Method and apparatus for displaying network attacks by means of network topology, and computer device
By generating multi-layered network topology structures and displaying affected devices in OT networks, the problem of attack analysis difficulties caused by excessive assets in large OT networks is solved, achieving efficient attack impact analysis and visualization, and improving the efficiency of OT network security incident analysis.
Patent Information
- Application Number
- PCT/CN2024/105310
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-12
- Publication Date
- 2026-01-15
AI Technical Summary
In large-scale OT networks, existing technologies struggle to clearly display all assets on a single page and perform effective attack analysis and visualization of affected assets, especially when there are too many assets in a large-scale OT network.
By collecting device information from network security monitoring, a multi-layered network topology is generated, and attack information on devices is received. Affected devices are displayed in the multi-layered network topology, and affected assets are displayed using color markings and regions. Potentially affected devices are analyzed by combining control commands and communication protocols.
It improves the efficiency of analyzing large-scale OT network security incidents, can automatically identify all assets and areas affected by the same attack, and conduct in-depth analysis through multi-layer network topology, highlighting the devices attacked by the network attack, which facilitates operators to conduct in-depth analysis.
Smart Images

Figure CN2024105310_15012026_PF_FP_ABST
Abstract
Description
Network topology reveals methods, devices, and computer equipment used in network attacks. Technical Field
[0001] This application relates to the field of network security, and more specifically, to a method, apparatus, computer device, and storage medium for displaying network attacks through network topology. Background Technology
[0002] In large-scale OT (Operational Technology) networks, due to the development of digitalization, many OT devices are connected to a single Ethernet network, making it difficult to display all assets on a single page and perform attack analysis on the OT network topology.
[0003] In some security monitoring systems, operators can edit assets on the network topology map for clearer display. The system can store the edited network topology for future display of a fixed topology. This approach partially addresses the issue of unclear OT network topology on a single page, but due to the sheer number of assets in large-scale OT networks, it is not suitable for attack analysis and visualization of affected assets on OT network topologies.
[0004] Summary of the Invention
[0005] This summary section is provided to introduce some selected concepts in a simplified form, which will be further described in the detailed description section below. This summary section is not intended to identify any key or essential features of the claimed subject matter, nor is it intended to help determine the scope of the claimed subject matter.
[0006] Based on this, this application discloses a method for displaying network attacks through network topology, comprising:
[0007] Collect device information for network security monitoring;
[0008] Based on the device information, a multi-layer network topology is generated;
[0009] Receive attack information about the device;
[0010] Based on the attack information, the affected devices are displayed in the multi-layer network topology.
[0011] The above method can display all devices and network attacks in a list, allowing operators to view the number of assets and areas affected by a certain type of attack and conduct further analysis based on the attack type, thereby improving the efficiency of analyzing large-scale OT network security incidents.
[0012] Furthermore, generating a multi-layer network topology based on the device information includes:
[0013] Based on the regional division and quantity threshold, a multi-layer network topology is generated.
[0014] Using the above methods, when an asset is attacked, attack impact analysis can be performed automatically to identify all assets and areas affected by the same attack, thereby helping operators in the OT network to efficiently find all assets affected by the same security incident.
[0015] Furthermore, after receiving the attack information of the device, it also includes...
[0016] Analyze other affected devices based on the control commands or communication protocols of the device.
[0017] By using the methods described above, potentially affected devices can be identified through control commands and communication protocols, which can help operators conduct in-depth analysis of critical assets that are vulnerable to attacks on industrial control protocols.
[0018] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0019] In the multi-layer network topology, the affected devices are color-coded.
[0020] The above methods can highlight devices that have been attacked by cyberattacks, making them easier to identify and analyze the impact of subsequent cyberattacks.
[0021] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0022] Upon receiving a first external instruction, the affected devices within the area are displayed.
[0023] Using the above method, the total number of attacked assets in a region can be displayed in a special area at the top of the region in a multi-layer network topology, which facilitates operators to perform in-depth analysis of all attacked assets.
[0024] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0025] Receive a second external instruction to display information about the attack event and the affected devices.
[0026] The above methods can help operators understand attack events and the attributes and information of attacked devices, making it easier to analyze the impact of network attacks on devices.
[0027] Furthermore, this application discloses an apparatus for displaying network attacks through network topology, comprising:
[0028] The information collection module is used to collect device information in network security monitoring;
[0029] The network generation module is used to generate a multi-layer network topology based on the device information.
[0030] A network display module is used to receive attack information about the device and, based on the attack information, display the affected device in the multi-layer network topology.
[0031] This application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-described method.
[0032] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method.
[0033] This application also provides a computer program product tangibly stored on a computer-readable medium and comprising computer-executable instructions that, when executed, cause at least one processor to perform the methods described above. Attached Figure Description
[0034] Implementations of this disclosure are illustrated in the accompanying drawings by way of example rather than limitation, and similar reference numerals in the drawings denote the same or similar parts.
[0035] Figure 1 is a schematic flowchart of a method for displaying network topology according to an embodiment of this application.
[0036] Figure 2 is a schematic diagram of a network topology display device according to an embodiment of this application.
[0037] Figure 3 is a schematic diagram of a computer device showing a network topology according to an embodiment of this application.
[0038] Figure 4 is a schematic diagram of the architecture of a network topology display system according to an embodiment of this application.
[0039] The reference numerals in the accompanying drawings are as follows: S101-S103 Step 200: Device 201: Module 202: Module 203: Module 204: Module 300: Computer device 302: Processor 304: Memory Detailed Implementation
[0040] In the following description, numerous specific details are set forth for illustrative purposes. However, it will be understood that the invention can be implemented without these specific details. In other examples, well-known circuits, structures, and techniques have not been shown in detail so as not to affect the understanding of the description.
[0041] In this application, the implementation scenario is as follows: A method and system for attack impact analysis using multi-layer visualization of network topology in large-scale OT network security monitoring is proposed. When there are too many assets in a large-scale OT network, multi-layer visualization of OT network assets is performed. Then, when a certain device asset is attacked, attack impact analysis is conducted to identify all device assets affected by the same attack. In the multi-layer OT network topology structure, all affected assets and areas will be marked, and the specific protocol communication used by the attack will also be visualized to aid in the analysis of attack paths and impacts.
[0042] Specifically, this application discloses a method for displaying network attacks through network topology, comprising:
[0043] S101 collects device information for network security monitoring.
[0044] Specifically, the device can be an OT device. An agent is then installed in the OT device to acquire its connection data, security configuration, logs, and behavior, and transmits this data to the Central OT Security Monitoring Server via a security monitoring sensor.
[0045] Furthermore, in some embodiments, OT devices are connected to switches via Ethernet. Security monitoring sensors are used to acquire OT traffic in the OT network to monitor communication information and network behavior between assets within the OT network.
[0046] In some embodiments, the device may also be referred to as an asset, for example, an attacked device may be referred to as an attacked asset.
[0047] S102, Generate a multi-layer network topology based on the device information.
[0048] Specifically, the central OT security monitoring server collects asset and communication information from OT devices and networks, automatically generating a multi-layered network topology on a single page. The central OT security monitoring server then monitors the security status of OT devices and networks.
[0049] S103, receive the attack information of the device, and display the affected device in the multi-layer network topology according to the attack information.
[0050] Specifically, when the central OT security monitoring server detects an attacked asset, it checks all assets associated with the attacked asset to see if other assets have been attacked in the same way. The central OT security monitoring server will examine the security event types of assets associated with the attacked asset to identify assets affected by the same attack.
[0051] Specifically, when the central OT security monitoring server detects an asset under attack, it performs attack type analysis to check if other assets have been attacked in the same way. The central OT security monitoring server will analyze attack communications based on the asset connection results database, and then perform affected asset detection, checking all assets connected to the attacked asset to see if these assets have been subjected to the same attack.
[0052] If a new asset is subjected to the same attack, an asset region analysis will be performed to determine which region the asset belongs to. For example, based on the asset's region information, the first-level region to which the attacked asset belongs is determined; then the second-level and third-level regions are determined in turn.
[0053] After finding all assets connected to the first attacked asset, the central OT security monitoring server will find all assets connected to these attacked assets to determine if more assets have been subjected to the same attack.
[0054] Once all interconnected attacked assets are located, the central OT security monitoring server will obtain all attacked assets and the connections between them.
[0055] For assets not associated with the attacked asset, this application will perform a similar check to identify the attacked asset, and then find all assets currently under attack. Finally, all attacked assets and their connections will be determined.
[0056] The above method can display all devices and network attacks in a list, allowing operators to view the number of assets and areas affected by a certain type of attack and conduct further analysis based on the attack type, thereby improving the efficiency of analyzing large-scale OT network security incidents.
[0057] Furthermore, generating a multi-layer network topology based on the device information includes:
[0058] Based on the regional division and quantity threshold, a multi-layer network topology is generated.
[0059] Specifically, in a multi-layer OT network topology, all assets in the first layer are divided into multiple regions, with a limited number of assets in each region. If the number of regions exceeds the limit, the regions in the first layer are further subdivided into different, more granular regions in the second layer. If the number of partitions in the second layer is too large, the partitions in the second layer can be classified into different hierarchical partitions in the third layer, until the number of partitions in each layer does not exceed the limit threshold.
[0060] Using the above methods, when an asset is attacked, attack impact analysis can be performed automatically to identify all assets and areas affected by the same attack, thereby helping operators in the OT network to efficiently find all assets affected by the same security incident.
[0061] Furthermore, after receiving the attack information of the device, it also includes...
[0062] Analyze other affected devices based on the control commands or communication protocols of the device.
[0063] Specifically, if an asset is detected to be under attack, the system will perform an attack impact analysis based on the multi-layer OT network topology to identify affected assets and the communication relationships between them. In addition to checking whether interconnected assets are affected by the same attack, it will also check whether assets in independent security domains that are not interconnected are affected by the same attack, thus identifying all affected assets. The central OT security monitoring server will then visualize the affected assets and their connection status on the multi-layer OT network topology page.
[0064] In some embodiments, because some assets with industrial applications in an OT network may be exploited to attack the control system via industrial control protocols, the central OT security monitoring server will examine the network communication behavior between the attacked assets to detect whether there are abnormal control commands or communications via industrial control protocols between one of the attacked assets and other assets. If there is abnormal industrial control protocol network behavior between two assets, a line of a special color, such as dark red, will be marked on the connection.
[0065] By using the methods described above, potentially affected devices can be identified through control commands and communication protocols, which can help operators conduct in-depth analysis of critical assets that are vulnerable to attacks on industrial control protocols.
[0066] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0067] In the multi-layer network topology, the affected devices are color-coded.
[0068] In this implementation, the central OT security monitoring server identifies all affected assets, checks for any connections between them, and then obtains all possible attack paths between the assets. All assets subjected to the same attack are marked with the same color, for example, red on the asset icon in the OT network topology diagram. If there is a connection between two assets, the connection point will be marked with a line and a special color (such as red).
[0069] In some embodiments, based on the analysis results of the attack impact between assets in a multi-layer OT network topology, an attack layer visualization diagram can be created according to the method described above. If assets in different areas of the second layer are interconnected and subjected to the same attack, the connection between the two areas in the second layer will be marked with a line of a special color, such as red. If there is a connection between attacked assets between different partitions of the third layer, the connection between the two partitions in the third layer will be marked with a line of a special color, such as red.
[0070] The above methods can highlight devices that have been attacked by cyberattacks, making them easier to identify and analyze the impact of subsequent cyberattacks.
[0071] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0072] Upon receiving the first external instruction, display the affected devices within the area.
[0073] Specifically, impact analysis and visualization in multi-layered network topologies will be automatically generated, and when an asset is attacked, its security zone and asset can be marked with special colors.
[0074] Furthermore, if assets in the OT network are subjected to multiple types of attacks, the attack types will be listed in a small area at the corner of the multi-layered OT network topology. If a user clicks on one type of attack, the system will display an icon at the top of the corresponding area showing the number of attacked assets in each area. If a user clicks on the icon for the number of affected assets in an area, the system will display all affected areas and attacked assets in that area by attack type. Users can also click on the button labeled "All" to display all affected areas and attacked assets in the OT network topology by attack type. Users can then click on the icon of an attacked asset to gain further insights into the asset and the details of the attack.
[0075] Using the above method, the total number of attacked assets in a region can be displayed in a special area at the top of the region in a multi-layer network topology, which facilitates operators to perform in-depth analysis of all attacked assets.
[0076] Furthermore, based on the attack information, the affected devices displayed in the multi-layer network topology include:
[0077] Receive a second external instruction to display the attack event and the device information.
[0078] At the top layer of the multi-layered OT network topology, the number of attacked assets and the number of affected areas in each region will be displayed in an icon area at the top of the corresponding region. If a user clicks the icon for the number of affected assets in a region, the system will display all affected areas and attacked assets in that region. Users can also click the button labeled "All" to display all affected areas and attacked assets in the OT network topology. Users can then click the icon for attacked assets to access further details about that asset and the attack event. Additionally, clicking on a specific attack type will display all affected areas and assets.
[0079] The above methods can help operators understand attack events and the attributes and information of attacked devices, making it easier to analyze the impact of network attacks on devices.
[0080] The attack impact analysis method disclosed in this application, which employs multi-layer visualization of network topology for security monitoring of large-scale OT networks, can perform attack impact analysis when assets in the OT network are under attack, and has the following advantages:
[0081] (1) This method can automatically perform attack impact analysis when an asset is attacked, and find all assets and areas affected by the same attack, thereby helping operators in the OT network to efficiently find all assets affected by the same security event.
[0082] (2) This method can mark all affected assets and areas in a multi-layer OT network topology with special colors, and display the total number of attacked assets in a special area at the top of the area in the multi-layer network topology, which facilitates operators to perform in-depth analysis of all attacked assets.
[0083] (3) This method can mark attacks and special protocol communications, such as marking the industrial control protocols used by the attack with lines of special colors, which can help operators conduct in-depth analysis of critical assets that are attacked by industrial control protocols.
[0084] (4) This method can display all attacks in a list, allowing operators to view the number of assets and areas affected by a certain attack and to conduct further analysis based on the attack type, thereby improving the efficiency of analyzing large-scale OT network security incidents.
[0085] The following methods can be followed during the testing process:
[0086] (1) First, examine the static code and component structure. If the product also has runtime environment and encapsulation unit skills, such as functional blocks, then reusing the underlying code for attack impact layer visualization and attack correlation analysis should also be an issue. If a similar extension point mechanism is used to generate template code and implement it, then the method disclosed in this application may be applicable.
[0087] (2) The runtime mechanism will be checked next. If the runtime resolution of the extension point provider and the extension point implementation is similar, for example, the dependencies will be checked first, and then the parameters will be transmitted from the attack impact layer visualization and attack correlation analysis of the extension point implementation to the extension point provider.
[0088] (3) Finally, compare the similarities and differences of the solutions in detail to confirm whether they should be used.
[0089] Throughout the specification, references to "an implementation," "implementation," "exemplary implementation," "some implementations," "various implementations," etc., indicate that the implementation of the invention described may include specific features, structures, or characteristics. However, it is not implied that every implementation must include these specific features, structures, or characteristics. Furthermore, some implementations may have some, all, or none of the features described for other implementations.
[0090] It should be understood that although the steps in the flowchart of Figure 1 are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in Figure 1 may include multiple steps or multiple stages, which are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps.
[0091] Figure 2 provides an apparatus 200 for displaying network attacks through network topology. The apparatus 200 includes:
[0092] Information collection module 201 is used to collect device information in network security monitoring;
[0093] The network generation module 202 is used to generate a multi-layer network topology based on the device information;
[0094] The network display module 203 is used to receive the attack information of the device and display the affected device in the multi-layer network topology according to the attack information.
[0095] Figure 4 illustrates an embodiment of the hardware structure of this application. The figure includes a Central OT Security Monitoring Server, a Security Monitoring Sensor, an agent, and OT devices. OT devices are the devices or assets to be monitored. The agent acquires connection data, security configurations, logs, and behaviors of the OT devices and transmits this information to the Central OT Security Monitoring Server via the Security Monitoring Sensor. The Central OT Security Monitoring Server collects asset and communication information from OT devices and the network, automatically generating a multi-layered network topology on a single page. The Central OT Security Monitoring Server monitors the security status of OT devices and the network. When the Central OT Security Monitoring Server detects an attack on an OT device, for example, if the agent reports abnormal behavior or attack signals from the OT device, the Central OT Security Monitoring Server checks all assets associated with the attacked asset, analyzes the network attack and its impact on the devices, and highlights the affected devices, areas, and attack events in the network topology. It can then receive external commands to further display detailed information such as the number of devices, the number of areas, and the type of attack event. The above method can display all devices and network attacks in a list, allowing operators to view the number of assets and areas affected by a certain type of attack and conduct further analysis based on the attack type, thereby improving the efficiency of analyzing large-scale OT network security incidents.
[0096] It should be noted that the device may contain more or fewer modules to implement the described functions. For example, at least one module in FIG2 may be further divided into a plurality of different sub-modules, each sub-module being used to perform at least a portion of the operations described herein in conjunction with the corresponding module. Furthermore, in some examples, device 200 may also include additional modules for performing other operations already described in the specification. Moreover, those skilled in the art will understand that the exemplary device 200 may be implemented using software, hardware, firmware, or any combination thereof.
[0097] Figure 3 provides a computer device. According to one embodiment, the computer device 300 may include a processor 302 that executes a computer program stored in a memory 304. When executed by the processor, the computer program implements the method described above.
[0098] Those skilled in the art will understand that the structure shown in Figure 3 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0099] Those skilled in the art will understand that all or part of the processes in the methods described above can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0100] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the above steps.
[0101] This application also provides a computer program product tangibly stored on a computer-readable medium and including computer-executable instructions that, when executed, cause at least one processor to perform the methods described above.
[0102] Furthermore, the computer program can be stored and run in the cloud to execute the method. Furthermore, the components of the program can be deployed on multiple devices or in the cloud; for example, corresponding steps can be deployed and run on a local computer, or run on different cloud devices, transmitting signals via communication connections, or they can also be deployed and run on a local computer. This application does not limit the described approach or method; corresponding technologies can be flexibly deployed and fully utilized to execute and complete the method using cloud computing, big data, supercomputing capabilities, and other equipment and technologies.
[0103] Some implementations of this disclosure may include an article of writing. The article of writing may include a storage medium for storing logic. Examples of storage media may include one or more types of computer-readable storage media capable of storing electronic data, including volatile or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, and so on. Examples of logic may include various software units, such as software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computational code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. In some implementations, for example, the article of writing may store executable computer program instructions that, when executed by a processor, cause the processor to perform the methods and / or operations described herein. Executable computer program instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, and so on. Executable computer program instructions can be implemented according to a predefined computer language, method, or syntax used to command the computer to perform specific functions. These instructions can be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.
[0104] The examples described above include those of the disclosed architecture. It is certainly impossible to describe every conceivable combination of components and / or methods, but those skilled in the art will understand that many other combinations and arrangements are also possible. Therefore, this novel architecture is intended to cover all such alternatives, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. A method for displaying network attacks through network topology, wherein, include: Collect device information for network security monitoring; Based on the device information, a multi-layer network topology is generated; Receive attack information on the device, and display the affected device in the multi-layer network topology based on the attack information.
2. The method according to claim 1, wherein, Based on the device information, a multi-layer network topology is generated, including: Based on the regional division and quantity threshold, a multi-layer network topology is generated.
3. The method according to claim 1, wherein, After receiving the attack information of the device, the process also includes: Analyze other affected devices based on the control commands or communication protocols of the device.
4. The method according to claim 1, wherein, Based on the attack information, the affected devices are displayed in the multi-layer network topology, including: In the multi-layer network topology, the affected devices are color-coded.
5. The method according to claim 1, wherein, Based on the attack information, the affected devices are displayed in the multi-layer network topology, including: Upon receiving a first external instruction, the affected devices within the area are displayed.
6. The method according to claim 1, wherein, Based on the attack information, the affected devices are displayed in the multi-layer network topology, including: Receive a second external instruction to display information about the attack event and the affected devices.
7. An apparatus (200) for displaying network attacks through network topology, wherein, include: The information collection module (201) is used to collect device information in network security monitoring; The network generation module (202) is used to generate a multi-layer network topology based on the device information; The network display module (203) is used to receive the attack information of the device and display the affected device in the multi-layer network topology according to the attack information.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein... When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product tangibly stored on a computer-readable medium and comprising computer-executable instructions that, when executed, cause at least one processor to perform the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Method for video monitoring system to implement Topo map of network devices on web
CN101094392A
A network topological structure exhibition method and device
CN101217410A
Internet-of-things attack event tracking method and device, and computer equipment
CN111885034A
Network attack link visualization analysis method and system based on attack graph
CN115766286A
Analysis system, method, and program
US20220191220A1