Industrial Internet device condition monitoring methods, systems, equipment and media

CN122741561APending Publication Date: 2026-09-11NANJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611089179.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-22
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0005]本发明针对现有技术中的不足,提供一种工业互联网设备状态监测方法、系统、设备和介质,解决现有技术中主动探测可能影响工业控制设备稳定性、单模态特征难以捕获隐蔽逻辑异常、简单特征拼接不能表达时序与空间逻辑的深层关联、动态工况下误报率高以及复杂模型难以在低功耗边缘网关部署的技术问题

Benefits of technology

本发明在不向工业控制网络注入主动探测报文的条件下,基于工业通信时序统计指纹、协议逻辑转移热力图指纹、跨模态自注意力融合和信息熵自适应集成学习,对工业互联网设备运行状态进行在线监测、攻击识别与早期衰退判定。准确捕获隐蔽逻辑异常,动态工况下误报率低,提高工业控制设备的稳定性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122741561A_ABST
    Figure CN122741561A_ABST
Patent Text Reader

Abstract

This invention discloses a method, system, device, and medium for industrial internet device status monitoring. The method includes: capturing data frames from an industrial control network to form an initial window frame set; calculating a five-tuple session identifier for each data frame in the set to reconstruct the device communication session stream; performing sample cleaning on the reconstructed device communication session stream to obtain cleaned time window samples; extracting original statistical feature vectors based on the time window samples to construct a one-dimensional temporal statistical fingerprint; calculating state transition frequency and transition probability based on the function code sequence in the time window samples to construct a two-dimensional protocol logic heatmap; generating a composite state fingerprint based on the one-dimensional temporal statistical fingerprint and the two-dimensional protocol logic heatmap; inputting the composite state fingerprint into multiple heterogeneous base classifiers to obtain the probability of each state category; and calculating the operating status of the industrial internet device based on the probability of each state category. This invention improves the accuracy of device status monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of industrial internet security monitoring, industrial control equipment health management, edge artificial intelligence and anomaly detection technology, and specifically to an industrial internet equipment status monitoring method, system, device and medium. Background Technology

[0002] In industrial internet scenarios, programmable logic controllers (PLCs), remote terminal units, industrial sensors, actuators, and host computers typically operate on highly deterministic, periodic control communication over extended periods. Existing status monitoring solutions generally fall into three categories: the first uses physical sensors such as vibration, temperature, and current sensors for threshold alarms or frequency domain diagnostics; the second obtains equipment online status through active scanning, liveness detection messages, or asset identification tools; and the third extracts single-dimensional features such as packet length, message arrival time intervals, and protocol function codes from industrial network traffic or logs, and then uses traditional classifiers or isolated forests for anomaly detection.

[0003] While the aforementioned solutions can detect some obvious faults in controlled experimental environments, they still have the following drawbacks when facing highly dynamic, strongly coupled, and aging equipment in industrial settings. First, physical sensing solutions require additional wiring and downtime for modifications, and are insensitive to malicious control logic carried by legitimate protocols, often only triggering alarms after physical consequences occur. Second, active probing injects additional traffic into the control network; aging controllers or devices with vulnerable protocol stacks may crash or restart due to non-standard requests, high-frequency requests, or buffer overflows, disrupting production continuity. Third, single network statistical features are insufficient to distinguish between "malicious logic switching under normal cycles" and "ordinary network jitter under abnormal timing," resulting in a high false negative rate for advanced persistent threats and early slow decay. Fourth, existing multi-source fusion methods typically remain at the level of vector splicing or manual weighting, failing to utilize the spatial transfer structure of protocol operation sequences or dynamically adjust the confidence contributions of different models based on current operating conditions. Fifth, sudden broadcast storms, batch equipment start-ups and shutdowns, and operating condition switching in industrial settings can lead to non-stationary noise, making the decision boundaries of a single model prone to failure and generating massive false alarms.

[0004] Therefore, there is an urgent need for an industrial internet device condition monitoring solution that simultaneously satisfies zero-intrusion data acquisition, interpretable protocol logic modeling, deep cross-modal fusion, lightweight edge deployment, and dynamic robust decision-making. Summary of the Invention

[0005] This invention addresses the shortcomings of existing technologies by providing an industrial internet device status monitoring method, system, device, and medium. It solves the technical problems in existing technologies, such as the potential impact of active detection on the stability of industrial control equipment, the difficulty of capturing hidden logical anomalies with single-modal features, the inability of simple feature splicing to express the deep correlation between temporal and spatial logic, the high false alarm rate under dynamic operating conditions, and the difficulty of deploying complex models on low-power edge gateways.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] An industrial internet device status monitoring method includes the following steps: Capture data frames from the industrial control network and form a set of original window frames according to a preset time window; For each data frame in the original window frame set, calculate the five-tuple session identifier, reassemble the device communication session stream according to the five-tuple session identifier, and perform sample cleaning on the reassembled device communication session stream to obtain the cleaned time window sample. The original statistical feature vector is extracted from the time window samples, and the original statistical feature vector is standardized to construct a one-dimensional time series statistical fingerprint; The state transition frequency and transition probability are calculated based on the function code sequence in the time window sample, and a two-dimensional protocol logic heatmap is constructed. Generate composite state fingerprints based on one-dimensional time-series statistical fingerprints and two-dimensional protocol logic heatmaps; Using composite state fingerprints as input, the probability of each state category is obtained through multiple heterogeneous base classifiers; Information entropy, dynamic weights, and comprehensive scores are calculated based on the probabilities of each state category, and the operating status of industrial internet devices is output through weighted soft voting.

[0008] To optimize the above technical solution, the specific measures also include: Furthermore, the five-tuple session identifier includes the source address, destination address, source port, destination port, and transport layer protocol; The sample cleaning includes removing pure confirmation frames, retransmission frames, and outlier jitter frames. The method for determining outlier jitter frames is as follows: If a data frame satisfies the following formula, then the data frame is considered an outlier jitter frame and is discarded:

[0009] In the formula, It is the time interval for the arrival of the u-th data frame. and These are the mean and standard deviation of the arrival time interval of data frames within the t-th time window, respectively.

[0010] Furthermore, the extraction of the original statistical feature vector based on time window samples specifically involves: Extracting time window samples S t The statistical characteristics of the message arrival time interval sequence, payload length sequence, communication direction, abnormal response, and retransmission behavior are calculated to obtain the original statistical feature vector. Expressed as:

[0011] In the formula, , , and These represent the mean, standard deviation, skewness, and kurtosis of the time interval between message arrivals, respectively. , , and These represent the mean, standard deviation, skewness, and kurtosis of the effective payload length, respectively. Indicates the peak frequency of traffic within the window. Indicates the direction switching rate. Indicates the proportion of abnormal responses. Indicates the retransmission ratio; The standardization of the original statistical feature vector to construct a one-dimensional time-series statistical fingerprint specifically involves: set up r For feature dimension index, for The r One-dimensional component, standardized one-dimensional time series statistical fingerprint X t The rth dimension for:

[0012] In the formula, and These are the calibration mean and calibration standard deviation of the r-th dimension feature in the historical stable samples, respectively. To prevent smooth terms with a denominator of zero; Each feature component is standardized to obtain a standardized one-dimensional time-series statistical fingerprint X. t .

[0013] Furthermore, the calculation of state transition frequency and transition probability based on the function code sequence in the time window sample specifically involves: Extracting time window samples S t Function code sequence F in t ,set up This represents the total number of function code states. and For function code status index, For normalized summation index, The Laplace smoothing coefficient is... This is an indicator function; it takes the value 1 if the condition is true and 0 otherwise, determined by the function code sequence F. t Frequency of generated state transitions Defined as:

[0014] In the formula, This represents the number of function codes within the t-th time window. For the first function code in the sequence l Function codes; By state transition frequency Calculate the Markov transition probability from state i to state j within the t-th time window. :

[0015] The specific steps for constructing the two-dimensional protocol logic heatmap are as follows: Markov transition probability Mapped to grayscale pixel values, forming an N × N two-dimensional protocol logic heatmap G. t The pixel value in the i-th row and j-th column for:

[0016] In the formula, This represents the rounding function.

[0017] Furthermore, the method of generating composite state fingerprints based on one-dimensional time-series statistical fingerprints and two-dimensional protocol logic heatmaps... Specifically: One-dimensional time-series statistical fingerprint X t Input cyclic encoder, set For the parameters of the loop encoder, the hidden state output by the loop encoder is:

[0018] In the formula, This is the hidden state of the cyclic encoder output. It is a cyclic encoder; The query matrix is ​​obtained based on the hidden state. The formula is as follows:

[0019] In the formula, It is the query mapping weight. It is a query mapping bias; The two-dimensional protocol logic heatmap G tThe input is a depthwise separable convolution, which includes at least one depthwise convolution and at least one pointwise convolution. set up The number of depthwise separable convolution channels. For depthwise separable convolution channel indexes, To output channel indices for pointwise convolution, Then the first Each depth-separable convolution output for:

[0020] In the formula, A two-dimensional protocol logic heatmap of the k-th channel of an input depthwise separable convolution. For the first Each depthwise convolutional kernel weight; No. Pointwise convolutional response for:

[0021] In the formula, For pointwise convolution weights; Each pointwise convolutional response forms a convolutional branch feature map R, and mapping the convolutional branch feature map R yields the key matrix. Sum matrix :

[0022]

[0023] In the formula, These are the weights and biases of the key mapping, respectively. These are the weights and biases of the value mapping, respectively; Cross-modal self-attention output for:

[0024] In the formula, For normalized exponential functions, The dimensions of the query and key matrix; Composite state fingerprints are generated based on one-dimensional temporal statistical fingerprints and cross-modal self-attention outputs. as follows:

[0025] In the formula, To batch the normalization operator, and These represent the weights and biases of the fully connected dimensionality reduction layer. A statistical summary mapping for one-dimensional time-series statistical fingerprints; The recurrent encoder and depthwise separable convolution were deployed on the edge side for model quantization before use.

[0026] Furthermore, the heterogeneous base classifier includes at least a random forest classifier, a support vector machine classifier, and a multilayer perceptron classifier; The heterogeneous base classifier was deployed on the edge side for model quantization before use; The random forest classifier is used to determine the state of temporal distortions, the support vector machine classifier is used to determine the state of protocol logic texture anomalies, and the multilayer perceptron classifier is used to determine the state of high-dimensional composite fingerprint boundaries. Composite fingerprint Parallel input The heterogeneous base classifier, the first The base classifier outputs the first... Probability of class state ; The calculation of information entropy, dynamic weight, and comprehensive score based on the probability of each state category is specifically as follows: Information entropy of the output distribution of the m-th base classifier for:

[0027] In the formula, It is the total number of state categories. It is to prevent Smoothing terms that are 0; Calculate dynamic weights based on information entropy:

[0028] In the formula, These are the dynamic weights of the m-th base classifier. The classifier traverses the index in the weighted normalization summation; The overall score is calculated as follows:

[0029] In the formula, The overall score for state c; Final state category Choose the category with the highest overall score.

[0030] Furthermore, the method also includes: If the final running state corresponding to the current preset time window is determined to be normal, and the cleaned time window sample S of the current preset time window... t The generated composite state fingerprint With historical stable baseline parameter set The distance between the two Maslow's drift Below the preset drift threshold At that time, Add sliding baseline cache and only update ; The mean vector of the historical stable baseline. The covariance matrix of the historical stable baseline; when Exceed At that time, only alarms or manual confirmation are triggered, and the model parameters of the recurrent encoder, depthwise separable convolution, and heterogeneous base classifier are not automatically updated.

[0031] This invention also proposes an industrial internet equipment status monitoring system, comprising: The data acquisition module is used to capture data frames from the industrial control network and form an original window frame set according to a preset time window. It calculates a five-tuple session identifier for each data frame in the original window frame set, reassembles the device communication session stream according to the five-tuple session identifier, and performs sample cleaning on the reassembled device communication session stream to obtain a cleaned time window sample. The feature extraction module is used to extract the original statistical feature vector based on the time window samples, and to standardize the original statistical feature vector to construct a one-dimensional time-series statistical fingerprint; it calculates the state transition frequency and transition probability based on the function code sequence in the time window samples, and constructs a two-dimensional protocol logic heatmap; A cross-modal self-attention fusion module is used to generate composite state fingerprints based on one-dimensional temporal statistical fingerprints and two-dimensional protocol logic heatmaps; An integrated decision module is used to obtain the probability of each state category by taking the composite state fingerprint as input and passing it through multiple heterogeneous base classifiers; based on the probability of each state category, information entropy, dynamic weights and comprehensive scores are calculated, and the operating status of industrial Internet devices is output through weighted soft voting.

[0032] The present invention also proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the industrial internet device status monitoring method as described above.

[0033] The present invention also proposes a computer-readable storage medium storing a computer program that enables a computer to execute the industrial internet device status monitoring method described above.

[0034] The beneficial effects of this invention are: This invention, without injecting active probe messages into the industrial control network, utilizes industrial communication time-series statistical fingerprinting, protocol logic transfer heatmap fingerprinting, cross-modal self-attention fusion, and information entropy adaptive ensemble learning to perform online monitoring, attack identification, and early degradation determination of industrial Internet device operating status. It accurately captures hidden logic anomalies, has a low false alarm rate under dynamic operating conditions, and improves the stability of industrial control equipment.

[0035] The effectiveness of this invention is achieved through the synergistic effect of five technical features: "zero-intrusion acquisition, dual-modal protocol fingerprinting, cross-modal attention, edge quantization, and entropy-weighted integration." The front end eliminates active disturbances, the middle end improves the separability of minor logical anomalies, and the back end suppresses the contribution of unreliable classifiers in real time according to the working conditions, thereby simultaneously solving the problems of security, accuracy, robustness, and deployment cost. Attached Figure Description

[0036] Figure 1 This is a flowchart of the industrial internet equipment status monitoring method proposed in this invention.

[0037] Figure 2 This is a schematic diagram of dual-modal device fingerprint construction and cross-modal self-attention fusion.

[0038] Figure 3 This is a schematic diagram of heterogeneous integration decision based on adaptive weighted information entropy.

[0039] Figure 4 This is a block diagram of an industrial internet equipment condition monitoring system. Detailed Implementation

[0040] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0041] Example 1 This embodiment employs a fully bypassed physical isolation architecture. The industrial control layer includes multiple PLCs, remote I / O, industrial sensors, and a host computer. The devices are connected to a managed industrial switch via an industrial Ethernet network. The switch's ordinary ports are used for production control communication, while the mirror port, Port 24, is configured as an observation port to replicate bidirectional communication from a specified VLAN or port to the edge monitoring gateway.

[0042] The edge monitoring gateway uses a quad-core ARM Cortex-A55 or equivalent low-power processor, with at least 2GB of memory, and includes at least two physical network ports: eth0 and eth1. eth0 connects to the switch's mirror port and operates in promiscuous receive mode, without being configured with a routable transmit address for the control network. eth1 connects to a dedicated IT operations and maintenance management network, sending data only during alarms, log synchronization, or model version management. This connection ensures that no active probe packets are injected into the PLC or host computer during the monitoring process.

[0043] This invention proposes a method for monitoring the status of industrial internet devices. The process of the method is as follows: Figure 1 As shown, it includes the following steps: S1. Capture data frames from the industrial control network and form a set of original window frames according to a preset time window. ;

[0044] In the formula, Let U be the u-th mirrored data frame, and T be the preset time window length. It is the starting time of the t-th time window; For each data frame in the original window frame set, calculate the 5-tuple session identifier, which includes the source address. Destination address Source port Destination port and transport layer protocols The 5-tuple session identifier is defined as:

[0045] In the formula, It is a 5-tuple session identifier, and Hash(·) is a deterministic hash function.

[0046] The device communication session stream is reassembled based on the five-tuple session identifier, and the reassembled device communication session stream is sample-cleaned while maintaining the temporal order of the remaining data frames to obtain a cleaned time window sample. The sample cleaning includes removing pure acknowledgment frames, retransmission frames, and outlier jitter frames. The method for determining outlier jitter frames is as follows: If a data frame satisfies the following formula, then the data frame is considered an outlier jitter frame and is discarded:

[0047] In the formula, It is the time interval for the arrival of the u-th data frame. and These are the mean and standard deviation of the arrival time interval of data frames within the t-th time window, respectively.

[0048] Samples within the time window after cleaning In this context, application layer industrial protocol features must include a function code sequence. .set up For the first function code in the sequence Function codes, For the first The number of function codes within a time window, then:

[0049] The process of dual-modal device fingerprint construction and cross-modal self-attention fusion is as follows: Figure 2 This includes the following steps S2 to S4.

[0050] S2. Extract the original statistical feature vector based on the time window sample, and standardize the original statistical feature vector to construct a one-dimensional time series statistical fingerprint.

[0051] The extraction of the original statistical feature vector based on time window samples is specifically as follows: Extracting time window samples S t The statistical characteristics of the message arrival time interval sequence, payload length sequence, communication direction, abnormal response, and retransmission behavior are calculated to obtain the original statistical feature vector. Expressed as:

[0052] In the formula, , , and These represent the mean, standard deviation, skewness, and kurtosis of the time interval between message arrivals, respectively. , , and These represent the mean, standard deviation, skewness, and kurtosis of the effective payload length, respectively. Indicates the peak frequency of traffic within the window. Indicates the direction switching rate. Indicates the proportion of abnormal responses. Indicates the retransmission ratio.

[0053] The standardization of the original statistical feature vectors to construct a one-dimensional time-series statistical fingerprint is as follows: set up r For feature dimension index, for The r One-dimensional component, standardized one-dimensional time series statistical fingerprint X t The rth dimension for:

[0054] In the formula, and These are the calibration mean and calibration standard deviation of the r-th dimension feature in the historical stable samples, respectively. To prevent smooth terms with a denominator of zero; Each feature component is standardized to obtain a standardized one-dimensional time-series statistical fingerprint X. t .

[0055] S3. Calculate the state transition frequency and transition probability based on the function code sequence in the time window sample, and construct a two-dimensional protocol logic heatmap; The specific steps for calculating the state transition frequency and transition probability based on the function code sequence in the time window sample are as follows: Extracting time window samples S t Function code sequence F in t ,set up This represents the total number of function code states. and For function code status index, For normalized summation index, The Laplace smoothing coefficient is... This is an indicator function; it takes the value 1 if the condition is true and 0 otherwise, determined by the function code sequence F. t Frequency of generated state transitions Defined as:

[0056] In the formula, This represents the number of function codes within the t-th time window. For the first function code in the sequence l Function codes; By state transition frequency Calculate the Markov transition probability from state i to state j within the t-th time window. :

[0057] The specific steps for constructing a two-dimensional protocol logic heatmap are as follows: Markov transition probability Mapped to grayscale pixel values, forming an N × N two-dimensional protocol logic heatmap G. t The pixel value in the i-th row and j-th column for:

[0058] In the formula, This represents the rounding function.

[0059] S4. Generate composite state fingerprints based on one-dimensional time-series statistical fingerprints and two-dimensional protocol logic heatmaps; Generate composite state fingerprints based on one-dimensional time-series statistical fingerprints and two-dimensional protocol logic heatmaps. Specifically: One-dimensional time-series statistical fingerprint X t Input cyclic encoder, set For the parameters of the loop encoder, the hidden state output by the loop encoder is:

[0060] In the formula, This is the hidden state of the cyclic encoder output. It is a cyclic encoder; in scenarios where computing power is more limited, the cyclic encoder can be replaced by a one-dimensional convolution or gated cyclic unit.

[0061] The query matrix is ​​obtained based on the hidden state. The formula is as follows:

[0062] In the formula, It is the query mapping weight. It is a query mapping bias; The two-dimensional protocol logic heatmap G t The input is a depthwise separable convolution, which includes at least one depthwise convolution and at least one pointwise convolution. In scenarios with more limited computing power, the depthwise separable convolution can be replaced by the low-rank attention module of the lightweight visual Transformer.

[0063] set up The number of depthwise separable convolution channels. For depthwise separable convolution channel indexes, To output channel indices for pointwise convolution, Then the first Each depth-separable convolution output for:

[0064] In the formula, A two-dimensional protocol logic heatmap of the k-th channel of an input depthwise separable convolution. For the first Each depthwise convolutional kernel weight; No. Pointwise convolutional response for:

[0065] In the formula, For pointwise convolution weights; Each pointwise convolutional response forms a convolutional branch feature map R, and mapping the convolutional branch feature map R yields the key matrix. Sum matrix :

[0066]

[0067] In the formula, These are the weights and biases of the key mapping, respectively. These are the weights and biases of the value mapping, respectively; Cross-modal self-attention output for:

[0068] In the formula, For normalized exponential functions, The dimensions of the query and key matrix; Composite state fingerprints are generated based on one-dimensional temporal statistical fingerprints and cross-modal self-attention outputs. as follows:

[0069] In the formula, To batch the normalization operator, and These represent the weights and biases of the fully connected dimensionality reduction layer. A statistical summary mapping for one-dimensional time-series statistical fingerprints; The recurrent encoder and depthwise separable convolution were deployed on the edge side for model quantization before use.

[0070] Information entropy adaptive weighted heterogeneous integration decision such as Figure 3 This includes the following steps S5 and S6.

[0071] S5. Using the composite state fingerprint as input, obtain the probability of each state category through multiple heterogeneous base classifiers; the heterogeneous base classifiers include at least a random forest classifier, a support vector machine classifier, and a multilayer perceptron classifier. The heterogeneous base classifier was deployed on the edge side for model quantization before use; The random forest classifier is used to determine the state of temporal distortions, the support vector machine classifier is used to determine the state of protocol logic texture anomalies, and the multilayer perceptron classifier is used to determine the state of high-dimensional composite fingerprint boundaries. Composite fingerprint Parallel input The heterogeneous base classifier, the first The base classifier outputs the first... Probability of class state ; S6. Calculate information entropy, dynamic weight and comprehensive score based on the probability of each state category, and output the operating status of industrial Internet equipment through weighted soft voting.

[0072] The information entropy, dynamic weights, and comprehensive scores are calculated based on the probabilities of each state category as follows: Information entropy of the output distribution of the m-th base classifier for:

[0073] In the formula, It is the total number of state categories. It is to prevent Smoothing terms that are 0; Calculate dynamic weights based on information entropy:

[0074] In the formula, These are the dynamic weights of the m-th base classifier. The classifier traverses the index in the weighted normalization summation; The overall score is calculated as follows:

[0075] In the formula, The overall score for state c; Final state category Choose the category with the highest overall score.

[0076] The method in this embodiment also includes: Complex models are difficult to deploy on low-power edge gateways. Therefore, the INT8 model is quantized by the recurrent encoder and depthwise separable convolution in step S4 and the heterogeneous base classifier in step S5 to achieve lightweight edge deployment.

[0077] INT8 model quantization specifically involves quantizing the model's weight tensor and activation tensor. This represents the weight tensor to be quantized. This represents the activation tensor to be quantized. Let be the quantization scaling factor and the INT8 quantization value of the weight tensor, respectively.

[0078] set up , Let be the quantization scaling factor and the INT8 quantization value of the activation tensor, respectively.

[0079] set up This is the result of an integer matrix multiplication. To obtain an approximate real-value output after dequantization, the quantization inference process is as follows:

[0080] In the formula, It is the quantized weight tensor. It is the quantized activation tensor.

[0081] If the final running state corresponding to the current preset time window is determined to be normal, and the cleaned time window sample S of the current preset time window... t The generated composite state fingerprint With historical stable baseline parameter set The distance between the two Maslow's drift Below the preset drift threshold At that time, Add sliding baseline cache and only update ; The mean vector of the historical stable baseline. The covariance matrix of the historical stable baseline; when Exceed At that time, only alarms or manual confirmation are triggered, and the model parameters of the recurrent encoder, depthwise separable convolution, and heterogeneous base classifier are not automatically updated.

[0082] Mahal drift distance The calculation formula is as follows:

[0083] Example 2 This invention proposes an industrial internet device status monitoring system corresponding to the method in Embodiment 1, such as... Figure 4 As shown, it includes: The data acquisition module is used to capture data frames from the industrial control network and form an original window frame set according to a preset time window. It calculates a five-tuple session identifier for each data frame in the original window frame set, reassembles the device communication session stream according to the five-tuple session identifier, and performs sample cleaning on the reassembled device communication session stream to obtain a cleaned time window sample. The feature extraction module is used to extract the original statistical feature vector based on the time window samples, and to standardize the original statistical feature vector to construct a one-dimensional time-series statistical fingerprint; it calculates the state transition frequency and transition probability based on the function code sequence in the time window samples, and constructs a two-dimensional protocol logic heatmap; A cross-modal self-attention fusion module is used to generate composite state fingerprints based on one-dimensional temporal statistical fingerprints and two-dimensional protocol logic heatmaps; An integrated decision module is used to obtain the probability of each state category by taking the composite state fingerprint as input and passing it through multiple heterogeneous base classifiers; based on the probability of each state category, information entropy, dynamic weights and comprehensive scores are calculated, and the operating status of industrial Internet devices is output through weighted soft voting.

[0084] The implementation methods of each module and its function in the system are completely consistent with the steps of the method in Implementation Example 1, so they will not be repeated here.

[0085] Example 3 This invention proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the industrial internet device status monitoring method as described in Embodiment 1.

[0086] Example 4 This invention proposes a computer-readable storage medium storing a computer program that causes a computer to execute the industrial internet device status monitoring method as described in Embodiment 1.

[0087] The effects of the present invention are illustrated below using experimental data from the present invention and comparative examples.

[0088] Comparative Example 1 uses an active liveness detection method to periodically scan the PLC, only uses the network layer time-series statistical features, and performs hard decision-making using an isolated forest; Comparative Example 2 uses passive data collection but does not construct a Markov heatmap, and only performs one-dimensional feature stitching; Comparative Example 3 constructs bimodal features but uses fixed average voting and does not calculate information entropy dynamic weights.

[0089] 120 hours of continuous operation data were collected in a test network consisting of 60 S7-1200 PLCs, industrial temperature and humidity sensors, and a host computer. At the 50th hour, 1000 forged Modbus register tampering instructions were injected, along with 2Gbps of invalid broadcast messages to simulate a sudden broadcast storm. The experimental results are shown in the table below.

[0090]

[0091] As shown in the table above, this invention maintains the downtime rate of the monitored PLC at 0% through bypass mirroring and unidirectional acquisition; reduces the false alarm rate of hidden logic tampering to 0.4% through Markov heatmap and cross-modal attention fusion; controls the false alarm rate to 1.1% under broadcast storms and network jitter through information entropy adaptive weighting; and achieves a single inference latency of 45 ms, model memory of approximately 3.8 MB, and peak power consumption of approximately 1.2 W on the edge side through INT8 quantization, meeting the requirements for low-power edge deployment in industrial settings.

[0092] In the embodiments disclosed in this application, a computer storage medium may be a tangible medium that may contain or store programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of computer storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, and portable compact disc read-only memory (CD). ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0093] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0094] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A method for monitoring the status of industrial internet devices, characterized in that, Includes the following steps: Capture data frames from the industrial control network and form a set of original window frames according to a preset time window; For each data frame in the original window frame set, calculate the five-tuple session identifier, reassemble the device communication session stream according to the five-tuple session identifier, and perform sample cleaning on the reassembled device communication session stream to obtain the cleaned time window sample. The original statistical feature vector is extracted from the time window samples, and the original statistical feature vector is standardized to construct a one-dimensional time series statistical fingerprint; The state transition frequency and transition probability are calculated based on the function code sequence in the time window sample, and a two-dimensional protocol logic heatmap is constructed. Generate composite state fingerprints based on one-dimensional time-series statistical fingerprints and two-dimensional protocol logic heatmaps; Using composite state fingerprints as input, the probability of each state category is obtained through multiple heterogeneous base classifiers; Information entropy, dynamic weights, and comprehensive scores are calculated based on the probabilities of each state category, and the operating status of industrial internet devices is output through weighted soft voting.

2. The industrial internet equipment status monitoring method as described in claim 1, characterized in that, The five-tuple session identifier includes the source address, destination address, source port, destination port, and transport layer protocol; The sample cleaning includes removing pure confirmation frames, retransmission frames, and outlier jitter frames. The method for determining outlier jitter frames is as follows: If a data frame satisfies the following formula, then the data frame is considered an outlier jitter frame and is discarded: In the formula, It is the time interval for the arrival of the u-th data frame. and These are the mean and standard deviation of the arrival time interval of data frames within the t-th time window, respectively.

3. The industrial internet device status monitoring method as described in claim 1, characterized in that, The extraction of the original statistical feature vector based on time window samples specifically involves: Extracting time window samples S t The statistical characteristics of the message arrival time interval sequence, payload length sequence, communication direction, abnormal response, and retransmission behavior are calculated to obtain the original statistical feature vector. Expressed as: In the formula, , , and These represent the mean, standard deviation, skewness, and kurtosis of the time interval between message arrivals, respectively. , , and These represent the mean, standard deviation, skewness, and kurtosis of the effective payload length, respectively. Indicates the peak frequency of traffic within the window. Indicates the direction switching rate. Indicates the proportion of abnormal responses. Indicates the retransmission ratio; The standardization of the original statistical feature vector to construct a one-dimensional time-series statistical fingerprint specifically involves: set up r For feature dimension index, for The r One-dimensional component, standardized one-dimensional time series statistical fingerprint X t The rth dimension for: In the formula, and These are the calibration mean and calibration standard deviation of the r-th dimension feature in the historical stable samples, respectively. To prevent smooth terms with a denominator of zero; Each feature component is standardized to obtain a standardized one-dimensional time-series statistical fingerprint X. t .

4. The industrial internet device status monitoring method as described in claim 1, characterized in that, The calculation of state transition frequency and transition probability based on the function code sequence in the time window sample is specifically as follows: Extracting time window samples S t Function code sequence F in t ,set up This represents the total number of function code states. and For function code status index, For normalized summation index, The Laplace smoothing coefficient is... This is an indicator function; it takes the value 1 if the condition is true and 0 otherwise, determined by the function code sequence F. t Frequency of generated state transitions Defined as: In the formula, This represents the number of function codes within the t-th time window. For the first function code in the sequence l Function codes; By state transition frequency Calculate the Markov transition probability from state i to state j within the t-th time window. : The specific steps for constructing the two-dimensional protocol logic heatmap are as follows: Markov transition probability Mapped to grayscale pixel values, forming an N × N two-dimensional protocol logic heatmap G. t The pixel value in the i-th row and j-th column for: In the formula, This represents the rounding function.

5. The industrial internet device status monitoring method as described in claim 1, characterized in that, The specific steps for generating composite state fingerprints based on one-dimensional temporal statistical fingerprints and two-dimensional protocol logic heatmaps are as follows: One-dimensional time-series statistical fingerprint X t Input cyclic encoder, set For the parameters of the loop encoder, the hidden state output by the loop encoder is: In the formula, This is the hidden state of the cyclic encoder output. It is a cyclic encoder; The query matrix is ​​obtained based on the hidden state. The formula is as follows: In the formula, It is the query mapping weight. It is a query mapping bias; The two-dimensional protocol logic heatmap G t The input is a depthwise separable convolution, which includes at least one depthwise convolution and at least one pointwise convolution. set up The number of depthwise separable convolution channels. For depthwise separable convolution channel indexes, To output channel indices for pointwise convolution, Then the first Each depth-separable convolution output for: In the formula, A two-dimensional protocol logic heatmap of the k-th channel of an input depthwise separable convolution. For the first Each depthwise convolutional kernel weight; No. Pointwise convolutional response for: In the formula, For pointwise convolution weights; Each pointwise convolutional response forms a convolutional branch feature map R, and mapping the convolutional branch feature map R yields the key matrix. Sum matrix : In the formula, These are the weights and biases of the key mapping, respectively. These are the weights and biases of the value mapping, respectively; Cross-modal self-attention output for: In the formula, For normalized exponential functions, The dimensions of the query and key matrix; Composite state fingerprints are generated based on one-dimensional temporal statistical fingerprints and cross-modal self-attention outputs. as follows: In the formula, To batch the normalization operator, and These are the weights and biases of the fully connected dimensionality reduction layer, respectively. A statistical summary mapping for one-dimensional time-series statistical fingerprints; The recurrent encoder and depthwise separable convolution were deployed on the edge side for model quantization before use.

6. The industrial internet device status monitoring method as described in claim 5, characterized in that, The heterogeneous base classifier includes at least a random forest classifier, a support vector machine classifier, and a multilayer perceptron classifier; The heterogeneous base classifier was deployed on the edge side for model quantization before use; The random forest classifier is used to determine the state of temporal distortions, the support vector machine classifier is used to determine the state of protocol logic texture anomalies, and the multilayer perceptron classifier is used to determine the state of high-dimensional composite fingerprint boundaries. Composite fingerprint Parallel input The heterogeneous base classifier, the first The base classifier outputs the first... Probability of class state ; The calculation of information entropy, dynamic weight, and comprehensive score based on the probability of each state category is specifically as follows: Information entropy of the output distribution of the m-th base classifier for: In the formula, It is the total number of state categories. It is to prevent Smoothing terms that are 0; Calculate dynamic weights based on information entropy: In the formula, These are the dynamic weights of the m-th base classifier. The classifier traverses the index in the weighted normalization summation; To prevent smooth terms with a denominator of zero; The overall score is calculated as follows: In the formula, The overall score for state c; Final state category Choose the category with the highest overall score.

7. The industrial internet device status monitoring method as described in claim 6, characterized in that, The method further includes: If the final running state corresponding to the current preset time window is determined to be normal, and the cleaned time window sample S of the current preset time window... t The generated composite state fingerprint With historical stable baseline parameter set The distance between the two Maslow's drift Below the preset drift threshold At that time, Add sliding baseline cache and only update ; The mean vector of the historical stable baseline. The covariance matrix of the historical stable baseline; when Exceed At that time, only alarms or manual confirmation are triggered, and the model parameters of the recurrent encoder, depthwise separable convolution, and heterogeneous base classifier are not automatically updated.

8. An industrial internet equipment status monitoring system, characterized in that, include: The data acquisition module is used to capture data frames from the industrial control network and form a set of raw window frames according to a preset time window. For each data frame in the original window frame set, calculate the five-tuple session identifier, reassemble the device communication session stream according to the five-tuple session identifier, and perform sample cleaning on the reassembled device communication session stream to obtain the cleaned time window sample. The feature extraction module is used to extract the original statistical feature vector based on the time window samples, and to standardize the original statistical feature vector to construct a one-dimensional time series statistical fingerprint; The state transition frequency and transition probability are calculated based on the function code sequence in the time window sample, and a two-dimensional protocol logic heatmap is constructed. A cross-modal self-attention fusion module is used to generate composite state fingerprints based on one-dimensional temporal statistical fingerprints and two-dimensional protocol logic heatmaps; An integrated decision module is used to obtain the probability of each state category by taking the composite state fingerprint as input and passing it through multiple heterogeneous base classifiers. Information entropy, dynamic weights, and comprehensive scores are calculated based on the probabilities of each state category, and the operating status of industrial internet devices is output through weighted soft voting.

9. An electronic device, characterized in that, include: The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the industrial internet device status monitoring method as described in any one of claims 1-7.

10. A computer-readable storage medium storing a computer program, characterized in that, The computer program causes the computer to execute the industrial internet device status monitoring method as described in any one of claims 1-7.