Power system network security element distributed data acquisition method and system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGDONG POWER GRID CO LTD
- Filing Date
- 2023-03-02
- Publication Date
- 2026-08-07
AI Technical Summary
[0003]而来自于网络的安全威胁多种多样,要有效地分析这些安全威胁,则必须要将电力系统网络中的各种数据进行采集,然而,这些数据采集由于其种类不同、结构不同,规模不同,会造成数据难以统一分析,通常只能对各种数据分别在各自的系统中进行数据采集后上传,由专业的网络安全分析人员进行解读
Smart Images

Figure CN116319876B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system network security, and in particular to a method and system for distributed data acquisition of power system network security elements. Background Technology
[0002] Traditional power system networks contain various types of data, including operational status and performance data, logs and security events, raw traffic mirror packets, network traffic metadata (Flow), as well as asset information, topology information, configuration information, vulnerability information, user identity information, and threat intelligence information. Furthermore, the data structures of these various types of data differ, including structured, semi-structured, and unstructured data. Their scale also varies, ranging from high-speed data such as performance data, logs, raw traffic, and network traffic metadata to low-speed data such as asset data, topology data, configuration data, vulnerability data, identity data, and threat intelligence data.
[0003] Cybersecurity threats are diverse, and effectively analyzing them requires collecting various data from the power system network. However, due to the differences in data type, structure, and scale, unified analysis is difficult. Typically, data is collected separately from its respective systems and uploaded for interpretation by specialized cybersecurity analysts. However, this method requires a high level of expertise, is inefficient, and is not conducive to quickly identifying security threats within the power system network. Summary of the Invention
[0004] To overcome the problems existing in related technologies, this application provides a distributed data acquisition method and system for network security elements in power systems. It can collect security element data from various data sources in the power system network and conveniently provide the data to requesting nodes for display.
[0005] According to a first aspect of the embodiments of this application, a method for distributed data acquisition of network security elements in a power system is provided, comprising the following steps:
[0006] A scalable distributed data collector is constructed to collect safety element data from data sources distributed in the corresponding areas of the power system network.
[0007] An edge storage device is constructed for the corresponding area to receive security element data collected by the distributed data collector in the corresponding area;
[0008] The received security element data is preprocessed and stored in the edge storage under uniform constraints, and a local security element data data directory index is constructed and uploaded.
[0009] A unified virtual repository is built to receive and store the data directory indexes of edge storage in all regions, and integrates the data directory indexes of edge storage in all regions into a unified data directory index, providing data directory index retrieval services to the outside world.
[0010] Obtain the data request sent by the target request node to the unified virtual repository through the data directory index retrieval service;
[0011] The unified virtual repository responds to the data request, communicates with the edge storage that matches the data request, obtains the security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display.
[0012] According to a second aspect of the embodiments of this application, a distributed data acquisition system for network security elements of a power system is provided, comprising:
[0013] A scalable distributed data acquisition unit is used to collect safety element data from data sources distributed in the corresponding areas of the power system network, and transmit the collected safety element data to the edge storage of the corresponding area.
[0014] Edge storage is used to receive security element data collected by the distributed data collector in the corresponding area, preprocess the received security element data with unified constraints and then store it, and build a local data directory index for security element data, and upload the local data directory index for security element data to a unified virtual repository.
[0015] A unified virtual repository is used to receive and store the data directory indexes of edge storage devices in all regions, and integrate the data directory indexes of edge storage devices in all regions into a unified data directory index, providing a data directory index retrieval service to the outside world; in response to data requests sent by target request nodes through the data directory index retrieval service, it communicates with the edge storage device matching the data request, obtains the security element data corresponding to the data request from the matching edge storage device, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display.
[0016] This application discloses a distributed data acquisition method and system for power system network security elements. It collects security element data from data sources distributed across corresponding areas within the power system network using a scalable distributed data collector. The system stores this security element data using edge storage and constructs a local data catalog index for the security element data. A unified virtual repository receives and stores the data catalog indexes from all edge storage locations and integrates them into a unified data catalog index, providing a data catalog index retrieval service. Therefore, the security element data of the power system network does not need to be stored in a single location, nor does it require a single device to convert and analyze the entire power system network's security element data, while still ensuring the comprehensiveness of the queried data. When a target requesting node requests data, it can send a data request to the unified virtual repository through the data catalog index retrieval service, communicating with the edge storage that matches the data request, without needing to communicate with the corresponding data sources or information collection servers in each area. This physically isolates the query node from the data sources and edge storage, making it more convenient, secure, and reliable. The unified virtual repository retrieves security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the retrieved security element data, and returns the element visualization display page data to the corresponding request node for display, making the data display more intuitive. Moreover, the request node does not need to have analysis and processing capabilities; it only needs to receive the element visualization display page data to display the requested data.
[0017] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application.
[0018] To better understand and implement this invention, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a schematic diagram of the operating environment of the distributed data acquisition method for power system network security elements shown in the embodiments of this application;
[0021] Figure 2 This is a flowchart illustrating a distributed data acquisition method for power system network security elements, as shown in an embodiment of this application.
[0022] Figure 3 This is a schematic diagram of the structure of a distributed data acquisition system for power system network security elements, as shown in an embodiment of this application. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0024] It should be understood that the described embodiments are merely some, not all, of the embodiments in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without inventive effort are within the scope of protection of this application.
[0025] In the following description, when referring to the accompanying drawings, the same numbers in different drawings denote the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0026] In the description of this application, it should be understood that the terms "first," "second," "third," etc., are used only to distinguish similar objects and are not necessarily used to describe a specific order or sequence, nor should they be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances. The singular forms "a," "the," and "the" used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. The word "if" as used herein can be interpreted as "when," "when," or "in response to determination." Furthermore, in the description of this application, unless otherwise stated, "a plurality" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0027] Please see Figure 1 This is a schematic diagram illustrating the application environment of the distributed data acquisition method for power system network security elements shown in the embodiments of this application. Figure 1As shown, the distributed data acquisition method for power system network security elements can be applied to the field of power system network security applications. Its application environment includes a distributed data collector 101, an edge storage device 102, and a unified virtual repository 103. The distributed data collector 101, edge storage device 102, and unified virtual repository 103 communicate and interact via wired or wireless networks.
[0028] The distributed data collector 101 is used to collect security element data from data sources distributed across corresponding areas in the power system network and upload the collected data to the edge storage 102. The distributed data collector 101 has a TCP / IP communication interface and a traffic mirroring interface, which communicate with the data sources to obtain logs, virus, vulnerability, intelligence data, and traffic data, respectively. A communication client program runs on the distributed data collector 101 to communicate with the corresponding edge storage 102 and upload the collected security element data. A communication server program runs on the edge storage 102 to receive security element data uploaded by multiple distributed data collectors 101 and store it in its local data storage.
[0029] The virtual storage 103 communicates with the edge storage devices 102 distributed in various locations. It does not actually store security element data, nor does it communicate directly with the distributed data collector 101 or the data source. The virtual storage 103 provides a unified data directory index retrieval service to various requesting nodes based on the data directory index provided by the edge storage devices 102.
[0030] Example 1
[0031] The following will be combined with the appendix Figure 2 This application provides a detailed description of a distributed data acquisition method for power system network security elements provided in its embodiments.
[0032] Please see Figure 2 This application provides a distributed data acquisition method for power system network security elements, which includes the following steps:
[0033] Step S101: Construct a scalable distributed data acquisition device to collect security element data from data sources distributed in the corresponding areas of the power system network.
[0034] Step S102: Construct an edge storage for the corresponding area to receive security element data collected by the distributed data collector in the corresponding area;
[0035] Step S103: After preprocessing the received security element data with uniform constraints through the edge storage, store it and build a local security element data data directory index, and upload the local security element data data directory index.
[0036] Step S104: Build a unified virtual repository to receive and save the data directory indexes of the edge storage in all regions, and integrate the data directory indexes of the edge storage in all regions into a unified data directory index, and provide data directory index retrieval services to the outside world;
[0037] Step S105: Obtain the data request sent by the target request node to the unified virtual repository through the data directory index retrieval service;
[0038] Step S106: Respond to the data request through the unified virtual repository, communicate with the edge storage that matches the data request, obtain the security element data corresponding to the data request from the matched edge storage, construct element visualization display page data based on the obtained security element data, and return the element visualization display page data to the corresponding request node for display.
[0039] This application discloses a distributed data acquisition method for power system network security elements. It collects security element data from data sources distributed across corresponding areas within the power system network using a scalable distributed data collector. The method stores this security element data through edge storage and constructs a local data directory index for the security element data. A unified virtual repository receives and stores the data directory indexes from all edge storage locations, integrates these indexes into a unified data directory index, and provides a data directory index retrieval service. Therefore, the security element data of the power system network does not need to be stored in a single location, nor does it require a single device to convert and analyze the entire network's security element data, while still ensuring the comprehensiveness of the queried data. When a target requesting node requests data, it can send a data request to the unified virtual repository through the data directory index retrieval service, communicating with the edge storage that matches the data request. This eliminates the need to communicate with the corresponding data sources or information collection servers in each area, physically isolating the query node from the data sources and edge storage, making the process more convenient, secure, and reliable. The unified virtual repository retrieves security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the retrieved security element data, and returns the element visualization display page data to the corresponding request node for display, making the data display more intuitive. Moreover, the request node does not need to have analysis and processing capabilities; it only needs to receive the element visualization display page data to display the requested data.
[0040] For step S101, a scalable distributed data collector is constructed, and the distributed data collector is used to collect security element data from data sources distributed in the corresponding areas of the power system network.
[0041] In one embodiment, the security element data obtained from the power system network includes: log data, virus data, vulnerability data, intelligence data, and traffic data. The distributed data collector can correspondingly construct multiple data collectors, including a log data collector, a virus data collector, a vulnerability data collector, an intelligence data collector, and a traffic data collector. The log data collector, virus data collector, vulnerability data collector, and intelligence data collector all communicate with the data source using a TCP / IP communication interface to obtain log data, virus data, vulnerability data, and intelligence data, respectively. The traffic data collector communicates with the data source through a traffic mirroring interface to obtain traffic data.
[0042] Specifically, the log data collector can communicate with the data source using a TCP / IP communication interface and collect log data from the data source in accordance with the syslog protocol;
[0043] The virus data collector uses a TCP / IP communication interface to communicate with the data source and collects virus data from the antivirus program of the data source.
[0044] The vulnerability data collector uses a TCP / IP communication interface to communicate with the data source and collect vulnerability data from the system security software of the data source.
[0045] The intelligence data collector communicates with the data source using a TCP / IP communication interface and collects intelligence data from the data source's API interface.
[0046] The traffic data collector uses traffic mirroring technology, communicates with the data source through a traffic mirroring port, and uses the SPAN protocol to mirror and collect traffic data.
[0047] Traffic mirroring can mirror packets that pass through an Elastic Network Interface (ENI) and meet certain filtering criteria. It's very convenient to copy network traffic from an instance and then forward the copied traffic to a specified ENI.
[0048] In other embodiments, the security element data obtained from the power system network may further include other types of data related to the security of the power system network, which will not be described in detail here.
[0049] The data sources include, but are not limited to, security equipment systems deployed in key network protection units, private clouds, IDC data centers, and carrier locations. This includes, but is not limited to, various security devices such as website security monitoring systems, antivirus software, firewalls, intrusion detection systems, and APT detection systems; and network devices such as switches, streaming devices, and routers.
[0050] In one embodiment, after the step of collecting security element data from data sources distributed in the corresponding areas of the power system network using the distributed data collector, the method further includes:
[0051] The distributed data collector preprocesses and classifies the collected security element data, dividing it into high-speed data and low-speed data.
[0052] The high-speed data is transmitted to the edge memory via a high-frequency data bus, and the low-speed data is transmitted to the edge memory via a low-frequency data bus.
[0053] If the performance, logs, raw traffic, network traffic metadata, and other data are preprocessed and classified as high-speed data, this part of the data will be transmitted to the edge storage separately through the high-frequency data bus. After receiving the corresponding high-speed data, the edge storage will save it in its local high-speed cache / memory. If the asset, topology, configuration, vulnerability, identity, and intelligence data are preprocessed and classified as low-speed data, this part of the data will be transmitted to the edge storage separately through the low-frequency data bus. After receiving the corresponding low-speed data, the edge storage will save it in its local low-speed cache / memory.
[0054] Step S102: Construct an edge storage for the corresponding area to receive security element data collected by the distributed data collector in the corresponding area.
[0055] The edge storage is deployed at the edge of the system architecture and has certain edge computing and storage capabilities.
[0056] The edge storage can be an edge storage server deployed in the corresponding region, which communicates with the distributed data collector in the corresponding region to obtain uploaded security element data and save it in a local data storage device. The local data storage device is preferably a storage device based on Elasticsearch storage capabilities.
[0057] In the same area, only one edge storage device can be deployed, and one edge storage device can simultaneously acquire security element data uploaded by multiple distributed data collectors.
[0058] In one embodiment, the step of receiving security element data collected by the distributed data collector in the corresponding area includes:
[0059] The system receives security element data encrypted with SSL by the distributed data collector, decrypts it with SSL (Security Socket Layer) and stores it in the local memory of the corresponding edge storage.
[0060] SSL (Security Socket Layer) is a network security protocol. It's a security protocol implemented over the TCP / IP transport protocol, employing public-key cryptography. SSL widely supports various types of networks, and its advantage lies in its independence from application layer protocols. Higher-level application layer protocols, such as HTTP, FTP, and Telnet, can transparently build on top of the SSL protocol. The SSL protocol completes the negotiation of encryption algorithms, communication keys, and server authentication before application layer protocol communication. Afterward, all data transmitted by the application layer protocol is encrypted, thus ensuring the confidentiality of communication.
[0061] For step S103, the received security element data is preprocessed and stored using the edge storage under uniform constraints, and a local security element data data directory index is constructed and uploaded.
[0062] The edge storage performs preprocessing on the received security element data under uniform constraints, including standardization and filtering, merging, and multi-dimensional deduplication.
[0063] In one embodiment, the received security element data is standardized and filtered using a unified data dictionary through the edge storage, and the received security element data is merged and multi-dimensional deduplication is performed using a unified merging condition, wherein the data storage structure, data fields, and data dictionary of each edge storage are kept consistent.
[0064] In a single system, multiple edge storage devices can be deployed based on multiple edge nodes. The security element data of the entire system are stored in various distributed edge storage devices. The storage structure, fields, and data dictionary of each edge storage device are consistent. Therefore, there is no need for data aggregation or centralized storage.
[0065] After the edge storage device standardizes, filters, merges, and performs multi-factor deduplication on the different types and structures of security element data collected by each distributed data collector under unified constraints, the security element data stored in the local data storage of the edge storage device will be saved in a unified format, thereby facilitating retrieval and the construction of a unified data catalog index.
[0066] The edge storage constructs a local data directory index for security element data. The directory index conforms to the requirements of a unified index template, so that after the edge storage uploads the local data directory index, the unified virtual repository can obtain a unified data directory index.
[0067] For step S104, a unified virtual repository is constructed to receive and save the data directory indexes of the edge storage in all regions, and integrates the data directory indexes of the edge storage in all regions into a unified data directory index, providing data directory index retrieval services to the outside world.
[0068] The unified virtual repository, similar to a data indexer, does not store data itself, but can be shared and retrieved from all edge storage.
[0069] The unified virtual repository establishes a data directory index consistent with the edge storage of the entire network, namely the unified data directory index. Through the unified data directory index, the real data in each storage can be queried, and the data is not stored on the ground.
[0070] The unified virtual repository can publish a data directory index retrieval service. Requesting nodes that need to consume or use data can access the unified virtual repository through the data directory index retrieval service and submit data requests to the unified virtual repository.
[0071] For step S105, obtain the data request sent by the target request node to the unified virtual repository through the data directory index retrieval service.
[0072] There are many types of target request nodes, which can be used to retrieve relevant security element data, or for information display, etc. Various target request nodes can access the unified virtual repository through the data directory index retrieval service and submit data requests to the unified virtual repository, such as data display requests, data query requests, etc.
[0073] Based on the source and type of security element data, the target request node can be assigned permissions and domains, that is, different data access subscription permissions can be divided according to its authority and region, thus realizing the "tenancy" of data.
[0074] For step S106, the unified virtual repository responds to the data request, communicates with the edge storage that matches the data request, obtains the security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display.
[0075] The unified virtual repository responds to the data request by communicating with the corresponding edge storage through the data directory index provided by the edge storage that matches the data request, and directly retrieves the relevant data from the data directory index in the source repository.
[0076] When constructing the data for the element visualization display page, a unified element visualization display page model can be pre-constructed, and the acquired security element data can be filled into the unified element visualization display page model to generate the element visualization display page data.
[0077] Since the front-end display page and the source database of the data are not connected during the display of the target request node, security issues can be ensured, and there is no risk of credential stuffing through front-end vulnerabilities.
[0078] In specific settings, based on the ownership of the data assets corresponding to the security element data, different data owners can be granted corresponding data viewing permissions to prevent unauthorized access to data beyond their access rights and further ensure system security.
[0079] Furthermore, after preprocessing and storing the received security element data under uniform constraints through the edge memory, the following steps may also be included:
[0080] Big data analysis is performed on the stored security element data through edge storage, and the analysis results are generated and stored in the corresponding edge storage data storage.
[0081] Furthermore, a data catalog index of the analysis results can be constructed and uploaded to the unified virtual repository to update the unified data catalog index, so that the unified data catalog index contains the index of the analysis results.
[0082] Through the collection of security element data and big data analysis oriented towards situational awareness, the perception presentation layer of the unified virtual repository outputs specific security element analysis results to users. This process extensively utilizes visualization technology, drill-down models, and multi-tenant modes to form an intuitive, efficient, accurate, and flexible data presentation.
[0083] When conducting security element data analysis, it can be mainly divided into two parts: the analysis of website security posture and the analysis of the network security posture of key units.
[0084] When constructing the visualization display page data for the aforementioned elements, the unified virtual repository can employ visualization techniques such as situation maps, security situation trends, threat distribution, regional comparisons, detailed drill-downs, and analysis and early warning.
[0085] Furthermore, the unified virtual repository can generate security posture portal analysis data for key units according to different needs, and can provide security data monitoring corresponding to the unit's sites and asset scope for key units with security monitoring needs.
[0086] Example 2
[0087] As another embodiment of this application, a distributed data acquisition system for network security elements of a power system is provided.
[0088] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a distributed data acquisition system for power system network security elements according to this application. The distributed data acquisition system for power system network security elements includes:
[0089] The scalable distributed data acquisition unit 301 is used to acquire safety element data from data sources distributed in the corresponding area of the power system network, and transmit the acquired safety element data to the edge storage of the corresponding area.
[0090] Edge storage 302 is used to receive security element data collected by the distributed data collector in the corresponding area, preprocess the received security element data with unified constraints and then store it, build a local security element data data directory index, and upload the local security element data data directory index to a unified virtual repository.
[0091] The unified virtual repository 303 is used to receive and store the data directory indexes of edge storage in all regions, and integrate the data directory indexes of edge storage in all regions into a unified data directory index, providing a data directory index retrieval service to the outside world; in response to the data request sent by the target request node through the data directory index retrieval service, it communicates with the edge storage that matches the data request, obtains the security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display.
[0092] It should be noted that Embodiment 2 described above is an apparatus embodiment of this application and can be used to execute the method in Embodiment 1 of this application. For details not disclosed in the apparatus embodiments of this application, please refer to the method embodiments of this application.
[0093] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0094] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function selected in one or more boxes.
[0095] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function selected in one or more boxes.
[0096] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0097] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0098] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0099] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0100] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A method for distributed data acquisition of network security elements in a power system, characterized in that, Includes the following steps: A scalable distributed data collector is constructed to collect safety element data from data sources distributed in the corresponding areas of the power system network. An edge storage device is constructed for the corresponding area to receive security element data collected by the distributed data collector in the corresponding area; The received security element data is preprocessed and stored in the edge storage under uniform constraints, and a local security element data data directory index is constructed and uploaded. A unified virtual repository is built to receive and store the data directory indexes of edge storage in all regions, and integrates the data directory indexes of edge storage in all regions into a unified data directory index, providing data directory index retrieval services to the outside world. Obtain the data request sent by the target request node to the unified virtual repository through the data directory index retrieval service; The unified virtual repository responds to the data request, communicates with the edge storage that matches the data request, obtains security element data corresponding to the data request from the matched edge storage, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display. The step of preprocessing the received security element data under uniform constraints using the edge memory includes: The edge storage uses a unified data dictionary to standardize and filter the received security element data, and employs a unified merging condition to merge and perform multi-dimensional deduplication calculations on the received security element data. The data storage structure, data fields, and data dictionary of each edge storage are kept consistent.
2. The distributed data acquisition method for power system network security elements according to claim 1, characterized in that, The security data of the power system network includes: log data, virus data, vulnerability data, intelligence data, and traffic data; The distributed data collector includes a log data collector, a virus data collector, a vulnerability data collector, an intelligence data collector, and a traffic data collector; wherein, the log data collector, virus data collector, vulnerability data collector, and intelligence data collector all communicate with the data source using a TCP / IP communication interface, and the traffic data collector obtains traffic data by communicating with the data source through a traffic mirroring interface.
3. The distributed data acquisition method for power system network security elements according to claim 1, characterized in that, After the step of collecting security element data from data sources distributed in the corresponding areas of the power system network using the distributed data collector, the method further includes: The distributed data collector preprocesses and classifies the collected security element data, dividing it into high-speed data and low-speed data. The high-speed data is transmitted to the edge memory via a high-frequency data bus, and the low-speed data is transmitted to the edge memory via a low-frequency data bus.
4. The distributed data acquisition method for power system network security elements according to claim 1, characterized in that, The steps for receiving security element data collected by the distributed data collector in the corresponding area include: The system receives secure element data encrypted with SSL by the distributed data collector, decrypts it with SSL, and stores it in the local memory of the corresponding edge storage.
5. The distributed data acquisition method for power system network security elements according to claim 1, characterized in that, The steps for constructing the element visualization display page data based on the acquired security element data include: The acquired security element data is then input into a unified element visualization display page model to generate element visualization display page data.
6. The distributed data acquisition method for power system network security elements according to any one of claims 1 to 5, characterized in that, After the received security element data is preprocessed and stored using the edge memory under uniform constraints, the process further includes: Build distributed computing node processors to perform big data analysis on the stored security element data, generate analysis results, and save them in the corresponding edge storage.
7. A distributed data acquisition system for network security elements in a power system, characterized in that, include: A scalable distributed data acquisition unit is used to collect safety element data from data sources distributed in the corresponding areas of the power system network, and transmit the collected safety element data to the edge storage of the corresponding area. An edge storage device is used to receive security element data collected by the distributed data collector in the corresponding area, preprocess the received security element data under unified constraints, store it, and build a local data directory index for the security element data. The local data directory index for the security element data is then uploaded to a unified virtual repository. The step of preprocessing and storing the received security element data under unified constraints using the edge storage device includes: The received security element data is standardized and filtered using a unified data dictionary through the edge storage, and merged and deduplicated using unified merging conditions. The data storage structure, data fields, and data dictionary of each edge storage device remain consistent. A unified virtual repository is used to receive and store the data directory indexes of edge storage devices in all regions, and integrate the data directory indexes of edge storage devices in all regions into a unified data directory index, providing a data directory index retrieval service to the outside world; in response to data requests sent by target request nodes through the data directory index retrieval service, it communicates with the edge storage device matching the data request, obtains the security element data corresponding to the data request from the matching edge storage device, constructs element visualization display page data based on the obtained security element data, and returns the element visualization display page data to the corresponding request node for display.
Citation Information
Patent Citations
Data dynamic processing method based on distributed storage
CN111611222A
Distributed log processing method, device and system, equipment and medium
CN112231296A