Active defense method and system for information security of master station in distribution automation system

By deploying monitoring devices and trusted computing at the host layer, operating system and supporting platform layer, application layer, and network layer of the distribution automation system master station, the problem that traditional passive defense is difficult to resist unknown malicious attacks is solved, comprehensive active defense is achieved, and the security protection level of the distribution master station is improved.

CN113132318BActive Publication Date: 2025-09-16CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201911415119.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-31
Publication Date
2025-09-16
Estimated Expiration
2039-12-31

AI Technical Summary

Technical Problem

The security protection measures of the existing distribution automation system master station mainly rely on passive defense, which is difficult to effectively resist unknown malicious attacks and hacker intrusions, and there is a defense gap.

Method used

An active defense method is adopted. By deploying monitoring devices at the host layer, operating system and supporting platform layer, application layer and network layer, risk characteristics are obtained and risks are identified. Trusted computing is used to determine whether there has been tampering and malicious control. Honeypot system and sandbox system are combined to isolate and trace attacks, and a comprehensive active defense system is established.

Benefits of technology

It has improved the safety immunity capability of the distribution master station, and can provide timely and accurate warnings and respond to unknown malicious attacks, forming a comprehensive protection that combines active and passive methods, and enhancing the defense capability against unknown risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113132318B_ABST
    Figure CN113132318B_ABST
Patent Text Reader

Abstract

The present invention discloses an active defense method and system for information security of a master station of a distribution automation system. The method comprises: based on the system architecture of the distribution master station, dividing the active defense of the distribution master station into a host layer, an operating system and supporting platform layer, an application layer, and a network layer; based on monitoring devices deployed in the host layer, the operating system and supporting platform layer, the application layer, and / or the network layer, obtaining risk characteristics of the corresponding layer, and performing risk identification based on the risk characteristics to obtain trust rules; determining whether tampering and malicious control have been carried out through trusted computing based on the trust rules in the host layer, the operating system and supporting platform layer, and the application layer. The present invention changes the traditional passive defense technology of the distribution automation system into a forward-looking active defense, filling the gap of the traditional distribution master station in resisting unknown malicious attacks and comprehensively improving the security immunity capability of the distribution master station itself.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security protection for distribution automation systems, and in particular to an active defense method and system for information security of a master station of a distribution automation system. Background Art

[0002] At present, the security protection system of the distribution automation system is built on the principles of "security zoning, network dedicating, horizontal isolation, and vertical authentication", forming a deep defense system that spans the production control area and the management information area and covers the boundaries, hosts, terminals, etc. Among them, the security protection of the distribution automation system master station (referred to as the "distribution master station") includes the security protection of the master station itself, the security protection of the interaction with the terminal business, and the security protection of the system boundary, as shown in the attached Figure 1 shown.

[0003] (1) Safety protection of the main distribution station

[0004] 1) Host security requirements: The front-end server of the power distribution master station should use a secure and reinforced operating system certified by relevant departments; other servers such as database servers and workstations should use a secure operating system to meet safety and reliability requirements; the collection server should use a secure and reinforced operating system certified by relevant departments, and adopt at least one measure such as username / strong password, dynamic password, secure media, biometrics, and digital certificates to achieve user identity authentication and account management; the power distribution master station should use database, middleware and other supporting software tested and certified by relevant agencies to meet safety and reliability requirements; the operating system and supporting software should only install and run the components and applications required, and the identity authentication, access control, security audit, etc. of the operating system and database should comply with the regulations set within the industry;

[0005] 2) Regularly scan for master station vulnerabilities using special network security detection tools for the distribution automation system to discover security vulnerabilities such as weak passwords, redundant ports and services, and common viruses in the master station server, and conduct vulnerability analysis; by configuring intrusion detection and defense security equipment such as IDS / IPS, attack behaviors and malicious codes on the master station side can be detected and blocked.

[0006] (2) Security protection of business interaction between the distribution master station and the distribution terminal

[0007] The front-end of the power distribution master station is equipped with a power distribution encryption authentication device to achieve two-way identity authentication with the power distribution terminal and security protection of business data.

[0008] First, it features two-way identity authentication capabilities, using digital certificate technology to achieve two-way identity authentication with terminals, preventing unauthorized master stations from controlling terminals. Second, it provides secure data transmission, leveraging commercial cryptographic algorithms and other measures to ensure confidentiality, integrity, and anti-replay protection for business data exchanged with terminals. Third, a secure access zone is established in the production control area, physically isolating it from the production control area applications at the power distribution master station using a dedicated horizontal, one-way isolation device. All terminals connected to the production control area connect to the master station through the secure access zone.

[0009] (3) Security protection at the boundary of the main distribution station

[0010] 1) Security protection between the production control area and the main network dispatching system

[0011] The security level of the dispatching automation system is higher than that of the distribution automation system. To meet the two-way access control requirements between the two systems and prevent malicious attacks from invading the main network dispatching automation system from the distribution automation system, a power-specific horizontal one-way safety isolation device is deployed between the distribution automation master station zone I application and the main network dispatching automation system to achieve strong isolation between the two systems.

[0012] 2) Security protection between the production control area and the management information area

[0013] The security level of the distribution automation production control area is higher than that of the management information area. In order to meet the two-way access control requirements between the two areas of the distribution automation system and prevent malicious attacks from invading the production control area from the management information area, a power-specific horizontal one-way safety isolation device is deployed at the boundary of the two areas to achieve strong isolation between the two areas.

[0014] 3) Security protection with other systems

[0015] There is also a need for mutual access between the distribution automation master station system and other business systems in the same security domain, such as obtaining equipment asset information from the production management system (PMS). To meet such access control requirements, firewalls and other devices are deployed between the two systems to achieve logical isolation between the systems.

[0016] In summary, current security measures for distribution master stations focus on three key areas: first, identifying malicious attacks through the deployment of intrusion detection devices such as IDS / IPS; second, addressing malicious attacks such as tampering with business data and unauthorized access at the application layer; and third, establishing a protective "wall" through the use of physical and logical isolation devices, achieving a certain degree of network isolation. Current security measures for distribution master stations still primarily rely on passive, "blocking and detecting" defenses. These measures employ various physical isolation devices (such as power-specific horizontal one-way isolation devices and data isolation components), logical isolation devices (such as firewalls), and intrusion detection devices to establish access control rules and establish network isolation to prevent the spread of attacks. Furthermore, technologies such as identity authentication and data encryption are employed to manage device access and protect business interaction data. These protective measures can address a wide range of malicious attacks such as eavesdropping, tampering, and replay during business data interaction. However, with the diversification and openness of distribution master station communication methods and the increasing sophistication of hacker attack methods, traditional passive protection methods have limitations in preventing and detecting unknown risks and preventing hackers from invading equipment. Summary of the Invention

[0017] To address the aforementioned deficiencies in the existing technology, the present invention provides an active defense method and system for information security at the master station of a distribution automation system. To further enhance the ability of the distribution master station to defend against unknown malicious code attacks and illegal operations, it is urgent to develop active defense technologies for the master station. This technology can provide timely and accurate warnings before intrusions impact the distribution master station, and implement appropriate measures to avoid, mitigate, and reduce the risks faced by the distribution master station system. This will form a comprehensive, systematic "active + passive" protection system, enhancing the active defense capabilities of the distribution master station.

[0018] The present invention provides an active defense method for information security of a master station of a distribution automation system, comprising:

[0019] Based on the system architecture of the power distribution master station, the active defense of the power distribution master station is divided into the host layer, operating system and supporting platform layer, application layer and network layer;

[0020] Based on monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer and / or network layer, risk characteristics of the corresponding layer are obtained, and risk identification is performed based on the risk characteristics to obtain trust rules;

[0021] In the host layer, operating system, supporting platform layer and application layer, it is determined whether tampering and malicious control have occurred through trusted computing based on the trust rules.

[0022] Preferably, the monitoring device deployed in the host layer, operating system and supporting platform layer, application layer and / or network layer obtains the risk characteristics of the corresponding layer, including:

[0023] When the peripheral interface behavior measurement component is deployed in the host layer, risk feature data of the host layer is collected based on the peripheral interface behavior measurement component;

[0024] When a plug-in for acquiring operating system CPU resource usage and memory occupancy data is deployed in the operating system and supporting platform layer, risk feature data of the operating system and supporting platform layer is collected based on the plug-in for acquiring operating system CPU resource usage and memory occupancy data;

[0025] When an application process information plug-in is deployed in the application layer, risk feature data of the application layer is collected based on the application process information plug-in;

[0026] When a risk monitoring device is deployed in the network layer, various types of information of safety devices and network connection devices on the power distribution master station side are collected based on the risk monitoring device;

[0027] The risk characteristics include risk characteristic data and various types of information; the information includes network traffic, security events, access records, operation logs and operation status.

[0028] Preferably, the step of performing risk identification based on the risk characteristics to obtain trust rules includes:

[0029] Actively identify security risks using machine learning algorithms based on the risk characteristics;

[0030] When a security threat is identified, trust rules are obtained and an alarm or blocking control strategy is issued to the executor based on the policy model.

[0031] Preferably, after performing risk identification based on the risk characteristics, the method further includes:

[0032] Newly identified malicious codes and threat intelligence are shared throughout the entire power distribution master station system, and a linked intelligence library is established for network equipment and security devices at each link.

[0033] Preferably, the host layer, the operating system and the supporting platform layer, and the application layer all determine whether tampering and malicious control have occurred through trusted computing based on the trust rules, including:

[0034] Embed a trusted chip in the host layer or divide a trusted area on the CPU board, dynamically add trust rules to the trusted chip or trusted area, and use the trusted chip or trusted area as the trust source of the master station trusted computing environment;

[0035] At the host layer, the integrity of the underlying hardware drivers of the server and workstation is measured with the trust source. When the underlying hardware drivers of the server and workstation are intact, the host is started; otherwise, the host is stopped from starting.

[0036] In the operating system and supporting platform layer, when the trust source integrity of the host layer is verified, the digest value during the operating system startup process is compared with the preset digest value in the trust source. If they are consistent, the operating system is started, otherwise the startup of the operating system is stopped;

[0037] In the application layer, when the trust source integrity of the operating system and the supporting platform layer is verified, the digest value during the application startup process is compared with the preset digest value in the trust source. If they are consistent, the application is started, otherwise the startup of the application is stopped.

[0038] Preferably, a Docker container engine is deployed in the operating system and supporting platform layer.

[0039] Preferably, the designated main site business application program is deployed in a Docker container in the application layer.

[0040] Preferably, after deploying the designated main site business application in the Docker container, the method further includes:

[0041] The dispatcher control command password and user privacy in the application layer are desensitized.

[0042] Preferably, a server is allocated at the network boundary of the network layer to deploy a honeypot system to actively trap hacker attacks and isolate the attack behavior;

[0043] Deploy a sandbox system on the designated server to isolate and trace attack behaviors.

[0044] Based on the same inventive concept, the present invention also provides an active defense system for information security of a master station of a distribution automation system, comprising:

[0045] Set up in the host layer, operating system and supporting platform layer, application layer and network layer of the power distribution master station;

[0046] a risk identification module for obtaining risk characteristics of the corresponding layers based on monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer, and / or network layer, and performing risk identification based on the risk characteristics to obtain trust rules;

[0047] A trusted computing module is used to determine whether the host layer, operating system and supporting platform layer, and application layer have been tampered with or maliciously controlled through trusted computing based on the trust rules.

[0048] Preferably, the risk identification module at the host layer includes:

[0049] A monitoring device deployment unit at the host layer, configured to deploy a peripheral interface behavior measurement component at the host layer, and collect risk feature data of the host layer based on the peripheral interface behavior measurement component;

[0050] The risk identification unit at the host layer is used to actively identify security risks using machine learning algorithms on risk feature data at the host layer. It is also used to obtain trust rules when security threats are identified, and to issue alarms or blocking control strategies to the actuator based on the policy model.

[0051] Preferably, the risk identification module of the operating system and supporting platform layer includes:

[0052] A monitoring device deployment unit for the operating system and supporting platform layer, configured to deploy a plug-in for acquiring operating system CPU resource usage and memory occupancy data on the operating system and supporting platform layer, and to collect risk feature data for the operating system and supporting platform layer based on the plug-in;

[0053] The risk identification unit of the operating system and supporting platform layer is used to actively identify unknown risks based on the risk feature data of the operating system and supporting platform layer; it is also used to obtain trust rules when security threats are determined, and to issue alarms or blocking control strategies to the actuator based on the policy model.

[0054] Preferably, the risk identification module of the application layer includes:

[0055] A monitoring device deployment unit at the application layer, configured to deploy an application process information plug-in at the application layer and collect risk feature data of the application layer based on the application process information plug-in;

[0056] The risk identification unit of the application layer is used to identify the risks of application software and distribution master station services based on the risk feature data of the application layer; it is also used to obtain trust rules when a security threat is determined, and to issue an alarm or blocking control strategy to the actuator based on the policy model.

[0057] Preferably, the network layer risk identification module includes:

[0058] A monitoring device deployment unit at the network layer, configured to deploy a risk monitoring device at the network layer and collect various types of information on safety devices and network connection devices at the power distribution master station based on the risk monitoring device;

[0059] The risk identification unit of the network layer is used to identify risks based on the various types of information; it is also used to obtain trust rules when a security threat is determined, and to issue an alarm or blocking control strategy to the actuator based on the strategy model.

[0060] Preferably, the risk identification modules of the host layer, operating system and supporting platform layer, and application layer further include:

[0061] The risk prevention unit is used to share newly identified malicious codes and threat intelligence throughout the entire power distribution master station system, and establish a linked intelligence library for network equipment and security equipment in each link.

[0062] Preferably, the trusted computing module of the host layer is specifically used to measure the integrity of the underlying hardware drivers of the server and workstation with the trusted source, and when the underlying hardware drivers of the server and workstation are intact, the host is started, otherwise the host is stopped from starting;

[0063] The trusted computing module of the operating system and supporting platform layer is specifically used to compare the digest value during the operating system startup process with the preset digest value in the trusted source when the trust source integrity of the host layer is verified. If they are consistent, the operating system is started, otherwise the operating system is stopped from starting;

[0064] The trusted computing module of the application layer is specifically used to compare the summary value during the application startup process with the preset summary value in the trust source when the trust source integrity of the operating system and the supporting platform layer is verified. If they are consistent, the application is started; otherwise, the application is stopped from starting.

[0065] Preferably, the operating system and supporting platform further include:

[0066] Container engine unit, used to deploy the Docker container engine.

[0067] Preferably, the application layer further includes:

[0068] Container isolation unit, used to deploy the specified main site business application in a Docker container;

[0069] The data desensitization unit is used to perform data desensitization processing on the dispatcher control command password and user privacy in the application layer.

[0070] Preferably, the network layer includes:

[0071] The first protection unit is used to proactively trap hacker attacks and isolate attack behaviors based on the deployed honeypot system;

[0072] The second protection unit is used to deploy a sandbox system to collect evidence of attack behaviors, isolate the attacks, and trace their source.

[0073] Compared with the prior art, the present invention has the following beneficial effects:

[0074] The technical solution provided by the present invention is based on the system architecture of the distribution master station, and divides the active defense of the distribution master station into the host layer, operating system and supporting platform layer, application layer and network layer; based on the monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer and / or network layer, the risk characteristics of the corresponding layer are obtained, and risk identification is performed based on the risk characteristics to obtain trust rules; in the host layer, operating system and supporting platform layer and application layer, it is determined through trusted computing based on the trust rules whether tampering and malicious control have been carried out. The present invention can change the traditional passive defense technology of the distribution automation system into a forward-looking active defense through the host layer, operating system and supporting platform layer, application layer and network layer; as well as risk characteristic identification and trusted computing, filling the gap of the traditional distribution master station in resisting unknown malicious attacks, forming an integrated active defense system of the distribution master station from the host layer, operating system layer and network layer, and comprehensively improving the security immunity capability of the distribution master station itself.

[0075] The technical solution provided by the present invention dynamically supplements trust rules for a trusted computing system through risk identification, making trusted computing more comprehensive. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] Figure 1 This is the current power distribution automation system safety protection system of the present invention;

[0077] Figure 2 This is a flow chart of an active defense method for information security of a master station of a power distribution automation system according to the present invention;

[0078] Figure 3 This is a schematic diagram of the trusted protection of the main unit of the power distribution master station of the present invention;

[0079] Figure 4 This is a schematic diagram of containerized deployment of a power distribution master station application according to the present invention;

[0080] Figure 5 This is the Storm-based streaming data processing process of the power distribution master station of the present invention;

[0081] Figure 6 This is the batch data desensitization process of the power distribution master station of the present invention;

[0082] Figure 7 This is a schematic diagram of the active defense linkage strategy for the power distribution master station network boundary of the present invention;

[0083] Figure 8 This is a schematic diagram of the active defense architecture of the power distribution master station of the present invention. DETAILED DESCRIPTION

[0084] In order to better understand the present invention, the present invention is further described below with reference to the accompanying drawings and examples.

[0085] Example 1

[0086] like Figure 2 As shown, the present invention provides an active defense method for information security of a master station of a distribution automation system, comprising:

[0087] S1. Based on the system architecture of the power distribution master station, the active defense of the power distribution master station is divided into the host layer, operating system and supporting platform layer, application layer and network layer;

[0088] S2. Based on monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer, and / or network layer, obtain risk characteristics of the corresponding layer, and perform risk identification based on the risk characteristics to obtain trust rules;

[0089] S3. In the host layer, operating system and supporting platform layer, and application layer, it is determined through trusted computing based on the trust rules whether tampering and malicious control have occurred.

[0090] In the present invention, trust rules obtained based on risk identification are dynamically added to the rule base, providing a basis for trusted computing and enabling trusted computing to discover risks more comprehensively.

[0091] S2. The monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer, and / or network layer obtain risk characteristics of the corresponding layers, including:

[0092] When the peripheral interface behavior measurement component is deployed in the host layer, risk feature data of the host layer is collected based on the peripheral interface behavior measurement component;

[0093] When a plug-in for acquiring operating system CPU resource usage and memory occupancy data is deployed in the operating system and supporting platform layer, risk feature data of the operating system and supporting platform layer is collected based on the plug-in for acquiring operating system CPU resource usage and memory occupancy data;

[0094] When an application process information plug-in is deployed in the application layer, risk feature data of the application layer is collected based on the application process information plug-in;

[0095] When a risk monitoring device is deployed in the network layer, various types of information of safety devices and network connection devices on the power distribution master station side are collected based on the risk monitoring device;

[0096] The risk characteristics include risk characteristic data and various types of information; the information includes network traffic, security events, access records, operation logs and operation status.

[0097] Furthermore, risk identification is performed based on the risk characteristics to obtain trust rules, including:

[0098] Actively identify security risks using machine learning algorithms based on the risk characteristics;

[0099] When a security threat is identified, trust rules are obtained and an alarm or blocking control strategy is issued to the executor based on the policy model.

[0100] After risk identification based on the risk characteristics, the newly identified malicious code and threat intelligence are shared throughout the entire power distribution master station system, and a linked intelligence library is established for the network equipment and security equipment in each link.

[0101] S3. Determining whether tampering and malicious control have occurred in the host layer, operating system and supporting platform layer, and application layer through trusted computing based on the trust rules, including:

[0102] Embed a trusted chip in the host layer or divide a trusted area on the CPU board, dynamically add trust rules to the trusted chip or trusted area, and use the trusted chip or trusted area as the trust source of the master station trusted computing environment;

[0103] At the host layer, the integrity of the underlying hardware drivers of the server and workstation is measured with the trust source. When the underlying hardware drivers of the server and workstation are intact, the host is started; otherwise, the host is stopped from starting.

[0104] In the operating system and supporting platform layer, when the trust source integrity of the host layer is verified, the digest value during the operating system startup process is compared with the preset digest value in the trust source. If they are consistent, the operating system is started, otherwise the startup of the operating system is stopped;

[0105] In the application layer, when the trust source integrity of the operating system and the supporting platform layer is verified, the digest value during the application startup process is compared with the preset digest value in the trust source. If they are consistent, the application is started, otherwise the startup of the application is stopped.

[0106] Docker container engine deployed in the operating system and supporting platform layers.

[0107] In the application layer, the specified main site business application is deployed in a Docker container.

[0108] After deploying the designated main station business application in the Docker container, the dispatcher control command password and user privacy in the application layer are desensitized.

[0109] In this embodiment, a server is allocated at the network boundary of the network layer to deploy a honeypot system to actively trap hacker attacks and isolate the attack behavior;

[0110] Deploy a sandbox system on the designated server to isolate and trace attack behaviors.

[0111] Example 2

[0112] Based on the same inventive concept, the present invention also provides an active defense system for information security of a master station of a distribution automation system, comprising:

[0113] According to the system architecture of the distribution master station, the active defense of the production control area and the management information area in the distribution master station is divided into four different levels: the distribution master station host layer, the operating system and supporting platform layer, the application layer, and the network layer:

[0114] (1) Active defense at the host layer of the power distribution master station

[0115] Active defense at the host layer includes the following two aspects:

[0116] The first is to use trusted computing to achieve trusted protection at the hardware layer: First, the hardware layer divides the TPM trusted root as the trust source of the entire power distribution master station trusted system. This can be achieved by embedding a trusted chip or dividing the trusted area on the CPU board to ensure that the trusted chip or trusted area meets the TPM standard and cannot be illegally accessed; secondly, using the trusted root as the trust source, measure the integrity of the underlying hardware drivers of the server and workstation (that is, measure the integrity of the BIOS) to determine whether the hardware driver has been tampered with. If it is found to be damaged, the host will automatically stop starting. Trusted protection of the host is as follows: Figure 3 shown

[0117] The second is to measure the behavior of the main station's peripheral interfaces. Peripheral interfaces include USB ports, network ports, serial ports, and parallel ports. These interfaces are usually hot-swappable and have unified communication standards, making them easy targets for hackers to exploit. Therefore, it is necessary to monitor and control their behavior and control illegal operations.

[0118] At present, behavioral control of peripheral interfaces has been implemented for systems with higher security requirements. For example, by deploying a dedicated secure mobile storage media management system in the server, the use permissions of mobile storage media, mouse, keyboard, and printer are controlled, and usage behavior logs are recorded and audited, including access time, transmission content and other information; and it is stipulated that only dedicated secure storage media can access the server, and security authentication must be passed when exchanging data; in addition, when the storage medium is accessed, it is first scanned for viruses through antivirus software to avoid cross-infection and ferrying attacks on different hosts through peripheral devices.

[0119] On this basis, in order to further improve the host's active security defense capabilities, the peripheral interface behavior feature monitoring method can be adopted to monitor the characteristics of the files transmitted, the processes caused, etc., and through linkage with the machine learning module, an anomaly recognition mechanism can be established to achieve active identification of unknown risks.

[0120] (2) Active defense of operating systems and supporting platforms

[0121] Active defense at the operating system layer and supporting platform layer includes the following two aspects:

[0122] First, risk identification is achieved by monitoring the vulnerabilities, system files, resource usage and other characteristics of the operating system / database, etc. For known system-level vulnerabilities, a known vulnerability library can be established to achieve targeted and comprehensive scanning and judgment of various forms of vulnerabilities. For example, a network security analysis tool dedicated to power distribution is used to regularly scan the vulnerabilities of the main station system. The present invention classifies it as a passive defense category; for unknown system vulnerabilities, the vulnerability library method is no longer able to identify them, and the only way is to block the attack behavior by monitoring the abnormal characteristics that may be caused after they are exploited, so as to achieve the purpose of active defense. Abnormal behavior can be characterized by characteristics such as process characteristics, system resource usage (such as CPU usage, memory usage), and API interface calls. Therefore, it is necessary to monitor the above characteristics and establish an abnormal identification mechanism through linkage with the machine learning module to achieve active identification of unknown risks.

[0123] The second is trusted computing of the operating system and supporting platform to prevent illegal tampering with the system and platform. The trust measurement of the operating system and supporting platform is based on the trusted root and trust chain transmission at the host layer. Only when the integrity of the trusted root is intact can the integrity identification value (such as hash value or signature value) of the operating system and supporting platform be calculated through the trust mechanism to identify whether the system has been tampered with or maliciously controlled. If the identification value is inconsistent, it indicates that the system has been tampered with, and the server will stop starting.

[0124] (3) Active defense at the application layer

[0125] Active defense at the application layer includes the following four aspects:

[0126] 1) Risk identification

[0127] Including risk monitoring and identification of application software, and risk monitoring and identification of distribution master station business.

[0128] ① Risk monitoring and identification of application software. Risk monitoring of application software includes its own vulnerabilities, processes, resource usage and other characteristics. For known software vulnerabilities, they can be identified through a vulnerability library. This technology is already very mature, and the present invention classifies it as passive defense. Active defense mainly solves the identification of unknown vulnerabilities. There is no pre-established rule library for unknown vulnerabilities. Therefore, the identification of unknown vulnerabilities can only be achieved by monitoring the abnormal behavior characteristics that may be caused once they are exploited. Such as a sudden increase in CPU usage, a sudden increase in memory usage, abnormal process behavior, and calls to core API interfaces.

[0129] ② Risk monitoring and identification of distribution master station services. Monitoring of distribution master station services primarily involves monitoring the command messages issued by them, such as those for time synchronization, remote control, terminal parameter settings, and remote terminal program upgrades, to determine whether their format, integrity, and other content have been compromised.

[0130] 2) Trusted Computing

[0131] Trusted computing at the application layer is based on the trust chain transmission of the operating system and platform layer. Only when the integrity of the operating system and platform layer is not damaged, the integrity identification value of the application software is calculated through the trust mechanism to identify whether the application has been tampered with or maliciously controlled.

[0132] 3) Container Isolation

[0133] like Figure 4 As shown, the master station and important production business-related applications (such as SCADA, load transfer, integrated alarm, etc.) are put into Docker containers for operation, and each container can store one or more applications.

[0134] Docker consists of the following three components: Docker image (Image), Docker container (Container), Docker repository (Repository);

[0135] 1. Docker Image

[0136] A Docker image is a read-only template. For example, an image can contain a complete virtual machine operating system environment (e.g., Ubuntu), with only Apache or other required applications installed. Images can be used to create Docker containers. Docker also provides a simple mechanism for creating images or updating existing ones. Users can even download pre-made images from others for immediate use.

[0137] 2. Docker container

[0138] Docker uses containers to run applications. A container is a running instance created from an image and can be started, started, stopped, and deleted. Each container is an isolated and secure platform. Think of a container as a simplified Linux environment (including root user permissions, process space, user space, and network space) and the applications running within it.

[0139] 3. Docker Repository

[0140] A repository is a centralized location for storing image files. A registry server (registry) hosts multiple repositories, each containing multiple images, each with a unique tag. Once a user creates an image, they can use the push command to upload it to a public or private repository. The next time they want to use the image on another machine, they simply download it from the repository (pull).

[0141] Container isolation technology at the application layer establishes a virtual operating system for each or several applications to isolate each application, prevent the spread of malicious code and other viruses between different applications, and prevent attackers from attempting to obtain sensitive information from other applications or control other programs through one application.

[0142] 4) Data desensitization

[0143] Data desensitization technology at the application layer can prevent the leakage of sensitive information such as important production data (for example, the storage of dispatcher control command passwords) or user privacy. According to the application scenario of the data, the master station side data desensitization is divided into dynamic data desensitization and static data desensitization. For data with high real-time requirements, dynamic data desensitization (streaming data desensitization technology, such as the issuance and response of control instructions, telemetry / telecommunication messages, etc.) is adopted, and desensitization can be performed when sensitive data is used; for data with low real-time requirements, static data desensitization (batch data desensitization technology, such as terminal channels and point table configuration information) is adopted, and desensitization can only be performed when the data is in an inactive state (such as data storage desensitization).

[0144] ① Based on Storm streaming data desensitization technology

[0145] Storm is a distributed, reliable, and fault-tolerant data stream processing system. The input streams of the cluster are managed by Spout components. After a Spout passes data to a Bolt, the Bolt either passes the data to other Bolts or saves the data to some storage. A Storm cluster converts data passed by Spouts between a series of Bolts.

[0146] Since Storm's data processing method is incremental real-time processing, the data desensitization module should have the function of incremental data desensitization. When the data has not been fully transmitted, the desensitization module can be used to read historical data and combine it with the corresponding algorithm to desensitize the data, remove sensitive words, and generalize the data according to the desensitization rules. The advantage of streaming data desensitization is that data processing is performed from the moment the data begins to be transmitted, which matches the generation and transmission characteristics of the business data of the power distribution master station. The streaming data processing process based on Storm is as follows: Figure 5 shown.

[0147] ②Batch data desensitization technology

[0148] Batch data access means that the data comes from a stable and basically unchanged storage medium, and the data is collected into the data platform at one time through data scanning. The data is mainly historical data, and the data source generally comes from files, relational databases, NoSQL databases, etc. Batch data desensitization can be performed during the data import process, or after the data enters the data platform, the desensitization program module can be called to perform desensitization. Batch data desensitization can be combined with the correlation relationship of the data and use complex desensitization algorithms to achieve better desensitization effects. Batch data desensitization process is as follows: Figure 6 As shown, for log information, a desensitization method based on Flume is used, and for database information, a desensitization method based on Sqoop is used. Flume is a highly available, highly reliable, distributed system for massive log collection, aggregation and transmission; FlumeInterceptor is Flume's data interceptor, which calls the data desensitization program in the interceptor and outputs the desensitized data. The data then passes through the illegal information interceptor (Unid Interceptor) to complete illegal data filtering; Sqoop is suitable for data collection in relational databases. It can create intermediate tables, write user-defined functions and programs, and finally perform data desensitization in batches through the task scheduler. The data formed based on the two desensitization methods will eventually enter the Hadoop Cluster (distributed system architecture group) and will be distributed to each master station application for continued use along with the data scheduling link.

[0149] (4) Active defense at the network layer

[0150] The network protection objects of the distribution master station include the network boundary of the distribution master station (the boundary between the production control area and the management information area, and the boundary between the production control area and the security access area) and the network connection nodes of the internal server of the distribution master station.

[0151] The message interaction and network traffic at the network boundary provide excellent input resources for active defense. The traffic situation at the network boundary can be obtained by deploying security monitoring probes or through the interfaces of specified switches and security devices. Network connection nodes can collect attack behavior evidence by deploying security sandboxes, and realize log collection and analysis of malicious files and security events.

[0152] By modeling the collected data, malicious attacks are identified. At the same time, honeypot trapping functions are deployed in switches and firewalls. After redirecting illegal scanning and other attack messages to the honeypot, the honeypot interacts with it by providing false resources and further determines its attack intentions, thus achieving diversion linkage and realizing active real-time defense. Figure 7 shown.

[0153] This embodiment takes a distribution automation master station system as an example. Figure 8 As shown, the active defense technology of the integrated host layer, operating system and supporting platform layer, application layer, and network layer is based on the risk identification and prevention system and trusted computing as the two major support systems, supplemented by the operating system and supporting platform, the container isolation technology of the main station business application, data desensitization and the active trapping of the network and the security sandbox technology, to jointly build the active defense architecture of the distribution master station.

[0154] (1) Host layer

[0155] A TPM trusted chip is embedded on the host motherboard of the power distribution master station as the trust source of the master station's trusted computing environment, and a peripheral interface behavior measurement component is deployed to collect host layer risk feature data.

[0156] (2) Operating system and supporting platform layer

[0157] Taking the trusted chip at the host layer as the trust source, the summary value during the operating system startup process is calculated and compared with the preset summary value stored in the TMP chip. If they are consistent, the operating system can be started normally. If they are inconsistent, the startup is stopped immediately. A plug-in for obtaining the operating system's CPU resource utilization and memory occupancy data is deployed to collect risk feature data of the operating system and supporting platform layer. In addition, a Docker container engine needs to be deployed at the operating system layer.

[0158] (3) Application layer

[0159] Based on the integrity of the operating system and supporting platform layer, the summary value during the application startup process is calculated and compared with the preset summary value stored in the TMP chip. If they are consistent, the application can be started normally. If they are inconsistent, the startup is stopped immediately. An application process information plug-in is deployed to collect risk feature data at the application layer. In addition, important main station business applications (such as SCADA, load transfer, and integrated alarms) need to be deployed in Docker containers, and the dispatcher's control command passwords and user privacy must be desensitized.

[0160] (4) Network layer

[0161] A server is allocated at the network boundary of the power distribution master station system to deploy a honeypot system to actively trap hacker attacks and isolate the attack behavior; a sandbox system is deployed on important servers, and behaviors such as WEB browsing are all run through the sandbox system, which helps to isolate and trace the attack behavior in a timely manner.

[0162] The risk identification and prevention system includes four parts: feature monitoring, risk identification, risk assessment, and risk prevention, forming a risk monitoring strategy of "intelligent analysis, reputation sharing, and policy linkage": by deploying risk monitoring devices (probes or interfaces), network traffic, security events, access records, operation logs, operating status, and other types of information are collected from security equipment and network connection equipment on the distribution master station side; based on the collected data, machine learning algorithms are used to actively identify security risks; once a security threat is determined, corresponding control strategies such as alarms and blocking are issued to the actuator (such as a firewall or switch) based on the policy model; at the same time, newly identified malicious codes and threat intelligence will also be shared throughout the distribution master station system, and a linkage intelligence library will be established for the network equipment and security equipment in each link to achieve reputation sharing. In this embodiment, the risk identification and prevention system can be deployed in one or more layers of the host layer, operating system and supporting platform layer, application layer, and network layer.

[0163] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0164] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0165] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0166] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0167] The above are merely embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are included in the scope of the claims of the present invention to be approved.

Claims

1. An active defense method for information security of a master station of a distribution automation system, characterized in that: include: Based on the system architecture of the power distribution master station, the active defense of the power distribution master station is divided into the host layer, operating system and supporting platform layer, application layer and network layer; Based on monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer and / or network layer, risk characteristics of the corresponding layer are obtained, and risk identification is performed based on the risk characteristics to obtain trust rules; In the host layer, operating system and supporting platform layer and application layer, whether tampering and malicious control have been carried out is determined through trusted computing based on the trust rules; Trust rules obtained based on risk identification are dynamically added to the rule base; The step of performing risk identification based on the risk characteristics to obtain trust rules includes: Actively identify security risks using machine learning algorithms based on the risk characteristics; When a security threat is identified, trust rules are obtained and an alarm or blocking control strategy is issued to the executor based on the policy model.

2. The method according to claim 1, wherein The monitoring device deployed in the host layer, operating system and supporting platform layer, application layer and / or network layer obtains the risk characteristics of the corresponding layer, including: When the peripheral interface behavior measurement component is deployed in the host layer, risk feature data of the host layer is collected based on the peripheral interface behavior measurement component; When a plug-in for acquiring operating system CPU resource usage and memory occupancy data is deployed in the operating system and supporting platform layer, risk feature data of the operating system and supporting platform layer is collected based on the plug-in for acquiring operating system CPU resource usage and memory occupancy data; When an application process information plug-in is deployed in the application layer, risk feature data of the application layer is collected based on the application process information plug-in; When a risk monitoring device is deployed in the network layer, various types of information of safety devices and network connection devices on the power distribution master station side are collected based on the risk monitoring device; The risk characteristics include risk characteristic data and various types of information; the information includes network traffic, security events, access records, operation logs and operation status.

3. The method according to claim 1, wherein After the risk identification is performed based on the risk characteristics, the method further includes: Newly identified malicious codes and threat intelligence are shared throughout the entire power distribution master station system, and a linked intelligence library is established for network equipment and security devices at each link.

4. The method according to claim 1, wherein The host layer, the operating system and the supporting platform layer, and the application layer are all determined based on the trust rules through trusted computing to determine whether tampering and malicious control have occurred, including: Embed a trusted chip in the host layer or divide a trusted area on the CPU board, dynamically add trust rules to the trusted chip or trusted area, and use the trusted chip or trusted area as the trust source of the master station trusted computing environment; At the host layer, the integrity of the underlying hardware drivers of the server and workstation is measured with the trust source. When the underlying hardware drivers of the server and workstation are intact, the host is started; otherwise, the host is stopped from starting. In the operating system and supporting platform layer, when the trust source integrity of the host layer is verified, the digest value during the operating system startup process is compared with the preset digest value in the trust source. If they are consistent, the operating system is started, otherwise the startup of the operating system is stopped; In the application layer, when the trust source integrity of the operating system and the supporting platform layer is verified, the digest value during the application startup process is compared with the preset digest value in the trust source. If they are consistent, the application is started, otherwise the startup of the application is stopped.

5. The method according to claim 1, wherein The Docker container engine is deployed in the operating system and supporting platform layer.

6. The method according to claim 5, wherein In the application layer, the designated main site business application program is deployed in a Docker container.

7. The method according to claim 6, wherein After deploying the designated main site business application in the Docker container, the following steps are also included: The dispatcher control command password and user privacy in the application layer are desensitized.

8. The method according to claim 1, wherein A server is allocated at the network boundary of the network layer to deploy a honeypot system to actively trap hacker attacks and isolate the attack behavior; Deploy a sandbox system on the designated server to isolate and trace attack behaviors.

9. An active defense system for information security of the master station of a distribution automation system, characterized in that: include: Set up in the host layer, operating system and supporting platform layer, application layer and network layer of the power distribution master station; a risk identification module for obtaining risk characteristics of the corresponding layers based on monitoring devices deployed in the host layer, operating system and supporting platform layer, application layer, and / or network layer, and performing risk identification based on the risk characteristics to obtain trust rules; A trusted computing module, configured to determine whether the host layer, operating system and supporting platform layer, and application layer have been tampered with or maliciously controlled through trusted computing based on the trust rules; Trust rules obtained based on risk identification are dynamically added to the rule base; The risk identification module of the application layer includes: A monitoring device deployment unit at the application layer, configured to deploy an application process information plug-in at the application layer and collect risk feature data of the application layer based on the application process information plug-in; The risk identification unit of the application layer is used to identify the risks of application software and distribution master station services based on the risk feature data of the application layer; it is also used to obtain trust rules when a security threat is determined, and to issue an alarm or blocking control strategy to the actuator based on the policy model.

10. The system according to claim 9, wherein The risk identification module of the host layer includes: A monitoring device deployment unit at the host layer, configured to deploy a peripheral interface behavior measurement component at the host layer, and collect risk feature data of the host layer based on the peripheral interface behavior measurement component; The risk identification unit at the host layer is used to actively identify security risks using machine learning algorithms on risk feature data at the host layer. It is also used to obtain trust rules when security threats are identified, and to issue alarms or blocking control strategies to the actuator based on the policy model.

11. The system according to claim 9, wherein The risk identification module of the operating system and supporting platform layer includes: A monitoring device deployment unit for the operating system and supporting platform layer, configured to deploy a plug-in for acquiring operating system CPU resource usage and memory occupancy data on the operating system and supporting platform layer, and to collect risk feature data for the operating system and supporting platform layer based on the plug-in; The risk identification unit of the operating system and supporting platform layer is used to actively identify unknown risks based on the risk feature data of the operating system and supporting platform layer; it is also used to obtain trust rules when security threats are determined, and to issue alarms or blocking control strategies to the actuator based on the policy model.

12. The system according to claim 9, wherein The risk identification module of the network layer includes: A monitoring device deployment unit at the network layer, configured to deploy a risk monitoring device at the network layer and collect various types of information on safety devices and network connection devices at the power distribution master station based on the risk monitoring device; The risk identification unit of the network layer is used to identify risks based on the various types of information; it is also used to obtain trust rules when a security threat is determined, and to issue an alarm or blocking control strategy to the actuator based on the strategy model.

13. The system according to claim 9, wherein: The risk identification modules for the host layer, operating system, supporting platform layer, and application layer also include: The risk prevention unit is used to share newly identified malicious codes and threat intelligence throughout the entire power distribution master station system, and establish a linked intelligence library for network equipment and security equipment in each link.

14. The system according to claim 9, wherein: The trusted computing module of the host layer is specifically used to measure the integrity of the underlying hardware drivers of the server and workstation with the trusted source, and when the underlying hardware drivers of the server and workstation are intact, the host is started, otherwise the host is stopped; The trusted computing module of the operating system and supporting platform layer is specifically used to compare the digest value during the operating system startup process with the preset digest value in the trusted source when the trust source integrity of the host layer is verified. If they are consistent, the operating system is started, otherwise the operating system is stopped from starting; The trusted computing module of the application layer is specifically used to compare the summary value during the application startup process with the preset summary value in the trust source when the trust source integrity of the operating system and the supporting platform layer is verified. If they are consistent, the application is started; otherwise, the application is stopped from starting.

15. The system according to claim 9, wherein: The operating system and supporting platform also include: Container engine unit, used to deploy the Docker container engine.

16. The system according to claim 15, wherein: The application layer further includes: Container isolation unit, used to deploy the specified main site business application in a Docker container; The data desensitization unit is used to perform data desensitization processing on the dispatcher control command password and user privacy in the application layer.

17. The system of claim 9, wherein: The network layer includes: The first protection unit is used to proactively trap hacker attacks and isolate attack behaviors based on the deployed honeypot system; The second protection unit is used to deploy a sandbox system to collect evidence of attack behaviors, isolate the attacks, and trace their source.

Citation Information

Patent Citations

  • Trusted computing cryptogram platform suitable for general computation platform of electric system

    CN105468978A