Industry Internet Security Detection via Rule Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The industry field lacks effective security measures for data transmission and information passing between field devices, leading to potential security risks and increased difficulty in managing diverse security mechanisms across different devices.
Innovation Solution
A method and apparatus for detecting security using an industry internet operating system, which involves obtaining and analyzing operating data from field devices, determining characteristic data information, generating security detection rules, and issuing target security detection rules to execution devices for comprehensive security detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If different security guaranteeing mechanisms are applied to different field devices, then security coverage is improved, but device complexity and management difficulty increase
Solution Approach 1:
The patent implements a unified security detection mechanism that can detect multiple types of security threats across different field devices using the same execution device and detection framework. The security detection rule is designed to be universal, capable of handling various security scenarios without requiring separate mechanisms for each device type, thus reducing management complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The patent segments the security detection function into distinct modules: operating data information acquisition, characteristic data information extraction, security detection rule generation, and execution device deployment. This segmentation allows each module to be independently optimized and managed, reducing overall system complexity while maintaining comprehensive security detection capability across multiple field devices.
2Reliability
If comprehensive security detection rules are applied to all field devices, then security reliability is improved, but processing resources are consumed
Solution Approach 1:
The patent extracts only the necessary characteristic data information from operating data information that is specific to security detection needs. Rather than processing all operating data, the system identifies and processes only the relevant portions (characteristic data) that are sufficient for security detection, thus reducing processing resource consumption while maintaining effective security detection capability.
Solution Approach 2:
The patent extracts characteristic data information from comprehensive operating data information. The execution device obtains only the essential security-related features from the full operating data set, separating the necessary security detection elements from the unnecessary data, thereby reducing processing overhead while preserving security detection effectiveness.
3Measurement precision
If security detection rules are generated for each field device individually, then detection precision is improved, but device complexity increases
Solution Approach 1:
The patent generates a universal security detection rule that can be applied across multiple field devices. The execution device is configured with this single rule that automatically adapts to different devices by extracting their specific characteristic data, eliminating the need to create and manage separate rules for each device while maintaining detection precision through device-specific characteristic extraction.
Data Source
Figure 1A
Figure 1B
Figure 2A
AI summary
The invention relates to the field of industry internet technologies, particularly to a method and apparatus for detecting security using an industry internet operating system so as to address problems in the prior art of poor security of field devices, and high difficulty of manipulating the field devices. In the method, security detection rules corresponding to respective field devices are obtained according to various heterogeneous and dispersed operating data information in an industry field acquired in real-time into a database, in a big-data analysis mode of an industry big-data analysis platform, and some of the security detection rules corresponding to the field devices are selected and then issued to execution devices to detect the field devices for security to guarantee controllable security in the industry field. In this way, industry data can be acquired, parsed, stored, mined, optimized, and secured in the big-data analysis mode, so that an industry and the field devices can operate in a trusted operating environment.