Font Size: a A A

Research On Key Technology Of Reverse Analysis Of Unknown Industrial Control Protocol

Posted on:2022-01-11Degree:MasterType:Thesis
Country:ChinaCandidate:W J ZhongFull Text:PDF
GTID:2518306488493924Subject:Electronics and Communications Engineering
Abstract/Summary:PDF Full Text Request
The Industrial Internet is an important cornerstone of the fourth industrial revolution.It can realize the unified combination of factors such as machine factory warehouses,assembly lines,equipment,production workers,and customer service in the industrial control system to improve production efficiency and reduce costs.In this process,due to the use of private protocols(unknown industrial control protocols)that are not disclosed to the public by some manufacturers' equipment,it is impossible to achieve collaboration between different manufacturers' equipment,and it is impossible to complete the full network of the factory.To this end,this thesis is based on the information entropy of the protocol,combined with image recognition and other technologies,to complete the classification of unknown industrial control protocols,the extraction of protocol format and semantic inference,and the semantic recognition of key fields,as follows:First of all,to realize the classification of Fieldbus protocol and industrial Ethernet protocol in industrial control protocol,this thesis proposes an industrial control protocol frame encapsulation header identification method,by introducing a statistical model into the matching algorithm to find candidate frequent items and using correlation analysis algorithm to filter errors Item,identifying the industrial control protocol encapsulation header.Experiments on 9 kinds of industrial control protocols show that the accuracy of the algorithm's recognition rate reaches 100%.Secondly,to reversely analyze unknown industrial control protocols,algorithms for format extraction,field type inference,and semantic inference are proposed.According to the frame format characteristics of the Fieldbus protocol and the industrial Ethernet protocol,the corresponding format extraction algorithm is used to extract the protocol format,and the field type or field semantics of each segment in the protocol format is inferred through the heuristic algorithm of traversing the field type and semantic inference.Without prior knowledge,experiments were conducted on 5industrial Ethernet protocols and 3 Fieldbus protocols.The correct rate of format extraction reached 89.6%,and the field type and semantic inference rate reached 92.3%.Finally,to obtain the semantics and location of the key fields of the industrial control protocol,the semantic inference of the key fields of the industrial control protocol based on machine vision is proposed,and the key semantics of the industrial control protocol is inferred by combining the protocol interaction data and the visual picture data generated during the interaction process of the field devices.Location.This thesis verifies the Modbus-RTU protocol that carries different key information generated in different interaction processes on the industrial control experimental platform built,and the results show that the method can obtain the semantics and positions of the key fields of the industrial control protocol.The research results of this thesis not only have important practical significance for realizing the interconnection and intercommunication of all equipment in the factory and realizing the intelligent upgrade of the factory but also have important guiding value for improving the security of the industrial Internet.
Keywords/Search Tags:Protocol reverse analysis, unknown industrial control protocol, format extraction, semantic inference, key field semantics
PDF Full Text Request
Related items