Industrial internet network security risk assessment method and system

By acquiring and aggregating network information from mobile terminals, identifying potential risk factors, and simulating attack paths, this approach solves the challenges of assessment blind spots and threat tracking in the face of highly mobile and intermittently connected terminals, thus achieving dynamic and real-time security protection for industrial internet networks.

CN121985336APending Publication Date: 2026-05-05WUXI INSTITUTE OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
WUXI INSTITUTE OF TECHNOLOGY
Filing Date
2026-01-30
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Traditional cybersecurity risk assessment methods suffer from blind spots, inability to track evolving threats, and difficulty in continuously monitoring external access channels when dealing with highly mobile, intermittently connected devices (such as autonomous mobile robots, AMRs).

Method used

By acquiring and aggregating network information from mobile terminals, including physical location information, network connection information, and network communication behavior information, potential risk factors can be identified. Attack paths that attackers might use mobile terminals as springboards can be simulated to quantify risks, restrict the physical movement or network communication behavior of mobile terminals, and adjust network access rules to isolate potential attack targets.

Benefits of technology

It enables dynamic and real-time risk assessment of highly mobile and intermittently connected network terminals, effectively solving the problems of assessment blind spots and inability to track evolving threats, and improving the real-time, accuracy and proactiveness of industrial internet network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121985336A_ABST
    Figure CN121985336A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial internet network security risk assessment, and discloses an industrial internet network security risk assessment method and system. Physical position information, network connection information and network communication behavior information of a mobile terminal are acquired and gathered; and the real-time network state and behavior characteristics of the mobile terminal can be comprehensively mastered. According to the method, the potential risk factors of the mobile terminal can be identified based on the converged network information, an attacker is simulated to take the mobile terminal as an attack path of a springboard, and risk quantification is carried out on the attack path. The dynamic and real-time risk assessment mechanism effectively solves the problems that in the prior art, assessment blind areas exist in high-mobility and intermittent network connection terminals, and evolution threats cannot be tracked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial internet network security risk assessment technology, and in particular to an industrial internet network security risk assessment method and system. Background Technology

[0002] In modern industrial environments, the security of Industrial Internet networks is crucial for production continuity and data integrity. Traditional cybersecurity risk assessment methods typically rely on periodic scanning and static analysis, which are effective for environments with relatively fixed network structures. However, with the introduction of highly mobile, intermittently network-connected terminals such as autonomous mobile robots (AMRs), traditional methods face significant limitations. The real-time changing nature of these mobile terminals introduces complexities that traditional static assessments struggle to address, potentially leading to security blind spots and failing to track evolving threats.

[0003] In a large discrete manufacturing plant, to improve production efficiency, an Industrial Internet system was deployed, connecting PLCs, CNC machine tools, industrial robots, and various sensors via Industrial Ethernet. The plant's cybersecurity team employs standard cybersecurity risk assessment methods, regularly performing port scans, service identification, and vulnerability matching on all online devices within the network, and checking network device configurations and access control lists. This snapshot-based, periodic assessment model effectively identifies and addresses most static security issues, especially given the relatively fixed plant network structure.

[0004] However, with the introduction of an internal logistics team consisting of dozens of autonomous mobile robots (AMRs) in the factory, utilizing industrial-grade wireless networks for communication and task scheduling, the factory's network topology has become highly dynamic and complex, changing in real time. AMRs constantly move within the factory area, automatically switching between connected wireless access points, and their network online status is not continuous. This real-time variability and intermittent nature of network behavior poses a challenge to the existing periodic scanning and evaluation methods: during scanning windows, some AMRs may go offline due to charging or being in signal dead zones, causing the scanning program to fail to detect them, creating evaluation blind spots.

[0005] Furthermore, the AMR is provided by a third-party vendor, who, for remote fault diagnosis and software upgrades, requires a specific remote access tunnel to be opened on the factory firewall. This tunnel allows vendor engineers to connect directly to the AMR management server inside the factory via VPN, thereby accessing each AMR. This introduces a new, externally controlled attack entry point. Traditional risk assessment methods might identify this open VPN port, but they cannot continuously monitor the traffic content and behavior through this tunnel, nor can they assess whether the vendor's operations personnel's actions are compliant or malicious.

[0006] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention

[0007] This invention provides a method and system for assessing cybersecurity risks in the industrial internet, aiming to solve the technical problems of existing industrial internet cybersecurity risk assessment methods, such as assessment blind spots, inability to track evolving threats, and difficulty in continuously monitoring external access channels when facing highly mobile, intermittently connected network terminals (such as autonomous mobile robots, AMRs).

[0008] Firstly, in order to solve the above-mentioned technical problems, the present invention provides an industrial internet network security risk assessment method, comprising: The network information of the mobile terminal is acquired and aggregated, including physical location information, network connection information, and network communication behavior information. Based on the aggregated network information, potential risk factors of the mobile terminal are identified, and an attack path in which an attacker uses the mobile terminal as a springboard is simulated, and the risk of the attack path is quantified. Based on the risk quantification results, the physical movement or network communication behavior of the mobile terminal is restricted, and network access rules are adjusted to isolate the communication between the mobile terminal and potential attack targets.

[0009] Preferably, the step of identifying potential risk factors of the mobile terminal based on the aggregated network information and simulating an attack path where an attacker uses the mobile terminal as a springboard includes: Acquire the location data, network connection data, network communication behavior data, and environmental perception data of the mobile terminal; Based on the environmental perception data, it is determined whether the mobile terminal is in an area of ​​electromagnetic interference; When the mobile terminal is in the electromagnetic interference area, the communication characteristics of the mobile terminal are calibrated for background noise according to the preset environmental interference behavior law of the electromagnetic interference area. The purposeful analysis of the communication characteristics after background noise calibration includes: Compare the communication target with the mobile terminal's legitimate communication target whitelist; Compare the communication protocol with the valid protocols under the current task type of the mobile terminal; Associated communication time, physical location of the mobile terminal, and current task status; Based on the results of the purposeful analysis, identify malicious communications; Based on the malicious communication, the attack path is deduced.

[0010] Preferably, the purposeful analysis of the communication characteristics after background noise calibration includes: Obtain information on production plan adjustments, equipment upgrades, and network topology changes; Based on the production plan adjustment information, the equipment upgrade information, and the network topology change information, the whitelist of legitimate communication targets and the set of legitimate protocols are dynamically updated. Compare the background noise-calibrated communication target, the communication protocol, the dynamically updated whitelist of legitimate communication targets, and the set of legitimate protocols to obtain a first comparison result; Analyze the communication frequency after background noise calibration and the data packet size; Based on the first comparison and analysis results, malicious communication is identified.

[0011] Preferably, the analysis of the background noise-calibrated communication frequency and the data packet size includes: Obtain the production task type of the mobile terminal; Obtain the operating status information of the mobile terminal; Based on the production task type and the operating status information, obtain the normal range of the communication frequency; Based on the production task type and the operating status information, obtain the normal range of the data packet size; Compare the background noise calibrated communication frequency with the normal range of the communication frequency to obtain a second comparison result; The size of the data packet after background noise calibration is compared with the normal range of the data packet size to obtain a third comparison result; Based on the second comparison result and the third comparison result, a communication anomaly is determined.

[0012] Preferably, determining communication anomalies based on the second comparison result and the third comparison result includes: Obtain the communication frequency comparison result and data packet size comparison result of the mobile terminal; When the communication frequency comparison result or the data packet size comparison result shows that the communication is in the edge area of ​​the normal range, the communication is marked as edge abnormal communication; Obtain the historical communication behavior records of the mobile terminal; Obtain the sensitivity level of the target device involved in the abnormal edge communication; Analyze the difference between the fluctuation trend of the abnormal edge communication and the fluctuation trend in the historical communication behavior records; Based on the difference in fluctuation trends and the sensitivity level of the target device, the abnormal edge communication is determined to be malicious communication.

[0013] Preferably, the analysis of the fluctuation trend of the abnormal edge communication differs from the fluctuation trend in the historical communication behavior records, including: Obtain the real-time communication frequency and data packet size of the mobile terminal in its current production task type and operating status; Acquire the group behavior data of the mobile terminal in terms of communication frequency and data packet size of other similar mobile terminals in the current production task type and the current operating state; By comparing the real-time communication frequency and the data packet size with the group behavior data, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the fluctuation trend.

[0014] Preferably, comparing the real-time communication frequency and the data packet size with the group behavior data includes: Identify the correlation pattern between the real-time communication frequency and the data packet size in the group behavior data; By comparing the correlation patterns, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the correlation pattern.

[0015] Preferably, the correlation pattern between the real-time communication frequency and the data packet size in the group behavior data identification includes: Time series decomposition is performed on the communication frequency sequence and the data packet size sequence in the group behavior data to separate the trend component, periodic component and residual component; Pattern matching is performed on the trend component and the periodic component to identify multiple potential correlation patterns; The fit of multiple potential correlation patterns is evaluated based on the magnitude of the residual components; The association pattern with a fitting degree exceeding a preset threshold is selected as the association pattern between the communication frequency and the data packet size.

[0016] Preferably, evaluating the fit of multiple potential association patterns based on the magnitude of the residual components includes: Obtain the current production task type and the running status information of the mobile terminal; Based on the production task type and the operating status information, obtain the normal fluctuation range and evaluation sensitivity of the residual component; Based on the normal fluctuation range of the residual components and the evaluation sensitivity, the fitting scores of the multiple potential correlation patterns are calculated; The fit score is used to evaluate the degree of fit of the plurality of potential association patterns.

[0017] Secondly, an industrial internet cybersecurity risk assessment system includes: The detection end is used to acquire and aggregate network information of the mobile terminal, including physical location information, network connection information, and network communication behavior information. The simulation terminal is used to identify potential risk factors of the mobile terminal based on the aggregated network information, simulate the attack path of an attacker using the mobile terminal as a springboard, and quantify the risk of the attack path. The adjustment end is used to restrict the physical movement or network communication behavior of the mobile terminal based on the risk quantification results, and adjust network access rules to isolate the communication between the mobile terminal and potential attack targets.

[0018] This invention provides a method and system for assessing network security risks in the industrial internet. By acquiring and aggregating the physical location information, network connection information, and network communication behavior information of mobile terminals, it can comprehensively grasp the real-time network status and behavioral characteristics of mobile terminals. Based on this, the method can identify potential risk factors of mobile terminals using the aggregated network information and simulate attack paths where attackers use mobile terminals as springboards, quantifying the risks of these attack paths. This dynamic, real-time risk assessment mechanism effectively solves the problems of assessment blind spots and the inability to track evolving threats in existing technologies for highly mobile, intermittently connected terminals (such as autonomous mobile robots, AMRs). Finally, based on the risk quantification results, the method can restrict the physical movement or network communication behavior of mobile terminals and adjust network access rules to isolate communication between mobile terminals and potential attack targets, thereby achieving rapid response and effective containment of risks. Compared to traditional periodic scanning and static analysis methods, this application can continuously monitor the traffic content and behavior through external access channels and assess its compliance or the presence of malicious intent, overcoming the limitations of existing technologies in the face of complex and ever-changing industrial internet environments, and significantly improving the real-time performance, accuracy, and proactivity of industrial internet network security protection. Attached Figure Description

[0019] Figure 1 This is a flowchart of an industrial internet network security risk assessment method provided by an embodiment of the present invention; Figure 2 This is a flowchart of a method for calibrating background noise according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an industrial internet network security risk assessment system provided by the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Reference Figure 1 , Figure 1 This is a flowchart of an industrial internet network security risk assessment method provided by an embodiment of the present invention, including the following steps: S1, acquire and aggregate network information of the mobile terminal, the network information including physical location information, network connection information and network communication behavior information; S2, based on the aggregated network information, identify the potential risk factors of the mobile terminal, simulate the attack path of an attacker using the mobile terminal as a springboard, and quantify the risk of the attack path; S3. Based on the risk quantification results, restrict the physical movement or network communication behavior of the mobile terminal and adjust the network access rules to isolate the communication between the mobile terminal and potential attack targets.

[0022] The industrial internet network security risk assessment method proposed in this application aims to address the limitations of traditional methods when dealing with highly mobile, intermittently connected terminals (such as autonomous mobile robots, AMRs). By acquiring and aggregating network information from mobile terminals in real time, including physical location information, network connection information, and network communication behavior information, this method can comprehensively and dynamically grasp the security posture of mobile terminals. Based on this, the method can identify potential risk factors, simulate attack paths, and quantify risks, thereby providing data support for subsequent risk control. Finally, based on the risk quantification results, this method can flexibly restrict the physical movement or network communication behavior of mobile terminals and adjust network access rules to effectively isolate communication between mobile terminals and potential attack targets, thereby significantly improving the security protection capabilities of industrial internet networks.

[0023] In order to better understand the technical solutions proposed in this application, it is necessary to explain some key terms involved therein.

[0024] "Mobile terminal" refers to devices in the industrial internet environment that have mobility and are capable of network communication, such as autonomous mobile robots (AMRs), handheld scanners, and wireless sensor nodes. These terminals are characterized by the frequent changes in their physical location and network connection status.

[0025] "Network information" refers to data related to the network activities of mobile terminals, specifically including: "Physical location information" refers to the geographical coordinates or regional location of a mobile terminal in an industrial site, which can be obtained through technologies such as GPS, UWB (Ultra-Wideband), and Wi-Fi positioning.

[0026] "Network connection information" refers to the current network access status of the mobile terminal, such as the name of the connected wireless access point (AP), IP address, MAC address, signal strength, connection duration, etc.

[0027] "Network communication behavior information" refers to the specific communication activities carried out by the mobile terminal in the network, such as the source / destination IP address, port number, protocol type, data packet size, communication frequency, and communication content summary.

[0028] "Potential risk factors" refer to various factors that may lead to cybersecurity incidents, such as unauthorized communication behavior, abnormal data transmission patterns, known vulnerabilities, and configuration errors.

[0029] An "attack path" refers to a series of network nodes and operational steps that an attacker goes through to gradually penetrate from an initial point of intrusion (such as a compromised mobile terminal) to the final target (such as critical production equipment or control system).

[0030] "Risk quantification" refers to the qualitative or quantitative assessment of identified attack paths to determine their potential harm and probability of occurrence.

[0031] "Physical movement restriction" refers to restricting the range of activity of mobile terminals in a specific area through technical or management means, such as geofencing technology.

[0032] "Network communication behavior restriction" refers to controlling the network communication of mobile terminals, such as preventing them from accessing specific IP addresses, ports or protocols, or limiting their data transmission rate.

[0033] "Network access rules" refer to the policies configured on network devices such as firewalls and routers to control the flow of network traffic.

[0034] "Potential targets" refer to critical devices, systems, or data resources that attackers may attempt to compromise, steal, or control.

[0035] The core of the industrial internet network security risk assessment method proposed in this application lies in the comprehensive acquisition and intelligent analysis of mobile terminal network information, and on this basis, risk assessment and control.

[0036] First, regarding "acquiring and aggregating network information of mobile terminals, including physical location information, network connection information, and network communication behavior information," various technical means can be employed to achieve this step. For example, the physical location information of mobile terminals can be acquired in real time by deploying positioning base stations (such as UWB base stations or Wi-Fi positioning systems) within the factory. These base stations periodically receive positioning signals sent by mobile terminals and calculate their precise locations. Network connection information can be obtained through network monitoring modules deployed on wireless access points (APs). These modules can record data such as the MAC address, IP address, connected AP, signal strength, and connection duration of each mobile terminal. As for network communication behavior information, it can be achieved by deploying traffic mirroring or bypass monitoring devices at key network nodes. These devices can capture all incoming and outgoing traffic from mobile terminals and extract detailed information such as source / destination IP addresses, port numbers, protocol types, packet sizes, and communication frequencies. All this acquired information is then aggregated into a central data platform for storage and preliminary processing.

[0037] Secondly, regarding "identifying potential risk factors of the mobile terminal based on the aggregated network information, simulating attack paths where attackers use the mobile terminal as a springboard, and quantifying the risks of the attack paths," after acquiring and aggregating various network information of the mobile terminal, the next step is to use this information for risk identification and attack path simulation. For example, machine learning models can be used to analyze the aggregated network communication behavior information to identify communication behaviors that deviate significantly from normal behavior patterns. These deviations may indicate potential risk factors, such as unauthorized port scanning, abnormal data transmission volumes, or communication with blacklisted IP addresses.

[0038] Simultaneously, by combining the physical location and network connection information of the mobile terminal, a real-time network topology map can be constructed. On this topology map, attackers can simulate using identified risk factors, employing the mobile terminal as a springboard to attempt to penetrate other critical devices or systems. For example, if a mobile terminal is identified as having a known vulnerability, and a high-value PLC device exists within its currently connected network area, the system can simulate an attacker exploiting this vulnerability to attempt to access the PLC device through the mobile terminal, recording this potential attack path. For each simulated attack path, factors such as device vulnerabilities, data sensitivity, and access control policies involved in the path can be considered, and standardized risk assessment models such as CVSS (Common Vulnerability Scoring System) can be used to quantify the success probability and potential impact of the attack path, thereby obtaining a risk score.

[0039] Finally, regarding "restricting the physical movement or network communication behavior of the mobile terminal based on the risk quantification results, and adjusting network access rules to isolate communication between the mobile terminal and potential attack targets," after quantifying the attack path risk, the system will take corresponding risk control measures based on the quantification results. For example, if a mobile terminal is identified as having a high-risk attack path and its risk score exceeds a preset threshold, the system can immediately send an instruction to the mobile terminal management system to restrict the physical movement range of the mobile terminal, locking it in a secure area, or directly stopping its current task and guiding it back to a charging station for isolation. Simultaneously, the system can automatically adjust network access rules, such as adding new policies to the firewall to block all network communication between the mobile terminal and potential attack targets, or isolating it in a separate VLAN, thereby cutting off the attack path. These restrictions and adjustments are dynamic and real-time, enabling rapid response to changes in the risk situation and minimizing losses caused by potential attacks.

[0040] The industrial internet cybersecurity risk assessment method proposed in this application achieves comprehensive and dynamic perception of the security posture of mobile terminals in the industrial internet environment by integrating the physical location information, network connection information, and network communication behavior information of mobile terminals. The core innovation of this method lies in its ability to identify potential risk factors based on multi-source heterogeneous information and simulate attack paths where attackers use mobile terminals as springboards, thereby quantifying the risks of attack paths.

[0041] Compared to traditional methods that rely on periodic scanning and static analysis, this application's advantage lies in its ability to respond in real-time to the dynamic changes of mobile terminals. Traditional methods are prone to creating security blind spots and failing to effectively track evolving threats when dealing with highly mobile, intermittently connected terminals such as autonomous mobile robots (AMRs). For example, after the introduction of AMRs in a factory, the network topology becomes highly dynamic and complex in real-time. AMRs constantly move within the factory area, automatically switching connected wireless access points, and their network online status is not continuous. This makes it difficult for traditional snapshot-based periodic assessment models to detect and address all security issues.

[0042] This application overcomes the limitations of traditional methods by acquiring and aggregating network information from mobile terminals in real time. For example, by continuously monitoring the physical location, network connection status, and communication behavior of the AMR (Automatic Mobile Controller), its historical data and behavioral patterns can be recorded and analyzed even if the AMR is offline during the scanning window, thus avoiding assessment blind spots. Furthermore, this method can simulate attack paths where attackers use mobile terminals as springboards and quantify the risks of these paths. This allows security teams to gain a deeper understanding of potential threats and take targeted defensive measures. For instance, when an AMR is identified as having a high-risk attack path, the system can immediately restrict its physical movement or network communication behavior and adjust network access rules, effectively isolating potential attacks. This dynamic, real-time risk assessment and response mechanism significantly enhances the security protection capabilities of industrial internet networks, ensuring production continuity and data integrity.

[0043] Specifically, in some implementations of the aforementioned industrial internet network security risk assessment method, this application provides more detailed implementation steps for the step of identifying potential risk factors of mobile terminals based on aggregated network information and simulating attack paths where attackers use mobile terminals as springboards.

[0044] The process of identifying potential risk factors of the mobile terminal based on the aggregated network information and simulating an attack path where an attacker uses the mobile terminal as a springboard includes: Acquire the location data, network connection data, network communication behavior data, and environmental perception data of the mobile terminal; Based on the environmental perception data, it is determined whether the mobile terminal is in an area of ​​electromagnetic interference; When the mobile terminal is in the electromagnetic interference area, the communication characteristics of the mobile terminal are calibrated for background noise according to the preset environmental interference behavior law of the electromagnetic interference area. The purposeful analysis of the communication characteristics after background noise calibration includes: Compare the communication target with the mobile terminal's legitimate communication target whitelist; Compare the communication protocol with the valid protocols under the current task type of the mobile terminal; Associated communication time, physical location of the mobile terminal, and current task status; Based on the results of the purposeful analysis, identify malicious communications; Based on the malicious communication, the attack path is deduced.

[0045] Acquiring location data, network connection data, network communication behavior data, and environmental perception data from mobile terminals refers to the real-time collection and aggregation of this crucial information through various sensors and network devices deployed in industrial settings, as well as modules carried by the mobile terminals themselves. Location data indicates the physical location of the mobile terminal, network connection data reflects the network topology it accesses, network communication behavior data records details such as communication frequency, target, and protocol, while environmental perception data includes physical parameters of the environment in which the mobile terminal is located, such as electromagnetic field strength, temperature, and humidity.

[0046] Furthermore, based on the acquired environmental perception data, the system can determine whether the mobile terminal is in an electromagnetic interference area. In industrial environments, factors such as the operation of large equipment and cable laying can generate complex electromagnetic environments, leading to communication signal distortion or anomalies. When the mobile terminal is determined to be in an electromagnetic interference area, in order to eliminate the interference of environmental factors on communication characteristic analysis, the communication characteristics of the mobile terminal will be calibrated for background noise according to the preset environmental interference behavior patterns of that electromagnetic interference area. This calibration process aims to filter out or compensate for communication anomalies caused by electromagnetic interference, ensuring the accuracy of subsequent analysis.

[0047] Based on this, a purposeful analysis is performed on the communication characteristics after background noise calibration. Specifically, the purposeful analysis includes multiple dimensions: First, the target of the communication is compared with the mobile terminal's legitimate whitelist of communication targets to determine whether the recipient is an authorized entity. Second, the communication protocol is compared with the legitimate protocols under the mobile terminal's current task type to ensure that the protocol used for communication meets current business requirements. Finally, the time of communication, the physical location of the mobile terminal, and the current task status are considered to comprehensively determine the rationality and legality of the communication behavior. For example, if a mobile terminal communicates with a non-whitelisted target outside of working hours and in an unauthorized area, its malicious intent will be greatly increased.

[0048] Based on the results of the above purposeful analysis, the system can identify malicious communications. Once malicious communications are identified, the system can deduce attack paths that attackers might use the mobile terminal as a springboard, based on the characteristics and contextual information of these malicious communications. The deduction process can simulate the potential path by which an attacker, starting from the mobile terminal, gradually penetrates other critical assets of the industrial control system through network connections and known vulnerabilities.

[0049] This application's solution improves the accuracy of identifying potential risk factors in mobile terminals and the realism of attack path simulation by introducing multi-dimensional data acquisition and refined analysis mechanisms. Specifically, by acquiring location data, network connection data, network communication behavior data, and environmental awareness data, the system can comprehensively understand the operating status of the mobile terminal and its physical environment. The use of environmental awareness data enables the system to identify whether the mobile terminal is in an electromagnetic interference area, and in this case, to calibrate the communication characteristics against background noise based on preset environmental interference patterns. This calibration process effectively filters out the influence of environmental noise on communication data, ensuring the accuracy of subsequent analysis and avoiding misjudgments caused by environmental factors.

[0050] Furthermore, a purposeful analysis is performed on the communication characteristics after background noise calibration. By comparing the communication target with a whitelist of legitimate communication targets, comparing the communication protocol with legitimate protocols under the current task type, and associating the communication occurrence time, the physical location of the mobile terminal, and the current task status, a multi-dimensional legitimacy judgment model is constructed. This comprehensive analysis method can more accurately determine the intent of communication behavior, thereby effectively identifying potential malicious communication. Once malicious communication is identified, the system can deduce attack paths that attackers might use mobile terminals as springboards based on the characteristics and contextual information of these malicious communications, providing precise input for subsequent risk quantification and defense measures.

[0051] Through the aforementioned technical solutions, this application significantly improves the accuracy and reliability of industrial internet network security risk assessment. Specifically, by introducing environmental awareness data and performing background noise calibration, the negative impact of complex factors such as electromagnetic interference in industrial environments on communication data analysis is effectively addressed, reducing the false alarm rate. Furthermore, the multi-dimensional purposeful analysis mechanism, combining information such as communication targets, protocols, time, location, and task status, makes the identification of malicious communication more accurate, avoiding vulnerabilities that may arise from single-dimensional judgments. Therefore, the system can more accurately identify potential risk factors and more realistically simulate attack paths, providing stronger technical support for the security protection of the industrial internet and effectively enhancing overall network security defense capabilities.

[0052] Traditional industrial internet cybersecurity risk assessment methods often rely on pre-defined or statically updated whitelists of legitimate communication targets and sets of legitimate protocols when conducting targeted analysis of mobile terminal network communication characteristics. However, in the industrial internet environment, production plans, equipment upgrades, and network topology may change frequently. Failure to update these security policies in a timely manner may lead to legitimate communication being misjudged as abnormal, or malicious communication failing to be effectively identified due to policy lag, thus affecting the accuracy and real-time nature of risk assessments.

[0053] In this regard, refer to Figure 2 , Figure 2 This is a flowchart of a method for calibrating background noise according to an embodiment of the present invention, including: S21, obtain information on production plan adjustments, equipment upgrades, and network topology changes; S22, dynamically update the whitelist of legitimate communication targets and the set of legitimate protocols based on the production plan adjustment information, the equipment upgrade information, and the network topology change information; S23, compare the communication target after background noise calibration, the communication protocol with the dynamically updated whitelist of legal communication targets and the set of legal protocols, and obtain the first comparison result; S24, Analyze the communication frequency and data packet size after background noise calibration; S25, based on the first comparison result and analysis result, identify malicious communication.

[0054] Specifically, obtaining production plan adjustment information, equipment upgrade information, and network topology change information refers to acquiring the latest change data on production tasks, equipment status, and network architecture from sources such as industrial control systems, manufacturing execution systems (MES), or asset management systems (AMS). This information may include, but is not limited to, the start / end time of production tasks, the device IDs involved, device firmware or software version updates, and configuration changes or additions / removals of network devices (e.g., switches, routers).

[0055] Specifically, the whitelist of legitimate communication targets and the set of legitimate protocols are dynamically updated based on the production plan adjustment information, equipment upgrade information, and network topology change information. This aims to ensure that the security policy remains synchronized with the actual operational status of the industrial site. For example, when a production plan adjustment requires a mobile terminal to communicate with new production equipment, the IP address or port information of the new equipment will be added to the whitelist of legitimate communication targets; when an equipment upgrade introduces a new communication protocol, that protocol will be added to the set of legitimate protocols.

[0056] In practical applications, comparing the background noise-calibrated communication target, the communication protocol, and the dynamically updated whitelist of legitimate communication targets and the set of legitimate protocols to obtain the first comparison result means matching the real-time communication data after background noise calibration with the latest updated legitimate policies. If the communication target or communication protocol does not conform to the dynamically updated whitelist or protocol set, it is marked as abnormal and used as the first comparison result.

[0057] Furthermore, analyzing the background noise-calibrated communication frequency and the data packet size aims to identify potential anomalies at the behavioral pattern level. Even if the communication goals and protocols appear legitimate, abnormal communication frequencies (e.g., frequent communication far exceeding the normal range or prolonged silence) or abnormal data packet sizes (e.g., transmission of large amounts of non-business data or extremely small data packets) may indicate malicious behavior.

[0058] Ultimately, based on the first comparison and analysis results, identifying malicious communication means comprehensively considering the compliance of the communication target / protocol and the abnormality of the communication frequency / data packet size to make a more accurate judgment on malicious communication. For example, if the communication target or protocol is illegal, it is directly identified as malicious communication; if the communication target and protocol are legal, but the communication frequency or data packet size is significantly abnormal, it may also be identified as malicious communication.

[0059] This application's solution dynamically updates the whitelist of legitimate communication targets and the set of legitimate protocols by incorporating production plan adjustment information, equipment upgrade information, and network topology change information. Because the dynamic nature of the industrial internet environment is fully considered, the criteria for judging legitimate communication can reflect the current production status and network configuration in real time, thus avoiding false alarms or missed alarms due to policy lag. Simultaneously, by analyzing communication frequencies and packet sizes after background noise calibration, this solution can detect anomalies from deep patterns in communication behavior. Even if attackers attempt to disguise legitimate communication, their abnormal communication frequency or packet size characteristics are difficult to conceal. This multi-dimensional and dynamic analysis mechanism significantly improves the accuracy and robustness of malicious communication identification.

[0060] Through the above technical solution, this application effectively addresses the problem of outdated security policies caused by dynamic changes in the industrial environment in traditional methods. Dynamically updating the whitelist of legitimate communication targets and the set of legitimate protocols ensures a high degree of alignment between security policies and actual business scenarios, significantly reducing false alarm rates. Furthermore, combined with in-depth analysis of communication frequency and data packet size, the identification of malicious communication no longer relies solely on static identity or protocol matching, but can be more refined based on behavioral patterns. This improves the detection capability for new or covert attacks and provides more accurate and real-time foundational data for industrial internet network security risk assessment.

[0061] In some preferred embodiments, it is assumed that a mobile terminal 100 (e.g., an AGV) performs material handling tasks on an industrial production line. Initially, its legitimate communication target whitelist only contains communication addresses with the central dispatch system 200 and the charging pile 300, and its legitimate protocol set only contains the MQTT protocol.

[0062] Specifically, when the production plan is adjusted, requiring the AGV 100 to exchange data with the newly added intelligent warehouse robot 400, the system will obtain the production plan adjustment information. Based on this information, the communication address of the intelligent warehouse robot 400 will be dynamically added to the AGV 100's legitimate communication target whitelist. Simultaneously, if the intelligent warehouse robot 400 adopts a new communication protocol (e.g., OPC UA), that protocol will also be dynamically added to the legitimate protocol set.

[0063] Subsequently, when the AGV 100 communicates with the intelligent warehouse robot 400, even if the communication is new, it will be judged as legitimate by the first comparison result because the whitelist of legitimate communication targets and the set of legitimate protocols have been dynamically updated.

[0064] Furthermore, the system will also analyze the communication frequency and data packet size between the AGV 100 and the intelligent warehouse robot 400. For example, if the communication frequency between the AGV 100 and the intelligent warehouse robot 400 suddenly increases abnormally after the AGV 100 completes a material handling task, or transmits data packets far exceeding the task requirements, even if the communication target and protocol are legitimate, the system will identify this as potentially malicious communication, such as an attempt to steal data or inject instructions, based on the analysis results of the communication frequency and data packet size, combined with the first comparison results.

[0065] In this way, the solution proposed in this application can adapt to the rapid changes in industrial sites and identify potential malicious communications from multiple dimensions, thereby improving the accuracy and real-time nature of risk assessment.

[0066] In some embodiments of this application described above, when performing targeted analysis of the communication characteristics after background noise calibration, it is necessary to analyze the communication frequency and data packet size after background noise calibration. Specifically, the analysis of the communication frequency and data packet size after background noise calibration may include the following steps: First, the production task type of the mobile terminal is determined. This production task type can refer to the industrial production task currently being performed by the mobile terminal, such as data acquisition, equipment control, inspection, maintenance, or diagnostics. Different production task types typically correspond to different communication modes and data exchange requirements.

[0067] Secondly, the operating status information of the mobile terminal is obtained. This operating status information may include the mobile terminal's CPU utilization, memory usage, battery level, sensor status, network load, processing power, etc. The operating status of the mobile terminal directly affects its communication behavior; for example, under high load, communication may experience delays or frequency changes.

[0068] Furthermore, based on the acquired production task type and the operational status information, the normal range of the communication frequency is obtained. The normal range of the communication frequency is modeled and determined for specific production task types and operational states based on historical data, preset rules, expert experience, or machine learning models. For example, the normal range of the communication frequency may be higher when performing high-speed data acquisition tasks; while in standby or low-power modes, the normal range of the communication frequency may be lower.

[0069] Simultaneously, based on the acquired production task type and the operational status information, a normal range for the data packet size is determined. Similar to the communication frequency, the normal range for the data packet size is also dynamically determined based on the current context of the mobile terminal (production task type and operational status). For example, the data packet size may be smaller when transmitting control commands, while it may be larger when transmitting image or video data.

[0070] Subsequently, the communication frequency after background noise calibration is compared with the normal range of the communication frequency to obtain a second comparison result. The second comparison result is used to indicate the degree of deviation between the actual communication frequency and the normal range.

[0071] Next, the size of the data packet after background noise calibration is compared with the normal range of the data packet size to obtain a third comparison result. The third comparison result is used to indicate the degree of deviation between the actual data packet size and the normal range.

[0072] Finally, based on the second and third comparison results, a communication anomaly is determined. A communication anomaly is identified when the actual communication frequency or data packet size significantly exceeds its corresponding normal range.

[0073] This application's solution dynamically and granularly defines the normal range of communication frequency and data packet size by incorporating the production task type and operational status information of the mobile terminal. Traditional methods may use static or coarse-grained normal ranges, leading to normal communication behavior being misjudged as abnormal when the mobile terminal switches tasks or changes its status, or abnormal behavior being ignored because it falls within a broad "normal" range. This solution is based on a deep understanding of the complexity of mobile terminal behavior in the Industrial Internet environment. By closely linking communication behavior with specific business contexts (production tasks) and equipment status (operational status), it makes the analysis of communication frequency and data packet size more targeted and accurate. This allows for more effective identification of communication patterns that are inconsistent with current normal business activities, thus providing a more reliable basis for subsequent malicious communication identification.

[0074] Through the above technical solution, this application can significantly improve the accuracy of malicious communication identification in industrial internet network security risk assessment. Specifically, by considering the production task type and operating status information of mobile terminals, a more refined and dynamic baseline of communication behavior can be established, avoiding false alarms and missed alarms caused by changes in environment or tasks. This context-aware analysis method enables the system to more accurately distinguish between normal business communication and potential malicious communication, thereby improving the effectiveness of risk assessment and providing more reliable data support for subsequent risk quantification and response measures.

[0075] In some embodiments described above, communication anomalies are determined by comparing communication frequency and data packet size with normal ranges. However, in real-world industrial internet environments, some potential malicious communications may not simply exceed normal ranges, but rather operate subtly on the fringes of these ranges, or their abnormal behavior may be quite covert. Relying solely on simple range comparisons may not effectively identify these communication anomalies in the "gray area," leading to overlooked or misjudged security risks. Therefore, this application further proposes a more refined method for determining communication anomalies. This method introduces the concept of edge-zone abnormal communication and combines historical behavior records and the sensitivity level of the target device to more accurately identify potential malicious communications.

[0076] In this regard, this application further proposes the following steps for determining communication anomalies: Obtain the communication frequency comparison result and the data packet size comparison result of the mobile terminal; When the communication frequency comparison result or the data packet size comparison result shows that the communication is in the edge area of ​​the normal range, the communication is marked as edge abnormal communication; Obtain the historical communication behavior records of the mobile terminal; Obtain the sensitivity level of the target device involved in the abnormal edge communication; Analyze the difference between the fluctuation trend of the abnormal edge communication and the fluctuation trend in the historical communication behavior records; Based on the difference in fluctuation trends and the sensitivity level of the target device, the abnormal edge communication is determined to be malicious communication.

[0077] Specifically, the "communication frequency comparison result" and "data packet size comparison result" refer to the judgment results obtained by comparing the communication frequency with the normal range and comparing the data packet size with the normal range. The "edge region of the normal range" can be understood as the region where the communication frequency or data packet size, although not completely exceeding the preset normal range, is very close to its upper or lower limit, or statistically shows a certain deviation from typical normal behavior. When the communication characteristics fall into this edge region, it is marked as "edge abnormal communication," indicating that the communication has potential risks and requires further in-depth analysis.

[0078] The "historical communication behavior records" refer to detailed data on the mobile terminal's communication frequency, data packet size, communication targets, and communication protocols over a past period under the same or similar production task types and operating states. These records provide an important reference baseline for determining the true nature of current abnormal edge communication. The "sensitivity level of the target device" refers to the importance of the device receiving or sending data targeted by the abnormal edge communication in the industrial control system and the potential impact after an attack. For example, core controllers, safety valves, and critical sensors on the production line may be assigned a high sensitivity level.

[0079] In practical applications, "analyzing the difference between the fluctuation trend of the abnormal edge communication and the fluctuation trend in the historical communication behavior record" refers to observing the change patterns of parameters such as frequency and magnitude of abnormal edge communication over a period of time and comparing them with the historical fluctuation patterns of the mobile terminal under normal conditions. For example, even if the communication frequency is still on the edge of the normal range, if its fluctuation pattern suddenly becomes abnormally stable or violent, showing a significant difference from the random or periodic fluctuation patterns in the historical record, this may indicate abnormal behavior.

[0080] This application's solution effectively addresses the limitations of traditional methods in identifying potentially malicious communication at the edge of the normal range by introducing the concept of "edge-range abnormal communication" and combining it with multi-dimensional information for comprehensive judgment. Specifically, when communication frequency comparison results or data packet size comparison results show that communication is in the edge area of ​​the normal range, the system no longer simply considers it normal communication, but marks it as edge-range abnormal communication, thereby triggering deeper analysis. By acquiring the historical communication behavior records of the mobile terminal, a baseline of the terminal's normal behavior can be established, making it possible to subsequently analyze the differences between the fluctuation trends of edge-range abnormal communication and historical fluctuation trends. This difference analysis can reveal communication that, even if the parameter values ​​are not significantly abnormal, exhibits abnormal behavioral patterns.

[0081] Furthermore, by acquiring the sensitivity level of the target device in abnormal edge communication, risk assessment can be combined with business importance. For example, even slight abnormal fluctuations will have an increased risk level if the target device is a highly sensitive critical device. Therefore, this solution can comprehensively consider the edge nature of communication parameters, the abnormality of behavioral patterns, and the importance of the target asset, thus more comprehensively and accurately determining whether abnormal edge communication is malicious, avoiding misjudgments or omissions that may result from judging based on a single indicator.

[0082] Through the aforementioned technical solution, this application can significantly improve the accuracy and robustness of industrial internet network security risk assessment. Especially for malicious behaviors attempting to circumvent traditional detection mechanisms and launch covert attacks within normal parameter ranges, this solution can effectively discover and determine their malicious nature by identifying "abnormal edge communication" and combining it with historical behavioral trends and the sensitivity level of the target device for in-depth analysis. This not only reduces the false negative rate, enabling the timely identification of potential, difficult-to-detect threats, but also, by considering the sensitivity of the target device, makes the risk assessment results more business-oriented, allowing for priority responses to high-risk, high-impact threats, thereby more effectively protecting the safe and stable operation of industrial control systems.

[0083] In some preferred embodiments, a specific example is given below. Suppose a mobile terminal in an industrial internet, such as an AGV (Automated Guided Vehicle) used for inspection, whose communication frequency and data packet size typically fluctuate within a specific range when performing routine inspection tasks. According to the method for judging communication anomalies described above, if both the communication frequency and data packet size are within the normal range, it will be judged as normal communication.

[0084] However, at a certain point, the communication frequency and data packet size comparison results of the AGV showed that although its communication frequency was still within the normal range, it was very close to the upper limit of the normal range and had been persisting for some time. At this point, according to the scheme of this application, this communication would be marked as edge-abnormal communication. The system then retrieved the historical communication behavior records of the AGV and found that when performing such inspection tasks, its communication frequency usually exhibited random, small fluctuations, while the current communication pattern that was continuously close to the upper limit was significantly different from the fluctuation trend in the historical records. Furthermore, the system found that the target device of this edge-abnormal communication was a data acquisition gateway connected to the core production control system, and this gateway was assigned a high sensitivity level.

[0085] Based on the above analysis, namely that the communication frequency is in the edge of the normal range, the fluctuation trend differs from the historical record, and the target device has a high sensitivity level, the system ultimately determines that this abnormal communication is malicious. For example, this could be an attacker attempting to evade detection through slow data leakage or continuous probing. The solution in this application can promptly identify such a hidden threat and trigger corresponding security response measures, such as isolating the AGV's network communication, thereby effectively preventing potential attacks.

[0086] In some embodiments described above, this application proposes judging communication anomalies based on communication frequency comparison results and data packet size comparison results, and further identifying malicious communication by analyzing the difference between the fluctuation trends of edge anomaly communication and the fluctuation trends in historical communication behavior records. However, in practical applications, relying solely on the historical communication behavior records of a single mobile terminal to judge the difference in fluctuation trends of edge anomaly communication may be insufficient to accurately capture subtle and highly disguised malicious behaviors, especially in the industrial internet environment, where the reference value of historical data may be limited due to the diversity of device operating states and task types. Therefore, this application further proposes a more refined analysis method to analyze the difference between the fluctuation trends of the aforementioned edge anomaly communication and the fluctuation trends in historical communication behavior records.

[0087] The above analysis of the differences between the fluctuation trends of the abnormal edge communication and the fluctuation trends in the historical communication behavior records includes: Obtain the real-time communication frequency and data packet size of the mobile terminal in its current production task type and operating status; Acquire the group behavior data of the mobile terminal in terms of communication frequency and data packet size of other similar mobile terminals in the current production task type and the current operating state; By comparing the real-time communication frequency and the data packet size with the group behavior data, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the fluctuation trend.

[0088] Specifically, obtaining the real-time communication frequency and data packet size of the mobile terminal under its current production task type and operating status refers to continuously monitoring and collecting the instantaneous communication data stream of the target mobile terminal under a specific production task and operating status, and extracting key indicators such as its communication frequency and data packet size. Here, real-time communication frequency can be understood as the number of data packets sent or received per unit time, while data packet size refers to the number of bytes in each data packet. These data reflect the current communication activity and data transmission volume of the mobile terminal.

[0089] Furthermore, acquiring the group behavior data of communication frequency and data packet size of other similar mobile terminals under the current production task type and operating state refers to collecting and aggregating the communication behavior data of other mobile terminals operating under the same or similar production task type and operating state. Similar mobile terminals typically refer to devices that are similar in function, configuration, deployment environment, and tasks performed. Group behavior data can provide a benchmark or reference for normal behavior patterns, reflecting the communication characteristics of a large number of legitimate devices operating normally in a specific industrial scenario.

[0090] Therefore, comparing the real-time communication frequency and data packet size with the group behavior data to identify the fluctuation trend of the abnormal edge communication and its difference from the fluctuation trend refers to comparing and analyzing the real-time communication frequency and data packet size of the target mobile terminal with the group behavior data of similar mobile terminals. This comparison is not merely a simple numerical comparison, but focuses more on identifying the degree and direction of deviation between the target mobile terminal's communication behavior pattern (i.e., fluctuation trend) and the normal group behavior pattern. For example, it can be analyzed whether the target mobile terminal's communication frequency or data packet size is within the normal fluctuation range of the group behavior data, or whether its fluctuation pattern differs significantly from the group pattern, thereby determining whether it exhibits an abnormal fluctuation trend.

[0091] This application's solution effectively addresses the limitations of relying solely on historical communication behavior records of a single mobile terminal when identifying differences in communication fluctuation trends at the edge of anomalies by introducing group behavior data from similar mobile terminals as a reference benchmark. Specifically, when real-time communication frequency and data packet size are obtained for a mobile terminal's current production task type and operating state, this real-time data reflects its immediate communication status. However, single real-time or historical data may be insufficient to determine whether it is truly abnormal. By further acquiring group behavior data on communication frequency and data packet size from other similar mobile terminals under the same task type and operating state, this solution constructs a dynamic and statistically significant normal behavior model. This group behavior data can smooth out accidental, non-malicious fluctuations of individual devices, more accurately reflecting the communication characteristics of normal devices in this industrial scenario. Subsequently, by comparing the target mobile terminal's real-time communication frequency and data packet size with this group behavior data, it is possible to identify whether the target mobile terminal's communication fluctuation trend differs significantly from the normal group behavior pattern. This dynamic comparison based on group behavior allows even communication anomalies that are on the edge of normal range to be identified more accurately by their deviation from group patterns, thereby improving the sensitivity and accuracy of detecting potential malicious communication.

[0092] Through the aforementioned technical solution, this application can more accurately and robustly identify the differences between the fluctuation trends of abnormal edge communication of mobile terminals in the Industrial Internet and their normal behavior patterns. Compared to relying solely on historical data from a single mobile terminal, introducing group behavior data from similar mobile terminals as a reference effectively overcomes the potential limitations or timeliness of historical data, providing a more representative and dynamic benchmark for judging communication anomalies. This allows even malicious communications that are on the edge of normal communication and possess strong camouflage to be effectively captured through their deviation from the normal behavior patterns of the group. Consequently, it significantly improves the accuracy of identifying potential network security risks and the ability to issue early warnings, reduces the false alarm rate, and thus provides more reliable data support and decision-making basis for Industrial Internet network security risk assessment.

[0093] In some preferred embodiments, a specific example is given below. Assume a batch of AGVs (Automated Guided Vehicles) used for material handling (as mobile terminals) exist on an industrial production line. When performing the production task of "moving from point A to point B," their communication frequency and data packet size typically follow a specific pattern. When the communication frequency and data packet size of one AGV show that its communication is on the edge of the normal range, it is marked as borderline abnormal communication. At this point, to further determine whether it is malicious communication, the system obtains the real-time communication frequency and data packet size of that AGV under the current "moving from point A to point B" task type and "running" state. Simultaneously, the system collects and analyzes the communication frequency and data packet size of all other AGVs on the production line performing the same "moving from point A to point B" task and in the "running" state, forming a group behavior data model.

[0094] For example, group behavior data shows that under normal circumstances, AGVs typically communicate between 50-60Hz and have data packet sizes between 100-120 bytes during transport, with fluctuations exhibiting a stable periodicity. If the target AGV's real-time communication frequency is 58Hz and its data packet size is 118 bytes, seemingly on the edge of normal, but its fluctuation trend shows irregular, sudden spikes, or if the correlation pattern between its communication frequency and data packet size differs significantly from the correlation pattern identified in the group behavior data (e.g., in the group, the data packet size increases synchronously with the frequency increase, while in the target AGV, the frequency increases but the data packet size remains unchanged), then even if the value is still in the edge region, this abnormal fluctuation trend difference can be identified by comparing it with the group behavior data. Therefore, the system can determine that this abnormal communication is not normal system fluctuation but rather a communication behavior with potentially malicious intent, thereby triggering further security response measures.

[0095] In some embodiments described above in this application, the fluctuation trends and differences in abnormal edge communication are identified by comparing the real-time communication frequency and data packet size of a mobile terminal with the group behavior data of similar mobile terminals. However, in practical applications, simple direct comparison may not be sufficient to reveal the deep correlation patterns between communication frequency and data packet size, especially when facing complex or covert attacks. This may lead to inaccurate identification of abnormal fluctuations, thereby affecting the accuracy of risk assessment.

[0096] In response, this application further proposes the above-mentioned comparison of the real-time communication frequency and the data packet size with the group behavior data, including: Identify the correlation pattern between the real-time communication frequency and the data packet size in the group behavior data; By comparing the correlation patterns, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the correlation pattern.

[0097] Specifically, identifying the correlation pattern between the real-time communication frequency and the data packet size in the group behavior data refers to analyzing a large amount of historical group behavior data to uncover the inherent relationship and coordinated change patterns exhibited by communication frequency and data packet size under normal operating conditions. This correlation pattern can manifest as a specific proportional relationship, synchronous fluctuation trends, or dynamic behaviors that influence each other under specific conditions. For example, under certain production task types, an increase in communication frequency may be accompanied by specific changes in data packet size, forming a predictable pattern.

[0098] The comparison of the correlation patterns to identify the fluctuation trends of the abnormal edge communication and their differences can be understood as comparing the fluctuation trends of the real-time communication frequency and data packet size of the current abnormal edge communication with the pre-identified normal correlation patterns. The purpose is not only to focus on the anomalies of a single indicator, but more importantly, to detect the anomalies in the synergistic relationships between two or more indicators, thereby revealing potential malicious communication behaviors more comprehensively and deeply.

[0099] This application's solution, by introducing the identification of correlation patterns between communication frequency and data packet size in group behavior data, can capture the inherent regularities of normal communication behavior more precisely. Traditional comparisons may only focus on whether a single indicator exceeds a threshold, ignoring the coordinated changes between indicators. By identifying correlation patterns, a more complex baseline of normal behavior can be established, making the judgment of fluctuation trends in edge-related abnormal communication no longer limited to simple numerical deviations, but capable of detecting coordinated anomalies that do not conform to normal correlation patterns. For example, under normal circumstances, if the data packet size should increase accordingly when the communication frequency increases, but in edge-related abnormal communication, the frequency increases while the data packet size decreases abnormally, this deviation from the correlation pattern can be effectively identified, thereby improving the detection capability of covert attacks.

[0100] Through the aforementioned technical solutions, this application can more accurately and sensitively identify the differences between the fluctuation trends of abnormal edge communication and normal behavior. By deeply analyzing the correlation patterns between communication frequency and data packet size, false alarms caused by fluctuations in a single indicator can be effectively avoided. Simultaneously, it can also detect covert attacks that evade traditional detection mechanisms through subtle, coordinated changes. This significantly improves the accuracy and reliability of industrial internet network security risk assessment, providing a more solid data foundation for subsequent risk quantification and response, thereby effectively enhancing network security protection capabilities in the industrial internet environment.

[0101] In some preferred embodiments, it is assumed that when a mobile terminal performs a specific production task, its normal communication behavior exhibits a positive correlation between communication frequency and data packet size; that is, the higher the frequency, the larger the data packet, and this relationship shows a stable linear or non-linear trend in group behavior data. When the mobile terminal exhibits edge-abnormal communication, such as a slight increase in communication frequency while the data packet size remains unchanged or slightly decreases, this phenomenon may be considered normal fluctuation in single-indicator analysis. However, the solution of this application first identifies the normal positive correlation pattern between communication frequency and data packet size in group behavior data. Subsequently, the fluctuation trend of the real-time frequency and data packet size combination of the edge-abnormal communication is compared with the normal correlation pattern. If it is found that the combination of increased frequency and unchanged data packet size of the edge-abnormal communication significantly deviates from the normal positive correlation pattern, even if the single indicator does not completely exceed the normal range, it can be identified as a fluctuation trend difference inconsistent with the normal correlation pattern, and thus judged as potential malicious communication. For example, this difference can be quantified by calculating the distance or deviation between the real-time data point and the correlation pattern curve; when the deviation exceeds a preset threshold, it is considered an anomaly.

[0102] In some embodiments of this application, the correlation pattern between real-time communication frequency and data packet size in group behavior data is identified, and then this correlation pattern is compared to identify the difference between the fluctuation trend of abnormal edge communication and historical fluctuation trends. However, in actual industrial internet environments, communication data often has complex temporal characteristics, such as trends, periodicity, and random fluctuations. If only a simple correlation pattern recognition method is used, it may not be able to accurately capture the real and stable correlation behind the data, and it is easily affected by noise or short-term fluctuations, resulting in an inaccurate or ineffective correlation pattern, which in turn affects the accuracy of judging the difference in fluctuation trends of abnormal edge communication.

[0103] In this regard, this application further proposes a specific method for identifying the correlation pattern between the real-time communication frequency and the data packet size in the aforementioned group behavior data, including: Time series decomposition is performed on the communication frequency sequence and the data packet size sequence in the group behavior data to separate the trend component, periodic component and residual component; Pattern matching is performed on the trend component and the periodic component to identify multiple potential correlation patterns; The fit of multiple potential correlation patterns is evaluated based on the magnitude of the residual components; The association pattern with a fitting degree exceeding a preset threshold is selected as the association pattern between the communication frequency and the data packet size.

[0104] Specifically, time series decomposition refers to breaking down a time series of data into several components, typically including a trend component, a periodic component (or seasonal component), and a residual component. The trend component reflects the long-term growth or decline trend of the data; the periodic component reflects the recurring patterns in the data within fixed time intervals, such as daily, weekly, or yearly periodic changes; and the residual component represents the random fluctuations or noise in the data after removing the effects of trend and periodicity. Through this decomposition, the structural changes and randomness behind the data can be understood more clearly.

[0105] The pattern matching of the trend and periodic components involves identifying specific relationship patterns, such as synchronous changes, lags, or leads, between the communication frequency sequence and the data packet size sequence within the decomposed trend and periodic components. For example, cross-correlation analysis, dynamic time warping (DTW), or machine learning-based sequence pattern recognition algorithms can be used to discover these potential correlation patterns. Identifying multiple potential correlation patterns is crucial for comprehensively considering various correlation methods that may exist in different contexts.

[0106] In practical applications, evaluating the fit of multiple potential correlation patterns based on the magnitude of the residual components refers to measuring the explanatory power of each potential correlation pattern on the original data by analyzing the magnitude of the residual components. The smaller the residual component, the better the pattern fits the original data, meaning the more accurately the pattern describes the true relationship between communication frequency and data packet size. The fit can be quantified using statistical indicators such as mean squared error (MSE), root mean square error (RMSE), or R-squared value.

[0107] Furthermore, selecting the correlation pattern with a fitting degree exceeding a preset threshold as the correlation pattern between the communication frequency and the data packet size is to ensure the reliability and effectiveness of the selected pattern. The preset threshold can be set based on historical data analysis, expert experience, or system performance requirements. Only when the fitting degree of the pattern reaches or exceeds the threshold is the pattern considered sufficiently stable and representative, and can be used for subsequent identification of fluctuation trend differences.

[0108] This application's solution, by introducing time series decomposition technology, can decompose the complex fluctuations of communication frequency sequences and data packet size sequences in group behavior data into more easily analyzable trend, periodic, and residual components. This allows for pattern matching of the trend and periodic components separately, identifying multiple potential, more fundamental correlation patterns and avoiding interference from noise and short-term fluctuations in the original data. Since the residual component represents the random portion unexplained by the model, evaluating its magnitude objectively quantifies the fit of each potential correlation pattern, thereby selecting those patterns that more accurately and stably reflect the true relationship between communication frequency and data packet size. It is precisely this hierarchical and refined analysis method that makes the identified correlation patterns more robust and accurate, laying a solid foundation for subsequent precise identification of fluctuation trend differences in marginal abnormal communications.

[0109] Through the above technical solution, this application overcomes the limitations of traditional methods in identifying correlation patterns in complex industrial internet environments, which are susceptible to noise interference and lack accuracy. Specifically, time series decomposition clearly reveals long-term trends and periodic patterns in the data, avoiding the misleading influence of short-term random fluctuations on correlation pattern identification; pattern matching can systematically discover potential and diverse correlations between communication frequency and data packet size; and the fitting degree evaluation based on the residual component size ensures the reliability and representativeness of the selected correlation patterns. Therefore, this application can obtain more accurate and robust correlation patterns between communication frequency and data packet size, significantly improving the accuracy of identifying differences in edge-related abnormal communication fluctuation trends, thereby effectively improving the overall accuracy and reliability of industrial internet network security risk assessment and reducing the risk of false alarms and missed alarms.

[0110] In some preferred embodiments, a specific example is given below. Suppose that on an industrial production line, a mobile terminal's communication frequency and data packet size are continuously monitored and recorded while performing a specific task. To identify the correlation pattern between the mobile terminal's communication frequency and data packet size in normal group behavior, the collected historical communication frequency and data packet size sequences are first decomposed into time series. For example, the STL (Seasonal-Trend decomposition using Loess) method can be used to decompose each sequence into a trend component, a periodic component (e.g., daily or weekly communication patterns), and a residual component.

[0111] Next, pattern matching is performed on the trend components of the decomposed communication frequency and the trend components of the data packet size, and simultaneously on the periodic components of the communication frequency and the periodic components of the data packet size. For example, a dynamic time warping algorithm can be used to measure the similarity of two sequences in the time dimension, thereby identifying possible synchronous changes or lag relationships between them and forming multiple potential association patterns.

[0112] Subsequently, for each identified potential correlation pattern, the magnitude of its corresponding residual component is calculated, for example, by calculating the mean squared error. The smaller the residual component, the better the pattern fits the original data. If, after calculation, the mean squared error of a certain pattern is significantly lower than that of other patterns and below a preset threshold (e.g., 0.05), then this pattern is selected as the true correlation pattern between communication frequency and data packet size for the mobile terminal under the current production task type and operating state. When subsequent monitoring reveals a significant deviation between the mobile terminal's real-time communication behavior and this correlation pattern, it can be more accurately determined as edge-related abnormal communication, and its malicious nature can be further assessed.

[0113] In some existing technologies, when assessing the fit of multiple potential correlation patterns based on the magnitude of residual components, the actual operating environment and task status of mobile terminals may not be fully considered. This generalized assessment method may lead to misjudgment of residual component fluctuations, thus affecting the accuracy of correlation pattern fit assessment, especially in complex and dynamically changing scenarios such as the Industrial Internet. Failure to address these issues may result in misidentification of normal communication patterns or failure to promptly detect potential abnormal communication behaviors, thereby impacting the effectiveness of cybersecurity risk assessment.

[0114] In response, this application further proposes a more refined evaluation method, which dynamically determines the normal fluctuation range and evaluation sensitivity of the residual components by combining the current production task type and operating status information of the mobile terminal, thereby calculating a more valuable fitting score to improve the accuracy and reliability of the correlation pattern fitting degree evaluation.

[0115] The above assessment of the fit of multiple potential association patterns based on the magnitude of the residual components specifically includes: Obtain the current production task type and the running status information of the mobile terminal; Based on the production task type and the operating status information, obtain the normal fluctuation range of the residual component and the evaluation sensitivity; Based on the normal fluctuation range of the residual components and the evaluation sensitivity, the fitting scores of the multiple potential correlation patterns are calculated; The fit score is used to evaluate the degree of fit of the plurality of potential association patterns.

[0116] Specifically, acquiring the current production task type and operating status information of the mobile terminal refers to the system collecting or obtaining in real time from the industrial control system the category of the production task being performed by the mobile terminal (e.g., inspection, data acquisition, equipment maintenance, etc.) and its current operating status (e.g., idle, running, fault standby, etc.). This information can be obtained through interface integration with the industrial control system (such as MES, SCADA system) or through analysis of sensor data reported by the mobile terminal itself. Its purpose is to provide necessary contextual information for subsequent residual component evaluation.

[0117] The process of obtaining the normal fluctuation range and assessment sensitivity of residual components based on production task type and operational status information can be understood as the system setting a reasonable fluctuation range for residual components under different production task types and operational states based on a pre-established knowledge base or through learning from historical data. For example, under equipment maintenance tasks, communication patterns may fluctuate significantly, and the normal fluctuation range of residual components can be appropriately widened; while under stable production tasks, communication patterns should be more stable, and the normal fluctuation range of residual components should be more stringent. Assessment sensitivity refers to the tolerance for residual components deviating from the normal range under specific tasks and states, aiming to make the assessment results more consistent with actual operating conditions.

[0118] In practical applications, fitting scores for multiple potential association patterns are calculated based on the normal fluctuation range of the residual components and the evaluation sensitivity. Specifically, the fitting score for each potential association pattern is calculated using a pre-defined scoring model (e.g., based on distance metrics, probability density functions, or fuzzy logic) based on the degree of deviation of the residual components from the normal fluctuation range and the evaluation sensitivity. A higher fitting score indicates a better match between the pattern and the residual components of actual communication behavior. The purpose is to provide a quantitative indicator to measure the degree of pattern matching.

[0119] Furthermore, evaluating the fit of multiple potential correlation patterns based on the fit scores involves comparing the calculated fit scores with a preset threshold, or ranking the fit scores of different patterns, to determine which correlation patterns better represent the relationship between the communication frequency and data packet size of the mobile terminal. The aim is to screen out the correlation patterns that best reflect the characteristics of current communication behavior, providing an accurate basis for subsequent anomaly identification and risk assessment.

[0120] This application's solution incorporates information about the current production task type and operating status of the mobile terminal, enabling dynamic adjustment of the normal fluctuation range and evaluation sensitivity of the residual components based on actual operating conditions. Because the communication behavior patterns and fluctuation characteristics of mobile terminals differ significantly under different production tasks and operating states, traditional evaluation methods using a single threshold or fixed range are insufficient to accurately reflect their true state. By acquiring this contextual information, the system can set a more precise normal fluctuation range for the residual components and adjust the evaluation sensitivity according to the task's sensitivity, thereby avoiding misjudging normal fluctuations as abnormalities or ignoring potential abnormal behaviors. Furthermore, by calculating the fitting score, multiple potential correlation patterns can be quantitatively compared, ensuring that the final selected correlation pattern more accurately reflects the communication characteristics of the mobile terminal under specific operating conditions, thus providing a more reliable basis for subsequent malicious communication identification and attack path deduction.

[0121] Through the above technical solution, this application can significantly improve the accuracy and robustness of assessing the fitting degree of the correlation pattern between communication frequency and data packet size. By considering the production task type and operating status of the mobile terminal, misjudgments caused by changes in operating conditions can be avoided, making the assessment results closer to the actual situation. This helps to more accurately identify abnormal communication behaviors that differ significantly from normal patterns, thereby improving the refinement level of industrial internet network security risk assessment, effectively reducing false alarm rate and false negative rate, and enhancing the system's security protection capabilities.

[0122] In some preferred embodiments, a specific example is given below. Assume that on an industrial production line, a mobile terminal (e.g., an AGV) is performing a "material transport" task, operating at full capacity. The system first obtains the current production task type and operating status information of the AGV. Based on historical data and expert knowledge, the system understands that in the "material transport" and "full capacity" state, the residual components of the AGV's communication frequency and data packet size typically fluctuate within a small range, and the system is highly sensitive to abnormal fluctuations because communication in this state usually involves critical control commands and status reporting. Therefore, based on this information, the system sets a narrower normal fluctuation range for the residual components and increases the evaluation sensitivity. Subsequently, the system calculates the residual components of the current AGV's communication behavior and compares them with multiple preset potential correlation patterns, calculating the fitting score for each pattern.

[0123] For example, if the residual component of a certain correlation pattern exceeds the set normal fluctuation range, or if it is within the range but the fit score is low, it indicates that the pattern does not match the current actual communication behavior well. In this way, even if the residual component has only slight anomalies, it can be identified in time due to the increased evaluation sensitivity, thereby more accurately assessing the fit of the correlation pattern and providing a more reliable basis for subsequent judgment on whether malicious communication exists.

[0124] refer to Figure 3 , Figure 3 This is a schematic diagram of the structure of an industrial internet network security risk assessment system provided by an embodiment of the present invention, including: The detection end is used to acquire and aggregate network information of the mobile terminal, including physical location information, network connection information, and network communication behavior information. The simulation terminal is used to identify potential risk factors of the mobile terminal based on the aggregated network information, simulate the attack path of an attacker using the mobile terminal as a springboard, and quantify the risk of the attack path. The adjustment end is used to restrict the physical movement or network communication behavior of the mobile terminal based on the risk quantification results, and adjust network access rules to isolate the communication between the mobile terminal and potential attack targets.

[0125] The industrial internet network security risk assessment system proposed in this application aims to achieve real-time, dynamic assessment and control of mobile terminal security risks in the industrial internet environment through a modular design. The system continuously acquires and aggregates various network information from mobile terminals through a detection end, providing a comprehensive data foundation for subsequent risk analysis. Subsequently, the simulation end uses this aggregated information to intelligently identify potential risk factors and simulate attack paths to quantify risks. Finally, the adjustment end automatically executes risk control measures based on the quantification results, including restricting the physical movement or network communication behavior of mobile terminals and adjusting network access rules, thereby effectively isolating potential threats and significantly improving the security protection capabilities of industrial internet networks. This systematic solution can effectively address the security challenges posed by highly mobile and intermittently connected terminals, compensating for the shortcomings of traditional static assessment methods.

[0126] To better understand the technical solution proposed in this application, it is necessary to explain some key components involved. The meanings of terms such as "mobile terminal," "network information," "physical location information," "network connection information," "network communication behavior information," "potential risk factor," "attack path," "risk quantification," "physical movement restriction," "network communication behavior restriction," "network access rules," and "potential attack target" have already been described in the above embodiments, and will not be repeated here. It should be emphasized that the system proposed in this application implements its functions through the following core components: Specifically, the detection terminal is used to acquire and aggregate network information from mobile terminals. As a preferred implementation, the detection terminal can be configured to include multiple sub-modules. For example, the data acquisition module is used to obtain the physical location information, network connection information, and network communication behavior information of the mobile terminal in real time from different data sources (such as positioning base stations, wireless access points, network traffic mirroring devices, etc.).

[0127] For example, the data acquisition module can obtain the precise physical location of the mobile terminal through UWB base stations or Wi-Fi positioning systems deployed inside the factory; obtain connection information through monitoring agents integrated into the wireless access point; and capture network traffic and extract communication behavior information through network splitters or bypass monitoring devices.

[0128] The data aggregation module is used to uniformly format, clean, and integrate heterogeneous network information collected from different data sources, and store it in a central data platform. For example, the data aggregation module can use message queues or stream processing technologies to standardize real-time data streams, ensuring data consistency and availability. In practical applications, the detection end can be a standalone hardware device, such as a dedicated network security probe, or a software module deployed on existing network equipment (such as switches and routers), with the aim of providing a comprehensive, real-time view of mobile terminal network activity.

[0129] Furthermore, the simulation terminal is used to identify potential risk factors of the mobile terminal based on the aggregated network information, simulate the attack path of an attacker using the mobile terminal as a springboard, and quantify the risk of the attack path.

[0130] As a preferred implementation, the simulation terminal can be configured to include the following functional modules: a risk identification module, used to perform in-depth analysis of the network information aggregated by the detection terminal, identify abnormal communication behaviors or configuration defects that do not conform to normal behavior patterns, thereby determining potential risk factors. For example, the risk identification module can use machine learning algorithms to train on historical communication data, establish a baseline of normal behavior, and compare the deviation of the current communication behavior from the baseline in real time to detect anomalies. An attack path simulation module, used to construct and deduce attack paths that attackers may use mobile terminals as intermediate springboards to penetrate into critical assets based on the identified potential risk factors, combined with network topology, device vulnerability information, and security policies. For example, this module can use graph theory algorithms or attack graph technology to abstract devices and connections in the network into nodes and edges, and simulate the path of an attacker starting from a mobile terminal, through a series of vulnerability exploits or privilege escalation, and finally reaching the target device. A risk quantification module, used to evaluate each simulated attack path, calculate its potential success probability and possible business impact, thereby obtaining a quantified risk score. For example, the risk quantification module can combine CVSS (Common Vulnerability Scoring System) scores, asset sensitivity levels, attack difficulty, and other factors to comprehensively score attack paths. The simulation end can be a high-performance server cluster running complex analysis algorithms and simulation models, aiming to provide in-depth insights and predictive capabilities regarding potential threats.

[0131] Furthermore, the adjustment terminal is used to restrict the physical movement or network communication behavior of the mobile terminal based on the risk quantification results, and to adjust network access rules to isolate communication between the mobile terminal and potential attack targets. As a preferred embodiment, the adjustment terminal can be configured to include the following functional modules: a policy decision module, used to automatically generate corresponding risk control policies based on the risk quantification results output by the simulation terminal, combined with preset security policies and business priorities. For example, when the risk score of a mobile terminal reaches a high-risk level, the policy decision module can decide to immediately physically isolate and block its network access. A behavior restriction execution module, used to send instructions to the mobile terminal management system or physical control system to restrict the physical movement range of the mobile terminal or stop its current task. For example, this module can be integrated with a geofencing system to automatically trigger an alarm and restrict its movement when the mobile terminal enters an unauthorized area. A network rule adjustment module, used to coordinate with network security devices (such as firewalls, intrusion prevention systems, and SDN controllers) to dynamically update network access rules to block or isolate communication between risky mobile terminals and potential attack targets. For example, this module can automatically add a rule to the firewall to deny communication from a specific IP address or port, or dynamically assign mobile terminals to isolated VLANs. Thus, the adjustment terminal can be a centralized control platform responsible for translating risk assessment results into actual defensive actions, with the aim of achieving rapid response and effective containment of industrial internet network security risks.

[0132] The industrial internet network security risk assessment system proposed in this application significantly enhances the security protection capabilities of industrial internet networks through its modular design and real-time dynamic assessment and control mechanism. Compared with traditional methods that rely on periodic scanning and static analysis, this system can effectively address the security challenges posed by highly mobile, intermittently connected terminals (such as autonomous mobile robots, AMRs). Traditional methods, when dealing with devices like AMRs, are prone to security blind spots due to the frequent changes in their physical location and network connections, and are unable to track evolving threats. This system overcomes the lag in data acquisition inherent in traditional methods by continuously and in real-time acquiring and aggregating the physical location information, network connection information, and network communication behavior information of mobile terminals through the detection end.

[0133] For example, even if an AMR goes offline at a certain point in time, its historical behavior data can still be recorded and analyzed by the system, thus avoiding blind spots in assessment. Furthermore, the simulation end can intelligently identify potential risk factors based on this real-time data and simulate attack paths where attackers use mobile terminals as springboards, quantifying the risks. This proactive attack path simulation capability allows security teams to gain a deeper understanding of potential threats and take targeted defensive measures, rather than simply relying on passively discovering known vulnerabilities. Finally, the adjustment end can dynamically and in real-time restrict the physical movement or network communication behavior of mobile terminals and adjust network access rules based on the risk quantification results, thereby achieving rapid response and effective isolation of potential attacks. This closed-loop mechanism from real-time perception and intelligent analysis to dynamic control ensures the continuous security of industrial internet networks and the stability of production when facing complex and ever-changing threats.

[0134] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for assessing cybersecurity risks in the industrial internet, characterized in that, include: The network information of the mobile terminal is acquired and aggregated, including physical location information, network connection information, and network communication behavior information. Based on the aggregated network information, potential risk factors of the mobile terminal are identified, and an attack path in which an attacker uses the mobile terminal as a springboard is simulated, and the risk of the attack path is quantified. Based on the risk quantification results, the physical movement or network communication behavior of the mobile terminal is restricted, and network access rules are adjusted to isolate the communication between the mobile terminal and potential attack targets.

2. The industrial internet network security risk assessment method according to claim 1, characterized in that, The process of identifying potential risk factors of the mobile terminal based on the aggregated network information and simulating an attack path where an attacker uses the mobile terminal as a springboard includes: Acquire the location data, network connection data, network communication behavior data, and environmental perception data of the mobile terminal; Based on the environmental perception data, it is determined whether the mobile terminal is in an area of ​​electromagnetic interference; When the mobile terminal is in the electromagnetic interference area, the communication characteristics of the mobile terminal are calibrated for background noise according to the preset environmental interference behavior law of the electromagnetic interference area. The purposeful analysis of the communication characteristics after background noise calibration includes: Compare the communication target with the mobile terminal's legitimate communication target whitelist; Compare the communication protocol with the valid protocols under the current task type of the mobile terminal; Associated communication time, physical location of the mobile terminal, and current task status; Based on the results of the purposeful analysis, identify malicious communications; Based on the malicious communication, the attack path is deduced.

3. The industrial internet network security risk assessment method according to claim 2, characterized in that, The purposeful analysis of the communication characteristics after background noise calibration includes: Obtain information on production plan adjustments, equipment upgrades, and network topology changes; Based on the production plan adjustment information, the equipment upgrade information, and the network topology change information, the whitelist of legitimate communication targets and the set of legitimate protocols are dynamically updated. Compare the background noise-calibrated communication target, the communication protocol, the dynamically updated whitelist of legitimate communication targets, and the set of legitimate protocols to obtain a first comparison result; Analyze the communication frequency after background noise calibration and the data packet size; Based on the first comparison and analysis results, malicious communication is identified.

4. The industrial internet network security risk assessment method according to claim 3, characterized in that, The analysis of the background noise-calibrated communication frequency and the data packet size includes: Obtain the production task type of the mobile terminal; Obtain the operating status information of the mobile terminal; Based on the production task type and the operating status information, obtain the normal range of the communication frequency; Based on the production task type and the operating status information, obtain the normal range of the data packet size; Compare the background noise calibrated communication frequency with the normal range of the communication frequency to obtain a second comparison result; The size of the data packet after background noise calibration is compared with the normal range of the data packet size to obtain a third comparison result; Based on the second comparison result and the third comparison result, a communication anomaly is determined.

5. The industrial internet network security risk assessment method according to claim 4, characterized in that, The step of determining communication anomalies based on the second comparison result and the third comparison result includes: Obtain the communication frequency comparison result and data packet size comparison result of the mobile terminal; When the communication frequency comparison result or the data packet size comparison result shows that the communication is in the edge area of ​​the normal range, the communication is marked as edge abnormal communication; Obtain the historical communication behavior records of the mobile terminal; Obtain the sensitivity level of the target device involved in the abnormal edge communication; Analyze the difference between the fluctuation trend of the abnormal edge communication and the fluctuation trend in the historical communication behavior records; Based on the difference in fluctuation trends and the sensitivity level of the target device, the abnormal edge communication is determined to be malicious communication.

6. The industrial internet network security risk assessment method according to claim 5, characterized in that, The analysis of the fluctuation trend of the abnormal edge communication and the difference between the fluctuation trend in the historical communication behavior records includes: Obtain the real-time communication frequency and data packet size of the mobile terminal in its current production task type and operating status; Acquire the group behavior data of the mobile terminal in terms of communication frequency and data packet size of other similar mobile terminals in the current production task type and the current operating state; By comparing the real-time communication frequency and the data packet size with the group behavior data, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the fluctuation trend.

7. The industrial internet network security risk assessment method according to claim 6, characterized in that, The comparison of the real-time communication frequency and the data packet size with the group behavior data includes: Identify the correlation pattern between the real-time communication frequency and the data packet size in the group behavior data; By comparing the correlation patterns, the fluctuation trend of the edge abnormal communication is identified and the difference between the fluctuation trend and the correlation pattern.

8. The industrial internet network security risk assessment method according to claim 7, characterized in that, The correlation pattern between the real-time communication frequency and the data packet size in the identification of the group behavior data includes: Time series decomposition is performed on the communication frequency sequence and the data packet size sequence in the group behavior data to separate the trend component, periodic component and residual component; Pattern matching is performed on the trend component and the periodic component to identify multiple potential correlation patterns; The fit of multiple potential correlation patterns is evaluated based on the magnitude of the residual components; The association pattern with a fitting degree exceeding a preset threshold is selected as the association pattern between the communication frequency and the data packet size.

9. The industrial internet network security risk assessment method according to claim 8, characterized in that, The step of evaluating the fit of multiple potential association patterns based on the magnitude of the residual components includes: Obtain the current production task type and the running status information of the mobile terminal; Based on the production task type and the operating status information, obtain the normal fluctuation range and evaluation sensitivity of the residual component; Based on the normal fluctuation range of the residual components and the evaluation sensitivity, the fitting scores of the multiple potential correlation patterns are calculated; The fit score is used to evaluate the degree of fit of the plurality of potential association patterns.

10. An industrial internet network security risk assessment system, characterized in that, include: The detection end is used to acquire and aggregate network information of the mobile terminal, including physical location information, network connection information, and network communication behavior information. The simulation terminal is used to identify potential risk factors of the mobile terminal based on the aggregated network information, simulate the attack path of an attacker using the mobile terminal as a springboard, and quantify the risk of the attack path. The adjustment end is used to restrict the physical movement or network communication behavior of the mobile terminal based on the risk quantification results, and adjust network access rules to isolate the communication between the mobile terminal and potential attack targets.