Integrated detection device and method for power monitoring local area network

By designing an integrated detection device for the power monitoring LAN, the problem that existing tools cannot effectively analyze the network data of the power monitoring LAN is solved, rapid fault diagnosis of the power monitoring LAN and monitoring of illegal IP devices are achieved, and the security and reliability of network communications are improved.

CN116055367BActive Publication Date: 2025-09-16SHIZUISHAN POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211584564.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-09-16
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

Existing network communication fault diagnosis and analysis tools cannot effectively analyze the network data of the power monitoring local area network, and cannot distinguish the legitimacy of the network transmission data of the power secondary equipment, resulting in the inability to effectively diagnose the cause of the network communication fault.

Method used

An integrated detection device for the power monitoring local area network was designed, including a data processing module, a capacitive touch screen, a network interface, a 4G/5G base station wireless clock module, a dedicated interface expansion module, an electronic hard disk, etc. By acquiring network data and performing IP address legitimacy judgment, power protocol analysis, traffic statistics, and storm source monitoring, it generates fault detection reports and prediction trend charts to provide to operation and maintenance personnel for troubleshooting.

Benefits of technology

It realizes the rapid diagnosis of network communication failures in the power monitoring LAN and the real-time monitoring of illegal IP devices, can timely eliminate potential network storm failures, and improves the security and reliability of network communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055367B_ABST
    Figure CN116055367B_ABST
Patent Text Reader

Abstract

An integrated detection device for a power monitoring local area network includes a data processing module, a capacitive touch screen, a network interface, a 4G / 5G base station wireless clock module, a dedicated interface expansion module, an electronic hard disk, and a power supply module. When the data processing module determines that the IP address in the network sorting data is in a preset legal table, it analyzes and checks the protocol information of the message in the network sorting data according to the pre-stored power protocol standard parameter table; analyzes whether the protocol type is the power communication protocol specified by the system; if it is a specified protocol type, outputs a preset error message when it is determined that it does not meet the standard specification; the error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and the network data flow is statistically analyzed based on the network sorting data to predict the network storm source, so that the various causes of secondary equipment network communication failures can be comprehensively analyzed and diagnosed. The present application also provides an integrated detection method for a power monitoring local area network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power network monitoring, and in particular to an integrated detection device and method for a power monitoring local area network. Background Art

[0002] The network communication of the telecontrol secondary equipment of the power system and the network communication of the intelligent equipment in the station often experience communication interruptions or occasional network failures during operation. In serious cases, it will affect the normal operation of the secondary equipment network system. In order to prevent network risks and ensure the safe and reliable operation of the secondary equipment network communication, it is necessary to quickly diagnose and troubleshoot network communication failures and conduct real-time monitoring of illegal network IP intrusion devices.

[0003] Existing network communication fault diagnosis and analysis tools have single functions and are not specifically designed for power monitoring local area networks. For example, the commonly used Wireshark network monitoring software is only used to monitor communication data of general network protocols and analyze common network faults. It cannot distinguish whether the data transmitted by the power secondary equipment network is valid, cannot determine the legitimacy of network data, and does not involve power communication protocol data level detection and analysis (including: IEC101, 103, 104, IEC61850, etc.), which leads to the inability to effectively analyze and diagnose the causes of secondary equipment network communication faults. Summary of the Invention

[0004] In view of this, the present invention discloses an electric power monitoring local area network integrated detection device applicable to an electric power monitoring local area network.

[0005] It is also necessary to provide a power monitoring local area network detection method applicable to the power monitoring local area network.

[0006] An integrated detection device for a power monitoring local area network includes a data processing module, a capacitive touch screen, a network interface, a 4G / 5G base station wireless clock module, a dedicated interface expansion module, an electronic hard disk, and a power supply module. The data processing module is electrically connected to the capacitive touch screen, the network interface, the 4G / 5G base station wireless clock module, the dedicated interface expansion module, the electronic hard disk, and the power supply module.

[0007] The dedicated interface expansion module is used to provide an expansion interface for external devices. The 4G / 5G base station wireless clock module is used to obtain the clock information of the base station and provide the clock information to the data processing module.

[0008] The data processing module obtains network data from the network port of the switch in the power monitoring local area network through the network interface, and adds clock information to the obtained network data to obtain network collation data, and determines whether the IP address in the network collation data is in the preset legal table. If it is determined that the IP address in the network collation data is not in the preset legal table, an alarm message is generated to remind the operation and maintenance personnel to promptly eliminate the illegal IP access device;

[0009] When it is determined that the IP address in the network sorting data is in the preset legal table, the protocol information of the message in the network sorting data is analyzed according to the pre-stored power protocol standard parameter table to analyze whether the protocol type is the specified power communication protocol. If it is not the specified protocol type, a preset error message is output. If it is the specified protocol type, it is determined whether the protocol data in the network sorting data complies with the standard specifications. If it does not comply with the standard specifications, a preset error message is output. The error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report for the corresponding layer that does not comply with the standard is generated and displayed.

[0010] The data processing module also performs traffic statistics on the network sorting data and generates corresponding traffic statistics values, and compares the traffic statistics values ​​with the preset network storm benchmark parameter values. When the traffic statistics values ​​are compared to be not less than the network storm benchmark parameter values, a network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time. According to the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve, network storm source prediction trend chart data is generated to provide to operation and maintenance personnel to eliminate potential network storm faults in a timely manner; a peak experience table is generated according to each storm source traffic value, and the network storm source monitoring and analysis mathematical model is automatically corrected to avoid false alarms of network storm source faults.

[0011] An integrated detection method for a power monitoring local area network comprises the following steps:

[0012] Obtain the clock information of the mobile service provider's base station;

[0013] Acquire network data from a network port of a switch in a power monitoring local area network through a network interface, and add clock information to the acquired network data to obtain network collated data;

[0014] Determine whether the IP address in the network data is in the preset legal table. If it is determined that the IP address in the network data is not in the preset legal table, an alarm message is generated to remind the operation and maintenance personnel to promptly eliminate the illegal IP access device;

[0015] When it is determined that the IP address in the network sorting data is in the preset legal table, the protocol information of the message in the network sorting data is analyzed according to the pre-stored power protocol standard parameter table; the protocol type is analyzed to see whether it is the prescribed power communication protocol; if it is not the prescribed protocol type, a preset error message is output; if it is the prescribed protocol type, whether the protocol data of the network sorting data complies with the standard specification is determined; if it does not comply with the standard specification, a preset error message is output; the error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol type is located, and a fault detection report of the corresponding layer that does not comply with the standard is generated and displayed;

[0016] Traffic statistics are performed on the network sorting data to generate corresponding traffic statistics values, and the traffic statistics values ​​are compared with the preset network storm baseline parameter values. When the traffic statistics values ​​are compared to be not less than the network storm baseline parameter values, the preset network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time. According to the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve, network storm source prediction trend chart data is generated to provide operation and maintenance personnel with timely elimination of potential network storm faults; a peak experience table is generated according to the value of each storm source traffic, and the network storm source monitoring and analysis mathematical model is automatically corrected to avoid false alarms of network storm source faults.

[0017] In the above-mentioned integrated detection device and method for the electric power monitoring local area network, the clock information of the base station of the mobile service provider is obtained; the network data is obtained from the switch network port in the electric power monitoring local area network through the network interface, and the clock information is added to the obtained network data to obtain the network sorting data; when it is determined that the IP address in the network sorting data is in the preset legal table, the protocol information of the message in the network sorting data is analyzed according to the pre-stored electric power protocol standard parameter table; the protocol type is analyzed to see whether it is the prescribed electric power communication protocol, and if it is not the prescribed protocol type, the preset error message is output; if it is the prescribed protocol type, the protocol data in the network sorting data is determined to comply with the standard specifications, and if it does not comply with the standard specifications, the preset error message is output; the error message is output according to the protocol information The corresponding layer in the network model where the information is located is classified and counted by levels, and a non-compliant fault detection report of the corresponding level is generated and displayed; the network sorting data is subjected to traffic statistics and corresponding traffic statistics values ​​are generated, and the traffic statistics values ​​are compared with the preset network storm baseline parameter values. When the traffic statistics values ​​are compared and are not less than the network storm baseline parameter values, the preset network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time. According to the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve, network storm source prediction trend chart data is generated to provide to operation and maintenance personnel to eliminate potential network storms in a timely manner, so that the cause of the secondary equipment network communication failure can be analyzed and diagnosed. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a schematic diagram of the functional modules of an integrated detection device for a power monitoring local area network according to a preferred embodiment.

[0019] Figure 2 for Figure 1 Schematic diagram of the functional units of the data processing module.

[0020] In the figure: an integrated detection device for a power monitoring local area network 10, a data processing module 20, a clock information correction unit 21, a network data acquisition and organization unit 22, a network address legitimacy judgment unit 23, a protocol type analysis unit 24, a traffic information statistics analysis unit 25, a network storm monitoring and analysis unit 26, a capacitive touch screen 30, a network interface 40, a 4G / 5G base station wireless clock module 50, a dedicated interface expansion module 60, an electronic hard disk 70, and a power supply module 80. DETAILED DESCRIPTION

[0021] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and corresponding drawings. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0022] like Figure 1 As shown, the integrated detection device 10 for the electric power monitoring local area network provided by the present invention includes a data processing module 20, a capacitive touch screen 30, a network interface 40, a 4G / 5G base station wireless clock module 50, a dedicated interface expansion module 60, an electronic hard disk 70, and a power supply module 80. The data processing module 20 is electrically connected to the capacitive touch screen 30, the network interface 40, the 4G / 5G base station wireless clock module 50, the dedicated interface expansion module 60, the electronic hard disk 70, and the power supply module 80.

[0023] The dedicated interface expansion module 60 is used to provide an expansion interface for external devices, and the 4G / 5G base station wireless clock module 50 is used to obtain the standard clock information of the base station under various indoor and outdoor environmental conditions and provide the clock information to the data processing module 20.

[0024] The data processing module 20 acquires network data from the network port of a switch in the power monitoring local area network via the network interface 40, adds clock information to the acquired network data to obtain network data, and determines whether the IP address in the network data is in a preset legal table. If it is determined that the IP address in the network data is not in the preset legal table, an alarm is generated to remind the operation and maintenance personnel to promptly eliminate the illegal IP access device and keep a record. If it is determined that the IP address in the network data is in the preset legal table, the protocol information of the message in the network data is analyzed according to the pre-stored power protocol standard parameter table to determine whether the protocol type is the system-specified power communication protocol, that is, the system-specified power communication protocol recorded in the power protocol standard parameter table. If it is not the specified protocol type, a preset error message is output. If it is the specified protocol type, the protocol data in the network data is determined to comply with the standard specifications. If it does not comply with the standard specifications, a preset error message is output. The error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report for the corresponding layer that does not comply with the standard is generated and displayed. For example, protocol data compliance is checked by checking whether the protocol type is within the specified range. If the protocol type is not within the specified range, a preset error message alarm is recorded and output. Non-compliance includes errors such as incorrect protocol type and protocol format not meeting requirements. For the IEC101 protocol, the protocol is verified by checking the message header byte, control code, and check code. For the IEC103 communication protocol, it has two message formats: fixed-frame length message and variable-frame length message. The former is mainly used to transmit information such as "summons, commands, confirmations, and responses", while the latter is mainly used to transmit information such as "commands" and "data". The protocol is verified by checking the message header byte, control code, and check code. For the IEC104 protocol, the transmission interface (TCP to user) is a directional stream interface. It does not define any start or stop mechanism for the ASDU in IEC 60870-5-101. To detect the start and end of the ASDU, each APCI includes the following delimiting elements: a start character, the specified length of the ASDU, and a control field. A complete APDU can be sent to verify the protocol. For the IEC61850 protocol, IEC61850 describes the structure and layout of the entire substation through the SCD (system configuration) file, uses object-oriented modeling technology, and the data model has self-describing capabilities. It checks whether the protocol data interpretation is describable. By analyzing the protocol data, information such as the data type, value, and characteristics can be obtained.

[0025] The data processing module 20 also performs traffic statistics on the network sorting data and generates corresponding traffic statistics values, and compares the traffic statistics values ​​with the preset network storm benchmark parameter values. When the traffic statistics values ​​are compared to be not less than the network storm benchmark parameter values, the data processing module 20 issues the preset network storm source fault information. The data processing module 20 also draws a traffic peak / time curve based on the traffic peak data in the network and the time, and generates network storm source prediction trend chart data based on the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve to provide operation and maintenance personnel with timely elimination of potential network storm faults; generates a peak experience table based on each storm source traffic value, and automatically corrects the network storm source monitoring and analysis mathematical model to avoid false alarms of network storm source faults.

[0026] Furthermore, the data processing module 20 calibrates the clock of the integrated detection device 10 for the electric power monitoring local area network according to the clock information of the base station.

[0027] The data processing device 20 can be a single chip microcomputer or a microcomputer running a set of computer applications, wherein the computer applications are used to complete the integrated detection of the network status of the power monitoring local area network. After the data processing module 20 runs the computer applications, it generates the following functional modules. Please also refer to Figure 2 , the data processing module 20 includes: a clock information correction unit 21, a network data acquisition and sorting unit 22, a network address legitimacy judgment unit 23, a protocol type analysis unit 24, a traffic information statistics analysis unit 25, and a network storm monitoring and analysis unit 26;

[0028] The clock information correction unit 21 is used to calibrate the clock of the power monitoring local area network integrated detection device 10 according to the clock information of the base station;

[0029] The network data acquisition and sorting unit 22 is used to acquire network data from the network port of the switch in the power monitoring local area network through the network interface, and add the clock information to the acquired network data to obtain network sorted data;

[0030] The network address validity determination unit 23 is used to determine whether the IP address in the network data is in a preset valid table. If it is determined that the IP address in the network data is not in the preset valid table, an alarm is generated to remind the operation and maintenance personnel to promptly eliminate the problem and keep a record. If it is determined that the IP address in the network data is in the preset valid table, a first signal is transmitted to the protocol type analysis unit 24.

[0031] The protocol type analysis unit 24 is configured to respond to the first signal and analyze the protocol information of the message in the network collated data according to a pre-stored power protocol standard parameter table to determine whether the protocol type is a power communication protocol specified by the system. If not, a preset error message is output. If it is a specified protocol type, the protocol data in the network collated data is determined to be compliant with the standard. If not, a preset error message is output. The error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report for the corresponding layer that does not comply with the standard is generated and displayed.

[0032] The traffic information statistical analysis unit 25 is used to perform traffic statistics on the network sorting data and generate corresponding traffic statistical values, and compare the traffic statistical values ​​with the preset network storm benchmark parameter values. When the traffic statistical value is not less than the network storm benchmark parameter value, a network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time.

[0033] The network storm monitoring and analysis unit 26 is used to generate network storm source prediction trend chart data based on the preset network storm source monitoring and analysis mathematical model and traffic peak / time curve chart, so as to provide it to operation and maintenance personnel to promptly eliminate potential network storm failures; generate a peak experience table based on the value of each storm source traffic, and automatically correct the network storm source monitoring and analysis mathematical model to avoid false alarms of network storm source failures.

[0034] In this embodiment, a warning percentage M of a network traffic storm value is preset in the system, and the traffic information statistical analysis unit 25 performs traffic statistics on the network sorting data and generates corresponding traffic statistics. The traffic statistics value is the overall network traffic value for a predetermined period, and the single device traffic value of the above-mentioned predetermined period of a single device corresponding to the IP is calculated based on the IP address. The overall network traffic value, the single device traffic value, the IP address and the sniffed MAC are matched to draw a network overall traffic and single device traffic value / time curve graph; the traffic statistics value is obtained by integrating the total traffic in the above-mentioned predetermined period, and the single device traffic value is obtained by integrating the single device traffic value in the above-mentioned predetermined period. Obtain N points, the network storm monitoring and analysis unit 26 calculates the ratio P of the flow integral of a single device to the total flow integral, where P=N points / N total, and displays it in the form of an icon in the overall network flow and the flow value / time curve of a single device in combination with the IP and Mac addresses of the single device. When the flow ratio P monitored online exceeds the set warning line M value, it indicates that the corresponding single device is the storm source, and the icon of the corresponding single device is displayed in a striking manner to remind the user to investigate the relevant information of the single device; a peak experience table is generated based on each flow ratio P and the network status corresponding to the flow ratio P, and the warning line M value is dynamically updated to avoid false alarms of network storm source failures.

[0035] This application also provides a method for integrated detection of a power monitoring local area network, comprising the following steps:

[0036] Step S100, obtaining clock information of a base station of a mobile service provider;

[0037] Step S102: acquiring network data from a network port of a switch in the power monitoring local area network through a network interface, and adding clock information to the acquired network data to obtain network collated data;

[0038] Step S104: determining whether the IP address in the network data is in a pre-set valid table. If it is determined that the IP address in the network data is not in the pre-set valid table, an alarm message is generated to remind the operation and maintenance personnel to promptly eliminate the problem and keep a record.

[0039] Step S106: When it is determined that the IP address in the network collated data is in the preset legal table, the protocol information of the message in the network collated data is analyzed according to the pre-stored power protocol standard parameter table; the protocol type is analyzed to determine whether it is the power communication protocol specified by the system, that is, the power communication protocol specified by the system as recorded in the power protocol standard parameter table; if it is not the specified protocol type, a preset error message is output; if it is the specified protocol type, whether the protocol data in the network collated data complies with the standard specification is determined; if it does not comply with the standard specification, a preset error message is output; the error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report for the corresponding layer that does not comply with the standard is generated and displayed;

[0040] Step S108, perform traffic statistics on the network sorting data and generate corresponding traffic statistics values, and compare the traffic statistics values ​​with the preset network storm benchmark parameter values. When the traffic statistics values ​​are compared to be not less than the network storm benchmark parameter values, the pre-stored network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time. According to the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve, network storm source prediction trend chart data is generated to provide to operation and maintenance personnel to eliminate potential network storm faults in a timely manner; a peak experience table is generated according to each storm source traffic value, and the network storm source monitoring and analysis mathematical model is automatically corrected to avoid false alarms of network storm source faults.

[0041] Among them, the step of "performing traffic statistics on the network sorting data and generating corresponding traffic statistics values, and comparing the traffic statistics values ​​with the preset network storm benchmark parameter values, and when the traffic statistics values ​​are compared to be not less than the network storm benchmark parameter values, drawing a traffic peak / time curve diagram according to the traffic peak data in the network and the time at which they are located" is specifically as follows: presetting the warning percentage M of the network traffic storm value in the system, performing traffic statistics on the network sorting data and generating corresponding traffic statistics values, the traffic statistics value is the overall network traffic value for a predetermined period, and calculating the single device traffic value of the single device corresponding to the IP for the above-mentioned predetermined period based on the IP address, matching the overall network traffic value, the single device traffic value, the IP address and the sniffed MAC, and drawing them into the overall network traffic and single device traffic value / time curve diagrams.

[0042] Among them, "according to the preset network storm source monitoring and analysis mathematical model and traffic peak / time curve, network storm source prediction trend chart data is generated to provide to operation and maintenance personnel for timely elimination" specifically: the traffic statistics value is obtained by integrating the total traffic in the above-mentioned predetermined period to obtain N total, and the single device traffic value is obtained by integrating the single device traffic value in the above-mentioned predetermined period to obtain N points, and the ratio P of the traffic integral of the single device to the total traffic integral is calculated, where P=N points / N total, and combined with the IP and Mac addresses of the single device, it is displayed in the form of an icon in the overall network traffic and the single device traffic value / time curve. When the traffic ratio P monitored online exceeds the set warning line M value, it indicates that the corresponding single device is a storm source, and the icon of the corresponding single device is displayed in a striking manner to remind the user to investigate the relevant information of the single device.

Claims

1. An integrated detection device for a power monitoring local area network, characterized in that: It includes a data processing module, a capacitive touch screen, a network interface, a 4G / 5G base station wireless clock module, a dedicated interface expansion module, an electronic hard disk, and a power supply module. The data processing module is electrically connected to the capacitive touch screen, the network interface, the 4G / 5G base station wireless clock module, the dedicated interface expansion module, the electronic hard disk, and the power supply module. The dedicated interface expansion module is used to provide an expansion interface for external devices. The 4G / 5G base station wireless clock module is used to obtain the clock information of the base station and provide the clock information to the data processing module. The data processing module calibrates the clock of the integrated detection device of the power monitoring local area network according to the clock information of the base station; The data processing module includes: clock information correction unit, network data acquisition and sorting unit, network address legitimacy judgment unit, protocol type analysis unit, traffic information statistics analysis unit, network storm monitoring and analysis unit; A clock information correction unit, which calibrates the clock of the integrated detection device of the power monitoring local area network according to the clock information of the base station; A network data acquisition and collation unit acquires network data from a network port of a switch in the power monitoring local area network through a network interface, and adds clock information to the acquired network data to obtain network collated data; a network address legitimacy determination unit for determining whether an IP address in the network collation data is in a preset legal table, and generating an alarm message to remind operation and maintenance personnel to promptly eliminate illegal IP access devices and keep records when determining that the IP address in the network collation data is in the preset legal table; and transmitting a first signal to the protocol type analysis unit when determining that the IP address in the network collation data is in the preset legal table; The protocol type analysis unit responds to the first signal and analyzes the protocol information of the message in the network sorting data according to the pre-stored power protocol standard parameter table to analyze whether the protocol type is the specified power communication protocol. If it is not the specified protocol type, a preset error message is output. If it is the specified protocol type, the protocol data in the network sorting data is judged to be in compliance with the standard specification. If it does not comply with the standard specification, a preset error message is output. The error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report of non-compliance with the specification for the corresponding layer is generated and displayed. Among them, for the IEC101 protocol and IEC103 protocol, the protocol is verified by detecting the header byte, control code and check code of the message; for the IEC 60870-5-101 protocol, the protocol is verified by transmitting a complete APDU; for the IEC61850 protocol, the protocol is verified by checking whether the protocol data interpretation is describable. The traffic information statistics analysis unit performs traffic statistics on the network collated data and generates corresponding traffic statistics values, and compares the traffic statistics values ​​with the preset network storm benchmark parameter values. When the traffic statistics values ​​are not less than the network storm benchmark parameter values, a network storm source fault message is issued, and a traffic peak value / time curve is drawn based on the traffic peak data in the network and the time at which they occur; The network storm monitoring and analysis unit generates network storm source prediction trend chart data based on the preset network storm source monitoring and analysis mathematical model and traffic peak / time curve chart, providing it to operation and maintenance personnel to promptly eliminate potential network storm source failures; it generates a peak experience table based on the value of each storm source traffic, automatically corrects the network storm source monitoring and analysis mathematical model, and avoids false alarms of network storm source failures.

2. The integrated detection device for a power monitoring local area network according to claim 1, characterized in that: A warning percentage M of the network traffic storm value is preset in the system. The traffic information statistical analysis unit performs traffic statistics on the network sorted data and generates corresponding traffic statistical values. The traffic statistical values ​​are the overall network traffic values ​​for a predetermined period of time, and the single device traffic value of the single device corresponding to the IP for the above-mentioned predetermined period of time is calculated based on the IP address. The overall network traffic value, single device traffic value, IP address and sniffed MAC are matched to draw a network overall traffic and single device traffic value / time curve graph.

3. The integrated detection device for a power monitoring local area network according to claim 2, characterized in that: The traffic statistics value is obtained by integrating the total traffic in the above-mentioned predetermined period to obtain N total traffic, and the traffic value of a single device is obtained by integrating the traffic value of a single device in the above-mentioned predetermined period to obtain N points. The network storm monitoring and analysis unit calculates the ratio P of the traffic integral of a single device to the total traffic integral, where P=N points / N total, and displays it in the form of an icon in the overall network traffic and the traffic value / time curve of a single device in combination with the IP and Mac addresses of the single device. When the traffic ratio P monitored online exceeds the warning line M value set by the system, it indicates that the corresponding single device is a storm source, and the icon of the corresponding single device is displayed in a striking manner to remind the user to investigate the relevant information of the single device; A peak experience table is generated based on each traffic ratio P and the network status corresponding to the traffic ratio P, and the warning line M value is dynamically updated to avoid false alarms of network storm source failures.

4. A method for integrated detection of a power monitoring local area network, comprising the following steps: Obtain clock information of wireless base stations of mobile service providers; Acquire network data from a network port of a switch in a power monitoring local area network through a network interface, and add clock information to the acquired network data to obtain network collated data; Determine whether the IP address in the network data is in the preset legal table. If it is determined that the IP address in the network data is not in the preset legal table, an alarm message is generated to remind the operation and maintenance personnel to eliminate it in time and keep records; When it is determined that the IP address in the network collated data is in the preset legal table, the protocol information of the message in the network collated data is analyzed according to the pre-stored power protocol standard parameter table; the protocol type is analyzed to see whether it is the prescribed power communication protocol, and if it is not the prescribed protocol type, a preset error message is output; if it is the prescribed protocol type, whether the protocol data in the network collated data complies with the standard specification is determined, and if it does not comply with the standard specification, a preset error message is output; Error information is hierarchically classified and counted according to the corresponding layer in the network model where the protocol information is located, and a fault detection report for the corresponding layer that does not meet the specifications is generated and displayed. For the IEC101 and IEC103 protocols, the protocol is verified by checking the header byte, control code and check code of the message; for the IEC 60870-5-101 protocol, the protocol is verified by sending a complete APDU; for the IEC61850 protocol, the protocol is verified by checking whether the protocol data interpretation is describable. The network sorting data is subjected to traffic statistics and corresponding traffic statistics values ​​are generated, and the traffic statistics values ​​are compared with the preset network storm baseline parameter values. When the traffic statistics values ​​are compared to be not less than the network storm baseline parameter values, the preset network storm source fault information is issued, and a traffic peak / time curve is drawn according to the traffic peak data in the network and the time. According to the preset network storm source monitoring and analysis mathematical model and the traffic peak / time curve, network storm source prediction trend chart data is generated to provide to operation and maintenance personnel to eliminate potential network storm faults in a timely manner; a peak experience table is generated according to the value of each storm source traffic, and the network storm source monitoring and analysis mathematical model is automatically corrected to avoid false alarms of network storm source faults.

5. The integrated detection method for electric power monitoring local area network according to claim 4, characterized in that: The specific steps of "performing traffic statistics on the network sorting data and generating corresponding traffic statistics values, and comparing the traffic statistics values ​​with the preset network storm baseline parameter values, and when the traffic statistics values ​​are compared to be not less than the network storm baseline parameter values, drawing a traffic peak / time curve chart based on the traffic peak data in the network and the time at which they are located" are as follows: presetting a warning percentage M of the network traffic storm value in the system, performing traffic statistics on the network sorting data and generating corresponding traffic statistics values, the traffic statistics values ​​being the overall network traffic values ​​for a predetermined period, and calculating the single device traffic values ​​of a single device corresponding to the IP for the above-mentioned predetermined period based on the IP address, matching the overall network traffic value, the single device traffic value, the IP address and the sniffed MAC, and drawing the overall network traffic and single device traffic value / time curve charts.

6. The integrated detection method for electric power monitoring local area network according to claim 4, characterized in that: "Based on the preset network storm source monitoring and analysis mathematical model and traffic peak / time curve, network storm source prediction trend chart data is generated to provide operation and maintenance personnel with timely elimination of potential network storm failures." Specifically: the traffic statistics value is obtained by integrating the total traffic in the predetermined time period to obtain N total, and the traffic value of a single device is obtained by integrating the traffic value of a single device in the above predetermined time period to obtain N points. The ratio P of the traffic integral of a single device to the total traffic integral is calculated, where P=N points / N total, and is displayed in the form of an icon in the overall network traffic and the traffic value / time curve of a single device in combination with the IP and Mac address of the single device. When the traffic ratio P monitored online exceeds the set warning line M value, it indicates that the corresponding single device is a storm source, and the icon of the corresponding single device is displayed in a striking manner to remind the user to investigate the relevant information of the single device.

Citation Information

Patent Citations

  • Power distribution network control system safety protection method and system

    CN105049403A

  • Power secondary equipment network communication fault detection system and method

    CN115242686A