Intelligent question answering system special for electric power intranet
By designing an intelligent question-and-answer system dedicated to the power intranet, the security risks of the power intranet are solved, and the precise management of personnel information, enhanced identity verification, data encryption and real-time monitoring and processing of network security are achieved, which significantly improves the overall security of the power system.
Patent Information
- Application Number
- CN202510050371.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-06-03
AI Technical Summary
The power intranet has problems such as unsafe terminal access, confusing IP address management, system loopholes and illegal operation of data by personnel, resulting in data security risks.
Design an intelligent question-and-answer system dedicated to the power intranet, including account management module, personnel information collection module, identity verification module, data security management module, record management module, network security monitoring module, intrusion processing module and intrusion operation misleading module. Through these modules, precise management of personnel information in the power intranet, enhanced identity verification, data encryption and real-time monitoring and processing of network security.
It effectively solves the security risks of the power intranet, enhances the overall security of the system, prevents illegal access and operations, ensures the security of data transmission, and promptly responds to and curbs network security threats.
Smart Images

Figure CN120086326A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power intranet security, and relates to an intelligent question-and-answer system dedicated to the power intranet. Background Art
[0002] With the booming development of the economy, the power system, as one of the infrastructure of modern society, has been accelerating in its construction and development, and its supporting role for economic activities has become increasingly prominent. In this process, the wide application of information technology has undoubtedly provided strong support for the intelligent and efficient operation of the power system. However, the deep integration of information technology into the power intranet has also brought a series of security risks that cannot be ignored. If these risks are not effectively resolved, it will directly affect the normal operation of the enterprise, and further restrict the working efficiency of the power system.
[0003] The information security issue of the power intranet is of self-evident importance. It is not only a solid guarantee for the normal operation of the power system, but also the key to ensuring the stable and reliable power supply. Once the information security of the power intranet is threatened, it may lead to serious consequences such as data leakage and system paralysis, bringing great inconvenience to social and economic development and people's lives. However, the current information security situation of the power intranet is not optimistic: First, the terminal access is insecure, and some devices are connected to the intranet without strict authentication, providing opportunities for hackers to attack; Second, the IP address management is chaotic, lacking an effective address allocation and supervision mechanism, enabling attackers to easily find and attack the target system; Third, the system has vulnerabilities, and known security vulnerabilities are not repaired in time, facilitating the intrusion of malicious software; Fourth, some staff operate data illegally. Due to lack of security awareness or being driven by interests, some staff members perform illegal operations, resulting in data leakage or tampering. Summary of the Invention
[0004] Aiming at the problems existing in the prior art, the present invention provides an intelligent question-and-answer system dedicated to the power intranet, so as to solve the technical problem that the data of the power system has security risks due to insecure terminal access, chaotic IP addresses, system vulnerabilities and illegal operation of data by personnel in the prior art.
[0005] The present invention is realized through the following technical solutions: An intelligent question-and-answer system dedicated to the power intranet includes an account management module, a personnel information collection module, an identity verification module, a data security management module, a record management module, a network security monitoring module, an intrusion processing module, an intrusion operation misdirection module and a central control unit that communicate with each other; The account management module is used to manage the basic information, subordination relationship, special permissions and contact information of the personnel in the power intranet; The personnel information collection module is used to collect the biometric information of the personnel in the power intranet, and record the on-the-job status and location information of the personnel; The identity authentication module is used to conduct security questions and answers on the identity of the operator and the purpose of operating the device data, so as to authenticate the operator; The data security management module is used to encrypt the data and business information in the database, and manage the data transmission security; The record management module is used to record the instructions for personnel to operate the device, data modification behaviors and operator information, and generate operation logs; The network security monitoring module is used to monitor the network environment; The intrusion handling module is used to deal with network security threats; The intrusion operation misleading module is used to confuse the intruder, protect the real data, induce the upload of improper operation information to the security defense, and delay the intrusion progress.
[0006] Preferably, the biometric information of the personnel includes social identity information, voice, fingerprints and face features.
[0007] Preferably, the account management module includes an identity information management unit, a subordination relationship management unit, a special permission management unit and a contact information management unit. The identity information management unit is used to manage the basic identity information of the personnel related to the power intranet. The subordination relationship management unit is used to manage and associate the superior-subordinate relationship of the personnel. The special permission management unit is used to grant confidential permissions to the personnel and manage these personnel separately. The contact information management unit is used to manage the contact information of the personnel. The central control unit is used to control the hub connecting other units.
[0008] Preferably, the personnel information collection module includes a social identity collection unit, a voice information collection unit, a personnel fingerprint collection unit, a face information collection unit and a personnel status collection unit. The social identity collection unit is used to collect the social identity information of the personnel. The voice information collection unit is used to collect the voice information of the personnel and store it as the comparison basis for subsequent voice devices. The personnel fingerprint collection unit is used to collect the fingerprint information of the personnel and store it. The face information collection unit is used to collect the face information of the personnel and store it. The personnel status collection unit is used to collect the on-the-job status information and location information of the personnel.
[0009] Preferably, the identity authentication module includes an intelligent Q&A authentication unit, a voice authentication unit, a fingerprint authentication unit, a face authentication unit, and an auxiliary authentication unit. The intelligent Q&A authentication unit is used to conduct security Q&A on the identity of the personnel and the purpose of operating the device data for the isometry of the confidentiality of the device data operated by the personnel. The voice authentication unit is used to authenticate the voice of the personnel. The fingerprint authentication unit is used to authenticate the fingerprint of the personnel. The face authentication unit is used to verify the face of the personnel. The auxiliary authentication unit is used to contact relevant project personnel or superiors in the subordination relationship for operation confirmation.
[0010] Preferably, the data security management module includes a database encryption unit, a business security management unit, and a data transmission management unit. The database encryption unit is used to encrypt the data in the database. The business security management unit is used to encrypt the relevant information of the business. The data transmission management unit is used to conduct security management on remote data transmission, device interface transmission, and communication records. Preferably, the record management module includes an operation instruction record unit, a data modification record unit, and an operator record unit. The operation instruction record unit is used to record the instruction information of the personnel operating the device. The data modification record unit is used to record the operation of the personnel modifying the data. The operator record unit is used to collect the personnel information of the device operator and generate a log.
[0011] Preferably, the network security monitoring module includes an illegal external connection monitoring unit, a virus monitoring unit, and a malicious access monitoring unit. The illegal external connection monitoring unit is used to monitor whether the personnel connect to the external network without permission. The virus monitoring unit is used to detect and kill the viruses hidden in the data. The malicious access monitoring unit is used to monitor the dynamic information of malicious access to the internal network.
[0012] Preferably, the intrusion processing module includes a warning prompt unit, an emergency alarm unit, and an abnormal device isolation unit. The warning prompt unit is used to give warning prompts to the intruders and improper operators. The emergency alarm unit is used to automatically alarm and process the events of illegal operations. The abnormal device isolation unit is used to isolate the abnormal devices separately and track the location information of the devices.
[0013] Preferably, the intrusion operation misleading module includes a false data simulation unit, a false interface induction unit, an information collection induction unit, and a false progress delay unit. The false data simulation unit is used to simulate one or more similar pieces of data for real confidential information. The false interface induction unit is used to cover the real operation at the back end with a false front-end page. The information collection induction unit is used to induce personnel who perform improper operations to collect information and upload it to the security system. The false progress delay unit is used to establish a false and inefficient data transmission progress.
[0014] Compared with the prior art, the present invention has the following beneficial technical effects: The present invention discloses an intelligent question-answering system dedicated to the power intranet. Through the account management module and the personnel information collection module, the system can accurately manage the basic information, permissions, and biometric features of power intranet personnel, fundamentally solving the security risks caused by inaccurate personnel information or chaotic permission management. In particular, the collection of biometric information greatly improves the accuracy and security of identity verification. Secondly, the identity verification module verifies the operators in the form of security questions and answers to ensure that only authorized personnel can operate, effectively preventing illegal access and operations. This mechanism greatly enhances the security of the system and avoids the risks caused by illegal operation of data by personnel. Furthermore, the data security management module encrypts the data and business information in the database and manages the data transmission security at the same time, solving the possible leakage risks during data transmission. The application of encryption technology makes it impossible to easily interpret the data even if it is intercepted during transmission. In addition, the network security monitoring module and the intrusion processing module cooperate together to monitor the network environment in real time and respond to network security threats. Once abnormal behavior is detected, the intrusion processing module will be immediately activated, and through measures such as warning, alarming, and isolation, effectively curbing the spread of security threats. Finally, the application of the intrusion operation misleading module adds an additional layer of intelligent protection to the system. By confusing the intruder and inducing the upload of improper operation information to the security system, this module not only protects the security of real data but also greatly delays the intrusion progress, buying valuable time for the system administrator to respond to and handle security incidents. The intelligent question-answering system dedicated to the power intranet effectively solves the security risks and improves the overall security of the power system by comprehensively managing accounts and personnel information, strengthening identity verification, encrypting data security, and monitoring the network in real time. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0016] Figure 1 It is the system block diagram of the present invention; Figure 2 It is the block diagram of the account management module of the present invention; Figure 3 It is the block diagram of the personnel information collection module of the present invention; Figure 4 It is the block diagram of the identity verification module of the present invention; Figure 5 It is the block diagram of the data security management module of the present invention; Figure 6 It is the block diagram of the record management module of the present invention; Figure 7 It is the block diagram of the network security monitoring module of the present invention; Figure 8 It is the block diagram of the intrusion processing module of the present invention; Figure 9 It is the block diagram of the intrusion operation misdirection module of the present invention.
[0017] Among them, 1. Account management module; 2. Personnel information collection module; 3. Identity verification module; 4. Data security management module; 5. Record management module; 6. Network security monitoring module; 7. Intrusion processing module; 8. Intrusion operation misdirection module; 9. Central control unit; 10. Identity information management unit; 11. Subordination relationship management unit; 12. Special permission management unit; 13. Contact information management unit; 14. Social identity collection unit; 15. Voice information collection unit; 16. Personnel fingerprint collection unit; 17. Facial information collection unit; 18. Personnel status collection unit; 19. Intelligent question and answer verification unit; 20. Voice verification unit; 21. Fingerprint verification unit; 22. Facial verification unit; 23. Auxiliary verification unit; 24. Database encryption unit; 25. Business security management unit; 26. Data transmission management unit; 27. Operation instruction recording unit; 28. Data modification recording unit; 29. Operator recording unit; 30. Illegal external connection monitoring unit; 31. Virus monitoring unit; 32. Malicious access monitoring unit; 33. Warning prompt unit; 34. Emergency alarm unit; 35. Abnormal device isolation unit; 36. False data simulation unit; 37. False interface induction unit; 38. Information collection induction unit; 39. False progress delay unit. Specific implementation manners
[0018] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0019] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0020] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0021] In the description of the embodiments of the present invention, it should be noted that if terms such as "upper", "lower", "horizontal", "inner", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the invention product is usually placed during use, it is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation of the present invention. In addition, terms such as "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.
[0022] In addition, if the term "horizontal" appears, it does not mean that the component is required to be absolutely horizontal, but it can be slightly inclined. For example, "horizontal" only means that its direction is more horizontal relative to "vertical", and does not mean that the structure must be completely horizontal, but it can be slightly inclined.
[0023] In the description of the embodiments of the present invention, it should also be noted that unless otherwise clearly specified and limited, if terms such as "set", "installed", "connected", "connected" are understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0024] The following further describes the present invention in detail with reference to the accompanying drawings: Such asFigures 1-9 As shown in Figures 1-9 , an intelligent question-answering system dedicated to the power intranet provided by an embodiment of the present invention includes an account management module 1, a personnel information collection module 2, an identity authentication module 3, a data security management module 4, a record management module 5, a network security monitoring module 6, an intrusion processing module 7, an intrusion operation misdirection module 8, and a central control unit 9; The account management module 1 is used to manage the basic information, subordination relationship, special permissions, and contact information of power intranet personnel; the personnel information collection module 2 is used to collect the biometric information of power intranet personnel and record the on-the-job status and location information of personnel; the identity authentication module 3 is used to conduct security questions and answers on the identity of operators and the purpose of operating device data to implement the verification of operators; the data security management module 4 is used to encrypt the data and business information in the database and manage the data transmission security; the record management module 5 is used to record the instructions for personnel to operate the device, data modification behaviors, and operator information, and generate operation logs; the network security monitoring module 6 is used to monitor the network environment; the intrusion processing module 7 is used to respond to network security threats; the intrusion operation misdirection module 8 is used to confuse intruders, protect real data, induce the upload of improper operation information to the security defense, and delay the intrusion progress.
[0025] First, the social identity collection unit 14, voice information collection unit 15, personnel fingerprint collection unit 16, face information collection unit 17, and personnel status collection unit 18 in the personnel information collection module 2 are used to collect the social information, voice information, fingerprint information, face information, on-the-job status information, and location information of power system-related personnel respectively. The account management module 1 includes an identity information management unit 10, a subordination relationship management unit 11, a special permission management unit 12, and a contact information management unit 13. The identity information management unit 10 is used to manage the basic identity information of personnel related to the power intranet. Then, the special permission management unit 12 in the account management module 1 is used to manage the permissions of personnel. The subordination relationship management unit 11 is used to manage and associate the superior-subordinate relationship of personnel. The special permission management unit 12 is used to grant confidential permissions to personnel and manage these personnel separately. The contact information management unit 13 is used to manage the contact information of personnel. When a person needs to access or operate a device to obtain data, the identity of the person can be verified to different degrees according to the confidentiality level of the accessed data. The central control unit 9 is used to control the hub connecting other units.
[0026] The personnel information collection module 2 includes a social identity collection unit 14, a voice information collection unit 15, a personnel fingerprint collection unit 16, a face information collection unit 17, and a personnel status collection unit 18. The social identity collection unit 14 is used to collect the social identity information of personnel. The voice information collection unit 15 is used to collect the voice information of personnel and store it as a comparison basis for subsequent voice devices. Among them, through the intelligent question-and-answer verification unit 19, voice verification unit 20, fingerprint verification unit 21, face verification unit 22, and auxiliary verification unit 23 in the identity verification module 3, the personnel identity information can be verified to different degrees, which can be one verification or multiple verifications. The personnel fingerprint collection unit 16 is used to collect the fingerprint information of personnel and store it. The face information collection unit 17 is used to collect the face information of personnel and store it. The personnel status collection unit 18 is used to collect the on-the-job status information and location information of personnel.
[0027] The identity verification module 3 includes an intelligent question-and-answer verification unit 19, a voice verification unit 20, a fingerprint verification unit 21, a face verification unit 22, and an auxiliary verification unit 23. The intelligent question-and-answer verification unit 19 is used to conduct a security question-and-answer on the identity of personnel and the purpose of operating device data according to the level of confidentiality of the device data operated by personnel. When the data to be accessed is too confidential, the intelligent question-and-answer verification unit 19 can conduct intelligent questioning on the user. The content of the questioning includes the verification of identity information and the questioning of the purpose of accessing data. If the result of the reply is consistent with the content recorded in the database, authorization is granted. The voice verification unit 20 is used to verify the voice of personnel. The fingerprint verification unit 21 is used to verify the fingerprint of personnel. The face verification unit 22 is used to verify the face of personnel. The auxiliary verification unit 23 is used to contact relevant project personnel or superiors in the subordination relationship for operation confirmation.
[0028] The data security management module 4 includes a database encryption unit 24, a service security management unit 25, and a data transmission management unit 26. If there are differences, the superior contact information of the personnel or the contact information of relevant project personnel is obtained through the subordination relationship management unit 11 and the contact information management unit 13 in the account management module 1. Then, through the auxiliary verification unit 23, the access requirement verification of the personnel is assisted through the method of multi-person confirmation. The database encryption unit 24 is used to encrypt the data in the database. The service security management unit 25 is used to encrypt the relevant information of the service. The data transmission management unit 26 is used to conduct security management on remote data transmission, device interface transmission, and communication records.
[0029] The record management module 5 includes an operation instruction recording unit 27, a data modification recording unit 28, and an operator recording unit 29. The operation instruction recording unit 27 is used to record the instruction information of personnel operating the device. The data and service information can be protected through the database encryption unit 24, the service security management unit 25, and the data transmission management unit 26 in the data security management module 4. The illegal external connection monitoring unit 30 can monitor the illegal connection of personnel to the external network to avoid information leakage caused by personnel connecting to the external network. The data modification recording unit 28 is used to record the operations of personnel modifying data, and the operator recording unit 29 is used to collect the information of personnel operating the device and generate a log.
[0030] The network security monitoring module 6 includes an illegal external connection monitoring unit 30, a virus monitoring unit 31, and a malicious access monitoring unit 32. The illegal external connection monitoring unit 30 is used to monitor the connection of personnel to the external network without permission. When there are improper operations during personnel operating the device, first, the operation instruction recording unit 27 can record the operation instructions of personnel, and at the same time, the data modification recording unit 28 can record the modification of data by personnel. The virus monitoring unit 31 is used to detect and kill viruses hidden in the data, and the malicious access monitoring unit 32 is used to monitor the dynamic information of malicious access to the internal network.
[0031] The intrusion handling module 7 includes a warning prompt unit 33, an emergency alarm unit 34, and an abnormal device isolation unit 35. When it is detected that personnel have improper actions on operating the system, then the warning prompt unit 33, the emergency alarm unit 34, and the abnormal device isolation unit 35 in the intrusion handling module 7 start to work. During this process, the false data simulation unit 36 can connect to the front-end real data interface and switch to the pre-simulated false data information to deceive personnel. The warning prompt unit 33 is used to give warning prompts to intruders and personnel with improper operations. The emergency alarm unit 34 is used to automatically handle alarm events for illegal operations. The abnormal device isolation unit 35 is used to isolate the abnormal devices separately and track the location information of the devices.
[0032] The intrusion operation misguidance module 8 includes a false data simulation unit 36, a false interface induction unit 37, an information collection induction unit 38, and a false progress delay unit 39. The false data simulation unit 36 is used to simulate one or more similar data for real confidential information. The false interface induction unit 37 is used to cover the real operation at the back end with a false front-end page, and through the false interface induction unit 37, the original normal page is maintained, but the button pointing at the front end to the back end is changed, so that during the operation of personnel, the operation at the back end is completely inconsistent with the prompt of the front-end page, and in cooperation with the false progress delay unit 39, the illegal operators can be delayed, buying time for the police officers and avoiding the leakage of confidential information. The information collection induction unit 38 is used to induce the personnel with improper operations to collect information and upload it to the security system. The false progress delay unit 39 is used to establish a false and inefficient data transmission progress.
[0033] The working principle of an intelligent question-and-answer system dedicated to the power internal network in the present invention is as follows: First, the social identity collection unit, voice information collection unit, personnel fingerprint collection unit, face information collection unit, and personnel status collection unit in the personnel information collection module are used to collect the social information, voice information, fingerprint information, face information, in-service status information, and location information of relevant personnel in the power system respectively. Then, the special permission management unit in the account management module manages the permissions of personnel. When a person needs to access or operate equipment to obtain data, the identity of the person can be verified to different degrees according to the confidentiality level of the accessed data. Among them, through the intelligent question-and-answer verification unit, voice verification unit, fingerprint verification unit, face verification unit, and auxiliary verification unit in the identity verification module, the identity information of the person can be verified to different degrees, which can be one verification or multiple verifications. When the data to be accessed is too confidential, the intelligent question-and-answer verification unit can ask intelligent questions to the user, and the content of the questions includes the verification of identity information and the purpose of the accessed data. If the reply result is consistent with the content recorded in the database, authorization is given. If there are differences, the superior contact information of the person or the contact information of relevant project personnel can be obtained through the subordinate relationship management unit and the contact information management unit in the account management module. Then, through the auxiliary verification unit, the access requirement verification of the person can be assisted through the method of multi-person confirmation. The database encryption unit, business security management unit, and data transmission management unit in the data security management module can protect data and business information. The illegal external connection monitoring unit can monitor the illegal connection of personnel to the external network to avoid information leakage caused by personnel connecting to the external network. When a person has improper operations when operating the equipment, first, the operation instruction recording unit can record the operation instructions of the person, and at the same time, the data modification recording unit can record the data modification of the person. When it is detected that the person has actions of an improper operation system, then the warning prompt unit, emergency alarm unit, and abnormal device isolation unit in the intrusion processing module start to work. During this process, the false data simulation unit can connect to the real data interface at the front end and switch to the pre-simulated false data information to deceive people, and the false interface induction unit can keep the original normal page, but the button pointing at the front end to the back end is changed, so that during the operation process of the person, the operation at the back end is completely inconsistent with the prompt on the front-end page, and in cooperation with the false progress delay unit, the illegal operator can be delayed, buying time for the police and avoiding the leakage of confidential information.
[0034] The present invention provides an intelligent question-and-answer system dedicated to the power internal network. Through the false data simulation unit, the real data interface at the front end can be connected to switch to the pre-simulated false data information to deceive people, and through the false interface induction unit, the original normal page is maintained, but the button pointing from the front end to the back end is changed, so that during the operation of personnel, the operation at the back end is completely inconsistent with the prompts on the front-end page, and in cooperation with the false progress delay unit, illegal operators can be delayed, buying time for police officers and avoiding the leakage of confidential information. At the same time, through the intelligent question-and-answer verification unit, voice verification unit, fingerprint verification unit, face verification unit and auxiliary verification unit, the identity information of personnel can be verified to different degrees. When the data to be accessed is too confidential, the intelligent question-and-answer verification unit can ask intelligent questions to the user. The questions include the verification of identity information and the purpose of accessing the data. If the answer result is consistent with the content recorded in the database, authorization is given. If there are differences, the contact information of the superior of the personnel or the contact information of relevant project personnel is obtained, and then auxiliary verification and access requirement verification are carried out to prevent leakage of secrets.
[0035] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An intelligent question-answering system dedicated to power intranet, characterized in that: It includes an account management module (1), a personnel information collection module (2), an identity authentication module (3), a data security management module (4), a record management module (5), a network security monitoring module (6), an intrusion processing module (7), an intrusion operation misleading module (8) and a central control unit (9) that communicate with each other; The account management module (1) is used to manage the basic information, subordinate relationships, special permissions and contact information of power intranet personnel; The personnel information collection module (2) is used to collect biometric information of personnel in the power intranet and record the personnel's working status and location information; The identity verification module (3) is used to conduct security questions and answers on the identity of the operator and the purpose of the operating device data, thereby verifying the operator; The data security management module (4) is used to encrypt the data and business information in the database and manage the security of data transmission; The record management module (5) is used to record the instructions of personnel operating the equipment, data modification behavior and operator information, and generate an operation log; The network security monitoring module (6) is used to monitor the network environment; The intrusion processing module (7) is used to deal with network security threats; The intrusion operation misleading module (8) is used to confuse intruders, protect real data, induce improper operation information to be uploaded to security, and delay the progress of the intrusion.
2. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The biometric information of the person includes social identity information, voice, fingerprints and facial features.
3. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The account management module (1) comprises an identity information management unit (10), a subordinate relationship management unit (11), a special authority management unit (12) and a contact information management unit (13); the identity information management unit (10) is used to manage basic identity information of personnel related to the power intranet, the subordinate relationship management unit (11) is used to manage and associate the superior-subordinate subordinate relationships of personnel, the special authority management unit (12) is used to grant confidentiality authority to personnel and manage these personnel individually, and the contact information management unit (13) is used to manage the contact information of personnel.
4. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The personnel information collection module (2) comprises a social identity collection unit (14), a voice information collection unit (15), a personnel fingerprint collection unit (16), a facial information collection unit (17) and a personnel status collection unit (18); the social identity collection unit (14) is used to collect the social identity information of the personnel, the voice information collection unit (15) is used to collect the voice information of the personnel and store it as a basis for comparison of subsequent voice equipment, the personnel fingerprint collection unit (16) is used to collect the fingerprint information of the personnel and store it, the facial information collection unit (17) is used to collect the facial information of the personnel and store it, and the personnel status collection unit (18) is used to collect the on-the-job status information and location information of the personnel.
5. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The identity verification module (3) comprises an intelligent question-and-answer verification unit (19), a voice verification unit (20), a fingerprint verification unit (21), a face verification unit (22) and an auxiliary verification unit (23); the intelligent question-and-answer verification unit (19) is used to conduct security questions and answers on the identity of a person and the purpose of operating device data in order to ensure the confidentiality of the data of the device operated by the person; the voice verification unit (20) is used to verify the voice of the person; the fingerprint verification unit (21) is used to verify the fingerprint of the person; the face verification unit (22) is used to verify the face of the person; and the auxiliary verification unit (23) is used to contact project-related personnel or superiors in a subordinate relationship to confirm the operation.
6. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The data security management module (4) comprises a database encryption unit (24), a business security management unit (25) and a data transmission management unit (26); the database encryption unit (24) is used to encrypt data in the database, the business security management unit (25) is used to encrypt relevant information of the business, and the data transmission management unit (26) is used to perform security management on remote data transmission, device interface transmission and communication records.
7. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The record management module (5) comprises an operation instruction recording unit (27), a data modification recording unit (28) and an operator recording unit (29); the operation instruction recording unit (27) is used to record instruction information of a person operating a device, the data modification recording unit (28) is used to record an operation of a person modifying data, and the operator recording unit (29) is used to collect information about a person operating the device and generate a log.
8. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The network security monitoring module (6) comprises an illegal external connection monitoring unit (30), a virus monitoring unit (31) and a malicious access monitoring unit (32); the illegal external connection monitoring unit (30) is used to monitor personnel connecting to the external network without permission, the virus monitoring unit (31) is used to detect and kill viruses hidden in data, and the malicious access monitoring unit (32) is used to monitor dynamic information of malicious access to the internal network.
9. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The intrusion processing module (7) comprises a warning prompt unit (33), an emergency alarm unit (34) and an abnormal device isolation unit (35); the warning prompt unit (33) is used to give warning prompts to intruders and improper operators, the emergency alarm unit (34) is used to automatically alarm events of illegal operations, and the abnormal device isolation unit (35) is used to isolate abnormal devices and track the location information of the devices.
10. The intelligent question-answering system dedicated to the power intranet according to claim 1, characterized in that: The intrusion operation misleading module (8) comprises a false data simulation unit (36), a false interface induction unit (37), an information collection induction unit (38) and a false progress delay unit (39); the false data simulation unit (36) is used to simulate one or more similar data for real confidential information, the false interface induction unit (37) is used to cover up the real operation of the back end with a false front-end page, the information collection induction unit (38) is used to induce personnel who perform improper operations to collect information and upload it to the security system, and the false progress delay unit (39) is used to establish a false and inefficient data transmission progress.
Citation Information
Cited By
Chromatographic data monitoring management method and system
CN121141922A
Chromatographic data monitoring management method and system
CN121141922B