Industrial control flow transmission methods, devices, storage media and computer equipment
By introducing virtual switching devices for traffic control and forwarding, the problems of complex and inflexible traffic acquisition processes in existing technologies are solved, enabling dynamic acquisition and security auditing of industrial control traffic, and improving the system's flexibility and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU DPTECH TECH
- Filing Date
- 2026-02-03
- Publication Date
- 2026-06-02
Smart Images

Figure CN122137789A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to an industrial control flow transmission method, apparatus, storage medium, and computer equipment. Background Technology
[0002] In industrial control network environments, to avoid network attacks and operational risks, it is necessary to perform security audits on the network traffic of each independent functional area. A common security auditing method is to use the port mirroring function of a switch to mirror the traffic of each functional area to the physical network port of a dedicated auditing device. To further improve auditing performance, the auditing device typically uses Data Plane Development Kit (DPDK) technology to collect the mirrored traffic under the physical network port. That is, the physical network card carrying the physical network port is unbound from the operating system kernel driver and bound to the DPDK user-space driver. This allows the DPDK process to bypass the kernel and directly capture data packets at high speed in user space, and forward them to the auditing application running in the auditing device for deep analysis and security detection.
[0003] However, existing industrial control traffic acquisition methods have a strong binding relationship between the DPDK process and the physical network card. If it is necessary to change the physical network port for traffic acquisition, the ongoing audit process must be interrupted, and the device must be restarted after reconfiguring the new binding relationship in order to update the physical network port being acquired. This physical network port replacement process is complicated and difficult to adapt to the dynamically changing traffic acquisition needs of each independent functional area. Summary of the Invention
[0004] In view of this, this application provides an industrial control traffic transmission method, apparatus, storage medium, and computer equipment to solve the problem that the industrial control traffic audit system in the existing industrial control traffic acquisition and audit equipment is too highly coupled, resulting in a complex process for updating the acquired physical network port, and to realize the dynamic updating and flexible configuration of the acquired physical network port.
[0005] Specifically, this application is implemented through the following technical solution: In a first aspect, embodiments of this application provide an industrial control traffic transmission method, including: Acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the auditing device; the registered interface is dynamically updated according to the industrial functional area to be audited by using the first terminal access point interface accessed by the virtual switching device. If so, then based on the address information carried by the data frame, the target control rule to which the data frame is matched is determined from the preset flow control rules; When the target control rule indicates that auditing the data frame is permitted, the data frame is forwarded to the virtual switching device, and the data frame is sent to the industrial control traffic auditing system using the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is used to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
[0006] Secondly, embodiments of this application also provide an industrial control flow transmission device, comprising: The first determining module is used to acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the auditing device; the registered interface is dynamically updated according to the industrial functional area to be audited by using the first terminal access point interface accessed by the virtual switching device. The second determining module is used to determine the target control rule hit by the data frame from the preset flow control rules based on the address information carried by the data frame if the data frame is hit. The sending module is configured to forward the data frame to the virtual switching device when the target control rule indicates that auditing the data frame is permitted, and to send the data frame to the industrial control traffic auditing system using the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is configured to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
[0007] Thirdly, an optional implementation of this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the industrial control flow transmission method described in the first aspect above.
[0008] Fourthly, an optional implementation of this application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the industrial control flow transmission method described in the first aspect above.
[0009] The industrial control traffic transmission method, apparatus, storage medium, and computer equipment provided in this application introduce a virtual switching device as the core scheduling unit. The physical network interfaces corresponding to the industrial functional areas to be audited are registered in an interface list, and the interface list is dynamically updated through the first terminal access point interface accessed by the virtual switching device. This debinds the physical network card from the industrial control traffic audit system, allowing for flexible changes to the physical network interface without interrupting the ongoing audit process when the industrial functional areas to be audited change. This overcomes the shortcomings of traditional industrial control traffic (i.e., industrial control traffic) audit methods, which involve complex and inflexible processes for changing traffic collection areas. By identifying the source of arriving data frames, it is possible to accurately distinguish whether arriving data frames originate from the industrial functional areas to be audited, thereby avoiding resource consumption caused by auditing traffic from non-audited areas. For data frames that meet the source requirements, precise matching with preset traffic control rules ensures that only data frames permitted by the rules are forwarded securely and directionally to the industrial control traffic audit system for auditing through the second terminal access point interface accessed by the virtual switching device. Under the premise of strict data flow control, a closed-loop process from dynamic interface management and secure traffic filtering to targeted transmission of audit traffic is completed. Thus, this application enables real-time adaptation to the traffic collection and auditing needs of different industrial functional areas without stopping the auditing process, effectively solving the problems of cumbersome dynamic traffic collection operation process and high traffic collection security risks caused by the fixed binding relationship in the prior art. Attached Figure Description
[0010] Figure 1 This is a flowchart illustrating an exemplary embodiment of an industrial control flow transmission method according to this application; Figure 2 This is a schematic diagram illustrating the specific transmission process of an industrial control flow transmission method according to an exemplary embodiment of this application; Figure 3 This is a schematic diagram illustrating the construction of a virtual switching device and its dynamic interface management process, as shown in an exemplary embodiment of this application. Figure 4 This is a schematic diagram of an industrial control flow transmission device shown in an exemplary embodiment of this application; Figure 5 This is a schematic diagram of the structure of a computer device shown in an exemplary embodiment of this application. Detailed Implementation
[0011] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0012] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0013] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0014] Research has revealed that in industrial control network environments, various industrial functional areas are isolated from each other. To prevent network attacks and mitigate operational risks, comprehensive security auditing of network traffic in each area is necessary. To achieve accurate auditing, port mirroring functionality on switches deployed in each industrial area is typically used to mirror traffic to dedicated auditing equipment. To ensure high packet processing performance and improve auditing efficiency, current auditing equipment often employs DPDK technology to optimize traffic capture. This involves debinding the physical network interface card (NIC) from the operating system kernel driver and binding it to a user-space driver compatible with the DPDK process, allowing the traffic acquisition process to bypass the kernel and directly capture packets. When using the DPDK process for traffic acquisition, the DPDK process can directly capture mirrored packets with extremely low latency and CPU overhead by polling the taken-over physical NIC, and then forward the received mirrored packets directly to the upper-layer auditing equipment. The auditing equipment utilizes an Industrial Monitor and Audit System (IMA) to perform core auditing operations such as protocol parsing, behavioral analysis, and threat detection on the received data packets. Finally, audit logs are generated based on the audit results (such as alarm logs for detected high-risk messages), which makes it easier for maintenance personnel to trace anomalies based on the audit logs when industrial functional areas are attacked.
[0015] However, existing industrial control traffic transmission methods, based on DPDK technology, have a strong binding relationship between the acquisition process and the physical network interface card (NIC), and this binding relationship needs to be pre-set when the auditing device starts. If it is necessary to change the physical NIC corresponding to traffic acquisition, the running auditing process must be interrupted, the binding relationship between the acquisition process and the physical NIC must be manually reconfigured, and the relevant services or devices must be restarted to complete the update of the acquisition NIC. The operation process is cumbersome and affects the continuity of auditing. At the same time, due to the lack of a convenient operation interface, the interface configuration process relies on professional command line operations, which requires a high level of professional skills from the operation and maintenance personnel and is prone to errors. In addition, when multiple physical NICs share the same device identifier (such as the Peripheral Component Interconnect express (PCIe) identifier), it only supports the simultaneous binding or unbinding of these physical NICs, and cannot achieve independent management of NICs in a single functional area, making it difficult to adapt to the actual application scenarios in industrial scenarios where the traffic acquisition needs of each functional area change dynamically.
[0016] Based on the above research, this application proposes an industrial control traffic auditing method, device, storage medium, and computer equipment. It establishes a virtual switching device as the core forwarding hub, and the IMA system automatically creates dedicated terminal access point interfaces to connect with the virtual switching device, forming a stable audit data channel. Subsequently, physical network interfaces are dynamically accessed or removed from the virtual switching device through the first terminal access point interface, enabling on-demand collection and flexible start / stop of traffic from different industrial functional areas. The entire process does not require restarting the audit service. By configuring fine-grained traffic control rules on the virtual switching device, the security of the audit process and the controllability of data flow are ensured. A graphical management interface is provided, encapsulating the underlying interface addition, deletion, and status monitoring operations, greatly reducing the complexity of operation and maintenance. Thus, by constructing a dynamically configurable, securely isolated, and easily managed traffic collection and scheduling platform, this application achieves a closed-loop process from flexible traffic access and precise policy control to continuous operation of audit services. It effectively solves the problems of complex and inflexible processes for changing traffic collection network ports and the risk of audit interruption caused by the rigid architecture of existing technologies, and significantly improves the maintainability, scalability, and overall security performance of industrial network traffic audit systems.
[0017] The shortcomings of the above solutions are the result of the inventor's practical experience and careful research. Therefore, the discovery process of the above problems and the solutions proposed in this application below should be considered as the inventor's contributions to this application.
[0018] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0019] Open vSwitch (OVS): An open-source, software-based virtual switch widely used in cloud computing and virtualization environments; Linux (Linux Is Not Unix) is a free and open-source Unix-like operating system.
[0020] To facilitate understanding of this embodiment, a detailed description of the industrial control traffic transmission method disclosed in this application embodiment will be provided first. The execution subject of the industrial control traffic transmission method provided in this application embodiment is generally a terminal device or other processing device with certain computing capabilities. The terminal device can be a user equipment (UE), mobile device, user terminal, terminal, personal digital assistant device (PDA), handheld device, auditing device, computer device, etc. In some possible implementations, the industrial control traffic transmission method can be implemented by the processor calling computer-readable instructions stored in the memory.
[0021] The following describes the industrial control traffic transmission method provided in this application embodiment, taking the industrial control traffic auditing device as the execution subject as an example.
[0022] like Figure 1 The flowchart shown is a method for transmitting industrial control traffic according to an embodiment of this application, which may include the following steps: S101: Acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the audit device; the registered interface is the first terminal access point interface accessed by the virtual switching device, which is dynamically updated according to the industrial functional area to be audited.
[0023] Here, the aforementioned industrial control traffic auditing device (hereinafter referred to as the auditing device) is the hardware entity deployed to implement the industrial control traffic transmission method provided in this application, which includes basic hardware and an operating system. The operating system provides the operating environment and core network services for the upper-layer industrial control traffic auditing system. The industrial control traffic auditing system, as an integrated software suite deployed on the operating system, is used to perform specific traffic reception, analysis, and auditing tasks. Specifically, this application can provide a visual management and configuration interface for the industrial control traffic auditing system in the auditing device, allowing maintenance personnel to interact with the auditing device and the industrial control traffic auditing system through the management and configuration interface. The industrial control traffic auditing system can drive its core auditing application to perform specific traffic reception, analysis, and auditing tasks based on interactive commands.
[0024] An industrial functional area refers to an independent unit in an industrial production system that undertakes specific processes or control tasks. For example, a thermal power plant may include multiple independent industrial functional areas such as boiler fuel conveyor belt control, various steam valve control, generator speed regulation, energy storage equipment management, and power transmission dispatch.
[0025] The data frame to be collected is the data frame received by the auditing device. If the data frame originates from the target physical interface, it indicates that the data frame is a mirrored data frame from the industrial control production network and needs to be collected by the IMA for auditing. Conversely, if the data frame does not originate from the target physical interface, it can be determined that the data frame does not need to be collected by the IMA. The data frame specifically includes protocol header information for network addressing (such as source / destination Media Access Control (MAC) address, Virtual Local Area Network (VLAN) tag, Internet Protocol Address (IP address), and source / destination port number) and application layer protocol payload carrying the actual control instructions (such as function codes, register addresses, and operands in Modbus Protocol over Transmission Control Protocol (Modbus TCP), or operation instructions and parameters in S7 Communication Protocol (S7comm protocol)). Based on this information, the IMA system can identify the source of the data frame, determine whether it belongs to an industrial functional area, and if so, the specific industrial functional area it belongs to, and analyze its operational content. Industrial control flow, or simply industrial control flow, includes mirrored data frames from various industrial functional areas.
[0026] A physical network interface (represented as eth) refers to the physical network card interface on an industrial control traffic auditing device used to receive mirrored traffic from a specific industrial functional area. In this application, each physical network interface is uniquely assigned to an industrial functional area. For example, when auditing the "boiler control area" of a thermal power plant, the mirrored traffic from the switch in that area will be connected to the physical network interface eth1 of the auditing device; in this case, eth1 is a physical network interface.
[0027] The data frames to be collected are explicitly associated with each industrial functional area through a mapping relationship between the industrial functional area and the physical network interface. Specifically, each independent industrial functional area is typically planned as an independent network segment or VLAN in the production network, and its network traffic is guided to the corresponding dedicated physical network interface on the auditing device through the mirroring function of the switch. Therefore, for any arriving data frame, the auditing device can uniquely determine which functional area it originated from based on the identity of the physical network interface on which it was received.
[0028] A virtual switching device is a logical device that is simulated by software within the operating system of an auditing device and possesses standard Layer 2 network switching capabilities. As a central switching hub, a virtual switching device can connect multiple physical or virtual network interfaces to the same broadcast domain and forward data frames based on MAC addresses.
[0029] Optionally, in this application, the virtual switching device can be a pre-created virtual bridge or a pre-created multi-layer virtual switch using more powerful software switching technologies such as Open vSwitch (OVS).
[0030] The interface list is a dynamic list maintained by the virtual switch. This list dynamically records all currently active and registered interfaces, clearly defining which physical network interfaces are authorized to send and receive data frames through the virtual switch. This enables selective collection and management of traffic from different industrial functional areas. In other words, each interface in the interface list is a registered interface of the virtual switch. Each registered interface maintained in the interface list corresponds to a physical network interface of the industrial functional area requiring traffic auditing. For example, the interface list might record the currently connected physical network interfaces eth1 (e.g., for the boiler control area), eth2 (e.g., for the generator control area), etc. The physical network interfaces corresponding to each industrial functional area, when maintained in the interface list, can be considered registered to the virtual switch and are therefore called registered interfaces. Each registered interface maintained in the interface list can be called the target physical network interface. However, due to different collection needs, traffic from different industrial functional areas may need to be collected and audited. Therefore, a physical network interface corresponding to a certain industrial functional area may be maintained as a registered interface in the interface list at certain times and removed from the interface list at other times, thus no longer being considered a registered interface. Therefore, the registered interface can be the first terminal access point interface accessed through the virtual switching device, and the interface list is dynamically updated according to the physical network interface corresponding to the industrial functional area to be audited.
[0031] The first terminal access point interface is a virtual network interface created by the IMA system to enable centralized and dynamic management of the physical network interfaces connected to the virtual switching device. The specific management process will be described in detail later.
[0032] In practice, a virtual switch is pre-created within the auditing equipment, maintaining a dynamic list of interfaces. The registered interfaces (e.g., eth1, eth2) in this list are dynamically updated based on the industrial functional area to be audited, via management commands sent from the auditing equipment's IMA system through the first terminal access point interface. When a data frame arrives, the auditing equipment's operating system kernel captures the frame and determines the interface identifier of its source interface. This source interface can be, for example, a physical network interface or another virtual network interface. The system checks if the source interface's identifier is in the virtual switch's currently maintained interface list. If it is, the source interface is identified as the target physical network interface, and subsequent steps S102 and S103 are executed. If not, the acquired data frame is determined to be traffic that does not require auditing and does not need to be forwarded to the IMA system for auditing.
[0033] In one implementation, the pre-creation process for the virtual switching device in S101 can be carried out according to the following steps: Step 1: Create an initial virtual switch device in the operating system kernel of the audit device, and configure security parameters for the initial virtual switch device to obtain an intermediate virtual switch device.
[0034] Here, security parameters refer to the set of core parameter configurations for virtual switching devices designed to ensure network isolation and data flow, including but not limited to Virtual Local Area Network (VLAN) filtering function parameters and port isolation mode parameters.
[0035] Intermediate virtual switching devices refer to virtual switching devices that have been basically created in the operating system kernel of the auditing device and have been configured with security parameters (such as VLAN filtering and port isolation).
[0036] In practice, within the operating system (such as Linux) of the auditing device, an initial virtual switch (e.g., an initial virtual bridge named br_ima) is created in the operating system kernel by executing command code (e.g., the command `ip linkadd name br_ima type bridge`). Then, a series of configuration commands are used to set core security parameters for the initial virtual bridge, resulting in an intermediate virtual bridge. These core security parameters include enabling VLAN filtering to allow the bridge to identify and process traffic with different VLAN tags, achieving logical isolation; and enabling port isolation mode to lay the foundation for rules that prevent direct communication between different access ports of the virtual switch.
[0037] Step 2: After activating the intermediate virtual switch, configure the performance parameters of the intermediate virtual switch through the operating system to obtain the created virtual switch.
[0038] In industrial control network environments, it is typically necessary to continuously and efficiently transmit mirrored traffic to auditing devices with low latency. However, the default configuration of intermediate virtual switches may contain unnecessary protocol calculations or processing overhead. Therefore, to significantly improve traffic transmission efficiency, reduce transmission latency, and avoid network fluctuations caused by address aging and protocol interactions, performance parameters can be further configured for intermediate virtual switches to better meet auditing requirements and achieve system-level configuration optimization.
[0039] Performance parameters are a set of performance optimization configurations set for intermediate virtual switching devices to build an efficient, low-latency, and stable data forwarding plane for the virtual switching devices, ensuring that they can reliably send high-speed mirrored traffic from the production network to audit devices.
[0040] Specifically, performance parameters include, but are not limited to: disabling the Spanning Tree Protocol (STP), disabling network filtering framework (NetworkFilter, or netfilter) calls, and setting the MAC address aging time to never expire. Disabling STP avoids negotiation latency introduced by loop detection mechanisms in a defined mirrored network topology. Disabling netfilter prevents packets forwarded by the virtual switch from passing through the operating system's firewall rule chain, significantly reducing processing overhead and improving throughput. Setting the MAC address aging time to never expire maintains the long-term stability of the virtual switch's address forwarding table, avoiding temporary network fluctuations caused by address entry timeout deletion and relearning.
[0041] In practice, the intermediate virtual switch can be activated first, changing its state from DOWN to UP, so that it can begin processing network traffic normally. Then, using the operating system's system configuration tools, key performance parameters are set for the intermediate virtual switch, such as disabling its spanning tree protocol; disabling the virtual switch's calls to the netfilter framework in the operating system kernel; and configuring the bridge's MAC address aging time to never expire. After configuring these performance parameters, a virtual switch with both secure isolation and efficient forwarding capabilities is created.
[0042] In one implementation, after obtaining the created virtual switching device, it can be integrated with the audit device's IMA by following these steps: A1: Create at least two terminal access point interfaces through the industrial control traffic auditing system; the at least two terminal access point interfaces include a first terminal access point interface and a second terminal access point interface.
[0043] Here, both the first terminal access point interface (defined as ima_tap0) and the second terminal access point interface (defined as ima_tap1) are virtual network interfaces created by the IMA system. ima_tap0, as a management interface, can be specifically used for centralized configuration and status management of the various physical network interfaces connected to the virtual switching device. For example, when auditing the "warehousing and logistics area" industrial functional area needs to begin, IMA sends a command to the virtual switching device through this ima_tap0 interface to dynamically add the physical network interface of the "warehousing and logistics area" area to its managed interface list. When auditing the "warehousing and logistics area" area needs to be cancelled, IMA sends a command to the virtual switching device through this ima_tap0 interface to remove the physical network interface identifier of the "warehousing and logistics area" area from the interface list.
[0044] The second terminal access point interface (ima_tap1) serves as a data transceiver interface, specifically designed to receive and forward mirrored traffic from the target physical network interface and send it to the IMA system's analysis engine for processing.
[0045] In practice, during startup, the IMA system automatically creates at least two virtual terminal access point interfaces by calling the virtual network device creation interface provided by its operating system kernel (such as the Terminal Access Point (TAP) driver in Linux). These two created terminal access point interfaces can include at least one ima_tap0 and at least one ima_tap1. Internally, these two terminal access point interfaces are initialized as independent logical network endpoints and enter a ready state, awaiting subsequent configuration and connection.
[0046] A2: Connect at least two terminal access point interfaces to the created virtual switching device.
[0047] In practice, the IMA system invokes network configuration commands from the operating system to sequentially configure at least two existing Terminal Access Point interfaces (i.e., at least one ima_tap0 and at least one ima_tap1) as member ports of the newly created virtual switching device (such as the virtual bridge br_ima). At this point, these two virtual Terminal Access Point interfaces are logically "inserted" into the virtual switching device, becoming ports capable of traffic forwarding and laying the physical connection foundation for subsequently carrying management signaling and production traffic data. Thus, the IMA system automatically starts and completes the creation and access of the TAP device without manual intervention, achieving seamless integration between the virtual switching device and the IMA system.
[0048] In one implementation, the interface list maintained by the virtual switching device in S101 above can be dynamically updated according to the following steps B1 and B2: B1: In response to an audit edit request for an industrial functional area, determine whether the physical network interface to be edited for the corresponding industrial functional area exists.
[0049] Here, the audit edit request is used to change the network traffic audit status of a specific industrial functional area, thereby dynamically adjusting the industrial functional areas and monitoring policies monitored by the IMA system. Since auditing an industrial functional area is essentially auditing mirrored traffic from the physical network interface corresponding to that area, the audit edit request can include editing operations on the physical network interface corresponding to the specific industrial functional area. In this application, the editing operation can specifically include add and delete operations.
[0050] For example, in a monitoring network of an urban rail transit system, when maintenance personnel need to start network security monitoring of a newly added "platform screen door control area", an "add" type audit editing request can be triggered; conversely, if an "existing ticketing system area" has expired, a "delete" type audit editing request can be triggered to release audit resources.
[0051] A physical network interface to be edited refers to a physical network interface that the audit editing request indicates needs to be added or removed.
[0052] In practice, when editing is required, the user can initiate an audit editing request through the management interface of the industrial control flow audit system. This request specifies the industrial functional area / physical network interface whose audit status needs to be changed and the specific editing intent. The audit device then receives the user's audit editing request and, based on the preset mapping relationship between industrial functional areas and physical network interfaces, resolves the physical network interface identifier corresponding to that industrial functional area. Subsequently, it determines whether the physical network interface corresponding to this identifier actually exists in the IMA system. If it does not exist, it prompts that the interface does not exist, completing the response to the editing operation. If it exists, it further executes step B2 below.
[0053] B2: If so, then follow the editing instructions in the audit editing request and edit the physical network interface to be edited in the currently maintained interface list through the first terminal access point interface.
[0054] In practice, once it is confirmed that the physical network interface to be edited exists in the IMA system, the audit edit request can be parsed to determine the type of edit operation for the physical network interface to be edited. Based on this operation type, a corresponding configuration instruction is generated and sent to the created virtual switching device through the management interface ima_tap0. The kernel module of the virtual switching device, based on the received configuration instruction, directly performs the corresponding edit operation on its currently maintained interface list, thereby achieving dynamic adjustment of the monitoring status of the physical network interface to be edited.
[0055] If it is confirmed that the physical network interface to be edited does not exist in the IMA system, the current editing process can be terminated, and a message indicating that the interface does not exist can be returned to the user through the management interface. For example, an alarm notification stating "Physical network interface does not exist" can be generated and displayed to all users.
[0056] It should be noted that the industrial control flow auditing method provided in this application can support simultaneous configuration changes for multiple industrial functional areas requiring auditing. Specifically, it can respond to a composite audit editing request containing multiple editing intentions, or it can process multiple independent audit editing requests in parallel. For each industrial functional area involved, steps B1 and B2 are executed independently, thereby achieving dynamic adjustment of the interface list.
[0057] In one implementation, when the audit edit request is an audit add request, the edit operation is the same as the add operation, and the physical network interface to be edited is the physical network interface to be added. In this case, step B2 can be implemented according to steps C1-C3 as follows: C1: Determine whether the physical network interface to be added is in the currently maintained interface list.
[0058] In practice, for the physical network interface to be added, the list of interfaces currently maintained by the virtual interactive device can be obtained first. For example, the list of currently maintained interfaces can be obtained through the operating system's network management interface (such as through the iplinkshow command or its equivalent programming interface). Then, it can be determined whether the physical network interface to be added is in the currently maintained interface list by checking whether the interface identifier of the physical network interface to be added is stored in the interface list.
[0059] Alternatively, you can obtain the "master device" attribute of the physical network interface to be added (e.g., eth6). If this attribute points to a virtual switch (e.g., its master field is br_ima), then the interface is already a member of the virtual switch's interface list. Conversely, if the master field is empty or points to another device, then it is not in the interface list. Based on this, by determining whether the physical network interface to be added is already in the currently maintained interface list, problems such as configuration conflicts, resource waste, or potential network logic errors caused by repeatedly adding the same physical network interface can be avoided.
[0060] C2: If not, configure the working mode of the physical network interface to be added to obtain the configured physical network interface to be added.
[0061] Here, working mode configuration refers to the process of initializing the physical network interface to be added as a clean Layer 2 data channel, thereby stripping the interface of any Layer 3 network configuration that may affect transparent traffic forwarding, such as IP address, routing table entries, etc., thus ensuring that the interface is only used as a passive Layer 2 mirror traffic receiving port.
[0062] In practice, if the physical network interface to be added is not in the currently maintained interface list, the working mode configuration of the physical network interface to be added can be performed to obtain the configured physical network interface. For example, using the operating system's network configuration commands, all existing network layer configurations on the physical network interface can be removed (e.g., deleting any assigned IP addresses); then, the link state of the interface is turned off and then reactivated to ensure that it is completely reset from any previous network session and has network transmission and reception capabilities. Finally, the working flag of the interface is set, and all routing-related functions are disabled, thereby initializing it as a network port working in pure Layer 2 mode and not participating in Layer 3 routing.
[0063] Alternatively, if the physical network interface to be added is confirmed to be in the currently maintained interface list, the current addition process can be terminated, and a message such as "The physical network interface to be added already exists in the interface list" can be returned to the user through its management interface, without performing any configuration operations on that interface. This prevents configuration conflicts caused by duplicate additions. In this way, by determining whether the physical network interface to be added is in the IMA system and whether it is in the interface list, invalid operations on non-existent interfaces and duplicate configurations of existing or added interfaces can be avoided. For example, in the industrial control network of a large logistics center, if a user requests to monitor the "cold chain warehouse monitoring area," the system resolves the corresponding physical network interface identifier as eth3. After querying, if eth3 is not recognized by the IMA operating system driver, it will prompt that eth3 does not exist; if eth3 exists and is already in the interface list, it will prompt that eth3 is in the list; if eth3 exists but is not in the interface list, the initial verification is completed and the working mode configuration is performed.
[0064] C3: Add the configured physical network interfaces to the interface list of the virtual switch device through the first terminal access point interface.
[0065] In practice, an add member command can be sent to the virtual switch via ima_tap0. This command contains the identifier of the physical network interface to be added (e.g., eth3), which has already been configured in its working mode. Upon receiving this command, the virtual switch's kernel driver performs internal operations, officially registering the physical network interface identified as eth3 as a new member port and adding it to its maintained interface list. After this operation, the physical network interface is logically connected to the virtual switch, successfully incorporated into the IMA's traffic acquisition system, and becomes an effective port for the virtual switch to forward Layer 2 traffic.
[0066] Understandably, each physical network interface to be added that has successfully connected to the virtual switching device and completed registration constitutes a new target physical network interface that can be used to receive traffic from a specific industrial functional area.
[0067] In one implementation, after performing step C3 above, in order to ensure that the traffic of the industrial functional area corresponding to the newly accessed physical network interface can be audited securely and controllably, and to strictly prevent it from causing any interference or security risks to the existing network, traffic control rules can be set for the newly accessed physical network interface according to the following steps: Configure preset traffic control rules for the physical network interface to be added; the preset traffic control rules include at least a first traffic control rule, a second traffic control rule, and a third traffic control rule; wherein, the first traffic control rule allows data frames to flow from the physical network interface to be added to the second terminal access point interface; the second traffic control rule does not allow data frames to flow from the second terminal access point interface to the physical network interface to be added; and the third traffic control rule does not allow data frames to flow directly between the physical network interface to be added and other physical network interfaces in the interface list.
[0068] Here, preset traffic control rules refer to a set of security policies predefined and configured within the virtual switching device, used to enforce path control and access restrictions on data frames flowing through the auditing device, in order to build a secure and isolated traffic auditing environment.
[0069] The first flow control rule is a security policy, defined as: allowing data frames to flow unidirectionally from the specified physical network interface to ima_tap1, which is used to establish a controlled and irreversible data transmission path within the virtual switching device, thereby ensuring that traffic from the external production network mirror can be safely and reliably sent to the IMA system for analysis.
[0070] For example, in the "tablet press control area" network of a pharmaceutical production line, when the physical network interface of this area is added, applying the first flow control rule means that all device communication data mirrored from this area is allowed to flow to the ima_tap1 interface for analysis by the IMA system.
[0071] The second flow control rule is a reverse isolation strategy, defined as: prohibiting data frames from flowing from ima_tap1 to any connected physical network interface. This rule is used to build an absolutely unidirectional data flow barrier within the virtual switching device, completely preventing any responses, instructions, or unexpected data packets generated by the IMA system during data processing from flowing back into the industrial production network, thereby ensuring that auditing operations are purely, non-intrusive, and bypass eavesdropping.
[0072] For example, in a monitoring scenario of a "distribution automation zone" in a city's smart grid, applying this second flow control rule means that the IMA system can analyze the flow from this zone, but all data generated by the IMA system itself (including analysis results, logs, and even erroneous operation instructions) is strictly blocked by this rule and cannot be sent back to any device in the distribution automation zone network through the original path.
[0073] The first and second flow control rules work together to construct an absolute one-way communication channel between the IMA and the production network, allowing only "input" and no output.
[0074] The third flow control rule is a lateral isolation strategy, defined as: prohibiting data frames from directly flowing between any two physical network interfaces connected to the virtual switching device. This rule forces all mirrored traffic from different industrial functional areas to be forwarded and processed through ima_tap1, thereby completely eliminating the possibility of monitoring traffic "short-circuiting" between different production areas and ensuring that all mirrored traffic from the target physical interface is captured and analyzed by the IMA system without omission.
[0075] For example, in a monitoring network at a petrochemical plant, a third-party flow control rule would prevent the direct exchange of any data packets between the physical network interfaces of the "catalytic cracking zone" and the "tank metering zone." This means that even if the traffic from both zones is mirrored to the same auditing device, any direct communication between them will be blocked by the auditing device, effectively preventing the lateral spread of threats between different critical production areas through monitoring links.
[0076] In practice, for each new physical network interface to be added to the interface list of the virtual switch, the rule management module submits a set of rules for that new interface to the kernel rule table of the virtual switch. Taking the interface identifier of the physical network interface to be added to the interface list of the virtual switch as eth3, the first flow control rule configured for this interface is: when the input port of a data frame comes from eth3, perform the action of allowing (which can be represented as ACCEPT) forwarding to the ima_tap1 interface, thereby establishing a one-way data path from the production area to the IMA. The second flow control rule configured is: when the input port of a data frame is ima_tap1 and the output port is eth3, perform the action of dropping (which can be represented as DROP), thereby constructing a reverse communication barrier. The third flow control rule configured is: for every data frame transmission request between [eth3, other physical network interfaces], perform the DROP action, thereby blocking all direct connection paths between physical interfaces.
[0077] In another implementation, when the audit edit request is an audit delete request, the edit operation is the same as the delete operation, and the physical network interface to be edited is the physical network interface to be deleted. In this case, step B2 can be implemented according to steps D1-D2 as follows: D1: Determine whether the physical network interface to be deleted is in the currently maintained interface list.
[0078] Here, the physical network interface to be deleted refers to the physical network interface that needs to be removed from the currently maintained interface list, as indicated by the audit deletion request.
[0079] For example, the process of determining whether a physical network interface to be deleted is in the currently maintained interface list is similar to the process of determining whether a physical network interface to be added is in the currently maintained interface list, and will not be repeated here.
[0080] D2: If so, then through the first terminal access point interface, delete the physical network interface to be deleted from the currently maintained interface list and clear the preset traffic control rules related to the physical network interface to be deleted.
[0081] In practice, if the physical network interface to be deleted is determined to be in the currently maintained interface list, a remove interface member command can be sent to the virtual switch via ima_tap0. This command includes the identifier of the physical network interface to be deleted (e.g., eth5). Upon receiving the command, the kernel driver of the virtual switch will officially deregister and remove the physical network interface identified as eth5 from its currently maintained interface list. Simultaneously, ima_tap0 can instruct the virtual switch to clear all preset traffic control rules related to the physical interface to be deleted. This means deleting all allow and block rules previously configured for this interface that relate to communication with ima_tap1 and other physical interfaces. Optionally, depending on actual auditing needs, the network function of the physical interface to be deleted can be disabled, such as temporarily shutting down the interface, changing its configuration, or repurposing it. If the physical network interface to be deleted is not determined to be in the current interface list, the current deletion process is terminated, and a message such as "The physical network interface to be deleted is not in the interface list" is returned to the user through the management interface. For example, in a pharmaceutical factory's "automated packaging area" monitoring network, when there's a need to stop monitoring that area, an audit deletion request can be generated to remove the physical network interface (e.g., eth5) corresponding to that area. Upon receiving this request, if it's confirmed that the eth5 interface is a current member of the virtual bridge br_ima, an instruction is issued via ima_tap0 to remove eth5 from the virtual bridge and clear all its traffic rules; the area is then removed from the audit scope. If a query reveals that eth5 is not a current member of the virtual bridge br_ima, status information is directly returned to avoid invalid operations.
[0082] S102: If so, then based on the address information carried in the data frame, determine the target control rule that the data frame hits from the preset flow control rules.
[0083] Here, the address information carried by the data frame can be a key network identifier included in the data frame header, used to identify its source and destination. For example, the address information can be the source / destination MAC address and the interface identifier of the physical network interface from which the data frame originates. The source MAC address identifies the hardware identity of the industrial control equipment (e.g., a specific Programmable Logic Controller (PLC)) sending the data frame; the destination MAC address identifies the industrial control equipment receiving the data frame. The interface identifier directly indicates which specific industrial functional area the data frame originates from. By comparing the address information with preset flow control rules, it can be determined which control rule the data frame should match. For example, in a "distributed photovoltaic inverter area" of a smart grid, a data frame originating from a specific inverter (MAC address 00:1B:63:AA:BB:CC) and entering through interface eth8, carries address information (source / destination MAC and interface identifier eth8), which can serve as key credentials for determining whether it is allowed to flow to the auditing application or should be blocked.
[0084] The target control rule is a control rule that matches a data frame within a pre-defined set of flow control rules.
[0085] In practice, the kernel rule matching engine of the virtual switch in the auditing device extracts key address information carried in the data frame from the target physical network interface, specifically including its source / destination MAC address and the interface identifier (e.g., eth2) of the target physical network interface corresponding to the data frame. Subsequently, the matching engine of the virtual switch uses this address information as a matching key and compares it sequentially with the preset flow control rule set in the device. Since the data frame originates from mirrored traffic of the target physical network interface, its flow direction is logically from the external network to the virtual switch, therefore it will never hit any of the second flow control rules in the preset rules (i.e., the rules that prohibit flow from ima_tap1 to the physical interface). The matching result will point to two possible paths: if its address information matches the flow characteristics defined by the first flow control rule (e.g., allowing flow from physical interface eth2 to ima_tap1), then this rule is determined as the target control rule; if its address information indicates that the industrial control device under the destination address corresponds to a certain physical network interface, then it may hit the third flow control rule (i.e., prohibiting direct flow between physical interfaces), in which case this third flow control rule is determined as the target control rule.
[0086] S103: When the target control rule indicates that auditing data frames is allowed, the data frame is forwarded to the virtual switching device, and the data frame is sent to the industrial control traffic auditing system through the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is used to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
[0087] Here, when the target control rule indicates that auditing data frames is allowed, it means that the data frame hits the first flow control rule. In this case, the data frame is forwarded to the virtual switch and then sent to the IMA system via the ima_tap1 connected to the virtual switch. The IMA system then performs flow auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame. If the target control rule indicates that blocking is allowed, it means that the data frame hits the third flow control rule. In this case, the data frame is not forwarded to the virtual switch or subsequent IMA systems; instead, it can be ignored, thus achieving blocking of the data frame.
[0088] In practice, if the auditing device determines that the target control rule matched by the data frame is the first flow control rule, it can send the data frame to the virtual switching device. Then, using the kernel forwarding engine of the virtual switching device, the data frame is submitted to the common switching forwarding plane of the virtual switching device. Following the forwarding path defined by the target control rule, the switching engine determines the output port of the data frame as ima_tap1 and sends it out from ima_tap1. Since the other end of ima_tap1 is directly connected to the data receiving module of the IMA system, the data frame can be delivered to the IMA system instantly and completely through ima_tap1, entering the IMA system's processing queue to await deep parsing.
[0089] Then, the kernel forwarding engine of the virtual switch performs operations according to the instructions of the target control rules: First, the virtual switch submits the data frame from the internal buffer of the target physical network interface that received it to its public switching and forwarding plane; then, according to the forwarding path defined by the target control rules, the switching engine determines the output port of the data frame as ima_tap1 and sends it out from ima_tap1. Since the other end of ima_tap1 is directly connected to the IMA's data receiving module, the data frame is delivered to the IMA in real time and completely through this software channel, entering its processing queue to await deep parsing.
[0090] For example, in the "rolling temperature control zone" of a metallurgical plant, a data frame from a temperature sensor, entering through the eth2 interface and hitting the first flow control rule, will be sent from the ima_tap1 interface to the data acquisition end of the IMA system via the internal switching of the virtual bridge br_ima. After receiving this frame, the IMA system can analyze and perform security analysis on the industrial control flow of the "rolling temperature control zone" based on its payload content.
[0091] like Figure 2 The above is a schematic diagram of the specific transmission process of an industrial control traffic transmission method provided in this application embodiment. The IMA system collects and audits industrial control network traffic through a virtual switching device. The virtual switching device is configured with a first terminal access point interface ima_tap0 and a second terminal access point interface ima_tap1, where ima_tap0 is a control interface and ima_tap1 is a data interface. Both serve as the communication channel between the virtual switching device and the IMA. Simultaneously, the virtual switching device is connected to multiple target physical network interfaces from eth1, eth2 to ethn. These physical network interfaces are used to access traffic from various functional areas in the industrial control network (such as mirrored traffic output from area switches). The virtual switching device is equipped with preset traffic control rules, including a first traffic control rule, a second traffic control rule, and a third traffic control rule, to manage traffic forwarding logic. After the traffic from the industrial control network flows in through the corresponding physical network interfaces, the virtual switching device processes the acquired traffic according to the preset traffic control rules and transmits the processed traffic to the IMA system through ima_tap1 for traffic auditing. ima_tap0 assists in the management of the various physical network interfaces accessed by the virtual switching device.
[0092] In one implementation, to ensure the long-term stable and efficient operation of the virtual switching device after it is connected to the industrial control traffic auditing system, and to effectively manage and continuously optimize the status of the virtual switching device and its interfaces, the status monitoring and maintenance of the virtual switching device can be achieved according to the following steps S1 and S2: S1: Obtain the device status information of the virtual switching device and the interface status information of each registered interface of the virtual switching device according to a preset time interval.
[0093] Here, the preset time interval is a pre-configured periodic time parameter used to provide a stable and controllable time window for periodic status collection, performance evaluation, and maintenance operations. Specifically, the preset time interval can be determined according to the IMA system's operation and maintenance requirements and auditing requirements; for example, the interval can be 30 minutes.
[0094] Device status information reflects the current operation and configuration of the virtual switch, providing the foundation for auditing and managing it. This information may include, but is not limited to: the virtual switch's current operating status (e.g., UP or DOWN), a list of connected member interfaces (i.e., each registered interface and each virtual interface), and effective core configuration parameters (e.g., whether VLAN filtering and port isolation are enabled). Obtaining this information allows direct confirmation of whether the virtual switch is functioning correctly, and whether its managed network topology and critical security functions are configured as expected.
[0095] Interface status information can include real-time operational data and configuration details related to each physical network interface and virtual terminal access point interface (ima_tap0 and ima_tap1) connected to the virtual switching device.
[0096] Interface status information includes the current link status of each interface (e.g., connectivity), detailed traffic statistics (e.g., the number of packets received / sent, the number of bytes, and various error and drop counts), and port-level configuration parameters (e.g., speed, duplex mode). By periodically collecting this interface status information, problems such as continuous packet loss on a physical network interface, abnormal surges in ima_tap traffic, or configurations not taking effect as expected can be detected in a timely manner.
[0097] In practice, a status collection task can be automatically triggered according to a preset time period (e.g., every 30 minutes) to collect the basic operating status of the virtual switching device (e.g., the virtual bridge br_ima), the currently maintained interface list, the detailed configuration of each port (e.g., port number, priority, isolation status), and the current status and match counters of all preset traffic control rules. Subsequently, iterates through each physical network interface and virtual terminal access point interface connected to the virtual switching device, collecting their interface status information one by one, such as detailed traffic data for each interface in the previous time interval. This data includes the number of data packets received and sent, the total number of bytes, and various error and drop counts (e.g., packet error rate, packet drop rate), thus completing a complete snapshot of the operating status and performance data. The match counter value represents the number of times a preset traffic control rule is matched; one preset traffic control rule corresponds to one match counter.
[0098] S2: Based on device status information and interface status information, optimize the performance of the first terminal access point interface and the second terminal access point interface, and generate a visual status view and operation analysis report.
[0099] In practical implementation, the collected device and interface status information can be comprehensively analyzed and processed. Based on the analysis results, optimization can be performed, and a visual status view and operational analysis report of the audited device / IMA system / virtual switch device can be generated. For example, for ima_tap0 and ima_tap1, their processing capacity and stability can be automatically assessed based on the traffic load and error count in the interface status information. For example, if the packet drop rate of ima_tap1 continues to increase, the size of its associated kernel buffer or scheduling priority can be dynamically adjusted to alleviate congestion and optimize data reception performance. At the same time, based on the member list and rule match count in the device status information and various traffic statistics in the interface status information, a visual status view and operational analysis report are automatically generated. The visual status view intuitively displays the real-time traffic trends of each physical network interface, the rule hit rate of the virtual switch device, and the interface health status in chart form. The operational analysis report summarizes key events such as interface anomalies and rule changes, performance indicators, and configuration compliance check results within the period. Expired configurations and rules can be cleaned up periodically. Through continuous monitoring, analysis, and optimization, the long-term stable operation of the system is ensured, meeting the established performance and security requirements.
[0100] For example, in a centralized monitoring network of an underground utility tunnel (covering gas and water supply pipeline monitoring), analysis revealed that the flow rate of the ima_tap1 interface was approaching its limit, prompting automatic parameter optimization. Simultaneously, a report was generated, using a line graph to show the periodic fluctuations in flow rate of the eth3 interface in the "Gas Pipeline Pressure Monitoring Area," and a table to summarize the error counts for each area's interfaces. The report also indicated that the eth5 interface in the "Water Supply Pump Room Control Area" had an intermittent Cyclic Redundancy Check (CRC) error, recommending a check of the physical link. Based on this, a complete operation and maintenance loop was completed, from status monitoring and intelligent analysis to optimization suggestions and visualization.
[0101] like Figure 3 The above is a schematic diagram illustrating the specific process of constructing a virtual switching device and dynamically managing its interfaces, as provided in an embodiment of this application. Figure 3Taking a virtual bridge named br_ima as an example, the construction and interface management process is explained as follows: To begin building the virtual switch, first create a virtual bridge named br_ima, configure security parameters (such as enabling VLAN filtering, enabling port isolation mode, and setting the status to DOWN), and then activate br_ima. Configure performance parameters for br_ima (disable spanning tree protocol, disable netfilter calls, and set the MAC address aging time to never expire), and then wait for the IMA system to start. After the IMA system starts, it will automatically create TAP devices (including ima_tap0 and ima_tap1). Connect ima_tap0 and ima_tap1 to br_ima to complete the creation of br_ima. Next, proceed to the br_ima and its interface management phase, which includes three types of operations: interface addition, which requires first checking if the network interface to be added exists; if it does not exist, indicate that the interface does not exist; if it exists, check if it is in the interface list currently maintained by br_ima. If the interface exists in the list, it will indicate that it is already in br_ima; otherwise, the addition operation will begin. This involves adding the interface to br_ima after configuring the working mode, and then configuring the preset traffic control rules (specifically including configuring the first, second, and third traffic control rules sequentially). After confirming the interface conditions are met, the addition process will terminate. For interface deletion, it is necessary to first determine if the physical network interface to be deleted is in the interface list currently maintained by br_ima. If it does not exist, it will indicate that it is not in br_ima; if it exists, the deletion operation will begin. This involves deleting the interface from the br_ima interface list, clearing the relevant preset traffic control rules, and cleaning up sub-process rules (including traversing each rule in the FORWARD chain, determining if the current rule is related to the physical network interface to be deleted; if so, deleting the current rule; otherwise, continuing to traverse the next rule and returning to the step of "determining if the current rule is related to the physical network interface to be deleted," until traversal is complete). After traversal is complete, it can be concluded that the rule cleanup is complete, the interface deletion is successful, and the deletion process can be terminated. The status information query operation first queries the br_ima status information, then displays the br_ima running status, br_ima configuration information, and br_ima preset traffic control rules. Next, it begins querying the interface status, traversing all br_ima connected interfaces (including registered interfaces, ima_tap0, and ima_tap1, etc.). For the currently traversed interface, it obtains its interface name and displays its received statistics (including data frame received statistics and data frame sent statistics). It then determines if there are any untraversed interfaces; if so, it continues to the next interface and returns to the step of obtaining the interface name; otherwise, based on the statistics of each interface and the br_ima status information query, it outputs a status view and analysis report. The entire process ends upon completion of the query.In this way, by providing a visual configuration page, this application can reduce operation and maintenance costs and difficulties; by using a virtual interactive device for physical network interface management, it avoids the problem of strong binding between the DPDK physical network card and the IMA in existing technologies. When there is a need to manage multiple physical network interfaces, independent management of each physical network interface can be achieved based on the virtual interactive device, without restarting the corresponding audit application of the IMA system when changing physical network interfaces, thus achieving 24 / 7 audit operation.
[0102] Based on the same inventive concept, this application also provides an industrial control flow transmission device corresponding to the industrial control flow transmission method. Since the principle of the device in this application is similar to the above-mentioned industrial control flow transmission method in this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0103] like Figure 4 The diagram shown is a schematic of an industrial control flow transmission device provided in an embodiment of this application, comprising: The first determining module 401 is used to acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the auditing device; the registered interface is dynamically updated according to the industrial functional area to be audited by using the first terminal access point interface accessed by the virtual switching device. The second determining module 402 is used to determine the target control rule hit by the data frame from the preset flow control rules based on the address information carried by the data frame if the data frame is hit. The sending module 403 is used to forward the data frame to the virtual switching device when the target control rule indicates that auditing the data frame is allowed, and to send the data frame to the industrial control traffic auditing system using the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is used to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
[0104] In one possible implementation, the apparatus further includes a creation module 404 for pre-creating the virtual switching device according to the following steps: An initial virtual switching device is created in the operating system kernel of the auditing device, and security parameters are configured for the initial virtual switching device to obtain an intermediate virtual switching device; After activating the intermediate virtual switch, the operating system configures the performance parameters for the intermediate virtual switch to obtain the created virtual switch.
[0105] In one possible implementation, after the virtual switching device is created, the creation module 404 is further configured to: The industrial control traffic auditing system creates at least two terminal access point interfaces; the at least two terminal access point interfaces include the first terminal access point interface and the second terminal access point interface; Connect the at least two terminal access point interfaces to the created virtual switching device.
[0106] In one possible implementation, the device further includes an update module 405 for dynamically updating the interface list according to the following steps: In response to an audit edit request for the industrial functional area, determine whether the physical network interface to be edited for the industrial functional area exists. If so, then according to the editing operation indicated by the audit editing request, the physical network interface to be edited is edited in the currently maintained interface list through the first terminal access point interface.
[0107] In one possible implementation, if the audit edit request is an audit add request, the edit operation includes an add operation; the physical network interface to be edited is a physical network interface to be added. The update module 405, when editing the physical network interface to be edited in the currently maintained interface list through the first terminal access point interface according to the editing operation indicated by the audit editing request, is used to: Determine whether the physical network interface to be added is in the currently maintained interface list; If not, then configure the working mode of the physical network interface to be added to obtain the configured physical network interface to be added; The configured physical network interfaces to be added are added to the interface list of the virtual switching device through the first terminal access point interface.
[0108] In one possible implementation, after the update module 405 adds the configured physical network interface to be added to the interface list of the virtual switch device via the first terminal access point interface, it is further configured to: Configure preset traffic control rules for the physical network interface to be added; the preset traffic control rules include at least a first traffic control rule, a second traffic control rule, and a third traffic control rule. The first flow control rule allows data frames to flow from the physical network interface to be added to the second terminal access point interface. The second flow control rule is to disallow data frames from the second terminal access point interface to the physical network interface to be added; The third flow control rule prohibits the direct flow of data frames between the physical network interface to be added and other physical network interfaces in the interface list.
[0109] In one possible implementation, if the audit edit request is an audit delete request, the edit operation includes a delete operation; the physical network interface to be edited is the physical network interface to be deleted. The update module 405, when editing the physical network interface to be edited in the currently maintained interface list through the first terminal access point interface according to the editing operation indicated by the audit editing request, is used to: Determine whether the physical network interface to be deleted is in the currently maintained interface list; If so, the physical network interface to be deleted is removed from the currently maintained interface list through the first terminal access point interface, and the preset traffic control rules associated with the physical network interface to be deleted are cleared.
[0110] In one possible implementation, the apparatus further includes a generation module 406, for: According to a preset time interval, acquire the device status information of the virtual switching device and the interface status information of each registered interface of the virtual switching device; Based on the device status information and the interface status information, the performance of the first terminal access point interface and the second terminal access point interface is optimized, and a visual status view and operation analysis report are generated.
[0111] The processing flow of each module in the device and the interaction flow between each module can be referred to the relevant descriptions in the above method embodiments, and will not be detailed here.
[0112] Based on the same technical concept, embodiments of this application also provide a computer device. (Refer to...) Figure 5 The diagram shown is a structural schematic of a computer device provided in an embodiment of this application, comprising: The processor 501, memory 502, and bus 503 are included. Memory 502 stores machine-readable instructions that can be executed by the processor 501. The processor 501 executes the machine-readable instructions stored in memory 502. When the machine-readable instructions are executed by the processor 501, the processor 501 performs the steps S101 to S103 described above.
[0113] The aforementioned memory 502 includes a main memory 5021 and an external memory 5022. The main memory 5021, also known as internal memory, is used to temporarily store the computational data in the processor 501, as well as the data exchanged with external memory such as a hard disk 5022. The processor 501 exchanges data with the external memory 5022 through the main memory 5021. When the computer device is running, the processor 501 and the memory 502 communicate through the bus 503, so that the processor 501 executes the execution instructions mentioned in the above method embodiments.
[0114] This application also provides a computer-readable storage medium storing a computer program. When a processor runs the computer program, it executes the steps of the industrial control flow transmission method described in the above-described method embodiments. The storage medium can be a volatile or non-volatile computer-readable storage medium.
[0115] This application also provides a computer program product, which carries program code. The instructions included in the program code can be used to execute the steps of the industrial control flow transmission method described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.
[0116] The computer program product can be implemented specifically through hardware, software, or a combination thereof. In one alternative embodiment, the computer program product is specifically embodied in a computer storage medium; in another alternative embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0117] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed device and method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interface; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.
[0118] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0119] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0120] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0121] If the technical solution of this application involves personal information, the product using this technical solution has clearly informed the user of the personal information processing rules and obtained the user's voluntary consent before processing the personal information. If the technical solution of this application involves sensitive personal information, the product using this technical solution has obtained the user's separate consent before processing the sensitive personal information, and also meets the requirement of "express consent". For example, at personal information collection devices such as cameras, clear and prominent signs are set up to inform users that they have entered the scope of personal information collection and that personal information will be collected. If an individual voluntarily enters the collection scope, it is deemed that they have agreed to the collection of their personal information; or on the personal information processing device, with clear signs / information informing users of the personal information processing rules, authorization is obtained from the user through pop-up information or by asking the user to upload their personal information; wherein, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.
[0122] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An industrial control flow transmission method, characterized in that, The method includes: Acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the auditing device; the registered interface is dynamically updated according to the industrial functional area to be audited by using the first terminal access point interface accessed by the virtual switching device. If so, then based on the address information carried by the data frame, the target control rule to which the data frame is matched is determined from the preset flow control rules; When the target control rule indicates that auditing the data frame is permitted, the data frame is forwarded to the virtual switching device, and the data frame is sent to the industrial control traffic auditing system using the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is used to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
2. The method according to claim 1, characterized in that, The virtual switching device is pre-created according to the following steps: An initial virtual switching device is created in the operating system kernel of the auditing device, and security parameters are configured for the initial virtual switching device to obtain an intermediate virtual switching device; After activating the intermediate virtual switch, the operating system configures the performance parameters for the intermediate virtual switch to obtain the created virtual switch.
3. The method according to claim 2, characterized in that, After the virtual switching device is created, the following is also included: The industrial control traffic auditing system creates at least two terminal access point interfaces; the at least two terminal access point interfaces include the first terminal access point interface and the second terminal access point interface; Connect the at least two terminal access point interfaces to the created virtual switching device.
4. The method according to claim 1, characterized in that, The list of interfaces is dynamically updated according to the following steps: In response to an audit edit request for the industrial functional area, determine whether the physical network interface to be edited for the industrial functional area exists. If so, then according to the editing operation indicated by the audit editing request, the physical network interface to be edited is edited in the currently maintained interface list through the first terminal access point interface.
5. The method according to claim 4, characterized in that, When the audit editing request is an audit add request, the editing operation includes an add operation; the physical network interface to be edited is the physical network interface to be added. The editing operation, as instructed by the audit editing request, involves editing the physical network interface to be edited in the currently maintained interface list through the first terminal access point interface, including: Determine whether the physical network interface to be added is in the currently maintained interface list; If not, then configure the working mode of the physical network interface to be added to obtain the configured physical network interface to be added; The configured physical network interfaces to be added are added to the interface list of the virtual switching device through the first terminal access point interface.
6. The method according to claim 5, characterized in that, After adding the configured physical network interface to be added to the interface list of the virtual switching device through the first terminal access point interface, the method further includes: Configure preset traffic control rules for the physical network interface to be added; the preset traffic control rules include at least a first traffic control rule, a second traffic control rule, and a third traffic control rule. The first flow control rule allows data frames to flow from the physical network interface to be added to the second terminal access point interface. The second flow control rule is to disallow data frames from the second terminal access point interface to the physical network interface to be added; The third flow control rule prohibits the direct flow of data frames between the physical network interface to be added and other physical network interfaces in the interface list.
7. The method according to claim 4, characterized in that, If the audit edit request is an audit delete request, the edit operation includes a delete operation; the physical network interface to be edited is the physical network interface to be deleted. The editing operation, as instructed by the audit editing request, involves editing the physical network interface to be edited in the currently maintained interface list through the first terminal access point interface, including: Determine whether the physical network interface to be deleted is in the currently maintained interface list; If so, the physical network interface to be deleted is removed from the currently maintained interface list through the first terminal access point interface, and the preset traffic control rules associated with the physical network interface to be deleted are cleared.
8. The method according to claim 1, characterized in that, The method further includes: According to a preset time interval, acquire the device status information of the virtual switching device and the interface status information of each registered interface of the virtual switching device; Based on the device status information and the interface status information, the performance of the first terminal access point interface and the second terminal access point interface is optimized, and a visual status view and operation analysis report are generated.
9. An industrial control flow transmission device, characterized in that, The device includes: The first determining module is used to acquire the data frame to be collected and determine whether the data frame comes from the target physical network interface; the target physical network interface is any registered interface in the interface list currently maintained by the virtual switching device pre-created in the auditing device; the registered interface is dynamically updated according to the industrial functional area to be audited by using the first terminal access point interface accessed by the virtual switching device. The second determining module is used to determine the target control rule hit by the data frame from the preset flow control rules based on the address information carried by the data frame if the data frame is hit. The sending module is configured to forward the data frame to the virtual switching device when the target control rule indicates that auditing the data frame is permitted, and to send the data frame to the industrial control traffic auditing system using the second terminal access point interface accessed by the virtual switching device; the industrial control traffic auditing system is configured to perform traffic auditing analysis on the target functional area corresponding to the target physical network interface based on the data frame.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the industrial control flow transmission method as described in any one of claims 1 to 8.
11. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the industrial control flow transmission method as described in any one of claims 1 to 8.