An industrial network security protection method
By analyzing the process information and equipment data of industrial equipment, the security level of sample access behavior was confirmed and access permissions were set, which solved the problem of low industrial network security protection capabilities and achieved effective constraints and security guarantees on the access process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING SHANGTIE ELECTRONIC ENG CO LTD
- Filing Date
- 2026-04-24
- Publication Date
- 2026-07-10
AI Technical Summary
The security protection capabilities of existing industrial networks are relatively low, making them vulnerable to attacks that could lead to data leaks or malicious control of equipment, thus affecting production safety.
By acquiring process information and equipment data from industrial equipment, analyzing process-related data, confirming the security level of sample access behavior, and setting access permissions based on this, the data is entered into the industrial gateway for constraint.
It enhances the security of industrial networks, prevents unauthorized access, and ensures the security of production data and equipment.
Smart Images

Figure CN122372295A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically an industrial network security protection method. Background Technology
[0002] With the integration of informatization and industrialization, the security of industrial networks has become increasingly prominent. Once security vulnerabilities emerge, the likelihood of industrial networks being attacked by viruses, Trojans, and other threats increases, thus exposing them to security threats. Currently, the typical security measures adopted for industrial networks involve deploying firewalls between the enterprise management layer and external networks.
[0003] Due to limited protective measures, if the firewall between the company's management and the external network is breached by attackers, the industrial network can be easily controlled, leading to the theft of production data or the malicious manipulation of on-site equipment, thus affecting normal production operations.
[0004] This indicates that existing technologies suffer from low industrial network security protection capabilities. Summary of the Invention
[0005] The purpose of this invention is to provide an industrial network security protection method that solves the technical problem of low industrial network security protection capability in the prior art.
[0006] This invention provides an industrial network security protection method, the method comprising: Obtain current process information and equipment data for industrial equipment; Based on the current process information and equipment data of industrial equipment, obtain several process-related data items, as well as the sensitivity value data corresponding to each process-related data item; Based on several process-related data, multiple sample access behaviors were identified; each sample access behavior includes at least one process-related data and a corresponding preset action. Based on the sample access behavior and the sensitive value data of the various process-related data corresponding to the sample access behavior, the security level of the sample access behavior is obtained. Access permissions are set based on the security level of each sample's access behavior, and then entered into the industrial gateway corresponding to the industrial equipment.
[0007] Furthermore, the process information includes process duration, process output, and process content; the equipment data includes several equipment operating parameters; based on the current process information and equipment data of the industrial equipment, several process-related data items are obtained, as well as the sensitivity value data corresponding to each process-related data item, including: Based on the process content, several process-related data are obtained from several equipment operating parameters, as well as the standard sensitivity value data corresponding to each process-related data. Based on process duration and process output, obtain adjustment parameters; Based on the adjustment parameters, the standard sensitivity value data corresponding to each process-related data is adjusted to obtain the sensitivity value data corresponding to each process-related data; the sensitivity value data includes the sensitivity value corresponding to each preset action of the process-related data.
[0008] Furthermore, based on several process-related data points, multiple sample access behaviors were identified, including: Obtain the preset action data corresponding to each process-related data item; Based on several process-related data and the preset action data corresponding to each process-related data, multiple process data combinations are obtained; each process data combination includes at least one process-related data and a preset action for each process-related data. Each process data combination is filtered based on preset filtering conditions to obtain several target process data combinations. Based on the target process data combination, the sample access behavior was confirmed.
[0009] Furthermore, based on the sample access behavior and the sensitivity value data of the corresponding process-related data, the security level of the sample access behavior is obtained, including: Based on the sensitivity value data of each process-related data, obtain the sensitivity value corresponding to the preset action of each process-related data in the sample access behavior; Based on the sensitivity values corresponding to the preset actions of each process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained. The security level of sample access behavior is obtained based on the total sensitivity value of sample access behavior and the number of items in process-related data.
[0010] Furthermore, based on the sensitivity values corresponding to preset actions for each process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained, including: Retrieve historical access data; historical access data includes access statistics corresponding to various process-related data. Based on historical access data, obtain the weights of preset actions corresponding to various process-related data in the sample access behavior; Based on the sensitivity values and weights of the preset actions corresponding to various process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained.
[0011] Furthermore, based on the total sensitivity value of sample access behavior and the number of items in process-related data, the security level of sample access behavior is obtained, including: Based on the number of items in the process-related data of sample access behavior, obtain the safety adjustment parameters corresponding to the sample access behavior; The security level of the sample access behavior is obtained based on the security adjustment parameters and total sensitivity value corresponding to the sample access behavior.
[0012] Furthermore, access permissions are set based on the security level of each sample's access behavior, and recorded in the industrial gateway corresponding to the industrial equipment, including: Access permission setting rules; Based on the permission setting rules and the security level of sample access behavior, confirm the access permissions of sample access behavior; Update the access permissions of each sample access behavior to the industrial gateway corresponding to the industrial equipment, and record the update time.
[0013] Furthermore, the permission setting rules include: Several access roles and the access scope corresponding to each access role.
[0014] Furthermore, it also includes: The industrial gateway monitors the actual access process of the access role in real time, and obtains several process-related data and the actual actions of each process-related data. Based on several process-related data and the actual actions of each process-related data, the actual access behavior is obtained in real time. Based on several sample access behaviors corresponding to the access permissions of the access role, the security of the actual access behavior of the access role is determined in real time. If not, generate an alarm message.
[0015] Furthermore, the preset filtering criteria include: The union of several target process data sets includes all process-related data; The number of combinations of data and / or target process data shall not exceed the preset number of access behaviors; The preset actions corresponding to the various process-related data in the target process data combination conform to the preset action rules of the current process content.
[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: In this invention, process-related data is obtained by analyzing the current process information and equipment data of industrial equipment to confirm sample access behaviors associated with industrial equipment. By using the sensitivity values corresponding to various process-related data of the sample access behaviors, the security level of the sample access behaviors is obtained, allowing for the setting of access permissions to constrain the actual access process. This solves the technical problem of low industrial network security protection capabilities in existing technologies. Attached Figure Description
[0017] Figure 1 This is a schematic diagram illustrating the principle of an industrial network security protection method according to the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0019] like Figure 1 As shown, the present invention provides an industrial network security protection method, the method comprising: S1: Obtain current process information and equipment data of industrial equipment; In this embodiment, each industrial equipment has differences in process information during different product processing processes; the process information includes process duration, process output, and process content.
[0020] S2: Based on the current process information and equipment data of the industrial equipment, obtain several process-related data items, as well as the sensitivity value data corresponding to each process-related data item; In this embodiment, the sensitive information involved in the equipment data differs during the processing of different products by industrial equipment.
[0021] S3: Based on several process-related data, confirm multiple sample access behaviors; each sample access behavior includes at least one process-related data and a corresponding preset action. In this embodiment, the preset actions for process-related data include query actions, update actions, insertion operations, and deletion operations.
[0022] S4: Based on the sample access behavior and the sensitive value data of various process-related data corresponding to the sample access behavior, obtain the security level of the sample access behavior; In this embodiment, the higher the security level of sample access behavior, the higher the corresponding access permission requirements.
[0023] S5: Set access permissions based on the security level of each sample's access behavior and record them in the industrial gateway corresponding to the industrial equipment.
[0024] In this embodiment, the industrial equipment is connected to the industrial gateway. When external devices access the industrial equipment, they must go through the industrial gateway. By recording the access permissions of each sample access behavior into the industrial gateway, the actual access process is constrained to ensure network security.
[0025] The specific implementation process of this embodiment includes: In this embodiment, by analyzing the current process information and equipment data of industrial equipment, process-related data is obtained to confirm sample access behaviors associated with industrial equipment. By using the sensitivity values corresponding to various process-related data of the sample access behaviors, the security level of the sample access behaviors is obtained to facilitate setting access permissions for these behaviors and thus constraining the actual access process. This solves the technical problem of low industrial network security protection capabilities in existing technologies.
[0026] In this embodiment, the process information includes process duration, process output, and process content; the equipment data includes several equipment operating parameters; based on the current process information and equipment data of the industrial equipment, several process-related data items are obtained, as well as the sensitivity value data corresponding to each process-related data item, including: S21: Based on the process content, obtain several process-related data from several equipment operating parameters, as well as the standard sensitive value data corresponding to each process-related data; In this embodiment, a relationship mapping between process content and process-related data is pre-set for each industrial device; when the process content changes, several process-related data items corresponding to the current process content are quickly obtained through the relationship mapping between process content and process-related data. In this embodiment, a corresponding standard sensitivity value is set for each preset action of each process-related data; the higher the standard sensitivity value of a preset action of a process-related data, the more sensitive the preset action is.
[0027] S22: Obtain adjustment parameters based on process duration and process output; In this embodiment, the calculation formula for the adjustment parameter includes: ; Where TZ represents the adjustment parameter; GC represents the process duration; GC B GL represents the standard process duration; GL represents the process output. B This indicates the standard process output.
[0028] In some embodiments, process duration and process output include planned duration and planned output.
[0029] S23: Adjust the standard sensitivity data corresponding to each process-related data based on the adjustment parameters, and obtain the sensitivity data corresponding to each process-related data; the sensitivity data includes the sensitivity value corresponding to each preset action of the process-related data.
[0030] In this embodiment, the product of the standard sensitivity value corresponding to each preset action of the adjustment parameters and process-related data is used as the sensitivity value corresponding to each preset action to obtain the sensitivity value data corresponding to the process-related data.
[0031] In this embodiment, based on several process-related data, multiple sample access behaviors are confirmed, including: S31: Obtain the preset action data corresponding to each process-related data; In this embodiment, the preset action data includes multiple preset actions; S32: Based on several process-related data and the preset action data corresponding to each process-related data, obtain multiple process data combinations; each process data combination includes at least one process-related data and a preset action for each process-related data. In this embodiment, multiple process-related data are arranged and combined to obtain multiple process data combinations.
[0032] S33: Filter each combination of process data based on preset filtering conditions to obtain several target combination of process data; In this embodiment, the preset filtering conditions include: the union of several target process data combinations including all process-related data; and / or the number of target process data combinations is not greater than the preset number of access behaviors; and / or the preset actions corresponding to each process-related data in the target process data combination conform to the preset action rules of the current process content.
[0033] S34: Based on the target process data combination, confirm the sample access behavior.
[0034] In this embodiment, the preset actions corresponding to each process-related data in the target process data combination constitute the sample access behavior.
[0035] In this embodiment, the security level of the sample access behavior is obtained based on the sensitive value data of the sample access behavior and the corresponding process-related data, including: S41: Based on the sensitivity value data of each process-related data, obtain the sensitivity value corresponding to the preset action of each process-related data in the sample access behavior; S42: Based on the sensitivity values corresponding to the preset actions of each process-related data in the sample access behavior, obtain the total sensitivity value of the sample access behavior; In this embodiment, the higher the total sensitivity value of a sample access behavior, the more sensitive the sample access behavior is.
[0036] S43: Based on the total sensitivity value of sample access behavior and the number of items in process-related data, obtain the security level of sample access behavior.
[0037] In this embodiment, the higher the total sensitivity value of the sample access behavior and the more items of process-related data there are, the higher the security level corresponding to the sample access behavior and the higher the access permissions required.
[0038] In this embodiment, based on the sensitivity values corresponding to preset actions of various process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained, including: S421: Obtain historical access data; historical access data includes access statistics data corresponding to various process-related data. S422: Based on historical access data, obtain the weights of preset actions corresponding to various process-related data in the sample access behavior; S423: Based on the sensitivity values and weights of the preset actions corresponding to various process-related data in the sample access behavior, obtain the total sensitivity value of the sample access behavior.
[0039] In this embodiment, the sum of the products of the sensitivity values and weights corresponding to the preset actions of each process-related data is used as the total sensitivity value of the sample access behavior.
[0040] In this embodiment, the security level of sample access behavior is obtained based on the total sensitivity value of sample access behavior and the number of items in process-related data, including: S431: Based on the number of items in the process-related data of the sample access behavior, obtain the safety adjustment parameters corresponding to the sample access behavior; The calculation formula for the safety adjustment parameter in this embodiment includes: ; Where K is the safety adjustment parameter, and XM is the number of process-related data items related to sample access behavior; XM B The number of standard items for process-related data on sample access behavior.
[0041] S432: Obtain the security level of sample access behavior based on the security adjustment parameters and total sensitivity value corresponding to the sample access behavior.
[0042] In this embodiment, the security level of sample access behavior is determined based on the product of the security adjustment parameter and the total sensitivity value. In this embodiment, the security levels are divided into five levels from high to low: Level 1, Level 2, Level 3, Level 4, and Level 5; each security level has a range for the product of the security adjustment parameter and the total sensitivity value.
[0043] Based on the range of the product of the security adjustment parameters corresponding to each security level and the total sensitivity value, the security level of sample access behavior can be quickly determined.
[0044] In this embodiment, access permissions are set based on the security level of each sample's access behavior, and recorded in the industrial gateway corresponding to the industrial equipment, including: S51: Permission setting rules for obtaining access rights; In this embodiment, the permission setting rules include: several access roles and the access scope corresponding to each access role; S52: Based on the permission setting rules and the security level of sample access behavior, confirm the access permissions of sample access behavior; In this embodiment, each sample access behavior corresponds to at least one access permission. Only when an access role with the required access permission performs a sample access behavior can it be considered legitimate.
[0045] S53: Update the access permissions of each sample access behavior to the industrial gateway corresponding to the industrial equipment, and record the update time.
[0046] In this embodiment, each industrial gateway is connected to at least one industrial device. When multiple industrial devices are connected to an industrial gateway, the industrial gateway stores sample access behaviors and access permissions for each industrial device in separate partitions. The industrial gateway records the update time when the access permissions of an industrial device are updated.
[0047] This embodiment also includes: S61: The industrial gateway monitors the actual access process of the access role in real time, and obtains several process-related data and the actual actions of each process-related data. In this embodiment, the industrial gateway records the actual actions corresponding to each process-related data item when the access role accesses the data. S62: Based on several process-related data items and the actual actions of each process-related data item, obtain the actual access behavior in real time; In this embodiment, a series of consecutive process-related data items and the actual actions performed on each of the process-related data items constitute the actual access behavior.
[0048] S63: Based on several sample access behaviors corresponding to the access permissions of the access role, determine in real time whether the actual access behavior of the access role is secure. In this embodiment, the actual access behavior is compared with the sample access behavior to determine whether there is a sample access behavior that matches the actual access behavior. If there is, the actual access behavior of the access role is determined to be secure; if not, the actual access behavior of the access role is determined to be insecure.
[0049] S64: If not, generate an alarm message.
[0050] In this embodiment, when the security of the access role's actual access behavior is determined in real time, the industrial gateway continues to collect the actual actions corresponding to the process-related data during the access. The security of the access role's actual access behavior is determined in real time until the access role ends its actual access behavior.
[0051] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0052] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. An industrial network security protection method, characterized in that: The methods include: Obtain current process information and equipment data for industrial equipment; Based on the current process information and equipment data of industrial equipment, obtain several process-related data items, as well as the sensitivity value data corresponding to each process-related data item; Based on several process-related data, the access behavior of multiple samples was confirmed. Each sample access behavior includes at least one piece of process-related data and a corresponding preset action; Based on the sample access behavior and the sensitive value data of the various process-related data corresponding to the sample access behavior, the security level of the sample access behavior is obtained. Access permissions are set based on the security level of each sample's access behavior, and then entered into the industrial gateway corresponding to the industrial equipment.
2. The industrial network security protection method as described in claim 1, characterized in that: Process information includes process duration, process output, and process content; equipment data includes several equipment operating parameters; based on the current process information and equipment data of the industrial equipment, several process-related data items are obtained, as well as the corresponding sensitivity value data for each process-related data item, including: Based on the process content, several process-related data are obtained from several equipment operating parameters, as well as the standard sensitivity value data corresponding to each process-related data. Based on process duration and process output, obtain adjustment parameters; Based on the adjustment parameters, the standard sensitivity value data corresponding to each process-related data is adjusted to obtain the sensitivity value data corresponding to each process-related data; the sensitivity value data includes the sensitivity value corresponding to each preset action of the process-related data.
3. The industrial network security protection method as described in claim 2, characterized in that: Based on several process-related data points, the access behaviors of multiple samples were confirmed, including: Obtain the preset action data corresponding to each process-related data item; Based on several process-related data and the preset action data corresponding to each process-related data, multiple process data combinations are obtained; each process data combination includes at least one process-related data and a preset action for each process-related data. Each process data combination is filtered based on preset filtering conditions to obtain several target process data combinations. Based on the target process data combination, the sample access behavior was confirmed.
4. The industrial network security protection method as described in claim 3, characterized in that: Based on the sample access behavior and the sensitivity value data of the corresponding process-related data, the security level of the sample access behavior is obtained, including: Based on the sensitivity value data of each process-related data, obtain the sensitivity value corresponding to the preset action of each process-related data in the sample access behavior; Based on the sensitivity values corresponding to the preset actions of each process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained. The security level of sample access behavior is obtained based on the total sensitivity value of sample access behavior and the number of items in process-related data.
5. The industrial network security protection method as described in claim 4, characterized in that: Based on the sensitivity values corresponding to preset actions for various process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained, including: Retrieve historical access data; historical access data includes access statistics corresponding to various process-related data. Based on historical access data, obtain the weights of preset actions corresponding to various process-related data in the sample access behavior; Based on the sensitivity values and weights of the preset actions corresponding to various process-related data in the sample access behavior, the total sensitivity value of the sample access behavior is obtained.
6. The industrial network security protection method as described in claim 5, characterized in that: Based on the total sensitivity value of sample access behavior and the number of items in process-related data, the security level of sample access behavior is obtained, including: Based on the number of items in the process-related data of sample access behavior, obtain the safety adjustment parameters corresponding to the sample access behavior; The security level of the sample access behavior is obtained based on the security adjustment parameters and total sensitivity value corresponding to the sample access behavior.
7. The industrial network security protection method as described in claim 1, characterized in that: Access permissions are set based on the security level of each sample's access behavior, and entered into the industrial gateway corresponding to the industrial equipment, including: Access permission setting rules; Based on the permission setting rules and the security level of sample access behavior, confirm the access permissions of sample access behavior; Update the access permissions of each sample access behavior to the industrial gateway corresponding to the industrial equipment, and record the update time.
8. The industrial network security protection method as described in claim 7, characterized in that: The permission setting rules include: Several access roles and the access scope corresponding to each access role.
9. The industrial network security protection method as described in claim 8, characterized in that: Also includes: The industrial gateway monitors the actual access process of the access role in real time, and obtains several process-related data and the actual actions of each process-related data. Based on several process-related data and the actual actions of each process-related data, the actual access behavior is obtained in real time. Based on several sample access behaviors corresponding to the access permissions of the access role, the security of the actual access behavior of the access role is determined in real time. If not, generate an alarm message.
10. The industrial network security protection method as described in claim 3, characterized in that: Preset filter criteria include: The union of several target process data sets includes all process-related data; The number of combinations of data and / or target process data shall not exceed the preset number of access behaviors; The preset actions corresponding to the various process-related data in the target process data combination conform to the preset action rules of the current process content.