大数据 ›› 2023, Vol. 9 ›› Issue (4): 98-115.doi: 10.11959/j.issn.2096-0271.2023051

• 专题:跨域数据管理 • 上一篇    

Argus:基于多源数据驱动的工控安全态势感知系统

朱天晨1,2, 赵军3, 李博1,2,4, 李建欣1,2,4   

  1. 1 北京航空航天大学计算机学院,北京 100191
    2 北京市大数据与脑机智能高精尖中心(北京航空航天大学),北京 100191
    3 山东师范大学信息科学与工程学院,山东 济南 250358
    4 中关村实验室,北京 100191
  • 出版日期:2023-07-01 发布日期:2023-07-01
  • 作者简介:朱天晨(1996- ),男,北京航空航天大学计算机学院博士生,主要研究方向为大数据分析与处理、强化学习、序列决策等
    赵军(1989- ),男,博士,山东师范大学信息科学与工程学院讲师,主要研究方向为工业控制系统安全、网络威胁情报、图神经网络
    李博(1980- ),男,博士,北京航空航天大学计算机学院副研究员,北京市大数据科学与脑机智能高精尖中心高级研究员,主要研究方向为网络安全、工业互联网、大数据安全等
    李建欣(1979- ),男,博士,北京航空航天大学计算机学院教授、党委书记,北京市大数据科学与脑机智能高精尖创新中心研究员,主要研究方向为大数据分析与处理、机器学习和可信计算等
  • 基金资助:
    国家自然科学基金资助项目(U20B2053)

Argus: multi-source data-driven industrial control security situational awareness system

Tianchen ZHU1,2, Jun ZHAO3, Bo LI1,2,4, Jianxin LI1,2,4   

  1. 1 School of Computer Science and Engineering, Beihang University, Beijing 100191, China
    2 Beijing Advanced Innovation Center for Big Data and Brain Computing, Beijing 100191, China
    3 School of Information Science and Engineering, Shandong Normal University, Jinan 250358, China
    4 Zhongguancun Laboratory, Beijing 100191, China
  • Online:2023-07-01 Published:2023-07-01
  • Supported by:
    The National Natural Science Foundation of China(U20B2053)

摘要:

工业控制(工控)系统是国家工业制造与民用基础设施的“大脑”,近年来安全风险日益突出,已成为网络安全中的重点防护目标。针对工控安全数据分散、威胁感知滞后的问题,设计了多源数据驱动的工控安全态势感知系统Argus,提出了工控安全感知链,研发了无状态极速设备扫描、威胁情报精准提取、可疑攻击行为检测等工控安全态势自主感知技术,实现了多通道、立体式工控安全监测与态势感知。实验结果显示,相比传统工控安全态势感知方法,Argus系统的感知精度提升超过10%,效率提升两个数量级,并可前摄性地预警、缓解潜在安全风险。

关键词: 工业控制系统, 多源数据融合, 态势感知, 威胁情报

Abstract:

Industrial control system (ICS) is the brain of national industrial manufacturing and civil infrastructure.However, the security risks associated with ICS have become increasingly prominent, making it a significant target for cybersecurity protection.This paper proposed a solution for the issues associated with ICS security data dispersion and delayed threat perception.Specifically, the paper presented a multi-source data-driven ICS security situational awareness system named Argus, which incorporated an awareness chain for ICS security.Furthermore, the paper developed autonomous situational awareness technologies for ICS security, such as stateless high-speed device scanning, precise threat intelligence extraction, and suspicious attack behavior detection, to achieve multi-channel and three-dimensional ICS security monitoring and situational awareness.The experimental results indicated that, compared with conventional ICS situational awareness methods, the perception accuracy of the Argus system has improved by over 10%, with efficiency improvements by two orders of magnitude.Additionally, Argus allows for proactive warning and mitigation of potential security risks.

Key words: industrial control system, multi-source data fusion, situation awareness, threat intelligence

中图分类号: 

No Suggested Reading articles found!