Power station monitoring system network security protection method and system, electronic equipment and storage medium

By constructing a signal transmission threshold prediction model, the signal quantity and security status of the power plant monitoring system equipment are monitored, and network security detection and temporary control are carried out. This solves the network stability problem of the power plant monitoring system and ensures the safe operation and rapid response capability of the network.

CN119094165BActive Publication Date: 2025-12-19CHINA YANGTZE POWER
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411065393.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2025-12-19
Estimated Expiration
2044-08-05

AI Technical Summary

Technical Problem

Existing technologies for power plant monitoring system network security primarily focus on data security, while neglecting the issue of stable network operation. This makes the monitoring system network vulnerable to attacks, affecting the overall operational stability.

Method used

By constructing a signal transmission threshold prediction model, based on unit operation data and the signal transmission threshold of power generation equipment, the number of equipment signals is monitored, the safety status of the equipment is determined, and network security detection and temporary control are carried out on equipment in an unsafe state, generating early warning information.

Benefits of technology

This ensures the safe operation of the power plant monitoring system network, avoids large-scale, inefficient detection, enables rapid response to security incidents, improves emergency rescue efficiency, and ensures network stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094165B_ABST
    Figure CN119094165B_ABST
Patent Text Reader

Abstract

A power station monitoring system network security protection method, based on current power station operation data to generate signal sending threshold of each device; monitor the signal sending quantity of each device within the preset monitoring time length; based on the signal sending threshold and the signal sending quantity, judge whether each device is in a safe state; network security detection is carried out on the device in the non-safe state; the device with network security detection threat is temporarily controlled and the early warning information is generated. The method solves the problem of attacking the whole monitoring network by cracking a certain device, protects the network security operation, at the same time, generates early warning signal and controls the device with network security detection threat, further ensures the stable operation of the power station monitoring system network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of monitoring technology, and relates to a power station monitoring system network security protection method and system, an electronic device and a storage medium. BACKGROUND

[0002] A power station is a facility responsible for producing electricity, including thermal power plants, hydroelectric power stations, wind power stations, solar power stations, and other renewable energy power stations.

[0003] The power station monitoring system network is a complex network composed of multiple devices, sensors and control systems, and is designed to ensure the safe, reliable and economically efficient operation of the power station. The power station monitoring system network mainly includes the following parts: data acquisition devices, data transmission devices, data processing and analysis devices, control devices, display devices, human-computer interaction devices, etc.

[0004] The security of the power station monitoring system network is very important, and the existing technology generally adopts the following methods to ensure security,

[0005] 1) Network devices, security devices, operating systems, database systems, etc. will use two or more than two identification technologies to identify users, and at least one identification technology will use password technology to achieve, such as: establishing an authentication server and distributing device administrator tokens to realize a two-factor authentication mechanism based on dynamic passwords.

[0006] 2) Network communication channels will build encrypted transmission channels through power special encryption devices, and use digital certificates of password algorithms that meet the requirements to realize the identity identification of communication entities, and verify the validity of device digital certificates.

[0007] 3) Use password technology to perform security access authentication on devices connected from the outside to the internal network, and ensure the authenticity of the access device.

[0008] 4) Servers, database management systems, etc. will use password technology to ensure the integrity of system resource access control information, and ensure the integrity and authenticity of important executable programs.

[0009] 5) Application system operation and maintenance users and business users will use two or more than two identification technologies to identify users, and at least one identification technology will use password technology to ensure the authenticity of the user's identity.

[0010] 6) The application system will use cryptographic techniques to protect the access control information integrity, use cryptographic techniques or cryptographic products to ensure the confidentiality of data transmission, the application system business data will use cryptographic techniques or cryptographic products to ensure the confidentiality of the storage process, use cryptographic techniques or cryptographic products to ensure the integrity of important data transmission, use cryptographic techniques or cryptographic products to ensure the integrity of important data storage process.

[0011] In summary, the prior art focuses more on how to ensure the data security problem in the monitoring system, and ignores the problem of stable operation of the monitoring system network, therefore, how to ensure the safe operation of the monitoring system network is a problem to be solved. SUMMARY

[0012] The technical problem to be solved by the present application is to provide a power station monitoring system network security protection method, which realizes the safe operation of the monitoring system network.

[0013] To solve the above technical problems, the technical solution adopted by the present application is: a power station monitoring system network security protection method, comprising the following steps:

[0014] S1, based on the current unit operation data and the power generation power of the power station, respectively using the signal sending threshold value prediction model corresponding to each device to generate the signal sending threshold value of each device; monitoring the signal sending quantity of each device within a preset monitoring time length;

[0015] S1-1, preprocessing the meteorological data and the power generation power;

[0016] S1-2, inputting the preprocessed meteorological data and power generation power into the signal sending threshold value prediction model corresponding to each device respectively, and obtaining the to-be-verified threshold value generated by each signal sending threshold value prediction model respectively;

[0017] S1-3, verifying whether each to-be-verified threshold value is within a preset range; if yes, then taking each to-be-verified threshold value as the signal sending threshold value of the corresponding device respectively;

[0018] S2, judging whether each device is in a safe state based on the signal sending threshold value and the signal sending quantity; when the signal sending quantity is greater than the signal sending threshold value, it is judged that the device is in an unsafe state;

[0019] S3, performing network security detection on the device in the unsafe state;

[0020] S4, temporarily managing and controlling the device that poses a threat to network security detection and generating a warning information; temporarily managing and controlling the device that poses a threat to network security detection and generating a warning information includes: determining the management and warning level of the device that poses a threat to network security detection based on the signal sending threshold and the signal sending quantity; temporarily managing and controlling the device that poses a threat to network security detection based on the management and warning level and generating a warning information.

[0021] Determining the management and warning level of the device that poses a threat to network security detection based on the signal sending threshold and the signal sending quantity includes: when the signal sending quantity is 101%-130% of the signal sending threshold, the management and warning level is level three; when the signal sending quantity is 131%-150% of the signal sending threshold, the management and warning level is level two; and when the signal sending quantity is greater than 150% of the signal sending threshold, the management and warning level is level one.

[0022] Temporarily managing and controlling the device that poses a threat to network security detection based on the management and warning level and generating a warning information includes: when the management and warning level is level three, not managing and controlling the device, and generating a level three warning information; when the management and warning level is level two, managing and controlling the device according to the signal sending quantity threshold, and generating a level two warning information; and when the management and warning level is level one, prohibiting the device from sending signals, and generating a level one warning information.

[0023] In S1, monitoring the signal sending quantity of each device within a preset monitoring time length includes: obtaining preset monitoring frequency and monitoring time length information; generating a monitoring time based on the preset monitoring frequency and monitoring time length information; and collecting the signal sending quantity of each device within the monitoring time.

[0024] In S1, using the signal sending threshold prediction model corresponding to the device includes the following steps:

[0025] SA1, collecting historical data of all devices, calculating correlation coefficients between each device based on the historical data using a correlation analysis tool, and generating a correlation matrix; collecting historical data of each device, including running state and sensor data; using a correlation analysis tool to analyze correlation coefficients or covariance and assessing the correlation between each device based on historical data;

[0026] SA2, the correlation coefficient between the i-th device and the j-th device in the correlation matrix is calculated by the following formula:

[0027] ;

[0028] Wherein, Xi is the data of the i th device, Xj is the data of the j th device, corr(Xi, Xj) is the correlation coefficient between Xi and Xj; cov(Xi, Xj) is the covariance of Xi and Xj, var(Xi) and var(Xj) are the variance of Xi and Xj respectively;

[0029] SA3, using a machine learning algorithm to construct an initial signal sending threshold prediction model, wherein the weight of each device to the signal sending threshold of the i th device is introduced into the model;

[0030] Based on the correlation matrix and historical data between devices, an initial signal sending threshold prediction model is constructed using a machine learning algorithm, so that the generated signal sending threshold can fully reflect the correlation between devices; the machine learning algorithm includes regression analysis, neural network; the initial signal sending threshold prediction model of the i th device is as follows:

[0031] ;

[0032] Wherein, Thresholdi is the signal sending threshold of the i th device, Wij is the weight of the j th device to the signal sending threshold of the i th device.

[0033] According to the correlation between each device and the i th device, the influence degree of each related device on the signal sending threshold is determined, and the above weight is adjusted; through the above weight adjustment mechanism, the device with higher correlation with the i th device has greater influence;

[0034] The weight Wij of the signal sending threshold of the j th device and the i th device is adjusted by the following formula:

[0035] ;

[0036] Wherein, Wij is the weight of the j th device to the signal sending threshold of the i th device, corr weight is the correlation strength conversion function of the weight, f(Temperature, Vibration, …) is a complex function of temperature, vibration factors;

[0037] The data of each device is continuously collected, and the corresponding weight is adjusted in time according to the data change; a real-time monitoring system is established to continuously monitor the state and data change of each device; when the data change exceeds a certain range, the corresponding weight is adjusted in time according to the new data; the application effect of the signal sending threshold is monitored, and the signal sending threshold prediction model is optimized and adjusted according to the application effect; the application effect is characterized by various evaluation indexes, including the false rejection rate, and the accuracy, stability and reliability of the method are further improved through optimization and adjustment.

[0038] The process of optimizing and adjusting the signal sending threshold prediction model according to the false positive rate specifically includes:

[0039] First, define the objective function, the false positive rate is obtained by calculating the ratio of the number of false positives and false negatives to the total number of samples; define the objective function as the false positive rate, denoted as Error_Rate, and its calculation formula is:

[0040] ;

[0041] Where FalsePositive is the number of false positives, FalseNegative is the number of false negatives, and TotalSamples is the total number of samples;

[0042] Second, determine the optimization algorithm, choose gradient descent, genetic algorithm, and particle swarm optimization to minimize the false positive rate;

[0043] Third, establish the optimization model, associate the objective function ErrorRate with the parameters or variables in the signal sending threshold prediction model, and establish the optimization model, that is, take the parameters or variables of the signal sending threshold prediction model as the independent variables of the optimization problem, and take the false positive rate as the objective function;

[0044] Fourth, set the initial parameters, provide the initial parameter or variable values for the optimization model according to historical data or experience, and use them to start the iteration process of the optimization model;

[0045] Fifth, execute the optimization algorithm, use the optimization model to optimize the objective function to reduce the false positive rate;

[0046] Sixth, convergence judgment, set a convergence condition, that is, stop optimization when the change of the objective function value is less than a certain threshold or the number of iterations reaches a certain value, monitor the convergence of the optimization model, and judge whether the condition for stopping optimization is met;

[0047] Seventh, apply the optimization results, apply the optimized parameters and / or variables to the signal sending threshold prediction model, and update the signal sending threshold prediction model.

[0048] The security protection system of the power plant monitoring system network security protection method has a threshold generation unit, a data monitoring unit, a judgment unit, a security monitoring unit, and a temporary control and early warning information generation unit connected in sequence.

[0049] The electronic device of the power plant monitoring system network security protection method has at least one processor and a memory in communication with the at least one processor.

[0050] The computer readable storage medium of the power plant monitoring system network security protection method stores computer instructions for causing a computer to execute the power plant monitoring system network security protection method.

[0051] The main benefits of the present application are:

[0052] By monitoring the signal sending quantity of each device and the signal sending threshold generated according to the operating data, it is determined whether the device is suspected to be cracked (i.e., in an unsafe state), and then further network security detection is performed on the suspected cracked device, and finally temporary control and early warning information are generated according to the device that poses a threat to network security detection. The above scheme not only starts from whether the device is in a safe state, performs preliminary screening, and then performs network security detection, avoiding large-scale and inefficient network security detection, but also solves the problem of attacking the entire monitoring network by cracking a certain device, protects the network security operation, and generates an early warning signal and controls the device that poses a threat to network security detection, further ensuring the stable operation of the power plant monitoring system network.

[0053] The signal sending threshold prediction model is combined with the unit operating data and the power generation power to dynamically determine the signal sending threshold, so as to intelligently control each device in combination with different working conditions.

[0054] The devices threatened to network security detection are rated based on the signal sending threshold and the signal sending quantity, different levels adopt different processing modes, and the overall influence of directly shutting down a device on the power station is avoided.

[0055] The management and early warning levels are further determined by the ratio of the signal sending quantity to the signal sending threshold, and different management means and early warning information are implemented according to different early warning levels, so that different early warning levels are set for different situations, which is beneficial to quickly respond when a security event actually occurs and improve the emergency rescue efficiency, and meanwhile, the input of safety resources can be flexibly adjusted according to the actual situation. BRIEF DESCRIPTION OF DRAWINGS

[0056] The application will be further described below in combination with the drawings and embodiments.

[0057] Fig. 1 The method flowchart of the application.

[0058] Fig. 2 The network security protection system diagram of the application.

[0059] Fig. 3 The structural schematic diagram of the electronic device of the application. DETAILED DESCRIPTION

[0060] As Figs. 1-3 In the present application, a power station monitoring system network security protection method,

[0061] Embodiment 1,

[0062] In a first aspect, the present application provides a power station monitoring system network security protection method, applied to a power station network security protection device, and adopting the following technical scheme:

[0063] Based on the current unit operation data and the power generation power of the power station, a signal sending threshold prediction model corresponding to each device is used to generate a signal sending threshold of each device; and the signal sending quantity of each device within a preset monitoring time length is monitored;

[0064] Based on the signal sending threshold and the signal sending quantity, it is determined whether each device is in a safe state;

[0065] The device in the non-safe state is subjected to network security detection;

[0066] The device threatened to network security detection is subjected to temporary management and control, and early warning information is generated.

[0067] As an optional implementation manner, the signal sending threshold prediction model corresponding to each device is used to generate a signal sending threshold of each device based on the current meteorological data and the power generation power of the power station, including:

[0068] preprocessing the weather data and the power generation;

[0069] inputting the preprocessed weather data and the power generation into respective signal sending threshold prediction models corresponding to respective devices, and obtaining respective to-be-verified thresholds generated by the respective signal sending threshold prediction models;

[0070] verifying whether the respective to-be-verified thresholds are within a preset range;

[0071] if yes, taking the respective to-be-verified thresholds as signal sending thresholds of the respective devices.

[0072] As an optional implementation, judging whether the respective devices are in a safe state based on the signal sending thresholds and the signal sending quantities comprises:

[0073] judging that the device is in an unsafe state when the signal sending quantity is greater than the signal sending threshold.

[0074] As an optional implementation, temporarily managing and controlling the device that poses a threat to network security detection and generating an early warning information comprises:

[0075] determining a management and early warning level of the device that poses a threat to network security detection based on the signal sending threshold and the signal sending quantity;

[0076] temporarily managing and controlling the device that poses a threat to network security detection and generating an early warning information based on the management and early warning level.

[0077] As an optional implementation, determining a management and early warning level of the device that poses a threat to network security detection based on the signal sending threshold and the signal sending quantity comprises:

[0078] when the signal sending quantity is 101%-130% of the signal sending threshold, the management and early warning level is level three;

[0079] when the signal sending quantity is 131%-150% of the signal sending threshold, the management and early warning level is level two;

[0080] when the signal sending quantity is greater than 150% of the signal sending threshold, the management and early warning level is level one.

[0081] As an optional implementation, temporarily managing and controlling the device that poses a threat to network security detection and generating an early warning information based on the management and early warning level comprises:

[0082] when the management and early warning level is level three, not managing and controlling the device, and generating a level-three early warning information;

[0083] When the management and early warning level is the second level, the number of signal sending of the threshold management device is controlled according to the threshold, and second-level early warning information is generated;

[0084] When the management and early warning level is the first level, the signal sending of the device is prohibited, and first-level early warning information is generated.

[0085] As an optional implementation, the monitoring of the number of signal sending of each device in a preset monitoring time length comprises:

[0086] obtaining preset monitoring frequency and monitoring time length information;

[0087] generating a monitoring time based on the preset monitoring frequency and monitoring time length information;

[0088] collecting the number of signal sending of each device in the monitoring time.

[0089] In a second aspect, the disclosure embodiment further provides an electric station monitoring system network security protection system, comprising:

[0090] a threshold generation and data monitoring unit, which generates a signal sending threshold of each device based on current unit operation data and power generation power of the electric station using a signal sending threshold prediction model corresponding to each device; and monitors the number of signal sending of each device in a preset time period;

[0091] a judgment unit, which judges whether each device is in a safe state based on the signal sending threshold and the number of signal sending;

[0092] a security monitoring unit, which performs network security detection on the device in the non-safe state;

[0093] a temporary management and early warning information generation unit, which performs temporary management on the device posing a threat to the network security detection and generates early warning information.

[0094] In a third aspect, the disclosure embodiment further provides an electronic device, which adopts the following technical solution:

[0095] The electronic device comprises at least one processor and a memory in communication connection with the at least one processor; the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the electric station monitoring system network security protection method described above.

[0096] In a fourth aspect, the disclosure embodiment further provides a computer readable storage medium, which stores computer instructions for enabling a computer to execute the electric station monitoring system network security protection method described above.

[0097] Embodiment 2,

[0098] A power station is a facility responsible for producing electrical energy, including thermal power plants, hydroelectric power stations, wind power stations, solar power stations, and other renewable energy power stations.

[0099] A power station monitoring system network is a complex network composed of multiple devices, sensors, and control systems, designed to ensure the safe, reliable, and economically efficient operation of the power station. The power station monitoring system network mainly includes the following parts: data acquisition devices, data transmission devices, data processing and analysis devices, control devices, display devices, and human-computer interaction devices.

[0100] With reference to Fig. 1 The first aspect of the present application provides a power station monitoring system network security protection method, applied to power station network security protection devices such as firewalls, switches, routers, intrusion prevention systems, bastion hosts, etc., comprising:

[0101] Step S1, based on the current unit operation data and the power generation power of the power station, respectively using the signal sending threshold prediction model corresponding to each device to generate the signal sending threshold of each device; monitoring the number of signal sending of each device within a preset monitoring time length;

[0102] For example, the unit operation data of a hydroelectric power station includes unit speed, power generation voltage, power generation current, power generation frequency, water level, and flow rate.

[0103] Specifically, the signal sending threshold prediction model corresponding to each device is generated based on the current unit operation data and the power generation power of the power station, respectively, including:

[0104] The unit operation data and the power generation power are preprocessed; preprocessing includes cleaning data, removing outliers and missing data; data standardization or normalization to enable the model to better handle data of different scales.

[0105] The preprocessed unit operation data and power generation power are respectively input into the signal sending threshold prediction model corresponding to each device, and the respective signal sending threshold prediction model generates a to-be-verified threshold value;

[0106] Respectively verify whether each to-be-verified threshold value is within a preset range;

[0107] If yes, then respectively take each to-be-verified threshold value as the signal sending threshold of the corresponding device.

[0108] Specifically, each device has a corresponding signal sending threshold prediction model, which is trained by historical data, and the historical data for training includes unit operation data, power generation and the amount of data of the sending signal; the model trained based on the historical data can generate the signal sending threshold according to the current unit operation data and power generation.

[0109] Since in the power plant monitoring system, each device is not isolated from each other, there will be certain influence between devices, and in the embodiments of the present disclosure, the influence between devices can be considered in the process of building the model, and exemplarily, building the signal sending threshold prediction model corresponding to the i th device includes:

[0110] 1. Collect the historical data of all devices, and use the correlation analysis tool to calculate the correlation coefficient between devices based on the historical data, and generate a correlation matrix.

[0111] Specifically, the historical data of each device is collected, including operating state, sensor data, etc. The correlation analysis tool, such as correlation coefficient or covariance, is used to evaluate the correlation between devices based on historical data.

[0112] Exemplarily, the correlation coefficient between the i th device and the j th device in the correlation matrix is calculated by the following formula:

[0113] ;

[0114] Wherein, Xi is the data of the i th device, Xj is the data of the j th device, corr(Xi, Xj) is the correlation coefficient between Xi and Xj; cov(Xi, Xj) is the covariance of Xi and Xj, and var(Xi) and var(Xj) are the variances of Xi and Xj.

[0115] 2. Use a machine learning algorithm to build an initial signal sending threshold prediction model, which introduces the weight of each device on the signal sending threshold of the i th device in the model.

[0116] Based on the correlation matrix and historical data between devices, a machine learning algorithm such as regression analysis, neural network, etc. is used to build an initial signal sending threshold prediction model, so that the generated signal sending threshold can fully reflect the correlation between devices.

[0117] Exemplarily, the initial signal sending threshold prediction model of the i th device is as follows:

[0118]

[0119] Wherein, Thresholdi is the signal sending threshold of the ith device, and Wij is the weight of the jth device to the signal sending threshold of the ith device.

[0120] 3. According to the correlation between each device and the ith device, the influence degree of each related device to the signal sending threshold is determined, and the above weight is adjusted.

[0121] Through the above weight adjustment mechanism, the device with higher correlation to the ith device has greater influence.

[0122] Exemplarily, the weight Wij of the jth device to the signal sending threshold of the ith device is adjusted by the following formula.

[0123]

[0124] Wherein, Wij is the weight of the jth device to the signal sending threshold of the ith device, corr weight is the correlation strength to weight conversion function, and f(Temperature, Vibration, …) is a complex function of multiple factors such as temperature, vibration, etc.

[0125] 4. Continuously collect data of each device, and adjust the corresponding weight in time according to the data change.

[0126] In the embodiment of the present disclosure, a real-time monitoring system can be established to continuously monitor and collect the state and data change of each device. When the data change exceeds a certain range, the corresponding weight is adjusted in time according to the new data.

[0127] 5. Monitor the application effect of the signal sending threshold, and optimize and adjust the signal sending threshold prediction model according to the application effect.

[0128] The application effect can be represented by various pre-established evaluation indexes, such as false positive rate, etc. Through optimization and adjustment, the accuracy, stability and reliability of the method can be further improved.

[0129] Exemplarily, the process of optimizing and adjusting the signal sending threshold prediction model according to the false positive rate specifically includes:

[0130] a. Define the objective function: the false positive rate is obtained by calculating the ratio of the number of false positive and false negative to the total number of samples. The objective function is defined as the false positive rate, denoted as Error_Rate, and the calculation formula is:

[0131]

[0132] Where FalsePositive is the number of false positives, FalseNegative is the number of false negatives, and TotalSamples is the total number of samples.

[0133] b. Determine the optimization algorithm: select appropriate optimization algorithms such as gradient descent, genetic algorithm, particle swarm optimization, etc. to minimize the false positive rate.

[0134] c. Establish an optimization model: associate the objective function ErrorRate with the parameters or variables in the signal transmission threshold prediction model, and establish an optimization model, that is, take the parameters or variables of the signal transmission threshold prediction model as the independent variables of the optimization problem, and take the false positive rate as the objective function.

[0135] d. Set the initial parameters: provide the initial values of the parameters or variables of the optimization model according to historical data or experience, which is used to start the iteration process of the optimization model.

[0136] e. Execute the optimization algorithm: optimize the objective function using the optimization model to reduce the false positive rate.

[0137] f. Convergence judgment: set a convergence condition, such as stopping optimization when the change of the objective function value is less than a certain threshold or the number of iterations reaches a certain value, monitor the convergence of the optimization model, and judge whether the condition for stopping optimization is reached.

[0138] g. Apply the optimization results: apply the optimized parameters and / or variables to the signal transmission threshold prediction model to update the signal transmission threshold prediction model.

[0139] This step uses the signal transmission threshold prediction model combined with unit operation data and power generation to dynamically determine the signal transmission threshold, so as to intelligently control each device under different working conditions.

[0140] Specifically, the monitoring of the number of signal transmissions of each device within a preset monitoring time includes:

[0141] The preset monitoring frequency and monitoring time information is obtained; the monitoring frequency specifically refers to how often to monitor, for example, every hour, every 2 hours, every 6 hours, or every day, etc., and the monitoring time refers to the duration of each monitoring, for example, 5 minutes, 10 minutes, 30 minutes, or 1 hour, etc.

[0142] Specifically, obtaining the preset monitoring frequency and monitoring time information includes:

[0143] The monitoring frequency and monitoring time are generated in combination with the occurrence time of historical network attacks and the power generation cycle data;

[0144] For example, the monitoring frequency at night is more frequent than that in the daytime, and the monitoring duration is longer. The monitoring frequency in the peak season of power generation is more frequent than that in the off-season, and the monitoring duration is longer.

[0145] Generate the monitoring time based on the preset monitoring frequency and monitoring duration information. The monitoring time here refers to the specific monitoring time period, for example, monitoring from 8:00 to 8:30 on a certain day. Here, it refers to the time period from 8:00 to 8:30.

[0146] Collect the number of signal transmissions of each device within the monitoring time. Based on the above example, collect the number of signal transmissions sent from 8:00 to 8:30, for example, 324.

[0147] This step generates the monitoring frequency and monitoring duration by combining the occurrence time of historical network attacks and the power generation demand at the time, thereby intelligently adjusting the monitoring time, collecting the signal transmission amount of each device within the monitoring time, and intelligently optimizing the computing power of the computer under the condition of ensuring safety.

[0148] Step S2, determine whether each device is in a safe state based on the signal transmission threshold and the number of signal transmissions;

[0149] Specifically, determining whether each device is in a safe state based on the signal transmission threshold and the number of signal transmissions includes:

[0150] When the number of signal transmissions is greater than the signal transmission threshold, it is determined that the device is in an unsafe state.

[0151] As can be known, the signal transmission threshold in this step is obtained according to the previous step, and the signal transmission threshold is dynamic.

[0152] Step S3, performing network security detection on the device in an unsafe state;

[0153] The network security detection here is for network security detection such as viruses, attacks, illegal access, etc.

[0154] Step S4, temporarily managing and controlling the device that poses a threat to network security detection and generating an early warning information.

[0155] Specifically, temporarily managing and controlling the device that poses a threat to network security detection and generating an early warning information includes:

[0156] Determining the management and control and early warning level of the device that poses a threat to network security detection based on the signal transmission threshold and the number of signal transmissions;

[0157] Temporarily managing and controlling the device that poses a threat to network security detection based on the management and control and early warning level and generating an early warning information.

[0158] In this step, the devices in the non-safe state are rated based on the signal sending threshold and the signal sending quantity, different levels are treated differently, and the direct shutdown of a certain device avoids the overall impact on the power station.

[0159] In summary, the embodiments of the present disclosure provide a power station monitoring system network security protection method. The method determines whether a device is suspected to be cracked, i.e., in a non-safe state, by monitoring the signal sending quantity of each device and the signal sending threshold generated according to the operation data, then further performs network security detection on the suspected cracked device, and finally temporarily controls and generates a warning information according to the device that poses a threat to network security detection. The above scheme not only starts from whether the device is in a safe state for preliminary screening, and then performs network security detection, avoiding large-scale and inefficient network security detection, but also solves the problem of attacking the entire monitoring network by cracking a certain device, protects the network security operation, and generates a warning signal and controls the device that poses a threat to network security detection, further ensuring the stable operation of the power station monitoring system network.

[0160] As an optional implementation, determining the control and warning level of the device that poses a threat to network security detection based on the signal sending threshold and the signal sending quantity includes:

[0161] When the signal sending quantity is 101%-130% of the signal sending threshold, the control and warning level is level three;

[0162] When the signal sending quantity is 131%-150% of the signal sending threshold, the control and warning level is level two;

[0163] When the signal sending quantity is greater than 150% of the signal sending threshold, the control and warning level is level one. It can be known that in the warning level, level one is greater than level two, which is greater than level three.

[0164] As an optional implementation, temporarily controlling the device that poses a threat to network security detection and generating a warning information based on the control and warning level includes:

[0165] When the control and warning level is level three, the device is not controlled, and level three warning information is generated;

[0166] When the control and warning level is level two, the signal sending quantity of the threshold-controlled device is controlled, and level two warning information is generated;

[0167] When the control and warning level is level one, the device is prohibited from sending signals, and level one warning information is generated.

[0168] In the embodiment, the ratio of the signal sending quantity and the signal sending threshold value is used to further determine the control and early warning level, and different control means and early warning information are implemented according to different early warning levels, so that different early warning levels are set according to different situations, which is beneficial to quickly respond when a safety event actually occurs and improve the efficiency of emergency rescue, and meanwhile, the input of safety resources can be flexibly adjusted according to the actual situation.

[0169] On the other hand, with reference to Fig. 2 The power station monitoring system network security protection system provided by the application comprises:

[0170] A threshold generation and data monitoring unit generates a signal sending threshold value of each device based on unit operation data and power generation power of the power station by using a signal sending threshold value prediction model corresponding to each device; and monitors the signal sending quantity of each device in a preset time period.

[0171] A judgment unit judges whether each device is in a safe state based on the signal sending threshold value and the signal sending quantity.

[0172] A safety monitoring unit temporarily controls the device in the non-safe state.

[0173] A temporary control and early warning information generation unit temporarily controls the device with a threat in network security detection and generates early warning information.

[0174] The power station monitoring system network security protection system provided by the embodiment of the application determines whether a device is suspected to be cracked, i.e., in a non-safe state, by monitoring the signal sending quantity of each device and the signal sending threshold value generated according to operation data, then further performs network security detection on the suspected cracked device, and finally temporarily controls the device with a threat in network security detection and generates early warning information. The above scheme not only performs preliminary screening from whether the device is in a safe state, and then performs network security detection, thereby avoiding large-scale and inefficient network security detection, but also solves the problem of attacking the entire monitoring network by cracking a device, thereby protecting the network security operation. Meanwhile, early warning signals are generated and the device with a threat in network security detection is controlled, thereby further ensuring the stable operation of the power station monitoring system network.

[0175] An electronic device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer readable instructions. Specifically, the memory can include one or more computer program products that can include various forms of computer readable storage media, such as volatile memory or non-volatile memory. The volatile memory may, for example, include random access memory (RAM), cache, or the like. The non-volatile memory may, for example, include read only memory (ROM), hard disk, flash memory, or the like.

[0176] The processor can be a central processing unit (CPU) or other form of processing unit that has data processing and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer readable instructions stored in the memory, so that the electronic device performs all or part of the steps of the power station monitoring system network security protection method according to the embodiments of the present disclosure.

[0177] As Fig. 3 A structural schematic diagram of an electronic device according to embodiments of the present disclosure is shown. It shows a structural schematic diagram suitable for implementing the electronic device in embodiments of the present disclosure. Fig. 3 The electronic device shown is merely an example and should not impose any limitation on the functions and use range of embodiments of the present disclosure.

[0178] As Fig. 3 As shown, the electronic device can include a processor, such as a central processing unit, a graphics processing unit, or the like, which can perform various appropriate actions and processes according to programs stored in read only memory (ROM) or loaded from storage into random access memory (RAM). In the RAM, various programs and data required for operation of the electronic device are also stored. The processor, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0179] Generally, the following devices can be connected to the I / O interface: input devices including, for example, sensors or visual information acquisition devices; output devices including, for example, display screens; storage devices including, for example, magnetic tapes, hard disks, or the like; and communication devices. The communication devices can allow the electronic device to communicate wirelessly or by wire with other devices, such as edge computing devices, to exchange data. Although Fig. 3 An electronic device with various devices is shown, but it should be understood that it is not required to implement or have all the devices shown. More or fewer devices can be implemented or provided instead.

[0180] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the power station monitoring system network security protection method of the embodiments of the present disclosure are performed.

[0181] Detailed descriptions of the embodiments can refer to the corresponding descriptions of the previous embodiments, which will not be repeated here.

[0182] The computer-readable storage medium according to the embodiments of the present disclosure has non-transitory computer-readable instructions stored thereon. When the non-transitory computer-readable instructions are run by a processor, all or part of the steps of the power station monitoring system network security protection method of the embodiments of the present disclosure described above are performed.

[0183] The computer-readable storage medium described above includes, but is not limited to, optical storage media such as CD-ROM and DVD, magneto-optical storage media such as MO, magnetic storage media such as magnetic tape or a removable hard disk, media with built-in rewritable non-volatile memory such as a memory card, and media with built-in ROM such as a ROM cartridge.

[0184] The above-described embodiments are only preferred technical solutions of the present application, and should not be regarded as limitations of the present application. The embodiments in the present application and the features in the embodiments can be combined with each other as long as they do not conflict. The protection scope of the present application should be based on the technical solutions claimed in the claims, including equivalent replacement solutions of the technical features claimed in the claims. That is, equivalent replacement improvements within this scope are also within the protection scope of the present application.

Claims

1. A power plant monitoring system cyber security protection method, characterized by, The method comprises the following steps: S1, generating a signal sending threshold value of each device based on current unit operation data and power generation power of the power plant using a signal sending threshold value prediction model corresponding to each device respectively; Monitoring the number of signal sending of each device within a preset monitoring time length; Preprocessing the unit operation data and the power generation power; preprocessing includes cleaning data, removing outliers and missing data; S1-1, preprocessing the unit operation data and the power generation power; S1-2, inputting the preprocessed unit operation data and power generation power into the signal sending threshold value prediction model corresponding to each device respectively to obtain the to-be-verified threshold value generated by each signal sending threshold value prediction model respectively; S1-3, verifying whether each to-be-verified threshold value is within a preset range; if yes, taking each to-be-verified threshold value as the signal sending threshold value of the corresponding device respectively; S2, judging whether each device is in a safe state based on the signal sending threshold value and the signal sending number; when the signal sending number is greater than the signal sending threshold value, it is judged that the device is in an unsafe state; S3, performing network security detection on the device in the unsafe state; S4, temporarily managing and controlling the device with a threat to network security and generating an early warning information; temporarily managing and controlling the device with a threat to network security and generating an early warning information comprises: determining the management and control and early warning level of the device with a threat to network security based on the signal sending threshold value and the signal sending number; temporarily managing and controlling the device with a threat to network security and generating an early warning information based on the management and control and early warning level; In S1, using the signal sending threshold value prediction model corresponding to the device comprises the following steps: SA1, collecting historical data of all devices, calculating the correlation coefficient between each device based on the historical data using a correlation analysis tool, and generating a correlation matrix; collecting the historical data of each device, including the running state, sensor data; using the correlation analysis tool, analyzing the correlation coefficient or covariance, and evaluating the correlation between each device based on the historical data; SA2, the correlation coefficient between the i-th device and the j-th device in the correlation matrix is calculated by the following formula: ; Wherein, Xi is the historical data of the i-th device, Xj is the historical data of the j-th device, corr(Xi, Xj) is the correlation coefficient between Xi and Xj; cov(Xi, Xj) is the covariance of Xi and Xj, and var(Xi) and var(Xj) are the variances of Xi and Xj respectively; SA3, using a machine learning algorithm to construct an initial signal sending threshold value prediction model, and introducing the weight of the signal sending threshold value of each device to the i-th device in the model; Based on the correlation matrix and historical data between devices, an initial signal sending threshold value prediction model is constructed using a machine learning algorithm, so that the generated signal sending threshold value can fully reflect the correlation between devices; the machine learning algorithm includes regression analysis, neural network; the initial signal sending threshold value prediction model of the i-th device is as follows: ; Wherein, Thresholdi is the signal sending threshold of the ith device, Wij is the weight of the jth device to the signal sending threshold of the ith device.

2. The power plant monitoring system cyber security protection method of claim 1, wherein: The determination of the management and early warning level of the device threatening the network security detection based on the signal sending threshold and the signal sending quantity comprises: when the signal sending quantity is 101%-130% of the signal sending threshold, the management and early warning level is three; when the signal sending quantity is 131%-150% of the signal sending threshold, the management and early warning level is two; and when the signal sending quantity is greater than 150% of the signal sending threshold, the management and early warning level is one.

3. The power plant monitoring system cyber security protection method of claim 1, wherein: The temporary management of the device threatening the network security detection based on the management and early warning level and the generation of early warning information comprise: when the management and early warning level is three, the device is not managed, and three-level early warning information is generated; when the management and early warning level is two, the signal sending quantity of the threshold management device is determined, and two-level early warning information is generated; and when the management and early warning level is one, the device is prohibited from sending signals, and one-level early warning information is generated.

4. The power plant monitoring system cyber security protection method of claim 1, wherein the step of In S1, the monitoring of the signal sending quantity of each device within a preset monitoring time length comprises: obtaining preset monitoring frequency and monitoring time length information; generating a monitoring time based on the preset monitoring frequency and monitoring time length information; and collecting the signal sending quantity of each device within the monitoring time.

5. The power plant monitoring system cyber security protection method of claim 1, wherein: According to the correlation between each device and the ith device, the influence degree of each related device on the signal sending threshold is determined, and the weight is adjusted; through the weight adjustment mechanism, the device with higher correlation with the ith device has greater influence; The weight Wij of the signal sending threshold is adjusted by the following formula: ; Wherein, Wij is the weight of the jth device to the signal sending threshold of the ith device, corrweight is the correlation strength conversion function of the weight, f(Temperature, Vibration, …) is a complex function of temperature, vibration factors; The data of each device is continuously collected, and the corresponding weight is adjusted in time according to the data change; a real-time monitoring system is established to continuously monitor and collect the state and data change of each device; when the data change exceeds a certain range, the corresponding weight is adjusted in time according to the new data; the application effect of the signal sending threshold is monitored, and the signal sending threshold prediction model is optimized and adjusted according to the application effect; the application effect is characterized by various pre-established evaluation indexes, including the false positive rate, and the accuracy, stability and reliability of the method are further improved through optimization and adjustment.

6. The power plant monitoring system cyber security protection method of claim 5, wherein: The process of optimizing and adjusting the signal sending threshold prediction model according to the false positive rate comprises: First, define the objective function, the false positive rate is obtained by calculating the ratio of the number of false positives and false negatives to the total number of samples; define the objective function as the false positive rate, denoted as Error_Rate, and its calculation formula is: ; Wherein, FalsePositive is the number of false positives, FalseNegative is the number of false negatives, and TotalSamples is the total number of samples; Second step, determine the optimization algorithm, select gradient descent, genetic algorithm, particle swarm optimization to minimize the false positive rate; Third step, establish an optimization model, associate the target function ErrorRate with the parameters or variables in the signal transmission threshold prediction model, and establish an optimization model, that is, take the parameters or variables of the signal transmission threshold prediction model as the independent variables of the optimization problem, and take the false positive rate as the objective function; Fourth step, set the initial parameters, provide the initial parameter or variable values for the optimization model according to historical data or experience, and use them to start the iteration process of the optimization model; Fifth step, execute the optimization algorithm, optimize the target function using the optimization model to reduce the false positive rate; Sixth step, convergence judgment, set a convergence condition, that is, stop optimization when the change of the target function value is less than a certain threshold or the number of iterations reaches a certain value, monitor the convergence of the optimization model, and judge whether the stopping optimization condition is met; Seventh step, apply the optimization results, apply the optimized parameters and / or variables to the signal transmission threshold prediction model, and update the signal transmission threshold prediction model.

7. A security system for implementing the method of any one of claims 1 to 6, characterized by: The threshold generation unit is connected with a data monitoring unit, a judgment unit, a security monitoring unit, and a temporary control and early warning information generation unit in sequence. The threshold generation unit generates signal transmission thresholds for each device based on current unit operation data and power generation power of the power plant using signal transmission threshold prediction models corresponding to each device. The data monitoring unit is used to monitor the number of signal transmissions of each device in a preset time period. The judgment unit determines whether each device is in a safe state based on the signal transmission thresholds and the number of signal transmissions. The security monitoring unit performs network security detection on devices in a non-safe state. The temporary control and early warning information generation unit performs temporary control on devices that pose a threat to network security and generates early warning information.

8. An electronic device for implementing the method of any one of claims 1 to 6, characterized by: The computer readable storage medium stores computer instructions for causing a computer to execute the power plant monitoring system network security protection method.

9. A computer readable storage medium for implementing the method of any one of claims 1 to 6, characterized by: The computer readable storage medium stores computer instructions for causing a computer to execute the power plant monitoring system network security protection method.

Citation Information

Patent Citations

  • Message processing method and device

    CN107547559A

  • Key information infrastructure security protection cloud service system

    CN111885176A