Electricity consumption collection safety monitoring method based on intelligent remote control
By identifying the power consumption structure topology and event correlation tree and building a remote monitoring platform, the problem of real-time identification and response to safety hazards in the power system power collection and safety management is solved, and dynamic monitoring and resource optimization of the power consumption network are realized.
Patent Information
- Application Number
- CN202411662601.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-20
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-11-20
AI Technical Summary
In existing technologies, the safety management of power system electricity consumption collection has problems such as difficulty in real-time identification and response to safety hazards, decision-making bias, slow response speed of traditional solutions, difficulty in coping with power grid changes, and unreasonable resource allocation, resulting in important areas not being effectively monitored and resources in other areas being wasted.
By identifying the local electricity consumption structure of the electricity consumption jurisdiction area, establishing the electricity consumption structure topology map, combining situation identification and intent analysis in the attack security and behavioral security dimensions, mining the event correlation tree, building a remote monitoring platform, and conducting dynamic monitoring and remote control management, real-time security risk identification and response to the electricity network can be achieved.
It achieves real-time identification and response to potential safety hazards in the power network, avoids decision-making bias, and improves the safety of the power system and resource utilization efficiency.
Smart Images

Figure CN119171638B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power system safety monitoring, and in particular to a method for safety monitoring of electricity consumption collection based on intelligent remote control. Background Art
[0002] In the context of power consumption data security management in modern power systems, the increasing number of power-consuming devices and the increasing complexity of distributed power grids have led to increasingly prominent security issues in power networks, exacerbating resource constraints. Efficient monitoring and dynamic management of distributed power networks to ensure the security of equipment in each area has become a critical component of power system management. Traditional power consumption security management approaches are relatively simplistic and static, often relying on fixed monitoring equipment or simple rule-based settings. These approaches lack in-depth analysis and real-time response to large-scale power consumption data and potential threats, making it difficult to comprehensively and accurately assess security risks in each area. Irrational approaches to security monitoring and resource allocation can lead to ineffective monitoring of certain critical areas and waste of resources in other areas. Traditional solutions suffer from slow response times and inaccurate decision-making to address sudden power consumption anomalies and potential attacks, making them unable to adapt to the ever-changing operational conditions of the power grid.
[0003] At present, relevant technologies have technical problems such as difficulty in real-time identification and response of safety hazards in electricity collection systems, and decision-making bias. Summary of the Invention
[0004] This application provides a power consumption collection and security monitoring method based on intelligent remote control. It uses the method of identifying the distributed local power consumption structure within the power consumption jurisdiction area and establishing a power consumption structure topology map with node structure type identification. Based on the two dimensions of attack security and behavioral security, it assists in situation identification and intent analysis, and mines the event association tree. Combining the topology map and the event association tree, a remote monitoring platform is constructed, and dynamic monitoring and updating are performed through the active and passive conversion units. The platform perceives and collects security assessments of the power consumption network, generates a safety monitoring sheet, and provides power consumption guidance for the front-end equipment based on this, while realizing remote control management. It realizes the technical effect of real-time identification and response to potential safety hazards in the power consumption network through intelligent remote control and dynamic adjustment, and effectively avoids decision-making deviations.
[0005] This application provides a method for monitoring power consumption data security based on intelligent remote control, including:
[0006] For the electricity consumption jurisdiction area, the distributed local electricity consumption structure is identified and the electricity consumption structure topology is established, wherein the topological nodes of the electricity consumption structure topology are identified with the structure type; with attack security and behavioral security as the security dimensions, situation identification and intent analysis are assisted, and the event association tree is mined; combining the electricity consumption structure topology with the event association tree, a remote monitoring platform is constructed, wherein the remote monitoring platform performs monitoring and updating based on the active-passive conversion unit; assisting the remote monitoring platform to perform electricity network perception and electricity collection security assessment, and determine the safety monitoring list; based on the safety monitoring list, front-end electricity consumption guidance is carried out to assist the remote monitoring platform in remote control and management.
[0007] The electricity consumption data collection and security monitoring method based on intelligent remote control proposed in this application first identifies the distributed local electricity consumption structure within the electricity consumption jurisdiction area and establishes an electricity consumption structure topology map with node structure type identification. Based on the two dimensions of attack security and behavioral security, it assists in situation identification and intent analysis, and mines the event association tree. Combining the topology map and the event association tree, a remote monitoring platform is constructed, and dynamic monitoring and updating are performed through the active-passive conversion unit. The platform perceives and collects security assessments of the electricity consumption network, generates a safety monitoring sheet, and provides electricity consumption guidance to the front-end equipment based on this, while realizing remote control and management. Through intelligent remote control and dynamic adjustment, it achieves the technical effect of real-time identification and response to potential safety hazards in the electricity consumption network and effectively avoids decision-making bias. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments of the present invention are briefly introduced below. Flowcharts are used in this application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed in precise order. Instead, various steps may be processed in reverse order or simultaneously as needed. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.
[0009] Figure 1 A flow chart of a method for safely monitoring electricity consumption collection based on intelligent remote control provided in an embodiment of the present application.
[0010] Figure 2 A schematic diagram of the process flow of mining event association trees for the electricity consumption collection and safety monitoring method based on intelligent remote control provided in an embodiment of the present application. DETAILED DESCRIPTION
[0011] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below.
[0012] In order to make the purpose, technical solutions and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limiting this application. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0013] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict, and the terms “first\second” involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. The terms “including” and “having” and any variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products, or devices. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are for the purpose of describing the embodiments of this application only.
[0014] The present application provides a method for monitoring power consumption safety based on intelligent remote control. Figure 1 As shown, the method includes:
[0015] Step S100 identifies the distributed local power structure for the power consumption jurisdiction area and establishes a power structure topology, wherein the topological nodes of the power structure topology are identified with structure types. Specifically, the power consumption jurisdiction area is first clarified, and the distributed local power structure is comprehensively and accurately identified through field surveys and equipment inventories, data monitoring and analysis, and archival material review and integration. Then, based on the identified local power structure, a power structure topology is constructed and represented graphically, with each node representing a power device or a key power component. The topological hierarchy is determined, and the structure type of each topological node is identified, such as industrial power equipment, commercial power equipment, residential power equipment, etc., to facilitate subsequent targeted safety monitoring and management.
[0016] Step S200 uses attack security and behavioral security as security dimensions to assist with situation identification and intent analysis, mining an event association tree. Specifically, the two security dimensions of attack security and behavioral security are first identified. Regarding attack security, the focus is on external malicious attacks such as hacker attacks and malware intrusions, and possible attack methods are classified and analyzed. Regarding behavioral security, the focus is on internal user electricity usage behavior, and a user behavior monitoring mechanism is established to identify abnormal electricity usage. Situation identification is then performed, utilizing sensors and monitoring equipment to monitor the power system's operating status in real time and establish a data acquisition and transmission system. The monitoring data is analyzed and algorithmic models are used for in-depth mining to understand the overall situation of the power environment and identify potential security risks. Intent analysis is performed. To identify the deceptive nature of malicious attacks, the attacker's intent is inferred by analyzing the characteristics, patterns, and targets of the attack behavior, and a malicious attack feature library is established. To identify the misleading nature of abnormal and fault data, the causes and consequences are analyzed in depth to avoid decision-making bias and establish an abnormal data processing mechanism. Retrieve electricity consumption safety records, determine the record information group, divide the intuitive and non-intuitive parts, determine their event correlation characteristics respectively, combine the characteristics of the intuitive and non-intuitive parts and integrate them to determine the event correlation tree, and finally visualize the event correlation tree to better understand and analyze the safety status of the power system.
[0017] In one possible implementation, Figure 2As shown, using attack security and behavioral security as security dimensions, assisting with situation identification and intent analysis, and mining an event association tree, step S200 further includes step S210, which retrieves and retrieves electricity usage security records. By analyzing electricity usage characteristics and data flows, groups of record information are identified, where each group of record information corresponds to a recorded event. Specifically, the time range, electricity usage jurisdiction, and specific equipment or system scope of the electricity usage security records to be retrieved are specified. For example, the electricity usage security records of all enterprises within a certain industrial park within the past year can be retrieved. Relevant electricity usage security records can be retrieved through database queries, file system searches, or specialized security management system interfaces. These records may include records of equipment failures, network attacks, and abnormal electricity usage behavior. For example, an abnormal electricity usage record in a specific area within a specific time period can be retrieved from the power company's security database. The retrieved security records are parsed to extract electricity usage characteristics and data flow information. Electricity usage characteristics may include changes in parameters such as current, voltage, and power, while data flow information may include network traffic and data transmission patterns. For example, the current change curve in a device failure record and the network data flow at the time of the failure can be analyzed. Based on the analyzed power usage characteristics and data flow information, relevant records are grouped to determine record information groups. Each record information group corresponds to a recorded event, such as a device failure or a network attack. For example, if multiple records show an abnormal increase in current in a certain area at the same time, and network traffic also shows abnormal changes, these records can be combined into a record information group, corresponding to a possible power system failure event.
[0018] Step S220 traverses the recorded information groups and classifies each group into intuitive and non-intuitive sections. Specifically, starting with the first recorded information group, each recorded information group is processed sequentially. For each recorded information group, the information that is relatively easy to understand and directly observe is classified as the intuitive section. The intuitive section typically includes obvious abnormalities in power usage, such as a sudden increase in current or equipment shutdown. For example, if a recorded information group shows that the current of a device suddenly rises from the normal range to a very high value and the device issues a fault alarm, this current increase and fault alarm information can be classified as the intuitive section. Information in the recorded information group that requires further analysis and understanding is classified as the non-intuitive section. The non-intuitive section may include hidden factors, potential causes, or subtle connections. For example, in a recorded information group, although the current changes abnormally, there are no obvious signs of equipment failure. In this case, there may be hidden network problems or malicious attacks, and this information can be classified as the non-intuitive section. The non-intuitive section is marked with a bias guidance mark to focus on these possible directions in subsequent analysis. For example, non-intuitive parts can be marked with biased guidance marks such as "may be caused by a network attack" or "need further inspection of device software".
[0019] Step S230, determining the event association features of the intuitive part. Specifically, the information of the intuitive part is deeply analyzed to determine the association features between these intuitive phenomena. For example, if the currents of multiple devices increase at the same time and are all located in the same area, then it can be inferred that there may be a problem with the power supply in the area, which is an event association feature. To extract the event association features of the intuitive part, common features or patterns can be found by comparing the intuitive phenomena in different record information groups. For example, if multiple record information groups all show that devices frequently fail in a specific time period, and these devices are of the same type, then the event association feature of "specific types of devices are prone to failure in a specific time period" can be extracted.
[0020] Step S240 traverses the non-intuitive portion, performs behavioral identification and intentional understanding, and determines the event correlation features of the non-intuitive portion, wherein the non-intuitive portion is marked with a bias guidance mark. Specifically, the divided non-intuitive portion is traversed and analyzed one by one. By analyzing the information in the non-intuitive portion, possible behavioral patterns are identified. For example, if the non-intuitive portion shows abnormal changes in network traffic but no obvious signs of an attack, by analyzing the source, destination, and change pattern of the network traffic, it can be determined that the increase in traffic may be caused by an automatic software update on a certain device, or abnormal network behavior by an internal user. Based on the behavioral identification, the intention behind these behaviors is further understood. For example, if it is identified that an automatic software update on a certain device has caused an increase in network traffic, it can be understood as normal behavior of the device manufacturer to improve device performance. If it is abnormal network behavior of an internal user, it is necessary to further understand whether the user's intention is an unintentional operational error or an intentional violation. Based on the results of behavioral identification and intentional understanding, the event correlation features of the non-intuitive portion are determined. For example, if a non-intuitive component is determined to be caused by an internal user's illegal electricity usage, we can extract the event correlation feature "This user's illegal electricity usage may cause power system security issues." Non-intuitive components are tagged with bias guidance, allowing for more targeted analysis based on the direction of the tag.
[0021] Step S250: The event correlation features of the intuitive portion and the non-intuitive portion are fused and integrated to determine the event correlation tree, wherein the event correlation tree corresponds to the recorded events. Specifically, the event correlation features of the intuitive portion and the non-intuitive portion are compared to identify similarities and differences. For example, the intuitive portion may indicate that a device failure is caused by excessive current, while the non-intuitive portion may indicate that the excessive current is due to abnormal device operation caused by a cyber attack. These two features are related to each other. Based on the comparison results, the event correlation features of the intuitive portion and the non-intuitive portion are fused. Fusion can be performed using methods such as weighted averaging and logical merging. For example, if the feature weight of the intuitive portion is 0.6 and the feature weight of the non-intuitive portion is 0.4, then the features of the two portions can be weighted averaged based on these two weights to obtain a fused event correlation feature. The fused event correlation features are then integrated to form a complete event correlation tree. Each node in the event correlation tree represents an event correlation feature, and the connections between nodes represent the correlation relationship between events. For example, if the fused features indicate a correlation between a device failure, a cyberattack, and excessive current, corresponding nodes can be created in the event correlation tree, and connections can be used to represent the relationships between them. The correspondence between each node in the event correlation tree and a recorded event can be determined. The corresponding recorded event can be found by comparing the event correlation features with the recorded information group. For example, if a node in the event correlation tree indicates "device failure is related to a cyberattack," the recorded information group can be used to identify recorded events that indicate device failure and are potentially related to a cyberattack, and a corresponding relationship can be established between them. The established correspondences can be verified to ensure that the event correlation tree accurately reflects the logical relationships between recorded events. This can be achieved by reanalyzing the recorded information group, conducting real-world case studies, or discussing with experts. For example, if a recorded event is found to have no corresponding node in the event correlation tree, the event correlation feature extraction and fusion process should be re-examined to ensure that all recorded events are correctly located in the event correlation tree. Event correlation trees can be mined from electricity safety records, providing powerful support for electricity safety monitoring and management.
[0022] In one possible implementation, the event correlation features of the intuitive and non-intuitive parts are integrated and combined to determine the event correlation tree, wherein the event correlation tree corresponds to the recorded events. Step S250 further includes step S251 of traversing the event correlation features and determining precursor nodes based on the risk level, wherein the time span of the precursor nodes is positively correlated with the risk level. Specifically, the traversal begins with the identified event correlation features. These event correlation features may be obtained through steps such as analyzing electricity consumption safety records, processing the intuitive and non-intuitive parts, and fusion. For example, assume that several event correlation features have been identified, such as "equipment failure is related to current anomalies" and "cyber attacks may cause data anomalies." Each event correlation feature is examined individually to understand its specific content and meaning. For each feature, the associated electricity safety event, related equipment or systems, and possible influencing factors are analyzed. For example, for the feature "equipment failure is related to current anomalies," further analysis is performed to identify possible causes of the current anomaly, such as equipment aging and overloaded operation, as well as potential consequences of the equipment failure, such as power outages and data loss. A risk assessment is performed on each event correlation feature to determine its risk level. Risk assessment can consider multiple factors, such as the likelihood of an event occurring, the extent of the resulting losses, and the impact on power system stability. For example, if an event correlation feature indicates a high probability of occurrence and results in severe equipment damage and widespread power outages, its risk level is relatively high. Precursor nodes are determined based on the risk level. Precursor nodes are signs or characteristics that may appear before an event occurs. By monitoring these precursor nodes, early warning of potential power safety risks can be provided. For example, if an event correlation feature has a high risk level, specific current fluctuations, abnormal network traffic, and other conditions may occur before the event associated with the feature occurs. These conditions can serve as precursor nodes. The time span of precursor nodes is positively correlated with the risk level. That is, the higher the risk level of an event, the longer the time span of its precursor nodes may appear. For example, for a high-risk power system fault event, precursor nodes such as minor current fluctuations and increased equipment temperature may appear days or even weeks before the fault occurs. For a low-risk event, however, precursor nodes may only appear hours or minutes before the event.
[0023] Step S252 determines a precursor characteristic value based on the precursor node, labels the event association feature, and generates the event association tree. Specifically, the determined precursor node is analyzed in depth to understand its specific characteristics and manifestations. For example, if a precursor node is an abnormal change in current, then the amplitude, frequency, duration, and other characteristics of the current change need to be analyzed. Based on the analysis results of the precursor node, a precursor characteristic value based on the precursor node is determined. The precursor characteristic value can be a specific numerical value, a range, or a descriptive indicator. For example, if the characteristic of the precursor node of an abnormal change in current is that the current amplitude continues to rise above a certain threshold within a certain period of time, then this threshold can be used as the precursor characteristic value. The determined precursor characteristic value can be used to label the event association feature so that potential power safety risks can be quickly identified and judged in actual monitoring. At the same time, the precursor characteristic value can also serve as a trigger condition for the early warning system. When the monitored power consumption data meets the precursor characteristic value, the system can promptly issue an alarm to remind relevant personnel to take measures. The event association feature is labeled using the determined precursor characteristic value. Tagging involves adding a specific label or annotation to an event correlation feature, indicating that the feature is associated with a specific precursor node and precursor feature value. For example, for the event correlation feature "equipment failure is related to current anomaly," a tag such as "precursor feature of a possible sustained current rise exceeding a threshold" can be added. The tagged event correlation features are integrated to generate an event correlation tree. The event correlation tree is a graphical representation in which each node represents an event correlation feature, and the connections between nodes represent the correlations between events. The event correlation tree clearly illustrates the logical relationships between different electricity safety events and the potential risk propagation paths. For example, if a device failure represented by one event correlation feature could cause a network outage represented by another event correlation feature, a connection will be created between the two features in the event correlation tree. As new electricity safety records are accumulated and analyzed, the event correlation tree can be continuously updated and optimized. For example, if a new event correlation feature or precursor node is discovered, it can be added to the event correlation tree; if the risk level of an event correlation feature changes, its position and mark in the event correlation tree can be adjusted accordingly, which can more accurately identify and warn of electricity safety risks and provide strong guarantees for the stable operation of the power system.
[0024] In one possible implementation, the precursor feature value based on the precursor node is determined, the event association feature is marked, and the event association tree is generated. Step S252 further includes step S2521, which determines the attack chain and locates the precursor node for the attack security dimension, integrates the malicious code penetration feature of the precursor node, and compensates for the event association feature. Specifically, in the power consumption collection safety monitoring, for the attack security dimension, first clarify its importance, and determine various attack methods and scopes including hacker attacks. Then, by collecting attack-related information such as network traffic and device logs, determine the source, target and path of the attack, and build an attack chain model, including multiple stages such as reconnaissance and weaponization. Then, analyze the characteristics of each stage of the attack chain to determine possible precursor nodes, such as network scanning in the reconnaissance stage, which can be used as a precursor. Then analyze the possible malicious code, understand its penetration characteristics and integrate it into the precursor node to improve the accuracy of the early warning. Finally, we review the event correlation features and compare and analyze the precursor nodes that integrate the malicious code penetration features to make them more complete and accurate, so as to effectively monitor and prevent the risks of attack security dimensions and improve the accuracy and reliability of electricity consumption collection safety monitoring.
[0025] Step S300 combines the power consumption structure topology and the event correlation tree to construct a remote monitoring platform, where the remote monitoring platform performs monitoring updates based on the active-passive conversion unit. Specifically, during the construction of the remote monitoring platform, the power consumption structure topology and the event correlation tree are first combined. The power consumption structure topology displays physical information, such as the layout of power equipment and lines within the power consumption area, while the event correlation tree presents the logical relationships and development context of different security events. After combining these two, the platform performs monitoring updates using the active-passive conversion unit. The active-passive conversion unit plays a key role in switching monitoring modes. The passive monitoring mode determines passive sensing information through sensor networking, utilizing various sensors and network monitoring devices installed in the power system to collect operating parameters and network traffic in real time. The active monitoring mode transmits passive sensing information back, performs sensing situation analysis and event correlation feature mining to determine the passive sensing logic. This information is then decomposed to the minimum logical granularity and integrated with logical conversion to determine the monitoring logic. Ultimately, the remote monitoring platform is updated based on this information, enabling comprehensive real-time monitoring and effective management of power consumption security.
[0026] In one possible implementation, a remote monitoring platform is constructed by combining the power consumption structure topology with the event correlation tree. The remote monitoring platform performs monitoring and updates based on the active-passive conversion unit. Step S300 further includes step S310, where passive sensing information is determined through sensor networking. Specifically, various sensors, such as current sensors, voltage sensors, and temperature sensors, as well as networked devices, are widely deployed in the power system within the power consumption jurisdiction to ensure real-time collection of information such as the operating status and environmental parameters of power equipment. Simultaneously, a stable network connection is established to ensure timely transmission of sensor data. Sensors and networked devices continuously monitor the power system, collecting various data, including current, voltage, power, device temperature, and network traffic. This data constitutes passive sensing information, reflecting the actual operating status of the power system at the current moment. For example, current sensors monitor the current level of each device in real time, while temperature sensors monitor the operating temperature of the device. The collected passive sensing information is collated and preliminarily analyzed to remove noise and abnormal data to ensure data accuracy and reliability. For example, a data filtering algorithm is used to remove noise interference from the current sensor data, ensuring that the data more accurately reflects the actual current situation.
[0027] In step S320, the passive sensing information is transmitted back to the active-passive conversion unit. Through sensing situation analysis and event correlation feature mining, the passive sensing logic is determined. Specifically, the organized passive sensing information is transmitted back to the active-passive conversion unit via a network connection. This unit is a core component of the remote monitoring platform, responsible for processing and analyzing sensing information. The active-passive conversion unit performs sensing situation analysis on the transmitted passive sensing information. This includes analyzing the changing trends of parameters such as current and voltage to determine whether the power system is stable; analyzing changes in network traffic to detect abnormal network activity; and analyzing parameters such as device temperature to determine whether the device is experiencing abnormal conditions such as overheating. For example, a sudden and sustained increase in current may indicate an increase in load or a fault in the power system. Simultaneously, the active-passive conversion unit performs event correlation feature mining. Combining this with the previously constructed event correlation tree, the active-passive conversion unit analyzes the correlation between the current passive sensing information and known security events. For example, if the current current change is associated with a device failure event in the event correlation tree, it may indicate an impending similar failure. Through sensing situation analysis and event correlation feature mining, the passive sensing logic is determined. This logic describes the power system status and possible development trends reflected by the current passive sensing information, as well as its potential association with security events. For example, if the analysis results indicate an abnormal increase in current and similar characteristics to a historical fault event, the passive sensing logic may indicate a risk of equipment failure.
[0028] Step S330 decomposes the passive sensing logic at the smallest logical granularity and performs logical transformation and fusion to determine the monitoring logic. Specifically, the determined passive sensing logic is decomposed at the smallest logical granularity. The passive sensing logic is decomposed into the most basic logical units for more in-depth analysis and transformation. For example, the passive sensing logic of "there is a risk of equipment failure" can be decomposed into more specific logical units such as "abnormal increase in current," "temperature increase," and "abnormal network traffic." The decomposed logical units are then logically transformed. Based on different monitoring requirements and safety standards, these logical units are converted into a more suitable form for monitoring. For example, "abnormal increase in current" can be converted into "current rate of change exceeds a certain threshold" to facilitate monitoring and judgment. The transformed logical units are then merged to form a new monitoring logic. Through logical fusion, multiple factors can be comprehensively considered to improve monitoring accuracy and reliability. For example, logical units such as "current rate of change exceeds a certain threshold," "temperature increase exceeds a certain range," and "abnormal network traffic" can be merged into monitoring logic such as "there may be a device failure, requiring enhanced monitoring." After the smallest logical granularity decomposition, logical transformation, and fusion, the final monitoring logic is determined. This monitoring logic will serve as the basis for updating the remote monitoring platform, guiding the platform to conduct more accurate monitoring of the power system.
[0029] Step S340 updates the remote monitoring platform based on the monitoring logic. Specifically, the remote monitoring platform adjusts its monitoring parameters according to the determined monitoring logic. For example, if the monitoring logic indicates a need for enhanced current monitoring of a particular device, the platform adjusts the sampling frequency and alarm threshold of the current sensor corresponding to that device. Simultaneously, the platform updates its monitoring strategy. Based on the requirements of the monitoring logic, it determines monitoring priorities and response measures for different scenarios. For example, if the monitoring logic indicates a risk of cyberattack, the platform activates a network security monitoring strategy to strengthen the analysis and filtering of network traffic. The remote monitoring platform also updates its data display to better reflect the information focused by the monitoring logic. For example, the operating status and parameters of key monitored devices are more prominently displayed on the platform interface, making it easier for monitoring personnel to identify issues promptly. The updated remote monitoring platform continuously monitors the power system according to the new monitoring logic and continuously collects new passive sensing information. Based on this new information, the platform can further adjust and optimize the monitoring logic, forming a continuous and optimized monitoring process. This completes a complete solution process from sensor network perception to determination of the monitoring logic and then to updating the remote monitoring platform, ensuring that the remote monitoring platform can monitor the safety of power consumption and data collection in real time and accurately.
[0030] In one possible implementation, a remote monitoring platform is constructed by combining the power consumption structure topology with the event association tree. The remote monitoring platform performs monitoring updates based on the active-passive conversion unit, and step S300 further includes step S350, which constructs a passive branch using the underlying logic of situational awareness, situational recognition, risk management, and risk presentation. Specifically, first, comprehensive situational awareness of the power consumption system is achieved through various monitoring methods, including sensors installed on power equipment and lines for real-time collection of physical parameters such as current, voltage, and temperature; network monitoring equipment for monitoring network traffic and communication status; and a security logging system for recording the operating status of equipment and security events. For example, sensors can monitor a sudden increase in the current of a device in real time, a key source of situational awareness. This information is integrated and analyzed to determine the overall state of the power system. For example, if multiple sensors simultaneously detect abnormal current flow, this indicates a potential fault or safety risk in the system. Building on situational awareness, situational awareness is conducted, in-depth analysis of the collected information is conducted to understand the underlying causes and potential impacts of the current power system. For example, if an abnormal increase in current flow is detected, analysis may indicate that a device is overloaded or has a potential short circuit. Combining historical data and expert knowledge, the current situation can be assessed and determined. For example, by comparing the current value with historical data from the same period, whether it is outside the normal range can be determined. Alternatively, based on expert experience, a specific current change pattern may indicate a potential fault. Once a potential risk is identified, risk management is required, including the development of appropriate emergency measures and plans to address potential safety incidents. For example, if a device is identified as overloaded, measures such as reducing its load or adjusting power distribution can be taken. Risk management processes can then be initiated, and relevant departments and personnel can be coordinated to respond to the emergency. For example, equipment maintenance personnel can be notified to inspect and repair potentially faulty equipment; or power dispatch strategies can be adjusted to ensure stable system operation. Identified risks can be presented to relevant personnel in an intuitive manner through visual monitoring platforms and alarm systems. For example, the location and changing trends of equipment with abnormal current can be displayed in the form of charts on a remote monitoring platform. Alternatively, an audio-visual alarm system can be used to alert staff to potential security risks, providing detailed risk information and suggestions to help relevant personnel make decisions. For example, risk severity assessments, possible impact ranges, and recommended disposal measures can be provided. Analysis and logical mining can be performed on passive monitoring information, such as those not covered by the model or that have already caused security incidents. For example, if a security incident is caused by a new attack method that is not covered by the existing monitoring model, then in-depth analysis of the incident is required to identify its characteristics and patterns, and to convert the passive monitoring information into logical features that can be proactively monitored in advance.By analyzing passive monitoring information, we can extract features and logical relationships that can be used for early warning. For example, if a security incident is found to consistently occur at specific times or on specific devices, these features can be used as the logical basis for active monitoring, enabling early detection and early warning of similar incidents. Using these logical features, we can update the remote monitoring module and integrate these converted logical features into the remote monitoring platform, enabling it to more effectively monitor and prevent similar security incidents. For example, we can add a focused monitoring function for specific times and devices to the remote monitoring platform.
[0031] Step S360: Obtain an active-passive conversion logic library and construct conversion branches based on logical internal competition. These conversion branches are used to explore active-passive logical relationships. Specifically, various active-passive conversion logic rules and cases are collected and organized to establish an active-passive conversion logic library, including different types of security events, corresponding passive monitoring information, and the converted active monitoring logic. For example, for network attack events, record passive monitoring information such as network traffic characteristics and device status at the time of the attack, as well as the corresponding active monitoring logic, such as strengthening network traffic monitoring, setting specific firewall rules, etc., and continuously update and improve the active and passive conversion logic library. As new security events occur and are handled, new conversion logic is added to the library. For example, if a new malware attack occurs, after analysis and processing, its passive monitoring information and the converted active monitoring logic are added to the logic library. The logic internal competition mode is adopted, that is, different logic rules are allowed to compete and optimize internally. For the same security event, there may be multiple different active and passive conversion logics. By comparing their effects and applicability, the optimal logic is selected for application. For example, for a certain equipment failure event, there are two different active monitoring logics, one is based on monitoring of equipment temperature changes, and the other is based on monitoring of current fluctuations. Through practical application and comparison, we determine which logic is more accurate and effective, and build a conversion branch. The branch is specifically responsible for exploring the active and passive logical relationship. By analyzing and processing the active and passive conversion logic library, we find out the relationship between passive monitoring information and active monitoring logic in different types of security incidents. For example, for network attack incidents, we determine which network traffic characteristics can be used as passive monitoring information and what the corresponding active monitoring logic should be.
[0032] Step S370, coordinate the passive branch and the conversion branch to determine the active-passive conversion unit. Specifically, the passive branch and the conversion branch work together to jointly determine the active-passive conversion unit. The passive branch provides actual passive monitoring information and conversion requirements, while the conversion branch provides the logic and method of active-passive conversion. For example, when the passive branch detects a new security event, it passes its information to the conversion branch. The conversion branch finds the corresponding conversion logic based on the active-passive conversion logic library and feeds it back to the passive branch. The passive branch updates the remote monitoring module based on the converted active monitoring logic. Through the collaborative work of the passive branch and the conversion branch, the active-passive conversion unit is finally determined. The unit includes the logic, method and tool of active-passive conversion, which can realize the conversion from passive monitoring to active monitoring. The active-passive conversion unit can be integrated into the remote monitoring platform. As an important component of the platform, it can automatically perform active-passive conversion according to actual security events and monitoring requirements, improve the efficiency and accuracy of monitoring, build an effective active-passive conversion unit, realize the conversion from passive monitoring to active monitoring, and improve the ability and level of power collection safety monitoring.
[0033] Step S400, assisting the remote monitoring platform to conduct power network perception and power collection safety assessment, and determine the safety monitoring list. Specifically, the auxiliary remote monitoring platform needs to establish a stable connection with the platform and share the power network perception device data, while providing the platform with advanced analysis tools and algorithms. Then, power network perception is carried out, and perception devices are deployed in the power jurisdiction area to ensure their accuracy and reliability. The perception devices collect power data in real time and transmit it to the remote monitoring platform, and the collected data is pre-processed at the same time. Then, a power collection safety assessment is carried out to determine an evaluation index system including equipment, network, data security, etc., determine the evaluation criteria and weights for each indicator, adopt appropriate evaluation methods and formulate processes to ensure that the evaluation is comprehensive and accurate. Integrate the evaluation results to form a safety monitoring list, analyze and summarize to find out the safety issues and risks, and generate a detailed safety monitoring list based on the integrated results, in the form of a report or displayed on the remote monitoring platform to provide support for power collection safety management.
[0034] In one possible implementation, the remote monitoring platform is assisted in performing a safety assessment of power consumption network perception and power consumption collection, and determining a safety monitoring list. Step S400 further includes step S410, which assists the remote monitoring platform in controlling the front-end sensor equipment, determining the monitoring data stream, and performing acquisition timestamp marking. Specifically, an effective connection and communication is established with the remote monitoring platform to ensure that the platform can receive instructions and feedback information to it. For example, through a network connection or a dedicated data transmission channel, real-time interaction with the remote monitoring platform is achieved, providing the necessary support and assistance to the remote monitoring platform, including data processing, analysis, and storage. For example, after receiving control instructions sent by the remote monitoring platform, the front-end sensor equipment is operated accordingly, and the collected data is initially processed and then transmitted back to the platform. According to the instructions of the remote monitoring platform, the front-end sensor equipment is controlled, including starting or stopping the sensor equipment, adjusting the device parameter settings, selecting a specific monitoring mode, etc. For example, when the remote monitoring platform detects abnormal power consumption in a certain area, it can send instructions to start specific sensor equipment in that area to obtain more detailed monitoring data. Ensure the normal operation and stability of the front-end sensor equipment, perform regular maintenance and inspection on the sensor equipment, and deal with equipment failures and abnormal situations in a timely manner. For example, regularly calibrate and debug the sensor equipment to ensure the accuracy and reliability of its measurement data. The front-end sensor equipment starts to collect power consumption data according to the control instructions to form a monitoring data stream. The data can include various parameters such as current, voltage, power, and temperature. For example, the current sensor collects the current value in the circuit in real time, and the voltage sensor collects the voltage value. The data is combined into a monitoring data stream. The monitoring data stream is preliminarily screened and sorted to remove noise and abnormal data to ensure the quality of the data. For example, using data According to the filtering algorithm, noise interference in the current sensor data is removed to make the data more accurately reflect the actual power consumption. While determining the monitoring data stream, a collection timestamp is added to each data point. The timestamp can accurately record the collection time of the data and provide a time reference for subsequent data analysis and processing. For example, when the current sensor collects a current value, the current time is recorded as the timestamp of the data point to ensure the accuracy and consistency of the timestamp. A unified time standard and clock source are used to avoid the impact of time errors on data analysis. For example, all sensing devices use the same high-precision clock source to ensure the accuracy of the timestamp.
[0035] Step S420, the monitoring data stream is transmitted back, and a decision is made to determine the security indicator matrix. Specifically, the monitoring data stream with a timestamp is transmitted back to the remote monitoring platform through the network or other data transmission methods to ensure the stability and reliability of data transmission and avoid data loss or transmission errors. For example, a reliable network communication protocol and data encryption technology are used to ensure that the monitoring data stream can be safely and quickly transmitted to the remote monitoring platform. During the transmission process, the monitoring data stream can be compressed and encrypted to improve data transmission efficiency and security. For example, a data compression algorithm is used to reduce the amount of data and reduce the transmission bandwidth requirement; an encryption algorithm is used to encrypt the data to prevent the data from being stolen or tampered with. After the remote monitoring platform receives the monitoring data stream, it decides to determine the security indicator matrix based on the pre-set security indicator system. The full indicator system includes safety indicators in multiple dimensions, such as voltage stability, current anomalies, power factor, equipment failure rate, etc. The monitoring data stream is analyzed and processed to calculate the value of each safety indicator. For example, the value of the voltage stability indicator is calculated by statistically analyzing the voltage data over a period of time; the value of the current anomaly indicator is determined by performing anomaly detection on the current data. Based on the calculated safety indicator values, a safety indicator matrix is constructed. Each element in the matrix represents the value of a safety indicator at a specific time point or time period. For example, the safety indicator matrix can be a two-dimensional matrix, in which rows represent different safety indicators and columns represent different time points. The elements in the matrix are the values of the corresponding safety indicators at that time point.
[0036] Step S430, evaluate the safety indicator matrix and determine the safety monitoring list. Specifically, the constructed safety indicator matrix is evaluated, including a separate evaluation of each safety indicator and a comprehensive evaluation of the entire matrix. For example, the voltage stability indicator is evaluated to determine whether it is within the normal range; the entire safety indicator matrix is comprehensively evaluated to determine the overall safety status of the power system, and appropriate evaluation methods and models are used to evaluate the safety indicator matrix using statistical methods, machine learning algorithms, etc. For example, statistical quantities such as mean and standard deviation are used to analyze safety indicators; machine learning models are used to predict and classify the safety indicator matrix to determine whether there is a safety risk. According to the evaluation results of the safety indicator matrix, the safety monitoring list is determined. The list includes the safety status of the power system, existing safety issues and risks, and recommended improvement measures. The assessment results are analyzed and summarized to identify existing safety issues and risks. For example, if a safety indicator exceeds the normal range, or there is an abnormal correlation between multiple safety indicators, it may indicate the existence of a safety issue or risk. Based on the safety issues and risks, corresponding improvement measures and suggestions are proposed. For example, if the equipment failure rate is high, it can be recommended to strengthen equipment maintenance and management; if a large number of current anomalies are found, it can be recommended to inspect and optimize the lines. The safety status, safety issues and risks, and improvement measures are organized into a safety monitoring list for relevant personnel to review and handle. The safety monitoring list can be presented in the form of a report or displayed through a remote monitoring platform to achieve real-time monitoring and safety assessment of the power system, providing strong support for the safety management of power collection.
[0037] In a possible implementation, the security indicator matrix is evaluated to determine a security monitoring list, and step S430 further includes step S431 , performing event correlation analysis on the security indicator matrix to determine a first evaluation result. Specifically, the specific meaning of each indicator in the safety indicator matrix and the possible safety events involved are clarified. For example, the voltage stability indicator may be related to events such as equipment failure and power grid fluctuation; the current anomaly indicator may be related to events such as short circuit and overload. Historical safety event data and related cases are collected, and a correlation model between events and safety indicators is established. By analyzing past safety events, the changing patterns of safety indicators when different events occur are found to provide a reference for current event correlation analysis. The data in the safety indicator matrix is analyzed row by row and column by column to observe the changing trends and mutual relationships of each indicator. For example, if it is found that the voltage stability indicator decreases while the current anomaly indicator also increases, it may mean that there is equipment failure or power grid instability. Combined with the event correlation model, it is determined whether the data in the current safety indicator matrix is associated with known safety events. If there is a correlation, the type and severity of the possible safety event are further determined. The changes in multiple safety indicators are comprehensively considered to determine the first assessment result. The first assessment result can be a preliminary judgment on the current safety status of the power system, such as the possibility of medium-risk equipment failure or low-risk power grid fluctuation.
[0038] Step S432 traverses the security indicator matrix, performs self-verification of the source data address, locates it in the power structure topology, and determines the local address topology. Specifically, each data point in the security indicator matrix is traversed to obtain its corresponding source data address information. The source data address is a sensor number, a device IP address, etc., which is used to determine the source of the data. The source data address is self-verified to check the legitimacy and accuracy of the address, for example, checking whether the address format is correct and whether it is within the known address range. If a problem is found with the address, it needs to be corrected or the data needs to be retrieved. This address self-verification ensures that the data source in the security indicator matrix is reliable, providing accurate basic data for subsequent positioning and analysis. Match the source data address that has undergone address self-verification with the power structure topology to determine the location of the data in the power structure. The power structure topology is a description of the distributed local power structure within the power jurisdiction area, including the location and connection relationship of each power device, line node, etc. By locating the source data address in the power structure topology, the specific device, line or area to which the data belongs can be determined. For example, if the address of a sensor corresponds to a specific transformer node in the power structure topology, then it can be determined that the data collected by the sensor is related to the transformer. According to the positioning result in the power structure topology, it can be determined. Determine the address local topology where the source data is located. The address local topology refers to the local power consumption structure centered on the source data address, including the equipment, lines and other nodes directly connected to it. Analyze the characteristics and properties of the address local topology, such as device type, load conditions, connection relationships, etc. Considering that different power consumption data characteristics are located in different power consumption structures and their assessment standards and risks are different, intervene in the power structure to improve analysis accuracy. For example, if a sensor is located in an industrial power consumption area, the assessment standard of its data may be different from that in a residential power consumption area, because the load and operating characteristics of industrial power equipment are very different from those of residential power equipment.
[0039] Step S433, based on the address local topology, the first evaluation result is compensated and the safety monitoring form is generated. Specifically, according to the determined address local topology, its impact on electricity safety is analyzed, and the factors such as the equipment characteristics, load conditions, and connection stability in the local topology are considered to evaluate the possible safety risks. For example, if there are old equipment or high-load equipment in an address local topology, the risk of equipment failure may increase; if the connection relationship is complex or there are weak links, the risk of power grid fluctuations may increase. In combination with the characteristics of the address local topology, the first evaluation result is adjusted and compensated. If the first evaluation result does not fully consider the impact of the address local topology, the evaluation result can be corrected according to the analysis results of the local topology. For example, if the first evaluation result shows that there is a low risk of power grid fluctuations, but there are high-load equipment and complex connection relationships in the address local topology, the risk assessment result needs to be adjusted to medium risk, and the compensated evaluation result will be adjusted to medium risk. The assessment results are compiled into a safety monitoring sheet, which should include the overall safety status of the power system, existing safety issues and risks, specific risk sources (such as equipment, lines or areas), and recommended improvement measures. In the safety monitoring sheet, the impact of the address local topology on the safety assessment should be clearly pointed out so that relevant personnel can better understand the safety status and take targeted measures. For example, the safety monitoring sheet should state that high-load equipment in a certain area is the main factor leading to increased risk, and put forward corresponding equipment upgrades or load adjustment suggestions. The safety monitoring sheet can be presented in the form of a report or displayed through a remote monitoring platform, so that relevant personnel can understand the safety status of the power system in a timely manner and take corresponding measures, more accurately assess the safety status of the power system, generate targeted safety monitoring sheets, and provide strong support for the safety management of power collection.
[0040] Step S500: Provide front-end electricity usage guidance based on the safety monitoring sheet to assist the remote monitoring platform in remote control and management. Specifically, analyze the various contents of the safety monitoring sheet to interpret the overall safety status of the power system, safety risk issues, risk sources, and improvement measures. Then, based on the analysis results, determine the specific content of the front-end electricity usage guidance, such as reasonable electricity usage recommendations, equipment usage precautions, and abnormal situation handling methods, and select an appropriate method to convey the guidance information to the user to ensure clarity, understanding, and practicality. At the same time, ensure stable connection and communication with the remote monitoring platform and receive platform instructions and feedback information in a timely manner. The remote monitoring platform issues remote control instructions based on the safety monitoring sheet results and real-time monitoring data. After receiving the instructions, the front-end device performs the corresponding operations, such as adjusting equipment parameters, cutting off power, or starting backup equipment, and feedbacks the execution results to the platform. The platform can further adjust the control strategy based on the feedback, thereby improving the safety and management efficiency of electricity collection.
[0041] The embodiment of the present application adopts the method of identifying the distributed local power structure within the power jurisdiction area and establishing a power structure topology map with node structure type identification. Based on the two dimensions of attack security and behavioral security, it assists in situation identification and intent analysis, and mines the event association tree. Combining the topology map and the event association tree, a remote monitoring platform is constructed, and dynamic monitoring and updating are performed through the active and passive conversion units. The platform perceives and collects security assessments of the power network, generates a safety monitoring sheet, and provides power guidance for the front-end equipment based on this, while realizing remote control and management, achieving the technical effect of real-time identification and response to potential safety hazards in the power network through intelligent remote control and dynamic adjustment, and effectively avoiding decision-making deviations.
[0042] The above specific embodiments do not constitute a limitation to the scope of protection of this application. It should be understood by those skilled in the art that various modifications, combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of this application should be included in the scope of protection of this application. In some cases, the actions or steps recorded in this application can be performed in an order different from that in the embodiments and can still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A method for monitoring power consumption safety based on intelligent remote control, characterized in that: The method comprises: For the electricity consumption jurisdiction area, identifying the distributed local electricity consumption structure and establishing an electricity consumption structure topology, wherein the topological nodes of the electricity consumption structure topology are identified with a structure type; Taking attack security and behavioral security as security dimensions, it assists in situation identification and intent analysis, and mines event association trees; Combining the power structure topology with the event association tree, a remote monitoring platform is constructed, wherein the remote monitoring platform performs monitoring and updating based on the active-passive conversion unit; Assist the remote monitoring platform to conduct safety assessment of power network perception and power collection, and determine safety monitoring orders; Provide front-end electricity usage guidance based on the safety monitoring sheet, and assist the remote monitoring platform in remote control management; The mining event association tree includes: Retrieve and retrieve electricity consumption collection safety records, and determine record information groups by analyzing electricity consumption characteristics and data streams, where each group of record information corresponds to a recorded event; Traversing the record information groups, and dividing each group into an intuitive part and a non-intuitive part; determining event-related features of the intuitive portion; Traversing the non-intuitive portion, performing behavior recognition and intentional understanding, and determining event-related features of the non-intuitive portion, wherein the non-intuitive portion is marked with a bias guidance mark; fusing the event association features of the intuitive part and the non-intuitive part, integrating and determining the event association tree, wherein the event association tree corresponds to the recorded event; The remote monitoring platform performs monitoring updates based on the active-passive conversion unit, including: Determine passive perception information through sensor network perception, wherein the passive perception information is: The passive sensing information is transmitted back to the active-passive conversion unit, and the passive sensing logic is determined through sensing situation analysis and event correlation feature mining; Decomposing the passive sensing logic into minimum logical granularity and integrating the logical conversion to determine the monitoring logic; Based on the monitoring logic, updating the remote monitoring platform; Get the active-passive conversion unit, including: With situational awareness - situational cognition - risk disposal - risk presentation as the underlying logic, a passive branch is constructed; Obtain an active-passive conversion logic library, construct conversion branches using logic internal competition as a model, and use the conversion branches to mine active-passive logical relationships; Coordinate the passive branch and the conversion branch to determine the active-passive conversion unit; After fusing the event association features of the intuitive part and the non-intuitive part, the method includes: Traversing the event correlation features, determining a precursor node based on the risk level, wherein a time span based on the precursor node is positively correlated with the risk level; determining a precursor feature value based on the precursor node, marking the event correlation feature, and generating the event correlation tree; In terms of attack security dimensions, the attack chain is determined and the precursor node is located, the malicious code penetration characteristics of the precursor node are integrated, and the event correlation characteristics are compensated.
2. The method for electricity collection safety monitoring based on intelligent remote control according to claim 1, characterized in that: The electricity network perception and electricity collection security assessment includes: Assist the remote monitoring platform to control the front-end sensor equipment, determine the monitoring data flow and perform acquisition time stamping; Returning the monitoring data stream, making decisions and determining a security indicator matrix; Evaluate the safety indicator matrix and determine the safety monitoring list.
3. The method for safe monitoring of electricity consumption collection based on intelligent remote control according to claim 2, characterized in that: The evaluation of the safety indicator matrix includes: Performing event correlation analysis on the safety indicator matrix to determine a first assessment result; Traversing the security indicator matrix, performing address self-verification of source data, locating the data in the power structure topology, and determining the address local topology; Based on the address local topology, the first evaluation result is compensated to generate the security monitoring list.
Citation Information
Patent Citations
Self-adaptive topology electric energy meter remote monitoring method and platform
CN118611273A