Security hardening package sending method, apparatus and system, and device, medium and product

By determining the transmission time period based on the historical status of OT devices and sending security reinforcement packets when the real-time status meets the conditions, the problem of low transmission efficiency of security reinforcement packets in OT systems during non-production periods is solved, and efficient and secure transmission of reinforcement packets is achieved.

WO2026011436A1PCT designated stage Publication Date: 2026-01-15SIEMENS AG +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/105308
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In existing technologies, security hardening packages for OT systems are typically sent during maintenance or non-production periods, which exposes devices to attack risks for extended periods and results in low transmission efficiency.

Method used

By acquiring the historical performance, network, and security status of OT devices, a suitable transmission time period is determined, and a security hardening packet is sent when the real-time status meets the conditions. This includes parsing security logs and performance data, and recording breakpoints for subsequent resuming of transmission.

Benefits of technology

It improves the efficiency of sending security hardening packages, reduces the impact on the normal operation of OT equipment, and enhances the security of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024105308_15012026_PF_FP_ABST
    Figure CN2024105308_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the embodiments of the present invention are a security hardening package sending method, apparatus and system, and a device, a medium and a product. The method comprises: acquiring a sending time cycle corresponding to an operational technology (OT) device, wherein the sending time cycle is determined on the basis of historical performance states, historical network states and historical security states of the OT device within a historical time period, and the sending time cycle is a time cycle suitable for sending a security hardening package to the OT device; determining a real-time performance state, a real-time network state and a real-time security state of the OT device in the current round of the sending time cycle; and when the real-time performance state meets a first condition, the real-time network state meets a second condition and the real-time security state meets a third condition, initiating, in the current round of the sending time cycle, the sending process of sending the security hardening package to the OT device, such that the OT device executes security hardening processing on the basis of the security hardening package. Thus, the efficiency of sending a security hardening package and the security of an OT device are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Methods, apparatus, systems, equipment, media, and products for delivering security hardening packages. Technical Field

[0001] This invention relates to the field of network security technology, and in particular to methods, apparatus, systems, devices, media, and products for sending security hardening packages. Background Technology

[0002] Operational Technology (OT) systems are configured to automate industrial processes. An OT system can be a wind power system, an automobile manufacturing plant, a pharmaceutical factory, or a city's wastewater treatment system. Traditional OT systems employ a closed design, making them difficult to threaten through cyberattacks. However, with the development of automated manufacturing and process control technologies, OT systems widely adopt Information Technology (IT) and are no longer closed systems. Consequently, the security threats faced by OT systems are becoming increasingly serious. The need to protect OT systems from security attacks has become urgent. For example, the networks of a joint venture or subsidiary of an industrial enterprise, or even a service outsourcing company, may be connected to the industrial enterprise's OT system, thus posing a risk of cyberattacks.

[0003] OT operators need to identify vulnerabilities in OT systems and harden the security of target devices to improve the security status of OT systems. Typically, OT operators first transmit a security hardening package (e.g., containing security hardening scripts or security hardening patches) to the target device, and then run the security hardening package on the target device to complete the security hardening.

[0004] Currently, security hardening is typically performed during maintenance or non-production periods. This means there is a long wait before security hardening packages are sent to OT devices, during which time these devices may be exposed to various attacks.

[0005] Summary of the Invention

[0006] The present invention provides methods, apparatus, systems, devices, media, and products for sending security hardening packages.

[0007] A method for sending a security hardening packet includes:

[0008] Obtain the transmission time period corresponding to the OT device. The transmission time period is determined based on the historical performance status, historical network status, and historical security status of the OT device within a historical time period. The transmission time period is a suitable time period for sending security hardening packets to the OT device.

[0009] Determine the real-time performance status, real-time network status, and real-time security status of the OT device in the current round of the transmission time period;

[0010] When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, in the current round of the transmission time period, the transmission process of sending a security hardening package to the OT device is initiated, so that the OT device can perform security hardening processing based on the security hardening package.

[0011] It is evident that eliminating the need to send security hardening packages during maintenance or non-production periods improves the efficiency of security hardening package delivery and enhances the security of OT equipment.

[0012] In one implementation, obtaining the transmission time period corresponding to the OT device includes:

[0013] Using the identifier of the OT device as the search term, the database is used to query the search results corresponding to the search term. The database stores the association between the identifiers of multiple OT devices and their corresponding transmission time periods.

[0014] Therefore, the transmission time period of OT devices can be quickly obtained from the database by querying the identifier.

[0015] In one implementation, it includes:

[0016] During the transmission process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, or the real-time security status no longer meets the third condition, the transmission process is stopped and the breakpoint of the transmission process is recorded.

[0017] As can be seen, the transmission process stops when the conditions are no longer met, thus not affecting the current normal operation of the OT equipment. Moreover, by recording the breakpoints in the transmission process, it is convenient to resume transmission from the breakpoint later, thereby improving the transmission efficiency of the security hardening packet.

[0018] In one implementation, it includes:

[0019] After the transmission process is stopped, the transmission process is resumed from the breakpoint when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, and the real-time security status recovers to meet the third condition within the transmission time period.

[0020] As can be seen, resuming the transmission process from the breakpoint when the conditions are met again not only ensures the integrity of the security-enhanced packet but also improves transmission efficiency.

[0021] In one implementation, it includes:

[0022] Acquire the security logs and / or suspicious objects of the OT device during the historical time period, the host performance data and / or the performance data of the predetermined process during the historical time period, and the host network status data and / or the network status data of the predetermined process during the historical time period.

[0023] The security logs and / or the suspicious objects are first parsed to determine the historical security status within the historical time period.

[0024] A second parsing is performed on the host performance data and / or the performance data of the predetermined process to determine the historical performance status within the historical time period.

[0025] A third parsing is performed on the network status data of the host and / or the network status data of the predetermined process to determine the historical network status within the historical time period.

[0026] From the historical time period, determine the common time period in which the historical security state, the historical network state, and the historical performance state all meet their respective constraints;

[0027] The transmission time period is determined based on the common time period.

[0028] Therefore, the embodiments of the present invention fully consider the determinism and periodicity of OT equipment and realize a method for determining the transmission time period based on historical data.

[0029] An apparatus for delivering a security reinforcement package, comprising:

[0030] The acquisition module is used to acquire the transmission time period corresponding to the OT device. The transmission time period is determined based on the historical performance status, historical network status and historical security status of the OT device within a historical time period. The transmission time period is a time period suitable for sending security hardening packets to the OT device.

[0031] The determination module is used to determine the real-time performance status, real-time network status, and real-time security status of the OT device in the current round of the transmission time period;

[0032] The startup module is configured to initiate the sending process of sending a security hardening package to the OT device in the current round of the sending time period when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the OT device can perform security hardening processing based on the security hardening package.

[0033] It is evident that eliminating the need to send security hardening packages during maintenance or non-production periods improves the efficiency of security hardening package delivery and enhances the security of OT equipment.

[0034] In one embodiment, the acquisition module is used to query the database for search results corresponding to the OT device identifier as the search term, wherein the database stores the association between the identifiers of multiple OT devices and their corresponding transmission time periods.

[0035] Therefore, the sending time period can be quickly obtained from the database by querying using identifiers.

[0036] In one embodiment, the startup module is configured to, during the transmission process, stop the transmission process and record the breakpoint of the transmission process when the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, or the real-time security status no longer meets the third condition.

[0037] As can be seen, the transmission process stops when the conditions are no longer met, thus not affecting the current normal operation of the OT equipment. Moreover, by recording the breakpoints in the transmission process, it is convenient to resume transmission from the breakpoint later, thereby improving the transmission efficiency of the security hardening packet.

[0038] In one embodiment, the startup module is configured to resume the transmission process from the breakpoint after the transmission process has been stopped, when the real-time performance state recovers to meet the first condition, the real-time network state recovers to meet the second condition, and the real-time security state recovers to meet the third condition within the transmission time period.

[0039] As can be seen, resuming the transmission process from the breakpoint when the conditions are met again not only ensures the integrity of the security-enhanced packet but also improves transmission efficiency.

[0040] In one embodiment, the acquisition module is configured to acquire security logs and / or suspicious objects of the OT device within the historical time period, host performance data and / or performance data of predetermined processes within the historical time period, and host network status data and / or network status data of predetermined processes within the historical time period; perform a first analysis on the security logs and / or suspicious objects to determine the historical security status within the historical time period; perform a second analysis on the host performance data and / or performance data of predetermined processes to determine the historical performance status within the historical time period; perform a third analysis on the host network status data and / or network status data of predetermined processes to determine the historical network status within the historical time period; determine a common time period from the historical time period where the historical security status, the historical network status, and the historical performance status all meet their respective constraints; and determine the transmission time period based on the common time period.

[0041] Therefore, the embodiments of the present invention fully consider the determinism and periodicity of OT equipment and realize a method for determining the transmission time period based on historical data.

[0042] A system for sending security hardening packets, comprising:

[0043] N data collection agents are deployed in N OT devices. Each of the N data collection agents is used to collect real-time performance data, real-time network status data, real-time security logs and / or real-time suspicious objects of the corresponding OT device in the current round of its respective transmission time period. The transmission time period is determined based on the historical performance status, historical network status and historical security status of the corresponding OT device in a historical time period. The transmission time period is a time period suitable for sending security hardening packages to the corresponding OT device.

[0044] A monitoring server is used to determine the real-time security status based on the real-time security logs and / or real-time suspicious objects, to determine the real-time performance status based on the real-time performance data, and to determine the real-time network status based on the real-time network status data.

[0045] A security reinforcement packet sending server is configured to initiate a security reinforcement packet sending process to the corresponding OT device in the current round of the sending time period of the corresponding OT device when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the corresponding OT device can perform security reinforcement processing based on the security reinforcement packet.

[0046] In one implementation, it includes:

[0047] The monitoring equipment is used to aggregate real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects from the N OT devices, and send the aggregation results to the monitoring server.

[0048] In one implementation, it includes:

[0049] There are M distribution devices, each of which corresponds to at least one OT device, where M is a positive integer of at least 1 and M is less than or equal to N;

[0050] Each of the M distribution devices is configured to receive a security reinforcement package for the at least one OT device from the reinforcement package sending server, and send the security reinforcement package for the at least one OT device to the at least one OT device.

[0051] An electronic device, comprising:

[0052] processor;

[0053] Memory for storing the executable instructions of the processor;

[0054] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the method of sending a security hardening packet as described above.

[0055] A computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implement the method of sending a security-hardened packet as described above.

[0056] A computer program product includes a computer program that, when executed by a processor, implements the method of sending a security-hardening packet as described above. Attached Figure Description

[0057] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which will make the above and other features and advantages of the present invention more apparent to those skilled in the art. In the drawings:

[0058] Figure 1 is an exemplary flowchart of a method for sending a security hardening package according to an embodiment of the present invention.

[0059] Figure 2 is an exemplary schematic diagram of determining the transmission time period according to an embodiment of the present invention.

[0060] Figure 3 is an exemplary structural diagram of a system for sending a security hardening package according to an embodiment of the present invention.

[0061] Figure 4 is a schematic diagram of an exemplary process for sending a security hardening package according to an embodiment of the present invention.

[0062] Figure 5 is an exemplary structural diagram of an apparatus for sending a security reinforcement package according to an embodiment of the present invention.

[0063] Figure 6 is a structural diagram of an electronic device according to an embodiment of the present invention.

[0064] The accompanying figure is labeled as follows: Detailed Implementation

[0065] To make the objectives, technical solutions, and advantages of the present invention clearer, the following embodiments are provided to further illustrate the present invention in detail.

[0066] For the sake of brevity and intuitiveness, the following description uses several representative embodiments to illustrate the solution of the present invention. Numerous details in the embodiments are only used to aid in understanding the solution of the present invention. However, it is obvious that the technical solution of the present invention can be implemented without being limited to these details. To avoid unnecessarily obscuring the solution of the present invention, some embodiments are not described in detail, but only a framework is given. In the following text, "comprising" means "including but not limited to," and "according to..." means "at least according to..., but not limited to only according to...". Due to Chinese language habits, unless the quantity of a component is specifically indicated below, it means that the component can be one or more, or can be understood as at least one.

[0067] There are many fundamental differences between IT systems and OT systems. For example, these differences include at least: (1) OT systems typically need to control physical processes in critical environments and have strong requirements for process security and protection; (2) OT systems have a lifespan of 15 to 20 years; (3) OT systems require high availability, integrity, and confidentiality; (4) OT systems have highly deterministic systems and networks; (5) OT systems typically have real-time applications with responses closely related to time, and high latency and / or jitter are unacceptable; (6) Data in OT systems typically uses simple data types, has high data rates, and requires real-time analysis; (7) Networks in OT systems typically consist of human-machine interfaces (HMIs), sensors, input / output interfaces (IO), dedicated controllers (e.g., PLCs, RTUs), coded displays, and touchscreens; (8) It is difficult to schedule patch restarts in OT systems, and patch restarts have negative impacts, etc.

[0068] Crucially, compared to IT systems (primarily human-to-human communication), OT systems (primarily machine-to-machine communication) exhibit a high degree of determinism and periodicity.

[0069] To address the aforementioned significant characteristics of OT systems, this invention employs predefined statistical or correlation analysis methods from historical monitoring data of OT devices to determine suitable time periods for sending security reinforcement packages to the OT devices. Then, in the current round of the time period, security reinforcement packages are distributed to the OT devices based on continuous monitoring of their real-time status. If, during continuous monitoring, an OT device is identified as entering an unsuitable state (e.g., high network load, excessively busy status, or under attack), sending security reinforcement packages to the OT device is suspended until the status becomes appropriate and secure again, at which point sending resumes. Since sending security reinforcement packages does not need to be fixed during maintenance or non-production periods, the efficiency of security reinforcement package delivery is improved, and the security of the OT devices is enhanced.

[0070] Figure 1 is an exemplary flowchart of a method for sending a security hardening packet according to an embodiment of the present invention. As shown in Figure 1, the method includes:

[0071] Step 101: Obtain the transmission time period corresponding to the OT device. The transmission time period is determined based on the historical performance status, historical network status, and historical security status of the OT device within a historical time period. The transmission time period is a suitable time period for sending security hardening packets to the OT device.

[0072] Here, OT (Operational Technology) devices include technical equipment used in industrial environments to monitor and control production processes, electromechanical equipment, and tooling. These devices are typically directly related to the actual operation of industrial production lines, responsible for tasks such as real-time data acquisition, processing, and equipment control. OT devices have a wide range of applications, including but not limited to industrial sensors, actuators, programmable logic controllers (PLCs), and host computers, etc.

[0073] Preferably, the OT device is specifically implemented as a host computer. A host computer is a computer that can directly issue control commands; it generally refers to the main computer or host computer in an industrial control system, used to monitor various equipment and systems in the industrial production process. These host computers typically display various signal changes on their screens, such as hydraulic pressure, water level, and temperature, thereby achieving real-time monitoring and control of the industrial process.

[0074] A security hardening package may include security hardening scripts and / or security hardening patches. Specifically: a security hardening script is a set of instructions or command language used to automate operations and perform security hardening tasks on OT devices; a security hardening patch is a program that fixes code defects or vulnerabilities and can be used to correct security vulnerabilities in OT devices.

[0075] The number of security hardening packages can be one or more. In one implementation, multiple security hardening scripts and / or multiple security hardening patches can be packaged into a single package, and then the single package can be divided into multiple security hardening packages to be transmitted, thereby facilitating subsequent breakpoint resume processing.

[0076] In one implementation, the method shown in Figure 1 includes a process for pre-determining the transmission time period for each OT device. This process includes:

[0077] (1) Obtain security logs and / or suspicious objects of OT devices within a historical time period, host performance data and / or performance data of scheduled processes within a historical time period, and host network status data and / or network status data of scheduled processes within a historical time period. For example, suspicious objects can be any object that may contain malicious programs or malicious code. For example, suspicious objects may include: suspicious files, suspicious process names, suspicious execution behaviors, suspicious file contents, suspicious network behaviors, etc.

[0078] (2) Perform a first analysis on security logs and / or suspicious objects to determine the historical security status within a historical time period; perform a second analysis on host performance data and / or scheduled process performance data to determine the historical performance status within a historical time period; and perform a third analysis on host network status data and / or scheduled process network status data to determine the historical network status within a historical time period.

[0079] (3) From the historical time period, identify the common time period in which the historical security state, historical network state and historical performance state all meet their respective constraints.

[0080] (4) Determine the sending time period based on a common time period. For example, the sending time period can be a certain time period within a day, a week, or a month, etc.

[0081] Specifically, the historical time period can be a relatively long period (e.g., a week, a month, a quarter, or a whole year, etc.) to ensure the accuracy of the transmission time cycle. Preferably, the historical time period spans multiple transmission time cycles and is close to the current time. More preferably, the historical time period is adjustable.

[0082] Let's take the most recent week as an example to illustrate.

[0083] First, obtain the security logs and / or suspicious objects of the OT device for the past week. Then, analyze the security logs and / or suspicious objects for the past week to determine the security status of the OT device. For example, the security status may specifically include: the time of identified attack within the week (e.g., the specific date and hour), the dates of potential attack within the week, the dates of identified no attack within the week, and so on.

[0084] Next, acquire the host performance data and / or scheduled process performance data of the OT device over the past week. For example, host performance data may include: the overall CPU utilization of the OT device (i.e., the host), the overall RAM utilization of the OT device, the overall disk utilization of the OT device, the overall GPU utilization of the OT device, etc. Scheduled processes can be critical processes determined by user commands. For example, scheduled processes may include WinCC, Step7, PCS7, etc. Scheduled process performance data may include: the CPU utilization of the scheduled process, the RAM utilization of the scheduled process, the disk utilization of the scheduled process, the GPU utilization of the scheduled process, etc. Analyze the host performance data and / or scheduled process performance data of the OT device over the past week to determine the performance status of the OT device over the past week. Performance status may specifically include: the time during which the host and scheduled processes were not busy (e.g., specific dates and hours within those dates), the time during which both the host and scheduled processes were busy, the time during which the host was not busy and all scheduled processes were busy, the time during which the host was busy and all scheduled processes were not busy, etc.

[0085] Next, obtain the host network status data and / or scheduled process network status data of the OT device for the most recent week. For example, host network status data may include: the available network bandwidth of the OT device as a whole (i.e., the host) and the network interface utilization rate of the OT device as a whole, etc. Scheduled process network status data may include: the available network bandwidth of the scheduled process and the network interface utilization rate of the scheduled process, etc. Parse the host network status data and / or scheduled process network status data of the OT device for the most recent week to determine the network status of the OT device for the most recent week. Network status may specifically include: times within the week when the network utilization of the host and scheduled processes is not prominent (e.g., specific dates and specific hours within those dates); times within the week when the network utilization of both the host and scheduled processes is prominent; times within the week when the host's network utilization is not prominent but the scheduled process's network utilization is prominent; times within the week when the host's network utilization is prominent but the scheduled process's network utilization is not prominent, etc.

[0086] Furthermore, a common time period is identified from the past week where historical security status, historical network status, and historical performance status all meet their respective constraints. For example, suppose the constraints for historical security status are: neither the host nor the scheduled process is busy; the constraints for historical network status are: neither the host nor the scheduled process has significant network usage; and the constraints for historical security status are: no attacks are detected. Assume the identified common time period is Monday from 3 PM to 5 PM. Then, the suitable time period for sending security hardening packets to OT devices is determined to be every Monday from 3 PM to 5 PM. This time period can have multiple rounds (i.e., multiple Mondays from 3 PM to 5 PM), with the current round being the Monday from 3 PM to 5 PM closest to the current time.

[0087] The above exemplary descriptions of historical time periods and typical examples of constraints will be appreciated by those skilled in the art. Such descriptions are merely exemplary and are not intended to limit the scope of protection of the embodiments of the present invention.

[0088] Similarly, the transmission time period of each OT device can be determined, and the association between the identifier of each OT device and the corresponding transmission time period can be stored in the database.

[0089] In one implementation, step 101 includes: using the identifier of the OT device as the search term, querying the database for the search results corresponding to the search term, wherein the database stores the association between the identifiers of multiple OT devices and their corresponding transmission time periods.

[0090] For example, the following relationships are stored in the database: (1) OT device 1, identified as aaa, with a transmission time period of Monday; (2) OT device 2, identified as bbb, with a transmission time period of Wednesday; (3) OT device 3, identified as ccc, with a transmission time period of Thursday to Friday; (4) OT device 4, identified as ddd, with a transmission time period of 3 PM to 4 PM on Tuesday. When it is desired to obtain the transmission time period of OT device 1, a query is performed in the database using "aaa" as the search term. The search result is "Monday", so the transmission time period of OT device 1 is Monday.

[0091] Step 102: Determine the real-time performance status, real-time network status, and real-time security status of the OT device in the current round of the transmission time period.

[0092] Here, for example, assuming the transmission time period is Monday, and the current time is Monday (i.e., in the current round of the transmission time period), the real-time performance status, real-time network status, and real-time security status of the OT device in the current round of the transmission time period are determined.

[0093] Step 103: When the real-time performance status meets the predetermined first condition, the real-time network status meets the predetermined second condition, and the real-time security status meets the predetermined third condition, in the current round of the transmission time period, the transmission process of sending a security hardening package to the OT device is initiated, so that the OT device can perform security hardening processing based on the security hardening package.

[0094] In one implementation: the first condition is equivalent to the historical performance state constraint used when determining the transmission time period; the second condition is equivalent to the historical network state constraint used when determining the transmission time period; and the third condition is equivalent to the historical security state constraint used when determining the transmission time period. Optionally, the first, second, and third conditions may differ from their respective constraints used when determining the transmission time period. Preferably, the first, second, and third conditions are more stringent than their respective constraints to ensure the accuracy of the transmission time. For example, suppose the historical network state constraint is: network occupancy of the host or the predetermined process is not prominent; the second condition could be: network occupancy of both the host and the predetermined process is not prominent. Therefore, when the real-time performance state characterizes that network occupancy of both the host and the predetermined process is not prominent, the real-time performance state meets the second condition.

[0095] During the transmission process, the performance status, network status, and security status of the OT device are continuously collected. Therefore, the real-time performance status, real-time network status, and real-time security status of the OT device may change.

[0096] In one implementation, the method includes: during transmission, stopping the transmission process and recording the breakpoint when the real-time performance state no longer meets a first condition, the real-time network state no longer meets a second condition, or the real-time security state no longer meets a third condition. Therefore, stopping the transmission process when the conditions are no longer met does not affect the current normal operation of the OT device. Furthermore, recording the breakpoint facilitates subsequent execution of resume transmission, improving the transmission efficiency of the security-hardened packet.

[0097] In one implementation, the method includes: after stopping the transmission process, when the real-time performance status recovers to meet a first condition, the real-time network status recovers to meet a second condition, and the real-time security status recovers to meet a third condition within the transmission time period, the transmission process is resumed from the breakpoint. Therefore, resuming the transmission process from the breakpoint when the conditions are met again ensures the integrity of the security-enhanced packet and improves transmission efficiency.

[0098] Figure 2 is an exemplary schematic diagram of determining the transmission time period according to an embodiment of the present invention. In Figure 2, the following are obtained from the OT device within a historical time period: (1) historical security logs and / or historical suspicious objects 10; (2) historical performance data 11; and (3) historical network status data 12.

[0099] The historical security logs and / or historical suspicious objects 10 are parsed to obtain the historical security status 13. For example, the historical security status 13 may specifically include: the time when an attack was determined within the historical time period, the date on which an attack may have occurred within the historical time period, the date on which no attack was determined within the historical time period, and so on.

[0100] The historical performance data 11 is parsed to obtain the historical performance status 14. The parsing process may include comparing the historical performance data 11 with predetermined thresholds (which may be one or more) to determine busy and non-busy times, etc. Here, the thresholds may be specified by the user based on instructions, determined based on the maximum value of the performance data (e.g., using the product of the maximum value of the performance data and a predetermined percentage (e.g., 80%) as the threshold), or based on any transformed value of the predetermined value or the maximum value of the performance data.

[0101] The historical network state data 12 is parsed to obtain the historical performance state 15. The parsing process may include comparing the historical network state data 12 with predetermined thresholds (which may be one or more) to determine periods of high network occupancy and periods of low network occupancy, etc. Here, the thresholds may be specified by the user based on instructions, determined based on the maximum value of the network state data (e.g., using the product of the maximum value of the network state data (e.g., available bandwidth) and a predetermined percentage (e.g., 80%) as the threshold), or based on any transformed value of the predetermined value or the maximum value of the performance data.

[0102] In the process 16 of determining the transmission time period, a common time period 17 is identified where historical security status, historical network status, and historical performance status all meet their respective constraints. For example, a common time period 17 is identified where there are no attack dates, no busy times, and times when network usage is not prominent. The transmission time period of the OT device is determined based on this common time period 17. For example, when the common time period 17 is Monday to Wednesday, Monday to Wednesday can be defined as one transmission time period, or Monday, Tuesday, and Wednesday can be defined as separate transmission time periods, or the same or different hour intervals of Monday, Tuesday, or Wednesday can be defined as multiple transmission time periods.

[0103] This invention also proposes a system for sending security hardening packets. Figure 3 is an exemplary structural diagram of a system for sending security hardening packets according to an embodiment of the present invention. As shown in Figure 3, the system includes:

[0104] N data collection agents 41, 42…4N are deployed across N OT devices 241, 242…24N. These N OT devices 241, 242…24N are connected to N routing devices 251, 252…25N. Each of the N data collection agents 41, 42…4N collects real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects from the corresponding OT device in the current round of the transmission time period. The transmission time period is determined based on the historical performance, network, and security status of the OT device over a historical time period and is a suitable time period for sending security hardening packets to the OT device. Each of the N data collection agents 41, 42…4N, via the routing devices connected to the corresponding OT device, sends its collected real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects from the current round to the monitoring server 20.

[0105] The monitoring server 20 is used to determine the real-time security status of the corresponding OT device based on the real-time security logs and / or real-time suspicious objects sent by each acquisition agent, to determine the real-time performance status of the corresponding OT device based on the real-time performance data sent by each acquisition agent, and to determine the real-time network status of the corresponding OT device based on the real-time network status data sent by each acquisition agent.

[0106] Preferably, the monitoring server 20 pre-determines the transmission time period for each OT device based on its historical performance, network, and security status within a historical time period, and sends the transmission time period of each OT device to the hardening packet sending server 21 and the corresponding OT device. Each OT device informs the collection agent contained within it of its own transmission time period, so that the collection agent can time and collect real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects in the current round of the transmission time period.

[0107] The hardening packet sending server 21 is used to initiate the sending process of sending a security hardening packet to the corresponding OT device when the real-time performance status of the corresponding OT device meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the corresponding OT device can perform security hardening processing based on the security hardening packet.

[0108] The system also includes: a monitoring device 23, used to aggregate real-time performance data, real-time network status data, real-time security logs and / or real-time suspicious objects from N OT devices 41, 42...4N, and send the aggregated results to the monitoring server 20; M distribution devices 221...22M, where each distribution device corresponds to at least one OT device, where M is a positive integer of at least 1 and M is less than or equal to N; each of the M distribution devices 221...22M is used to receive a security hardening package for the corresponding at least one OT device from the hardening package sending server 21, and send the security hardening package for the corresponding at least one OT device to the corresponding at least one OT device.

[0109] Figure 4 is a schematic diagram of an exemplary process for sending a security hardening package according to an embodiment of the present invention. As shown in Figure 4, the process includes:

[0110] First, the transmission time period 56 of the OT device is read from the database 70. Then, the real-time security log and / or real-time suspicious object 50, real-time performance data 51, and real-time network status data 52 in the current round of the transmission time period 56 of the OT device are obtained. The real-time security log and / or real-time suspicious object 50 are parsed to determine the real-time security status 53 (e.g., whether the OT device is currently under attack), the real-time performance data 51 is parsed to determine the real-time performance status 54 (e.g., whether the OT device is currently experiencing high performance load), and the real-time network status data 52 is parsed to determine the real-time network status 55 (e.g., whether the OT device's current network usage is high).

[0111] In the first verification 57, it is determined whether the real-time security state 53, real-time performance state 54 and real-time network state 55 all meet their respective conditions. When all conditions are met (corresponding to the "Y branch"), the sending process 59 of sending a security hardening packet to the OT device is started; when not all conditions are met (corresponding to the "N branch"), the waiting process 58 is executed, during which no security hardening packet is sent to the OT device.

[0112] After initiating the security reinforcement package sending process 59, the following data may change over time in the OT device: (1) real-time security logs and / or real-time suspicious objects 50; (2) real-time performance data 51; (3) real-time security status 52, and further parse out: (1) updated real-time security status 53; (2) updated real-time performance status 54; (3) updated real-time network status 55. In the second verification, it is determined whether the updated real-time security status 53, updated real-time performance status 54, and updated real-time network status 55 all meet their respective conditions (which can be equivalent to the conditions in step 57). When all conditions are met (corresponding to the "Y branch"), the security reinforcement package continues to be sent to the OT device; when not all conditions are met (corresponding to the "N branch"), the waiting process 61 is executed. During the waiting process 61, the security reinforcement package is no longer sent to the OT device and the breakpoint is recorded. When the conditions are met again in the subsequent recovery, the security reinforcement package is sent to the OT device again from the breakpoint in the current round of the sending time period 56. Continue executing the above process until the security hardening package is successfully sent.

[0113] Figure 5 is an exemplary structural diagram of an apparatus for sending a security hardening package according to an embodiment of the present invention. As shown in Figure 5, the apparatus 500 for sending a security hardening package includes: an acquisition module 501, used to acquire a transmission time period corresponding to an OT device, the transmission time period being determined based on the historical performance status, historical network status, and historical security status of the OT device within a historical time period, and the transmission time period being a suitable time period for sending a security hardening package to the OT device; a determination module 502, used to determine the real-time performance status, real-time network status, and real-time security status of the OT device in the current round of the transmission time period; and a start module 503, used to start the transmission process of sending a security hardening package to the OT device in the current round of the transmission time period when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the OT device performs security hardening processing based on the security hardening package.

[0114] In one implementation, the acquisition module 501 is used to query the database for the search results corresponding to the OT device identifier as the search term. The database stores the association between the identifiers of multiple OT devices and their corresponding transmission time periods.

[0115] In one implementation, the startup module 503 is used to stop the transmission process and record the breakpoint of the transmission process when the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, or the real-time security status no longer meets the third condition during the transmission process.

[0116] In one implementation, the startup module 503 is configured to resume the transmission process from the breakpoint when, after the transmission process has stopped, the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, and the real-time security status recovers to meet the third condition within the transmission time period.

[0117] In one embodiment, the acquisition module 501 is configured to acquire security logs and / or suspicious objects of the OT device within a historical time period, host performance data and / or performance data of predetermined processes within a historical time period, and host network status data and / or network status data of predetermined processes within a historical time period; perform a first analysis on the security logs and / or suspicious objects to determine the historical security status within the historical time period; perform a second analysis on the host performance data and / or performance data of predetermined processes to determine the historical performance status within the historical time period; perform a third analysis on the host network status data and / or network status data of predetermined processes to determine the historical network status within the historical time period; determine a common time period from the historical time period where the historical security status, historical network status, and historical performance status all meet their respective constraints; and determine a transmission time period based on the common time period.

[0118] This invention also proposes an electronic device with a processor-memory architecture. Figure 6 is a structural diagram of the electronic device according to an embodiment of the present invention. As shown in Figure 6, the electronic device 600 includes a processor 601, a memory 602, and a computer program stored in the memory 602 and executable on the processor 601. When the computer program is executed by the processor 601, it implements the method of sending a security-hardened packet as described above. Specifically, the memory 602 can be implemented as various storage media such as electrically erasable programmable read-only memory (EEPROM), flash memory, and programmable programmable read-only memory (PROM). The processor 601 can be implemented as including one or more central processing units (CPUs) or one or more field-programmable gate arrays (FPGAs), wherein the FPGA integrates one or more CPU cores. Specifically, the CPU or CPU core can be implemented as a CPU, MCU, or DSP, etc.

[0119] It should be noted that not all steps and modules in the above processes and structural diagrams are mandatory; some steps or modules can be omitted as needed. The execution order of the steps is not fixed and can be adjusted as required. The division of modules is merely for the convenience of description and functional division. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can also be implemented by the same module. These modules can be located in the same device or in different devices.

[0120] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include specially designed permanent circuitry or logic devices (such as dedicated processors, such as FPGAs or ASICs) to perform specific operations. A hardware module may also include programmable logic devices or circuitry (such as general-purpose processors or other programmable processors) temporarily configured by software to perform specific operations. The choice between mechanical implementation, dedicated permanent circuitry, or temporarily configured circuitry (such as software-configured circuitry) can be made based on cost and time considerations.

[0121] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for sending a security hardening packet, characterized in that, include: Get (101) the transmission time period corresponding to the operating technology device, the transmission time period is determined based on the historical performance status, historical network status and historical security status of the operating technology device in a historical time period, and the transmission time period is a time period suitable for sending security reinforcement packets to the operating technology device; Determine (102) the real-time performance status, real-time network status, and real-time security status of the operating technology device in the current round of the transmission time period; When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, in the current round of the transmission time period, the transmission process of sending a security hardening package to the operating technology device is initiated (103), so that the operating technology device performs security hardening processing based on the security hardening package.

2. The method according to claim 1, characterized in that, The acquisition (101) corresponds to the transmission time period of the operating technology device, including: Using the identifier of the operating technology device as the search term, the database is used to query the search results corresponding to the search term. The database stores the association between the identifiers of multiple operating technology devices and their corresponding transmission time periods.

3. The method according to claim 1 or 2, characterized in that, include: During the transmission process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, or the real-time security status no longer meets the third condition, the transmission process is stopped and the breakpoint of the transmission process is recorded.

4. The method according to claim 3, characterized in that, include: After the transmission process is stopped, the transmission process is resumed from the breakpoint when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, and the real-time security status recovers to meet the third condition within the transmission time period.

5. The method according to any one of claims 1-4, characterized in that, include: Acquire the security logs and / or suspicious objects of the operating technology device during the historical time period, the host performance data and / or the performance data of the predetermined process during the historical time period, and the host network status data and / or the network status data of the predetermined process during the historical time period. The security logs and / or the suspicious objects are first parsed to determine the historical security status within the historical time period. A second parsing is performed on the host performance data and / or the performance data of the predetermined process to determine the historical performance status within the historical time period. A third parsing is performed on the network status data of the host and / or the network status data of the predetermined process to determine the historical network status within the historical time period. From the historical time period, determine the common time period in which the historical security state, the historical network state, and the historical performance state all meet their respective constraints; The transmission time period is determined based on the common time period.

6. A device for delivering a security reinforcement package, characterized in that, include: The acquisition module (501) is used to acquire the transmission time period corresponding to the operating technology device. The transmission time period is determined based on the historical performance status, historical network status and historical security status of the operating technology device in a historical time period. The transmission time period is a time period suitable for sending security reinforcement packets to the operating technology device. The determining module (502) is used to determine the real-time performance status, real-time network status and real-time security status of the operating technology device in the current round of the transmission time period; The startup module (503) is used to initiate the sending process of sending a security hardening package to the operating technology device in the current round of the sending time period when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the operating technology device can perform security hardening processing based on the security hardening package.

7. The apparatus according to claim 6, characterized in that, The acquisition module (501) is used to query the database for the search results corresponding to the search item, using the identifier of the operating technology device as the search item. The database stores the association between the identifiers of multiple operating technology devices and their corresponding transmission time periods.

8. The apparatus according to claim 6 or 7, characterized in that, The startup module (503) is used to stop the transmission process and record the breakpoint of the transmission process when the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, or the real-time security status no longer meets the third condition during the transmission process.

9. The apparatus according to claim 8, characterized in that, The startup module (503) is used to resume the transmission process from the breakpoint after the transmission process has been stopped, when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, and the real-time security status recovers to meet the third condition within the transmission time period.

10. The apparatus according to any one of claims 6-9, characterized in that, The acquisition module (501) is used to acquire the security logs and / or suspicious objects of the operating technology device during the historical time period, the host performance data and / or the performance data of the predetermined process during the historical time period, and the host network status data and / or the network status data of the predetermined process during the historical time period. The security logs and / or the suspicious objects are first analyzed to determine the historical security status within the historical time period; the host performance data and / or the performance data of the predetermined processes are second analyzed to determine the historical performance status within the historical time period; the network status data of the host and / or the network status data of the predetermined processes are third analyzed to determine the historical network status within the historical time period; from the historical time period, a common time period in which the historical security status, the historical network status, and the historical performance status all meet their respective constraints is determined; based on the common time period, the transmission time period is determined.

11. A system for sending security hardening packets, characterized in that, include: N data collection agents (41, 42...4N) are deployed in N operational technology devices (241, 242...24N). Each of the N data collection agents (41, 42...4N) is used to collect real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects of the corresponding operational technology device in the current round of its respective transmission time period. The transmission time period is determined based on the historical performance status, historical network status, and historical security status of the corresponding operational technology device within a historical time period. The transmission time period is a time period suitable for sending security hardening packets to the corresponding operational technology device. The monitoring server (20) is used to determine the real-time security status based on the real-time security logs and / or real-time suspicious objects, determine the real-time performance status based on the real-time performance data, and determine the real-time network status based on the real-time network status data. The reinforcement packet sending server (21) is used to initiate the sending process of sending a security reinforcement packet to the corresponding operating technology device in the current round of the sending time period of the corresponding operating technology device when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, and the real-time security status meets a predetermined third condition, so that the corresponding operating technology device can perform security reinforcement processing based on the security reinforcement packet.

12. The system according to claim 11, characterized in that, include: The monitoring device (23) is used to aggregate the real-time performance data, real-time network status data, real-time security logs and / or real-time suspicious objects of the N operating technology devices (41, 42...4N), and send the aggregation results to the monitoring server (20).

13. The system according to claim 12, characterized in that, include: M distribution devices (221……22M), wherein each distribution device corresponds to at least one operating technology device, wherein M is a positive integer of at least 1, and M is less than or equal to N; Each of the M distribution devices (221……22M) is configured to receive a security reinforcement package of the at least one operating technology device from the reinforcement package sending server (21) and send the security reinforcement package of the at least one operating technology device to the at least one operating technology device.

14. An electronic device, characterized in that, include: Processor (601); A memory (602) for storing executable instructions of the processor (601); The processor (601) is configured to read the executable instructions from the memory (602) and execute the executable instructions to implement the method of sending a security hardening packet according to any one of claims 1-5.

15. A computer-readable storage medium storing computer instructions thereon, characterized in that, When the computer instructions are executed by the processor, they implement the method of sending a security hardening packet as described in any one of claims 1-5.

16. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the method of sending a security-hardened packet as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Industrial control system network security simulation test platform and computer equipment

    CN114157493A

  • Method and system for security monitoring of OT systems

    CN114270281A

  • Application method and system for remote upgrade of solid-state battery pack

    CN116860296A

  • Intelligent network security system and method based on big data analysis

    CN117254973A

  • Water conservancy key information infrastructure network security situation awareness platform

    CN118138293A