A network security deduction method, device, electronic device and storage medium for the power industry

By building a virtual simulation system based on the typical network topology of the power industry and simulating the interaction between attackers and defenders, the problem of existing technologies relying on real power equipment is solved, flexible and efficient network security simulation is achieved, and the protection capabilities of the power system are improved.

CN119276627BActive Publication Date: 2025-09-19GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411677504.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-09-19
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

Existing cybersecurity deduction methods in the power industry rely on real power equipment, resulting in high operational complexity and poor flexibility. They are difficult to cover a wide range of network attack and defense scenarios, and have high requirements for equipment security, increasing system instability.

Method used

A virtual simulation system based on the typical network topology of the power industry is constructed. By randomly selecting role command operations and sequences, the interaction between attackers and defenders is simulated until the preset conditions are met. The simulation results are recorded to avoid dependence on real power equipment.

Benefits of technology

It improves the flexibility and efficiency of cybersecurity simulations in the power industry, reduces dependence on professional and technical personnel, reduces costs, and ensures the accuracy and comprehensiveness of simulation results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276627B_ABST
    Figure CN119276627B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security deduction method, device, electronic device and storage medium for the electric power industry. The method comprises: constructing a network security deduction system; repeatedly executing a security deduction operation until a preset number of executions is reached or the network is successfully invaded, and recording the deduction results; wherein the security deduction operation comprises: for each role participating in the deduction, randomly selecting a number of command operations from its executable command operation list as command operations to be executed; randomly determining the order in which each role executes the command operations and generating an execution order; sending the order in which the roles execute the command operations and the command operations to be executed as deduction instance data to the network security deduction system, so that the network security deduction system generates and feeds back the deduction results after receiving the data; by implementing the present invention, the flexibility and efficiency of network security deduction in the electric power industry can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology in the power industry, and in particular to a network security deduction method, device, electronic equipment and storage medium for the power industry. Background Art

[0002] With the deepening of informatization and digitalization, the network architecture of the power industry has become increasingly complex, involving a large number of network device nodes and network areas. As critical infrastructure, network security in the power industry is of paramount importance. Any cyberattack not only has the potential to cause economic losses but also threatens the normal operation of society and national security. Improving the network security protection capabilities of the power industry and predicting and responding to cyberattacks have become urgent issues. Network security simulation and deduction technologies play an important role in simulating network attacks and defenses in the power industry and evaluating defense effectiveness. They help decision-makers develop effective network security strategies and enhance the protection capabilities of the power system.

[0003] However, existing simulation methods face several challenges. Existing systems typically require access to real power equipment for simulation. This use of real power equipment requires professional technicians to develop precise and complex execution procedures tailored to the actual situation, particularly the equipment parameters. Without effective process planning, some operations could damage power equipment, increasing system instability and risk. However, these concerns about equipment safety have limited the diversity and comprehensiveness of simulation operations, making it difficult for simulation results to cover a wider range of cyber attack and defense scenarios. Summary of the Invention

[0004] Embodiments of the present invention provide a method, apparatus, electronic device, and storage medium for power industry network security deduction. By implementing the present invention, network security deduction in the power industry can be implemented without concerns about power equipment security issues that limit the diversity and comprehensiveness of deduction operations, thereby improving the flexibility and efficiency of network security deduction in the power industry.

[0005] An embodiment of the present invention provides a method for network security deduction in the power industry, including:

[0006] Obtain a typical network topology for the power industry, the roles involved in network security simulations, and a list of executable command operations for these roles;

[0007] Build a network security simulation system based on the typical network topology of the power industry, the roles involved in network security simulation, and the list of executable command operations for these roles;

[0008] Repeat the security deduction operation until the preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution;

[0009] The security deduction operation includes:

[0010] For each role participating in the cybersecurity simulation, randomly select several command operations from its executable command operation list as the command operations to be executed;

[0011] Randomly determine the order in which each character executes command operations, and generate the order in which the characters execute command operations;

[0012] The order in which the roles execute command operations and the command operations to be executed by each role are sent as instance data of this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data;

[0013] Receive and record the deduction results; wherein the deduction results include the impact of each role's execution of command operations on the network.

[0014] Furthermore, the network security deduction system is constructed based on the typical network topology of the power industry, the roles involved in the network security deduction, and the executable command operation list of the roles, including:

[0015] Under the constraints of the preset network device node connection relationship ontology, knowledge extraction is performed on the network device node connection relationship information in the typical network topology of the power industry to generate network device node connection relationship entities that conform to the network device node connection relationship ontology specifications;

[0016] Under the constraints of the preset network device node ontology, knowledge extraction is performed on the network device node information in the typical network topology of the power industry to generate network device node entities that conform to the network device node connection relationship ontology specification;

[0017] Under the constraints of the preset command operation list ontology, knowledge extraction is performed on the executable command operation list of the role to generate a command operation list entity that conforms to the command operation ontology specification;

[0018] Under the constraints of the preset role ontology, knowledge is extracted from the roles involved in network security deduction to generate role entities that meet the role ontology specifications;

[0019] A network security deduction system is constructed based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

[0020] Furthermore, the roles involved in the network security deduction include attackers and defenders.

[0021] Furthermore, the executable command operation list of the role includes: an executable command operation list of the attacker and an executable command operation list of the defender;

[0022] The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation;

[0023] The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

[0024] Furthermore, the network device node entity includes: a DMZ zone network device node entity, a first security zone network device node entity, and a second security zone network device node entity;

[0025] The DMZ zone network device node entity includes: FTP server, WEB server, management server, first firewall, public network router;

[0026] The first security zone network device node entity includes: a first forward isolation device, a first reverse isolation device, a first SCADA module, a first horizontal switch, a first vertical switch, a vertical encryption authentication gateway, a first local area network switch, and equipment equipped with a substation system;

[0027] The second security zone network device node entity includes: a second forward isolation device, a second reverse isolation device, a second horizontal switch, a second vertical switch, a second SCADA module, a second firewall, a second LAN switch, and a device equipped with an electricity billing system.

[0028] Based on the above method embodiments, the present invention provides corresponding device embodiments.

[0029] An embodiment of the present invention provides a network security deduction device for the electric power industry, comprising: a data acquisition module, a deduction system construction module, a security deduction module, and a deduction result recording module.

[0030] The data acquisition module is used to obtain a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles;

[0031] The deduction system construction module is used to construct a network security deduction system based on the typical network topology of the power industry, the roles involved in network security deduction, and the executable command operation list of the roles;

[0032] The security deduction module is configured to randomly select a number of command operations from a list of executable command operations for each role participating in the network security deduction as command operations to be executed; randomly determine the order in which each role executes the command operations to generate an order in which the roles execute the command operations; send the order in which the roles execute the command operations and the command operations to be executed by each role as instance data for this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data; receive and record the deduction results, wherein the deduction results include the impact of each role's execution of the command operations on the network;

[0033] The deduction result recording module is used to repeatedly execute the security deduction module until a preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution.

[0034] Furthermore, the deduction system construction module includes: a network device node connection relationship entity construction unit, a network device node entity construction unit, a command operation list entity construction unit, a role entity construction unit and a system construction unit;

[0035] The network device node connection relationship entity construction unit is used to extract knowledge of network device node connection relationship information in a typical network topology of the power industry under the constraints of a preset network device node connection relationship ontology, and generate a network device node connection relationship entity that conforms to the network device node connection relationship ontology specification;

[0036] The network device node entity construction unit is used to extract knowledge of network device node information in a typical network topology of the power industry under the constraints of a preset network device node ontology, and generate a network device node entity that complies with the network device node connection relationship ontology specification;

[0037] The command operation list entity construction unit is used to extract knowledge from the executable command operation list of the role under the constraints of the preset command operation list ontology, and generate a command operation list entity that complies with the command operation ontology specification;

[0038] The role entity construction unit is used to extract knowledge of the roles involved in the network security deduction under the constraints of the preset role ontology, and generate role entities that meet the role ontology specifications;

[0039] The system construction unit is used to construct a network security deduction system based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

[0040] Furthermore, the data acquisition module includes the executable command operation list of the role, including: the executable command operation list of the attacker and the executable command operation list of the defender;

[0041] The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation;

[0042] The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

[0043] Based on the above method embodiment, the present invention provides a corresponding electronic device embodiment.

[0044] An embodiment of the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the power industry network security deduction method described in any one of the above-mentioned method embodiments can be implemented.

[0045] Based on the above method embodiment, the present invention provides a corresponding storage medium embodiment.

[0046] An embodiment of the present invention provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the power industry network security deduction method described in any one of the above method embodiments can be implemented.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] Embodiments of the present invention provide a method, apparatus, electronic device, and storage medium for network security simulation in the power industry. The method constructs a network security simulation system based on a typical network topology in the power industry, the roles involved in network security simulation, and a list of executable command operations for those roles. The system repeatedly executes security simulation operations until a preset number of executions is reached or the network is successfully intruded, and records the simulation results after each execution.

[0049] The cybersecurity simulation system constructed in this invention is based on the typical network topology of the power industry and does not involve access to actual power equipment. Therefore, for each role participating in the cybersecurity simulation, a number of commands can be randomly selected from their list of executable commands as pending commands, without having to worry about power equipment security issues limiting the diversity and comprehensiveness of simulation operations. This design overcomes the drawback of existing technologies that require complex execution processes developed by professional technicians due to their dependence on power equipment. It significantly reduces the threshold for non-technical personnel to use it in the decision-making process, further improving the flexibility and efficiency of cybersecurity simulation in the power industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 The present invention provides a flowchart of a method for network security deduction in the power industry according to an embodiment of the present invention.

[0051] Figure 2 1 is a flowchart of a security deduction operation provided by an embodiment of the present invention.

[0052] Figure 3 This is a structural diagram of a network security deduction device for the power industry provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0053] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0054] like Figure 1 As shown, an embodiment of the present invention provides a network security deduction method for the power industry, which includes at least the following steps:

[0055] Step S1: Obtain a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles;

[0056] Specifically, the roles involved in the network security deduction include attackers and defenders.

[0057] Exemplarily, the list of executable command operations of the roles includes: an attacker's executable command operation list and a defender's executable command operation list;

[0058] The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation;

[0059] The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

[0060] It should be noted that the typical network topology of the power industry includes: nodes of various network devices in the power system and their connection relationships;

[0061] It's understandable that obtaining a typical network topology for the power industry, along with a list of roles involved in cybersecurity simulations and their executable commands and operations, provides accurate foundational data for cybersecurity simulations. This allows simulations to accurately reflect the various device nodes and their connections within the power system, ensuring the simulation's authenticity and relevance. By clearly defining the executable commands and operations for each role, precise simulations can be performed based on their permissions and responsibilities, avoiding excessive permissions and unreasonable operations, and ensuring the simulation's reliability and effectiveness.

[0062] Step S2: constructing a network security deduction system based on a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles;

[0063] In an optional embodiment, the network security deduction system is constructed based on a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles, including:

[0064] Under the constraints of the preset network device node connection relationship ontology, knowledge extraction is performed on the network device node connection relationship information in the typical network topology of the power industry to generate network device node connection relationship entities that conform to the network device node connection relationship ontology specifications;

[0065] Under the constraints of the preset network device node ontology, knowledge extraction is performed on the network device node information in the typical network topology of the power industry to generate network device node entities that conform to the network device node connection relationship ontology specification;

[0066] Under the constraints of the preset command operation list ontology, knowledge extraction is performed on the executable command operation list of the role to generate a command operation list entity that conforms to the command operation ontology specification;

[0067] Under the constraints of the preset role ontology, knowledge is extracted from the roles involved in network security deduction to generate role entities that meet the role ontology specifications;

[0068] A network security deduction system is constructed based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

[0069] Optionally, the network device node body includes node type, node name, node ID, name of the network area to which the node belongs, number of the network area to which the node belongs, and node status.

[0070] The command operation list body includes the operation command type, the role type to which the operation command belongs, the operation command ID, the operation command name, the operation command description, the operation command effect description, the operation command quantity constraint, the role to which the operation command belongs, the operation command network device node attribute constraint, and the operation command network device node attribute execution result.

[0071] The role ontology includes role type, role ID, role optional operation command set, and role used operation command set.

[0072] The network device node connection relationship entity includes network device nodes and connection relationships between network device nodes.

[0073] Optionally, the network device node entity includes: a DMZ zone network device node entity, a first security zone network device node entity, and a second security zone network device node entity;

[0074] The DMZ zone network device node entity includes: FTP server, WEB server, management server, first firewall, public network router;

[0075] The first security zone network device node entity includes: a first forward isolation device, a first reverse isolation device, a first SCADA module, a first horizontal switch, a first vertical switch, a vertical encryption authentication gateway, a first local area network switch, and equipment equipped with a substation system;

[0076] The second security zone network device node entity includes: a second forward isolation device, a second reverse isolation device, a second horizontal switch, a second vertical switch, a second SCADA module, a second firewall, a second LAN switch, and a device equipped with an electricity billing system.

[0077] Optionally, the command operation list entity includes: an attacker's command operation list entity and a defender's command operation list entity;

[0078] The attacker's command operation list entity includes: 1 remote code execution operation, 10 vulnerability scanning operations, 6 Trojan horse implantation operations, 6 brute force cracking operations, 1 bypass attack operation, 1 route hijacking operation, and 1 PLC remote control operation.

[0079] The defender's command operation list entity includes 1 intrusion detection operation, 10 vulnerability scanning operations, 6 vulnerability patch operations, 6 log analysis operations, 3 Trojan removal operations, 1 honeypot placement operation, 1 PLC security protection operation, and 1 routing firmware protection operation.

[0080] It is understandable that by constructing a network security deduction scheme based on the typical network topology of the power industry, the roles involved in the network security deduction, and the executable command operation list of the roles, it is possible to effectively simulate the complex network environment of the power industry and accurately reflect the connection relationship between various network devices and nodes. This construction method enables the actual operation of the power network to be truly reproduced during the deduction process, thereby improving the accuracy and operability of the deduction results. At the same time, setting executable command operation lists for different roles ensures that the operational behavior of each role in the deduction is consistent with the actual authority and operation scope, avoiding the risk of authority abuse or misoperation, and improving the security and effectiveness of the deduction process. Through this method, it no longer relies on real physical equipment, avoids high costs and high technical requirements for professionals, and makes network security deduction simpler, more flexible, and less expensive.

[0081] Step S3: Repeat the security deduction operation until a preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution;

[0082] like Figure 2 As shown, a preferred embodiment provides the security deduction operation, including:

[0083] Step S3.1: For each role participating in the cybersecurity simulation, randomly select several command operations from its executable command operation list as command operations to be executed;

[0084] Step S3.2: Randomly determine the order in which each character executes the command operation, and generate the order in which the characters execute the command operation;

[0085] Step S3.3: Send the order in which the characters execute command operations and the command operations to be executed by each character as instance data for this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data;

[0086] Step S3.4: Receive and record the deduction results; wherein the deduction results include the impact of each role's execution of command operations on the network.

[0087] It's understandable that by repeatedly executing security simulations, we can comprehensively assess network security capabilities, identify potential security vulnerabilities, and verify them. Ensuring the accumulation of simulation results from each run helps to gradually optimize security policies, thereby improving network security and the ability to respond to complex attacks. Furthermore, by setting a predetermined number of runs or intrusion conditions, the comprehensiveness and effectiveness of the simulation process is ensured.

[0088] In a preferred embodiment, a network deduction experiment based on the network device node entity is provided, and the initial setting is as follows:

[0089] Character entity: There are 1 attacker and 1 defender.

[0090] Network device node entities: Based on the typical network topology of the power industry, the following network device nodes are included: DMZ: Public network router, firewall, FTP server, web server, management server. Second security zone: Forward isolation device, reverse isolation device, horizontal switch, vertical switch, SCADA module, firewall, LAN switch, and electricity billing system.

[0091] First security zone: forward isolation device, reverse isolation device, SCADA module, horizontal switch, vertical switch, vertical encryption authentication gateway, LAN switch, substation system.

[0092] Command operation list entity:

[0093] Attacker command operation list entities: 1 remote code execution operation, 10 vulnerability scanning operations, 6 Trojan implantation operations, 6 brute force cracking operations, 1 side channel attack operation, 1 route hijacking operation, and 1 PLC remote control operation.

[0094] Defender command operation list entities: 1 intrusion detection operation, 10 vulnerability scanning operations, 6 vulnerability patch operations, 6 log analysis operations, 1 honeypot placement operation, 3 Trojan removal operations, 1 PLC security protection operation, and 1 router firmware protection operation.

[0095] The specific deduction process is as follows:

[0096] Round 1:

[0097] Attacker commands: vulnerability scanning, brute force cracking, and Trojan horse implantation.

[0098] Defender commands: vulnerability scanning operations, log analysis operations, and vulnerability patch operations.

[0099] Execution order: The attacker acts first.

[0100] Attacker actions:

[0101] Step 1: The attacker performs a vulnerability scan on the DMZ's public network router and discovers a weak SSH password vulnerability. Step 2: The attacker performs a brute force cracking operation and successfully gains SSH access to the router.

[0102] Step 3: Gain persistent control of the public network router through Trojan implantation.

[0103] Defender Action:

[0104] Step 4: The defender performs a vulnerability scan on the DMZ firewall and finds no vulnerabilities.

[0105] Step 5: Perform log analysis and find no abnormal traffic.

[0106] Step 6: Execute the vulnerability patch operation on the DMZ zone WEB server and the update is successful.

[0107] Round 2:

[0108] Attacker commands: vulnerability scanning operations, bypass attack operations, and Trojan horse implantation operations.

[0109] Defender commands: log analysis operations, vulnerability patch operations, and honeypot placement operations.

[0110] Execution order: Defender acts first.

[0111] Defender Action:

[0112] Step 7: The defender performs log analysis on the DMZ public network router and finds no abnormal logins (because the attacker has cleared the logs).

[0113] Step 8: Execute the vulnerability patch operation on the second security zone SCADA module and update it successfully.

[0114] Step 9: Place the honeypot operation on the FTP service executor in the DMZ area. The deployment is successful.

[0115] Attacker actions:

[0116] Step 10: The attacker bypasses the DMZ firewall through a bypass attack and enters the second security zone network. Step 11: A vulnerability scan is performed on the horizontal switch in the second security zone, and a default password vulnerability is discovered.

[0117] Step 12: By executing the Trojan implantation operation, the Trojan is successfully implanted on the horizontal switch in the second security zone. Round 3:

[0118] Attacker commands: vulnerability scanning, Trojan implantation, and route hijacking.

[0119] Defender commands: vulnerability patching, log analysis, and Trojan removal.

[0120] Execution order: The attacker acts first.

[0121] Attacker actions:

[0122] Step 13: The attacker performs a vulnerability scan on the SCADA module in the second security zone and discovers an unpatched remote code execution vulnerability.

[0123] Step 14: By executing the Trojan implantation operation, the Trojan is successfully implanted on the SCADA module in the second security zone and control is obtained.

[0124] Step 15: Perform route hijacking operations on the vertical switches in the second security zone to control data flow.

[0125] Defender Action:

[0126] Step 16: An attempt is made to patch the vulnerability in the SCADA module in the second security zone, but the attacker has already taken control of the device and the operation fails.

[0127] Step 17: Perform log analysis on the horizontal switch in the second security zone and discover abnormal traffic.

[0128] Step 18: An attempt was made to remove the Trojan from the horizontal switch in the second security zone, but the attempt failed.

[0129] Round 4:

[0130] Attacker commands: vulnerability scanning operations, brute force cracking operations, and remote code execution operations.

[0131] Defender commands: intrusion detection operations, PLC security protection operations, and vulnerability patch operations.

[0132] Execution order: Defender acts first.

[0133] Defender Action:

[0134] Step 19: Perform network-wide intrusion detection operations, detect network anomalies in the second security zone, and issue an alarm.

[0135] Step 20: Perform PLC security protection operations on the PLC device in the first security zone to strengthen the security policy.

[0136] Step 21: Execute the vulnerability patch operation on the SCADA module of the first security zone and update it successfully.

[0137] Attacker actions:

[0138] Step 22: Perform a vulnerability scan operation on the reverse isolation device in the first security zone and discover an unknown vulnerability.

[0139] Step 23: Successfully execute remote code operations on the reverse isolation device, breaking through the isolation and entering the first security zone network.

[0140] Step 24: Perform brute force cracking on the SCADA module in the first security zone and successfully gain access rights. Round 5:

[0141] Attacker commands: Trojan implantation, PLC remote control, and route hijacking.

[0142] Defender commands: Trojan removal operations, log analysis operations, and router firmware protection operations.

[0143] Execution order: The attacker acts first.

[0144] Attacker actions:

[0145] Step 25: By executing the Trojan horse implantation operation, the attacker implants the Trojan horse on the SCADA module in the first security zone and obtains full control.

[0146] Step 26: Control the traffic of the vertical switch in the first security zone by performing a route hijacking operation.

[0147] Step 27: Execute PLC remote control operations to tamper with the operating parameters of the substation system.

[0148] Defender Action:

[0149] Step 28: The defender attempts to remove the Trojan from the SCADA module in the first security zone, but fails. Step 29: Log analysis is performed on the SCADA module in the first security zone, and abnormal activity is discovered.

[0150] Step 30: An attempt is made to perform routing firmware protection operations on the vertical switch in the first security zone, but the device has been controlled by the attacker.

[0151] Round 6:

[0152] Attacker commands: vulnerability scanning, Trojan implantation, and remote code execution.

[0153] Defender commands: intrusion detection operations, PLC security protection operations, and vulnerability patch operations.

[0154] Execution order: Defender acts first.

[0155] Defender Action:

[0156] Step 31: Perform network-wide intrusion detection and find that the network in the first security zone is threatened.

[0157] Step 32: Execute PLC safety protection operations to strengthen the safety protection of PLC equipment in the first safety zone.

[0158] Step 33: An attempt is made to patch the vulnerability on the vertical switch in the first security zone, but the device has been controlled by the attacker.

[0159] Attacker actions:

[0160] Step 34: Perform a vulnerability scan on the vertical encryption authentication gateway in the first security zone and discover a configuration vulnerability.

[0161] Step 35: Successfully execute remote code operations on the first security zone encryption authentication gateway to obtain high-privilege control. Step 36: Successfully implant a Trojan on the first security zone encryption authentication gateway by executing the Trojan implant operation, fully controlling the communication.

[0162] Round 7:

[0163] Attacker commands: PLC remote control operations, route hijacking operations, and Trojan horse implantation operations.

[0164] Defender commands: Trojan removal operations, vulnerability patch operations, and log analysis operations.

[0165] Execution order: The attacker acts first.

[0166] Attacker actions:

[0167] Step 37: Execute PLC remote control operations to tamper with the logic of all PLC devices in the first security zone.

[0168] Step 38: Control the network traffic of all switches in the first security zone by performing route hijacking operations.

[0169] Step 39: By executing the Trojan implantation operation, the Trojan is successfully implanted in the substation system in the first security zone, causing the substation system to be paralyzed.

[0170] Defender Action:

[0171] Step 40: The defender attempts to perform a Trojan removal operation on the substation system in the first security zone, but the removal fails because the system is paralyzed.

[0172] Step 41: Execute vulnerability patching operation on all devices in the first security zone. The devices have been completely controlled and the operation is invalid.

[0173] Step 42: When performing log analysis, the system crashes and log analysis cannot be performed.

[0174] Round 8:

[0175] Attacker commands: remote code execution, PLC remote control, and Trojan implantation.

[0176] Defender commands: intrusion detection operations, PLC security protection operations, and honeypot placement operations.

[0177] Execution order: Defender acts first.

[0178] Defender Action:

[0179] Step 43: The defender performs intrusion detection operations, and the results show that the system is paralyzed and the intrusion detection fails.

[0180] Step 44: Perform PLC security protection operations on the PLC device, but the device has been tampered with by the attacker and the protection is invalid.

[0181] Step 45: An attempt is made to place the honeypot on the entire network. However, the operation fails because the network is unavailable.

[0182] Attacker actions:

[0183] Step 46: The attacker performs remote code execution on all remaining devices in the first security zone, completely disrupting the normal operation of the system.

[0184] Step 47: Continue to further damage the PLC device by executing PLC remote control operations and tamper with more critical operation logic.

[0185] Step 48: By executing the Trojan implantation operation, the Trojan is successfully implanted on the backup system, causing the backup system to crash and preventing system recovery.

[0186] Deduction results

[0187] After eight rounds of deductions and a total of 48 operational steps, the attackers ultimately succeeded in breaching the power industry's multi-layered defenses. Through vulnerability exploitation, Trojan horse implantation, bypass attack privilege escalation, route hijacking privilege escalation, and PLC remote control privilege escalation, the attackers gained full control of key equipment on the power industry network, paralyzing the entire system. Despite implementing multiple protective measures, including vulnerability patching firewall rules, log analysis firewall rules, and PLC security protection firewall rules, the attackers' ultimate victory was unsuccessful.

[0188] Based on the above method embodiments, the present invention provides corresponding device embodiments.

[0189] like Figure 3 As shown, an embodiment of the present invention provides a network security deduction device for the power industry, comprising: a data acquisition module, a deduction system construction module, a security deduction module, and a deduction result recording module;

[0190] The data acquisition module is used to obtain a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles;

[0191] The deduction system construction module is used to construct a network security deduction system based on the typical network topology of the power industry, the roles involved in network security deduction, and the executable command operation list of the roles;

[0192] The security deduction module is configured to randomly select a number of command operations from a list of executable command operations for each role participating in the network security deduction as command operations to be executed; randomly determine the order in which each role executes the command operations to generate an order in which the roles execute the command operations; send the order in which the roles execute the command operations and the command operations to be executed by each role as instance data for this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data; receive and record the deduction results, wherein the deduction results include the impact of each role's execution of the command operations on the network;

[0193] The deduction result recording module is used to repeatedly execute the security deduction module until a preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution.

[0194] In an optional embodiment, the deduction system construction module includes: a network device node connection relationship entity construction unit, a network device node entity construction unit, a command operation list entity construction unit, a role entity construction unit and a system construction unit;

[0195] The network device node connection relationship entity construction unit is used to extract knowledge of network device node connection relationship information in a typical network topology of the power industry under the constraints of a preset network device node connection relationship ontology, and generate a network device node connection relationship entity that conforms to the network device node connection relationship ontology specification;

[0196] The network device node entity construction unit is used to extract knowledge of network device node information in a typical network topology of the power industry under the constraints of a preset network device node ontology, and generate a network device node entity that complies with the network device node connection relationship ontology specification;

[0197] The command operation list entity construction unit is used to extract knowledge from the executable command operation list of the role under the constraints of the preset command operation list ontology, and generate a command operation list entity that complies with the command operation ontology specification;

[0198] The role entity construction unit is used to extract knowledge of the roles involved in the network security deduction under the constraints of the preset role ontology, and generate role entities that meet the role ontology specifications;

[0199] The system construction unit is used to construct a network security deduction system based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

[0200] In a preferred embodiment, the data acquisition module, the list of executable command operations of the role includes: an executable command operation list of the attacker and an executable command operation list of the defender;

[0201] The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation;

[0202] The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

[0203] It should be noted that the embodiments of the device described above correspond to the above-mentioned embodiments of the present invention, and can implement any of the methods described above in the present invention. In addition, the embodiments of the above-mentioned device are merely schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the drawings of the embodiment of the device provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0204] Based on the above method embodiment of the present invention, a corresponding electronic device embodiment is provided.

[0205] An embodiment of the present invention provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power industry network security deduction method described in any one of the present inventions, or, when the processor executes the computer program, it implements the functions of each module in the above-mentioned device embodiments.

[0206] Exemplarily, the computer program may be divided into one or more modules, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.

[0207] The terminal device may be a computing device such as a desktop computer, a notebook computer, a PDA, a cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.

[0208] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the terminal device, connecting various parts of the entire terminal device using various interfaces and lines.

[0209] The memory can be used to store the computer programs and / or modules, and the processor implements various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory, and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required for a function, etc.; the data storage area can store data created based on the use of the mobile phone, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0210] Based on the above method embodiment, the present invention provides a corresponding storage medium embodiment;

[0211] Another embodiment of the present invention provides a storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute any of the above-mentioned power industry network security deduction methods of the present invention.

[0212] The above-mentioned storage medium is a computer-readable storage medium, and the computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0213] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art may combine and integrate different embodiments or examples described in this specification, as well as features of different embodiments or examples, unless they are mutually inconsistent.

[0214] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A network security deduction method for the power industry, characterized in that: include: Obtain a typical network topology for the power industry, the roles involved in network security simulations, and a list of executable command operations for these roles; Build a network security simulation system based on the typical network topology of the power industry, the roles involved in network security simulation, and the list of executable command operations for these roles; Repeat the security deduction operation until the preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution; The security deduction operation includes: For each role participating in the cybersecurity simulation, randomly select several command operations from its executable command operation list as the command operations to be executed; Randomly determine the order in which each character executes command operations, and generate the order in which the characters execute command operations; The order in which the roles execute command operations and the command operations to be executed by each role are sent as instance data of this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data; Receive and record the deduction results; wherein the deduction results include the impact of each role's execution of command operations on the network.

2. The power industry network security deduction method according to claim 1, characterized in that: The network security deduction system is constructed based on the typical network topology of the power industry, the roles involved in network security deduction, and the executable command operation list of the roles, including: Under the constraints of the preset network device node connection relationship ontology, knowledge extraction is performed on the network device node connection relationship information in the typical network topology of the power industry to generate network device node connection relationship entities that conform to the network device node connection relationship ontology specifications; Under the constraints of the preset network device node ontology, knowledge extraction is performed on the network device node information in the typical network topology of the power industry to generate network device node entities that conform to the network device node connection relationship ontology specification; Under the constraints of the preset command operation list ontology, knowledge extraction is performed on the executable command operation list of the role to generate a command operation list entity that conforms to the command operation ontology specification; Under the constraints of the preset role ontology, knowledge is extracted from the roles involved in network security deduction to generate role entities that meet the role ontology specifications; A network security deduction system is constructed based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

3. The power industry network security deduction method according to claim 2, characterized in that: The roles involved in network security deduction include attackers and defenders.

4. The power industry network security deduction method according to claim 3, characterized in that: The executable command operation list of the role includes: an executable command operation list of the attacker and an executable command operation list of the defender; The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation; The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

5. The power industry network security deduction method according to claim 4, characterized in that: The network device node entity includes: a DMZ zone network device node entity, a first security zone network device node entity, and a second security zone network device node entity; The DMZ zone network device node entity includes: FTP server, WEB server, management server, first firewall, public network router; The first security zone network device node entity includes: a first forward isolation device, a first reverse isolation device, a first SCADA module, a first horizontal switch, a first vertical switch, a vertical encryption authentication gateway, a first local area network switch, and equipment equipped with a substation system; The second security zone network device node entity includes: a second forward isolation device, a second reverse isolation device, a second horizontal switch, a second vertical switch, a second SCADA module, a second firewall, a second LAN switch, and a device equipped with an electricity billing system.

6. A network security deduction device for the power industry, characterized in that: include: Data acquisition module, deduction system construction module, safety deduction module and deduction result recording module; The data acquisition module is used to obtain a typical network topology of the power industry, roles involved in network security deduction, and a list of executable command operations for the roles; The deduction system construction module is used to construct a network security deduction system based on the typical network topology of the power industry, the roles involved in network security deduction, and the executable command operation list of the roles; The security deduction module is configured to randomly select a number of command operations from a list of executable command operations for each role participating in the network security deduction as command operations to be executed; randomly determine the order in which each role executes the command operations to generate an order in which the roles execute the command operations; send the order in which the roles execute the command operations and the command operations to be executed by each role as instance data for this round of deduction to the network security deduction system, so that the network security deduction system generates and feeds back deduction results after receiving the instance data; receive and record the deduction results, wherein the deduction results include the impact of each role's execution of the command operations on the network; The deduction result recording module is used to repeatedly execute the security deduction module until a preset number of executions is reached or the network is successfully invaded, and record the deduction results after each execution.

7. The power industry network security deduction device according to claim 6, characterized in that: The deduction system construction module includes: a network device node connection relationship entity construction unit, a network device node entity construction unit, a command operation list entity construction unit, a role entity construction unit and a system construction unit; The network device node connection relationship entity construction unit is used to extract knowledge of network device node connection relationship information in a typical network topology of the power industry under the constraints of a preset network device node connection relationship ontology, and generate a network device node connection relationship entity that conforms to the network device node connection relationship ontology specification; The network device node entity construction unit is used to extract knowledge of network device node information in a typical network topology of the power industry under the constraints of a preset network device node ontology, and generate a network device node entity that complies with the network device node connection relationship ontology specification; The command operation list entity construction unit is used to extract knowledge from the executable command operation list of the role under the constraints of the preset command operation list ontology, and generate a command operation list entity that complies with the command operation ontology specification; The role entity construction unit is used to extract knowledge of the roles involved in the network security deduction under the constraints of the preset role ontology, and generate role entities that meet the role ontology specifications; The system construction unit is used to construct a network security deduction system based on the network device node connection relationship entity, the network device node entity, the command operation list entity and the role entity.

8. The power industry network security deduction device according to claim 7, characterized in that: The data acquisition module includes the executable command operation list of the role, including the executable command operation list of the attacker and the executable command operation list of the defender; The attacker's executable command operation list includes: remote code execution operation, first vulnerability scanning operation, Trojan horse implantation operation, brute force cracking operation, bypass attack operation, route hijacking operation and PLC remote control operation; The list of executable command operations of the defender includes: intrusion detection operation, second vulnerability scanning operation, vulnerability patch operation, log analysis operation, honeypot placement operation, Trojan removal operation, PLC security protection operation and routing firmware protection operation.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, it can implement the power industry network security deduction method described in any one of claims 1 to 5.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it can implement the power industry network security deduction method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network security deduction method, device and equipment and storage medium

    CN112073411A

  • Network attack and defense deduction platform based on simulation experiment design

    CN112118272A