Energy-saving control device management system based on industrial internet
By using an industrial internet-based energy-saving control equipment management system, component information is identified hierarchically, security domains are divided, data and status information are collected, and distributed anomaly detection and dynamic protection are performed. This solves the security problems of industrial energy-saving control networks and achieves efficient attack protection and anomaly management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 广州崇实自动控制科技有限公司
- Filing Date
- 2026-04-07
- Publication Date
- 2026-05-29
Smart Images

Figure CN122120002A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of equipment management and analysis, and in particular to an energy-saving control equipment management system based on the Industrial Internet. Background Technology
[0002] Energy-saving control technology is shifting from single-point adjustment to system-wide collaboration. Edge computing gateways are becoming increasingly common, enabling local data cleaning and anomaly filtering. AI algorithms are being gradually embedded in controllers, allowing central air conditioning clusters to automatically adjust frequencies based on load predictions, achieving measured energy savings of 15%–50%. Digital twins are being used in energy systems to simulate faults and optimize strategies in advance. Protocol compatibility between inverters, smart meters, and PLCs is also improving, with fewer instances of mixing Modbus, BACnet, and OPC UA. However, some shortcomings still exist. With the continuous improvement of networking, datafication, and control coordination of energy-saving control equipment (components), the attack surface faced by the system has significantly expanded. Correspondingly, security protection capabilities must be strengthened in tandem; otherwise, it will become a key weakness restricting the reliable operation of energy-saving control technology. Currently, existing industrial energy-saving control networks still have significant deficiencies in areas such as protection resource allocation, lateral threat blocking, data reliability, robustness of the detection architecture, false alarm rate control, and identification of coordinated attacks. Specifically, these deficiencies manifest as: unbalanced protection resource allocation, difficulty in blocking the spread of lateral threats, insufficient reliability of raw data, poor robustness of centralized detection architectures, high false alarm rates, and difficulty in identifying coordinated attacks—all security issues related to energy-saving control equipment.
[0003] To address the aforementioned technical shortcomings, an energy-saving control equipment management system based on the Industrial Internet is proposed. Summary of the Invention
[0004] The purpose of this invention is to address the technical shortcomings of existing industrial energy-saving control networks, such as unbalanced allocation of protection resources, difficulty in blocking the spread of lateral threats, insufficient reliability of raw data, poor robustness of centralized detection architecture, high false alarm rate, and difficulty in identifying coordinated attacks. It achieves the engineering goals of making attacks difficult to penetrate, difficult to spread after penetration, early detection of anomalies, automatic correction of false alarms, and full traceability of handling, thus significantly improving the security and operational efficiency of industrial energy-saving control networks.
[0005] To achieve the above objectives, the present invention adopts the following technical solution: The energy-saving control equipment management system based on the Industrial Internet includes a signal-connected energy-saving control equipment hierarchical unit, a network micro-isolation unit, a sensing and acquisition unit, a data storage unit, an abnormal behavior detection unit, and a dynamic safety protection unit. The energy-saving control equipment hierarchical unit identifies and records the component information of all networked energy-saving control components and their corresponding preset security levels, generates safe and energy-saving component information, and sends it to the data storage unit for storage. Based on information about secure and energy-saving components, the network micro-segmentation unit divides the energy-saving control network into multiple security domains and presets access control permissions. The configuration results of the security domain division form an industrial energy-saving Internet of Things network with secure isolation characteristics. The sensing and acquisition unit collects the component operation data and component status information of the energy-saving control component and sends them to the abnormal behavior detection unit at preset time intervals; The abnormal behavior detection unit is used to receive data uploaded by the sensing and acquisition unit, retrieve information on safety and energy-saving components and security domain division results from the data storage unit, and calculate abnormal scores and risk levels through hierarchical distributed detection to achieve the identification and hierarchical alarm of attack behavior. The safety dynamic protection unit is used to receive the abnormal score and risk level output by the abnormal behavior detection unit, perform a second review of the detection and processing results, and control the energy-saving control equipment hierarchical unit, network micro-isolation unit, sensing and acquisition unit and abnormal behavior detection unit in reverse according to the review conclusion.
[0006] Furthermore, energy-saving control components include sensors, PLCs, edge devices, telemetry sensors, frequency converters, smart meters, actuators, temperature controllers, smart circuit breakers, energy meters, and remote I / O units; component information includes device identification, device type, technical parameters, network attributes, physical location, and service affiliation; the preset security levels are pre-classified into high, medium, and low levels based on the comprehensive impact of the energy-saving control components being compromised or malfunctioning, with high level corresponding to edge gateways and group control PLCs, medium level corresponding to smart meters and smart circuit breakers, and low level corresponding to temperature and humidity sensors and light sensors.
[0007] Furthermore, the methods for dividing security domains in network micro-segmentation units include: dividing them into virtual terminal security domains and device terminal security domains based on virtual terminals and device terminals; dividing them hierarchically from top to bottom into regional level, park level, functional unit level, and device level security domains, where each device level security domain corresponds to the central air conditioning, production equipment, monitoring equipment, and their controllers in each building within the park; dividing them into cooling control domains, power control domains, lighting control domains, and data acquisition control domains based on control type; or dividing them into source port domains and destination port domains based on communication ports. The network micro-segmentation unit presets an access control list for each security domain. The access control list includes at least the range of source IP addresses, the range of destination IP addresses, the protocol type, the port number, and the communication direction for allowed communication. For communication requests across security domains, the request is allowed if it meets the preset whitelist rules of both the source and destination domains or is manually authorized; otherwise, it is rejected by default. The network micro-segmentation unit also supports time-based dynamic access control, allowing data exchange between the central air conditioning control domain and the monitoring and management domain during production hours, and only allowing heartbeat detection communication between the emergency response unit and designated equipment domains during non-production hours; for critical equipment domains, inbound connections are restricted to specific management ports of the edge gateway, and any direct lateral communication between equipment domains is prohibited.
[0008] Furthermore, the component operation data collected by the sensing and acquisition unit includes equipment operation data collected by the sensors and the operation data of the energy-saving control components themselves. The equipment operation data includes voltage, current, power, temperature, pressure, and flow rate; the component status information includes HMAC data signature information, heartbeat packet transmission status, and physical anti-tampering status flags. HMAC data signature information is used to verify data integrity and source legitimacy; heartbeat packet transmission status is indicated by the sensor actively sending a fixed-format status message containing the device's unique identifier, timestamp, and heartbeat sequence number at preset time intervals to indicate whether the device is online or offline. The receiving end sets the status flag to offline if it does not receive a heartbeat message three times in a row; the physical anti-tamper status flag is generated by an anti-tamper switch installed inside the sensor housing, where a status bit of 0 indicates that the housing is intact, and a status bit of 1 indicates that the housing has been opened or the anti-tamper circuit has been damaged. The sensor appends the status bit to the end of the message each time it sends a data packet. If the status bit changes from 0 to 1 without authorization, an alarm is triggered and the device is added to the blacklist; for sensors without a hardware anti-tamper switch, GPS coordinates or RSSI signal characteristic baselines are used instead. When the coordinates deviate or the signal characteristics exceed a preset threshold, the anti-tamper status flag is set to 1.
[0009] Furthermore, the abnormal behavior detection unit includes edge units deployed on each edge gateway and a global detection master unit deployed on the central server. Its hierarchical distributed detection includes the following steps: The first step is edge data preprocessing and baseline construction: On each edge gateway, the energy-saving control elements and their preset security levels are identified based on the information of the security and energy-saving elements. HMAC signature is used to verify data integrity and filter invalid data packets. Based on the valid data within a continuous time period, a short-term behavior baseline is constructed using a sliding window algorithm. When the deviation between the actual data and the baseline exceeds a preset threshold, the abnormal event and several data points before and after it are packaged and uploaded to the central server. The second step is to construct the global behavior baseline and calculate the anomaly score at the central end: The global detection master unit receives the reported abnormal events, constructs the global behavior baseline of each component by combining historical normal data, and calculates the anomaly score and risk level by using a control analysis model combined with a weighted scoring method. The third step is to implement graded alarms and differentiated handling: based on anomaly scoring and the preset security level of components, low-risk components only log, medium-risk components send prompts to low-risk components, push warnings to medium-risk components, and display yellow alarms and trigger pre-isolation for high-risk components, and high-risk components trigger red alarms and perform blacklist isolation regardless of the level. The fourth step is cross-domain collaboration and spatiotemporal correlation analysis: based on security domain division information, spatiotemporal correlation analysis is performed on abnormal events of multiple components within the same security domain to determine collaborative attacks and dynamically adjust the access control list. Step 5, Distributed load balancing and network outage fault tolerance: When the edge gateway CPU load exceeds the constraint value, it automatically transmits the data stream of the lower-level components. When the network is interrupted, the locally cached data will be transmitted after the network is restored.
[0010] Furthermore, the specific steps of the control analysis model are as follows: The first step is to retrieve the historical normal data of the component within a preset period from the data storage unit as a training sample set. Each sample is a multi-dimensional feature vector, which includes voltage, current, power, temperature, pressure, and flow rate in the component operation data, as well as heartbeat packet reception interval, HMAC signature verification result, and physical anti-tampering status bit in the component status information. The second step is to randomly select a preset number of samples from the training sample set to construct model units: randomly select a feature dimension and its segmentation value between the minimum and maximum values in the current sub-sample set, divide the samples whose feature dimension is less than the segmentation value into the left child node, and divide the samples whose feature dimension is greater than or equal to the segmentation value into the right child node, and recursively repeat the above division process until the number of current sample nodes is equal to the preset minimum value, and repeat the above construction process to generate a preset number of model units, forming a set of model units. The third step is to input the data point to be detected into each model unit, calculate the path length of the data point in each model unit, and then calculate the average of the path lengths of all model units. The fourth step is to calculate the original anomaly score: Substitute the average path length mentioned above into the preset normalization function, which is calculated based on the subsample size and harmonic number to obtain the original anomaly score with a value between 0 and 1. The closer the value is to 1, the more abnormal the data point is, and the closer the value is to 0, the more normal it is.
[0011] Furthermore, the specific steps of the weighted scoring method are as follows: The first step is to retrieve the weight factors corresponding to the preset security level of the components from the data storage unit, with high-level components having the largest weight, medium-level components having the second largest weight, and low-level components having the smallest weight. The second step is to map the original anomaly scores output by the control analysis model to a preset scoring interval, which has a minimum and a maximum value, to obtain the basic score. The third step is to calculate the weighted anomaly score: multiply the base score by an adjustment factor, which is obtained by multiplying the difference between the preset amplification factor and the weight factor and then adding 1. Then, the calculation result is limited to the minimum and maximum values of the preset score range. The fourth step is to add additional points to the weighted anomaly score if the anomaly is associated with multiple independent detection dimensions. For each additional dimension associated, a preset score is added, but the total score does not exceed the maximum value of the scoring range, thus obtaining the final anomaly score. The fifth step involves setting two risk level thresholds, both of which are within the scoring range. The final abnormal score is then compared with these two thresholds: if the final abnormal score is less than the first threshold, it is classified as low risk; if the final abnormal score is greater than or equal to the first threshold but less than the second threshold, it is classified as medium risk; and if the final abnormal score is greater than or equal to the second threshold, it is classified as high risk.
[0012] Furthermore, cross-domain collaboration and spatiotemporal correlation analysis specifically includes the following steps: First, assume that there are multiple security domains in the industrial energy-saving Internet of Things network, and that a number of energy-saving control components are deployed in each security domain. The total number of components is recorded as a specific value. The abnormal behavior detection unit uses a preset time window as the sliding step size to extract abnormal events in each security domain that reach the medium risk level or above within the time window, form an event set, and record the number of events. Next, two preset thresholds are set: an absolute number threshold and a proportion threshold. If the number of events is greater than or equal to the absolute number threshold, or the ratio of the number of events to the total number of components in the security domain is greater than or equal to the proportion threshold, then a coordinated attack is determined to have occurred in the security domain. At this time, the coordinated attack combined anomaly score of the security domain is calculated: the highest anomaly score of the component in the event set is taken and multiplied by a coordinated amplification factor, which is equal to 1 plus a preset coordinated amplification factor multiplied by the proportion of the abnormal component to the total number of components in the security domain. Then, the calculation result is limited to the maximum value of the score range. If the combined score reaches or exceeds the high-risk threshold, then the risk level of all components participating in the abnormal event in the security domain is increased by one level, of which medium risk is increased to high risk and high risk remains unchanged, and the attack type is recorded as worm proliferation or side-channel attack. Subsequently, the abnormal propagation across security domains is analyzed: the abnormal behavior detection unit monitors the cross-domain communication requests recorded by the network micro-segmentation unit in real time. For each communication request from the source security domain to the destination security domain, it checks whether it matches a preset access control list, which includes the source IP range, destination IP range, protocol type, port number, and communication direction. If the request does not meet any allowed rule, it is marked as an unauthorized cross-domain request, and the number of unauthorized requests to the source security domain is accumulated within a preset time window. A cross-domain attack judgment threshold is set. When the accumulated number reaches the threshold, it is judged as a cross-domain attack attempt, and a cross-domain attack score is calculated: the ratio of the number of unauthorized requests to the judgment threshold is multiplied by a medium-risk threshold, and then the result is limited to the maximum value within the score range. Finally, based on the above analysis results, a dynamic response is executed: For intra-domain coordinated attacks, the abnormal behavior detection unit sends the merged coordinated attack event to the emergency response unit. This coordinated attack event includes the security domain identifier, timestamp, merged score, and list of affected components. The emergency response unit instructs the network micro-segmentation unit to temporarily tighten the access control permissions of the security domain. For cross-domain attacks, the network micro-segmentation unit is instructed to immediately block all outbound communication from the source security domain, dynamically update the access control list to add denial rules, set a temporary validity period, and highlight the boundary of the isolated security domain in the visualization unit.
[0013] Furthermore, the secondary verification of the security dynamic protection unit includes: comparing the abnormal events output by the abnormal behavior detection unit with the historical normal data templates stored in the data storage unit. If the deviation is within the preset allowable range, it is judged as a false alarm or transient disturbance and marked as to be observed. If the deviation exceeds the allowable range and is associated with at least two independent detection dimensions at the same time, it is judged as a real attack and marked as a confirmed threat. The independent detection dimensions include HMAC signature failure, continuous loss of heartbeat packets, and the anti-tampering flag changing from 0 to 1. Based on the review conclusions, reverse control is implemented: Firstly, the reverse control energy-saving control equipment hierarchical unit: when the verification confirms a real attack and the attack source is concentrated in a specific type of component, the instruction temporarily raises the preset security level of all components of that type by one level, and sends the adjusted security level information to the data storage unit for storage until manual intervention is required to remove it; Secondly, the reverse control network micro-isolation unit: when the verification confirms the existence of a coordinated attack across security domains, the instruction dynamically shrinks the access control permissions of the infected security domain, highlights the isolation boundary in the visualization unit, and generates alarm information; Third, the reverse control sensing and acquisition unit: when the verification confirms that it is a false alarm or transient disturbance, the instruction will temporarily shorten the preset transmission interval of the element and continuously acquire high-frequency data for secondary confirmation. If there is no abnormality, the original transmission interval will be restored and the alarm will be cleared. If there is a covert attack, it will be immediately upgraded to a confirmed threat and the emergency response unit will be triggered to perform isolation operation. Fourth, the reverse control abnormal behavior detection unit: takes the review conclusion as feedback input, dynamically updates the weighting factor of the global behavior baseline and the abnormal threshold of the control analysis model, adds deviation patterns that are repeatedly judged as false alarms to the whitelist, adds newly discovered attack patterns to the blacklist feature library, and adjusts the weighting factors of high-level, medium-level and low-level components.
[0014] Furthermore, it also includes an emergency response unit and a visualization unit; the emergency response unit is used to automatically perform blacklist isolation, network disconnection and backup edge gateway switching when the abnormal behavior detection unit determines that the abnormal behavior is a high-risk anomaly or the security dynamic protection unit confirms a threat; the visualization unit is used to display the security domain topology, alarm information and isolated security domain edges.
[0015] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: This invention classifies all networked energy-saving control components into multiple security levels based on the comprehensive impact of intrusion or failure. It then divides these security levels into multi-dimensional security domains and configures whitelist access control lists to prohibit direct horizontal communication between device domains. It collects component operating data and status information, forcibly adding HMAC data signatures, heartbeat status, and physical anti-tampering flags to all transmitted data. For sensors without hardware tamper-proof switches, GPS coordinates or RSSI signal baselines are used as substitutes for anti-tampering functionality. A hierarchical distributed architecture combining edge preprocessing and central global analysis is adopted. Anomaly scores are calculated through security level weighted scoring and multi-dimensional additional scoring mechanisms, combined with spatiotemporal correlation analysis to accurately identify coordinated attacks and cross-domain anomaly propagation. The detection results are then re-verified, and reverse control is used to form a closed-loop adaptive protection system for each unit, linking emergency response and visualization units to achieve automated threat handling.
[0016] It achieves pre-emptive planning, in-process inter-domain isolation, and post-event review and optimization, forming a full lifecycle intelligent protection system. It effectively solves the technical defects of existing industrial energy-saving control networks, such as unbalanced allocation of protection resources, difficulty in blocking the spread of lateral threats, insufficient credibility of raw data, poor robustness of centralized detection architecture, high false alarm rate, and difficulty in identifying coordinated attacks. It achieves the engineering goals of making attacks difficult to penetrate, difficult to spread after penetration, early detection of anomalies, automatic correction of false alarms, and full traceability of handling, significantly improving the security and operational efficiency of industrial energy-saving control networks. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings. Figure 1 This is a flowchart illustrating the overall system architecture and safety / energy-saving closed-loop process of the present invention. Figure 2 This is a flowchart illustrating the system initialization and network security baseline construction process of this invention; Figure 3 This is a flowchart of the sensing data acquisition and reliable transmission process of the present invention; Figure 4 This is the overall flowchart of the hierarchical distributed abnormal behavior detection of the present invention; Figure 5 This is a flowchart illustrating the core anomaly scoring and risk level calculation process of this invention. Figure 6 This is a flowchart of the cross-domain collaboration and spatiotemporal correlation attack detection process of the present invention; Figure 7 This is a flowchart of the safety dynamic protection and reverse closed-loop control of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example 1: like Figure 1 The energy-saving control equipment management system based on the Industrial Internet shown includes a signal-connected energy-saving control equipment hierarchical unit, a network micro-isolation unit, a sensing and acquisition unit, an abnormal behavior detection unit, a data storage unit, a visualization unit, and a dynamic security protection unit. like Figures 1-2The energy-saving control device classification unit shown is used to identify and record the component information of all networked energy-saving control components and their corresponding preset security levels to generate safe energy-saving component information, and send this safe energy-saving component information to the data storage unit for storage. Energy-saving control components include sensors, PLCs, edge devices, telemetry sensors, frequency converters, smart meters, actuators, temperature controllers, smart circuit breakers, energy meters, remote I / O units, etc., thereby covering the physical component foundation of the entire "sensing, transmission, control, execution, and feedback" link, enabling the industrial Internet energy-saving control system to collect energy consumption data in real time, identify equipment status, and execute optimization strategies. Component information includes equipment identification, equipment type, technical parameters, network attributes, physical location, and business affiliation. The preset security levels are pre-divided into high, medium, and low levels according to the comprehensive impact of the energy-saving control system after the energy-saving control component is invaded or fails. High level corresponds to edge gateways and group control PLCs, medium level corresponds to smart meters and smart circuit breakers, and low level corresponds to temperature and humidity sensors and light sensors. For example, the information entry of a certain temperature and humidity sensor is preset to the "low" level.
[0020] The network micro-segmentation unit is used to divide the energy-saving control network into multiple security domains based on the preset security levels and types of each component contained in the security and energy-saving component information stored in the data storage unit, according to the equipment security level, equipment type, and communication requirements. For each security domain, access control permissions matching the equipment security level are preset, thereby configuring an industrial energy-saving Internet of Things network with security isolation characteristics. The security domain division results and access control lists corresponding to the industrial energy-saving Internet of Things network are sent to the data storage unit for storage. At the same time, the security domain topology is displayed graphically on a visualization unit, such as a computer screen or a large monitoring screen, for intuitive observation.
[0021] Security domains can be divided into virtual terminal security domains and device terminal security domains based on virtual terminals and device terminals; they can also be divided into regional, park, functional unit, and device-level security domains from top to bottom, with each device-level security domain corresponding to the central air conditioning, production equipment, monitoring equipment, and their controllers in each building within the park; they can also be divided into cooling control domains, power control domains, lighting control domains, and data acquisition control domains based on control type, or into source port domains and destination port domains based on communication ports. Based on the combination of various partitioning methods mentioned above, the network micro-segmentation unit presets an access control list for each security domain. The access control list includes at least: the range of source IP addresses allowed for communication, the range of destination IP addresses, the protocol type, the port number, and the communication direction. For communication requests across security domains, the request is allowed if it meets the preset whitelist rules of both the source domain and the destination domain, or if the corresponding permissions are manually added; otherwise, it is rejected by default. In addition, the network micro-segmentation unit also supports dynamic access control based on time periods. For example, during production periods, data exchange between the central air conditioning control domain and the monitoring and management domain is allowed, while during non-production periods, only heartbeat detection communication between the emergency response unit and the designated device domain is allowed. For critical device domains, such as the central air conditioning host controller, inbound connections are further restricted to specific management ports of the edge gateway, prohibiting any direct lateral communication between device domains. This effectively blocks the lateral movement path of attackers after a single point of intrusion, thereby enabling them to make decisions or guide attacks.
[0022] That is, without hindering the normal energy-saving control data flow, it systematically curbs the spread of internal network threats with minimal performance overhead, thereby improving the robustness and reliability of the overall system.
[0023] like Figure 3 The sensor acquisition unit shown is used to collect component operating data and component status information and send them to the abnormal behavior detection unit within a preset period, such as once every 20 seconds, thereby saving resources. like Figure 4 The operating data of the components shown includes equipment operating data collected by sensors, specifically physical quantities that reflect the working status of the equipment, such as voltage, current, power, temperature, pressure, and flow rate, as well as the voltage, current, power, temperature, and pressure of the components themselves.
[0024] Component status information includes HMAC data signature information, heartbeat packet transmission status, and physical anti-tampering status flags. The HMAC data signature information is used to verify data integrity and source legitimacy. The heartbeat packet transmission status indicates the device's online / offline status; specifically, it's a fixed-format status message actively sent by the sensor to the data storage unit at preset time intervals, such as 20 seconds in the example above. This message contains at least a unique device identifier, a timestamp, and a preset "heartbeat sequence number." If the receiving end does not receive a heartbeat message from a device three times consecutively, it sets the corresponding status flag for that device to "offline"; otherwise, it remains "online." The heartbeat message does not contain collected device operating data; it only serves to prove sensor network connectivity and program activity.
[0025] The physical tamper-proof status flag is used to indicate whether the device casing has been opened or damaged. This refers to a mechanical or electronic tamper-proof switch installed inside the sensor casing, such as a microswitch, reed switch with magnet, or optical detection contact. When the casing is closed and not opened, the tamper-proof switch is in a normally closed or normally open state. The microcontroller inside the sensor reads the switch signal level and generates an "tamper-proof status bit." This status bit is preset to 0, indicating that the casing is intact and has not been opened; conversely, it is preset to 1, indicating that the casing has been opened or the tamper-proof circuit has been damaged. The sensor appends this status bit to the end of each data packet it sends, including normal operation data or heartbeat packets. If the status bit changes from 0 to 1 without authorization, the system determines that the sensor has been physically intruded upon, immediately triggers an alarm, and adds the sensor to the blacklist. In addition, for low-cost sensors that do not have hardware tamper-proof switches, the physical tamper-proof status flag can be replaced by the GPS coordinates or RSSI signal characteristic baseline of the sensor's fixed installation location. When a coordinate offset or signal characteristic exceeds a preset threshold is detected, the tamper-proof status flag is also set to 1.
[0026] The abnormal behavior detection unit receives component operation data and component status information uploaded by the sensing and acquisition unit at preset time intervals, and retrieves safety and energy-saving component information and the security domain division results of the industrial energy-saving IoT network from the data storage unit. The component operation data includes equipment operation data collected by sensors, such as voltage, current, power, temperature, pressure, and flow rate; and the energy-saving control component's own operation data, such as its own voltage, current, power, temperature, and pressure. The component status information includes HMAC data signature information, heartbeat packet transmission status, and physical anti-tampering status flags. The safety and energy-saving component information includes the preset security level of each energy-saving control component, its component type, network attributes, physical location, and service affiliation. This preset security level can be set to multiple levels, such as high, medium, and low. The security domain division results of the industrial energy-saving IoT network include access control lists and dynamic time-period policies between each security domain. like Figure 4 -like Figure 6 The abnormal behavior detection unit shown includes edge units deployed on each edge gateway and a global detection master unit deployed on the central server. Its hierarchical distributed detection steps are as follows: Step 1: Edge data preprocessing and baseline construction for edge units First, on each edge gateway, based on the information on the safe and energy-saving components stored in the data storage unit, the locally accessed energy-saving control components and their preset security levels are identified. Next, for each component, the HMAC signature in the received component operation data and component status information is used to perform data integrity verification, and invalid data packets that fail to verify the signature are filtered out. Subsequently, based on valid data within a continuous time period, a sliding window algorithm is used to construct a short-term behavioral baseline for the component. This baseline includes the mean, variance, and timing pattern of the component's operating data and heartbeat packet transmission status. For example, under normal conditions, a heartbeat occurs every 20 seconds. If no heartbeat is received for three consecutive times, the device is taken offline. At the same time, the normal value of the physical anti-tampering status flag is recorded, with a default value of 0. Finally, when the deviation of the actual data from the baseline exceeds a preset threshold, the abnormal event and the three data points before and after it are packaged and uploaded to the central server; otherwise, they are directly discarded or compressed at the edge to reduce network load. The preset threshold is defined as follows: actual data deviation > 20%, heartbeat packet missing times ≥ 2, or the anti-tampering flag changing from 0 to 1.
[0027] Step 2: Establishing a global behavior baseline and calculating anomaly scores at the central endpoint The central server's global detection unit receives abnormal events reported from all edge gateways and, combined with historical normal data stored in the data storage unit at a preset period, constructs a global behavioral baseline for each energy-saving control element. The preset storage period can be set to 30 days, 60 days, etc., and the amount of historical normal data stored at the preset period can also be set, such as 100 MB if the data volume is greater than 50 MB, to ensure a sufficiently large data volume for quantification. The global behavior baseline includes the statistical characteristics of the component's operating data, and also incorporates the cross-device association characteristics of the industrial energy-saving IoT network security domain to which the component belongs, such as the simultaneous change of the anti-tampering status flags of multiple components in the same security domain, or the time synchronization of the offline mode of the internal jump packet in the same area. The specific algorithm is as follows: the control analysis model is combined with the weighted scoring method to calculate the abnormal score of each abnormal event. The weighting factor is dynamically adjusted according to the preset safety level of the component: the weight of high-level components is greater than that of medium-level components, which is greater than that of low-level components.
[0028] The specific steps of the control analysis model are as follows: The control analysis model is used to quantify the degree of abnormality of abnormal event data for each energy-saving control element. Its input is the multi-dimensional feature vector of a single element within the detection window, and its output is the original abnormality score of the element.
[0029] S1. Retrieve historical normal data of the component within a preset period from the data storage unit as a training sample set. Each sample is a multi-dimensional feature vector, denoted as... ,in These represent physical quantities such as voltage, current, power, temperature, pressure, and flow rate in the component's operating data, as well as heartbeat packet reception interval, HMAC signature verification result, and physical anti-tampering status bits in the component's status information. S2. Randomly select from the training sample set Each sample is used as a subset to construct a model unit; the process of constructing a model unit is as follows: S201. Randomly select a feature dimension. and its segmentation value ,in It lies between the minimum and maximum values of this feature in the current subsample set; S202 will use the features of the current node's sample set Less than The sample is assigned to the left child node, greater than or equal to The samples are assigned to the right child node; S203 recursively repeats the above partitioning process for the left and right child nodes until the current sample node count is 1; S204, repeat the steps S201-S203 above to generate... Each model unit is used to form a set of model units; S4. For each abnormal event data point to be detected This is a feature vector composed of component operation data and status information uploaded by the sensing and acquisition unit and preprocessed at the edge. This feature vector is then input into each individual model unit to calculate the path length of the data point within each individual model unit. , ; Calculate the average path length of this data point in the isolated forest. ; S5. Calculate the raw outlier score for this data point. : in For a given subsample size The average path length normalization factor is calculated using the following formula: It is the harmonic number, which is , The value changes as i changes; it is a function.
[0030] raw outlier score The value range is (0, 1]. The closer the value is to 1, the more abnormal the data point is, and the closer it is to 0, the more normal it is.
[0031] The specific steps for weighted scoring are as follows: First, retrieve the weighting factor corresponding to the preset security level of the component from the data storage unit. : If the component's preset safety level is high, then the weighting factor... For components such as edge gateways and group control PLCs, if the preset safety level of the components is medium (e.g., smart meters and smart circuit breakers), then the weighting factor... If the component's preset safety level is low (such as a temperature and humidity sensor or a light sensor), then the weighting factor... And a > b > c; Next, the raw anomaly scores output by the control analysis model are... Mapping to the preset interval D yields the basic score. The maximum value of the preset interval D is Dmax, and the minimum value is Dmin. Then, the weighted anomaly score S is calculated. : S in The amplification factor is a preset value, which is set by those skilled in the art according to the actual scenario, so that the weighted score of advanced components is improved compared with the basic score, while the score of low-level components remains basically unchanged or is slightly reduced. Additionally, if the anomaly is associated with multiple independent detection dimensions, a bonus score will be added to the weighted score. Each additional dimension associated increases the score by e points, but the total score cannot exceed the Dmax value. in This represents the number of associated detection dimensions. The larger the k value, the more dimensions are associated. Finally, based on the final anomaly score Determine the risk level. Preset two thresholds. and Among them, satisfying : like It was determined to be at a low risk level; like It was determined to be at a medium risk level; like It was classified as a high-risk level.
[0032] The aforementioned final anomaly score and risk level serve as the output of the abnormal behavior detection unit, which is then used by the dynamic safety protection unit for secondary verification.
[0033] Step 3: Tiered Alarms and Differentiated Handling Based on the anomaly score and the component's preset safety level, the specific graded handling is as follows: When the anomaly score is low risk: only the event log is recorded, and no alarm is triggered; if the component is at a low security level, it is ignored; if it is at a high or medium level, the anomaly count of the component is updated.
[0034] When the anomaly score is medium risk: for low-level components, send a general alert to the visualization unit; for medium-level components, push an early warning message to the maintenance personnel, requiring confirmation within an hour; for high-level components, immediately display a yellow alarm on the monitoring screen and trigger the pre-isolation process of the emergency response unit, such as restricting the data connection of the component to retain only heartbeat detection.
[0035] When the anomaly score is high-risk: regardless of the component's security level, a red alarm is immediately triggered and highlighted in the visualization unit; at the same time, the emergency response unit is invoked to automatically perform blacklist isolation, adding the component to the blacklist, cutting off all its cross-security domain communication, and recording specific reasons such as anti-tampering flag transition or HMAC signature failure.
[0036] Step 4: Cross-domain collaboration and spatiotemporal correlation analysis Based on the security domain division information in the industrial energy-saving Internet of Things network, spatiotemporal correlation analysis is performed on the abnormal events of multiple components in the same security domain: when more than a preset number of components in the same security domain trigger anomalies of medium risk or above within the same time period, and these components belong to the same physical area, such as the air conditioning system in the same workshop, the anomaly scores of each component are automatically merged and the risk level is raised by one level, and it is judged as a coordinated attack. For example, if the medium risk is raised to high risk, it is predicted to be a side-channel attack or worm spread. For abnormal propagation across security domains, the abnormal behavior detection unit, in conjunction with the access control list preset by the network micro-segmentation unit, analyzes whether the abnormal event involves unauthorized cross-domain communication attempts, such as a low-level sensor sending a large number of forged heartbeat packets to a high-level edge gateway. Once detected, the cross-domain request is immediately marked as an attack and the access control list is dynamically updated to temporarily block all outbound communication from the source security domain.
[0037] The specific steps of cross-domain collaboration and spatiotemporal correlation analysis are as follows: First, let the set of security domains in the industrial energy-saving Internet of Things network be denoted as . Each security domain It is equipped with several energy-saving control components, the total number of which is The abnormal behavior detection unit uses a time window. Extract each security domain using the sliding step size. An event set consists of abnormal events that reach a medium-risk level or above within the specified time window. Let the number of abnormal events in this set be . That is, the final anomaly score. Constitutes an event set .
[0038] Next, determine whether coordinated attacks occur within the same security domain. Two preset thresholds are set: an absolute number threshold and a minimum number threshold. and proportional threshold If satisfied or If any of the conditions in the above conditions are met, a coordinated attack is determined to have occurred within that security domain. In this case, a coordinated attack anomaly score for that security domain is calculated. The formula is: in To obtain the highest anomaly score from the elements in the event set, The preset synergistic amplification factor, This represents the proportion of abnormal components to the total number of components in that security domain. If the combined score reaches the high-risk threshold... If the above applies, the risk level of all components involved in the abnormal event within the security domain will be raised by one level, i.e., medium risk will be raised to high risk, while high risk will remain unchanged, and the attack type will be recorded as "worm spread" or "side-channel attack".
[0039] Subsequently, the propagation of anomalies across security domains is analyzed. The anomaly detection unit monitors cross-domain communication requests recorded by the network micro-segmentation unit in real time. For requests originating from the security domain... To the destination security domain For each communication request, check whether it matches the preset access control list. This includes the source IP range, destination IP range, protocol type, port number, and communication direction. If the request does not meet any of the allowed rules, it is marked as an unauthorized cross-origin request and will be flagged within a time window. Internal cumulative source security domain The number of unauthorized requests is denoted as .
[0040] Set a threshold for cross-domain attack detection .when When this occurs, it is determined to be a cross-domain attack attempt, and a cross-domain attack score is calculated. : in This is the medium-risk threshold. Note that this formula ensures that the cross-domain score is at least [value missing] when the number of unauthorized requests reaches the threshold. This triggered a medium-risk alert.
[0041] Finally, a dynamic response is executed based on the above analysis results: For coordinated attacks within the same domain, the abnormal behavior detection unit sends the merged coordinated attack event to the incident response unit. The coordinated attack event includes a security domain identifier, timestamp, merged score, and a list of affected components. The emergency response unit instructs the network micro-segmentation unit to temporarily tighten access control permissions for the security domain, such as allowing only heartbeat detection communication; for cross-domain attacks, the network micro-segmentation unit instructs the network micro-segmentation unit to immediately block the source security domain. All outbound communications, excluding the pre-defined emergency heartbeat channel, dynamically update the access control list to add denial rules, set a temporary validity period of 30 minutes, and highlight the isolated security domain boundary in the visualization unit. Through the above spatiotemporal correlation analysis and cross-domain propagation detection, accurate identification and proactive defense against coordinated attacks are achieved.
[0042] Step 5: Distributed Load Balancing and Network Outage Tolerance When the CPU load of a lightweight detection subunit of an edge gateway exceeds the constraint value, the unit automatically transmits the data streams of all locally connected low-security-level components directly to the central server without performing edge preprocessing, in order to ensure the real-time detection of high-level and mid-level components. If the network between the central server and the edge gateway is interrupted, the edge gateway will cache the local abnormal events and raw data in the solid-state drive. After the network is restored, the data will be retransmitted to the data storage unit in timestamp order, and the global detection master unit will recalculate the abnormality score.
[0043] Through the aforementioned hierarchical distributed processing, the abnormal behavior detection unit, based on the comprehensive utilization of the security level output by the energy-saving control equipment hierarchical unit, the component operation data and status information uploaded by the sensing and acquisition unit, and the security domain partitioning results generated by the network micro-isolation unit, achieves accurate identification and differentiated response to attack behaviors, while ensuring the robustness of the system under conditions of limited edge computing resources and network instability.
[0044] like Figure 7 The security dynamic protection unit shown is used to receive the abnormal score, risk level and attack type judgment results output by the abnormal behavior detection unit, and to perform a second review of the detection and processing results. At the same time, based on the review conclusion, it reversely controls the energy-saving control equipment hierarchical unit, network micro-isolation unit, sensing and acquisition unit and abnormal behavior detection unit to achieve deep closed-loop processing. The specific steps for the second review are as follows: First, the abnormal events output by the abnormal behavior detection unit are compared with the historical normal data templates stored in the data storage unit. If the deviation is within the preset allowable range, for example, although the abnormal score reaches the medium risk level, the actual physical quantity does not exceed 10% of the equipment's rated value, it is judged as a false alarm or transient disturbance, and the verification result is marked as "to be observed". If the deviation exceeds the allowable range and is associated with at least two independent detection dimensions at the same time, it is judged as a real attack, and the verification result is marked as "confirmed threat". Detection dimensions include HMAC signature failure, continuous loss of heartbeat packets, and the anti-tampering flag changing from 0 to 1. Based on the above review conclusions, the safety dynamic protection unit performs the following reverse re-control: Firstly, the reverse control energy-saving control equipment classification unit: when the verification confirms a real attack and the attack source is concentrated in a specific type of component, the security dynamic protection unit instructs the energy-saving control equipment classification unit to temporarily raise the preset security level of all components of that type by one level, and sends the adjusted security level information to the data storage unit for storage until manual intervention is required to remove it; Secondly, the reverse control network micro-segmentation unit: when the verification confirms the existence of a coordinated attack across security domains, the security dynamic protection unit instructs the network micro-segmentation unit to dynamically shrink the access control permissions of the infected security domain. For example, it may change the communication protocol between the source security domain and the destination security domain from allowing all to only allowing ICMP probes, or temporarily close all outbound ports of the security domain. At the same time, the network micro-segmentation unit is required to highlight the boundary of the isolated security domain on the visualization unit and generate alarm information. Third, the reverse control sensing and acquisition unit: When the verification confirms that a certain component is a false alarm or transient disturbance, the security dynamic protection unit instructs the sensing and acquisition unit to temporarily shorten the preset transmission interval of the component from 20 seconds to 5 seconds, and continue for 30 seconds to obtain higher frequency data for secondary confirmation; if the high-frequency data confirms that there is no abnormality, the original transmission interval is restored and the alarm is cleared; if the high-frequency data confirms the existence of a covert attack, such as intermittent tampering, it is immediately upgraded to "confirmed threat" and the emergency response unit is triggered to perform isolation operation; Fourth, the reverse control abnormal behavior detection unit: The security dynamic protection unit uses the review conclusion as feedback input to the abnormal behavior detection unit to dynamically update the weighting factor of the global behavior baseline and the abnormal threshold of the control analysis model; specifically, deviation patterns that are repeatedly judged as false alarms are added to the whitelist, and newly discovered attack patterns are added to the blacklist feature library. At the same time, the weighting factors of high-level, medium-level, and low-level components are adjusted to continuously optimize the accuracy and adaptability of the detection model; including false alarm features and real attack features, such as temporarily increasing the weight of medium-level components that are frequently attacked.
[0045] Through the aforementioned secondary verification and reverse re-control, the security dynamic protection unit achieves closed-loop deep processing of the energy-saving control equipment hierarchical unit, network micro-isolation unit, sensing and acquisition unit, and abnormal behavior detection unit, forming an adaptive security mechanism of "detection-verification-feedback-adjustment-re-detection". This effectively reduces the false alarm rate, enhances the system's defense against unknown attacks, and works in conjunction with the network micro-isolation unit to further strengthen the security isolation characteristics of the industrial energy-saving Internet of Things network.
[0046] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0047] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. An energy-saving control equipment management system based on the Industrial Internet, comprising a signal-connected energy-saving control equipment hierarchical unit, a network micro-isolation unit, a sensing and acquisition unit, a data storage unit, an abnormal behavior detection unit, and a dynamic safety protection unit; characterized in that, The energy-saving control equipment classification unit identifies and records the component information of all networked energy-saving control components and their corresponding preset security levels, generates safe and energy-saving component information, and sends it to the data storage unit for storage. Based on information about secure and energy-saving components, the network micro-segmentation unit divides the energy-saving control network into multiple security domains and presets access control permissions. The configuration results of the security domain division form an industrial energy-saving Internet of Things network with secure isolation characteristics. The sensing and acquisition unit collects the component operation data and component status information of the energy-saving control component and sends them to the abnormal behavior detection unit at preset time intervals; The abnormal behavior detection unit is used to receive data uploaded by the sensing and acquisition unit, retrieve information on safety and energy-saving components and security domain division results from the data storage unit, calculate abnormal scores and risk levels through hierarchical distributed detection, and determine the identification and hierarchical alarm of attack behavior. The safety dynamic protection unit is used to receive the abnormal score and risk level output by the abnormal behavior detection unit, perform a second review and judgment on the detection and processing results, and execute reverse control and parameter optimization through the review and judgment.
2. The energy-saving control equipment management system based on the Industrial Internet according to claim 1, characterized in that, Energy-saving control components include sensors, PLCs, edge devices, telemetry sensors, frequency converters, smart meters, actuators, temperature controllers, smart circuit breakers, energy meters, and remote I / O units. Component information includes device identification, device type, technical parameters, network attributes, physical location, and service affiliation. The preset security levels are pre-classified into high, medium, and low levels based on the comprehensive impact of the energy-saving control components being compromised or malfunctioning. High level corresponds to edge gateways and group control PLCs, medium level corresponds to smart meters and smart circuit breakers, and low level corresponds to temperature and humidity sensors and light sensors.
3. The energy-saving control equipment management system based on the Industrial Internet according to claim 1, characterized in that, The methods for dividing security domains in network micro-segmentation units include: dividing them into virtual terminal security domains and device terminal security domains based on virtual terminals and device terminals; dividing them hierarchically from top to bottom into regional level, park level, functional unit level, and device level security domains, where each device level security domain corresponds to the central air conditioning, production equipment, monitoring equipment, and their controllers in each building within the park; dividing them into cooling control domains, power control domains, lighting control domains, and data acquisition control domains based on control type; or dividing them into source port domains and destination port domains based on communication ports. The network micro-segmentation unit presets an access control list for each security domain. The access control list includes the range of source IP addresses, the range of destination IP addresses, the protocol type, the port number, and the communication direction allowed for communication. For communication requests across security domains, the request is allowed if it meets the preset whitelist rules of both the source and destination domains or is manually authorized; otherwise, it is rejected by default. The network micro-segmentation unit also features dynamic access control based on time periods. During production periods, it allows data exchange between the central air conditioning control domain and the monitoring and management domain. During non-production periods, it only allows heartbeat detection communication between the emergency response unit and designated equipment domains. For critical equipment domains, it restricts inbound connections to specific management ports of the edge gateway and prohibits any direct lateral communication between equipment domains.
4. The energy-saving control equipment management system based on the Industrial Internet according to claim 1, characterized in that, The component operation data collected by the sensing and acquisition unit includes equipment operation data collected by sensors and the operation data of the energy-saving control components themselves. Equipment operation data includes voltage, current, power, temperature, pressure, and flow rate; component status information includes HMAC data signature information, heartbeat packet transmission status, and physical anti-tampering status flags.
5. The energy-saving control equipment management system based on the Industrial Internet according to any one of claims 1-4, characterized in that, The abnormal behavior detection unit includes edge units deployed on each edge gateway and a global detection master unit deployed on the central server. Its hierarchical distributed detection includes the following steps: The first step is edge data preprocessing and baseline construction: On each edge gateway, the energy-saving control elements and their preset security levels are identified based on the information of the security and energy-saving elements. HMAC signature is used to verify data integrity and filter invalid data packets. Based on the valid data within a continuous time period, a short-term behavior baseline is constructed using a sliding window algorithm. When the deviation between the actual data and the baseline exceeds a preset threshold, the abnormal event and several data points before and after it are packaged and uploaded to the central server. The second step is to construct the global behavior baseline and calculate the anomaly score at the central end: The global detection master unit receives the reported abnormal events, constructs the global behavior baseline of each component by combining historical normal data, and calculates the anomaly score and risk level by using a control analysis model combined with a weighted scoring method. The third step is to implement graded alarms and differentiated handling: based on anomaly scoring and the preset security level of components, low-risk components only log, medium-risk components send prompts to low-risk components, push warnings to medium-risk components, and display yellow alarms and trigger pre-isolation for high-risk components, and high-risk components trigger red alarms and perform blacklist isolation regardless of the level. The fourth step is cross-domain collaboration and spatiotemporal correlation analysis: based on security domain division information, spatiotemporal correlation analysis is performed on abnormal events of multiple components within the same security domain to determine collaborative attacks and dynamically adjust the access control list. Step 5, Distributed load balancing and network outage fault tolerance: When the edge gateway CPU load exceeds the constraint value, it automatically transmits the data stream of the lower-level components. When the network is interrupted, the locally cached data will be transmitted after the network is restored.
6. The energy-saving control equipment management system based on the Industrial Internet according to claim 5, characterized in that, The specific steps of the control analysis model are as follows: The first step is to retrieve the historical normal data of the component within a preset period from the data storage unit as a training sample set. Each sample is a multi-dimensional feature vector, which includes voltage, current, power, temperature, pressure, and flow rate in the component operation data, as well as heartbeat packet reception interval, HMAC signature verification result, and physical anti-tampering status bit in the component status information. The second step is to randomly select a preset number of samples from the training sample set to construct model units: randomly select a feature dimension and its segmentation value between the minimum and maximum values in the current sub-sample set, divide the samples whose feature dimension is less than the segmentation value into the left child node, and divide the samples whose feature dimension is greater than or equal to the segmentation value into the right child node, and recursively repeat the above division process until the number of current sample nodes is equal to the preset minimum value, and repeat the above construction process to generate a preset number of model units, forming a set of model units. The third step is to input the data point to be detected into each model unit, calculate the path length of the data point in each model unit, and then calculate the average of the path lengths of all model units. The fourth step is to calculate the raw anomaly score: Substitute the average path length mentioned above into the preset normalization function, which is calculated based on the subsample size and harmonic number to obtain the raw anomaly score with a value between 0 and 1.
7. The energy-saving control equipment management system based on the Industrial Internet according to claim 5, characterized in that, The specific steps of the weighted scoring method are as follows: The first step is to retrieve the weight factors corresponding to the preset security level of the components from the data storage unit, with high-level components having the largest weight, medium-level components having the second largest weight, and low-level components having the smallest weight. The second step is to map the original anomaly scores output by the control analysis model to a preset scoring interval, which has a minimum and a maximum value, to obtain the basic score. The third step is to calculate the weighted anomaly score: multiply the base score by an adjustment factor, which is obtained by multiplying the difference between the preset amplification factor and the weight factor and then adding 1. Then, the calculation result is limited to the minimum and maximum values of the preset score range. The fourth step is to add additional points to the weighted anomaly score if the anomaly is associated with multiple independent detection dimensions. For each additional dimension associated, a preset score is added, but the total score does not exceed the maximum value of the scoring range, thus obtaining the final anomaly score. The fifth step involves setting two risk level thresholds, both of which are within the scoring range. The final abnormal score is then compared with these two thresholds: if the final abnormal score is less than the first threshold, it is classified as low risk; if the final abnormal score is greater than or equal to the first threshold but less than the second threshold, it is classified as medium risk; and if the final abnormal score is greater than or equal to the second threshold, it is classified as high risk.
8. The energy-saving control equipment management system based on the Industrial Internet according to claim 5, characterized in that, Cross-domain collaboration and spatiotemporal correlation analysis specifically include the following steps: First, assume that there are multiple security domains in the industrial energy-saving Internet of Things network, and that a number of energy-saving control components are deployed in each security domain. The total number of components is recorded as a specific value. The abnormal behavior detection unit uses a preset time window as the sliding step size to extract abnormal events in each security domain that reach the medium risk level or above within the time window, form an event set, and record the number of events. Next, two preset thresholds are set: an absolute number threshold and a proportion threshold. If the number of events is greater than or equal to the absolute number threshold, or the ratio of the number of events to the total number of components in the security domain is greater than or equal to the proportion threshold, then a coordinated attack is determined to have occurred in the security domain. At this time, the coordinated attack combined anomaly score of the security domain is calculated: the highest anomaly score of the component in the event set is taken and multiplied by a coordinated amplification factor, which is equal to 1 plus a preset coordinated amplification factor multiplied by the proportion of the abnormal component to the total number of components in the security domain. Then, the calculation result is limited to the maximum value of the score range. If the combined score reaches or exceeds the high-risk threshold, then the risk level of all components participating in the abnormal event in the security domain is increased by one level, of which medium risk is increased to high risk and high risk remains unchanged, and the attack type is recorded as worm proliferation or side-channel attack. Subsequently, the abnormal propagation across security domains was analyzed: the abnormal behavior detection unit monitors the cross-domain communication requests recorded by the network micro-segmentation unit in real time. For each communication request from the source security domain to the destination security domain, it checks whether it matches the preset access control list, which includes the source IP range, destination IP range, protocol type, port number and communication direction. If the request does not meet any of the allowed rules, it will be marked as an unauthorized cross-domain request, and the number of unauthorized requests to the source security domain will be accumulated within a preset time window; Set a threshold for cross-domain attack detection. When the cumulative number of attempts reaches this threshold, it is considered a cross-domain attack attempt. Calculate the cross-domain attack score: multiply the ratio of the number of unauthorized requests to the detection threshold by the medium-risk threshold, and then limit the result to the maximum value within the score range. Finally, based on the above analysis results, a dynamic response is executed: For intra-domain coordinated attacks, the abnormal behavior detection unit sends the merged coordinated attack event to the emergency response unit. This coordinated attack event includes the security domain identifier, timestamp, merged score, and list of affected components. The emergency response unit instructs the network micro-segmentation unit to temporarily tighten the access control permissions of the security domain. For cross-domain attacks, the network micro-segmentation unit is instructed to immediately block all outbound communication from the source security domain, dynamically update the access control list to add denial rules, set a temporary validity period, and highlight the boundary of the isolated security domain in the visualization unit.
9. The energy-saving control equipment management system based on the Industrial Internet according to claim 1, characterized in that, The secondary verification of the security dynamic protection unit includes: comparing the abnormal events output by the abnormal behavior detection unit with the historical normal data templates stored in the data storage unit. If the deviation is within the preset allowable range, it is judged as a false alarm or transient disturbance and marked as to be observed. If the deviation exceeds the allowable range and is associated with at least two independent detection dimensions at the same time, it is judged as a real attack and marked as a confirmed threat. The independent detection dimensions include HMAC signature failure, continuous loss of heartbeat packets, and the anti-tampering flag changing from 0 to 1. Based on the review conclusions, reverse control is implemented: Firstly, the reverse control energy-saving control equipment hierarchical unit: when the verification confirms a real attack and the attack source is concentrated in a specific type of component, the instruction temporarily raises the preset security level of all components of that type by one level, and sends the adjusted security level information to the data storage unit for storage until manual intervention is required to remove it; Secondly, the reverse control network micro-isolation unit: when the verification confirms the existence of a coordinated attack across security domains, the instruction dynamically shrinks the access control permissions of the infected security domain, highlights the isolation boundary in the visualization unit, and generates alarm information; Third, the reverse control sensing and acquisition unit: when the verification confirms that it is a false alarm or transient disturbance, the instruction will temporarily shorten the preset transmission interval of the element and continuously acquire high-frequency data for secondary confirmation. If there is no abnormality, the original transmission interval will be restored and the alarm will be cleared. If there is a covert attack, it will be immediately upgraded to a confirmed threat and the emergency response unit will be triggered to perform isolation operation. Fourth, the reverse control abnormal behavior detection unit: takes the review conclusion as feedback input, dynamically updates the weighting factor of the global behavior baseline and the abnormal threshold of the control analysis model, adds deviation patterns that are repeatedly judged as false alarms to the whitelist, adds newly discovered attack patterns to the blacklist feature library, and adjusts the weighting factors of high-level, medium-level and low-level components.
10. The energy-saving control equipment management system based on the Industrial Internet according to any one of claims 1-9, characterized in that, It also includes an emergency response unit and a visualization unit; the emergency response unit is used to automatically perform blacklist isolation, network disconnection and backup edge gateway switching when the abnormal behavior detection unit determines that the abnormal behavior is a high-risk anomaly or the security dynamic protection unit confirms a threat; the visualization unit is used to display the security domain topology, alarm information and the boundary of the isolated security domain.