Chinese Journal of Network and Information Security ›› 2022, Vol. 8 ›› Issue (3): 169-175.doi: 10.11959/j.issn.2096-109x.2022032

• Papers • Previous Articles     Next Articles

Defense strategy of industrial control worm based on SEIPQR model

Jie PAN1, Lan YE2, He ZHAO3, Xinlei ZHANG3   

  1. 1 China Mobile Group Design Institute Co., Ltd., Beijing 100080, China
    2 China Mobile Group, Beijing 100032, China
    3 China Mobile Procurement Shared Service Center, Beijing 100053, China
  • Revised:2022-03-04 Online:2022-06-15 Published:2022-06-01

Abstract:

Computer viruses keep evolving with the development of society and progress of technologies, and they become more complex and hidden.The worm virus is the earliest computer virus, which has evolved to an industrial control worm virus and caused a great impact on the safety of the industrial system.Neither the single network isolation nor the patching immunity is unable to keep up with the spreading of the worm virus.The propagation mode and characteristics of the worm virus in the industrial control system were analyzed.Based on the related works of network isolation and patching, a defense strategy against the worm virus was proposed.This strategy was originated from the fundamental infectious disease model, and then a mathematics model (SEIPQR) was proposed to simulate the trend of worm virus propagation.The model included six situations: Susceptible, Exposed, Infected, Quarantine and Recovered.The state transition diagrams of the model was created, and the calculus equations were obtained from the state transition diagrams.Under the condition that the number of system equipment is fixed, the equations were transformed.The equations were solved by solving the basic regeneration number R0, and six equation expressions of the model ware analyzed when the number of exposed hosts and infected hosts is zero.According to the principle of the Routh-Hurwitz, the system is asymptotically stable when R0<1, and unstable if R0>1.Then the dynamic characteristics of the SEIPQR model under different patching probability, different isolation rate and different infection rate were compared by numerical simulation.Furthermore, the disease-free equilibrium point and endemic equilibrium point of the model were obtained.The simulation results showed that, when the whole system is infected with worm virus, timely patching the susceptible devices and isolating the network can effectively inhibit the spread of industrial control worm virus.

Key words: industrial control network, industrial control worm, epidemic model, numerical simulation

CLC Number: 

No Suggested Reading articles found!