An Automatic Configuration Method and System for a Scheduling Data Network Security Protection Device

By using transparent proxy and template library to identify communication protocols in the substation scheduling data network and automatically configure security protection devices, the security management problem of scheduling data network is solved and the operation and maintenance management efficiency is improved.

CN115866042BActive Publication Date: 2025-07-22STATE GRID JIANGSU ELECTRIC POWER CO LTD MAINTENANCE BRANCH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211504918.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-29
Publication Date
2025-07-22
Estimated Expiration
2042-11-29

AI Technical Summary

Technical Problem

The security issues of the substation scheduling data network are difficult to manage in a unified manner, and the configuration personnel requirements are high, which affects the efficiency of operation and maintenance management.

Method used

Through the scheduling data network security protection device, accesses the network in a transparent proxy, obtains application data packets, and uses a dedicated template library to identify and match protocols, automatically releases compliance and establishes communication channels.

Benefits of technology

Reduced on-site configuration work, improved the efficiency of substation operation and maintenance management, and ensured network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115866042B_ABST
    Figure CN115866042B_ABST
Patent Text Reader

Abstract

The present invention discloses an automatic configuration method and system for a dispatching data network security protection device. Specifically, the dispatching data network security protection device is connected to the network in a transparent proxy mode; the device receives TCP connections and proxies services to obtain application data packets; the application data packets are matched with templates in a template library; a channel is established for the TCP connections that match successfully, and an alarm prompt is given for the connections that do not match. The method of the present invention reduces the on-site configuration work and improves the efficiency of substation operation and maintenance management on the premise of ensuring network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an automatic configuration method and system for a dispatching data network security protection device, belonging to the technical field of power grid dispatching automation. Background Art

[0002] With the increasing number of services in intelligent substations, the security importance of the substation dispatching data network has been increasing day by day, and the security problems of the substation dispatching data network have gradually emerged. As the boundary of the substation's external export, the security of the dispatching data network directly affects the data acquisition and control of the entire station. If the dispatching data network is invaded, the impact is significant.

[0003] The dispatching data network at the substation exit often includes various protocols, such as IEC104 protocol, IEC103 protocol, IEC61850 protocol, PMU protocol, network security monitoring device communication protocol, etc. These specifications each carry corresponding dispatching services. Since these services are managed by different departments of the dispatching, it is often difficult for anyone to uniformly identify these protocols. If it is necessary to configure the security protection device deployed in the dispatching data network, the requirements for the configuration personnel are too high. Summary of the Invention

[0004] The purpose of this application is to provide an automatic configuration method and system for a dispatching data network security protection device. By proxying the application layer of the protocol and using a dedicated template library for identification, compliant protocols are automatically released, improving the efficiency of substation operation and maintenance management.

[0005] To achieve the above object, this application adopts the following technical solutions:

[0006] The present invention provides an automatic configuration method for a dispatching data network security protection device, including:

[0007] Connect the dispatching data network security protection device to the communication network;

[0008] Receive connections through the dispatching data network security protection device proxy TCP service to obtain application data packets;

[0009] Match the obtained application data packets with the communication protocol templates in the pre-configured template library to determine the communication protocol to which the packets belong;

[0010] Establish a communication channel between the devices on both sides of the dispatching data network security protection device for the successfully matched application data packets.

[0011] Further, the connecting the dispatching data network security protection device to the communication network includes:

[0012] The dispatching data network security protection device is connected to the communication network in a serial manner and proxies the TCP service.

[0013] Furthermore, a template library is pre-configured, including:

[0014] Extract the features of common dispatching data network application layer communication protocols to form communication protocol templates.

[0015] Furthermore, match the obtained application data packets with the communication protocol templates in the pre-configured template library to determine the communication protocol to which the packets belong, including:

[0016] Extract the communication protocol features in the application data packets;

[0017] Perform a bitwise AND operation with the features in the communication protocol templates in the template library to determine whether the communication protocol features of the obtained application data packets match the features in the communication protocol templates, and determine the communication protocol to which the packets belong.

[0018] Furthermore, establishing communication channels between the devices on both sides of the dispatching data network security protection device for the successfully matched application data packets includes:

[0019] Establish end-to-end communication channels within the dispatching data network security protection device according to the source IP, destination IP, and destination port of the TCP connection where the successfully matched application data packets are located.

[0020] Furthermore, after the communication channels are established, the dispatching data network security protection device no longer proxies the service of the TCP connection where the successfully matched application data packets are located.

[0021] Furthermore, after the TCP connection where the successfully matched application data packets are located is interrupted, the established communication channels are automatically closed.

[0022] Furthermore, if the application data packets do not match the communication protocol templates in the template library, an alarm prompt is given.

[0023] Furthermore, the alarm prompt is given by means of syslog or interface display.

[0024] A dispatching data network security protection device automatic configuration system for implementing the foregoing dispatching data network security protection device automatic configuration method includes:

[0025] A dispatching data network security protection device, which is connected to the communication network in a serial manner and proxies the TCP service;

[0026] A template library, which includes the features of various communication protocols of the dispatching data network to form communication protocol templates;

[0027] The configuration of the dispatching data network security protection device is as follows:

[0028] An acquisition module, configured to receive a TCP connection and acquire application data packets;

[0029] A matching module, configured to match the acquired application data packets with communication protocol templates in a template library to determine the communication protocol to which the packets belong;

[0030] A connection module, configured to establish a communication channel between devices on both sides of the dispatching data network security protection device for the successfully matched application data packets.

[0031] The beneficial effects of the present invention are as follows:

[0032] By applying layer proxy to the protocol and using a dedicated template library for identification, the present invention automatically releases compliant protocols, reduces on-site configuration work, and improves the efficiency of substation operation and maintenance management. Description of the Drawings

[0033] Figure 1 It is a flowchart of an automatic configuration method for a dispatching data network security protection device provided by an embodiment of the present invention. Detailed Embodiments

[0034] The technical solution of the present invention will be further described in detail below in conjunction with the drawings and specific embodiments, so that those skilled in the art can better understand the present invention and implement it, but the embodiments given are not intended to limit the present invention.

[0035] Embodiment 1

[0036] This embodiment provides an automatic configuration method for a dispatching data network security protection device, as Figure 1 shown, including the following steps:

[0037] S100, connect the dispatching data network security protection device to the communication network.

[0038] In this embodiment, the dispatching data network security protection device is connected to the communication network in a transparent proxy manner.

[0039] "Transparent" means that after the device is connected in series, the communication devices on both sides still communicate in the original manner, and the devices on both sides cannot perceive the existence of the intermediate device.

[0040] "Proxy" means that the device proxies the TCP service.

[0041] In this embodiment, the dispatching data network security protection device is serially connected to the communication network through two network interfaces, one in and one out.

[0042] As an implementation manner, in this embodiment, the network port 1 of the dispatching data network security protection device is connected to the corresponding network port of the telecontrol device, and the network port 2 is connected to the dispatching data network switch. After the device is accessed, the telecontrol device still communicates with the dispatching master station, and neither the telecontrol device nor the dispatching master station can perceive the existence of the dispatching data network security protection device. The device internally monitors the ports 0-65535 of the TCP protocol to monitor the communication between the telecontrol device and the dispatching master station.

[0043] S200, receive the connection through the TCP service proxy of the dispatching data network security protection device, and obtain the application data packet.

[0044] When TCP communication occurs between the communication devices on both sides of the device, the device will proxy the server side of TCP and receive the connection, so as to obtain the application data packet.

[0045] In this embodiment, when the dispatching master station initiates an IEC104 connection with the destination port 2404, since the device proxies this port, the device will establish a TCP connection with the master station and obtain the IEC104 packet initiated by the master station.

[0046] S300, match the obtained application data packet with the communication protocol template in the template library to determine the communication protocol to which the packet belongs.

[0047] It should be noted that the template library is a template made according to the characteristics of each communication protocol of the dispatching data network. This template can be directly used to match with the packet to obtain the communication protocol to which the packet belongs.

[0048] The template library is constructed according to the characteristics of the common dispatching data network application layer communication protocols.

[0049] In this embodiment, the communication protocol characteristics in the application data packet are extracted, and a bitwise AND operation is performed with the characteristics in the template library to determine whether the obtained application data packet matches the template library, and then determine the communication protocol to which the packet belongs.

[0050] In this embodiment, after the device obtains the IEC104 packet, it does not know that the packet belongs to the IEC104 protocol. It is necessary to compare the packet with the characteristics corresponding to various protocols in the template library. Finally, it successfully matches the IEC104 protocol, so as to determine that the packet is a legal IEC104 protocol.

[0051] S400, establish a communication channel for the successfully matched application data packet.

[0052] In this embodiment, according to the source IP, destination IP, and destination port of the TCP connection where the successfully matched application data packet is located, an end-to-end communication channel is established in the device;

[0053] After the communication channel is established, the device no longer proxies the services of this communication pair, and the communication devices on both sides can communicate directly with each other.

[0054] In this embodiment, when it is detected that the application layer message is a legal IEC104 protocol, the device will automatically generate a whitelist configuration, which takes effect in real time, forwards the message to the following telecontrol device, and maintains communication between the master station and the telecontrol device.

[0055] It should be noted that after the whitelist configuration is generated, if subsequent new connections can match this whitelist, the message can be directly forwarded without re-matching.

[0056] It should be noted that when the TCP connection is interrupted, the communication channel will be automatically closed and wait for the next connection.

[0057] In this embodiment, an alarm prompt is given for connections that do not match successfully.

[0058] If the application layer message does not match the communication protocol template in the template library, the message may be a malformed message or an attack message, and the device can give an alarm prompt through methods such as syslog or interface display.

[0059] This embodiment can reduce the on-site configuration work and improve the efficiency of substation operation and maintenance management.

[0060] Embodiment 2

[0061] This embodiment provides an automatic configuration system for a dispatching data network security protection device, which is used to implement the automatic configuration method of the dispatching data network security protection device in the foregoing Embodiment 1. The system includes:

[0062] A dispatching data network security protection device, which is connected to the communication network in a serial manner and proxies the TCP service;

[0063] A template library, which includes the characteristics of various communication protocols of the dispatching data network and constitutes a communication protocol template;

[0064] The dispatching data network security protection device is configured as follows:

[0065] An acquisition module, which is used to receive a TCP connection and acquire application data messages;

[0066] A matching module, which is used to match the acquired application data messages with the communication protocol templates in the template library to determine the communication protocol to which the messages belong;

[0067] A connection module, which is used to establish a communication channel between the devices on both sides of the dispatching data network security protection device for the application data messages that match successfully.

[0068] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0069] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks

[0070] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks

[0071] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or a plurality of flows and / or blocks

[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.

Claims

1. A method for automatically configuring a scheduling data network security protection device, characterized in that Including: The dispatching data network security protection device is accessed to the communication network in the way of transparent proxy. The term "transparent" means that after the device is accessed in a serial manner, the communication devices on both sides still communicate in the original way and cannot perceive the existence of the middle dispatching data network security protection device. The term "proxy" means that the dispatching data network security protection device proxies the TCP service. Specifically, the dispatching data network security protection device is serially accessed to the communication network through two network interfaces, one in and one out. Among them, network interface 1 of the dispatching data network security protection device is connected to the external network interface of the telecontrol device, and network interface 2 is connected to the dispatching data network switch. After access, the telecontrol device still communicates with the dispatching master station, and neither the telecontrol device nor the dispatching master station can perceive the existence of the dispatching data network security protection device. The dispatching data network security protection device will monitor ports 0-65535 of the TCP protocol internally to monitor the communication between the telecontrol device and the dispatching master station. When TCP communication occurs between the communication devices on both sides of the dispatching data network security protection device, the dispatching data network security protection device acts as the proxy of the TCP server side, receives the connection, and obtains the application data packet. Match the obtained application data packet with the communication protocol templates in the pre-configured template library to determine the communication protocol to which the packet belongs, including: extracting the communication protocol features in the application data packet; performing a bitwise AND operation with the features in the communication protocol templates in the template library to determine whether the communication protocol features of the obtained application data packet match the features in the communication protocol templates, and determining the communication protocol to which the packet belongs. The pre-configured template library includes: extracting the features of common dispatching data network application layer communication protocols to form communication protocol templates. Establish a communication channel between the devices on both sides of the dispatching data network security protection device for the application data packet with successful matching, including: automatically generating a whitelist configuration according to the source IP, destination IP, and destination port of the TCP connection where the application data packet with successful matching is located, establishing an end-to-end communication channel within the dispatching data network security protection device, and maintaining communication between the dispatching master station and the telecontrol device. After the communication channel is established, the dispatching data network security protection device no longer proxies the service of the TCP connection where the application data packet with successful matching is located.

2. The automatic configuration method of a scheduling data network security protection device according to claim 1, characterized in that, After the TCP connection where the application data packet with successful matching is located is interrupted, the established communication channel is automatically closed.

3. The automatic configuration method of a scheduling data network security protection device according to claim 1, characterized in that, If the application data packet does not match the communication protocol template in the template library, an alarm prompt is given.

4. The automatic configuration method of a scheduling data network security protection device according to claim 3, characterized in that, The alarm prompt is given through syslog or interface display.

5. A dispatching data network security protection device automatic configuration system for implementing the automatic configuration method of the dispatching data network security protection device according to any one of claims 1 to 4, characterized in that, Including: The dispatching data network security protection device, which is accessed to the communication network in a serial manner and proxies the TCP service; The template library, which includes the features of various communication protocols of the dispatching data network to form communication protocol templates; The configuration of the dispatching data network security protection device: An acquisition module, which is used to receive the TCP connection and obtain the application data packet; A matching module, which is used to match the obtained application data packet with the communication protocol templates in the template library to determine the communication protocol to which the packet belongs; A connection module for establishing a communication channel between the devices on both sides of the scheduling data network security protection device for the application data packets with successful matching.

Citation Information

Patent Citations

  • Mobile substation monitoring alarm system and method

    CN111509863A