A power monitoring system asset risk assessment method and device, a terminal device and a storage medium

By obtaining the network topology and operation data of the power monitoring system, building an asset exposure database, and combining it with the vulnerability database for risk assessment, we solved the problems of frequent asset scanning affecting business continuity and low assessment frequency in the power monitoring system, and achieved efficient and dynamic risk assessment and protection.

CN119047836BActive Publication Date: 2025-10-10GUANGDONG POWER GRID CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411238920.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-05
Publication Date
2025-10-10
Estimated Expiration
2044-09-05

AI Technical Summary

Technical Problem

Existing power monitoring system asset risk assessments frequently use vulnerability library scanning, which affects equipment operation and business continuity, or the assessment frequency is too low to gain insight into real-time risks, and cannot meet the dynamic changes of the power monitoring system.

Method used

By acquiring network topology data and system operation data, conducting communication protocol analysis, building an asset exposure database, and combining it with the preset vulnerability database to conduct vulnerability scanning and risk assessment, we can monitor changes in asset exposure in real time and dynamically adjust protection strategies.

Benefits of technology

It achieves the efficient identification of risks of power monitoring system assets without affecting system operation, reduces the difficulty of assessment, dynamically adjusts protection strategies, and meets the real-time risk assessment needs of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119047836B_ABST
    Figure CN119047836B_ABST
Patent Text Reader

Abstract

The application discloses a kind of electric power monitoring system asset risk assessment method, device, terminal equipment and storage medium, method includes: according to the network topology data and system operation data of the electric power monitoring system to be evaluated obtained, the communication protocol analysis is carried out to the electric power monitoring system to be evaluated, and the asset of monitoring system to be evaluated is obtained;According to the asset of the electric power monitoring system to be evaluated, the situation awareness is carried out to asset in the preset time interval, and the asset exposure surface database of the electric power monitoring system to be evaluated is constructed;According to asset exposure surface database and preset vulnerability database, the vulnerability scanning is carried out to the electric power monitoring system to be evaluated, and the vulnerability information of asset is obtained;According to asset exposure surface database, vulnerability information and vulnerability database, the risk assessment is carried out to the electric power monitoring system to be evaluated, and the asset risk assessment result of the electric power monitoring system to be evaluated is obtained. By implementing the application, the difficulty of electric power monitoring system risk assessment is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a method, device, terminal equipment and storage medium for asset risk assessment of an electric power monitoring system. Background Art

[0002] Power monitoring system assets refer to all physical and non-physical assets used to monitor and control the power generation and supply process. Power monitoring systems typically consist of multiple systems, and these subsystems may come from different vendors. These vendors' devices utilize different technologies and communication protocols, resulting in highly unique monitoring equipment. This makes it difficult to apply universal vulnerability libraries and risk quantification standards, complicating risk assessment. Furthermore, because power monitoring systems require high levels of business continuity, any operations that could cause system disruptions, including vulnerability scanning, must be performed with caution. Frequent use of vulnerability libraries for risk assessments, such as vulnerability scanning, can impact equipment operation and business continuity, increasing the probability of triggering system failures during the scanning process and creating additional security risks. However, if the frequency of risk assessments for power monitoring system assets is too low, it will be difficult to gain insight into real-time risk status, making it difficult to meet the dynamic asset risk requirements of power monitoring systems. Summary of the Invention

[0003] The embodiments of the present invention provide a method, apparatus, terminal device, and storage medium for assessing asset risk in a power monitoring system. These methods effectively address the existing problem of frequently using vulnerability libraries to conduct risk assessment operations such as vulnerability scanning, which can impact device operation and business continuity, increase the probability of triggering system failures during the scanning process, and create additional security risks. However, if the frequency of asset risk assessment in a power monitoring system is too low, it is difficult to gain insight into its real-time risk status, making it difficult to meet the dynamic changes in the asset risk of the power monitoring system.

[0004] An embodiment of the present invention provides a method for assessing asset risk in a power monitoring system, comprising:

[0005] Obtain network topology data and system operation data of the power monitoring system to be evaluated;

[0006] performing communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data to obtain assets of the monitoring system to be evaluated;

[0007] Based on the assets of the power monitoring system to be evaluated, situational awareness of the assets is performed within a preset time interval to build an asset exposure database of the power monitoring system to be evaluated;

[0008] Performing vulnerability scanning on the power monitoring system to be assessed based on the asset exposure database and a preset vulnerability database to obtain asset vulnerability information;

[0009] A risk assessment is performed on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information and the loophole database to obtain an asset risk assessment result of the power monitoring system to be assessed.

[0010] Furthermore, based on the network topology data and the system operation data, a communication protocol analysis is performed on the power monitoring system to be evaluated to obtain the assets of the monitoring system to be evaluated, including:

[0011] Determine node attribute information of each node in the power monitoring system to be evaluated based on the network topology data; the node attribute information includes: node IP address, node port number and node service type;

[0012] Based on the system proprietary protocol in the system operation data, the system proprietary protocol is analyzed by using the protocol reverse engineering method and the data packet analysis method to obtain the proprietary protocol characteristics of the power monitoring system to be evaluated;

[0013] Determining whether there is a system proprietary protocol response port in the power monitoring system to be evaluated based on the node attribute information, the proprietary protocol characteristics, and a preset proprietary protocol characteristic model library;

[0014] If so, obtaining a response message from the system's proprietary protocol response port, and identifying the assets of the monitoring system to be evaluated based on the response message;

[0015] If not, an asset discovery engine is constructed according to the proprietary protocol characteristics, and the ports of the power monitoring system to be evaluated are scanned according to the asset discovery engine to obtain the assets of the power monitoring system to be evaluated.

[0016] Furthermore, based on the assets of the power monitoring system to be evaluated, situational awareness of the assets is performed within a preset time interval to construct an asset exposure database of the power monitoring system to be evaluated, including:

[0017] Determine the network behavior characteristics, communication mode characteristics, and service status characteristics of the assets in the power monitoring system to be evaluated;

[0018] Clustering assets within a preset time interval based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics to obtain asset groups;

[0019] Analyze the network communication relationship between different assets based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics, and construct an asset association topology diagram between the assets;

[0020] An asset exposure surface database of the power monitoring system to be evaluated is constructed based on the asset group and the asset association topology map.

[0021] Furthermore, the construction of the preset vulnerability database includes:

[0022] Obtain historical vulnerability event information of the power monitoring system and historical vulnerability information corresponding to the historical vulnerability event information; the historical vulnerability information includes vulnerability description, vulnerability affected version and vulnerability risk level;

[0023] Perform semantic extraction based on the historical vulnerability event information to obtain vulnerability attack methods and attack device types;

[0024] Perform semantic extraction based on the vulnerability description to obtain the vulnerability type;

[0025] Build a vulnerability database based on vulnerability attack methods, attack device types, vulnerability types, vulnerability-affected versions, and vulnerability risk levels.

[0026] Furthermore, a vulnerability scan is performed on the power monitoring system to be evaluated based on the asset exposure database and the preset vulnerability database to obtain asset vulnerability information, including:

[0027] Determining basic attributes of an asset based on the asset exposure database; the basic attributes include an operating system version, a middleware version, and an open port type;

[0028] Determining the vulnerability type corresponding to the basic attribute according to the vulnerability impact version corresponding to the basic attribute in a preset vulnerability database;

[0029] Perform vulnerability scanning on the assets of the power monitoring system to be assessed based on the vulnerability types corresponding to the basic attributes, and generate a preliminary vulnerability list; the preliminary vulnerability list includes: potential vulnerabilities, preliminary risk levels of potential vulnerabilities, and existing vulnerabilities;

[0030] Conduct code audits on potential vulnerabilities based on the preliminary vulnerability list to obtain vulnerability information of the assets.

[0031] Furthermore, a risk assessment is performed on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database to obtain an asset risk assessment result of the power monitoring system to be assessed, including:

[0032] Associating the vulnerability information with the vulnerability database to calculate a first score indicating the severity of the vulnerability;

[0033] Determining, based on the asset exposure database, a second score for indicating the importance of the asset;

[0034] Calculating a comprehensive risk score of the power monitoring system to be evaluated based on the first score and the second score;

[0035] According to the comprehensive risk score and the preset risk threshold, the magnitude relationship between the comprehensive risk score and the preset risk threshold is determined to obtain an asset risk assessment result of the power monitoring system to be assessed.

[0036] Furthermore, it also includes:

[0037] Monitor the asset exposure database of the power monitoring system to be evaluated in real time. When the asset exposure database changes, calculate the database similarity between the asset exposure database after the change and the asset exposure database before the change.

[0038] When the database similarity is less than a preset similarity threshold, the changed asset exposure database and the vulnerability database are associated to obtain the latest vulnerability associated with the asset exposure of the power monitoring system to be evaluated;

[0039] Determine the protection level corresponding to the vulnerability risk level based on the vulnerability risk level corresponding to the latest vulnerability;

[0040] According to the protection level, the firewall and IPS protection strategy corresponding to the protection level are activated; and according to the firewall and IPS protection strategy, the power monitoring system to be evaluated is protected.

[0041] As an improvement to the above solution, another embodiment of the present invention provides a device for assessing asset risk in a power monitoring system, comprising:

[0042] System data acquisition module, used to obtain network topology data and system operation data of the power monitoring system to be evaluated;

[0043] A system asset discovery module, configured to perform communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data, and obtain the assets of the monitoring system to be evaluated;

[0044] An asset database construction module is used to perform situational awareness of the assets of the power monitoring system to be evaluated within a preset time interval and to construct an asset exposure database of the power monitoring system to be evaluated;

[0045] A vulnerability scanning module is used to perform vulnerability scanning on the power monitoring system to be evaluated based on the asset exposure database and a preset vulnerability database to obtain vulnerability information of the asset;

[0046] The risk assessment module is used to perform risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information and the vulnerability database, and obtain an asset risk assessment result of the power monitoring system to be assessed.

[0047] Another embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements an asset risk assessment method for a power monitoring system as described in the above embodiment.

[0048] Another embodiment of the present invention provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the power monitoring system asset risk assessment method described in the above embodiment.

[0049] By implementing the present invention, at least the following beneficial effects are achieved:

[0050] The present invention provides a method, apparatus, terminal device and storage medium for assessing the asset risk of an electric power monitoring system. The method can obtain network topology data and system operation data of the electric power monitoring system to be assessed; perform communication protocol analysis on the electric power monitoring system to be assessed based on the network topology data and the system operation data to obtain the assets of the monitoring system to be assessed; perform situational awareness of the assets within a preset time interval based on the assets of the electric power monitoring system to be assessed, and construct an asset exposure database for the electric power monitoring system to be assessed; perform vulnerability scanning on the electric power monitoring system to be assessed based on the asset exposure database and a preset vulnerability database to obtain vulnerability information of the assets; perform risk assessment on the electric power monitoring system to be assessed based on the asset exposure database, the vulnerability information and the vulnerability database to obtain an asset risk assessment result for the electric power monitoring system to be assessed. By analyzing the network topology data and system operation data of the power monitoring system to be evaluated, the assets of the monitoring system to be evaluated can be identified, and then situational awareness of the assets can be performed within a preset time interval, and an asset exposure database of the power monitoring system to be evaluated can be constructed, so as to perform vulnerability scanning, and realize vulnerability scanning and evaluation work within the preset time interval. Vulnerability scanning is neither used frequently nor too low in frequency. At the same time, based on the asset exposure database, vulnerability information and vulnerability database, a risk assessment of the power monitoring system to be evaluated is performed, and an asset risk assessment result of the power monitoring system to be evaluated is obtained. The asset exposure and vulnerability status of the power monitoring system can be comprehensively assessed. Even if the system assets include equipment from different manufacturers, quantitative analysis can be performed based on the constructed asset exposure database and asset vulnerability information, thereby reducing the difficulty of risk assessment of the power monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 This is a flow chart of a method for risk assessment of assets in a power monitoring system provided by one embodiment of the present invention;

[0052] Figure 2 It is a structural diagram of an asset risk assessment device for a power monitoring system provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0053] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0054] See also Figure 1 , is a flow chart of a method for assessing asset risk in a power monitoring system provided by one embodiment of the present invention, comprising:

[0055] S1. Obtain network topology data and system operation data of the power monitoring system to be evaluated;

[0056] S2. Performing communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data to obtain assets of the monitoring system to be evaluated;

[0057] S3. Based on the assets of the power monitoring system to be evaluated, perform situational awareness of the assets within a preset time interval and build an asset exposure database of the power monitoring system to be evaluated;

[0058] S4. Performing a vulnerability scan on the power monitoring system to be assessed based on the asset exposure database and a preset vulnerability database to obtain asset vulnerability information;

[0059] S5. Perform risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database to obtain an asset risk assessment result of the power monitoring system to be assessed.

[0060] Specifically, the network topology data of the power monitoring system to be evaluated includes system nodes and their topological relationships. Network scanning can be used to obtain the network topology structure and obtain this data. Node attribute information for each node in the power monitoring system to be evaluated can then be determined. This node attribute information includes the node's IP address, port number, and service type. System operation data includes the system deployment environment, such as proprietary protocols such as IEC 60870-5-104, DNP3, and Modbus. The assets of the monitoring system to be evaluated refer to the equipment, software, data, and other resources that perform various functions and roles within the monitoring system. The asset exposure database refers to the asset information exposed to external attackers in the cyberspace of the power monitoring system to be evaluated. The pre-defined vulnerability database stores and categorizes various known security vulnerabilities. Asset vulnerability information refers to weaknesses within an asset or asset group that could be exploited by threats to cause damage. These weaknesses may exist in various aspects, including configuration, hardware, software, and information. The asset risk assessment results include an asset risk assessment score for the power monitoring system to be evaluated.

[0061] In a preferred embodiment of the present invention, the network topology data and system operation data of the power monitoring system to be evaluated are first obtained; then, based on the network topology data and the system operation data, a communication protocol analysis is performed on the power monitoring system to be evaluated to obtain the assets of the monitoring system to be evaluated; then, based on the assets of the power monitoring system to be evaluated, situational awareness of the assets is performed within a preset time interval to construct an asset exposure database of the power monitoring system to be evaluated; then, based on the asset exposure database and a preset vulnerability database, a vulnerability scan is performed on the power monitoring system to be evaluated to obtain vulnerability information of the assets; finally, based on the asset exposure database, the vulnerability information and the vulnerability database, a risk assessment is performed on the power monitoring system to be evaluated to obtain an asset risk assessment result of the power monitoring system to be evaluated.

[0062] Preferably, based on the network topology data and the system operation data, performing communication protocol analysis on the power monitoring system to be evaluated to obtain the assets of the monitoring system to be evaluated includes:

[0063] Determine node attribute information of each node in the power monitoring system to be evaluated based on the network topology data; the node attribute information includes: node IP address, node port number and node service type;

[0064] Based on the system proprietary protocol in the system operation data, the system proprietary protocol is analyzed by using the protocol reverse engineering method and the data packet analysis method to obtain the proprietary protocol characteristics of the power monitoring system to be evaluated;

[0065] Determining whether there is a system proprietary protocol response port in the power monitoring system to be evaluated based on the node attribute information, the proprietary protocol characteristics, and a preset proprietary protocol characteristic model library;

[0066] If so, obtaining a response message from the system's proprietary protocol response port, and identifying the assets of the monitoring system to be evaluated based on the response message;

[0067] If not, an asset discovery engine is constructed according to the proprietary protocol characteristics, and the ports of the power monitoring system to be evaluated are scanned according to the asset discovery engine to obtain the assets of the power monitoring system to be evaluated.

[0068] Specifically, protocol reverse engineering and packet parsing are existing technologies. A pre-defined proprietary protocol feature model library includes protocol message formats, key fields, and protocol features extracted from state machines for all proprietary protocols, including syntactic and semantic features. For example, IEC 60870-5-104, DNP3, and Modbus leverage the public specifications and features of these protocols to extract key fields and protocol message formats, and construct a specialized proprietary protocol feature model library.

[0069] In a preferred embodiment of the present invention, node attribute information for each node in the power monitoring system to be evaluated is determined based on the network topology data; this node attribute information includes: node IP address, node port number, and node service type. A network topology diagram of the power monitoring system can be constructed based on this node attribute information. The resulting network topology diagram and the heterogeneity of different systems provide basic information and a reference basis for identifying proprietary protocols. Based on the system's deployment environment, system fingerprinting is used to identify the operating system type, version number, and middleware type of different subsystems, thereby determining the heterogeneity of the system. The network topology diagram reveals the distribution and communication relationships of each node in the system, while heterogeneity analysis helps understand the operating systems and middleware that different subsystems may use, thereby inferring the potential proprietary protocols. Combining this information allows for more efficient traffic capture and parsing, and using a proprietary protocol feature model library to identify specific proprietary protocol types and versions, thereby achieving a comprehensive understanding and monitoring of internal communications within the power control system.

[0070] Specifically, without affecting the normal operation of the system, passive data acquisition methods such as traffic mirroring are used to capture internal system communication traffic. Using a pre-established proprietary protocol feature model library, the captured traffic data is parsed and feature extracted to identify proprietary protocol features such as the type and version of the proprietary protocol used in the system. Alternatively, protocol reverse engineering and data packet parsing are used to extract the protocol features of the proprietary protocol from the format, fields, and state machine of the protocol message. Then, based on node attribute information and by simulating protocol communication process information, the network interfaces, service ports, and dedicated interfaces of the power monitoring system are detected to determine whether the power monitoring system to be evaluated has a system proprietary protocol response port, that is, whether the port responds to the proprietary protocol. If a proprietary protocol port exists, a response message from the system proprietary protocol response port is obtained. Based on the content of the port response message and the content in the proprietary protocol feature model library, the assets of the monitoring system to be evaluated are identified, including the asset type, version, and configuration. If not, an asset discovery engine is constructed based on the proprietary protocol features, and the ports of the power monitoring system to be evaluated are scanned using the asset discovery engine to obtain the assets of the power monitoring system to be evaluated.

[0071] Schematically, the assets of the power monitoring system to be assessed include: Device Type: Identify the types of different devices in the power monitoring system, such as PLCs (programmable logic controllers), RTUs (remote terminal units), SCADA systems (supervisory control and data acquisition systems), smart meters, etc.; Device Version: Determine the version information of the software or firmware running on each device or system, which is crucial for understanding the system's update status and potential vulnerabilities; Device Configuration: Obtain device configuration information, including network interface configuration, service port settings, enabled protocols and their parameters. This configuration data can help further understand the device's operating mode and potential security risks; Network Interface: Identify the network interface of each device in the power monitoring system and obtain key information such as the relevant IP address and MAC address; Service Port: Discover and record the service ports opened by devices in the system, understand the service types and protocols carried by these ports, and determine their specific uses; Specialized Interface: Identify any special interfaces that may exist in the system. These interfaces may be used for communication with specific proprietary protocols and are important ways for devices to communicate with other systems or devices.

[0072] Illustratively, determining whether there is a system-specific protocol response port in the power monitoring system to be evaluated includes: (1) According to the preset specific protocol characteristic model library, construct communication messages conforming to specific specific protocols. These messages simulate real communication processes, contain appropriate formats, contents and sequences to ensure that they can trigger the response of the device. And design an adaptive protocol communication framework, so that the message can be dynamically adjusted according to the characteristics of different protocols to adapt to the subtle differences of various protocols. (2) Using the constructed communication messages, different detection techniques (such as TCPSYN scanning, UDP detection, ARP scanning, etc.) are used to detect the network interface, service port and special interface in the power monitoring system. Send the constructed protocol message to the target port to simulate the communication request. (3) Capture the response message returned by the target port through network scanning tools or traffic capture tools (such as Wi reshark, Tcpdump, etc.). (4) Compare the captured response message with the content in the specific protocol characteristic model library to determine whether the response message conforms to the known specific protocol characteristics. (5) If the format, field, state and other characteristics of the response message match the specific protocol characteristics in the specific protocol characteristic model library, it can be determined that the port uses the specific protocol. (6) At the same time, the identified port is associated with the asset information to generate the mapping relationship between the port and the asset, and record it in the asset library.

[0073] Specifically, through an in-depth analysis of the proprietary protocols of power monitoring systems, we first established a protocol reverse engineering environment, including tools such as traffic mirroring, packet capture, and protocol decoding. Using tools like Wireshark and Tcpdump, we selected typical proprietary protocol packet samples and decoded and analyzed them using Wireshark. We observed the format, fields, and length of the protocol messages, compared them with common application-layer protocols such as HTTP and FTP, and summarized the specificities of the proprietary protocols. We then used reverse engineering tools like IDA Pro and Ollydbg to disassemble and debug the key communication programs or modules of the proprietary protocols, analyzing the protocol's state machine, data structure, encoding and decoding logic, and other internal implementation logic. The reverse engineering results were abstracted and refined, resulting in a comprehensive proprietary protocol feature model library. Based on these extracted proprietary protocol features, we created an asset discovery engine. Taking into account the specificities of proprietary protocols, we designed an adaptive protocol communication framework that dynamically adjusts communication message parameters such as format, content, and sequence based on the characteristics of different protocols. Based on a proprietary protocol feature model library, an asset discovery engine was created. This engine implements various detection techniques, such as TCPSYN scanning, UDP detection, and ARP scanning. By constructing different protocol packets, it detects open IP addresses, port numbers, MAC addresses, and other information in the system. Using port fingerprinting technology, it matches the rules in the proprietary protocol feature model library to identify the device type, version, service, and other information behind the port, generating a mapping between the port and the asset. The engine also features automated scanning and regular inspection capabilities, dynamically updating the asset library through continuous network scanning and asset inventory.

[0074] Preferably, based on the assets of the power monitoring system to be evaluated, situational awareness of the assets is performed within a preset time interval to construct an asset exposure database of the power monitoring system to be evaluated, including:

[0075] Determine the network behavior characteristics, communication mode characteristics, and service status characteristics of the assets in the power monitoring system to be evaluated;

[0076] Clustering assets within a preset time interval based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics to obtain asset groups;

[0077] Analyze the network communication relationship between different assets based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics, and construct an asset association topology diagram between the assets;

[0078] An asset exposure surface database of the power monitoring system to be evaluated is constructed based on the asset group and the asset association topology map.

[0079] In a preferred embodiment of the present application, according to the assets to be evaluated in the power monitoring system, passive flow monitoring and active detection are used to obtain network communication data, service port status and application information of the assets; through data cleaning and feature extraction, network behavior features, communication mode features and service state features of the assets are obtained. According to the network behavior features, the communication mode features and the service state features, machine learning algorithms are used to cluster the assets within a preset time interval to obtain asset groups; then data correlation analysis is used to judge the network communication relationship, service calling relationship and data transmission relationship between different assets, the network communication relationship between different assets is analyzed according to the network behavior features, the communication mode features and the service state features, and an asset correlation topology graph between assets is constructed. For the assets in each asset group, a deep learning algorithm is used to construct a feature model of the corresponding asset network behavior and communication mode; the network behavior features, the communication mode features and the service state features are input into the corresponding feature model to obtain the feature vector representation of the assets under the feature model; through feature vector comparison and similarity calculation, the similarity between the new assets and the existing assets is judged, and the category of the assets in the asset classification system is determined; the feature vector of the assets, the asset correlation topology graph and the classification information are stored in the database to construct a fine-grained asset exposure surface database.

[0080] In another preferred embodiment of the present invention, through passive traffic monitoring and active detection, it was determined that a certain asset communicated with five different IP addresses within an hour, opened three service ports: 80, 443, and 3306, and used three applications: Nginx, Tomcat, and MySQL. Data cleaning and feature extraction revealed that the asset received an average of 1,000 packets per minute and sent an average of 800 packets per minute. Port 80 handled a maximum of 50 concurrent connections per second, the connection success rate for port 443 was 98%, and the average response time for port 3306 was 10 milliseconds. Data association analysis revealed network communications between this asset and three other assets: two of these assets invoked its services, and one received data transmitted by it. This led to the construction of an asset association topology. Using the K-means clustering algorithm, the 1,000 assets were grouped into five asset groups based on network behavior, communication pattern, and service status characteristics. For each asset in an asset group, a long short-term memory neural network is used to construct a feature model with 10 hidden layers and 100 neurons per layer. The asset's feature vector is input into the trained feature model, resulting in a 200-dimensional feature vector representation. The Euclidean distance between this vector and all asset vectors in the asset library is calculated. The smallest distance, just 1, is found with a specific asset. Based on this, the newly added asset is determined to belong to the same category. The 200-dimensional feature vector, the asset association topology consisting of 5 nodes and 10 edges, and its category information are stored in the asset exposure database, bringing the asset under fine-grained management.

[0081] Specifically, the construction of the preset vulnerability database includes:

[0082] Obtain historical vulnerability event information of the power monitoring system and historical vulnerability information corresponding to the historical vulnerability event information; the historical vulnerability information includes vulnerability description, vulnerability affected version and vulnerability risk level;

[0083] Perform semantic extraction based on the historical vulnerability event information to obtain vulnerability attack methods and attack device types;

[0084] Perform semantic extraction based on the vulnerability description to obtain the vulnerability type;

[0085] Build a vulnerability database based on vulnerability attack methods, attack device types, vulnerability types, vulnerability-affected versions, and vulnerability risk levels.

[0086] In a preferred embodiment of the present invention, historical vulnerability event information and corresponding historical vulnerability information from the power monitoring system are obtained; the historical vulnerability information includes vulnerability descriptions, affected versions, and vulnerability risk levels. Natural language processing is used to perform semantic extraction on the historical vulnerability event information to obtain vulnerability attack methods and attack device types. Semantic extraction is then performed based on the vulnerability descriptions to obtain vulnerability types. The characteristics and vulnerabilities of the power monitoring equipment are then extracted to obtain security risk factors, which are then further optimized. These security risk factors include default passwords, hard-coded credentials, and debug interfaces. Finally, a vulnerability database is constructed based on the vulnerability attack methods, attack device types, vulnerability types, affected versions, and vulnerability risk levels.

[0087] Preferably, a vulnerability scan is performed on the power monitoring system to be evaluated based on the asset exposure database and a preset vulnerability database to obtain asset vulnerability information, including:

[0088] Determining basic attributes of an asset based on the asset exposure database; the basic attributes include an operating system version, a middleware version, and an open port type;

[0089] Determining the vulnerability type corresponding to the basic attribute according to the vulnerability impact version corresponding to the basic attribute in a preset vulnerability database;

[0090] Perform vulnerability scanning on the assets of the power monitoring system to be assessed based on the vulnerability types corresponding to the basic attributes, and generate a preliminary vulnerability list; the preliminary vulnerability list includes: potential vulnerabilities, preliminary risk levels of potential vulnerabilities, and existing vulnerabilities;

[0091] Conduct code audits on potential vulnerabilities based on the preliminary vulnerability list to obtain vulnerability information of the assets.

[0092] In a preferred embodiment of the present invention, asset vulnerability information refers to defects or weaknesses in the asset's design, implementation, and configuration that could be exploited by threats to cause damage. Based on the asset exposure database, basic asset attributes are determined; these basic attributes include operating system version, middleware version, and open port type. By analyzing these basic attributes, the vulnerability impact version corresponding to each basic attribute is searched in a pre-set vulnerability database to determine the vulnerability type corresponding to each basic attribute. Based on the vulnerability types corresponding to these basic attributes, a vulnerability scan is performed on the assets of the power monitoring system to be assessed to generate a preliminary vulnerability list. If the preliminary vulnerability list is not empty, code auditing techniques are used to audit potential vulnerabilities in the preliminary vulnerability list based on the vulnerability risk level in the vulnerability database. This audit identifies the vulnerabilities present in the asset and determines the existing vulnerabilities and preliminary risk levels of the potential vulnerabilities. Based on the potential and existing vulnerabilities, a security vulnerability list is generated. Penetration testing is then conducted against the asset using the security vulnerability list to simulate attacks and determine whether the security vulnerabilities can be remotely exploited. During testing, specific attack scenarios are constructed to verify the exploitability and actual damage of the vulnerabilities. If a security vulnerability can be exploited remotely, the scanning process is dynamically tracked and debugged to determine the exploitation conditions and the degree of harm. Dynamic tracking and debugging further determine the exploitation conditions (such as whether specific permissions and access conditions are required) and the degree of harm (such as the scope of data leakage and damage to system integrity), ultimately obtaining asset vulnerability information.

[0093] Preferably, a risk assessment is performed on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database to obtain an asset risk assessment result of the power monitoring system to be assessed, including:

[0094] Associating the vulnerability information with the vulnerability database to calculate a first score indicating the severity of the vulnerability;

[0095] Determining, based on the asset exposure database, a second score for indicating the importance of the asset;

[0096] Calculating a comprehensive risk score of the power monitoring system to be evaluated based on the first score and the second score;

[0097] According to the comprehensive risk score and the preset risk threshold, the magnitude relationship between the comprehensive risk score and the preset risk threshold is determined to obtain an asset risk assessment result of the power monitoring system to be assessed.

[0098] In a preferred embodiment of the present invention, a first score representing the degree of vulnerability damage is calculated based on the vulnerability information and the vulnerability database, and the degree of damage in the vulnerability information and the vulnerability risk level in the vulnerability database are correlated. Then, based on the asset exposure database and the vulnerability information, the importance of the connection relationship between each node in the asset and the asset group classification relationship is determined based on the asset association topology in the asset exposure database. Then, based on the utilization conditions in the vulnerability information and the importance of the asset group classification relationship, a second score representing the importance of the asset is determined. Then, based on the first score and the second score, a comprehensive risk score for the power monitoring system to be evaluated is calculated. Finally, based on the comprehensive risk score and a preset risk threshold, the relationship between the comprehensive risk score and the preset risk threshold is determined to obtain an asset risk assessment result for the power monitoring system to be evaluated. For example, the preset risk threshold is divided into high risk (8-10 points), medium risk (6-8 points), and low risk (less than 6 points). If the comprehensive risk score is 8 points, the asset risk assessment result for the power monitoring system to be evaluated is high risk; if the comprehensive risk score is 6 points, the asset risk assessment result for the power monitoring system to be evaluated is medium risk; and if the comprehensive risk score is 5 points, the asset risk assessment result for the power monitoring system to be evaluated is low risk.

[0099] In a preferred embodiment of the present invention, 100 vulnerabilities of power monitoring equipment are semantically analyzed and extracted, wherein vulnerabilities with a vulnerability description similarity greater than 80% are classified into one category, and finally a vulnerability database containing 75 typical vulnerabilities is obtained. When optimizing the vulnerability database, for example, 50 incident cases were analyzed, of which 30 incidents involved vulnerabilities in the vulnerability database, and 20% of the vulnerability information in the vulnerability database was updated through association analysis. When parsing the function of the device, for example, 1,000 power monitoring devices were analyzed, and it was found that 400 of them had default password risks, 300 had debugging interface risks, and 100 had hard-coded credential risks, and the vulnerability database was optimized accordingly. When assessing the vulnerability risk, for example, a power monitoring device has a serious vulnerability, its hazard level is scored as 4 points, and its difficulty of exploitation is scored as 2 points, then the comprehensive risk score of the vulnerability is 4×2=8 points, which belongs to the high risk level. When forming an equipment risk assessment report, for example, a risk assessment is conducted on 1,000 power monitoring devices, and the final assessment shows that there are 100 high-risk devices, 300 medium-risk devices, and 600 low-risk devices.

[0100] In another preferred embodiment of the present invention, a certain asset was discovered to be using the Windows Server 2012 operating system, Apache Tomcat 5 middleware, and open ports 80, 443, and 3389. Analysis revealed that the asset's operating system and middleware versions were both relatively old, and its associated vulnerability database contained three high-risk and five medium-risk vulnerabilities, necessitating focused detection for vulnerability types such as SQL injection and file upload. Vulnerability scanning was used to inspect the asset, revealing six preliminary vulnerabilities, including one SQL injection and two weak passwords. Based on the vulnerability risk level, code auditing techniques were employed to focus on two high-risk SQL injection vulnerabilities, ultimately confirming the presence of one SQL injection vulnerability in the asset. Penetration testing revealed that this SQL injection vulnerability could be exploited remotely, allowing an attacker to construct malicious SQL statements and obtain sensitive information from the database. Tracing and debugging determined that exploitation of the vulnerability required an unauthorized database connection, with the potential for access to 90% of the database's sensitive data. The risk assessment module comprehensively considers factors such as asset importance and vulnerability severity, and calculates a risk score of 8.5 out of 10, which is considered high risk. Analysis of asset security risks revealed, for example, a high-risk SQL injection vulnerability in the web application, multiple security risks associated with older middleware versions, and unpatched servers. This resulted in an asset security risk assessment report, recommending swift vulnerability remediation and software upgrades to strengthen security protection.

[0101] Indicatively, it also includes:

[0102] Monitor the asset exposure database of the power monitoring system to be evaluated in real time. When the asset exposure database changes, calculate the database similarity between the asset exposure database after the change and the asset exposure database before the change.

[0103] When the database similarity is less than a preset similarity threshold, the changed asset exposure database and the vulnerability database are associated to obtain the latest vulnerability associated with the asset exposure of the power monitoring system to be evaluated;

[0104] Determine the protection level corresponding to the vulnerability risk level based on the vulnerability risk level corresponding to the latest vulnerability;

[0105] According to the protection level, the firewall and IPS protection strategy corresponding to the protection level are activated; and according to the firewall and IPS protection strategy, the power monitoring system to be evaluated is protected.

[0106] In a preferred embodiment of the present application, the asset exposure surface database of the power monitoring system to be evaluated is monitored in real time. In the case of changes in the asset exposure surface database, the library similarity of the changed asset exposure surface database and the asset exposure surface database before the change is calculated according to the changed asset exposure surface database and the asset exposure surface database before the change, and it is judged whether the power monitoring system is subjected to a new attack, resulting in changes in the network topology data and system operation data of the system and thus changes in the asset exposure surface database. Then, in the case where the library similarity is less than a preset similarity threshold, it is indicated that the system is subjected to a new attack, resulting in changes in the network topology data and system operation data of the system, and the changed asset exposure surface database and the vulnerability database are associated to obtain the latest vulnerability associated with the asset exposure surface of the power monitoring system to be evaluated. According to the vulnerability risk level of the latest vulnerability in the vulnerability database, the protection level corresponding to the vulnerability risk level is determined. If the vulnerability database does not record the vulnerability of this type, the latest vulnerability is responded to as the highest risk level and stored in the vulnerability database, so as to determine the corresponding protection level as the highest level. Finally, according to the protection level, the firewall and IPS protection strategy corresponding to the protection level are started, and the power monitoring system to be evaluated is protected according to the firewall and IPS protection strategy.

[0107] In another preferred embodiment of the present invention, based on the exposure data of the asset, the technical stack characteristics of each asset are extracted through asset fingerprint identification to construct an asset portrait; the vulnerability information is standardized and integrated to eliminate redundancy and noise, forming a panoramic view of the vulnerability of the asset; the risk assessment results are associated with the asset portrait and the panoramic view of the vulnerability, and an asset security knowledge graph is constructed using a graph database; based on the asset security knowledge graph, a random forest is used to construct a risk prediction model, and based on the threat situation information and vulnerability information currently faced by the asset, the threat events and risk levels suffered by the asset are predicted; if the predicted risk level exceeds the preset risk threshold, a risk alarm is triggered and risk alarm information is generated, which includes a risk description, risk level, and affected assets; based on the predicted threat events and risk level, combined with the asset's importance information and vulnerability information, a corresponding security protection strategy is generated, which includes access control, data encryption, and security monitoring measures. Specifically, by using web crawler technology, such as the Scrapy framework, the exposure data of the asset can be obtained efficiently. Using asset fingerprinting technologies, such as Nmap, we extract characteristics of the asset's technology stack, including its operating system, web server, and database, to construct a multi-dimensional asset profile. The collected vulnerability information is normalized using the CVE standard. Using similarity algorithms such as cosine similarity, vulnerabilities are clustered and integrated to remove redundant and noisy data, ultimately forming a comprehensive view of the asset's vulnerability landscape. Using the graph database Neo4j, we correlate the asset profile, vulnerability landscape, and risk assessment results to construct an asset security knowledge graph. Based on this, we select the random forest algorithm to train a risk prediction model. The model inputs include threat profiles facing the asset, such as the number of malicious IP accesses and the severity of the vulnerability. It outputs the probability and risk level of the asset being threatened. When the predicted risk level exceeds a preset threshold, such as 7, a risk alert is triggered, generating an alert message containing a risk description, risk level, and affected assets. Furthermore, combining the asset's importance score with the vulnerability severity, we automatically generate security protection strategies. For example, for high-risk assets, we deploy access control measures, implement AES encryption for sensitive data, strengthen security monitoring, and establish rules for detecting abnormal behavior. By implementing this embodiment, we can achieve automated discovery, early warning, and protection of asset security risks, significantly improving security operational efficiency. Through risk prediction models, we can proactively identify potential threats, generate alerts and protection strategies, and improve emergency response speed. By comprehensively considering asset exposure, known vulnerabilities, and historical incident cases, we can conduct customized risk assessments and generate targeted security protection strategies.The dynamic and adaptive nature of this process ensures the effectiveness and timeliness of protective measures; through continuous asset exposure monitoring and difference analysis, the asset exposure database and vulnerability database are constantly updated, dynamic adjustment of risk assessment and protection strategies is achieved, and self-adaptation and continuous optimization of the closed-loop security protection system are achieved; the above-mentioned technical means are integrated into the entire life cycle management of assets, from asset introduction to retirement, covering security risk assessment and protection throughout the entire process, ensuring that newly added assets can also be quickly integrated into the overall security framework, reducing security blind spots and risks caused by asset changes.

[0108] In another preferred embodiment of the present invention, asset exposure change information is obtained from the asset exposure monitoring system, and historical data in the asset exposure database is compared through a difference analysis algorithm to determine newly added or changed exposure data; the exposure data is updated to the asset exposure database to achieve dynamic update of the asset exposure database; data association analysis is used to dynamically associate the updated asset exposure database with the vulnerability database to determine the vulnerabilities associated with the newly added or changed exposures; based on the results of the vulnerability association analysis, risk indicators corresponding to the vulnerabilities are obtained from the risk knowledge base; and the newly added or changed exposures, vulnerabilities, and risk indicators are comprehensively analyzed. The system conducts a comprehensive assessment to determine the latest risk score and risk level of an asset. If the latest risk score or risk level exceeds a preset risk threshold, it triggers a security policy update mechanism. Based on the latest risk score and risk level, it determines the security policy and matches the protection policy configuration to the policy. Through the protection policy configuration delivery interface, it automatically distributes the updated security policy to relevant security protection devices, including firewalls and IPS, to dynamically adjust the security policy. The system continuously monitors changes in asset exposure and protection effectiveness, providing real-time feedback on these changes and effectiveness, forming a dynamic, closed-loop, continuous protection mechanism. Specifically, the asset exposure monitoring system collects asset exposure change information every five minutes and uses a difference analysis algorithm to compare it with historical data in the asset exposure database to identify new or changed exposure data. The difference analysis algorithm uses a similarity-based comparison method with a threshold of 8. Data above this threshold is considered unchanged, while data below this threshold is considered new or changed. New or changed exposure data derived from the difference analysis is updated to the asset exposure database hourly, enabling dynamic updates. Data association analysis and natural language processing techniques are used to extract keywords from the updated asset exposure and vulnerability databases. Exposures with a similarity greater than 9 are then associated with vulnerabilities through word vector similarity calculations to identify vulnerabilities associated with new or changed exposures. Based on the results of the vulnerability association analysis, risk indicators corresponding to the vulnerabilities, including vulnerability severity level and exploitation difficulty, are retrieved from the risk knowledge base. A comprehensive assessment of the new or changed exposures, associated vulnerabilities, and risk indicators is conducted. A rule-based risk assessment model is used to weight different risk factors to calculate the latest risk score for the asset. Risk levels are then classified based on the score range. If the latest risk score exceeds 8 or the risk level is high, a security policy update is triggered. Based on the latest risk score and risk level, corresponding protection measures are matched from the security policy knowledge base. The knowledge base contains pre-configured firewall rule and IPS rule templates corresponding to different risk levels, allowing for the generation of targeted protection policy configurations based on the risk profile.Through the security configuration issuing interface, the updated protection strategy is automatically issued to the firewall and IPS device by using the SSH protocol, the issuing process takes no more than 1 minute, and the protection strategy is dynamically adjusted. The asset exposure change information and the protection effect information are continuously monitored, the monitoring period is 10 minutes, the asset exposure change information and the protection effect information are fed back in real time, if the protection strategy is invalid or the asset exposure surface is continuously deteriorated, etc., the above process is automatically triggered, a dynamic closed-loop continuous protection mechanism is formed, and real-time perception and rapid response to asset security risks are realized.

[0109] In another preferred embodiment of the present invention, based on the discovery of assets in the power monitoring system, key information of the assets is obtained; the security risk level of the assets is determined through analysis of key information, and a list of high-risk assets is determined. If the asset is a high-risk asset, then according to the security protection strategy, security protection measures are matched to form an asset security reinforcement plan; an automated configuration management tool is used to apply the asset security reinforcement plan to the asset to complete asset security protection; logs and monitoring data during the operation of the asset are obtained, and through security analysis, the asset security status and risk changes are judged to identify suspicious behavior; if an asset security incident or risk change is found, the asset security response process is triggered and handled according to the preset disposal plan; if the asset changes, the asset information is re-acquired, and the asset risk prediction and protection process is entered to achieve continuous management and control of the entire life cycle of the asset. Specifically, the power monitoring system network is automatically scanned by the asset discovery tool to obtain key information such as the asset's IP address, operating system, port, service, etc., and the asset fingerprint recognition technology is used to achieve an identification rate of over 95%. Risk prediction models are used to comprehensively assess asset vulnerabilities, configurations, permissions, and other factors. A fuzzy comprehensive evaluation method is used to calculate asset security risk scores, categorizing risk levels into low, medium, and high. Assets with scores greater than 8 are classified as high-risk. For high-risk assets, corresponding security measures are implemented, such as closing non-essential ports, patching vulnerabilities, and strengthening identity authentication, to form an asset security hardening plan. Through automated configuration management tools such as Ansible, the hardening plan is applied to assets, enabling rapid and comprehensive security protection. Asset system logs, network traffic, and other data are continuously monitored, and machine learning algorithms are used for security analysis. Anomaly detection models are used to determine asset security status and identify suspicious behavior. When security incidents are discovered, pre-defined automated response processes are used to quickly isolate affected assets and prevent the spread of attacks. Changes to assets, such as adding new equipment or upgrading software, trigger the asset security assessment process again, dynamically updating the asset's risk profile and protective measures. The asset management platform centrally displays information on asset security risks, protection status, and security incidents, creating an intuitive and visual overview of asset security. By leveraging asset security big data and optimizing risk prediction models through machine learning algorithms, the accuracy of risk identification is improved, while security protection strategies are dynamically adjusted to achieve intelligent and adaptive asset security management and control.

[0110] By implementing this embodiment, the network topology data and system operation data of the power monitoring system to be evaluated are analyzed, and the assets of the monitoring system to be evaluated can be identified. Then, situational awareness of the assets is performed within a preset time interval, and an asset exposure database of the power monitoring system to be evaluated is constructed, so as to perform vulnerability scanning, and vulnerability scanning is performed within a preset time interval to carry out evaluation work. Vulnerability scanning is neither used frequently nor too low in frequency. At the same time, a risk assessment of the power monitoring system to be evaluated is performed based on the asset exposure database, vulnerability information, and vulnerability database, and an asset risk assessment result of the power monitoring system to be evaluated is obtained. This can comprehensively assess the asset exposure and vulnerability situations in the power monitoring system. Even if the system's assets include equipment from different manufacturers, quantitative analysis can be performed based on the constructed asset exposure database and asset vulnerability information, thereby reducing the difficulty of risk assessment of the power monitoring system.

[0111] See also Figure 2 , is a schematic diagram of the structure of an asset risk assessment device for a power monitoring system provided by one embodiment of the present invention, comprising:

[0112] System data acquisition module, used to obtain network topology data and system operation data of the power monitoring system to be evaluated;

[0113] A system asset discovery module, configured to perform communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data, and obtain the assets of the monitoring system to be evaluated;

[0114] An asset database construction module is used to perform situational awareness of the assets of the power monitoring system to be evaluated within a preset time interval and to construct an asset exposure database of the power monitoring system to be evaluated;

[0115] A vulnerability scanning module is used to perform vulnerability scanning on the power monitoring system to be evaluated based on the asset exposure database and a preset vulnerability database to obtain vulnerability information of the asset;

[0116] The risk assessment module is used to perform risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information and the vulnerability database, and obtain an asset risk assessment result of the power monitoring system to be assessed.

[0117] The application provides an electric power monitoring system asset risk assessment device, network topology data and system operation data of an electric power monitoring system to be assessed are acquired by a system data acquisition module; then in a system asset discovery module, the network topology data and the system operation data are used for communication protocol analysis on the electric power monitoring system to be assessed, so that assets of the monitoring system to be assessed are obtained; then in an asset database construction module, the assets of the electric power monitoring system to be assessed are used for situation awareness on the assets within a preset time interval, so that an asset exposure surface database of the electric power monitoring system to be assessed is constructed; then in a vulnerability scanning module, the asset exposure surface database and a preset vulnerability database are used for vulnerability scanning on the electric power monitoring system to be assessed, so that vulnerability information of the assets is obtained; finally in a risk assessment module, the asset exposure surface database, the vulnerability information and the vulnerability database are used for risk assessment on the electric power monitoring system to be assessed, so that an asset risk assessment result of the electric power monitoring system to be assessed is obtained. By analyzing the network topology data and the system operation data of the electric power monitoring system to be assessed, the assets of the monitoring system to be assessed can be identified, then the assets are subjected to situation awareness within a preset time interval, so that the asset exposure surface database of the electric power monitoring system to be assessed is constructed, thereby the vulnerability scanning is performed, the vulnerability scanning is performed within the preset time interval to carry out the assessment work, the vulnerability scanning is not used frequently, and the frequency of the vulnerability scanning is not too low; meanwhile, the asset exposure surface database, the vulnerability information and the vulnerability database are used for risk assessment on the electric power monitoring system to be assessed, so that the asset risk assessment result of the electric power monitoring system to be assessed is obtained, the asset exposure surface condition and the vulnerability condition in the electric power monitoring system can be comprehensively assessed, even if the assets of the system include devices from different manufacturers, the asset exposure surface database and the vulnerability information of the assets can be used for quantitative analysis, and the difficulty of the risk assessment of the electric power monitoring system is reduced.

[0118] It should be noted that the apparatus embodiments described above are only schematic and that one part can or can not be physically separate to other parts shown as separate components, and that these components shown as separate components can or can not be physical components, i.e. can be located in one place or distributed over multiple network components. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment. In addition, the connection relationship between the modules in the apparatus embodiment provided by the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.

[0119] Those skilled in the art can clearly understand that, for the convenience and brevity, the specific working process of the above-described device can refer to the corresponding process in the foregoing method embodiments, which will not be described here.

[0120] Another embodiment of the present invention provides a terminal device comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power monitoring system asset risk assessment method described in the above embodiment. The terminal device can be a computing device such as a desktop computer, a notebook computer, a PDA, or a cloud server. The terminal device can include, but is not limited to, a processor and a memory.

[0121] The processor may be a central processing unit (CPU), or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, and connects various parts of the entire terminal device using various interfaces and lines.

[0122] The memory can be used to store the computer program, and the processor realizes various functions of the terminal device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (SMC), a secure digital (SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device or other volatile solid-state storage device.

[0123] Another embodiment of the present invention provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the power monitoring system asset risk assessment method described in the above embodiment.

[0124] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by the processor, the steps of the above-mentioned method embodiments can be implemented. The computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunications signal, and a software distribution medium.

[0125] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A method for assessing asset risk in a power monitoring system, characterized in that: include: Obtain network topology data and system operation data of the power monitoring system to be evaluated; performing communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data to obtain assets of the monitoring system to be evaluated; Based on the assets of the power monitoring system to be evaluated, situational awareness of the assets is performed within a preset time interval to build an asset exposure database of the power monitoring system to be evaluated; Performing vulnerability scanning on the power monitoring system to be assessed based on the asset exposure database and a preset vulnerability database to obtain asset vulnerability information; Performing a risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database to obtain an asset risk assessment result of the power monitoring system to be assessed; Based on the network topology data and the system operation data, a communication protocol analysis is performed on the power monitoring system to be evaluated to obtain the assets of the monitoring system to be evaluated, including: Determine node attribute information of each node in the power monitoring system to be evaluated based on the network topology data; the node attribute information includes: node IP address, node port number and node service type; Based on the system proprietary protocol in the system operation data, the system proprietary protocol is analyzed by using the protocol reverse engineering method and the data packet analysis method to obtain the proprietary protocol characteristics of the power monitoring system to be evaluated; Determining whether there is a system proprietary protocol response port in the power monitoring system to be evaluated based on the node attribute information, the proprietary protocol characteristics, and a preset proprietary protocol characteristic model library; If so, obtaining a response message from the system's proprietary protocol response port, and identifying the assets of the monitoring system to be evaluated based on the response message; If not, construct an asset discovery engine based on the proprietary protocol characteristics, and scan the ports of the power monitoring system to be evaluated using the asset discovery engine to obtain the assets of the power monitoring system to be evaluated; Based on the assets of the power monitoring system to be assessed, situational awareness of the assets is performed within preset time intervals to build an asset exposure database for the power monitoring system to be assessed, including: Determine the network behavior characteristics, communication mode characteristics, and service status characteristics of the assets in the power monitoring system to be evaluated; Clustering assets within a preset time interval based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics to obtain asset groups; Analyze the network communication relationship between different assets based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics, and construct an asset association topology diagram between the assets; An asset exposure surface database of the power monitoring system to be evaluated is constructed based on the asset group and the asset association topology map.

2. The method for asset risk assessment of a power monitoring system according to claim 1, wherein: The construction of the preset vulnerability database includes: Obtain historical vulnerability event information of the power monitoring system and historical vulnerability information corresponding to the historical vulnerability event information; the historical vulnerability information includes vulnerability description, vulnerability affected version and vulnerability risk level; Perform semantic extraction based on the historical vulnerability event information to obtain vulnerability attack methods and attack device types; Perform semantic extraction based on the vulnerability description to obtain the vulnerability type; Build a vulnerability database based on vulnerability attack methods, attack device types, vulnerability types, vulnerability-affected versions, and vulnerability risk levels.

3. The method for asset risk assessment of a power monitoring system according to claim 2, wherein: A vulnerability scan is performed on the power monitoring system to be assessed based on the asset exposure database and the preset vulnerability database to obtain asset vulnerability information, including: Determining basic attributes of an asset based on the asset exposure database; the basic attributes include an operating system version, a middleware version, and an open port type; Determining the vulnerability type corresponding to the basic attribute according to the vulnerability impact version corresponding to the basic attribute in a preset vulnerability database; Perform vulnerability scanning on the assets of the power monitoring system to be assessed based on the vulnerability types corresponding to the basic attributes, and generate a preliminary vulnerability list; the preliminary vulnerability list includes: potential vulnerabilities, preliminary risk levels of potential vulnerabilities, and existing vulnerabilities; Conduct code audits on potential vulnerabilities based on the preliminary vulnerability list to obtain vulnerability information of the assets.

4. The method for assessing asset risk of a power monitoring system according to claim 1, wherein: Performing a risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database to obtain an asset risk assessment result of the power monitoring system to be assessed, including: Associating the vulnerability information with the vulnerability database to calculate a first score indicating the severity of the vulnerability; Determining a second score representing the importance of the asset based on the asset exposure database and the vulnerability information; Calculating a comprehensive risk score of the power monitoring system to be evaluated based on the first score and the second score; According to the comprehensive risk score and the preset risk threshold, the magnitude relationship between the comprehensive risk score and the preset risk threshold is determined to obtain an asset risk assessment result of the power monitoring system to be assessed.

5. The method for asset risk assessment of a power monitoring system according to claim 2, wherein: Also includes: Monitor the asset exposure database of the power monitoring system to be evaluated in real time. When the asset exposure database changes, calculate the database similarity between the asset exposure database after the change and the asset exposure database before the change. When the database similarity is less than a preset similarity threshold, the changed asset exposure database and the vulnerability database are associated to obtain the latest vulnerability associated with the asset exposure of the power monitoring system to be evaluated; Determine the protection level corresponding to the vulnerability risk level based on the vulnerability risk level corresponding to the latest vulnerability; According to the protection level, the firewall and IPS protection strategy corresponding to the protection level are activated; and according to the firewall and IPS protection strategy, the power monitoring system to be evaluated is protected.

6. An asset risk assessment device for a power monitoring system, characterized in that: include: System data acquisition module, used to obtain network topology data and system operation data of the power monitoring system to be evaluated; A system asset discovery module, configured to perform communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data, and obtain the assets of the monitoring system to be evaluated; An asset database construction module is used to perform situational awareness of the assets of the power monitoring system to be evaluated within a preset time interval and to construct an asset exposure database of the power monitoring system to be evaluated; A vulnerability scanning module is used to perform vulnerability scanning on the power monitoring system to be evaluated based on the asset exposure database and a preset vulnerability database to obtain vulnerability information of the asset; a risk assessment module, configured to perform a risk assessment on the power monitoring system to be assessed based on the asset exposure database, the vulnerability information, and the vulnerability database, and obtain an asset risk assessment result of the power monitoring system to be assessed; The system asset discovery module is configured to perform communication protocol analysis on the power monitoring system to be evaluated based on the network topology data and the system operation data to obtain the assets of the monitoring system to be evaluated, including: Determine node attribute information of each node in the power monitoring system to be evaluated based on the network topology data; the node attribute information includes: node IP address, node port number and node service type; Based on the system proprietary protocol in the system operation data, the system proprietary protocol is analyzed by using the protocol reverse engineering method and the data packet analysis method to obtain the proprietary protocol characteristics of the power monitoring system to be evaluated; Determining whether there is a system proprietary protocol response port in the power monitoring system to be evaluated based on the node attribute information, the proprietary protocol characteristics, and a preset proprietary protocol characteristic model library; If so, obtaining a response message from the system's proprietary protocol response port, and identifying the assets of the monitoring system to be evaluated based on the response message; If not, construct an asset discovery engine based on the proprietary protocol characteristics, and scan the ports of the power monitoring system to be evaluated using the asset discovery engine to obtain the assets of the power monitoring system to be evaluated; The asset database construction module is used to perform situational awareness of the assets of the power monitoring system to be evaluated within a preset time interval and to construct an asset exposure database of the power monitoring system to be evaluated, including: Determine the network behavior characteristics, communication mode characteristics, and service status characteristics of the assets in the power monitoring system to be evaluated; Clustering assets within a preset time interval based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics to obtain asset groups; Analyze the network communication relationship between different assets based on the network behavior characteristics, the communication mode characteristics, and the service status characteristics, and construct an asset association topology diagram between the assets; An asset exposure surface database of the power monitoring system to be evaluated is constructed based on the asset group and the asset association topology map.

7. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the method for asset risk assessment of an electric power monitoring system as described in any one of claims 1 to 5 is implemented.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the power monitoring system asset risk assessment method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Configurable automatic asset risk assessment method and device and medium

    CN117857162A