Intelligent coal preparation plant network security protection system

By introducing virtual servers and control modules into the coal preparation plant network system, and combining data source address classification and security analysis, the problem of insufficient intelligence in data security identification in the coal preparation plant network system was solved, and the efficiency and security of data reception were improved.

CN116208422BActive Publication Date: 2026-06-02PINGDINGSHAN ZHONGXUAN AUTOMATIC CONTROL SYST

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PINGDINGSHAN ZHONGXUAN AUTOMATIC CONTROL SYST
Filing Date
2023-03-16
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing coal preparation plant network systems lack virtual servers and control modules, which makes it impossible to effectively analyze the security of suspicious information, affecting data reception efficiency and the level of intelligence in security identification.

Method used

By introducing virtual servers and control modules into the data management system, and through the coordinated control of the data acquisition and identification module, data storage server, security analysis module, and control module, data source addresses are classified into whitelists, graylists, and blacklists for classification, screening, and security analysis to ensure the security of the data storage server.

Benefits of technology

It ensures the security and reliability of the coal preparation plant's network system, prevents dangerous data from entering the data storage server, reduces the burden on the security analysis module, ensures data reception efficiency and security, and prevents the leakage of confidential information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208422B_ABST
    Figure CN116208422B_ABST
Patent Text Reader

Abstract

The application discloses a kind of intelligent coal preparation plant network security protection systems, belong to network security technical field, the main equipment of the present application includes: interface, data acquisition identification module, data storage server, virtual server, security analysis module, regulation and control module, wherein, regulation and control module can be coordinated control to data acquisition identification module, data storage server, security analysis module, regulation and control module is identified to the identification result of input data by data acquisition identification module, data is distributed to different servers and is saved or temporarily stored, and control security analysis module analyzes and detects the data temporarily stored in virtual server, finally filters out harmful data, under the condition that not affecting the normal reception of coal preparation plant network system security data, information with security risk is classified and screened, ensure the safety and reliability of coal preparation plant network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a network security protection system for an intelligent coal preparation plant. Background Technology

[0002] With the increasing prominence of information security issues in industrial control systems, more complex information security threats are emerging. Because coal preparation plant production control systems have high real-time requirements, ensuring the security and reliability of the network system has become a necessary prerequisite for normal production. Preventing the information received by the coal preparation plant's network system from being compromised has become an important research issue in network information.

[0003] Chinese Patent Publication No. CN108055261A discloses a method for deploying an industrial network security system. This method includes: monitoring security risks in the industrial network, conducting risk assessments, and obtaining risk assessment results; classifying the security level of the industrial control system in the industrial network based on the risk assessment results; and determining a security protection equipment deployment scheme for the industrial network based on the security level of the industrial control system. The industrial network is divided into a field access layer, a factory aggregation layer, and an industrial core layer, and the security protection equipment deployment scheme includes security protection equipment deployment schemes for the field access layer, factory aggregation layer, and industrial core layer. This invention also provides an industrial network security system. Through this invention, based on the analysis of industrial network security protection risks and the requirements of network security level protection, a hierarchical security protection equipment deployment scheme for the industrial network is determined, thereby enabling the standardized and efficient construction of an industrial network security protection system and improving the security of the industrial control system in the industrial network.

[0004] The above devices lack virtual servers and control modules, making it impossible to process suspicious information on a virtual server and analyze its security. This results in a decrease in the system's intelligence in identifying information security, affecting the data reception efficiency of the coal preparation plant. Summary of the Invention

[0005] To address this issue, the present invention provides a network security protection system for intelligent coal preparation plants, which overcomes the problem in existing technologies that cannot run suspicious information on a virtual server to analyze the security of suspicious information, resulting in a decrease in the system's intelligence in identifying information security.

[0006] To achieve the above objectives, the present invention provides a network security protection system for intelligent coal preparation plants, comprising:

[0007] The interface has several parts, which are used to connect to external devices;

[0008] A data management system, which is connected to several of the aforementioned interfaces, including,

[0009] A data acquisition and identification module is installed inside the data management system and is connected to several interfaces respectively. It is used to acquire data information from several interfaces and identify the data information.

[0010] A data storage server, located within the data management system, is used to store data information from the coal preparation plant.

[0011] A virtual server, which is set up inside the data storage server, is used to store temporary data;

[0012] A security analysis module, located within the data management system, is used to perform security analysis on temporary data.

[0013] The control module, located within the data management system, coordinates and controls the data acquisition and identification module, the data storage server, and the security analysis module. The control module uses the data acquisition and identification module's identification results to allocate data to different servers for storage or temporary storage, and controls the security analysis module to analyze and detect data temporarily stored in virtual servers, ultimately filtering out harmful data to ensure the security of data information in the data storage server.

[0014] Furthermore, the virtual server has a suspicious folder inside it. The virtual server can receive suspicious data from the data acquisition and identification module and temporarily store the suspicious data in the suspicious folder. The suspicious folder cannot send out its suspicious information unless it receives a data retrieval instruction from the control module.

[0015] The security analysis module can analyze suspicious data in suspicious folders and control the data programs in suspicious folders to start running.

[0016] In particular, the control module divides the data source addresses into whitelist addresses, graylist addresses, and blacklist addresses based on the level of trust.

[0017] The control module numbers the interfaces as follows: interface A1, interface A2, ..., interface An, where n is an integer greater than 2. For different interfaces, the control module sets different data judgment sets. For the i-th interface, i = 1, 2, ..., n.

[0018] The control module is configured with a whitelist set Bi of source addresses for receiving data at the i-th interface, where Bi = {Ci1, Ci2, ..., Ciz}, where Ci1 is the first whitelist address of the i-th interface, Ci2 is the second whitelist address of the i-th interface, and Ciz is the Z-th whitelist address of the i-th interface.

[0019] The control module is configured with a gray list data determination set group Ei, Ei = {Ei1, S}, where Ei1 is the gray list set of source addresses for data received by the i-th interface, and S is the set of secure data allowed to be received by the data storage server; for Ei1, Ei1 = {Fi1, Fi2, ..., Fiz}, where Fi1 is the first gray list address of the i-th interface, Fi2 is the second gray list address of the i-th interface, and Fiz is the Z-th gray list address of the i-th interface; for S, S = {D1, D2, ..., Dz}, where D1 is the first type of secure data allowed to be received by the data storage server, D2 is the second type of secure data allowed to be received by the data storage server, ..., Dz is the Z-th type of secure data allowed to be received by the data storage server;

[0020] The control module is configured with a blacklist set Gi of source addresses for the data received by the i-th interface, where Gi = {Hi1, Hi2, ..., Hiz}, where Hi1 is the first blacklist address of the i-th interface, Hi2 is the second blacklist address of the i-th interface, and Hiz is the Z-th blacklist address of the i-th interface.

[0021] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0022] If Up∈Bi, the control module determines that the data is secure data transmitted from a whitelisted address and transmits the data to the data storage server.

[0023] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0024] If Up∈Ei1 and U∈S, the control module determines that the data is secure data transmitted from the graylist address and transmits the data to the data storage server;

[0025] If Up∈Ei1 and The control module determines that the data is unknown security data passed from a graylist address, and then transmits the data to the virtual server.

[0026] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0027] If Up∈Gi, the control module determines that the data is from a blacklisted address, intercepts the data, and transmits the source address of the data information to the security analysis module.

[0028] The security analysis module searches for data with the same source address in the data storage server and the virtual server, performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis results indicate it is dangerous.

[0029] Furthermore, the control module controls the virtual server to open or start unknown security data transmitted by the data acquisition and identification module, and controls the security analysis module to perform security checks on the unknown security data after it has been opened or started.

[0030] If the security analysis module determines that the unknown security data is secure data, the control module controls the virtual server to transmit the data to the data storage server;

[0031] If the security analysis module determines that the unknown security data is dangerous data, the control module controls the virtual server to delete the data, and controls the security analysis module to search for data with the same source address in the data storage server and the virtual server, and performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis result is dangerous data;

[0032] If the security analysis module cannot determine the danger of the unknown security data, the control module determines the unknown security data as suspicious data and controls the virtual server to transfer the suspicious data to the suspicious folder.

[0033] Furthermore, the control module controls the virtual server to run the information in the suspicious folder, and controls the security analysis module to analyze the data in the suspicious folder.

[0034] If the suspicious data requires accessing data from the data storage server in the system, the control module will initiate the anti-leakage verification procedure.

[0035] If the suspicious data needs to be transmitted to the data storage server in the system, the control module initiates a copy verification procedure.

[0036] Furthermore, the control module initiates a leak prevention verification procedure to analyze whether the data to be retrieved for the suspicious data is confidential data from the coal preparation plant.

[0037] If suspicious data requires access to confidential data from the coal preparation plant, the control module determines that the suspicious data is dangerous data and deletes it.

[0038] If suspicious data requires access to non-confidential data from the coal preparation plant, the control module retrieves the required data to the suspicious data, controls the security analysis module to analyze the security of the suspicious data after retrieval, and transmits data deemed secure in the suspicious folder to the data storage server, while deleting data in the suspicious folder that cannot be determined to be secure.

[0039] The control module initiates a copy verification program, copies the portion of the suspicious data that needs to be transmitted to the data storage server, and runs the copied data on the virtual server. The security analysis module then performs security checks on the copied data running on the virtual server.

[0040] If the copied data is safe data, the control system will transfer the copied data to the data storage server and delete the data in the suspicious folder;

[0041] If the copied data is dangerous, the control system will delete the copied data in the virtual server and the data in the suspicious folder.

[0042] In particular, the security analysis module records the data security test results and saves the security test record results to the data storage server;

[0043] The control module monitors the security test result records in the data storage server and analyzes the source addresses of data identified as dangerous by the security analysis module.

[0044] If dangerous data appears once in the data sent to the system from the same whitelist source address, the control module will change the whitelist source address to the graylist source address.

[0045] If dangerous data appears twice in data sent to the system from the same gray list source address, the control module will change the gray list source address to the black list source address.

[0046] Compared with the prior art, the beneficial effects of the present invention are as follows: The control module can coordinate and control the data acquisition and identification module, the data storage server, and the security analysis module. The control module uses the identification results of the input data by the data acquisition and identification module to allocate the data to different servers for storage or temporary storage, and controls the security analysis module to analyze and detect the data temporarily stored in the virtual server, and finally filter out harmful data. Without affecting the normal reception of security data by the coal preparation plant network system, the information with security risks is classified and screened to ensure the security and reliability of the coal preparation plant network system.

[0047] By constructing a virtual server in the data storage server, data that fails to identify security issues in the data acquisition and identification module is temporarily stored, and the data is processed in the virtual server, thus preventing dangerous data from directly entering the data storage server and causing damage or theft of important information.

[0048] By dividing the source addresses of data into whitelisted addresses, graylisted addresses, and blacklisted addresses, the system can directly receive information from whitelisted addresses, directly reject information from blacklisted addresses, and only perform security analysis on information from graylisted addresses, thus significantly reducing the extent to which the system uses the security analysis module.

[0049] The control system determines the confidentiality of the data required for suspicious data and then initiates a copy verification procedure to delete suspicious information that may lead to the leakage of confidential information of the coal preparation plant, thus ensuring the integrity and interests of the coal preparation plant's network.

[0050] By reclassifying incoming dangerous data addresses, the reliability of the system obtaining information from whitelisted addresses is ensured. Attached Figure Description

[0051] Figure 1 This is a schematic diagram of the structure of an intelligent coal preparation plant network security protection system according to an embodiment of the present invention; Detailed Implementation

[0052] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0053] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0054] It should be noted that in the description of this invention, the terms "upper", "lower", "left", "right", "inner", "outer", etc., which indicate directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.

[0055] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0056] Please see Figure 1 As shown, Figure 1 This is a schematic diagram of the structure of an intelligent coal preparation plant network security protection system according to an embodiment of the present invention;

[0057] This invention provides a network security protection system for an intelligent coal preparation plant, including interfaces, which are provided with a plurality of interfaces for connecting to external devices;

[0058] A data management system, which is connected to several of the aforementioned interfaces, including,

[0059] A data acquisition and identification module is installed inside the data management system and is connected to several interfaces respectively. It is used to acquire data information from several interfaces and identify the data information.

[0060] A data storage server, located within the data management system, is used to store data information from the coal preparation plant.

[0061] A virtual server, which is set up inside the data storage server, is used to store temporary data;

[0062] A security analysis module, located within the data management system, is used to perform security analysis on temporary data.

[0063] The control module, located within the data management system, coordinates and controls the data acquisition and identification module, the data storage server, and the security analysis module. The control module uses the data acquisition and identification module's identification results to allocate data to different servers for storage or temporary storage, and controls the security analysis module to analyze and detect data temporarily stored in virtual servers, ultimately filtering out harmful data to ensure the security of data information in the data storage server.

[0064] Furthermore, the virtual server has a suspicious folder inside it. The virtual server can receive suspicious data from the data acquisition and identification module and temporarily store the suspicious data in the suspicious folder. The suspicious folder cannot send out its suspicious information unless it receives a data retrieval instruction from the control module.

[0065] The security analysis module can analyze suspicious data in suspicious folders and control the data programs in suspicious folders to start running.

[0066] If the system has virtual servers and suspicious folders, it cannot determine whether the suspicious data is dangerous when it receives it. This leads to a decrease in the system's intelligent security identification capabilities and affects the data receiving efficiency of the coal preparation plant. By building virtual servers in the data storage server, data that the data acquisition and identification module fails to identify as safe can be temporarily stored. The data can then be processed in the virtual server, preventing dangerous data from directly entering the data storage server and causing damage or theft of important information.

[0067] In particular, the control module divides the data source addresses into whitelist addresses, graylist addresses, and blacklist addresses based on the level of trust.

[0068] The control module numbers the interfaces as follows: interface A1, interface A2, ..., interface An, where n is an integer greater than 2. For different interfaces, the control module sets different data judgment sets. For the i-th interface, i = 1, 2, ..., n.

[0069] The control module is configured with a whitelist set Bi of source addresses for receiving data at the i-th interface, where Bi = {Ci1, Ci2, ..., Ciz}, where Ci1 is the first whitelist address of the i-th interface, Ci2 is the second whitelist address of the i-th interface, and Ciz is the Z-th whitelist address of the i-th interface.

[0070] The control module is configured with a gray list data determination set group Ei, Ei = {Ei1, S}, where Ei1 is the gray list set of source addresses for data received by the i-th interface, and S is the set of secure data allowed to be received by the data storage server; for Ei1, Ei1 = {Fi1, Fi2, ..., Fiz}, where Fi1 is the first gray list address of the i-th interface, Fi2 is the second gray list address of the i-th interface, and Fiz is the Z-th gray list address of the i-th interface; for S, S = {D1, D2, ..., Dz}, where D1 is the first type of secure data allowed to be received by the data storage server, D2 is the second type of secure data allowed to be received by the data storage server, ..., Dz is the Z-th type of secure data allowed to be received by the data storage server;

[0071] The control module is configured with a blacklist set Gi of source addresses for the data received by the i-th interface, where Gi = {Hi1, Hi2, ..., Hiz}, where Hi1 is the first blacklist address of the i-th interface, Hi2 is the second blacklist address of the i-th interface, and Hiz is the Z-th blacklist address of the i-th interface.

[0072] If the source addresses of the data are not categorized, the system needs to perform security checks on all data information. The computing power of the security analysis module cannot meet the data reception speed of the coal preparation plant network, thus affecting the data reception efficiency of the coal preparation plant network. By dividing the source addresses of the data into whitelist addresses, graylist addresses, and blacklist addresses, the system can directly receive information from whitelist addresses, directly reject information from blacklist addresses, and only perform security analysis on information from graylist addresses, which greatly reduces the extent to which the system uses the security analysis module.

[0073] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0074] If Up∈Bi, the control module determines that the data is secure data transmitted from a whitelisted address and transmits the data to the data storage server.

[0075] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0076] If Up∈Ei1 and U∈S, the control module determines that the data is secure data transmitted from the graylist address and transmits the data to the data storage server;

[0077] If Up∈Ei1 and The control module determines that the data is unknown security data passed from a graylist address, and then transmits the data to the virtual server.

[0078] Furthermore, when the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface.

[0079] If Up∈Gi, the control module determines that the data is from a blacklisted address, intercepts the data, and transmits the source address of the data information to the security analysis module.

[0080] The security analysis module searches for data with the same source address in the data storage server and the virtual server, performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis results indicate it is dangerous.

[0081] Furthermore, the control module controls the virtual server to open or start unknown security data transmitted by the data acquisition and identification module, and controls the security analysis module to perform security checks on the unknown security data after it has been opened or started.

[0082] If the security analysis module determines that the unknown security data is secure data, the control module controls the virtual server to transmit the data to the data storage server;

[0083] If the security analysis module determines that the unknown security data is dangerous data, the control module controls the virtual server to delete the data, and controls the security analysis module to search for data with the same source address in the data storage server and the virtual server, and performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis result is dangerous data;

[0084] If the security analysis module cannot determine the danger of the unknown security data, the control module determines the unknown security data as suspicious data and controls the virtual server to transfer the suspicious data to the suspicious folder.

[0085] Furthermore, the control module controls the virtual server to run the information in the suspicious folder, and controls the security analysis module to analyze the data in the suspicious folder.

[0086] If the suspicious data requires accessing data from the data storage server in the system, the control module will initiate the anti-leakage verification procedure.

[0087] If the suspicious data needs to be transmitted to the data storage server in the system, the control module initiates a copy verification procedure.

[0088] Furthermore, the control module initiates a leak prevention verification procedure to analyze whether the data to be retrieved for the suspicious data is confidential data from the coal preparation plant.

[0089] If suspicious data requires access to confidential data from the coal preparation plant, the control module determines that the suspicious data is dangerous data and deletes it.

[0090] If suspicious data requires access to non-confidential data from the coal preparation plant, the control module retrieves the required data to the suspicious data, controls the security analysis module to analyze the security of the suspicious data after retrieval, and transmits data deemed secure in the suspicious folder to the data storage server, while deleting data in the suspicious folder that cannot be determined to be secure.

[0091] The control module initiates a copy verification program, copies the portion of the suspicious data that needs to be transmitted to the data storage server, and runs the copied data on the virtual server. The security analysis module then performs security checks on the copied data running on the virtual server.

[0092] If the copied data is safe data, the control system will transfer the copied data to the data storage server and delete the data in the suspicious folder;

[0093] If the copied data is dangerous, the control system will delete the copied data in the virtual server and the data in the suspicious folder.

[0094] If the control system fails to determine the confidentiality of the information in the data storage server required for the suspicious data in the suspicious folder, the information extracted from the data may be confidential, leading to the leakage of confidential information of the coal preparation plant. The control system determines the confidentiality of the data required for the suspicious data and initiates a copy verification procedure to delete the suspicious information that may cause the leakage of confidential information of the coal preparation plant, thus ensuring the integrity and interests of the coal preparation plant's network.

[0095] In particular, the security analysis module records the data security test results and saves the security test record results to the data storage server;

[0096] The control module monitors the security test result records in the data storage server and analyzes the source addresses of data identified as dangerous by the security analysis module.

[0097] If dangerous data appears once in the data sent to the system from the same whitelist source address, the control module will change the whitelist source address to the graylist source address.

[0098] If dangerous data appears twice in data sent to the system from the same gray list source address, the control module will change the gray list source address to the black list source address.

[0099] If the security analysis module fails to record the data security test results, the system will continue to receive a large amount of dangerous data from whitelisted addresses after the whitelisted and graylisted addresses send dangerous data to the coal preparation plant network, leading to network paralysis. By reclassifying the incoming dangerous data addresses, the reliability of the system obtaining information from whitelisted addresses is ensured.

[0100] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

Claims

1. A system for intelligent network security protection of a coal preparation plant, characterized in that, include, The interface has several parts, which are used to connect to external devices; A data management system, which is connected to several of the aforementioned interfaces, including, A data acquisition and identification module is installed inside the data management system and is connected to several interfaces respectively. It is used to acquire data information from several interfaces and identify the data information. A data storage server, located within the data management system, is used to store data information from the coal preparation plant. A virtual server, which is set up inside the data storage server, is used to store temporary data; A security analysis module, located within the data management system, is used to perform security analysis on temporary data. The control module is located inside the data management system. The control module can coordinate and control the data acquisition and identification module, the data storage server, and the security analysis module. The control module uses the recognition results of the input data by the data acquisition and identification module to allocate the data to different servers for storage or temporary storage, and controls the security analysis module to analyze and detect the data temporarily stored in the virtual server, and finally filter out harmful data, thereby ensuring the security of data information in the data storage server. The control module is configured with a gray list data determination set group Ei, Ei = {Ei 1, S}, where Ei 1 is the gray list set of source addresses for data received by the i-th interface, and S is the set of secure data allowed to be received by the data storage server; for Ei 1, Ei 1 = {Fi 1, Fi 2, ..., Fiz}, where Fi 1 is the first gray list address of the i-th interface, Fi 2 is the second gray list address of the i-th interface, and Fiz is the Z-th gray list address of the i-th interface; for S, S = {D 1, D 2, ..., Dz}, where D 1 is the first type of secure data allowed to be received by the data storage server, D 2 is the second type of secure data allowed to be received by the data storage server, ..., Dz is the Z-th type of secure data allowed to be received by the data storage server; When the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface. If Up∈Ei 1 and The control module determines that the data is unknown security data passed from a graylist address, and then transmits the data to the virtual server. The control module controls the virtual server to open or start unknown security data transmitted by the data acquisition and identification module, and controls the security analysis module to perform security checks on the unknown security data after it has been opened or started. If the security analysis module determines that the unknown security data is secure data, the control module controls the virtual server to transmit the data to the data storage server; If the security analysis module determines that the unknown security data is dangerous data, the control module controls the virtual server to delete the data, and controls the security analysis module to search for data with the same source address in the data storage server and the virtual server, and performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis result is dangerous data; If the security analysis module cannot determine the danger of the unknown security data, the control module determines the unknown security data as suspicious data and controls the virtual server to transfer the suspicious data to the suspicious folder; If the suspicious data needs to be transmitted to the data storage server in the system, the control module will initiate a copy verification procedure. The control module initiates a copy verification program, copies the portion of the suspicious data that needs to be transmitted to the data storage server, and runs the copied data on the virtual server. The security analysis module then performs security checks on the copied data running on the virtual server. If the copied data is dangerous, the control module will delete the copied data in the virtual server and the data in the suspicious folder. If dangerous data appears twice in data sent to the system from the same gray list source address, the control module will change the gray list source address to the black list source address.

2. The intelligent coal preparation plant network security protection system according to claim 1, characterized in that, The virtual server has a suspicious folder inside it. The virtual server can receive suspicious data from the data acquisition and identification module and temporarily store the suspicious data in the suspicious folder. The suspicious folder cannot send out its suspicious information unless it receives a data retrieval instruction from the control module. The security analysis module can analyze suspicious data in suspicious folders and control the data programs in suspicious folders to start running.

3. The intelligent coal preparation plant network security protection system according to claim 1, characterized in that, The control module categorizes data source addresses into whitelist addresses, graylist addresses, and blacklist addresses based on their level of trust. The control module numbers the interfaces as follows: interface A1, interface A2, ..., interface An, where n is an integer greater than 2. For different interfaces, the control module sets different data judgment sets. For the i-th interface, i = 1, 2, ..., n. The control module is configured with a whitelist set Bi of source addresses for receiving data on the i-th interface, where Bi = {Ci 1, Ci2, ..., Ciz}, where Ci 1 is the first whitelist address of the i-th interface, Ci2 is the second whitelist address of the i-th interface, and Ciz is the Z-th whitelist address of the i-th interface; The control module is configured with a blacklist set Gi of source addresses for the data received by the i-th interface, where Gi = {Hi 1,Hi2,...,Hiz}, where Hi 1 is the first blacklist address of the i-th interface, Hi2 is the second blacklist address of the i-th interface, and Hiiz is the Z-th blacklist address of the i-th interface.

4. The intelligent coal preparation plant network security protection system according to claim 3, characterized in that, If Up∈Bi, the control module determines that the data is secure data transmitted from a whitelisted address and transmits the data to the data storage server.

5. The intelligent coal preparation plant network security protection system according to claim 3, characterized in that, When the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface. If Up∈Ei 1 and U∈S, the control module determines that the data is secure data passed from the graylist address and transmits the data to the data storage server.

6. The intelligent coal preparation plant network security protection system according to claim 3, characterized in that, When the i-th interface transmits data, the data acquisition and identification module identifies the source address Up of the data U transmitted through the i-th interface. If Up∈Gi, the control module determines that the data is from a blacklisted address, intercepts the data, and transmits the source address of the data information to the security analysis module. The security analysis module searches for data with the same source address in the data storage server and the virtual server, performs security monitoring and analysis on the data with the same source address, and deletes the data whose analysis results indicate it is dangerous.

7. The intelligent coal preparation plant network security protection system according to claim 6, characterized in that, The control module controls the virtual server to run the information in the suspicious folder, and controls the security analysis module to analyze the data in the suspicious folder. If the suspicious data requires accessing data from the data storage server in the system, the control module will initiate the anti-leakage verification procedure.

8. The intelligent coal preparation plant network security protection system according to claim 7, characterized in that, The control module initiates a leak prevention verification procedure to analyze whether the data to be retrieved for the suspicious data is confidential data from the coal preparation plant. If suspicious data requires access to confidential data from the coal preparation plant, the control module determines that the suspicious data is dangerous data and deletes it. If suspicious data requires access to non-confidential data from the coal preparation plant, the control module retrieves the required data to the suspicious data, controls the security analysis module to analyze the security of the suspicious data after retrieval, and transmits data deemed secure in the suspicious folder to the data storage server, while deleting data in the suspicious folder that cannot be determined to be secure. If the copied data is safe data, the control system will transfer the copied data to the data storage server and delete the data in the suspicious folder.

9. The intelligent coal preparation plant network security protection system according to claim 8, characterized in that, The security analysis module records the data security test results and saves the security test record results to the data storage server; The control module monitors the security test result records in the data storage server and analyzes the source addresses of data identified as dangerous by the security analysis module. If dangerous data appears once in the data sent to the system from the same whitelist source address, the control module will change the whitelist source address to the graylist source address.