Energy supply and demand status dynamic monitoring system and method
By designing a dynamic monitoring system for energy supply and demand status, we can achieve real-time monitoring of energy supply and demand status and identification and tracing of abnormal behaviors, solve the problem of insufficient security monitoring in the energy business main station and security access area, and improve the system's security and anti-attack capabilities.
Patent Information
- Application Number
- CN202111489287.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-08
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2041-12-08
AI Technical Summary
In the existing technology, energy business main stations, substations and secure access areas lack monitoring methods for security events and alarm information of servers, switches, databases and security equipment. The host operating system lacks its own immunity and is vulnerable to vulnerabilities and unknown virus attacks.
A dynamic monitoring system for energy supply and demand status is designed, which includes a control terminal, a linkage module, a data acquisition module, a dynamic monitoring module, an energy output module, a verification unit, an output path monitoring module, a refresh module, a judgment module, a habit behavior memory module, a honeypot deployment module, an attack behavior feature and target extraction module and a traceability module. Through the collaborative work of these modules, real-time monitoring of energy supply and demand status and identification and traceability of abnormal behavior can be achieved.
It effectively prevents the host control end from being attacked and invaded, ensures normal access and interaction of system functions, avoids system crashes, improves system security, and improves the risk perception and early warning capabilities of offensive malicious intrusions through honeypot tracing technology.
Smart Images

Figure CN114401108B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of energy supply and demand network detection, and in particular to a system and method for dynamic monitoring of energy supply and demand status. Background Art
[0002] Smart energy grids are composed of diverse power sources and loads that are widely distributed in time and space. Both the power source and load sides can act as dispatchable resources to balance power supply and demand. Flexible load variability is a key means of balancing power fluctuations. By guiding users to change their electricity usage habits and behaviors, various flexible and adjustable resources can be integrated to participate in power system peak regulation and renewable energy consumption.
[0003] Currently, energy business main stations, substations, and secure access areas lack security monitoring methods for various security events and alarm information on servers, switches, databases, and security equipment. The host operating system does not yet have its own immunity and is easily attacked by vulnerabilities and unknown viruses. Summary of the Invention
[0004] Technical issues solved:
[0005] In response to the above-mentioned shortcomings of the existing technology, the present invention provides a dynamic monitoring system and method for energy supply and demand status, which solves the problems of lack of security monitoring means for various security events and alarm information of servers, switches, databases and security equipment in energy business main stations, substations and secure access areas, and the host operating system does not have its own immunity and is easily attacked by vulnerabilities and unknown viruses.
[0006] Technical solution:
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions:
[0008] A dynamic monitoring system for energy supply and demand status, comprising:
[0009] The control terminal is a terminal server that controls energy supply and demand;
[0010] The linkage module is used to integrate the risk perception module and the early warning prompt module to form data information interaction and conduct collaborative operation;
[0011] Data acquisition module, used to collect real-time data of energy supply and demand request process;
[0012] Dynamic monitoring module, used to monitor the dynamics of energy supply and demand request data transmission process;
[0013] Energy output module, used to review energy supply and demand requests and execute energy allocation and output commands;
[0014] A verification unit is used to serve the output path monitoring module, compare the output path monitoring module with the energy output module, and determine the consistency of energy transmission and distribution;
[0015] Output path monitoring module, used to monitor abnormal behavior in the energy output process;
[0016] The refresh module is used to serve the output path monitoring module, refresh the detection path in the output state, and reduce the detection delay difference;
[0017] A judgment module is used to judge whether the abnormal behavior of the energy output module during energy output is an uncontrollable fluctuation within the range of natural factors;
[0018] The habit behavior memory module is used to form energy supply and demand output execution habits, which serves as a reference for the output power in normal state.
[0019] Honeypot deployment module, used to deploy honeypots in the energy output path to trap abnormal intrusions or induce attacks;
[0020] Attack behavior feature and target extraction module, used to obtain the features of abnormal intrusion behavior or attack; used to obtain intrusion behavior, attack path and control end target;
[0021] The tracing module is used to trace the output abnormal path to capture abnormal behavior and the control end IP of the attack path.
[0022] Furthermore, the linkage module includes:
[0023] The risk perception module is used to read energy supply and demand transmission data and analyze operations for hidden threat requests;
[0024] The early warning prompt module is used to read the analysis results generated by the risk perception module and send an early warning prompt queue to the control terminal for hidden threat request items.
[0025] Furthermore, the judgment result of the judgment module is based on the refresh module and is obtained by comparing the verification unit with the output path monitoring module.
[0026] Furthermore, the risk perception module autonomously updates based on the periodic memory data extracted by the habit behavior memory module, and the early warning prompt module autonomously updates based on the traceability target feature analysis and similar target operation extracted by the traceability module.
[0027] Furthermore, the verification unit operates in a cycle of one day / time to complete data alternation, and the refresh module outputs a refresh cycle of half the duration of a single energy supply and demand request.
[0028] A method for dynamically monitoring energy supply and demand status, comprising the following steps:
[0029] Stp1: Verify and confirm the energy network supply and demand status request information;
[0030] Stp2: Acquires real-time data on the energy network's operating status, and simultaneously encodes and records the coordinated changes in the "grid," "energy storage," "power source," and "load."
[0031] Stp3: Generate energy network traffic peak records and traffic fluctuation difference calculations, and retrieve peak record data during abnormal fluctuation periods;
[0032] Stp4: Check the honeypot triggering status and operation frequency cycle trajectory, and perform sub-items according to the detection results;
[0033] Step 5: Determine whether the honeypots in the system have been triggered, damaged, or frequently contacted by risky targets, and perform maintenance.
[0034] Stp6: Carry out safety integration and trial operation according to the dynamics of energy supply and demand. When the operation is stable, monitor it through a decreasing system until the dynamics are stable without accidents.
[0035] Furthermore, the step Stp5 includes the following sub-steps:
[0036] Stp51-1: Honeypot interception successful;
[0037] Stp51-2: The honeypot defense mechanism is determined to be effective, and the intrusion attack is traced.
[0038] Stp51-3: Record similar abnormal paths and requests, check historical dynamic records, and require re-verification of bound protocol links;
[0039] Step 51-4: The honeypot is destroyed or climbed over, and step 51-2 is executed again;
[0040] Stp51-5: Actively shut down dynamic supply and demand channels, assess losses at all levels of the energy dynamic chain, block paths related to attack paths, set up risk awareness and early warning for similar path requests, and prompt sharing for similar path requests;
[0041] Stp52: Analyze suspected risk target items, conduct historical screening and judgment, and provide corresponding risk warning suggestions.
[0042] Furthermore, the energy supply and demand subordinates cannot infer from each other, and through encryption processing, the subordinates are restricted from unilaterally obtaining data rights.
[0043] Furthermore, the homomorphic encryption algorithm is efficient:
[0044] R and S are fields, and the encryption function E: R→S is called:
[0045] Additive homomorphism, if there exists an efficient algorithm, E(x+y)=E(x)+E(y) or x+y=D(E(x)+E(y)) holds, and does not leak x and y.
[0046] Multiplication homomorphism means that if there exists an efficient algorithm, E(x×y)=E(x) E(y) or xy=D(E(x) E(y)) holds, and does not leak x and y.
[0047] Mixed multiplication homomorphism is a condition where E(x×y)=E(x)y or xy=D(E(x)y) exists and does not leak x.
[0048] Subtraction homomorphism, if there exists an efficient algorithm, E(xy)=E(x)-E(y) or xy=D(E(x)-E(y)), and does not leak x and y, then E is called a subtraction homomorphism.
[0049] Division homomorphism: If there exists an efficient algorithm such that E(x / y)=E(x) / E(y) or x / y=D(E(x) / E(y)) and does not leak x and y, then E is called a subtraction homomorphism.
[0050] Algebraic homomorphism if E is both an additive homomorphism and a multiplicative homomorphism.
[0051] Arithmetic homomorphism, if E is simultaneously homomorphic to addition, homomorphic to subtraction, homomorphic to multiplication, and homomorphic to division
[0052] Where E is the charge;
[0053] X and Y are the target quantities of lower-level data on energy supply and demand, respectively.
[0054] Furthermore, in the steps Stp51 - 1 and Stp51 - 4 , when the honeypot is attacked by an intrusion, the intrusion attack process is recorded through the storage space set up through the independent channel inside the honeypot to form a simulated reconstructed image.
[0055] Beneficial effects:
[0056] Compared with the known public technology, the technical solution provided by the present invention has the following beneficial effects:
[0057] The present invention can effectively ensure normal access and interaction of system functions through various protection and monitoring mechanisms, preventing the host control end from being easily crashed and unable to operate due to attacks, invasions or vulnerabilities, and at the same time avoiding the problem of energy supply and demand subordinates requesting data to calculate each other's secret data.
[0058] The present invention can trace the intrusion ID by trapping the honeypot, and through analysis, it can improve the system's risk perception and early warning of aggressive malicious intrusions, achieving the beneficial effect that the longer the operation time, the higher the system security factor. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] To more clearly illustrate the technical solutions of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.
[0060] Figure 1 This is a structural diagram of a dynamic monitoring system for energy supply and demand status;
[0061] Figure 2 It is a structural diagram of a method for dynamic monitoring of energy supply and demand status;
[0062] Figure 3 This is an example diagram of the secure multi-party computing method in the present invention;
[0063] Figure 4 This is a diagram showing the use of the honeypot location attack active trapping framework structure in the present invention;
[0064] Figure 5 This is a schematic diagram of the interception interval of the honeypot contact abnormal target period in the present invention;
[0065] The numbers in the figure represent: 1. Control terminal; 2. Linkage module; 21. Risk perception module; 22. Early warning module; 3. Data acquisition module; 4. Dynamic monitoring module; 5. Energy output module; 6. Verification unit; 7. Output path monitoring module; 8. Refresh module; 9. Judgment module; 10. Habitual behavior memory module; 11. Honeypot deployment module; 12. Attack behavior characteristics and target extraction module; 13. Tracing module. DETAILED DESCRIPTION
[0066] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present invention.
[0067] The present invention will be further described below with reference to the embodiments.
[0068] Example 1:
[0069] A dynamic monitoring system for energy supply and demand status in this embodiment refers to Figure 1 ,include:
[0070] Control terminal 1 is a terminal server that controls energy supply and demand;
[0071] Linkage module 2 is used to integrate risk perception module 21 and early warning prompt module 22 to form data information interaction and perform collaborative operation;
[0072] Data acquisition module 3, used to collect real-time data of energy supply and demand request process;
[0073] Dynamic monitoring module 4, used to monitor the dynamics of the energy supply and demand request data transmission process;
[0074] Energy output module 5, used to review energy supply and demand requests and execute energy allocation and output commands;
[0075] Verification unit 6, used to serve output path monitoring module 7, compares output path monitoring module 7 with reference to energy output module 5, and determines the consistency of energy transmission and distribution;
[0076] Output path monitoring module 7, used to monitor abnormal behavior in the energy output process;
[0077] The refresh module 8 is used to serve the output path monitoring module 7, refresh the detection path in the output state, and reduce the detection delay difference;
[0078] The judgment module 9 is used to judge whether the abnormal behavior of the energy output module 5 during the energy output process is an uncontrollable fluctuation within the range of natural factors;
[0079] The habit behavior memory module 10 is used to form energy supply and demand output execution habits, which serve as a reference for the output power in the normal state.
[0080] A honeypot deployment module 11 is used to deploy honeypots in the energy output path to trap abnormal intrusions or induce attacks;
[0081] Attack behavior feature and target extraction module 12, used to obtain the features of abnormal intrusion behavior or attack; used to obtain intrusion behavior, attack path and control end target;
[0082] The tracing module 13 is used to trace the output abnormal path to capture the control end IP of abnormal behavior and attack path.
[0083] like Figure 1 As shown, the linkage module 2 includes:
[0084] The risk perception module 21 is used to read energy supply and demand transmission data and analyze operations for hidden threat requests;
[0085] The early warning prompt module 22 is used to read the analysis results generated by the risk perception module 21 and send an early warning prompt queue to the control terminal 1 for the hidden threat request item.
[0086] like Figure 1 As shown, the judgment result of the judgment module 9 is based on the refresh module 8 and is obtained by comparing the verification unit 6 with the output path monitoring module 7.
[0087] The control terminal 1 operated by the user and the main control linkage module 2 regulate the risk perception module 21 and the early warning prompt module 22, and monitor the energy supply and demand operation status in real time. The energy supply request is obtained by the data acquisition module 3 to trigger the dynamic monitoring module 4 to output the flow through the energy output module 5. During the output process, the output path is monitored by the output path monitoring module 7, and the output path is synchronously proofread with the help of the verification unit 6 and the refresh module 8. The proofreading result is transmitted to the judgment module 9 for judgment and the triggering situation of the honeypot deployment module 11 is analyzed at the same time. If the honeypot has been triggered or damaged, the attacked honeypot needs to be extracted through the attack behavior characteristics and target extraction module 12. Finally, the extracted data is traced back to the early warning prompt module 22 controlled by the control terminal 1 as the newly loaded early warning content.
[0088] like Figure 1 As shown, the risk perception module 21 extracts the periodic memory data based on the habit behavior memory module 10 and updates autonomously, and the early warning prompt module 22 extracts the traceability target feature analysis based on the traceability module 13 and runs similar targets and updates autonomously.
[0089] This setting can provide the risk perception module 21 with an actual comparison of risk perception and provide the risk perception module 21 with specific standards for risk perception assessment.
[0090] like Figure 1 As shown, the verification unit 6 operates in a cycle of Day / time to complete data alternation, and the refresh module 8 refreshes the cycle in a half of the output duration of a single energy supply and demand request.
[0091] Such a setting can effectively ensure the stability of monitoring abnormal situations during energy output requests and ensure that output abnormal situations can be discovered in a timely manner.
[0092] Example 2:
[0093] A method for dynamically monitoring energy supply and demand status, comprising the following steps:
[0094] Stp1: Verify and confirm the energy network supply and demand status request information;
[0095] Stp2: Acquires real-time data on the energy network's operating status, and simultaneously encodes and records the coordinated changes in the "grid," "energy storage," "power source," and "load."
[0096] Stp3: Generate energy network traffic peak records and traffic fluctuation difference calculations, and retrieve peak record data during abnormal fluctuation periods;
[0097] Stp4: Check the honeypot triggering status and operation frequency cycle trajectory, and perform sub-items according to the detection results;
[0098] Step 5: Determine whether the honeypots in the system have been triggered, damaged, or frequently contacted by risky targets, and perform maintenance.
[0099] Stp6: Carry out safety integration and trial operation according to the dynamics of energy supply and demand. When the operation is stable, monitor it through a decreasing system until the dynamics are stable without accidents.
[0100] like Figure 2 As shown, step Stp5 includes the following sub-steps:
[0101] Stp51-1: Honeypot interception successful;
[0102] Stp51-2: The honeypot defense mechanism is determined to be effective, and the intrusion attack is traced.
[0103] Stp51-3: Record similar abnormal paths and requests, check historical dynamic records, and require re-verification of bound protocol links;
[0104] Step 51-4: The honeypot is destroyed or climbed over, and step 51-2 is executed again;
[0105] Stp51-5: Actively shut down dynamic supply and demand channels, assess losses at all levels of the energy dynamic chain, block paths related to attack paths, set up risk awareness and early warning for similar path requests, and prompt sharing for similar path requests;
[0106] Stp52: Analyze suspected risk target items, conduct historical screening and judgment, and provide corresponding risk warning suggestions.
[0107] like Figure 3 As shown, the lower-level parties of energy supply and demand cannot infer from each other, and through encryption processing, the lower-level party’s unilateral access to data is restricted.
[0108] This structural framework can effectively prevent the energy supply and demand subordinates from attacking the connected sub-subordinates when being invaded, thereby further improving the security of the energy supply and demand request output process.
[0109] Example 3:
[0110] like Figure 2 As shown, the homomorphic encryption effective algorithm:
[0111] R and S are fields, and the encryption function E: R→S is called:
[0112] Additive homomorphism, if there exists an efficient algorithm, E(x+y)=E(x)+E(y) or x+y=D(E(x)+E(y)) holds, and does not leak x and y.
[0113] Multiplication homomorphism means that if there exists an efficient algorithm, E(x×y)=E(x) E(y) or xy=D(E(x) E(y)) holds, and does not leak x and y.
[0114] Mixed multiplication homomorphism is a condition where E(x×y)=E(x)y or xy=D(E(x)y) exists and does not leak x.
[0115] Subtraction homomorphism, if there exists an efficient algorithm, E(xy)=E(x)-E(y) or xy=D(E(x)-E(y)), and does not leak x and y, then E is called a subtraction homomorphism.
[0116] Division homomorphism: If there exists an efficient algorithm such that E(x / y)=E(x) / E(y) or x / y=D(E(x) / E(y)) and does not leak x and y, then E is called a subtraction homomorphism.
[0117] Algebraic homomorphism if E is both an additive homomorphism and a multiplicative homomorphism.
[0118] Arithmetic homomorphism, if E is simultaneously homomorphic to addition, homomorphic to subtraction, homomorphic to multiplication, and homomorphic to division
[0119] Where E is the charge;
[0120] X and Y are the target quantities of lower-level data on energy supply and demand, respectively.
[0121] Homomorphic encryption is a type of encryption method with special natural properties. Compared with general encryption algorithms, in addition to basic encryption operations, homomorphic encryption can also perform multiple computational functions between ciphertexts. In other words, computing first and then decrypting is equivalent to decrypting first and then computing. This feature is of great significance for protecting information security. Using homomorphic encryption technology, multiple ciphertexts can be computed before decrypting them, eliminating the need to decrypt each ciphertext and incur high computational costs. Homomorphic encryption technology can also be used to perform computations on ciphertexts without requiring a key party to perform computations on the ciphertext. This can reduce communication costs and transfer computational tasks, thereby balancing the computational costs of all parties.
[0122] Homomorphic encryption technology allows the decryptor to only obtain the final result, without accessing every ciphertext message, thus improving information security. Due to its advantages in computational complexity, communication complexity, and security, increasing research efforts are being devoted to exploring its theory and applications. Cloud computing has garnered widespread attention in recent years, and one of the challenges in its implementation is ensuring data privacy. Homomorphic encryption can, to a certain extent, address this technical challenge.
[0123] like Figure 2 As shown, in steps Stp51-1 and Stp51-4, when the honeypot is attacked by an intrusion, the intrusion attack process is recorded through the storage space set up through its internal independent channel to form a simulated reconstructed image.
[0124] With this setting, when the system is hacked, the system restores the hacking process by reconstructing the image, helping users to find vulnerabilities in the energy supply and demand system and related energy supply and demand systems more quickly.
[0125] Example 4:
[0126] like Figure 5 As shown in the figure, this figure is generated in the energy supply and demand process after the honeypot is deployed. Through specific analysis on the horizontal and vertical axes, it can quickly find the maximum amplitude of the honeypot triggering or the honeypot frequently contacting the risk target during the independent operation cycle, so that users can make targeted analysis and provide a guarantee for the stable operation of the honeypot trapping operation itself.
[0127] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A dynamic monitoring system for energy supply and demand status, characterized in that: include: The control terminal (1) is a terminal server for controlling energy supply and demand; The linkage module (2) is used to integrate the risk perception module (21) and the early warning prompt module (22) to form data information interaction and perform collaborative operation; Data acquisition module (3), used to collect real-time data of energy supply and demand request process; A dynamic monitoring module (4) for monitoring the dynamics of the energy supply and demand request data transmission process; Energy output module (5), used to review energy supply and demand requests and execute energy allocation and output commands; A verification unit (6) is used to serve the output path monitoring module (7), and compare the output path monitoring module (7) with the energy output module (5) to determine the consistency of energy transmission and distribution; Output path monitoring module (7), used to monitor abnormal behavior in the energy output process; A refresh module (8) is used to serve the output path monitoring module (7) to refresh the detection path in the output state and reduce the detection delay difference; A judgment module (9) is used to judge whether the abnormal behavior of the energy output module (5) during the energy output process is an uncontrollable fluctuation within the range of natural factors; The habit behavior memory module (10) is used to form the energy supply and demand output execution habit, which serves as a reference for the output power in the normal state. A honeypot deployment module (11) is used to deploy honeypots in the energy output path to trap abnormal intrusions or induce attacks; Attack behavior feature and target extraction module (12), used to obtain features of abnormal intrusion behavior or attack; used to obtain intrusion behavior, attack path and control end target; The tracing module (13) is used to trace the abnormal output path to capture abnormal behavior and the control end IP of the attack path; The control terminal (1) is operated by the user, and the main control linkage module (2) regulates the risk perception module (21) and the early warning prompt module (22), and monitors the energy supply and demand operation status in real time. The energy supply and transmission request is obtained by the data acquisition module (3) to trigger the dynamic monitoring module (4) to output the flow through the energy output module (5). During the output process, the output path is monitored by the output path monitoring module (7), and the output path is synchronously proofread with the help of the verification unit (6) and the refresh module (8). The proofreading result is transmitted to the judgment module (9) for judgment and analysis of the triggering situation of the honeypot deployment module (11). If the honeypot has been triggered or damaged, it is necessary to extract data from the attacked honeypot through the attack behavior feature and target extraction module (12). Finally, the extracted data is traced back to the early warning prompt module (22) controlled by the control terminal (1) as a newly loaded early warning content.
2. The energy supply and demand status dynamic monitoring system according to claim 1, characterized in that: The linkage module (2) comprises: Risk perception module (21), used to read energy supply and demand transmission data and analyze operations for hidden threat requests; The early warning prompt module (22) is used to read the analysis results generated by the risk perception module (21) and send an early warning prompt queue to the control terminal (1) for the hidden threat request item.
3. The energy supply and demand status dynamic monitoring system according to claim 1, characterized in that: The judgment result of the judgment module (9) is based on the refresh module (8) and is obtained by comparing the verification unit (6) with the output path monitoring module (7).
4. The energy supply and demand status dynamic monitoring system according to claim 1, characterized in that: The risk perception module (21) extracts periodic memory data based on the habit behavior memory module (10) and updates autonomously. The early warning prompt module (22) extracts traceability target characteristics based on the traceability module (13) and analyzes similar targets and updates autonomously.
5. The energy supply and demand status dynamic monitoring system according to claim 1, characterized in that: The verification unit (6) operates in a cycle of one day / time to complete data alternation, and the refresh module (8) refreshes the cycle in a half of the output duration of a single energy supply and demand request.
6. A method for dynamically monitoring energy supply and demand status, the method being an implementation method of the system for dynamically monitoring energy supply and demand status according to any one of claims 1 to 5, comprising the following steps: Stp1: Verify and confirm the energy network supply and demand status request information; Stp2: Acquires real-time data on the energy network's operating status and encodes and records the coordinated changes in the conversion between "grid," "energy storage," "power source," and "load." Stp3: Generate energy network traffic peak records and traffic fluctuation difference calculations, and retrieve peak record data during abnormal fluctuation periods; Stp4: Check the honeypot triggering status and operation frequency cycle trajectory, and perform sub-items according to the detection results; Step 5: Determine whether the honeypots in the system have been triggered, damaged, or frequently contacted by risky targets, and perform maintenance. Stp6: Carry out safety integration and trial operation according to the dynamics of energy supply and demand. When the operation is stable, monitor it through a decreasing system until the dynamics are stable without accidents.
7. A method for dynamic monitoring of energy supply and demand status according to claim 6, characterized in that: The step Stp5 includes the following sub-steps: Stp51-1: Honeypot interception successful; Stp51-2: The honeypot defense mechanism is determined to be effective, and the intrusion attack is traced. Stp51-3: Record similar abnormal paths and requests, check historical dynamic records, and require re-verification of bound protocol links; Step 51-4: The honeypot is destroyed or climbed over, and step 51-2 is executed again; Stp51-5: Actively shut down dynamic supply and demand channels, assess losses at all levels of the energy dynamic chain, block paths related to attack paths, set up risk awareness and early warning for similar path requests, and prompt sharing for similar path requests; Stp52: Analyze suspected risk target items, conduct historical screening and judgment, and provide corresponding risk warning suggestions.
8. A method for dynamic monitoring of energy supply and demand status according to claim 6, characterized in that: The energy supply and demand subordinates cannot infer each other, and through encryption processing, the subordinates are restricted from unilaterally obtaining data rights.
9. A method for dynamic monitoring of energy supply and demand status according to claim 8, characterized in that: Homomorphic encryption effective algorithm: R and S are fields, and the encryption function E: R→S is called: Additive homomorphism: if there exists an efficient algorithm, E(x+y)=E(x)+E(y) or x+y=D(E(x)+E(y)) holds, and does not leak x and y; Multiplication homomorphism: if there exists an efficient algorithm, E(x×y)=E(x) E(y) or xy=D(E(x) E(y)) holds, and does not leak x and y; Mixed multiplication homomorphism, if there exists an efficient algorithm, E(x×y)=E(x) y or xy=D(E(x) y) holds, and does not leak x; Subtraction homomorphism: if there exists an efficient algorithm, E(xy)=E(x)-E(y) or xy=D(E(x)-E(y)), and it does not leak x and y, then E is called a subtraction homomorphism; Division homomorphism: If there exists an efficient algorithm such that E(x / y)=E(x) / E(y) or x / y=D(E(x) / E(y)) and does not leak x and y, then E is called a subtraction homomorphism. Algebraic homomorphism, if E is both an additive homomorphism and a multiplicative homomorphism; Arithmetic homomorphism, if E is simultaneously homomorphic to addition, homomorphic to subtraction, homomorphic to multiplication, and homomorphic to division Where E is the charge; X and Y are the target quantities of lower-level data on energy supply and demand, respectively; In steps Stp51-1 and Stp51-4, when the honeypot is attacked by an intrusion, the intrusion attack process is recorded through the storage space set up through its internal independent channel to form a simulated reconstructed image.
Citation Information
Patent Citations
High-interaction honeypot based network security system and implementation method thereof
CN102739647A
Unknown loophole attack detection method, device, equipment and storage medium
CN109302426A