A complex network-based power monitoring system vulnerability risk grading method
By assessing the impact of vulnerabilities in critical factors within power monitoring systems, the problem of the inapplicability of existing industrial control system vulnerability scoring standards is solved, enabling accurate assessment of vulnerability risks in power monitoring systems and meeting the security protection requirements of power monitoring systems.
Patent Information
- Application Number
- CN202211297182.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-21
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2042-10-21
AI Technical Summary
The existing industrial control system vulnerability scoring standards are applicable to information system vulnerability scoring, but not to power monitoring systems. Furthermore, they fail to incorporate the security protection regulations for power monitoring systems, resulting in an imperfect vulnerability risk assessment method for power monitoring systems with complex networks.
This paper presents a method for vulnerability risk assessment of power monitoring systems based on complex networks. By acquiring vulnerability information and device information of the power monitoring system, it determines multiple influencing factors of important factors according to security partitions, including important devices, important services, important ports and important protocols, assesses their impact from vulnerabilities, and finally determines the vulnerability risk level of the power monitoring system.
It realizes vulnerability risk assessment that combines the security protection regulations of power monitoring systems with actual important factors, improves the applicability and accuracy of the assessment, and can effectively assess the vulnerability risk of power monitoring systems being attacked maliciously.
Smart Images

Figure CN115622783B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a power monitoring system vulnerability risk grading method based on a complex network. BACKGROUND
[0002] Industrial control system security problems are increasingly prominent, and industrial control vulnerabilities are important entry points for attackers to implement destruction. As a benchmark for the high development and deep integration of industrial control systems, once the industrial control network of a power enterprise has a vulnerability, it will cause serious losses. The power monitoring system is the nerve network and control center of the entire power system, and is of great significance to the safe and stable operation of the power grid and the reliable supply of electricity. With the continuous advancement of smart grid construction, computer technology and information technology are widely used in the field of power monitoring systems. The threat and risk problems brought by security vulnerabilities as a "companion" are increasingly serious. According to relevant regulations of China's power monitoring system security protection, power monitoring system security protection mainly includes four aspects: first, security zoning; second, networking; third, horizontal isolation; and fourth, vertical authentication. Security zoning is mainly to distinguish between the production control area and the management area. The production control area controls production, and information management is the management of power sources and related administrative affairs. Networking refers to the use of separate network equipment to build a network for all data networks within the scope of a power enterprise. In terms of physics, it is necessary to dispatch power data networks from other public networks. Horizontal isolation means that the control area and the larger range of information management must be established by relevant national departments. Vertical authentication is the transmission of related data and the security protection of the vertical boundary. After a series of operations, the production control area of the power system is protected and effectively controlled.
[0003] The existing industrial control vulnerability scoring standard is based on the Common Vulnerability Scoring System (CVSS), which is suitable for information system vulnerability scoring and is not suitable for power monitoring system vulnerability scoring. Moreover, the existing industrial control vulnerability scoring standard does not consider the actual important factors related to the power monitoring system security protection regulations. Therefore, there is a problem of imperfect power monitoring system vulnerability risk assessment method for complex networks in the prior art. SUMMARY
[0004] The present application provides a power monitoring system vulnerability risk grading method based on a complex network, which at least solves the problem of imperfect power monitoring system vulnerability risk assessment method for complex networks in the related art.
[0005] According to a first aspect of an embodiment of the present application, a method for grading vulnerability risk of a power monitoring system based on a complex network is provided, the method comprising: obtaining vulnerability information of the power monitoring system and device information of the complex network, wherein the complex network is determined according to a security partition of the power monitoring system; determining scores of important factors affected by the vulnerability according to a plurality of influence factors of the important factors in the complex network and the device information, wherein the important factors include important devices, important services, important ports, and important protocols; and determining a vulnerability risk level of the power monitoring system according to the scores of the plurality of important factors affected by the vulnerability.
[0006] Optionally, the complex network comprises a production control zone security I area, a production control zone security II area, and a management information area, and the determining the scores of the important factors affected by the vulnerability according to the plurality of influence factors of the important factors in the complex network and the device information comprises: determining a score of important devices affected by the vulnerability according to a data confidentiality influence factor of each device affected by the vulnerability, a correlation degree influence factor between devices, a permission influence factor possessed by the device, a running critical service device influence factor, and a total number of important devices in the production control zone security I area, the production control zone security II area, and the management information area.
[0007] Optionally, the complex network comprises a production control zone security I area, a production control zone security II area, and a management information area, and the determining the scores of the important factors affected by the vulnerability according to the plurality of influence factors of the important factors in the complex network and the device information further comprises: determining a score of important services of the production control zone security I area affected by the vulnerability according to a three-remote service influence factor of each device affected by the vulnerability in the production control zone security I area and a total number of devices running three-remote services in the production control zone security I area; determining a score of important services of the production control zone security II area affected by the vulnerability according to a phasor measurement unit (PMU) service influence factor of each device affected by the vulnerability in the production control zone security II area, a network security monitoring service influence factor, and a total number of devices running the PMU service and / or the network security monitoring service in the production control zone security II area; determining a score of important services of the management information area affected by the vulnerability according to a mail sending and receiving service influence factor of each device affected by the vulnerability in the management information area and a total number of devices running the mail sending and receiving service in the management information area; and determining the score of the important services affected by the vulnerability according to the score of the important services of the production control zone security I area affected by the vulnerability, the score of the important services of the production control zone security II area affected by the vulnerability, and the score of the important services of the management information area affected by the vulnerability.
[0008] Optionally, the complex network comprises a production control zone security I area, a production control zone security II area and a management information area, and the determining the score of the important factor affected by the vulnerability according to the complex network and the multiple impact factors of the important factor in the device information further comprises: determining the score of the important port affected by the vulnerability according to a private port abnormal closing impact factor of each device affected by the vulnerability, a number of private port abnormal closings, a total number of private ports, a high-risk port abnormal opening impact factor of each device affected by the vulnerability, a number of high-risk port abnormal openings, a total number of high-risk ports, and a total number of devices containing important ports in the production control zone security I area, the production control zone security II area and the management information area, wherein the important ports comprise private ports and high-risk ports.
[0009] Optionally, the complex network comprises a production control zone security I area, a production control zone security II area and a management information area, and the determining the score of the important factor affected by the vulnerability according to the complex network and the multiple impact factors of the important factor in the device information further comprises: determining the score of the important protocol affected by the vulnerability according to a Modbus TCP protocol impact factor of each device affected by the vulnerability, a Modbus ASCII protocol impact factor, a Modbus RTU protocol impact factor, a SIMATICS 7 protocol impact factor, and a total number of devices in the production control zone security I area and the production control zone security II area.
[0010] Optionally, the determining the vulnerability risk level of the power monitoring system according to the scores of the multiple important factors affected by the vulnerability comprises: determining the vulnerability risk level of the power monitoring system according to a number of non-zero items in the scores of the multiple important factors affected by the vulnerability, wherein the more the number of non-zero items, the higher the vulnerability risk level.
[0011] Optionally, the method further comprises: determining a risk degree under any vulnerability risk level according to a sum of the scores of the multiple important factors affected by the vulnerability, wherein the greater the sum of the scores of the multiple important factors affected by the vulnerability, the higher the risk degree under the any vulnerability risk level.
[0012] According to a second aspect of the embodiments of the present application, there is further provided a device for grading vulnerability risk of a power monitoring system based on a complex network, the device comprising: an obtaining module configured to obtain vulnerability information of the power monitoring system and device information of the complex network, wherein the complex network is determined according to a security partition of the power monitoring system; a first determining module configured to determine a score of an important factor affected by a vulnerability according to a plurality of influence factors of the important factor in the complex network and the device information, wherein the important factor comprises an important device, an important service, an important port and an important protocol; and a second determining module configured to determine a vulnerability risk level of the power monitoring system according to the scores of the plurality of important factors affected by the vulnerability.
[0013] Optionally, the first determining module comprises a first determining unit configured to determine the score of the important device affected by the vulnerability according to a data confidentiality influence factor of each device affected by the vulnerability, a correlation degree influence factor between devices, a permission influence factor possessed by the device, a running critical service device influence factor, and a total number of important devices in the production control zone security I area, the production control zone security II area and the management information zone.
[0014] Optionally, the first determining module further comprises: a second determining unit configured to determine the score of the important service of the production control zone security I area affected by the vulnerability according to a three-remote service influence factor of each device affected by the vulnerability in the production control zone security I area and a total number of devices running three-remote service in the production control zone security I area; a third determining unit configured to determine the score of the important service of the production control zone security II area affected by the vulnerability according to a synchrophasor measurement service influence factor of each device affected by the vulnerability in the production control zone security II area, a network security monitoring service influence factor, and a total number of devices running synchrophasor measurement service and / or network security monitoring service in the production control zone security II area; a fourth determining unit configured to determine the score of the important service of the management information zone affected by the vulnerability according to a mail sending and receiving service influence factor of each device affected by the vulnerability in the management information zone and a total number of devices running mail sending and receiving service in the management information zone; and a fifth determining unit configured to determine the score of the important service affected by the vulnerability according to the score of the important service of the production control zone security I area affected by the vulnerability, the score of the important service of the production control zone security II area affected by the vulnerability, and the score of the important service of the management information zone affected by the vulnerability.
[0015] Optionally, the first determining module further comprises a sixth determining unit, configured to determine the score of the important ports affected by the vulnerability according to the private port abnormal closing influence factor of each device affected by the vulnerability, the number of private port abnormal closings, the total number of private ports, the high-risk port abnormal opening influence factor of each device affected by the vulnerability, the number of high-risk port abnormal openings, the total number of high-risk ports, and the total number of devices containing important ports in the production control area security I area, the production control area security II area, and the management information area.
[0016] Optionally, the first determining module further comprises a seventh determining unit, configured to determine the score of the important protocols affected by the vulnerability according to the Modbus TCP protocol influence factor of each device affected by the vulnerability, the Modbus ASCII protocol influence factor, the Modbus RTU protocol influence factor, the SIMATICS 7 protocol influence factor, and the total number of devices in the production control area security I area and the production control area security II area.
[0017] Optionally, the second determining module comprises a determining unit, configured to determine the vulnerability risk level of the power monitoring system according to the number of non-zero items in the scores of the plurality of important factors affected by the vulnerability.
[0018] Optionally, the determining unit comprises a determining sub-module, configured to determine the risk degree under any vulnerability risk level according to the sum of the scores of the plurality of important factors affected by the vulnerability, wherein the greater the sum of the scores of the plurality of important factors affected by the vulnerability, the higher the risk degree under the any vulnerability risk level.
[0019] According to a third aspect of the embodiments of the present application, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory complete communication with each other through the communication bus; the memory is configured to store a computer program; and the processor is configured to execute the method steps in any of the above embodiments by running the computer program stored in the memory.
[0020] According to a fourth aspect of the embodiments of the present application, a computer readable storage medium is provided, which stores a computer program, wherein the computer program is configured to execute the method steps in any of the above embodiments when running.
[0021] In the embodiment of the present application, the vulnerability information of the power monitoring system and the device information of the complex network are acquired; the scores of important factors affected by the vulnerability are determined according to various influence factors of important factors in the complex network and the device information, wherein the important factors include important devices, important services, important ports and important protocols; and the vulnerability risk level of the power monitoring system is determined according to the scores of the important factors affected by the vulnerability. Since the present application considers the influence of the security partition of the power monitoring system and the important devices, important services, important ports and important protocols in the vulnerability risk assessment, the vulnerability and the existing vulnerability risk caused by the malicious attack on the power monitoring system are assessed and graded, so as to achieve the purpose of combining the relevant regulations of the security protection of the power monitoring system and considering the relevant important factors in the actual power monitoring system, and solve the problem of the imperfect vulnerability risk assessment method of the power monitoring system of the complex network in the related art.
[0022] In the embodiment of the present application, the vulnerability risk level of the power monitoring system is determined according to the scores of the important factors affected by the vulnerability, so as to achieve the purpose of comprehensively assessing the security partition and the relevant important factors in the actual power monitoring system on the vulnerability risk of the power monitoring system. The applicability and accuracy of the vulnerability risk assessment of the power monitoring system are improved. BRIEF DESCRIPTION OF DRAWINGS
[0023] The accompanying drawings, which are incorporated into and form a part of the specification, illustrate an embodiment consistent with the present application and, together with the description, serve to explain the principles of the application.
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained based on these drawings without any creative labor.
[0025] Figure 1 is a schematic diagram of a hardware environment of an optional power monitoring system vulnerability risk grading method based on a complex network according to an embodiment of the present application;
[0026] Figure 2 is a flowchart of an optional power monitoring system vulnerability risk grading method based on a complex network according to an embodiment of the present application;
[0027] Figure 3 is a structural block diagram of an optional power monitoring system vulnerability risk grading device according to an embodiment of the present application;
[0028] Figure 4 is a structural block diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order to make the person skilled in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the protection scope of the present application.
[0030] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in other than the order illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to such processes, methods, products or devices. In addition, the meaning of "and / or" in the present application includes three parallel solutions, for example, "A and / or B" includes A solution, or B solution, or A and B solutions are satisfied at the same time.
[0031] According to an aspect of the embodiments of the present application, there is provided a complex network-based power monitoring system vulnerability risk grading method. Optionally, in the present embodiment, the complex network-based power monitoring system vulnerability risk grading method can be applied to the hardware environment as shown in Figure 1 As shown in Figure 1 The terminal 102 can include a memory 104, a processor 106 and a display 108 (optional components). The terminal 102 can be connected to a server 112 through a network 110, which can be used to provide services (such as application services) for the terminal or the client installed on the terminal, and a database 114 can be set on the server 112 or independent of the server 112, which can be used to provide data storage services for the server 112. In addition, the server 112 can run a processing engine 116, which can be used to execute the steps performed by the server 112.
[0032] Optionally, the terminal 102 can be, but is not limited to, a terminal capable of computing data, such as a mobile terminal (e.g., a mobile phone, a tablet computer), a notebook computer, a PC (Personal Computer), and the like. The network can include, but is not limited to, a wireless network or a wired network. The wireless network includes Bluetooth, WIFI (Wireless Fidelity), and other wireless communication networks. The wired network can include, but is not limited to, a wide area network, a metropolitan area network, and a local area network. The server 112 can include, but is not limited to, any hardware device capable of computing.
[0033] In addition, in the embodiment, the power monitoring system vulnerability risk grading method based on a complex network can also be applied to a powerful independent processing device without data interaction. For example, the processing device can be a terminal device with powerful processing capability, that is, each operation in the power monitoring system vulnerability risk grading method based on a complex network can be integrated into an independent processing device. The above is only an example, and the embodiment does not make any limitation thereto.
[0034] Optionally, in the embodiment, the power monitoring system vulnerability risk grading method based on a complex network can be executed by the server 112, or by the terminal 102, or by both the server 112 and the terminal 102. The terminal 102 executing the power monitoring system vulnerability risk grading method based on a complex network according to the embodiment of the application can also be executed by a client installed thereon.
[0035] Taking the power monitoring system vulnerability risk grading method based on a complex network applied to a central processing unit as an example, Figure 2 is a flowchart of an optional power monitoring system vulnerability risk grading method based on a complex network according to the embodiment of the application, as shown in Figure 2 the flowchart of the method can include the following steps:
[0036] In step S201, the vulnerability information of the power monitoring system and the device information of the complex network are acquired, wherein the complex network is determined according to the security partition of the power monitoring system. Optionally, according to the relevant provisions of the security protection of the power monitoring system, the security protection of the power monitoring system mainly contains four aspects, that is, the security partition, the network, the horizontal isolation and the vertical authentication. Among them, the security partition is to distinguish the production control area and the management area, the production control area is the master control of production, and the management information area is the management of the power supply and the system and other relevant administrative affairs. In the embodiment of the present application, the acquisition of the vulnerability information of the power monitoring system includes the acquisition of the vulnerability caused by malicious attacks and the existing vulnerability in the power monitoring system; the acquisition of the device information of the complex network is to acquire the number of devices in each area and the influence factors of each device on various important factors according to the security partition result.
[0037] In step S202, the scores of the important factors affected by the vulnerability are determined according to the various influence factors of the important factors in the complex network and the device information, wherein the important factors include important devices, important businesses, important ports and important protocols. Optionally, in order to solve the problem that the existing industrial control vulnerability scoring standard is applicable to information system vulnerability scoring but not applicable to power monitoring system vulnerability scoring, the present application combines the related important factors involved in the actual power monitoring system vulnerability risk assessment to conduct vulnerability risk assessment. Specifically, the power monitoring system vulnerability risk level is evaluated from four aspects of important devices, important businesses, important ports and important protocols, and the scores of the important factors affected by the vulnerability are determined.
[0038] In step S203, the power monitoring system vulnerability risk level is determined according to the scores of the important factors affected by the vulnerability. Optionally, according to the scores of the important factors affected by the vulnerability determined in the previous step, the power monitoring system vulnerability risk level is determined.
[0039] In the embodiment of the present application, the vulnerability information of the power monitoring system and the device information of the complex network are acquired; the scores of the important factors affected by the vulnerability are determined according to the various influence factors of the important factors in the complex network and the device information, wherein the important factors include important devices, important businesses, important ports and important protocols; the power monitoring system vulnerability risk level is determined according to the scores of the important factors affected by the vulnerability. Since the security partition of the power monitoring system and the influence of important devices, important businesses, important ports and important protocols are considered in the vulnerability risk assessment, the vulnerability risk of the power monitoring system caused by malicious attacks and the existing vulnerability is evaluated and graded, which achieves the purpose of combining the relevant provisions of the security protection of the power monitoring system and considering the related important factors in the actual power monitoring system, and solves the problem of imperfect power monitoring system vulnerability risk assessment method for complex network in the related art.
[0040] As an optional embodiment, the complex network comprises a production control zone security I area, a production control zone security II area and a management information area, and the score of the important factor affected by the vulnerability is determined according to the multiple influence factors of the important factor in the complex network and the device information, and the score of the important device affected by the vulnerability is determined according to the data confidentiality influence factor of each device affected by the vulnerability, the correlation degree influence factor between devices, the permission influence factor possessed by the device, the running critical business device influence factor, and the total number of important devices in the production control zone security I area, the production control zone security II area and the management information area.
[0041] Optionally, the number of important devices in the production control zone security I area, the production control zone security II area and the management information area is determined according to the obtained device information of the complex network, it is assumed that the total number of important devices in the production control zone security I area is N1 (N1>0), the total number of important devices in the production control zone security II area is N2 (N2>0), and the total number of important devices in the management information area is N3 (N3>0), and the influence factors of the important devices are respectively a data confidentiality influence factor α, a correlation degree influence factor β between devices, a permission influence factor χ possessed by the device, and a running critical business device influence factor δ, then the score K of the important device affected by the vulnerability is q1 As shown in formula (1):
[0042]
[0043] In the formula, i represents the number of s important devices affected by the vulnerability, the value range of s is 0≤s≤N1+N2+N3, N1+N2+N3 represents the total number of important devices in the production control zone security I area, the production control zone security II area and the management information area, α i +β i +χ i +δ i represents the sum of all influence factors of the i-th device affected by the vulnerability, since the importance of the device may be different, the values of the influence factors of different devices may also be different, wherein α i , β i , χ i , δ i ∈[0,10]. In this embodiment, the influence of the important device affected by the vulnerability is evaluated according to the multiple influence factors of the important device after the security partition.
[0044] As an optional embodiment, the complex network comprises a production control area security I area, a production control area security II area and a management information area, and the score of the important factor affected by the vulnerability is determined according to the multiple influence factors of the important factor in the complex network and the equipment information, and further comprises: determining the score of the important business of the production control area security I area affected by the vulnerability according to the three remote business influence factors of each equipment affected by the vulnerability in the production control area security I area and the total number of equipment running the three remote business in the production control area security I area; determining the score of the important business of the production control area security II area affected by the vulnerability according to the synchronous phasor measurement business influence factor, the network security monitoring business influence factor of each equipment affected by the vulnerability in the production control area security II area and the total number of equipment running the synchronous phasor measurement business and / or the network security monitoring business in the production control area security II area; determining the score of the important business of the management information area affected by the vulnerability according to the receiving and sending email business influence factor of each equipment affected by the vulnerability in the management information area and the total number of equipment running the receiving and sending email business in the management information area; and determining the score of the important business affected by the vulnerability according to the score of the important business of the production control area security I area affected by the vulnerability, the score of the important business of the production control area security II area affected by the vulnerability and the score of the important business of the management information area affected by the vulnerability.
[0045] Optionally, the influence of the important business on the vulnerability risk assessment is considered, and specifically, it is assumed that the important business of the production control area security I area is the three remote business, i.e. remote control, remote signaling and remote measurement, the corresponding influence factor is the three remote business influence factor η, and the total number of equipment running the three remote business in the production control area security I area is N1, so the score of the important business of the production control area security I area affected by the vulnerability is shown in formula (2):
[0046]
[0047] In the formula, x represents the number of n important equipment whose three remote business is affected by the vulnerability, the value range of n is 0≤n≤N1, N1 represents the total number of equipment running the three remote business in the production control area security I area, η x ∈[0,10] represents the three remote business influence factor of the xth equipment whose three remote business is affected by the vulnerability, wherein η x The values of the three remote business influence factors η x of the multiple equipment can be equal or not equal.
[0048] The important business of the production control area security II area is the synchronous phasor measurement business and the network security monitoring business, and the corresponding influence factors are the synchronous phasor measurement business influence factor φ and the network security monitoring business influence factor The total number of devices running the phasor measurement service and / or the network security monitoring service in the safety II area of the production control area is N2, and the score of the important service in the safety II area of the production control area affected by the vulnerability is shown in formula (3):
[0049]
[0050] In the formula, y represents the number of important devices of t phasor measurement services and / or network security monitoring services affected by the vulnerability, the value range of t is 0≤t≤N2, N2 represents the total number of devices running the phasor measurement service and / or the network security monitoring service in the safety II area of the production control area, and φ y , respectively represent the influence factor of the phasor measurement service and the network security monitoring service of the yth device.
[0051] The important service of the management information area is the mail sending and receiving service, and the corresponding influence factor is the mail sending and receiving service influence factor γ. The total number of devices running the mail sending and receiving service in the management information area is N3, and the score of the important service of the management information area affected by the vulnerability is shown in formula (4):
[0052]
[0053] In the formula, z represents the number of important devices of r mail sending and receiving services affected by the vulnerability, the value range of r is 0≤r≤N3, N3 represents the total number of devices running the mail sending and receiving service in the management information area, and γ z ∈[0,10] represents the mail sending and receiving service influence factor of the zth device.
[0054] In summary, the score of the important service affected by the vulnerability is determined according to the score of the important service in the safety I area of the production control area affected by the vulnerability, the score of the important service in the safety II area of the production control area affected by the vulnerability, and the score of the important service in the management information area affected by the vulnerability. The score of the important service affected by the vulnerability K q2 as shown in formula (5):
[0055]
[0056] In this embodiment, the influence of the vulnerability on the important service is evaluated according to the various influence factors of the important service after the security partition.
[0057] As an optional embodiment, the complex network comprises a production control area security I area, a production control area security II area and a management information area, and the score of the important factor affected by the vulnerability is further determined according to a plurality of influence factors of the important factor in the complex network and the device information, and the score of the important port affected by the vulnerability is further determined according to a private port abnormal closing influence factor of each device affected by the vulnerability, a private port abnormal closing port number, a private port total number, a high-risk port abnormal opening influence factor of each device affected by the vulnerability, a high-risk port abnormal opening port number, a high-risk port total number, and a total number of devices containing important ports in the production control area security I area, the production control area security II area and the management information area, wherein the important port includes the private port and the high-risk port.
[0058] Optionally, the private port abnormal closing influence factor λ, the private port total number is σ (σ>0), the high-risk port abnormal opening influence factor ξ, and the 7 high-risk ports that must be closed are 135, 137, 138, 139, 161, 445 and 3389. It should be noted that the private port is normally opened, and the high-risk port is normally closed. The score K of the important port affected by the vulnerability q3 As shown in formula (6):
[0059]
[0060] In the formula, k represents the number of important devices of l important ports affected by the vulnerability, the value range of l is 0≤l≤N, N represents the total number of devices containing important ports in the production control area security I area, the production control area security II area and the management information area, p and u respectively represent the number of ports of the private port affected by the vulnerability and abnormally closed, and the number of ports of the high-risk port affected by the vulnerability and abnormally opened, λ l , ζ l ∈[0,10] respectively represent the private port abnormal closing influence factor of the lth device and the high-risk port abnormal opening influence factor of the lth device. In this embodiment, the influence of the important port affected by the vulnerability is evaluated according to a plurality of influence factors of the important port after the security partition, wherein the important port considers the private port and the high-risk port.
[0061] As an optional embodiment, the complex network comprises a production control area security I area, a production control area security II area and a management information area, and the score of the important factor affected by the vulnerability further comprises: determining the score of the important protocol affected by the vulnerability according to the Modbus TCP protocol influence factor, the Modbus ASCII protocol influence factor, the Modbus RTU protocol influence factor, the SIMATICS 7 protocol influence factor of each device affected by the vulnerability and the total number of devices in the production control area security I area and the production control area security II area.
[0062] Optionally, the influence factor of the important protocol comprises a Modbus TCP (Transmission Control Protocol) protocol influence factor θ, a Modbus ASCII (American Standard Code for Information Interchange) protocol influence factor , a Modbus RTU (Remote Terminal Unit) protocol influence factor τ and a S7 (SIMATICS 7) protocol influence factor ω. q4 As shown in formula (7):
[0063]
[0064] In the formula, w represents the number of k important devices affected by the vulnerability, and the value range of k is 0≤k≤N1+N2, N1+N2 represents the total number of devices in the production control area security I area and the production control area security II area, represents the sum of all influence factors of the wth device affected by the vulnerability, wherein θ k , τ k , ω k ∈[0,10]. In this embodiment, the influence of the important protocol on the important device affected by the vulnerability is evaluated according to the multiple influence factors of the important protocol after the security partition.
[0065] As an optional embodiment, the method for determining the vulnerability risk level of the power monitoring system according to the scores of the multiple important factors affected by the vulnerability comprises: determining the vulnerability risk level of the power monitoring system according to the number of non-zero items in the scores of the multiple important factors affected by the vulnerability, wherein the more the number of non-zero items, the higher the vulnerability risk level. Optionally, the scores of the multiple important factors affected by the vulnerability are K q1 ,K q2 ,K q3 ,K q4 The vulnerability risk grading for determining the vulnerability risk level of the power monitoring system is shown in formula (8):
[0066]
[0067] K q1 ,K q2 ,K q3 ,K q4 respectively represent important equipment affected by vulnerability score, important business affected by vulnerability score, important port affected by vulnerability score and important protocol affected by vulnerability score. In the embodiment, the purpose of comprehensive security partition and related important factors in actual power monitoring system for evaluating power monitoring system vulnerability risk is achieved.
[0068] As an optional embodiment, the method further comprises: determining the risk degree under any vulnerability risk level according to the sum of scores of multiple important factors affected by vulnerability, wherein the greater the sum of scores of multiple important factors affected by vulnerability, the higher the risk degree under any vulnerability risk level. Alternatively, under any vulnerability risk level, the risk degree is determined according to the sum of scores of multiple important factors affected by vulnerability and K q , i.e. K q = K q1 + K q2 + K q3 + K q4 determines the risk degree under any vulnerability risk level. Suppose that K q1 ,K q2 ,K q3 ,K q4 If the two values are 0, at this time, the power monitoring system vulnerability risk level is medium risk, and further, according to the sum of scores of multiple important factors affected by vulnerability, i.e. K q = K q1 + K q2 + K q3 + K q4 the risk degree under this risk level (i.e. medium risk) can be determined. Specifically, the greater the sum of scores of multiple important factors affected by vulnerability, the higher the risk degree under any vulnerability risk level, i.e. the greater the value of K q under the same risk level, the higher the corresponding risk degree.
[0069] According to another aspect of the embodiment of the present application, a complex network-based power monitoring system vulnerability risk grading device for implementing the above-mentioned complex network-based power monitoring system vulnerability risk grading method is further provided. Figure 3 is a structural block diagram of an optional complex network-based power monitoring system vulnerability risk grading device according to the embodiment of the present application, as shown in Figure 3As shown, the apparatus can comprise: an acquisition module 301 configured to acquire vulnerability information of a power monitoring system and device information of a complex network, wherein the complex network is determined according to a security partition of the power monitoring system; a first determination module 302 configured to determine a score of an important factor affected by the vulnerability according to a plurality of influence factors of the important factor in the complex network and the device information, wherein the important factor comprises an important device, an important service, an important port and an important protocol; and a second determination module 303 configured to determine a vulnerability risk level of the power monitoring system according to the scores of the plurality of important factors affected by the vulnerability.
[0070] It should be noted that the acquisition module 301 in this embodiment can be configured to perform the above step S201, the first determination module 302 in this embodiment can be configured to perform the above step S202, and the second determination module 303 in this embodiment can be configured to perform the above step S203.
[0071] Through the above modules, the security partition of the power monitoring system and the influence of the important device, the important service, the important port and the important protocol are considered in the vulnerability risk assessment, the vulnerability and the existing vulnerability risk of the power monitoring system subjected to malicious attacks are evaluated and graded, the purpose of combining the relevant regulations of the power monitoring system security protection and considering the relevant important factors in the actual power monitoring system is achieved, and the problem of the imperfect vulnerability risk assessment method for the complex network of the power monitoring system in the related art is solved.
[0072] As an optional embodiment, the first determination module comprises a first determination unit configured to determine the score of the important device affected by the vulnerability according to a data confidentiality influence factor of each device affected by the vulnerability, a correlation degree influence factor between devices, a permission influence factor possessed by the device, a running critical service device influence factor, and a total number of important devices in a production control zone security I area, a production control zone security II area and a management information zone.
[0073] As an optional embodiment, the first determining module further comprises: a second determining unit, configured to determine the score of the important business affected by the vulnerability in the production control safety I area according to the three-remote business influence factor of each device affected by the vulnerability in the production control safety I area and the total number of devices running the three-remote business in the production control safety I area; a third determining unit, configured to determine the score of the important business affected by the vulnerability in the production control safety II area according to the phasor measurement business influence factor, the network security monitoring business influence factor of each device affected by the vulnerability in the production control safety II area and the total number of devices running the phasor measurement business and / or the network security monitoring business in the production control safety II area; a fourth determining unit, configured to determine the score of the important business affected by the vulnerability in the management information area according to the mail sending and receiving business influence factor of each device affected by the vulnerability in the management information area and the total number of devices running the mail sending and receiving business in the management information area; and a fifth determining unit, configured to determine the score of the important business affected by the vulnerability according to the score of the important business affected by the vulnerability in the production control safety I area, the score of the important business affected by the vulnerability in the production control safety II area and the score of the important business affected by the vulnerability in the management information area.
[0074] As an optional embodiment, the first determining module further comprises: a sixth determining unit, configured to determine the score of the important port affected by the vulnerability according to the private port abnormal closing influence factor of each device affected by the vulnerability, the number of private port abnormal closing, the total number of private ports, the high-risk port abnormal opening influence factor of each device affected by the vulnerability, the number of high-risk port abnormal opening, the total number of high-risk ports and the total number of devices containing important ports in the production control safety I area, the production control safety II area and the management information area, wherein the important port comprises the private port and the high-risk port.
[0075] As an optional embodiment, the first determining module further comprises: a seventh determining unit, configured to determine the score of the important protocol affected by the vulnerability according to the Modbus TCP protocol influence factor, the Modbus ASCII protocol influence factor, the Modbus RTU protocol influence factor, the SIMATICS 7 protocol influence factor of each device affected by the vulnerability and the total number of devices in the production control safety I area and the production control safety II area.
[0076] As an optional embodiment, the second determining module comprises: a determining unit, configured to determine the vulnerability risk level of the power monitoring system according to the number of non-zero items in the score of the plurality of important factors affected by the vulnerability, wherein the more the number of non-zero items, the higher the vulnerability risk level.
[0077] As an optional embodiment, the determining unit comprises a determining sub-module, configured to determine the risk degree at any vulnerability risk level according to the sum of scores of important factors affected by the vulnerability, wherein the greater the sum of scores of important factors affected by the vulnerability, the higher the risk degree at any vulnerability risk level.
[0078] It should be noted that the above modules have the same examples and application scenarios as the corresponding steps, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules can run in the hardware environment as shown in Figure 1 , which can be implemented by software or hardware, wherein the hardware environment comprises a network environment.
[0079] According to another aspect of the embodiment of the present application, an electronic device for implementing the above-mentioned power monitoring system vulnerability risk grading method based on complex network is also provided, which can be a server, a terminal, or a combination thereof.
[0080] Figure 4 is a structural block diagram of an optional electronic device according to the embodiment of the present application, as shown in Figure 4 , comprising a processor 401, a communication interface 402, a memory 403 and a communication bus 404, wherein the processor 401, the communication interface 402 and the memory 403 complete mutual communication through the communication bus 404, wherein the memory 403 is configured to store a computer program; the processor 401 is configured to execute the computer program stored in the memory 403 to implement the following steps:
[0081] obtaining vulnerability information of the power monitoring system and device information of the complex network, wherein the complex network is determined according to a security partition of the power monitoring system; determining scores of important factors affected by the vulnerability according to a plurality of influence factors of important factors in the complex network and the device information, wherein the important factors comprise important devices, important services, important ports and important protocols; and determining a vulnerability risk level of the power monitoring system according to the scores of the plurality of important factors affected by the vulnerability.
[0082] Optionally, in the embodiment, the communication bus can be a PCI (Peripheral Component Interconnect, Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture, Extended Industry Standard Architecture) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 4 only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0083] The communication interface is used for communication between the aforementioned electronic devices and other devices.
[0084] The memory may include RAM, or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0085] As an example, such as Figure 4 As shown, the memory 403 may include, but is not limited to, the acquisition module 301, the first determination module 302, and the second determination module 303 in the aforementioned complex network-based power monitoring system vulnerability risk assessment device. Furthermore, it may also include, but is not limited to, other module units in the aforementioned complex network-based power monitoring system vulnerability risk assessment device, which will not be elaborated upon in this example.
[0086] The processors mentioned above can be general-purpose processors, including but not limited to: CPU (Central Processing Unit), NP (Network Processor), etc.; they can also be DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0087] In addition, the aforementioned electronic devices also include: a display for showing the vulnerability risk assessment results of a power monitoring system based on complex networks.
[0088] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments, and will not be repeated here.
[0089] Those skilled in the art will understand that Figure 4 The structure shown is for illustrative purposes only. The device implementing the above-mentioned method for classifying the vulnerability risk of power monitoring systems based on complex networks can be a terminal device, such as a smartphone (e.g., an Android phone, an iOS phone), a tablet computer, a PDA, a mobile Internet device (MID), a PAD, or other terminal devices. Figure 4 This does not limit the structure of the aforementioned electronic devices. For example, the terminal device may also include components that are more... Figure 4more or less components than those shown, such as no network interface, display, or the like, or a different configuration of components than those shown. Figure 4
[0090] Those skilled in the art can understand that all or part of the steps of various methods in the above embodiments can be completed by instructing the terminal device related hardware through programs, and the programs can be stored in a computer readable storage medium, which can include a flash disk, a ROM, a RAM, a magnetic disk or an optical disk, and the like.
[0091] According to still another aspect of the embodiments of the present application, a storage medium is also provided. Optionally, in the present embodiment, the above-mentioned storage medium can be used to store program codes for executing the method for grading vulnerability risk of power monitoring system based on complex network.
[0092] Optionally, in the present embodiment, the above-mentioned storage medium can be located on at least one of the network devices in the network shown in the above-mentioned embodiments.
[0093] Optionally, in the present embodiment, the storage medium is configured to store program codes for executing the following steps:
[0094] obtaining vulnerability information of the power monitoring system and device information of the complex network, wherein the complex network is determined according to a security partition of the power monitoring system; determining scores of important factors affected by the vulnerability according to a plurality of influence factors of the important factors in the complex network and the device information, wherein the important factors include important devices, important services, important ports and important protocols; and determining a vulnerability risk level of the power monitoring system according to the scores of the plurality of important factors affected by the vulnerability.
[0095] Optionally, specific examples in the present embodiment can refer to the examples described in the above-mentioned embodiments, and the present embodiment will not be described here.
[0096] Optionally, in the present embodiment, the above-mentioned storage medium can include but is not limited to a U disk, a ROM, a RAM, a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0097] According to still another aspect of the embodiments of the present application, a computer program product or computer program is also provided, which includes computer instructions stored in a computer readable storage medium; a processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to make the computer device execute the steps of the method for grading vulnerability risk of power monitoring system based on complex network in any one of the above-mentioned embodiments.
[0098] The above-mentioned serial numbers of the embodiments of the present application are only for description, and do not represent the advantages or disadvantages of the embodiments.
[0099] The integrated units in the above embodiments, if implemented in the form of software function units and sold or used as independent products, can be stored in the above computer-readable storage medium. Based on such understanding, the technical solutions of the present application or all or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing one or more computer devices (which can be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the power monitoring system vulnerability risk grading method based on a complex network according to the various embodiments of the present application.
[0100] In the above embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0101] In the several embodiments provided by the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the above-mentioned device embodiment is only schematic, for example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed each other can be through some interface, indirect coupling or communication connection between units or modules, which can be electrical or other forms.
[0102] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed on multiple network units. Part or all of the units can be selected to achieve the purpose of the scheme provided in the embodiment according to actual needs.
[0103] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of software function unit.
[0104] The above is only the preferred embodiment of the present application. It should be noted that for those skilled in the art, without departing from the principle of the present application, a number of improvements and refinements can be made, which should also be considered as the protection scope of the present application.
Claims
1. A method for vulnerability risk rating of a power monitoring system based on complex networks, characterized in that, The method comprises: obtaining vulnerability information of the power monitoring system and device information of a complex network, wherein the complex network is determined according to a security partition of the power monitoring system; determining a score of an important factor affected by a vulnerability according to a plurality of influence factors of the important factor in the complex network and the device information, wherein the important factor comprises an important device, an important business, an important port and an important protocol; the complex network comprises a production control zone security I area, a production control zone security II area and a management information area; and the determining the score of the important factor affected by the vulnerability according to the plurality of influence factors of the important factor in the complex network and the device information further comprises: determining a score of an important business of the production control zone security I area affected by a vulnerability according to a three-remote business influence factor of each device affected by the vulnerability in the production control zone security I area and a total number of devices running a three-remote business in the production control zone security I area; the score of the important business of the production control zone security I area affected by the vulnerability is as follows: In the formula, x represents the number of important devices of n telemetering services affected by the vulnerability, n is in the range of 0≤n≤N1, N1 represents the total number of devices running the telemetering service in the safety I area of the production control area, η x ∈[0,10] represents the telemetering service influence factor of the xth device affected by the vulnerability, wherein η x According to the specific device conditions of each subarea of the power monitoring system, the values of the telemetering service influence factors η x of the plurality of devices are equal or unequal. determining a score of an important business of the production control zone security II area affected by a vulnerability according to a phasor measurement unit business influence factor, a network security monitoring business influence factor of each device affected by the vulnerability in the production control zone security II area and a total number of devices running a phasor measurement unit business and / or a network security monitoring business in the production control zone security II area; the score of the important business of the production control zone security II area affected by the vulnerability is as follows: In the formula, y represents the number of important devices of the t synchronous phasor measurement service and / or network security monitoring service affected by the vulnerability, the value range of t is 0≤t≤N2, N2 represents the total number of devices running the synchronous phasor measurement service and / or network security monitoring service in the production control area security II area, respectively represent the influence factor of the synchronous phasor measurement service and the network security monitoring service of the yth device. determining a score of an important business of the management information area affected by a vulnerability according to a mail sending and receiving business influence factor of each device affected by the vulnerability in the management information area and a total number of devices running a mail sending and receiving business in the management information area; the score of the important business of the management information area affected by the vulnerability is as follows: In the formula, z represents the number of important devices of the mail sending and receiving service affected by the vulnerability, r is in the range of 0≤r≤N3, N3 represents the total number of devices running the mail sending and receiving service in the management information area, γ z ∈[0,10] represents the mail sending and receiving service influence factor of the zth device. determining a score of the important business affected by a vulnerability according to the score of the important business of the production control zone security I area affected by the vulnerability, the score of the important business of the production control zone security II area affected by the vulnerability and the score of the important business of the management information area affected by the vulnerability; Score K of important business affected by the vulnerability q2 As shown below: determining a vulnerability risk level of the power monitoring system according to the scores of a plurality of important factors affected by a vulnerability.
2. The method of claim 1, wherein, The complex network comprises a production control zone security I area, a production control zone security II area and a management information area; and the determining the score of the important factor affected by the vulnerability according to the plurality of influence factors of the important factor in the complex network and the device information comprises: determining a score of an important device affected by a vulnerability according to a data confidentiality influence factor of each device affected by the vulnerability, a correlation degree influence factor between devices, a permission influence factor possessed by the device, a critical business device influence factor and a total number of important devices in the production control zone security I area, the production control zone security II area and the management information area.
3. The method of claim 1, wherein, The complex network comprises a production control zone security I area, a production control zone security II area and a management information area; and the determining the score of the important factor affected by the vulnerability according to the plurality of influence factors of the important factor in the complex network and the device information further comprises: The score of the important ports affected by the vulnerability is determined according to the private port abnormal closing influence factor of each device affected by the vulnerability, the number of private port abnormal closing ports, the total number of private ports, the high-risk port abnormal opening influence factor of each device affected by the vulnerability, the number of high-risk port abnormal opening ports, the total number of high-risk ports, and the total number of devices containing important ports in the production control area security I area, the production control area security II area and the management information area.
4. The method of claim 1, wherein, The score of the important factors affected by the vulnerability is determined according to the multiple influence factors of the important factors in the complex network and the device information, and the score of the important factors affected by the vulnerability further comprises: The score of the important protocols affected by the vulnerability is determined according to the Modbus TCP protocol influence factor of each device affected by the vulnerability, the Modbus ASCII protocol influence factor, the Modbus RTU protocol influence factor, the SIMATICS 7 protocol influence factor, and the total number of devices in the production control area security I area and the production control area security II area.
5. The method of claim 1, wherein, The score of the important factors affected by the vulnerability is determined according to the multiple influence factors of the important factors in the complex network and the device information, and the score of the important factors affected by the vulnerability further comprises: The vulnerability risk level of the power monitoring system is determined according to the number of non-zero items in the score of the multiple important factors affected by the vulnerability, wherein the more the number of non-zero items, the higher the vulnerability risk level.
6. The method of claim 5, wherein, The method further comprises: The risk degree under any vulnerability risk level is determined according to the sum of the scores of the multiple important factors affected by the vulnerability, wherein the greater the sum of the scores of the multiple important factors affected by the vulnerability, the higher the risk degree under any vulnerability risk level.
7. A complex network-based power monitoring system vulnerability risk rating apparatus, comprising: The device comprises: An acquisition module is configured to acquire vulnerability information of the power monitoring system and device information of a complex network, wherein the complex network is determined according to a security partition of the power monitoring system; A first determination module is configured to determine a score of important factors affected by a vulnerability according to multiple influence factors of the important factors in the complex network and the device information, wherein the important factors include important devices, important businesses, important ports and important protocols; the complex network comprises a production control area security I area, a production control area security II area and a management information area, and the score of the important factors affected by the vulnerability is further determined according to the multiple influence factors of the important factors in the complex network and the device information. The score of the important businesses of the production control area security I area affected by the vulnerability is determined according to the three-remote business influence factor of each device affected by the vulnerability in the production control area security I area and the total number of devices running three-remote business in the production control area security I area. The score of the important businesses of the production control area security I area affected by the vulnerability is as follows: In the formula, x represents the number of important devices of n telemetering services affected by the vulnerability, n is in the range of 0≤n≤N1, N1 represents the total number of devices running the telemetering service in the safety I area of the production control area, η x ∈[0,10] represents the telemetering service influence factor of the xth device affected by the vulnerability, wherein η x According to the specific device conditions of each subarea of the power monitoring system, the telemetering service influence factors η x of the plurality of devices are equal or not equal in value. According to the influence factor of the phasor measurement service of each device affected by the vulnerability in the production control area safety II area, the network security monitoring service influence factor, and the total number of devices running the phasor measurement service and / or the network security monitoring service of the production control area safety II area, a score of important service affected by the vulnerability of the production control area safety II area is determined. The score of important service affected by the vulnerability of the production control area safety II area is as follows: In the formula, y represents the number of important devices of the t synchronous phasor measurement service and / or network security monitoring service affected by the vulnerability, the value range of t is 0≤t≤N2, N2 represents the total number of devices running the synchronous phasor measurement service and / or network security monitoring service in the production control area security II area, respectively represent the influence factor of the synchronous phasor measurement service and the network security monitoring service of the yth device. According to the influence factor of the mail sending and receiving service of each device affected by the vulnerability in the management information area, and the total number of devices running the mail sending and receiving service of the management information area, a score of important service affected by the vulnerability of the management information area is determined. The score of important service affected by the vulnerability of the management information area is as follows: In the formula, z represents the number of important devices of the mail sending and receiving service affected by the vulnerability, r is in the range of 0≤r≤N3, N3 represents the total number of devices running the mail sending and receiving service in the management information area, γ z ∈[0,10] represents the mail sending and receiving service influence factor of the zth device. According to the score of important service affected by the vulnerability of the production control area safety I area, the score of important service affected by the vulnerability of the production control area safety II area, and the score of important service affected by the vulnerability of the management information area, a score of important service affected by the vulnerability is determined. Score K of important business affected by the vulnerability q2 As shown below: A second determination module is configured to determine the vulnerability risk level of the power monitoring system according to the score of important factors affected by the vulnerability.
8. An electronic device comprising a processor, a communication interface, a memory and a communication bus, wherein, The processor, the communication interface and the memory complete mutual communication through the communication bus, and the method comprises the following steps: The memory is configured to store a computer program. The processor is configured to execute the method steps of any one of claims 1 to 6 by running the computer program stored on the memory.
9. A computer readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to implement the method steps in any one of claims 1 to 6.
Citation Information
Patent Citations
Method and system for evaluating network space security of power monitoring system
CN114745287A