Power industry control terminal intelligent repair protection method based on vulnerability scanning
Patent Information
- Application Number
- CN202611103085.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-23
- Publication Date
- 2026-09-11
AI Technical Summary
[0004]为了解决现有方法在对电力工控终端的漏洞进行修复时存在的修复不及时或修复动作扰动过大,导致修复不够精准的问题,本发明的目的在于提供基于漏洞扫描的电力工控终端智能修复防护方法,所采用的技术方案具体如下:
本发明首先通过获取电力工控终端的漏洞扫描结果、当前开放入口集合、观察窗口内的通信会话以及正常业务来源对象集合,从漏洞是否存在、关联入口是否开放、访问来源是否属于正常业务三个维度逐层对漏洞进行了确认和判断,并基于上述确认结果和判断结果确定漏洞的风险参数,该风险参数能够真实刻画漏洞在当前电力工控终端实际网络环境中的可利用程度,从而为后续修复防护动作的量化评估提供了科学、客观、可计算的基础,提高了自动化决策的可靠性和适应性;根据漏洞扫描结果生成包含补丁升级类动作、端口或服务关闭类动作、以及访问控制或防火墙规则类动作的候选修复防护动作,并结合各候选修复防护动作对漏洞可达风险的降低量以及对正常业务通信的扰动程度来筛选目标动作并执行,该过程将修复防护动作的风险降低效果与业务扰动代价纳入考虑范围,使得最终执行的动作是在保证有效降低漏洞可达风险的前提下、对正常电力工控业务通信影响最小的最优动作。相比现有技术中盲目打补丁或简单关闭端口的方法,本发明提供的方法能够在保障安全性的同时,最大程度地维持电力工控终端业务的连续性和稳定性,解决了现有漏洞扫描结果与修复动作执行之间缺少结合真实通信关系和业务扰动约束进行智能决策的技术问题,实现了电力工控终端漏洞修复防护的智能化和精准化。
Smart Images

Figure CN122741218A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vulnerability repair technology, and more specifically to an intelligent repair and protection method for power industrial control terminals based on vulnerability scanning. Background Technology
[0002] Power system control terminals undertake tasks such as dispatch communication, plant monitoring, remote control data acquisition, protection information transmission, engineering maintenance, and production control support. Their operational status is closely related to the continuous and stable operation of the power system. Existing vulnerability scanning tools can typically output the vulnerability number, vulnerability level, affected services, and remediation suggestions for terminals. However, in power system control scenarios, vulnerability handling cannot be simply carried out in a "high-risk priority, immediate patching" manner. Some vulnerabilities, although of high level, may not have corresponding open ports or have no real access source in the current network. In such cases, immediate high-disturbance patching is unreasonable. Some vulnerabilities may not be of the highest level, but their entry points overlap with dispatch, remote control, plant monitoring, or engineering maintenance links. If exploited, they may affect critical business communications, requiring priority protection measures.
[0003] Power industrial control terminals generally suffer from several drawbacks, including the inability to shut down arbitrarily, high patch compatibility requirements, complex device versions, strict communication whitelists, and limited maintenance windows. Directly and automatically issuing patches, closing ports, or modifying access control policies based solely on vulnerability levels could lead to interruptions in normal industrial control communication, failures in maintenance links, abnormal business processes, or device unavailability. Current technologies lack a decision-making process that integrates real-world communication relationships and business disturbance constraints between vulnerability scanning results and remediation actions. This results in vulnerability remediation and protection relying excessively on human experience, leading to untimely remediation or overly disruptive remediation actions. Summary of the Invention
[0004] To address the problems of untimely or excessively disruptive patching methods in existing power control terminals, leading to inaccurate patching, the present invention aims to provide an intelligent patching and protection method for power control terminals based on vulnerability scanning. The specific technical solution adopted is as follows: This invention provides an intelligent repair and protection method for power industrial control terminals based on vulnerability scanning. The method includes the following steps: Obtain the vulnerability scan results, currently open entry points, communication sessions, and normal business source objects within the observation window of the power industrial control terminal; Based on the vulnerability scan results, confirm whether the vulnerability exists, compare the associated entry point in the vulnerability scan results with the current open entry point set, determine whether the associated entry point is open, and determine whether the source object accessing the associated entry point in the communication session belongs to the normal business source object set. Based on the confirmation results and judgment results, determine the risk parameters of the vulnerability. Based on the vulnerability scan results, candidate remediation and protection actions are generated, including patch upgrade actions, port or service closure actions, and access control or firewall rule actions. Target actions are selected and executed based on the reduction in vulnerability reachability risk and the degree of disruption to normal business communication caused by each candidate remediation and protection action. The vulnerability reachability risk is determined based on risk parameters.
[0005] Preferably, the step of determining the risk parameters of the vulnerability based on the confirmation result and the judgment result includes: If a candidate vulnerability exists, it is determined whether there is an intersection between the associated entry point of the candidate vulnerability and the current set of open entry points, and the vulnerability entry point opening value is determined. When the associated entry point is open, the ratio of the number of source objects accessing the associated entry point to the total number of source objects accessing the terminal in the observation window is calculated. Combining the ratio with the vulnerability entry point opening value, the vulnerability entry point reachability value is determined. The ratio of the number of source objects accessing the associated entry point that belong to the set of normal business source objects to the total number of source objects accessing the associated entry point is determined as the degree of association between the candidate vulnerability and the power business chain. The vulnerability scan confirmation value, the vulnerability entry point open value, the vulnerability entry point reachability value, and the correlation degree together constitute the risk parameter; The method for obtaining the vulnerability scan confirmation value is as follows: if a candidate vulnerability exists, the vulnerability scan confirmation value is set to 1; if no candidate vulnerability exists, the vulnerability scan confirmation value is set to 0. The candidate vulnerability can be any vulnerability.
[0006] Preferably, obtaining the vulnerability entry point open value includes: For candidate vulnerabilities, obtain the set of associated entry points of the candidate vulnerabilities from the vulnerability scanning results; If the set of associated entry points of the candidate vulnerability intersects with the set of currently open entry points, then the open value of the entry point of the candidate vulnerability is set to the first value. If the set of associated entry points of the candidate vulnerability does not intersect with the set of currently open entry points, then the open value of the entry point of the candidate vulnerability is set to a second value; the first value is greater than the second value.
[0007] Preferably, the step of generating candidate remediation and protection actions based on the vulnerability scan results includes: For candidate vulnerabilities, candidate handling methods are obtained based on the vulnerability scanning results; Based on the candidate handling methods of the candidate vulnerabilities, candidate remediation and protection actions are generated for the candidate vulnerabilities.
[0008] Preferably, the acquisition of the reduction in vulnerability reachability risk by each candidate remediation and protection action includes: For any candidate remediation action for a candidate vulnerability: Based on the type of any candidate remediation and protection action, the risk parameters of the candidate vulnerability are updated to obtain the risk parameters of the candidate vulnerability after the execution of any candidate remediation and protection action. Based on the difference in risk parameters before and after the action is executed, the amount by which any candidate remediation and protection action reduces the vulnerability reachability risk is determined.
[0009] Preferably, the effect of the patch upgrade action is to set the vulnerability scan confirmation value to zero; the effect of the port or service closure action is to remove the entry corresponding to the action from the current open entry set and update the vulnerability entry open value; the effect of the access control or firewall rule action is to generate the source object set after the action by removing the object set to be blocked by the corresponding action from the source object set of the access vulnerability entry.
[0010] Preferably, the acquisition of the degree of disturbance to normal business communication includes: For actions such as closing ports or services, as well as actions such as access control or firewall rules, the candidate repair and protection actions to be executed are compared with the normal business communication sessions in the observation window to obtain the degree of disturbance of the corresponding candidate repair and protection actions to normal business communication. For patch upgrade actions, the expected duration of service unavailability when the patch upgrade action is executed on the terminal is obtained, and the ratio of the expected service unavailability duration to the allowed maintenance window duration is used as the degree of disturbance of the patch upgrade action to normal service communication.
[0011] Preferably, the step of comparing the candidate repair and protection action to be executed with the normal business communication session in the observation window to obtain the degree of disturbance of the corresponding candidate repair and protection action to normal business communication includes: The first number of normal business sessions hit by the proposed candidate repair and protection action is counted, and the ratio of the first number to the total number of normal business sessions is used as the degree of disturbance to normal business communication by the corresponding candidate repair and protection action.
[0012] Preferably, the step of selecting target actions based on the reduction in vulnerability reachability risk and the degree of disruption to normal business communication caused by each candidate remediation and protection action includes: Calculate the vulnerability scan confirmation value after each patch upgrade action is executed, and determine whether there are patch upgrade actions with a vulnerability scan confirmation value of 0 and a disturbance level not exceeding the allowable value. If there are, the corresponding action is selected as the result; if not, calculate the vulnerability entry opening value after each port or service shutdown action is executed, and select the port or service shutdown action with a vulnerability entry opening value of 0 and a disturbance level of 0 as the result. If there are no port or service closure actions with an open vulnerability entry value of 0 and a disturbance level of 0 after execution, then calculate the reduction in vulnerability reachability risk and the disturbance level to normal business communication after the execution of each access control or firewall rule action, and select the access control or firewall rule actions with a reduction in vulnerability reachability risk greater than 0 and a disturbance level of 0 as the selection result. Select the action that reduces the vulnerability reachability risk the most from the selection results as the target action.
[0013] Preferably, if all candidate repair and protection actions meet the preset conditions, the automatic repair execution is terminated, and enhanced monitoring rules and a manual review work order are output: The preset conditions are: the reduction in vulnerability reachability risk after each candidate remediation and protection action is equal to 0, or, except for patch upgrade actions that satisfy the requirement that the disturbance level does not exceed the allowable value, the disturbance level of normal business communication of the remaining candidate remediation and protection actions with a reduction in vulnerability reachability risk greater than 0 is greater than 0.
[0014] The present invention has at least the following beneficial effects: This invention first obtains vulnerability scan results, the set of currently open entry points, communication sessions within the observation window, and the set of normal business source objects from the power industrial control terminal. It then confirms and judges the vulnerability layer by layer from three dimensions: whether the vulnerability exists, whether the associated entry point is open, and whether the access source belongs to normal business. Based on the above confirmation and judgment results, it determines the vulnerability's risk parameters. These risk parameters can realistically characterize the exploitability of the vulnerability in the actual network environment of the current power industrial control terminal, thus providing a scientific, objective, and calculable basis for the quantitative evaluation of subsequent remediation and protection actions, improving the reliability and adaptability of automated decision-making. Based on the vulnerability scan results, it generates candidate remediation and protection actions, including patch upgrade actions, port or service closure actions, and access control or firewall rule actions. It then combines the reduction in vulnerability reachability risk and the degree of disruption to normal business communication of each candidate remediation and protection action to select and execute target actions. This process takes into account the risk reduction effect of the remediation and protection actions and the business disruption cost, ensuring that the final executed action is the optimal action with the least impact on normal power industrial control business communication while effectively reducing vulnerability reachability risk. Compared with existing technologies that blindly patch or simply close ports, the method provided by this invention can maintain the continuity and stability of power industrial control terminal services to the greatest extent while ensuring security. It solves the technical problem that existing vulnerability scanning results and repair actions lack intelligent decision-making based on real communication relationships and business disturbance constraints, and realizes intelligent and precise vulnerability repair and protection for power industrial control terminals. Attached Figure Description
[0015] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 The flowchart illustrates the intelligent repair and protection method for power industrial control terminals based on vulnerability scanning, as provided in this embodiment of the invention. Detailed Implementation
[0017] The following description, in conjunction with the accompanying drawings, details the specific scheme of the intelligent repair and protection method for power industrial control terminals based on vulnerability scanning provided by this invention.
[0018] Example of an intelligent repair and protection method for power industrial control terminals based on vulnerability scanning: This embodiment proposes an intelligent repair and protection method for power industrial control terminals based on vulnerability scanning, such as... Figure 1As shown, the intelligent repair and protection method for power industrial control terminals based on vulnerability scanning in this embodiment includes the following steps: Step S1: Obtain the vulnerability scan results, the set of currently open entry points, the set of communication sessions and normal business source objects in the observation window of the power industrial control terminal.
[0019] In the process of patching and protecting the vulnerabilities of the power industrial control terminal to be detected, it is first necessary to perform a low-disturbance vulnerability scan on the power industrial control terminal and read the structured results of this scan task. The structured results include the terminal number and the vulnerability scan results. The vulnerability scan results include the vulnerability number, the original vulnerability level, the vulnerability matching status, the vulnerability associated entry point, and the candidate handling methods. The candidate handling methods include candidate patching and protection actions.
[0020] The terminal ID is used to identify the target for subsequent calculations; the vulnerability ID is used to distinguish different vulnerabilities; the original vulnerability level is used to retain the scanner's basic judgment of the vulnerability's severity; the vulnerability matching status indicates whether the scanner has confirmed the existence of the corresponding vulnerability on the terminal; the vulnerability-related entry point indicates the service, port, or protocol entry point that the vulnerability depends on; and the candidate handling methods indicate optional actions such as patch upgrades, service shutdown, port closure, access control, and whitelist restrictions. If a vulnerability scan result only provides the vulnerability ID and original vulnerability level, without providing the vulnerability matching status, vulnerability-related entry point, or candidate handling methods, then the vulnerability will not enter the automatic remediation calculation process but will instead generate a record awaiting manual review.
[0021] By using a host security agent, terminal management script, system service list reading command, or industrial control security management platform, the set of services currently running and the set of currently open entry points for the terminal can be obtained. The set of currently open entry points contains multiple currently open entry points. This data is used to compare with the vulnerability-related entry points in the vulnerability scan results to determine whether the service, port, or protocol entry point on which the vulnerability depends is actually open on the current terminal.
[0022] The system reads communication session records from the observation window of industrial firewalls, host firewalls, industrial security gateways, switch mirrored traffic, or whitelist systems. These records include at least the source object, destination terminal, destination port, communication protocol, allow or block result, and session occurrence time. This data is used to statistically analyze the source objects that have accessed the terminal within the observation window, as well as those that have accessed vulnerability-related entry points. Simultaneously, the system reads the set of normal business source objects for the terminal from the business whitelist, communication configuration table, security partition configuration, or business system configuration to determine whether the source objects accessing vulnerability-related entry points belong to the existing power business chain. The observation window is a preset time period with the current time as the last moment; the preset duration can be 30 days.
[0023] Obtain the corresponding minimum execution constraint data based on the candidate handling methods. For patch upgrades or version upgrades, read the expected service unavailability duration from the test environment rehearsal records, historical work orders for the same model terminal, or patch management records, and confirm whether a rollback package exists. For actions such as closing ports, shutting down services, access control, and whitelist restrictions, compare the proposed action with the normal business communication sessions in the observation window to determine the number of normal business sessions that the action may hit. If the expected service unavailability duration or rollback conditions cannot be obtained for patch actions, or if a clear target for blocking cannot be formed for communication actions, the action will not enter the automatic execution calculation process but will be transferred to manual review.
[0024] This embodiment uses the above method to obtain the vulnerability scanning results of the power industrial control terminal, the set of currently open entry points, the communication sessions in the observation window, the set of normal business source objects, the candidate handling methods, the rollback conditions or normal business hit status corresponding to the candidate handling methods, and the expected service unavailability duration.
[0025] Step S2: Based on the vulnerability scan results, confirm whether the vulnerability exists, compare the associated entry point in the vulnerability scan results with the current open entry point set, determine whether the associated entry point is open, and determine whether the source object accessing the associated entry point in the communication session belongs to the normal business source object set. Based on the confirmation results and judgment results, determine the risk parameters of the vulnerability.
[0026] After obtaining data information such as vulnerability scan results, current open entry points, communication sessions in the observation window, and normal business source object set, the degree of risk realization of the vulnerability on the current power industrial control terminal will be determined step by step according to the progressive relationship of "whether the vulnerability has been scanned and confirmed, whether the vulnerability entry point is open on the local machine, whether the vulnerability entry point is accessed by a real source, and whether the access source belongs to the power business chain".
[0027] The following explanation uses any vulnerability from the vulnerability scan results as an example. Other vulnerabilities can be handled using the method provided in this embodiment.
[0028] Specifically, any vulnerability is recorded as a candidate vulnerability.
[0029] If no candidate vulnerability is found in the vulnerability matching status, the vulnerability scan confirmation value of the candidate vulnerability is set to 0. If a candidate vulnerability is found in the vulnerability matching status, the vulnerability scan confirmation value of the candidate vulnerability is set to 1. Only vulnerabilities that have been confirmed by the vulnerability scanning task will proceed to the subsequent judgment of entry point access, communication reachability, and remediation and protection. Unconfirmed vulnerabilities will not enter the automatic handling process.
[0030] After obtaining the vulnerability scan confirmation value of the candidate vulnerability, it is further determined whether there is an intersection between the associated entry point of the candidate vulnerability and the current open entry point set. That is, it is equivalent to determining whether the entry point on which the candidate vulnerability depends is actually open. When there is an intersection between the associated entry point of the candidate vulnerability and the current open entry point set, the open value of the candidate vulnerability entry point is set to the first value. When there is no intersection between the associated entry point set of the candidate vulnerability and the current open entry point set, the open value of the candidate vulnerability entry point is set to the second value, and the reachable value of the candidate vulnerability entry point is set to 0. The first value is greater than the second value. In this embodiment, the first value is 1 and the second value is 0.
[0031] A vulnerability is considered to have the potential for further access only if it has been scanned and confirmed, and its associated entry point is indeed open (there is an intersection between the candidate vulnerability's associated entry point and the currently open entry point set). If the vulnerability scan results do not provide an associated entry point for the candidate vulnerability, the candidate vulnerability will be subject to manual review and will not be included in the selection of automatic remediation and protection actions.
[0032] When the vulnerability entry point open value of the candidate vulnerability is the first value, that is, when the associated entry point is open, it is further determined whether there is a real access source for the vulnerability entry point in the current network. Specifically, the ratio of the number of source objects accessing the associated entry point to the total number of source objects accessing the terminal in the observation window is calculated, and this ratio is recorded as the first ratio. Combining the first ratio with the vulnerability entry point open value, the vulnerability entry point reachability value is determined, that is, the product of the first ratio and the vulnerability entry point open value is used as the vulnerability entry point reachability value of the candidate vulnerability.
[0033] After obtaining the reachability value of the vulnerability entry point, the next step is to determine whether the source object accessing the vulnerability entry point belongs to the power business chain. Specifically, the ratio of the number of source objects accessing the associated entry point that belong to the normal business source object set to the total number of source objects accessing the associated entry point is used as the degree of association between the candidate vulnerability and the power business chain. This embodiment does not use subjective judgment of the importance of terminal business, but instead counts how many of the source objects accessing the vulnerability entry point belong to the existing power business chain. If the degree of association between the candidate vulnerability and the power business chain is high, it indicates that the vulnerability entry point has a high degree of overlap with the actual power business communication relationship, and more attention should be paid to the impact on normal business communication when fixing it. If the degree of association between the candidate vulnerability and the power business chain is 0, it indicates that the source object accessing the vulnerability entry point does not belong to the registered normal business chain. In this case, it is more appropriate to prioritize cutting off such access through access control or whitelisting.
[0034] Using the above method, we can obtain the vulnerability scan confirmation value, vulnerability entry point open value, vulnerability entry point reachability value, and the degree of correlation between the vulnerability and the power business chain. The obtained vulnerability scan confirmation value, vulnerability entry point open value, vulnerability entry point reachability value, and the degree of correlation between the vulnerability and the power business chain are recorded as risk parameters, that is, we obtain the risk parameters before the candidate remediation and protection actions are executed.
[0035] Step S3: Generate candidate remediation and protection actions based on the vulnerability scan results. The candidate remediation and protection actions include patch upgrade actions, port or service closure actions, and access control or firewall rule actions. Based on the reduction of vulnerability reachability risk and the degree of disturbance to normal business communication by each candidate remediation and protection action, select target actions and execute the target actions. The vulnerability reachability risk is determined based on risk parameters.
[0036] For each vulnerability, multiple candidate remediation actions are obtained based on the vulnerability scan results. These candidate remediation and protection actions include patch upgrades, port or service shutdowns, and access control or firewall rule actions. All candidate remediation actions for each vulnerability constitute the candidate remediation action set for that vulnerability.
[0037] The following embodiment will still use a candidate vulnerability as an example for explanation.
[0038] For any candidate remediation action for a candidate vulnerability: if the candidate remediation action is a patch upgrade action, its effect is to set the vulnerability scan confirmation value to 0; if the candidate remediation action is a port or service closure action, its effect is to remove the entry corresponding to the action from the current set of open entry points and update the vulnerability entry point open value; if the candidate remediation action is an access control or firewall rule action, its effect is to remove the set of objects to be blocked by the corresponding action from the set of source objects accessing the vulnerability entry point, thereby generating the set of source objects after the action, that is, reducing the source objects accessing the vulnerability entry point, thereby reducing the vulnerability entry point reachability value. For the candidate remediation action, the risk parameters after the action are regenerated according to the broken chain position of the action. That is, the position of the risk chain that the candidate remediation action affects is determined. The risk chain position includes the vulnerability scanning and confirmation stage, the vulnerability entry point opening stage, and the source object reachability stage. If the candidate remediation action does not affect a certain chain variable, the variable retains its value before the action. If the candidate remediation action affects a certain chain variable, only that variable is changed and it is naturally passed to the subsequent risk parameters by the subsequent formula.
[0039] Specifically, for the candidate remediation and protection action, if the candidate remediation and protection action is a patch upgrade action, then the vulnerability scan confirmation value after the action is executed is set to 0; if the candidate remediation and protection action is not a patch upgrade action, then the vulnerability scan confirmation value after the action is executed remains unchanged, that is, the vulnerability scan confirmation value obtained in step S2 is maintained, that is, the vulnerability scan confirmation value after the action is executed is equal to the vulnerability scan confirmation value before its execution.
[0040] If the candidate remediation action is a port or service closure action, then the entry corresponding to the action is removed from the current open entry set to obtain an updated open entry set. The vulnerability entry open value is then updated based on the updated open entry set to obtain the vulnerability entry open value after the action is executed. Specifically, it is determined whether there is an intersection between the candidate vulnerability's associated entry and the updated open entry set. If there is an intersection, the vulnerability entry open value after the action is executed is set to the first value; if there is no intersection, the vulnerability entry open value after the action is executed is set to the second value. Based on the updated vulnerability entry open value, the vulnerability entry reachability value after the action is executed is updated: if the updated vulnerability entry open value is the second value, the vulnerability entry reachability value after the action is executed is set to 0.
[0041] If the candidate remediation action is an access control or firewall rule action, then the set of objects to be blocked by the corresponding action is removed from the set of source objects at the access vulnerability entry point. The remaining source objects constitute the set of source objects after the action. The set of objects to be blocked by the corresponding action is determined by the access control rule, whitelist rule, or industrial firewall rule to be issued. Then, the ratio of the number of source objects in the set of source objects after the action to the total number of source objects in the observation window is calculated, and this ratio is recorded as the second ratio. The product of the second ratio and the vulnerability entry point open value is taken as the vulnerability entry point reachability value after the action is executed.
[0042] It should be noted that: In this embodiment, if the denominator is zero when performing the above ratio and normalization calculations, the ratio calculation of the current indicator will be stopped, a preset alarm message will be output, and the action will be downgraded to a manual review process.
[0043] The above steps updated the risk parameters that needed to be updated based on the type of candidate repair and protection actions, and obtained the risk parameters after the action was executed. It should be noted that: risk parameters not mentioned in the above risk parameter update process are risk parameters that do not need to be updated, that is, the risk parameters before and after the action are the same.
[0044] Using the methods described above, the risk parameters before and after the execution of the candidate remediation action were determined. Next, based on the differences in these risk parameters, the reduction in vulnerability reachability risk caused by the candidate remediation action will be determined.
[0045] Specifically, for a candidate vulnerability, its original level is obtained and normalized. The normalized result ranges from [0, 1] and is used as the level feature value of the candidate vulnerability. In this embodiment, the maximum and minimum values are used for normalization, with the maximum and minimum values being the maximum and minimum level values of all vulnerabilities, respectively. Then, the product of the vulnerability scan confirmation value, the level feature value, and the vulnerability entry reachability value of the candidate vulnerability is used as the vulnerability reachability risk value of the candidate vulnerability before the candidate remediation and protection actions are executed.
[0046] For any candidate remediation and protection action for a candidate vulnerability: the product of the vulnerability scan confirmation value after the action is executed, the level characteristic value of the candidate vulnerability, and the vulnerability entry reachability value of the candidate vulnerability after the action is executed is taken as the vulnerability reachability risk value of the candidate vulnerability after the candidate remediation and protection action is executed.
[0047] Furthermore, the difference between the vulnerability reachability risk value of the candidate vulnerability before the execution of the candidate remediation and protection action and the vulnerability reachability risk value of the candidate vulnerability after the execution of the candidate remediation and protection action is taken as the amount of reduction in vulnerability reachability risk by the candidate remediation and protection action for the candidate vulnerability.
[0048] Using the above methods, we can obtain the reduction in vulnerability reachability risk of all candidate remediation and protection actions for the candidate vulnerability.
[0049] After obtaining the reduction in vulnerability reachability risk for each candidate remediation action, it is necessary to further determine whether the candidate remediation actions will disrupt normal power operations.
[0050] Specifically, for actions such as port or service closure and access control or firewall rule actions, the candidate repair and protection actions to be executed are compared with the normal business communication sessions in the observation window to obtain the degree of disturbance to normal business communication caused by the corresponding candidate repair and protection actions. Specifically, the number of normal business sessions hit by the candidate repair and protection actions to be executed is counted and recorded as the first number; the ratio of the first number to the total number of normal business sessions is used as the degree of disturbance to normal business communication caused by the corresponding candidate repair and protection actions. For patch upgrade actions, the expected service downtime caused when the patch upgrade action is executed on the terminal is obtained, and the ratio of the expected service downtime to the allowed maintenance window duration is used as the degree of disturbance of the patch upgrade action; in particular, if the expected service downtime caused when the patch upgrade action is executed on the terminal cannot be obtained, the patch upgrade action will not enter the automatic execution selection and will be directly transferred to manual review.
[0051] Furthermore, for candidate vulnerabilities, it is determined whether there are any patch upgrade actions that result in a vulnerability scan confirmation value of 0 and a disturbance level not exceeding the allowable value. If so, the corresponding action is selected. If not, the vulnerability entry point open value after the execution of each port or service shutdown action is calculated, and the port or service shutdown action with a vulnerability entry point open value of 0 and a disturbance level of 0 is selected. The allowable value is a disturbance limit threshold pre-set by the system, which can be 0.5.
[0052] If there are no port or service closure actions with an open vulnerability value of 0 and a disturbance level of 0 after execution, then calculate the reduction in vulnerability reachability risk and the disturbance level to normal business communication after the execution of each access control or firewall rule action, and select the access control or firewall rule action with a reduction in vulnerability reachability risk greater than 0 and a disturbance level of 0.
[0053] After obtaining the selection results, the action that reduces the vulnerability reachability risk the most is selected as the target action, and the target action is executed on the candidate vulnerability.
[0054] If all candidate remediation and protection actions meet the preset conditions, the automatic remediation execution will be terminated, and enhanced monitoring rules and manual review work orders will be output. The preset conditions are: the reduction in vulnerability reachability risk after the execution of each candidate remediation and protection action is equal to 0, or, except for patch upgrade actions that meet the requirement that the disturbance level does not exceed the allowable value, the disturbance level of normal business communication of the actions with a reduction in vulnerability reachability risk greater than 0 in the other candidate remediation and protection actions is greater than 0.
[0055] Thus, by using the method provided in this embodiment, intelligent repair and protection against vulnerabilities in power industrial control terminals can be achieved.
[0056] This embodiment first obtains the vulnerability scan results of the power industrial control terminal, the set of currently open entry points, the communication sessions in the observation window, and the set of normal business source objects. It confirms and judges the vulnerability layer by layer from three dimensions: whether the vulnerability exists, whether the associated entry point is open, and whether the access source belongs to normal business. Based on the above confirmation and judgment results, the risk parameters of the vulnerability are determined. These risk parameters can realistically depict the exploitability of the vulnerability in the actual network environment of the current power industrial control terminal, thus providing a scientific, objective, and calculable basis for the quantitative evaluation of subsequent remediation and protection actions, improving the reliability and adaptability of automated decision-making. Based on the vulnerability scan results, candidate remediation and protection actions are generated, including patch upgrade actions, port or service closure actions, and access control or firewall rule actions. The target action is selected and executed by combining the reduction of vulnerability access risk and the degree of disturbance to normal business communication of each candidate remediation and protection action. This process takes into account the risk reduction effect of the remediation and protection action and the business disturbance cost, so that the final action is the optimal action with the least impact on normal power industrial control business communication while ensuring effective reduction of vulnerability access risk. Compared with existing technologies that blindly patch or simply close ports, the method provided in this embodiment can maintain the continuity and stability of power industrial control terminal services to the greatest extent while ensuring security. It solves the technical problem that existing vulnerability scanning results and repair actions lack intelligent decision-making based on real communication relationships and business disturbance constraints, and realizes intelligent and precise vulnerability repair and protection for power industrial control terminals.
[0057] It should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for intelligent repair and protection of power industrial control terminals based on vulnerability scanning, characterized in that, The method includes the following steps: Obtain the vulnerability scan results, currently open entry points, communication sessions, and normal business source objects within the observation window of the power industrial control terminal; Based on the vulnerability scan results, confirm whether the vulnerability exists, compare the associated entry point in the vulnerability scan results with the current open entry point set, determine whether the associated entry point is open, and determine whether the source object accessing the associated entry point in the communication session belongs to the normal business source object set. Based on the confirmation results and judgment results, determine the risk parameters of the vulnerability. Based on the vulnerability scan results, candidate remediation and protection actions are generated, including patch upgrade actions, port or service closure actions, and access control or firewall rule actions. Target actions are selected and executed based on the reduction in vulnerability reachability risk and the degree of disruption to normal business communication caused by each candidate remediation and protection action. The vulnerability reachability risk is determined based on risk parameters.
2. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 1, characterized in that, The risk parameters for determining vulnerabilities based on confirmation and judgment results include: If a candidate vulnerability exists, it is determined whether there is an intersection between the associated entry point of the candidate vulnerability and the current set of open entry points, and the vulnerability entry point opening value is determined. When the associated entry point is open, the ratio of the number of source objects accessing the associated entry point to the total number of source objects accessing the terminal in the observation window is calculated. Combining the ratio with the vulnerability entry point opening value, the vulnerability entry point reachability value is determined. The ratio of the number of source objects accessing the associated entry point that belong to the set of normal business source objects to the total number of source objects accessing the associated entry point is determined as the degree of association between the candidate vulnerability and the power business chain. The vulnerability scan confirmation value, the vulnerability entry point open value, the vulnerability entry point reachability value, and the correlation degree together constitute the risk parameter; The method for obtaining the vulnerability scan confirmation value is as follows: if a candidate vulnerability exists, the vulnerability scan confirmation value is set to 1; if no candidate vulnerability exists, the vulnerability scan confirmation value is set to 0. The candidate vulnerability can be any vulnerability.
3. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 2, characterized in that, Obtaining the vulnerability entry point open value includes: For candidate vulnerabilities, obtain the set of associated entry points of the candidate vulnerabilities from the vulnerability scanning results; If the set of associated entry points of the candidate vulnerability intersects with the set of currently open entry points, then the open value of the entry point of the candidate vulnerability is set to the first value. If the set of associated entry points of the candidate vulnerability does not intersect with the set of currently open entry points, then the open value of the entry point of the candidate vulnerability is set to a second value; the first value is greater than the second value.
4. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 1, characterized in that, The step of generating candidate remediation and protection actions based on the vulnerability scan results includes: For candidate vulnerabilities, candidate handling methods are obtained based on the vulnerability scanning results; Based on the candidate handling methods of the candidate vulnerabilities, candidate remediation and protection actions are generated for the candidate vulnerabilities.
5. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 2, characterized in that, The acquisition of the reduction in vulnerability reachability risk for each candidate remediation and protection action includes: For any candidate remediation action for a candidate vulnerability: Based on the type of any candidate remediation and protection action, the risk parameters of the candidate vulnerability are updated to obtain the risk parameters of the candidate vulnerability after the execution of any candidate remediation and protection action. Based on the difference in risk parameters before and after the action is executed, the amount by which any candidate remediation and protection action reduces the vulnerability reachability risk is determined.
6. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 5, characterized in that, The effect of the patch upgrade action is to set the vulnerability scan confirmation value to zero; the effect of the port or service closure action is to remove the corresponding entry from the current open entry set and update the vulnerability entry open value; the effect of the access control or firewall rule action is to remove the object set to be blocked by the corresponding action from the source object set of the access vulnerability entry, and generate the source object set after the action.
7. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 1, characterized in that, The acquisition of the degree of disturbance to normal business communication includes: For actions such as closing ports or services, as well as actions such as access control or firewall rules, the candidate repair and protection actions to be executed are compared with the normal business communication sessions in the observation window to obtain the degree of disturbance of the corresponding candidate repair and protection actions to normal business communication. For patch upgrade actions, the expected duration of service unavailability when the patch upgrade action is executed on the terminal is obtained, and the ratio of the expected service unavailability duration to the allowed maintenance window duration is used as the degree of disturbance of the patch upgrade action to normal service communication.
8. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 7, characterized in that, The step of comparing the candidate repair and protection actions to be executed with the normal business communication sessions in the observation window to obtain the degree of disturbance to normal business communication by the corresponding candidate repair and protection actions includes: The first number of normal business sessions hit by the proposed candidate repair and protection action is counted, and the ratio of the first number to the total number of normal business sessions is used as the degree of disturbance to normal business communication by the corresponding candidate repair and protection action.
9. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 2, characterized in that, The process of selecting target actions based on the reduction in vulnerability reachability risk and the degree of disruption to normal business communication caused by each candidate remediation and protection action includes: Calculate the vulnerability scan confirmation value after each patch upgrade action is executed, and determine whether there are patch upgrade actions with a vulnerability scan confirmation value of 0 and a disturbance level not exceeding the allowable value. If there are, the corresponding action is selected as the result; if not, calculate the vulnerability entry opening value after each port or service shutdown action is executed, and select the port or service shutdown action with a vulnerability entry opening value of 0 and a disturbance level of 0 as the result. If there are no port or service closure actions with an open vulnerability entry value of 0 and a disturbance level of 0 after execution, then calculate the reduction in vulnerability reachability risk and the disturbance level to normal business communication after the execution of each access control or firewall rule action, and select the access control or firewall rule actions with a reduction in vulnerability reachability risk greater than 0 and a disturbance level of 0 as the selection result. Select the action that reduces the vulnerability reachability risk the most from the selection results as the target action.
10. The intelligent repair and protection method for power industrial control terminals based on vulnerability scanning according to claim 9, characterized in that, If all candidate repair and protection actions meet the preset conditions, the automatic repair execution will be terminated, and enhanced monitoring rules and manual review work orders will be output. The preset conditions are: the reduction in vulnerability reachability risk after each candidate remediation and protection action is equal to 0, or, except for patch upgrade actions that satisfy the requirement that the disturbance level does not exceed the allowable value, the disturbance level of normal business communication of the remaining candidate remediation and protection actions with a reduction in vulnerability reachability risk greater than 0 is greater than 0.