Method, apparatus and system for locating abnormal scheduling layer messages based on automatic analysis
By automatically classifying and modeling the dispatch layer network messages, generating a benchmark library, judging exceptions in real time and generating alarm signals, the network monitoring problem of substation scheduling layer is solved, and rapid response and abnormal positioning of network security is achieved.
Patent Information
- Application Number
- CN202211504469.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-29
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-11-29
AI Technical Summary
The existing technology cannot effectively monitor the substation scheduling layer network from a business perspective, resulting in difficulty in discovering and handling network security issues in a timely manner.
By automatically classifying, modeling and feature extraction of network messages on the scheduling layer, generating a benchmark library, judging exceptions in real time and generating alarm signals, it is sent to the monitoring terminal for display and alarm using a private protocol with authentication and encryption.
It realizes intuitive monitoring and abnormal positioning of the network operation of the substation scheduling layer, improving the efficiency of network security monitoring and rapid exception handling.
Smart Images

Figure CN115801560B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of message processing technology, and particularly relates to a method, device and system for abnormal positioning of dispatching layer messages based on automatic analysis. Background Art
[0002] The communication network of a substation belongs to a local area network, and the only external communication outlet is the dispatching layer network. Various telemetry and telecontrol data in the station will be sent to the dispatching through the dispatching layer network, and the control commands issued by the dispatching are also sent to the station through the dispatching layer network. As the gateway for external communication of the substation, the security of the dispatching layer network is particularly important. Once the dispatching layer network is invaded or threatened maliciously, it will have a serious impact on the operation of the substation.
[0003] Currently, the dispatching layer network is controlled by the dispatching. The dispatching can only obtain some alarms such as illegal connections of the dispatching layer network through the alarms of the longitudinal encryption device, and cannot monitor the dispatching layer network from a business perspective. Summary of the Invention
[0004] In view of the above problems, the present invention proposes a method, device and system for abnormal positioning of dispatching layer messages based on automatic analysis. By analyzing and judging service data, the operation status of the substation dispatching layer network is intuitively displayed, which is convenient for operation and maintenance personnel to monitor the network security and locate abnormalities of the dispatching layer.
[0005] In order to achieve the above technical objectives and effects, the present invention is realized through the following technical solutions:
[0006] In the first aspect, the present invention provides a method for abnormal positioning of dispatching layer messages based on automatic analysis, including:
[0007] Automatically classify the captured message data stream according to the characteristics of the dispatching layer network messages to obtain multiple classified data;
[0008] Model, extract features and analyze each classified data respectively to generate a reference library used as a basis for abnormal judgment, and the reference library includes data and behaviors;
[0009] Based on the reference library, judge the real-time message status, record and locate the abnormal link when an abnormality occurs. The abnormal link includes the time when the abnormality occurs, the statistical characteristics of the link and the abnormal content, and at the same time generate an alarm signal;
[0010] Send the alarm signal to the monitoring terminal in real time through a private protocol with authentication and encryption, so that the monitoring terminal can perform unified display and alarm.
[0011] Optionally, the message data stream is a master-slave station communication protocol, including IEC104 protocol messages, IEC103 protocol messages, and IEC61850 protocol messages.
[0012] Optionally, each classified data corresponds to a different application layer protocol.
[0013] Optionally, the same classified data has the same protocol, destination IP address, source IP address, destination port, and source port.
[0014] Optionally, separately modeling each classified data means: separately extracting data and behaviors for each classified data.
[0015] Optionally, the feature extraction refers to extracting protocol features for different application layer protocols according to the classification results, extracting analysis point numbers for IEC104 protocol messages, extracting group number entry numbers for IEC103 protocol messages, and extracting FCDA for IEC61850 protocol messages.
[0016] Optionally, the content of the alarm signal includes: the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content.
[0017] Optionally, the capture of the message data stream is implemented by packet capturing through the mirror port of the scheduling layer switch, or by a dedicated device with message capturing and analysis capabilities connected in series in the channel.
[0018] In a second aspect, the present invention provides a scheduling layer message anomaly location device based on automatic analysis, including:
[0019] A data classification module, configured to automatically classify the captured message data stream according to the characteristics of the scheduling layer network message, and obtain multiple classified data;
[0020] A reference library generation module, configured to separately model, extract features, and analyze each classified data, and generate a reference library used as a basis for anomaly judgment, where the reference library includes data and behaviors;
[0021] An anomaly analysis module, configured to judge the real-time message status based on the reference library, record and locate the anomaly link when an anomaly occurs, where the anomaly link includes the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content, and generate an alarm signal at the same time;
[0022] An alarm module, configured to send the alarm signal to the monitoring terminal in real time through a private protocol with authentication and encryption, so that the monitoring terminal performs unified display and alarm.
[0023] In a third aspect, the present invention provides a scheduling layer message anomaly location system based on automatic analysis, including a storage medium and a processor;
[0024] The storage medium is used to store instructions;
[0025] The processor is configured to operate according to the instructions to execute the steps of the method according to any one of the first aspect.
[0026] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0027] The present invention classifies and models various application layer protocols at the level of scheduling network data flow, generates a benchmark library, and compares real-time messages with the benchmark library to find abnormal information, which can intuitively display the operation of the substation scheduling layer network and facilitate the monitoring by operation and maintenance personnel; and when the scheduling layer network is abnormal, the abnormal link can be quickly located, facilitating the operation and maintenance personnel to quickly handle problems. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to make the content of the present invention more clearly understood, the following further describes the present invention in detail according to specific embodiments in conjunction with the accompanying drawings, wherein:
[0029] Figure 1 It is a schematic flow chart of a method for locating abnormal messages in the scheduling layer according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] In order to make the objectives, technical solutions and advantages of the present invention clearer, the following further describes the present invention in detail with reference to the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the protection scope of the present invention.
[0031] The following describes in detail the application principle of the present invention with reference to the accompanying drawings.
[0032] Embodiment 1
[0033] An embodiment of the present invention provides a method for locating abnormal messages in the scheduling layer based on automatic analysis, including the following steps:
[0034] (1) Automatically classify the captured message data stream according to the characteristics of the scheduling layer network messages to obtain multiple classified data;
[0035] (2) Model, extract features and analyze each classified data respectively to generate a benchmark library used as a basis for abnormal judgment, where the benchmark library includes data and behaviors;
[0036] (3) Based on the benchmark library, judge the status of real-time messages, record and locate the abnormal link when an abnormality occurs. The abnormal link includes the time when the abnormality occurs, the statistical characteristics of the link, and the abnormal content, and at the same time generate an alarm signal;
[0037] (4) Send the alarm signal to the monitoring terminal in real time through a private protocol with authentication and encryption, so that the monitoring terminal can perform unified display and alarm.
[0038] In a specific implementation manner of the embodiment of the present invention, the message data stream is the master-slave station communication protocol, including IEC104 protocol messages, IEC103 protocol messages, and IEC61850 protocol messages. Each classification data corresponds to a different application layer protocol. The same classification data has the same protocol, destination IP address, source IP address, destination port, and source port.
[0039] In a specific implementation manner of the embodiment of the present invention, modeling the classification data respectively means: extracting data and behaviors for each classification data respectively. Taking IEC104 as an example, modeling means extracting the values of tele-signals and tele-measurements and the behavior habits of remote control as the model of this data stream.
[0040] In a specific implementation manner of the embodiment of the present invention, the feature extraction refers to extracting protocol features for different application layer protocols according to the classification results. For IEC104 protocol messages, extract analysis point numbers; for IEC103 protocol messages, extract group number entry numbers; for IEC61850 protocol messages, extract FCDA.
[0041] In a specific implementation manner of the embodiment of the present invention, the content of the alarm signal includes: the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content.
[0042] In a specific implementation manner of the embodiment of the present invention, the capture of the message data stream is realized by capturing packets through the mirror port of the scheduling layer switch, or by a dedicated device with message capture and analysis capabilities connected in series in the channel.
[0043] In a specific implementation manner of the embodiment of the present invention, the values in the reference library will be refreshed according to the real-time analysis of the data stream. The anomalies that occur include: the jump of tele-measurement is greater than the preset threshold, the jump of tele-signal without remote control operation, remote control operation during non-working hours, TCP connection interruption, etc.
[0044] The following will explain in detail the scheduling layer message anomaly location method in the embodiment of the present invention in combination with a specific implementation manner.
[0045] Step 1: Automatically classify and model the captured message data stream according to the characteristics of the dispatching layer network messages. The characteristics of the dispatching data network messages refer to the characteristics obtained through protocol analysis for the communication protocols adopted by the dispatching data network. The captured data stream includes the master-slave communication protocols commonly used in substations (such as IEC 104 protocol messages, IEC 103 protocol messages, IEC 61850 protocol messages), and the statistical characteristics of the message data stream are that it has the same protocol, destination IP address, source IP address, destination port, and source port. The feature extraction of the message data stream is achieved through packet capture at the mirror port of the dispatching layer switch or through a dedicated device with message capture and analysis capabilities connected in series in the channel. Since the data transmitted at the dispatching layer, or the data carried by the protocol, is mainly teleinformation, telemetry, and telecontrol data, the modeling of the data stream refers to extracting the values of teleinformation and telemetry and the behavior habits of telecontrol from the data stream.
[0046] Step 2: Automatically analyze and generate a reference library through feature extraction as the basis for anomaly judgment. The reference library includes data and behaviors. Feature extraction is achieved through the analysis of specific protocols. For IEC 104 protocol messages, the main analysis point is the point number (corresponding to the information body address in the IEC 104 protocol). For IEC 103 protocol messages, the main analysis is the group number and item number (corresponding to group and item in the IEC 103 protocol). For IEC 61850 protocol messages, the main analysis is FCDA (functional constrained data attribute), and a reference library is established based on the values corresponding to these features (such as 0 or 1 for teleinformation, and values such as 245.1 for telemetry). The reference library for teleinformation records the status of teleinformation, and the status usually includes open, closed, and invalid. The reference library for telemetry records the value of telemetry, usually a floating-point number. The reference library for telecontrol records the status of telecontrol, usually control open or control close. In addition, the reference library should also record the timestamp corresponding to the message to determine whether it is a telecontrol during non-working hours.
[0047] Step 3: Monitor and statistically analyze each frame of the message in real time, determine the data status, record and locate the abnormal link when an abnormality occurs. The abnormal link includes the time of abnormality occurrence, the statistical characteristics of the link, and the content of the abnormality. Meanwhile, an alarm signal is generated. Since the line load may change, the values in the reference library will also change accordingly. The values in the reference library will be refreshed according to the real-time analysis of the data stream. The abnormalities that occur include: the jump of the telemetry is greater than the preset threshold, and the jump of the telemetry may indicate a short circuit in the transmission line; the jump of the tele-signal without remote control operation usually occurs along with the occurrence of remote control; the remote control operation during non-working hours is usually planned; the TCP connection is interrupted. If the data is not refreshed for a long time, it may indicate a communication failure. When it is determined that an abnormality occurs, the abnormal information is immediately sent to the monitoring terminal. The abnormal information includes the time of abnormality occurrence, the statistical characteristics of the link, and the content of the abnormality.
[0048] Step 4: Send the alarm in real time to the monitoring terminal through a private protocol with authentication and encryption, and perform unified display and alarm on the monitoring terminal. The monitoring terminal here can be either the local monitoring environment or the platform environment of the master station. Data transmission through a private protocol with authentication and encryption can prevent eavesdropping in communication and ensure the confidentiality, integrity, and non-repudiation of data transmission.
[0049] Embodiment 2
[0050] Based on the same inventive concept as Embodiment 1, an abnormal link positioning device for dispatching layer messages based on automatic analysis is provided in an embodiment of the present invention, including:
[0051] A data classification module, configured to automatically classify the captured message data stream according to the characteristics of the dispatching layer network message, and obtain multiple classified data;
[0052] A reference library generation module, configured to respectively model, extract features, and analyze each classified data, and generate a reference library used as a basis for abnormality judgment, where the reference library includes data and behaviors;
[0053] An abnormality analysis module, configured to judge the real-time message status based on the reference library, record and locate the abnormal link when an abnormality occurs. The abnormal link includes the time of abnormality occurrence, the statistical characteristics of the link, and the content of the abnormality. Meanwhile, an alarm signal is generated;
[0054] An alarm module, configured to send the alarm signal to the monitoring terminal in real time through a private protocol with authentication and encryption, so that the monitoring terminal performs unified display and alarm.
[0055] The remaining parts are the same as those in Embodiment 1.
[0056] Embodiment 3
[0057] In an embodiment of the present invention, a dispatching layer message anomaly location system based on automatic analysis is provided, including a storage medium and a processor;
[0058] The storage medium is used to store instructions;
[0059] The processor is configured to operate according to the instructions to execute the steps of the method according to any one of Embodiment 1.
[0060] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0061] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0062] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0064] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the purpose of the present invention and the scope protected by the claims. All of these fall within the protection scope of the present invention.
[0065] The above has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and all of these changes and improvements fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for abnormal positioning of scheduling layer messages based on automatic analysis, characterized in that, Including: Automatically classify the captured packet data stream according to the characteristics of the dispatching layer network packets to obtain multiple classified data; Perform modeling, feature extraction, and analysis on each classified data respectively to generate a reference library used as a basis for anomaly judgment, where the reference library includes data and behaviors; Based on the reference library, judge the real-time packet status, record and locate the anomaly link when an anomaly occurs. The anomaly link includes the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content, and at the same time generate an alarm signal; Through a private protocol with authentication and encryption, send the alarm signal to the monitoring terminal in real time, so that the monitoring terminal can perform unified display and alarm; Each classified data corresponds to a different application layer protocol; The same classified data has the same protocol, destination IP address, source IP address, destination port, and source port; Performing modeling on each classified data respectively means: extracting data and behaviors for each classified data respectively; The feature extraction refers to extracting protocol features according to the classification results for different application layer protocols. For IEC104 protocol packets, extract the analysis point number, for IEC103 protocol packets, extract the group number and entry number, and for IEC61850 protocol packets, extract FCDA; The content of the alarm signal includes: the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content.
2. The method for abnormal positioning of scheduling layer messages based on automatic analysis according to claim 1, wherein: The packet data stream is the master-slave station communication protocol, including IEC104 protocol packets, IEC103 protocol packets, and IEC61850 protocol packets.
3. A method for abnormal positioning of scheduling layer messages based on automatic analysis according to claim 1, characterized in that: The capture of the packet data stream is realized by packet capturing through the mirror port of the dispatching layer switch, or by a dedicated device with packet capturing and analysis capabilities connected in series in the channel.
4. A dispatching layer message anomaly location device based on automatic analysis, characterized in that Including: A data classification module, which is used to automatically classify the captured packet data stream according to the characteristics of the dispatching layer network packets to obtain multiple classified data; A reference library generation module, which is used to perform modeling, feature extraction, and analysis on each classified data respectively to generate a reference library used as a basis for anomaly judgment, where the reference library includes data and behaviors; An anomaly analysis module, which is used to judge the real-time packet status based on the reference library, record and locate the anomaly link when an anomaly occurs. The anomaly link includes the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content, and at the same time generate an alarm signal; An alarm module, which is used to send the alarm signal to the monitoring terminal in real time through a private protocol with authentication and encryption, so that the monitoring terminal can perform unified display and alarm; Each classified data corresponds to a different application layer protocol; The same classified data has the same protocol, destination IP address, source IP address, destination port, and source port; Performing modeling on each classified data respectively means: extracting data and behaviors for each classified data respectively; The feature extraction refers to extracting protocol features according to the classification results for different application layer protocols. For IEC104 protocol packets, extract the analysis point number, for IEC103 protocol packets, extract the group number and entry number, and for IEC61850 protocol packets, extract FCDA; The content of the alarm signal includes: the time when the anomaly occurs, the statistical characteristics of the link, and the anomaly content.
5. A dispatching layer message anomaly location system based on automatic analysis, characterized in that, Comprising a storage medium and a processor; The storage medium is used for storing instructions; The processor is used for operating according to the instructions to execute the steps of the method according to any one of claims 1-3.
Citation Information
Patent Citations
Information security monitoring method and system
CN108063753A