A knowledge graph generation method and system for vulnerability analysis of a power monitoring system

By using knowledge graph generation methods, security risk data of power monitoring systems are acquired and analyzed. Keyword importance is configured, and a nine-square grid heatmap of IP addresses and a knowledge graph are generated. This solves the intelligent requirement for security vulnerability analysis of power monitoring systems and enables efficient assessment and analysis of power system vulnerabilities.

CN113961716BActive Publication Date: 2026-01-06STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +3
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111239041.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-25
Publication Date
2026-01-06
Estimated Expiration
2041-10-25

AI Technical Summary

Technical Problem

Existing technologies cannot effectively meet the intelligent requirements of power monitoring system security vulnerability analysis, lack the ability to discover, analyze and handle internal security vulnerabilities of power monitoring systems, and graph databases are insufficiently applied in power system security vulnerability analysis.

Method used

By employing a knowledge graph generation method, security risk assessment data is acquired, keyword importance weights are configured, and the data is converted into digital tags to generate a nine-square grid heatmap of IP addresses. Based on this heatmap, a knowledge graph is generated to visually display the risk and vulnerability levels of IP addresses and analyze the vulnerabilities of the power monitoring system and their impact.

Benefits of technology

It enables intuitive analysis and assessment of the vulnerabilities of power monitoring systems, reduces the possibility of detection oversights, can extract security events that require key monitoring, and improves the accuracy of power system security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113961716B_ABST
    Figure CN113961716B_ABST
Patent Text Reader

Abstract

The application discloses a kind of knowledge graph generation method and system for electric power monitoring system vulnerability analysis, method includes: obtaining security risk assessment actual data and is divided into open service data and vulnerability data;Based on the keyword of actual data obtained, configure the weight of keyword importance, convert the literal information of actual data into numbers, obtain the digital label corresponding to different data;According to the high, medium and low of risk value and vulnerability, the digital label is graded, the IP address number of digital label contained in each grade after grading is counted, and the IP address number heat map is generated;Based on IP address number heat map, obtain the association information of open service data and vulnerability data, generate knowledge graph for analyzing the vulnerability of electric power monitoring system according to the association information.The application can meet the intelligent demand of electric power industry, and the application has a significant advantage in the defect level and risk level of electric power system security vulnerability analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a knowledge graph generation method and system for vulnerability analysis of power monitoring systems, belonging to the field of power trading technology. Background Technology

[0002] Ensuring the security of power systems is a crucial factor in national economic development. Currently, while power monitoring systems have achieved a basic level of cybersecurity situational awareness at the macro level, they still lack the capability to discover, analyze, and address internal security vulnerabilities. Therefore, utilizing knowledge graph-based dynamic vulnerability assessment technology can enable multi-dimensional mining of the deep relationships between security vulnerabilities in critical information infrastructure of power monitoring systems. This allows for the scientific and dynamic analysis and assessment of these vulnerabilities and their impacts. Currently, knowledge graphs are primarily implemented on graph databases.

[0003] Graph databases are essentially a new type of NoSQL database, where data is primarily based on graph theory. Because graph databases are non-relational, they are better suited for solving complex relational problems. Relational databases, due to their computational and memory-intensive nature, often require multi-server clusters for processing. Furthermore, other NoSQL databases are often tailored to different data models, exhibiting strong specificity and targeting. Therefore, for applications involving vulnerability and risk level analysis in power system security, graph databases outperform relational databases and other NoSQL databases when compared side-by-side.

[0004] The current application of knowledge graph technology and graph databases is insufficient to meet the intelligent needs of the power industry today, and cannot meet the need to build knowledge graph entity relationships when analyzing the security vulnerabilities of power systems. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a knowledge graph generation method and system for vulnerability analysis of power monitoring systems. This method can intuitively and clearly display the existing quantity and distribution of IP addresses in terms of risk and vulnerability levels, reducing the possibility of detection oversights. To achieve the above objective, this invention employs the following technical solution:

[0006] In a first aspect, the present invention provides a knowledge graph generation method for vulnerability analysis of power monitoring systems, the method comprising:

[0007] Obtain actual security risk assessment data and categorize it into open service data and vulnerability data;

[0008] Based on the keywords of the acquired actual data, the importance weight of the keywords is configured, and the text information of the actual data is converted into numbers to obtain numerical labels corresponding to different data.

[0009] The digital tags are classified into high, medium, and low risk values ​​and vulnerabilities. The number of IP addresses contained in each level after classification is counted, and a nine-square heat map of IP address count is generated.

[0010] Based on the generated nine-square grid heatmap of IP addresses, the correlation information between open service data and vulnerability data is obtained, and a knowledge graph is generated based on the obtained correlation information.

[0011] In conjunction with the first aspect, the actual data for the security risk assessment further includes asset information and security risk assessment data;

[0012] The asset information includes: equipment name, equipment region, equipment IP address, and equipment operating security zone;

[0013] The security risk assessment data includes: the number of equipment security risks and the verification time.

[0014] In conjunction with the first aspect, preferably, the digital tags corresponding to the asset information and security risk assessment data are the base tags.

[0015] In conjunction with the first aspect, the open service data further includes device data, service data, and open service descriptions;

[0016] The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time;

[0017] The service data includes the service name, port, and port operating protocol;

[0018] The core data includes the service name and port.

[0019] In conjunction with the first aspect, the vulnerability data further includes device data, vulnerability data, and a detailed description of the vulnerability;

[0020] The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time;

[0021] The vulnerability data includes the vulnerability name, risk level, and a brief description of the vulnerability.

[0022] The core data includes the vulnerability name and the device IP address.

[0023] In conjunction with the first aspect, preferably, the numerical tags corresponding to the open service data and vulnerability data are auxiliary tags.

[0024] In conjunction with the first aspect, the association information between the open service data and the vulnerability data is further defined as the result of associating device data with service data, open service descriptions, vulnerability data, and detailed vulnerability descriptions.

[0025] In conjunction with the first aspect, the generation of the knowledge graph further includes: based on the needs of the power system, on-site personnel divide open service data and vulnerability data into "entity" data and "relationship" data that constitute the knowledge graph from an easy-to-view perspective.

[0026] In conjunction with the first aspect, it further includes preprocessing the actual data of the security risk assessment, including: data fusion, entity extraction and entity deambiguation of the structured data that has been digitized in the actual data of the security risk assessment.

[0027] In conjunction with the first aspect, the digital tags further include the importance of keywords and the actual data obtained from the security risk assessment.

[0028] In conjunction with the first aspect, further, in the nine-square grid heatmap of IP addresses, the horizontal axis represents high, medium, and low vulnerability, the vertical axis represents high, medium, and low risk value, and the value of each square is the number of IP addresses.

[0029] Secondly, the present invention provides a knowledge graph generation system for vulnerability analysis of power monitoring systems, comprising:

[0030] Acquisition module: Used to acquire the actual electricity consumption / generation information of load aggregators and green energy power plants;

[0031] Calculation scheme generation module: Used to generate settlement schemes based on information on market access, transaction clearing, and settlement rules of load aggregators and green energy power plants using a pre-built settlement system;

[0032] Settlement module: Used to settle accounts between load aggregators and green energy power plants based on the settlement plan;

[0033] The calculation scheme generation module includes: a construction module for constructing the settlement system.

[0034] Compared with the prior art, the beneficial effects achieved by the knowledge graph generation method and system for vulnerability analysis of power monitoring systems provided in this embodiment of the invention include:

[0035] This invention acquires actual security risk assessment data and categorizes it into open service data and vulnerability data; based on security risk assessment data from power system security and other monitoring systems, this invention analyzes the characteristics of the data.

[0036] This invention assigns importance weights to keywords in the acquired actual data, converts the textual information of the actual data into numbers, and obtains numerical tags corresponding to different data; it can generate numerical tags based on importance.

[0037] This invention classifies digital tags according to their risk value and vulnerability level (high, medium, low), counts the number of IP addresses contained in each level after classification, and generates a nine-square heat map of IP address counts. This invention can intuitively and clearly show the existing quantity and distribution of IP addresses at risk and vulnerability levels, and can consider the attributes of the devices corresponding to the IP addresses from two dimensions: vulnerability and risk value.

[0038] Based on the generated nine-square grid heatmap of IP addresses, the correlation information between open service data and vulnerability data is obtained. A knowledge graph is generated based on the obtained correlation information. The knowledge graph is used to analyze and evaluate the vulnerability of the power monitoring system and its impact. The application of knowledge graph in this invention can intelligently analyze actual data, effectively evaluate security events, extract security events that need to be monitored, and reduce the possibility of detection omissions. Attached Figure Description

[0039] Figure 1 This is a flowchart of a knowledge graph generation method for vulnerability analysis of power monitoring systems provided in Embodiment 1 of the present invention;

[0040] Figure 2 This is a security risk assessment of actual data and classification results of a knowledge graph generation method for vulnerability analysis of power monitoring systems, provided in Embodiment 1 of the present invention.

[0041] Figure 3 This is a nine-grid heatmap of IP addresses provided in Embodiment 1 of the present invention for a knowledge graph generation method for vulnerability analysis of power monitoring systems;

[0042] Figure 4 This is a knowledge graph generation method for vulnerability analysis of power monitoring systems provided in Embodiment 1 of the present invention. Detailed Implementation

[0043] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.

[0044] Example 1:

[0045] like Figure 1 This invention provides a method for generating a knowledge graph for vulnerability analysis of power monitoring systems, comprising:

[0046] Obtain actual security risk assessment data and categorize it into open service data and vulnerability data;

[0047] Based on the keywords of the acquired actual data, the importance weight of the keywords is configured, and the text information of the actual data is converted into numbers to obtain numerical labels corresponding to different data.

[0048] The digital tags are classified into high, medium, and low risk values ​​and vulnerabilities. The number of IP addresses contained in each level after classification is counted, and a nine-square heat map of IP address count is generated.

[0049] Based on the generated nine-square grid heatmap of IP addresses, the correlation information between open service data and vulnerability data is obtained, and a knowledge graph is generated based on the obtained correlation information.

[0050] like Figure 2 As shown, the actual data for security risk assessment includes asset information and security risk assessment data, with the corresponding digital labels for asset information and security risk assessment data serving as the basic labels.

[0051] The asset information includes: equipment name, equipment region, equipment IP address, and equipment operating security zone;

[0052] The security risk assessment data includes: the number of equipment security risks and the verification time.

[0053] Open service data includes device data, service data, and open service descriptions;

[0054] The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time;

[0055] The service data includes the service name, port, and port operating protocol;

[0056] The core data includes the service name and port.

[0057] Vulnerability data includes device data, vulnerability data, and a detailed description of the vulnerability;

[0058] The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time;

[0059] The vulnerability data includes the vulnerability name, risk level, and a brief description of the vulnerability.

[0060] The core data includes the vulnerability name and the device IP address.

[0061] Specifically, the association information between the open service data and vulnerability data is the result of associating device data with service data, open service descriptions, vulnerability data, and detailed vulnerability descriptions. The numerical labels corresponding to the open service data and vulnerability data are auxiliary labels.

[0062] It should be noted that this also includes preprocessing the actual data of the security risk assessment, including: data fusion, entity extraction, and entity deambiguation of the structured data that has already been digitized in the actual data of the security risk assessment.

[0063] The digital tags include the importance of keywords and the actual data obtained from the security risk assessment. Table 1 shows the numerical values ​​of the digital tags configured based on the importance of keywords.

[0064] Table 1 shows the numerical values ​​of the numeric tags configured based on keyword importance.

[0065] numerical value of the number tag title of actual data in safety risk assessment 179 Vulnerability 171 Verification time 92 IP address 138 Danger level 168 Brief description of the vulnerability 136 Vulnerability Details 19 Specific time data 5 Specific IP address

[0066] As shown in Table 1, the numerical values ​​of the labels corresponding to “Vulnerability” to “Detailed Description of Vulnerability” are relatively large (the numerical range of the data labels is 0-193). This is because these data are titles, which are not frequently used in subsequent data and are not included in subsequent calculations as key data. Therefore, the labels are placed later. On the other hand, the numerical values ​​of the labels corresponding to specific time data or specific IP addresses are smaller and are of higher importance.

[0067] Figure 3 The image shown is a nine-square grid heatmap of IP addresses, created by processing data obtained by relevant operating units of the State Grid Corporation of China in 2019. Each IP address has two attribute ratings: risk value and vulnerability. Each attribute rating has three levels: high, medium, and low. In the nine-square grid heatmap, the horizontal axis represents high, medium, and low vulnerability, and the vertical axis represents high, medium, and low risk value. The nine-square grid heatmap clearly shows the number of IP addresses in each category.

[0068] The knowledge graph generation process includes: based on the needs of the power system, on-site personnel categorize open service data and vulnerability data into "entity" data and "relationship" data to form the knowledge graph from an easy-to-view perspective. Data obtained by relevant operating units of the State Grid Corporation of China in 2019 is processed and drawn as follows: Figure 4 The knowledge graph shown has circles representing the time of "entities" and lines connecting the "entities" representing "relationships".

[0069] Example 2:

[0070] This invention provides a knowledge graph generation system for vulnerability analysis of power monitoring systems, comprising:

[0071] Acquisition module: Used to acquire actual security risk assessment data and divide it into open service data and vulnerability data;

[0072] Text tagging module: Based on the keywords in the acquired actual data, it configures the importance weight of keywords, converts the text information of the actual data into numbers, and obtains numerical tags corresponding to different data.

[0073] IP Address Count Nine-Grid Heatmap Generation Module: Used to classify digital tags according to risk value and vulnerability (high, medium, low), count the number of IP addresses contained in each level after classification, and generate an IP address count nine-grid heatmap.

[0074] Output module: Based on the generated nine-square grid heatmap of IP addresses, it obtains the correlation information between open service data and vulnerability data, and generates a knowledge graph based on the obtained correlation information. The knowledge graph is used to analyze and evaluate the vulnerability of the power monitoring system and its impact.

[0075] A knowledge graph generation system for vulnerability analysis of power monitoring systems, including a processor and a storage medium;

[0076] The storage medium is used to store instructions;

[0077] The processor is configured to operate according to the instructions to execute the steps of the method described in Embodiment 1.

[0078] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method described in Embodiment 1.

[0079] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0080] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0081] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0082] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0083] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A knowledge graph generation method, characterized in that, The method includes: Obtain actual security risk assessment data and categorize it into open service data and vulnerability data; The actual data for the security risk assessment includes asset information and security risk assessment data. The asset information includes: equipment name, equipment region, equipment IP address, and equipment operating security zone; The security risk assessment data includes: the number of equipment security risks and the verification time; The open service data includes device data, service data, and open service descriptions. The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time; The service data includes the service name, port, and port operating protocol; The core data includes the service name and port. The vulnerability data includes device data, vulnerability data, and a detailed description of the vulnerability; The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time; The vulnerability data includes the vulnerability name, risk level, and a brief description of the vulnerability. The core data includes the vulnerability name and the device IP address. The association information between the open service data and the vulnerability data is the result of associating device data with service data, open service description, vulnerability data, and detailed vulnerability description; Based on the keywords of the acquired actual data, the importance weight of the keywords is configured, and the text information of the actual data is converted into numbers to obtain numerical labels corresponding to different data. The digital tags are classified into high, medium, and low risk values ​​and vulnerabilities. The number of IP addresses contained in each level after classification is counted, and a nine-square heat map of IP address count is generated. Based on the generated nine-square grid heatmap of IP addresses, the correlation information between open service data and vulnerability data is obtained, and a knowledge graph is generated based on the obtained correlation information. 2.The knowledge graph generation method of claim 1, wherein, The association information between the open service data and the vulnerability data is the result of associating device data with service data, open service descriptions, vulnerability data, and detailed vulnerability descriptions. 3.The knowledge graph generation method of claim 1, wherein, The generation of the knowledge graph includes: based on the needs of the power system, on-site personnel divide open service data and vulnerability data into "entity" data and "relationship" data that constitute the knowledge graph from an easy-to-view perspective. 4.The knowledge graph generation method of claim 1, wherein, It also includes preprocessing the actual data of the security risk assessment, including: data fusion, entity extraction and entity deambiguation of the structured data that has been digitized in the actual data of the security risk assessment. 5.The knowledge graph generation method of claim 1, wherein, The digital tags include the importance of keywords and the actual data obtained from the security risk assessment. 6.The method of Claim 1, wherein, In the nine-square heatmap of IP addresses, the horizontal axis represents high, medium, and low vulnerability, and the vertical axis represents high, medium, and low risk value. The value of each square is the number of IP addresses.

7. A knowledge graph generation system, characterized by, include: Acquisition Module: Used to acquire actual security risk assessment data and divide it into open service data and vulnerability data; wherein, the actual security risk assessment data includes asset information and security risk assessment data; The asset information includes: equipment name, equipment region, equipment IP address, and equipment operating security zone; The security risk assessment data includes: the number of equipment security risks and the verification time; The open service data includes device data, service data, and open service descriptions. The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time; The service data includes the service name, port, and port operating protocol; The core data includes the service name and port. The vulnerability data includes device data, vulnerability data, and a detailed description of the vulnerability; The equipment data includes equipment name, equipment region, equipment IP, equipment operating security zone, number of equipment security risks, and verification time; The vulnerability data includes the vulnerability name, risk level, and a brief description of the vulnerability. The core data includes the vulnerability name and the device IP address. The association information between the open service data and the vulnerability data is the result of associating device data with service data, open service description, vulnerability data, and detailed vulnerability description; Text tagging module: Based on the keywords in the acquired actual data, it configures the importance weight of keywords, converts the text information of the actual data into numbers, and obtains numerical tags corresponding to different data. IP Address Count Nine-Grid Heatmap Generation Module: Used to classify digital tags according to risk value and vulnerability (high, medium, low), count the number of IP addresses contained in each level after classification, and generate an IP address count nine-grid heatmap. Output module: Based on the generated IP address grid heatmap, it obtains the correlation information between open service data and vulnerability data, and generates a knowledge graph based on the obtained correlation information.

Citation Information

Patent Citations

  • Data security protection method and device

    CN108092981A

  • Network security situation awareness method for power monitoring system

    CN110460459A

  • Data security intelligent management and control platform suitable for power industry

    CN112215505A