Method and system for testing network security monitoring device of power monitoring system

By creating a security event template for monitoring objects and sending simulated security event messages, the problems of difficulty in obtaining monitoring objects and difficult performance testing in traditional testing methods are solved, and efficient automated testing of network security monitoring devices of power monitoring systems are realized.

CN120434016APending Publication Date: 2025-08-05STATE GRID ELECTRIC POWER RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510699072.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In the testing methods of traditional power monitoring systems network security monitoring devices, it is difficult to obtain all monitoring objects, complex deployment, low manual triggering of security events, and difficult to perform performance testing.

Method used

By creating security event templates of various monitoring objects, assigning IP addresses and performing IP binding, parameterizing date and time information of security events, sending simulated security event messages, and realizing automated testing.

Benefits of technology

Improve testing efficiency, ensure the correct format of security events, can truly simulate multiple types of security events, and accurately perform test results, simplifying the hardware requirements of the test environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure HDA0005424018610000011
    Figure HDA0005424018610000011
  • Figure HDA0005424018610000021
    Figure HDA0005424018610000021
  • Figure HDA0005424018610000031
    Figure HDA0005424018610000031
Patent Text Reader

Abstract

The invention discloses a method and system for testing a network security monitoring device of a power monitoring system, and the method comprises the steps: creating various monitoring object security event templates, including server security event templates, firewall security event templates, one-way isolation device security event templates, intrusion detection system security event templates, anti-virus system security event templates and switch security event templates; selecting a reference value and a step length to allocate IP addresses for various monitoring objects; adding the distributed detection object IP address to a local network interface, and carrying out IP binding after network connection is established; date and time information of the security event is parameterized and formatted by adding a system timestamp; and sending a simulation security event message of the monitored object, and releasing resources after the test is finished. The function test efficiency of the network security monitoring device of the power monitoring system is greatly improved, the performance test of the network security monitoring device of the power monitoring system can be realized, and the problem that a conventional network tester cannot perform comprehensive test is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a testing method and system for a network security monitoring device, and in particular to a testing method and system for a network security monitoring device of an electric power monitoring system. Background Art

[0002] Traditional testing methods for network security monitoring devices in power monitoring systems use various physical hardware devices as monitoring targets to build a test environment. This presents at least the following problems: First, it is difficult to obtain all the physical devices used as monitoring targets, which increases the difficulty of deploying the test environment. Second, deploying a large number of physical monitoring targets increases the complexity of the test network and the difficulty of debugging. Third, security events for various monitoring targets require manual triggering, which is not only inefficient but also cannot guarantee that the generated security event message format meets the requirements of the testing standards. When suspected issues arise, it takes time to locate and resolve the issues. Fourth, it is difficult to implement performance testing of various monitoring targets.

[0003] As more and more network security monitoring device products enter the power market, it is necessary to construct an efficient testing method and system for network security monitoring devices of power monitoring systems to ensure that the power system can timely analyze and perceive the security situation of the power monitoring system and reduce the security risks of the power monitoring system. Summary of the Invention

[0004] Purpose of the invention: The purpose of the present invention is to provide a testing method and system for a network security monitoring device of an electric power monitoring system, which can efficiently test the network security monitoring device of an electric power monitoring system by simulating security event messages sent by various monitoring objects.

[0005] Technical solution: The present invention provides a method for testing a network security monitoring device of a power monitoring system, comprising:

[0006] Create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system, and switch security event templates;

[0007] Select the benchmark value and step size to assign IP addresses to various monitoring objects;

[0008] Add the assigned detection target IP address to the local network interface and perform IP binding after establishing a network connection;

[0009] Parameterize the date and time information of security events and format them by adding system timestamps;

[0010] Send simulated security event messages to the monitored object and release resources after the test is completed.

[0011] Preferably, the security event includes an event level and event information, and the event information includes but is not limited to date, time, device name, device type, event type, and content description.

[0012] Preferably, the reference value defaults to the middle value of the address segment 128. If the end address value of the monitoring device's acquisition port IP is greater than or equal to the reference value, each type of monitoring object is decremented based on the acquisition port IP according to the specified step size, otherwise the monitoring object IP address is incremented.

[0013] Preferably, the adding of the system timestamp includes taking the date and time fields in the event message as variables, and filling the date and time fields of the event message according to the system timestamp when preparing to send the event after the network connection is established.

[0014] Preferably, the adding to the local network interface includes creating a transport layer network connection, creating a TCP connection for server-type security events, and creating a UDP connection for other types of security events.

[0015] Preferably, the method further comprises releasing resources after the test is completed, including releasing network connection resources and deleting the added IP addresses.

[0016] Preferably, the method also includes constructing a server security event message by calculating the message length and checksum according to the TCP custom protocol specification, wherein the message length is the byte length of the original message content after encoding using utf-8, and the message checksum is the result of accumulating the ASCII code value of the original message and performing an AND operation with the constant 0xff.

[0017] The present invention also provides a test system for a network security monitoring device of an electric power monitoring system, comprising:

[0018] Create security event module: used to create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system and switch security event templates;

[0019] IP address allocation module: used to select the benchmark value and step size to allocate IP addresses for various monitoring objects;

[0020] Establishing a network connection module: used to add the assigned detection object IP address to the local network interface and perform IP binding after the network connection is established;

[0021] Formatting module: used to parameterize the date and time information of security events and format them by adding system timestamps;

[0022] Message sending module: used to send simulated security event messages of monitored objects.

[0023] A computer device includes one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the testing method of a network security monitoring device of an electric power monitoring system are implemented.

[0024] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a method for testing a network security monitoring device of a power monitoring system.

[0025] Beneficial effects: Compared with the prior art, the present invention has the following significant advantages: (1) Through the security event data templates of various monitoring objects, the format errors and event omissions of security event data are avoided, which not only saves hardware investment in the test environment, but also can efficiently generate security events and easily locate problems; (2) By using parameterized date and time and assigning different IP addresses to various monitoring objects according to policies, a complete simulation of security events is achieved; (3) The TCP custom protocol, GB / T 31992 protocol, and SNMPTrap protocol specified in the Q / GDW11914-2018 document are simulated to achieve a scenario where multiple types of security events coexist in a real simulation production environment, and its performance test results are more accurate; (4) According to the TCP custom protocol specification, the server security event message is constructed by calculating the message length and checksum, which solves the problem that conventional network testers cannot establish a connection or cannot construct a legal message; (5) The security events of various monitoring objects are triggered synchronously, and the test automation of the network security monitoring device of the power monitoring system is realized, which greatly improves the test efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 The figure is a flow chart of the method of the present invention.

[0027] Figure 2 An example diagram of SNMP variable binding.

[0028] Figure 3 Flowchart for allocating IP addresses to monitored objects.

[0029] Figure 4 Flowchart for adding the IP address of the monitoring object to the local network interface. DETAILED DESCRIPTION

[0030] The technical solution of the present invention will be further described below with reference to the accompanying drawings.

[0031] The present invention provides a method for testing a network security monitoring device of an electric power monitoring system, comprising:

[0032] Create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system, and switch security event templates;

[0033] Select the benchmark value and step size to assign IP addresses to various monitoring objects;

[0034] Add the assigned detection target IP address to the local network interface and perform IP binding after establishing a network connection;

[0035] Parameterize the date and time information of security events and format them by adding system timestamps;

[0036] Send simulated security event messages to the monitored object and release resources after the test is completed.

[0037] According to the data collection requirements of Q / GDW 11914-2018, the server security event templates include user login, user logout, login failure, USB device insertion, USB device removal, serial port occupation, serial port release, abnormal network access, user permission change, network port UP, network DOWN, key file / directory change, CD-ROM loading, CD-ROM unloading, existence of CD-ROM device, open illegal services / ports, etc.

[0038] The format of the server security event template is as follows:

[0039] <Event Level> Date Time Device Name Device Type Event Type Event Subtype Content Description;

[0040] Among them, the event level is 1-5, 1 means urgent; 2 means important; 3 means minor; 4 means general; 5 means notification; the date format is YYYY-MM-DD, which is a variable; the time format is HH:MM:SS, which is a variable; the device name is the identifier of the server type device; the device type is SVR; the event type and event subtype are both numeric characters; the content description represents the specific content of the description of the event.

[0041] According to the data collection requirements of Q / GDW 11914-2018, the firewall security event templates include user login, user logout, login failure, network port up, network down, security policy modification, access that does not comply with security policy, attack alarm, CPU usage exceeding threshold, memory usage exceeding threshold, etc.

[0042] The format of the firewall security event template is as follows:

[0043] <Event Level> Date Time Device Name Device Type Event Type Event Subtype Content Description;

[0044] The event level, date, time, device name, event type, event subtype, and content description are consistent with those for server security events. The device type is FW.

[0045] According to the data collection requirements of Q / GDW 11914-2018, the one-way isolation device security event templates include user login, configuration modification, access that does not comply with security policies, CPU usage exceeding the threshold, memory usage exceeding the threshold, etc.

[0046] The template format for one-way isolation device safety events is as follows:

[0047] <Event Level> Date Time Device Name Device Type Event Type Event Subtype Content Description;

[0048] The event level, date, time, device name, event type, event subtype, and content description are consistent with those of server-type security events. The device type indicates that FID is a forward isolation device and BID is a reverse isolation device.

[0049] According to the data collection requirements of Q / GDW 11914-2018, the intrusion detection system security event template includes intrusion events;

[0050] The format of the intrusion detection system security event template is as follows:

[0051] <Event Level> Date Time Device Name Device Type Event Type Content Description;

[0052] The event level is 1 or 2. The date, time, device name, event type, and content description are consistent with those for server security events. The device type is IDS, and the intrusion detection system has only one event and no event subtypes.

[0053] According to the data collection requirements of Q / GDW 11914-2018, the antivirus system security event template includes virus logs;

[0054] The format of the intrusion detection system security event template is as follows:

[0055] <Event Level> Date Time Device Name Device Type Event Type Content Description;

[0056] The event level is 1. The date, time, device name, event type, and content description are consistent with those for server-type security events. The device type is AV. The antivirus system has only one event and no event subtype.

[0057] According to the data collection requirements of Q / GDW 11914-2018, the switch security event templates include: user login, user logout, login failure, user password modification, user operation information, configuration change, network port UP, network port DOWN, network port traffic exceeding threshold, etc.

[0058] The switch security event template uses the SNMP variable binding table to combine and assign values to various OIDs in the MIB library to form a series of variable-bindings. Each variable-bindings represents a switch security event. The SNMP variable binding example is as follows: Figure 1 shown.

[0059] The method for allocating IP addresses of various monitoring objects is to allocate IP addresses to various monitoring objects according to the selected reference value, which defaults to the middle value of the address segment 128; if the end address value of the IP of the acquisition port of the monitoring device is greater than or equal to the reference value, then the IP addresses of various monitoring objects are decremented based on the acquisition port IP according to the specified step size, which defaults to 1; otherwise, the IP addresses of the monitoring objects are incremented, such as Figure 2 shown.

[0060] The adding of the local network interface IP address and binding includes adding the allocated monitoring object IP address to the local network interface, such as Figure 3 As shown in the figure, after establishing a network connection, perform IP binding so that the security event message carries the content of the specified IP address. Create a transport layer network connection. For server-type security events, create a TCP connection; for other types of devices, create a UDP connection.

[0061] The adding of timestamp includes taking the date and time fields in the event message as variables, and filling the date and event fields of the event message according to the system timestamp when preparing to send the event after the network connection is established, so as to achieve the effect of completely simulating the event realistically, and at the same time facilitate the network security monitoring device to query the security event according to the time sequence, and facilitate the performance testing of the network security monitoring device in terms of time efficiency.

[0062] The method also includes sending simulated security event messages of various detection objects according to project requirements such as functional testing and performance testing, and releasing resources after the test is completed, including releasing network connection resources and deleting added IP addresses.

[0063] The present invention also provides a test system for a network security monitoring device of an electric power monitoring system, comprising:

[0064] Create security event module: used to create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system and switch security event templates;

[0065] IP address allocation module: used to select the benchmark value and step size to allocate IP addresses for various monitoring objects;

[0066] Establishing a network connection module: used to add the assigned detection object IP address to the local network interface and perform IP binding after the network connection is established;

[0067] Formatting module: used to parameterize the date and time information of security events and format them by adding system timestamps;

[0068] Message sending module: used to send simulated security event messages of monitored objects.

Claims

1. A testing method for a network security monitoring device of an electric power monitoring system, characterized in that: include: Create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system, and switch security event templates; Select the benchmark value and step size to assign IP addresses to various monitoring objects; Add the assigned detection target IP address to the local network interface and perform IP binding after establishing a network connection; Parameterize the date and time information of security events and format them by adding system timestamps; Send simulated security event messages to the monitored object and release resources after the test is completed.

2. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The security event includes an event level and event information, and the event information includes but is not limited to date, time, device name, device type, event type, and content description.

3. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The reference value defaults to the middle value of the address segment, 128. If the end address value of the monitoring device's acquisition port IP is greater than or equal to the reference value, each type of monitoring object will be decremented based on the acquisition port IP according to the specified step size; otherwise, the monitoring object IP address will be incremented.

4. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The adding of the system timestamp includes taking the date and time fields in the event message as variables, and filling the date and time fields of the event message according to the system timestamp when preparing to send the event after the network connection is established.

5. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The adding to the local network interface includes creating a transport layer network connection, creating a TCP connection for server-type security events, and creating a UDP connection for other types of security events.

6. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The method further includes releasing resources after the test is completed, including releasing network connection resources and deleting the added IP addresses.

7. The method for testing a network security monitoring device of a power monitoring system according to claim 1, characterized in that: The method also includes constructing a server security event message by calculating the message length and checksum according to the TCP custom protocol specification, wherein the message length is the byte length of the original message content after encoding using UTF-8, and the message checksum is the result of the accumulation of the ASCII code value of the original message and the constant 0xff.

8. A test system for a network security monitoring device of an electric power monitoring system, characterized in that: include: Create security event module: used to create security event templates for various monitoring objects, including server, firewall, one-way isolation device, intrusion detection system, antivirus system and switch security event templates; IP address allocation module: used to select the benchmark value and step size to allocate IP addresses for various monitoring objects; Establishing a network connection module: used to add the assigned detection object IP address to the local network interface and perform IP binding after the network connection is established; Formatting module: used to parameterize the date and time information of security events and format them by adding system timestamps; Message sending module: used to send simulated security event messages of monitored objects.

9. A computer device, characterized in that: It includes one or more processors, a memory and one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of a testing method for a network security monitoring device of an electric power monitoring system as described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of a method for testing a network security monitoring device of a power monitoring system according to any one of claims 1 to 7 are implemented.