A cloud edge collaboration-based distributed industrial big data security intelligent analysis and risk early warning system

CN122802232APending Publication Date: 2026-09-22JIUYILI DIGITAL TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611025205.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-10
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0005]本发明的目的在于提供一种基于云边协同的分布式工业大数据安全智能分析与风险预警系统,以解决上述背景技术中提出的现有全局风险传播推演依赖固定拓扑耦合关系、无法适配设备工况动态波动下的传导特性变化,以及风险演化分析未区分多类型传播路径时延差异、风险扩散态势预判精度不足的问题

Benefits of technology

1.本发明采用基于设备工况的动态耦合强度计算技术,以节点实时负荷率测算耦合关系有效系数,对基础拓扑耦合强度进行逐对有效性修正,生成随设备运行状态动态更新的耦合强度矩阵,摆脱了传统方案依赖固定拓扑关联的推演局限,使风险传导特性的刻画与工业现场实际运行状态高度契合,有效提升全局风险演化研判的客观准确性;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802232A_ABST
    Figure CN122802232A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of industrial big data analysis, and in particular to a distributed industrial big data security intelligent analysis and risk early warning system based on cloud edge collaboration. It comprises: an edge data acquisition and security preprocessing unit; a security analysis and local early warning unit; a cloud edge collaborative management and security interaction unit; a global industrial big data security intelligent analysis unit; a global risk grading early warning and collaborative disposal unit. The present application adopts a dynamic coupling strength calculation technology based on equipment working conditions to correct the topological coupling strength with the node real-time load rate, generate a dynamic coupling matrix, and break away from the deduction limitations of traditional schemes relying on fixed topological association. At the same time, the present application adopts a type-based time delay matching and hidden state evolution deduction technology with time delay constraints to distinguish the two types of propagation path time delay differences for recursive evolution, accurately predict the risk situation, and effectively improve the global risk judgment accuracy and early warning foresight.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial big data analytics, and more specifically, to a distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration. Background Technology

[0002] The Industrial Internet industry is currently entering a stage of large-scale implementation, and cloud-edge collaborative architecture has become the mainstream deployment form for industrial big data security protection. It is widely used in process industries, discrete manufacturing, and other scenarios, undertaking core functions such as equipment operation monitoring, network security situation awareness, and risk warning. As the scale of networked devices in industrial fields continues to expand, cross-node global risk evolution assessment technology has become a core necessity for industrial security protection systems.

[0003] Currently, two types of technical solutions have been developed for large-scale application in the industry. One type is a centralized cloud-based risk analysis system based on fixed topology associations. This system establishes node relationships based on the industrial network topology and conducts centralized risk assessment on all backhauled data. Its advantages include strong global coverage and a mature deployment architecture, and it has been widely used in large industrial parks. The other type is a global situational awareness aggregation system based on the superposition of anomalies in single nodes. This system aggregates the independent detection results of each edge node to form a global security status. Its advantages include low engineering implementation threshold and strong reusability of single-node detection results, making it suitable for multi-node distributed deployment scenarios.

[0004] However, existing technical solutions still face common technical bottlenecks in engineering implementation. Firstly, current risk propagation simulations are mostly based on fixed topological coupling relationships, failing to dynamically adjust the risk transmission intensity according to real-time equipment operating conditions, and thus unable to adapt to changes in risk transmission characteristics under fluctuating equipment loads in industrial settings. Secondly, current risk evolution analyses often use uniform latency parameters, failing to distinguish the latency characteristics of network communication and process transmission—two different propagation paths—in industrial scenarios, resulting in insufficient accuracy in predicting the timing and scope of risk diffusion. These problems easily lead to risk evolution assessments deviating from actual on-site conditions and insufficient foresight in early warning, making it difficult to meet the upgraded demand for accurate risk early warning in complex industrial scenarios. Developing a new global risk analysis solution adapted to dynamic industrial operating conditions and latency differences has significant industrial value. Therefore, we propose a distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration. Summary of the Invention

[0005] The purpose of this invention is to provide a distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration, in order to solve the problems mentioned in the background technology, such as existing global risk propagation inference relying on fixed topological coupling relationships, inability to adapt to the changes in transmission characteristics under dynamic fluctuations in equipment operating conditions, and insufficient accuracy in risk evolution analysis in distinguishing the time delay differences of multiple types of propagation paths and predicting the risk diffusion situation.

[0006] To address the aforementioned technical problems, the present invention aims to provide a distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration, comprising: The edge data acquisition and security preprocessing unit acquires the operating data and network traffic data of multi-source heterogeneous equipment in the industrial field, and performs protocol adaptation parsing, data desensitization verification, format normalization and security screening on the raw industrial data to obtain a standardized edge security dataset. The security analysis and local early warning unit receives a standardized edge security dataset and cloud-based collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit. It performs lightweight anomaly detection, risk feature extraction, and local security handling on industrial data of single nodes and local areas, generating local risk early warning signals, edge analysis results, and local handling status information. The cloud-edge collaborative management and security interaction unit receives edge analysis results and local handling status information, receives cloud collaborative handling instructions generated by the global risk classification early warning and collaborative handling unit, and uses an encrypted transmission channel and a task dynamic scheduling mechanism to perform bidirectional data interaction processing between edge computing nodes and cloud nodes, outputs edge summary analysis data and handling status summary information, and sends cloud collaborative handling instructions to the edge side. The global industrial big data security intelligent analysis unit receives edge-collected analysis data and handling status summary information, and uses risk propagation hidden state inference technology that combines dynamic coupling of equipment operating conditions and time delay constraints to conduct security situation assessment and risk diffusion evolution processing on cross-node industrial data in the whole region, and obtains global security risk analysis results. The global risk classification, early warning and collaborative handling unit receives the global security risk analysis results, performs risk level mapping, early warning strategy matching and classification triggering processing on various security risks, and generates global risk early warning results and cloud-based collaborative handling instructions.

[0007] As a further improvement to this technical solution, the edge data acquisition and security preprocessing unit includes a multi-source heterogeneous data acquisition and access module and an edge data security preprocessing module, wherein: The multi-source heterogeneous data acquisition and access module collects and accesses raw industrial data based on the operating data and network traffic data of multi-source heterogeneous equipment in the industrial field, using protocol adaptation parsing and access verification technology. The edge data security preprocessing module uses the original industrial data from the multi-source heterogeneous data acquisition and access module to perform initial security screening using data desensitization verification and format normalization techniques, resulting in a standardized edge security dataset.

[0008] As a further improvement to this technical solution, the security analysis and local early warning unit includes a lightweight anomaly detection and feature extraction module and a local early warning and security handling execution module, wherein: The lightweight anomaly detection and feature extraction module is based on a standardized edge security dataset. It uses lightweight anomaly detection and risk feature extraction technology to analyze industrial data of single nodes and local areas to obtain edge analysis results. The local early warning and security handling execution module uses edge analysis results from the lightweight anomaly detection and feature extraction module and cloud-based collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit to determine the risk status and execute handling operations using local security handling and early warning triggering technology, generating local risk early warning signals and local handling status information.

[0009] As a further improvement to this technical solution, the cloud-edge collaborative management and security interaction unit includes an edge data aggregation and uplink scheduling module and a cloud command issuance and channel management module, wherein: The edge data aggregation and uplink scheduling module, based on the edge analysis results and local handling status information output by each security analysis and local early warning unit, adopts a task dynamic scheduling mechanism to aggregate, arrange and prioritize the transmission of data reported by multiple nodes, generate edge summary analysis data and handling status summary information, and completes uplink data transmission through an encrypted transmission channel. The cloud-based command issuance and channel control module, based on the cloud-based collaborative handling command generated by the global risk classification early warning and collaborative handling unit, uses an encrypted transmission channel and a dynamic task scheduling mechanism to perform target node matching and transmission timing scheduling of the command, and issues the cloud-based collaborative handling command to the corresponding security analysis and local early warning unit.

[0010] As a further improvement to this technical solution, the global industrial big data security intelligent analysis unit includes a multi-node anomaly feature spatiotemporal alignment module, a dynamic coupling strength calculation module, a risk propagation hidden state construction module, and a hidden state evolution deduction module, wherein: The multi-node anomaly feature spatiotemporal alignment module performs spatiotemporal standardization processing on multi-source data based on edge summary analysis data and handling status summary information, and outputs a spatiotemporally standardized cross-node dataset. The dynamic coupling strength calculation module is based on a spatiotemporally standardized cross-node dataset, which performs dynamic correction processing on the effectiveness of node coupling relationships to generate a dynamic coupling strength matrix. The risk propagation hidden state construction module performs categorized time delay matching and hidden state construction processing based on the dynamic coupling strength matrix and the node anomaly features in the spatiotemporally standardized cross-node dataset to generate an initial risk propagation hidden state vector. The hidden state evolution deduction module performs multi-variable joint hidden state recursive evolution processing based on the initial risk propagation hidden state vector and the summary information of the disposal status, and obtains the global security risk analysis results.

[0011] As a further improvement to this technical solution, the multi-source state reconstruction and alignment process of the multi-node anomaly feature spatiotemporal alignment module includes the following steps: S41.1. Split edge summary analysis data and disposal status summary information according to node identifier, extract the abnormal features, equipment load parameters and disposal status data corresponding to each edge node, and obtain a single node independent status dataset. S41.2. Based on the unified clock in the cloud, and combined with the clock offset correction of each edge node, normalize and correct the original reporting timestamps of the independent state datasets of each single node to obtain the standard timestamps corresponding to each state point. S41.3 Based on the spatial topology of the industrial network, match the corresponding topology location identifier for the status data of each single node to complete the spatial dimension alignment; S41.4 Reconstruct the state data of all nodes into a unified state sequence for all nodes according to the chronological order of standard timestamps, and generate a spatiotemporally standardized cross-node dataset.

[0012] As a further improvement to this technical solution, the dynamic correction process for the effectiveness of node coupling relationships in the dynamic coupling strength calculation module includes the following steps: S42.1 Extract the real-time operating load parameters of each device from the spatiotemporally standardized cross-node dataset to obtain the node load rate of the corresponding node; S42.2 Calculate the effective coefficient of the coupling relationship of the corresponding node based on the load range of the node load rate; when the node load rate does not exceed the normal load threshold, the effective coefficient takes the full value; when it is between the normal load threshold and the overload failure threshold, the effective coefficient decreases linearly with the increase of load; when the overload failure threshold is reached, the effective coefficient returns to zero. S42.3. Based on the basic topological coupling matrix, for any two connected nodes, take the minimum value of the effective coefficient of the coupling relationship between the two end nodes as the correction coefficient, and perform effective correction on the basic coupling strength between the nodes to obtain the dynamic coupling strength matrix. S42.4 Outputs a dynamic coupling strength matrix that is updated in real time according to the operating conditions of the equipment.

[0013] As a further improvement to this technical solution, the risk propagation hidden state construction module includes a network communication coupling delay matching submodule, a process link coupling delay matching submodule, and a hidden state vector fusion construction submodule, wherein: The network communication coupling delay matching submodule is used to extract the coupling relationship of network communication nodes from the dynamic coupling strength matrix, match the propagation delay parameters of the network transmission delay source, and obtain the network link propagation delay set. The process link coupling delay matching submodule is used to extract the coupling relationship of production process nodes from the dynamic coupling strength matrix, match the propagation delay parameters of material transmission and process transmission delay sources, and obtain the process link propagation delay set. The hidden state vector fusion construction submodule constructs an initial risk propagation hidden state vector containing dimensions of risk transmission strength, diffusion sequence, and impact potential based on node anomaly characteristics, dynamic coupling strength matrix, network link propagation delay set, and process link propagation delay set.

[0014] As a further improvement to this technical solution, the multivariate joint hidden state recursive evolution process of the hidden state evolution deduction module includes the following steps: S44.1 Input the initial risk propagation hidden state vector, dynamic coupling strength matrix, type propagation delay constraint parameters, and edge local handling status information; S44.2 Execute single-step hidden state recursive operation. During the operation, the node transmission relationship corresponding to the dynamic coupling strength, the diffusion timing rule corresponding to the propagation delay constraint, and the propagation path conduction attenuation effect corresponding to the edge local handling state are simultaneously integrated to update the risk propagation hidden state vector for the next moment. S44.3. Iteratively execute the hidden state recursion operation at a fixed time step until the preset deduction time is reached or the hidden state evolution result tends to stabilize. S44.4 Output the hidden state evolution results after iterative convergence, and generate global security risk analysis results including propagation path, scope of influence and evolution trend.

[0015] As a further improvement to this technical solution, the global risk classification early warning and collaborative handling unit includes a risk level mapping and early warning triggering module and a collaborative handling instruction generation module, wherein: The risk level mapping and early warning triggering module performs risk level mapping, early warning strategy matching and hierarchical triggering based on the global security risk analysis results, and generates global risk early warning results. The collaborative handling instruction generation module generates cloud-based collaborative handling instructions based on the global security risk analysis results and the corresponding matching early warning strategies, adapting handling actions and standardizing instruction encapsulation.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention adopts dynamic coupling strength calculation technology based on equipment operating conditions. It calculates the effective coefficient of coupling relationship by measuring the real-time load rate of nodes, performs pairwise effectiveness correction on the basic topology coupling strength, and generates a coupling strength matrix that is dynamically updated with the equipment operating status. This breaks away from the limitations of traditional schemes that rely on fixed topology associations for deduction, and makes the characterization of risk transmission characteristics highly consistent with the actual operating status of industrial sites, effectively improving the objectivity and accuracy of global risk evolution assessment. 2. This invention employs a type-based propagation delay matching and delay-constrained hidden state evolution deduction technique to distinguish the delay differences between two types of risk propagation paths: network communication and process transmission. It constructs a risk propagation hidden state vector that includes transmission strength, diffusion sequence, and impact potential. Simultaneously, it integrates delay constraints and treatment attenuation effects to carry out recursive evolution. This overcomes the shortcomings of traditional solutions that use uniform delay parameters for judgment, and can accurately predict risk propagation paths, impact ranges, and evolution trends, thereby enhancing the foresight of safety risk early warning. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the overall system framework of the present invention; The meanings of the labels in the diagram are as follows: 1. Edge data acquisition and secure preprocessing unit; 11. Multi-source heterogeneous data acquisition and access module; 12. Edge data secure preprocessing module; 2. Security analysis and local early warning unit; 21. Lightweight anomaly detection and feature extraction module; 22. Local early warning and security response execution module; 3. Cloud-edge collaborative management and security interaction unit; 31. Edge data aggregation and uplink scheduling module; 32. Cloud command issuance and channel management module; 4. Global Industrial Big Data Security Intelligent Analysis Unit; 41. Multi-Node Anomaly Feature Spatiotemporal Alignment Module; 42. Dynamic Coupling Strength Calculation Module; 43. Risk Propagation Hidden State Construction Module; 44. Hidden State Evolution Deduction Module; 5. Global risk classification, early warning, and collaborative response unit; 51. Risk level mapping and early warning triggering module; 52. Collaborative response instruction generation module. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0019] like Figure 1 As shown, this embodiment provides a distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration. It is suitable for multi-node equipment security monitoring and global risk early warning scenarios in industrial sites. Based on a collaborative architecture of edge computing nodes and cloud servers, it collects, aggregates, and intelligently analyzes multi-source heterogeneous industrial data. This embodiment uses a hidden state inference mechanism based on dynamic coupling strength calculation and type-based propagation delay constraints to assess the risk propagation situation. During operation, the edge terminal handles data preprocessing, anomaly detection, and local early warning, while the cloud terminal executes cross-node risk evolution inference and hierarchical handling decisions. Both ends coordinate commands and data through a secure channel. The system includes: Edge data acquisition and security preprocessing unit 1 collects operational data and network traffic data from multi-source heterogeneous equipment in industrial sites. It performs protocol adaptation parsing, data anonymization verification, format normalization, and initial security screening on the raw industrial data to obtain a standardized edge security dataset. Specifically, edge data acquisition and security preprocessing unit 1 is deployed on each edge computing node, serving as the system data entry point and providing a preprocessed structured data foundation for subsequent local security analysis and cloud-based global analysis. It includes a multi-source heterogeneous data acquisition and access module 11 and an edge data security preprocessing module 12, wherein: The multi-source heterogeneous data acquisition and access module 11 collects and accesses raw industrial data based on the operation data and network traffic data of multi-source heterogeneous equipment in the industrial field, using protocol adaptation parsing and access verification technology. Specifically, the multi-source heterogeneous data acquisition and access module 11 is internally configured with a protocol adaptation and parsing component. This component calls the corresponding protocol parsing driver based on the device type and protocol identifier pre-registered by each device in the system. Industrial field device types include programmable logic controllers, distributed control systems, industrial robots, CNC machine tools, sensors, and industrial switches, with corresponding communication protocols covering Modbus TCP / RTU, OPC UA, PROFINET, EtherNet / IP, and MQTT. The protocol adaptation and parsing component parses the raw messages encapsulated by different protocols into a unified data payload, extracting three types of information: first, device operating status parameters, including temperature, pressure, speed, current, and load rate; second, device operating event records, including device start / stop, mode switching, and fault codes; and third, network traffic session information, including source IP address, destination IP address, port number, transport layer protocol type, message length, and timestamp.

[0020] During the access process, the multi-source heterogeneous data acquisition and access module 11 also performs access verification. Access verification includes: verifying whether the device identifier of the data source is in the list of legally registered devices, verifying whether the message format meets the integrity requirements of the corresponding protocol specification, and checking whether the deviation between the data reporting timestamp and the local clock of the edge node is within the allowable range. For raw messages that fail access verification, the multi-source heterogeneous data acquisition and access module 11 marks them as abnormal access data and logs them separately, excluding them from subsequent preprocessing processes; raw data that passes verification is used as raw industrial data and output to the edge data security preprocessing module 12.

[0021] The edge data security preprocessing module 12, based on the raw industrial data from the multi-source heterogeneous data acquisition and access module 11, performs initial security screening using data desensitization verification and format normalization techniques to obtain a standardized edge security dataset. Specifically, the processing of the edge data security preprocessing module 12 includes four stages in sequence: data desensitization, data verification, format normalization, and initial security screening.

[0022] In the data desensitization stage, the edge data security preprocessing module 12 automatically identifies fields in the original industrial data that involve production formula parameters, equipment identity credentials, and network address mapping tables according to the preset sensitive field rule library. Based on the field type, it performs desensitization processing by field truncation, hash mapping, or replacement masking, so that the desensitized data retains its analytical value while eliminating the risk of information leakage.

[0023] In the data verification stage, the edge data security preprocessing module 12 performs integrity verification and rationality verification on the de-identified data in sequence. The integrity verification is used to check whether there are empty values ​​or format errors in each required field; the rationality verification is based on the preset effective range of each parameter, and removes outlier data that exceeds the physical range or is obviously unreasonable. For example, data with temperature values ​​exceeding the upper limit of the sensor range is discarded.

[0024] In the format normalization stage, the edge data security preprocessing module 12 converts the verified multi-source heterogeneous data into a preset standardized data pattern. The normalization process includes three aspects: timestamps are uniformly converted to UTC standard timestamps with millisecond-level precision; numerical types and units are uniformly converted to preset standard units, such as uniformly converting pressure values ​​reported by different devices to kilopascals; and the data structure is uniformly organized using a key-value structure of "node identifier-timestamp-parameter name-parameter value-data quality identifier".

[0025] In the initial security screening stage, the edge data security preprocessing module 12 calls its built-in rule matching engine to perform rapid security screening on the normalized data. The screening rules include matching based on IP address blacklists, verification based on port whitelists, and comparison based on traffic baseline thresholds. For data entries that match known malicious characteristics or deviate from the baseline by more than a threshold, the edge data security preprocessing module 12 marks them as suspicious data and attaches a corresponding security label; the remaining data entries are marked as normal data.

[0026] After the above four steps of processing, each data record carries a corresponding data quality identifier and security tag. These data records together constitute a standardized edge security dataset, which is submitted to the security analysis and local early warning unit 2 for subsequent anomaly detection and feature extraction processing.

[0027] The security analysis and local early warning unit 2 receives standardized edge security datasets and cloud-based collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit 3. It performs lightweight anomaly detection, risk feature extraction, and local security handling on industrial data from single nodes and local areas, generating local risk early warning signals, edge analysis results, and local handling status information. Specifically, the security analysis and local early warning unit 2 is deployed on edge computing nodes, undertaking the function of rapid local detection and response. Its generated edge analysis results and local handling status information are uploaded to the cloud via the cloud-edge collaborative management and security interaction unit 3, providing basic data for global risk evolution assessment. It includes a lightweight anomaly detection and feature extraction module 21 and a local early warning and security handling execution module 22, wherein: The lightweight anomaly detection and feature extraction module 21 is based on a standardized edge security dataset. It uses lightweight anomaly detection and risk feature extraction technology to analyze industrial data in single nodes and local areas to obtain edge analysis results. Specifically, after receiving the standardized edge security dataset, the lightweight anomaly detection and feature extraction module 21 first performs traffic triage according to the security tags carried in the data records. For parameters marked as normal operating status parameters, the lightweight anomaly detection and feature extraction module 21 sends them to the preset lightweight anomaly detection model for line-by-line detection. Considering the limited computing resources of edge computing nodes, the lightweight anomaly detection model adopts a statistical baseline-based method, comparing the current parameter value with the historical baseline interval under the corresponding operating condition. When the parameter value deviates from the baseline interval by more than a preset deviation threshold, it is determined that the parameter has a single-point anomaly, and a parameter-level anomaly label is generated. For network traffic session information, the lightweight anomaly detection and feature extraction module 21 performs aggregation statistics according to time windows, extracts the traffic rate, connection frequency, and port distribution characteristics within the window, calculates the deviation from the preset traffic behavior baseline, and marks windows with deviations exceeding the corresponding threshold as traffic behavior anomaly windows.

[0028] After anomaly detection is completed, the lightweight anomaly detection and feature extraction module 21 extracts risk features from the detected anomalies. For parameter-level anomalies, the extracted features include the node identifier of the anomaly parameter, the start and end times of the anomaly, the anomaly amplitude, and the duration of the anomaly. For traffic behavior anomalies, the extracted features include the source IP address, destination IP address, port number, protocol type, and traffic deviation multiple within the anomaly window. In addition, the lightweight anomaly detection and feature extraction module 21 also correlates and aggregates multiple anomalies occurring on the same node or adjacent nodes within the same time window, merging multiple single-point anomalies with temporal correlation or parameter coupling into a local risk event, and extracting the risk type label and the list of involved nodes for this risk event. All anomaly tags, risk feature data, and risk event information generated after the above anomaly detection and feature extraction processing constitute the edge analysis results, which are output to the local early warning and security handling execution module 22.

[0029] The local early warning and security handling execution module 22 uses the edge analysis results of the lightweight anomaly detection and feature extraction module 21 and the cloud collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit 3 to determine the risk status and execute the handling operation based on the local security handling and early warning triggering technology, and generates local risk early warning signals and local handling status information.

[0030] Specifically, the local early warning and safety response execution module 22 internally contains a local risk assessment rule base and a response action mapping table. Upon receiving the edge analysis results, the local early warning and safety response execution module 22 first calls the local risk assessment rule base to determine the risk status based on the risk characteristic data and risk event information in the edge analysis results. The local risk assessment rule base is configured with judgment rules for single nodes and local areas. Rule conditions include anomaly type, anomaly amplitude, anomaly duration, and whether critical equipment is involved. Each rule corresponds to a local risk level, such as high risk, medium risk, or low risk. For edge analysis results that match the judgment rules, the local early warning and safety response execution module 22 generates a corresponding local risk early warning signal. The early warning signal includes the risk level, involved nodes, risk type, and time information. Simultaneously, the local early warning and safety response execution module 22 searches for corresponding response actions in the response action mapping table based on the risk level and risk type. Response actions include pushing alarms to on-site operation terminals, triggering audible and visual alarm devices, and blocking or downgrading control commands for specific equipment.

[0031] Based on this, the local early warning and security response execution module 22 will also check whether there are cloud-based collaborative response instructions issued by the cloud-edge collaborative management and security interaction unit 3. When a cloud-based collaborative response instruction exists, the local early warning and security response execution module 22 will merge and deduplicate the response actions specified in the cloud-based collaborative response instruction with the locally determined response actions. For the actions specified in the cloud-based collaborative response instruction that are to be executed first, they will directly override the local response decisions.

[0032] After completing the handling actions, the local early warning and safety handling execution module 22 records the execution results and execution time of each action, and summarizes them together with the risk assessment results and risk early warning signals to form local handling status information. The local handling status information, along with the local risk early warning signals, is output to the cloud-edge collaborative management and security interaction unit 3 for cloud aggregation and further analysis.

[0033] The cloud-edge collaborative management and security interaction unit 3 receives edge analysis results and local handling status information, and receives cloud-based collaborative handling instructions generated by the global risk classification early warning and collaborative handling unit 5. It uses an encrypted transmission channel and a dynamic task scheduling mechanism to perform bidirectional data interaction processing between edge computing nodes and cloud nodes, outputting edge-end aggregated analysis data and handling status summary information, and issuing cloud-based collaborative handling instructions to the edge side. Specifically, the cloud-edge collaborative management and security interaction unit 3 is deployed on a cloud server, serving as a communication hub connecting the edge side and the cloud analysis side, and undertaking the functions of multi-node data aggregation, transmission scheduling, and instruction distribution. It includes an edge data aggregation and uplink scheduling module 31 and a cloud instruction issuance and channel management module 32, wherein: The edge data aggregation and uplink scheduling module 31, based on the edge analysis results and local handling status information output by each security analysis and local early warning unit 2, adopts a task dynamic scheduling mechanism to aggregate, arrange and prioritize the transmission of multi-node reported data, generate edge summary analysis data and handling status summary information, and complete uplink data transmission through an encrypted transmission channel. Specifically, the edge data aggregation and uplink scheduling module 31 continuously receives edge analysis results and local handling status information reported by the security analysis and local early warning units 2 in each edge computing node during operation. Due to the dispersed deployment locations of each edge node and the differences in network conditions, the arrival time of the data reported by each node is not completely synchronized. The edge data aggregation and uplink scheduling module 31 maintains a data receiving buffer queue internally to temporarily store and acknowledge the arrival of various types of reported messages.

[0034] During the aggregation and orchestration phase, the edge data aggregation and uplink scheduling module 31 extracts edge analysis results and local handling status information arriving in the buffer queue in batches according to a preset aggregation cycle. During extraction, the edge data aggregation and uplink scheduling module 31 merges data from the same node within the same aggregation cycle based on the node identifier and reporting timestamp in the reporting message, extracting abnormal features, risk event records, and handling execution status to form a single-node reporting summary. Based on this, the edge data aggregation and uplink scheduling module 31 further merges the single-node reporting summaries of all nodes to generate edge summary analysis data and handling status summary information covering the entire region. The edge summary analysis data includes the risk type, abnormal features, and time series distribution detected by each node, while the handling status summary information includes the handling actions executed by each node, the execution time, and the handling results.

[0035] During the transmission priority scheduling phase, the edge data aggregation and uplink scheduling module 31 assesses the transmission priority of the generated edge summary analysis data and handling status summary information. The priority assessment is based on the local risk level and risk type of the included risk events. Summary data involving high-risk levels or critical equipment risk events are assigned high transmission priority, while routine detection data is assigned ordinary transmission priority. The edge data aggregation and uplink scheduling module 31 sequentially sends the summary data into the encrypted transmission channel according to the order of priority from high to low. The encrypted transmission channel employs a two-way authentication and data encryption mechanism. The summary data is encrypted and encapsulated before transmission, and the receiving end can only read the data content after decryption and verification. After the uplink transmission is completed, the edge summary analysis data and handling status summary information are delivered to the global industrial big data security intelligent analysis unit 4 as data input for global risk evolution simulation.

[0036] The cloud-based command issuance and channel control module 32, based on the cloud-based collaborative handling command generated by the global risk classification early warning and collaborative handling unit 5, uses an encrypted transmission channel and a task dynamic scheduling mechanism to perform target node matching and transmission timing scheduling of the command, and issues the cloud-based collaborative handling command to the corresponding security analysis and local early warning unit 2.

[0037] Specifically, after receiving the cloud-based collaborative handling instruction generated by the global risk classification early warning and collaborative handling unit 5, the cloud-based instruction issuance and channel control module 32 first parses the instruction, extracting fields such as the target node identifier, specified handling action, instruction priority, and effective time limit contained in the instruction. Based on the target node identifier, the cloud-based instruction issuance and channel control module 32 matches it in the registered edge node list to determine one or more target edge nodes to which the instruction needs to be issued, and obtains the current online status and communication address of each target node.

[0038] For the matched target node, the cloud-based command issuance and channel management module 32 schedules the transmission timing according to the command priority and the communication link status of each node. The command priority includes three levels: urgent, high, and normal. Urgent commands are sent immediately when the channel is idle and can preempt the transmission resources of normal commands; high-level commands are sent in queue according to their arrival order; normal commands are sent selectively when the channel load is below a preset threshold.

[0039] Meanwhile, the cloud-based command delivery and channel control module 32 checks the validity period of each command to be delivered. Commands that are not delivered within the validity period will be automatically cancelled and logged, and will not be delivered again. Commands confirmed through scheduling are encrypted and encapsulated by the cloud-based command delivery and channel control module 32 using the encrypted transmission channel, and then sent to the target communication address of the security analysis and local early warning unit 2 on the corresponding edge node. After delivery, the cloud-based command delivery and channel control module 32 receives the command receipt confirmation acknowledgment returned from the edge side and records the command delivery status and acknowledgment time for subsequent traceability and query.

[0040] The Global Industrial Big Data Security Intelligent Analysis Unit 4 receives edge-collected analysis data and handling status summary information. It employs a risk propagation hidden state inference technique combining dynamic coupling of equipment operating conditions and time-delay constraints to conduct security situation assessment and risk diffusion evolution processing on cross-node industrial data across the entire region, obtaining global security risk analysis results. Specifically, the Global Industrial Big Data Security Intelligent Analysis Unit 4 is deployed on a cloud server, utilizing cloud computing resources to centrally analyze and deeply infer multi-node data reported from the edge side. The generated global security risk analysis results form the basis for subsequent risk classification, early warning, and collaborative handling. It includes a multi-node anomaly feature spatiotemporal alignment module 41, a dynamic coupling strength calculation module 42, a risk propagation hidden state construction module 43, and a hidden state evolution inference module 44, wherein: The multi-node anomaly feature spatiotemporal alignment module 41 performs spatiotemporal standardization processing on multi-source data based on edge summary analysis data and disposal status summary information, and outputs a spatiotemporally standardized cross-node dataset. The multi-source state reconstruction and alignment process of the multi-node anomaly feature spatiotemporal alignment module 41 includes the following steps: S41.1. Split edge summary analysis data and disposal status summary information according to node identifier, extract the abnormal features, equipment load parameters and disposal status data corresponding to each edge node, and obtain a single node independent status dataset. In this step, the multi-node anomaly feature spatiotemporal alignment module 41 splits the edge summary analysis data and the handling status summary information according to the node identifier. After splitting, the data corresponding to each edge node independently constitutes a single-node independent status dataset, denoted as the first... Single-node independent state dataset of edge nodes within a statistical period ;in, This represents the set of abnormal features of the node, including parameter-level anomaly markers and risk event records; This represents the set of device load parameters for this node, which includes at least the real-time operating load parameters of the devices. This represents the set of data representing the processing status of this node, recording the processing actions that have been executed locally and their execution status. Number the edge nodes. , The total number of edge nodes participating in the aggregation.

[0041] S41.2. Based on the unified clock in the cloud, and combined with the clock offset correction of each edge node, normalize and correct the original reporting timestamps of the independent state datasets of each single node to obtain the standard timestamps corresponding to each state point. In this step, the multi-node anomaly feature spatiotemporal alignment module 41 uses the unified cloud clock as a reference and combines it with the pre-calibrated clock offset correction amount of each edge node to perform normalization correction on the original reported timestamps in the independent state dataset of each single node. The correction method is as follows: for the first... For any state point reported by an edge node, its original reporting timestamp is denoted as . The clock skew correction for this node is The corrected standard timestamp Calculate using the following formula: ; in, The unit is milliseconds; This represents the offset of the local clock of the edge node relative to the unified clock in the cloud, in milliseconds. A positive value indicates that the edge node clock is slower than the cloud clock, and a negative value indicates that the edge node clock is faster than the cloud clock. This is the converted standard timestamp referenced to the unified cloud clock, in milliseconds. After this correction, the data reported by different nodes are comparable in the time dimension, and each state point obtains its corresponding standard timestamp.

[0042] S41.3 Based on the spatial topology of the industrial network, match the corresponding topology location identifier for the status data of each single node to complete the spatial dimension alignment; In this step, the multi-node anomaly feature spatiotemporal alignment module 41 matches the corresponding topological location identifier for each individual node's status data based on the pre-defined industrial network spatial topology in the system. The industrial network spatial topology is represented by a topology map. Stored in the form of , where For a set of nodes, each node Each corresponds to a device or edge computing node; Let be the set of edges, each edge This indicates that there is a network communication connection or production process connection between the two nodes. The multi-node anomaly feature spatiotemporal alignment module 41, based on the node identifier in the single-node status data, aligns the node in the topology graph... The topology level of the node and the list of adjacent nodes are searched, and the topology location identifier is appended to the corresponding state data to complete the spatial dimension alignment.

[0043] S41.4 Reconstruct the state data of all nodes into a unified state sequence for all nodes according to the chronological order of standard timestamps, and generate a spatiotemporally standardized cross-node dataset.

[0044] In this step, the multi-node anomaly feature spatiotemporal alignment module 41 rearranges and reorganizes the state data of all nodes according to the chronological order of standard timestamps, reconstructing a unified state sequence for all nodes. The reconstructed state sequence is indexed by the time axis and records the time points. The full node state snapshot is Then we have: ; in, Indicates the first Each node at standard time The state data includes the node's operational status, anomaly characteristics, and handling status at that moment. State snapshots at all moments are sorted in ascending order by standard timestamps to generate a spatiotemporally standardized cross-node dataset, which serves as the spatiotemporally consistent data input for subsequent dynamic coupling strength calculations and hidden state evolution deductions.

[0045] The dynamic coupling strength calculation module 42, based on a spatiotemporally standardized cross-node dataset, performs dynamic correction processing on the effectiveness of node coupling relationships to generate a dynamic coupling strength matrix. In this embodiment, the core improvement of the dynamic coupling strength calculation module 42 lies in proposing to use the real-time load rate of the equipment as the independent variable and to calculate the effective coefficient of the coupling relationship in the form of a piecewise linear function. This allows for pairwise dynamic correction of the static basic topology coupling matrix, enabling the risk transmission relationship between nodes to change in real time with actual operating conditions, avoiding the judgment bias caused by the fixed topology coupling assumptions used in traditional schemes. The dynamic correction process of the node coupling relationship effectiveness of the dynamic coupling strength calculation module 42 includes the following steps: S42.1 Extract the real-time operating load parameters of each device from the spatiotemporally standardized cross-node dataset to obtain the node load rate of the corresponding node; In this step, the dynamic coupling strength calculation module 42 extracts the real-time operating load parameters of each device from the spatiotemporally normalized cross-node dataset. For the first... Let there be nodes, and let them be at time [time]. The real-time operating load parameters are This parameter represents the device load rate reported by the edge nodes, such as CPU utilization, motor load rate, or production line cycle load rate. The value range is a dimensionless value between [0,1], where 0 indicates that the equipment is unloaded and 1 indicates that the equipment is fully loaded.

[0046] S42.2 Calculate the effective coefficient of the coupling relationship of the corresponding node based on the load range of the node load rate; when the node load rate does not exceed the normal load threshold, the effective coefficient takes the full value; when it is between the normal load threshold and the overload failure threshold, the effective coefficient decreases linearly with the increase of load; when the overload failure threshold is reached, the effective coefficient returns to zero. In this step, the dynamic coupling strength calculation module 42 calculates the effective coupling coefficient of the corresponding node based on the load range of the node's load rate. Here, the effective coupling coefficient characterizes the node's ability to act as a risk propagation path; that is, the higher the node's load level, the weaker its ability to handle external risk events, and the lower the risk conduction capability of the corresponding link. The system has preset normal load thresholds. and overload failure threshold Two parameters, satisfying Record the first Each node at time... The effective coefficient of the coupling relationship is Its calculation rule is represented by a piecewise linear function: ; in, For the first Each node at time... Node load rate; This is the normal load threshold, typically 0.6 or 0.7, indicating that the equipment maintains its ability to conduct risk within the normal operating load range. The overload failure threshold is typically set at 0.9 or 0.95, indicating that the equipment is close to or has reached an overload state, its own processing capacity is saturated, and it no longer provides an effective pathway for risk propagation. The effective coefficient of the calculated coupling relationship is dimensionless and its value ranges from [0,1].

[0047] The meaning of this calculation rule is as follows: When the node load rate does not exceed the normal load threshold, the effective coefficient is set to the full value of 1, that is, the node is in normal working condition and its conduction capability as a risk propagation path is not affected by load factors; when the node load rate exceeds the normal load threshold but has not yet reached the overload failure threshold, the effective coefficient decreases linearly with the increase of load, reflecting that the node's processing capacity is gradually occupied by its own load and its conduction capability in the risk propagation path gradually weakens; when the node load rate reaches or exceeds the overload failure threshold, the effective coefficient is set to zero, and it is considered that the node itself is in an overload protection or processing capacity saturation state, and the propagation path of the node is interrupted at the node.

[0048] S42.3. Based on the basic topological coupling matrix, for any two connected nodes, take the minimum value of the effective coefficient of the coupling relationship between the two end nodes as the correction coefficient, and perform effective correction on the basic coupling strength between the nodes to obtain the dynamic coupling strength matrix. In this step, the dynamic coupling strength calculation module 42 uses the pre-set basic topology coupling matrix in the system. Based on this, for any two connected nodes, the smaller of the effective coupling coefficients of the two endpoints is taken as a correction coefficient to effectively correct the basic coupling strength between the nodes. Basic Topological Coupling Matrix for A matrix whose elements Represents a node With nodes The inherent coupling strength between them under static conditions is a dimensionless constant value pre-calibrated based on the industrial network topology and the physical relationship between the equipment. The dynamic coupling strength matrix is ​​denoted as... Its elements The calculation formula is: ; in, Nodes in the basic topological coupling matrix With nodes The basic coupling strength between them; and They are nodes and nodes At any moment The effective coefficient of the coupling relationship; This means that the smaller of the effective coefficients of the two ends of the link is taken as the correction coefficient. This design reflects the "weakest link effect" of the risk transmission link, that is, the effectiveness of risk transmission along the link is determined by the weaker of the two ends of the link. For the corrected node With nodes The dynamic coupling strength between the nodes is updated in real time as the load rates of the two endpoints change. This applies to the basic topology coupling matrix. By performing the above correction operation on each connected node pair, the dynamic coupling strength matrix can be obtained. The dynamic coupling strength matrix is ​​a symmetric matrix, i.e. This corresponds to the bidirectional equivalence of risk transmission between nodes; for node pairs with no direct connection, the dynamic coupling strength is 0.

[0049] S42.4 Outputs a dynamic coupling strength matrix that is updated in real time according to the operating conditions of the equipment.

[0050] In this step, the dynamic coupling strength calculation module 42 outputs a dynamic coupling strength matrix that is updated in real time according to the equipment operating conditions. Due to the node load rate of each device The dynamic coupling strength matrix changes in real time with the production operation status. The system is recalculated and updated based on the latest load parameters in each calculation cycle, ensuring that the coupling strength values ​​in the matrix are always synchronized with the actual operating conditions.

[0051] The risk propagation hidden state construction module 43, based on the dynamic coupling strength matrix and the node anomaly features in the spatiotemporally standardized cross-node dataset, performs categorized delay matching and hidden state construction processing to generate an initial risk propagation hidden state vector. In this embodiment, the core improvement of the risk propagation hidden state construction module 43 lies in classifying the coupling relationships between nodes into network communication and process link types, respectively matching millisecond-level network transmission delays and second-level process propagation delays, and constructing an initial risk propagation hidden state vector with nodes as indices and comprehensive risk intensity as components. This overcomes the deficiency of traditional schemes that use uniform delay parameters and cannot characterize the timing characteristics of differentiated propagation paths. The risk propagation hidden state construction module 43 includes a network communication coupling delay matching submodule, a process link coupling delay matching submodule, and a hidden state vector fusion construction submodule, wherein: The network communication coupling delay matching submodule is used to extract the coupling relationship of network communication nodes from the dynamic coupling strength matrix, match the propagation delay parameters of the network transmission delay source, and obtain the network link propagation delay set; Specifically, the network communication coupling delay matching submodule uses the dynamic coupling strength matrix... Extract node coupling relationships categorized by coupling type as "network communication". The system classifies and labels node coupling relationships by type. Let the coupling relationship... The type is marked as ,in This indicates a network communication coupling relationship, referring to the communication connection established between nodes through industrial Ethernet, fieldbus, or wireless network. The risk propagation path is the spread of network attacks or abnormal traffic in the network link. This indicates a process link coupling relationship, referring to the upstream and downstream connections established between nodes through physical process links such as material conveying pipelines, conveyor belts, and reaction processes.

[0052] Furthermore, the network communication coupling delay matching submodule searches a pre-defined network transmission delay parameter table based on the link attributes corresponding to the network communication coupling relationship, and matches the corresponding propagation delay parameters. The network transmission delay parameter table is pre-established based on measured or calibrated delay data of each link in the industrial network topology, and is used for coupling relationships... Its network transmission delay is denoted as The unit is milliseconds.

[0053] Furthermore, the network communication coupling delay matching submodule matches all... After matching the coupling relationships one by one, the network link propagation delay set is obtained by summing them up. .

[0054] The process link coupling delay matching submodule is used to extract the coupling relationship of production process nodes from the dynamic coupling strength matrix, match the propagation delay parameters of material transmission and process transmission delay sources, and obtain the process link propagation delay set. Specifically, the process link coupling delay matching submodule uses the dynamic coupling strength matrix... The coupling type is extracted from nodes tagged as "production process". The process link coupling delay matching submodule searches a pre-defined process propagation delay parameter table based on the link attributes corresponding to the production process coupling relationship, and matches the corresponding propagation delay parameter. The process propagation delay parameter table is pre-calibrated based on the material transfer time, reaction time, or heat conduction time of each stage in the production process flow. For coupling relationships... Its process conduction delay is denoted as The unit is seconds. The process link coupling delay matching submodule matches all conditions... After matching the coupling relationships one by one, the propagation delay set of the process link is obtained. .

[0055] The hidden state vector fusion construction submodule constructs an initial risk propagation hidden state vector based on node anomaly characteristics, dynamic coupling strength matrix, network link propagation delay set and process link propagation delay set, which includes the dimensions of risk transmission strength, diffusion sequence and impact potential.

[0056] Specifically, the hidden state vector fusion construction submodule is based on node anomaly features and dynamic coupling strength matrix in the spatiotemporally standardized cross-node dataset. Network link propagation delay set With process link propagation delay set Then, perform fusion and construction processing. For the initial moment... Let the initial risk propagation hidden state vector be . The vector has a length of A column vector, each component For a given node, this represents the overall risk intensity at the initial moment, a dimensionless scalar with a value range of [0,1]. Initial risk propagation hidden state vector. The specific construction rules are as follows: For nodes that are detected to have abnormal characteristics, i.e., abnormal characteristics exist. The hidden state vector fusion construction submodule treats the nodes as initial risk source nodes and calculates their corresponding hidden state components in the following manner. First, determine the risk transmission strength factor of the node, which is the maximum value among the dynamic coupling strengths between the risk source node and all its adjacent nodes, i.e. ,in Represents a node The set of neighboring nodes, Dimensionless, reflecting the maximum potential intensity of risk transmission outward from the node at the initial moment. Secondly, the impact potential factor of the node is determined by a comprehensive evaluation of the abnormal amplitude and abnormality type of the node's anomaly characteristics. Its value is the product of the node's current abnormal amplitude and the preset impact weight corresponding to its abnormality type, denoted as... Dimensionless The abnormal amplitude is calculated by normalizing the deviation of the current parameter value from the upper limit of the normal baseline interval, i.e., abnormal amplitude = (current parameter value - upper limit of baseline interval) / (upper limit of parameter range - upper limit of baseline interval). The result is constrained to... Within the range; the preset impact weights corresponding to the anomaly types are preset according to the risk impact level, with typical values ​​as follows: anomalies involving core control equipment have a weight of 0.8~1.0, anomalies involving general sensing equipment have a weight of 0.4~0.6, and anomalies involving non-critical auxiliary equipment have a weight of 0.2~0.3. After combining the above two factors, the initial comprehensive risk intensity of this risk source node is obtained as follows: For nodes where no abnormal features were detected, their initial comprehensive risk intensity is set to zero. 0.

[0057] Furthermore, the hidden state vector fusion construction submodule also constructs a propagation delay matrix for different types of links for subsequent evolutionary deduction. For each coupled link... Its link propagation delay According to link type Sure: like ,but ; like ,but .

[0058] To facilitate handling latency parameters with different dimensions within a unified recursive framework, network transmission latency is uniformly converted from milliseconds to seconds. The conversion method is as follows: The propagation delays of all links constitute the link propagation delay matrix. All delay values ​​are in seconds. The hidden state vector fusion construction submodule will use the initial risk propagation hidden state vector. and link propagation delay matrix Output to the hidden state evolution deduction module 44.

[0059] The hidden state evolution deduction module 44, based on the initial risk propagation hidden state vector and the summary information of the handling state, performs multivariate joint hidden state recursive evolution processing to obtain the global security risk analysis results. In this embodiment, the core improvement of the hidden state evolution deduction module 44 lies in the fact that the single-step recursive operation simultaneously integrates three types of information: dynamic coupling strength, categorized propagation delay constraints, and edge local handling state. This allows the evolution process to reflect changes in coupling strength under equipment operating condition fluctuations, temporal differences in differentiated propagation paths, and the blocking and attenuation effects of executed handling actions on the propagation paths. The multivariate joint hidden state recursive evolution process of the hidden state evolution deduction module 44 includes the following steps: S44.1 Input the initial risk propagation hidden state vector, dynamic coupling strength matrix, type propagation delay constraint parameters, and edge local handling status information; In this step, the hidden state evolution inference module 44 acquires input data, which includes the initial risk propagation hidden state vector. Dynamic coupling strength matrix Link propagation delay matrix And edge-local handling status information. The edge-local handling status information originates from the summary handling status information output by the cloud-edge collaborative management and security interaction unit 3, and is used to characterize the blocking or attenuation effect of the handling actions executed by each edge node on the risk propagation path. For the first... Each node is recorded at time [time]. The disposal status factor is , , This indicates that the node did not take any action, and the risk can be transmitted outward normally through the node; This indicates that the node has been blocked, and the transmission path of the risk from the node outward has been completely cut off; When the value is between 0 and 1, it indicates that the node has undergone degradation measures, and the ability to transmit risk outwards is reduced proportionally. An example mapping rule is: when performing restrictive measures such as reducing equipment load or downgrading the operating mode, the typical value of the treatment status factor is 0.3 to 0.5; when performing monitoring-related measures such as enhanced acquisition or increased sensitivity, the treatment status factor remains at 1, without affecting the risk transmission capability.

[0060] S44.2 Execute single-step hidden state recursive operation. During the operation, the node transmission relationship corresponding to the dynamic coupling strength, the diffusion timing rule corresponding to the propagation delay constraint, and the propagation path conduction attenuation effect corresponding to the edge local handling state are simultaneously integrated to update the risk propagation hidden state vector for the next moment. In this step, the hidden state evolution deduction module 44 performs a single-step hidden state recursive calculation. Let the... The hidden state vector for each deduction step is The time step of a single-step recursion is denoted as The unit is seconds. The value is determined based on the link propagation delay matrix. The order of magnitude of the minimum delay value is determined, typically taking values ​​of 0.1 seconds or 0.5 seconds. Next moment. Hidden state vector Update each component according to the following rules.

[0061] For nodes Its hidden state components The update calculation expression is: ; After completing the recursive incremental calculation, the result is subjected to saturation limiting normalization. The processing rule is as follows: ; The physical meaning of the above recursive formula is: nodes The risk state at the next moment is equal to its current accumulated risk state, plus the risk increment transmitted from all neighboring nodes via effective links at the current moment; when the accumulated risk state reaches the maximum value of 1, it enters a saturation state and no longer continues to increase, ensuring that the hidden state components are always constrained within [0, 1]. Within the range.

[0062] in, For nodes At any moment The hidden state component values ​​are dimensionless; For nodes At any moment The hidden state component value, which represents the node The risk situation that had accumulated in the previous moment; For nodes The set of neighboring nodes; For a moment node To the node The dynamic coupling strength is determined by the dynamic coupling strength matrix. The corresponding element is given in the middle; For nodes At any moment The disposal status factor represents the node. The remaining proportion of the ability to transmit risks externally after the impact of response actions; For nodes At any moment The hidden state component value is the risk state of the source node.

[0063] Let the delay constraint indicator function be denoted by the upstream node. The moment when a non-zero hidden state first appears is Its definition is: ; in, For link The propagation delay, from the link propagation delay matrix The data is retrieved in seconds. This indicator function means that it only applies if the upstream node... Only when the cumulative simulation time after a risk occurs reaches or exceeds the propagation delay of the link will the link be connected in this step of the recursion, allowing the risk to propagate along the link; if the cumulative simulation time has not yet reached the propagation delay, the link is considered disconnected in this step and will not participate in the risk propagation for the time being.

[0064] Risk increment is simultaneously constrained by three factors: first, the dynamic coupling strength of the link. First, it reflects the transmission capability of the link under the current operating conditions; second, it is a delay constraint indicator function. The factors include: 1) whether the time conditions required for the risk to propagate along the link have been met; and 2) the handling status factor of the source node. This reflects that the source node's ability to transmit information outwards has been weakened due to local handling actions.

[0065] It should be noted that for a node that changes from zero to non-zero during the recursion process (i.e., a node affected by the risk), once its hidden state component is greater than zero, it will automatically become a new risk source node in the next recursion step and participate in the risk propagation calculation to its neighboring nodes, thereby realizing the cascading diffusion evolution of risk along the network topology.

[0066] S44.3. Iteratively execute the hidden state recursion operation at a fixed time step until the preset deduction time is reached or the hidden state evolution result tends to stabilize. In this step, the hidden state evolution inference module 44 proceeds at a fixed time step. The hidden state recursion is performed iteratively step by step. After each iteration, the hidden state evolution deduction module 44 checks whether the iteration termination condition is met. There are two termination conditions; the iteration terminates if either one is met: The first termination condition is that the cumulative simulation time reaches the preset simulation time. ,Right now , Typical values ​​range from several minutes to tens of minutes, depending on the maximum delay level of process transmission in industrial scenarios; The second termination condition is that after a series of iterations, the changes in each dimension of the hidden state vector are all below a preset convergence threshold. That is, satisfy ,in The infinite norm of a vector. The preset positive convergence threshold is typically set to 10. −3 Or 10 −4 This termination condition corresponds to the scenario where risk diffusion enters a steady state: when the hidden states of all affected nodes reach saturation or stop growing, the iteration result tends to stabilize, and the deduction can be terminated early. If no termination condition is met, the updated hidden state vector is used. As input for the next iteration, continue the single-step recursive operation of step S44.2.

[0067] S44.4 Output the hidden state evolution results after iterative convergence, and generate global security risk analysis results including propagation path, scope of influence and evolution trend.

[0068] In this step, the hidden state evolution deduction module 44 outputs the hidden state evolution results at the time of iteration convergence after the iteration terminates. Let the iteration termination time be denoted as . The final hidden state vector is The hidden state evolution result contains the risk propagation path of each risk source node, which is recursively determined by the node sequence in each time step where the hidden state components are propagated from non-zero nodes to adjacent zero-value nodes, making them non-zero; the scope of influence is determined by the set of all nodes affected by the propagation, i.e. Sure; The preset threshold for determining impact is typically 0.1. A node is considered to be effectively affected only when its hidden state component reaches or exceeds this threshold. The evolution trend is determined by each time step. The trajectory of the hidden state vector change is determined. The hidden state evolution deduction module 44 organizes the above information in a structured manner, generates a global security risk analysis result containing the propagation path, scope of influence and evolution trend, and outputs it to the global risk classification early warning and collaborative handling unit 5.

[0069] The Global Risk Grading Early Warning and Collaborative Response Unit 5 receives the global security risk analysis results and performs risk level mapping, early warning strategy matching, and graded triggering processing for various security risks, generating global risk early warning results and cloud-based collaborative response instructions. Specifically, the Global Risk Grading Early Warning and Collaborative Response Unit 5 is deployed on a cloud server as the output execution link of the system analysis results. The global risk early warning results it generates are used to notify operation and maintenance personnel or to coordinate with the superior security operation center. The cloud-based collaborative response instructions it generates are distributed to the corresponding edge nodes for collaborative response through the Cloud-Edge Collaborative Control and Security Interaction Unit 3. It includes a risk level mapping and early warning triggering module 51 and a collaborative response instruction generation module 52, wherein: The risk level mapping and early warning triggering module 51 performs risk level mapping, early warning strategy matching and hierarchical triggering based on the global security risk analysis results, and generates global risk early warning results. Specifically, the risk level mapping and early warning triggering module 51 receives the global security risk analysis results output by the hidden state evolution inference module 44. These results include three parts: risk propagation path, scope of impact, and evolution trend. The risk level mapping and early warning triggering module 51 first performs risk level mapping based on the scope of impact and evolution trend.

[0070] The risk level mapping and early warning triggering module 51 has a pre-set risk level mapping rule table, which defines the correspondence between global risk levels and judgment conditions. Specifically, the global risk level is divided into three levels: Level 1 risk (high risk), Level 2 risk (medium risk), and Level 3 risk (low risk). The judgment conditions are based on a comprehensive evaluation of indicators from two dimensions: The first dimension is the scope of influence, determined by the final hidden state vector. Number of nodes corresponding to the non-zero component Total number of nodes in the entire region ratio Sure, Dimensionless; The second dimension is the evolutionary trend, which is the maximum growth rate of the hidden state vector within the deduction period. Characterization, The unit is per second. When and When, it is mapped to Level 1 risk, where To determine the high threshold of the impact range, a typical value is 0.3. For a high threshold of diffusion rate, a typical value is 0.5 / second; when and At that time, it is mapped to a three-level risk, among which To minimize the impact, a low threshold is typically set, with a value of 0.1. The diffusion rate is set to a low threshold, typically 0.1 / second; other cases are mapped to secondary risk.

[0071] After completing the risk level mapping, the risk level mapping and early warning triggering module 51 performs early warning strategy matching processing based on the mapped risk levels. The early warning strategy library has preset early warning strategy templates corresponding to each risk level, including: the early warning strategy for Level 1 risk is to immediately push an emergency alarm notification to the operation and maintenance management personnel, and at the same time report the risk details to the cloud security operation center. The notification methods include SMS, voice call, and in-application emergency pop-up; the early warning strategy for Level 2 risk is to push a general alarm notification to the operation and maintenance management personnel. The notification methods are in-application message reminder and email notification, and the risk event is recorded in the security event log; the early warning strategy for Level 3 risk is to record the risk event in the security event log, and push it to the operation and maintenance management personnel in the form of a daily report after periodic summaries.

[0072] Finally, the risk level mapping and early warning triggering module 51 executes tiered triggering processing based on the matched early warning strategy, generating a global risk early warning result. The data structure of the global risk early warning result includes: early warning number, generated using a timestamp plus sequence number; early warning time, taken as the current system time; risk level, which can be level one, two, or three; and the scope of impact, including a list of affected nodes and... Numerical representation; risk propagation path, represented by a node sequence; handling suggestions, derived from recommended handling text in the early warning strategy template. Global risk early warning results are pushed to designated notification channels on one hand, and transmitted to the collaborative handling instruction generation module 52 on the other.

[0073] The collaborative handling instruction generation module 52, based on the global security risk analysis results and the corresponding matching early warning strategies, performs handling action adaptation and instruction standardization encapsulation processing to generate cloud-based collaborative handling instructions.

[0074] Specifically, the collaborative handling instruction generation module 52 receives the global security risk analysis results and the early warning strategy matched by the risk level mapping and early warning triggering module 51. The collaborative handling instruction generation module 52 internally maintains a handling action adaptation rule base, which defines the mapping relationship between risk level, risk type, and recommended handling actions. The types of handling actions include network isolation actions, such as issuing ACL blocking rules to specific ports of a specified node; process degradation actions, such as issuing instructions to reduce the operating load or switch to a safe mode for specified equipment; and monitoring enhancement actions, such as increasing the traffic collection frequency and anomaly detection sensitivity for specified nodes.

[0075] The collaborative handling instruction generation module 52 first extracts a list of key nodes located on the risk propagation path based on the propagation path information in the global security risk analysis results. The selection rules for key nodes are as follows: on the propagation path, priority is given to branch nodes with multiple outgoing edges, and nodes located at the intersection of network communication coupling links and process coupling links. For each extracted key node, the collaborative handling instruction generation module 52 searches the handling action adaptation rule base for a handling action that matches its node type and risk level. If multiple candidate actions are found, they are sorted according to a preset priority, from high to low priority: network isolation actions, process degradation actions, and monitoring enhancement actions. The action with the highest priority is selected as the recommended handling action for that node.

[0076] After determining the handling actions for each key node, the collaborative handling instruction generation module 52 performs standardized instruction encapsulation. The cloud-based collaborative handling instructions adopt a unified structured format, with each instruction containing the following fields: Instruction Number, generated using a combination of warning number and sequence number; Target Node Identifier, a unique identifier for the corresponding edge node; Handling Action Code, the corresponding action identifier from a preset action code table, such as "ACL_BLOCK_PORT" indicating port blocking and "DEVICE_SAFE_MODE" indicating switching to safe mode; Handling Parameters, specifying the specific parameters required for action execution, such as the port number to be blocked or the target load rate after degradation; Instruction Priority, with values ​​of urgent, high, or normal, Level 1 risk corresponding to urgent priority, Level 2 risk to high priority, and Level 3 risk to normal priority; Instruction Validity Time Limit, indicating the latest execution time for the instruction, after which the instruction automatically expires, with a validity time limit of 30 seconds for Level 1 risk instructions, 120 seconds for Level 2 risk instructions, and 600 seconds for Level 3 risk instructions.

[0077] After encapsulation, the collaborative handling instruction generation module 52 outputs the cloud-based collaborative handling instruction to the cloud-edge collaborative management and security interaction unit 3, which then performs target node matching and dispatch scheduling.

[0078] Those skilled in the art will understand that the process of implementing all or part of the steps of the above embodiments can be carried out by hardware or by a program instructing the relevant hardware.

[0079] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention.

Claims

1. A distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration, characterized in that, include: Edge data acquisition and security preprocessing unit (1) acquires the operation data and network traffic data of multi-source heterogeneous equipment in the industrial field, and performs protocol adaptation parsing, data desensitization verification, format normalization and security screening on the original industrial data to obtain a standardized edge security dataset. The security analysis and local early warning unit (2) receives a standardized edge security dataset and receives cloud collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit (3). It performs lightweight anomaly detection, risk feature extraction and local security handling on single node and local area industrial data, and generates local risk early warning signals, edge analysis results and local handling status information. The cloud-edge collaborative management and security interaction unit (3) receives edge analysis results and local handling status information, receives cloud collaborative handling instructions generated by the global risk classification early warning and collaborative handling unit (5), and uses encrypted transmission channels and task dynamic scheduling mechanisms to perform bidirectional data interaction processing between edge computing nodes and cloud nodes, outputs edge summary analysis data and handling status summary information, and sends cloud collaborative handling instructions to the edge side; The global industrial big data security intelligent analysis unit (4) receives edge summary analysis data and handling status summary information, and adopts risk propagation hidden state inference technology combining equipment operating conditions dynamic coupling and time delay constraints to conduct security situation assessment and risk diffusion evolution processing of cross-node industrial data in the whole region, and obtains global security risk analysis results. The global risk classification early warning and collaborative handling unit (5) receives the global security risk analysis results and performs risk level mapping, early warning strategy matching and classification triggering processing on various security risks, generating global risk early warning results and cloud collaborative handling instructions.

2. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 1, characterized in that, The edge data acquisition and security preprocessing unit (1) includes a multi-source heterogeneous data acquisition and access module (11) and an edge data security preprocessing module (12), wherein: The multi-source heterogeneous data acquisition and access module (11) collects and accesses raw industrial data based on the operation data and network traffic data of multi-source heterogeneous equipment in the industrial field, using protocol adaptation parsing and access verification technology. The edge data security preprocessing module (12) uses data desensitization verification and format normalization technology to perform security screening based on the original industrial data from the multi-source heterogeneous data acquisition and access module (11) to obtain a standardized edge security dataset.

3. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 1, characterized in that, The security analysis and local early warning unit (2) includes a lightweight anomaly detection and feature extraction module (21) and a local early warning and security handling execution module (22), wherein: The lightweight anomaly detection and feature extraction module (21) is based on a standardized edge security dataset and uses lightweight anomaly detection and risk feature extraction technology to analyze industrial data of single nodes and local areas to obtain edge analysis results. The local early warning and security handling execution module (22) uses local security handling and early warning triggering technology to determine the risk status and execute handling operations based on the edge analysis results of the lightweight anomaly detection and feature extraction module (21) and the cloud collaborative handling instructions issued by the cloud-edge collaborative management and security interaction unit (3), generating local risk early warning signals and local handling status information.

4. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 1, characterized in that, The cloud-edge collaborative management and security interaction unit (3) includes an edge data aggregation and uplink scheduling module (31) and a cloud command issuance and channel management module (32), wherein: The edge data aggregation and uplink scheduling module (31) uses the edge analysis results and local handling status information output by each security analysis and local early warning unit (2) to aggregate, arrange and prioritize the transmission of multi-node reported data using a task dynamic scheduling mechanism, generate edge summary analysis data and handling status summary information, and complete uplink data transmission through an encrypted transmission channel. The cloud command issuance and channel control module (32) generates cloud collaborative handling instructions based on the global risk classification early warning and collaborative handling unit (5). It uses an encrypted transmission channel and a task dynamic scheduling mechanism to perform target node matching and transmission timing scheduling of the instructions, and issues cloud collaborative handling instructions to the corresponding security analysis and local early warning unit (2).

5. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 1, characterized in that, The global industrial big data security intelligent analysis unit (4) includes a multi-node anomaly feature spatiotemporal alignment module (41), a dynamic coupling strength calculation module (42), a risk propagation hidden state construction module (43), and a hidden state evolution deduction module (44), wherein: The multi-node anomaly feature spatiotemporal alignment module (41) performs spatiotemporal standardization processing of multi-source data based on edge summary analysis data and disposal status summary information, and outputs a spatiotemporal standardized cross-node dataset. The dynamic coupling strength calculation module (42) performs dynamic correction processing of the effectiveness of node coupling relationship based on the spatiotemporal standardized cross-node dataset, and generates a dynamic coupling strength matrix. The risk propagation hidden state construction module (43) performs categorized time delay matching and hidden state construction processing based on the dynamic coupling strength matrix and the node anomaly features in the spatiotemporally standardized cross-node dataset to generate the initial risk propagation hidden state vector. The hidden state evolution deduction module (44) performs multi-variable joint hidden state recursive evolution processing based on the initial risk propagation hidden state vector and the summary information of the disposal state, and obtains the global security risk analysis results.

6. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 5, characterized in that, The multi-source state reconstruction and alignment process of the multi-node anomaly feature spatiotemporal alignment module (41) includes the following steps: S41.

1. Split edge summary analysis data and disposal status summary information according to node identifier, extract the abnormal features, equipment load parameters and disposal status data corresponding to each edge node, and obtain a single node independent status dataset. S41.

2. Based on the unified clock in the cloud, and combined with the clock offset correction of each edge node, normalize and correct the original reporting timestamps of the independent state datasets of each single node to obtain the standard timestamps corresponding to each state point. S41.3 Based on the spatial topology of the industrial network, match the corresponding topology location identifier for the status data of each single node to complete the spatial dimension alignment; S41.4 Reconstruct the state data of all nodes into a unified state sequence for all nodes according to the chronological order of standard timestamps, and generate a spatiotemporally standardized cross-node dataset.

7. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 5, characterized in that, The dynamic correction process for the effectiveness of node coupling relationships in the dynamic coupling strength calculation module (42) includes the following steps: S42.1 Extract the real-time operating load parameters of each device from the spatiotemporally standardized cross-node dataset to obtain the node load rate of the corresponding node; S42.2 Calculate the effective coefficient of the coupling relationship of the corresponding node based on the load range of the node load rate; when the node load rate does not exceed the normal load threshold, the effective coefficient takes the full value; when it is between the normal load threshold and the overload failure threshold, the effective coefficient decreases linearly with the increase of load; when the overload failure threshold is reached, the effective coefficient returns to zero. S42.

3. Based on the basic topological coupling matrix, for any two connected nodes, take the minimum value of the effective coefficient of the coupling relationship between the two end nodes as the correction coefficient, and perform effective correction on the basic coupling strength between the nodes to obtain the dynamic coupling strength matrix. S42.4 Outputs a dynamic coupling strength matrix that is updated in real time according to the operating conditions of the equipment.

8. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 5, characterized in that, The risk propagation hidden state construction module (43) includes a network communication coupling delay matching submodule, a process link coupling delay matching submodule, and a hidden state vector fusion construction submodule, wherein: The network communication coupling delay matching submodule is used to extract the coupling relationship of network communication nodes from the dynamic coupling strength matrix, match the propagation delay parameters of the network transmission delay source, and obtain the network link propagation delay set. The process link coupling delay matching submodule is used to extract the coupling relationship of production process nodes from the dynamic coupling strength matrix, match the propagation delay parameters of material transmission and process transmission delay sources, and obtain the process link propagation delay set. The hidden state vector fusion construction submodule constructs an initial risk propagation hidden state vector containing dimensions of risk transmission strength, diffusion sequence, and impact potential based on node anomaly characteristics, dynamic coupling strength matrix, network link propagation delay set, and process link propagation delay set.

9. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 5, characterized in that, The multivariate joint hidden state recursive evolution process of the hidden state evolution deduction module (44) includes the following steps: S44.1 Input the initial risk propagation hidden state vector, dynamic coupling strength matrix, type propagation delay constraint parameters, and edge local handling status information; S44.2 Execute single-step hidden state recursive operation. During the operation, the node transmission relationship corresponding to the dynamic coupling strength, the diffusion timing rule corresponding to the propagation delay constraint, and the propagation path conduction attenuation effect corresponding to the edge local handling state are simultaneously integrated to update the risk propagation hidden state vector for the next moment. S44.

3. Iteratively execute the hidden state recursion operation at a fixed time step until the preset deduction time is reached or the hidden state evolution result tends to stabilize. S44.4 Output the hidden state evolution results after iterative convergence, and generate global security risk analysis results including propagation path, scope of influence and evolution trend.

10. The distributed industrial big data security intelligent analysis and risk early warning system based on cloud-edge collaboration according to claim 1, characterized in that, The global risk classification early warning and collaborative response unit (5) includes a risk level mapping and early warning triggering module (51) and a collaborative response instruction generation module (52), wherein: The risk level mapping and early warning triggering module (51) performs risk level mapping, early warning strategy matching and hierarchical triggering based on the global security risk analysis results, and generates global risk early warning results. The collaborative handling instruction generation module (52) generates cloud-based collaborative handling instructions by adapting handling actions and standardizing instruction encapsulation based on the global security risk analysis results and the corresponding matching early warning strategies.