Security protection system based on power system information communication network

Through the collaborative work of terminal security access, network communication protection and business security monitoring modules, combined with multi-factor authentication and in-depth analysis of power-specific protocols, the problems of insufficient identification of protocol attacks and delayed discovery of unknown threats in the power system information and communication network have been solved, achieving efficient security protection and business continuity guarantees.

CN120768673AInactive Publication Date: 2025-10-10四川电力设计咨询有限责任公司

Patent Information

Application Number
CN202511242344.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2025-10-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing security protection system of the power system information and communication network has deficiencies in insufficient identification of protocol attacks, delayed discovery of unknown threats, and weak business continuity guarantees, and is unable to effectively respond to complex and changing network threats.

Method used

The terminal security access module, network communication protection module, business security monitoring module and security operation management module are used to realize terminal identity authentication, communication traffic analysis and detection, business data compliance verification and centralized monitoring and automated response of security incidents, combined with multi-factor authentication, in-depth analysis of power-specific protocols, machine learning and active defense driven by threat intelligence.

Benefits of technology

It achieves full coverage and closed-loop protection of the power system's information and communication network, significantly reduces security risks, quickly identifies and blocks high-risk attacks, ensures business system availability and data integrity, and enhances the power system's ability to resist attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768673A_ABST
    Figure CN120768673A_ABST
Patent Text Reader

Abstract

The invention relates to the field of electric power system information communication networks, in particular to a safety protection system based on an electric power system information communication network, which comprises a terminal safety access module used for carrying out identity authentication and access control on external terminal equipment in the electric power system information communication network, preventing illegal terminals from accessing the network, and sending the terminal safety access module to the terminal safety access module. And the network communication protection module is used for performing protocol analysis on the communication flow in the power system information communication network. Through cooperative work of four layers of modules of global coverage, closed-loop protection, terminal, network, service and operation, a global scene of an information communication network of a power system is covered, a'monitoring-analysis-response-defense 'closed loop is formed, no dead corner of security protection is realized, the security risk is remarkably reduced, the high-risk attack blocking success rate is improved, the data leakage risk is reduced, and the security and protection efficiency is improved. And the security event discovery time is shortened, and the anti-attack capability and the risk resistance level of the power system are comprehensively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of power system information communication network, in particular to a security protection system based on power system information communication network. BACKGROUND

[0002] The power system information communication network is the digital foundation supporting core businesses such as power grid operation control, dispatching management and equipment monitoring, covering all links from power generation, power transmission, power transformation, power distribution, power utilization to dispatching. With the rapid development of power system intelligence (such as smart grid and energy internet) and digitization (such as Internet of Things terminal access and cloud computing platform application), the network structure is becoming increasingly complex, business interaction is becoming more frequent, and security threats are becoming more diversified, concealed and destructive (such as APT attacks, data tampering and device hijacking). The traditional security system of "border protection + static rules" has been unable to cope with new threats.

[0003] However, the existing security protection system based on the power system information communication network has the following problems: insufficient protocol protection capability, unable to cope with power-specific protocol attacks, only detecting format abnormalities, ignoring logical vulnerabilities, lacking identification of protocol distortion attacks, terminal protection defects, unable to adapt to a large number of heterogeneous devices, making the identity authentication mechanism single, the behavior monitoring coverage insufficient, the business security coupling weak, the threat detection and response lagging, relying on static rules and manual analysis, lacking power-specific standard adaptation, and the audit and traceability capability weak. The present application solves the three core pain points in the security protection of the power system information communication network in the prior art, namely insufficient protocol attack identification, unknown threat discovery lag and weak business continuity guarantee, through technical innovation (protocol deep analysis, AI threat hunting), function integration (business and security coupling), performance optimization (second-level response, high concurrency support) and compliance enhancement (power standard adaptation). SUMMARY

[0004] The present application aims to provide a security protection system based on the power system information communication network, mainly for solving the technical problems of insufficient protocol attack identification, unknown threat discovery lag and weak business continuity guarantee in the prior art.

[0005] To solve the above technical problems, the present application provides the following technical solutions: A security protection system based on the power system information communication network, comprising a terminal security access module, a network communication protection module, a business security monitoring module and a security operation management module. The terminal security access module is used for identity authentication and access control of external terminal devices in the power system information communication network, preventing illegal terminal access to the network. A network communication protection module is configured to perform protocol analysis, abnormal traffic detection and network isolation on the communication traffic in the power system information communication network, and to block illegal communication behaviors. A business security monitoring module is configured to perform compliance verification on the power system core business data and operation instructions, and to prevent business data tampering and illegal instruction execution. A security operation management module is configured to perform centralized monitoring, correlation analysis and automatic response on the network-wide security events, and to realize closed-loop disposal of security threats.

[0006] The working principle and beneficial effects of the present application are as follows: 1. Working principle: terminal security access control is realized through the terminal security access module, so as to guarantee the legality of the terminal, and the communication traffic is deeply detected through the network communication protection module, so as to block illegal network behaviors, then the business data and operation are double-verified through the business security monitoring module, so as to prevent core business tampering, and the security event intelligent analysis and collaborative response are realized through the cooperation of the security operation management module, so as to realize threat closed-loop disposal, and the terminal security access module, the network communication protection module, the business security monitoring module and the security operation management module realize real-time data interaction (such as terminal abnormal behavior reporting to the operation management module, network isolation instruction issuing to the communication protection module) through standardized interfaces, realize the cooperative linkage of the protection capabilities of each level, and the system finally achieves the following security goals.

[0007] 2. Beneficial effects: (1) Terminal legality guarantee: through multi-factor authentication (password + digital certificate / hardware token) and behavior baseline monitoring (CPU, memory, traffic, process), illegal terminals (such as counterfeit devices, unauthorized devices) can be effectively prevented from accessing the power system information communication network, and the risk of horizontal attack (such as malicious software spreading) caused by terminal intrusion can be reduced, and the lightweight Agent design (memory occupation ≤ 50MB, CPU occupation ≤ 3%) is suitable for resource-limited IoT terminals (such as smart meters), which can guarantee security while avoiding significant impact on terminal performance, abnormal behavior is blocked in real time, and based on the dynamic monitoring of the pre-defined behavior baseline (such as abnormal login at night, data export during non-operation period), illegal operations can be identified and blocked within ≤ 1 second, and terminal hijacking and internal attack can be prevented.

[0008] (2) Power protocol level security protection supports deep analysis (field level semantic analysis) of IEC 61850, DL / T 634.5104 and other power special protocols, can identify protocol abnormal messages, illegal control instructions (such as unauthorized switch operation) and other attacks, solves the problem that traditional DPI technology can only detect "format anomalies" but cannot identify "logic vulnerabilities", the blocking rate is ≥99%, the SDN dynamic isolation technology (response time ≤1 second) realizes network partitioning, domain isolation and traffic blocking of infected terminals, prevents attack spread (such as from a single terminal to the entire substation network), and efficiently handles traffic anomalies. The response time of the abnormality detection based on the traffic baseline model (covering traffic surge, DDoS attack and other scenarios) is ≤50 milliseconds, which can quickly curb the sudden attack in the communication network and ensure the stability of power dispatching and control instruction transmission.

[0009] (3) Dual protection of business data and operation, through the national secret SM3 hash algorithm (verification time ≤10ms / MB) and compliance check rule library, the integrity of core data such as power grid topology and user electricity information is ensured; combined with LSTM+GNN machine learning model (abnormality detection recall rate ≥95%), advanced threats such as data tampering and false instructions can be identified, and the blocking success rate is ≥99.5%; business logic secondary authorization verification (response time ≤2 seconds) performs multi-level approval on key operations (such as substation switch control and power outage plan adjustment), avoiding misoperation or malicious control caused by single-point permission vulnerabilities.

[0010] (4) Threat intelligence driven active defense, interfacing with the national level power industry threat intelligence library (update frequency ≤1 hour), can quickly identify threats such as malicious IP and virus samples (matching accuracy ≥99%), realize the transition from "passive response" to "active hunting", shorten the attack discovery time to ≤0.5 hours (traditional system average 4 hours), and the correlation analysis engine based on graph database (supporting ≥100 million cross-dimension logs) can mine attack chains and potential threats (such as long-term latent behavior of APT attacks) within ≤10 seconds, improve unknown threat discovery capability, and automatically and efficiently handle SOAR tools to realize automatic response of security events (such as isolating infected equipment and banning malicious IP), high-risk event handling time ≤30 seconds, policy execution success rate ≥99%, significantly reducing the risk of manual intervention delay and misoperation.

[0011] In summary, full coverage and closed-loop protection, terminal, network, business and operation four-layer modules work together, covering the full domain scenario of power system information communication network (from terminal access to business operation to threat disposal), forming a "monitoring-analysis-response-defense" closed loop, realizing security protection without dead angle; Significantly reduce security risks, high-risk attack blocking success rate ≥ 99.5%, data leakage risk reduction ≥ 90%, security incident discovery time reduced by 80% (from an average of 4 hours to 0.5 hours), and overall improve the anti-attack capability and risk resistance level of the power system.

[0012] The terminal security access module comprises: I. An identity authentication unit for verifying the identity of an external terminal device through a multi-factor authentication mechanism, the multi-factor authentication mechanism comprising at least two of a password, a digital certificate, and a hardware token, wherein the multi-factor authentication mechanism supports three combinations of a password and a digital certificate, a password and a hardware token, and a digital certificate and a hardware token, and the authentication response time is ≤ 500 ms (for a regular external terminal device) and ≤ 1 s (for a resource-limited terminal); II. A behavior monitoring unit for collecting running state data (including CPU occupancy, memory usage, network traffic, and process list) of the external terminal device and comparing it with a predefined terminal behavior baseline to identify abnormal behavior, wherein the collected indicators are CPU occupancy (accuracy ± 1%), memory usage (accuracy ± 1%), network traffic (accuracy ± 0.1 Mbps), and process list (full collection), the behavior baseline model is dynamically updated based on historical data (update period ≤ 24 hours), the abnormal detection accuracy is ≥ 95%, and the response time for illegal behavior is ≤ 1 s (block network connection and generate an alarm); III. An admission control unit for cutting off the network connection of the external terminal device and generating an alarm information when the identity authentication of the external terminal device fails or the behavior is abnormal; The terminal security access module ensures the legality of the terminal accessing the power system information communication network through dual verification of the identity and behavior of the external terminal device.

[0013] The network communication protection module comprises: I. A protocol analysis unit for identifying abnormal combinations of power protocol fields through a logical relationship matrix, analyzing special protocol packets (including IEC61850, DL / T634.5104, and IEC60870-5-104 protocols) transmitted in the power system information communication network, and extracting key fields and operation instructions of the packets, wherein IEC61850 is a GOOSE / SV packet, the analysis fields are control instruction authority level (such as "remote control / remote adjustment" authority), data packet timing constraints (such as packet interval ≤ 100 ms), and device state association rules (such as logical matching of switch state and current value), and the protocol analysis delay is ≤ 10 ms (for a single packet); II. Abnormal traffic detection unit, for detecting abnormal features (including traffic surge, illegal protocol packets and DDoS attack traffic) in communication traffic based on traffic baseline model, and generating blocking instructions, wherein the traffic baseline model is dynamically updated based on historical traffic data (sampling period ≤ 1 minute), covering traffic surge (threshold ≥ 300% baseline), illegal protocol packets (matching feature library ≥ 100,000) and DDoS attack traffic (recognition accuracy ≥ 99%), and the detection response time is ≤ 50ms (triggering blocking instructions); III. Network isolation unit, for dynamically isolating network traffic (including partition domain isolation and infected terminal traffic blocking) through software defined network (SDN) technology to prevent illegal communication behavior from spreading, wherein the SDN dynamic isolation delay is ≤ 1s (infected terminal traffic blocking), the partition domain isolation granularity is divided according to business type (such as dispatching data network, management information region) or physical area (such as substation, power distribution room), and the isolation strategy update time is ≤ 5s; The network communication protection module protects the communication security of the power system information communication network through deep analysis of power special protocols and dynamic control of traffic.

[0014] The business security monitoring module comprises: I. Threat intelligence integration unit, for interfacing with the national-level power industry threat intelligence library to obtain the latest malicious IP address, virus sample characteristics and attack method information; II. Security event analysis unit, for performing cross-dimension correlation on security event logs (including terminal logs, network traffic logs and business operation logs) through a correlation analysis engine (based on graph database technology) to identify attack chains and potential threats; III. Data verification unit: integrity verification: national secret SM3 hash algorithm, verification time ≤ 10ms / MB (power grid topology data), ≤ 5ms / 10,000 (user electricity information); Compliance check: business rule library update period ≤ 7 days, rule matching accuracy rate ≥ 98%; IV. Abnormal behavior analysis unit: machine learning model: LSTM time series analysis: training data volume ≥ 100 million / month, abnormal detection recall rate ≥ 95%, false positive rate ≤ 5%, graph neural network (GNN): node number ≥ 100,000 (devices / users), edge number ≥ 1,000,000 (interaction relationship), attack chain mining accuracy rate ≥ 90%; Business logic verification: secondary authorization response time ≤ 2s (such as dispatching instructions requiring secondary confirmation from the dispatching center); Business operation compliance: key operation audit coverage rate: 100% (such as substation switch control, power outage plan adjustment); Illegal instruction interception rate: ≥ 99.5% (such as fake dispatching instructions, unauthorized control operations).

[0015] The security operation management module comprises: I. An automated response unit for automatically handling security events (including isolating infected devices, banning malicious IPs, and restoring business systems) through a security orchestration automation and response (SOAR) tool. The SOAR tool has a high handling efficiency: high-risk event response time ≤ 30s (such as isolating infected devices and banning malicious IPs), policy execution success rate ≥ 99%, and policy optimization period ≤ 24 hours (based on AI analysis results to dynamically adjust protection policies). The security operation management module realizes efficient response to threats in power system information communication networks.

[0016] The protocol analysis unit further comprises: I. A semantic-level analysis subunit for analyzing the logical relationship of fields in power-specific protocols (including the authority level of control instructions, the timing constraints of data messages, and the association rules of device states), and identifying abnormal combinations of protocol fields (such as illegal control authority combinations and out-of-bound value instructions). The semantic-level analysis subunit improves the detection capability of power-specific protocol attacks (such as APT attacks and logical vulnerability exploitation) through semantic-level analysis of protocol fields.

[0017] The abnormal behavior analysis unit further comprises: I. A knowledge graph construction subunit for constructing a power industry-specific threat knowledge graph, integrating device asset information, business logic rules, and historical attack event data. The knowledge graph is constructed using a Neo4j graph database, integrating device asset information (SN serial number), business logic rules (IEC 61850 protocol constraints), and historical attack events (CVE vulnerability database), and extracting entity relationships through a BERT model. II. An attack chain mining subunit for correlating and analyzing the threat knowledge graph through a graph neural network (GNN) to mine potential attack paths and unknown threats. The knowledge graph construction subunit and attack chain mining subunit improve the discovery capability of unknown attacks through AI-driven threat hunting.

[0018] The behavior monitoring unit further comprises: The lightweight agent subunit is used for deploying a low-power consumption security agent on a resource-limited external terminal device (such as a smart meter and an IoT sensor), supporting collection and caching of local behavior data in an offline environment, and synchronizing to a cloud analysis platform after networking, wherein memory occupation: ≤50 MB (resource-limited terminal), ≤100 MB (ordinary terminal), CPU occupation: ≤3% (resource-limited terminal), ≤5% (ordinary terminal), offline data cache capacity: ≥1 GB (supporting 72 hours of local storage); The lightweight agent subunit meets the security protection needs of the power external terminal device through low resource occupation design.

[0019] The data verification unit further comprises: The data encryption subunit is used for encrypting and storing and transmitting power core business data (including power grid topology and user power consumption information) by using the national SM4 algorithm. The data desensitization subunit is used for dynamically desensitizing sensitive fields according to data grading classification rules (including core data, business data and public data) (such as hiding part of the fields of user mobile phone numbers and simplifying power grid topology display). The data encryption subunit and the data desensitization subunit prevent core data leakage through multi-level data security protection.

[0020] When the system is applied to a provincial and above power system information communication network, the following security protection effects are achieved: One, the security event discovery time is shortened to 0.5 hours (the traditional system is 4 hours on average); Two, the success rate of blocking high-risk attacks reaches more than 99.5%; Three, the business system availability is not less than 99.99% (satisfying the requirement of “minute-level fault recovery” of the power system); In summary, the security event discovery time: ≤0.5 hours (from attack occurrence to system alarm); The success rate of blocking high-risk attacks: ≥99.5% (such as APT attack, data tampering attack); The business system availability: ≥99.99% (annual downtime ≤52 minutes, satisfying the requirement of “minute-level fault recovery” of the power system); The data leakage risk reduction rate: ≥90% (through encryption and access control); The system protects the terminal legitimacy, communication security, business controllability and threat response efficiency of the power system information communication network through global collaborative protection. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1A framework diagram of a security protection system based on a power system information communication network according to the present application; Figure 2 A framework diagram of an abnormal behavior analysis unit based on a power system information communication network according to the present application; Figure 3 A framework diagram of a behavior monitoring unit based on a power system information communication network according to the present application; Figure 4 A framework diagram of a data verification unit based on a power system information communication network according to the present application. DETAILED DESCRIPTION

[0022] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.

[0023] As shown in Figures 1-4 A security protection system based on a power system information communication network, comprising: I. A terminal security access module for identity authentication and access control of external terminal equipment in the power system information communication network, preventing illegal terminal access to the network, the terminal security access module comprising: an identity authentication unit for identity verification of the external terminal equipment through a multi-factor authentication mechanism, the multi-factor authentication mechanism including at least two of a password, a digital certificate and a hardware token, wherein the multi-factor authentication mechanism supports three combinations of the password and the digital certificate, the password and the hardware token, and the digital certificate and the hardware token, and the authentication response time is ≤500ms (for regular external terminal equipment) and ≤1s (for resource-limited terminal); The behavior monitoring unit is used to collect the running state data (including CPU occupancy, memory usage, network traffic and process list) of the external terminal device, and compare it with the predefined terminal behavior baseline to identify abnormal behavior. The collected indicators are: CPU occupancy (accuracy ± 1%), memory usage (accuracy ± 1%), network traffic (accuracy ± 0.1 Mbps), and process list (full collection). The behavior baseline model is dynamically updated based on historical data (update period ≤ 24 hours), with an abnormal detection accuracy of ≥ 95%. The response time for illegal behavior is ≤ 1s (block network connection and generate an alarm). The behavior monitoring unit also includes a lightweight Agent subunit, which is used to deploy a low-power security agent on resource-limited external terminal devices (such as smart meters and IoT sensors). It supports the collection and caching of local behavior data in offline environments and synchronizes to the cloud analysis platform after networking. The memory usage is ≤ 50MB (resource-limited terminal) and ≤ 100MB (ordinary terminal). The CPU occupancy is ≤ 3% (resource-limited terminal) and ≤ 5% (ordinary terminal). The offline data cache capacity is ≥ 1GB (supporting 72 hours of local storage). The admission control unit is used to cut off the network connection of the external terminal device and generate an alarm information when the identity authentication of the external terminal device fails or the behavior is abnormal. When the external terminal device accesses the network, it needs to pass through a multi-factor authentication mechanism (such as password + digital certificate, digital certificate + hardware token, etc.), and the identity authentication unit verifies its identity legitimacy. If the authentication fails, the admission control unit directly blocks the network connection of the terminal and generates an alarm; Behavior baseline monitoring: The running state data (including CPU occupancy, memory usage, network traffic, process list, etc.) of the terminal is collected by the lightweight Agent, and compared with the predefined behavior baseline model in real time. If abnormal behavior (such as data export at night during non-operating and maintenance period, process injection, etc.) is detected, the admission control unit immediately cuts off the network access permission of the terminal, preventing illegal terminals from penetrating into the internal network. II. Network communication protection module, for protocol analysis, abnormal traffic detection and network isolation of communication traffic in power system information communication network, blocking illegal communication behavior, network communication protection module includes: protocol analysis unit, for identifying abnormal combination of power protocol fields through logical relationship matrix, analyzing special protocol messages (including IEC61850, DL / T634.5104 and IEC60870-5-104 protocol) transmitted in power system information communication network, extracting key fields and operation instructions of the message, wherein IEC61850 is GOOSE / SV message, analysis fields: control instruction authority level (such as "remote control / remote adjustment" authority), data message timing constraint (such as message interval≤100ms) and device state association rule (such as logical matching of switch state and current value), protocol analysis delay:≤10ms (single message), the protocol analysis unit also includes: semantic level analysis subunit, for analyzing field level logical relationship of power special protocol (including control instruction authority level, data message timing constraint and device state association rule), identifying abnormal combination of protocol fields (such as illegal control authority combination and out-of-bound value instruction); Abnormal traffic detection unit, for detecting abnormal features (including traffic surge, illegal protocol message and DDoS attack traffic) in communication traffic based on traffic baseline model, and generating blocking instructions, wherein the traffic baseline model: based on historical traffic data (sampling period≤1 minute) dynamic update, covering traffic surge (threshold≥300% baseline), illegal protocol message (matching feature library≥100,000) and DDoS attack traffic (recognition accuracy≥99%), detection response time:≤50ms (trigger blocking instruction); Network isolation unit, for dynamic isolation of network traffic (including partition domain isolation and traffic blocking of infected terminals) through software defined network (SDN) technology, to prevent illegal communication behavior from spreading, wherein SDN dynamic isolation delay:≤1s (infected terminal traffic blocking), partition domain isolation granularity: divided by business type (such as dispatching data network, management information area) or physical area (such as substation, power distribution room), isolation strategy update time≤5s, the network communication protection module extracts key fields (such as control instruction authority level, device state association rule, data message timing constraint, etc.) through the protocol analysis unit, and compares them with the pre-defined legal protocol logic, if the field combination is abnormal (such as unauthorized control instruction, illegal state jump), it is marked as suspicious traffic; Abnormal traffic detection and dynamic isolation: The abnormal traffic detection unit identifies abnormal features (such as illegal protocol packets, threshold traffic) in communication traffic based on a traffic baseline model (dynamically updated, covering scenarios such as traffic surge, DDoS attacks), and if it determines that the traffic is attack traffic, it implements dynamic isolation (response time ≤ 1 second) on the infected terminal or attack source through the network isolation unit (based on SDN technology) to block its network access rights and prevent the attack from spreading to the entire network; Three, business security monitoring module, for compliance verification and abnormal behavior analysis unit of power system core business data and operation instruction, prevent business data tampering and illegal instruction execution, business security monitoring module includes: threat intelligence integration unit, for connecting national electric power industry threat intelligence library, get the latest malicious IP address, virus sample characteristics and attack method information, security event analysis unit, for threat intelligence integration and event response, through the correlation analysis engine (based on graph database technology) to cross-dimensionally correlate security event logs (including terminal logs, network traffic logs and business operation logs), identify attack chain and potential threats, correlation analysis engine: based on graph database (such as Neo4j), support ≥100 million cross-dimensionally correlated logs (such as terminal logs + network traffic logs + business operation logs), attack chain identification time ≤10s, log storage period: ≥180 days (comply with the requirements of the security protection), security operation management module for event response and strategy optimization, it includes automatic response unit, for through security orchestration automation and response (SOAR) tool, automatic disposal of security events (including isolation of infected equipment, ban malicious IP and restore business system), SOAR tool disposal efficiency: high-risk event response time ≤30s (such as isolation of infected equipment, ban malicious IP), strategy execution success rate ≥99%, strategy optimization period: ≤24 hours (based on AI analysis results dynamically adjust protection strategy), automation response and strategy optimization: automatic response unit through SOAR tool to automatically dispose security events (such as isolation of infected equipment, ban malicious IP, restore business system), high-risk event response time ≤30s, strategy execution success rate ≥99%, at the same time, the system based on AI analysis results dynamically optimize protection strategy (such as adjusting traffic baseline threshold, updating protocol whitelist), form "detection-response-optimization" closed-loop management; Data verification unit: integrity verification: SM3 hash algorithm, verification time ≤10ms / MB (power grid topology data), ≤5ms / 10,000 (user electricity information), the data verification unit also includes: data encryption subunit, for using SM4 algorithm to encrypt the power core business data (including power grid topology and user electricity information) for storage and transmission, data desensitization subunit, for dynamically desensitizing sensitive fields (such as hiding part of the user's mobile phone field and simplifying the power grid topology display) according to the data classification rules (including core data, business data and public data); Compliance check: business rule library update period ≤7 days, rule matching accuracy ≥98%; Abnormal behavior analysis unit: machine learning model: LSTM time series analysis: training data volume ≥100 million / month, abnormal detection recall rate ≥95%, false positive rate ≤5%, graph neural network (GNN): node number ≥100,000 (device / user), edge number ≥1,000,000 (interaction relationship), attack chain mining accuracy ≥90%, the abnormal behavior analysis unit also includes: knowledge graph construction subunit, for constructing a special threat knowledge graph for the power industry, integrating device asset information, business logic rules and historical attack event data, the knowledge graph is constructed using a Neo4j graph database, integrating device asset information (SN serial number), business logic rules (IEC 61850 protocol constraints) and historical attack events (CVE vulnerability library), extracting entity relationships through a BERT model, attack chain mining subunit, for correlating analysis of the threat knowledge graph through a graph neural network (GNN) to mine potential attack paths and unknown threats, data integrity verification and compliance check: the data verification unit of the business security monitoring module verifies the integrity of the core business data such as power grid topology, user electricity information and dispatching instructions using the SM3 hash algorithm (verification time ≤10ms / MB), and checks the compliance in combination with the pre-defined business rule library (such as dispatching instruction format, power-off plan logic), if the data is tampered with (such as mismatched hash value) or violates the business rules (such as abnormal modification of electricity price parameters), an alarm is triggered and the data is intercepted; Abnormal behavior analysis and secondary authorization verification: the abnormal behavior analysis unit identifies abnormal features (such as sudden increase in instruction frequency, boundary crossing of permissions, logic conflicts) in business operations through machine learning models (such as LSTM time series analysis instruction frequency, graph neural network mining operation correlation), and the business logic verification unit starts a secondary authorization mechanism (response time ≤2 seconds) to require the dispatching center or administrator to manually confirm, ensuring that the operation source is legal and complies with the business process; Business logic verification: secondary authorization response time ≤2s (such as dispatching instructions requiring secondary confirmation from the dispatching center); Business operation compliance: key operation audit coverage: 100% (such as substation switch control, power outage plan adjustment); Illegal instruction interception rate: ≥99.5% (such as counterfeit dispatching instructions, unauthorized control operations).

[0024] When the system is applied to the provincial and above power system information communication network, the following security protection effects are realized: I. The security event discovery time is shortened to 0.5 hours (the traditional system is 4 hours on average); II. The success rate of blocking high-risk attacks reaches more than 99.5%; III. The availability of business systems is not less than 99.99% (satisfying the requirement of "minute-level fault recovery" of the power system); In summary, the security event discovery time is ≤0.5 hours (from the occurrence of an attack to the alarm of the system); The success rate of blocking high-risk attacks is ≥99.5% (such as APT attacks and data tampering attacks); The availability of business systems is ≥99.99% (the annual downtime is ≤52 minutes, satisfying the requirement of "minute-level fault recovery" of the power system); The data leakage risk reduction rate is ≥90% (through encryption and access control).

[0025] From the above, the specific implementation manner of the present application is as follows: Step one, when the external terminal device accesses the network, it needs to pass through a multi-factor authentication mechanism (such as a combination of a password + a digital certificate, a digital certificate + a hardware token, etc.), and the identity authentication unit verifies the identity legality thereof, and if the authentication fails, the access control unit directly blocks the network connection of the terminal and generates an alarm; Behavior baseline monitoring: through a lightweight agent, the running state data (including CPU occupancy, memory usage, network traffic, process list, etc.) of the terminal is collected, and is compared with a pre-defined behavior baseline model in real time, and if an abnormal behavior (such as data export at night during a non-operation and maintenance period, process injection, etc.) is detected, the access control unit immediately cuts off the network access permission of the terminal, preventing illegal terminals from penetrating into the internal network; Step two, protocol analysis and field-level verification: the network communication protection module passes through a protocol analysis unit to deeply analyze the power special protocol message (such as the GOOSE / SV message of IEC 61850, the DL / T 634.5104 remote control instruction, etc.), extracts key fields (such as the control instruction permission level, the device state association rule, the data message time sequence constraint, etc.), and compares them with a pre-defined legal protocol logic, and if an abnormal field combination (such as an unauthorized control instruction, an illegal state jump) is found, it is marked as suspicious traffic; Abnormal traffic detection and dynamic isolation: The abnormal traffic detection unit identifies abnormal characteristics (such as illegal protocol packets, threshold traffic) in communication traffic based on a traffic baseline model (dynamically updated, covering scenarios such as traffic surge, DDoS attacks), and if it determines that the traffic is attack traffic, it implements dynamic isolation (response time ≤ 1 second) on infected terminals or attack sources through a network isolation unit (based on SDN technology) to block their network access rights and prevent the attack from spreading to the entire network. Step three, data integrity verification and compliance check: The data verification unit of the business security monitoring module verifies the integrity of core business data such as power grid topology, user electricity information, and dispatching instructions using the national SM3 hash algorithm (verification time ≤ 10 ms / MB), and checks compliance in combination with a pre-defined business rule library (such as dispatching instruction format, power outage plan logic). If the data is tampered with (such as mismatched hash values) or violates business rules (such as abnormal modification of electricity price parameters), an alarm is triggered and the data is blocked. Abnormal behavior analysis and secondary authorization verification: The abnormal behavior analysis unit identifies abnormal characteristics (such as sudden increase in instruction frequency, boundary crossing, and logic conflict) in business operations through machine learning models (such as LSTM time series analysis instruction frequency and graph neural network mining operation correlation), and the business logic verification unit initiates a secondary authorization mechanism (response time ≤ 2 seconds) for key operations (such as substation switch control and power outage plan adjustment) to require manual confirmation from the dispatching center or administrator to ensure that the operation is legal and complies with the business process. Step four, threat intelligence integration and correlation analysis: The threat intelligence integration unit of the security operations management module interfaces with the national-level electric power industry threat intelligence library in real time (update frequency ≤ 1 hour) to obtain the latest malicious IP, virus sample characteristics, and other information. The security event analysis unit uses a correlation analysis engine (based on graph database technology) to perform cross-dimensional correlation (supports processing of ≥100,000 logs per second) on terminal logs, network traffic logs, and business operation logs to mine attack chains and potential threats (such as long-term latent behavior of APT attacks). Step five, automated response and policy optimization: The automated response unit uses SOAR tools to automatically handle security incidents (such as isolating infected devices, banning malicious IPs, and restoring business systems), with a high-risk event response time of ≤ 30 seconds and a policy execution success rate of ≥ 99%. At the same time, the system dynamically optimizes the defense strategy (such as adjusting traffic baseline thresholds and updating protocol white lists) based on AI analysis results, forming a "detection-response-optimization" closed-loop management. In summary, the terminal security access module, the network communication protection module, the service security monitoring module and the security operation management module interact data in real time through standardized interfaces (such as terminal abnormal behavior reporting to the operation management module, network isolation instruction issuing to the communication protection module), realize the cooperative linkage of the protection capabilities of each level, and finally achieve the following security goals: Terminal legality: prevent illegal devices from accessing, and reduce the internal network penetration risk; Communication security: block illegal protocols and abnormal traffic, and ensure the reliability of power dispatching instruction transmission; Service controllability: prevent data tampering and illegal operation, and ensure that the power grid operation instruction is compliant; Threat response efficiency: quickly discover and dispose of security incidents, and shorten the attack impact time.

[0026] The above is only an embodiment of the present application, and well-known specific structures and characteristics in the scheme are not described in detail. It should be noted that for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which should be considered as the protection scope of the present application, and these will not affect the effect and practicality of the present application. The protection scope claimed in the present application should be subject to the content of its claims, and the specific implementation mode and the like recorded in the specification can be used to explain the content of the claims.

Claims

1. A safety protection system based on the power system information communication network, characterized in that: It includes terminal security access module, network communication protection module, business security monitoring module and security operation management module; Terminal security access module, used to authenticate and control access to external terminal devices, preventing illegal terminals from accessing the network; The network communication protection module is used to perform protocol analysis, abnormal traffic detection and network isolation on the communication traffic in the power system information communication network to block illegal communication behavior; The business security monitoring module is used to verify the compliance of the core business data and operation instructions of the power system to prevent business data tampering and illegal instruction execution; The security operations management module is used to centrally monitor, correlate and analyze security incidents across the entire network, and automatically respond to them, achieving closed-loop handling of security threats.

2. A security protection system based on the power system information communication network according to claim 1, characterized in that: The terminal security access module further comprises an identity authentication unit, a behavior monitoring unit and an access control unit. The behavior monitoring unit collects operating status data of external terminal devices and compares it with a predefined terminal behavior baseline.

3. A security protection system based on the power system information communication network according to claim 1, characterized in that: The network communication protection module also includes a protocol parsing unit, an abnormal flow detection unit and a network isolation unit, wherein the protocol parsing unit is used to parse the special protocol messages transmitted in the power system information communication network, the abnormal flow detection unit is used to detect abnormal features in the communication flow based on the flow baseline model and generate blocking instructions, and the network isolation unit is used to dynamically isolate network flow through software-defined network technology.

4. A security protection system based on the power system information communication network according to claim 1, characterized in that: The business security monitoring module is used to focus on data validation and also includes a threat intelligence integration unit, a security incident analysis unit, a data verification unit and an abnormal behavior analysis unit. The threat intelligence integration unit is connected to the national power industry threat intelligence library to identify attack chains and potential threats. The data verification unit is divided into integrity verification and compliance check. The integrity verification is the national secret SM3 hash algorithm. The abnormal behavior analysis unit is used to build a threat knowledge graph dedicated to the power industry and perform correlation analysis on the threat knowledge graph to explore potential attack paths and unknown threats. The security incident analysis unit is used for threat intelligence integration and incident response.

5. A security protection system based on the power system information communication network according to claim 1, characterized in that: The security operations management module is used to specialize in incident response and also includes an automated response unit. The automated response unit automatically handles security incidents through security orchestration automation and response tools.

6. A safety protection system based on the power system information communication network according to claim 3, characterized in that: The protocol parsing unit also includes a semantic-level parsing subunit, which parses the field-level logical relationship of the power-specific protocol and identifies abnormal combinations of protocol fields, and is used to identify abnormal combinations of power protocol fields through a logical relationship matrix.

7. A safety protection system based on the power system information communication network according to claim 4, characterized in that: The abnormal behavior analysis unit also includes a knowledge graph construction subunit and an attack chain mining subunit, wherein the knowledge graph construction subunit is used to construct a threat knowledge graph dedicated to the power industry, and the attack chain mining subunit is used to perform association analysis on the threat knowledge graph through a graph neural network.

8. The security protection system based on the power system information communication network according to claim 2, characterized in that: The behavior monitoring unit also includes a lightweight Agent subunit, which supports the collection and caching of local behavior data in an offline environment and synchronizes it to the cloud analysis platform after connecting to the network.

9. A safety protection system based on the power system information communication network according to claim 4, characterized in that: The data verification unit also includes a data encryption subunit and a data desensitization subunit, wherein the data encryption subunit adopts the national secret SM4 algorithm to encrypt, store and transmit the core business data of the power industry, and the data desensitization subunit dynamically desensitizes sensitive fields according to data classification rules.

Citation Information

Patent Citations

  • A packaging system

    IE61850B1

  • Field operation terminal security access protection and detection system

    CN110691064A

  • Network information security protection system

    CN118353702A

  • Network information security protection method and system based on artificial intelligence dynamic defense

    CN120165968A

  • Multi-class network security threat perception and active and passive cooperative response processing system and method

    CN120223394A

Cited By

  • Computer virus protection method and system

    CN121351071A

  • A computer virus protection method and system

    CN121351071B

  • Data closed-loop synchronization method and system and storage medium

    CN121887835A