Method, apparatus, device, and medium for detecting anomaly in OT network

By determining importance weights for devices and connections in OT networks and using clustering algorithms, the method improves anomaly detection accuracy by optimizing the graph structure and extracting key features.

WO2026091013A1PCT designated stage Publication Date: 2026-05-07SIEMENS AG +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SIEMENS AG
Filing Date
2024-10-31
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing OT network anomaly detection methods fail to distinguish between devices and connections, leading to low detection accuracy.

Method used

Determine first and second weights representing device and connection importance, respectively, and use these weights to construct a feature vector for anomaly detection, employing clustering algorithms to optimize the graph structure and improve accuracy.

Benefits of technology

Accurately detects OT network anomalies by considering device and connection importance, enhancing detection accuracy and extracting key features effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024129043_07052026_PF_FP_ABST
    Figure CN2024129043_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a method, apparatus, device, and medium for detecting anomaly in OT network. The method comprises: determining a first weight representing importance of a device in an OT network; determining a second weight representing importance of a connection in the OT network; determining a feature vector of the OT network based on the first weight and the second weight; and detecting an anomaly in the OT network based on the feature vector of the OT network. Determining feature vector of OT network based on the importance of devices and connections in the OT network can accurately detect OT network anomalies. Moreover, clustering algorithm is used to optimize graph structure of OT network, key features of the graph structure can be accurately and effectively extracted, thus improving the anomaly detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Method, apparatus, device, and medium for detecting anomaly in OT networkTECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, in particular to a method, apparatus, device, and medium for detecting anomaly in Operational Technology (OT) network.BACKGROUND

[0002] OT network is an industrial communication network used to connect production field devices and various systems to realize automatic control. OT network usually includes Programmable Logic Controller (PLC) , Distributed Control System (DCS) and Supervisory Control and Data Acquisition (SCADA) systems, which are responsible for controlling and monitoring physical processes in enterprise, such as manufacturing process, power generation and water treatment.

[0003] OT network anomalies include network connection problems or system failures. OT network anomalies usually include: network connection interruption; device failure; data transmission error; network security issues, etc.

[0004] At present, no distinction is made between devices or connections between devices when detecting OT network anomalies, which has the disadvantage of low detection accuracy.SUMMARY

[0005] Embodiments of the present disclosure propose a method, apparatus, device, and medium for detecting anomaly in OT network.

[0006] In a first aspect, a method for detecting anomaly in an OT network is provided. The method includes:

[0007] determining a first weight representing importance of a device in an OT network;

[0008] determining a second weight representing importance of a connection in the OT network;

[0009] determining a feature vector of the OT network based on the first weight and the second weight; and

[0010] detecting an anomaly in the OT network based on the feature vector of the OT network.

[0011] In a second aspect, an apparatus for detecting anomaly in an OT network is provided. The apparatus includes:

[0012] a first determining module, configured to determine a first weight representing importance of a device in an OT network;

[0013] a second determining module, configured to determine a second weight representing importance of a connection in the OT network;

[0014] a third determining module, configured to determine a feature vector of the OT network based on the first weight and the second weight; and

[0015] a detecting module, configured to detect an anomaly in the OT network based on the feature vector of the OT network.

[0016] In a third aspect, an electronic device is provided. The electronic device comprising a processor and a memory, wherein an application program executable by the processor is stored in the memory for causing the processor to execute a method for detecting anomaly in an OT network as described in any of the above.

[0017] In a fourth aspect, a computer-readable medium comprising computer-readable instructions stored thereon is provided, wherein the computer-readable instructions for executing a method for detecting anomaly in an OT network as described in any of the above.

[0018] In a fifth aspect, a computer program product comprising a computer program, when the computer program is executed by a processor for executing a method for detecting anomaly in an OT network as described in any of the above.

[0019] According to the above technical solutions, determining a first weight representing importance of a device in an OT network; determining a second weight representing importance of a connection in the OT network; determining a feature vector of the OT network based on the first weight and the second weight; and detecting an anomaly in the OT network based on the feature vector of the OT network. Therefore, determining feature vector of the OT network based on the importance of devices and connections in the OT network can accurately detect OT network anomalies. Moreover, clustering algorithm is used to optimize graph structure of OT network, key features of the graph structure can be accurately and effectively extracted, thus improving the anomaly detection accuracy.BRIEF DESCRIPTION OF THE DRAWINGS

[0020] To make technical solutions of examples of the present disclosure clearer, accompanying drawings to be used in description of the examples will be simply introduced hereinafter. Obviously, the accompanying drawings to be described hereinafter are only some examples of the present disclosure. Those skilled in the art may obtain other drawings according to these accompanying drawings without creative labor.

[0021] Fig. 1 is an exemplary flow chart of a method for detecting anomaly in OT network according to an embodiment of the present disclosure.

[0022] Fig. 2 is an exemplary schematic diagram of an OT network according to an embodiment of the present disclosure.

[0023] Fig. 3 is an exemplary schematic diagram of clustering process of the OT network according to an embodiment of the present disclosure.

[0024] Fig. 4 is an exemplary schematic diagram of cluster graph of the OT network according to an embodiment of the present disclosure.

[0025] Fig. 5 is a flowchart of an exemplary process for detecting anomaly in a factory network according to an embodiment of the present disclosure.

[0026] Fig. 6 is an exemplary structure diagram of an apparatus for detecting anomaly in an OT network according to an embodiment of the present disclosure.

[0027] Fig. 7 is an exemplary structural diagram of an electronic device according to an embodiment of the present disclosure.

[0028] List of reference numbers: DETAILED DESCRIPTION

[0029] To make the purpose, technical scheme, and advantages of the disclosure clearer, the following examples are given to further explain the disclosure in detail. Nouns and pronouns related to people in this patent application are not limited to specific gender.

[0030] To be concise and intuitive in description, the scheme of the disclosure is described below by describing several representative embodiments. Many details in the embodiments are only used to help understand the scheme of the disclosure. However, it is obvious that the technical scheme of the disclosure can be realized without being limited to these details. To avoid unnecessarily blurring the scheme of the disclosure, some embodiments are not described in detail, but only the framework is given. Hereinafter, "including" refers to "including but not limited to" , "according to... " refers to "at least according to..., but not limited to... " . When the number of an element is not specifically indicated below, it means that the element can be one or more, or can be understood as at least one. The terms "a" or "an" in this disclosure should not be understood as one, but as at least one.

[0031] At present, when detecting OT network anomalies, the importance of OT devices and connections between devices is not considered, which leads to inaccurate detection results.

[0032] In embodiments of the present disclosure, respective weights representing the importance of respective devices and respective connections in an OT network are determined, and then feature vector of the OT network is determined based on the weights, so as to realize bottleneck detection of important devices and important connections, and thus accurately detect the OT network anomaly.

[0033] The above disclosure provides a detailed explanation of the technical defects existing in the existing technology, the reasons for these defects, and the process of thinking and analyzing how to overcome them. In fact, the understanding of the above-mentioned technical defects is not universal knowledge in this field, but rather a novel discovery made by the applicant in their research. In addition, the tracing of the causes of the technical defect and the process of thinking and analyzing how to overcome it are also the gradual analysis results of the applicant in the actual research process, and are not universal knowledge in this field.

[0034] Fig. 1 is an exemplary flow chart of a method for detecting anomaly in OT network according to an embodiment of the present disclosure. The method shown in Figure 1 may be executed by a controller in the OT network or a controller outside the OT network. The method shown in Figure 1 may also be executed by a software module, a firmware module, a plug-in module or a piece of program code generated in any editing languages. The method shown in Figure 1 may also be executed in various hardware / software combination systems.

[0035] As shown in Figure 1, the method includes:

[0036] Step 101: determining a first weight representing importance of a device in an OT network.

[0037] OT network usually contains a large number of devices. Each device is determined its own first weight based on its own importance. Therefore, respective first weights for devices in the OT network are determined  respectively. The devices in OT network usually include sensors, controllers, actuators, PLCs, DCS, computer numerical control (CNC) , remote terminal unit (RTU) , motion controllers, robots, etc.

[0038] In one embodiment, determining a first weight, which represents importance of a device in an OT network comprises at least one of the following methods:

[0039] (a) determining the first weight based on an average load of the device in a predetermined time, wherein the first weight increases with the average load.

[0040] Here, considering that the greater the average load is, the more important the device is, the first weight increases with the average load of the device.

[0041] (b) determining the first weight based on the type of the device, wherein the first weight increases with importance of the type of the device.

[0042] Here, when the device type is a key device type in the OT network, the first weight of the device has a higher value, when the device type is a common device type in the OT network, the first weight of the device has a lower value. For example, when the device is a router, switch, server or PLC in the OT network, it has a higher first weight. When the device is a laptop or smartphone of a technician in the OT network, it has a lower first weight.

[0043] (c) determining the first weight based on a setting parameter of the device, wherein the first weight increases with importance of the setting parameter.

[0044] For example, for switch A and switch B of the same type in the OT network, if the setting load of switch A is larger than that of switch B, the first weight of switch A is greater than that of switch B.

[0045] (d) determining the first weight based on authorization level of the device, wherein the first weight increases with the authorization level.

[0046] Step 102: determining a second weight representing importance of a connection in the OT network.

[0047] OT network usually contains a large number of connections between devices. The connection here refers to the direct connection between any two devices in the OT network.

[0048] In one embodiment, the determining a second weight representing importance of a connection in the OT network comprises at least one of the following:

[0049] (a) determining the second weight based on an average network traffic of the connection in a predetermined time, wherein the second weight increases with the average network traffic.

[0050] (b) determining the second weight based on type of the connection, wherein the second weight increases with importance of the type of the connection.

[0051] (c) determining the second weight based on communication frequency of the connection, wherein the second weight increases with the communication frequency.

[0052] (d) determining the second weight based on communication rate of the connection, wherein the second weight increases with the communication rate.

[0053] (e) determining the second weight based on source address of the connection, wherein the second weight increases with importance of the source address.

[0054] (f) determining the second weight based on destination address of the connection, wherein the second weight increases with importance of the destination address.

[0055] Preferably, the determining the second weight based on type of the connection comprises: determining the second weight as a first value when the type is an industrial communication connection; determining the second weight as a second value when the type is a universal communication connection; wherein the first value is greater than the second value.

[0056] Here, considering the importance of industrial communication connection is usually greater than that of universal communication connection. Therefore, the second weight of the industrial communication connection is set to be greater than the second weight of the universal communication connection. For example, industrial communication connections may include industrial Ethernet connections, such as PROFINET connection, Ether CAT connection, POWERLINK connection, etc. Industrial communication connections can also include field bus connections, such as CAN connection, Modbus connection, Profibus connection, HART connection, Device Net connection, etc. Universal communication connections may include HTTP connection, SMTP connection, UDP connection, Bluetooth connection, 5G connection, and Zigbee connection, etc.

[0057] The above exemplary description shows an exemplary example of determining the first weight and the second weight. Those skilled in the art can realize that this description is only exemplary and is not used to limit the protection scope of the embodiment of the disclosure.

[0058] Step 103: determining a feature vector of the OT network based on the first weight and the second weigh.

[0059] Here, feature vector of the OT network can be determined based on feature vectors of respective devices in the OT network, the first weights of respective devices, feature vectors of respective connections in the OT network, and the second weights of respective connections.

[0060] In machine learning, feature vector usually refers to a vector used to represent data features. Each dimension represents a feature. For example, in image recognition, a feature vector can be a collection of pixel intensity, edge intensity, or corners. The vector composed of these features can be used to describe and recognize images. For example, feature vector of a device may include device type, supplier, device status, parameter configuration, etc. The feature vector of the device can further contain network service information, such as the size of the input / output service of the device, and service mode, etc. The feature vector of the device can further contain  network log information, such as the type and occurrence time of events. The feature vector of a connection between devices may include the connection type, connection rate and communication frequency between devices. The feature vector of the connection between devices can also contain information such as the amount of data transmitted between devices, the source address and destination address of traffic.

[0061] For example: firstly, calculate respective products of respective feature vectors of devices and respective first weights of the devices. Then, sum the products of all devices to get a first sum result. Secondly, calculate respective products of respective feature vectors of connections and respective second weights of the connections. Then, sum products of all connections to get a second sum result. Then add the first summation result and the second summation result to get the feature vector of the OT network.

[0062] Considering the large number of devices and connections in the OT network, computing the feature vector of the OT network directly has a large amount of computation. The OT network can be clustered based on a clustering method to simplify the calculation of the feature vector of the OT network.

[0063] In one embodiment, step 103 specifically includes: determining a diagram structure of the OT network; clustering the graph structure to obtain a cluster graph, the cluster graph comprises a cluster node and a cluster edge, wherein the cluster node corresponds to a cluster of devices, and the cluster edge corresponds to a connection between clusters; determining a feature vector of the cluster node based on feature vectors of respective devices in the cluster and the first weights of the respective devices; determining a feature vector of the cluster edge based on feature vectors of respective connections with respective devices in an adjacent cluster and the second weights of the respective connections; determining a feature vector of the OT network based on the feature vector of the cluster node and the feature vector of the cluster edge.

[0064] Clustering algorithm can be used to analyze the graph structure of OT network and group similar devices into the same cluster. For example, spectral clustering algorithm can be used. Spectral clustering algorithm is a clustering method based on graph theory, which transforms the clustering problem of data into the problem of graph segmentation. By constructing a similarity graph of data and using the Laplacian matrix of the graph for spectral analysis, data clustering is realized. Spectral clustering algorithm can recognize the sample space of arbitrary shape and converge to the global optimal solution. Its basic idea is to use the eigenvector obtained from the feature decomposition of the sample data's similarity matrix to cluster, which is independent of the sample's characteristics, but only related to the number of samples. Spectral clustering algorithms can be divided into two spectral clustering algorithms and multi spectral clustering algorithms. Two-way spectral clustering algorithm uses 2-way partition criterion, while multi way spectral clustering algorithm uses k-way partition criterion. Specific algorithms include PF algorithm, SM algorithm, SLH algorithm, KVV algorithm and Mcut algorithm.

[0065] Step 104: detecting an anomaly in the OT network based on the feature vector of the OT network.

[0066] In one embodiment, detecting an anomaly in the OT network based on the feature vector of the OT network comprises: performing a full connection operation on the feature vector of the OT network; inputting the feature vector performed the full connection operation into a trained classifier, wherein the classifier is suitable for predicting probability of anomaly based on the feature vector performed the full connection operation; determining anomaly occurs in the OT network when the probability is greater than a predetermined threshold. The above steps may be executed by a controller in the OT network or a controller outside the OT network. The above steps may also be executed by a software module, a firmware module, a plug-in module or a piece of program code generated in any editing languages. The above steps may also be executed in various hardware / software combination systems.

[0067] In one embodiment, performing a full connection operation on the feature vector of the OT network comprises: inputting the feature vector of the OT network into a full connection module comprising a first full connection layer and a second full connection layer, wherein the first full connection layer performs a full connection operation on a concatenated feature vector of all cluster nodes in the feature vector of the OT network, and the second full connection layer performs a full connection operation on a concatenated feature vector of all cluster edges in the feature vector of the OT network; concatenating output vector of the first fully connected layer and output vector of the second fully connected layer. The above steps may be executed by a controller in the OT network or a controller outside the OT network. The above steps may also be executed by a software module, a firmware module, a plug-in module or a piece of program code generated in any editing languages. The above steps may also be executed in various hardware / software combination systems.

[0068] In one embodiment, the method also includes the process of training a classifier. The training process includes: inputting a training sample containing a feature vector of an OT networks for training and a tag into the classifier, where the tag contains a probability of anomaly occurrence for the OT network; receive a predicted anomaly probability based on the training sample from the classifier; based on the difference between the predicted anomaly probability and the tag, a loss function value of the classifier is determined; configure model parameters of the classifier to make the loss function value lower than a preset threshold. Wherein, based on the loss function value, a back-propagation is performed on the classifier to update model parameters of the classifier, until the loss function value of the classifier is less than a preset value, that is, the training process of the classifier is completed. The trained classifier has the ability to predict anomaly probability of an OT network based on feature vector of the OT network. Similarly, the above training process may be performed by a controller in the OT network or a controller outside the OT network. For example, the controller that executes the above training  process may be implemented as any one of the following: Central Processing Unit (CPU) , Graphics Processing Unit (GPU) , Tensor Processing Unit (TPU) , Neural Network Processing Unit (NPU) , Deep Learning Processing Unit (DPU) , Accelerated Processing Unit (APU) , or General-Purpose Computing on Graphics Processing Unit (GPGPU) . The above training process may also be executed by a software module, a firmware module, a plug-in module or a piece of program code generated in any editing languages. The above training process may also be executed in various hardware / software combination systems.

[0069] Therefore, according to embodiments of the present disclosure, determining a first weight representing importance of a device in an OT network; determining a second weight representing importance of a connection in the OT network; determining a feature vector of the OT network based on the first weight and the second weight; and detecting an anomaly in the OT network based on the feature vector of the OT network. Therefore, determining feature vector of the OT network based on the importance of devices and connections in the OT network can accurately detect OT network anomalies. Moreover, clustering algorithm is used to optimize graph structure of OT network, key features of the graph structure can be accurately and effectively extracted, thus improving the anomaly detection accuracy.

[0070] Fig. 2 is an exemplary schematic diagram of an OT network according to an embodiment of the present disclosure.

[0071] As shown in Figure 2, the OT network includes devices a1~a6. There is a connection L1 between device a1 and device a3. There is a connection L2 between device a4 and device a6. There is a connection L3 between device a3 and device a5. There is a connection L4 between device a5 and device a6. There is a connection L5 between device a1 and device a2. There is a connection L6 between device a2 and device a4.

[0072] Assume that the feature vector of device a1 is A1 and the weight of device a1 is t1, the feature vector of device a2 is A2 and the weight of device a2 is t2, the feature vector of device a3 is A3 and the weight of device a3 is t3, the feature vector of device a4 is A4 and the weight of device a4 is t4, the feature vector of device a5 is A5 and the weight of device a5 is t5, the feature vector of device a6 is A6 and the weight of device a6 is t6. Among them, feature vectors A1~A6 respectively contain the same type of features such as device type, model, supplier, device status and configuration parameters.

[0073] The feature vector of edge L1 is B1 and the weight of edge L1 is j1, the feature vector of edge L2 is B2 and the weight of edge L2 is j2, the feature vector of edge L3 is B3 and the weight of edge L3 is j3, the feature vector of edge L4 is B4 and the weight of edge L4 is j4, the feature vector of edge L5 is B5 and the weight of edge L5 is j5, the feature vector of edge L6 is B6 and the weight of edge L6 is j6. Among them, feature vectors B1~B6 respectively contain the same type of features such as connection type, connection rate, communication frequency,  data volume, source address and destination address.

[0074] Fig. 3 is an exemplary schematic diagram of clustering process of the OT network according to an embodiment of the present disclosure. In Figure. 3, device a1, device a2, and device a4 are clustered into cluster 11.Device a3, device a5, and device a6 are clustered into cluster 12.

[0075] The feature vector of cluster 11 is M1, where M1=A1*t1+A2*t2+A4*t4. The feature vector of cluster 12 is M2, where M2=A3*t3+A5*t5+A6*t6. The feature vector of edge L of cluster 11 and cluster 12 is: N1=B1*j1+B2 *j2. That is, based on the edge L1 between device a1 in cluster 11 and device a3 in cluster 12, and the edge L2 between device a4 in cluster 11 and device a6 in cluster 12, the vector of cluster edge L between cluster 11 and cluster 12 is determined. Therefore, when determining the vector of cluster edge L between cluster 11 and cluster 12, it is unnecessary to consider the edges merely inside cluster 11 and cluster 12.

[0076] Fig. 4 is an exemplary schematic diagram of cluster graph of the OT network according to an embodiment of the present disclosure Therefore, the feature vector of the OT network is { {M1, M2} , {N1} } .

[0077] Input the feature vector of the OT network: { {M1, M2} , {N1} } into a full connection module containing a first full connection layer and a second full connection layer, wherein the first full connection layer performs a full connection operation on a concatenated feature vector of cluster 11 and cluster 12: {M1, M2} , and the second full connection layer performs a full connection operation on the feature vector of edge L: {N1} ; concatenating the output vector of the first full connection layer and the output vector of the second full connection layer into the feature vector: {f1 ( {M1, M2} } , f2 ( {N1} ) } , where f1 () is the processing function of the first full connection layer; f2 () is the processing function of the second full connection layer.

[0078] Then, input the feature vector performed the full connection operation: {f1 ( {M1, M2} } , f2 ( {N1} ) } into a trained classifier, wherein the classifier is suitable f for predicting probability of anomaly based on the feature vector performed the full connection operation. When the probability is greater than a predetermined threshold, it is determined that the OT network is in an abnormal state.

[0079] In the above description, a detailed technical solution for detecting anomalies in OT networks based on device importance and connection importance is disclosed.

[0080] Below, Taking the implementation of OT network as an example of factory network, embodiments of the present disclosure are described in detail. With the continuous development of factory network, businesses and individuals are enjoying the convenience it brings. However, the advancement of factory network also brings the advancement of attack methods, and the increasing number of cyber-attacks on factory networks in recent years profoundly reflects that the attack methods have become more diversified and secretive.

[0081] In the current security monitoring of factory networks, by evaluating information such as the operating status  and logs of a single device in factory network, it is difficult to detect hidden and complex attacks. In the face of this challenge, we need to consider how we can rationally and effectively utilize information from all devices in the entire factory network to determine whether the entire factory network has been attacked in a comprehensive manner. This task is not only challenging, but also important. The current technical equipment in the factory is the part that needs to be strictly controlled, and if any anomaly occurs, it can cause a chain of irreversible damages to the factory. Therefore, this solution aims to capture the network anomalies of technical devices in the factory, start from the macroscopic network topology of the technical devices, integrate and analyze the data, and then determine whether the network has been attacked.

[0082] Embodiments of the present disclosure first extract a common network features of the process equipment in the factory, then abstractly describes the factory network topology using the graph structure, simplifies the network topology using clustering method to improve the processing efficiency, and at the same time uses the feature extraction capability provided by the graph neural network to generate features of the whole factory network based on the features of the nodes and edges of the factory network, and, finally, determines the existence of anomalies using a classifiers. A new algorithm for industrial control anomaly detection based on graph neural network is proposed in the following steps.

[0083] Fig. 5 is a flowchart of an exemplary process for detecting anomaly in a factory network according to an embodiment of the present disclosure. As shown in Figure 5, the process includes:

[0084] Step 501: Diverse source features are extracted from diverse technical device data, covering technical devices, network traffic packets, network logs, etc., in order to exhaustively and accurately portray the network conditions and states of technical devices.

[0085] In order to utilize the network information more comprehensively, both node embedding and edge embedding in the network are considered. Specifically, node embedding synthesizes a number of attribute information of technical devices, such as device type, model, vendor, etc., as well as device status, configuration, etc. At the same time, it also incorporates network traffic information, such as the size of the device's input / output traffic, traffic patterns, etc., as well as network log information, such as the type of events, occurrence time, etc. Edge embedding, on the other hand, mainly utilizes connection type, connection rate, and communication frequency between devices, as well as key information such as the amount of data transferred between devices, and the source and destination of traffic.

[0086] Step 502: The multivariate features extracted in step 501 are further fused, and the optimization of features is achieved by merging similar data types and eliminating features that cannot clearly reflect the detection of anomalies.

[0087] This optimization process maps the high-dimensional features to a low-dimensional space with the help of graph convolution module, taking into account the node features and edge features. This mapping process is dynamically updated by back propagation algorithm during neural network training.

[0088] Step 503: The optimization features obtained in step 502 are integrated to describe the network topology using a graph model. Specifically, the devices in the network are abstracted as nodes in the graph structure, and the relationships and traffic interactions between devices are abstracted as edges in the graph.

[0089] Step 504: Initializing weight parameters.

[0090] In one embodiment of the present disclosure, assign a learnable weight parameter to each edge and node in the graph. Specifically, the weight parameter is initialized for each edge and node of the graph in step 503. The weights are initialized for the edges based on the communication frequency and the connection rate between the devices, and the weights are initialized for the nodes based on the traffic load and the configuration parameters of the devices. After initializing the weight parameters, the network will update the weight parameters by back propagation algorithm. For each iteration, the weights are updated by calculating the gradient of the loss function with respect to the weight parameters so that the weights of the edges and nodes are dynamically adjusted during training to minimize the loss function.

[0091] Step 505: The graph structure is simplified by applying a clustering algorithm to analyze the graph structure by clustering and grouping similar nodes into the same cluster to form subgraphs.

[0092] Step 506: Each cluster generated by steps 505 is mapped to a single node, and a feature vector of the cluster is generated using the feature vectors of the nodes in the cluster by a weighted pooling method.

[0093] Specifically, the feature vectors of the clusters are derived by weighted summation of the product of the node feature vectors and the corresponding node weight coefficients.

[0094] Step 507: Connecting edges are generated for adjacent clusters in step 505 and a connecting edge feature vector of the cluster is generated by weighted pooling method using the feature vectors of the connecting edges of the nodes in the cluster.

[0095] Similarly, the connected edge feature vectors of the clusters are derived by weighted summation of the product of the edge feature vectors and the corresponding edge weight coefficients.

[0096] Step 508: Edge weights and node weights of the subgraph are further generated.

[0097] Specifically, the edge weights of the subgraph are derived by calculating the average of the weights of the connected edges of the nodes in the neighboring clusters, and the node weights of the subgraph are derived by calculating the average of the weights of the nodes in the clusters.

[0098] Step 509: The feature vectors of nodes and edges generated in steps 506 and 507 are again optimized using  the graph convolution module to further improve the quality of the features.

[0099] Step 510: The feature vectors of the nodes and the feature vectors of the edges in the subgraph are passed through a weighted pooling layer to derive the node embeddings and edge embeddings of the whole graph, which are then spliced into the node embeddings and edge embeddings to form a feature vector representation of the whole network.

[0100] Step 511: In order to further compress the feature space and extract key information, embodiments of the present disclosure optimize the feature vectors obtained in step 510 using two fully connected layers to map them from a high-dimensional space to a low-dimensional space to better reflect those features.

[0101] Step 512: The feature vector obtained in step 511 is passed through a binary classifier.

[0102] Here, the classifier calculates the probability values of the two categories of normal and abnormal by means of a Softmax function, compares them with a set threshold, and thereby generates labels for the data to determine whether there is an anomaly in the system. Specifically, the dichotomous classifier takes as input a feature representation of the entire network topology optimized by integrating important feature information of nodes and edges of the subgraph, and is trained using a supervised learning method to minimize the dichotomous cross-entropy loss function by continuously adjusting internal parameters, thereby improving the efficiency and accuracy of the anomaly detection.

[0103] In the above process, steps 502 and 503 constitute feature extraction 31, steps 503 and 504 constitute network topology modeling 32, step 502~step 503 constitute graph structure simplification 33, and step 510~step 512 constitute feature processing and optimization 34.

[0104] Therefore, embodiments of the present disclosure take at least one of the following prominent features:

[0105] (1) Innovative application of graph neural network and clustering algorithm in network abnormality detection of technical equipment in factories: embodiments of the present disclosure combine the graph neural network and clustering algorithm and apply them purposefully in the field of network abnormality detection of technical equipment in factories. Taking into account the diverse scenarios of technical equipment in factories, specific adjustments and optimizations are made to make the algorithm more relevant to the actual application requirements.

[0106] (2) Optimizing the graph structure through clustering to improve operational efficiency: embodiments of the present disclosure adopt a clustering algorithm to optimize the graph structure, and accurately and efficiently extract key features of the graph structure by reducing the dimensionality of the data, thus greatly improving the operational efficiency of the algorithm.

[0107] (3) Weighted summation strategy of subgraph feature vectors: compared with the traditional averaging  operation, embodiments of the present disclosure perform weighted summation of the features of nodes and edges in the subgraph to generate the feature vectors of the subgraph. This strategy fully considers the difference in importance of each edge and each node in the network topology, and captures the feature information of the subgraph more comprehensively by assigning learnable weighting parameters, thereby improving the accuracy of anomaly detection.

[0108] (4) Making full use of the feature information of edges: embodiments of the present disclosure make full use of the data information in the industrial control environment to generate the feature vectors of edges for the network topology. This enhances the model's ability to understand and represent the network topology, making the anomaly detection more comprehensive and in-depth.

[0109] (5) Optimizing the feature extraction process: embodiments of the present disclosure improve and optimize the feature extraction process, so that the extracted data better retains the key features used for anomaly detection, and at the same time substantially reduces the proportion of interference terms, thereby enhancing the accuracy of the anomaly detection results.

[0110] In the above description, take the factory network and spectral clustering algorithm as examples to demonstrate embodiments of the present disclosure. Those skilled in the art can realize that embodiments of the present disclosure are not limited to industrial field networks such as factory networks, but also can be applied to factory backbone networks connecting different workshops or factories, etc.

[0111] Fig. 6 is an exemplary structure diagram of an apparatus for detecting anomaly in an OT network according to an embodiment of the present disclosure. As shown in Figure 6, the apparatus 600 includes: a first determining module 601, configured to determine a first weight representing importance of a device in an OT network; a second determining module 602, configured to determine a second weight representing importance of a connection in the OT network; a third determining module 603, configured to determine a feature vector of the OT network based on the first weight and the second weight; and a detecting module 604, configured to detect an anomaly in the OT network based on the feature vector of the OT network.

[0112] In one embodiment, the first determining module 601 is configured to perform at least one of the following: determining the first weight based on an average load of the device in a predetermined time, wherein the first weight increases with the average load; determining the first weight based on type of the device, wherein the first weight increases with importance of the type; determining the first weight based on a setting parameter of the device, wherein the first weight increases with importance of the setting parameter; determining the first weight based on authorization level of the device, wherein the first weight increases with the authorization level.

[0113] In one embodiment, the second determining module 602 is configured to perform at least one of the  following: determining the second weight based on an average network traffic of the connection in a predetermined time, wherein the second weight increases with the average network traffic; determining the second weight based on type of the connection, wherein the second weight increases with importance of the type; determining the second weight based on communication frequency of the connection, wherein the second weight increases with the communication frequency; determining the second weight based on communication rate of the connection, wherein the second weight increases with the communication rate; determining the second weight based on source address of the connection, wherein the second weight increases with importance of the source address; determining the second weight based on destination address of the connection, wherein the second weight increases with importance of the destination address.

[0114] In one embodiment, the third determining module 603 is configured to determine a diagram structure of the OT network, cluster the graph structure to obtain a cluster graph, the cluster graph comprises a cluster node and a cluster edge, wherein the cluster node corresponds to a cluster of devices, and the cluster edge corresponds to a connection between clusters, determine a feature vector of the cluster node based on feature vectors of respective devices in the cluster and the first weights of the respective devices; determine a feature vector of the cluster edge based on feature vectors of respective connections with respective devices in an adjacent cluster and the second weights of the respective connections; determine a feature vector of the OT network based on the feature vector of the cluster node and the feature vector of the cluster edge.

[0115] Embodiments of the present disclosure also propose an electronic device with a processor memory architecture. Fig. 7 is an exemplary structural diagram of an electronic device according to an embodiment of the present disclosure. As shown in Figure 7, electronic device 700 includes a processor 701, a memory 702, and a computer program stored on memory 702 that can run on processor 701. When the computer program is executed by processor 701, the method for detecting anomaly in OT network. as described in either of the above is implemented. Among them, memory 702 can be implemented as various storage media such as electrically erasable programmable read-only memory (EEPROM) , flash memory, programmable program read-only memory (PROM) , etc. Processor 701 can be implemented to include one or more central processors or one or more field programmable gate arrays, wherein the field programmable gate array integrates one or more central processor cores. Specifically, the central processing unit or core can be implemented as a CPU, MCU, DSP, and so on.

[0116] It should be noted that not all steps and modules in the above processes and structural diagrams are necessary, and some steps or modules can be ignored according to actual needs. The execution sequence of each step is not fixed and can be adjusted as needed. The division of each module is only for the convenience of describing the functional division used. In actual implementation, a module can be divided into multiple modules, and the  functions of multiple modules can also be implemented by the same module. These modules can be in the same device or different devices.

[0117] The hardware modules in each implementation can be implemented mechanically or electronically. For example, a hardware module may include specially designed permanent circuits or logic devices (such as dedicated processors, such as FPGA or ASIC) to complete specific operations. Hardware modules can also include programmable logic devices or circuits temporarily configured by software (such as general-purpose processors or other programmable processors) for performing specific operations. As for the specific use of mechanical methods, either dedicated permanent circuits or temporarily configured circuits (such as software configuration) to implement hardware modules, it can be determined based on cost and time considerations.

[0118] The above is only a preferred embodiment of the present disclosure and is not intended to limit the scope of protection of the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1.A method for detecting anomaly in an OT network, comprising:determining (101) a first weight representing importance of a device in an OT network;determining (102) a second weight representing importance of a connection in the OT network;determining (103) a feature vector of the OT network based on the first weight and the second weight; anddetecting (104) an anomaly in the OT network based on the feature vector of the OT network.2.The method according to claim 1, wherein the determining (101) a first weight representing importance of a device in an OT network comprises at least one of the following:determining the first weight based on an average load of the device in a predetermined time, wherein the first weight increases with the average load;determining the first weight based on type of the device, wherein the first weight increases with importance of the type of the device;determining the first weight based on a setting parameter of the device, wherein the first weight increases with importance of the setting parameter;determining the first weight based on authorization level of the device, wherein the first weight increases with the authorization level.3.The method according to claim 1, wherein the determining (102) a second weight representing importance of a connection in the OT network comprises at least one of the following:determining the second weight based on an average network traffic of the connection in a predetermined time, wherein the second weight increases with the average network traffic;determining the second weight based on type of the connection, wherein the second weight increases with importance of the type of the connection;determining the second weight based on communication frequency of the connection, wherein the second weight increases with the communication frequency;determining the second weight based on communication rate of the connection, wherein the second weight increases with the communication rate;determining the second weight based on source address of the connection, wherein the second weight increases with importance of the source address;determining the second weight based on destination address of the connection, wherein the second weight increases with importance of the destination address.4.The method according to claim 3, wherein the determining the second weight based on type of the  connection comprises:determining the second weight as a first value when the type is an industrial communication connection;determining the second weight as a second value when the type is a universal communication connection;wherein the first value is greater than the second value.5.The method according to claim 1, wherein the determining (103) a feature vector of the OT network based on the first weight and the second weight comprises:determining a diagram structure of the OT network;clustering the graph structure to obtain a cluster graph, the cluster graph comprises a cluster node and a cluster edge, wherein the cluster node corresponds to a cluster of devices, and the cluster edge corresponds to a connection between clusters;determining a feature vector of the cluster node based on feature vectors of respective devices in the cluster and the first weights of the respective devices;determining a feature vector of the cluster edge based on feature vectors of respective connections with respective devices in an adjacent cluster and the second weights of the respective connections;determining a feature vector of the OT network based on the feature vector of the cluster node and the feature vector of the cluster edge.6.The method according to any one of claims 1-5, wherein the detecting (104) an anomaly in the OT network based on the feature vector of the OT network comprises:performing a full connection operation on the feature vector of the OT network;inputting the feature vector performed the full connection operation into a trained classifier, wherein the classifier is suitable for predicting probability of anomaly based on the feature vector performed the full connection operation;determining anomaly occurs in the OT network when the probability is greater than a predetermined threshold.7.The method according to claim 6, wherein the performing a full connection operation on the feature vector of the OT network comprises:inputting the feature vector of the OT network into a full connection module comprising a first full connection layer and a second full connection layer, wherein the first full connection layer performs a full connection operation on a concatenated feature vector of all cluster nodes in the feature vector of the OT network, and the second full connection layer performs a full connection operation on a concatenated feature vector of all cluster edges in the feature vector of the OT network;concatenating output vector of the first fully connected layer and output vector of the second fully connected layer.8.An apparatus for detecting anomaly in an OT network, comprising:a first determining module (601) , configured to determine a first weight representing importance of a device in an OT network;a second determining module (602) , configured to determine a second weight representing importance of a connection in the OT network;a third determining module (603) , configured to determine a feature vector of the OT network based on the first weight and the second weight; anda detecting module (604) , configured to detect an anomaly in the OT network based on the feature vector of the OT network.9.The apparatus according to claim 8, wherein the first determining module (601) is configured to perform at least one of the following:determining the first weight based on an average load of the device in a predetermined time, wherein the first weight increases with the average load;determining the first weight based on type of the device, wherein the first weight increases with importance of the type;determining the first weight based on a setting parameter of the device, wherein the first weight increases with importance of the setting parameter;determining the first weight based on authorization level of the device, wherein the first weight increases with the authorization level.10.The apparatus according to claim 8, wherein the second determining module (602) is configured to perform at least one of the following:determining the second weight based on an average network traffic of the connection in a predetermined time, wherein the second weight increases with the average network traffic;determining the second weight based on type of the connection, wherein the second weight increases with importance of the type;determining the second weight based on communication frequency of the connection, wherein the second weight increases with the communication frequency;determining the second weight based on communication rate of the connection, wherein the second weight increases with the communication rate;determining the second weight based on source address of the connection, wherein the second weight increases with importance of the source address;determining the second weight based on destination address of the connection, wherein the second weight increases with importance of the destination address.11.The apparatus according to claim 8, wherein the third determining module (603) is configured to determine a diagram structure of the OT network, cluster the graph structure to obtain a cluster graph, the cluster graph comprises a cluster node and a cluster edge, wherein the cluster node corresponds to a cluster of devices, and the cluster edge corresponds to a connection between clusters, determine a feature vector of the cluster node based on feature vectors of respective devices in the cluster and the first weights of the respective devices; determine a feature vector of the cluster edge based on feature vectors of respective connections with respective devices in an adjacent cluster and the second weights of the respective connections; determine a feature vector of the OT network based on the feature vector of the cluster node and the feature vector of the cluster edge.12.An electronic device, comprising a processor (701) and a memory (702) , wherein an application program executable by the processor (701) is stored in the memory (702) for causing the processor (701) to execute a method for detecting anomaly in an OT network according to any one of claims 1-7.13.A computer-readable medium comprising computer-readable instructions stored thereon, wherein the computer-readable instructions for executing a method for detecting anomaly in an OT network according to any one of claims 1-7.14.A computer program product comprising a computer program, upon the computer program is executed by a processor for executing a method for detecting anomaly in an OT network according to any one of claims 1-7.

Citation Information

Patent Citations

  • Method and system for checking abnormal optical network unit in passive optical network

    CN113747274A

  • Industrial control network abnormal behavior detection method and system

    CN114124445A

  • Abnormal behavior detection method and device, electronic equipment and storage medium

    CN117729027A

  • Abnormality detection device, abnormality detection method, and abnormality detection program

    JP2024079965A

  • Systems and methods for analyzing and controlling network traffic

    US20240223580A1