The invention relates to an
industrial control system anomaly detection method based on a dual-contour model. Involved industrial
control network equipment comprises a security gateway, a
programmable logic controller (PLC), onsite sensor equipment, a
security management platform, and an engineer
station. The method comprises the following steps of S1, the engineer
station configures and operates a
system, the PLC of each region discriminates controlled equipment connected to an IP module of the PLC, an information
list is distributed to the controlled equipment, and a periodic communication mode is formed for master and slave stations; S2, the PLC timely feeds back
data information to the security gateway, a data packet deep analysis
system of the security gateway extracts data features and eliminates superfluous attribute features, and only features related to a
system behavior mode are left, wherein the features related to the system behavior mode comprises protocol features, data
packet transmission direction features and register value variation rules based on the communication frequency; and S3, an
anomaly detection subsystem carries out
anomaly detection and sends an alarm to the
security management platform for an abnormal result.