Methods for monitoring an industrial network
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2019-02-28
- Publication Date
- 2026-07-23
AI Technical Summary
Conventional central attack detection systems in industrial networks are vulnerable to communication link failures, which can disrupt attack detection and monitoring, especially in hierarchically structured networks.
A decentralized monitoring system is implemented, dividing the network into segments with local monitoring units that collect and evaluate data independently, allowing for continuous attack detection even if communication links to the central unit are interrupted.
Ensures robust and secure monitoring and detection of attacks across the industrial network, maintaining stability and operational continuity even in the event of failures or attacks, with minimal configuration overhead and cost.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a method for monitoring an industrial network as well as a computing unit and a Computer program for its execution. State of the art
[0002] By means of so-called industrial networks, a large number of different components of an industrial plant can be networked together, to operate such a system automatically, for example, or to monitor it with the help of remote computing units. For this purpose, The industrial network should be structured according to the so-called automation pyramid. According to such an automation solution, or... The automation pyramid divides the network into different hierarchical levels, or different network components, and those of The functions performed by these components define different hierarchy levels.
[0003] One of these levels is the so-called field level, in which, in particular, the actual manufacturing- or processing process takes place. This field level usually represents the lowest hierarchical level. The field level describes mechanical, Electrical, hydraulic, pneumatic, or similar components, e.g., generators, motors, drives. Furthermore, the field level includes Field devices that are directly integrated into these components of the production plant and are used for the control or regulation of these components. Production equipment is required. The field level includes, in particular, field devices such as sensors, actuators, drives, probes, Pushbuttons and switches.
[0004] These field devices of the field level can be connected to controllers in a control level higher than the field level (English: “Control”). Field-level sensors can be connected to, for example, programmable logic controllers (PLCs). Data can be forwarded to these controllers, or the controllers can transmit control signals to the actuators at the field level.
[0005] Controls at the control level can in turn be connected to computing units in a higher-level process control level (English: process control level). “Supervisory Level”). These processing units at the process control level can be used in particular as human-machine interfaces. The interface can function, for example, to display measurement data and thus to visualize and monitor the data at the field level. the manufacturing or processing process. For example, users can also benefit from the computing units at this level. Alarm messages or other notifications will be issued.
[0006] Computing units of the process control level are in turn connected to computing units in a higher-level operational control level (English: “Operational and Control Level”), which allows operational processes to be created, monitored and executed. For example, this operational management level can include PCs, servers, etc. The operational management level, in turn, is linked to the enterprise management level (English: enterprise management level). "Enterprise Level") is the superior level, which usually represents the highest hierarchical level, in which organization, planning, Management of the entire plant will take place.
[0007] In order to ensure safety and know-how protection, it is important to protect such industrial plants or industrial facilities. To be able to monitor networks for attacks. Disclosure of the invention
[0008] According to the invention, a method for monitoring an industrial network, a computing unit, and a A computer program for its execution, incorporating the features of the independent patent claims, is proposed. Advantageous embodiments are: The subject matter of the dependent claims and the following description.
[0009] The industrial network comprises a variety of network components. In particular, the industrial network includes components interconnected within an industrial plant.
[0010] The network is divided into at least two hierarchy levels, each with a different hierarchy level, wherein per Each hierarchy level must include at least one network component. These levels can be, for example, a field level, a The control level, a process control level, an operations control level, and an enterprise control level comprise network components of each. Hierarchy levels can be of different natures and can be designed, for example, as sensors, actuators, control units, programmable logic controllers, PCs, servers, smart devices, etc.
[0011] Each hierarchy level has at least one segment, wherein each segment has at least one network component of the respective Hierarchy level encompasses. In particular, each network component of a hierarchy level is assigned to exactly one segment. Per segment Each unit includes at least one component monitoring unit and / or at least one communication monitoring unit.
[0012] Such a component monitoring unit (English: "Host Agent") is used to monitor at least one network component of the The respective segment is provided for. For this purpose, the component monitoring unit can, for example, provide specific component-specific information. Receiving and evaluating information from the respective network components, in particular to detect attacks or violations of to recognize predefined rules. In particular, the component monitoring units can independently perform checks or audits of Network components. For example, the component monitoring units can each function as an antivirus unit or as a unit for Be trained to verify checksums. Basically, any software unit can run on standalone hardware or on existing hardware. This includes, in particular, the ability to trigger appropriate alarms in the event of detected attacks or rule violations. generate which are forwarded to a higher-level monitoring unit for further evaluation.
[0013] Such a communication monitoring unit (English: “Network Sensor”) is used to monitor communication in provided for the respective segment. For this purpose, the communication monitoring unit can, for example, passively read data traffic, for example, by using network ports (port mirroring) or a test port (test port). Access Port”, TAP). In particular, the communication monitoring units are not designed to perform attack detection themselves. to carry out, but rather transmit information regarding data traffic to a higher-level monitoring unit for further evaluation.
[0014] In one of the segments, a central monitoring unit is provided to evaluate information for the detection of attacks. It is advantageous for the central monitoring unit to be located in a segment at a process control level (English: "Supervisory Level") or an enterprise level.
[0015] In at least one of the remaining segments, there is at least one decentralized or local monitoring unit (“subnetwork”). Management Agent (SMA). At least one component monitoring unit and / or at least one The communication monitoring unit of the remaining segments is each assigned to one of at least one decentralized monitoring unit.
[0016] If a decentralized monitoring unit is provided in one of the other segments, then at least one Component monitoring unit and / or at least one communication monitoring unit of this segment expediently this assigned to a decentralized monitoring unit.
[0017] If, however, no decentralized monitoring unit is provided in one of the other segments, then at least one Component monitoring unit and / or at least one communication monitoring unit of this segment expediently assigned to the decentralized monitoring unit that is provided for in the next higher hierarchical level.
[0018] These decentralized monitoring units of the individual segments each receive initial information from the assigned at least a component monitoring unit and / or at least one assigned communication monitoring unit. These first Information can include, for example, alarms or notifications from the respective component monitoring units, when these detect an attack on a specific network component. Alternatively or additionally, this initial information can also be obtained from the Communication monitoring units collect information regarding data traffic between network components in the be the respective segment.
[0019] This central monitoring unit (English: “Centralized Security Management System”, CSMS) is in particular designed to It is designed to collect, correlate, and evaluate information from network components at all hierarchy levels. In particular, it can The central monitoring unit detects attacks across the entire industrial network. In the event of a detected error, the central unit can Furthermore, the monitoring unit should be able to recognize the extent of the attack and, in particular, assess how dangerous it is. The attack on the network, for example, what consequences the attack has for the industrial network, how much the attack affects the network will restrict access and which network components or functions are affected by the attack. The central monitoring unit is in particular designed as a complex system with complex evaluation and attack detection mechanisms, which furthermore in particular has information about the entire industrial network.
[0020] In order to detect attacks, the central monitoring unit expediently includes a database or has access to a such a database in which Reference information regarding known attacks or attack methods is stored, and current information is linked to this reference information. Various network components can be compared. Furthermore, the central monitoring unit can also detect anomalies or... To detect unexpected behavior in order to identify previously unknown attacks. For example, the central monitoring unit can For this purpose, the information is analyzed using statistical analyses and machine learning techniques. and / or a rule-based system (rule-based knowledge). Besides detecting attacks, the The central monitoring unit can perform additional functions, such as responding to alarms or reports from other sources. Network components react or independently perform checks or audits.
[0021] In particular, the component monitoring units and the communication monitoring units function as part of a Intrusion Detection System (IDS), where the component monitoring units expediently function like a host-based IDS ("Host-IDS") and the communication monitoring units like a network-based IDS ("Network IDS"). Conventional IDS attack detection systems are typically centralized. Monitoring systems are trained, i.e., host IDs and network IDs typically transmit information directly to a central CSMS monitoring unit for further analysis and attack detection. In hierarchically structured industrial networks. However, there is a risk that a communication link from host IDs or network IDs to a corresponding CSMS unit in a a higher hierarchy level may be interrupted, for example due to an attack, maintenance, or a defect. of the relevant communication system. In such a case of an interrupted communication link, only one option may be available. Limited or even no attack detection may be possible.
[0022] The present method provides a way to access the communication link even when the communication link is interrupted. The central monitoring unit enables monitoring of the entire industrial network and reliable attack detection. In contrast to conventional centralized attack detection systems, the present method uses decentralized monitoring. proposed. For this purpose, the hierarchy levels are each divided into at least one segment, and decentralized monitoring units are provided.
[0023] These decentralized or local monitoring units (“Subnetwork Management Agent”, SMA) are expediently less complexly designed than the central monitoring unit and specifically intended to transmit information from the assigned to collect component and communication monitoring units. In regular network operation, the decentralized units serve this purpose. Monitoring units are expediently used to transmit information from the individual segments to the central monitoring unit. to be forwarded for further evaluation. However, should the central monitoring unit be unreachable, individual or all decentralized units may be affected. Monitoring units will at least partially take over the functions of the central monitoring unit until it is reachable again.
[0024] The decentralized monitoring units each receive initial information from the assigned at least one Component monitoring unit and / or the assigned at least one communication monitoring unit. These first Information can include, for example, alarms or notifications from the respective component monitoring units, when these detect an attack on a specific network component. Alternatively or additionally, this initial information can also be obtained from the Communication monitoring units collect information regarding data traffic between network components in the respective segment. Furthermore, the central monitoring unit expediently receives information from the component or... Communication monitoring unit in its own segment and evaluates this data.
[0025] When a communication link to the central monitoring unit exists, the decentralized monitoring units transmit Each second piece of information, depending on the respective first piece of information received, is sent to the central monitoring unit, which then... The second piece of information is evaluated to detect attacks. In the case of error-free communication, the central system takes over this task. The monitoring unit analyzes data to detect attacks across the entire industrial network.
[0026] Due to the decentralized monitoring units and their distribution in individual segments, even in the event of an interruption Communication still offers the possibility of performing attack detection in the individual segments.
[0027] For this purpose, the at least one decentralized monitoring unit evaluates when the communication link to the central The monitoring unit is interrupted, the respective initial information received is itself used for recognition. from attacks, or at least partially from them. In this case, if the communication link is interrupted in the individual segments, Individual and independent decentralized, local attack detection can continue to be carried out. This option is available. For example, if there is vulnerable communication between all segments of the industrial network, i.e., if the Communication links between the individual segments are vulnerable to potential attacks.
[0028] Alternatively or additionally, at least one decentralized monitoring unit can be used if the communication link to the The central monitoring unit is interrupted; second information is sent depending on the respective first information received. a predetermined monitoring unit transmits this second piece of information to at least one decentralized monitoring unit. to detect attacks. In this case, this predetermined monitoring unit conveniently functions as a replacement for the central monitoring unit and takes over its tasks, at least partially, when the communication link is interrupted. This capability This is particularly useful, for example, when a communication link from this predetermined monitoring unit to segments in subordinate Hierarchy levels are secure and not, or at least hardly, vulnerable to attack, whereas a communication link of the predetermined The monitoring unit is exposed to an increased risk of attack on hierarchically superior segments.
[0029] With an error-free communication connection to the central monitoring unit, the decentralized monitoring units function thus, in particular, as an interface between the central monitoring unit and the individual segments or the Component monitoring units and communication monitoring units of the individual segments. The central monitoring unit In this case, a global attack detection can be performed across the entire network. However, if a communication link to If the central monitoring unit is interrupted, e.g. due to an attack, maintenance, etc., individual or all decentralized units may be affected. Local monitoring units take over at least some of the tasks of the central monitoring unit and perform local attack detection. carry out these measures, at least temporarily until the communication link is restored. Even if the decentralized monitoring units are not as complex as the central monitoring unit and, for example, cannot perform all the functions of the central unit. Monitoring unit, in the event of an interrupted communication link, can still be used by the decentralized monitoring units At least a certain degree of attack detection can be maintained. Therefore, the present method allows for a certain level of attack detection at any given time. Monitoring and attack detection of the entire industrial network or each individual segment of the industrial network is enabled become.
[0030] In contrast to conventional central attack detection systems, the component monitoring units transmit and Communication monitoring units of the individual segments within the framework of the present procedure do not directly obtain their initial information to a single central monitoring unit, but to the respective assigned, local, decentralized monitoring unit, which is individually can react to this initial information. Each hierarchical level and, furthermore, each segment can thus be appropriately addressed individually. Attacks and security incidents are being addressed. This makes it expedient to implement decentralized responses in individual segments. The monitoring unit can react locally to anomalies such as potential attacks and, furthermore, use the central monitoring unit to assess the extent of a to recognize such attacks and react accordingly.
[0031] Thus, the present method proposes a decentralized monitoring system which is robust and secure against attacks can be detected. In particular, the method can achieve a high degree of stability, especially the ability to recover after an attack. to restore error-free operation of the network after a failure, and furthermore a high degree of tolerance, in particular the ability to ensure the network remains operational even in the event of an attack, error or failure.
[0032] Furthermore, the present method requires little configuration effort and is cost-effective and easy to operate. In particular, existing industrial networks can be easily adapted to carry out the present procedure. can be retrofitted. The central monitoring unit, the decentralized monitoring units, and the component and Communication monitoring units can be easily integrated into the industrial network, for example each as separate hardware units or as executed software. For example, such software can be installed on existing network components. The process can be carried out using existing computing units. Furthermore, the present method enables network monitoring by means of to implement a modular system, whereby the individual modules or monitoring units can, for example, also can be sourced from different suppliers or third-party manufacturers.
[0033] Preferably, the predetermined monitoring unit of the at least one decentralized monitoring unit is in a The highest hierarchical level to which a communication link exists is provided. For example, in the case of a In case of an interrupted communication link, it must always be determined anew which of the decentralized monitoring units will be designated as these. The monitoring unit functions. It is also conceivable that it is predetermined or configured which of the decentralized monitoring units is used. as the predetermined monitoring unit. The latter option is particularly useful if, for example, some segments especially at lower hierarchical levels, they can communicate securely and with minimal risk of attack, and if, in turn, the Communication between other segments, especially at higher hierarchical levels, is more vulnerable to attack.
[0034] According to an advantageous embodiment, the at least one decentralized monitoring unit evaluates the received first It extracts information, appropriately generates alarms when attacks are detected, and forwards these alarms as a second piece of information, depending on... existing communication link to the central monitoring unit or to the predetermined decentralized monitoring unit. The corresponding higher-level monitoring unit can further evaluate these alarms, for example to assess whether an attack has actually occurred. Is it present, and if so, what specific attack is present?
[0035] Alternatively or additionally, the at least one decentralized monitoring unit prepares the received initial information Advantageously, it collects and transmits the corresponding processed information as a second piece of information. During this processing, it can... The initial information is expediently pre-processed and / or filtered. In particular, this allows a large amount of forwarded data to be processed. Data and the computational effort required for further evaluation of the second piece of information will be reduced.
[0036] Alternatively or additionally, the at least one decentralized monitoring unit can advantageously receive the initial information directly forward the second piece of information. In this case, no evaluation or processing is appropriate; instead, the first Informants will be forwarded unchanged for further evaluation.
[0037] If, after an interrupted communication link, the communication link to the central monitoring unit Once restored, the results of the respective evaluations of the initial information are advantageously obtained through at least one decentralized system. Monitoring unit and / or the respective evaluations of the second information by the predetermined monitoring unit to the central The monitoring unit forwards the results for further evaluation. In this case, the central monitoring unit can, for example, Check, verify, and, where appropriate, investigate further. For example, if such a result is an alarm due to a If a potential attack is detected, the central monitoring unit can, once it is reachable again, check, for example, whether it actually occurred. An attack is underway.
[0038] Preferably, the evaluation of the first information and / or the second information for detecting attacks is carried out in each case in The analysis is performed depending on a predefined segment-specific model. In particular, these models each describe an error-free model. Operation of the respective segment when no attack is present, for example, typical data or operational scenarios of error-free operation. The models can, for example, provide comparative values for data exchange, communication, requests and responses to requests between the The respective network components of the segment are included in the course of error-free operation. The individual segment-specific models can They can vary in complexity depending on the required stability and / or tolerance. Furthermore, the complexity of the segment-specific Models depend on further predefined or specifiable criteria, for example, on the risk that a potential attack poses to the represents an industrial network or the computing capacity of the individual decentralized monitoring units.
[0039] Preferably, the specified segment-specific models are generated by entering data into the respective segment. each at least one component monitoring unit and / or each at least one communication monitoring unit collected, for example, during regular, error-free operation or during a special test or Configuration operation. This collected data is preferably evaluated, preferably by means of statistical analyses and / or by means of machine learning techniques, for example using neural networks or a support vector method (English: “Support Vector Machine”, SVM), and / or by means of a rule-based system (English: “rule-based knowledge”). Advantageously, these segment-specific models can be generated by the central monitoring unit and, in particular, distributed to the individual The data will be transmitted to decentralized monitoring units or the predetermined monitoring unit.
[0040] It is also conceivable that the individual decentralized monitoring units for the segment or for the segments of their Create corresponding segment-specific models for the assigned component or communication monitoring units and send them to the central system. Transmit to monitoring unit.
[0041] A preferred embodiment of the method relates to a configuration of the industrial network, in particular a first-time Configuration before network commissioning. The industrial network is best configured after the individual Network components were introduced and interconnected.
[0042] Preferably, the industrial network is configured by introducing the central monitoring unit into the network, for example as a separate hardware element or as executable software, especially in a computing unit already present in the network, especially at a process control level (English: "Supervisory Level") or an enterprise control level (English: "Enterprise") Level").
[0043] Furthermore, preferably at least one decentralized monitoring unit is introduced into the network, for example also each as a separate hardware component or executable software, especially in existing computing units. The individual components are then... decentralized monitoring units are authenticated or registered by the central monitoring unit.
[0044] After successful authentication, the at least one decentralized monitoring unit receives from the central monitoring unit Configuration data regarding the assigned at least one component monitoring unit and / or the assigned at least a communications monitoring unit. This configuration data can, for example, contain security policies for the respective segments. This includes, for example, information regarding communication allowed in the segments, etc. In particular, the configuration data includes information. or configurations for component monitoring units and communication monitoring units of the respective segments. Furthermore The configuration data can, for example, contain information regarding the communication between the central monitoring unit and This includes decentralized monitoring units. It is expedient to process the received configuration data from each decentralized unit. Monitoring units are first validated and only implemented and used after subsequent validation.
[0045] Preferably, at least one component monitoring unit and / or at least one component monitoring unit are then installed per segment. Communication monitoring unit introduced and authenticated by the assigned at least one decentralized monitoring unit. registered. These monitoring units can also each be configured, for example, as a separate hardware element or executable software. It could be, for example, a component and / or communication monitoring unit and / or a decentralized monitoring unit. Each is executed as software on the same computing unit of the respective system. After successful authentication, the decentralized Monitoring units per segment should expedite the process of checking whether configuration data is available for the authenticated units. If If this is the case, the configuration data should be validated against the security policies for the segment.
[0046] Upon successful validation, the at least one decentralized monitoring unit preferably configures the assigned at least one component monitoring unit and / or the assigned at least one communication monitoring unit according to the Configuration data.
[0047] If an error occurs during one of the configuration steps described above, for example because authentication or validation fails If the operation can be carried out successfully, an error message can be displayed and help can be requested from a user.
[0048] After successful configuration of the at least one component monitoring unit and / or the at least one Advantageously, the communication monitoring unit can also generate the specified segment-specific models. For example For this purpose, a special test operation can first be carried out for each segment, during which relevant data will be collected. and be evaluated.
[0049] An advantageous embodiment of the method relates to the replacement of a decentralized monitoring unit, for example if This might be necessary due to a defect or a security vulnerability. In particular, the central monitoring unit can initially be accessed via the You will be notified of the upcoming exchange to avoid generating an alarm or error message. For example, this could be related to... The purpose is to disable alarm generation for the duration of a maintenance interval.
[0050] Advantageously, a decentralized monitoring unit is replaced by first replacing the decentralized monitoring unit to be replaced. is removed from the network, for example by removing the relevant hardware unit or deleting the relevant software. Subsequently, a new decentralized monitoring unit is introduced into the network and authenticated by the central monitoring unit. or registered. The new decentralized monitoring unit then receives the configuration data from the central monitoring unit. regarding the respective segment. If segment-specific models already exist for the respective segment, and these are centrally located... The data stored in the monitoring unit will be transmitted, in particular, to the new decentralized monitoring unit.
[0051] Furthermore, the present invention makes it possible to easily perform checks or verifications requested by a user. To conduct audits of a specific network component. In particular, such a review will be performed on the central monitoring unit. A document is requested to verify that this check does not violate any security policy. Upon successful verification, the The request is forwarded to the decentralized monitoring unit to which the network component being checked is assigned. The decentralized The monitoring unit then triggers the check, so that the network component to be checked collects the corresponding test data and sends it to the decentralized monitoring unit transmits the test data. This unit then forwards the test data to the central monitoring unit, which processes the test data. evaluates and outputs a corresponding result of the evaluation to the user.
[0052] The method is suitable for a wide range of industrial networks or correspondingly networked industrial plants, for example, for tunnel boring machines, hydraulic punches / presses, general automation, semiconductor handling, robotics, etc. The process is particularly suitable for machine tools, such as a welding system, a screw system, a wire saw, or a Milling machine, or a web processing machine, such as a printing press (e.g. newspaper printing press, gravure printing press, screen printing press, inline flexographic printing press) or a packaging machine, or a (conveyor belt) system for the manufacture of an automobile or for the manufacture of Components of an automobile (e.g., combustion engines or control units).
[0053] A computing unit according to the invention, e.g. a control unit of a printing press, is, in particular, programmed to, to carry out a method according to the invention.
[0054] The implementation of a method according to the invention in the form of a computer program or computer program product is also possible. Using program code to carry out all process steps is advantageous because it incurs particularly low costs, especially if a The executing control unit is used for other tasks and is therefore already present. Suitable data carriers for providing the Computer programs are primarily magnetic, optical, and electrical storage media, such as hard drives, flash memory, EEPROMs, and DVDs. Downloading a program via computer networks (Internet, intranet, etc.) is also possible.
[0055] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawing.
[0056] It is understood that the features mentioned above and those to be explained below are not limited to the features specified in each case. not only in combination, but also in other combinations or on their own, without exceeding the scope of the present invention. leave.
[0057] The invention is schematically illustrated in the drawing with reference to exemplary embodiments and is described below with reference to The drawing is described in detail. List of characters Figures 1 and 2 each schematically show an industrial network representing a preferred embodiment of the method according to the invention. Figures 3 to 5 each schematically show a preferred embodiment of the method according to the invention as a Block diagram. Detailed description of the drawing
[0058] In Fig. 1, an industrial network is schematically depicted and labelled 100. By means of the industrial network 100, a A multitude of different components of an industrial plant are interconnected. For example, such a plant might consist of... It could be a processing machine. The network can be Ethernet-based.
[0059] The network 100 is divided into different so-called automation pyramids or automation solutions. Hierarchy levels 110, 120, 130, 140, 150 are structured, with each of the hierarchy levels 110, 120, 130, 140, 150 containing a multitude various network components are present.
[0060] In the present example, the lowest hierarchical level is a field level 110, in which in particular the actual manufacturing or processing process of the web processing machine takes place. As a network or Machine components in this field level 110 include, for example, field devices such as sensors 114, 117, probes 112, and radio-controlled switches. 116 as well as motors or actuators 113, 115 e.g. intended for moving robot arms.
[0061] In a control level 120 that is superior to the field level 110, the following network components are available for example, control units 122, 124 and programmable logic controllers (PLCs) 123, 125 are provided, in particular to the To control network components at field level 110. For this purpose, the network components of field and control level 110 are used. , 120 are networked via network distributors 111a, 111b, 111c, 121a, 121b (e.g., a switch). For example, field devices 112 and 113 are connected via A distributor 111a is connected to the higher-level distributor 121a, and field devices 114 and 115 are connected via a distributor 111b. Field devices 116 and 117, for example, are connected to the higher-level distributor 121b via a distributor 111c.
[0062] In a process control level 130 (English: “Supervisory Level”) that is superior to the control level 120, the following function Network components, for example as human-machine interfaces for visualizing and monitoring the field level 110 carried out manufacturing or processing. Such network components of the process control level 130 can be, for example, operator panels. 132, PCs 133, etc. Distributors 121a and 121b of control level 120 are connected for this purpose to a distributor 131 of the Process control level 130 connected.
[0063] The process control level 130 is superior to a so-called operational control level 140 (English: “Operational and Control Level”), in which Operational processes can be created, monitored, and executed. Network components at this operational control level can include, for example, PCs. 142 and servers 143, 144, 145. For example, such servers may contain data relating to the operation carried out at field level 110. The manufacturing or processing process is archived. Furthermore, distributor 131 of process control level 130 is expediently equipped with a Distributor 141 is connected to the operational control level 140.
[0064] The highest hierarchical level, for example, is the so-called Enterprise Level 150, in which organization, planning, and management of the entire company that operates the plant take place. Network components of this Enterprise management level 150 includes, for example, PCs 155, laptops 156, printers 157, and also, for example, remote computing units 152. 153, 154, for example, in the sense of so-called "cloud computing". Furthermore, a distribution list 151 is provided at the corporate management level 150, with to which the distributor 141 is connected to the operational control level 140.
[0065] Communication between any two network distributors can preferably be carried out using conventional firewall units or similar devices as shown. be assured.
[0066] For example, the network components of the field level 110, the control level 120 and the process control level 130 can be in be located in the same building in which the manufacturing or processing process is carried out by the web processing machine The network components of the operations and enterprise management levels 140 and 150, however, can also be located at a considerable distance from the building. the web processing machine. Furthermore, the network components in levels 110, 120, 130 can be arranged, in particular via Local, wired communication links such as fieldbuses are interconnected. The networking to the network components of the However, operational and corporate management (140, 150) can also be carried out, in particular, via wireless communication links. for example via the internet.
[0067] It is understood that the industrial network may include further hierarchical levels in addition to those described above. Likewise, It is conceivable that some of the above-mentioned levels are not provided for or are, for example, combined into a common level.
[0068] In order to ensure security and know-how protection, the industrial network 100 is implemented in a preferred manner The embodiment of the method according to the invention is monitored for attacks.
[0069] Within the framework of the method, each hierarchy level 110, 120, 130, 140, 150 has at least one segment, wherein each A network component is expediently assigned to exactly one segment. It goes without saying that more network components per segment are also possible. Segments can be localized, although this is often not common practice due to the high costs involved. In particular, only A network component is provided, and only the most important network information can be captured.
[0070] In the present example, the field level 110 is divided into three segments 110a, 110b, 110c, with the network components 111a, 112 and 113. Network components 111b, 114 and 115 are assigned to segment 110a, and network components 111c are assigned to segment 110b. 116 and 117 belong to segment 110c.
[0071] The control level 120 is, for example, divided into two segments 120a and 120b, wherein the network components 121a , 122 and 123 are assigned to segment 120a, and network components 121b, 124, and 125 are assigned to segment 120b. The process control level 130, which The operational management level 140 and the enterprise level 150 are each divided into a segment 130a, 140a and 150a respectively, which is expediently corresponds to the respective level.
[0072] Furthermore, within the framework of the method, various monitoring units are provided for each segment, as described below in relation to This is explained in Fig. 2, in which the industrial network 100 shown in Fig. 1 is also schematically represented. Identical reference numerals. In Figures 1 and 2, the denote identical or structurally identical elements. For the sake of clarity, not all elements shown in Figure 1 are depicted. Network components are again shown in Fig. 2; however, it is understood that the network 100, as shown in Fig. 2, also includes the components shown in Fig. 2. The network components shown in Fig. 1 are intended to include.
[0073] As shown in Fig. 2, a central monitoring unit is located in segment 150a of enterprise level 150. (Centralized Security Management System, CSMS) 210 is provided for. Segments 120a, 120b, 130a, and 140a each contain A decentralized monitoring unit (“Subnetwork Management Agent”, SMA) 222a, 222b, 223, 224 is provided. A decentralized monitoring unit is not necessarily required at field level 110, as this information is provided by a decentralized Monitoring units can be managed at a higher control level. However, it is understood that even within the segments... 110a , 110b , 110c of field level 110 each a decentralized monitoring unit may be provided.
[0074] Furthermore, at least one component monitoring unit is provided per segment for monitoring at least one Network component of the respective segment and / or at least one communication monitoring unit for monitoring a Communication is planned in the respective segment.
[0075] For example, in the segment 110a of the field level 110, two component monitoring units 231a are provided to To monitor field devices 112 and 113. Accordingly, two component monitoring units 231b are located in segment 110b. intended for monitoring field devices 114 and 115 and in segment 110c two component monitoring units 231c for Monitoring of field devices 116 and 117. For example, these component monitoring units 231a, 231b, 231c can each be used. These are provided as separate hardware units, which are connected to the respective distributors 111a, 111b or 111c. Component monitoring units can also be, for example, embedded software applications in the field devices 112 and 113.
[0076] For example, two component monitoring units 232a are provided in segment 120a of the control level 120, where one of these two units 232a is intended for monitoring the control unit 122 and the other of the two units 232a for monitoring the PLC 123. Accordingly, segment 120b also contains, for example, two component monitoring units. 232b provides for a unit for monitoring the control unit 124 and one for monitoring the PLC 125. For example, these can Component monitoring units 232a, 232b are each executed as software by the respective control unit or PLC.
[0077] Furthermore, a communication monitoring unit 242a is provided in segment 120a, which, for example, passively monitors data traffic. in segment 120a, for example by means of network port mirroring of distributor 121a. A corresponding communications monitoring unit 242b is also provided in segment 120b.
[0078] Accordingly, component monitoring units 233, 234, 235 are also provided in segments 130a, 140a and 150a for Monitoring of the network components of the respective segment is provided, which, for example, may each be designed as executed software. can.
[0079] Furthermore, in segments 130a, 140a, 150a, a communication monitoring unit 243, 244 and 245 respectively is provided for monitoring. the communication in the respective segments 130a, 140a and 150a, each of which includes, for example, "port mirroring" of the respective distributors 131, 141 and 151.
[0080] By easily integrating the units into the industrial network, especially based on Ethernet, communication can be simplified. The system also utilizes established and proven methods between units, such as syslog. These are to establish a standard for transmitting log messages in an IP computer network.
[0081] In the context of the present procedure, the central monitoring unit (CSMS) 210 is specifically designed to provide information to collect, correlate, and evaluate data from all network components at all hierarchy levels in order to detect attacks across the entire industrial sector. To be able to detect network 100 and to assess the extent of the corresponding attack.
[0082] The decentralized or local monitoring units (SMA) 222a , 222b , 223 , 224 are, however, less complex. trained as the central monitoring unit 210, they each serve to transmit information from the components and To forward communication monitoring units to the central monitoring unit 210 for further evaluation.
[0083] The decentralized monitoring unit 222a of segment 120a includes, in addition to the component monitoring units 232a and the Communication monitoring unit 242a of this segment 120a also the component monitoring units 231a and 231b of the hieratic subordinate segments 110a and 110b were assigned.
[0084] The decentralized monitoring unit 222b of segment 120b includes the component monitoring units 232b and the Communication monitoring unit 242b of segment 120b and the component monitoring units 231c of segment 110c assigned.
[0085] In segment 130a are the component monitoring units 233 and the communication monitoring unit 243 of the there assigned to the designated decentralized monitoring unit 223. Accordingly, the component monitoring units are located in segment 140a. 234 and the communication monitoring unit 244 of the decentralized monitoring unit 224 provided in this segment 140a assigned.
[0086] If the central monitoring unit 210 is not reachable, the decentralized monitoring units can at least partially to take over the functions of the central monitoring unit 210. Therefore, within the framework of the present procedure, a interrupted communication link to the central monitoring unit 210, monitoring of the entire industrial network 100 to enable this, as will be explained below with reference to Figs. 3 to 5.
[0087] Figures 3 to 5 schematically show a preferred embodiment of the method according to the invention as a block diagram. depicted.
[0088] Fig. 3 relates to the case where an error-free communication connection to the central monitoring unit 210 exists. In a In step 301, the individual decentralized monitoring units 222a, 222b, 223, 224 receive initial information from their assigned units. individual component monitoring units 231a, 231b, 231c, 232a, 232b, 233, 234 or communication monitoring units 242a, 242b, 243, 244. Furthermore, the central monitoring unit 210 receives initial information from the component monitoring units. 235 and the communication monitoring unit 245 of segment 150a. For example, this initial information could each be to receive notifications from the respective component monitoring units or to gather information regarding the data traffic of the respective communication monitoring units.
[0089] In step 302, the individual decentralized monitoring units 222a, 222b, 223, 224 prepare the respective received They gather initial information, for example by preprocessing and filtering it. In step 303, the decentralized systems transmit... Monitoring units 222a, 222b, 223, 224 forward this processed information as a second piece of information to the central monitoring unit 210. .
[0090] In step 304, the central monitoring unit 210 evaluates the second set of information. Furthermore, the central monitoring unit evaluates 210 also the first information from the component monitoring units 235 and the communication monitoring unit 245 of their own Segments 150a. As part of this evaluation, the central monitoring unit 210 checks whether in one or more of the segments 110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a indicates an attack. If this is the case, the central monitoring unit 210 initiates step 306. A corresponding countermeasure will be taken. If, however, no attack is detected, regular monitoring will continue, it was indicated. by reference numeral 305 .
[0091] Fig. 4 now relates to the case where the communication link to the central monitoring unit 210 is interrupted, for example due to a defect in network distributor 151.
[0092] In this case, in step 401, the individual decentralized monitoring units 222a , 222b , receive analogously to step 301. 223, 224 first information from the individual component monitoring units 231a, 231b, 231c, 232a, 232b, 233, 234 respectively. Communication monitoring units 242a, 242b, 243, 244 of their respective segments.
[0093] In step 402, the decentralized monitoring units 222a, 222b, 223, 224 each evaluate their received initial information at least This assessment partly determines whether an attack is present in the respective segments. For example, this evaluation is based on... segment-specific models, each describing typical initial information that is usually received in error-free operation become.
[0094] Furthermore, in step 403 it is checked whether the communication connection to the central monitoring unit 210 has been restored. Until this is the case, the decentralized monitoring units 222a, 222b, 223, 224 will continue monitoring their segments. indicated by reference 404 .
[0095] When the communication link is restored, the individual decentralized monitoring units 222a , 222b , transmit 223, 224 in step 405 the results of their evaluations to the central monitoring unit 210, which then forwards these results evaluates. For example, if one or more of the decentralized monitoring units detect an attack in one of the Once segments have been detected, the central monitoring unit 210 checks in step 405 whether it is actually an attack and initiates appropriate countermeasures.
[0096] According to this preferred embodiment of the method according to the invention shown in Fig. 4, the individual decentralized Monitoring units in the individual segments operate individually and independently of each other in the event of an interrupted communication link. It also performs decentralized, local attack detection. This option is particularly useful, for example, when there is a risk of attack between all segments. The industrial network has vulnerable communication, i.e., if the communication links of the individual segments are compromised. among themselves, they are vulnerable to potential attacks.
[0097] According to a preferred embodiment of the method of the invention, it is provided that alternatively or additionally, when In the event of an interrupted communication link, a predetermined monitoring unit acts as a replacement for the central monitoring unit. and at least partially takes over their tasks. This option is particularly suitable, for example, if a communication link of this predetermined monitoring unit to segments in subordinate hierarchy levels is secure and not, or at least hardly, vulnerable to attack, However, a communication link from the predetermined monitoring unit to hierarchically superior segments of an elevated is exposed to the risk of attack.
[0098] Such a case is shown in Fig. 5. In this case, too, it is assumed that the communication link to the central Monitoring unit 210, for example, is interrupted due to a defect in the network distributor 151. For example, the predetermined Monitoring unit 223 of segment 130a of process control level 130 is designated to replace the central monitoring unit 210. function until it is reachable again.
[0099] In accordance with step 401, in step 501 the individual decentralized monitoring units 222a , 222b , 223 receive , 224 first information from the individual component monitoring units 231a , 231b , 231c , 232a , 232b , 233 , 234 respectively. Communication monitoring units 242a, 242b, 243, 244 of their respective segments.
[0100] In step 502, the individual decentralized monitoring units 222a, 222b, 223, 224 prepare the respective received They gather initial information, for example by preprocessing and filtering this information, as described in step 302. They then transmit this information in step 503. the decentralized monitoring units 222a, 222b, 224 transmit this processed information as second information to the predetermined Monitoring Unit 223 .
[0101] In step 504, the predetermined monitoring unit 223 evaluates the second set of information which it has generated itself, as well as the second Information from the other decentralized monitoring units 222a, 222b, 224 at least partially, in order to detect attacks in segments 110a, 110b, 110c, 120a, 120b, 130a, 140a. This evaluation is carried out in particular using segment-specific models, which Describe typical second information of the individual segments 110a , 110b , 110c , 120a , 120b , 130a , 140a in a fault-free operation.
[0102] Analogous to step 403, step 505 also checks whether the communication link to the central monitoring unit 210 has been restored. Until this is the case, the decentralized monitoring unit 223 continues with its backup operation, indicated by Reference number 506 .
[0103] When the communication link is restored, the predetermined decentralized monitoring unit 223 transmits in step 507 the results of their evaluations are sent to the central monitoring unit 210, which further evaluates these results analogously to step 405. If For example, if an attack is detected in one of the segments, the central monitoring unit 210 checks in step 507 whether it confirms that it is indeed an attack and initiates appropriate countermeasures.
Claims
[1] Method for monitoring an industrial network (100), wherein the network (100) is divided into at least two hierarchy levels (110, 120, 130, 140, 150) each with a different hierarchical level, where at least one network component is provided for each hierarchy level (110, 120, 130, 140, 150), wherein each hierarchy level (110, 120, 130, 140, 150) has at least one segment (110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a), wherein each segment (110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a) contains at least one network component of the respective hierarchy level (110, 120, 130, 140, 150) includes, wherein each segment (110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a) has at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) for monitoring at least one network component of the respective segment (110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a) and / or at least one communications monitoring unit (242a, 242b, 243, 244, 245) for monitoring communications in the respective segment (110a, 110b, 110c, 120a, 120b, 130a, 140a, 150a) are provided for, wherein in one of the segments (150a) a central monitoring unit (210) is provided to collect information for detecting attacks to evaluate, and wherein in at least one of the remaining segments (110a, 110b, 110c, 120a, 120b, 130a, 140a) at least one decentralized Monitoring unit (222a, 222b, 223, 224) is provided, wherein at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) and / or at least one Communication monitoring unit (242a, 242b, 243, 244, 245) of the remaining segments (110a, 110b, 110c, 120a, 120b, 130a, 140a) each one of the are assigned to at least one decentralized monitoring unit (222a, 222b, 223, 224), wherein at least one decentralized monitoring unit (222a, 222b, 223, 224) each receives initial information from the assigned at least a component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234) and / or the assigned at least one Communication monitoring unit (242a, 242b, 243, 244) receives (301, 401, 501), where, if a communication link to the central monitoring unit (210) exists, which has at least one decentralized Monitoring unit (222a, 222b, 223, 224) each sends second pieces of information depending on the respective first pieces of information received to the central monitoring unit (210) transmits (303), which evaluates this second piece of information to detect attacks (304), where, if the communication link to the central monitoring unit (210) is interrupted, at least one decentralized The monitoring unit (222a, 222b, 223, 224) evaluates the respective initial information received itself to detect attacks (402) and / or second information depending on the respective first information received to a predetermined monitoring unit (223) which transmits at least one decentralized monitoring unit (222a, 222b, 223, 224) (503) which uses this second information to detect evaluates attacks (504). [2] Method according to claim 1, wherein the predetermined monitoring unit (223) of the at least one decentralized monitoring unit (222a, 222b, 223, 224) is provided at a hierarchically highest level of hierarchy to which a communication link exists. [3] Method according to claim 1 or 2, wherein the at least one decentralized monitoring unit (222a, 222b, 223, 224) receives the first evaluates information, generates alarms and forwards these alarms as secondary information and / or the received first information processed and corresponding processed information transmitted as second information (302, 502) and / or the received first Information is transmitted directly as a second piece of information. [4] Method according to one of the preceding claims, wherein, in the event of an interrupted communication link, the communication link to the central monitoring unit (210) is restored, results of the respective evaluations of the initial information by the at least one decentralized monitoring unit (222a, 222b, 223, 224) and / or the respective evaluations of the second information by the predetermined monitoring unit (223) to the central monitoring unit (210) for further evaluation (405, 507). [5] Method according to one of the preceding claims, wherein the evaluation of the first information and / or the second information to Attack detection is carried out depending on a given segment-specific model (304, 402, 504). [6] The method of claim 5, wherein the predetermined segment-specific models are generated by using data from at least one Component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) and / or the respective at least one Communication monitoring unit (242a, 242b, 243, 244, 245) collected and analyzed using statistical analysis and / or machine learning. and / or evaluated using a rule-based system. [7] Method according to any one of the preceding claims, wherein the industrial network (100) is configured by the central monitoring unit (210) is introduced into the network (100), which includes at least one decentralized monitoring unit (222a, 222b, 223, 224) is introduced into the network (100) and authenticated by the central monitoring unit (210), at least one decentralized monitoring unit (222a, 222b, 223, 224) receives configuration data from the central monitoring unit (210). regarding the assigned at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) and / or the assigned at least one communications monitoring unit (242a, 242b, 243, 244, 245) receives, per segment (110a, 110b, 110c, 120a, 120b, 130a, 140a) which has at least one component monitoring unit (221a, 221b, 221c, 232a, 232b, 233, 234, 235) and / or at least one communications monitoring unit (242a, 242b, 243, 244, 245) introduced and by the assigned is authenticated by the decentralized monitoring unit (221a, 221b, 221c, 222a, 222b, 223, 224). the at least one decentralized monitoring unit (222a, 222b, 223, 224) the assigned at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234) and / or the assigned at least one communications monitoring unit (242a, 242b, 243, 244) Configured according to the configuration data. [8] Method according to claims 6 and 7, wherein, according to the configuration of the at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234) and / or at least one communications monitoring unit (242a, 242b, 243, 244) furthermore the specified Segment-specific models are generated. [9] Method according to one of the preceding claims, wherein a decentralized monitoring unit (222a, 222b, 223, 224) is replaced, by the decentralized monitoring unit to be replaced is removed from the network (100), a new decentralized monitoring unit is introduced into the network (100) and authenticated by the central monitoring unit (210), the new decentralized monitoring unit from the central monitoring unit (210) the configuration data regarding the assigned at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) and / or the assigned at least one Communication monitoring unit (242a, 242b, 243, 244, 245) receives. [10] Industrial network (100) with a plurality of network components, at least one component monitoring unit (231a, 231b, 231c, 232a, 232b, 233, 234, 235) and / or at least one communications monitoring unit (242a, 242b, 243, 244, 245), a central monitoring unit (210) and at least one decentralized monitoring unit (222a, 222b, 223, 224) which is set up to implement a procedure to be carried out according to one of the foregoing claims. [11] Computer program that causes an industrial network (100) according to claim 10 to execute a method according to any one of claims 1 to 9 to carry out. [12] Machine-readable storage medium with a computer program stored thereon according to claim 11.