A security detection method, device and equipment of an industrial control network and a medium
Patent Information
- Application Number
- CN202610871828.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-16
- Publication Date
- 2026-09-29
AI Technical Summary
[0015]本申请实施例提供的一种工业控制网络的安全检测方法、装置、设备及介质,通过部署在工业控制网络中的被动流量探针采集原始流量,能够实现对生产环境的零干扰;对专有工业协议的会话数据进行全字段语义解析,能够实现深层次的语义级脆弱性检测;通过规则匹配以及基于图算法和时序算法对通信行为模型的分析,实现对工业控制系统的安全风险的多维度深度挖掘;最终生成综合漏洞报告,提升检测结果的全面性。
Smart Images

Figure CN122845181A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology for industrial control systems, and in particular to a security detection method, apparatus, equipment, and medium for industrial control networks. Background Technology
[0002] With the deep integration of the Industrial Internet and the continuous improvement of intelligent manufacturing, the network boundaries of Industrial Control Systems (ICS) are becoming increasingly blurred, and the cybersecurity threats they face are becoming more diversified, sophisticated, and covert.
[0003] However, traditional proactive security detection methods originating from information technology (IT) networks, such as vulnerability scanners and intrusion detection systems, reveal serious shortcomings when applied to industrial control environments with high availability and real-time requirements. The act of proactively sending probe packets can easily cause resource overload, instruction blocking, or even system crashes in critical industrial control equipment such as PLCs, RTUs, and DCS controllers, directly leading to production interruptions and resulting in significant economic losses and security risks. Furthermore, traditional detection methods often limit their understanding of industrial control protocols to port and service identification, lacking the ability to deeply analyze core semantics, thus failing to discover deep-seated security vulnerabilities existing at the protocol logic layer and business application layer. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a security detection method, device, equipment and medium for industrial control networks, which performs full-field semantic parsing of session data of proprietary industrial protocols without interfering with the production environment; and achieves multi-dimensional in-depth mining of security risks of industrial control systems through rule matching and analysis of communication behavior models based on graph algorithms and time-series algorithms.
[0005] This application provides a security detection method for industrial control networks, the method comprising: By using passive traffic probes deployed in the industrial control network, raw traffic in the industrial control network is collected, and the collected raw traffic is preprocessed to obtain session data. Based on the message characteristics of the session data, the corresponding proprietary protocol parser is invoked to perform full-field semantic parsing on the session data and generate structured semantic information; The structured semantic information is matched with rules in a predefined industrial control system vulnerability knowledge base to determine the first network vulnerability detection information; A communication behavior model is constructed based on the structured semantic information, and the communication behavior model is analyzed by graph algorithms and time-series algorithms to obtain second network vulnerability detection information; wherein, the communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol operation state sequence; A comprehensive vulnerability report is generated by combining the first network vulnerability detection information and the second network vulnerability detection information.
[0006] Furthermore, a communication behavior model is constructed based on the structured semantic information, including: Based on the source address, destination address, and communication timing in the structured semantic information, the request-response relationship between devices is recorded, and the request-response relationship model is constructed; wherein, the request-response relationship model includes at least one of the device identifiers, communication modes, and communication frequencies of the communicating parties; Based on the protocol state field in the structured semantic information, the state transition sequence is extracted, and the protocol state machine model is constructed.
[0007] Furthermore, the request-response relationship model is analyzed using a graph algorithm to obtain second network vulnerability detection information, including: In the request-response relationship model, devices are abstracted as nodes, and the relationships between devices are abstracted as edges to construct a heterogeneous graph of the industrial control network. A graph neural network model is used to perform multi-layer message propagation calculations on the heterogeneous graph of the industrial control network to obtain the representation vector of each node; Based on the representation vector of each node, node anomaly classification is performed to obtain second network vulnerability detection information about device anomalies.
[0008] Furthermore, the request-response relationship model is analyzed using a graph algorithm to obtain second network vulnerability detection information, which also includes: The probability of an attack reaching a predetermined key node from an arbitrary source node is calculated based on the representation vector of each node. Based on the reachability probability, potential cross-device attack chains are identified, and second network vulnerability detection information related to the attack path is generated.
[0009] Furthermore, the protocol state machine model is analyzed using a time-series algorithm to obtain second network vulnerability detection information, including: Extract multivariate time series features for each device or communication link in the protocol state machine model and cut them into sliding window sequences of fixed length; The sliding window sequence is input into a pre-trained time-series anomaly detection model to calculate the reconstruction probability; wherein, the time-series anomaly detection model is obtained by unsupervised training using time-series features containing normal communication traffic. Based on the reconstruction probability, the temporal anomaly score is determined, and the second network vulnerability detection information related to the temporal anomaly is obtained.
[0010] Furthermore, by combining the first network vulnerability detection information and the second network vulnerability detection information, a comprehensive vulnerability report is generated, including: Based on the DS evidence theory, the first network vulnerability detection information and the second network vulnerability detection information are fused to obtain comprehensive network vulnerability detection information with confidence scores; The comprehensive network vulnerability detection information is processed by evidence association on an individual event basis, and the corresponding original traffic, session data and communication behavior model context are associated to form an evidence chain. The comprehensive network vulnerability detection information is classified into risk levels and / or types to obtain the classification results; Based on the chain of evidence and the division results, the comprehensive vulnerability report is generated.
[0011] Furthermore, the method also includes: Obtain feedback signals regarding the comprehensive vulnerability report; Based on the feedback signal, incremental training or parameter fine-tuning is performed on the graph neural network model on which the graph algorithm depends and the time anomaly detection model on which the time sequence algorithm depends.
[0012] This application embodiment also provides a security detection device for an industrial control network, the device comprising: The acquisition module is used to acquire raw traffic in the industrial control network through passive traffic probes deployed in the industrial control network, and to preprocess the acquired raw traffic to obtain session data; The parsing module is used to call the corresponding proprietary protocol parser based on the message characteristics of the session data to perform full-field semantic parsing of the session data and generate structured semantic information; The matching module is used to match the structured semantic information with rules in a predefined industrial control vulnerability knowledge base to determine the first network vulnerability detection information; The analysis module is used to construct a communication behavior model based on the structured semantic information, and to analyze the communication behavior model through graph algorithms and time-series algorithms to obtain second network vulnerability detection information; wherein, the communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol operation state sequence; The generation module is used to combine the first network vulnerability detection information and the second network vulnerability detection information to generate a comprehensive vulnerability report.
[0013] This application also provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. When the machine-readable instructions are executed by the processor, the steps of the security detection method for industrial control networks described above are performed.
[0014] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the security detection method for industrial control networks described above.
[0015] This application provides a security detection method, apparatus, equipment, and medium for industrial control networks. By collecting raw traffic through passive traffic probes deployed in the industrial control network, it can achieve zero interference with the production environment; by performing full-field semantic parsing on session data of proprietary industrial protocols, it can achieve deep semantic-level vulnerability detection; by analyzing communication behavior models through rule matching and graph-based and time-series algorithms, it can achieve multi-dimensional and in-depth mining of security risks in industrial control systems; and finally, it generates a comprehensive vulnerability report to improve the comprehensiveness of the detection results.
[0016] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart of a security detection method for an industrial control network provided in an embodiment of this application is shown; Figure 2 This paper shows a schematic diagram of the structure of a security detection system for an industrial control network provided in an embodiment of this application; Figure 3 This illustration shows a structural schematic diagram of a security detection device for an industrial control network provided in an embodiment of this application; Figure 4A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. Based on the embodiments of this application, every other embodiment obtained by those skilled in the art without inventive effort falls within the scope of protection of this application.
[0020] Research has revealed that with the deep integration of the Industrial Internet and the continuous improvement of intelligent manufacturing, the network boundaries of Industrial Control Systems (ICS) are becoming increasingly blurred, and the cybersecurity threats they face are becoming more diversified, sophisticated, and covert.
[0021] However, traditional proactive security detection methods originating from information technology (IT) networks, such as vulnerability scanners and intrusion detection systems, reveal serious shortcomings when applied to industrial control environments with high availability and real-time requirements. The act of proactively sending probe packets can easily cause resource overload, instruction blocking, or even system crashes in critical industrial control equipment such as PLCs, RTUs, and DCS controllers, directly leading to production interruptions and resulting in significant economic losses and security risks. Furthermore, traditional detection methods often limit their understanding of industrial control protocols to port and service identification, lacking the ability to deeply analyze core semantics, thus failing to discover deep-seated security vulnerabilities existing at the protocol logic layer and business application layer.
[0022] Based on this, this application provides a security detection method for industrial control networks, which performs full-field semantic parsing of session data of proprietary industrial protocols without interfering with the production environment; and achieves multi-dimensional in-depth mining of security risks of industrial control systems through rule matching and analysis of communication behavior models based on graph algorithms and time-series algorithms.
[0023] The detection method provided in this application embodiment can be executed by a security detection system; please refer to... Figure 1 and Figure 2 , Figure 1 A flowchart illustrating a security detection method for an industrial control network provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of a security detection system for an industrial control network provided in an embodiment of this application. Figure 1As shown in the embodiments of this application, the security detection method includes: S101. By using passive traffic probes deployed in the industrial control network, the raw traffic in the industrial control network is collected, and the collected raw traffic is preprocessed to obtain session data.
[0024] like Figure 2 As shown, the data acquisition and preprocessing layer is responsible for acquiring the raw industrial control network data in an interference-free manner and performing preliminary processing to provide high-quality data input for upper-level analysis.
[0025] Among them, the raw traffic of the industrial control network (A1) is the data source of this application embodiment. The traffic originates from key communication links in the industrial control network, such as the network boundary between the field control layer and the process monitoring layer, and the backbone links of the core switch. These links carry all communication messages between various industrial control devices such as PLCs, HMIs, SCADA servers, and engineering workstations.
[0026] Passive Traffic Probe (A2): This is the physical basis of the embodiments of this application. The probe is typically deployed as a hardware device or virtual machine at a critical node in the network. It does not actively send any data packets, but instead redirects all traffic copies of the target port to the monitoring port where the probe resides by configuring the port mirroring (SPAN) function of the switch or router. Therefore, this purely passive monitoring mechanism can fundamentally eliminate the possibility of interference with production equipment.
[0027] Traffic Preprocessing Module (A3): The raw network traffic is a continuous bit stream. This module can transform the raw traffic into meaningful session data. Specific preprocessing methods may include: Packet Reassembly: Processing network packets that may be fragmented and reassembling them into complete application layer packets; Session Segmentation: Dividing the continuous packet stream into independent communication sessions based on the TCP / IP 5-tuple (source IP, destination IP, source port, destination port, transport layer protocol), for example, distinguishing a complete Modbus TCP connection between an HMI and a PLC; Basic Packet Field Extraction: Initially extracting common network layer and transport layer information for each packet, such as timestamp, packet length, TTL, etc., to provide metadata for subsequent analysis.
[0028] S102. Based on the message characteristics of the session data, the corresponding proprietary protocol parser is invoked to perform full-field semantic parsing on the session data and generate structured semantic information.
[0029] like Figure 2As shown, the system also includes a core parsing and modeling layer; among which, the deep packet parsing engine (B1) receives preprocessed session data from (A3) and automatically distributes it to the corresponding proprietary protocol parser according to packet characteristics (such as target port, specific magic number).
[0030] For example, Figure 2 The diagram illustrates four protocol parsers: Protocol A parser (B2) Modbus / TCP, Protocol B parser (B3) Siemens S7, Protocol C parser (B4) Profibus-DP, and Protocol D parser (B5) Ethnet / IP. These proprietary protocol parsers are the concrete execution units of the deep packet analysis engine. Each parser embeds complete syntax and semantic knowledge of the corresponding industry protocol, enabling full-field semantic parsing of session data.
[0031] Taking Modbus / TCP and Siemens S7 as an example, the Modbus / TCP parser (B2) parses the function code in the PDU (such as 01 for reading coils, 05 for writing single coils), as well as the starting address and quantity in the subsequent data fields. For example, it can identify a message as "Write data to 10 registers starting with holding register 40001".
[0032] Siemens S7 Protocol Parser (B3): This parser is more complex and can parse the job / response structure, function groups (such as programming, cyclic data access), data types (such as Bit, Byte, Word, DWord), data block numbers (DB Block Number), and offset addresses of S7 communication. For example, it can identify a read / write operation targeting a bit variable "DB10.DBX20.0".
[0033] After deep parsing, the unstructured message payload is transformed into structured data objects rich in business semantics, thus obtaining structured semantic information. These objects contain all the key fields parsed earlier, such as: Protocol Type: S7; Operation Type: Write; Target: DB10, DBB200; Value: 0xFFFF, etc. This forms the basis for all subsequent intelligent analysis.
[0034] S103. Match the structured semantic information with the rules in the predefined industrial control vulnerability knowledge base to determine the first network vulnerability detection information.
[0035] Here, the Industrial Control System Vulnerability Knowledge Base (C1) is a combination of static and dynamic knowledge bases. It stores: Security configuration baselines: such as "Write operations to DB1 (System Configuration Block) are prohibited" and "Modbus function code 05 (write to a single coil) can only be initiated by an authorized master station"; CVE vulnerability characteristics: publicly disclosed CVE vulnerabilities in industrial control equipment are transformed into detectable rules, such as "For a certain PLC model, a specific function code and parameter combination can trigger a denial-of-service attack"; and process logic rules: rules defined based on an understanding of the production process, such as "When the equipment is running, the emergency stop signal should not be reset."
[0036] The rule matching engine (C2) performs real-time, high-speed matching of structured semantic information with rules in the industrial control system vulnerability knowledge base (C1) to determine the first network vulnerability detection information. For example, when an S7 message with function code 0x29 (secure programming) from a non-engineering station IP is parsed, the rule matching engine (C2) will immediately match the rule "unauthorized secure programming operation" in the knowledge base, thereby discovering a configuration vulnerability.
[0037] S104. Construct a communication behavior model based on the structured semantic information, and analyze the communication behavior model using graph algorithms and time-series algorithms to obtain the second network vulnerability detection information.
[0038] The communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol's operational state sequence.
[0039] On the one hand, the communication behavior modeling module (B7) in the core parsing and modeling layer can use the output structured semantic information (B6) to learn the normal behavior profile of the industrial control network and build a communication behavior model.
[0040] In specific implementation, the communication behavior model constructed based on the structured semantic information in S104 may include: Step a1: Based on the source address, destination address, and communication timing in the structured semantic information, record the request-response relationship between devices and construct the request-response relationship model.
[0041] The request-response relationship model includes at least one of the following: device identifiers of the communicating parties, communication mode, and communication frequency. This model records and learns which devices in the network have communication relationships and the typical communication patterns between them. For example, the model records that an HMI with IP address 192.168.1.10 typically sends a read request to a PLC with IP address 192.168.1.20, and the PLC responds.
[0042] Step a2: Extract the state transition sequence from the protocol state field in the structured semantic information and construct the protocol state machine model.
[0043] This model describes the expected state sequence of an industrial control protocol during normal operation. For example, for an S7 connection, a TCP connection is typically established first, followed by COTP connection negotiation, and finally S7 communication. Any communication that violates this state sequence (such as sending S7 data directly without negotiation) will be marked as abnormal.
[0044] On the other hand, the system also includes an intelligent analysis and mining layer, which can proactively and deeply mine security vulnerabilities in the system by utilizing the information provided by the core parsing layer. In step S104, the communication behavior model is analyzed using graph algorithms and time-series algorithms to obtain the second network vulnerability detection information, which can be executed by the intelligent inference engine (C3). This engine deals with more hidden and complex risks that cannot be directly covered by rules.
[0045] In one possible implementation, when analyzing the request-response relationship model using a graph algorithm in step S104 to obtain the second network vulnerability detection information, it may specifically include: Step b1: Abstract the devices in the request-response relationship model as nodes, and the relationships between devices as edges to construct a heterogeneous graph of the industrial control network.
[0046] The feature engineering and graph construction module (C3_1) transforms the data from (B6) and (B7) into a format suitable for complex model processing. Specifically, this includes graph construction; abstracting devices as graph nodes, and constructing different types of edges based on communication relationships (such as TCP connections) and logical relationships (such as read / write dependencies) to form a dynamic heterogeneous graph of the industrial control network. Nodes have initial feature vectors. (Originating from device attributes and behavioral characteristics), the edges contain type information (communication, physical, logical, etc.).
[0047] Step b2: Use a graph neural network model to perform multi-layer message propagation calculation on the heterogeneous graph of the industrial control network to obtain the representation vector of each node.
[0048] In this step, the graph neural network model (C3_2) employs a relational graph convolutional network (R-GCN) to process heterogeneous industrial control network graphs. At each layer... ,node The features are updated as follows:
[0049] Through multi-layer propagation, each node obtains a dense representation vector that incorporates global topological information. .
[0050] Step b3: Classify node anomalies based on the representation vector of each node to obtain second network vulnerability detection information about device anomalies.
[0051] In this step, the anomaly classification module (C3_5) is based on The devices are classified as abnormal to obtain secondary network vulnerability detection information about the device abnormalities, such as the abnormality type of a certain device being a compromised host.
[0052] Furthermore, in S104, the request-response relationship model is analyzed using a graph algorithm to obtain second network vulnerability detection information, which may also include: Step b4: Calculate the reachability probability of an attack from any source node to a preset key node based on the representation vector of each node.
[0053] Step b5: Identify potential cross-device attack chains based on the reachability probability and generate second network vulnerability detection information related to the attack path.
[0054] Here, the attack path reasoning (C3_4) module can utilize the node representation vectors. Calculate the attack from the node To the critical node reachability probability Then, based on the reachability probability, potential cross-device attack chains are identified. For example, if the reachability probability of a certain path is greater than a preset threshold, that path is considered a potential cross-device attack chain; or the paths are sorted from largest to smallest reachability probability, and the top N paths are considered potential cross-device attack chains; thus, the second network vulnerability detection information related to the attack path is obtained.
[0055] In one example, the system can issue a warning: although maintenance workstation A is currently only observed collecting information, its position in the diagram indicates that it has a high-risk path to influence critical actuator C by controlling intermediate PLC B. This application's embodiment, through its ability to infer potential attack chains, shifts security protection from reactive response to proactive warning, greatly enhancing the initiative of defense.
[0056] In another possible implementation, in S104, the protocol state machine model is analyzed using a timing algorithm to obtain second network vulnerability detection information, including: Step c1: Extract multivariate time series features for each device or communication link based on the protocol state machine model, and cut them into sliding window sequences of fixed length.
[0057] Here, the feature engineering and graph construction module (C3_1) can also perform temporal feature extraction; it extracts multivariate time series features for each device or communication link in the protocol state machine model, such as the number of requests for a specific function code per unit time, session duration, message length statistics, etc., and cuts them into fixed-length sliding window sequences. .
[0058] Step c2: Input the sliding window sequence into the pre-trained temporal anomaly detection model and calculate the reconstruction probability.
[0059] The time-series anomaly detection model (C3_3) uses a hybrid model combining variational autoencoder (VAE) and LSTM to learn normal communication time-series patterns. Specifically, it is obtained by unsupervised training using time-series features containing normal communication traffic.
[0060] The encoder in the timing anomaly detection model will use the timing window Mapping to latent space The decoder from Reconstruct the input. During inference, calculate the reconstruction probability:
[0061] Step c3: Determine the temporal anomaly score based on the reconstruction probability to obtain the second network vulnerability detection information related to the temporal anomaly.
[0062] In this step, the time series anomaly scoring module (C3_6) converts the reconstruction probability and the pre-configured mapping relationship to obtain the time series anomaly score.
[0063] S105. Combine the first network vulnerability detection information and the second network vulnerability detection information to generate a comprehensive vulnerability report.
[0064] In specific implementation, step S105 may include: S1051. Based on the DS evidence theory, the first network vulnerability detection information and the second network vulnerability detection information are fused to obtain comprehensive network vulnerability detection information with confidence scores.
[0065] In this step, the evidence fusion and uncertainty quantification module (C3_7) receives and fuses various network vulnerability detection information (such as information from C3_4, C3_5, C3_6, etc.). For example, Dempster's evidence theory can be used; exemplarily, the Dempster combination rule is as follows:
[0066] in, This represents the conflict coefficient.
[0067] Furthermore, this application embodiment also addresses the Dirichlet distribution parameters output by the model for classification tasks. Quantifying cognitive uncertainty, entropy value This represents the total uncertainty. In summary, this module outputs a comprehensive network vulnerability detection report with a confidence score. This information can be represented as a security incident conclusion, such as: 85% confidence that this was an attack scan.
[0068] S1052. Perform evidence association processing on the comprehensive network vulnerability detection information according to individual events, and associate the corresponding original traffic, session data and communication behavior model context to form an evidence chain.
[0069] In this step, the comprehensive network vulnerability detection information may include multiple events. The evidence association and risk verification module (C5) performs evidence association processing on the comprehensive network vulnerability detection information according to individual events, associating a single abnormal event with the relevant original traffic, session data, and communication behavior model context (such as the model's input and output) to form an evidence chain. For example, when reporting the comprehensive network vulnerability detection information "unauthorized write operation detected," it will also attach a screenshot of the original message that caused the alarm (Evidence 1), the role of the host that initiated the operation in the relational model (Evidence 2), and the process links that this operation may affect (Evidence 3).
[0070] S1053. Classify the comprehensive network vulnerability detection information by risk level and / or type to obtain the classification results.
[0071] In this step, the evidence association and risk verification module (C5) uses internationally accepted standards (such as CVSS) to rate the vulnerability risk (high, medium, low); in addition, the multi-dimensional vulnerability discovery module (C4) can classify the comprehensive network vulnerability detection information into three categories, such as classifying the discovered vulnerabilities into three categories: (1) Configuration vulnerabilities: such as weak passwords, default passwords, unnecessary service port openings, and excessive access permissions. (2) Logical vulnerabilities: such as protocol implementation vulnerabilities, predictable sequence numbers, abnormal instruction sequences, and potential risks of buffer overflows. (3) Business vulnerabilities: such as operations that violate process logic (abnormal process start and stop), abnormal modification of key parameters, and bypassing of security interlocks.
[0072] S1054. Based on the evidence chain and the division results, the comprehensive vulnerability report is generated.
[0073] Furthermore, the system also includes a result output and response layer, which presents the evidence chain and partitioning results to security operations personnel in a visual and operable form, and supports linkage with external systems.
[0074] The comprehensive vulnerability report generation module (D1) automatically generates detailed vulnerability reports. The report content includes at least: vulnerability title and description: clearly stating the nature of the vulnerability; protocol-level evidence: containing specific message details and field parsing results that triggered the vulnerability; associated CVE number: directly associating it with known CVE vulnerabilities if they match; risk level and impact analysis: explaining the severity of the vulnerability and its potential impact; and remediation recommendations: providing specific and actionable hardening or remediation steps.
[0075] The Real-Time Security Alarm and Situation Awareness Module (D2) provides real-time alarm functionality for high-risk vulnerabilities, immediately notifying maintenance personnel via audio-visual alerts, SMS messages, and work order systems. Simultaneously, all vulnerability discoveries, device assets, and network relationships are integrated into a global security situation view, intuitively displaying the security health status of the entire industrial control network.
[0076] Furthermore, the security detection method provided in this application embodiment also includes: Obtain feedback signals for the comprehensive vulnerability report; based on the feedback signals, perform incremental training or parameter fine-tuning on the graph neural network model on which the graph algorithm depends and the time-series anomaly detection model on which the time-series algorithm depends.
[0077] Here, the intelligent inference engine (C3) also includes an online model update and feedback learning loop (C3_8), which provides a feedback loop. When a comprehensive vulnerability report is confirmed or denied by a security analyst, this feedback signal is used to incrementally update the model parameters in the graph neural network model (C3_2) and the temporal anomaly detection model (C3_3), achieving continuous learning and adaptive optimization.
[0078] After introducing this loop, the execution flow of this embodiment becomes a continuous closed-loop process: the data flow begins with (A1) the raw traffic of the industrial control network, which is passively collected by the passive traffic probe (A2) and preprocessed by the traffic preprocessing module (A3). Then, it enters the deep packet parsing engine (B1) for semantic parsing, producing structured semantic information (B6). This data is used for behavior modeling by the communication behavior modeling module (B7) and, together with the industrial control vulnerability knowledge base (C1), is input into the rule matching engine (C2) for rule matching and the intelligent inference engine (C3) for deep mining. The discovered vulnerabilities are verified and evaluated by the evidence association and risk verification module (C5), and finally, reports and alarms are generated and output through the comprehensive vulnerability report generation module (D1) and the real-time security alarm and situational awareness module (D2). The feedback results of the output can be fed back to the industrial control vulnerability knowledge base (C1) and the communication behavior model (B7), enabling the system to learn and continuously optimize itself.
[0079] This application provides a security detection method for industrial control networks, which has the following technical effects: First, it achieves deep semantic-level vulnerability detection: Traditional industrial control system security detection tools are mostly based on IT security technologies, and their protocol analysis capabilities are limited, usually remaining at the level of identifying ports, services, and application protocol types (e.g., this is Modbus traffic). This application's embodiment achieves semantic-level parsing of all fields of protocols such as Modbus and S7 through proprietary protocol parsing. Based on this deep understanding, the parsing results are further and effectively matched with security rules in the knowledge base, thereby discovering deep semantic-level vulnerabilities.
[0080] Secondly, it enables systemic risk insight and enhances the breadth of threat detection: A dynamic heterogeneous graph of the industrial control network is constructed, and a graph neural network model is applied for node embedding learning to quantify the potential impact between devices; based on the node embedding vectors, potential attack paths are identified and warned of by calculating reachability probabilities. This not only detects anomalies in individual devices or sessions, but also identifies potential cross-device attack paths and systemic risks by analyzing the complex relationships and interaction patterns between devices, achieving a more comprehensive security posture assessment.
[0081] Third, it enhances the detection system's adaptive capability to detect unknown threats: This application's embodiments not only rely on a fixed rule base but also utilize unsupervised learning and temporal modeling to discover potential threats that do not conform to known characteristics but exhibit abnormal behavior. It also provides a credibility assessment of the detection results, reducing false positives and false negatives. While rule-based detection is effective for known vulnerabilities, its effectiveness against novel or unknown attacks is limited. The temporal anomaly detection model in this application's embodiments uses unsupervised learning, training the model using only normal traffic data to learn normal temporal patterns in industrial control communication (such as periodic data collection and specific request-response intervals). During detection, it identifies abnormal behaviors deviating from the learned patterns by calculating reconstruction probabilities, without relying on prior knowledge of the attack. This enables the system to detect hidden threats that are difficult to describe by rules.
[0082] Fourth, an intelligent model dynamic optimization loop integrating online learning and feedback: A closed loop is established, using confirmation / negation feedback on alarms as training data. Incremental updates or fine-tuning are performed on the Graph Neural Network (R-GCN) and the Temporal Anomaly Detection Model (VAE-LSTM) to enable the system to continuously adapt to network changes and learn from expert knowledge, achieving continuous performance evolution and forming the system's "intelligent" closed loop.
[0083] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a security detection device for an industrial control network provided in an embodiment of this application. Figure 3As shown, the security detection device 300 includes: The acquisition module 310 is used to acquire raw traffic in the industrial control network through a passive traffic probe deployed in the industrial control network, and to preprocess the acquired raw traffic to obtain session data. The parsing module 320 is used to call the corresponding proprietary protocol parser based on the message characteristics of the session data to perform full-field semantic parsing of the session data and generate structured semantic information; The matching module 330 is used to match the structured semantic information with rules in a predefined industrial control vulnerability knowledge base to determine the first network vulnerability detection information; Analysis module 340 is used to construct a communication behavior model based on the structured semantic information, and analyze the communication behavior model through graph algorithm and time sequence algorithm to obtain second network vulnerability detection information; wherein, the communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol running state sequence; The generation module 350 is used to combine the first network vulnerability detection information and the second network vulnerability detection information to generate a comprehensive vulnerability report.
[0084] Furthermore, when the analysis module 340 is used to construct a communication behavior model based on the structured semantic information, the analysis module 340 is used to: Based on the source address, destination address, and communication timing in the structured semantic information, the request-response relationship between devices is recorded, and the request-response relationship model is constructed; wherein, the request-response relationship model includes at least one of the device identifiers, communication modes, and communication frequencies of the communicating parties; Based on the protocol state field in the structured semantic information, the state transition sequence is extracted, and the protocol state machine model is constructed.
[0085] Furthermore, when the analysis module 340 analyzes the request-response relationship model using a graph algorithm to obtain the second network vulnerability detection information, the analysis module 340 is used to: In the request-response relationship model, devices are abstracted as nodes, and the relationships between devices are abstracted as edges to construct a heterogeneous graph of the industrial control network. A graph neural network model is used to perform multi-layer message propagation calculations on the heterogeneous graph of the industrial control network to obtain the representation vector of each node; Based on the representation vector of each node, node anomaly classification is performed to obtain second network vulnerability detection information about device anomalies.
[0086] Furthermore, when the analysis module 340 analyzes the request-response relationship model using a graph algorithm to obtain the second network vulnerability detection information, the analysis module 340 is also used to: The probability of an attack reaching a predetermined key node from an arbitrary source node is calculated based on the representation vector of each node. Based on the reachability probability, potential cross-device attack chains are identified, and second network vulnerability detection information related to the attack path is generated.
[0087] Furthermore, when the analysis module 340 analyzes the protocol state machine model using a timing algorithm to obtain the second network vulnerability detection information, the analysis module 340 is also used for: Extract multivariate time series features for each device or communication link in the protocol state machine model and cut them into sliding window sequences of fixed length; The sliding window sequence is input into a pre-trained time-series anomaly detection model to calculate the reconstruction probability; wherein, the time-series anomaly detection model is obtained by unsupervised training using time-series features containing normal communication traffic. Based on the reconstruction probability, the temporal anomaly score is determined, and the second network vulnerability detection information related to the temporal anomaly is obtained.
[0088] Furthermore, when generating a comprehensive vulnerability report by combining the first network vulnerability detection information and the second network vulnerability detection information, the generation module 350 is used to: Based on the DS evidence theory, the first network vulnerability detection information and the second network vulnerability detection information are fused to obtain comprehensive network vulnerability detection information with confidence scores; The comprehensive network vulnerability detection information is processed by evidence association on an individual event basis, and the corresponding original traffic, session data and communication behavior model context are associated to form an evidence chain. The comprehensive network vulnerability detection information is classified into risk levels and / or types to obtain the classification results; Based on the chain of evidence and the division results, the comprehensive vulnerability report is generated.
[0089] Furthermore, the safety detection device 300 also includes a feedback module; the feedback module is used for: Obtain feedback signals regarding the comprehensive vulnerability report; Based on the feedback signal, incremental training or parameter fine-tuning is performed on the graph neural network model on which the graph algorithm depends and the time anomaly detection model on which the time sequence algorithm depends.
[0090] Please see Figure 4 , Figure 4This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 4 As shown, the electronic device 400 includes a processor 410, a memory 420, and a bus 430.
[0091] The memory 420 stores machine-readable instructions that can be executed by the processor 410. When the electronic device 400 is running, the processor 410 and the memory 420 communicate via the bus 430. When the machine-readable instructions are executed by the processor 410, the steps of the security detection method for industrial control networks as described in the above method embodiment can be performed. For specific implementation details, please refer to the method embodiment, which will not be repeated here.
[0092] This application also provides a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it can execute the steps of the security detection method for industrial control networks as described in the above method embodiments. For specific implementation details, please refer to the method embodiments, which will not be repeated here.
[0093] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0094] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0095] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0096] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0097] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0098] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A security detection method for an industrial control network, characterized in that, The method includes: By using passive traffic probes deployed in the industrial control network, raw traffic in the industrial control network is collected, and the collected raw traffic is preprocessed to obtain session data. Based on the message characteristics of the session data, the corresponding proprietary protocol parser is invoked to perform full-field semantic parsing on the session data and generate structured semantic information; The structured semantic information is matched with rules in a predefined industrial control system vulnerability knowledge base to determine the first network vulnerability detection information; A communication behavior model is constructed based on the structured semantic information, and the communication behavior model is analyzed by graph algorithms and time-series algorithms to obtain second network vulnerability detection information; wherein, the communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol operation state sequence; A comprehensive vulnerability report is generated by combining the first network vulnerability detection information and the second network vulnerability detection information.
2. The method according to claim 1, characterized in that, Based on the structured semantic information, a communication behavior model is constructed, including: Based on the source address, destination address, and communication timing in the structured semantic information, the request-response relationship between devices is recorded, and the request-response relationship model is constructed; wherein, the request-response relationship model includes at least one of the device identifiers, communication modes, and communication frequencies of the communicating parties; Based on the protocol state field in the structured semantic information, the state transition sequence is extracted, and the protocol state machine model is constructed.
3. The method according to claim 2, characterized in that, The request-response relationship model is analyzed using a graph algorithm to obtain second network vulnerability detection information, including: In the request-response relationship model, devices are abstracted as nodes, and the relationships between devices are abstracted as edges to construct a heterogeneous graph of the industrial control network. A graph neural network model is used to perform multi-layer message propagation calculations on the heterogeneous graph of the industrial control network to obtain the representation vector of each node; Based on the representation vector of each node, node anomaly classification is performed to obtain second network vulnerability detection information about device anomalies.
4. The method according to claim 3, characterized in that, The request-response relationship model is analyzed using a graph algorithm to obtain second network vulnerability detection information, which also includes: The probability of an attack reaching a predetermined key node from an arbitrary source node is calculated based on the representation vector of each node. Based on the reachability probability, potential cross-device attack chains are identified, and second network vulnerability detection information related to the attack path is generated.
5. The method according to claim 2, characterized in that, The protocol state machine model is analyzed using a time-series algorithm to obtain second network vulnerability detection information, including: Extract multivariate time series features for each device or communication link in the protocol state machine model and cut them into sliding window sequences of fixed length; The sliding window sequence is input into a pre-trained time-series anomaly detection model to calculate the reconstruction probability; wherein, the time-series anomaly detection model is obtained by unsupervised training using time-series features containing normal communication traffic. Based on the reconstruction probability, the temporal anomaly score is determined, and the second network vulnerability detection information related to the temporal anomaly is obtained.
6. The method according to claim 1, characterized in that, Combining the first network vulnerability detection information and the second network vulnerability detection information, a comprehensive vulnerability report is generated, including: Based on the DS evidence theory, the first network vulnerability detection information and the second network vulnerability detection information are fused to obtain comprehensive network vulnerability detection information with confidence scores; The comprehensive network vulnerability detection information is processed by evidence association on an individual event basis, and the corresponding original traffic, session data and communication behavior model context are associated to form an evidence chain. The comprehensive network vulnerability detection information is classified into risk levels and / or types to obtain the classification results; Based on the chain of evidence and the division results, the comprehensive vulnerability report is generated.
7. The method according to claim 1, characterized in that, The method further includes: Obtain feedback signals regarding the comprehensive vulnerability report; Based on the feedback signal, incremental training or parameter fine-tuning is performed on the graph neural network model on which the graph algorithm depends and the time anomaly detection model on which the time sequence algorithm depends.
8. A security detection device for an industrial control network, characterized in that, The device includes: The acquisition module is used to acquire raw traffic in the industrial control network through passive traffic probes deployed in the industrial control network, and to preprocess the acquired raw traffic to obtain session data; The parsing module is used to call the corresponding proprietary protocol parser based on the message characteristics of the session data to perform full-field semantic parsing of the session data and generate structured semantic information; The matching module is used to match the structured semantic information with rules in a predefined industrial control vulnerability knowledge base to determine the first network vulnerability detection information; The analysis module is used to construct a communication behavior model based on the structured semantic information, and to analyze the communication behavior model through graph algorithms and time-series algorithms to obtain second network vulnerability detection information; wherein, the communication behavior model includes a request-response relationship model for recording communication relationships between devices, and a protocol state machine model for describing the protocol operation state sequence; The generation module is used to combine the first network vulnerability detection information and the second network vulnerability detection information to generate a comprehensive vulnerability report.
9. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory via the bus. The machine-readable instructions are executed by the processor to perform the steps of the security detection method for an industrial control network as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the security detection method for an industrial control network as described in any one of claims 1 to 7.