Netinfo Security ›› 2026, Vol. 26 ›› Issue (8): 1224-1236.doi: 10.3969/j.issn.1671-1122.2026.08.005

Previous Articles     Next Articles

Cross-domain collaborative zero-trust model for industrial Internet to counter APT data theft

Feng Jingyu, Yin Jingyi(), Zhang Senyong, Li Jinghui   

  1. National Engineering Research Center for Wireless Security, Xi’an University of Posts and Telecommunications, Xi’an 710121, China
  • Received:2026-01-15 Online:2026-08-10 Published:2026-09-23
  • Contact: Yin Jingyi E-mail:203936711@qq.com

Abstract:

With the increasing integration of information technology and industrial control systems, advanced persistent threat (APT) have caused increasingly severe sensitive data leaks in the industrial Internet. However, current APT theft defenses have mainly focused on the information technology (IT) domain of the industrial Internet, neglecting cross-domain threats that penetrate into the operational technology (OT) domain after bypassing IT domain defenses. To address this challenge, this paper proposed a cross-domain collaborative zero-trust model for industrial Internet to counter APT data theft. First, a deployment scheme for cross-domain collaborative software defined perimeter (SDP) zero-trust components was designed to simultaneously monitor behavioral data from both IT and OT domains, thereby avoiding missed threat detection caused by insufficient data from a single domain, the behavioral data were normalized and feature-processed to construct a differentiated dynamic trust assessment model. After that, the BiLSTM-MultiHead Attention model was introduced to capture the temporal dependencies of APT cross-domain behaviors, and a mutation factor prediction scheme was developed to enable rapid responses to compromised terminal behaviors and dynamic adjustments of trust values. Furthermore, a cross-domain collaborative decision-making and compromise detection algorithm was designed to identify and promptly block compromised terminals. Experimental results show that the proposed model demonstrates better collaborative defense performance against APT cross-domain threats on the CMU-CERT dataset, with a mutation factor prediction precision of 99.81%, enabling effective identification of compromised terminals.

Key words: industrial Internet, APT data theft, SDP, differentiated dynamic trust assessment

CLC Number: