Integrated security management method and system for power infrastructure
Patent Information
- Application Number
- CN202310798746.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-02
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2043-07-02
AI Technical Summary
[0003]本申请通过提供了用于电力基础设施的一体化安全管控方法及系统,旨在解决现有技术中存在对于电力基础设施遭受的攻击不能精准识别并快速响应,导致系统安全性、稳定性差的技术问题
[0008] This system acquires target power infrastructure information, formulates security strategies, identifies key network boundaries and service domains based on the power system topology, deploys corresponding security devices at these boundaries and domains, and links these devices through an integrated security management platform. Triggering conditions and response measures are established, creating a linkage mechanism for real-time monitoring of device status. A security event detection model is used to analyze the real-time monitoring results. When malicious behavior is detected, the linkage mechanism is triggered, generating a security event response command for emergency response. This addresses the technical problem in existing technologies where attacks on power infrastructure cannot be accurately identified and responded to quickly, leading to poor system security and stability. It achieves real-time monitoring of power infrastructure, and the established linkage rules and security event detection model can automatically trigger the linkage mechanism and generate corresponding security event response commands, achieving automated response and handling. This enhances system stability and reliability, ensuring the normal operation of power infrastructure.
Smart Images

Figure CN116996264B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power infrastructure technology, and more specifically to an integrated safety management and control method and system for power infrastructure. Background Technology
[0002] With the rapid development of informatization and networking, power infrastructure is gradually transforming towards digitalization and intelligence. However, this also brings more security risks and threats. In particular, with the widespread application of technologies such as the Internet, the Internet of Things, and cloud computing, power infrastructure faces increasing security problems such as cyberattacks, vulnerability exploitation, and data breaches. To ensure the safe operation of power infrastructure, corresponding security management measures are needed. However, the commonly used security management methods for power infrastructure still have certain drawbacks, and there is still room for improvement in the security management of power infrastructure. Summary of the Invention
[0003] This application provides an integrated security management method and system for power infrastructure, aiming to solve the technical problem in the prior art that the attack on power infrastructure cannot be accurately identified and responded to quickly, resulting in poor system security and stability.
[0004] In view of the above problems, this application provides an integrated security management method and system for power infrastructure.
[0005] The first aspect disclosed in this application provides an integrated security management and control method for power infrastructure. The method includes: acquiring target power infrastructure information and formulating a security strategy; determining major network boundaries and service domains based on the power system topology according to the security strategy; deploying corresponding security devices for the major network boundaries and service domains according to the topology plan; linking the major network boundaries, service domains, and security devices through the integrated security management and control platform, establishing triggering conditions and response measures, and establishing a linkage mechanism; performing real-time monitoring of device status based on the linkage results, and detecting the real-time monitoring results through a security event detection model; and triggering the linkage mechanism when malicious behavior is detected, generating a security event response command, and performing emergency response through the security event response command.
[0006] Another aspect of this application discloses an integrated security management and control system for power infrastructure. The system includes: a security policy acquisition module for acquiring target power infrastructure information and formulating security policies; a service domain acquisition module for determining major network boundaries and service domains based on the security policies and the power system topology; a security device deployment module for deploying corresponding security devices to the major network boundaries and service domains according to topology planning; a linkage mechanism establishment module for linking the major network boundaries, service domains, and security devices through the integrated security management and control platform, establishing triggering conditions and response measures, and establishing a linkage mechanism; a device status monitoring module for real-time monitoring of device status based on linkage results and detecting the real-time monitoring results through a security event detection model; and an emergency response module for triggering the linkage mechanism, generating a security event response command, and performing emergency response when malicious behavior is detected.
[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0008] This system acquires target power infrastructure information, formulates security strategies, identifies key network boundaries and service domains based on the power system topology, deploys corresponding security devices at these boundaries and domains, and links these devices through an integrated security management platform. Triggering conditions and response measures are established, creating a linkage mechanism for real-time monitoring of device status. A security event detection model is used to analyze the real-time monitoring results. When malicious behavior is detected, the linkage mechanism is triggered, generating a security event response command for emergency response. This addresses the technical problem in existing technologies where attacks on power infrastructure cannot be accurately identified and responded to quickly, leading to poor system security and stability. It achieves real-time monitoring of power infrastructure, and the established linkage rules and security event detection model can automatically trigger the linkage mechanism and generate corresponding security event response commands, achieving automated response and handling. This enhances system stability and reliability, ensuring the normal operation of power infrastructure.
[0009] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0010] Figure 1 This application provides a schematic flowchart of an integrated security management and control method for power infrastructure.
[0011] Figure 2 This application provides a schematic diagram illustrating a possible process for formulating security strategies in an integrated security management and control method for power infrastructure.
[0012] Figure 3 This application provides a schematic diagram of a possible structure for an integrated security management and control system for power infrastructure.
[0013] Explanation of reference numerals in the attached diagram: Security policy acquisition module 10, business domain acquisition module 20, security device deployment module 30, linkage mechanism establishment module 40, device status monitoring module 50, emergency response module 60. Detailed Implementation
[0014] This application provides an integrated security management and control method for power infrastructure, which solves the technical problem in the prior art that the attack on power infrastructure cannot be accurately identified and responded to quickly, resulting in poor system security and stability. It realizes real-time monitoring of power infrastructure, and establishes linkage rules and security event detection models, which can automatically trigger linkage mechanisms and generate corresponding security event response instructions to achieve automated response and handling, thereby enhancing the stability and reliability of the system and ensuring the normal operation of power infrastructure.
[0015] After introducing the basic principles of this application, various non-limiting embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0016] Example 1
[0017] like Figure 1 As shown in the embodiments of this application, an integrated security management and control method for power infrastructure is provided, the method comprising:
[0018] Step S100: Obtain information on the target power infrastructure and formulate a security strategy;
[0019] Specifically, the integrated security management and control method for power infrastructure provided in this application embodiment is applied to an integrated security management and control platform, which is used for integrated security management and control of power infrastructure.
[0020] Furthermore, such as Figure 2 As shown, step S100 of this application further includes:
[0021] Step S110: Collect basic datasets of the target power infrastructure, including architecture, risk assessment, and security requirements;
[0022] Step S120: Extract features from the basic dataset to obtain basic features;
[0023] Step S130: Train a decision tree using the basic dataset and use the basic features as nodes of the decision tree, wherein each branch represents the possible values of the feature and the leaf node represents a safety policy;
[0024] Step S140: Develop a security strategy using the decision tree.
[0025] Specifically, this involves determining the architecture and components of the power infrastructure, including information such as the structure of the power system, network topology, and equipment configuration, and collecting data through various means, such as network scanning, asset inventory, vulnerability scanning, and log analysis.
[0026] The collected data is classified and identified to determine its category and attributes. Based on the actual situation, appropriate features are selected for analysis and extraction. For example, network topology, device configuration, and vulnerability information can be selected as features. The selected features are standardized and transformed, and representative and important features are extracted from the processed features for subsequent modeling and analysis.
[0027] A decision tree is a machine learning algorithm that performs decision analysis and prediction based on a tree structure. In a decision tree model, each internal node represents a feature or attribute, each branch represents different values of that feature, and each leaf node represents a target classification or regression result.
[0028] Based on the feature selection results, a suitable decision tree algorithm is chosen for training. The extracted basic features serve as nodes in the decision tree, each branch represents the possible values of that feature, and the leaf nodes represent a security policy. The trained decision tree model can be used to assess and monitor the security status of power infrastructure and formulate corresponding security policies. Specifically, based on the security policy corresponding to each leaf node, the security policy typically includes aspects such as target protection, threat prevention, attack detection, and vulnerability remediation.
[0029] By establishing a power infrastructure safety assessment and monitoring system based on decision tree models, more effective technical support and guidance can be provided for the safety assurance of the power system.
[0030] Step S200: Based on the security policy and the topology of the power system, determine the main network boundaries and service domains;
[0031] Specifically, a power system comprises multiple subsystems and devices, which have complex relationships and dependencies. Various data related to the power system are collected, including network topology, device configuration, and vulnerability information. Topology analysis methods are used to analyze and study the power system's topology, determining the relationships and dependencies between subsystems. Based on the topology analysis results, the power system's network boundaries are defined. According to the topology and security policy requirements, the power system is divided into internal and external networks, and the main network boundaries are determined. Based on the power system's functions and characteristics, different types of services are divided into different business domains, each with clearly defined security protection strategies and control measures.
[0032] Step S300: Based on the topology plan, deploy corresponding security devices for the main network boundaries and service domains;
[0033] Furthermore, step S300 of this application also includes:
[0034] Step S310: Establish multiple boundary deployment schemes for the main network boundaries;
[0035] Step S320: Establish multiple business domain deployment schemes for the aforementioned business domains;
[0036] Step S330: Randomly combine the multiple boundary deployment schemes with the multiple business domain deployment schemes to obtain multiple deployment schemes;
[0037] Step S340: Evaluate the multiple deployment schemes and select the deployment scheme with the highest adaptability as the optimal scheme;
[0038] Step S350: Deploy the security equipment based on the optimal solution.
[0039] Specifically, the security requirements of the power system are clarified based on the topology planning, including protection targets, threat prevention, attack detection, and vulnerability remediation. Multiple boundary deployment schemes and multiple business domain deployment schemes are established for major network boundaries and business domains respectively to meet different security needs and actual situations. Boundary deployment schemes involve the combination and configuration of security devices such as firewalls, intrusion detection systems, and virtual private networks. When developing boundary deployment schemes, factors such as topology, attack threats, and business types need to be considered. Business domain deployment schemes involve the formulation and implementation of security policies such as access control, authentication, and data encryption. When developing business domain deployment schemes, factors such as business type, data sensitivity, and security requirements need to be considered.
[0040] Multiple boundary deployment schemes and multiple business domain deployment schemes are combined in pairs. For each combination scheme, random combinations can be made according to different weight parameters to generate more deployment schemes. For example, a genetic algorithm can be used for random combination to increase the number of feasible schemes, thereby improving the accuracy of subsequent evaluation and selection of the optimal scheme.
[0041] Establish a set of evaluation metrics, including security, equipment performance, scalability, and cost. Based on these metrics, evaluate all deployment schemes and calculate a score for each. Select the scheme with the highest adaptability as the optimal scheme and save it for subsequent security equipment deployment. Determine the types and quantities of security equipment for the boundaries and business domains based on the optimal scheme, and formulate deployment plans for these security equipment, including equipment location, configuration, and parameter settings. Install and configure the security equipment, and conduct testing and verification. In this way, select the scheme with the highest adaptability from multiple deployment schemes as the optimal scheme to ensure the security and reliability of the power system.
[0042] Furthermore, the formula for calculating fitness in step S340 of this application is as follows:
[0043] k i =w1O i +w2P i +w3Q i
[0044] Where, k i For the fitness of the i-th deployment scheme, O i Let w1 be the security score for the i-th deployment scheme, and P be the weight of the security score. i Let w2 be the device performance score in the i-th deployment scheme, and Q be the weight of the device performance score. i Let w1 be the cost score in the i-th deployment scheme, w3 be the weight of the cost score, and the sum of w1, w2, and w3 is 1.
[0045] Step S400: Through the integrated security management and control platform, link the main network boundary, the business domain and the security device, and establish triggering conditions and response measures to establish a linkage mechanism;
[0046] Specifically, in order to realize the linkage between core network boundaries, service domains and security devices, an integrated security management and control platform needs to be established first. The platform can integrate various security devices and systems, including firewalls, intrusion detection systems, security monitoring systems, etc. The trigger conditions for different events or threats and corresponding response measures are defined, wherein the trigger conditions are related to security policies, such as suspicious traffic, attack behaviors, vulnerability exploitation, etc.; the response measures involve specific security devices and operations, such as blocking IP addresses, closing ports, sending alarm notifications, etc.
[0047] Corresponding linkage rules are formulated according to the event trigger conditions and response measures. For example, the linkage rules are set as "if..., then..." statements, linkage parameters such as linkage rules, trigger conditions, and response measures are configured on the integrated security management and control platform, and the linkage mechanism is tested and verified to ensure its normal operation. After the linkage mechanism is established, the security devices in the core network boundaries and service domains are linked. Specifically, all security devices are connected to the integrated security management and control platform, and the linkage relationship between the security devices is configured according to the established linkage rules. For example, when an intrusion detection system detects an attack behavior, the firewall automatically blocks the relevant IP address.
[0048] Through the above steps, the linkage between core network boundaries, service domains and security devices can be realized, trigger conditions, response measures and the linkage mechanism can be established, which can greatly improve the safety and reliability of the power system, and provide more comprehensive safety protection measures and technical support for system managers.
[0049] Further, after step S400 of the present application, the following steps are further included:
[0050] Step S400-1: defining a state space, an action space and a reward function;
[0051] Step S400-2: establishing a security management and control model based on a deep reinforcement learning algorithm;
[0052] Step S400-3: simulating security events to generate different state sequences, training the security management and control model through the state sequences, and performing security management and control on power infrastructure through the security management and control model.
[0053] Specifically, the state space is a set of variables describing system states, the action space is a set of operations available for the system to execute, and the reward function is a function for evaluating whether an action is good or bad. A deep reinforcement learning algorithm, such as deep Q-learning, is used to establish a security management and control model, which can predict the optimal action for the next step according to the current system state and available actions, and update the parameters of the model by comparing with the actual reward function.
[0054] After establishing the security management model, one or more security event types, such as network attacks and intrusion detection, are selected. Based on the selected event types, a series of different state sequences are generated, and the optimal action and corresponding reward function for each state are recorded. Using the established deep reinforcement learning algorithm, these state sequences are trained to update the parameters of the security management model. The trained model is then deployed to an integrated security management platform for the security management of power infrastructure. Furthermore, by simulating security events to train the model, the optimal action for the next step can be predicted more accurately, thus enabling more accurate security management of power infrastructure.
[0055] Step S500: Real-time monitoring of equipment status is performed based on the linkage results, and the real-time monitoring results are detected using a security event detection model;
[0056] Specifically, by collecting log files generated by the device, the operating status of the device can be monitored in real time. For example, by monitoring the device's performance indicators such as CPU utilization, memory utilization, and bandwidth utilization, it can be determined whether the device is experiencing any abnormalities. By using methods such as ping commands, the connectivity of the device can be monitored, and network faults can be detected.
[0057] Historical equipment operating status data is used as training data for the model. This data is processed and analyzed, and a safety event detection model is built based on neural networks. This model can predict whether the equipment will experience abnormal behavior in the future, based on historical data and linkage rules. The integrated safety management platform monitors the equipment status in real time, and the monitoring data is input into the safety event detection model. The model analyzes the monitoring data according to linkage rules and historical data to determine whether the equipment is experiencing abnormal behavior. If an abnormality is detected, the integrated safety management platform will promptly send an alarm notification.
[0058] Step S600: When malicious behavior is detected, the linkage mechanism is triggered to generate a security event response command, and emergency response is carried out through the security event response command.
[0059] Specifically, a security incident detection model is used to detect real-time monitoring results. If malicious behavior is detected, a linkage mechanism needs to be triggered promptly, generating a corresponding security incident response instruction. This instruction includes an incident description, problem localization, emergency measures, and an incident response plan. The incident description details the detected malicious behavior or security incident; problem localization identifies the source and scope of the problem, as well as the affected systems and devices; emergency measures outline corresponding measures, such as service shutdown, network disconnection, and IP address blocking; and the incident response plan defines the response time, task allocation, and relevant resource requirements. After generating the security incident response instruction, corresponding emergency response measures are implemented.
[0060] Furthermore, this application also includes:
[0061] Step S710: Retrieve the emergency response log;
[0062] Step S720: Perform system vulnerability analysis based on the emergency response log, and update patches based on the analysis results;
[0063] Step S730: Continuously monitor the power system according to the patch.
[0064] Specifically, after an emergency response is carried out on a safety incident in a power infrastructure, it is necessary to retrieve the emergency response log in order to further understand and analyze the incident. The emergency response log can record all information related to the emergency response, such as time, location, personnel, and measures.
[0065] By analyzing emergency response logs, we can further understand the source and scope of security incidents, and determine the location and type of security vulnerabilities. Based on the analysis results, we can formulate corresponding solutions, such as updating patches, fixing vulnerabilities, and strengthening network security. After patching, to ensure the long-term safe operation of power infrastructure, continuous monitoring is required to promptly identify existing security vulnerabilities. Based on the monitoring results, all vulnerabilities in the power infrastructure should be classified and addressed, and the corresponding patches should be updated in a timely manner.
[0066] By following the steps above, security vulnerabilities in power infrastructure can be analyzed and repaired, and the long-term safe operation of the system can be ensured through continuous monitoring.
[0067] In summary, the integrated safety management and control method and system for power infrastructure provided in this application have the following technical effects:
[0068] The system acquires target power infrastructure information, formulates security strategies, identifies major network boundaries and business domains based on the power system topology, deploys corresponding security devices at these boundaries and domains, and links these devices through an integrated security management platform. It also establishes triggering conditions and response measures, creates a linkage mechanism, and performs real-time monitoring of device status. A security event detection model is used to analyze the real-time monitoring results. When malicious behavior is detected, the linkage mechanism is triggered, generating a security event response command for emergency response.
[0069] This invention addresses the technical problem in existing technologies where attacks on power infrastructure cannot be accurately identified and responded to quickly, leading to poor system security and stability. It achieves real-time monitoring of power infrastructure and establishes linkage rules and a security event detection model, which can automatically trigger linkage mechanisms and generate corresponding security event response commands. This achieves automated response and handling, thereby enhancing system stability and reliability and ensuring the normal operation of power infrastructure.
[0070] Example 2
[0071] Based on the same inventive concept as the integrated security management and control method for power infrastructure in the foregoing embodiments, such as Figure 3 As shown, this application provides an integrated security management and control system for power infrastructure, comprising an integrated security management and control platform, the system including:
[0072] Security policy acquisition module 10, which is used to acquire target power infrastructure information and formulate security policies;
[0073] The service domain acquisition module 20 is used to determine the main network boundaries and service domains based on the power system topology according to the security policy.
[0074] Security device deployment module 30, which is used to deploy corresponding security devices to the main network boundaries and service domains according to the topology plan;
[0075] Linkage mechanism establishment module 40 is used to link the main network boundary, the business domain and the security device through the integrated security management and control platform, and establish triggering conditions and response measures to establish a linkage mechanism.
[0076] The equipment status monitoring module 50 is used to monitor the equipment status in real time based on the linkage results, and to detect the real-time monitoring results through a safety event detection model.
[0077] Emergency response module 60 is used to trigger the linkage mechanism when malicious behavior is detected, generate a security event response command, and carry out emergency response through the security event response command.
[0078] Furthermore, the system also includes:
[0079] The basic data acquisition module is used to collect basic datasets of the target power infrastructure, including architecture, risk assessment, and security requirements.
[0080] The feature extraction module is used to extract features from the basic dataset to obtain basic features;
[0081] The decision tree training module is used to train a decision tree using the base dataset and to use the base features as nodes of the decision tree, wherein each branch represents the possible values of the feature and the leaf node represents a safety policy.
[0082] The security policy formulation module is used to formulate security policies through the decision tree.
[0083] Furthermore, the system also includes:
[0084] The boundary deployment scheme establishment module is used to establish multiple boundary deployment schemes for the main network boundaries;
[0085] The business domain deployment module is used to create multiple business domain deployment schemes for the business domain.
[0086] The random combination module is used to randomly combine the multiple boundary deployment schemes with the multiple business domain deployment schemes to obtain multiple deployment schemes;
[0087] The deployment scheme evaluation module is used to evaluate the multiple deployment schemes and select the deployment scheme with the highest adaptability as the optimal scheme.
[0088] The security equipment deployment module is used to deploy the security equipment based on the optimal solution.
[0089] Furthermore, the formula for calculating the fitness is as follows:
[0090] k i =w1O i +w2P i +w3Q i
[0091] Where, k i For the fitness of the i-th deployment scheme, O i Let w1 be the security score for the i-th deployment scheme, and P be the weight of the security score. i Let w2 be the device performance score in the i-th deployment scheme, and Q be the weight of the device performance score. i Let w1 be the cost score in the i-th deployment scheme, w3 be the weight of the cost score, and the sum of w1, w2, and w3 is 1.
[0092] Furthermore, the system also includes:
[0093] The reward function definition module is used to define the state space, action space, and reward function;
[0094] The security management model building module is used to build security management models based on deep reinforcement learning algorithms.
[0095] The safety management module is used to simulate safety events, generate different state sequences, train the safety management model using the state sequences, and perform safety management of power infrastructure using the safety management model.
[0096] Furthermore, the system also includes:
[0097] The log retrieval module is used to retrieve emergency response logs;
[0098] The vulnerability analysis module is used to perform system vulnerability analysis based on the emergency response logs and update patches based on the analysis results;
[0099] A continuous monitoring module is used to continuously monitor the power system according to the patch.
[0100] Through the foregoing detailed description of the integrated security management and control method for power infrastructure, those skilled in the art can clearly understand the integrated security management and control method and system for power infrastructure in this embodiment. As for the apparatus disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and relevant parts can be referred to the method section.
[0101] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An integrated safety management and control method for power infrastructure, characterized in that, The method includes: Acquire information about the target power infrastructure and formulate security strategies; This includes developing security strategies, including: Collect basic datasets of the target power infrastructure, including architecture, risk assessment, and security requirements; Feature extraction is performed on the basic dataset to obtain basic features; A decision tree is trained using the aforementioned basic dataset, and the basic features are used as nodes in the decision tree. Each branch represents the possible values of the feature, and each leaf node represents a safety policy. Security strategies are formulated using the decision tree. Based on the security policy, the main network boundaries and service domains are determined according to the power system topology. Based on the topology plan, deploy corresponding security devices at the main network boundaries and service domains; According to the topology plan, corresponding security devices are deployed at the main network boundaries and service domains, including: For the aforementioned main network boundaries, multiple boundary deployment schemes are established; For the aforementioned business domains, establish multiple business domain deployment schemes; The multiple boundary deployment schemes and the multiple business domain deployment schemes are randomly combined to obtain multiple deployment schemes; The multiple deployment schemes are evaluated, and the deployment scheme with the highest adaptability is selected as the optimal scheme; The security equipment shall be deployed based on the optimal solution described above. The integrated security management platform links the main network boundary, the business domain, and the security devices, and establishes triggering conditions and response measures to create a linkage mechanism. After establishing the linkage mechanism, it also includes: Define the state space, action space, and reward function; A security management model is established based on deep reinforcement learning algorithms. Simulate safety events to generate different state sequences, train the safety management model using the state sequences, and use the safety management model to manage the safety of power infrastructure. Based on the linkage results, the equipment status is monitored in real time, and the real-time monitoring results are detected by a security event detection model; When malicious behavior is detected, the linkage mechanism is triggered to generate a security incident response command, and emergency response is carried out through the security incident response command.
2. The method as described in claim 1, characterized in that, The formula for calculating fitness is as follows: in, Let i be the fitness of the i-th deployment scheme. The security score for the i-th deployment scheme. As the weight of the security score, Score the device performance in the i-th deployment scheme. The weighting of equipment performance scores For the cost score of the i-th deployment scheme, As the weight for cost scoring, , , The sum of is 1.
3. The method as described in claim 1, characterized in that, Also includes: Retrieve emergency response logs; Based on the emergency response log, perform system vulnerability analysis and update patches according to the analysis results; The power system is continuously monitored according to the patch.
4. An integrated safety management and control system for power infrastructure, characterized in that, An integrated security management and control method for power infrastructure as described in any one of claims 1-3, comprising an integrated security management and control platform, including: A security policy acquisition module is used to acquire target power infrastructure information and formulate security policies. This includes developing security strategies, including: Collect basic datasets of the target power infrastructure, including architecture, risk assessment, and security requirements; Feature extraction is performed on the basic dataset to obtain basic features; A decision tree is trained using the aforementioned basic dataset, and the basic features are used as nodes in the decision tree. Each branch represents the possible values of the feature, and each leaf node represents a safety policy. Security strategies are formulated using the decision tree. A service domain acquisition module is used to determine the main network boundaries and service domains based on the power system topology according to the security policy. A security device deployment module is used to deploy corresponding security devices to the main network boundaries and service domains according to the topology plan. According to the topology plan, corresponding security devices are deployed at the main network boundaries and service domains, including: For the aforementioned main network boundaries, multiple boundary deployment schemes are established; For the aforementioned business domains, establish multiple business domain deployment schemes; The multiple boundary deployment schemes and the multiple business domain deployment schemes are randomly combined to obtain multiple deployment schemes; The multiple deployment schemes are evaluated, and the deployment scheme with the highest adaptability is selected as the optimal scheme; The security equipment shall be deployed based on the optimal solution described above. The linkage mechanism establishment module is used to link the main network boundary, the business domain and the security device through the integrated security management and control platform, and to establish triggering conditions and response measures to establish a linkage mechanism. After establishing the linkage mechanism, it also includes: Define the state space, action space, and reward function; A security management model is established based on deep reinforcement learning algorithms; Simulate safety events to generate different state sequences, train the safety management model using the state sequences, and use the safety management model to manage the safety of power infrastructure. The equipment status monitoring module is used to monitor the equipment status in real time based on the linkage results, and to detect the real-time monitoring results through a safety event detection model. An emergency response module is included, which is used to trigger the linkage mechanism when malicious behavior is detected, generate a security incident response command, and perform emergency response through the security incident response command.
Citation Information
Patent Citations
On-line intelligent system for safety emergency based on multiple communication networks and sensing equipment
CN104852992A
Network security protection security method and system based on unit cell
CN114978584A