A method for detecting power equipment protocol vulnerabilities based on fuzz testing

By performing multiple vulnerability scans and data fusion on the communication data packets of power equipment, combined with the communication line interference score, the problem of low matching between vulnerability data and trigger conditions in fuzzy testing is solved, and the accuracy of communication vulnerability detection of power equipment is improved.

CN118972148BActive Publication Date: 2025-05-23STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411232028.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-03
Publication Date
2025-05-23
Estimated Expiration
2044-09-03

AI Technical Summary

Technical Problem

In the prior art, the randomness and diversity of test samples during fuzz testing cannot fully cover all possible protocol states and data frame formats, resulting in some important vulnerabilities being missed or falsely positive, and there is a problem that the vulnerability data and vulnerability trigger conditions are low.

Method used

By obtaining the communication data packets of the power equipment to be tested, first and second vulnerability scans are performed to obtain test samples, and data fusion of these test samples is performed, and vulnerability scan reports are generated to improve detection accuracy.

Benefits of technology

It has achieved improved the accuracy of power equipment communication vulnerability detection, effectively solved the problem of low matching between vulnerability data and vulnerability triggering conditions, and improved the comprehensiveness and accuracy of vulnerability detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972148B_ABST
    Figure CN118972148B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for detecting a protocol vulnerability of an electric power device based on fuzzy testing, and relates to the technical field of detecting a protocol vulnerability of an electric power device. The method for detecting a protocol vulnerability of an electric power device based on fuzzy testing comprises the following steps: a first vulnerability scan; a second vulnerability scan; and data fusion. The present invention obtains a communication data packet of a communication line to be tested in the electric power device to be tested and performs a first vulnerability scan to obtain a first test sample, then performs a second vulnerability scan on the remaining communication data packet after the first vulnerability scan to obtain a second test sample, and finally performs data fusion on the first test sample and the second test sample and combines the obtained communication line interference score to obtain detection project data, thereby achieving the effect of improving the accuracy of detecting communication vulnerabilities of electric power devices, and solving the problem of low matching between vulnerability data and vulnerability triggering conditions in the process of detecting communication vulnerabilities of electric power devices in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power equipment protocol vulnerability detection, and in particular to a power equipment protocol vulnerability detection method based on fuzzy testing. Background Art

[0002] With the rapid development of Internet of Things technology and communication capabilities, the power Internet of Things, as an important part of industrial control systems, is also constantly improving and developing. By integrating advanced sensing technology, communication technology and intelligent control technology, the power Internet of Things has realized the intelligent interconnection of power equipment, greatly improving the operating efficiency and reliability of the power system. However, the rapid development of the power Internet of Things is also accompanied by a series of security challenges. Since the industrial control protocol of the power Internet of Things is mainly based on the design of industrial control systems, its complexity and particularity make it difficult for traditional network security protection measures to be fully applicable. The industrial control protocol of the power Internet of Things must not only meet the communication needs between devices, but also ensure the security and stability of the communication process, which puts higher requirements on the security of the protocol. Therefore, a power equipment protocol vulnerability detection method based on fuzzy testing came into being.

[0003] The existing power equipment protocol vulnerability detection method achieves accurate detection of vulnerabilities in the power equipment protocol by building a fuzzy testing system, configuring the tested protocol and its data frames, generating mutation strategies and test samples, then transferring the test samples to the tested device for testing, and finally storing the test results and generating a detection report.

[0004] For example, the invention patent with announcement number: CN114205340B announces a fuzzy testing method and device based on smart power equipment, including: determining the target power protocol corresponding to the target smart power equipment; mutating the mutable fields of the target power protocol according to a preset mutation strategy to generate test cases; sending the test cases to the target smart power equipment to enable the target smart power equipment to execute the test cases.

[0005] For example, the patent application with publication number: CN116743447A discloses a method and system for power Internet of Things device vulnerability mining based on fuzzy testing, including: filtering out redundant test cases based on the taint propagation path similarity comparison method to generate a valid test case set; screening the test cases in the valid test case set, and eliminating the test cases with fitness less than the set value using a genetic algorithm; using a protocol state machine to guide the correlation between the test cases and the protocol state of the edge device; judging whether the test case causes an exception based on the state of the data packet returned by the object under test, and then judging whether there is a vulnerability; after determining that there is a vulnerability, returning to the test case for normal state monitoring, and performing test case tests one by one until an exception is found, thereby locating the vulnerability.

[0006] However, in the process of implementing the technical solution of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems:

[0007] In the prior art, during the fuzz testing process, due to the randomness and diversity of test samples, it is impossible to fully cover all possible protocol states and data frame formats, resulting in some important vulnerabilities being missed or falsely reported. There is also a problem of low matching between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection. Summary of the invention

[0008] The embodiment of the present application solves the problem of low matching between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection in the prior art by providing a power equipment protocol vulnerability detection method based on fuzzy testing, thereby improving the accuracy of power equipment communication vulnerability detection.

[0009] The embodiment of the present application provides a method for detecting a protocol vulnerability of an electric power device based on fuzzy testing, comprising the following steps: S1, obtaining a communication data packet of a communication line to be tested in the electric power device to be tested, and performing a first vulnerability scan on the communication data packet to obtain a first test sample, wherein the first vulnerability scan is used to check whether the communication data packet contains first vulnerability data matching a first target vulnerability, wherein the first vulnerability data includes a first data frame, a first data volume, and a first data update count in the communication data packet, and the first test sample is used to verify a vulnerability triggering condition of the first access data; S2, performing a second vulnerability scan on the remaining communication data packets after the first vulnerability scan to obtain a second test sample, wherein the second vulnerability scan is used to check whether the remaining communication data packets contain second vulnerability data matching a second target vulnerability, wherein the second vulnerability data includes a second data frame, a second data volume, and a second data update count in the remaining communication data packets, and the second test sample is used to verify a vulnerability triggering condition of the second access data; S3, performing data fusion on the first test sample and the second test sample to generate a vulnerability scan report, and at the same time obtaining detection project data in combination with the obtained communication line interference score, wherein the communication line interference score is used to measure the degree of interference of the first vulnerability data and the second vulnerability data on the communication line of the electric power device.

[0010] Furthermore, the first vulnerability scan is performed on the communication data packet, and then the process of the first vulnerability scan is monitored in real time to obtain a first vulnerability scan index. The first vulnerability scan index is used to measure the speed of the vulnerability scan of the communication data packet in the first vulnerability scan. The specific acquisition step is: the first data transmission speed of the communication data packet in the first vulnerability scan is obtained in real time by a speed sensor, and the first vulnerability scan index is obtained in combination with the first vulnerability data. The first vulnerability scan index is calculated by the following formula:

[0011]

[0012] Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, e is a natural constant, YI m.n represents the first vulnerability scan index of the mth communication data packet in the nth first vulnerability scan, β 1 Indicates the first data transmission speed safety factor, It indicates the first data transmission speed of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data transmission speed, a 1 Indicates the first data frame security factor, It represents the first data frame of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data frame, a 2 represents the first data volume safety factor, It indicates the first data volume of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data volume, a 3 Indicates the first data update times safety factor, Indicates the number of first data updates of the mth communication data packet in the nth first vulnerability scan, Indicates the number of times the reference first data is updated.

[0013] Furthermore, the second vulnerability scan is performed on the remaining communication data packets after the first vulnerability scan, and then the second vulnerability scan process is monitored in real time to obtain a second vulnerability scan index, and the second vulnerability scan index is used to measure the vulnerability scan speed of the remaining communication data packets in the second vulnerability scan. The specific acquisition step is: the second data transmission speed of the remaining communication data packets in the second vulnerability scan process is obtained in real time by a speed sensor, and the second vulnerability scan index is obtained in combination with the second vulnerability data. The second vulnerability scan index is calculated by the following formula:

[0014]

[0015] Where, f is the number of the remaining communication data packets, f = 1, 2, ..., F, F is the total number of the remaining communication data packets, y is the number of times the second vulnerability scan is performed, y = 1, 2, ..., Y, Y is the total number of times the second vulnerability scan is performed, e is a natural constant, ER f.y represents the second vulnerability scan index of the fth remaining communication data packet in the yth second vulnerability scan, β 2 Indicates the second data transmission speed safety factor, represents the second data transmission speed of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data transmission speed, b 1 Indicates the second data frame security factor, represents the second data frame of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data frame, b 2 represents the second data volume safety factor, represents the second data volume of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data volume, b 3 Indicates the second data update times safety factor, represents the number of times the second data of the fth remaining communication data packet is updated in the yth second vulnerability scan, Indicates the number of times the reference second data is updated.

[0016] Furthermore, the data fusion of the first test sample and the second test sample also includes obtaining a communication quality score by combining the obtained first vulnerability scanning index and the second vulnerability scanning index. The communication quality score is used to measure the transmission efficiency of the communication line to be tested in the power equipment when transmitting the first vulnerability data and the second vulnerability data. The communication quality score is calculated by the following formula:

[0017]

[0018] Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, ZHI represents the communication quality score on the communication line to be tested, YI m.n It represents the first vulnerability scanning index of the mth communication data packet on the communication line to be tested in the nth first vulnerability scanning.

[0019] Furthermore, the data fusion of the first test sample and the second test sample also includes obtaining a sample correlation index based on the result of the data fusion, and the sample correlation index is used to measure the degree of correlation between the first access data in the first test sample and the second access data in the second test sample. The specific acquisition method is as follows: within a preset time period, the total number of data fields of the first access data in the first test sample is counted, and the total number of data fields of the second access data in the second test sample is counted, and the number of identical data fields and the total number of data fields are obtained accordingly, the number of identical data fields represents the number of identical data fields between the data fields of the first access data and the data fields of the second access data, and the total number of data fields represents the sum of the total number of data fields of the first access data and the total number of data fields of the second access data; the data field matching rate is obtained based on the number of identical data fields and the total number of data fields, and the sample correlation index is obtained by combining the obtained first vulnerability scanning index and the second vulnerability scanning index. The data field matching rate represents the ratio of the number of identical data fields to the total number of data fields.

[0020] Furthermore, the communication line interference score is calculated by the following formula:

[0021]

[0022] In the formula, ZONG represents the communication line interference score of the communication line to be tested within the preset time period, ZHI represents the communication quality score of the communication line to be tested within the preset time period, and GUAN represents the sample correlation index between the first test sample and the second test sample on the communication line to be tested.

[0023] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:

[0024] 1. The communication data packets of the communication line to be tested in the power equipment to be tested are obtained and a first vulnerability scan is performed to obtain a first test sample. Then, a second vulnerability scan is performed on the remaining communication data packets after the first vulnerability scan to obtain a second test sample. Finally, data fusion is performed on the first test sample and the second test sample and combined with the obtained communication line interference score to obtain the detection project data, thereby improving the accuracy of data fusion, and then improving the accuracy of power equipment communication vulnerability detection, effectively solving the problem of low matching between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection in the prior art.

[0025] 2. By performing a first preprocessing on the acquired communication data packet and comparing it with the first target vulnerability, if the data volume corresponding to the access data in the communication data packet after the first preprocessing is consistent with the data volume corresponding to the first target vulnerability, the first vulnerability scan is completed, otherwise the first vulnerability scan is continued until the data volume corresponding to the access data in the communication data packet after the preprocessing is consistent with the data volume corresponding to the first target vulnerability, thereby achieving a more accurate match between the access data and the first target vulnerability, thereby achieving an improvement in the accuracy of the first vulnerability scan.

[0026] 3. Perform a first variation processing on the first test sample, and transmit the first variation processed first test sample to the communication line to be tested to obtain a first response speed, and determine whether the obtained first response speed is equal to a preset response speed. If so, the vulnerability trigger condition of the first access data is met and a first test feedback is performed, otherwise the obtained first response speed is stored in a preset database, thereby improving the accuracy of obtaining the first response speed, and further improving the accuracy and reliability of the first test feedback. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 A flow chart of a method for detecting power equipment protocol vulnerabilities based on fuzzy testing provided in an embodiment of the present application;

[0028] Figure 2 A verification flow chart of a vulnerability triggering condition for the first access data provided in an embodiment of the present application;

[0029] Figure 3 A flow chart for obtaining sample correlation indicators provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] The embodiment of the present application solves the problem of low matching between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection in the prior art by providing a power equipment protocol vulnerability detection method based on fuzzy testing. The method obtains a communication data packet of a communication line to be tested in the power equipment to be tested, and checks whether the communication data packet contains a first data frame, a first data volume, and a first data update frequency that match the unauthorized first access data in the communication line to be tested, to obtain a first test sample. Then, the method checks whether the remaining data packet after the first vulnerability scan contains a second data frame, a second data volume, and a second data update frequency that match the unauthorized second access data in the communication line to be tested, to obtain a second test sample. Finally, the first test sample and the second test sample are data-fused to generate a vulnerability scan report. At the same time, the obtained communication line interference score is combined to reflect the priority of the degree of influence of the first vulnerability data and the second vulnerability data on the communication line of the power equipment, thereby improving the accuracy of power equipment communication vulnerability detection.

[0031] The technical solution in the embodiment of the present application is to solve the problem of low matching between vulnerability data and vulnerability triggering conditions in the above-mentioned power equipment communication vulnerability detection process. The overall idea is as follows:

[0032] By obtaining the communication data packets of the communication line to be tested in the power equipment to be tested, the first vulnerability scan and the second vulnerability scan are performed respectively to obtain the first test sample and the second test sample. At the same time, the first test sample and the second test sample are data fused and combined with the obtained communication line interference score to obtain the detection project data, thereby achieving the effect of improving the accuracy of power equipment communication vulnerability detection.

[0033] In order to better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0034] like Figure 1 As shown, it is a flow chart of a method for detecting a protocol vulnerability of an electric power device based on fuzzy testing provided by an embodiment of the present application, the method comprising the following steps: S1, obtaining a communication data packet of a communication line to be tested in the electric power device to be tested, and performing a first vulnerability scan on the communication data packet to obtain a first test sample, the communication data packet is transmitted on the communication line to be tested in the electric power device to be tested, the first vulnerability scan is used to check whether the communication data packet contains first vulnerability data matching a first target vulnerability, the first target vulnerability is unauthorized first access data in the communication line to be tested, the first vulnerability data includes a first data frame, a first data volume and a first data update number in the communication data packet, and the first test sample is used to verify the vulnerability triggering condition of the first access data; S2, performing a second vulnerability scan on the remaining communication data packets after the first vulnerability scan to obtain a second test sample, the remaining communication data packets are the data packets remaining after the first vulnerability scan of the communication data packets, and the second vulnerability The scan is used to check whether the remaining communication data packets contain second vulnerability data that matches the second target vulnerability. The second target vulnerability is the unauthorized second access data in the communication line to be tested. The second vulnerability data includes the second data frame, the second data volume and the second data update times in the remaining communication data packets. The second test sample is used to verify the vulnerability trigger condition of the second access data; S3, the first test sample and the second test sample are data-fused to generate a vulnerability scan report, and the detection project data is obtained by combining the obtained communication line interference score. The data fusion is used to reflect the correlation between the first vulnerability data and the second vulnerability data. The vulnerability scan report includes the first vulnerability data description and the second vulnerability data description. The communication line interference score is used to measure the interference degree of the first vulnerability data and the second vulnerability data on the communication line of the power equipment. The detection project data is used to reflect the priority of the impact degree of the first vulnerability data and the second vulnerability data on the communication line of the power equipment.

[0035] In this embodiment, when a scanning tool (such as a network sniffer) acquires a communication data packet, the content in the communication data packet (such as an unauthorized user's access attempt to the communication data packet) is compared with the unauthorized first access data in the first target vulnerability according to a preset matching rule to obtain a first data match item, wherein the preset matching rule is usually set by a preset personnel after summing and averaging the historical communication data in a preset communication database (such as the number of access requests by the access user). In actual applications, the unauthorized first access data is usually the access attempt data (such as the number of accesses to the communication data packet) made by the access user who has not passed the identity authentication to the communication data packet, and the first data match item represents a one-to-one match item between the content of the first vulnerability data in the communication data (first data frame, first data volume, and first data update count) and the content of the reference first vulnerability data corresponding to the first access data in the first target vulnerability (reference first data frame, reference first data volume, and reference first data update count).

[0036] Similarly, when the network sniffer acquires the remaining communication data packets, it will compare the content in the remaining communication data packets (such as unauthorized users' access attempts to the remaining communication data packets) with the unauthorized second access data in the second target vulnerability according to a preset matching pattern to obtain a second data match item. In actual applications, the preset matching pattern is usually unauthorized historical second access data, and the unauthorized second access data is usually access attempt data of the remaining communication data packets by access users who have not passed identity authentication (such as the number of accesses to the remaining communication data packets). The second data match item represents a data item that corresponds one-to-one with the content of the second vulnerability data in the communication data (second data frame, second data volume, and second data update count) and the content of the reference second vulnerability data corresponding to the second access data in the second target vulnerability (reference second data frame, reference second data volume, and reference second data update count).

[0037] The reference first data frame and the reference second data frame are usually represented by summing and averaging the data frames in the preset communication database, the reference first data volume and the reference second data volume are usually represented by summing and averaging the communication data volumes in the preset communication database, and the reference first data update times and the reference second data update times are usually represented by summing and averaging the data update times in the preset communication database.

[0038] Specifically, the vulnerability scanning report describes in detail the first vulnerability data found in the first test sample, usually the first vulnerability data type. Similarly, the second vulnerability data found in the second test sample is described in detail, including the second vulnerability data type and the impact range. In actual applications, the first vulnerability data and the second vulnerability data are usually different links in the same attack chain on the communication line; the detection item data usually includes data packet loss, communication interruption and power equipment restart. It should be noted that the degree of impact on the power equipment communication line is usually ranked according to the amount of data lost, the number of communication interruptions and the number of power equipment restarts. For example, when the number of communication interruptions is greater than or equal to the preset number of communication interruptions, it is a high impact, otherwise it is a low impact. The preset number of communication interruptions is usually represented by the sum and average of the historical communication interruption times in the preset database, thereby improving the matching degree between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection.

[0039] In actual vulnerability detection application scenarios, the power equipment protocol vulnerability detection project data is mainly combined with the vulnerability detection target to automatically generate detection cases that meet the legal input requirements of the program. Well-designed power-specific equipment protocol vulnerability detection cases can effectively detect whether there are known vulnerabilities or security issues (such as data tampering and data deletion) in the power-specific equipment protocol, and provide test scenarios and data references for security testing and security assessment, thereby improving the safety and reliability of power equipment.

[0040] Furthermore, the specific process of performing a first vulnerability scan on a communication data packet is as follows: performing a first preprocessing on the acquired communication data packet and comparing it with a first target vulnerability; if the amount of data corresponding to the access data in the communication data packet after the first preprocessing is consistent with the amount of data corresponding to the first target vulnerability, the first vulnerability scan is completed; otherwise, the first vulnerability scan is continued until the amount of data corresponding to the access data in the communication data packet after the preprocessing is consistent with the amount of data corresponding to the first target vulnerability; the first preprocessing includes decoding and protocol parsing of the communication data packet.

[0041] In this embodiment, the purpose of decoding the communication data packet is to convert the captured communication data packet from its binary or network transmission format into a readable format, and the purpose of protocol parsing is to deeply understand the structure and content of the communication data packet and extract key information related to the first target vulnerability detection. The specific steps include: through a network protocol, such as the Transmission Control Protocol (TCP), parsing the protocol header of the communication data packet to obtain the source address, destination address, port number, and sequence number, and then extracting the actually transmitted data portion from the communication data packet, which usually contains attack instructions related to the first target vulnerability.

[0042] Fuzzy matching algorithm is one of the core algorithms of power-specific equipment protocol vulnerability analysis technology. It is mainly used to identify known patterns in the protocol, such as request response pattern and heartbeat packet pattern. It includes: brute-force matching algorithm (BF) and string matching algorithm (KMP). In order to improve the speed and efficiency of processing communication data packets on the communication line to be tested, a brute-force matching algorithm is usually selected to perform a first preprocessing on the acquired communication data packet and match it with the first target vulnerability. The specific steps are: starting from the starting position of the text string of the communication data packet, compare the communication data packet pattern string and each character of the text string in turn until each character of the communication data packet pattern string corresponds to each character of the text string. If the communication data packet pattern string matches successfully, the position where the communication data packet pattern string first appears in the text string is returned, thereby improving the accuracy and real-time performance of the first vulnerability scanning of the communication data packet.

[0043] Further, a first vulnerability scan is performed on the communication data packet, and then the process of the first vulnerability scan is monitored in real time to obtain a first vulnerability scan index, which is used to measure the speed of the vulnerability scan of the communication data packet in the first vulnerability scan. The specific acquisition steps are: obtaining a first data transmission speed of the communication data packet in the first vulnerability scan in real time through a speed sensor, the first data transmission speed is used to measure the speed of the communication data packet transmitted on the communication line to be tested in the first vulnerability scan, and at the same time combining the first vulnerability data to obtain the first vulnerability scan index, which is calculated by the following formula:

[0044]

[0045] Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, e is a natural constant, YI m.n represents the first vulnerability scan index of the mth communication data packet in the nth first vulnerability scan, β 1 Indicates the first data transmission speed safety factor, It indicates the first data transmission speed of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data transmission speed, a 1 Indicates the first data frame security factor, It represents the first data frame of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data frame, a 2 represents the first data volume safety factor, It indicates the first data volume of the mth communication data packet in the nth first vulnerability scan. Indicates the reference first data volume, a 3 Indicates the safety factor of the first data update times, Indicates the number of first data updates of the mth communication data packet in the nth first vulnerability scan, Indicates the number of times the reference first data is updated.

[0046] Among them, the first data transmission speed safety factor, the first data frame security factor, the first data volume safety factor and the first data update times safety factor are obtained from a preset database. The first data transmission speed safety factor is used to ensure that the speed of the communication data packet during the first vulnerability scanning process does not exceed the preset speed range. The first data frame safety factor is used to ensure that the data frame of the communication data packet during the first vulnerability scanning process is not greater than the reference first data frame. The first data volume safety factor is used to ensure that the amount of data transmitted per unit time by the communication data packet during the first vulnerability scanning process is not greater than the reference first data volume. The first data update times safety factor is used to ensure that the number of data updates of the communication data packet during the first vulnerability scanning process is not greater than the reference first data update times.

[0047] In this embodiment, in order to simplify the analysis, we define Where V1 m.n A1 represents the first data transmission speed coefficient of the mth communication data packet in the nth first vulnerability scan, m.n Indicates the first data frame coefficient of the mth communication data packet in the nth first vulnerability scan, B1 m.n represents the first data volume coefficient of the mth communication data packet in the nth first vulnerability scan, C1 m.n It represents the first data update coefficient of the mth communication data packet in the nth first vulnerability scan. The simplified calculation formula of the first vulnerability scan index is: The statistical table of changes in the first vulnerability scanning index is shown in Table 1:

[0048] Table 1 Statistics of changes in the first vulnerability scanning index

[0049]

[0050]

[0051] It should be understood that the preset speed range is usually represented by the result of summing up the data transmission speeds in the preset database and removing the standard deviation. The transmission speed of the communication data packet in the first vulnerability scan (i.e., the first data transmission speed) is usually measured in real time by a speed sensor. The reference first data transmission speed is usually represented by the result of summing up and averaging the communication data transmission speeds in the preset database. The first data frame, the first data volume and the first data update times of the communication data packet are usually monitored and counted in real time by a transmission sensor on the communication line to be tested.

[0052] Specifically, the first data transmission speed safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the first data transmission speed and its corresponding safety factor is constructed based on the relationship between the historical data transmission speed of the communication data packet and the first vulnerability scanning index, and the real-time first data transmission speed is input into the mapping set to obtain the corresponding first data transmission speed safety factor.

[0053] The first data frame security factor is obtained from a preset database. As can be seen from the above embodiments, the first data frame is usually the integrity of the communication data packet during the first vulnerability scanning process. In a specific embodiment, a mapping set of the first data frame and its corresponding security factor is constructed based on the relationship between the historical data frame of the communication data packet and the first vulnerability scanning index, and the real-time first data frame is input into the mapping set to obtain the corresponding first data frame security factor.

[0054] The first data volume safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the first data volume and its corresponding safety factor is constructed according to the relationship between the historical data volume of the communication data packet and the first vulnerability scanning index, and the real-time first data volume is input into the mapping set to obtain the corresponding first data volume safety factor.

[0055] The first data update times safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the first data update times and their corresponding safety factors is constructed based on the relationship between the historical data update times of the communication data packet and the first vulnerability scanning index, and the real-time first data update times are input into the mapping set to obtain the corresponding first data update times safety factor, thereby achieving more accurate acquisition of the first vulnerability scanning index, thereby achieving improved accuracy in power equipment communication vulnerability detection, and effectively solving the problem of low matching between vulnerability data and vulnerability triggering conditions in the power equipment communication vulnerability detection process in the prior art.

[0056] Further, such as Figure 2As shown, it is a verification flow chart of the vulnerability trigger condition of the first access data provided in an embodiment of the present application. The specific steps of verifying the vulnerability trigger condition of the first access data include: performing a first variation processing on the first test sample, and transmitting the first test sample after the first variation processing to the communication line to be tested to obtain a first response speed. The first variation processing includes modifying the first data frame structure, adjusting the size of the first data volume, and changing the number of first data updates. The first response speed is used to measure the response degree of the communication line to be tested to the first test sample; judging whether the obtained first response speed is equal to the preset response speed, if so, the vulnerability trigger condition of the first access data is met and a first test feedback is performed, otherwise the obtained first response speed is stored in a preset database, and the first test feedback is used to send the vulnerability trigger condition corresponding to the first test sample to the vulnerability repair personnel.

[0057] In this embodiment, the data frame is the basic unit in network communication, which contains complete information of the transmitted data, such as the source address, the destination address, and the data content. In all embodiments of the present invention, the data frame is generally the integrity of the data content (no duplicate data and text data), that is, the data content integrity corresponding to the first data frame of the communication data packet and the data content integrity corresponding to the remaining communication data packets; modifying the first data frame structure generally includes changing the data in the communication data packet (such as the number of unauthorized accesses and the access time), the frame header information (such as type, length) of the communication data packet during transmission, and adding or deleting data fields; adjusting the size of the first data volume by adjusting the amount of data in the data frame in the communication data packet; the first data update number refers to the frequency of sending or receiving data frames in the communication data packet within a period of time, and changing the first data update number can simulate different network traffic.

[0058] Specifically, a distance sensor is usually used to measure in real time the transmission distance of a first test sample on the communication line to be tested within a preset time period (such as one minute or ten minutes) to obtain a first response speed, wherein the first response speed represents the ratio of the transmission distance of the first test sample on the communication line to be tested to the preset time period, and the preset response speed is usually represented by the result of summing and averaging the historical response speeds in a preset database; the content of the first test feedback usually includes: the time and place of the test, and the observed phenomenon (such as the response speed being equal to the preset response speed); the purpose of the feedback is to report the results of the first test to relevant personnel (such as developers, security teams, network administrators), and take corresponding measures to fix vulnerabilities or optimize performance, thereby achieving more accurate verification of the vulnerability triggering conditions of the first access data.

[0059] Furthermore, the specific process of performing a second vulnerability scan on the remaining communication data packets is as follows: performing a second preprocessing on the obtained remaining communication data packets and comparing them with the second target vulnerability. If the data volume corresponding to the access data in the remaining communication data packets after the second preprocessing is consistent with the data volume corresponding to the second target vulnerability, the second vulnerability scan is completed; otherwise, the second vulnerability scan is continued until the data volume corresponding to the access data in the remaining communication data packets after the preprocessing is consistent with the data volume corresponding to the second target vulnerability. The second preprocessing includes decoding and protocol parsing of the remaining communication data packets.

[0060] In this embodiment, the purpose of decoding the remaining communication data packets is to convert the captured remaining communication data packets from their binary or network transmission format into a readable format, and the purpose of protocol parsing is to deeply understand the structure and content of the remaining communication data packets and extract key information related to the second target vulnerability detection. The specific steps include: parsing the protocol header of the remaining communication data packets through the network protocol (such as TCP), obtaining the source address, destination address, port number, and sequence number, and then extracting the actually transmitted data portion from the remaining communication data packets. This part of the data usually contains attack instructions related to the second target vulnerability.

[0061] It can be seen from the contents of the above embodiments that in order to improve the speed and efficiency of processing the remaining communication data packets on the communication line to be tested, a brute force matching algorithm is usually selected to perform a second preprocessing on the acquired remaining communication data packets and match them with the second target vulnerability. The specific steps are: starting from the starting position of the text string of the remaining communication data packet, the remaining communication data packet pattern string (such as request response data) and each character of the text string are compared in turn until the remaining communication data packet pattern string and each character of the text string correspond one-to-one, thereby achieving improved accuracy and real-time performance of the second vulnerability scanning of the remaining communication data packet.

[0062] Further, a second vulnerability scan is performed on the remaining communication data packets, and then the second vulnerability scan process is monitored in real time to obtain a second vulnerability scan index, which is used to measure the vulnerability scan speed of the remaining communication data packets in the second vulnerability scan. The specific acquisition steps are: obtaining the second data transmission speed of the remaining communication data packets in the second vulnerability scan process in real time through a speed sensor, and the second data transmission speed is used to measure the speed of the remaining communication data packets in the second vulnerability scan on the communication line to be tested. The second vulnerability scan index is obtained in combination with the second vulnerability data. The second vulnerability scan index is calculated by the following formula:

[0063]

[0064] Where, f is the number of the remaining communication data packets, f = 1, 2, ..., F, F is the total number of the remaining communication data packets, y is the number of times the second vulnerability scan is performed, y = 1, 2, ..., Y, Y is the total number of times the second vulnerability scan is performed, e is a natural constant, ER f.y represents the second vulnerability scan index of the fth remaining communication data packet in the yth second vulnerability scan, β 2 Indicates the second data transmission speed safety factor, represents the second data transmission speed of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data transmission speed, b 1 Indicates the second data frame security factor, represents the second data frame of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data frame, b 2 represents the second data volume safety factor, represents the second data volume of the fth remaining communication data packet in the yth second vulnerability scan, Indicates the reference second data volume, b 3 Indicates the second data update times safety factor, represents the number of times the second data of the fth remaining communication data packet is updated in the yth second vulnerability scan, Indicates the number of times the reference second data is updated.

[0065] Among them, the second data transmission speed safety factor, the second data frame security factor, the second data volume security factor and the second data update times security factor are obtained from a preset database. The second data transmission speed safety factor is used to ensure that the speed of the remaining communication data packets during the second vulnerability scanning process does not exceed the preset speed range. The second data frame security factor is used to ensure that the data frame of the remaining communication data packets during the second vulnerability scanning process is not greater than the reference second data frame. The second data volume security factor is used to ensure that the amount of data transmitted per unit time by the remaining communication data packets during the second vulnerability scanning process is not greater than the reference second data amount. The second data update times security factor is used to ensure that the number of data updates of the remaining communication data packets during the second vulnerability scanning process is not greater than the reference second data update times.

[0066] In this embodiment, the transmission speed (i.e., the second data transmission speed) of the remaining communication data packets in the first vulnerability scan is usually measured in real time by a speed sensor. The reference second data transmission speed is usually represented by the result of summing and averaging the remaining communication data transmission speeds in a preset database. The second data frame, the second data volume, and the second data update times of the remaining communication data packets are usually monitored and counted in real time by a transmission sensor on the communication line to be tested. It should be noted that when and When the corresponding second data transmission speed safety factor, second data frame safety factor, second data volume safety factor and second data update times safety factor are all 1, the value of the second vulnerability scanning index is the most accurate, that is, the remaining communication data packets have the fastest vulnerability scanning speed in the second vulnerability scanning.

[0067] Specifically, the second data transmission speed safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the second data transmission speed and its corresponding safety factor is constructed according to the relationship between the historical data transmission speed of the remaining communication data packets and the second vulnerability scanning index, and the real-time second data transmission speed is input into the mapping set to obtain the corresponding second data transmission speed safety factor.

[0068] The second data frame security factor is obtained from a preset database. As can be seen from the above embodiments, the second data frame is usually the integrity of the communication data packet during the second vulnerability scanning process. In a specific embodiment, a mapping set of the second data frame and its corresponding security factor is constructed based on the relationship between the historical data frame of the remaining communication data packet and the second vulnerability scanning index, and the real-time second data frame is input into the mapping set to obtain the corresponding second data frame security factor.

[0069] The second data volume safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the second data volume and its corresponding safety factor is constructed according to the relationship between the historical data volume of the remaining communication data packets and the second vulnerability scanning index, and the real-time second data volume is input into the mapping set to obtain the corresponding second data volume safety factor.

[0070] The second data update times safety factor is obtained from a preset database. In a specific embodiment, a mapping set of the second data update times and their corresponding safety factors is constructed based on the relationship between the historical data update times of the remaining communication data packets and the second vulnerability scanning index, and the real-time second data update times are input into the mapping set to obtain the corresponding second data update times safety factor, thereby achieving more accurate acquisition of the second vulnerability scanning index, thereby achieving an improvement in the matching degree between the vulnerability data and the vulnerability triggering conditions of the communication data packets during the vulnerability scanning process, and effectively solving the problem of low matching degree between the vulnerability data and the vulnerability triggering conditions of the communication data packets during the vulnerability scanning process in the prior art.

[0071] Furthermore, the specific steps of verifying the vulnerability trigger condition of the second access data include: performing a second variation processing on the second test sample, and transmitting the second test sample after the second variation processing to the communication line to be tested to obtain a second response speed, the second variation processing includes modifying the second data frame structure, adjusting the second data volume, and changing the second data update times, the second response speed is used to measure the response degree of the communication line to be tested to the second test sample; judging whether the obtained second response speed is equal to the preset response speed, if so, the vulnerability trigger condition of the second access data is met and a second test feedback is performed, otherwise the obtained second response speed is stored in a preset database, and the second test feedback is used to send the vulnerability trigger condition corresponding to the second test sample to the vulnerability repair personnel.

[0072] In this embodiment, modifying the second data frame structure generally includes changing the data in the remaining communication data packets (such as the number of unauthorized accesses and the access time), the frame header information (such as type, length) of the remaining communication data packets during transmission, and adding or deleting data fields; adjusting the size of the second data volume by adjusting the amount of data in the data frames in the remaining communication data packets; the second data update number refers to the frequency of sending or receiving data frames in the remaining communication data packets within a period of time, and changing the second data update number can simulate different network traffic.

[0073] Specifically, a distance sensor is usually used to measure in real time the transmission distance of a first test sample on the communication line to be tested within a preset time period (such as one minute or ten minutes) to obtain a first response speed, wherein the first response speed represents the ratio of the transmission distance of the first test sample on the communication line to be tested to the preset time period, and the preset response speed is usually represented by the result of summing and averaging the historical response speeds in a preset database; the content of the first test feedback usually includes: the time and place of the test, and the observed phenomenon (such as the response speed being equal to the preset response speed); the purpose of the feedback is to report the results of the first test to relevant personnel (such as developers, security teams, network administrators), and take corresponding measures to fix vulnerabilities or optimize performance, thereby achieving more accurate verification of the vulnerability triggering conditions of the second access data.

[0074] Further, data fusion is performed on the first test sample and the second test sample, which also includes obtaining a communication quality score by combining the obtained first vulnerability scanning index and the second vulnerability scanning index. The communication quality score is used to measure the transmission efficiency of the communication line to be tested in the power equipment when transmitting the first vulnerability data and the second vulnerability data. The communication quality score is calculated by the following formula:

[0075]

[0076] Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, ZHI represents the communication quality score on the communication line to be tested, YI m.n It represents the first vulnerability scanning index of the mth communication data packet on the communication line to be tested in the nth first vulnerability scanning.

[0077] In this embodiment, in order to simplify the analysis, we define In the formula, Y1 represents the first vulnerability scanning coefficient of the communication data packet on the communication line to be tested in the first vulnerability scanning, and E1 represents the second vulnerability scanning index of the remaining communication data packets on the communication line to be tested in the second vulnerability scanning. The simplified calculation formula of the communication quality score is: The statistical table of changes in communication quality scores is shown in Table 2:

[0078] Table 2 Statistics of changes in communication quality scores

[0079]

[0080]

[0081] It should be understood that the algorithm of this embodiment combines the first vulnerability scanning index and the second vulnerability scanning index factors to obtain the communication quality score through comprehensive analysis. The first vulnerability scanning index and the second vulnerability scanning index in this formula not only unilaterally affect the value of the communication quality score, but the first vulnerability scanning index also indirectly affects the value of the second vulnerability scanning index. When the amount of data in the communication data packet that completes the first vulnerability scan is large, the efficiency of the first vulnerability scan will be reduced, while the efficiency of the remaining communication data packets to complete the second vulnerability scan will be high. For example, assuming that the first vulnerability scanning index represents a vulnerability that affects the security of the network communication protocol, the second vulnerability scanning index may be a vulnerability that depends on the network communication protocol. A vulnerability in the correctness of the communication protocol, such as a data tampering vulnerability that exploits a protocol vulnerability. In this case, if the first vulnerability scanning index is very high (i.e., the vulnerability is serious or has not been fixed), then the second vulnerability scanning index may become more serious or easier to exploit, because the second vulnerability scanning index may be precisely utilizing the protocol weaknesses exposed by the first vulnerability scanning index, thereby improving the accuracy and real-time performance of obtaining the communication quality score, and further improving the matching degree between the vulnerability data and the vulnerability triggering conditions of the communication data packet during the vulnerability scanning process, effectively solving the problem of low matching degree between the vulnerability data and the vulnerability triggering conditions of the communication data packet during the vulnerability scanning process in the prior art.

[0082] Further, such as Figure 3As shown, it is a flow chart for obtaining the sample correlation index provided in an embodiment of the present application, data fusion is performed on the first test sample and the second test sample, and then the sample correlation index is obtained according to the result of the data fusion, and the sample correlation index is used to measure the degree of correlation between the first access data in the first test sample and the second access data in the second test sample. The specific acquisition method is as follows: within a preset time period, the total number of data fields of the first access data in the first test sample is counted, and the total number of data fields of the second access data in the second test sample is counted, and the number of identical data fields and the total number of data fields are obtained accordingly, the number of identical data fields represents the number of identical data fields between the data fields of the first access data and the data fields of the second access data, and the total number of data fields represents the sum of the total number of data fields of the first access data and the total number of data fields of the second access data; the data field matching rate is obtained according to the number of identical data fields and the total number of data fields, and the sample correlation index is obtained by combining the obtained first vulnerability scanning index and the second vulnerability scanning index, and the data field matching rate represents the ratio of the number of identical data fields to the total number of data fields.

[0083] In this embodiment, the calculation expression of the sample correlation index is:

[0084]

[0085] Wherein, GUAN represents the sample correlation index between the first test sample and the second test sample on the communication line to be tested, and G represents the data field matching rate between the first access data and the second access data on the communication line to be tested.

[0086] It is important to understand that when YI m.n =ER f.y And when G=1, the sample correlation index is equal to 2. At this time, the correlation between the first access data in the first test sample and the second access data in the second test sample is the highest. Since the first vulnerability scanning index and the second vulnerability scanning index are both obtained by the communication data packets and the remaining communication data packets during the vulnerability scanning process, the first vulnerability scanning index and the second vulnerability scanning index do not have a zero value when used as independent variables.

[0087] The algorithm of this embodiment combines the first vulnerability scanning index, the second vulnerability scanning index and the data field matching rate factors, and comprehensively analyzes to obtain the sample correlation index. The data field matching rate in this formula and the first vulnerability scanning index and the second vulnerability scanning index not only unilaterally affect the value of the sample correlation index, but the data field matching rate also indirectly affects the value of the first vulnerability scanning index and the second vulnerability scanning index. Assuming that there are two vulnerability scanning results A and B, which correspond to the first vulnerability scanning index and the second vulnerability scanning index respectively, if the data field matching rates of A and B are equal, it means that the two vulnerabilities are similar in multiple key data points, which will lead to an increase in the values ​​of the first vulnerability scanning index and the second vulnerability scanning index, because they reflect the increase in the number of vulnerabilities discovered during the scanning process and the increase in severity, thereby achieving an improvement in the accuracy and reliability of obtaining the sample correlation index, and then achieving an improvement in the accuracy of power equipment communication vulnerability detection, and effectively solving the problem of low matching between vulnerability data and vulnerability trigger conditions in the power equipment communication vulnerability detection process in the prior art.

[0088] Furthermore, the communication line interference score is calculated by the following formula:

[0089]

[0090] In the formula, ZONG represents the communication line interference score of the communication line to be tested within the preset time period, ZHI represents the communication quality score of the communication line to be tested within the preset time period, and GUAN represents the sample correlation index between the first test sample and the second test sample on the communication line to be tested.

[0091] In this embodiment, the algorithm of this embodiment combines the communication quality score and the sample correlation index factors, and comprehensively analyzes to obtain the communication line interference score. The communication quality score and the sample correlation index in this formula not only unilaterally affect the value of the communication line interference score, but also affect each other. For example, even if the communication quality score is high, if the sample correlation index is also high (indicating that the two vulnerability data have significant synergy), then the communication line interference score may still be very high; on the other hand, if the communication quality score is very low, but the sample correlation index is also low (indicating that the two vulnerability data are relatively independent), then the specific value of the communication line interference score will depend on the trade-off between these two factors, thereby achieving improved accuracy and efficiency in obtaining the communication line interference score, and further achieving improved matching between the vulnerability data and the vulnerability triggering conditions of the communication data packet in the vulnerability scanning process, effectively solving the problem of low matching between the vulnerability data and the vulnerability triggering conditions of the communication data packet in the vulnerability scanning process in the prior art.

[0092] To summarize, the embodiment of the present application obtains the communication data packet of the communication line to be tested in the power equipment to be tested and performs a first vulnerability scan to obtain a first test sample, then performs a second vulnerability scan on the remaining communication data packet after the first vulnerability scan to obtain a second test sample, and finally performs data fusion on the first test sample and the second test sample and combines the obtained communication line interference score to obtain the detection project data, thereby achieving an improvement in the accuracy of data fusion, and then achieving an improvement in the accuracy of power equipment communication vulnerability detection, effectively solving the problem of low matching between vulnerability data and vulnerability triggering conditions in the process of power equipment communication vulnerability detection in the prior art.

[0093] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0094] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0095] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0096] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0097] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0098] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing, characterized in that: The following steps are involved: S1, obtaining a communication data packet of a communication line to be tested in the power device to be tested, and performing a first vulnerability scan on the communication data packet to obtain a first test sample, wherein the first vulnerability scan is used to check whether the communication data packet contains first vulnerability data matching a first target vulnerability, wherein the first vulnerability data includes a first data frame, a first data volume, and a first data update number in the communication data packet, and the first test sample is used to verify a vulnerability trigger condition of the first access data; S2, performing a second vulnerability scan on the remaining communication data packets after the first vulnerability scan to obtain a second test sample, wherein the second vulnerability scan is used to check whether the remaining communication data packets contain second vulnerability data matching the second target vulnerability, the second vulnerability data including a second data frame, a second data volume, and a second data update count in the remaining communication data packets, and the second test sample is used to verify a vulnerability trigger condition for the second access data; S3, performing data fusion on the first test sample and the second test sample to generate a vulnerability scan report, and combining the acquired communication line interference score to obtain detection project data, wherein the communication line interference score is used to measure the degree of interference of the first vulnerability data and the second vulnerability data on the communication line of the power equipment.

2. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The specific process of performing the first vulnerability scan on the communication data packet is as follows: The acquired communication data packet is subjected to a first preprocessing and compared with a first target vulnerability. If the data volume corresponding to the access data in the communication data packet after the first preprocessing is consistent with the data volume corresponding to the first target vulnerability, the first vulnerability scan is completed. Otherwise, the first vulnerability scan is continued until the data volume corresponding to the access data in the communication data packet after the preprocessing is consistent with the data volume corresponding to the first target vulnerability. The first preprocessing includes decoding of the communication data packet and protocol parsing.

3. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The first vulnerability scan is performed on the communication data packet, and then the process of real-time monitoring the first vulnerability scan is further included to obtain a first vulnerability scan index, wherein the first vulnerability scan index is used to measure the speed of the vulnerability scan of the communication data packet in the first vulnerability scan, and the specific acquisition steps are: The first data transmission speed of the communication data packet in the first vulnerability scan is obtained in real time by the speed sensor, and the first vulnerability scan index is obtained by combining the first vulnerability data. The first vulnerability scan index is calculated by the following formula: Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, e is a natural constant, YI m.n represents the first vulnerability scanning index of the mth communication data packet in the nth first vulnerability scanning, β1 represents the first data transmission speed safety factor, It indicates the first data transmission speed of the mth communication data packet in the nth first vulnerability scan. represents the reference first data transmission speed, a1 represents the first data frame safety factor, It represents the first data frame of the mth communication data packet in the nth first vulnerability scan. represents the reference first data frame, a2 represents the first data volume safety factor, It indicates the first data volume of the mth communication data packet in the nth first vulnerability scan. represents the reference first data amount, a3 represents the first data update times safety factor, Indicates the number of first data updates of the mth communication data packet in the nth first vulnerability scan, Indicates the number of times the reference first data is updated; The first data transmission speed safety factor is used to ensure that the speed of the communication data packet during the first vulnerability scanning process does not exceed a preset speed range; The first data frame security factor is used to ensure that the data frame of the communication data packet in the first vulnerability scanning process is not larger than the reference first data frame; The first data volume safety factor is used to ensure that the amount of data transmitted per unit time by the communication data packet during the first vulnerability scanning process is not greater than the reference first data volume; The first data update times safety factor is used to ensure that the number of data updates of the communication data packet during the first vulnerability scanning process is not greater than the reference first data update times.

4. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The specific steps of verifying the vulnerability triggering condition of the first access data include: Performing a first variation process on the first test sample, and transmitting the first test sample after the first variation process to the communication line to be tested to obtain a first response speed, wherein the first response speed is used to measure the response degree of the communication line to be tested to the first test sample; Determine whether the acquired first response speed is equal to the preset response speed. If so, it indicates that the vulnerability trigger condition of the first access data is met and the first test feedback is performed. Otherwise, the acquired first response speed is stored in the preset database. The first test feedback is used to send the vulnerability trigger condition corresponding to the first test sample to the vulnerability repair personnel.

5. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The specific process of performing a second vulnerability scan on the remaining communication data packets after the first vulnerability scan is as follows: The obtained remaining communication data packets are subjected to a second preprocessing and compared with the second target vulnerability. If the data volume corresponding to the access data in the remaining communication data packets after the second preprocessing is consistent with the data volume corresponding to the second target vulnerability, the second vulnerability scan is completed. Otherwise, the second vulnerability scan is continued until the data volume corresponding to the access data in the remaining communication data packets after the preprocessing is consistent with the data volume corresponding to the second target vulnerability. The second preprocessing includes decoding and protocol parsing of the remaining communication data packets.

6. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The second vulnerability scan is performed on the remaining communication data packets after the first vulnerability scan, and then the second vulnerability scan process is monitored in real time to obtain a second vulnerability scan index, where the second vulnerability scan index is used to measure the vulnerability scan speed of the remaining communication data packets in the second vulnerability scan, and the specific acquisition steps are: The second data transmission speed of the remaining communication data packets in the second vulnerability scanning process is obtained in real time by the speed sensor, and the second vulnerability scanning index is obtained by combining the second vulnerability data. The second vulnerability scanning index is calculated by the following formula: Where, f is the number of the remaining communication data packets, f = 1, 2, ..., F, F is the total number of the remaining communication data packets, y is the number of times the second vulnerability scan is performed, y = 1, 2, ..., Y, Y is the total number of times the second vulnerability scan is performed, e is a natural constant, ER f.y represents the second vulnerability scanning index of the fth remaining communication data packet in the yth second vulnerability scanning, β2 represents the second data transmission speed safety factor, represents the second data transmission speed of the fth remaining communication data packet in the yth second vulnerability scan, represents the reference second data transmission speed, b1 represents the second data frame safety factor, represents the second data frame of the fth remaining communication data packet in the yth second vulnerability scan, represents the reference second data frame, b2 represents the second data volume safety factor, represents the second data volume of the fth remaining communication data packet in the yth second vulnerability scan, represents the reference second data amount, b3 represents the second data update times safety factor, represents the number of times the second data of the fth remaining communication data packet is updated in the yth second vulnerability scan, Indicates the number of times the reference second data is updated; The second data transmission speed safety factor is used to ensure that the speed of the remaining communication data packets during the second vulnerability scanning process does not exceed a preset speed range; The second data frame security factor is used to ensure that the data frame of the remaining communication data packet in the second vulnerability scanning process is not larger than the reference second data frame; The second data volume safety factor is used to ensure that the amount of data transmitted per unit time by the remaining communication data packets during the second vulnerability scanning process is not greater than the reference second data volume; The second data update times safety factor is used to ensure that the data update times of the remaining communication data packets in the second vulnerability scanning process is not greater than the reference second data update times.

7. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 1, characterized in that: The specific steps of verifying the vulnerability triggering condition of the second access data include: Performing a second variation process on the second test sample, and transmitting the second variation-processed second test sample to the communication line to be tested to obtain a second response speed, where the second response speed is used to measure the response degree of the communication line to be tested to the second test sample; Determine whether the acquired second response speed is equal to the preset response speed. If so, it indicates that the vulnerability trigger condition of the second access data is met and a second test feedback is performed. Otherwise, the acquired second response speed is stored in a preset database. The second test feedback is used to send the vulnerability trigger condition corresponding to the second test sample to the vulnerability repair personnel.

8. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 6, characterized in that: The data fusion of the first test sample and the second test sample also includes obtaining a communication quality score by combining the obtained first vulnerability scanning index and the second vulnerability scanning index. The communication quality score is used to measure the transmission efficiency of the communication line to be tested in the power equipment when transmitting the first vulnerability data and the second vulnerability data. The communication quality score is calculated by the following formula: Where m is the number of the communication data packet, m = 1, 2, ..., M, M is the total number of communication data packets, n is the number of the first vulnerability scan, n = 1, 2, ..., N, N is the total number of the first vulnerability scan, ZHI represents the communication quality score on the communication line to be tested, YI m.n It represents the first vulnerability scanning index of the mth communication data packet on the communication line to be tested in the nth first vulnerability scanning.

9. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 8, characterized in that: The data fusion of the first test sample and the second test sample further includes obtaining a sample correlation index according to the result of the data fusion, wherein the sample correlation index is used to measure the correlation degree between the first access data in the first test sample and the second access data in the second test sample. The specific obtaining method is as follows: Counting the total number of data fields of the first access data in the first test sample within a preset time period, and counting the total number of data fields of the second access data in the second test sample, thereby obtaining the number of identical data fields and the total number of data fields, wherein the number of identical data fields represents the number of identical data fields between the data fields of the first access data and the data fields of the second access data, and the total number of data fields represents the sum of the total number of data fields of the first access data and the total number of data fields of the second access data; The data field matching rate is obtained according to the number of identical data fields and the sum of the data fields, and the sample correlation index is obtained by combining the obtained first vulnerability scanning index and the second vulnerability scanning index.

10. A method for detecting power equipment protocol vulnerabilities based on fuzzy testing as claimed in claim 9, characterized in that: The communication line interference score is calculated by the following formula: In the formula, ZONG represents the communication line interference score of the communication line to be tested within the preset time period, ZHI represents the communication quality score of the communication line to be tested within the preset time period, and GUAN represents the sample correlation index between the first test sample and the second test sample on the communication line to be tested.

Citation Information

Patent Citations

  • A fuzzy testing method and device based on intelligent power equipment

    CN114205340B

  • Fuzzy test-based power Internet of Things equipment vulnerability mining method and system

    CN116743447A

  • Modbus protocol-oriented fuzz testing method

    CN105721230A

  • Vulnerability testing method and device, equipment and medium

    CN116915442A