A method and system for evaluating information security strategy for distributed power supply

By constructing a threat graph and utilizing threat intelligence analysis, assigning attributes to nodes to be evaluated, calculating execution difficulty, and employing the TOPSIS algorithm to evaluate the security strategies of distributed power systems, this approach addresses the lack of objectivity and standardization in existing technologies, and achieves quantitative and practical evaluation of security strategies.

CN118157904BActive Publication Date: 2026-05-22STATE GRID CORPORATION OF CHINA +3
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID CORPORATION OF CHINA
Filing Date
2024-01-08
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

In existing technologies, the security strategy assessment of distributed power monitoring systems lacks objectivity, cannot quantify the system's security protection capabilities, and lacks unified security protection technology standards, leading to increased cybersecurity risks.

Method used

By constructing a threat graph, utilizing threat intelligence analysis and security measure parsing, assigning attribute values ​​to the threat nodes to be evaluated, calculating the execution difficulty of paths and nodes, generating security policy evaluation results, and employing the TOPSIS algorithm for comprehensive evaluation, the concept of whole-graph threat difficulty is introduced to objectively assess security policies.

Benefits of technology

It achieves objectivity and readability in the security strategy evaluation results of distributed power systems, can quantify security protection capabilities, has wider adaptability, avoids the influence of subjective assignment, focuses on specific risk scenarios, and improves the practicality of the evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118157904B_ABST
    Figure CN118157904B_ABST
Patent Text Reader

Abstract

A distributed power supply-oriented information security strategy evaluation method and system, the method comprising: acquiring a network topology of a distributed power supply power monitoring system, constructing a threat graph, querying and analyzing threat intelligence for the threat graph, defining baseline attributes of each threat node to be evaluated in the distributed power supply power monitoring system, and assigning attribute values to each node in the threat graph according to the query and analysis results by using each baseline attribute; calculating the attribute value of each path based on the attribute value of each node, and solving the execution difficulty of the node attribute and the execution difficulty of the path attribute by using the attribute value of each node and the attribute value of each path, respectively, to obtain the execution difficulty range of the threat graph; analyzing the security measures of the current scene and substituting the analysis results into the threat nodes to be evaluated, recalculating the execution difficulty of the threat graph, and combining the execution difficulty range of the threat graph to generate a security strategy evaluation result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power systems, and more specifically, to a method and system for evaluating information security strategies for distributed power sources. Background Technology

[0002] With the massive influx of various types of distributed power sources into the grid, the explosive growth in terminal scale, and the widespread application of wireless communication, the risk of network security breaches has increased dramatically. Once the dispatch and control system is compromised, it could severely disrupt the safe and stable operation of the power system, leading to serious consequences such as large-scale power plant outages. The network security risks brought about by distributed power source integration include the following:

[0003] 1. The number of distributed power supply terminals has exploded and reached massive levels. The security boundaries of power monitoring systems are becoming increasingly blurred, with diverse access methods such as virtual power plants and energy storage integration making the new power system network space larger and more complex.

[0004] 2. Distributed power devices are mostly located in unattended, open physical environments, making them vulnerable to physical exploitation, firmware tampering, and other forms of network exposure, leading to an increasing number of attack springboards.

[0005] 3. There are many types of new distributed power terminals, and the data transmission methods are not yet standardized. Access is mainly via public wireless networks, and there is a lack of unified security protection technical standards, which leads to problems such as allowing faulty devices to enter the network.

[0006] 4. Distributed power terminals for different services pose a challenge to the grid's security protection architecture based on partition isolation, further increasing the difficulty of management.

[0007] Currently, the evaluation of security strategies for distributed power monitoring systems relies too heavily on subjective values ​​for various indicators, failing to provide a quantitative assessment of a system's security capabilities.

[0008] To address the aforementioned issues, there is an urgent need for an information security strategy evaluation method and system for distributed power sources. Summary of the Invention

[0009] To address the shortcomings of existing technologies, this invention provides an information security strategy evaluation method and system for distributed power sources. Compared to traditional expert scoring mechanisms, this invention assigns values ​​to threat capabilities and security protection capabilities through threat intelligence analysis and security measure parsing, making the evaluation results more objective. It also provides a security strategy evaluation method that reflects the level of security strategy protection capabilities through a threat graph difficulty scoring system, making the security strategy evaluation results more readable and interpretable.

[0010] The present invention adopts the following technical solution.

[0011] The first aspect of this invention relates to a method for evaluating information security strategies for distributed power sources. The method includes the following steps: obtaining the network topology of a distributed power source power monitoring system; constructing a threat graph for the distributed power source power monitoring system, the threat graph including device nodes, threat nodes to be evaluated, and technical implementation paths; querying and analyzing threat intelligence based on the threat graph; defining baseline attributes for each threat node to be evaluated in the distributed power source power monitoring system; assigning attribute values ​​to each node in the threat graph based on the baseline attributes of each threat node to be evaluated and the query and analysis results; calculating the attribute values ​​of each path based on the attribute values ​​of each node; and using the attribute values ​​of each node and each path to solve for the execution difficulty of the node attributes and the execution difficulty of the path attributes, respectively, to obtain the execution difficulty range of the threat graph. The method further involves analyzing the security measures in the current scenario and substituting the analysis results into the threat nodes to be evaluated, recalculating the execution difficulty of the threat graph, and combining the execution difficulty range of the threat graph to generate a security strategy evaluation result for the distributed power source grid connection.

[0012] Preferably, both the threat node to be evaluated and the technical implementation path include attribute information; the attribute information of the threat node to be evaluated includes the permissions required for technical execution, the knowledge and skills required for technical execution, and the obstacles faced in technical execution; the attribute information of the technical implementation path includes the average technical difficulty and the number of threat nodes to be evaluated.

[0013] Preferably, the permissions required for technical execution include no permissions required, only low permissions required, administrator permissions required, and system permissions required; the knowledge and skills required for technical execution include no knowledge and skills required, basic knowledge and skills required, high knowledge and skills required, and specialized knowledge and skills required; obstacles to technical execution include no security measures, only security monitoring measures, security protection measures that increase the difficulty of technical execution, and security protection measures that greatly increase the difficulty of technical execution; and attribute values ​​are assigned to the nodes of the threat nodes to be evaluated based on the type of attribute information.

[0014] Preferably, a node attribute matrix is ​​constructed based on the attribute values ​​of each node in the threat graph and then standardized; the execution difficulty range of each node attribute after standardization is calculated, as well as the execution difficulty of each threat node to be evaluated.

[0015] Preferably, based on the technical execution difficulty range of each threat node to be evaluated, the average technical execution difficulty range of each path is calculated and used as the attribute value of each path in the threat graph; a node attribute matrix is ​​constructed based on the attribute value of each path in the threat graph and standardized; the execution difficulty range of each path attribute after standardization is calculated.

[0016] Preferably, the execution difficulty range of the threat graph is calculated based on the technical difficulty range of the execution difficulty range of each path; the execution difficulty range of the threat graph is used as the upper and lower limits of the execution difficulty of the threat graph, thereby obtaining the execution difficulty interval of the threat graph.

[0017] Preferably, the current security policy is analyzed and substituted into the node attribute matrix, and the node attribute matrix is ​​reassigned to obtain the attack difficulty of the threat graph under the current security policy.

[0018] Preferably, the evaluation result of the current security strategy is calculated based on the attack difficulty of the threat graph under the current security measures and the attack difficulty range of the threat graph.

[0019] A second aspect of this invention relates to an information security policy evaluation system for distributed power sources utilizing the method of the first aspect of this invention. The system includes an acquisition module, an allocation module, and an evaluation module. The acquisition module acquires the network topology of the distributed power source grid-connected system, constructs a threat graph for the system, and the threat graph includes device nodes, threat nodes to be evaluated, and technical implementation paths. The allocation module queries and analyzes threat intelligence based on the threat graph, defines baseline attributes for each threat node to be evaluated in the distributed power source grid-connected system, assigns attribute values ​​to each node in the threat graph based on the query and analysis results using the baseline attributes of each threat node to be evaluated, and calculates the attack difficulty range of the current threat graph based on the assigned baseline. The evaluation module analyzes the security policy of the current scenario, reassigns node attributes using the analysis results, and generates a security policy evaluation result for the current scenario.

[0020] A third aspect of this invention relates to a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to perform operations according to the instructions to execute the steps of the method in the first aspect of this invention. The beneficial effects of this invention are that, compared with the prior art, the information security strategy evaluation method and system for distributed power sources in this invention, compared with expert assignment methods, the threat intelligence-based assignment method is more objective and can effectively avoid the influence of subjective assignment on the results. Compared with vulnerability assessment methods based on the probability of attack exploitation, it uses the concept of threat difficulty to evaluate security strategies, and introduces the concept of whole-graph threat difficulty, so that the security strategy evaluation is no longer limited to a certain risk path, but is oriented towards specific risk scenarios.

[0021] Furthermore, this invention lists security measures as an independent attribute for the first time, making the security policy evaluation method more adaptable. Since the attributes 'permissions required for technical execution' and 'knowledge and skill reserves required for technical execution' are inherent attributes of attack techniques and will not change with the change of threat scenarios, the security policy score for the current scenario can be calculated simply by adjusting the value of the attribute 'obstacles faced by technical execution', thus completing the security policy evaluation.

[0022] The beneficial effects of the present invention also include:

[0023] 1. The security protection capability evaluation mechanism in this invention can objectively evaluate the security protection level of distributed power supplies based on risk scenarios, providing data support for security capability construction and improvement. Compared with attributes such as "attack cost," "attack difficulty," and "attack concealment," the attribute definition method of this invention is clearer and easier to analyze and evaluate. In obtaining the risk range, the relevant evaluation basis used in the method comes from relevant threat intelligence information, avoiding subjective assignment.

[0024] 2. The TOPSIS algorithm ensures that there is no direct relationship between the weights of the attributes. Any one of the three attributes can directly determine whether the technique can be successfully implemented. Therefore, weighted methods like the Analytic Hierarchy Process (AHP) are not applicable in this scheme. We use the TOPSIS algorithm to replace the AHP for comprehensive evaluation. Compared to methods like the AHP that require expert experience to assign values, this method is more objective.

[0025] 3. The threat map generation in this solution is based on a specific network topology and pre-sets specific targets. Compared to the overall power grid analysis of the original solution, this solution focuses more on specific scenarios. Compared to the theoretical research of the original solution, the threat map generation method of this solution focuses more on specific risk scenarios and pays more attention to practicality. Attached Figure Description

[0026] Figure 1This is a schematic diagram of the 10KV voltage level grid-connected network architecture in the information security strategy evaluation method for distributed power sources of the present invention.

[0027] Figure 2 This is a schematic diagram of the 380V / 220V grid-connected network architecture in the information security strategy evaluation method for distributed power sources of the present invention;

[0028] Figure 3 This is a schematic diagram of the attack route for obtaining SCADA server administrator privileges in the information security strategy evaluation method for distributed power sources of the present invention.

[0029] Figure 4 This is a diagram illustrating an attack on a 10kV voltage level distributed power source in the information security strategy evaluation method for distributed power sources according to the present invention. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this invention are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, all other embodiments not described in this invention obtained by those skilled in the art based on the embodiments described in this invention without creative effort should fall within the protection scope of this invention.

[0031] The first aspect of the present invention relates to an information security strategy evaluation method for distributed power sources, the method comprising steps 1 to 3.

[0032] Step 1: Obtain the network topology of the distributed power grid-connected system, construct a threat graph for the distributed power grid-connected system, including device nodes, nodes of the threat nodes to be evaluated, and technical implementation paths.

[0033] To obtain the safe state of distributed power grid connection, the method first constructs various hypothetical technologies that could threaten the system, so as to conduct a preliminary construction and analysis of the potential threats to the system, and on this basis, seeks new security strategy evaluation methods.

[0034] Before constructing the threat graph from the attacker's perspective in this invention, the network topology of the distributed power monitoring system must first be obtained. In the distributed power scenario, the system mainly includes two scenarios: 10KV voltage level grid connection scenario and 380V / 220V voltage level grid connection scenario. The logical topology of the 10KV voltage level grid connection scenario and the logical architecture of the 380V / 220V voltage level grid connection scenario are different. Figure 1This is a schematic diagram of the 10KV voltage level grid-connected network architecture in the information security strategy evaluation method for distributed power sources of the present invention. Figure 2 This is a schematic diagram of the 380V / 220V grid-connected network architecture in the information security strategy evaluation method for distributed power sources of the present invention.

[0035] like Figure 1 In a 10kV grid-connected scenario, data from the data acquisition server and the power generation terminal is uploaded to the local server R1 via RTU, and then transmitted to the SCADA front-end server and the SCADA server via multiple routing devices.

[0036] like Figure 2 In 380V / 220V voltage level scenarios, data from the power generation terminal is transmitted to the marketing front-end server and marketing system via multiple routing devices after passing through a concentrator or a smart converged terminal in the distribution area.

[0037] Therefore, considering the different network topologies, the threat graph construction also varies. In this invention, the assumed risks can be implemented from two different directions. Generally, attacks against the power grid mainly disrupt grid stability. This can be achieved by controlling SCADA servers and issuing erroneous control commands to remote power plants and substations, thereby disrupting grid stability. On the other hand, it can also be achieved by sending erroneous data to the grid side, triggering the grid's protection mechanisms, thus disrupting grid stability. In one embodiment, the method selects the source of the erroneous data to be constructed from the direction of the SCADA server. Therefore, the attack path is determined from top to bottom based on the topology. Taking a 10kV voltage level grid connection as an example, the top of the topology is the SCADA server, and vulnerabilities are searched downwards sequentially. Therefore, the method constructs the system's attack graph.

[0038] In one embodiment of this invention, the threat graph is constructed based on the ICS Industrial Technology Matrix in ATT&CK, which contains 12 strategies. These 12 strategies represent 12 stages of an attack, and these stages are sequential: initial access, execution, persistence, privilege escalation, defense bypass, credential access, discovery, lateral movement, information gathering, command and control, data leakage, and impact. In the actual construction of the security policy threat graph, risk targets, attack capabilities, and attack paths are determined from the ATT&CK industrial matrix based on the attack objectives, and corresponding attack strategies are selected to ultimately form the security policy threat graph.

[0039] During the attack capability verification process, the method examines the technical information related to the SCADA server, excluding technologies that do not pose a risk to the SCADA system. For example, it identifies which technologies involve remote access, which require data copying via removable media, and which include user graphical interfaces, command-line interfaces, etc., as detailed in Table 1. Each of these processes may contain different attack paths and methods. Therefore, the method constructs a threat map based on the attack methods and targets related to the technologies involved.

[0040]

[0041]

[0042] Table 1. Information on Attack Techniques Related to SCADA Servers

[0043] The aforementioned technologies can serve as nodes in the threat graph, enabling its construction. Attack paths are determined from top to bottom based on the topology. Taking a 10kV grid connection as an example, the top of the topology is the SCADA server. Based on the information in Table 1, the attack paths are determined.

[0044] Figure 3 This is a schematic diagram illustrating the attack route for obtaining SCADA server administrator privileges in the information security strategy evaluation method for distributed power sources according to the present invention. Figure 3 As shown, for ease of demonstration, only the attack path during the privilege escalation phase is considered. Subsequent policies are not included in the security policy threat graph. In addition, since the SCADA server also has downlink devices, there is an attack lateral movement scenario. Therefore, the lateral movement policy is added to the security policy threat graph.

[0045] Figure 4 This is a diagram illustrating a 10kV voltage level distributed power supply attack in an information security strategy evaluation method for distributed power sources according to the present invention. Figure 4 As shown, after constructing the security policy threat map of the SCADA server, the attack paths of the SCADA front-end server and the RTU attack paths are constructed according to the topology. The process is the same as that of constructing the SCADA server. Finally, we obtain a security policy threat map for a 10KV voltage level grid-connected scenario.

[0046] The difficulty of implementing a threat node can be evaluated from three aspects: the permissions required for technical execution, the knowledge and skills required for technical execution, and the obstacles encountered in technical execution. The permissions required for technical execution include whether an attacker needs specific access privileges to execute the technique. The knowledge and skills required for technical execution include whether an attacker needs specific knowledge, resources, and technical capabilities to execute the technique. The obstacles encountered in technical execution include whether the target system has corresponding protective measures, monitoring mechanisms, or recovery capabilities.

[0047] The attribute values ​​of the threat nodes to be evaluated are shown in Table 2.

[0048]

[0049] Table 2. Values ​​of Attributes for Threat Nodes to be Evaluated

[0050] Generally speaking, the difficulty of an attack node to be assessed is mainly reflected in the permissions required to execute the technique, the knowledge and skills required to execute the technique, and the obstacles encountered in executing the technique. The lower the required permissions, the less knowledge and skills are required, and the fewer obstacles are encountered, the easier it is to carry out the attack. Conversely, the higher the required permissions, the more knowledge and skills are required, and the more obstacles are encountered, the more difficult it is to carry out the attack.

[0051] Specifically, the permissions required for executing a technology can be: no permissions are required: executing the technology does not require any permissions, such as denial-of-service attacks or scanning techniques; or, only lower permissions are required: executing the technology requires some basic permissions, such as user permissions or the execution permission of a certain program; or, administrator privileges are required: executing the technology requires administrator privileges (administrator privileges, root privileges, etc.).

[0052] The knowledge and skills required for technical execution can be categorized as follows: No knowledge or skills required: Executing this technology requires no specific knowledge or skills and can be accomplished using automated tools, such as proactive scanning (T1595) and denial-of-service (T0813). Basic knowledge and skills required: Executing this technology requires basic knowledge and skills and necessitates certain parameter settings for the tools, such as command-line interfaces (T0807) and program uploads (T0845). High level of knowledge and skills required: Executing this technology requires a high level of knowledge and skills and necessitates the use of custom tools or scripts, such as T0830 and T0874. Specialized knowledge and skills required: Executing this technology requires specialized knowledge and skills and a sufficient understanding of the target, such as standard application layer protocols (T0869).

[0053] The obstacles to the implementation of the technology include: no security measures: the implementation of the technology will not be hindered by security measures; only security monitoring measures: the implementation of the technology will be monitored by security monitoring measures, but will not be hindered.

[0054] Security measures that increase the difficulty of execution include: the execution of the technology will be hindered by security measures, thereby increasing the difficulty of execution, such as access control based on ACL, encryption based on simple encryption algorithms, etc.

[0055] It has security protection measures and greatly increases the difficulty of technical execution: the execution of this technology will be hindered by security measures, which greatly increases the difficulty of executing the technology, such as access control based on physical isolation methods and encryption based on dedicated algorithms.

[0056] Therefore, the method quantifies the attribute values ​​of the threat nodes to be evaluated to facilitate subsequent calculations. The quantified attack attributes are shown in Table 3.

[0057] Permissions required for technical execution Knowledge and skills required for technical execution Obstacles to technology implementation 1 1 1 2 2 2 3 3 3 4 4 4

[0058] Table 3. Quantified Threat Node Attributes for Evaluation

[0059] The difficulty of the threat node attributes to be evaluated is represented by 1, 2, 3, and 4 from low to high.

[0060] Similarly, after constructing the attributes of the technical nodes, the method evaluates the entire technical implementation path. The difficulty of a technical implementation path depends not only on the difficulty of the threat nodes to be evaluated within that path, but also on the specific technologies included in that path. Therefore, simply using the average value method to evaluate the difficulty of a technical implementation path cannot accurately reflect its execution difficulty. For example, given two paths L1 and L2 with the same average technical implementation difficulty, but L1 having a longer attack path than L2, then clearly L1 has a higher technical implementation difficulty than L2.

[0061] Therefore, in order to evaluate the path more objectively, path L is defined. j There are two attributes: average skill difficulty S ave And the number of threat nodes to be assessed, m.

[0062] Step 2: For threat graph query and analysis of threat intelligence, define the baseline attributes of each threat node to be evaluated in the distributed power grid system, and assign attribute values ​​to each node in the threat graph based on the query and analysis results using the baseline attributes of each threat node to be evaluated.

[0063] The method defines three attribute values ​​for a technology: the permissions required for its execution, the knowledge and skills required for its execution, and the obstacles encountered in its execution. In practical applications, for any given technology, the required permissions and the necessary knowledge and skills are objectively real and are essential conditions for its execution. To avoid subjective errors when assigning values ​​to these two attributes, threat intelligence can be analyzed to assign values.

[0064] In the ATT&CK database, each technology is supported by corresponding threat intelligence. Therefore, you can view the threat intelligence associated with a technology to determine the values ​​of the two attributes: the permissions required to execute the technology and the knowledge and skills required to execute the technology.

[0065] For example, querying the ATT&CK database, the threat intelligence related to technology T0886 is shown in Table 4.

[0066]

[0067]

[0068] Table 4 Threat Intelligence Table for Attack Technique T0886

[0069] Technology T0886 typically achieves initial access through various application protocols. Since these protocols are based on shared or proprietary protocols, no administrative privileges are required on the target device. Therefore, the value of the "Permissions required for technology execution" attribute of this technology is "Requires lower privileges".

[0070] Although many tools are mentioned in the threat intelligence, most of these tools are written by the attackers themselves and are not publicly available. Furthermore, the payload and other content of the tools need to be set by the attackers themselves. Therefore, the value of the "knowledge and skills required for the execution of the technology" attribute is "requires a high level of knowledge and skills".

[0071] The method sets the attribute "Hinders to technical execution" to 1, meaning that the technical execution will not encounter any resistance. In this case, the calculated technical execution difficulty is the lower bound of the difficulty.

[0072] Therefore, the baseline attribute values ​​of technology T0886 obtained by the method are: permission required for technology execution = 1, knowledge and skill reserves required for technology execution = 3, and obstacles faced in technology execution = 1.

[0073] As shown in the table above, the technology typically achieves initial access through various application protocols. Since these are all based on public or private protocols, no administrative privileges are required on the target device. Therefore, the value of the "Permissions Required for Execution" attribute for technology T0886 is "Requires Low Privileges." Although many tools are mentioned in the threat intelligence, these tools are mostly written by the attackers themselves and are not publicly available. Furthermore, the tool payloads and other details need to be configured by the attackers themselves. Therefore, the value of the "Knowledge and Skills Required for Execution" attribute for this technology is "Requires High Knowledge and Skills." Setting the attribute "Obstacles to Execution" to 1 means that the technology will not encounter any resistance during execution. In this case, the calculated execution difficulty is the lower limit of the difficulty.

[0074] Thus, the baseline attribute values ​​of attack technique T0886 are obtained as 2, 3, and 1.

[0075] To calculate the execution difficulty range of the threat graph, the method constructs an execution difficulty range algorithm. To avoid bias caused by subjectivity in the execution difficulty range, the method uses the TOPSIS algorithm to determine a technique, namely the threat execution difficulty of a node.

[0076] Assuming g represents the threat node to be evaluated, m represents the number of technologies in a threat graph, and a represents the number of attributes, then a technology can be represented as g. i An attribute can be represented as g ia 1 <= i <= m, 1 <= a <= 3. Assume that for each g... i For each, there exists a positive ideal solution A+ and a negative ideal solution A-.

[0077] Therefore, the method standardizes the attributes of each technology using the following formula:

[0078]

[0079] After standardization, a standardized attribute matrix for the technology is obtained, as shown in Table 5.

[0080] technology Attribute 1 Attribute 2 Attribute 3 <![CDATA[g1]]> <![CDATA[x 11 ]]> <![CDATA[x 12 ]]> <![CDATA[x 13 ]]> <![CDATA[g2]]> <![CDATA[x 21 ]]> <![CDATA[x 22 ]]> <![CDATA[x 23 ]]> …… …… …… …… <![CDATA[g m ]]> <![CDATA[x m1 ]]> <![CDATA[x m2 ]]> <![CDATA[x m3 ]]>

[0081] Table 5. Standardized Attack Technique Attribute Matrix

[0082] Preferably, the attribute value of each path is calculated based on the attribute value of each node, and the execution difficulty range of the node attribute and the execution difficulty range of the path attribute are solved by using the attribute value of each node and the attribute value of each path respectively, so as to obtain the execution difficulty range of the threat graph, thereby generating the security strategy evaluation result for distributed power grid connection.

[0083] After the attribute values ​​are standardized, the method needs to determine the positive ideal solution A+ and the negative ideal solution A-. A+ and A- correspond to the upper and lower limits of the attribute values, respectively. Since the permissions required for technical execution and the knowledge and skills required for technical execution are objective attributes with fixed values, the values ​​of the obstacles faced by technical execution determine the positive ideal solution A+ and the negative ideal solution A-, which in this method are 4 and 1. Substituting 4 and 1 into Formula 1, the positive ideal solution A+ is:

[0084]

[0085] The negative ideal solution A- is:

[0086]

[0087] The final ideal solution A+ is:

[0088]

[0089] The negative ideal solution A- is:

[0090]

[0091] Subsequently, a comparison of a certain technology g i The distance between A+ and A- is used to derive a comprehensive score S. i This rating represents the level of difficulty in implementing this technology. S i The calculation formula is:

[0092]

[0093] In the above formula, the method obtains the level of effectiveness of a certain attack technique against nodes in the attack graph. Similarly, because the method uses standardization, the calculation of positive and negative ideal solutions and the difficulty level of the calculated technique can also be performed using standardized data.

[0094] An attack graph has n paths, and each path has m paths. i One attack, then path L j The average attack difficulty is:

[0095]

[0096] In the formula, the path attribute matrix is ​​constructed as shown in Table 6.

[0097] path Average technical difficulty Number of technologies <![CDATA[L1]]> <![CDATA[S 1ave ]]> <![CDATA[m1]]> <![CDATA[L2]]> <![CDATA[S 2ave ]]> <![CDATA[m2]]> …… <![CDATA[L n ]]> <![CDATA[S nave ]]> <![CDATA[m n ]]>

[0098] Table 6 Path Attribute Matrix

[0099] The matrix elements are standardized by index, L j Standardized attribute x ja for:

[0100]

[0101] g ja For path L j The attribute values. After standardization, the method calculates the positive ideal solution A+ and the negative ideal solution A-. Then, the maximum and minimum values ​​of the attribute values ​​are selected respectively, i.e.:

[0102]

[0103]

[0104] Finally, path L is obtained. i Overall difficulty rating SLi for:

[0105]

[0106] After evaluating each path, we construct a threat graph to represent the overall average difficulty.

[0107] Once the threat graph is determined, the number of paths can be determined. Adding protective measures will not reduce or change the paths, but only change the overall difficulty of the paths. The correlation between different paths is not significant. Therefore, the average difficulty of the threat graph can be calculated using the averaging method, which is to take the average value of the paths.

[0108]

[0109] The baseline attributes of all technologies in the threat graph are defined, and the attack difficulty of the threat graph calculated based on this baseline is the lower limit G of the attack difficulty of the current threat graph. min Set the attribute values ​​of all technologies in the threat graph to the maximum, i.e., g. i = [4,4,4], then calculate the upper limit of attack difficulty G of the current threat graph. max Determine the execution difficulty range of the current threat graph, which is (G). min G max ).

[0110] Once the difficulty range of the attack graph is determined, the security protection strategy can be scored. Determining the protection level involves reviewing existing security strategies to see if they can increase the difficulty of implementing each attack technique in the attack graph. Taking T0886 as an example, T0886 can be implemented through various remote protocols; for example, for a SCADA server, there are protocols such as RDP and SMB. Looking at existing security strategies, the HIDS installed on the SCADA server can monitor and intercept traffic information entering and leaving the SCADA server in real time. However, since HIDS is based on a signature database, if the attack payload is carefully crafted, it can bypass HIDS detection. In this case, HIDS increases the attack difficulty level. Therefore, its attribute "obstacles to technique execution" should be "has security protection measures and increases the difficulty of technique execution."

[0111] After adding the protection level, the T0886 attribute values ​​were modified to 2, 3, 3, which correspondingly changed the difficulty of technical execution.

[0112] After modifying the server program, the method can calculate the technical execution difficulty under the current protection strategy, and use the risk range of the threat graph as the basis for the scoring system to obtain the security strategy evaluation result for the distributed power grid connection:

[0113]

[0114] Among them, G min and G max The risk range is represented by G, which is the score after the strategy improvement.

[0115] Multiple security strategies are scored, with higher scores indicating greater difficulty in attack and thus greater security. The score range is (0, 100). Therefore, when evaluating a specific security strategy, a higher score generally indicates greater security.

[0116] In one embodiment, the attribute baseline calibration results are shown in Table 7.

[0117]

[0118]

[0119] Table 7 Attribute baseline calibration results

[0120] A technique might have different assignments in the two phases. For example, T0859 might be assigned (1, 3, 1) in the Lateral Movement phase and (3, 2, 1) in the Persistence phase. This is because, in some cases, the default credentials for controlling system devices may be publicly available. Leaked credentials can be used to bypass access controls on various resources on the host and within the network, and may even be used for persistent access to remote systems. Compromised and default credentials can also grant adversaries additional privileges on specific systems and devices, or access to restricted areas of the network. Attackers might choose not to use malware or tools, and the legitimate access provided by these credentials, to make it more difficult to detect their presence or control devices and send legitimate commands in unexpected ways. Alternatively, attackers might create accounts, sometimes using predefined usernames and passwords, to provide a backup method for persistent access. Therefore, the assignment of T0859 is not the same in different phases.

[0121] After standardization, the above table is obtained as Table 8.

[0122]

[0123] Table 8 Standardization Table

[0124] Subsequently, based on the calculation of the positive and negative ideal solutions, the positive and negative ideal solutions of the SCADA threat map are obtained as follows: A+ = [0.43133109281375365, 0.363636363636365, 1.0] and A- = [0.10783277320343841, 0.090909090909091, 0.25]. The technical execution difficulty is thus obtained as shown in Table 9.

[0125]

[0126] Table 9 Technical Implementation Difficulty

[0127] In this invention, there are a total of 80 technical implementation paths, and the path attribute matrix is ​​shown in Table 10.

[0128] path Technical difficulty Number of technologies 1 0.18825023660454027 4 2 …… ……

[0129] Table 10 Path Attribute Matrix

[0130] After standardization, the standardized matrix is ​​shown in Table 11.

[0131] path Technical difficulty Number of technologies 1 0.09354648785617958 0.11180339887498948 2 0.10812912921864118 0.11180339887498948 3 …… ……

[0132] Table 11 Standardization Matrix

[0133] Subsequently, the positive ideal solution A+ was calculated to be [0.139232641351327, 0.11180339887498948], and the negative ideal solution A- was calculated to be [0.07938174805179811, 0.11180339887498948]. Finally, according to the formula, we obtained the path score as shown in Table 12.

[0134] path Technical Difficulty Score 1 0.23666714101480196 2 0.4803166599865828 3 ……

[0135] Table 12 Path Scoring

[0136] Next, calculate the overall threat map execution difficulty: G = 0.5257580033654309, which is the lower limit of the current map difficulty G. min =0.5257580033654309. Setting all attribute values ​​to the maximum yields the current graph's execution difficulty cap, G. max =0.5417070495662349, meaning the execution difficulty range of this graph is (0.5257580033654309, 0.5417070495662349).

[0137] Therefore, the method yields the range of threat graph execution difficulty.

[0138] In one embodiment of this invention, the SCADA server is located in the main station's security zone 1, and is equipped with security measures such as HIDS, antivirus, and trusted computing. The SCADA server uses a domestically developed operating system, which greatly reduces the occurrence of vulnerabilities. For communication, the SCADA server interacts with the production management zones through forward and reverse isolation devices, which constitute physical isolation. Data transmission is performed using e-text, which prevents the transmission of malicious code. Regarding the workstations, the workstations are not connected to the internet, and corresponding protective measures are deployed on them. Like the SCADA server, the workstations also use a domestically developed operating system. Therefore, the method can adjust the attribute values ​​assigned to each node according to the actual configuration, thereby recalculating the risk score of the graph.

[0139] After reassignment, under security policy A, the attack difficulty of the SCADA attack graph is G = 0.531045171840125. Using the Score formula, the score for security policy A is 33.15037406078601.

[0140] Furthermore, TOPSIS (Technique for Order of Preference by Similarity to Ideal Solution), mentioned in this invention, is a multi-attribute decision analysis method aimed at determining the optimal decision solution. Based on the concept of Euclidean distance, it compares the distance between each decision solution and the ideal solution, as well as the distance between each decision solution and the negative ideal solution, thereby determining the optimal solution.

[0141] ICS is an abbreviation for Industrial Control System, which refers to computer systems used to monitor and control industrial processes, such as power grids, water conservancy, petrochemicals, and manufacturing. Industrial control systems typically include components such as Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and Programmable Logic Controllers (PLCs). The security of industrial control systems is a critical issue because they can be vulnerable to cyberattacks or malware, potentially impacting critical infrastructure and services.

[0142] SCADA is an industrial control system used for real-time monitoring and control of industrial equipment, assets, processes, and events. RTU is an abbreviation for Remote Terminal Unit, which is an electronic device used for remote monitoring and control of industrial equipment, assets, processes, and events.

[0143] Furthermore, the method also employs the concept of attack graphs. An attack graph is a graphical method for describing and analyzing the lifecycle of a cyberattack. Attack graphs can help security personnel understand and defend against cyber threats, providing a common language and methodology for assessing and improving security capabilities.

[0144] The basic idea of ​​an attack graph is to represent various security elements in a network (such as hosts, services, vulnerabilities, and privileges) and attacker behaviors (such as exploiting vulnerabilities, privilege escalation, and lateral movement) using vertices and edges, forming a directed graph. Each edge represents an atomic attack, and each vertex represents an attack state or condition. Attack graphs can show all possible attack paths and effects in a network, thereby helping security personnel discover network vulnerabilities, select optimal defense strategies, and reduce network risks and losses.

[0145] The generation of attack graphs requires certain rules and derivation systems, which reflect factors such as network security configurations, vulnerability information, and attacker capabilities. The process of generating attack graphs is similar to mathematical derivation, starting from initial conditions and deriving all possible attack targets and attack paths based on rules.

[0146] Attack graphs have applications in network security assessment, attack detection, attack prediction, and attack defense. They help security personnel identify network vulnerabilities, select optimal defense strategies, and reduce network risks and losses.

[0147] The ATT&CK framework is a cybersecurity knowledge base developed by the US non-profit organization MITRE. It collects adversary tactics and techniques based on real-world observations to describe and analyze the lifecycle of cyberattacks. The purpose of the ATT&CK framework is to help security professionals better understand and defend against cyber threats, providing a common language and methodology for assessing and improving security capabilities. The ATT&CK framework includes the following components: tactics, techniques, sub-techniques, data sources, mitigation, software, and activities. Descriptions and links to use cases for the ATT&CK framework include: cybersecurity assessment, attack detection, attack prediction, and attack defense.

[0148] The method of this invention can also be calculated using attack count methods. For example, leaf nodes can be quantified using indicators, and multi-attribute utility theory can be employed to assign three security attributes to each leaf node. The probability of a leaf node being successfully attacked is... Among them, W cost W diff W detLet U(x) represent the weight of the security attribute, and U(x) represent the utility value of the security attribute. It is assumed that the utility value is inversely proportional to the security attribute score: U(x) = c / x. To reduce subjectivity, a fuzzy analytic hierarchy process (FAHP) is used to calculate the weight corresponding to each security attribute. A fuzzy judgment matrix is ​​constructed based on the scale table. Finally, the weights of the three attributes are obtained from the matrix using the least squares method, as shown in the formula:

[0149]

[0150] Where n is the matrix order and a is the weighting factor.

[0151] Among them, the probability of the parent node of a node with an "OR" logical relationship is 1.

[0152] P = max{P1, P2, ..., P} n}

[0153] A node that has an AND logical relationship has a parent node with a probability of being realized.

[0154] P = P1 × P2 × ... × P n

[0155] A node with a sequential AND logical relationship has a parent node with a probability of being realized.

[0156] P=P1×P(2|1)×P(3|1,2)×....P(n|1,2,...n)

[0157] Finally, the success probability of attacking the root node is obtained, using the formula:

[0158]

[0159] Among them, S i S represents an attack path, which is a set of attack sequences from leaf nodes. i ={L1,L2,...,L n}, where k is the number of attack paths.

[0160] Considering the subjective nature of the rating method in this approach, and the fact that it doesn't reflect the impact of existing security measures on the score, the analytic hierarchy process (AHP) relies heavily on expert experience in calculating security attribute weights (Table 3), making it highly subjective. Furthermore, evaluating the overall success probability of an attack chain is not applicable to evaluating domain security protection levels. Therefore, the previous embodiment is considered the optimal implementation.

[0161] A second aspect of this invention relates to a security strategy assessment system based on threat graph difficulty using the method of the first aspect of this invention. The system includes an acquisition module, an allocation module, and an assessment module. The acquisition module is used to acquire the network topology of a distributed power grid-connected system, construct a threat graph for the distributed power grid-connected system, the threat graph including nodes and technical implementation paths corresponding to the threat nodes to be assessed. The allocation module is used to query and analyze threat intelligence based on the threat graph, define baseline attributes for each of the threat nodes to be assessed in the distributed power grid-connected system, and assign attribute values ​​to each node in the threat graph using the baseline attributes of each of the threat nodes to be assessed. The assessment module is used to calculate the attribute value of each path based on the attribute value of each node, and use the attribute values ​​of each node and each path to solve for the risk range of the node attributes and the risk range of the path attributes, respectively, to obtain the risk range of the threat graph, thereby generating a security strategy assessment result for the distributed power grid-connected system.

[0162] A third aspect of the present invention relates to a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to perform the steps of the method according to the first aspect of the present invention.

[0163] A fourth aspect of the present invention relates to a computer-readable storage medium having a computer program stored thereon, characterized in that the program, when executed by a processor, implements the steps of the method of the first aspect of the present invention.

[0164] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for evaluating information security strategies for distributed power sources, characterized in that, The method includes the following steps: Obtain the network topology of the distributed power supply power monitoring system, and construct a threat map for the distributed power supply power monitoring system. The threat map includes device nodes, threat nodes to be evaluated, and technical implementation paths. For querying and analyzing threat intelligence in the threat graph, baseline attributes are defined for each threat node to be evaluated in the distributed power monitoring system. These baseline attributes include the permissions required for technical execution, the required knowledge and skills, and the obstacles encountered during execution. The required permissions include no permissions, basic permissions, administrator permissions, and system permissions. The required knowledge and skills include no knowledge or skills, basic knowledge and skills, the ability to use self-made tools or scripts, and specialized knowledge and skills. The obstacles encountered during execution include no security measures, only security monitoring measures, security protection measures that increase the difficulty of execution, and security protection measures that greatly increase the difficulty of execution. Based on the query and analysis results, attribute values ​​are assigned to each node in the threat graph using the baseline attributes of each threat node to be evaluated. The attribute value of each path is calculated based on the attribute value of each node. The execution difficulty of the node attribute and the execution difficulty of the path attribute are solved by using the attribute value of each node and the attribute value of each path respectively, so as to obtain the execution difficulty range of the threat graph. The security measures in the current scenario are analyzed and the analysis results are substituted into the threat nodes to be evaluated. The execution difficulty of the threat graph is recalculated, and the evaluation result of the security strategy for the grid connection of the distributed power supply is generated by combining the execution difficulty range of the threat graph.

2. The information security strategy evaluation method for distributed power sources according to claim 1, characterized in that: The technical implementation path includes attribute information; The attribute information of the technical implementation path includes the average technical difficulty and the number of threat nodes to be evaluated.

3. The information security strategy evaluation method for distributed power sources according to claim 2, characterized in that: A node attribute matrix is ​​constructed based on the attribute values ​​of each node in the threat graph, and then standardized. Calculate the range of execution difficulty for each node attribute after standardization, as well as the execution difficulty for each threat node to be evaluated.

4. The information security strategy evaluation method for distributed power sources according to claim 3, characterized in that: Based on the technical execution difficulty range of each threat node to be evaluated, the average technical execution difficulty range of each path is calculated and used as the attribute value of each path in the threat graph; A node attribute matrix is ​​constructed based on the attribute values ​​of each path in the threat graph, and then standardized. Calculate the range of execution difficulty for each path attribute after standardization.

5. The information security strategy evaluation method for distributed power sources according to claim 4, characterized in that: The execution difficulty range of the threat graph is calculated based on the technical difficulty range of the execution difficulty range of each path; The range of execution difficulty of the threat graph is used as the upper and lower limits of the execution difficulty of the threat graph, thereby obtaining the range of execution difficulty of the threat graph.

6. The information security strategy evaluation method for distributed power sources according to claim 5, characterized in that: Analyze the current security policy and substitute it into the node attribute matrix. Reassign values ​​to the node attribute matrix to obtain the attack difficulty of the threat graph under the current security policy.

7. The information security strategy evaluation method for distributed power sources according to claim 6, characterized in that: Based on the attack difficulty of the threat graph and the attack difficulty range of the threat graph under the current security measures, the evaluation result of the current security strategy is calculated.

8. A system for evaluating information security strategies for distributed power sources using the method described in any one of claims 1-7, characterized in that: The system includes an acquisition module, an allocation module, and an evaluation module; wherein... The acquisition module is used to acquire the network topology of the distributed power grid-connected system and construct a threat map for the distributed power grid-connected system. The threat map includes device nodes, threat nodes to be evaluated, and technical implementation paths. The allocation module is used to query and analyze threat intelligence for the threat graph, define the baseline attributes of each threat node to be evaluated in the distributed power grid system, allocate attribute values ​​to each node in the threat graph based on the query and analysis results using the baseline attributes of each threat node to be evaluated, and calculate the attack difficulty range of the current threat graph based on the allocated baseline. The evaluation module analyzes the security policy of the current scenario, uses the analysis results to reassign node attributes, and thus generates an evaluation result of the security policy of the current scenario.

9. A terminal, comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is configured to operate according to the instructions to perform the steps of the method according to any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method according to any one of claims 1-7.