Method and apparatus for secure communication of information based on tcp / ip
Patent Information
- Application Number
- CN202510360149.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2026-09-29
AI Technical Summary
[0008]本发明实施方式的目的是提供一种基于TCP/IP的信息安全通讯方法及装置,以至少解决上述的TCP/IP协议缺乏完整性检测、恶意数据包造成网络拥堵、数据包明文传输易被篡改的问题
[0008]本发明实施方式的目的是提供一种基于TCP/IP的信息安全通讯方法及装置,以至少解决上述的TCP/IP协议缺乏完整性检测、恶意数据包造成网络拥堵、数据包明文传输易被篡改的问题。
Smart Images

Figure CN122845140A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, specifically to a TCP / IP-based information security communication method, a TCP / IP-based information security communication device, a machine-readable storage medium, and an electronic device. Background Technology
[0002] With the improvement of industrial automation, production efficiency has been greatly enhanced, but production safety has also become an indispensable part of process industry production. In the petrochemical industry, industrial automation safety involves fundamental elements such as the hardware, operating system, communication protocol, and application system of the industrial control system during information transmission. An industrial control system is a general term encompassing various types of control systems, including Supervisory Control and Data Acquisition (SCADA), Distributed Control System (DCS), and Safety Instrumented System (SIS). It consists of multiple automation control components and process control components that acquire and monitor real-time data. Initially, most industrial control systems were relatively closed and independent, and therefore information security was not considered in their initial design; their security was only related to the reliability of the system itself. However, in recent years, the connection between Ethernet-based industrial control networks and computer networks has led to a series of new security issues. For example, every instrument connected to the automation unit network can communicate with any other instrument, actuator, or computer in the network, meaning access to automation instruments or systems can be initiated from anywhere. Therefore, strengthening the information security of industrial control systems is particularly important.
[0003] The TCP / IP protocol model (Transmission Control Protocol / Internet Protocol) comprises a series of network protocols that form the foundation of the Internet and is its core protocol. Ethernet based on TCP / IP is characterized by its openness, abundant hardware and software resources, and wide application. The reference model divides the protocol into four layers: the data link layer, the network layer, the transport layer, and the application layer. Among these, the data link layer is the most complex. Its most common attack method is network sniffing, which makes TCP / IP Ethernet vulnerable to data loss due to attacks. Furthermore, attackers can use data analysis to obtain critical data such as account information and passwords.
[0004] Attacks at the network layer include ARP spoofing and ICMP spoofing. ARP (Address Resolution Protocol) is a TCP / IP protocol that retrieves the physical address from an IP address. Typically, during IP packet transmission, one or more subnets may use Layer 1 network access, and ARP acts as the source host's first lookup tool. If the physical address corresponding to the IP address is not found, it sends the host and the physical address information related to the IP address to the source host. Simultaneously, the source host sends a response, including its own IP address and the ARP query result, to the destination host. If ARP identifies an incorrect link, it directly applies suspicious information, which then enters the target host. The ARP protocol is stateless; regardless of whether a request has been received, the host automatically caches any received ARP responses. If the information contains a virus, ARP spoofing can lead to network information security leaks. Therefore, ARP identification should be strengthened with more security measures and additional identification checkpoints. Identification should not be based solely on IP names; other IP-related properties must also be considered. ICMP is also an Internet Control Message Protocol, primarily used for transmitting control information between hosts and routers. This protocol allows control over information such as network connectivity, host reachability, and route availability. In the event of an error, data packets are immediately retransmitted by the host, and an error description is automatically returned. This protocol is crucial for network security. However, due to its inherent characteristics, it is highly vulnerable to intrusion. Typically, if a target host continuously sends a large number of ICMP data packets, it will consume excessive CPU resources, ultimately causing system crashes.
[0005] At the transport layer, network security issues such as IP spoofing also exist. This involves forging one's own IP address and sending malicious requests to a target host, attacking it. Because the IP address is hidden, the host cannot accurately identify the source of the attack. Alternatively, it can gain the target host's trust to steal confidential information. IP spoofing is often used in DoS attacks because the sources of data packets are diverse and cannot be effectively filtered, significantly reducing the effectiveness of basic IP defenses. Furthermore, in the ICMP transport channel, since ICMP is part of the IP layer, any port in the IP software can send a PING file to ICMP as a request to request permission for data transmission. ICMP responds, and this command verifies the legitimacy of the message. The transport layer generally agrees to all data transmission requests. This is mainly because PING software programming cannot intelligently identify malicious information; general network security systems and firewalls automatically assume PING is present, thus ignoring its potential security risks.
[0006] DNS spoofing attacks exist at the application layer. DNS spoofing refers to the attacker impersonating a domain name server, providing incorrect DNS information to the target host. This can mislead users into accessing unauthorized servers, making them believe in fraudulent IP addresses. Furthermore, on PTP networks, interfaces may receive data that does not belong to the host, which is another application-layer security issue. Some Trojan viruses can exploit this vulnerability to infiltrate, causing data leaks and leading to network security problems.
[0007] Therefore, without changing the original advantages of the simple and open TCP / IP protocol, how to solve the problems of TCP / IP protocol lacking integrity detection, network congestion caused by malicious data packets, and easy tampering of plaintext data packets, in order to strengthen the security of TCP / IP protocol, and thus ensure secure and reliable communication between industrial control system clients and servers, and reduce the possibility of attacker intrusion, is an urgent problem to be solved. Summary of the Invention
[0008] The purpose of this invention is to provide a TCP / IP-based information security communication method and apparatus to at least solve the problems mentioned above, such as the lack of integrity detection in the TCP / IP protocol, network congestion caused by malicious data packets, and the susceptibility of plaintext data packet transmission to tampering.
[0009] To achieve the above objectives, the first aspect of the present invention provides a TCP / IP-based information security communication method applied to an industrial control system. The method includes: performing data processing checks on the communication input data of the industrial control system based on an information security communication check model; wherein the information security communication check model is constructed from data communication check rules corresponding to at least one data check indicator; determining information security hardening requirement data corresponding to each data check indicator based on the data processing check results; performing information security hardening on the corresponding industrial control system based on the information security hardening requirement data corresponding to each data check indicator; after determining that information security hardening is complete, performing a communication information security test on the communication program of the hardened industrial control system; using the communication information security test-passed, hardened communication program of the industrial control system as the current communication program of the industrial control system; and performing information security communication of the industrial control system based on the current communication program of the industrial control system.
[0010] A second aspect of the present invention provides a TCP / IP-based information security communication device deployed in an industrial control system. The device includes: a data processing and inspection module for performing data processing and inspection on the communication input data of the industrial control system based on an information security communication inspection model; wherein the information security communication inspection model is constructed from data communication inspection rules corresponding to at least one data inspection indicator; a hardening requirement data determination module for determining information security hardening requirement data corresponding to each data inspection indicator based on the data processing and inspection results; an information security hardening module for performing information security hardening on the corresponding industrial control system based on the information security hardening requirement data corresponding to each data inspection indicator; and a communication information security testing module for performing communication information security testing on the communication program of the hardened industrial control system after information security hardening is completed, using the communication program of the hardened industrial control system that passes the communication information security test as the current communication program of the industrial control system, and performing information security communication of the industrial control system based on the current communication program of the industrial control system.
[0011] In a third aspect, the present invention provides a machine-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the TCP / IP-based secure communication method described above.
[0012] In a fourth aspect, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the aforementioned TCP / IP-based secure communication method.
[0013] The above technical solution provides a TCP / IP-based information security communication method and apparatus. Following the data communication inspection rules corresponding to each data inspection indicator in the information security communication inspection model, it performs data processing inspection on the communication input data of the industrial control system to conduct information security communication inspection on the current communication program of the industrial control system. Based on the data processing inspection results, it determines the information security hardening requirement data corresponding to each data inspection indicator, and then comprehensively performs information security hardening on the corresponding industrial control system based on the information security hardening requirement data corresponding to each data inspection indicator. After determining that the information security hardening is complete, it conducts a communication information security test on the communication program of the hardened industrial control system. The communication program of the hardened industrial control system that passes the communication information security test is used as the current communication program of the industrial control system, and information security communication of the industrial control system is performed based on the current communication program. This method and apparatus addresses the problems of TCP / IP protocol being vulnerable to attack, information easily lost, and lacking detection methods, providing a specific method for achieving information security inspection and hardening. It can improve the security problems existing in the communication of industrial control systems while ensuring the functional safety and physical security reliability of the industrial control system, and provides detailed measures, processes, and implementation methods for information security inspection, hardening, and testing. Without altering the inherent simplicity and openness of the TCP / IP protocol, this solution addresses the shortcomings of TCP / IP, such as lack of integrity checks, network congestion caused by malicious data packets, and vulnerability to tampering during plaintext data transmission. It effectively prevents attacks including data tampering, data storms, denial-of-service attacks, obfuscated data, vulnerability exploitation, and operator error. This powerful tool enhances the information security of industrial control systems, significantly improving communication security while maintaining functionality and reliability, thus ensuring the effectiveness of TCP / IP protocol security hardening. This guarantees secure and reliable communication between industrial control system clients and servers, reducing the likelihood of attacker intrusion.
[0014] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0015] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:
[0016] Figure 1 This is a flowchart of an information security communication method based on TCP / IP provided in one embodiment of the present invention;
[0017] Figure 2This is a flowchart illustrating an information security enhancement procedure for the ARP protocol according to one embodiment of the present invention;
[0018] Figure 3 This is a flowchart of checking the validity period of the source IP address in the ARP protocol, provided by one embodiment of the present invention;
[0019] Figure 4 This is a flowchart of checking the validity period of a target MAC address in the ARP protocol, provided by one embodiment of the present invention;
[0020] Figure 5 This is a flowchart of the process for handling IP protocol where the source IP address is not the destination IP address, provided by one embodiment of the present invention.
[0021] Figure 6 This is a flowchart of a modified TCP scan robustness procedure provided in one embodiment of the present invention;
[0022] Figure 7 This is a block diagram of an information security communication device based on TCP / IP provided in one embodiment of the present invention;
[0023] Figure 8 This is a schematic diagram of an electronic device structure provided by a preferred embodiment of the present invention.
[0024] Explanation of reference numerals in the attached figures
[0025] 10 - Electronic device, 100 - Processor, 101 - Memory, 102 - Computer program. Detailed Implementation
[0026] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0027] Example 1
[0028] Figure 1 This is a flowchart illustrating a TCP / IP-based secure communication method according to one embodiment of the present invention. Figure 1 As shown, this invention provides a TCP / IP-based secure communication method applied to an industrial control system. The method includes:
[0029] S110: Based on the information security communication inspection model, perform data processing inspection on the communication input data of the industrial control system; wherein, the information security communication inspection model is constructed by data communication inspection rules corresponding to at least one data inspection indicator;
[0030] Specifically, according to the data communication inspection rules corresponding to each data inspection indicator in the information security communication inspection model, the communication input data of the industrial control system is inspected for data processing in order to conduct information security communication inspection on the current communication program of the industrial control system.
[0031] In some embodiments of this example, the aforementioned data inspection indicators include data syntax indicators, data storm indicators, fuzzy data indicators, and scan robustness indicators. The data syntax processing inspection rules corresponding to the data syntax indicators are used to check the validity and completeness of the communication input data of the industrial control system according to the syntax rules of the communication protocol used to transmit the communication input data. The data storm processing inspection rules corresponding to the data storm indicators are used to check for data storms of various communication protocols during the transmission of communication input data of the industrial control system. Specifically, a data storm of various communication protocols indicates that the number of inputs of communication input data of the industrial control system transmitted based on the corresponding communication protocol exceeds a preset threshold, causing an anomaly in the transmission process of the communication input data corresponding to that communication protocol. The fuzzy data processing inspection rules corresponding to the fuzzy data indicators are used to check for fuzzy data in the communication input data of the industrial control system according to the communication protocol of the communication input data. Fuzzy data represents fields in the communication input data that have random variation characteristics. The scan robustness inspection rules corresponding to the scan robustness indicators are used to check the industrial control system's ability to cope with network scanning. The industrial control system's ability to cope with network scanning includes at least whether the industrial control system has the ability to respond to network scanning requests corresponding to various communication protocols.
[0032] In some embodiments of this example, the aforementioned communication protocols include ARP, IPv4, ICMP, TCP, and UDP. The specific content of the data syntax processing and checking rules corresponding to the data syntax indicators includes: checking the validity and integrity of data packets and headers of communication input data transmitted based on the ARP protocol, as well as the ARP header; checking the validity and integrity of data packets and headers of communication input data transmitted based on the IPv4 protocol; checking the validity and integrity of data packets and headers of communication input data transmitted based on the ICMP protocol, the source address of ICMP packets, and the combination of ICMP types and codes; checking the validity and integrity of data packets and headers of communication input data transmitted based on the TCP protocol, the source address of TCP packets, TCP / IP syntax, TCP random numbers, TCP data priority, TCP data timestamps, and connection state identifiers TCP ACK / Echo; and checking the validity and integrity of data packets and headers of communication input data transmitted based on the UDP protocol, the validity of UDP packet data, and the source address of UDP packets.
[0033] Specifically, the data syntax processing and checking rules systematically check the validity of communication input data frames (reports) according to the syntax rules of the corresponding communication protocol. This ensures that the communication module and system functions correctly process invalid and valid inputs, guaranteeing the functionality and status of the industrial control system. The data syntax processing and checking rules include the following: 1. Checking the validity and integrity of ARP packets and headers, and ARP header syntax; 2. Checking the validity and integrity of IPv4 packets and headers; 3. Checking the validity and integrity of ICMP packets and headers, ICMP packet source address, and combinations of ICMP types and codes; 4. Checking the validity and integrity of TCP packets and headers, TCP packet source address, TCP / IP syntax checking, TCP random number checking, TCP data priority checking, TCP data timestamp checking, and TCP ACK / Echo checking; 5. Checking the validity and integrity of UDP packets and headers, checking the validity of UDP packet data, and checking the UDP packet source address.
[0034] In some implementations of this embodiment, the above communication protocols include ARP protocol, IPv4 protocol, ICMP protocol, TCP protocol and UDP protocol; the specific content of the data storm processing and inspection rules corresponding to the data storm index includes: checking data storms of ARP protocol, data storms of IPv4 protocol, data storms of ICMP protocol, data storms of TCP protocol, data storms of UDP protocol, ARP protocol address spoofing data and ARP protocol mapping update data.
[0035] Specifically, a data storm refers to a situation where a large amount of data is input or requested in a short period of time (per second). Communication modules need to handle inputs that may be subject to data storms under extreme conditions. Therefore, communication modules should have corresponding functions or processing mechanisms to correctly handle data storms and ensure the normal operation of the industrial control system. A typical data storm lasts 120 seconds. Data storm handling and checking rules include checking for ARP, IP, ICMP, TCP, and UDP data storms, ARP protocol address spoofing, and protocol mapping updates.
[0036] In some implementations of this embodiment, the specific content of the fuzzy data processing and inspection rules corresponding to the above-mentioned fuzzy data indicators includes: checking the fuzzy data in the communication input data transmitted based on different communication protocols according to the fuzzy data judgment rules corresponding to various communication protocols; wherein, the fuzzy data judgment rules corresponding to various communication protocols are obtained by one or more combinations of data CRC check rules, data checksum rules, corresponding communication protocol field judgment rules and upper-layer application multi-field rules.
[0037] Specifically, fuzzy data refers to data whose changes are random and unsystematic. It can be an entire invalid field or a change in one or more bits within valid data. Communication systems should have the capability to process fuzzy data, identify valid and invalid data inputs, and ensure the stable operation of industrial control systems. This includes fuzzy data processing and checking for IP, ICMP, TCP, and UDP protocols, specifically involving data checksums, protocol field judgments, and multi-field rule judgments from upper-layer applications.
[0038] In some embodiments of this example, the specific content of the scan robustness check rules corresponding to the above-mentioned scan robustness indicators includes: performing TCP scan robustness checks and UDP scan robustness checks on the industrial control system; wherein, the TCP scan robustness check is used to check whether the industrial control system has the ability to respond to network scan requests corresponding to the TCP protocol; the UDP scan robustness check is used to check whether the industrial control system has the ability to respond to network scan requests corresponding to the UDP protocol.
[0039] Specifically, scan robustness refers to the ability of an industrial control system to withstand network scans. Scanning is a standard cybersecurity assessment procedure used to collect network information. As industrial control systems increasingly connect to networks, they need to possess a certain level of scan resilience. This includes properly handling data packets to maintain normal control and view processing capabilities during storm periods. The specific rules for scan robustness checks include TCP scan robustness checks and UDP scan robustness checks.
[0040] S120: Based on the data processing inspection results, determine the information security hardening requirements data corresponding to each data inspection indicator;
[0041] S130: Based on the information security hardening requirements data corresponding to each data inspection indicator, perform information security hardening of the corresponding industrial control system;
[0042] Specifically, after completing the data processing and inspection of the communication input data of the industrial control system in step S110, the information security hardening requirement data corresponding to each data inspection index (including data syntax index, data storm index, fuzzy data index and scan robustness index) is determined. Then, by combining the information security hardening requirement data corresponding to each data inspection index, a communication security hardening scheme for hardening the current communication program of the industrial control system is obtained.
[0043] S140: After determining that information security hardening is completed, a communication information security test is performed on the communication program of the hardened industrial control system. The communication program of the hardened industrial control system that passes the communication information security test is used as the current communication program of the industrial control system. Based on the current communication program of the industrial control system, information security communication of the industrial control system is carried out.
[0044] Specifically, this method performs data processing checks on the communication input data of the industrial control system according to the data communication check rules corresponding to each data check indicator in the information security communication check model, thereby conducting information security communication checks on the current communication program of the industrial control system. Based on the data processing check results, the information security hardening requirement data corresponding to each data check indicator is determined. Then, by comprehensively considering the information security hardening requirement data corresponding to each data check indicator, information security hardening of the corresponding industrial control system is executed. After determining that information security hardening is complete, a communication information security test is performed on the communication program of the hardened industrial control system. The communication program of the hardened industrial control system that passes the communication information security test is used as the current communication program of the industrial control system. Based on the current communication program of the industrial control system, information security communication of the industrial control system is performed. This method addresses the problems of TCP / IP protocol being vulnerable to attacks, information loss, and lack of detection methods, providing a specific method for achieving information security checks and hardening. It can improve the security problems existing in the communication of industrial control systems while ensuring the functional safety and physical security reliability of the industrial control system, and provides detailed measures, processes, and implementation methods for information security checks, hardening, and testing. Without altering the inherent simplicity and openness of the TCP / IP protocol, this solution addresses the shortcomings of TCP / IP, such as lack of integrity checks, network congestion caused by malicious data packets, and vulnerability to tampering during plaintext data transmission. It effectively prevents attacks including data tampering, data storms, denial-of-service attacks, obfuscated data, vulnerability exploitation, and operator error. This powerful tool enhances the information security of industrial control systems, significantly improving communication security while maintaining functionality and reliability, thus ensuring the effectiveness of TCP / IP protocol security hardening. This guarantees secure and reliable communication between industrial control system clients and servers, reducing the likelihood of attacker intrusion.
[0045] The TCP / IP-based information security communication method described above comprises two parts: an inspection and hardening method, and a testing method. The inspection and hardening method includes: data syntax processing inspection, data storm handling inspection, fuzzy data processing inspection, robustness scanning inspection, and information security hardening. The testing method includes: Modbus TCP protocol communication robustness testing and OPC UA protocol communication robustness testing. This TCP / IP-based information security communication method can be applied to various TCP / IP protocols, has a wide range of applications, and includes both inspection and hardening steps. After application, this method provides a more comprehensive improvement in the security of industrial control systems. This method can be used for the design and development of information security hardening for industrial control systems used in process industries, while also ensuring the security of production equipment from the perspective of the industrial control system itself. This method improves the development process of industrial control system information security, which is mainly based on inspection, hardening, and testing, providing enterprises with new solutions. The illustrated process can be solidified to form a complete system communication security hardening and testing program, enabling customized development for different control systems and equipment, with broad application prospects.
[0046] In some embodiments of this example, the above-mentioned communication information security test on the communication program of the information security-hardened industrial control system includes: sequentially performing Modbus TCP protocol communication robustness test and OPC UA protocol communication robustness test on the communication program of the information security-hardened industrial control system; wherein, the Modbus TCP protocol communication robustness test is to test the communication robustness of the information security-hardened industrial control system's communication program under the Modbus TCP protocol; the OPC UA protocol communication robustness test is to test the communication robustness of the information security-hardened industrial control system's communication program under the OPC UA protocol.
[0047] Specifically, the Modbus TCP protocol is an application layer protocol based on TCP / IP, using an Ethernet interface and a master-slave communication method for connection-oriented reliable communication. The OPC UA protocol is also an application layer protocol based on TCP / IP, employing a service-oriented architecture to allow efficient and reliable data exchange between industrial automation equipment and industrial control systems. It also incorporates built-in security features, including data encryption, authentication, and access control. By testing the robustness of the Modbus TCP and OPC UA protocols, the effectiveness of security hardening can be indirectly verified, achieving the purpose of information security testing.
[0048] In some implementations of this embodiment, the Modbus TCP protocol communication robustness test includes read coil test, read discrete input test, read holding register test, read input register test, write single coil test, write single register test, write multiple coil test, write multiple register test, read file record test, write file record test, mask write register test, read / write multiple register test, read FIFO queue test, read device identifier test, unified messaging application service test, and diagnostic service test.
[0049] In some implementations of this embodiment, the OPC UA protocol communication robustness test includes the following tests: Activate Session Request Test, Create Monitored Item Request Test, Create Session Request Test, Create Subscription Request Test, Obtain Endpoint Used by Server Request Test, Open Secure Channel Request Test, Close Secure Channel Request Test, Close Session Request Test, Add Node Request Test, Cancel Request Test, Read Request Test, Browse Node Reference Test, Publish Request Test, Query First Request Test, Query Next Request Test, Historical Read Request Test, Write Request Test, Historical Update Request Test, Call Request Test, Browse State Model Test, Read State Model Test, and Publish State Model Test.
[0050] It should be noted that this method differs clearly in its basic analysis, design methodology, intended use, and application. It addresses the fundamental problems of industrial control systems, such as the lack of integrity checks in the TCP / IP protocol, network congestion caused by malicious data packets, and the vulnerability of plaintext data packets to tampering. It provides specific methods for conducting communication security checks, hardening, and testing of industrial control systems, making it more feasible and effective. The beneficial effects are described in the following aspects:
[0051] 1. In the information security development stage of industrial control systems, this method provides an overall development process from communication security inspection and hardening to testing based on the TCP / IP protocol. By establishing a comprehensive security inspection mechanism, it accurately identifies potential security threats such as data tampering, denial-of-service attacks, and vulnerability exploitation. Based on the inspection results, it precisely repairs potential security vulnerabilities and finally provides testing methods to verify the communication robustness of industrial control systems.
[0052] 2. The communication security inspection, hardening, and testing methods proposed in this paper are powerful tools for improving product development efficiency. The results can be directly applied to the actual design and development of industrial control systems, and corresponding methodological steps and examples are provided. The illustrated workflow can be formalized to form a complete information security development procedure for industrial control systems. This improves development efficiency, reduces the development cycle, and enables a comprehensive enhancement of the information security of industrial control systems.
[0053] Example 2
[0054] This invention provides a TCP / IP-based information security communication method, which includes a TCP / IP-based information security communication inspection and hardening method. The specific steps of the TCP / IP-based information security communication inspection and hardening method are as follows:
[0055] S1. Data Syntax Processing Check: The data syntax processing check includes the following:
[0056] (1) Check the validity and integrity of ARP packets and headers, and the ARP header syntax;
[0057] (2) Check the validity and integrity of IPv4 packets and headers;
[0058] (3) Check the validity and integrity of ICMP packets and headers, the source address of ICMP packets, and the combination of ICMP types and codes;
[0059] (4) Check the validity and integrity of TCP packets and headers, source address of TCP packets, TCP / IP syntax check, TCP random number check, TCP data priority check, TCP data timestamp check, and TCP ACK / Echo check;
[0060] (5) Check the validity and integrity of UDP packets and headers, check the validity of UDP packet data, and check the source address of UDP packets.
[0061] S2. Data Storm Handling Check: The data storm handling check includes checking for ARP, IP, ICMP, TCP, and UDP data storms, ARP protocol address spoofing, and protocol mapping updates.
[0062] S3. Fuzzy Data Processing Inspection: Fuzzy data processing inspection includes fuzzy data processing inspection of IP, ICMP, TCP, and UDP, specifically data checksum + judgment of each protocol field + judgment of multiple fields of upper layer application rules.
[0063] S4. Scan for robustness: Scan for robustness includes TCP scan for robustness and UDP scan for robustness.
[0064] S5. Information security hardening: Information security hardening refers to the communication security optimization plan formed after the above S1 to S4 inspection steps are completed. The actual hardening plan can be determined according to the actual inspection results.
[0065] Taking the Security Information System (SIS) in an industrial control system as an example, this document details the implementation process of communication information security inspection and hardening in an industrial control system. The specific implementation process of this embodiment is as follows (only the detailed content of step 1, data syntax processing inspection, is listed here; the detailed inspection content of the remaining steps is similar to step 1):
[0066] Step 1: Data Syntax Processing Check: The validity and integrity of ARP, IPv4, ICMP, TCP, and UDP packets and headers are checked respectively. This includes checking the ARP header syntax, the source addresses of ICMP, TCP, and UDP packets, the combination of ICMP types and codes, TCP / IP syntax, TCP random numbers, TCP data priority, TCP data timestamps, TCP ACK / Echo, and the validity of UDP packet data. The check results are shown in Table 1. Table 1 shows the data syntax processing check results:
[0067] Table 1. Results of Data Syntax Processing Check
[0068]
[0069]
[0070]
[0071]
[0072]
[0073]
[0074]
[0075] Based on Table 1, the data syntax processing reinforcement requirements are obtained, and a data syntax processing reinforcement scheme is given in step 5.
[0076] Step 2: Data Storm Handling Check: The data storm handling check includes checking for ARP, IP, ICMP, TCP, and UDP data storms, ARP address spoofing, and protocol mapping updates, as shown in Table 2. Table 2 shows the results of the data storm handling check.
[0077] Table 2 Data Storm Handling Inspection Results
[0078]
[0079]
[0080]
[0081] Based on Table 2, the data storm processing hardening requirements are obtained, and the data storm processing hardening scheme is given in step 5.
[0082] Step 3: Fuzzy Data Processing Check: The fuzzy data processing check includes checks on IP, ICMP, TCP, and UDP fuzzy data processing, specifically data checksums, protocol field judgments, and multi-field rule judgments from upper-layer applications, as shown in Table 3. Table 3 shows the results of the fuzzy data processing check.
[0083] Table 3. Results of Fuzzy Data Processing Inspection
[0084]
[0085] Based on Table 3, the reinforcement requirements for fuzzy data processing are obtained, and the reinforcement scheme for fuzzy data processing is given in step 5.
[0086] Step 4: Robustness Check: The robustness check includes TCP and UDP robustness checks, as shown in Table 4. Table 4 presents the results of the robustness check.
[0087] Table 4 Results of Scanning Robustness Examination
[0088]
[0089]
[0090] Based on Table 4, the reinforcement requirements for the scan robustness check are obtained, and the reinforcement scheme for the scan robustness is given in step 5.
[0091] Step 5: Information Security Program Hardening: Specific examples of information security program hardening are as follows:
[0092] 5.1 ARP Protocol Ethernet Source MAC Address Matching: In the `etharp_input(struct pbuf*p,struct netif*netif)` method, add code to check if the Ethernet source MAC address matches the sending MAC address. Since the `pbuf_header` function moves the Ethernet header pointer forward, it's necessary to move it back to trace the source MAC address. Figure 2 As shown, Figure 2 This is a flowchart of an information security enhancement program for the ARP protocol provided in one embodiment of the present invention.
[0093] 5.2 When receiving messages using the ARP protocol, check the validity period of the source IP address: In the `etharp_input(struct pbuf*p, struct netif*netif)` method, add code to check the validity period of the source IP address, such as... Figure 3 As shown, Figure 3 This is a flowchart for checking the validity period of the source IP address in the ARP protocol, provided by one embodiment of the present invention.
[0094] 5.3 When receiving messages using the ARP protocol, check the validity period of the target MAC address: In the `etharp_input(struct pbuf*p, struct netif*netif)` method, add code to check the validity period of the target MAC address, such as... Figure 4 As shown, Figure 4 This is a flowchart for checking the validity period of a target MAC address in the ARP protocol, provided by one embodiment of the present invention.
[0095] 5.4. IP source IP address is not the destination IP address: In the `ip4_input(struct pbuf*p, struct netif*netif)` method, add the following code to check if the IP source IP address is not the destination IP address: Figure 5 As shown, Figure 5 This is a flowchart illustrating the process of handling IP protocol source IP address not being target IP address, provided by one embodiment of the present invention.
[0096] 5.5 TCP Scan Robustness Modification (Refer to UDP): In the `tcp_input(struct pbuf*p, struct netif*inp)` method, add the following response code: [ICMP port unreachable response code]. Figure 6 As shown, Figure 6 This is a flowchart of a modified TCP scan robustness procedure provided in one embodiment of the present invention.
[0097] 5.6 ARP Protocol Address / Mapping Spoofing Protection (ARP Cache Storm):
[0098] 5.6.1 Static MAC-->IP mapping table enabled: To address the ARP cache table corruption handling capability, a static MAC-->IP mapping table is used.
[0099] Specifically, it is declared in lwipopts.h
[0100] #define ETHARP_SUPPORT_STATIC_ENTRIES1
[0101] And register it using etharp_add_static_entry / etharp_remove_static_entry.
[0102] 5.6.2 Optimization and adjustment of cache table size:
[0103] Declaration in lwipopts.h
[0104] #define ARP_TABLE_SIZE optimization value
[0105] 5.6.3 Optimization and adjustment of cache table retention time:
[0106] Declaration in lwipopts.h
[0107] #define ARP_MAXAGE optimization value
[0108] 5.7 ARP Reply Blocked (ARP Reply Storm): Currently, LWIP's ARP replies are mainly for IP addresses that are already in use. dhcp_arp_reply(netif,&sipaddr); disable LWIP_DHCP.
[0109] Declaration in lwipopts.h
[0110] #define LWIP_DHCP 0
[0111] 5.8 TCP Concurrency Capability (TCP Concurrency Check):
[0112] Declaration in lwipopts.h
[0113] #define MEMP_NUM_TCP_PCB design value
[0114] 5.9 TCP Listening Capability (TCP SYN Data Storm):
[0115] 5.9.1 Limiting the Number of Connections in the Listening Queue: Enabled by `tcp_listen_with_backlog()`. This function limits the number of unprocessed connections in the listening queue. To use this function, `TCP_LISTEN_BACKLOG = 1` needs to be set in the configuration file `lwipopts.h`.
[0116] #define TCP_LISTEN_BACKLOG 1
[0117] 5.9.2 Optimization and Adjustment to Speed Up the Elimination of Invalid SYN Requests: Optimize the time for eliminating invalid SYN requests.
[0118] In src\include\lwip\priv\tcp_priv.h
[0119] #define TCP_SYN_RCVD_TIMEOUT optimization value / *milliseconds* /
[0120] 5.9.3 Optimization and adjustment of the number of TCP connections to listen for: Modify the configuration file lwipopts.h
[0121] #define TCP_LISTEN_BACKLOG adjustment value
[0122] 5.10 Handling TCP FIN Data Storms:
[0123] 5.10.1 Improved waiting time for eliminating invalid FINs: Optimized the waiting time for eliminating invalid FINs.
[0124] In src\include\lwip\opt.h
[0125] #define TCP_FIN_WAIT_TIMEOUT optimization value / *milliseconds* /
[0126] 5.10.2 Improved TCP Closing Time: Optimized TCP closing time.
[0127] In src\include\lwip\priv\tcp_priv.h
[0128] #define LWIP_TCP_CLOSE_TIMEOUT_MS_DEFAULT optimization value
[0129] Example 3
[0130] This invention provides a TCP / IP-based secure communication method, which includes a testing method. The specific steps of the testing method are as follows:
[0131] Step 1: Perform a robustness test on Modbus TCP protocol communication;
[0132] Step 1.1 Read Coil Test: Send a malformed read coil request packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions;
[0133] Step 1.2 Read Discrete Input Test: Send a malformed packet containing read discrete input requests with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such anomalies;
[0134] Step 1.3 Read Holding Register Test: Send a malformed Read Holding Register Request packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions;
[0135] Step 1.4 Read Input Register Test: Send a malformed Read Input Register Request packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions;
[0136] Step 1.5 Write Single Coil Test: Send a malformed Write Single Coil Request packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions;
[0137] Step 1.6 Write Single Register Test: Send a malformed packet containing write single register requests with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions;
[0138] Step 1.7 Write Multiple Coil Test: Send multiple coil request malformed packets with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0139] Step 1.8 Write Multiple Registers Test: Send a write multiple registers request malformation packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0140] Step 1.9 Read File Record Test: Send a malformed file record read request packet with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0141] Step 1.10 Write File Record Test: Send a malformed write file record request packet with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0142] Step 1.11 Masked Write Register Test: Send a masked write register request malformed packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0143] Step 1.12 Read / Write Multiple Registers Test: Send a malformed packet containing read / write multiple register requests with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0144] Step 1.13 Read FIFO queue test: Send a malformed FIFO queue read request packet with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0145] Step 1.14 Read Device Identifier Test: Send a Malformed Read Device Identifier Request packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0146] Step 1.15 Unified Messaging Application Service Test: Send a Unified Messaging Application Service Request Malformation Packet with field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0147] Step 1.16 Diagnostic Service Test: Send a diagnostic service request malformation packet containing field data errors and field structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0148] Step 2: Perform OPC UA protocol communication robustness test.
[0149] Step 2.1 Activation Session Request Test: Send an malformed activation session request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0150] Step 2.2 Create Monitored Item Request Test: Send a malformed Create Monitored Item Request packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such anomalies.
[0151] Step 2.3 Session Request Creation Test: Send a malformed session request creation data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0152] Step 2.4 Create Subscription Request Test: Send a malformed subscription request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0153] Step 2.5 Obtain the endpoint request test used by the server: Send a malformed data packet containing field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0154] Step 2.6 Open Secure Channel Request Test: Send a malformed Open Secure Channel Request packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0155] Step 2.7 Close Security Channel Request Test: Send a malformed Close Security Channel Request packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0156] Step 2.8 Close Session Request Test: Send a malformed Close Session Request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0157] Step 2.9 Add Node Request Test: Send a malformed Add Node Request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0158] Step 2.10 Cancellation Request Test: Send a malformed cancellation request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0159] Step 2.11 Read Request Test: Send a malformed read request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0160] Step 2.12 Browse Node Reference Test: Send a malformed browser node reference request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0161] Step 2.13 Publish Request Test: Send a malformed publish request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0162] Step 2.14 Query First Request Test: Send a query first request malformed data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0163] Step 2.15 Query Next Request Test: Send a query next request malformed data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0164] Step 2.16 Historical Read Request Test: Send a malformed historical read request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such anomalies.
[0165] Step 2.17 Write Request Test: Send a malformed write request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0166] Step 2.18 Historical Update Request Test: Send a malformed historical update request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle this type of exception.
[0167] Step 2.19 Call Request Test: Send a call request malformed data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0168] Step 2.20 Browse State Model Test: Send a malformed browser state model request data packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0169] Step 2.21 Read State Model Test: Send a malformed data packet containing read state model requests with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0170] Step 2.22 Release State Model Test: Send a malformed release state model request packet with field data errors and message structure errors to the DUT to examine the DUT's ability to handle such exceptions.
[0171] Example 4
[0172] Figure 7 This is a block diagram of a TCP / IP-based information security communication device provided in one embodiment of the present invention. Figure 7 As shown, this embodiment of the invention provides a TCP / IP-based information security communication device, deployed in an industrial control system. The device includes:
[0173] The data processing inspection module is used to perform data processing inspection on the communication input data of the industrial control system based on the information security communication inspection model; wherein, the information security communication inspection model is constructed by data communication inspection rules corresponding to at least one data inspection indicator;
[0174] The reinforcement requirement data determination module is used to determine the information security reinforcement requirement data corresponding to each data inspection indicator based on the data processing inspection results.
[0175] The information security hardening module is used to perform information security hardening of the corresponding industrial control system based on the information security hardening requirement data corresponding to each data inspection indicator.
[0176] The communication information security testing module is used to determine whether the communication program of the industrial control system has been hardened after information security hardening is completed. The communication program of the industrial control system that has been hardened after information security hardening and passes the communication information security test is used as the current communication program of the industrial control system. Based on the current communication program of the industrial control system, information security communication of the industrial control system is carried out.
[0177] Specifically, this device performs data processing checks on the communication input data of the industrial control system according to the data communication check rules corresponding to each data check indicator in the information security communication check model, thereby performing information security communication checks on the current communication program of the industrial control system. Based on the data processing check results, it determines the information security hardening requirement data corresponding to each data check indicator, and then performs information security hardening on the corresponding industrial control system by comprehensively considering the information security hardening requirement data corresponding to each data check indicator. After determining that the information security hardening is completed, it performs communication information security testing on the communication program of the industrial control system after information security hardening. The communication program of the industrial control system that passes the communication information security test after information security hardening is used as the current communication program of the industrial control system, and information security communication of the industrial control system is performed based on the current communication program of the industrial control system. This device addresses the problems of TCP / IP protocol being vulnerable to attacks, information being easily lost, and lacking detection methods, and provides specific methods for achieving information security checks and hardening. It can improve the security problems of industrial control system communication while ensuring the functional safety and physical security reliability of the industrial control system, and provides detailed measures, processes, and implementation methods for information security checks, hardening, and testing. Without altering the inherent simplicity and openness of the TCP / IP protocol, this solution addresses the shortcomings of TCP / IP, such as lack of integrity checks, network congestion caused by malicious data packets, and vulnerability to tampering during plaintext data transmission. It effectively prevents attacks including data tampering, data storms, denial-of-service attacks, obfuscated data, vulnerability exploitation, and operator error. This powerful tool enhances the information security of industrial control systems, significantly improving communication security while maintaining functionality and reliability, thus ensuring the effectiveness of TCP / IP protocol security hardening. This guarantees secure and reliable communication between industrial control system clients and servers, reducing the likelihood of attacker intrusion.
[0178] Example 5
[0179] The present invention also provides a machine-readable storage medium storing instructions that, when executed by a processor 100, configure the processor 100 to perform the aforementioned TCP / IP-based secure communication method.
[0180] Machine-readable storage media include both permanent and non-permanent, removable and non-removable media, which can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0181] The present invention also provides an electronic device 10, which includes a memory 101, a processor 100, and a computer program 102 stored in the memory 101 and executable on the processor 100. When the processor 100 executes the computer program 102, it implements the above-described TCP / IP-based secure communication method.
[0182] like Figure 8 The diagram shown is a schematic representation of an electronic device according to an embodiment of the present invention. Figure 8 As shown, the electronic device 10 of this embodiment includes a processor 100, a memory 101, and a computer program 102 stored in the memory 101 and executable on the processor 100. When the processor 100 executes the computer program 102, it implements the steps in the method embodiment described above. Alternatively, when the processor 100 executes the computer program 102, it implements the functions of each module / unit in the device embodiment described above.
[0183] For example, computer program 102 can be divided into one or more modules / units, one or more of which are stored in memory 101 and executed by processor 100 to complete the present invention. One or more modules / units can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of computer program 102 in electronic device 10. For example, computer program 102 can be divided into a data processing and inspection module, a hardening requirement data determination module, an information security hardening module, and a communication information security testing module.
[0184] Electronic device 10 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. Electronic device 10 may include, but is not limited to, processor 100 and memory 101. Those skilled in the art will understand that... Figure 8 This is merely an example of electronic device 10 and does not constitute a limitation on electronic device 10. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device may also include input / output devices, network access devices, buses, etc.
[0185] The processor 100 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0186] The memory 101 can be an internal storage unit of the electronic device 10, such as a hard disk or RAM of the electronic device 10. The memory 101 can also be an external storage device of the electronic device 10, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the electronic device 10. Furthermore, the memory 101 can include both internal and external storage units of the electronic device 10. The memory 101 is used to store computer programs and other programs and data required by the electronic device 10. The memory 101 can also be used to temporarily store data that has been output or will be output.
[0187] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0188] Those skilled in the art will understand that embodiments of this application can be provided as a method, system, or computer program 102 product. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program 102 product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0189] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program 102 products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program 102 instructions. These computer program 102 instructions can be provided to a processor 100 of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor 100 of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0190] These computer program 102 instructions may also be stored in a computer-readable storage medium 101 that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium 101 produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0191] These computer program 102 instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable apparatus for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0192] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0193] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A TCP / IP-based secure information communication method, characterized in that, Applied to industrial control systems, the method includes: Based on the information security communication inspection model, data processing inspection is performed on the communication input data of the industrial control system; wherein, the information security communication inspection model is constructed by data communication inspection rules corresponding to at least one data inspection indicator; Based on the data processing and inspection results, determine the information security hardening requirements corresponding to each data inspection indicator; Based on the information security hardening requirements data corresponding to each data inspection indicator, perform information security hardening on the corresponding industrial control system. After determining that information security hardening is completed, a communication information security test is performed on the communication program of the hardened industrial control system. The communication program of the hardened industrial control system that passes the communication information security test is used as the current communication program of the industrial control system. Based on the current communication program of the industrial control system, information security communication of the industrial control system is carried out.
2. The information security communication method based on TCP / IP according to claim 1, characterized in that, The data inspection metrics include data syntax metrics, data storm metrics, fuzzy data metrics, and scan robustness metrics; The data syntax indicators and the corresponding data syntax processing and checking rules are used to check the validity and integrity of the communication input data of the industrial control system according to the syntax rules of the communication protocol for transmitting communication input data. The data storm indicator and the corresponding data storm processing and inspection rules are used to check for data storms of various communication protocols during the transmission of communication input data of the industrial control system. Among them, the data storm of various communication protocols indicates that the number of input communication input data of the industrial control system transmitted based on the corresponding communication protocol is greater than a preset threshold, causing an abnormality in the transmission process of the communication input data corresponding to that communication protocol. The fuzzy data processing and inspection rules corresponding to the fuzzy data indicators are used to inspect the fuzzy data of the communication input data of the industrial control system according to the communication protocol of the communication input data; wherein, the fuzzy data represents the fields in the communication input data that have random variation characteristics; The scan robustness check rules corresponding to the scan robustness index are used to check the industrial control system's ability to respond to network scans; wherein, the industrial control system's ability to respond to network scans includes at least whether the industrial control system has the ability to respond to network scan requests corresponding to various communication protocols.
3. The TCP / IP-based secure communication method according to claim 2, characterized in that, The communication protocols include ARP, IPv4, ICMP, TCP, and UDP. The specific content of the data syntax processing and checking rules corresponding to the data syntax indicators includes: Check the validity and integrity of data packets and message headers of communication input data transmitted based on the ARP protocol, as well as the ARP protocol header; Check the validity and integrity of data packets and headers of communication input data transmitted based on the IPv4 protocol; Check the validity and integrity of data packets and headers of communication input data transmitted based on the ICMP protocol, the source address of ICMP data packets, and the combination of ICMP type and code; Check the validity and integrity of data packets and headers of communication input data transmitted based on the TCP protocol, the source address of TCP packets, TCP / IP syntax, TCP random numbers, TCP data priority, TCP data timestamps, and connection state identifiers TCP ACK / Echo; Check the validity and integrity of data packets and headers of communication input data transmitted based on the UDP protocol, the validity of UDP packet data, and the source address of UDP packets.
4. The TCP / IP-based secure communication method according to claim 2, characterized in that, The communication protocols include ARP, IPv4, ICMP, TCP, and UDP. The specific content of the data storm handling and inspection rules corresponding to the data storm indicators includes: Check for data storms in the ARP protocol, IPv4 protocol, ICMP protocol, TCP protocol, UDP protocol, ARP address spoofing data, and ARP mapping update data.
5. The TCP / IP-based secure communication method according to claim 2, characterized in that, The specific content of the fuzzy data processing inspection rules corresponding to the fuzzy data indicators includes: According to the fuzzy data judgment rules corresponding to various communication protocols, check the fuzzy data in the communication input data transmitted based on different communication protocols; The fuzzy data judgment rules corresponding to the various communication protocols are obtained by one or more combinations of data CRC check rules, data checksum rules, corresponding communication protocol field judgment rules, and upper-layer application multi-field rules.
6. The TCP / IP-based secure communication method according to claim 2, characterized in that, The specific content of the scan robustness check rules corresponding to the scan robustness index includes: Perform TCP and UDP scan robustness checks on the industrial control system; The TCP scan robustness check is used to check whether the industrial control system has the ability to respond to network scan requests corresponding to the TCP protocol. UDP scan robustness checks are used to verify whether an industrial control system has the capability to respond to network scan requests corresponding to the UDP protocol.
7. The TCP / IP-based secure communication method according to claim 1, characterized in that, The communication information security test performed on the communication program of the industrial control system after information security hardening includes: The communication programs of the industrial control system, after being hardened for information security, were subjected to Modbus TCP protocol robustness tests and OPC UA protocol robustness tests in sequence; among them, The Modbus TCP protocol communication robustness test is to test the communication robustness of the industrial control system's communication program under the Modbus TCP protocol after information security hardening. The OPC UA protocol communication robustness test is used to test the communication robustness of the communication program of an industrial control system that has been hardened with information security under the OPC UA protocol.
8. The TCP / IP-based secure communication method according to claim 7, characterized in that, The ModbusTCP protocol communication robustness test includes read coil test, read discrete input test, read holding register test, read input register test, write single coil test, write single register test, write multiple coil test, write multiple register test, read file record test, write file record test, mask write register test, read / write multiple register test, read FIFO queue test, read device identifier test, unified messaging application service test, and diagnostic service test.
9. The TCP / IP-based secure communication method according to claim 7, characterized in that, The OPC UA protocol communication robustness test includes the following tests: activate session request test, create monitored item request test, create session request test, create subscription request test, obtain endpoint request test used by the server, open secure channel request test, close secure channel request test, close session request test, add node request test, cancel request test, read request test, browse node reference test, publish request test, query first request test, query next request test, history read request test, write request test, history update request test, call request test, browse state model test, read state model test, and publish state model test.
10. A TCP / IP-based information security communication device, characterized in that, Deployed in an industrial control system, the device includes: The data processing inspection module is used to perform data processing inspection on the communication input data of the industrial control system based on the information security communication inspection model; wherein, the information security communication inspection model is constructed by data communication inspection rules corresponding to at least one data inspection indicator; The reinforcement requirement data determination module is used to determine the information security reinforcement requirement data corresponding to each data inspection indicator based on the data processing inspection results. The information security hardening module is used to perform information security hardening of the corresponding industrial control system based on the information security hardening requirement data corresponding to each data inspection indicator. The communication information security testing module is used to determine whether the communication program of the industrial control system has been hardened after information security hardening is completed. The communication program of the industrial control system that has been hardened after information security hardening and passes the communication information security test is used as the current communication program of the industrial control system. Based on the current communication program of the industrial control system, information security communication of the industrial control system is carried out.
11. A machine-readable storage medium storing instructions thereon, characterized in that, When executed by a processor, this instruction causes the processor to be configured to perform the TCP / IP-based secure communication method as described in any one of claims 1 to 9.
12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the TCP / IP-based secure communication method as described in any one of claims 1 to 9.