Data application security protection method and device adaptive to novel power system
By building a feature recognition model, the interface communication between microservices in the new power system is preliminarily identified, classified and de-redundant, an interface directory list is generated, and the security information of the interface communication is analyzed. This solves the security protection problem of data interaction in the new power system and realizes efficient and secure data interaction management.
Patent Information
- Application Number
- CN202510892385.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-06-30
AI Technical Summary
In new power systems, cross-regional and cross-domain data interactions are frequent and uncontrollable, and existing static protection methods are difficult to achieve safe, easy-to-use and efficient data security protection.
Build a feature recognition model to preliminarily identify, classify, and remove redundancy in interface communications between microservices, generate an interface directory list, and analyze the security information of interface communications, including activity, sensitive data, and interaction relationships.
It achieves security protection at the interface communication level, improves the security and efficiency of data interaction, can identify abnormal activities and potential attacks, and optimize resource allocation.
Smart Images

Figure CN120750573A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of new power systems, and in particular to a data application security protection method and device adapted to new power systems. Background Art
[0002] In order to adapt to the complex business scenarios of the new power system and protect the data security of critical infrastructure, we are currently actively promoting the construction of data security protection, and realizing the unified management and dynamic deployment of various protection capabilities through the data security protection management and control system.
[0003] Although the new power system can be configured with effective data security protection capabilities for different scenarios, data interaction situations change dynamically, especially with the increase in cross-regional and cross-domain interactions. If a simple permission or prohibition approach is adopted, it is difficult to achieve a balance between security, ease of use, and efficiency. There are also limitations in simply allocating permissions and strategies based on static protection. Therefore, how to improve data security protection capabilities in response to the changes and uncontrollable changes in data interaction scale and interaction risks is a technical problem that needs to be solved urgently. Summary of the Invention
[0004] The present application provides a data application security protection method and device that are adapted to the new power system. The main purpose is to first use a feature recognition model to preliminarily identify, preliminarily classify, remove redundancy and establish a directory classification for a large number of interface communications between microservices. This is equivalent to preprocessing a large amount of interface communication data, and then on this basis, especially according to the label classification and business data corresponding to the interface communication, analyze the security information of the interface communication to achieve a solution that provides security protection at the interface communication level.
[0005] In order to achieve the above objectives, this application mainly provides the following technical solutions:
[0006] In a first aspect, the present application provides a data application security protection method adapted to a new power system, the method comprising:
[0007] In the power system microservice architecture, each microservice is deployed on one or more servers. The microservice is a multiple independent service obtained by splitting the power system business.
[0008] Construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices; the feature recognition model includes at least: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module;
[0009] In the process of monitoring the interface communication between servers corresponding to different microservices, the preliminary identification module is used to identify the data format of the interface communication processing using the built-in identification rules;
[0010] According to the data format processed by the interface communication, using a preliminary classification module to manually adjust rules to match different interface communications to built-in URLs, wherein the data formats corresponding to the interface communications matched to the same built-in URL are the same;
[0011] The redundant information appearing in the interface communication corresponding to the same built-in URL is processed by the redundant processing module to obtain the redundantly processed business data corresponding to each interface communication;
[0012] The directory classification module uses the built-in interface label rules to label the business data in the interface communication corresponding to each built-in URL one by one to obtain the label classification corresponding to the interface communication;
[0013] For each built-in URL corresponding to the matching interface communication, generate an interface directory list corresponding to each built-in URL according to the label classification corresponding to the interface communication;
[0014] According to the label classification corresponding to different interface communications and the business data in the interface communications displayed in the interface directory list corresponding to each built-in URL, the security information corresponding to the interface communication is analyzed. The security information includes at least: interface activity, whether sensitive data is involved, and the interactive relationship between different interface communications.
[0015] A second aspect of the present application provides a data application security protection device adapted to a new type of power system, the device comprising:
[0016] A deployment unit, configured to deploy each microservice on one or more servers under a power system microservice architecture, wherein the microservice is a plurality of independent services obtained by splitting the power system business;
[0017] A construction unit is used to construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices; the feature recognition model includes at least: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module;
[0018] The preliminary identification module is used to identify the data format of the interface communication processing using built-in identification rules during the process of monitoring the interface communication between servers corresponding to different microservices;
[0019] The preliminary classification module is used to match different interface communications to built-in URLs using manual adjustment rules according to the data format of the interface communication processing, wherein the data format of the interface communications corresponding to the same built-in URL is the same;
[0020] The redundancy processing module is used to process redundant information appearing in the interface communication corresponding to the same built-in URL, and obtain the redundantly processed business data corresponding to each interface communication;
[0021] The directory classification module is used to label the business data in the interface communication corresponding to each built-in URL one by one using the built-in interface label rules to obtain the label classification corresponding to the interface communication;
[0022] A generating unit, configured to generate an interface directory list corresponding to each built-in URL according to a label classification corresponding to the interface communication corresponding to each built-in URL;
[0023] The first analysis unit is used to analyze the security information corresponding to the interface communication based on the label classification corresponding to the different interface communications displayed in the interface directory list corresponding to each built-in URL and the business data in the interface communication. The security information includes at least: interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications.
[0024] A third aspect of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the data application security protection method adapted to the new power system as described above is implemented.
[0025] A fourth aspect of the present application provides an electronic device, the device comprising at least one processor, and at least one memory and a bus connected to the processor;
[0026] The processor and the memory communicate with each other via the bus.
[0027] The processor is used to call the program instructions in the memory to execute the data application security protection method adapted to the new power system as described above.
[0028] By means of the above technical solution, the technical solution provided by this application has at least the following advantages:
[0029] The present application provides a data application security protection method and device adapted to a new type of power system. Under the microservice architecture of the power system, each microservice is deployed on one or more servers, and data is shared between different microservices, so that the amount of data in the interface communication between servers is also huge. For this reason, the present application pre-constructs a feature recognition model corresponding to the business data interaction interface, including: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module; the preliminary recognition model is used to preliminarily identify the data formats processed by different interface communications; for the data formats processed by different interface communications, a preliminary classification module is used to preliminarily classify a large number of interface communications, so that interface communications processing the same data format are matched to the same built-in URL; the redundancy processing module is used to process the redundant information appearing in the interface communication corresponding to each built-in URL one by one; the directory classification module is used to label the business data in the interface communication corresponding to each built-in URL to obtain the label classification corresponding to the interface communication. After the above is processed by the feature recognition model to obtain the label classification corresponding to the interface communication, this application then generates an interface directory list corresponding to each built-in URL, and then analyzes the security information of the interface communication, such as the interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications, based on the label classification corresponding to different interface communications displayed in the interface directory list and the business data in the interface communication, to implement a solution that provides security protection at the interface communication level.
[0030] Compared with the existing technology's demand for security protection that adapts to the complex business scenarios of new power systems, this application first uses a feature recognition model to preliminarily identify, preliminarily classify, remove redundancy, and establish a directory classification for a large number of interface communications between microservices. This is equivalent to preprocessing a large amount of interface communication data, and then on this basis, especially according to the label classification and business data corresponding to the interface communication, analyze the security information of the interface communication to achieve a solution that provides security protection at the interface communication level.
[0031] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present application. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0033] Figure 1A flow chart of a data application security protection method adapted to a new power system provided in an embodiment of the present application;
[0034] Figure 2 A schematic diagram of the workflow of a business data interaction interface feature recognition model provided in an embodiment of the present application;
[0035] Figure 3 A schematic diagram of an evaluation process for a data interaction security risk assessment model based on security indicator characteristics provided in an embodiment of the present application;
[0036] Figure 4 A schematic diagram of the stratification of indicators provided in an embodiment of the present application;
[0037] Figure 5 The forward transformation matrix M provided in the embodiment of the present application is formed;
[0038] Figure 6 A block diagram of a data application security protection device adapted to a new type of power system provided in an embodiment of the present application;
[0039] Figure 7 A block diagram of another data application security protection device adapted to a new type of power system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0040] The following describes exemplary embodiments of the present application in more detail with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present application and to fully convey the scope of the present application to those skilled in the art.
[0041] The embodiment of the present application provides a data application security protection method adapted to a new type of power system, such as Figure 1 As shown, the embodiment of the present invention provides the following specific steps:
[0042] 101. Under the power system microservice architecture, each microservice is deployed on one or more servers. Microservices are multiple independent services obtained by splitting the power system business.
[0043] 102. Construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices; the feature recognition model includes at least: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module.
[0044] The number of power system businesses involved in the new power system is huge. Under the power system microservice architecture, microservices are multiple independent services obtained by splitting the power system business, so the number of microservices is also huge, and each microservice is deployed on one or more servers, so the amount of data in the interface communication achieved by data sharing or data transmission between microservices will also be huge. The embodiment of the present application is to achieve data security protection at the interface communication level. In order to deal with such a large amount of interface communication, the embodiment of the present application is to construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices, and the feature recognition model is designed to include a preliminary recognition module, a preliminary classification module, a redundant processing module and a directory classification module. The purpose is to achieve layer-by-layer progressive data processing to process the interface communication of a large amount of data and extract important data information for security protection. The specific implementation steps of these modules are explained in detail below as 103-106.
[0045] 103. In the process of monitoring the interface communication between servers corresponding to different microservices, the preliminary identification module is used to use built-in identification rules to identify the data format of the interface communication processing.
[0046] In the embodiment of the present application, the work of the preliminary recognition module is the built-in recognition rule stage.
[0047] Core basis: Preliminary identification is carried out based on the Content-type (content type) and its own attributes of the interface; Identification object: Focus on the interface data type, and can identify common types such as Json (a lightweight data exchange format, commonly used for front-end and back-end data transmission), HTML (a markup language for building web page content), and XML (Extensible Markup Language, used for structured data storage and transmission), laying the foundation for subsequent processing.
[0048] 104. According to the data format of the interface communication processing, the preliminary classification module uses manual adjustment rules to match different interface communications to built-in URLs, wherein the data formats of the interface communications matched to the same built-in URL are the same.
[0049] In the embodiment of the present application, the work of the preliminary classification module is the manual rule adjustment stage.
[0050] Interface marking: Based on the preliminary results of the built-in identification rule stage, the URL (Uniform Resource Locator, which identifies the network location of the interface) that matches the built-in type is marked as an interface to clarify its basic category.
[0051] Furthermore, redundant parameters can be initially cleaned up at this stage, such as by using built-in delimiters (such as specific characters to separate different parameter segments) or regular rules (precisely matching and filtering parameters through regular expressions) to remove redundant interface parameters and simplify interface data; then, the built-in recognition rules are used to identify the interface again, and the same (delimiter / regular rule) method is used to clean up redundant parameters a second time to further optimize the accuracy of the interface data.
[0052] 105. Utilize the redundancy processing module to process redundant information appearing in the interface communications corresponding to the same built-in URL, and obtain redundantly processed service data corresponding to each interface communication.
[0053] In this embodiment, the redundancy processing module is used to remove redundant information. Multiple optimizations are performed: manual verification and optimization, where interface data is manually checked and adjusted to ensure data quality; automatic redundancy removal, where the program automatically cleans according to rules; and the application of built-in interface labeling rules to prepare for subsequent classification.
[0054] 106. Utilize the directory classification module to use the built-in interface label rule to label the business data in the interface communication corresponding to each built-in URL one by one, and obtain the label classification corresponding to the interface communication.
[0055] In the embodiment of the present application, the directory classification module is used to assist in achieving the output interface directory stage.
[0056] Classification and statistics: Through built-in interface labeling rules, interfaces are classified into sensitive interfaces (involving sensitive data and requiring strict control), external interfaces (interacting with external systems), business interfaces (supporting business processes), public interfaces (open to external calls), etc.; after generating a directory list, the number of interfaces is counted, and the interaction relationship (data transfer and dependency between interfaces), type distribution, activity (reflecting usage and load conditions, identifying busy / idle interfaces, abnormal activity traffic), and whether it is sensitive or not are analyzed, helping to fully understand interface assets and operating status.
[0057] For example, as shown in 101-106, the present application embodiment provides a workflow diagram of a business data interaction interface feature recognition model, such as Figure 2 shown.
[0058] 107. For each built-in URL corresponding to the matching interface communication, generate an interface directory list corresponding to each built-in URL according to the label classification corresponding to the interface communication.
[0059] 108. Based on the label classification corresponding to different interface communications and the business data in the interface communications displayed in the interface directory list corresponding to each built-in URL, analyze the security information corresponding to the interface communications. The security information at least includes: interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications.
[0060] As mentioned above, 107-108, it should be noted that, in the interface directory output stage, the embodiment of the present application is based on the premise that the interface communication corresponding to each built-in URL is obtained based on the preliminary classification module 104 above. It can be seen that "each built-in URL" is equivalent to a category of "interface communication" corresponding to the preliminary classification. Therefore, after this "preliminary classification", the subsequent data processing operations of the embodiment of the present application are equivalent to batch processing each "preliminary classification", such as removing redundant information in 105, and labeling and classifying the interface communication under each "preliminary classification" in 106, and finally summarizing to "generate an interface directory list corresponding to each built-in URL". The above data pre-processing and sorting of the original huge amount of interface communication data makes it more convenient to analyze each interface communication in the subsequent process, that is, to analyze the security information corresponding to the interface communication by integrating the label classification corresponding to the interface communication and the business data in the interface communication. The security information includes at least: interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications.
[0061] As described above, the data application security protection method adapted to the new power system provided by the embodiment of the present application, compared with the requirements of the existing technology for security protection adapted to the complex business scenarios of the new power system, the embodiment of the present application first uses a feature recognition model to preliminarily identify, preliminarily classify, remove redundancy and establish a directory classification for a large number of interface communications between microservices, which is equivalent to pre-processing a large amount of interface communication data, and then on this basis, especially according to the label classification and business data corresponding to the interface communication, analyze the security information of the interface communication to realize a solution that provides security protection at the interface communication level.
[0062] In some modified embodiments, in addition to providing a security protection solution at the interface communication level as described above, the present embodiment of the application uses the analysis and processing results of the interface communication in steps 101-108 above to further analyze the following:
[0063] Based on the interface activity in the security information corresponding to the interface communication, the load situation corresponding to different interface communications is measured and detected; based on whether the security information corresponding to the interface communication involves sensitive data and the interactive relationship between different interface communications, the presence of abnormal activities or abnormal traffic is measured and detected.
[0064] Interface activity can be analyzed based on access interface statistics. Interface activity reflects the usage and load of each network interface. By analyzing interface activity, you can determine which interfaces are busiest, which are idle, and whether there is any abnormal activity or traffic.
[0065] In the embodiment of the present application, the data source processed by the above "measurement detection" is statistical information such as "number of calls, response time, transmission traffic" collected based on interface access logs and monitoring systems.
[0066] The analytical value of such “measurement testing” can include, but is not limited to, the following:
[0067] Resource scheduling: Distinguish between "busy interfaces" (high-frequency calls, requiring expansion / optimization) and "idle interfaces" (low-frequency or useless, considering offline / merging), and allocate server resources reasonably.
[0068] Abnormal monitoring: Identify "abnormal activities / traffic" (for example, a sudden surge / drop in the number of calls to a certain interface, which may be due to an attack or business failure), and issue timely warnings and investigations.
[0069] The previous "interface identification, cleaning, and classification" provides a clear interface asset list for "activity analysis" (knowing which interfaces exist and what types they are). In turn, "activity analysis" completes the "operational quality dimension" of interface management - not only knowing "which interfaces exist", but also knowing "how these interfaces are used", allowing interface governance to extend from "static classification" to "dynamic monitoring and optimization", forming a complete interface life cycle management closed loop.
[0070] It can be seen that in the embodiment of the present application, the interface is first "sorted out" (identified, cleaned, and classified), and then "understood" (resource status, abnormal risks) through activity analysis, making interface management more refined and more valuable.
[0071] In some modified embodiments, the embodiment of the present application adopts the analysis and processing results of the interface communication as described in 101-108 above, and can further perform statistical analysis on IP addresses and protocols, such as including the following: for each built-in URL corresponding to the interface communication, obtain parameter information corresponding to the source IP address;
[0072] Determine whether there is potential attack behavior based on the access frequency in the parameter information corresponding to the source IP address.
[0073] Source IP address statistics can reflect active IP addresses, determine whether frequent access is malicious, and identify potential attackers or abnormal behaviors such as DoS attacks and malicious scanning.
[0074] Statistics of target IP addresses can indicate whether a server is busy, which servers are most likely to be targets of attacks, and identify potential security risks such as network vulnerabilities and unauthorized access.
[0075] Traffic protocol statistics can reflect the traffic distribution of different protocols, including TCP, UDP, ICMP, and other protocols. By analyzing traffic protocol statistics, you can understand the usage and communication patterns of different protocols, helping to optimize network resources and security policies.
[0076] In some modified embodiments, the present application embodiment uses the analysis and processing results of the interface communication in steps 101-108 above to further evaluate the data interaction security risk, such as by implementing the following steps:
[0077] A1 builds data interaction security indicators and their initial weights;
[0078] A2 builds a comparison matrix corresponding to the safety indicators by presetting safety decision rules. The comparison matrix compares any two safety indicators and scores them.
[0079] A3 updates the initial weight corresponding to the security indicator based on the result corresponding to the comparison matrix to obtain the target weight corresponding to the security indicator;
[0080] A4 uses security indicators and target weights to perform security risk assessment on data interaction for business data in interface communications corresponding to each built-in URL.
[0081] The embodiment of the present application utilizes the implementation steps A1-A4 above, which is equivalent to realizing a data interaction security risk assessment model based on security indicator characteristics, such as Figure 3 As shown below, combined Figure 3 The corresponding security risk assessment process has been implemented. The details of the process are explained in detail below, as follows (1)-(5).
[0082] (1) Data interaction security index weight based on analytic hierarchy process
[0083] The data exchange security risk assessment for new power systems involves multiple factors, each of which exhibits different key characteristics for data exchange security. When conducting data exchange security risk assessments, it is necessary to scientifically determine the importance of each factor and quantify its importance to determine the weight each factor occupies in the assessment. This allows for a more scientifically sound assessment and analysis of data exchange security. The rationality of weight assignment plays a crucial role in the scientific nature of data security assessments. Based on the actual situation, the Analytic Hierarchy Process (AHP) was used to calculate the weights of relevant factors through subjective assignment.
[0084] (2) AHP structural model
[0085] The importance of factors related to data exchange security is somewhat subjective. Considering this issue from the perspective of security and stability versus operational efficiency can yield diametrically opposed results. For example, from a security and stability perspective, issues like abnormal network traffic, abnormal paths, and sudden surges in traffic are prioritized, while from an operational efficiency perspective, network latency, latency variation, and packet loss rate are of considerable importance. Therefore, in establishing this data exchange security evaluation model, we introduced the more subjective analytic hierarchy process to calculate the weights of various factors.
[0086] According to the basic principle requirements of the hierarchical analysis method algorithm, the goals, considerations and decision-making objects are divided into the target layer and the criterion layer according to their relationship. The criteria include abnormal business access relationships, data network congestion risk, high-risk port scanning, IP path abnormalities, IP traffic abnormalities, packet loss rate, delay and delay change factors. The parameter source of the criterion layer is provided by the business data flow collection method, including interface activity, IP access times, business application access and other information. The target layer is business data flow security. The stratification of indicators is as follows: Figure 4 shown.
[0087] The security decision system constructs a comparison matrix, comparing data interaction security indicators pairwise and assigning scores based on their relative importance. The security decision system scores, ranging from 1 to 9, represent the importance of different indicators within the same dimension, from low to high. The meaning of the numerical scale is described in Table 1.
[0088] Table 1
[0089]
[0090] Among them, the scoring table of the safety decision-making system is shown in Table 2.
[0091]
[0092]
[0093] The above security assessment table is simplified to construct an N × N comparison matrix A. Through consistency check, the score of each element can be calculated by arithmetic mean method, and finally the weight value is obtained, as shown in Table 3.
[0094]
[0095] (3) Data security risk assessment based on TOPSIS superiority and inferiority distance method
[0096] The TOPSIS method is used to describe the gap between target data and the ideal optimal and worst values. Specifically, the optimal score is when data interaction security reaches a perfect state.
[0097] The scores of each indicator layer are known. Find the best and worst solutions among these evaluation objects, and then calculate the distance between each evaluation object and the best and worst solutions. The closer the distance to the best solution, the higher the score. The TOPSIS method mainly includes matrix forward transformation and matrix standardization. Forward transformation forms the following matrix M, such as Figure 5 exhibit.
[0098] After obtaining the normalized matrix, we perform standardization to make the different indicators have the same scale. The final result is data that obeys the standard normal distribution.
[0099] (4) Model evaluation score
[0100] First, the maximum and minimum values in the standardized matrix are calculated, and then the distance between the evaluation object and the maximum and minimum values is calculated, and normalization is performed on this basis.
[0101] (5) Data interaction security evaluation based on fuzzy comprehensive evaluation
[0102] The TOPSIS distance method can be used to obtain comprehensive quantitative values of data security parameter values and ideal optimal values and worst values, and describe the data interaction security trend based on the corresponding data. However, the distance method cannot qualitatively evaluate the comprehensive evaluation data. The fuzzy comprehensive evaluation method and the distance method complement each other, and ultimately obtain both quantitative and qualitative evaluation results.
[0103] The fuzzy comprehensive evaluation method is a comprehensive evaluation method based on fuzzy mathematics. This method transforms qualitative evaluation into quantitative evaluation based on the membership theory of fuzzy mathematics. This method uses fuzzy mathematics to provide an overall assessment of objects or entities subject to multiple factors. It offers clear and systematic results, effectively resolving fuzzy and difficult-to-quantify problems and is suitable for solving a variety of non-deterministic problems.
[0104] The steps of fuzzy comprehensive evaluation method are as follows:
[0105] ① Determine the factor set
[0106] ② Determine the comment set
[0107] ③Construct membership function
[0108] ④ Conduct single factor evaluation
[0109] ⑤Construct comprehensive evaluation matrix
[0110] ⑥Substitute weights for comprehensive evaluation
[0111] The eight data service flow operation security parameters involved in the study are included in the factor set of this fuzzy comprehensive evaluation, and the result is: U (factor set) = {service access relationship abnormality, data network congestion risk, high-risk port scanning, IP path abnormality, IP traffic abnormality, packet loss rate, delay, delay variation}.
[0112] According to the data security risk assessment requirements, data interaction security is rated into four levels: low, low, high, and high. The evaluation set required for fuzzy comprehensive evaluation is obtained.
[0113] V(comment set) = {lower, low, high, higher}.
[0114] Comprehensive data interaction security risk assessments can play an important role in identifying data security risks. According to this study's analysis, when the data interaction security score is above 0.3949, the data interaction security risk is low and the data security situation is relatively stable. If the data security score is below 0.3949, the data security situation is poor.
[0115] Furthermore, as a response to the above Figures 1 to 5 The embodiment of the present application provides a data application security protection device adapted to the new power system. This device embodiment corresponds to the aforementioned method embodiment. For ease of reading, this device embodiment will no longer describe the details of the aforementioned method embodiment one by one, but it should be clear that the device in this embodiment can implement all the contents of the aforementioned method embodiment. This device is used to implement a solution for providing security protection at the interface communication level, specifically as follows Figure 6 As shown, the device includes:
[0116] A deployment unit 21 is configured to deploy each microservice on one or more servers under the power system microservice architecture, wherein the microservice is a plurality of independent services obtained by splitting the power system business;
[0117] A construction unit 22 is configured to construct a feature recognition model corresponding to a business data interaction interface, which is used to monitor interface communications between servers corresponding to different microservices. The feature recognition model includes at least: a preliminary recognition module 221, a preliminary classification module 222, a redundancy processing module 223, and a directory classification module 224.
[0118] The preliminary identification module 221 is used to identify the data format of the interface communication processing using built-in identification rules during the process of monitoring the interface communication between servers corresponding to different microservices;
[0119] The preliminary classification module 222 is configured to match different interface communications to built-in URLs using manual adjustment rules based on the data formats processed by the interface communications, wherein the interface communications corresponding to the same built-in URL have the same data formats;
[0120] The redundancy processing module 223 is used to process redundant information appearing in the interface communication corresponding to the same built-in URL, and obtain the redundantly processed business data corresponding to each interface communication;
[0121] The directory classification module 224 is used to label the business data in the interface communication corresponding to each built-in URL one by one using the built-in interface label rules to obtain the label classification corresponding to the interface communication;
[0122] A generating unit 23 is configured to generate an interface directory list corresponding to each built-in URL according to a label classification corresponding to the interface communication corresponding to each built-in URL;
[0123] The first analysis unit 24 is used to analyze the security information corresponding to the interface communication based on the label classification corresponding to the different interface communications displayed in the interface directory list corresponding to each built-in URL and the business data in the interface communication. The security information at least includes: interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications.
[0124] Further, such as Figure 7 As shown, the first analysis unit 24 is specifically used for:
[0125] Measuring and detecting load conditions corresponding to different interface communications based on interface activity in the security information corresponding to the interface communications;
[0126] Whether there is abnormal activity or abnormal traffic is measured and detected based on whether the security information corresponding to the interface communication involves sensitive data and the interactive relationship between different interface communications.
[0127] Further, such as Figure 7 As shown, the device further includes: a second analysis unit 25, specifically configured to:
[0128] For each built-in URL corresponding to the matching interface communication, obtain the parameter information corresponding to the source IP address; and determine whether there is a potential attack behavior based on the access frequency in the parameter information corresponding to the source IP address.
[0129] Further, such as Figure 7 As shown, the device further includes: a third analysis unit 26, specifically configured to:
[0130] Construct data interaction security indicators and their initial weights;
[0131] By presetting safety decision rules, a comparison matrix corresponding to the safety indicators is constructed, wherein the comparison matrix compares any two safety indicators and scores them;
[0132] According to the result corresponding to the comparison matrix, the initial weight corresponding to the safety indicator is updated to obtain the target weight corresponding to the safety indicator;
[0133] For the business data in the interface communication corresponding to each built-in URL, the security indicator and the target weight are used to perform a security risk assessment on the data interaction.
[0134] In summary, the data application security protection device adapted to the new power system includes a processor and a memory. The above-mentioned deployment unit, construction unit, generation unit and first analysis unit are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions.
[0135] The processor contains a kernel, which retrieves the corresponding program unit from memory. One or more kernels can be configured. By adjusting kernel parameters, a feature recognition model is first used to perform preliminary identification, preliminary classification, and redundancy removal of large amounts of interface communications between microservices, and to establish a catalog classification. This is equivalent to preprocessing large amounts of interface communication data. Based on this, the security information of interface communications is analyzed, particularly based on the corresponding label classification and business data, to implement a security protection solution at the interface communication level.
[0136] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the data application security protection method adapted to the new power system as described above is implemented.
[0137] An embodiment of the present application provides an electronic device, which includes at least one processor, and at least one memory and a bus connected to the processor; wherein the processor and the memory communicate with each other through the bus; the processor is used to share program instructions in the memory to execute the data application security protection method adapted to the new power system as described above.
[0138] The present application also provides a computer program product which, when executed on a data processing device, is suitable for executing a program that initializes the steps of a data application security protection method adapted to a new type of power system.
[0139] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0140] In a typical configuration, the device includes one or more processors (CPUs), memory, and a bus. The device may also include input / output interfaces, network interfaces, and the like.
[0141] Memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip. Memory is an example of a computer-readable medium.
[0142] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0143] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0144] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0145] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A data application security protection method adapted to a new type of power system, characterized in that: The method comprises: In the power system microservice architecture, each microservice is deployed on one or more servers. The microservice is a multiple independent service obtained by splitting the power system business. Construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices; the feature recognition model includes at least: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module; In the process of monitoring the interface communication between servers corresponding to different microservices, the preliminary identification module is used to identify the data format of the interface communication processing using the built-in identification rules; According to the data format processed by the interface communication, using a preliminary classification module to manually adjust rules to match different interface communications to built-in URLs, wherein the data formats corresponding to the interface communications matched to the same built-in URL are the same; The redundant information appearing in the interface communication corresponding to the same built-in URL is processed by the redundant processing module to obtain the redundantly processed business data corresponding to each interface communication; The directory classification module uses the built-in interface label rules to label the business data in the interface communication corresponding to each built-in URL one by one to obtain the label classification corresponding to the interface communication; For each built-in URL corresponding to the matching interface communication, generate an interface directory list corresponding to each built-in URL according to the label classification corresponding to the interface communication; According to the label classification corresponding to different interface communications and the business data in the interface communications displayed in the interface directory list corresponding to each built-in URL, the security information corresponding to the interface communication is analyzed. The security information includes at least: interface activity, whether sensitive data is involved, and the interactive relationship between different interface communications.
2. The method according to claim 1, characterized in that The method further comprises: Measuring and detecting load conditions corresponding to different interface communications based on interface activity in the security information corresponding to the interface communications; Whether there is abnormal activity or abnormal traffic is measured and detected based on whether the security information corresponding to the interface communication involves sensitive data and the interactive relationship between different interface communications.
3. The method according to claim 1 or 2, characterized in that The method further comprises: For each built-in URL corresponding to the matching interface communication, obtain the parameter information corresponding to the source IP address; Determine whether there is potential attack behavior based on the access frequency in the parameter information corresponding to the source IP address.
4. The method according to claim 1 or 2, characterized in that The method further comprises: Construct data interaction security indicators and their initial weights; By presetting safety decision rules, a comparison matrix corresponding to the safety indicators is constructed, wherein the comparison matrix compares any two safety indicators and scores them; According to the result corresponding to the comparison matrix, the initial weight corresponding to the safety indicator is updated to obtain the target weight corresponding to the safety indicator; For the business data in the interface communication corresponding to each built-in URL, the security indicator and the target weight are used to perform a security risk assessment on the data interaction.
5. A data application security protection device adapted to a new type of power system, characterized in that: The device comprises: A deployment unit, configured to deploy each microservice on one or more servers under a power system microservice architecture, wherein the microservice is a plurality of independent services obtained by splitting the power system business; A construction unit is used to construct a feature recognition model corresponding to the business data interaction interface, which is used to monitor the interface communication between servers corresponding to different microservices; the feature recognition model includes at least: a preliminary recognition module, a preliminary classification module, a redundancy processing module and a directory classification module; The preliminary identification module is used to identify the data format of the interface communication processing using built-in identification rules during the process of monitoring the interface communication between servers corresponding to different microservices; The preliminary classification module is used to match different interface communications to built-in URLs using manual adjustment rules according to the data format of the interface communication processing, wherein the data format of the interface communications corresponding to the same built-in URL is the same; The redundancy processing module is used to process redundant information appearing in the interface communication corresponding to the same built-in URL, and obtain the redundantly processed business data corresponding to each interface communication; The directory classification module is used to label the business data in the interface communication corresponding to each built-in URL one by one using the built-in interface label rules to obtain the label classification corresponding to the interface communication; A generating unit, configured to generate an interface directory list corresponding to each built-in URL according to a label classification corresponding to the interface communication corresponding to each built-in URL; The first analysis unit is used to analyze the security information corresponding to the interface communication based on the label classification corresponding to the different interface communications displayed in the interface directory list corresponding to each built-in URL and the business data in the interface communication. The security information includes at least: interface activity, whether sensitive data is involved, and the interaction relationship between different interface communications.
6. The device according to claim 5, characterized in that The first analysis unit is specifically configured to: Measuring and detecting the load conditions corresponding to different interface communications based on the interface activity in the security information corresponding to the interface communications; Whether there is abnormal activity or abnormal traffic is measured and detected based on whether the security information corresponding to the interface communication involves sensitive data and the interactive relationship between different interface communications.
7. The device according to claim 5 or 6, characterized in that The device further includes a second analyzing unit, specifically configured to: For each built-in URL corresponding to the matching interface communication, obtain the parameter information corresponding to the source IP address; Determine whether there is potential attack behavior based on the access frequency in the parameter information corresponding to the source IP address.
8. The device according to claim 5 or 6, characterized in that The device further includes: a third analyzing unit, specifically configured to: Construct data interaction security indicators and their initial weights; By presetting safety decision rules, a comparison matrix corresponding to the safety indicators is constructed, wherein the comparison matrix compares any two safety indicators and scores them; According to the result corresponding to the comparison matrix, the initial weight corresponding to the safety indicator is updated to obtain the target weight corresponding to the safety indicator; For the business data in the interface communication corresponding to each built-in URL, the security indicator and the target weight are used to perform a security risk assessment on the data interaction.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the data application security protection method adapted to a new power system as described in any one of claims 1 to 4.
10. An electronic device, characterized in that: The device includes at least one processor, and at least one memory and a bus connected to the processor; The processor and the memory communicate with each other via the bus. The processor is used to call the program instructions in the memory to execute the data application security protection method adapted to the new power system as described in any one of claims 1-4.
Citation Information
Patent Citations
Automatic service verification method and device for verifying reliability of disaster recovery system
CN113434404A
Micro-service dependency link static analysis method and system based on syntactic analysis tree
CN114237625A
Data security risk monitoring method and device, electronic equipment and storage medium
CN118157880A
Power business data interface identification method and device
CN118296372A
Industrial data micro-service abnormity monitoring method, medium and system
CN119862092A
Cited By
Software component identification method based on installation directory discovery and dynamic and static collaborative analysis
CN121615133A