermore, remote support systems can be other emergency response toolkits or specially built expert platforms.

[0062] By linking with the cloud, the system enables remote interactive communication for emergency response personnel, overcoming the limitations of individual operations during emergency response. It allows for timely access to off-site assistance when dealing with complex issues, facilitating the efficient and coordinated mobilization of emergency response resources and expert teams. The threat resource aggregation and remote support system, based on the National Industrial Information Security Threat Resource Pool, employs an edge-cloud collaborative model combining a cloud system platform and on-site emergency response tools. This allows for remote updates, location tracking, and configuration of toolkits, ensuring real-time dynamic upgrades to emergency response tool capabilities.

[0063] In some embodiments of the present invention, the step of completing the emergency response operation based on the handling template, according to the threat data in the terminal threat resources of the industrial information security emergency response tool, and with the assistance of threat data from the cloud threat resource pool, includes:

[0064] Based on the aforementioned handling template, following the PDCERF handling process of preparation, detection, suppression, eradication, recovery, and tracking, and with the assistance of the handling tools in the industrial information security emergency response tool terminal, based on the threat data in the threat resources of the industrial information security emergency response tool terminal and combined with the threat data in the cloud threat resource pool, emergency handling operations can be supported for at least mainstream industrial equipment, industrial hosts, and industrial internet platforms.

[0065] The aforementioned handling tools include at least: built-in image backup, emergency forensics, asset identification, vulnerability detection, traffic analysis, log analysis, process analysis, malware detection, fusion analysis, and data recovery. These tools are required for the six handling steps and the handling template. For example, there are corresponding detection tools in the detection phase, and the relevant tools are selected for detection, analysis, and handling based on the tool usage recommendations in the handling template. These tools can be understood as medications prescribed by a hospital or scalpels used in surgery. The handling steps are carried out according to the PDCERF process and the handling template.

[0066] Corresponding to the above method, this embodiment of the invention also proposes a computer-readable storage medium storing an information transmission implementation program. When the program is executed by a processor, it implements the steps of the industrial information security emergency response method based on a cloud threat resource pool as described above.

[0067] This invention also proposes an industrial information security emergency response tool terminal, comprising:

[0068] The threat resources include threat data and various handling templates, each with a different handling strategy.

[0069] The data acquisition and analysis module is remotely connected to the cloud-based threat resource pool. The data acquisition and analysis module is used to sort out the on-site records and newly discovered threat data during this emergency response operation and upload them to the cloud-based threat resource pool in real time.

[0070] The template configuration module is communicatively connected to the threat resources. This module is used to determine the on-site situation and event symptoms, and based on the on-site situation and event symptoms, automatically analyzes and matches the corresponding emergency response template from the threat resources using prior knowledge features. The on-site situation includes: the degree of system application damage, the degree of system data damage, and the scope of system data impact. The event symptoms include: directly observed phenomena on-site, phenomena discovered during preliminary inspection, symptoms discovered through questioning, and comprehensive phenomena.

[0071] The emergency response module is communicatively connected to both the template configuration module and the threat resources, and is also remotely connected to the cloud-based threat resource pool. The emergency response module is used to complete the emergency response operation based on the response template, the threat data in the threat resources, and the threat data from the cloud-based threat resource pool. The cloud-based threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners.

[0072] The summary and archiving module is remotely connected to the cloud-based threat resource pool. The summary and archiving module is used to organize the source tracing and handling documents of this emergency response and share them to the cloud-based threat resource pool.

[0073] According to some embodiments of the present invention, each of the treatment templates corresponds to a feature calculation formula, and at least one of the elements and the weights of the elements in the feature calculation formulas of different treatment templates is different, wherein the elements correspond to the on-site situation and the event symptoms;

[0074] The template configuration module is used for:

[0075] Based on the on-site situation and the event symptoms, calculations are performed according to the feature calculation formulas corresponding to the various handling templates included in the threat resources to obtain multiple feature calculation results;

[0076] The handling template corresponding to the feature calculation result with the largest value among the multiple feature calculation results is used as the handling template for this emergency response.

[0077] According to some embodiments of the present invention, the disposal operation module establishes an information communication channel with the remote support system through cloud linkage to build a joint emergency response system; the remote support system may be other emergency response toolkits or a specially built expert platform.

[0078] The handling operation module is used to cooperate with the remote support system to complete the emergency handling operation based on the handling template, the threat data in the threat resources, and the threat data in the cloud threat resource pool.

[0079] According to some embodiments of the present invention, the disposal operation module is used for:

[0080] Based on the aforementioned handling template, following the PDCERF handling process of preparation, detection, suppression, eradication, recovery, and tracking, and with the assistance of handling tools based on threat data in the aforementioned threat resources and combined with threat data from the cloud-based threat resource pool, emergency handling operations can be supported for at least mainstream industrial equipment, industrial hosts, and industrial internet platforms.

[0081] The aforementioned processing tools include at least: built-in image backup, emergency forensics, asset identification, vulnerability detection, traffic analysis, log analysis, process analysis, malicious code detection, fusion analysis, and data recovery.

[0082] This invention also proposes an industrial information security emergency response system, comprising:

[0083] The cloud threat resource pool collects threat data at least through abnormal traffic collection, malware sample collection, and network scanners;

[0084] The remote support system adopts an edge-cloud collaborative model of "cloud system platform + on-site emergency response tool terminal" to remotely update, locate, and configure toolkits, ensuring real-time dynamic upgrades of emergency response tools. 。

[0085] The industrial information security emergency response tool terminal described above is communicatively connected to both the cloud threat resource pool and the remote support system.

[0086] The industrial information security emergency response system of this invention may further include:

[0087] The system includes a cloud-based management system and an expert review system. The expert review system can review data uploaded from the emergency response kit to the cloud-based threat resource pool, as well as threat data collected within the cloud-based threat resource pool. The cloud-based management system provides comprehensive management of both the emergency response kit and the cloud-based threat resource pool.

[0088] The industrial information security emergency response system according to an embodiment of the present invention will now be described in detail with reference to the accompanying drawings and a specific example. It is to be understood that the following description is merely exemplary and should not be construed as a specific limitation of the present invention.

[0089] Reference Figure 4 As shown, the industrial information security emergency response system of this invention includes an emergency response toolkit (i.e., an industrial information security emergency response tool terminal), a cloud threat resource pool, a remote support system, a cloud management system, and an expert review system.

[0090] The Industrial Information Security Emergency Response Kit is a terminal tool for emergency response personnel. It integrates with a cloud-based threat resource pool, breaking down information barriers and enabling real-time remote interactive communication. This allows for real-time updates and reporting of threat information. The cloud-based threat resource pool gathers massive amounts of threat information from external threat collection units, such as abnormal traffic collection, malicious code sample collection, and network scanner collection. The Industrial Information Security Emergency Response Kit, through its cloud-based integration, enables remote interactive communication for emergency response personnel, overcoming the limitations of individual operations during emergency response. It allows for timely access to external assistance when dealing with complex issues, facilitating the efficient and effective coordination of emergency response resources and expert teams. Furthermore, the kit utilizes the cloud-based threat resource pool for real-time sharing and updates of threat data, addressing the issue of outdated threat information within the kit. It synchronizes emerging and novel threat events from the cloud to the kit to improve emergency response capabilities and accuracy, while simultaneously uploading on-site threat information to the cloud-based threat resource pool to ensure its timeliness and reliability. The emergency response toolkit integrates a resource pool containing device fingerprints, vulnerability information, malware, security incidents, emergency knowledge, and response templates. An expert review system can review data uploaded from the emergency response toolkit to the cloud-based threat resource pool, as well as threat data collected within the cloud-based threat resource pool. The cloud-based management system provides comprehensive management of both the emergency response toolkit and the cloud-based threat resource pool.

[0091] The emergency response toolkit is used to complete the three major stages of event diagnosis, emergency response, and summary archiving.

[0092] Incident diagnosis, as the preparation phase for emergency response, primarily involves confirming the on-site situation, assessing symptoms and characteristics, and providing guidance based on diagnostic results. The main task of on-site situation confirmation is to determine the extent of damage to system applications, system data, and the scope and level of impact on system data according to emergency response standards. The main task of symptom and characteristic assessment is to preliminarily identify potential threats based on on-site observations, preliminary inspection findings, and symptom inquiries. The main task of providing guidance based on diagnostic results is to preliminarily predict the suspected causes of the threat event, the security incident level, and the security incident type based on symptom characteristics and the on-site situation, combined with an expert knowledge base.

[0093] Emergency response, as the core stage of emergency response, can leverage interaction with a cloud-based threat resource pool to help emergency responders efficiently perform operations such as detection, suppression, eradication, and recovery based on threat data. It can also utilize remote interactive communication functions for emergency response while standardizing emergency response procedures.

[0094] Emergency response procedures include the following stages:

[0095] 1. Preparation Phase: Focusing on prevention, the main tasks are identifying institutions and risks, and establishing security policies, systems, and procedures. Through cybersecurity measures, preparatory work is carried out, such as incident registration, emergency response, and, if conditions permit and permission is granted, establishing a data aggregation and analysis system, developing strategies and processes to achieve emergency response goals, establishing information communication channels through cloud-based collaboration, and forming a system capable of collectively handling emergencies.

[0096] Emergency response personnel assess the risk level based on the specific situation on-site, formally record and register the incident in the emergency task list for follow-up and handling. Simultaneously, they determine security policies, systems, and procedures based on the handling processes for similar incidents in a massive cloud-based threat resource pool and expert opinions.

[0097] 2. Detection Phase: This phase involves detecting whether the current emergency is in progress or has occurred afterward, identifying its causes, and determining the emergency response level and appropriate response plan. The main tasks include determining the nature and severity of the incident. Based on threat information from the cloud-based threat resource pool, such as handling templates, vulnerability databases, industrial control system fingerprint databases, malware databases, and security event databases, corresponding symptoms are matched. For example, vulnerability types are matched against vulnerability databases, device information against industrial control system fingerprint databases, and malware fragments against malware databases. Based on the matching results, handling template suggestions are provided to emergency response personnel from the handling template library to assist them in determining detection and remediation tools and procedures. Simultaneously, guidance is provided for recommending detection tools, analyzing anomalies, and estimating the scope of the security incident. By summarizing the findings, it is determined whether a large-scale network-wide incident has occurred, and the emergency response level and response plan are determined. Typical incident phenomena are detected, such as virus and malware attacks, hardware failures and equipment damage, data breaches and information theft, and unauthorized access and intrusion.

[0098] Based on the established procedures during the preparation phase, emergency response personnel conduct detection tasks to determine whether the incident occurred during or after the event, as well as the nature and severity of the incident. Based on the massive cloud threat resource pool containing suspected causes and handling templates for similar incidents, they select and determine the necessary detection and recovery tools for investigation and handling, conduct anomaly analysis, and finally determine the emergency level and plan.

[0099] 3. Suppression Phase: Limiting the scope, minimizing damage, and developing suppression strategies. The main task is to limit the scope of the attack and disruption while reducing potential losses. All suppression activities are based on accurate event detection; suppression strategies must be developed by combining the phenomena, nature, and scope identified in the detection phase. Suppression strategies typically include the following: completely shutting down all systems; disconnecting hosts or parts of the network from the network; modifying or deleting the attacked login accounts; strengthening monitoring of system or network behavior; setting up decoy servers to further obtain event information; and shutting down some services of the attacked system or other related systems.

[0100] Emergency detection personnel determine the scope of the impact based on the causes, phenomena, and nature of the events discovered during the detection phase. At the same time, based on the suppression strategies and behaviors of similar events in the massive cloud threat resource pool, they formulate specific suppression strategies in combination with the actual situation to suppress attack activities.

[0101] 4. Eradication Phase: Analyze and eliminate the root cause of the threat, and upload synchronized threat information. The main task is to analyze and completely eradicate the root cause to prevent attackers from using the same methods to attack the system again. Strengthen public awareness, upload and share threat information and solutions, and call on other users to update their emergency detection toolkits in real time to enhance detection efforts and identify and address issues in key industries and departments.

[0102] Building upon the suppression phase, emergency response personnel will conduct eradication operations to completely eliminate the threat and prevent attackers from using the same methods to attack systems and devices again via backdoors or other techniques. Simultaneously, they will strengthen detection efforts to identify and address potential issues within industries and key departments. Information regarding this threat event, such as abnormal traffic, malicious code, and vulnerability information, will be simultaneously uploaded to a massive cloud-based threat resource pool to ensure its timeliness and reliability. Other users are also urged to promptly (or automatically) update the threat resource information in their emergency toolkits, such as handling templates, vulnerability databases, industrial control system fingerprint databases, malicious code databases, and security event databases.

[0103] 5. Recovery Phase: Restore affected data, systems, and equipment to a normal state, and simultaneously harden the security of the restored system. The main tasks include completely restoring the damaged information to a normal operating state, recovering user data from trusted backup media, restoring system network connections, verifying the recovered system, observing other scans, and detecting signals that may indicate a re-intrusion. Furthermore, a comprehensive security hardening of the system is required after reinstallation, and a system recovery operation manual must be compiled and maintained.

[0104] After erasing the threat, emergency responders recover the compromised information from clean, reliable backup media provided in the toolkit. They also restore the system and devices to normal operating condition and monitor for any signs of re-intrusion. Following the incident, based on security hardening recommendations and relevant configuration documentation from a massive cloud-based threat resource pool, the system is hardened after reinstallation. A system recovery manual is also compiled and maintained.

[0105] 6. Summary Phase: Analyze, review, and integrate the incident response process, creating a revised summary document and synchronizing it to the cloud-based threat resource pool for iterative database updates. The main tasks include reviewing and integrating relevant information from the incident response process, conducting post-incident analysis and summarizing, revising security plans, policies, and procedures, and performing iterative training updates to prevent recurrence. Based on the severity and impact of the intrusion, determine whether to conduct a new risk analysis and create a new inventory of system and network assets. The summary phase mainly includes the following three aspects: generating a final incident handling report; reviewing problems identified during the incident response process, reassessing and modifying the incident response process; and evaluating deficiencies in communication among incident response personnel to facilitate more targeted post-incident training.

[0106] After recovering the damaged information and restoring the system and equipment to normal operation, emergency response personnel, guided by the emergency response kit, review the threat incident, integrate relevant information from the emergency response process, analyze and summarize, revise security strategies, and generate a comprehensive system document. This document is simultaneously uploaded to a massive cloud-based threat resource pool, providing more accurate and reliable guidance for the preparation phase of similar future threats and helping companies conduct targeted training for emergency response personnel afterward.

[0107] The eradication phase synchronizes threat event information, such as abnormal traffic, malicious code, and vulnerability information. The summary phase synchronizes summary solutions and event reviews, which are document-based summaries and event records.

[0108] As the final stage of emergency response, the summary and archiving process helps emergency responders reflect on and summarize the shortcomings and deficiencies in the emergency response process, enabling companies to track threat events in a reasonable and efficient manner, while also providing targeted training for responders.

[0109] This invention proposes the concept of a remote threat resource pool. Based on this, users can uniformly manage new and emerging threat events and information, such as buffer overflow vulnerabilities, phishing attacks, supply chain attacks, and network hijacking, reducing security risks and costs and enabling enterprises to move beyond isolated, isolated operations. This invention also proposes a specific emergency detection process and method for the industrial information security field: PDCERF. Based on this, industrial emergency response personnel can quickly and effectively detect and respond to sudden security incidents and perform standardized emergency response operations, while simultaneously helping enterprises improve their security incident response capabilities and refine their security management systems. Furthermore, this invention proposes a cloud-based, real-time, and interconnected approach between the emergency response kit and the threat resource pool. Communicating with the toolkit via 5G, wired, and wireless methods, the emergency response kit can keep pace with the latest developments and dynamically adjust, solving the problems of lag and rigid patterns in current technologies.

[0110] The emergency response kit of this invention enables remote interactive communication for emergency responders through cloud-based linkage, overcoming the limitations of individual operations during emergency response. It allows for timely access to off-site assistance when dealing with challenging situations, facilitating the efficient and timely mobilization of emergency response resources and expert teams. Furthermore, it enables real-time sharing and updating of threat data through a cloud-based threat resource pool, resolving the issue of outdated threat information within the emergency response kit. This not only synchronizes information on emerging and novel threat events from the cloud to the emergency response kit, improving emergency response capabilities and accuracy, but also uploads on-site threat information to the cloud-based threat resource pool, ensuring its timeliness and reliability.

[0111] In summary, the emergency response kit based on the threat resource pool not only enables remote interactive communication, making emergency response no longer a traditional, solitary mode, but also allows for timely updates of threat information, such as response templates, vulnerability databases, industrial control fingerprint databases, malware databases, and security event databases. It also dynamically adjusts guidance, making the emergency response kit shareable and timely, in line with the current trend of the Internet of Things.

[0112] It should be noted that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0113] It should be noted that any content not described in detail in this specification is common knowledge to those skilled in the art.

[0114] The terms “comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase “comprising one…” does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

Claims

1. An industrial information security emergency response method based on a cloud threat resource pool, characterized in that, include: Collect information about the scene and the symptoms of the incident; The on-site situation includes: the degree of damage to system applications, the degree of damage to system data, and the scope of impact on system data; the event symptoms include: phenomena directly observed on-site, phenomena discovered during preliminary inspections, symptoms discovered through questioning, and comprehensive phenomena. Based on the on-site situation and the event symptoms, prior knowledge features are used to automatically analyze and match the corresponding handling template from the terminal threat resources of the industrial information security emergency response tool; the terminal threat resources of the industrial information security emergency response tool contain a variety of handling templates, and each handling template has a different handling strategy; Based on the aforementioned handling template, and with the assistance of threat data from the terminal threat resources of the industrial information security emergency response tool, combined with threat data from the cloud threat resource pool, the emergency response operation is completed. The cloud threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners. Analyze the new threat data discovered during this emergency response operation and upload it to the cloud-based threat resource pool in real time; Compile the source tracing and handling documents for this emergency response and share them to the cloud-based threat resource pool.

2. The method as described in claim 1, characterized in that, Each of the aforementioned treatment templates corresponds to a feature calculation formula. At least one of the elements and the weights of the elements in the feature calculation formulas of different treatment templates is different. The elements correspond to the on-site situation and the event symptoms. The process of automatically analyzing and matching the corresponding handling template for this emergency response event from the terminal threat resources of industrial information security emergency response tools, based on the on-site situation and the event symptoms, and utilizing prior knowledge features, includes: Based on the on-site situation and the event symptoms, calculations are performed according to the feature calculation formulas corresponding to the various handling templates contained in the terminal threat resources of the industrial information security emergency response tool, to obtain multiple feature calculation results. The handling template corresponding to the feature calculation result with the largest value among the multiple feature calculation results is used as the handling template for this emergency response.

3. The method as described in claim 1, characterized in that, The emergency response operation, based on the aforementioned response template and using threat data from the terminal threat resources of the industrial information security emergency response tool, combined with threat data from the cloud-based threat resource pool, is completed as follows: Establish information communication channels with remote support systems through cloud-based collaboration to build a joint emergency response system; With the help of the joint emergency response system, based on the response template, and using the threat data in the terminal threat resources of the industrial information security emergency response tool, combined with the threat data in the cloud threat resource pool, this emergency response operation is completed.

4. The method as described in claim 1 or 3, characterized in that, The emergency response operation, based on the aforementioned response template and using threat data from the terminal threat resources of the industrial information security emergency response tool, combined with threat data from the cloud-based threat resource pool, is completed as follows: Based on the aforementioned handling template, following the PDCERF handling process of preparation, detection, suppression, eradication, recovery, and tracking, and with the assistance of the handling tools in the industrial information security emergency response tool terminal, based on the threat data in the threat resources of the industrial information security emergency response tool terminal and combined with the threat data in the cloud threat resource pool, emergency handling operations can be supported for at least mainstream industrial equipment, industrial hosts, and industrial internet platforms. The aforementioned processing tools include at least: built-in image backup, emergency forensics, asset identification, vulnerability detection, traffic analysis, log analysis, process analysis, malicious code detection, fusion analysis, and data recovery.

5. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores an information transmission implementation program, which, when executed by a processor, implements the steps of the industrial information security emergency response method based on a cloud threat resource pool as described in any one of claims 1 to 4.

6. An industrial information security emergency response tool terminal, characterized in that, include: The threat resources include threat data and various handling templates, each with a different handling strategy. The data acquisition and analysis module is remotely connected to the cloud-based threat resource pool. The data acquisition and analysis module is used to sort out the on-site records and newly discovered threat data during this emergency response operation and upload them to the cloud-based threat resource pool in real time. The template configuration module is communicatively connected to the threat resources. The template configuration module is used to determine the on-site situation and event symptoms, and based on the on-site situation and event symptoms, automatically analyzes and matches the corresponding emergency response template from the threat resources using prior knowledge features. The on-site situation includes: the degree of damage to system applications, the degree of damage to system data, and the scope of impact on system data; the event symptoms include: phenomena directly observed on-site, phenomena discovered during preliminary inspections, symptoms discovered through questioning, and comprehensive phenomena. The emergency response module is communicatively connected to both the template configuration module and the threat resources, and is also remotely connected to the cloud-based threat resource pool. The emergency response module is used to complete the emergency response operation based on the response template, the threat data in the threat resources, and the threat data from the cloud-based threat resource pool. The cloud-based threat resource pool collects threat data at least through abnormal traffic collection, malicious code sample collection, and network scanners. The summary and archiving module is remotely connected to the cloud-based threat resource pool. The summary and archiving module is used to organize the source tracing and handling documents of this emergency response and share them to the cloud-based threat resource pool.

7. The industrial information security emergency response tool terminal as described in claim 6, characterized in that, Each of the aforementioned treatment templates corresponds to a feature calculation formula. At least one of the elements and the weights of the elements in the feature calculation formulas of different treatment templates is different. The elements correspond to the on-site situation and the event symptoms. The template configuration module is used for: Based on the on-site situation and the event symptoms, calculations are performed according to the feature calculation formulas corresponding to the various handling templates included in the threat resources to obtain multiple feature calculation results; The handling template corresponding to the largest feature calculation result among the multiple feature calculation results is used as the handling template for this emergency response.

8. The industrial information security emergency response tool terminal as described in claim 6, characterized in that, The operation module establishes an information communication channel with the remote support system through cloud linkage, thereby building an industrial information security emergency response system. The handling operation module is used to cooperate with the remote support system to complete the emergency handling operation based on the handling template, the threat data in the threat resources, and the threat data in the cloud threat resource pool.

9. The industrial information security emergency response tool terminal as described in claim 6 or 8, characterized in that, The disposal operation module is used for: Based on the aforementioned handling template, following the PDCERF handling process of preparation, detection, suppression, eradication, recovery, and tracking, and with the assistance of the aforementioned handling tools based on the threat data in the threat resources and the threat data in the cloud threat resource pool, emergency handling operations can be supported for at least mainstream industrial equipment, industrial hosts, and industrial internet platforms. The aforementioned processing tools include at least: built-in image backup, emergency forensics, asset identification, vulnerability detection, traffic analysis, log analysis, process analysis, malicious code detection, fusion analysis, and data recovery.

10. An industrial information security emergency response system, characterized in that, include: The cloud threat resource pool collects threat data at least through abnormal traffic collection, malware sample collection, and network scanners; Remote support system; The industrial information security emergency response tool terminal as described in any one of claims 6-9 is communicatively connected to both the cloud threat resource pool and the remote support system.