A Power Grid Industrial Control Protocol Vulnerability Mining System Using Fuzz Testing

Through the combination of the fuzzy testing engine and the integrated script tool group, the problems of incomplete testing coverage and insufficient vulnerability detection in the exploitation of the power grid industrial control protocol are solved, and in-depth analysis of the power grid industrial control protocol and automated vulnerability handling are realized, and the safety and stability of the power system are improved.

CN117640199BActive Publication Date: 2025-07-11STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311609450.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-29
Publication Date
2025-07-11
Estimated Expiration
2043-11-29

AI Technical Summary

Technical Problem

Existing fuzzy testing cannot guarantee that the test cases cover all situations in the exploitation of vulnerabilities of the power grid industrial control protocol. The vulnerabilities were not effectively detected after preliminary scans, and there was a lack of secondary response and accurate vulnerability reports.

Method used

The fuzzy testing engine is used to combine multiple integrated script tool groups to calculate the comprehensive detection coefficient and system coefficient through data detection, acquisition, analysis and evaluation modules to generate vulnerability warnings and processing solutions.

Benefits of technology

It realizes in-depth analysis of the power grid industrial control protocol, quickly identify potential vulnerabilities and security risks, provides automatic evaluation and processing solutions, and ensures the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117640199B_ABST
    Figure CN117640199B_ABST
Patent Text Reader

Abstract

The present invention discloses a power grid industrial control protocol vulnerability mining system using fuzz testing, which relates to the field of clinical nursing technology. The system detects and collects fuzz testing engine data, power grid industrial control protocol data, and system data of the power distribution system through a data detection module and a data collection module. A protocol analysis module extracts protocol message data and buffer data, and calculates various coefficients to deeply analyze the performance characteristics of the power grid industrial control protocol. The fuzz testing engine coefficient Mhxs, the power grid industrial control protocol coefficient Dwxs, and the system coefficient Xtxs are calculated using formulas to evaluate the system status and performance. A vulnerability assessment module sets protocol and system assessment thresholds X, and evaluates vulnerabilities and potential risks in the power distribution system by comprehensively detecting the coefficient Zhxs and the system coefficient Xtxs. The vulnerability assessment module generates vulnerability alerts and sends them to the vulnerability handling module to prompt and warn the administrator.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security, and specifically to a power grid industrial control protocol vulnerability mining system using fuzz testing. Background Art

[0002] Power grid industrial control protocols refer to communication protocols used in power distribution systems, power transmission systems, and power industry control systems. These protocols are used to monitor, control, and manage power equipment and networks to ensure the normal operation and security of the power system. Power grid industrial control protocols play a key role in the power industry. Power grid vulnerability mining based on fuzz testing is a method for discovering and identifying potential vulnerabilities in power industry control systems. This method uses a fuzz testing engine to generate random, abnormal, or unexpected input data and sends it to the target of power grid industrial control devices or protocols to observe how the system responds to these inputs. By analyzing the system's reactions, potential vulnerabilities and security issues can be detected.

[0003] At present, fuzz testing is usually based on randomly generated input data, so it is impossible to ensure that test cases cover all possible situations, which may lead to some potential vulnerabilities not being detected. And at present, most vulnerability mining is a first-level response. After a preliminary scan, it enters the system. When no vulnerabilities are detected, it is not easy to perform a secondary response, that is, to perform secondary vulnerability mining by identifying system anomalies. And after vulnerability mining, it is unable to actively generate response strategies and accurate vulnerability reports and report them to the administrator so that the administrator can make accurate judgments and handle the vulnerabilities. Summary of the Invention

[0004] In view of the deficiencies of the prior art, the present invention provides a power grid industrial control protocol vulnerability mining system using fuzz testing, which solves the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: It includes a data detection module, a data collection module, a protocol analysis module, a vulnerability assessment module, and a vulnerability handling module;

[0006] On the power distribution system, several detection tools and scripts are installed. The data detection module detects the fuzz testing engine data, power grid industrial control protocol data, and system data in the power distribution system, and the data collection module collects the fuzz testing engine data, power grid industrial control protocol data, and system data.

[0007] The protocol analysis module includes a first analysis unit, a second analysis unit, a third analysis unit, and a fourth correlation analysis unit. The first analysis unit is used to extract a protocol message data set based on the fuzz testing engine data, analyze and calculate to obtain a protocol message coefficient Xyxs, and extract a buffer data set from the fuzz testing engine data, analyze and calculate to obtain a buffer coefficient Hcxs. The second analysis unit extracts the current power grid industrial control protocol data set from the power grid industrial control protocol data and calculates to obtain a power grid industrial control protocol coefficient Dwxs. The third analysis unit extracts a system data set based on the system data, performs calculation and analysis to obtain a system coefficient Xtxs. The fourth correlation analysis unit fits the protocol message coefficient Xyxs and the buffer coefficient Hcxs to obtain a fuzz testing engine coefficient Mhxs, and correlates the power grid industrial control protocol coefficient Dwxs with the fuzz testing engine coefficient Mhxs to obtain a comprehensive detection coefficient Zhxs.

[0008] The fuzz testing engine coefficient Mhxs, the power grid industrial control protocol coefficient Dwxs, and the system coefficient Xtxs are obtained through the following formulas respectively:

[0009]

[0010] Dwxs = [(Xcd * b1) + (Tfz * b2) + (Tyc * b3) + (Csl + b4)] + B;

[0011] Xtxs = [(Yxr * c1) + (Ncr * c2) + (Bkp * c3) + (Dbl + c4) + (Sgl + c5)] + C;

[0012] In the formula, a1 represents the proportional coefficient of the protocol message coefficient Xyxs, a2 represents the proportional coefficient of the buffer coefficient Hcxs, where a1 + a2 ≠ 1, 0.01 < a1 < 0.78, 0 < a2 < 0.89, and its specific value is adjusted and set by the user, and A is the first correction constant;

[0013] Xcd represents the protocol length, Tfz represents the communication load, Tyc represents the communication delay, Csl represents the transmission rate, and b1, b2, b3, and b4 are the proportional coefficients of the protocol length Xcd, the communication load Tfz, the communication delay Szc, and the transmission rate Csl respectively, and 0 < b1 < 1, 0 < b2 < 1, 0 < b3 < 1, 0 < b4 < 1, and its specific value is adjusted and set by the user, and B is the second correction constant;

[0014] Yxr represents the running memory utilization rate, Ncr represents the memory stock, Bkp represents the system crash frequency, Dbl represents the packet loss rate, Sgl represents the power voltage output power, c1, c2, c3, c4, and c5 are the proportionality coefficients of the running memory utilization rate Yxr, the memory stock Ncr, the system crash frequency Bkp, the packet loss rate Dbl, and the power voltage output power Sgl respectively, and 0.02 < c1 < 0.83, 0.03 < c2 < 0.97, 0.6 < c3 < 0.79, 0.02 < c4 < 0.86, 0.01 < c5 < 0.98. Their specific values are adjusted and set by the user, and C is the third correction constant;

[0015] The vulnerability assessment module sets the protocol assessment threshold G and the system assessment threshold X, compares and analyzes the comprehensive detection coefficient Zhxs and the system coefficient Xtxs with the vulnerability assessment threshold G and the system assessment threshold X to obtain the assessment result, and the vulnerability handling module generates a vulnerability warning based on the assessment result to prompt the administrator.

[0016] Preferably, the data detection module includes a first detection unit, a second detection unit, and a third detection unit;

[0017] The first detection unit is used to detect the message data and buffer data in the fuzz testing engine by using the first integrated script tool group and the second integrated script tool group to obtain the fuzz testing engine data;

[0018] The first integrated script tool group includes Atheris, AmericanFuzzyLop, and Boofuzz;

[0019] The second integrated script tool group includes Coverity, Fortify, and Checkmarx;

[0020] The second detection unit is used to detect the power grid industrial control protocol data by using the third integrated script tool group to obtain the power grid industrial control protocol data set;

[0021] The third integrated script tool group includes Wireshark, a protocol parser, and tcpdump;

[0022] The third detection unit is used to detect the system data in the power grid distribution system by using the fourth integrated script tool group to obtain the system data set;

[0023] The fourth integrated script tool group includes a performance monitoring tool, a memory analysis tool, a network monitoring tool, a power monitoring tool, and a system log.

[0024] Preferably, the data acquisition module includes a first acquisition unit, a second acquisition unit, and a third acquisition unit;

[0025] The first acquisition unit is used to acquire the fuzz testing engine data detected by the first detection unit. The fuzz testing engine data includes a message data set and a buffer data set. The message data set includes a field value Zdz, a valid value Yxz, a minimum boundary value Bjz, a maximum boundary value Zbj, and an extreme value Jdz. The buffer data set includes an input data length Cd, a buffer maximum value Zd, a buffer minimum value Zx, and a buffer capacity Rl;

[0026] The second acquisition unit is used to acquire the power grid industrial control protocol data set detected by the second detection unit. The power grid industrial control protocol data set includes a protocol length Xcd, a communication load Tfz, a communication delay Szc, and a transmission rate Csl;

[0027] The third acquisition unit is used to acquire the system data set detected by the third detection unit. The system data set includes a co-running memory utilization rate Yxr, a memory stock Ncr, a system crash frequency Bkp, a packet loss rate Dbl, and a power voltage output power Sgl.

[0028] Preferably, the first analysis unit includes a message analysis unit and a buffer analysis unit;

[0029] The message analysis unit is used to perform dimensionless processing on the message data set in the fuzz testing engine data, and then summarize and calculate to obtain a message coefficient Xyxs;

[0030] The message coefficient Xyxs is obtained through the following formula:

[0031] Xyxs = [(Zdz * d1) + (Yxz * d2) + (Bjz * d3) + (Zbj * d4) + (Jdz * d5)] + D

[0032] In the formula, d1, d2, d3, d4, and d5 represent the proportionality coefficients of the field value Zdz, the valid value Yxz, the minimum boundary value Bjz, the maximum boundary value Zbj, and the extreme value Jdz. Among them, 0.02 < d1 < 0.88, 0.04 < d2 < 0.97, 0.06 < d3 < 0.99, 0.04 < d4 < 0.86, 0.01 < d5 < 0.91, and their specific values are adjusted and set by the user. D is the fourth correction constant.

[0033] Preferably, the buffer analysis unit is used to perform dimensionless summary processing on the system data set summarized by the system data, and then summarize and calculate to obtain a buffer coefficient Hcxs;

[0034] The buffer coefficient Hcxs is obtained through the following formula:

[0035] Hcxs = [(Cd * e1) + (Zd * e2) + (Zx * e3) + (Rl * e4)] + E

[0036] Wherein, e1, e2, e3, and e4 are respectively the proportionality coefficients of the input data length Cd, the buffer maximum value Zd, the buffer minimum value Zx, and the buffer capacity Rl. Among them, 0 < e1 < 1, 0 < e2 < 1, 0 < e3 < 1, 0 < e4 < 1, and their specific values are adjusted and set by the user. E is the fifth correction constant.

[0037] Preferably, the fourth correlation analysis unit is used to perform dimensionless processing based on the fuzzy test engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs obtained by the first analysis unit and the second analysis unit, and then perform associated calculation to obtain the comprehensive detection coefficient Zhxs;

[0038] The comprehensive detection coefficient Zhxs is obtained through the following formula:

[0039]

[0040] Wherein, f1 and f2 represent the proportionality coefficients of the fuzzy test engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs. Among them, 0 < f1 < 1, 0 < f2 < 1, and their specific values are adjusted and set by the user. F is the sixth correction constant.

[0041] Preferably, the comprehensive detection coefficient Zhxs obtained by the fourth correlation analysis unit is compared and evaluated by the vulnerability assessment module. The vulnerability assessment module includes a primary assessment module and a secondary assessment module. The primary assessment module compares the obtained comprehensive detection coefficient Zhxs with the vulnerability assessment threshold G through the set vulnerability assessment threshold G to obtain the following assessment results;

[0042] When the comprehensive detection coefficient Zhxs > the vulnerability assessment threshold G, it indicates that the power grid industrial control protocol in the current power distribution system is greater than the message data and the constrained buffer randomly generated by the fuzzy test engine, and there is a vulnerability in the power grid industrial control protocol, then a first assessment result is generated;

[0043] When the comprehensive detection coefficient Zhxs < the vulnerability assessment threshold G, it indicates that the message data and the constrained buffer in the fuzzy test engine in the current power distribution system are greater than the protocol data in the power grid industrial control protocol, and there is a vulnerability, then a second assessment result is generated.

[0044] Preferably, when the comprehensive detection coefficient Zhxs = the vulnerability assessment threshold G by the secondary assessment module, it indicates that the current power grid industrial control protocol is in a normal state when performing preliminary detection by the fuzzy test engine, then the secondary assessment module is enabled;

[0045] The secondary evaluation module compares the obtained system coefficient Xtxs with the system evaluation threshold X through the set system evaluation threshold X, and obtains the following evaluation results;

[0046] When the system coefficient Xtxs ≥ the system evaluation threshold X, it indicates that there are vulnerabilities in the current power distribution system, and then a third evaluation result is generated;

[0047] When the system coefficient Xtxs < the system evaluation threshold X, it indicates that there are no vulnerabilities in the current power distribution system environment, and no evaluation result needs to be generated.

[0048] Preferably, the vulnerability evaluation module sends the generated first evaluation result and second evaluation result to the vulnerability handling module. The vulnerability handling module analyzes the obtained first evaluation result and second evaluation result to generate a response and generates primary treatment plan information. The specific primary treatment plan is as follows;

[0049] When the vulnerability handling module receives the first evaluation result, it optimizes the grid industrial control protocol. First, it simplifies the header protocol of the grid industrial control protocol, reduces the header information of the protocol data packet, uses a data compression algorithm to compress the amount of transmitted data, divides the data into small pieces for transmission, and follows the standardized grid industrial control protocol to further optimize and improve the grid industrial control protocol;

[0050] When the vulnerability handling module receives the second evaluation result, it is necessary to use intelligent algorithms and heuristic methods to generate test cases. Using intelligent algorithms and heuristic methods to generate test cases ensures that the generated message data is more representative and diverse, which is achieved by adjusting randomly generated field values and mutated field values. At the same time, ensure that these values follow the maximum and minimum parameter constraints. Optimize the buffers in the fuzz testing engine to ensure that their size and content meet the needs of the test, including adjusting the maximum and minimum constraint values of the buffer, adapting to different test scenarios and data requirements, optimizing the length constraints of the input protocol, ensuring that the test covers different lengths of input, and helping to detect potential buffer overflows and length vulnerabilities.

[0051] Preferably, the vulnerability evaluation module sends the generated third evaluation result to the vulnerability handling module. The vulnerability handling module analyzes the obtained third evaluation result to generate a response and generates secondary treatment plan information. The specific secondary treatment plan is as follows;

[0052] When the vulnerability handling module receives the third evaluation result, the first step is to report the vulnerability to the relevant team and the department responsible for vulnerability handling. The vulnerability report includes the nature, location, and severity of the vulnerability. The second step is that the vulnerability report should be verified by the security team and the personnel responsible for vulnerability management, and security patches should be written, vulnerabilities in the protocol should be fixed, and the system should be configured.

[0053] The present invention provides a power grid industrial control protocol vulnerability mining system using fuzz testing, which has the following beneficial effects:

[0054] (1) By combining a fuzz testing engine and multiple integrated script tool groups, the system can deeply analyze the message data and buffer data of the power grid industrial control protocol. This multi-level detection and analysis ability can quickly mine potential protocol vulnerabilities and security risks. The fuzz testing engine can generate various input data, including boundary values and abnormal data, to simulate the data that potential attackers may use, while the integrated script tool group can conduct an in-depth review of the protocol specifications to identify potential protocol parsing and processing errors.

[0055] (2) This system can not only detect vulnerabilities, but also automatically evaluate the severity of the vulnerabilities. Through the comprehensive detection coefficient Zhxs and the system coefficient Xtxs, the system can assess the risk of each detected vulnerability, thus helping administrators quickly and accurately identify the vulnerabilities. In addition, the system provides vulnerability handling solutions so that administrators can take targeted measures. If the vulnerability is serious, the system can automatically trigger vulnerability repair, update the protocol specifications, optimize data transmission and buffer management to minimize the potential attack surface.

[0056] (3) The system has a secondary response module for handling cases where the comprehensive detection coefficient Zhxs and the system coefficient Xtxs are equal. In this case, the fuzz testing engine may consider the protocol and system status normal, but there may actually be some unknown vulnerabilities. The role of the secondary response module is to further verify the system status and trigger more in-depth detection and repair measures when necessary, simulate attacks in the actual network environment to detect the potential impact of protocol vulnerabilities, regularly check the system configuration and vulnerability database to obtain the latest vulnerability information to ensure that the system maintains the latest security, and generate corresponding system vulnerability repair measures. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 It is a schematic flow diagram of a power grid industrial control protocol vulnerability mining system using fuzz testing according to the present invention.

[0058] In the figure: 1. Data detection module; 2. Data acquisition module; 3. Protocol analysis module; 4. Vulnerability assessment module; 5. Vulnerability handling module; 11. First detection unit; 12. Second detection unit; 13. Third detection unit; 21. First acquisition unit; 22. Second acquisition unit; 23. Third acquisition unit; 31. First analysis unit; 32. Second analysis unit; 33. Third analysis unit; 34. Fourth correlation analysis unit; 311. Message analysis unit; 312. Buffer analysis unit; 41. Primary assessment module; 42. Secondary assessment module. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0059] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0060] Embodiment 1

[0061] Please refer to Figure 1 , the present invention provides a power grid industrial control protocol vulnerability mining system using fuzz testing. To achieve the above objectives, the present invention is realized through the following technical solutions: including a data detection module 1, a data acquisition module 2, a protocol analysis module 3, a vulnerability assessment module 4, and a vulnerability handling module 5;

[0062] On the power distribution system, several detection tools and scripts are installed. The data detection module 1 detects the fuzz testing engine data, power grid industrial control protocol data, and system data in the power distribution system, and the data acquisition module 2 acquires the fuzz testing engine data, power grid industrial control protocol data, and system data.

[0063] The protocol analysis module 3 includes a first analysis unit 31, a second analysis unit 32, a third analysis unit 33, and a fourth correlation analysis unit 34. The first analysis unit 31 is used to extract the protocol message data set according to the fuzz testing engine data, analyze and calculate to obtain the protocol message coefficient Xyxs, and extract the buffer data set from the fuzz testing engine data, analyze and calculate to obtain the buffer coefficient Hcxs; and the second analysis unit 32 extracts the current power grid industrial control protocol data set from the power grid industrial control protocol data and calculates to obtain the power grid industrial control protocol coefficient Dwxs; then the third analysis unit 33 extracts the system data set according to the system data, conducts calculation and analysis to obtain the system coefficient Xtxs; and the fourth correlation analysis unit 34 fits the protocol message coefficient Xyxs and the buffer coefficient Hcxs to obtain the fuzz testing engine coefficient Mhxs, and correlates the power grid industrial control protocol coefficient Dwxs with the fuzz testing engine coefficient Mhxs to obtain the comprehensive detection coefficient Zhxs.

[0064] The fuzz testing engine coefficient Mhxs, the power grid industrial control protocol coefficient Dwxs, and the system coefficient Xtxs are obtained through the following formulas respectively:

[0065]

[0066] Dwxs = [(Xcd * b1) + (Tfz * b2) + (Tyc * b3) + (Csl + b4)] + B;

[0067] Xtxs = [(Yxr * c1) + (Ncr * c2) + (Bkp * c3) + (Dbl + c4) + (Sgl + c5)] + C;

[0068] In the formula, a1 represents the proportionality coefficient of the protocol message coefficient Xyxs, and a2 represents the proportionality coefficient of the buffer coefficient Hcxs, where a1 + a2 ≠ 1, 0.01 < a1 < 0.78, 0 < a2 < 0.89, and their specific values are adjusted and set by the user. A is the first correction constant;

[0069] Xcd represents the protocol length, Tfz represents the communication load, Tyc represents the communication delay, Csl represents the transmission rate, and b1, b2, b3, and b4 are the proportionality coefficients of the protocol length Xcd, communication load Tfz, communication delay Szc, and transmission rate Csl respectively, and 0 < b1 < 1, 0 < b2 < 1, 0 < b3 < 1, 0 < b4 < 1, and their specific values are adjusted and set by the user. B is the second correction constant;

[0070] Yxr represents the running memory utilization rate, Ncr represents the memory stock, Bkp represents the system crash frequency, Dbl represents the packet loss rate, Sgl represents the power voltage output power, and c1, c2, c3, c4, and c5 are the proportionality coefficients of the running memory utilization rate Yxr, memory stock Ncr, system crash frequency Bkp, packet loss rate Dbl, and power voltage output power Sgl respectively, and 0.02 < c1 < 0.83, 0.03 < c2 < 0.97, 0.6 < c3 < 0.79, 0.02 < c4 < 0.86, 0.01 < c5 < 0.98, and their specific values are adjusted and set by the user. C is the third correction constant;

[0071] The vulnerability assessment module 4 sets the protocol assessment threshold G and the system assessment threshold X, compares and analyzes the comprehensive detection coefficient Zhxs and the system coefficient Xtxs with the vulnerability assessment threshold G and the system assessment threshold X to obtain the assessment result, and the vulnerability handling module 5 generates a vulnerability warning based on the assessment result to prompt the administrator.

[0072] In this embodiment, the system detects and collects the fuzz testing engine data, grid industrial control protocol data, and system data of the power distribution system through the data detection module 1 and the data acquisition module 2. The protocol analysis module 3 extracts the protocol message data and buffer data, and calculates various coefficients to deeply analyze the performance characteristics of the grid industrial control protocol. The fuzz testing engine coefficient Mhxs, the grid industrial control protocol coefficient Dwxs, and the system coefficient Xtxs are calculated using formulas to evaluate the system status and performance. The vulnerability assessment module 4 sets the protocol and system assessment threshold X, and evaluates the vulnerabilities and potential risks in the power distribution system by comprehensively detecting the coefficient Zhxs and the system coefficient Xtxs. The vulnerability assessment module 4 generates a vulnerability alert and sends it to the vulnerability handling module 5 to prompt and warn the administrator, enabling the administrator to respond more quickly to potential threats.

[0073] Embodiment 2

[0074] This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The data detection module 1 includes a first detection unit 11, a second detection unit 12, and a third detection unit 13;

[0075] The first detection unit 11 is used to detect the message data and buffer data in the fuzz testing engine by using the first integrated script tool group and the second integrated script tool group to obtain the fuzz testing engine data;

[0076] The first integrated script tool group includes Atheris, AmericanFuzzyLop, and Boofuzz;

[0077] The second integrated script tool group includes Coverity, Fortify, and Checkmarx;

[0078] The second detection unit 12 is used to detect the grid industrial control protocol data by using the third integrated script tool group to obtain the grid industrial control protocol data set;

[0079] The third integrated script tool group includes Wireshark, a protocol parser, and tcpdump;

[0080] The third detection unit 13 is used to detect the system data in the grid power distribution system by using the fourth integrated script tool group to obtain the system data set;

[0081] The fourth integrated script tool group includes a performance monitoring tool, a memory analysis tool, a network monitoring tool, a power monitoring tool, and a system log.

[0082] In this embodiment, the data detection module 1 includes multiple detection units, including a first detection unit 11, a second detection unit 12, and a third detection unit 13. Each unit uses a different integrated script toolset to achieve the detection and acquisition of different data types. This combination enables the system to comprehensively monitor and collect key data in the power distribution system, providing the necessary information and basis for subsequent analysis and evaluation. Tools such as Atheris, AmericanFuzzyLop, and Boofuzz can generate various random and abnormal data, including boundary values and extreme values, and provide parameter configuration options to customize the way of generating data, thereby being used to detect various randomly generated message data. Coverity is used for static analysis of source code to find potential problems in protocol implementation, including buffer overflows and invalid input validation. Fortify can also detect insecure buffer usage in source code, including unvalidated user input for buffer size calculation and lack of sufficient boundary checks. Checkmarx focuses on detecting buffer overflow vulnerabilities in protocols. Network packet analysis tools such as Wireshark, protocol parsers, and tcpdump are used to capture, analyze, and display network packets in network communications. These tools help detect and analyze communications of various network protocols, including grid industrial control protocol information.

[0083] Embodiment 3

[0084] This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The data acquisition module 2 includes a first acquisition unit 21, a second acquisition unit 22, and a third acquisition unit 23;

[0085] The first acquisition unit 21 is used to acquire the fuzz testing engine data detected by the first detection unit 11. The fuzz testing engine data includes a message data set and a buffer data set. The message data set includes a field value Zdz, a valid value Yxz, a minimum boundary value Bjz, a maximum boundary value Zbj, and an extreme value Jdz. The buffer data set includes an input data length Cd, a buffer maximum value Zd, a buffer minimum value Zx, and a buffer capacity Rl;

[0086] The second acquisition unit 22 is used to acquire the grid industrial control protocol data set detected by the second detection unit 12. The grid industrial control protocol data set includes a protocol length Xcd, a communication load Tfz, a communication delay Szc, and a transmission rate Csl;

[0087] The third acquisition unit 23 is used to acquire the system data set detected by the third detection unit 13. The system data set includes a co - running memory utilization rate Yxr, a memory stock Ncr, a system crash frequency Bkp, a packet loss rate Dbl, and a power voltage output power Sgl.

[0088] In this embodiment, the data acquisition module 2 provides a comprehensive data source for the system through this multi-source data acquisition method, which helps to better understand the performance and operation of the power distribution system, further analyze and evaluate the characteristics of the grid industrial control protocol and the stability of the power distribution system, thereby improving the management efficiency and reliability of the system.

[0089] Embodiment 4

[0090] This embodiment is an explanatory description carried out in Embodiment 1. Please refer to Figure 1 , specifically: the first analysis unit 31 includes a message analysis unit 311 and a buffer analysis unit 312;

[0091] The message analysis unit 311 is used to perform dimensionless processing on the message data set in the fuzz testing engine data, and then summarize and calculate to obtain the message coefficient Xyxs;

[0092] The message coefficient Xyxs is obtained through the following formula:

[0093] Xyxs = [(Zdz * d1)+(Yxz * d2)+(Bjz * d3)+(Zbj * d4)+(Jdz * d5)] + D

[0094] In the formula, d1, d2, d3, d4, and d5 represent the proportionality coefficients of the field value Zdz, the effective value Yxz, the minimum boundary value Bjz, the maximum boundary value Zbj, and the extreme value Jdz. Among them, 0.02 < d1 < 0.88, 0.04 < d2 < 0.97, 0.06 < d3 < 0.99, 0.04 < d4 < 0.86, 0.01 < d5 < 0.91, and their specific values are adjusted and set by the user. D is the fourth correction constant.

[0095] In this embodiment, the first analysis unit 31 includes a message analysis unit 311 and a buffer analysis unit 312. Among them, the message analysis unit 311 is used to perform dimensionless processing on the message data set in the fuzz testing engine data, summarize and calculate the message data set to obtain the message coefficient Xyxs. The calculation formula of the message coefficient Xyxs includes the field values Zdz, Yxz, Bjz, Zbj, and Jdz, and the proportionality coefficients that can be adjusted by the user. This analysis process helps to extract important information about the message from the fuzz testing engine data and provides a basis for subsequent evaluation. Among them, these parameters are used to simulate various different input situations in fuzz testing, including normal situations and abnormal situations, to evaluate the robustness, stability, and security of the target system. Through these parameters, fuzz testing helps to discover potential vulnerabilities, security risks, and performance problems for improvement and repair.

[0096] Example 5

[0097] This example is an explanatory note for Example 1. Please refer to Figure 1 , specifically: The buffer analysis unit 312 is used to perform dimensionless summarization processing on the system data set summarized by the system data, and then summarize and calculate to obtain the buffer coefficient Hcxs;

[0098] The buffer coefficient Hcxs is obtained through the following formula:

[0099] Hcxs = [(Cd * e1) + (Zd * e2) + (Zx * e3) + (Rl * e4)] + E

[0100] In the formula, e1, e2, e3, and e4 are the proportionality coefficients of the input data length Cd, the buffer maximum value Zd, the buffer minimum value Zx, and the buffer capacity Rl, respectively. Among them, 0 < e1 < 1, 0 < e2 < 1, 0 < e3 < 1, 0 < e4 < 1, and their specific values are adjusted and set by the user. E is the fifth correction constant.

[0101] In this example, the role of the buffer analysis unit 312 is to evaluate the performance and security of the buffer in the system. By calculating the buffer coefficient Hcxs, it helps to identify potential problems for improvement and repair. This helps to improve the stability and security of the system. Fuzz testing of buffer parameters can help discover potential boundary condition problems, buffer overflow vulnerabilities, and security issues, which helps to improve the stability, security, and performance of the system and can uncover vulnerabilities.

[0102] Example 6

[0103] This example is an explanatory note for Example 1. Please refer to Figure 1 , specifically: The fourth correlation analysis unit 34 is used to perform dimensionless processing on the fuzzy test engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs obtained by the first analysis unit 31 and the second analysis unit 32, and then perform associated calculation to obtain the comprehensive detection coefficient Zhxs;

[0104] The comprehensive detection coefficient Zhxs is obtained through the following formula:

[0105]

[0106] In the formula, f1 and f2 represent the proportionality coefficients of the fuzzy test engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs. Among them, 0 < f1 < 1, 0 < f2 < 1, and their specific values are adjusted and set by the user. F is the sixth correction constant.

[0107] In this embodiment, the calculation and use of the comprehensive detection coefficient Zhxs help the administrator better understand the system status, identify potential threats, and make adjustments and optimizations as needed, thereby improving the reliability and security of the power distribution system. This process facilitates the stable operation and vulnerability management of the system.

[0108] Embodiment 7

[0109] This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The comprehensive detection coefficient Zhxs obtained by the fourth correlation analysis unit 34 is compared and evaluated by the vulnerability assessment module 4. The vulnerability assessment module 4 includes a primary assessment module 41 and a secondary assessment module 42. The primary assessment module 41 compares the obtained comprehensive detection coefficient Zhxs with the vulnerability assessment threshold G through the set vulnerability assessment threshold G, and obtains the following assessment results;

[0110] When the comprehensive detection coefficient Zhxs > the vulnerability assessment threshold G, it indicates that the grid industrial control protocol in the current power distribution system is greater than the message data and constrained buffer randomly generated by the fuzz testing engine, and there is a vulnerability in the grid industrial control protocol, then a first assessment result is generated;

[0111] When the comprehensive detection coefficient Zhxs < the vulnerability assessment threshold G, it indicates that the message data and constrained buffer in the fuzz testing engine in the current power distribution system are greater than the protocol data in the grid industrial control protocol, and there is a vulnerability, then a second assessment result is generated.

[0112] In this embodiment, this assessment process allows the system to identify potential vulnerabilities in the power distribution system based on the value of the comprehensive detection coefficient Zhxs, and generate corresponding assessment results according to specific situations, thereby helping the administrator better understand the risk status of the system, and contributing to taking appropriate security measures in a timely manner to ensure the reliability and security of the power distribution system.

[0113] Embodiment 8

[0114] This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: When the comprehensive detection coefficient Zhxs = the vulnerability assessment threshold G in the secondary assessment module 42, it indicates that the current grid industrial control protocol is in a normal state when being detected by the preliminary fuzz testing engine, then the secondary assessment module 42 is enabled;

[0115] The secondary assessment module 42 compares the obtained system coefficient Xtxs with the system assessment threshold X through the set system assessment threshold X, and obtains the following assessment results;

[0116] When the system coefficient Xtxs ≥ the system evaluation threshold X, it indicates that there are vulnerabilities in the current power distribution system, and then a third evaluation result is generated;

[0117] When the system coefficient Xtxs < the system evaluation threshold X, it indicates that there are no vulnerabilities in the current power distribution system environment, and there is no need to generate an evaluation result.

[0118] In this embodiment, the secondary evaluation module 42 determines whether to enable secondary evaluation by checking whether the comprehensive detection coefficient Zhxs is equal to the vulnerability evaluation threshold G. If the comprehensive detection coefficient Zhxs is equal to the vulnerability evaluation threshold G, it means that the grid industrial control protocol performs normally in the preliminary fuzz testing engine detection, and enters the next secondary evaluation. The secondary evaluation module 42 compares the system coefficient Xtxs with this threshold according to the pre-set system evaluation threshold X. If the system coefficient Xtxs is greater than or equal to the system evaluation threshold X, it indicates that there are potential vulnerabilities in the power distribution system and further processing is required. At this time, the system generates a third evaluation result.

[0119] Embodiment 9

[0120] This embodiment is an explanatory description based on Embodiment 8. Please refer to Figure 1 , specifically: The vulnerability evaluation module 4 sends the generated first evaluation result and second evaluation result to the vulnerability handling module 5. The vulnerability handling module 5 analyzes the obtained first evaluation result and second evaluation result to generate a response and generates primary processing scheme information. The specific primary processing scheme is as follows;

[0121] When the vulnerability handling module 5 receives the first evaluation result, it optimizes the grid industrial control protocol. First, it streamlines the header protocol of the grid industrial control protocol, reduces the header information of the protocol data packet, uses a data compression algorithm to compress the amount of transmitted data, divides the data into small pieces for transmission, and follows the standardized grid industrial control protocol to further optimize and improve the grid industrial control protocol;

[0122] When the vulnerability handling module 5 receives the second evaluation result, it is necessary to use intelligent algorithms and heuristic methods to generate test cases. Use intelligent algorithms and heuristic methods to generate test cases to ensure that the generated message data is more representative and diverse, which is achieved by adjusting randomly generated field values and mutated field values. At the same time, ensure that these values follow the constrained maximum and minimum parameters, optimize the buffers in the fuzz testing engine to ensure that their sizes and contents meet the needs of the test, including adjusting the maximum and minimum constraint values of the buffers, adapting to different test scenarios and data requirements, and optimizing the length constraints of the input protocol to ensure that the test covers inputs of different lengths, which helps to detect potential buffer overflows and length vulnerabilities.

[0123] In this embodiment, the first evaluation result and the second evaluation result generated by the primary evaluation module 41 are sent to the vulnerability handling module 5 for analysis to generate corresponding processing solutions. The primary processing solutions help improve the security and performance of the power distribution system. By optimizing the protocol and generating more diverse test cases, the system can better resist potential vulnerabilities and attacks.

[0124] Embodiment 10

[0125] This embodiment is an explanatory description based on Embodiment 9. Please refer to Figure 1 , specifically: The vulnerability evaluation module 4 sends the generated third evaluation result to the vulnerability handling module 5. The vulnerability handling module 5 analyzes the obtained third evaluation result to generate a response and generate secondary processing solution information. The specific secondary processing solutions are as follows;

[0126] When the vulnerability handling module 5 receives the third evaluation result, the first step is to report the vulnerability to the relevant team and the department responsible for vulnerability handling. The vulnerability report includes the nature, location, and severity of the vulnerability. In the second step, the vulnerability report should be verified by the security team and the personnel responsible for vulnerability management, and security patches should be written, vulnerabilities in the protocol should be fixed, and the system should be configured.

[0127] In this embodiment, the third evaluation result generated by the secondary evaluation module 42 is sent to the vulnerability handling module 5 for analysis. Through these secondary processing solutions, the vulnerabilities can be identified, verified, and repaired in a timely manner, thereby improving the security and stability of the system and reducing the risk of potential threats to the power distribution system.

[0128] Specific example: A certain power company introduced a vulnerability mining system for grid industrial control protocols using fuzz testing. The following is an example of this certain power company.

[0129] Fuzz testing engine coefficient Mhxs:

[0130]

[0131] Proportion coefficient: a1 = 0.24, a2 = 0.11, first correction constant A: 0.19;

[0132] Grid industrial control protocol coefficient Dwxs:

[0133] Dwxs = [(14 * 0.06) + (13 * 0.12) + (7 * 0.14) + (6 * 0.2)] + 0.02 = 4.6;

[0134] Protocol length Xcd: 14, communication load Tfz: 13, communication delay Szc: 7, transmission rate Csl: 6, proportionality coefficients: b1 = 0.06, b2 = 0.22, b3 = 0.14, b4 = 0.2, second correction constant B: 0.12;

[0135] System coefficient Xtxs:

[0136] Xtxs = [(7 * 0.04) + (3 * 0.06) + (2 * 0.08) + (6 * 0.02) + (5 * 0.03)] + 0.01 = 0.9;

[0137] Operating memory utilization Yxr: 7, memory stock Ncr: 3, system crash frequency Bkp: 2, packet loss rate Dbl: 6, power voltage output power Sgl: 5, proportionality coefficients: c1 = 0.04, c2 = 0.06, c3 = 0.08, c4 = 0.09, c5 = 0.3, third correction constant C: 0.01;

[0138] Message coefficient Xyxs:

[0139] Xyxs = [(8 * 0.31) + (6 * 0.03) + (12 * 0.08) + (9 * 0.1) + (4 * 0.28)] + 0.36 = 6;

[0140] Field value Zdz: 8, valid value Yxz: 6, minimum boundary value Bjz: 12, maximum boundary value Zbj: 9, extreme value Jdz: 4, proportionality coefficients: d1 = 0.31, d2 = 0.03, d3 = 0.08, d4 = 0.1, d5 = 0.28, fourth correction constant D: 0.13;

[0141] Buffer coefficient Hcxs:

[0142] Hcxs = [(16 * 0.07) + (12 * 0.14) + (6 * 0.22) + (4 * 0.14)] + 0.32 = 5;

[0143] Proportionality coefficients: e1 = 0.07, e2 = 0.14, e3 = 0.22, e4 = 0.14, input data length Cd: 16, buffer maximum value Zd: 12, buffer minimum value Zx: 6, buffer capacity Rl: 4, fifth correction constant E: 0.32;

[0144] Comprehensive detection coefficient Zhxs:

[0145]

[0146] Sixth correction constant F: 0.23;

[0147] Among them, the calculation results are all rounded to two decimal places.

[0148] At this time, set the vulnerability assessment threshold G to 1. At this time, the comprehensive detection coefficient Zhxs = the vulnerability assessment threshold G, then the secondary assessment module 42 is enabled, and the system assessment threshold X is set to 1. At this time, when the system coefficient Xtxs < the system assessment threshold X, it means that no vulnerability has been discovered in the current system and the system is normal.

[0149] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A power grid industrial control protocol vulnerability mining system using fuzz testing, characterized in that: It includes a data detection module (1), a data acquisition module (2), a protocol analysis module (3), a vulnerability assessment module (4) and a vulnerability handling module (5); On the power distribution system, several detection tools and scripts are installed. The data detection module (1) detects the fuzz testing engine data, grid industrial control protocol data and system data in the power distribution system, and the data acquisition module (2) acquires the fuzz testing engine data, grid industrial control protocol data and system data; The protocol analysis module (3) includes a first analysis unit (31), a second analysis unit (32), a third analysis unit (33) and a fourth correlation analysis unit (34). The first analysis unit (31) is used to extract the protocol message data set according to the fuzz testing engine data, analyze and calculate to obtain the protocol message coefficient Xyxs, and extract the buffer data set from the fuzz testing engine data, analyze and calculate to obtain the buffer coefficient Hcxs; And the second analysis unit (32) extracts the current grid industrial control protocol data set from the grid industrial control protocol data and calculates to obtain the grid industrial control protocol coefficient Dwxs; Then the third analysis unit (33) extracts the system data set according to the system data, conducts calculation and analysis to obtain the system coefficient Xtxs; and the fourth correlation analysis unit (34) fits the protocol message coefficient Xyxs and the buffer coefficient Hcxs to obtain the fuzz testing engine coefficient Mhxs, and correlates the grid industrial control protocol coefficient Dwxs with the fuzz testing engine coefficient Mhxs to obtain the comprehensive detection coefficient Zhxs; The fuzz testing engine coefficient Mhxs, the grid industrial control protocol coefficient Dwxs and the system coefficient Xtxs are obtained through the following formulas respectively: Dwxs = [(Xcd * b1) + (Tfz * b2) + (Tyc * b3) + (Csl + b4)] + B; Xtxs = [(Yxr * c1) + (Ncr * c2) + (Bkp * c3) + (Dbl + c4) + (Sgl + c5)] + C; In the formula, a1 represents the proportional coefficient of the protocol message coefficient Xyxs, and a2 represents the proportional coefficient of the buffer coefficient Hcxs, where a1 + a2 ≠ 1, 0.01 < a1 < 0.78, 0 < a2 < 0.89, and its specific value is adjusted and set by the user, and A is the first correction constant; Xcd represents the protocol length, Tfz represents the communication load, Tyc represents the communication delay, Csl represents the transmission rate, and b1, b2, b3 and b4 are the proportional coefficients of the protocol length Xcd, the communication load Tfz, the communication delay Szc and the transmission rate Csl respectively, and 0 < b1 < 1, 0 < b2 < 1, 0 < b3 < 1, 0 < b4 < 1, and its specific value is adjusted and set by the user, and B is the second correction constant; Yxr represents the running memory utilization rate, Ncr represents the memory stock, Bkp represents the system crash frequency, Dbl represents the packet loss rate, Sgl represents the power voltage output power, c1, c2, c3, c4, and c5 are the proportionality coefficients of the running memory utilization rate Yxr, the memory stock Ncr, the system crash frequency Bkp, the packet loss rate Dbl, and the power voltage output power Sgl respectively, and 0.02 < c1 < 0.83, 0.03 < c2 < 0.97, 0.1 < c3 < 0.79, 0.02 < c4 < 0.86, 0.01 < c5 < 0.

98. Their specific values are adjusted and set by the user. C is the third correction constant; The vulnerability assessment module (4) sets the protocol assessment threshold G and the system assessment threshold X, compares and analyzes the comprehensive detection coefficient Zhxs and the system coefficient Xtxs with the vulnerability assessment threshold G and the system assessment threshold X to obtain the assessment result, and the vulnerability handling module (5) generates a vulnerability warning based on the assessment result to prompt the administrator.

2. The vulnerability mining system for power grid industrial control protocols using fuzz testing according to claim 1, wherein: The data detection module (1) includes a first detection unit (11), a second detection unit (12), and a third detection unit (13); The first detection unit (11) is used to detect the message data and buffer data in the fuzz testing engine by using the first integrated script tool group and the second integrated script tool group to obtain the fuzz testing engine data; The first integrated script tool group includes Atheris, AmericanFuzzyLop, and Boofuzz; The second integrated script tool group includes Coverity, Fortify, and Checkmarx; The second detection unit (12) is used to detect the grid industrial control protocol data by using the third integrated script tool group to obtain the grid industrial control protocol data set; The third integrated script tool group includes Wireshark, a protocol parser, and tcpdump; The third detection unit (13) is used to detect the system data in the grid power distribution system by using the fourth integrated script tool group to obtain the system data set; The fourth integrated script tool group includes a performance monitoring tool, a memory analysis tool, a network monitoring tool, a power monitoring tool, and a system log.

3. The vulnerability mining system for power grid industrial control protocols using fuzz testing according to claim 1, characterized in that: The data acquisition module (2) includes a first acquisition unit (21), a second acquisition unit (22), and a third acquisition unit (23); The first acquisition unit (21) is used to acquire the fuzz testing engine data detected by the first detection unit (11). The fuzz testing engine data includes a message data set and a buffer data set. The message data set includes the field value Zdz, the valid value Yxz, the minimum boundary value Bjz, the maximum boundary value Zbj, and the extreme value Jdz. The buffer data set includes the input data length Cd, the buffer maximum value Zd, the buffer minimum value Zx, and the buffer capacity Rl; The second acquisition unit (22) is used to acquire the power grid industrial control protocol data set detected by the second detection unit (12). The power grid industrial control protocol data set includes protocol length Xcd, communication load Tfz, communication delay Szc, and transmission rate Csl; The third acquisition unit (23) is used to acquire the system data set detected by the third detection unit (13). The system data set includes co - running memory utilization rate Yxr, memory stock Ncr, system crash frequency Bkp, packet loss rate Dbl, and power supply voltage output power Sgl.

4. A power grid industrial control protocol vulnerability mining system using fuzz testing according to claim 1, characterized in that: The first analysis unit (31) includes a message analysis unit (311) and a buffer analysis unit (312); The message analysis unit (311) is used to perform dimensionless processing on the message data set in the fuzz testing engine data, and then summarize and calculate to obtain the message coefficient Xyxs; The message coefficient Xyxs is obtained through the following formula: Xyxs = [(Zdz * d1)+(Yxz * d2)+(Bjz * d3)+(Zbj * d4)+(Jdz * d5)] + D In the formula, d1, d2, d3, d4, and d5 represent the proportionality coefficients of the field value Zdz, effective value Yxz, minimum boundary value Bjz, maximum boundary value Zbj, and extreme value Jdz. Among them, 0.02 < d1 < 0.88, 0.04 < d2 < 0.97, 0.06 < d3 < 0.99, 0.04 < d4 < 0.86, 0.01 < d5 < 0.

91. Their specific values are adjusted and set by the user, and D is the fourth correction constant.

5. The vulnerability mining system for power grid industrial control protocols using fuzz testing according to claim 4, wherein: The buffer analysis unit (312) is used to perform dimensionless summary processing on the system data set summarized from the system data, and then summarize and calculate to obtain the buffer coefficient Hcxs; The buffer coefficient Hcxs is obtained through the following formula: Hcxs = [(Cd * e1)+(Zd * e2)+(Zx * e3)+(Rl * e4)] + E In the formula, e1, e2, e3, and e4 are the proportionality coefficients of the input data length Cd, buffer maximum value Zd, buffer minimum value Zx, and buffer capacity Rl respectively. Among them, 0 < e1 < 1, 0 < e2 < 1, 0 < e3 < 1, 0 < e4 < 1. Their specific values are adjusted and set by the user, and E is the fifth correction constant.

6. The vulnerability mining system for power grid industrial control protocol using fuzz testing according to claim 1, characterized in that: The fourth correlation analysis unit (34) is used to perform dimensionless processing on the fuzz testing engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs obtained by the first analysis unit (31) and the second analysis unit (32), and then perform associated calculation to obtain the comprehensive detection coefficient Zhxs; The comprehensive detection coefficient Zhxs is obtained through the following formula: In the formula, f1 and f2 represent the proportionality coefficients of the fuzz testing engine coefficient Mhxs and the power grid industrial control protocol coefficient Dwxs. Among them, 0 < f1 < 1, 0 < f2 < 1. Their specific values are adjusted and set by the user, and F is the sixth correction constant.

7. An industrial control protocol vulnerability mining system for power grid using fuzz testing according to claim 6, characterized in that: The comprehensive detection coefficient Zhxs obtained by the fourth correlation analysis unit (34) is compared and evaluated by the vulnerability assessment module (4). The vulnerability assessment module (4) includes a primary assessment module (41) and a secondary assessment module (42). The primary assessment module (41) compares the obtained comprehensive detection coefficient Zhxs with the vulnerability assessment threshold G through the set vulnerability assessment threshold G, and obtains the following evaluation results; When the comprehensive detection coefficient Zhxs > the vulnerability assessment threshold G, it means that the grid industrial control protocol in the current power distribution system is greater than the message data and constrained buffer randomly generated by the fuzz testing engine, and there is a vulnerability in the grid industrial control protocol, then a first evaluation result is generated; When the comprehensive detection coefficient Zhxs < the vulnerability assessment threshold G, it means that the message data and constrained buffer in the fuzz testing engine in the current power distribution system are greater than the protocol data in the grid industrial control protocol, and there is a vulnerability, then a second evaluation result is generated.

8. A power grid industrial control protocol vulnerability mining system using fuzz testing according to claim 7, characterized in that: When the comprehensive detection coefficient Zhxs = the vulnerability assessment threshold G by the secondary assessment module (42), it means that the current grid industrial control protocol is in a normal state when being detected by the preliminary fuzz testing engine, then the secondary assessment module (42) is enabled; The secondary assessment module (42) compares the obtained system coefficient Xtxs with the system assessment threshold X through the set system assessment threshold X, and obtains the following evaluation results; When the system coefficient Xtxs ≥ the system assessment threshold X, it means that there is a vulnerability in the current power distribution system, then a third evaluation result is generated; When the system coefficient Xtxs < the system assessment threshold X, it means that there is no vulnerability in the current power distribution system environment, and no evaluation result needs to be generated.

9. The vulnerability mining system for power grid industrial control protocols using fuzz testing according to claim 7, wherein: The vulnerability assessment module (4) sends the generated first evaluation result and second evaluation result to the vulnerability handling module (5). The vulnerability handling module (5) analyzes the obtained first evaluation result and second evaluation result to generate a response and generates primary handling scheme information. The specific primary handling scheme is as follows; When the vulnerability handling module (5) receives the first evaluation result, it optimizes the grid industrial control protocol. First, it streamlines the header protocol of the grid industrial control protocol, reduces the header information of the protocol data packet, uses a data compression algorithm to compress the transmitted data volume, divides the data into small pieces for transmission, and follows the standardized grid industrial control protocol to further optimize and improve the grid industrial control protocol; When the vulnerability handling module (5) receives the second evaluation result, it is necessary to use intelligent algorithms and heuristic methods to generate test cases. By using intelligent algorithms and heuristic methods to generate test cases, ensure that the generated message data is more representative and diverse, which is achieved by adjusting randomly generated field values and mutated field values. At the same time, ensure that these values follow the maximum and minimum parameters of the constraints, optimize the buffers in the fuzz testing engine to ensure that their sizes and contents meet the needs of the test, including adjusting the maximum and minimum constraint values of the buffers, adapting to different test scenarios and data requirements, and optimizing the length constraints of the input protocol to ensure that the test covers inputs of different lengths, which helps to detect potential buffer overflows and length vulnerabilities.

10. A power grid industrial control protocol vulnerability mining system using fuzz testing according to claim 8, characterized in that: The vulnerability assessment module (4) sends the generated third evaluation result to the vulnerability handling module (5). The vulnerability handling module (5) analyzes the obtained third evaluation result to generate a response and generate secondary processing scheme information. The specific secondary processing scheme is as follows; When the vulnerability handling module (5) receives the third evaluation result, the first step is to report the vulnerability to the relevant teams and the departments responsible for vulnerability handling. The vulnerability report includes the nature, location, and severity of the vulnerability. In the second step, the vulnerability report should be verified by the security team and the personnel responsible for vulnerability management, and security patches should be written, vulnerabilities in the protocol should be fixed, and the system should be configured.

Citation Information

Patent Citations

  • Power-grid industrial control protocol vulnerability mining system and method based on fuzzy test

    CN105245403A

  • Electric power Internet of Things protocol vulnerability detection system and method based on fuzzy testing

    CN113392402A