CN113452716A - PROFIBUS industrial control protocol safety ferrying method and device - Google Patents

PROFIBUS industrial control protocol safety ferrying method and device Download PDF

Info

Publication number
CN113452716A
CN113452716A CN202110731337.XA CN202110731337A CN113452716A CN 113452716 A CN113452716 A CN 113452716A CN 202110731337 A CN202110731337 A CN 202110731337A CN 113452716 A CN113452716 A CN 113452716A
Authority
CN
China
Prior art keywords
profibus
data packet
new
protocol
industrial control
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202110731337.XA
Other languages
Chinese (zh)
Inventor
崔逸群
毕玉冰
杨东
曾荣汉
刘超飞
胥冠军
朱博迪
邓楠轶
吕珍珍
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Xian Thermal Power Research Institute Co Ltd
Original Assignee
Xian Thermal Power Research Institute Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Xian Thermal Power Research Institute Co Ltd filed Critical Xian Thermal Power Research Institute Co Ltd
Priority to CN202110731337.XA priority Critical patent/CN113452716A/en
Publication of CN113452716A publication Critical patent/CN113452716A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0236Filtering by address, protocol, port number or service, e.g. IP-address or URL
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/22Parsing or analysis of headers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/26Special purpose or proprietary protocols or architectures

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a PROFIBUS industrial control protocol safety ferrying method and a device, comprising the following steps: the method comprises the steps that a PROFIBUS request data packet initiated by an upper network is received through a network interface, a PROFIBUS protocol is preprocessed and scheduled, and the functions of online loading and unloading, starting and closing are realized under the condition that a system is not restarted; disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to an intranet target; receiving a new PROFIBUS request data packet, and sending a PROFIBUS response data packet; receiving a PROFIBUS response data packet, disassembling, analyzing, filtering and packaging, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session. The invention realizes the upper and lower network session isolation of the PROFIBUS protocol of the industrial control system, processes data in a time-sharing way, reduces the data exchange delay and reduces the influence on the efficiency of the industrial control system.

Description

PROFIBUS industrial control protocol safety ferrying method and device
Technical Field
The invention belongs to the technical field of industrial control network safety, and particularly relates to a PROFIBUS industrial control protocol safety ferrying method and device.
Background
The Process field bus (Process Fieldbus) is an industrial control data protocol that has been rapidly developed in recent years, and mainly solves the problem of digital communication between field devices such as intelligent instruments, controllers, and actuators in an industrial field and the problem of information transfer between these field control devices and advanced control systems. The field bus has received a great deal of attention from many standards bodies and computer manufacturers because of a series of outstanding advantages, such as simplicity, reliability, economy and practicality.
With the large application of field bus protocols such as PROFIBUS in the field of industrial control, industrial control systems are opened from the initial closed state, interconnected from a single machine, and intelligentized from automation. While industrial enterprises obtain huge development kinetic energy, a great deal of potential safety hazards also appear. The application of the PROFIBUS industrial control protocol in the industrial control field is open and transparent, and the PROFIBUS industrial control protocol has certain programming vulnerability and is easy to be attacked by a network like all industrial control protocols. At present, most of firewalls and isolation gatekeepers used in the industrial control field are designed aiming at a TCP/IP protocol, and no good method for safely filtering the PROFIBUS industrial control protocol exists.
Disclosure of Invention
Aiming at the technical problems, the invention provides a method and a device for safety ferry of a PROFIBUS industrial control protocol, which realize the upper and lower network session isolation of the PROFIBUS protocol of an industrial control system, process data in a time-sharing manner, reduce the data exchange delay and reduce the influence on the efficiency of the industrial control system.
The invention is realized by adopting the following technical scheme:
a safety ferry method of a PROFIBUS industrial control protocol comprises the following steps:
s1, a PROFIBUS request data packet initiated by an upper network is received through a network interface, a PROFIBUS protocol is preprocessed and scheduled, and the functions of online loading and unloading, starting and closing are realized under the condition that the system is not restarted;
s2, disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to the intranet target;
s3, receiving a new PROFIBUS request data packet, and sending a PROFIBUS response data packet;
s4, receiving the PROFIBUS response data packet, disassembling, analyzing, filtering and packaging, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
A further improvement of the present invention is that step S2 specifically includes:
disassembling and recombining the PROFIBUS request data packet into an industrial control protocol data packet;
analyzing the industrial control protocol data packet, and extracting key fields;
matching the key fields based on the filtering rules and the strategy to realize the filtering of the instructions of reading, writing and controlling; the filtering is completed according to the information of the function code register;
and repackaging the allowed industrial control protocol data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to the intranet target.
The invention is further improved in that the method further comprises the step of recording all security events during protocol processing, and realizing real-time alarm.
A further improvement of the present invention is that step S4 specifically includes:
s41, disassembling and recombining the PROFIBUS response data packet to form a PROFIBUS protocol data packet;
s42, analyzing the PROFIBUS protocol data packet and extracting key fields;
s43, matching the key fields based on the filtering rules and the strategy to realize the filtering of the feedback and control instructions;
and S44, repackaging the allowed PROFIBUS protocol data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network.
A PROFIBUS industrial control protocol safety ferry device includes:
the system comprises a preprocessing module, a network interface and a control module, wherein the preprocessing module is used for receiving a PROFIBUS request data packet initiated by an upper network through the network interface, preprocessing and scheduling a PROFIBUS protocol, and realizing the functions of online loading and unloading, starting and closing under the condition of not restarting the system;
the protocol processing module is used for disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to an intranet target;
the lower-layer network module is used for receiving a new PROFIBUS request data packet and sending a PROFIBUS response data packet;
the protocol processing module is used for receiving the PROFIBUS response data packet, disassembling, analyzing, filtering and packaging the PROFIBUS response data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
The invention is further improved in that the protocol processing module has functions of constructing a session, truncating the session, and analyzing and processing a protocol.
A further development of the invention is that the protocol processing module comprises:
the decapsulation sub-module is used for disassembling and reconstructing the PROFIBUS response data packet to form a PROFIBUS protocol data packet;
the analysis submodule is used for analyzing the PROFIBUS protocol data packet and extracting key fields;
the filtering submodule is used for matching the key fields based on the filtering rules and the strategies to filter the feedback instructions and the control instructions;
and the encapsulation submodule is used for repackaging the allowed PROFIBUS protocol data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network.
A PROFIBUS industrial control protocol safety ferry system comprises: the system comprises a processor and a memory coupled with the processor, wherein the memory stores a computer program, and the computer program realizes the steps of the PROFIBUS industrial control protocol safety ferry method when being executed by the processor.
The invention has at least the following beneficial technical effects:
according to the PROFIBUS industrial control network safety filtering method and device based on the bidirectional ferry mechanism, provided by the invention, on the premise that the network structure of an industrial control system is not changed and production is not influenced, the safety protection of the PROFIBUS industrial control protocol is realized, and the potential threat aiming at the PROFIBUS protocol is blocked, so that the network safety level of the industrial control system taking the PROFIBUS protocol as the core is improved at lower cost.
Drawings
FIG. 1 is a flow chart of the steps;
fig. 2 is a functional diagram of a protocol processing module.
Fig. 3 is a schematic block diagram of a safety ferry method of a PROFIBUS industrial control protocol based on a ferry mode.
Detailed Description
Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be embodied in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. It should be noted that the embodiments and features of the embodiments may be combined with each other without conflict. The present invention will be described in detail below with reference to the embodiments with reference to the attached drawings.
As shown in fig. 1, the method for secure ferry of PROFIBUS industrial control protocol provided by the present invention includes the following steps:
s1, a PROFIBUS request data packet initiated by an upper network is received through a network interface, a PROFIBUS protocol is preprocessed, and the preprocessed PROFIBUS protocol is dispatched to a protocol processing module; the system is used for realizing online loading and unloading and starting and closing functions under the condition of not restarting the system; the protocol processing module, as shown in fig. 2, includes functions of constructing a session, truncating the session, and protocol analysis processing.
S2, the protocol processing module disassembles, analyzes, filters and encapsulates the PROFIBUS request data packet, constructs a new PROFIBUS request data packet and sends the new PROFIBUS request data packet to the intranet target;
s3, the lower layer network module receives the new PROFIBUS request data packet and sends a PROFIBUS response data packet;
s4, the protocol processing module receives the PROFIBUS response data packet, and performs disassembly, analysis, filtration and encapsulation to construct a new PROFIBUS response data packet and send the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
The step S4 specifically includes:
s41, disassembling and recombining the PROFIBUS response data packet to form a PROFIBUS protocol data packet;
s42, analyzing the PROFIBUS protocol data packet and extracting key fields;
s43, matching the key fields based on the filtering rules and the strategy to realize the filtering of the feedback and control instructions;
and S44, repackaging the allowed PROFIBUS protocol data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network.
The principle of the ferry mode-based filtering method of the invention is shown in fig. 3: when the system receives a PROFIBUS request 1 initiated by an upper layer network, the PROFIBUS session is cut off on a transmission layer, PROFIBUS industrial control protocol data is stripped, the PROFIBUS industrial control protocol data is packaged into a new PROFIBUS session after being processed, and a PROFIBUS request 2 is sent to a lower layer network. When the system receives the response from the lower network to the PROFIBUS request 2, the system truncates the response and reconstructs a new PROFIBUS session at the other end so as to complete the response to the PROFIBUS session 1. Therefore, the upper layer network and the lower layer network can not be synchronized, no direct PROFIBUS session exists, an isolation mechanism is formed, and data delay is small.
The invention provides a PROFIBUS industrial control protocol safety ferrying device, which comprises:
the system comprises a preprocessing module, a network interface and a control module, wherein the preprocessing module is used for receiving a PROFIBUS request data packet initiated by an upper network through the network interface, preprocessing and scheduling a PROFIBUS protocol, and realizing the functions of online loading and unloading, starting and closing under the condition of not restarting the system;
the protocol processing module is used for disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to an intranet target;
the lower-layer network module is used for receiving a new PROFIBUS request data packet and sending a PROFIBUS response data packet;
the protocol processing module is used for receiving the PROFIBUS response data packet, disassembling, analyzing, filtering and packaging the PROFIBUS response data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
The invention provides a PROFIBUS industrial control protocol safety ferrying system, which comprises: the system comprises a processor and a memory coupled with the processor, wherein the memory stores a computer program, and the computer program realizes the steps of the PROFIBUS industrial control protocol safety ferry method when being executed by the processor.
As will be appreciated by one skilled in the art, embodiments of the present application may be provided as a method, system, or computer program product. Accordingly, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, and the like) having computer-usable program code embodied therein.
The present application is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the application. It will be understood that each flow and/or block of the flow diagrams and/or block diagrams, and combinations of flows and/or blocks in the flow diagrams and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means which implement the function specified in the flowchart flow or flows and/or block diagram block or blocks.
These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart flow or flows and/or block diagram block or blocks.
The foregoing is a preferred embodiment of the present invention, and it should be noted that it is obvious to those skilled in the art that various modifications can be made without departing from the principle of the present invention, and these modifications should be construed as the protection scope of the present invention.

Claims (8)

1. A safety ferrying method for a PROFIBUS industrial control protocol is characterized by comprising the following steps:
s1, a PROFIBUS request data packet initiated by an upper network is received through a network interface, a PROFIBUS protocol is preprocessed and scheduled, and the functions of online loading and unloading, starting and closing are realized under the condition that the system is not restarted;
s2, disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to the intranet target;
s3, receiving a new PROFIBUS request data packet, and sending a PROFIBUS response data packet;
s4, receiving the PROFIBUS response data packet, disassembling, analyzing, filtering and packaging, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
2. The PROFIBUS industrial control protocol safety ferry method of claim 1, wherein step S2 specifically includes:
disassembling and recombining the PROFIBUS request data packet into an industrial control protocol data packet;
analyzing the industrial control protocol data packet, and extracting key fields;
matching the key fields based on the filtering rules and the strategy to realize the filtering of the instructions of reading, writing and controlling; the filtering is completed according to the information of the function code register;
and repackaging the allowed industrial control protocol data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to the intranet target.
3. The PROFIBUS industrial control protocol safety ferry method according to claim 2, further comprising a step of recording all safety events during protocol processing, and implementing real-time alarm.
4. The PROFIBUS industrial control protocol safety ferry method of claim 1, wherein step S4 specifically includes:
s41, disassembling and recombining the PROFIBUS response data packet to form a PROFIBUS protocol data packet;
s42, analyzing the PROFIBUS protocol data packet and extracting key fields;
s43, matching the key fields based on the filtering rules and the strategy to realize the filtering of the feedback and control instructions;
and S44, repackaging the allowed PROFIBUS protocol data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network.
5. The utility model provides a PROFIBUS industrial control agreement safety ferry device which characterized in that includes:
the system comprises a preprocessing module, a network interface and a control module, wherein the preprocessing module is used for receiving a PROFIBUS request data packet initiated by an upper network through the network interface, preprocessing and scheduling a PROFIBUS protocol, and realizing the functions of online loading and unloading, starting and closing under the condition of not restarting the system;
the protocol processing module is used for disassembling, analyzing, filtering and packaging the PROFIBUS request data packet, constructing a new PROFIBUS request data packet and sending the new PROFIBUS request data packet to an intranet target;
the lower-layer network module is used for receiving a new PROFIBUS request data packet and sending a PROFIBUS response data packet;
the protocol processing module is used for receiving the PROFIBUS response data packet, disassembling, analyzing, filtering and packaging the PROFIBUS response data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network; for the purpose of making the upper and lower nets unsynchronized without a direct PROFIBUS session.
6. The PROFIBUS industrial control protocol safety ferry device of claim 5, wherein the protocol processing module has functions of session construction, session truncation and protocol analysis processing.
7. The PROFIBUS industrial control protocol safety ferry device of claim 5, wherein the protocol processing module comprises:
the decapsulation sub-module is used for disassembling and reconstructing the PROFIBUS response data packet to form a PROFIBUS protocol data packet;
the analysis submodule is used for analyzing the PROFIBUS protocol data packet and extracting key fields;
the filtering submodule is used for matching the key fields based on the filtering rules and the strategies to filter the feedback instructions and the control instructions;
and the encapsulation submodule is used for repackaging the allowed PROFIBUS protocol data packet, constructing a new PROFIBUS response data packet and sending the new PROFIBUS response data packet to an upper network.
8. The utility model provides a PROFIBUS industrial control agreement safety ferry-boat system which characterized in that includes: the system comprises a processor and a memory coupled with the processor, wherein the memory stores a computer program, and the computer program realizes the steps of the PROFIBUS industrial control protocol safety ferry method when being executed by the processor.
CN202110731337.XA 2021-06-29 2021-06-29 PROFIBUS industrial control protocol safety ferrying method and device Pending CN113452716A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202110731337.XA CN113452716A (en) 2021-06-29 2021-06-29 PROFIBUS industrial control protocol safety ferrying method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202110731337.XA CN113452716A (en) 2021-06-29 2021-06-29 PROFIBUS industrial control protocol safety ferrying method and device

Publications (1)

Publication Number Publication Date
CN113452716A true CN113452716A (en) 2021-09-28

Family

ID=77814203

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202110731337.XA Pending CN113452716A (en) 2021-06-29 2021-06-29 PROFIBUS industrial control protocol safety ferrying method and device

Country Status (1)

Country Link
CN (1) CN113452716A (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102088444A (en) * 2009-12-03 2011-06-08 北京华控技术有限责任公司 PROFIBUS DP and PROFIBUS PA protocol conversion gateway module
CN102984170A (en) * 2012-12-11 2013-03-20 清华大学 System and method for safe filtering of industrial control network
CN105656883A (en) * 2015-12-25 2016-06-08 冶金自动化研究设计院 Unidirectional transmission internal and external network secure isolating gateway applicable to industrial control network
CN110943913A (en) * 2019-07-31 2020-03-31 广东互动电子网络媒体有限公司 Industrial safety isolation gateway

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102088444A (en) * 2009-12-03 2011-06-08 北京华控技术有限责任公司 PROFIBUS DP and PROFIBUS PA protocol conversion gateway module
CN102984170A (en) * 2012-12-11 2013-03-20 清华大学 System and method for safe filtering of industrial control network
CN105656883A (en) * 2015-12-25 2016-06-08 冶金自动化研究设计院 Unidirectional transmission internal and external network secure isolating gateway applicable to industrial control network
CN110943913A (en) * 2019-07-31 2020-03-31 广东互动电子网络媒体有限公司 Industrial safety isolation gateway

Similar Documents

Publication Publication Date Title
EP1816530B1 (en) Extending industrial control system communications capabilities
CN101882165B (en) Multithreading data processing method based on ETL (Extract Transform Loading)
CN105278398B (en) Operator action certification in industrial control system
CN105807631B (en) Industry control intrusion detection method and intruding detection system based on PLC emulation
EP3002649B1 (en) Industrial simulation using redirected i/o module configurations
CN102497395A (en) Breakpoint unloading application control method
CN103179039A (en) Method for effectively filtering normal network data package
CN113542263B (en) Firewall policy migration method and device
CN110995678A (en) Industrial control network-oriented efficient intrusion detection system
CN103078938A (en) Remote access control system and method
WO2021038527A1 (en) Systems and methods for enhancing data provenance by logging kernel-level events
Marsal et al. Evaluation of response time in Ethernet-based automation systems
CN113452716A (en) PROFIBUS industrial control protocol safety ferrying method and device
CN110376957B (en) PLC (programmable logic controller) safety event evidence obtaining method based on automatic construction of safety protocol
CN110266735A (en) Industry communications protocol white list access control based on timing
CN102377506A (en) Test message processing system
TW200305322A (en) Architecture and run-time environment for network filter drivers
CN109241157A (en) Data calling method, device, communication equipment and storage medium
CN108833333A (en) A kind of honey pot system based on DCS distributed AC servo system
CN105786450A (en) Bidding document file import method and device
CN1960273A (en) Method for dynamic real time capturing logic commands input from UNIX terminal user
CN115086084A (en) Safety isolation and information exchange system and method
Tai et al. Synthesis of the supremal covert attacker against unknown supervisors by using observations
CN110069042B (en) Production flow process control method, device, software system and control system
CN115378825B (en) Interactive simulation system and method based on application layer industrial control protocol analysis

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20210928

RJ01 Rejection of invention patent application after publication