Security hardening method, apparatus and system, electronic device, storage medium, and product

By determining the security hardening cycle based on the historical status of OT devices and performing hardening processing when the real-time status allows, the problem of low efficiency in the security hardening processing of OT systems in the prior art is solved, and more efficient and secure hardening processing is achieved.

WO2026011442A1PCT designated stage Publication Date: 2026-01-15SIEMENS AG +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/105317
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In existing technologies, security hardening of OT systems needs to be performed during maintenance or non-production periods, which exposes equipment to attack risks for extended periods and is inefficient.

Method used

By analyzing the historical performance, network, and security status of OT devices, a suitable security hardening cycle is determined. Hardening is initiated when the real-time status meets the conditions. The execution duration of the hardening package is simulated using a virtual environment, and an appropriate cycle is selected for hardening. Breakpoints are recorded for subsequent recovery.

Benefits of technology

It improves the efficiency of security hardening processes and the security of equipment, reduces the time equipment is exposed to attacks, and enhances the security and flexibility of OT systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024105317_15012026_PF_FP_ABST
    Figure CN2024105317_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in implementations of the present invention are a security hardening method, apparatus and system, an electronic device, a storage medium, and a product. The method comprises: acquiring a security hardening cycle corresponding to an operational technology (OT) device, wherein the security hardening cycle is determined on the basis of a historical performance state, a historical network state, a historical security state, and a historical control command state of the OT device within a historical time period; determining a real-time performance state, a real-time network state, a real-time security state, and a real-time control command state of the OT device in the current round of the security hardening cycle; and when the real-time performance state meets a predetermined first condition, the real-time network state meets a predetermined second condition, the real-time security state meets a predetermined third condition, and the real-time control command state meets a predetermined fourth condition, starting, in the current round of the security hardening cycle, the OT device to execute security hardening processing. The security of the OT device is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Security hardening methods, devices, systems, electronic devices, storage media and products Technical Field

[0001] This invention relates to the field of network security technology, and in particular to methods, apparatus, systems, electronic devices, storage media and products for security hardening. Background Technology

[0002] Operational Technology (OT) systems are configured to automate industrial processes. An OT system can be a wind power system, an automobile manufacturing plant, a pharmaceutical factory, or a city's wastewater treatment system. Traditional OT systems employ a closed design, making them difficult to threaten through cyberattacks. However, with the development of automated manufacturing and process control technologies, OT systems widely adopt Information Technology (IT) and are no longer closed systems. Consequently, the security threats faced by OT systems are becoming increasingly serious. The need to protect OT systems from security attacks has become urgent. For example, the networks of a joint venture or subsidiary of an industrial enterprise, or even a service outsourcing company, may be connected to the industrial enterprise's OT system, thus posing a risk of cyberattacks.

[0003] OT operators need to identify vulnerabilities in OT systems and harden the target devices to improve their security status. Typically, OT operators first transmit security hardening packages (such as security hardening scripts or security hardening patches) to the target devices, and then run the security hardening packages on the target devices to complete the security hardening.

[0004] Currently, security hardening of OT devices is typically performed during maintenance or non-production periods. This means that a long wait is required before security hardening packages can be implemented on OT devices, during which time the OT devices may be exposed to various attacks.

[0005] Summary of the Invention

[0006] The present invention provides methods, apparatus, systems, electronic devices, storage media, and products for security hardening.

[0007] A security reinforcement method includes:

[0008] Obtain the security hardening cycle corresponding to the OT device. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status and historical control command status of the OT device within a historical time period. The security hardening cycle is a time period suitable for performing security hardening processing on the OT device.

[0009] Determine the real-time performance status, real-time network status, real-time security status, and real-time control command status of the OT device in the current round of the security hardening cycle;

[0010] When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition, the OT device is initiated to perform security hardening processing in the current round of the security hardening cycle.

[0011] It is evident that eliminating the need to perform safety hardening procedures during maintenance or non-production periods improves the efficiency of safety hardening procedures and enhances the safety of OT equipment.

[0012] In one implementation, obtaining the security hardening cycle corresponding to the OT device includes:

[0013] Using the identifier of the OT device as the search term, the database is used to query the search results corresponding to the search term. The database stores the association between the identifiers of multiple OT devices and their corresponding security hardening cycles.

[0014] Therefore, the security hardening cycle of OT equipment can be quickly determined by querying the database using identifiers.

[0015] In one implementation, it includes:

[0016] When performing the security hardening process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, the real-time security status no longer meets the third condition, or the real-time control command status no longer meets the fourth condition, the security hardening process is stopped and the breakpoint of the security hardening process is recorded.

[0017] As can be seen, when the conditions are no longer met, the security hardening process is stopped, thus not affecting the current normal operation of the OT equipment. Moreover, by recording the breakpoint of the security hardening process, it is convenient to continue the security hardening process from the breakpoint in the future, thereby improving the execution efficiency of the security hardening process.

[0018] In one implementation, it includes:

[0019] After the security hardening process is stopped, when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, the real-time security status recovers to meet the third condition, and the real-time control command status recovers to meet the fourth condition during the security hardening period, the security hardening process resumes from the breakpoint.

[0020] As can be seen, when the conditions are met again, the security hardening process resumes from the breakpoint, which improves the execution efficiency of the security hardening process.

[0021] In one implementation, it includes:

[0022] Acquire the security logs and / or suspicious objects of the OT device during the historical time period, host performance data and / or performance data of the predetermined process during the historical time period, host network status data and / or network status data of the predetermined process during the historical time period, and network traffic during the historical time period.

[0023] The security logs and / or the suspicious objects are first parsed to determine the historical security status within the historical time period.

[0024] A second parsing is performed on the host performance data and / or the performance data of the predetermined process to determine the historical performance status within the historical time period.

[0025] A third parsing is performed on the network status data of the host and / or the network status data of the predetermined process to determine the historical network status within the historical time period.

[0026] The network traffic is parsed a fourth time to determine the status of historical control commands within the historical time period;

[0027] From the historical time period, determine the common time period in which the historical security status, the historical network status, the historical performance status, and the historical control command status all meet their respective constraints;

[0028] The safety reinforcement cycle is determined based on the common time period.

[0029] Therefore, the embodiments of the present invention fully consider the determinism and periodicity of OT equipment and realize a method for determining the security hardening cycle based on historical data.

[0030] In one implementation, the method includes:

[0031] In the current round of the transmission time period, a security hardening package is sent to the OT device so that the OT device can perform the security hardening process based on the security hardening package, wherein the transmission time period is determined based on the historical performance status, historical network status and historical security status, and the transmission time period is a time period suitable for sending the security hardening package to the OT device.

[0032] Therefore, there is no need to send security hardening packages during maintenance or non-production periods, which improves the efficiency of security hardening package delivery and enhances the security of OT equipment.

[0033] In one embodiment, there are multiple security hardening cycles and multiple security hardening packages, and the method includes:

[0034] In the virtual environment of the OT device, each security hardening package is simulated and executed to determine the execution duration of each security hardening package;

[0035] The process of obtaining the security hardening cycle corresponding to the OT device includes:

[0036] From multiple security hardening cycles, identify the security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages.

[0037] Therefore, the execution time of each security hardening package in the OT device is first simulated, and then the security hardening cycle with a duration greater than or equal to the sum of the execution times of all security hardening packages is determined, thereby ensuring that the selected security hardening cycle has sufficient duration to execute all security hardening packages.

[0038] In one implementation, the method includes:

[0039] When performing the security hardening process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, the real-time security status no longer meets the third condition, or the real-time control command status no longer meets the fourth condition, the security hardening process is stopped and the executed security hardening package is recorded.

[0040] Determine the remaining security hardening packages after removing the executed ones from the total security hardening packages;

[0041] From the plurality of security hardening cycles, determine the security hardening cycle whose duration is greater than or equal to the total execution time of the remaining security hardening packages.

[0042] Therefore, when security hardening packages cannot be executed continuously, updating the total execution time of the remaining security hardening packages in a timely manner can filter out more security hardening cycles to choose from, thus improving flexibility.

[0043] A security reinforcement device, comprising:

[0044] The acquisition module is used to acquire the security hardening period corresponding to the OT device. The security hardening period is determined based on the historical performance status, historical network status, historical security status and historical control command status of the OT device within a historical time period. The security hardening period is a time period suitable for performing security hardening processing on the OT device.

[0045] The determination module is used to obtain the real-time performance status, real-time network status, real-time security status, and real-time control command status of the OT device in the current round of the security hardening cycle;

[0046] The startup module is used to start the OT device to perform security hardening processing in the current round of the security hardening cycle when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition.

[0047] It is evident that eliminating the need to perform safety hardening procedures during maintenance or non-production periods improves the efficiency of safety hardening procedures and enhances the safety of OT equipment.

[0048] In one implementation, it includes:

[0049] The sending module is configured to send a security hardening package to the OT device in the current round of the sending time period, so that the OT device can perform the security hardening process based on the security hardening package, wherein the sending time period is determined based on the historical performance status, historical network status and historical security status, and the sending time period is a time period suitable for sending the security hardening package to the operating technology device.

[0050] Therefore, there is no need to send security hardening packages during maintenance or non-production periods, which improves the efficiency of security hardening package delivery and enhances the security of OT equipment.

[0051] In one implementation, there are multiple security reinforcement cycles and multiple security reinforcement packages;

[0052] The acquisition module is used to simulate the execution of each security hardening package in the virtual environment of the OT device to determine the execution duration of each security hardening package; and to determine the security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages from multiple security hardening cycles.

[0053] Therefore, the execution time of each security hardening package in the OT device is first simulated, and then the security hardening cycle with a duration greater than or equal to the sum of the execution times of all security hardening packages is determined, thereby ensuring that the selected security hardening cycle has sufficient duration to execute all security hardening packages.

[0054] A security hardening system, comprising:

[0055] N data collection agents are deployed in N OT devices. Each of the N data collection agents is used to collect real-time performance data, real-time network status data, real-time traffic, real-time security logs, and / or real-time suspicious objects of the corresponding OT device in the current round of its respective security hardening cycle. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status, and historical control command status of the corresponding OT device within a historical time period. The security hardening cycle is a time period suitable for performing security hardening processing in the corresponding OT device.

[0056] A monitoring server is used to determine the real-time security status based on the real-time security logs and / or real-time suspicious objects, the real-time performance status based on the real-time performance data, the real-time network status based on the real-time network status data, and the real-time control command status based on the real-time traffic. When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition, the corresponding OT device is activated to perform security hardening processing in the current round of the security hardening cycle.

[0057] In one embodiment, it includes: a security reinforcement packet sending server, configured to send a security reinforcement packet to the corresponding OT device in the current round of a sending time period, so that the corresponding OT device performs the security reinforcement process based on the security reinforcement packet, wherein the sending time period is determined based on the historical performance status, historical network status and historical security status, and the sending time period is a time period suitable for sending the security reinforcement packet to the corresponding OT device.

[0058] In one embodiment, it includes: a monitoring device for aggregating real-time performance data, real-time network status data, real-time traffic, real-time security logs, and / or real-time suspicious objects from the N OT devices, and sending the aggregation results to the monitoring server.

[0059] An electronic device, comprising:

[0060] processor;

[0061] Memory for storing the executable instructions of the processor;

[0062] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement any of the security hardening methods described above.

[0063] A computer-readable storage medium having computer instructions stored thereon, which, when executed by a processor, implement the security hardening method described above.

[0064] A computer program product includes a computer program that, when executed by a processor, implements the security hardening method described above. Attached Figure Description

[0065] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which will make the above and other features and advantages of the present invention more apparent to those skilled in the art. In the drawings:

[0066] Figure 1 is an exemplary flowchart of a security reinforcement method according to an embodiment of the present invention.

[0067] Figure 2 is an exemplary schematic diagram of determining the safety reinforcement cycle according to an embodiment of the present invention.

[0068] Figure 3 is an exemplary structural diagram of a security reinforcement system according to an embodiment of the present invention.

[0069] Figure 4 is an exemplary schematic diagram of the security reinforcement process according to an embodiment of the present invention.

[0070] Figure 5 is an exemplary structural diagram of a security reinforcement device according to an embodiment of the present invention.

[0071] Figure 6 is a structural diagram of an electronic device according to an embodiment of the present invention.

[0072] The accompanying figure is labeled as follows: Detailed Implementation

[0073] To make the objectives, technical solutions, and advantages of the present invention clearer, the following embodiments are provided to further illustrate the present invention in detail.

[0074] For the sake of brevity and intuitiveness, the following description uses several representative embodiments to illustrate the solution of the present invention. Numerous details in the embodiments are only used to aid in understanding the solution of the present invention. However, it is obvious that the technical solution of the present invention can be implemented without being limited to these details. To avoid unnecessarily obscuring the solution of the present invention, some embodiments are not described in detail, but only a framework is given. In the following text, "comprising" means "including but not limited to," and "according to..." means "at least according to..., but not limited to only according to...". Due to Chinese language habits, unless the quantity of a component is specifically indicated below, it means that the component can be one or more, or can be understood as at least one.

[0075] There are many fundamental differences between IT systems and OT systems. For example, these differences include at least: (1) OT systems typically need to control physical processes in critical environments and have strong requirements for process security and protection; (2) OT systems have a lifespan of 15 to 20 years; (3) OT systems require high availability, integrity, and confidentiality; (4) OT systems have highly deterministic systems and networks; (5) OT systems typically have real-time applications with responses closely related to time, and high latency and / or jitter are unacceptable; (6) Data in OT systems typically uses simple data types, has high data rates, and requires real-time analysis; (7) Networks in OT systems typically consist of human-machine interfaces (HMIs), sensors, input / output interfaces (IO), dedicated controllers (e.g., PLCs, RTUs), coded displays, and touchscreens; (8) It is difficult to schedule patch restarts in OT systems, and patch restarts have negative impacts, etc.

[0076] Crucially, compared to IT systems (primarily human-to-human communication), OT systems (primarily machine-to-machine communication) exhibit a high degree of determinism and periodicity.

[0077] In response to the aforementioned significant characteristics of OT systems, this invention employs predefined statistical or correlation analysis methods from historical monitoring data of OT devices to determine suitable time periods for performing security hardening processes on the OT devices. Then, in the current cycle of the time period, security hardening processes are performed on the OT devices based on continuous monitoring of their real-time status. If the monitoring identifies an unsuitable state for the OT device (e.g., high network load, busy OT device, OT device executing critical control commands, or OT device under attack, etc.), the security hardening process is paused until the state becomes appropriate and secure again, at which point it is restarted. Since security hardening processes do not need to be performed during fixed maintenance or non-production periods, the efficiency of security hardening processes is improved, and the security of OT devices is enhanced.

[0078] Figure 1 is an exemplary flowchart of a security reinforcement method according to an embodiment of the present invention. As shown in Figure 1, the method includes:

[0079] Step 101: Obtain the security hardening period corresponding to the OT device. The security hardening period is determined based on the historical performance status, historical network status, historical security status and historical control command status of the OT device within a historical time period. The security hardening period is a time period suitable for performing security hardening processing on the OT device.

[0080] Here, OT (Operational Technology) devices include technical equipment used in industrial environments to monitor and control production processes, electromechanical equipment, and tooling. These devices are typically directly related to the actual operation of industrial production lines, responsible for tasks such as real-time data acquisition, processing, and equipment control. OT devices have a wide range of applications, including but not limited to industrial sensors, actuators, programmable logic controllers (PLCs), and host computers, etc.

[0081] Preferably, the OT device is specifically implemented as a host computer. A host computer is a computer that can directly issue control commands; it generally refers to the main computer or host computer in an industrial control system, used to monitor various equipment and systems in the industrial production process. These host computers typically display various signal changes on their screens, such as hydraulic pressure, water level, and temperature, thereby achieving real-time monitoring and control of the industrial process.

[0082] The security hardening process typically includes: decompressing the security hardening package already saved in the OT device to obtain the security hardening files, and then executing the security hardening files. The security hardening files in the security hardening package may include security hardening scripts and / or security hardening patches. Specifically: a security hardening script is a set of instructions or command language used for automated operation to perform security hardening tasks on the OT device; a security hardening patch is a program that fixes code defects or vulnerabilities and can be used to correct security vulnerabilities in the OT device. There may be one or more security hardening packages. In one implementation, multiple security hardening scripts and / or multiple security hardening patches can be packaged into a single package, and then this single package can be divided into multiple security hardening packages to be transmitted, thereby facilitating subsequent breakpoint resumption processing.

[0083] In one implementation, the method shown in Figure 1 includes a process for pre-determining the security hardening cycle for each OT device. This process includes:

[0084] (1) Obtain security logs and / or suspicious objects of OT devices within a historical time period, host performance data and / or scheduled process performance data within a historical time period, network traffic within a historical time period, and host network status data and / or scheduled process network status data within a historical time period. For example, suspicious objects can be any object that may contain malicious programs or malicious code. For example, suspicious objects may include: suspicious files, suspicious process names, suspicious execution behaviors, suspicious file contents, suspicious network behaviors, etc.

[0085] (2) Perform a first analysis on security logs and / or suspicious objects to determine the historical security status within a historical time period; perform a second analysis on host performance data and / or scheduled process performance data to determine the historical performance status within a historical time period; perform a third analysis on host network status data and / or scheduled process network status data to determine the historical network status within a historical time period; and perform a fourth analysis on network traffic to determine the historical control command status within a historical time period.

[0086] (3) From the historical time period, determine the common time period in which the historical security state, historical network state, historical performance state and historical control command state all meet their respective constraints.

[0087] (4) Determine the sending time period based on a common time period. For example, the sending time period can be a certain time period within a day, a week, or a month, etc.

[0088] Specifically, the historical time period can be a relatively long period (e.g., a week, a month, a quarter, or a whole year, etc.) to ensure the accuracy of the transmission time cycle. Preferably, the historical time period spans multiple transmission time cycles and is close to the current time. More preferably, the historical time period is adjustable.

[0089] Let's take the most recent week as an example to illustrate.

[0090] First, obtain the security logs and / or suspicious objects of the OT device for the past week. Then, analyze the security logs and / or suspicious objects for the past week to determine the security status of the OT device. For example, the security status may specifically include: the time of identified attack within the week (e.g., the specific date and hour), the dates of potential attack within the week, the dates of identified no attack within the week, and so on.

[0091] Next, acquire the host performance data and / or scheduled process performance data of the OT device over the past week. For example, host performance data may include: the overall CPU utilization of the OT device (i.e., the host), the overall RAM utilization of the OT device, the overall disk utilization of the OT device, the overall GPU utilization of the OT device, etc. Scheduled processes can be critical processes determined by user commands. For example, scheduled processes may include WinCC, Step7, PCS7, etc. Scheduled process performance data may include: the CPU utilization of the scheduled process, the RAM utilization of the scheduled process, the disk utilization of the scheduled process, the GPU utilization of the scheduled process, etc. Analyze the host performance data and / or scheduled process performance data of the OT device over the past week to determine the performance status of the OT device over the past week. Performance status may specifically include: the time during which the host and scheduled processes were not busy (e.g., specific dates and hours within those dates), the time during which both the host and scheduled processes were busy, the time during which the host was not busy and all scheduled processes were busy, the time during which the host was busy and all scheduled processes were not busy, etc.

[0092] Next, obtain the host network status data and / or scheduled process network status data of the OT device for the most recent week. For example, host network status data may include: the available network bandwidth of the OT device as a whole (i.e., the host) and the network interface utilization rate of the OT device as a whole, etc. Scheduled process network status data may include: the available network bandwidth of the scheduled process and the network interface utilization rate of the scheduled process, etc. Parse the host network status data and / or scheduled process network status data of the OT device for the most recent week to determine the network status of the OT device for the most recent week. Network status may specifically include: times within the week when network utilization of the host and scheduled processes is not prominent (e.g., specific dates and specific hours within those dates); times within the week when network utilization of both the host and scheduled processes is prominent; times within the week when host network utilization is not prominent but scheduled process network utilization is prominent; times within the week when host network utilization is prominent but scheduled process network utilization is not prominent, etc.

[0093] Additionally, obtain the network traffic of the OT device over the past week. For example, obtain mirrored network traffic (including inbound and outbound directions) flowing through the switch over the past week via the monitoring port on the switch connected to the OT device. The specific protocols for the OT device's network traffic can include transport protocols and communication protocols. For example, transport protocols can include: Representational State Transfer Protocol (REST) / Hypertext Transfer Protocol, Constrained Application Protocol (CoAP), Message Queuing Telemetry Transport (MQTT), Data Distribution Service for Real-Time Systems (DDS), Advanced Message Queuing Protocol (AMQP), Extensible Messaging and Presence Protocol (XMPP), Java Message Service (JMS), and so on. For example, communication protocols can be implemented as Industrial Ethernet (PROFINET), Modbus, BACNet, RS-232, HART, MPI, and RS-485, etc. Then, based on network traffic analysis, the historical control command status for the most recent week is determined. The historical control command status can be determined based on whether the network traffic contains predetermined critical control commands (e.g., critical operations such as obtaining device status, changing parameters, starting or stopping the device). The historical control command status can specifically include: the times within the week when critical control commands needed to be executed (e.g., specific dates and hours) and the times within the week when critical control commands did not need to be executed. For example, based on traffic analysis, if a time period is found to contain no control commands or contain non-critical control commands (e.g., transmitting system status information), then that time period is determined to be a time period where critical control commands do not need to be executed. If a time period is found to contain critical control commands (e.g., uploading measurement data), then that time period is determined to be a time period where critical control commands need to be executed.

[0094] Furthermore, from the past week, a common time period was identified where historical security status, historical network status, historical performance status, and historical control command status all met their respective constraints. For example, suppose the constraints for historical security status are: neither the host nor the scheduled processes are busy; the constraints for historical network status are: neither the host nor the scheduled processes have significant network usage; the constraints for historical security status are: no attacks are detected; and the constraints for historical control command status are: a time period where critical control commands do not need to be executed. Assuming the identified common time period is Monday from 3 PM to 5 PM, then the suitable time period for performing security hardening on OT equipment is determined to be every Monday from 3 PM to 5 PM. It can be seen that this security hardening cycle can have multiple rounds (i.e., multiple Mondays from 3 PM to 5 PM), and the current round is the Monday from 3 PM to 5 PM closest to the current time.

[0095] The above exemplary descriptions of historical time periods and typical examples of constraints will be appreciated by those skilled in the art. Such descriptions are merely exemplary and are not intended to limit the scope of protection of the embodiments of the present invention.

[0096] Similarly, the security hardening cycle for each OT device can be determined, and the association between the individual identifier of the OT device and the corresponding security hardening cycle can be stored in the database.

[0097] In one implementation, step 101 includes: using the identifier of the OT device as the search term, querying the database for the search results corresponding to the search term, wherein the database stores the association between the identifiers of multiple OT devices and their corresponding security hardening cycles.

[0098] For example, the following relationships are stored in the database: (1) OT device 1, identified as aaa, has a security hardening cycle of Monday; (2) OT device 2, identified as bbb, has a security hardening cycle of Wednesday; (3) OT device 3, identified as ccc, has a security hardening cycle of Thursday to Friday; (4) OT device 4, identified as ddd, has a security hardening cycle of 3 PM to 4 PM on Tuesday. When you want to get the security hardening cycle of OT device 1, you can query the database with "aaa" as the search term. If the search result is "Monday", then the security hardening cycle of OT device 1 is Monday.

[0099] Step 102: Determine the real-time performance status, real-time network status, real-time security status, and real-time control command status of the OT device in the current round of the security hardening cycle.

[0100] Here, for example, assuming the transmission time period is Monday, and the current time is Monday (i.e., in the current round of the security hardening cycle), the real-time performance status, real-time network status, real-time security status, and real-time control command status of the OT device in the current round of the security hardening cycle are obtained.

[0101] Step 103: When the real-time performance status meets the predetermined first condition, the real-time network status meets the predetermined second condition, the real-time security status meets the predetermined third condition, and the real-time control command status meets the predetermined fourth condition, the OT device is started to perform security hardening processing in the current round of the security hardening cycle.

[0102] In one implementation: the first condition is equivalent to the historical performance state constraint used when determining the security hardening cycle; the second condition is equivalent to the historical network state constraint used when determining the security hardening cycle; the third condition is equivalent to the historical security state constraint used when determining the security hardening cycle; and the fourth condition is equivalent to the control command state constraint used when determining the security hardening cycle. Optionally, the first, second, third, and fourth conditions may differ from their respective constraints used when determining the security hardening cycle. Preferably, the first, second, third, and fourth conditions are more stringent than their respective constraints to ensure the accuracy of the security hardening cycle. For example, suppose the historical network state constraint is: network usage of the host or the predetermined process is not prominent; the second condition could be: network usage of both the host and the predetermined process is not prominent. Therefore, when the real-time performance state indicates that network usage of both the host and the predetermined process is not prominent, the real-time performance state meets the second condition.

[0103] During the security hardening process of OT devices, the performance status, network status, security status and network traffic of the OT devices are continuously collected. Therefore, the real-time performance status, real-time network status, real-time security status and real-time control command status of the OT devices may change.

[0104] In one implementation, the method includes: during transmission, when the real-time performance state no longer meets a first condition, the real-time network state no longer meets a second condition, the real-time security state no longer meets a third condition, or the real-time control command state no longer meets a fourth condition, stopping the security hardening process and recording the breakpoint of the security hardening process. It is evident that stopping the security hardening process when the conditions are no longer met does not affect the current normal operation of the OT device. Furthermore, recording the breakpoint of the security hardening process facilitates subsequent continuation of the security hardening process from the breakpoint, improving the execution efficiency of the security hardening process.

[0105] In one implementation, the process includes: after stopping the security hardening process, resuming the security hardening process from the breakpoint when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, the real-time security status recovers to meet the third condition, and the real-time control command status recovers to meet the fourth condition within the security hardening cycle. Therefore, when the conditions are met again, the security hardening process resumes from the breakpoint, eliminating the need to start the process from scratch and improving execution efficiency.

[0106] In one implementation, the method includes: sending a security hardening package to an OT device in the current round of a transmission time period, so that the OT device performs security hardening processing based on the security hardening package during the security hardening period, wherein the transmission time period is determined based on historical performance status, historical network status, and historical security status, and is a suitable time period for sending the security hardening package to the operating technology device. For example, from historical time periods, a common time period in which historical security status, historical network status, and historical performance status all meet their respective constraints is determined as the transmission time period.

[0107] In one implementation, there are multiple security hardening cycles and multiple security hardening packages. The method includes: simulating the execution of each security hardening package in a virtual environment of the OT device to determine the execution duration of each security hardening package; step 101 includes: determining from the multiple security hardening cycles a security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages.

[0108] For example: Assume there are M security hardening packages to be executed on an OT device. In a virtual environment simulating various resources of the OT device, determine the execution time of each of these M security hardening packages, denoted as T1, T2...T. M Calculate the total execution time Ta of these M security hardening packages, where Ta = T1 + T2 + ... + T M Then, from all available security hardening cycles for the OT device, determine the security hardening cycle with a duration greater than or equal to Ta, and select it as the security hardening cycle.

[0109] In one implementation, the method includes: when performing security hardening processing, stopping the execution of security hardening processing and recording the executed security hardening packages when the real-time performance state no longer meets a first condition, the real-time network state no longer meets a second condition, the real-time security state no longer meets a third condition, or the real-time control command state no longer meets a fourth condition; determining the remaining security hardening packages after removing the executed security hardening packages from all security hardening packages; and determining, from multiple security hardening cycles, a security hardening cycle whose duration is greater than or equal to the total execution time of the remaining security hardening packages.

[0110] For example: Assume that the number of security hardening packages to be executed on the OT equipment is M, namely P1, P2, P3, P4, P5...P M。 In the virtual environment of the OT device, these M security hardening packages (P1, P2, P3, P4, P5...P...) are identified. M The execution times for each of the following are T1, T2, T3, T4, T5...T M Calculate the total execution time Ta of these M security hardening packages, where Ta = T1 + T2 + T3 + T4 + T5 + ... + T M Next, from all available security hardening cycles for the OT device, determine the one with a duration greater than or equal to Ta, and select it as the chosen security hardening cycle, assuming security hardening cycle a is selected. Then, within security hardening cycle a, initiate security hardening processing on the OT device. If it is found that the execution conditions are no longer met within security hardening cycle a, stop the security hardening process and record the executed security hardening packages. Assuming the executed security hardening packages are P1, P2, and P3, calculate the remaining unexecuted security hardening packages (i.e., P4, P5... P...). M The total execution time Tb, where Tb = T4 + T5 + ... + T M Then, from all available hardening cycles for the OT device, excluding hardening cycle a, determine the hardening cycle with a duration greater than or equal to Tb, and select it as the chosen hardening cycle. Assume hardening cycle c is selected. Then, within hardening cycle c, the OT device continues to perform hardening processing, i.e., continues to execute hardening packages P4, P5…P… M .

[0111] Figure 2 is an exemplary schematic diagram of determining the transmission security hardening cycle according to an embodiment of the present invention. In Figure 2, the following are obtained from the OT device during a historical time period: (1) historical security logs and / or historical suspicious objects 10; (2) historical performance data 11; (3) historical network status data 12; and (4) historical network traffic 80.

[0112] The historical security logs and / or historical suspicious objects 10 are parsed to obtain the historical security status 13. For example, the historical security status 13 may specifically include: the time when an attack was determined within the historical time period, the date on which an attack may have occurred within the historical time period, the date on which no attack was determined within the historical time period, and so on.

[0113] The historical performance data 11 is parsed to obtain the historical performance status 14. The parsing process may include comparing the historical performance data 11 with predetermined thresholds (which may be one or more) to determine busy and non-busy times, etc. Here, the thresholds may be specified by the user based on instructions, determined based on the maximum value of the performance data (e.g., using the product of the maximum value of the performance data and a predetermined percentage (e.g., 80%) as the threshold), or based on any transformed value of the predetermined value or the maximum value of the performance data.

[0114] The historical network state data 12 is parsed to obtain the historical performance state 15. The parsing process may include comparing the historical network state data 12 with predetermined thresholds (which may be one or more) to determine periods of high network occupancy and periods of low network occupancy, etc. Here, the thresholds may be specified by the user based on instructions, determined based on the maximum value of the network state data (e.g., using the product of the maximum value of the network state data (e.g., available bandwidth) and a predetermined percentage (e.g., 80%) as the threshold), or based on any transformed value of the predetermined value or the maximum value of the performance data.

[0115] Historical network traffic 80 is parsed to obtain the historical control command status 81 within a historical time period. The parsing process may include determining the historical control command status based on whether the historical network traffic 80 contains predetermined key control commands (e.g., key operations such as obtaining device status, changing parameters, starting the device, or stopping the device). The historical control command status may specifically include: the time within the historical time period when key control commands need to be executed (e.g., the specific date and hour within the date) and the time within the historical time period when key control commands do not need to be executed, etc. For example, key control commands may include: control commands for obtaining device status; control commands for changing parameters; control commands for starting the device; control commands for stopping the device, etc.

[0116] In process 16, which determines the transmission time period, a common time period 17 is identified where the historical security state, historical network state, historical performance state, and historical control command state all meet their respective constraints. For example, the constraints for the historical security state are: neither the host nor the scheduled process is busy; the constraints for the historical network state are: neither the host nor the scheduled process has significant network usage; the constraints for the historical security state are: no attacks are detected; and the constraints for the historical control command state are: a time period during which critical control commands do not need to be executed. Based on the common time period 17, the security hardening cycle for the OT device is determined. For example, assuming the determined common time period is: Monday 3 PM to 5 PM, then the suitable time period for performing security hardening processing on the OT device is determined to be: every Monday 3 PM to 5 PM.

[0117] This invention also proposes a security hardening system. Figure 3 is an exemplary structural diagram of the security hardening system according to an embodiment of the invention. As shown in Figure 3, the system includes:

[0118] N data collection agents 41, 42…4N are deployed across N OT devices 241, 242…24N. These N OT devices 241, 242…24N are connected to N routing devices 251, 252…25N. Each of the N data collection agents 41, 42…4N collects real-time performance data, real-time network status data, real-time traffic, real-time security logs, and / or real-time suspicious objects from the corresponding OT device in the current round of its respective security hardening cycle. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status, and historical control command status of the corresponding OT device over a historical period. The security hardening cycle is a time period suitable for performing security hardening processing on the corresponding OT device. Each of the N data collection agents 41, 42…4N sends the real-time performance data, real-time network status data, real-time network traffic, real-time security logs, and / or real-time suspicious objects from the current round to the monitoring server 20 via the routing devices connected to the corresponding OT devices.

[0119] The monitoring server 20 is used to determine the real-time security status of the corresponding OT device based on the real-time security logs and / or real-time suspicious objects sent by each acquisition agent, to determine the real-time performance status of the corresponding OT device based on the real-time performance data sent by each acquisition agent, to determine the real-time network status of the corresponding OT device based on the real-time network status data sent by each acquisition agent, and to determine the real-time control command status of the corresponding OT device based on the real-time traffic sent by each acquisition agent. When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition, the corresponding operational technical device is initiated to perform security hardening processing in the current round of the security hardening cycle of the corresponding operational technical device.

[0120] Preferably, the monitoring server 20 predetermines the transmission time period for each OT device based on its historical performance, network, and security status within a historical time period, and sends this transmission time period to the hardening packet sending server 21 and the corresponding OT device. Each OT device informs its own transmission time period to the collection agent contained within it, allowing the collection agent to time its transmission and collect real-time performance data, real-time network status data, real-time security logs, and / or real-time suspicious objects in the current round of the transmission time period. The monitoring server 20 further determines the real-time security status of the corresponding OT device in the current round of the transmission time period based on the real-time security logs and / or real-time suspicious objects sent by each collection agent; determines the real-time performance status of the corresponding OT device in the current round of the transmission time period based on the real-time performance data sent by each collection agent; and determines the real-time network status of the corresponding OT device in the current round of the transmission time period based on the real-time network status data sent by each collection agent. The hardening packet sending server 21 is used to initiate the process of sending a security hardening packet to the corresponding OT device when the real-time performance status of the corresponding OT device in the current round of the sending time period meets a predetermined fifth condition, the real-time network status of the corresponding OT device in the current round of the sending time period meets a predetermined sixth condition, and the real-time security status of the corresponding OT device in the current round of the sending time period meets a predetermined seventh condition. After receiving the security hardening packet, the corresponding OT device can perform security hardening processing in subsequent processes.

[0121] The system also includes: a monitoring device 23, used to aggregate the real-time performance status, real-time network status, real-time traffic, real-time security logs and / or real-time suspicious objects of N OT devices 41, 42...4N, and uniformly send the aggregated results to the monitoring server 20; M distribution devices 221...22M, where each distribution device corresponds to at least one OT device, where M is a positive integer of at least 1 and M is less than or equal to N; each of the M distribution devices 221...22M is used to receive the security hardening package of the corresponding at least one OT device from the hardening package sending server 21, and send the security hardening package of the corresponding at least one OT device to the corresponding at least one OT device.

[0122] Figure 4 is an exemplary schematic diagram of a security reinforcement process according to an embodiment of the present invention. As shown in Figure 4, the process includes:

[0123] First, the security hardening cycle 56 of the OT device is read from database 70. Then, the real-time security logs and / or real-time suspicious objects 50, real-time performance data 51, real-time network status data 52, and real-time network traffic 90 of the current round of the security hardening cycle 56 of the OT device are obtained. The real-time security logs and / or real-time suspicious objects 50 are parsed to determine the real-time security status 53 (e.g., whether the OT device is currently under attack), the real-time performance data 51 is parsed to determine the real-time performance status 54 (e.g., whether the OT device is currently experiencing high performance load), the real-time network status data 52 is parsed to determine the real-time network status 55 (e.g., whether the OT device's current network usage is high), and the real-time network traffic 90 is parsed to determine the real-time control command status 91 (e.g., whether the OT device is currently executing critical control commands).

[0124] In the first verification 57, it is determined whether the real-time security state 53, real-time performance state 54, real-time control command state 91, and real-time network state 55 all meet their respective conditions. For example, these conditions may include: real-time security state 53 indicating no attack currently; real-time performance state 54 indicating no current busy status; real-time network state 55 indicating no significant network usage; and real-time control command state 91 indicating no critical control commands are currently being executed. When all these conditions are met (corresponding to the "Y branch"), the OT device is initiated to perform security hardening processing 59; when not all these conditions are met (corresponding to the "N branch"), a waiting process 58 is executed, during which no security hardening processing is performed.

[0125] After initiating the security hardening process 59 on the OT device, further detect the following data that may change over time: (1) real-time security logs and / or real-time suspicious objects 50; (2) real-time performance data 51; (3) real-time security status 52; (4) real-time network traffic 80, and further parse out: (1) updated real-time security status 53; (2) updated real-time performance status 54; (3) updated real-time network status 55; (4) updated real-time control command status 91. In the second verification, determine whether the updated real-time security status 53, updated real-time performance status 54, updated real-time network status 55 and updated real-time control command status 91 all meet their respective conditions (which can be equivalent to the conditions in step 57). When all conditions are met (corresponding to the "Y branch"), notify the OT device to continue performing the security hardening process; when not all conditions are met (corresponding to the "N branch"), execute the waiting process 61, in which notify the OT device not to perform the security hardening process.

[0126] Figure 5 is an exemplary structural diagram of a security hardening device according to an embodiment of the present invention. As shown in Figure 5, the security hardening device 500 includes: an acquisition module 501, used to acquire a security hardening cycle corresponding to an OT device, the security hardening cycle being determined based on the historical performance status, historical network status, historical security status, and historical control command status of the OT device within a historical time period, and the security hardening cycle being a time period suitable for performing security hardening processing on the OT device; a determination module 502, used to acquire the real-time performance status, real-time network status, real-time security status, and real-time control command status of the OT device in the current round of the security hardening cycle; and a start module 503, used to start the OT device to perform security hardening processing in the current round of the security hardening cycle when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition.

[0127] In one embodiment, it includes: a sending module 504, configured to send a security hardening package to an OT device in the current round of a sending time period, so that the OT device can perform security hardening processing based on the security hardening package, wherein the sending time period is determined based on historical performance status, historical network status and historical security status, and the sending time period is a time period suitable for sending the security hardening package to the OT device.

[0128] In one implementation, there are multiple security hardening cycles and multiple security hardening packages; the acquisition module 501 is used to simulate the execution of each security hardening package in the virtual environment of the OT device to determine the execution duration of each security hardening package; and from the multiple security hardening cycles, determine the security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages.

[0129] This invention also proposes an electronic device with a processor-memory architecture. Figure 6 is a structural diagram of the electronic device according to an embodiment of the present invention. As shown in Figure 6, the electronic device 600 includes a processor 601, a memory 602, and a computer program stored in the memory 602 and executable on the processor 601. When the computer program is executed by the processor 601, it implements any of the security hardening methods described above. Specifically, the memory 602 can be implemented as various storage media such as electrically erasable programmable read-only memory (EEPROM), flash memory, and programmable programmable read-only memory (PROM). The processor 601 can be implemented as including one or more central processing units (CPUs) or one or more field-programmable gate arrays (FPGAs), wherein the FPGA integrates one or more CPU cores. Specifically, the CPU or CPU core can be implemented as a CPU, MCU, or DSP, etc.

[0130] It should be noted that not all steps and modules in the above processes and structural diagrams are mandatory; some steps or modules can be omitted as needed. The execution order of the steps is not fixed and can be adjusted as required. The division of modules is merely for the convenience of description and functional division. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can also be implemented by the same module. These modules can be located in the same device or in different devices.

[0131] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include specially designed permanent circuitry or logic devices (such as dedicated processors, such as FPGAs or ASICs) to perform specific operations. A hardware module may also include programmable logic devices or circuitry (such as general-purpose processors or other programmable processors) temporarily configured by software to perform specific operations. The choice between mechanical implementation, dedicated permanent circuitry, or temporarily configured circuitry (such as software-configured circuitry) can be made based on cost and time considerations.

[0132] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A security reinforcement method, characterized in that, include: Obtain (101) the security hardening cycle corresponding to the operating technology equipment. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status and historical control command status of the operating technology equipment within a historical time period. The security hardening cycle is a time period suitable for performing security hardening processing on the operating technology equipment. Determine (102) the real-time performance status, real-time network status, real-time security status, and real-time control command status of the operating technology equipment in the current round of the security hardening cycle; When the real-time performance status meets the predetermined first condition, the real-time network status meets the predetermined second condition, the real-time security status meets the predetermined third condition, and the real-time control command status meets the predetermined fourth condition, in the current round of the security hardening cycle, the operation technology equipment is started to perform security hardening processing (103).

2. The method according to claim 1, characterized in that, The acquisition (101) corresponds to the safety hardening cycle of the operating technology equipment, including: Using the identifier of the operating technology equipment as the search term, the database is used to query the search results corresponding to the search term. The database stores the association between the identifiers of multiple operating technology equipment and their corresponding security hardening cycles.

3. The method according to claim 1, characterized in that, include: When performing the security hardening process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, the real-time security status no longer meets the third condition, or the real-time control command status no longer meets the fourth condition, the security hardening process is stopped and the breakpoint of the security hardening process is recorded.

4. The method according to claim 3, characterized in that, include: After the security hardening process is stopped, when the real-time performance status recovers to meet the first condition, the real-time network status recovers to meet the second condition, the real-time security status recovers to meet the third condition, and the real-time control command status recovers to meet the fourth condition during the security hardening period, the security hardening process resumes from the breakpoint.

5. The method according to any one of claims 1-4, characterized in that, include: The operation technology device acquires security logs and / or suspicious objects, host performance data and / or performance data of predetermined processes, host network status data and / or network status data of predetermined processes, and network traffic during the historical time period. The security logs and / or the suspicious objects are first parsed to determine the historical security status within the historical time period. A second parsing is performed on the host performance data and / or the performance data of the predetermined process to determine the historical performance status within the historical time period. A third parsing is performed on the network status data of the host and / or the network status data of the predetermined process to determine the historical network status within the historical time period. The network traffic is parsed a fourth time to determine the status of historical control commands within the historical time period; From the historical time period, determine the common time period in which the historical security status, the historical network status, the historical performance status, and the historical control command status all meet their respective constraints; The safety reinforcement cycle is determined based on the common time period.

6. The method according to any one of claims 1-5, characterized in that, The method includes: In the current round of the transmission time period, a security hardening packet is sent to the operating technology device so that the operating technology device can perform the security hardening process based on the security hardening packet, wherein the transmission time period is determined based on the historical performance status, historical network status and historical security status, and the transmission time period is a time period suitable for sending the security hardening packet to the operating technology device.

7. The method according to claim 6, characterized in that, There are multiple security reinforcement cycles and multiple security reinforcement packages. The method includes: In the virtual environment of the operating technology device, each security hardening package is simulated and executed to determine the execution duration of each security hardening package; The acquisition (101) corresponds to the safety hardening cycle of the operating technology equipment, including: From multiple security hardening cycles, identify the security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages.

8. The method according to claim 7, characterized in that, The method includes: When performing the security hardening process, if the real-time performance status no longer meets the first condition, the real-time network status no longer meets the second condition, the real-time security status no longer meets the third condition, or the real-time control command status no longer meets the fourth condition, the security hardening process is stopped and the executed security hardening package is recorded. Determine the remaining security hardening packages after removing the executed ones from the total security hardening packages; From the plurality of security reinforcement cycles, determine those with a duration greater than or equal to the total duration of the remaining security reinforcement packages. Security hardening cycle duration.

9. A safety reinforcement device, characterized in that, include: The acquisition module (501) is used to acquire the security hardening cycle corresponding to the operating technology device. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status and historical control command status of the operating technology device in a historical time period. The security hardening cycle is a time period suitable for performing security hardening processing in the operating technology device. The determination module (502) is used to obtain the real-time performance status, real-time network status, real-time security status and real-time control command status of the operating technology equipment in the current round of the security hardening cycle; The startup module (503) is used to start the operation technology device to perform security hardening processing in the current round of the security hardening cycle when the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition.

10. The apparatus according to claim 9, characterized in that, include: The sending module (504) is configured to send a security hardening package to the operating technology device in the current round of the sending time period, so that the operating technology device can perform the security hardening process based on the security hardening package, wherein the sending time period is determined based on the historical performance status, historical network status and historical security status, and the sending time period is a time period suitable for sending the security hardening package to the operating technology device.

11. The apparatus according to claim 10, characterized in that, Both the security reinforcement cycle and the security reinforcement package are multiple; The acquisition module (501) is used to simulate the execution of each security hardening package in the virtual environment of the operating technology device to determine the execution duration of each security hardening package; From multiple security hardening cycles, identify the security hardening cycle whose duration is greater than or equal to the sum of the execution durations of all security hardening packages.

12. A security reinforcement system, characterized in that, include: N data acquisition agents (41, 42...4N) are deployed in N operational technology devices (241, 242...24N). Each of the N data acquisition agents (41, 42...4N) is used to collect real-time performance data, real-time network status data, real-time traffic, real-time security logs, and / or real-time suspicious objects of the corresponding operational technology device in the current round of its respective security hardening cycle. The security hardening cycle is determined based on the historical performance status, historical network status, historical security status, and historical control command status of the corresponding operational technology device within a historical time period. The security hardening cycle is a time period suitable for performing security hardening processing in the corresponding operational technology device. The monitoring server (20) is used to determine the real-time security status based on the real-time security log and / or real-time suspicious objects, determine the real-time performance status based on the real-time performance data, determine the real-time network status based on the real-time network status data, and determine the real-time control command status based on the real-time traffic. When the real-time performance status meets a predetermined first condition, the real-time network status meets a predetermined second condition, the real-time security status meets a predetermined third condition, and the real-time control command status meets a predetermined fourth condition, the corresponding operational technology equipment is activated to perform security hardening processing in the current round of the security hardening cycle.

13. The system according to claim 12, characterized in that, include: A security reinforcement packet sending server (21) is used to send a security reinforcement packet to the corresponding operating technology device in the current round of the sending time period, so that the corresponding operating technology device can perform the security reinforcement process based on the security reinforcement packet, wherein the sending time period is determined based on the historical performance status, historical network status and historical security status, and the sending time period is a time period suitable for sending the security reinforcement packet to the corresponding operating technology device.

14. The system according to claim 11, characterized in that, include: The monitoring device (23) is used to aggregate the real-time performance data, real-time network status data, real-time traffic, real-time security logs and / or real-time suspicious objects of the N operating technology devices (41, 42...4N), and send the aggregation results to the monitoring server (20).

15. An electronic device, characterized in that, include: Processor (601); Memory (602) for storing executable instructions of the processor (601); The processor (601) is configured to read the executable instructions from the memory (602) and execute the executable instructions to implement the security hardening method according to any one of claims 1-8.

16. A computer-readable storage medium storing computer instructions thereon, characterized in that, When the computer instructions are executed by the processor, they implement the security hardening method according to any one of claims 1-8.

17. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the security hardening method according to any one of claims 1-8.

Citation Information

Patent Citations

  • General internet platform for real-time monitoring of digital products in small and medium-sized manufacturing industry

    CN115102827A

  • Safety guarantee system

    CN115314286A

  • Industrial control monitoring analysis early warning system and analysis early warning processing method

    CN116700197A

  • Access request processing method, system and device, computer equipment and storage medium

    CN116980164A

  • Overlay cyber security networked system and method

    US10250619B1