Power Internet of Things Information Security Risk Assessment Method, Device, Equipment and Medium

By constructing an information security risk assessment index system for the power Internet of Things and combining it with the particle swarm optimization algorithm and logistic chaos mapping to optimize weights, the problems of one-sidedness and subjectivity of the assessment results in the existing technology are solved, and the accuracy and robustness of the information security risk assessment of the power Internet of Things are achieved.

CN118842640BActive Publication Date: 2025-09-16STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411036904.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-31
Publication Date
2025-09-16
Estimated Expiration
2044-07-31

AI Technical Summary

Technical Problem

Existing technologies in the information security risk assessment of the power Internet of Things have problems such as one-sided and subjective assessment results and failure to consider dynamic factors, making it difficult to accurately assess the overall risk situation of the system.

Method used

The AHP hierarchical model is used to construct an information security risk assessment index system. The particle swarm optimization algorithm and Logistic chaos mapping are combined to optimize the weights. By obtaining asset value and security vulnerability data, an asset value assessment and vulnerability assessment index system is constructed. The weights are optimized through the particle swarm optimization algorithm to achieve accuracy and robustness of risk assessment.

Benefits of technology

It improves the efficiency and robustness of information security risk assessment of the power Internet of Things, reduces the subjectivity of manual scoring, ensures the accuracy and real-time nature of the assessment results, and alleviates consistency issues in the assessment process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842640B_ABST
    Figure CN118842640B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, equipment and medium for assessing information security risks of an electric power Internet of Things, and belongs to the field of information security technology. The method comprises: obtaining asset data and corresponding security vulnerability data in an electric power scenario, wherein the security vulnerability data includes frequency data of security incidents; constructing an information security risk assessment index system for an electric power Internet of Things system through the asset data and security vulnerability data; assigning weights to the index data in the information security risk assessment index system; and assessing the information security risks of an electric power Internet of Things system based on the frequency data of security incidents and weight data. The present invention optimizes expert scoring weights through a particle swarm optimization algorithm and a logistic chaos map, thereby alleviating the subjectivity of strong reliance on manual scoring, while ensuring that the weights have expert experience fidelity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology and relates to a method, device, equipment and medium for assessing information security risks of an electric power Internet of Things. Background Art

[0002] The Power Internet of Things (PoI) is the practical application of IoT technology combined with power systems. It integrates various information sensing, communication, smart metering, and access control functions. It covers a wide variety of devices and protocols, and can present complex risks when conducting cross-platform information transmission and data sharing. The risk assessment model for the Power Internet of Things system aims to measure the integrity of assets across all dimensions of the system through risk identification, risk analysis, and risk calculation, and assess the risk status faced by the system based on the frequency of threats, severity of vulnerabilities, and asset value. Single-dimensional assessment indicators in the Power Internet of Things system cannot accurately assess the overall risk situation. Developing a more comprehensive assessment method that rationally utilizes multi-dimensional risk assessment indicators is crucial for preventing potential risks in the Power Internet of Things system.

[0003] Existing techniques generally employ methods such as the Delphi method, the Analytic Hierarchy Process (AHP), and the Risk Matrix method for comprehensive risk assessment of the Power Internet of Things (PoI). The Delphi method relies on experts to evaluate the importance of individual indicators without comparing them with each other, resulting in biased assessment results. The AHP method determines the relative importance of indicators at each level based on a judgment matrix and refines and optimizes the manually determined relative importance weights using entropy weighting, fuzzy functions, or heuristic algorithms such as particle swarm optimization, genetic algorithms, and simulated annealing. This allows the revised manual scoring to pass consistency checks and eliminate logical errors. However, assessments based solely on expert experience are still subjective and fail to consider dynamic factors such as the frequency of threat events and the extent of asset damage within the Power Internet of Things (PoI). In information security assessments, a risk matrix is ​​established based on information such as the frequency of threat events detected and statistically analyzed, the number of damaged equipment, and other information to estimate the likelihood of a threat event and the extent of the loss, and to calculate a quantitative risk value. However, the asset value and vulnerability severity involved in the quantitative calculation still require manual assignment, which still requires mitigating subjectivity. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a method, device, equipment and medium for information security risk assessment of the power Internet of Things, thereby improving the efficiency and robustness of information security risk assessment.

[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions:

[0006] In a first aspect, the present invention provides a method for assessing information security risks in an electric power Internet of Things, comprising:

[0007] Acquire asset data and corresponding security vulnerability data in the power scenario, wherein the security vulnerability data includes frequency data of security incidents;

[0008] An information security risk assessment index system for the power Internet of Things system is constructed based on the asset data and security vulnerability data. The information security risk assessment index system includes an asset value assessment index system and a vulnerability assessment index system.

[0009] Assigning weights to indicator data in the information security risk assessment indicator system;

[0010] Based on the frequency data and weight data of safety accidents, the information security risks of the power Internet of Things system are assessed.

[0011] Furthermore, the risk assessment index system is constructed through the AHP hierarchical structure model, and its target layer includes an asset value assessment index system and a vulnerability assessment index system;

[0012] The criterion layers of the asset value assessment index system and the vulnerability assessment index system both include: cloud platform, communication transmission, edge side and terminal perception.

[0013] Furthermore, assigning weights to the indicator data of the risk assessment indicator system includes: obtaining asset value evaluation scores; constructing a judgment matrix for the indicator layer data corresponding to each criterion layer in the asset value assessment indicator system based on the obtained asset value evaluation scores; and calculating weights through the judgment matrix;

[0014] Obtain security vulnerability evaluation scores; construct a judgment matrix for indicator layer data corresponding to each criterion layer in the vulnerability assessment indicator system based on the obtained security vulnerability vulnerability evaluation scores; and calculate and obtain weights through the judgment matrix.

[0015] Furthermore, the method further includes: optimizing the weight, including:

[0016] Perform consistency check on the judgment matrix of each criterion layer;

[0017] If the consistency check fails, a fitness objective function and its constraints on the elements of the judgment matrix are established; and the fitness objective function with the constraints is solved to optimize the weights.

[0018] Furthermore, the fitness objective function calculation formula is:

[0019] ,

[0020] in, represents the number of criteria layer items, Indicates the The judgment matrix of the criterion layer, express The order of Indicates the optimized The consistency ratio, Indicates the optimized The offset distance, and is the weight of the two, and the value range is , ;

[0021] express The largest characteristic root of express No. OK Column elements, , , Indicates the optimized No. OK Column elements;

[0022] The constraints include: .

[0023] Furthermore, the fitness objective function with constraints is solved to optimize the weights, including: using a particle swarm optimization algorithm to change Size, to solve the output of the fitness objective function with constraints; get the output of the fitness objective function corresponding to The judgment matrix is ​​reconstructed through it, and the optimized weights are calculated.

[0024] Furthermore, the particle swarm is updated as follows:

[0025] ,

[0026] in, Indicates the The speed at which particles move in the next generation, Indicates the The position of the next generation of particles, Indicates the current iteration speed of the particle swarm, Indicates the current iteration position of the particle swarm; represents the number of particle iterations, represents the maximum number of iterations, Indicates the first particles, Indicates the size of the population, represents the global optimal solution of the population, represents the optimal solution of individual particles, represents the nonlinear inertia weight coefficient, and are the learning factors of particles learning from their own historical experience and the optimal individual in the group, is a random value uniformly distributed in the interval [0, 1]; is the state value of the chaos map, and its value range is (0, 1).

[0027] In a second aspect, the present invention further provides a device for assessing information security risks in the electric power Internet of Things, the device comprising:

[0028] A power data acquisition module, configured to acquire asset data and corresponding security vulnerability data in power scenarios, wherein the security vulnerability data includes frequency data of security incidents;

[0029] An information security risk assessment indicator system construction module is used to construct an information security risk assessment indicator system for the power Internet of Things system based on the asset data and security vulnerability data. The information security risk assessment indicator system includes an asset value assessment indicator system and a vulnerability assessment indicator system.

[0030] A weight allocation module, used to allocate weights to indicator data in the information security risk assessment indicator system;

[0031] The information security risk assessment module is used to assess the information security risk of the power Internet of Things system based on the frequency data and weight data of the security incidents.

[0032] Furthermore, the device also includes a risk warning module, which is used to issue a risk warning to the target enterprise if the subsequent event in the second prediction result is a risk event and the probability of occurrence of the subsequent event exceeds a preset threshold.

[0033] In a third aspect, the present invention further provides a computer device, comprising:

[0034] Memory for storing computer programs;

[0035] A processor is used to execute the computer program to implement the steps of the above-mentioned power Internet of Things information security risk assessment method.

[0036] In a fourth aspect, the present invention further provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the steps of the above-mentioned power Internet of Things information security risk assessment method.

[0037] Compared with the prior art, the present invention has the following beneficial effects:

[0038] The power Internet of Things information security risk assessment method provided by this invention constructs an information security risk assessment index system based on asset information and its corresponding security vulnerabilities. It also assigns weights to the indicator data within the information security risk assessment index system, taking into account the correlation and relative importance of factors influencing information security, ensuring the accuracy and robustness of the risk assessment. By optimizing expert scoring weights using a particle swarm optimization algorithm combined with logistic chaos mapping, this method avoids the problem of low real-time risk assessment caused by repeated manual scoring when consistency checks fail, simplifying the assessment process and alleviating the subjectivity of heavy reliance on manual scoring while ensuring that the optimized weights maintain a certain fidelity to expert experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 A schematic diagram of a flow chart of a method for assessing information security risks in the electric power Internet of Things provided by an embodiment of the present invention;

[0040] Figure 2 A comparison diagram of the change curves of the consistency ratio CR when solving the fitness objective function by the MPSO algorithm and the AMPSO algorithm of the present invention;

[0041] Figure 3 A comparison diagram of the change curve of the offset distance Dst when solving the fitness objective function by the MPSO algorithm and the AMPSO algorithm of the present invention;

[0042] Figure 4 A comparison diagram of the change curves of the Pareto solutions of the fitness functions of the MPSO algorithm and the AMPSO algorithm of the present invention;

[0043] Figure 5 A schematic diagram of the structure of a power Internet of Things information security risk assessment device provided by an embodiment of the present invention;

[0044] Figure 6 This is a diagram of the internal structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0045] The technical solution of the present invention is described in detail below through the accompanying drawings and specific embodiments. The same reference numerals in the drawings indicate the same or similar components or parts. It should be understood by those skilled in the art that these drawings are not necessarily drawn to scale. The embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations of the technical solution of the present application. In the absence of conflict, the embodiments of the present application and the technical features in the embodiments can be combined with each other.

[0046] The term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Additionally, the character " / " in this document generally indicates that the related objects are in an "or" relationship.

[0047] Example 1:

[0048] like Figures 1 to 4 As shown, an embodiment of the present invention provides a method for assessing information security risks of the power Internet of Things. Figure 1 This is a flow chart of the method for assessing information security risks in the power Internet of Things. This flow chart only shows the logical sequence of the method in this embodiment. In other possible embodiments of the present invention, different methods may be used without conflict. Figure 1 The steps shown or described are accomplished in the order shown.

[0049] The power Internet of Things information security risk assessment method provided in this embodiment can be applied to a terminal and can be executed by a power Internet of Things information security risk assessment device, which can be implemented by software and / or hardware and can be integrated into a terminal.

[0050] See also Figure 1 The method of the embodiment of the present invention specifically includes the following steps 1 to 4. Among them:

[0051] Step 1: Obtain asset data and corresponding security vulnerability data in the power scenario, wherein the security vulnerability data includes frequency data of security incidents.

[0052] Acquiring asset data in power scenarios involves collecting electrical safety parameters for transformers in substation scenarios, transmission line voltage and current load, and performance parameters such as equipment wear and tear and maintenance records for distribution facilities in transmission scenarios. Acquiring security vulnerability data in power scenarios involves identifying potential threats and risks in the system through vulnerability mining and detection technologies deployed on the power IoT cloud platform, as well as abnormal events recorded in security audit logs. These include edge device failures, network communication denial-of-service attacks, and cloud container runtime vulnerabilities.

[0053] In an embodiment of the present invention, asset data and corresponding security vulnerability data in the power scenario are obtained from four dimensions: cloud platform, communication transmission, edge side, and terminal perception. The security vulnerabilities in the security vulnerability data will destroy the value of the corresponding asset data.

[0054] Step 2: Build an information security risk assessment index system for the power Internet of Things system based on the asset data and security vulnerability data. The information security risk assessment index system includes an asset value assessment index system and a vulnerability assessment index system.

[0055] As shown in Table 1, in this embodiment of the present invention, an information security risk assessment indicator system for the power Internet of Things system is constructed using the AHP (Analytic Hierarchy Process) hierarchical model. Its target layer includes an asset value assessment indicator system and a vulnerability risk assessment indicator system. The criterion layer for both the asset value assessment indicator system and the vulnerability risk assessment indicator system includes cloud platforms, communication transmission, edge devices, and terminal perception.

[0056] Table 1 Information security risk assessment indicator system for power Internet of Things systems

[0057]

[0058] Step 3: Assign weights to the indicator data in the information security risk assessment indicator system.

[0059] Step 3 specifically includes: obtaining an asset value evaluation score; constructing a judgment matrix for the indicator layer data corresponding to each criterion layer in the asset value evaluation index system based on the obtained asset value evaluation score; and calculating weights using the judgment matrix. Obtaining a security vulnerability evaluation score; constructing a judgment matrix for the indicator layer data corresponding to each criterion layer in the vulnerability evaluation index system based on the obtained security vulnerability evaluation score; and calculating weights using the judgment matrix.

[0060] The asset value evaluation score is based on the relative value of the assets and is generated through expert scoring; the security vulnerability evaluation score is based on the relative vulnerability of the security vulnerability and is generated through expert scoring.

[0061] The expert scoring standard refers to the 9-level scaling method of AHP. Table 2 shows the expert scoring standard for the indicator layer data of the asset value evaluation index system.

[0062] Table 2 AHP 9-level scaling method

[0063]

[0064] When there are many risk factors in the judgment matrix, manual scoring may lead to contradictory logical errors in the results of pairwise comparisons of various indicators. Therefore, it is necessary to perform a consistency test on the judgment matrix of each criterion layer. If the consistency test fails, the weights need to be optimized.

[0065] The present invention reconstructs the judgment matrix by establishing a fitness objective function and its constraints on the elements of the judgment matrix, solving the fitness objective function with the constraints, and calculating the optimized weights through the reconstructed judgment matrix.

[0066] The calculation formula of the fitness objective function is:

[0067] ,

[0068] in, represents the number of criteria layer items, Indicates the The judgment matrix of the criterion layer, express The order of Indicates the optimized The consistency ratio, Indicates the optimized The offset distance, and is the weight of the two, and the value range is , In this embodiment, it is set to , ;

[0069] express The largest characteristic root of express No. OK Column elements, , , Indicates the optimized No. OK Column elements;

[0070] The constraints include:

[0071] Using the improved particle swarm optimization algorithm, the output of the fitness objective function with the constraints is minimized. ,The improvement method is to use the Logistic chaos mapping method to ,randomly initialize and update the particle population position.

[0072] The particle swarm is updated as follows:

[0073]

[0074] in, Indicates the The speed at which particles move in the next generation, Indicates the The position of the next generation of particles, Indicates the current iteration speed of the particle swarm, Indicates the current iteration position of the particle swarm; represents the number of particle iterations, represents the maximum number of iterations, Indicates the first particles, Indicates the size of the population, represents the global optimal solution of the population, represents the optimal solution of individual particles, It represents the nonlinear inertia weight coefficient, and its calculation formula is:

[0075] ,

[0076] and are the learning factors of particles learning from their own historical experience and the optimal individual in the group, is a random value uniformly distributed in the interval [0, 1]; is the state value of the chaos map, and its value range is (0, 1).

[0077] By adaptive inertia weight Update the current velocity and position coordinates of the particles to guide the initial population particles to move towards the global optimal solution. At the same time, build a Pareto solution archive and update the record of the Pareto optimal solution. The Pareto optimal solution refers to a non-inferior compromise solution that improves other objectives without sacrificing any one objective in the multi-objective optimization process of a given system. According to the search rules of the Pareto solution, the elements in the judgment matrix are screened and the inferior solutions that do not belong to the solution set are excluded to obtain the consistency ratio. , and retain the optimal solution of the relative importance weights of each level with a certain fidelity of expert review.

[0078] In order to verify the effect of updating the particle swarm position by the Logistic chaos mapping method, the judgment matrix is ​​solved by directly using the particle swarm optimization algorithm (MPSO) and the improved algorithm (AMPSO) of the present invention. [ 1 1 / 4 1 / 2 1 / 3 8 4 1 2 1 / 3 9 / 2 2 1 / 2 1 2 7 3 3 1 / 2 1 3 / 2 1 / 8 2 / 9 1 / 7 2 / 3 1 ] The fitness objective function , the results are shown in Table 3 below, Figures 2 to 4 The specific optimization process comparison of the two algorithms is shown.

[0079] Table 3 Results of MPSO algorithm and AMPSO algorithm of the present invention for solving fitness objective function

[0080]

[0081] Obtained by solving Reconstruct the judgment matrix and calculate the optimized weights.

[0082] Step 4: Based on the frequency data and weight data of security incidents, evaluate the information security risks of the power Internet of Things system.

[0083] According to the calculation formula in GB / T 20984-2022 Information Security Risk Assessment Method: , where A, T, and V represent device assets, security incident probability, and security vulnerability, respectively. The embodiment of the present invention quantifies the risk value to assess the risk level of each criterion layer.

[0084] The formula for calculating quantitative risk value is:

[0085] ,

[0086] in, represents the number of criteria layer items, Represents the asset value, and its calculation formula is:

[0087] ,

[0088] Indicates the vulnerability of security vulnerabilities, and the calculation formula is the same as Similarly, Indicates the frequency of safety incidents.

[0089] Example 2:

[0090] Based on the same inventive concept as Example 1, this embodiment of the present invention also provides a power Internet of Things information security risk assessment device for implementing the above-mentioned power Internet of Things information security risk assessment method. The implementation solution provided by this device is similar to the implementation solution described in the above-mentioned method. Therefore, the specific limitations in the power Internet of Things information security risk assessment device embodiment provided below can be found in the above-mentioned limitations of the power Internet of Things information security risk assessment method and will not be repeated here.

[0091] like Figure 5 As shown, an embodiment of the present invention provides an information security risk assessment device for the power Internet of Things, comprising:

[0092] A power data acquisition module, configured to acquire asset data and corresponding security vulnerability data in power scenarios, wherein the security vulnerability data includes frequency data of security incidents;

[0093] An information security risk assessment indicator system construction module is used to construct an information security risk assessment indicator system for the power Internet of Things system based on the asset data and security vulnerability data. The information security risk assessment indicator system includes an asset value assessment indicator system and a vulnerability assessment indicator system.

[0094] A weight allocation module, used to allocate weights to indicator data in the information security risk assessment indicator system;

[0095] The information security risk assessment module is used to assess the information security risk of the power Internet of Things system based on the frequency data and weight data of the security incidents.

[0096] Example 3:

[0097] The embodiment of the present invention further provides a computer device, which may be a server, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements the power Internet of Things information security risk assessment method in the aforementioned embodiment.

[0098] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0099] Example 4:

[0100] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the following method:

[0101] Acquire asset data and corresponding security vulnerability data in the power scenario, wherein the security vulnerability data includes frequency data of security incidents;

[0102] An information security risk assessment index system for the power Internet of Things system is constructed based on the asset data and security vulnerability data. The information security risk assessment index system includes an asset value assessment index system and a vulnerability assessment index system.

[0103] Assigning weights to indicator data in the information security risk assessment indicator system;

[0104] Based on the frequency data and weight data of safety accidents, the information security risks of the power Internet of Things system are assessed.

[0105] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0107] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0108] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0109] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which are all protected by the present invention.

Claims

1. A method for assessing information security risks of the power Internet of Things, characterized in that: include: Acquire asset data and corresponding security vulnerability data in the power scenario, wherein the security vulnerability data includes frequency data of security incidents; An information security risk assessment index system for the power Internet of Things system is constructed based on the asset data and security vulnerability data. The information security risk assessment index system includes an asset value assessment index system and a vulnerability assessment index system. Assigning weights to indicator data in the information security risk assessment indicator system; Assess the information security risk of the power Internet of Things system based on the frequency data and weights of the security incidents; The weights are calculated based on a judgment matrix, which is constructed based on the indicator layer data corresponding to each criterion layer in the information security risk assessment indicator system; Perform consistency check on the judgment matrix of each criterion layer; If the consistency check fails, establishing a fitness objective function and its constraints for the elements of the judgment matrix; solving the fitness objective function with the constraints to optimize the weights; The fitness objective function calculation formula is: , in, represents the number of criteria layer items, Indicates the The judgment matrix of the criterion layer, Indicates the optimized The consistency ratio, Indicates the optimized The offset distance, and are the weights of the two, express No. OK Column elements; is based on Elements and optimized Elements Calculated; Furthermore, the fitness objective function with constraints is solved to optimize the weights, including: using a particle swarm optimization algorithm to change Size, to solve the output of the fitness objective function with constraints; get the output of the fitness objective function corresponding to The judgment matrix is ​​reconstructed through it, and the optimized weights are calculated.

2. The method for assessing information security risks of the electric power Internet of Things according to claim 1, characterized in that: The risk assessment index system is constructed through the AHP hierarchical structure model, and its target layer includes an asset value assessment index system and a vulnerability assessment index system; The criterion layers of the asset value assessment index system and the vulnerability assessment index system both include: cloud platform, communication transmission, edge side and terminal perception.

3. The method for assessing information security risks of the electric power Internet of Things according to claim 2, characterized in that: The step of assigning weights to the indicator data of the risk assessment indicator system includes: obtaining an asset value evaluation score, constructing a judgment matrix for the indicator layer data corresponding to each criterion layer in the asset value assessment indicator system based on the obtained asset value evaluation score, and calculating the weight of the asset value indicator layer through the judgment matrix; Obtain security vulnerability vulnerability evaluation scores, and construct a judgment matrix for the indicator layer data corresponding to each criterion layer in the vulnerability assessment index system based on the obtained security vulnerability vulnerability evaluation scores. Through the judgment matrix, calculate the weight of the vulnerability assessment index layer.

4. The method for assessing information security risks of the electric power Internet of Things according to claim 1, characterized in that: The fitness objective function calculation formula is: , in, represents the number of criteria layer items, Indicates the The judgment matrix of the criterion layer, express The order of Indicates the optimized The consistency ratio, Indicates the optimized The offset distance, and is the weight of the two, and the value range is , ; express The largest characteristic root of express No. OK Column elements, , , Indicates the optimized No. OK Column elements; The constraints include: .

5. The method for assessing information security risks of the electric power Internet of Things according to claim 1, characterized in that: The particle swarm is updated as follows: , in, Indicates the The speed at which particles move in the next generation, Indicates the The position of the next generation of particles, Indicates the current iteration speed of the particle swarm, Indicates the current iteration position of the particle swarm; represents the number of particle iterations, represents the maximum number of iterations, Indicates the first particles, Indicates the size of the population, represents the global optimal solution of the population, represents the optimal solution of individual particles, represents the nonlinear inertia weight coefficient, and are the learning factors of particles learning from their own historical experience and the optimal individual in the group, is a random value uniformly distributed in the interval [0, 1]; is the state value of the chaos map, and its value range is (0, 1).

6. A power Internet of Things information security risk assessment device, characterized in that: include: A power data acquisition module, configured to acquire asset data and corresponding security vulnerability data in power scenarios, wherein the security vulnerability data includes frequency data of security incidents; An information security risk assessment indicator system construction module is used to construct an information security risk assessment indicator system for the power Internet of Things system based on the asset data and security vulnerability data. The information security risk assessment indicator system includes an asset value assessment indicator system and a vulnerability assessment indicator system. A weight allocation module, used to allocate weights to indicator data in the information security risk assessment indicator system; An information security risk assessment module, configured to assess the information security risk of the power Internet of Things system based on the frequency data and weight data of the security incidents; The weights are calculated based on a judgment matrix, which is constructed based on the indicator layer data corresponding to each criterion layer in the information security risk assessment indicator system; Perform consistency check on the judgment matrix of each criterion layer; If the consistency check fails, establishing a fitness objective function and its constraints for the elements of the judgment matrix; solving the fitness objective function with the constraints to optimize the weights; The fitness objective function calculation formula is: , in, represents the number of criteria layer items, Indicates the The judgment matrix of the criterion layer, Indicates the optimized The consistency ratio, Indicates the optimized The offset distance, and are the weights of the two, express No. OK Column elements; is based on Elements and optimized Elements Calculated; Furthermore, the fitness objective function with constraints is solved to optimize the weights, including: using a particle swarm optimization algorithm to change Size, to solve the output of the fitness objective function with constraints; get the output of the fitness objective function corresponding to The judgment matrix is ​​reconstructed through it, and the optimized weights are calculated.

7. A computer device, characterized in that: include: memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the power Internet of Things information security risk assessment method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the power Internet of Things information security risk assessment method described in any one of claims 1-5 are implemented.

Citation Information

Patent Citations

  • Asset vulnerability analysis method, device and system for power monitoring system

    CN115310801A

  • Power information physical system attack path risk assessment method

    CN117834294A