A method and system for intelligently identifying abnormal communication in a power monitoring system

By judging the communication type in the power monitoring system and using the login operation model and communication habit model to identify abnormal communications, the problem of low efficiency of manual identification is solved, and more efficient abnormal communication identification and processing is achieved.

CN114867021BActive Publication Date: 2025-09-09SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210319137.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2025-09-09
Estimated Expiration
2042-03-29

AI Technical Summary

Technical Problem

In the existing technology, abnormal communication behavior of power monitoring systems is difficult to identify quickly and accurately through manual methods, resulting in limited effectiveness in defending against network security threats.

Method used

By obtaining the communication behavior data of the power monitoring system, the communication type is determined, and whether to obtain feature data is decided based on the type. The login operation model and communication habit model are used to determine the risk type, and corresponding processing instructions are generated for disposal.

Benefits of technology

The abnormal communication recognition rate is improved, computer resources are saved, communication efficiency is improved, and the computational burden on the power monitoring system is reduced when identifying abnormal communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114867021B_ABST
    Figure CN114867021B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of communication security, and discloses a method and system for intelligently identifying abnormal communications in an electric power monitoring system, including: obtaining communication behavior data in the electric power monitoring system and determining the communication type; if the communication type is a control instruction, obtaining characteristic data of the communication behavior data, otherwise determining whether to obtain the characteristic data of the communication behavior data based on the communication analysis extraction rate; inputting the characteristic data into a login operation model and a communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data; generating a corresponding communication processing instruction based on the risk type to deal with the communication behavior; the present application has the effect of improving the efficiency of identifying abnormal communication behavior between devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of communication security, and in particular to a method and system for intelligently identifying abnormal communication in an electric power monitoring system. Background Art

[0002] The power monitoring system is used to collect power consumption data from each power user in real time, and conduct real-time online monitoring of parameters such as voltage, current, and power of each power user or electrical equipment. Based on the collected parameters, corresponding control instructions are issued to the substation and distribution systems to improve the stability of power supply. Therefore, a large amount of communication is required during the operation of the power monitoring system.

[0003] The current network security threats faced by power monitoring systems include network attacks such as message tampering, denial of service, Trojan programs, and password intrusion. Firewalls have limited defensive effectiveness against attacks such as password intrusion from within the power monitoring system. Anomalies in communication behavior can be identified to prevent attacks from within the power monitoring system. However, it is difficult to accurately and quickly identify abnormal communication behavior from the massive amount of communication relationship information in the network through manual methods.

[0004] Regarding the above-mentioned related technologies, the inventor believes that there is a problem that it is difficult to manually identify abnormal communication behaviors. Summary of the Invention

[0005] In order to improve the efficiency of identifying abnormal communication behavior between devices, the present application provides a method and system for intelligently identifying abnormal communication in a power monitoring system.

[0006] The above-mentioned invention objective 1 of this application is achieved by adopting the following technical solution:

[0007] A method for intelligently identifying abnormal communication in a power monitoring system, comprising:

[0008] Obtain communication behavior data in the power monitoring system and determine the communication type;

[0009] If the communication type is a control instruction, obtaining characteristic data of the communication behavior data; otherwise, determining whether to obtain the characteristic data of the communication behavior data based on the communication analysis extraction rate;

[0010] Inputting the characteristic data into a login operation model and a communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data;

[0011] Generate corresponding communication processing instructions based on the risk type to deal with the communication behavior.

[0012] By adopting the above technical solution, communication behavior data within the power monitoring system is obtained and the communication type is determined, which facilitates distinguishing a large number of communication behaviors in the power system and making different treatments for different types of communication behaviors. If the communication type is a control instruction, characteristic data of the communication behavior data is obtained, which facilitates subsequent determination of whether the communication behavior data is abnormal communication by analyzing the characteristic data of the communication behavior. If the communication type is not a control instruction, whether the characteristic data of the communication behavior data is obtained and subsequent abnormal communication determination is made based on the communication analysis extraction rate. By determining the communication type of the communication behavior data, control instructions with strong security relevance to the power monitoring system and other non-control instruction communications with weaker security relevance to the power monitoring system are distinguished, rather than making abnormal communication determinations for all communication behavior data, thereby saving computer resources of the power monitoring system and improving communication efficiency. The characteristic data is input into the login operation model and the communication habit model for comparison, so as to determine whether the communication behavior data is abnormal communication based on the two dimensions of login operation information and communication habit information of the communication behavior data corresponding to the characteristic data, thereby determining the risk type and improving the recognition rate of abnormal communication. Corresponding communication processing instructions are generated according to different risk types to make reasonable disposal of the communication behavior.

[0013] In a preferred example, the present application may be further configured as follows: if the communication type is a control instruction, obtaining characteristic data of the communication behavior data; otherwise, before determining whether to obtain the characteristic data of the communication behavior data based on the communication analysis extraction rate, the step further includes:

[0014] Obtain historical cyberattack data sets for the power monitoring system and determine the cyberattack risk level for the previous statistical period;

[0015] The communication analysis extraction rate for the current statistical period is determined based on the network attack risk level of the previous statistical period.

[0016] By adopting the above technical solution, a historical network attack data set of the power monitoring system is obtained, and the network attack risk level of the previous statistical period is calculated from the historical network attack data set, so as to know the risk of the power monitoring system being attacked by a network in the near future, so as to determine the communication analysis extraction rate of the current statistical period according to the network attack risk level of the previous statistical period, thereby achieving the effect of timely adjusting the extraction probability of non-control instructions in the power monitoring system, so as to make adjustments according to the actual needs of the power monitoring system.

[0017] In a preferred embodiment, the present application may be further configured to: input the characteristic data into the login operation model and the communication habit model for comparison, and before the step of determining the risk type of the communication behavior data corresponding to the characteristic data, further include:

[0018] Obtain historical communication behavior datasets and corresponding feature data, and create login operation models and communication habit models based on the feature data.

[0019] By adopting the above technical solution, a historical communication behavior data set is formed by randomly extracting part of the communication behavior data from the daily communication behavior data of the power monitoring system, and the corresponding feature data is obtained. A login operation model is created based on the user login operation behavior habits in the feature data corresponding to the historical communication behavior data set, and a communication habit model is created based on the user communication habits in the extracted feature data of daily communication behavior, so as to be used subsequently to determine whether the communication behavior data belongs to abnormal communication and generate a risk type.

[0020] In a preferred example, the present application may be further configured to: input the characteristic data into the login operation model and the communication habit model for comparison, and determine the risk type of the communication behavior data corresponding to the characteristic data, specifically including:

[0021] According to the login operation model, determine whether the account login operation behavior data corresponding to the characteristic data is abnormal, and output the judgment result;

[0022] According to the communication habit model, the abnormality of the device communication relationship data corresponding to the characteristic data is judged, and the judgment result is output.

[0023] By adopting the above-mentioned technical solution, after the characteristic data of the communication behavior data is input into the login operation model, the login operation of the account corresponding to the communication behavior data is compared with the login operation in the login operation model, so as to determine whether the account corresponding to the communication behavior data is an abnormal login and generate a judgment result; after the characteristic data of the communication behavior data is input into the communication habit model, the communication habits of the communication behavior data are compared with the communication habits in the communication habit model, so as to determine whether the communication behavior data is an abnormal communication and generate a judgment result.

[0024] In a preferred example, the present application may be further configured to: input the characteristic data into the login operation model and the communication habit model for comparison, and the step of determining the risk type of the communication behavior data corresponding to the characteristic data further includes:

[0025] Based on the judgment results output by the login operation model and the communication habit model, the risk type of the communication behavior data is generated.

[0026] By adopting the above technical solution, the characteristic data of the communication behavior data is input into the login operation model and the communication habit model, and a judgment result is generated after comparison. The risk type of the communication behavior data is generated according to the judgment results of the login operation model and the communication habit model, so that corresponding disposal measures can be made according to the risk type of the communication behavior data in the future.

[0027] In a preferred example, the present application may be further configured to: after the step of determining, based on the login operation model, whether the account login operation behavior data corresponding to the feature data is abnormal and outputting the determination result, further include:

[0028] If the judgment result of the login operation model is risky login, the communication function permissions weakly associated with the corresponding position of the account are restricted.

[0029] By adopting the above technical solution, if the login operation model judges that the characteristic data of the communication behavior data is a risky login, the work position corresponding to the account that issued the communication behavior data is obtained, and the permissions of the communication functions that are weakly associated with the position corresponding to the account are restricted; so that the user can complete basic work tasks in the case of risky login, and at the same time restrict more communication function permissions to improve the security of the power monitoring system and reduce abnormal communication behavior.

[0030] In a preferred example, the present application may be further configured as follows: if the judgment result of the login operation model is a risky login, after the step of restricting the communication function permissions weakly associated with the position corresponding to the account, the following steps may be further performed:

[0031] Acquire biometric verification information from an account with restricted communication function permissions, and restore the communication function permissions of the account based on the biometric verification information.

[0032] By adopting the above technical solution, when part of the communication function permissions of an account are restricted, biometric verification information from the account with restricted communication function permissions is obtained, and the communication permissions of the account are restored based on the biometric verification information, so that the user can verify his or her identity through more secure biometric verification information in the case of risky login, thereby reducing the risk level of the account, and partially or fully restoring the communication function permissions of the account, so that the user can use more communication functions in a risky login environment.

[0033] The second object of the present invention is achieved by the following technical solution:

[0034] An abnormal communication intelligent identification system for a power monitoring system, comprising:

[0035] A communication type determination module is used to obtain communication behavior data in the power monitoring system and determine the communication type;

[0036] a feature data acquisition module, configured to acquire feature data of the communication behavior data if the communication type is a control instruction, and otherwise determine whether to acquire feature data of the communication behavior data based on a communication analysis extraction rate;

[0037] a communication risk judgment module, configured to input the characteristic data into a login operation model and a communication habit model for matching, and to judge the risk type of the communication behavior data corresponding to the characteristic data;

[0038] The communication behavior handling module is used to generate corresponding communication processing instructions based on the risk type to handle the communication behavior.

[0039] By adopting the above technical solution, communication behavior data within the power monitoring system is obtained and the communication type is determined, which facilitates distinguishing a large number of communication behaviors in the power system and making different treatments for different types of communication behaviors. If the communication type is a control instruction, characteristic data of the communication behavior data is obtained, which facilitates subsequent determination of whether the communication behavior data is abnormal communication by analyzing the characteristic data of the communication behavior. If the communication type is not a control instruction, whether the characteristic data of the communication behavior data is obtained and subsequent abnormal communication determination is made based on the communication analysis extraction rate. By determining the communication type of the communication behavior data, control instructions with strong security relevance to the power monitoring system and other non-control instruction communications with weaker security relevance to the power monitoring system are distinguished, rather than making abnormal communication determinations for all communication behavior data, thereby saving computer resources of the power monitoring system and improving communication efficiency. The characteristic data is input into the login operation model and the communication habit model for comparison, so as to determine whether the communication behavior data is abnormal communication based on the two dimensions of login operation information and communication habit information of the communication behavior data corresponding to the characteristic data, thereby determining the risk type and improving the recognition rate of abnormal communication. Corresponding communication processing instructions are generated according to different risk types to make reasonable disposal of the communication behavior.

[0040] The third object of the present invention is achieved by the following technical solution:

[0041] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for intelligently identifying abnormal communication in the power monitoring system are implemented.

[0042] The fourth object of the present invention is achieved by the following technical solution:

[0043] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned abnormal communication intelligent identification method of the power monitoring system.

[0044] In summary, this application includes at least one of the following beneficial technical effects:

[0045] 1. Acquire the communication behavior data within the power monitoring system and determine the communication type. If the communication type is a control instruction, obtain the characteristic data of the communication behavior data for subsequent abnormal communication judgment. If the communication type is not a control instruction, determine whether to obtain the characteristic data of the communication behavior data and perform subsequent abnormal communication judgment based on the communication analysis extraction rate. Depending on the communication type, decide whether to directly perform abnormal communication judgment on the communication behavior data or perform abnormal communication judgment by sampling. This saves computer resources required for abnormal communication judgment and improves the communication efficiency within the power monitoring system.

[0046] 2. Obtain the historical network attack data set of the power monitoring system, calculate the network attack risk level of the previous statistical period from the historical network attack data set, and determine the communication analysis extraction rate of the current statistical period based on the network attack risk level of the previous statistical period, so as to achieve the effect of timely adjusting the extraction rate of non-control instruction type communication behavior data for abnormal communication judgment according to the risk level of the power monitoring system being attacked by the network.

[0047] 3. If the login operation model determines that the characteristic data of a certain communication behavior data is a risky login, the work position corresponding to the account that issued the communication behavior data is obtained, and the communication function permissions that are weakly related to the account's work position are restricted, so that the user can only perform communication behaviors that are strongly related to his or her position in the case of a risky login, thereby improving the security of the power monitoring system and reducing the occurrence of abnormal communication behaviors. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 This is a flow chart of a method for intelligently identifying abnormal communication in a power monitoring system according to an embodiment of the present application;

[0049] Figure 2 This is a flowchart for implementing step S20 in the method for intelligently identifying abnormal communication in a power monitoring system according to an embodiment of the present application;

[0050] Figure 3 This is a flowchart for implementing step S30 in the method for intelligently identifying abnormal communication in a power monitoring system according to one embodiment of the present application;

[0051] Figure 4 This is another implementation flowchart of step S30 in the abnormal communication intelligent identification method of the power monitoring system in one embodiment of the present application;

[0052] Figure 5 This is another implementation flowchart of step S30 in the abnormal communication intelligent identification method of the power monitoring system in one embodiment of the present application;

[0053] Figure 6This is another implementation flowchart of step S30 in the abnormal communication intelligent identification method of the power monitoring system in one embodiment of the present application;

[0054] Figure 7 This is another implementation flowchart of step S30 in the abnormal communication intelligent identification method of the power monitoring system in one embodiment of the present application;

[0055] Figure 8 This is a principle block diagram of an abnormal communication intelligent identification system of a power monitoring system in one embodiment of the present application;

[0056] Figure 9 It is a schematic diagram of a device in one embodiment of the present application. DETAILED DESCRIPTION

[0057] The present application is further described in detail below with reference to the accompanying drawings.

[0058] In one embodiment, if Figure 1 As shown, the present application discloses a method for intelligently identifying abnormal communication in a power monitoring system, which specifically includes the following steps:

[0059] S10: Acquire communication behavior data in the power monitoring system and determine the communication type.

[0060] Specifically, each piece of communication behavior data in the power monitoring system is obtained, and the communication type is determined based on the function of the obtained communication behavior data, where the communication type includes control instructions and non-control instructions, so that the communication behavior data of different communication types can be subsequently distinguished and abnormal communication judgment can be made based on different standards.

[0061] S20: If the communication type is a control instruction, obtain characteristic data of the communication behavior data; otherwise, determine whether to obtain characteristic data of the communication behavior data based on the communication analysis extraction rate.

[0062] In this embodiment, control instructions refer to operating instructions within the power monitoring system that may affect the safety of the power system; the communication analysis extraction rate refers to the sampling rate when making abnormal communication judgments on communication behavior data of non-control instruction types; and feature data refers to the data obtained after feature engineering processing of communication behavior data.

[0063] Specifically, the communication behavior within the power monitoring system usually includes control instructions and parameter collection information, among which the control instructions include but are not limited to switches for controlling the functions of the power monitoring system, instructions for controlling the on and off of circuits, and instructions for changing the voltage, current, power and other parameters of any power-consuming unit or power-consuming equipment in the connected circuit. These control instructions are likely to affect the power safety of power-consuming units and power-consuming equipment, and may further cause damage to personal safety and property safety. Therefore, all communication behavior data of the control instruction type should be judged as abnormal communication; in contrast, communication behavior of non-control instruction types has less impact on power safety. Therefore, random sampling can be used to judge abnormal communication for communication behavior data of non-control instruction types within the power monitoring system.

[0064] Specifically, when the communication type is a control instruction, feature engineering processing is performed on the communication behavior data to obtain feature data of the communication behavior data, so that subsequent abnormal communication judgment can be made based on the feature data; when the communication type is a non-control instruction, it is determined according to the preset communication analysis extraction rate whether to obtain the feature data corresponding to the non-control instruction type communication behavior data for subsequent abnormal communication judgment.

[0065] Specifically, feature engineering processing is performed on the communication behavior data to obtain feature data, which includes the communication time, communication protocol, IP addresses of the sender and receiver of the communication behavior data, communication port, and the device identification code, login time, and login method of the account corresponding to the communication behavior data.

[0066] Furthermore, communication behaviors that are not control instructions but have a significant impact on the safety and function of the power monitoring system can also be classified as control instructions, so that these communication behaviors that have a significant impact on the safety and function of the power monitoring system can also be inspected by the abnormal communication judgment function, further improving the safety of the power monitoring system.

[0067] S30: Inputting the characteristic data into the login operation model and the communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data.

[0068] In this embodiment, the login operation model refers to a model used to determine whether the login operation of the account corresponding to the feature data is an abnormal login; the communication habit model refers to a model used to determine whether the communication habits of the communication behavior data corresponding to the feature data are abnormal.

[0069] Specifically, the characteristic data is input into the login operation model and compared with the characteristics of the normally logged-in account recorded in the login operation model to determine the login status of the account corresponding to the characteristic data; the characteristic data is input into the communication habit model and compared with the characteristics of the normal communication behavior recorded in the communication habit model to determine whether the communication habits of the communication behavior data corresponding to the characteristic data are abnormal; and then the risk type of the communication behavior data corresponding to the characteristic data is determined based on the judgment results of the login operation model and the communication habit model.

[0070] S40: Generate corresponding communication processing instructions based on the risk type to handle the communication behavior.

[0071] In this embodiment, the risk type refers to a result generated based on the risk items determined after the characteristic data of the communication behavior data is judged by the login operation model and the communication habit model.

[0072] Specifically, the risk type is generated based on the login risk status of the account and the communication relationship risk status of the communication behavior. The login risk status includes normal login, risky login and dangerous login; the communication relationship risk status includes normal communication relationship, suspicious communication relationship and abnormal communication relationship; the risk types of communication behavior data include normal communication, suspicious communication and abnormal communication.

[0073] Specifically, when the risk type is normal communication, a communication processing instruction is generated to allow communication so that the communication behavior data can be transmitted normally; when the risk type is suspicious communication, a communication processing instruction is generated to allow risk communication and mark the login risk status and communication relationship risk status corresponding to the communication behavior data, so that the communication behavior data can be transmitted normally while marking possible risks, so that the staff can be aware of the risk situation of the communication; when the risk type is abnormal communication, a communication processing instruction is generated to prohibit abnormal communication to intercept the transmission of the communication behavior data to prevent threats to the network security of the power monitoring system.

[0074] In this embodiment, communication behavior data within the power monitoring system is obtained and the communication type is determined, so as to facilitate distinguishing a large number of communication behaviors in the power system and making different treatments for different types of communication behaviors. If the communication type is a control instruction, characteristic data of the communication behavior data is obtained, so as to facilitate subsequent determination of whether the communication behavior data belongs to abnormal communication by analyzing the characteristic data of the communication behavior. If the communication type is not a control instruction, whether to obtain the characteristic data of the communication behavior data and make subsequent abnormal communication determination is determined based on the communication analysis extraction rate. By determining the communication type of the communication behavior data, control instructions with strong security relevance to the power monitoring system and other non-control instruction communications with weaker security relevance to the power monitoring system are distinguished, rather than making abnormal communication determinations for all communication behavior data, thereby saving computer resources of the power monitoring system and improving communication efficiency. The characteristic data is input into the login operation model and the communication habit model for comparison, so as to determine whether the communication behavior data belongs to abnormal communication from two dimensions: the login operation information and the communication habit information of the communication behavior data corresponding to the characteristic data, thereby determining the risk type and improving the recognition rate of abnormal communication. Corresponding communication processing instructions are generated according to different risk types to make reasonable disposal of the communication behavior.

[0075] In one embodiment, if Figure 2 As shown, before step S20, the following steps are also included:

[0076] S21: Obtain a historical cyber attack dataset of the power monitoring system and determine the cyber attack risk level of the previous statistical period.

[0077] In this embodiment, the historical network attack data set refers to a data set generated by recording each network attack suffered by the power monitoring system and the corresponding time nodes; the attack risk level is determined based on the number of network attacks that occurred in each statistical period, reflecting the severity of the network attacks suffered by the power monitoring system in the statistical period.

[0078] Specifically, each network attack suffered by the power monitoring system is recorded to generate a historical network attack data set, and the network attack risk level of the previous statistical period is determined from the historical network attack data set according to the current time node; preferably, each natural week can be used as a statistical period; preferably, a medium-risk attack number threshold and a high-risk attack number threshold are set to determine the attack risk level. For example, the medium-risk attack number threshold is set to 5 times, and the high-risk attack number threshold is set to 10 times. Then, when the number of network attacks suffered in a statistical period is less than or equal to 5 times, the attack risk level is low risk; when the number of network attacks suffered in a period is between 6 and 10 times, the attack risk level is medium risk; when the number of network attacks suffered in a period is greater than or equal to 11 times, the attack risk level is high risk.

[0079] S22: Determine the communication analysis extraction rate for the current statistical period based on the network attack risk level of the previous statistical period.

[0080] Specifically, the current time node is obtained, and the communication analysis extraction rate of the current statistical period is determined based on the network attack risk level of the previous statistical period. Each network attack risk level corresponds to a communication analysis extraction rate. For example, when the network attack risk level is low risk, the network analysis extraction rate can be 30%; when the network attack risk level is medium risk, the network analysis extraction rate can be 40%; when the network attack risk level is high risk, the network analysis extraction rate can be 50%.

[0081] In one embodiment, if Figure 3 As shown, before step S30, the following steps are further included:

[0082] S31: Obtain a historical communication behavior dataset and corresponding feature data, and create a login operation model and a communication habit model based on the feature data.

[0083] In this embodiment, the historical communication behavior data set refers to a data set generated by recording historical communication behavior data in the power monitoring system.

[0084] Specifically, a number of communication behavior data are randomly extracted from the daily communication behavior data in the power monitoring system, and the suspicious communications and abnormal communications in the extracted communication behavior data are eliminated. A historical communication behavior data set is generated based on the remaining communication behavior data, and the feature data corresponding to the communication behavior data in the historical communication behavior data set is obtained to create a login operation model and a communication habit model.

[0085] Specifically, the device identification code, IP address, login method and login time data corresponding to the account that sent the communication behavior data in the characteristic data of the historical communication behavior data set are obtained, and these data are processed by a probability model to obtain a login operation model, where the probability model can include one or more of exponential distribution, Gaussian distribution, mixed model, clustering model, and Markov model.

[0086] Specifically, the IP addresses, communication ports, communication protocols, and communication time data of the two parties sending and receiving communication behavior data are obtained from the characteristic data of the historical communication behavior data set, and these data are processed by a probability model to obtain a communication habit model, where the probability model can include one or more of exponential distribution, Gaussian distribution, mixed model, and hierarchical model.

[0087] In one embodiment, if Figure 4 As shown, in step S30, it specifically includes:

[0088] S32: According to the login operation model, determine whether the account login operation behavior data corresponding to the feature data is abnormal, and output the judgment result.

[0089] Specifically, the feature data is input into the login operation model for comparison to determine whether the device identification code, IP address, login method and login time data corresponding to the account in the feature data are abnormal, and the judgment result of recording the login risk status is output. If all data are normal, the output judgment result is normal login; if one or more of the device identification code, IP address, login method and login time data are abnormal, the output judgment result is risky login and the risk item is marked. Among them, if the device identification code is abnormal, it is marked as a non-common device login, if the IP address is abnormal, it is marked as an off-site login, if the login method is abnormal, it is marked as a suspicious login method, and if the login time is abnormal, it is marked as a suspicious login time; if it is detected that the number of incorrect passwords during the account login process exceeds the preset password input threshold, the output judgment result is a dangerous login.

[0090] S33: According to the communication habit model, determine whether the device communication relationship data corresponding to the feature data is abnormal, and output the determination result.

[0091] Specifically, the feature data is input into the communication habit model for comparison to determine whether the IP addresses, communication ports, communication protocols, and communication time data of the two parties sending and receiving the communication behavior data in the feature data are abnormal, and the judgment result recording the risk status of the communication relationship is output. If all data are normal, the output judgment result is that the communication relationship is normal; if one or two of the IP address, communication port, communication protocol, and communication time data are abnormal, the output judgment result is that the communication relationship is suspicious; if one or two of the IP address, communication port, communication protocol, and communication time data are abnormal, the output judgment result is that the communication relationship is normal and suspicious and the risk item is marked; if three or more of the IP address, communication port, communication protocol, and communication time data are abnormal, the output judgment result is that the communication relationship is abnormal and the risk item is marked.

[0092] In one embodiment, if Figure 5 As shown, in step S30, it also includes:

[0093] S34: Generate risk types for the communication behavior data based on the judgment results output by the login operation model and the communication habit model.

[0094] Specifically, according to the judgment results output by the login operation model and the communication habit model, when the combination of the login risk status and the communication relationship risk status is normal login and normal communication relationship, the generated risk type is normal communication; when the combination of the login risk status and the communication relationship risk status is normal login and suspicious communication relationship, risky login and communication relationship is suspicious, and risky login and communication relationship is suspicious, the generated risk type is suspicious communication; when the combination of the login risk status and the communication relationship risk status is dangerous login and normal communication relationship, dangerous login and communication relationship is suspicious, dangerous login and communication relationship is abnormal, normal login and communication relationship is abnormal, risky login and communication relationship is abnormal, and dangerous login and communication relationship is abnormal, the generated risk type is abnormal communication.

[0095] In one embodiment, if Figure 6 As shown, after step S32, the following steps are further included:

[0096] S35: If the judgment result of the login operation model is risky login, the communication function permissions weakly associated with the corresponding position of the account are restricted.

[0097] Specifically, the judgment result of the login risk status of the account corresponding to the characteristic data output by the login operation model is used to limit the communication function permissions of the account. If the judgment result of the account is a normal login, the communication function permissions of the account will not be restricted. If the judgment result of the account is a risky login or a dangerous login, the job position of the user corresponding to the account is further obtained. At the same time, the communication function permissions obtained by the account are divided into strongly associated communication function permissions and weakly associated communication function permissions according to the job position. The communication function permissions weakly associated with the job position corresponding to the account are restricted. For accounts with risky or dangerous logins, only the communication function permissions strongly associated with their job positions are retained, so that they can complete their work normally. At the same time, the communication function permissions weakly associated with their job positions are restricted to reduce the possibility of abnormal communication behavior.

[0098] In one embodiment, if Figure 7 As shown, after step S35, the following steps are further included:

[0099] S36: Obtain biometric verification information from the account with restricted communication function permissions, and restore the communication function permissions of the account based on the biometric verification information.

[0100] In this embodiment, biometric authentication information refers to information that can verify the user's biometric identity when logging into an account.

[0101] Specifically, biometric verification information can be fingerprint information, facial image information, iris information, etc. When an account is restricted from some communication function permissions due to being identified as a risky login or a dangerous login, the user can use biometric verification information to fully or partially restore the restricted communication function permissions of the account.

[0102] Specifically, when an account is in a risky login or dangerous login state, a biometric verification prompt is sent to the account to prompt the user to restore the account's communication function permissions through biometric verification information.

[0103] It should be understood that the serial numbers of the steps in the above embodiments do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0104] In one embodiment, a system for intelligently identifying abnormal communication of a power monitoring system is provided. The system for intelligently identifying abnormal communication of a power monitoring system corresponds one-to-one to the method for intelligently identifying abnormal communication of a power monitoring system in the above embodiment.

[0105] like Figure 8 As shown, an abnormal communication intelligent identification system for a power monitoring system includes a communication type judgment module, a feature data acquisition module, a communication risk judgment module, and a communication behavior handling module. The detailed description of each functional module is as follows:

[0106] A communication type determination module is used to obtain communication behavior data in the power monitoring system and determine the communication type;

[0107] A feature data acquisition module, configured to acquire feature data of the communication behavior data if the communication type is a control instruction, and otherwise determine whether to acquire feature data of the communication behavior data based on the communication analysis extraction rate;

[0108] The communication risk judgment module is used to input the characteristic data into the login operation model and the communication habit model for matching, and judge the risk type of the communication behavior data corresponding to the characteristic data;

[0109] The communication behavior handling module is used to generate corresponding communication processing instructions based on the risk type to handle the communication behavior.

[0110] For the specific limitations of the abnormal communication intelligent identification system of the power monitoring system, please refer to the limitations of the abnormal communication intelligent identification method of the power monitoring system above, which will not be repeated here; the various modules in the above-mentioned abnormal communication intelligent identification system of the power monitoring system can be implemented in whole or in part through software, hardware and their combination; the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of the above-mentioned modules.

[0111] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 9 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as communication behavior data, feature data, login operation models, communication habit models, historical network attack data sets and communication analysis extraction rates. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it realizes a method for intelligently identifying abnormal communications in a power monitoring system.

[0112] In one embodiment, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are performed:

[0113] S10: Acquire communication behavior data in the power monitoring system and determine the communication type;

[0114] S20: If the communication type is a control instruction, obtain characteristic data of the communication behavior data; otherwise, determine whether to obtain characteristic data of the communication behavior data based on the communication analysis extraction rate;

[0115] S30: Inputting the characteristic data into the login operation model and the communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data;

[0116] S40: Generate corresponding communication processing instructions based on the risk type to handle the communication behavior.

[0117] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0118] S10: Acquire communication behavior data in the power monitoring system and determine the communication type;

[0119] S20: If the communication type is a control instruction, obtain characteristic data of the communication behavior data; otherwise, determine whether to obtain characteristic data of the communication behavior data based on the communication analysis extraction rate;

[0120] S30: Inputting the characteristic data into the login operation model and the communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data;

[0121] S40: Generate corresponding communication processing instructions based on the risk type to handle the communication behavior.

[0122] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0123] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0124] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, it should be understood by those skilled in the art that the technical solutions described in the aforementioned embodiments may still be modified, or some of the features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

Claims

1. A method for intelligently identifying abnormal communication in a power monitoring system, characterized by: The method for intelligently identifying abnormal communication in a power monitoring system comprises the following steps: Obtain communication behavior data in the power monitoring system and determine the communication type; If the communication type is a control instruction, obtaining characteristic data of the communication behavior data; otherwise, determining whether to obtain the characteristic data of the communication behavior data based on the communication analysis extraction rate; Inputting the characteristic data into a login operation model and a communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data; Generate corresponding communication processing instructions based on the risk type to deal with the communication behavior; The step of inputting the characteristic data into the login operation model and the communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data, specifically includes: According to the login operation model, determine whether the account login operation behavior data corresponding to the characteristic data is abnormal, and output the judgment result; Determine, based on the communication habit model, whether the device communication relationship data corresponding to the characteristic data is abnormal, and output a determination result; The account login operation behavior data includes device identification code, IP address, login method and login time data; The device communication relationship data includes IP address, communication port, communication protocol, and communication time data.

2. The method for intelligently identifying abnormal communication in a power monitoring system according to claim 1, characterized in that: If the communication type is a control instruction, obtaining characteristic data of the communication behavior data; otherwise, before determining whether to obtain characteristic data of the communication behavior data based on the communication analysis extraction rate, the method further includes: Obtain historical cyberattack data sets for the power monitoring system and determine the cyberattack risk level for the previous statistical period; The communication analysis extraction rate for the current statistical period is determined based on the network attack risk level of the previous statistical period.

3. The method for intelligently identifying abnormal communication in a power monitoring system according to claim 1, wherein: Before inputting the characteristic data into the login operation model and the communication habit model for comparison and determining the risk type of the communication behavior data corresponding to the characteristic data, the method further includes: Obtain historical communication behavior datasets and corresponding feature data, and create login operation models and communication habit models based on the feature data.

4. The method for intelligently identifying abnormal communication in a power monitoring system according to claim 1, characterized in that: The step of inputting the characteristic data into a login operation model and a communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data, further includes: Based on the judgment results output by the login operation model and the communication habit model, the risk type of the communication behavior data is generated.

5. The method for intelligently identifying abnormal communication in a power monitoring system according to claim 1, characterized in that: After determining, based on the login operation model, whether the account login operation behavior data corresponding to the characteristic data is abnormal and outputting the determination result, the method further includes: If the judgment result of the login operation model is risky login, the communication function permissions weakly associated with the corresponding position of the account are restricted.

6. The method for intelligently identifying abnormal communication in a power monitoring system according to claim 1, characterized in that: If the judgment result of the login operation model is risky login, after the step of restricting the communication function permissions weakly associated with the position corresponding to the account, the method further includes: Acquire biometric verification information from an account with restricted communication function permissions, and restore the communication function permissions of the account based on the biometric verification information.

7. An abnormal communication intelligent identification system for a power monitoring system, characterized in that: include: A communication type determination module is used to obtain communication behavior data in the power monitoring system and determine the communication type; a feature data acquisition module, configured to acquire feature data of the communication behavior data if the communication type is a control instruction, and otherwise determine whether to acquire feature data of the communication behavior data based on a communication analysis extraction rate; a communication risk judgment module, configured to input the characteristic data into a login operation model and a communication habit model for matching, and to judge the risk type of the communication behavior data corresponding to the characteristic data; A communication behavior handling module, configured to generate corresponding communication handling instructions based on the risk type to handle the communication behavior; The step of inputting the characteristic data into the login operation model and the communication habit model for comparison, and determining the risk type of the communication behavior data corresponding to the characteristic data, specifically includes: According to the login operation model, determine whether the account login operation behavior data corresponding to the characteristic data is abnormal, and output the judgment result; According to the communication habit model, the abnormality of the device communication relationship data corresponding to the characteristic data is judged, and the judgment result is output.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the abnormal communication intelligent identification method of the power monitoring system according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the abnormal communication intelligent identification method of the power monitoring system according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Information security monitoring method and system

    CN108063753A