The invention belongs to the field of industrial control safety, provides a PLC (
programmable logic controller)
memory behavior analysis-based
control system configuration logic
anomaly detection method, and solves the problems of logic
attack detection blind areas, incomplete detection coverage, process semantic deficiency and the like caused by hidden attacks (modifying PLC
control logic through a legal
programming interface). The method comprises the following steps: S1, collecting a PLC register with a
timestamp and a coil
state sequence; s2, identifying a key
memory address, constructing an address cluster set, and supporting event completion and
process mining; s3, generating an XES standard event log by adopting a clustering and symbol back-pushing method; s4, improving a
Heuristics Miner
algorithm, automatically identifying a starting point and an end point of a
control flow, and constructing a
dependency graph with an identifier; s5, converting the
control logic into a formalized model, and defining a legal state transition sequence; and S6, monitoring a real-time
event stream on line, mapping the real-time
event stream to the model and dynamically playing back the real-time
event stream, and realizing
anomaly detection by combining track alignment and comparison. The method is complete in coverage, clear in
semantics, capable of tracing
attack paths and capable of improving the defense capability of a logic layer.