信息网络安全 ›› 2026, Vol. 26 ›› Issue (8): 1224-1236.doi: 10.3969/j.issn.1671-1122.2026.08.005

• 学术研究 • 上一篇    下一篇

抗APT窃密的工业互联网跨域协同零信任模型

冯景瑜, 尹静怡(), 张森勇, 李静慧   

  1. 西安邮电大学无线网络安全技术国家工程研究中心西安 710121
  • 收稿日期:2026-01-15 出版日期:2026-08-10 发布日期:2026-09-23
  • 通讯作者: 尹静怡 E-mail:203936711@qq.com
  • 作者简介:冯景瑜(1984—),男,甘肃,教授,博士,CCF会员,主要研究方向为物联网安全、区块链、网络防御|尹静怡(2001—),女,甘肃,硕士研究生,主要研究方向为工业互联网安全|张森勇(2002—),男,河南,硕士研究生,主要研究方向为漏洞检测|李静慧(2002—),女,河南,硕士研究生,主要研究方向为物联网安全
  • 基金资助:
    国家自然科学基金(62572392);陕西省重点研发计划(2024GX-YBXM-076)

Cross-domain collaborative zero-trust model for industrial Internet to counter APT data theft

Feng Jingyu, Yin Jingyi(), Zhang Senyong, Li Jinghui   

  1. National Engineering Research Center for Wireless Security, Xi’an University of Posts and Telecommunications, Xi’an 710121, China
  • Received:2026-01-15 Online:2026-08-10 Published:2026-09-23
  • Contact: Yin Jingyi E-mail:203936711@qq.com

摘要:

随着信息技术和工控系统的融合日益紧密,高级持续性威胁(APT)对工业互联网造成的敏感数据泄露问题愈发严重。然而,现有APT窃密防御技术主要集中在工业互联网信息技术(IT)域,忽视了突破IT域侧防护后渗透进运营技术(OT)域的APT窃密跨域威胁。针对这一挑战,文章提出一种抗APT窃密的工业互联网跨域协同零信任模型。首先,设计跨域协同的软件定义边界(SDP)零信任组件部署方案,对IT域和OT域的行为数据进行同步关注,避免因单域数据缺失导致的威胁漏判,并对行为数据进行归一化特征处理,构建差异化动态信任评估模型;然后,引入BiLSTM-MultiHead Attention模型捕捉APT跨域行为时序依赖关系,构建突变因子预测方案,实现对失陷终端行为的快速响应和信任值动态调节。在此基础上,设计跨域协同决策与失陷判别算法,对失陷终端进行判别和及时阻断。实验结果表明,文章所提模型在CMU-CERT数据集上对APT窃密跨域威胁表现出较好的协同防御性能,突变因子预测精确率达99.81%,实现对失陷终端的有效识别。

关键词: 工业互联网, APT窃密, SDP, 差异化动态信任评估

Abstract:

With the increasing integration of information technology and industrial control systems, advanced persistent threat (APT) have caused increasingly severe sensitive data leaks in the industrial Internet. However, current APT theft defenses have mainly focused on the information technology (IT) domain of the industrial Internet, neglecting cross-domain threats that penetrate into the operational technology (OT) domain after bypassing IT domain defenses. To address this challenge, this paper proposed a cross-domain collaborative zero-trust model for industrial Internet to counter APT data theft. First, a deployment scheme for cross-domain collaborative software defined perimeter (SDP) zero-trust components was designed to simultaneously monitor behavioral data from both IT and OT domains, thereby avoiding missed threat detection caused by insufficient data from a single domain, the behavioral data were normalized and feature-processed to construct a differentiated dynamic trust assessment model. After that, the BiLSTM-MultiHead Attention model was introduced to capture the temporal dependencies of APT cross-domain behaviors, and a mutation factor prediction scheme was developed to enable rapid responses to compromised terminal behaviors and dynamic adjustments of trust values. Furthermore, a cross-domain collaborative decision-making and compromise detection algorithm was designed to identify and promptly block compromised terminals. Experimental results show that the proposed model demonstrates better collaborative defense performance against APT cross-domain threats on the CMU-CERT dataset, with a mutation factor prediction precision of 99.81%, enabling effective identification of compromised terminals.

Key words: industrial Internet, APT data theft, SDP, differentiated dynamic trust assessment

中图分类号: