A Substation Monitoring Background Security Defense Method and System
By classifying and encrypting the processes in the substation monitoring background, building a whitelist process list, scanning and comparing abnormal processes regularly, solving the problem of ineffective control of background running programs in the existing technology and improving security defense capabilities.
Patent Information
- Application Number
- CN202211330145.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-10-27
AI Technical Summary
The existing technology cannot effectively control programs that have been run in the substation monitoring background, resulting in safety hazards.
By obtaining the process list of hosts to be defended, it is classified into red list, black list and white list, and it is encrypted, and a list that does not need to be detected by the whitelist process, and scanning and comparing the exception process regularly for defense processing.
It realizes effective security defense against the substation monitoring background, improves the control capabilities of the security baseline, and prevents the operation of malicious programs.
Smart Images

Figure CN115664824B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of substation monitoring background, and particularly to a substation monitoring background security defense method and system. Background Art
[0002] The substation monitoring background has a remote file transfer function, where files are transmitted over the network to another server. Terminal security is a very important aspect.
[0003] The security baseline is the most basic security specification that each controlled terminal must meet. Only terminals that meet the security baseline will be considered qualified terminals within the network. In the substation monitoring background, the system can detect the process management policy, and for unqualified processes, the system should also give prompts for repair.
[0004] The process baseline operation policy configuration can restrict the processes running on the client, which is an important basis for achieving the security baseline of the substation monitoring background. For example, which processes must run (whitelist), which processes are prohibited from running (blacklist), and which processes can only run (whitelist). To prevent malicious users from changing the program name to evade whitelist checks, the detected processes are further checked by the MD5 checksum method to prevent malicious users from changing the program name to evade blacklist checks or bypass whitelist checks. By configuring the process operation policy configuration and performing checks on the premise of meeting the security baseline, the purpose of substation monitoring background security protection is achieved.
[0005] Currently, the power supply industry is gradually increasing its requirements for network security. Only terminals that meet the security baseline in the substation monitoring background will be considered qualified terminals within the network. By controlling the processes, unqualified network behaviors can be monitored. Currently, the substation monitoring background already has strict restrictions on access ports, accessed ports, and passwords, which can effectively block attacks from the external network on the substation monitoring background. However, for the programs already running in the substation monitoring background, security issues cannot be effectively controlled. Summary of the Invention
[0006] This application provides a substation monitoring background security defense method and system, which are used to solve the technical problem that the existing technology cannot effectively control the programs already running in the substation monitoring background.
[0007] In view of this, in the first aspect of this application, a substation monitoring background security defense method is provided, and the method includes:
[0008] Obtain the processes currently running on the host to be defended according to the IP of the host to be defended, and generate a list of currently running processes. Classify the processes in the list of currently running processes into: whitelist processes, blacklist processes, and whitelist processes;
[0009] Obtain the process names of each process in the list of running processes, and encrypt the process names of each process to obtain an encrypted list;
[0010] According to the exclusion keyword list and the exclusion directory list, construct a list of processes that do not need to be detected in the whitelist processes, so as to determine the whitelist processes to be detected;
[0011] Regularly scan the process names of the whitelist processes to be detected and the redlist processes, and at the same time compare and analyze them with the process names in the encrypted list to obtain abnormal processes, and perform defense processing on the abnormal processes.
[0012] Optionally, the defense processing of the abnormal process specifically includes:
[0013] When the running process is the abnormal process, issue an alarm prompt for the abnormal process, or record the process name of the abnormal process in the abnormal process detection list, or issue an alarm prompt for the abnormal process in the whitelist processes to be detected, and record it in the abnormal process detection list and stop the abnormal process at the same time.
[0014] Optionally, the constructing a list of processes that do not need to be detected in the whitelist processes according to the exclusion keyword list and the exclusion directory list, so as to determine the whitelist processes to be detected, specifically includes:
[0015] In the whitelist processes, determine whether the process is in the exclusion keyword list according to the signature information of the process. If so, mark the process as a process that does not need to be detected, and determine whether the process is in the files or sub-folders of the exclusion directory list. If so, mark the process as a process that does not need to be detected, so as to obtain the whitelist processes to be detected.
[0016] Optionally, the encrypting the process names of each process to obtain an encrypted list specifically includes: encrypting the process names of each process through MD5 encryption technology to obtain an encrypted list.
[0017] Optionally, when the running process is a process in the blacklist process, stop the process.
[0018] The second aspect of this application provides a substation monitoring background security defense system, and the system includes:
[0019] A classification unit, configured to obtain the processes running on the host to be defended according to the IP of the host to be defended, and generate a list of running processes, and classify the processes in the list of running processes into: redlist processes, blacklist processes, and whitelist processes;
[0020] An encryption unit, configured to obtain the process names of the processes in the list of running processes, encrypt the process names of the processes, and obtain an encrypted list;
[0021] A filtering unit, configured to construct a list of processes that do not need to be detected among the processes in the whitelist process according to the exclusion keyword list and the exclusion directory list, so as to determine the whitelist process to be detected;
[0022] A first defense unit, configured to periodically scan the process names of the whitelist process to be detected and the redlist process, and at the same time compare and analyze with the process names in the encrypted list to obtain abnormal processes, and perform defense processing on the abnormal processes.
[0023] Optionally, the defense unit specifically includes:
[0024] An analysis subunit, configured to periodically scan the process names of the whitelist process to be detected and the redlist process, and at the same time compare and analyze with the process names in the encrypted list to obtain abnormal processes
[0025] A defense subunit, configured to when the running process is the abnormal process, issue an alarm prompt for the abnormal process, or record the process name of the abnormal process into the abnormal process detection list, or issue an alarm prompt for the abnormal process in the whitelist process to be detected, and record it into the abnormal process detection list and stop the abnormal process at the same time.
[0026] Optionally, the filtering unit specifically is configured to:
[0027] In the whitelist process, determine whether the process is in the exclusion keyword list according to the signature information of the process. If so, mark the process as a process that does not need to be detected, and determine whether the process is in the file or subfolder of the exclusion directory list. If so, mark the process as a process that does not need to be detected, so as to obtain the whitelist process to be detected.
[0028] Optionally, the encryption unit specifically is configured to:
[0029] An acquisition subunit, configured to obtain the process names of the processes in the list of running processes;
[0030] An encryption subunit, configured to encrypt the process names of the processes through MD5 encryption technology to obtain an encrypted list.
[0031] Optionally, it further includes: a second defense unit;
[0032] The second defense unit is configured to stop the process when the running process is a process in the blacklist process.
[0033] As can be seen from the above technical solutions, the present application has the following advantages:
[0034] The present application provides a security defense method for a substation monitoring background, including: obtaining the processes running on the host to be defended according to the IP of the host to be defended, generating a list of running processes, and classifying the processes in the list of running processes into: red list processes, black list processes, and white list processes; obtaining the process names of the processes in the list of running processes, encrypting the process names of the processes to obtain an encrypted list; constructing a list of processes that do not need to be detected in the white list processes according to the exclusion keyword list and the exclusion directory list, so as to determine the white list processes to be detected; regularly scanning the process names of the white list processes to be detected and the red list processes, and at the same time comparing and analyzing with the process names in the encrypted list to obtain abnormal processes, and performing defense processing on the abnormal processes.
[0035] Compared with the prior art, the present application provides a security defense method for a substation monitoring background, effectively monitors the programs already running in the substation monitoring background, realizes a security baseline defense method and system for the substation monitoring background, solves the technical problem that the prior art cannot effectively control the programs already running in the substation monitoring background, and improves the security defense ability of the substation monitoring background. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 is a schematic flow chart of an embodiment of a security defense method for a power station monitoring background provided in an embodiment of the present application;
[0037] Figure 2 is a schematic flow chart of an embodiment of a security defense method for a power station monitoring background provided in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0039] Please refer to Figure 1 , a security defense method for a substation monitoring background provided in an embodiment of the present application, including:
[0040] Step 101, obtaining the processes running on the host to be defended according to the IP of the host to be defended, generating a list of running processes, and classifying the processes in the list of running processes into: red list processes, black list processes, and white list processes;
[0041] It should be noted that by inputting the specified IP of the host to be defended, the processes running on the host are obtained. A list of the processes running in the system with the input IP is automatically generated; at the same time, the processes in the list of running processes are classified into: red-list processes, black-list processes, and white-list processes; among them, the red list is a list of processes that must run, the black list is a list of processes that cannot run, and the white list is a list of processes that can only run.
[0042] Step 102: Obtain the process names of the processes in the list of running processes, and perform encryption processing on the process names of each process to obtain an encrypted list;
[0043] It should be noted that in the process generation list, find the process names, such as qq.exe, weixin.exe, and at the same time obtain the original file names of the generated programs (which can be obtained from the program properties of the process). Perform MD5 encryption on the process names to generate a list of MD5-encrypted process names.
[0044] Step 103: According to the exclusion keyword list and the exclusion directory list, construct a list of processes that do not need to be detected in the white-list processes, so as to determine the white-list processes to be detected;
[0045] It should be noted that in the white-list processes, determine whether the process is in the exclusion keyword list according to the signature information of the process. If so, mark the process as a process that does not need to be detected, and judge whether the process is in the files or sub-folders of the exclusion directory list. If so, mark the process as a process that does not need to be detected, so as to obtain the white-list processes to be detected (except for the processes that do not need to be detected, the remaining processes in the white list are all white-list processes to be detected).
[0046] Step 104: Regularly scan the process names of the white-list processes to be detected and the red-list processes, and at the same time compare and analyze them with the process names in the encrypted list to obtain abnormal processes, and perform defense processing on the abnormal processes.
[0047] It should be noted that to prevent malicious users from changing the program name to avoid blacklist checks, the process list process names (the process names of the white-list processes to be detected and the red-list processes) are regularly scanned, the MD5 checksum of the running process names is checked, and the MD5 checksum of the running process is compared with the list of MD5-encrypted process names generated for the first time. If the MD5 value of the running process name does not match, the process enters the next step of "disallowed operation mode option"
[0048] There are also three ways to enter the "disallowed operation mode option": "Prompt" only prompts that the process is not in the whitelist and does not intercept the process; "Only record" does not prompt that the process is not in the whitelist, but saves it in the detection record and does not intercept the process; "End process" only prompts that the process is in the whitelist, saves it in the detection record, and directly closes the process.
[0049] The above is a substation monitoring background security defense method provided in the embodiments of the present application. The following is a substation monitoring background security defense system provided in the embodiments of the present application.
[0050] Please refer to Figure 2 , a substation monitoring background security defense method provided in the embodiments of the present application, includes:
[0051] The classification unit 201 is used to obtain the processes running on the host to be defended according to the IP of the host to be defended, generate a list of running processes, and classify the processes in the list of running processes into: red list processes, black list processes, and white list processes;
[0052] The encryption unit 202 is used to obtain the process names of the processes in the list of running processes, and perform encryption processing on the process names of the processes to obtain an encrypted list;
[0053] The screening unit 203 is used to construct a list of processes that do not need to be detected in the white list processes according to the exclusion keyword list and the exclusion directory list, so as to determine the white list processes to be detected;
[0054] The first defense unit 204 is used to regularly scan the process names of the white list processes to be detected and the red list processes, and at the same time compare and analyze them with the process names in the encrypted list to obtain abnormal processes, and perform defense processing on the abnormal processes.
[0055] Further, in one embodiment, the substation monitoring background security defense method further includes: a second defense unit;
[0056] The second defense unit is used to stop the process when the running process is a process in the black list process.
[0057] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0058] In the description of this application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0059] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or plural.
[0060] In several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical or other forms.
[0061] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0062] In addition, each functional unit in the various embodiments of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0063] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (English full name: Read-Only Memory, English abbreviation: ROM), random access memories (English full name: Random Access Memory, English abbreviation: RAM), magnetic disks, or optical discs and other various media that can store program codes.
[0064] As described above, the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.
Claims
1. A safety defense method for a substation monitoring background, characterized in that Including: Obtain the processes running on the host to be defended according to the IP of the host to be defended, generate a list of running processes, and classify the processes in the list of running processes into: red list processes, black list processes, and white list processes; Obtain the process names of each process in the list of running processes, and perform encryption processing on the process names of each process to obtain an encrypted list; Construct a list of processes that do not need to be detected in the white list processes according to the exclusion keyword list and the exclusion directory list, so as to determine the white list processes to be detected; Regularly scan the process names of the white list processes to be detected and the red list processes, and at the same time compare and analyze them with the process names in the encrypted list to obtain abnormal processes, and perform defense processing on the abnormal processes.
2. The substation monitoring background security defense method according to claim 1, characterized in that, The defense processing of the abnormal processes specifically includes: When the running process is the abnormal process, issue an alarm prompt for the abnormal process, or record the process name of the abnormal process in the abnormal process detection list, or issue an alarm prompt for the abnormal process in the white list processes to be detected, and record it in the abnormal process detection list and stop the abnormal process at the same time.
3. The substation monitoring background security defense method according to claim 1, wherein The constructing a list of processes that do not need to be detected in the white list processes according to the exclusion keyword list and the exclusion directory list, so as to determine the white list processes to be detected specifically includes: In the white list processes, determine whether the process is in the exclusion keyword list according to the signature information of the process. If so, mark the process as a process that does not need to be detected, and judge whether the process is in the file or subfolder of the exclusion directory list. If so, mark the process as a process that does not need to be detected, so as to obtain the white list processes to be detected.
4. The substation monitoring background security defense method according to claim 1, characterized in that The performing encryption processing on the process names of each process to obtain an encrypted list specifically includes: performing encryption processing on the process names of each process through MD5 encryption technology to obtain an encrypted list.
5. The substation monitoring background security defense method according to claim 1, wherein When the running process is a process in the black list, stop the process.
6. A substation monitoring background security defense system, characterized in that, Including: A classification unit for obtaining the processes running on the host to be defended according to the IP of the host to be defended, generating a list of running processes, and classifying the processes in the list of running processes into: red list processes, black list processes, and white list processes; An encryption unit for obtaining the process names of each process in the list of running processes, and performing encryption processing on the process names of each process to obtain an encrypted list; A screening unit for constructing a list of processes that do not need to be detected in the white list processes according to the exclusion keyword list and the exclusion directory list, so as to determine the white list processes to be detected; A first defense unit for regularly scanning the process names of the white list processes to be detected and the red list processes, and at the same time comparing and analyzing them with the process names in the encrypted list to obtain abnormal processes, and performing defense processing on the abnormal processes.
7. The substation monitoring background security defense system according to claim 6, characterized in that, The defense unit specifically includes: An analysis subunit for regularly scanning the process names of the white list processes to be detected and the red list processes, and at the same time comparing and analyzing them with the process names in the encrypted list to obtain abnormal processes; A defense subunit, which is used to issue an alarm prompt for an abnormal process when the running process is the abnormal process, or record the process name of the abnormal process in the abnormal process detection list, or issue an alarm prompt for the abnormal process in the whitelist process to be detected and record it in the abnormal process detection list and stop the abnormal process at the same time.
8. The substation monitoring background security defense system according to claim 6, characterized in that, The screening unit is specifically used for: In the whitelist process, determine whether the process is in the exclusion keyword list according to the signature information of the process. If so, mark the process as a process that does not need to be detected, and determine whether the process is in the file or subfolder in the exclusion directory list. If so, mark the process as a process that does not need to be detected, so as to obtain the whitelist process to be detected.
9. The substation monitoring background security defense system according to claim 6, characterized in that, The encryption unit is specifically used for: An acquisition subunit, which is used to acquire the process names of the processes in the running process list; An encryption subunit, which is used to encrypt the process names of the processes through the MD5 encryption technology to obtain an encryption list.
10. The substation monitoring background security defense system according to claim 6, characterized in that, It further includes: A second defense unit; The second defense unit is used to stop the process when the running process is a process in the blacklist process.
Citation Information
Patent Citations
Method and device for detecting suspicious progresses
CN102855274A
Method for detecting malicious software of advanced metering infrastructure based on cloud security
CN106295323A