Power system asset vulnerability early warning method and system based on quantification model

By using quantitative models to assess the importance and vulnerability impact of power system assets, this approach solves the problem of existing technologies being unable to accurately identify asset risks, and achieves highly reliable and accurate vulnerability early warning.

CN115664978BActive Publication Date: 2025-12-05STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211297965.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2025-12-05
Estimated Expiration
2042-10-21

AI Technical Summary

Technical Problem

Existing methods for power system asset management and vulnerability detection are unable to accurately identify and assess asset security risks, leading to an increasing scope and severity of cyberattacks. Current methods are also unable to determine the risk level of asset vulnerabilities based on the actual situation of enterprises.

Method used

A quantitative model-based approach is adopted to acquire power system asset information data, identify and classify the data, establish an asset importance and vulnerability impact measurement model, calculate the asset vulnerability early warning level, and carry out early warning and rectification.

Benefits of technology

It enables accurate risk assessment of power system assets, clearly describes the number of assets and equipment that need to be protected, improves the reliability and accuracy of vulnerability early warning, and ensures the objectivity and scientific nature of the early warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664978B_ABST
    Figure CN115664978B_ABST
Patent Text Reader

Abstract

The application discloses a power system asset vulnerability early warning method based on a quantitative model, which comprises the following steps: acquiring and identifying asset information data of a target power system; establishing an asset importance measurement model to measure the importance of the asset information of the target power system; establishing an asset vulnerability influence measurement model to measure the influence of the vulnerability corresponding to the asset of the target power system; and calculating the asset vulnerability early warning level of the target power system according to the measurement results and performing asset vulnerability early warning. The application further discloses a system for implementing the power system asset vulnerability early warning method based on the quantitative model. Through the innovative quantitative model establishment and calculation, the application realizes the early warning of the power system asset vulnerability, clearly describes the number of assets that need to be protected and the asset equipment that need to be protected as the key, clearly explains the security risk of each device and the exposure range in the Internet, and has high reliability, good accuracy, good integrity and objectivity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer security technology, specifically relating to a method and system for early warning of power system asset vulnerabilities based on a quantitative model. Background Technology

[0002] With economic and technological development and the improvement of people's living standards, electricity has become an indispensable secondary energy source in people's production and daily life, bringing endless convenience. Therefore, ensuring a stable and reliable supply of electricity has become one of the most important tasks of the power system.

[0003] Currently, power systems manage and detect vulnerabilities in their assets (including hardware, operating systems, business systems, and data) at a granular level, focusing on hardware, host operating systems, and business application systems. This approach is sufficient and reliable for general operation and maintenance needs. However, with the rapid development of the internet, cybersecurity incidents exploiting computer vulnerabilities are frequent, and these attacks are becoming increasingly dangerous, widespread, and damaging to the system itself. Therefore, this current method of asset management and vulnerability detection is no longer suitable for today's more demanding network environment.

[0004] Furthermore, current vulnerability detection and early warning methods cannot clearly describe the number of assets requiring protection or the key assets and devices that need protection. They also cannot explain the security risks of each device and its exposure scope on the internet when conducting cybersecurity information analysis. In addition, existing methods rank vulnerabilities by risk level based solely on the vulnerability risks verified by vulnerability verification tools. However, higher-risk vulnerabilities may not be the most dangerous vulnerabilities within an enterprise, thus failing to determine the risk level of asset vulnerabilities based on the enterprise's actual situation. Summary of the Invention

[0005] One of the objectives of this invention is to provide a power system asset vulnerability early warning method based on a quantitative model that is highly reliable, accurate, complete, and objectively scientific.

[0006] The second objective of this invention is to provide a system for implementing the aforementioned power system asset vulnerability early warning method based on a quantitative model.

[0007] The power system asset vulnerability early warning method based on a quantitative model provided by this invention includes the following steps:

[0008] S1. Obtain asset information data of the target power system;

[0009] S2. Perform data identification on the asset information data obtained in step S1;

[0010] S3. Based on the identification results obtained in step S2, establish an asset importance measurement model and measure the importance of asset information of the target power system;

[0011] S4. Based on the measurement results obtained in step S3, establish an asset vulnerability impact measurement model and measure the impact of vulnerabilities corresponding to the assets of the target power system.

[0012] S5. Based on the measurement results obtained in steps S3 and S4, calculate the asset vulnerability warning level of the target power system and issue an asset vulnerability warning.

[0013] The power system asset vulnerability early warning method based on the quantitative model further includes the following steps:

[0014] S6. Based on the asset vulnerability warning issued in step S5, the corresponding personnel shall carry out warning processing and vulnerability rectification according to the corresponding warning level;

[0015] S7. Based on the processing and rectification results of step S6, conduct a vulnerability review.

[0016] Step S1, which involves obtaining asset information data of the target power system, specifically includes the following steps:

[0017] Collect and clean up asset data maintained by various units, departments and systems within the target power system, and use a unified entry point for unified and centralized management of asset information;

[0018] Assets are distinguished by network IP addresses, with each IP address representing an independent asset; these assets include physical servers, network devices, and virtual assets.

[0019] Asset data is collected from resource management platforms, network management systems, security management systems, and cloud platforms, and then supplemented manually.

[0020] Step S2, which involves data identification of the asset information data obtained in step S1, specifically includes the following steps:

[0021] Identify the obtained asset set A: the element a in asset set A is identified as a=<s,v,r,τ>;

[0022] s represents the network attribute of the asset, and s = <sa, sz>. sa represents the network region to which the asset belongs. The network region includes the enterprise industrial control zone, the enterprise intranet, the enterprise extranet, and external assets of the enterprise exposed to the Internet. sz represents the network domain of the asset. The network domain includes the terminal domain, the secondary system domain, and the tertiary system domain.

[0023] v represents the important business attributes carried by the asset, and v = <vt,va,vu>. vt represents the business application type of the asset, which includes business applications for the entire enterprise, business applications for a single department or secondary organization, and business applications for a number of specific users. va represents the business information security level protection classification of the asset. vu represents the number of users of the business carried by the asset, and vu = <vum,vua>. vum is the maximum number of users, and vua is the average number of active users.

[0024] Let r be the set of asset components, and r = < c1, c2, ..., c n >, c j Let c be the j-th component of the asset. j =<cp j ,cr j ,cs j >, cp j For the product type of the constituent components, cr j For the product version of the constituent components, cs j The operating status of the components includes not running, running but not opening remote ports, and running and opening remote ports;

[0025] τ represents the asset type; asset types include hardware servers, cloud servers, dedicated equipment, and terminals; hardware servers include web servers, database servers, cloud platform base servers, and other servers; cloud servers include Alibaba Cloud, Tencent Cloud, and Huawei Cloud; dedicated equipment includes network equipment, security equipment, storage devices, minicomputers, and other equipment; terminals include face terminals, laptops, handheld mobile terminals, and printers.

[0026] Step S3, which involves establishing an asset importance measurement model based on the identification results obtained in step S2, specifically includes the following steps:

[0027] The following formula is used as the asset importance measurement function:

[0028] F1=λ1f1+λ2f2

[0029] In the formula, λ1 is the weight value of asset network attributes; λ2 is the weight value of asset business attributes; λ1 + λ2 = 1; f1 is the asset network attribute evaluation function, and g1 is a piecewise function with different weights based on the region where the asset is located, and The asset's location is categorized into the enterprise industrial control zone, enterprise intranet, enterprise extranet, and external internet enterprise. Based on the importance of these zones, values ​​SA1 through SA4 are assigned sequentially, with SA1 > SA2 > SA3 > SA4, and {SA1,SA2,SA3,SA4} ∈ (0,1]. g2 is a piecewise function that assigns different weights based on the network domain of the asset. Each weight value is set according to the asset importance and security protection level of the network domain, and {SZ1,SZ2,...,SZ} n}∈(0,1]; f2 is the business importance attribute assessment function of the asset, and f2=g3·g4·g5; g3 is a piecewise function that sets different weights according to the business type. Different weights are assigned based on whether the business is geared towards the entire enterprise, a single department or secondary organization, or a number of specific users. Nvt represents the number of enterprise departments and secondary institutions, {VT1,VT2,VT3}∈(0,1]; g4 is a piecewise function that sets different weights according to the information security level protection classification of the business. Different weight values ​​are set according to the classification of the graded protection system, namely Level 1, Level 2, Level 3, and Level 4, where VS1 < VS2 < VS3 < VS4 and {VS1,VS2,VS3,VS4}∈(0,1]; g5 is a function that sets different weights based on the number of business users. vu m For the maximum number of users, β represents the average number of maximum users for the corresponding business type. i This represents the average number of active users for the corresponding type.

[0030] Step S4, which involves establishing an asset vulnerability impact measurement model, specifically includes the following steps:

[0031] The following formula is used as a model for measuring the impact of asset vulnerabilities:

[0032]

[0033] In the formula, N represents the total number of components involved in the asset set At for enterprise subtype t; P1(At|cp k Let At be the asset set At for firm subtype t calculated using the maximum likelihood estimation method, and let there exist types cp. k The probability distribution function of the components; P2(At|<cp) k ,cr k >) For the asset set At calculated using the maximum likelihood estimation method, there exists a type cp for the subtype t of the firm. kComposition and version is cr k The probability distribution function.

[0034] Step S5, which involves calculating the asset vulnerability warning level of the target power system based on the measurement results obtained in steps S3 and S4, and then issuing an asset vulnerability warning, specifically includes the following steps:

[0035] The following formula is used as the asset vulnerability warning level function:

[0036] F = M·F1 + u·F2

[0037] In the formula, F1 is the calculation result of the asset importance measurement function; F2 is the calculation result of the asset vulnerability impact measurement model; M is the piecewise function for graded early warning; u is an intermediate variable and u={ul,up,ur}, where ul is the hazard level, up is the product type affected by the vulnerability, and ur is the affected product version.

[0038] The warning level value F of the asset vulnerability is calculated, and the asset vulnerability is warned based on the warning level value.

[0039] This invention also discloses a system for implementing the power system asset vulnerability early warning method based on the quantitative model, comprising a data acquisition module, a data identification module, an asset importance measurement module, an asset vulnerability impact measurement module, and an asset vulnerability early warning module; the data acquisition module, data identification module, asset importance measurement module, asset vulnerability impact measurement module, and asset vulnerability early warning module are connected in series; the data acquisition module is used to acquire asset information data of the target power system and upload the data to the data identification module; the data identification module is used to perform data identification on the received data and upload the data to the asset importance measurement module; the asset importance measurement module is used to establish an asset importance measurement model based on the received data, measure the importance of asset information of the target power system, and upload the measurement data to the asset vulnerability impact measurement module; the asset vulnerability impact measurement module is used to establish an asset vulnerability impact measurement model based on the received data, measure the impact of vulnerabilities corresponding to assets of the target power system, and upload the measurement data to the asset vulnerability early warning module; the asset vulnerability early warning module is used to calculate the asset vulnerability early warning level of the target power system based on the received data and perform asset vulnerability early warning.

[0040] The system also includes an early warning processing and rectification module and a vulnerability review module; the early warning processing and rectification module and the vulnerability review module are connected in series, with the input of the early warning processing and rectification module connected to the output of the asset vulnerability early warning module; the early warning processing and rectification module is used to process and rectify vulnerabilities according to the received asset vulnerability early warning data, and upload the processing and rectification data to the vulnerability review module; the vulnerability review module is used to review vulnerabilities according to the received processing and rectification results.

[0041] The present invention provides a power system asset vulnerability early warning method and system based on a quantitative model. Through the innovative establishment and calculation of a quantitative model, it realizes the early warning of power system asset vulnerabilities, clearly describes the number of assets that need to be protected and the key asset equipment that needs to be protected, and clearly explains the security risks of each equipment and its exposure range on the Internet. Moreover, the present invention has high reliability, good accuracy, good integrity and is objective and scientific. Attached Figure Description

[0042] Figure 1 This is a schematic diagram of the method flow of the present invention.

[0043] Figure 2 This is a schematic diagram of the functional modules of the system of the present invention. Detailed Implementation

[0044] like Figure 1 The diagram shown illustrates the method flow of this invention: This invention provides a power system asset vulnerability early warning method based on a quantitative model, comprising the following steps:

[0045] S1. Obtain asset information data for the target power system; specifically including the following steps:

[0046] Collect and clean up asset data maintained by various units, departments and systems within the target power system, and use a unified entry point for unified and centralized management of asset information;

[0047] Assets are distinguished by network IP addresses, with each IP address representing an independent asset; these assets include physical servers, network devices, and virtual assets.

[0048] Asset data is collected from resource management platforms, network management systems, security management systems, and cloud platforms, and then supplemented manually.

[0049] S2. Perform data identification on the asset information data obtained in step S1; specifically including the following steps:

[0050] Identify the obtained asset set A: the element a in asset set A is identified as a=<s,v,r,τ>;

[0051] s represents the network attribute of the asset, and s = <sa, sz>. sa represents the network region to which the asset belongs. The network region includes the enterprise industrial control zone, the enterprise intranet, the enterprise extranet, and external assets of the enterprise exposed to the Internet. sz represents the network domain of the asset. The network domain includes terminal domain, secondary system domain, and tertiary system domain, etc.

[0052] v represents the important business attributes carried by the asset, and v = <vt,va,vu>. vt represents the business application type of the asset, which includes business applications for the entire enterprise, business applications for a single department or secondary organization, and business applications for a number of specific users. va represents the business information security level protection classification of the asset. vu represents the number of users of the business carried by the asset, and vu = <vum,vua>. vum is the maximum number of users, and vua is the average number of active users.

[0053] Let r be the set of asset components, and r = < c1, c2, ..., c n >, c j Let c be the j-th component of an asset (e.g., databases, middleware, web services, hosting services, etc. are all considered components of an asset) and c j =<cp j ,cr j ,cs j >, cp j For the product type of the constituent components, cr j For the product version of the constituent components, cs j The operating status of the components includes not running, running but not opening remote ports, and running and opening remote ports;

[0054] τ represents the asset type; asset types include hardware servers, cloud servers, dedicated equipment, and terminals; hardware servers include web servers, database servers, cloud platform base servers, and other servers; cloud servers include Alibaba Cloud, Tencent Cloud, and Huawei Cloud; dedicated equipment includes network equipment, security equipment, storage devices, minicomputers, and other equipment; terminals include mobile terminals, laptops, handheld mobile terminals, and printers.

[0055] S3. Based on the identification results obtained in step S2, establish an asset importance measurement model and measure the importance of asset information of the target power system; specifically, this includes the following steps:

[0056] The following formula is used as the asset importance measurement function:

[0057] F1=λ1f1+λ2f2

[0058] In the formula, λ1 is the weight value of asset network attributes; λ2 is the weight value of asset business attributes; λ1 + λ2 = 1; f1 is the asset network attribute evaluation function, and g1 is a piecewise function with different weights based on the region where the asset is located, and The asset's location is categorized into the enterprise industrial control zone, enterprise intranet, enterprise extranet, and external internet enterprise. Based on the importance of these zones, values ​​SA1 through SA4 are assigned sequentially, with SA1 > SA2 > SA3 > SA4, and {SA1,SA2,SA3,SA4} ∈ (0,1]. g2 is a piecewise function that assigns different weights based on the network domain of the asset. Each weight value is set according to the asset importance and security protection level of the network domain, and {SZ1,SZ2,...,SZ} n}∈(0,1]; f2 is the business importance attribute assessment function of the asset, and f2=g3·g4·g5; g3 is a piecewise function that sets different weights according to the business type. Different weights are assigned based on whether the business is geared towards the entire enterprise, a single department or secondary organization, or a number of specific users. Nvt represents the number of enterprise departments and secondary institutions, {VT1,VT2,VT3}∈(0,1]; g4 is a piecewise function that sets different weights according to the information security level protection classification of the business. Different weight values ​​are set according to the classification of the graded protection system, namely Level 1, Level 2, Level 3, and Level 4, where VS1 < VS2 < VS3 < VS4 and {VS1,VS2,VS3,VS4}∈(0,1]; g5 is a function that sets different weights based on the number of business users. vu m For the maximum number of users, β represents the average number of maximum users for the corresponding business type. i This represents the average number of active users for the corresponding type.

[0059] S4. Based on the measurement results obtained in step S3, establish an asset vulnerability impact measurement model and measure the impact of vulnerabilities corresponding to the assets of the target power system; specifically, this includes the following steps:

[0060] The following formula is used as a model for measuring the impact of asset vulnerabilities:

[0061]

[0062] In the formula, N represents the total number of components involved in the asset set At for enterprise subtype t; P1(At|cp kLet At be the asset set At for firm subtype t calculated using the maximum likelihood estimation method, and let there exist types cp. k The probability distribution function of the components; P2(At|<cp) k ,cr k >) For the asset set At calculated using the maximum likelihood estimation method, there exists a type cp for the subtype t of the firm. k Composition and version is cr k The probability distribution function;

[0063] S5. Based on the measurement results obtained in steps S3 and S4, calculate the asset vulnerability warning level of the target power system and issue an asset vulnerability warning; specifically, this includes the following steps:

[0064] The following formula is used as the asset vulnerability warning level function:

[0065] F = M·F1 + u·F2

[0066] In the formula, F1 is the calculation result of the asset importance measurement function; F2 is the calculation result of the asset vulnerability impact measurement model; M is the piecewise function for graded early warning; u is an intermediate variable and u={ul,up,ur}, where ul is the hazard level, up is the product type affected by the vulnerability, and ur is the affected product version.

[0067] Calculate the warning level value F of the asset vulnerability, and issue a warning for the asset vulnerability based on the warning level value;

[0068] S6. Based on the asset vulnerability warning issued in step S5, the corresponding personnel shall handle the warning and rectify the vulnerability according to the corresponding warning level. Specifically, the asset manager shall use a vulnerability scanning tool, combined with the vulnerability warning information, configure scanning rules, and scan the at-risk assets. The scanning priority shall be based on the asset's risk warning level. The warning response mechanism shall handle the warning according to the enterprise's pre-set plan for each level of warning handling procedures. Based on the vulnerability scanning results and vulnerability characteristics, the asset manager shall formulate a vulnerability rectification strategy, carry out vulnerability rectification, and report the rectification completion status to the enterprise's security management personnel after the rectification is completed.

[0069] S7. Based on the processing and rectification results of step S6, conduct a vulnerability review; the enterprise security management personnel will review the assets that have been rectified as reported by the asset manager, and if the rectification is confirmed, the vulnerability warning for that asset will be lifted.

[0070] like Figure 2The diagram shows the system functional modules of the present invention. The present invention also discloses a system for implementing the power system asset vulnerability early warning method based on a quantitative model, comprising a data acquisition module, a data identification module, an asset importance measurement module, an asset vulnerability impact measurement module, an asset vulnerability early warning module, an early warning processing and rectification module, and a vulnerability review module; the data acquisition module, data identification module, asset importance measurement module, asset vulnerability impact measurement module, asset vulnerability early warning module, early warning processing and rectification module, and vulnerability review module are connected in series; the data acquisition module is used to acquire asset information data of the target power system and upload the data to the data identification module; the data identification module is used to perform data identification on the received data and upload the data to the asset importance measurement module; the asset importance measurement module is used to determine the asset importance of the received data based on the data... The system establishes an asset importance measurement model to measure the importance of asset information in the target power system and uploads the measurement data to the asset vulnerability impact measurement module. The asset vulnerability impact measurement module, based on the received data, establishes an asset vulnerability impact measurement model and measures the impact of vulnerabilities corresponding to the assets of the target power system, uploading the measurement data to the asset vulnerability early warning module. The asset vulnerability early warning module, based on the received data, calculates the asset vulnerability early warning level of the target power system and issues asset vulnerability warnings. The early warning processing and rectification module, based on the received asset vulnerability early warning data, assigns corresponding personnel to perform early warning processing and vulnerability rectification at the appropriate warning level, and uploads the processing and rectification data to the vulnerability review module. The vulnerability review module, based on the received processing and rectification results, conducts vulnerability reviews.

Claims

1. A power system asset vulnerability early warning method based on a quantitative model, comprising the following steps: S1. Obtaining asset information data of a target power system; S2. Performing data recognition on the asset information data obtained in step S1; In particular embodiments, the method comprises: r is a set of asset components, and r = <c1, c2,..., c n > , c j j is the jth component of the asset and c j = <cp j , cr j , cs j > , cp j is the product type of the component, cr j is the product version of the component, cs j is the operational status of the component, the operational status including not running, running but not having remote ports open, and running and having remote ports open; S3. Establishing an asset importance measurement model according to the recognition result obtained in step S2, and measuring the importance of asset information of the target power system; S4. Establishing an asset vulnerability influence measurement model according to the measurement result obtained in step S3, and measuring the influence of the vulnerability corresponding to the asset of the target power system; The establishment of the asset vulnerability influence measurement model specifically comprises the following steps: The following formula is used as the asset vulnerability influence measurement model: where N is the total number of constituent components involved in the asset set At for the enterprise sub-type t; P1(At|cp k ) is the probability distribution function for the asset set At for the enterprise sub-type t, given that there is a constituent component of type cp k ; P2(At|<cp k ,cr k >) is the probability distribution function for the asset set At for the enterprise sub-type t, given that there is a constituent component of type cp k and version cr k ; S5. Calculating the asset vulnerability early warning level of the target power system according to the measurement results obtained in steps S3 and S4, and performing asset vulnerability early warning.

2. The method of claim 1, wherein the method further comprises: Further comprising the following steps: S6. According to the asset vulnerability early warning issued in step S5, the corresponding personnel are warned and the vulnerability is rectified according to the corresponding early warning level; S7. According to the processing and rectification result of step S6, the vulnerability is reviewed.

3. The method of claim 1 or 2, wherein The obtaining of the asset information data of the target power system in step S1 specifically comprises the following steps: Collect and clean the asset data maintained by each unit, each department and each system in the target power system, and use a unified portal for unified centralized management of asset information; Differentiate assets by network IP address, and each IP address represents an independent asset; The assets include physical servers, network devices and virtual assets; The collection of asset data is performed from resource management platforms, network management systems, security management systems and cloud platforms, and then supplemented by manual supplementation.

4. The method of claim 3, wherein the method further comprises: The data recognition of the asset information data obtained in step S1 in step S2 specifically comprises the following steps: The obtained asset set A is recognized: the element a in the asset set A is recognized as a = <s, v, r, τ> ; s is the network attribute of the asset, and s = <sa, sz>, sa represents the network large area to which the asset belongs, and the network large area includes enterprise industrial control area, enterprise intranet, enterprise extranet and enterprise external assets exposed to the Internet; sz represents the network domain to which the asset belongs, and the network domain includes terminal domain, secondary system domain and tertiary system domain; v is the business importance attribute carried by the asset, and v = <vt, vs, vu>, vt represents the business application type of the asset, and the business application type includes business for the whole enterprise, business for a single department or secondary institution and business for a number of specific users; vs represents the business information security level protection classification of the asset; vu represents the number of users carrying the business of the asset, and vu = <vum, vua>, vum is the maximum number of users, and vua is the average number of active users; τ is an asset type; the asset type includes a hardware server, a cloud server, a special-purpose device, and a terminal; the hardware server includes a Web server, a database server, a cloud platform base server, and other servers; the cloud server includes Ali Cloud, Tencent Cloud, and Huawei Cloud; the special-purpose device includes a network device, a security device, a storage device, a minicomputer, and other devices; the terminal includes a face terminal, a notebook, a handheld mobile terminal, and a printer.

5. The method of claim 4, wherein The step S3 establishes an asset importance measurement model according to the identification result obtained in the step S2, and specifically includes the following steps. The following formula is used as an asset importance measurement function: F1 = λ1f1 + λ2f2 wherein λ1 is a weight value of the asset network attribute; λ2 is a weight value of the asset business attribute; λ1 + λ2 = 1; f1 is an asset network attribute evaluation function, and g1 is a segmented function with different weights set according to the area where the asset is located, and The area where the asset is located is an enterprise industrial control area, an enterprise intranet, an enterprise extranet, and an Internet enterprise outside. According to the importance of the enterprise industrial control area, the enterprise intranet, the enterprise extranet, and the Internet enterprise outside, the values of SA1 to SA4 are set in sequence, SA1 > SA2 > SA3 > SA4, and {SA1, SA2, SA3, SA4} ∈ (0, 1]; g2 is a segmented function with different weights set according to the network domain where the asset is located, and The weight values are set according to the asset importance and the security protection level of the network domain, and {SZ1, SZ2,..., SZ n} ∈ (0, 1]; f2 is an asset-carrying business important attribute evaluation function, and f2 = g3 · g4 · g5; g3 is a segmented function with different weights set according to the business type, The different weights are set according to the business facing the entire enterprise, the business facing a single department or a secondary institution, and the business facing a number of specific users, and Nvt is the number of enterprise departments and secondary institutions, {VT1, VT2, VT3} ∈ (0, 1]; g4 is a segmented function with different weights set according to the asset business information security level protection classification, and The different weight values are set according to the first level, the second level, the third level, and the fourth level of the level protection classification, VS1 < VS2 < VS3 < VS4, and {VS1, VS2, VS3, VS4} ∈ (0, 1]; g5 is a function with different weights set according to the number of business users, and vum is the maximum number of users, is the average value of the maximum number of users of the corresponding type of business, β i is the average value of the average number of active users of the corresponding type.

6. The method of claim 5, wherein the method further comprises: The step S5 calculates an asset vulnerability early warning level of the target power system according to the measurement results obtained in the steps S3 and S4, and performs asset vulnerability early warning, and specifically includes the following steps. The following formula is used as an asset vulnerability early warning level function: F = M·F1 + u·F2 In the formula, F1 is a calculation result of the asset importance measurement function; F2 is a calculation result of the asset vulnerability influence measurement model; M is a segmented function for grading early warning; u is an intermediate variable and u = {ul, up, ur}, ul is a hazard level, up is a product type affected by the vulnerability, and ur is an affected product version; The asset vulnerability early warning level value F is calculated, and asset vulnerability early warning is performed according to the early warning level value.

7. A system for implementing the method for early warning of power system asset vulnerability based on a quantitative model according to any one of claims 1 to 6, characterized in that The system includes a data acquisition module, a data recognition module, an asset importance measurement module, an asset vulnerability influence measurement module, and an asset vulnerability early warning module; the data acquisition module, the data recognition module, the asset importance measurement module, the asset vulnerability influence measurement module, and the asset vulnerability early warning module are connected in series; the data acquisition module is configured to acquire asset information data of a target power system and upload the data to the data recognition module; The data recognition module is configured to perform data recognition on the received data and upload the data to the asset importance measurement module; The asset importance measurement module is configured to establish an asset importance measurement model according to the received data, measure the importance of asset information of the target power system, and upload the measurement data to the asset vulnerability influence measurement module; The asset vulnerability influence measurement module is configured to establish an asset vulnerability influence measurement model according to the received data, measure the influence of a vulnerability corresponding to the asset of the target power system, and upload the measurement data to the asset vulnerability early warning module; The asset vulnerability early warning module is configured to calculate an asset vulnerability early warning level of the target power system according to the received data and perform asset vulnerability early warning.

8. The system of claim 7, wherein The system further includes an early warning processing and rectification module and a vulnerability review module; the early warning processing and rectification module and the vulnerability review module are connected in series, and an input end of the early warning processing and rectification module is connected to an output end of the asset vulnerability early warning module; the early warning processing and rectification module is configured to perform early warning processing and vulnerability rectification on corresponding personnel according to the received asset vulnerability early warning data corresponding to the corresponding early warning level, and upload the processing and rectification data to the vulnerability review module; The vulnerability review module is configured to perform vulnerability review according to the received processing and rectification results.

Citation Information

Patent Citations

  • Risk assessment method and assessment system for power business system

    CN110033202A