An intelligent penetration detection method and system for power system
By conducting penetration tests on the power system, monitoring and processing penetration test parameter data, analyzing the abnormality of network traffic, system files and vulnerabilities, the accuracy of the power system security status analysis is solved, and timely early warning and network security is achieved.
Patent Information
- Application Number
- CN202411304727.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2044-09-19
AI Technical Summary
In the prior art, penetration testing of power systems is difficult to accurately and efficiently analyze security conditions, making it difficult to deal with complex cyber attacks.
By conducting penetration testing on the power system, monitoring and obtaining penetration testing parameter data, data processing, analyzing the abnormality of network traffic, system files and vulnerabilities, and providing early warnings and reminders.
It realizes accurate and efficient analysis of the safety status of the power system, promptly conducts early warnings, and improves the network security of the power system.
Smart Images

Figure CN119293795B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security testing, and in particular to an intelligent penetration detection method and system for a power system. Background Art
[0002] With the rapid development of information technology, power systems are becoming increasingly intelligent and informative. However, they are also facing increasing cybersecurity threats, such as hacker attacks and virus intrusions, which can paralyze power systems and cause severe socioeconomic losses. Penetration testing is a method used to simulate hacker attacks and assess system security. Traditional power system security testing methods often rely on manual experience, resulting in low efficiency and difficulty in responding to complex and diverse cyberattacks. Therefore, an efficient and intelligent penetration testing method is needed.
[0003] Existing penetration detection systems implement penetration detection functions by mechanically attacking the network of the object to be detected, finding existing vulnerabilities, testing the vulnerabilities and generating penetration attack reports.
[0004] For example, the invention patent announcement with announcement number: CN111475818B discloses a penetration attack method based on an AI-based automated penetration system, including: S1, determining the attack category; S2, prioritizing vulnerabilities; S3, detecting vulnerabilities one by one; S4, a special intelligent module matching other vulnerabilities; S5, prioritizing vulnerabilities; S6, detecting vulnerabilities one by one; S7, a special intelligent module optimizing and adjusting parameters; S8, a penetration attack module generating vulnerability verification results and vulnerability exploitation results.
[0005] For example, the patent application with publication number: CN115659348A discloses a rapid penetration testing method and testing device for a mobile device, which include: determining whether the mobile device is undergoing a penetration test for the first time; in the case where the mobile device is undergoing a penetration test for the first time: performing a test environment detection operation to obtain first environment detection information; determining a test function module based on the first environment detection information; performing a corresponding penetration testing operation based on the test function module to generate a corresponding first test result; in the case where the mobile device is not undergoing a penetration test for the first time: performing a test environment detection operation to obtain second environment detection information; determining whether the test environment has changed based on the second environment detection information; in the case where it is determined that the test environment has changed, determining an updated function module corresponding to the test environment; performing a corresponding penetration testing operation based on the updated function module to generate a second test result.
[0006] However, in the process of implementing the technical solutions of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems:
[0007] In the existing technology, the network structure of the power monitoring system is complex. When the power system is attacked by hackers or other threatening operations, many aspects of the power system will be affected. Penetration testing can be used to analyze the impact of the power system. However, due to the excessive amount of data obtained through penetration testing to show the impact of the power system, it is difficult to accurately and efficiently analyze the security status of the power system through penetration testing. Summary of the Invention
[0008] The embodiments of the present application provide an intelligent penetration detection method and system for power systems, thereby solving the problem in the prior art that it is difficult to accurately and efficiently analyze the security status of the power system through penetration testing, and achieving accurate and efficient analysis of the security status of the power system through penetration testing.
[0009] An embodiment of the present application provides an intelligent penetration detection method for an electric power system, comprising the following steps: performing a penetration test on the electric power system; monitoring and obtaining penetration test parameter data during the penetration test; processing the penetration test parameter data; analyzing the safety status of the electric power system based on the processed penetration test parameter data and issuing an early warning reminder.
[0010] Furthermore, the power system security situation includes: the degree of abnormality of the power system in network traffic, the degree of abnormality of the power system in system files, and the degree of abnormality of the power system in vulnerabilities; the penetration test parameter data includes network traffic abnormality parameter data, system file abnormality parameter data, and vulnerability security parameter data; the specific analysis process of the degree of abnormality of the power system in network traffic is: obtaining network traffic abnormality parameter data according to the penetration test parameter data; analyzing the network traffic abnormality parameter data to obtain a network traffic abnormality evaluation coefficient, and the network traffic abnormality evaluation coefficient is used to reflect the degree of abnormality of the power system in network traffic; analyzing the degree of abnormality of the power system in network traffic according to the network traffic abnormality evaluation coefficient.
[0011] Furthermore, the specific analysis process of analyzing the degree of abnormality of the power system in network traffic based on the network traffic abnormality degree assessment coefficient is as follows: obtaining the network traffic abnormality degree assessment coefficient, obtaining the network traffic abnormality degree threshold, comparing the network traffic abnormality degree assessment coefficient with the network traffic abnormality degree threshold; when the network traffic abnormality degree assessment coefficient is less than the network traffic abnormality degree threshold, it indicates that the power system performs normally in terms of network traffic; when the network traffic abnormality degree assessment coefficient is greater than or equal to the network traffic abnormality degree threshold, it indicates that the power system performs abnormally in terms of network traffic.
[0012] Furthermore, the specific analysis process of the abnormality degree of the power system in terms of system files is: obtaining system file abnormality degree parameter data based on penetration test parameter data; obtaining a system file abnormality degree evaluation index based on the analysis of the system file abnormality degree parameter data, and the system file abnormality degree evaluation index is used to express the abnormality degree of the power system in terms of system files; analyzing the abnormality degree of the power system in terms of system files based on the system file abnormality degree evaluation index.
[0013] Furthermore, the specific analysis process of analyzing the abnormality degree of the power system in terms of system files based on the system file abnormality degree assessment index is: obtaining the system file abnormality degree assessment index, obtaining the first system file abnormality degree threshold and the second system file abnormality degree threshold, comparing the system file abnormality degree assessment index with the first system file abnormality degree threshold and the second system file abnormality degree threshold; when the system file abnormality degree assessment index is greater than the first system file abnormality degree threshold and less than the second system file abnormality degree threshold, it indicates that the power system performs normally in terms of system files; when the system file abnormality degree assessment index is less than or equal to the first system file abnormality degree threshold or the system file abnormality degree assessment index is greater than or equal to the second system file abnormality degree threshold, it indicates that the power system performs abnormally in terms of system files.
[0014] Furthermore, the specific analysis process of the abnormality degree of the power system in terms of vulnerabilities is as follows: obtaining vulnerability safety degree parameter data based on penetration test parameter data; normalizing the vulnerability safety degree parameter data; obtaining a vulnerability safety degree assessment index based on the normalized vulnerability safety degree parameter data analysis, wherein the vulnerability safety degree assessment index is used to express the abnormality degree of the power system in terms of vulnerabilities; and analyzing the abnormality degree of the power system in terms of vulnerabilities based on the vulnerability safety degree assessment index.
[0015] Furthermore, the specific analysis process of analyzing the abnormality degree of the power system in terms of vulnerability based on the vulnerability safety level assessment index is: obtaining the vulnerability safety level assessment index, obtaining the first vulnerability safety level threshold and the second vulnerability safety level threshold; when the vulnerability safety level assessment index is greater than the first vulnerability safety level threshold and less than the second vulnerability safety level threshold, it indicates that the power system behaves normally in terms of vulnerability; when in other situations, it indicates that the power system behaves abnormally in terms of vulnerability.
[0016] Furthermore, the specific analysis process of analyzing the power system security situation and issuing early warning reminders is: obtaining the power system security situation; when one or more of the power system's abnormal network traffic, abnormal system file performance, and abnormal vulnerability performance occur in the power system security situation, it indicates that the power system is operating normally and no early warning reminder is issued; when two or more of the power system's abnormal network traffic, abnormal system file performance, and abnormal vulnerability performance occur in the power system security situation, it indicates that the power system is abnormal and an early warning reminder is issued.
[0017] Furthermore, the specific method for obtaining the network traffic anomaly degree assessment coefficient is as follows: performing a penetration test on the power system, obtaining the number of penetration tests, and numbering the number of penetration tests; performing multiple data acquisitions during each penetration test, and numbering the number of data acquisitions; obtaining from a database the number of ports used by the power system and the weight ratio of HTTP protocol traffic used by the power system and FTP protocol traffic used by the power system; obtaining network traffic anomaly degree parameter data; and constructing a network traffic anomaly degree assessment coefficient calculation formula based on the network traffic anomaly degree parameter data. The specific network traffic anomaly degree assessment coefficient calculation formula is:
[0018]
[0019] Where, It is represented as the evaluation coefficient of the abnormal degree of network traffic in the power system at the k0th penetration test, k0=1,2,...,k, k0 represents the number of penetration tests, k represents the total number of penetration tests, It represents the number of ports used in the power system during the k0th penetration test at the h0th data collection time, h0=1,2,...,h, h0 represents the number of data acquisition times, h represents the total number of data acquisition times, It is represented as the reference number of ports used by the power system during the k0th penetration test of the power system. It represents the Modbus protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the DNP3 protocol traffic of the power system during the k0th penetration test and the h0th data collection. It represents the HTTP protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the FTP protocol traffic used by the power system during the k0th penetration detection at the h0th data collection time. D1 represents the weight ratio of the number of ports used by the power system in the network traffic anomaly evaluation coefficient. D2 represents the weight ratio of the HTTP protocol traffic used by the power system and the FTP protocol traffic used by the power system in the network traffic anomaly evaluation coefficient.
[0020] An embodiment of the present application provides an intelligent penetration detection system for an electric power system, comprising: a penetration testing module, a parameter acquisition module, a data processing module and an early warning analysis module; wherein the penetration testing module is used to perform penetration testing on the electric power system; the parameter acquisition module is used to monitor and obtain penetration testing parameter data during the penetration testing process; the data processing module is used to perform data processing on the penetration testing parameter data; the early warning analysis module is used to analyze the security status of the electric power system based on the processed penetration testing parameter data and issue early warning reminders.
[0021] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0022] 1. By conducting penetration testing on the power system, monitoring and obtaining penetration test parameter data during the penetration test, and processing the penetration test parameter data, the power system security situation is analyzed and early warning reminders are issued based on the penetration test parameter data after data processing, thereby accurately and efficiently analyzing the security status of the power system through penetration testing, effectively solving the problem in the existing technology that it is difficult to accurately and efficiently analyze the security status of the power system through penetration testing.
[0023] 2. By obtaining network traffic anomaly parameter data based on penetration test parameter data, the network traffic anomaly parameter data is analyzed to obtain a network traffic anomaly evaluation coefficient, and then the abnormality of the power system in network traffic is analyzed according to the network traffic anomaly evaluation coefficient, thereby achieving a detailed and accurate analysis of the abnormality of the power system in network traffic.
[0024] 3. By obtaining the system file abnormality parameter data based on the penetration test parameter data, and analyzing the system file abnormality parameter data to obtain the system file abnormality evaluation index, the abnormality degree of the power system in terms of system files is analyzed according to the system file abnormality evaluation index, thereby accurately analyzing the abnormality degree of the power system in terms of system files. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 A flow chart of an intelligent penetration detection method for a power system provided in an embodiment of the present application;
[0026] Figure 2 A graph showing the system file anomaly evaluation index provided in an embodiment of the present application;
[0027] Figure 3 A schematic structural diagram of an intelligent penetration detection system for a power system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0028] The embodiments of the present application solve the problem in the prior art that it is difficult to accurately and efficiently analyze the safety status of the power system through penetration testing by providing an intelligent penetration detection method and system for the power system. By performing penetration testing on the power system, monitoring and obtaining penetration test parameter data during the penetration test, and processing the penetration test parameter data, the power system safety status is analyzed based on the processed penetration test parameter data and early warning reminders are issued, thereby achieving accurate and efficient analysis of the safety status of the power system through penetration testing.
[0029] The technical solution in the embodiments of the present application is to solve the above-mentioned problem of difficulty in accurately and efficiently analyzing the security status of the power system through penetration testing. The overall idea is as follows:
[0030] By conducting penetration testing on the power system; monitoring and obtaining penetration testing parameter data during the penetration testing process; processing the penetration testing parameter data; obtaining network traffic anomaly parameter data based on the processed penetration testing parameter data; analyzing the network traffic anomaly parameter data to obtain the network traffic anomaly evaluation coefficient; analyzing the power system's network traffic anomaly evaluation coefficient; obtaining system file anomaly parameter data based on the penetration testing parameter data; obtaining the system file anomaly evaluation index based on the system file anomaly parameter data; analyzing the power system's system file anomaly evaluation index; obtaining vulnerability security parameter data based on the penetration testing parameter data; normalizing the vulnerability security parameter data; obtaining the vulnerability security evaluation index based on the normalized vulnerability security parameter data; analyzing the power system's vulnerability security evaluation index The abnormality degree of the power system in terms of vulnerabilities; obtaining the power system security situation, the power system security situation includes: the abnormality degree of the power system in network traffic, the abnormality degree of the power system in system files and the abnormality degree of the power system in terms of vulnerabilities; the penetration test parameter data includes network traffic abnormality degree parameter data, system file abnormality degree parameter data and vulnerability security degree parameter data; when the power system shows abnormal performance in network traffic, abnormal performance in system files and abnormal performance in vulnerabilities of the power system in one or more of the power system security situations, it indicates that the power system is operating normally and no early warning reminder is issued; when the power system shows abnormal performance in network traffic, abnormal performance in system files and abnormal performance in vulnerabilities of the power system in two or more of the power system security situations, it indicates that the power system is abnormal and an early warning reminder is issued, thereby achieving the effect of accurately and efficiently analyzing the security status of the power system through penetration testing.
[0031] In order to better understand the above technical solution, the above technical solution will be described in detail below with reference to the accompanying drawings and specific implementation methods.
[0032] like Figure 1 As shown, it is a flow chart of an intelligent penetration detection method for a power system provided in an embodiment of the present application, the method comprising the following steps: performing a penetration test on the power system; monitoring and obtaining penetration test parameter data during the penetration test; performing data processing on the penetration test parameter data; analyzing the power system security situation based on the processed penetration test parameter data and issuing early warning reminders.
[0033] In this embodiment, with the promotion of smart grids, power monitoring systems have become more complex and large. These systems are responsible for real-time monitoring and control of the operating status of the power system to ensure the stability and security of the power supply. With the widespread application of information technology in power systems, network security threats are increasing. Hacker attacks, virus intrusions, etc. may cause power systems to collapse, resulting in serious social and economic losses. Penetration testing is a method that simulates hacker attacks and is used to assess system security. In power systems, penetration testing can help discover potential security vulnerabilities. By combining penetration testing and penetration test parameter data, the security status of the power system can be analyzed more accurately and efficiently.
[0034] By processing the penetration test parameter data, duplicate or erroneous data in the penetration test parameter data is removed, and the penetration test parameter data is made to be in the same order of magnitude and range, which is conducive to more accurate analysis of the power system security situation and early warning reminders based on the penetration test parameter data.
[0035] Furthermore, the safety status of the power system includes: the degree of abnormality of the power system in network traffic, the degree of abnormality of the power system in system files, and the degree of abnormality of the power system in vulnerabilities; the specific analysis process of the degree of abnormality of the power system in network traffic is: obtaining network traffic abnormality parameter data based on penetration test parameter data; analyzing the network traffic abnormality parameter data to obtain a network traffic abnormality evaluation coefficient, the network traffic abnormality evaluation coefficient is used to reflect the degree of abnormality of the power system in network traffic; analyzing the degree of abnormality of the power system in network traffic based on the network traffic abnormality evaluation coefficient.
[0036] In this embodiment, when the power system encounters the following situations, it indicates that the network traffic of the power system is abnormally affected and therefore requires further analysis. The situations include: a sudden increase or decrease in traffic, which may be related to a distributed denial of service attack or network device failure; unusual packet size or packet type, which may indicate malware or probing behavior; traffic activity on illegal ports, which may mean that someone is trying to exploit known vulnerabilities; unauthorized remote access attempts, especially access from external networks; port scanning activities, where attackers may be looking for open ports to attack.
[0037] In this embodiment, the network flow abnormality degree evaluation coefficient is obtained by analyzing the network flow abnormality degree parameter data, and then the abnormality degree of the power system in terms of network flow is analyzed according to the network flow abnormality degree evaluation coefficient, so that the analysis of the abnormality degree of the power system in terms of network flow is more accurate.
[0038] Furthermore, a specific method for obtaining the network traffic anomaly degree evaluation coefficient is as follows: performing penetration testing on the power system, obtaining the number of penetration testing times, and numbering the number of penetration testing times; performing multiple data acquisitions during each penetration testing, and numbering the number of data acquisitions; obtaining from a database the number of ports used by the power system and the weight ratio of HTTP protocol traffic used by the power system and FTP protocol traffic used by the power system; obtaining network traffic anomaly degree parameter data; and constructing a network traffic anomaly degree evaluation coefficient calculation formula based on the network traffic anomaly degree parameter data. The specific network traffic anomaly degree evaluation coefficient calculation formula is:
[0039]
[0040] Where, It is represented as the evaluation coefficient of the abnormal degree of network traffic in the power system at the k0th penetration test, k0=1,2,...,k, k0 represents the number of penetration tests, k represents the total number of penetration tests, It represents the number of ports used in the power system during the k0th penetration test at the h0th data collection time, h0=1,2,...,h, h0 represents the number of data acquisition times, h represents the total number of data acquisition times, It is represented as the reference number of ports used by the power system during the k0th penetration test of the power system. It represents the Modbus protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the DNP3 protocol traffic of the power system during the k0th penetration test and the h0th data collection. It represents the HTTP protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the FTP protocol traffic used by the power system during the k0th penetration detection at the h0th data collection time. D1 represents the weight ratio of the number of ports used by the power system in the network traffic anomaly evaluation coefficient. D2 represents the weight ratio of the HTTP protocol traffic used by the power system and the FTP protocol traffic used by the power system in the network traffic anomaly evaluation coefficient.
[0041] In this embodiment, historical network traffic anomaly parameter data is obtained, and by analyzing the historical network traffic anomaly parameter data, the relationship between the number of ports used by the power system, the HTTP protocol traffic used by the power system, the FTP protocol traffic used by the power system, and the network traffic anomaly evaluation coefficient is found. A fitting curve is obtained using a multiple linear regression method, and the fitting effect of the fitting curve is obtained by analyzing the mean square error of the fitting curve. The fitting curve corresponding to the minimum mean square error is used as the first fitting curve, and the corresponding weight ratio is obtained through the first fitting curve. The real-time number of ports used by the power system, the HTTP protocol traffic used by the power system, and the FTP protocol traffic used by the power system are substituted into the first fitting curve to obtain the corresponding weight ratio of the number of ports used by the power system, the HTTP protocol traffic used by the power system, and the FTP protocol traffic used by the power system.
[0042] The parameter data of network traffic abnormality degree include the number of ports used by the power system, the reference number of ports used by the power system, the Modbus protocol traffic used by the power system, the DNP3 protocol traffic used by the power system, the HTTP protocol traffic used by the power system, and the FTP protocol traffic used by the power system.
[0043] The parameter data of historical network traffic anomaly levels include the historical number of ports used by the power system, the reference number of ports used by the power system, the Modbus protocol traffic used by the power system, the DNP3 protocol traffic used by the power system, the HTTP protocol traffic used by the power system, and the FTP protocol traffic used by the power system.
[0044] When a power system uses an unusual port, it could be a listening port for a backdoor program. An attacker may have successfully installed a backdoor program on the system for remote control and data transmission. Unauthorized data transmission could indicate sensitive information leakage or the system being used as a springboard for further attacks. When a power system experiences unusual protocol traffic, for example, on a SCADA (Supervisory Control and Data Acquisition) network, typically only Modbus (serial communication protocol) or DNP3 (Distributed Network Protocol version 3) traffic should be observed. These traffic is used to control devices and sensors in the power system. Detecting a large amount of HTTP (Hypertext Transfer Protocol) or FTP (File Transfer Protocol) traffic could be abnormal. An attacker may be attempting to use HTTP or FTP to communicate with a component in the system to execute commands or transfer data. This unusual protocol traffic could indicate an attacker attempting to exploit known vulnerabilities or perform lateral movement. Therefore, it is necessary to monitor and analyze the ports and protocol traffic used in the power system.
[0045] In the algorithm of this embodiment, the network traffic anomaly degree parameter data is nonlinearly transformed by using a hyperbolic cosine function, and the excessively large or too small data in the network traffic anomaly degree parameter data is smoothed, which is conducive to obtaining a more accurate network traffic anomaly degree assessment coefficient.
[0046] When the power system is unaffected by external factors and operating normally, use a network scanning tool such as a network scanner or network management software to detect which ports of the power system are open on the network. Count the number of open ports to obtain a reference number of ports used by the power system. After a penetration test is performed on the power system, the above process is repeated to obtain the number of ports used by the power system. Use a network traffic monitoring tool such as a network traffic analyzer or a specialized SCADA network monitoring tool to capture and analyze network data packets to identify Modbus protocol traffic, DNP3 protocol traffic, HTTP protocol traffic, and FTP protocol traffic. This results in the Modbus protocol traffic, DNP3 protocol traffic, HTTP protocol traffic, and FTP protocol traffic used by the power system.
[0047] Furthermore, the specific analysis process of analyzing the degree of abnormality of the power system in network traffic based on the network traffic abnormality degree assessment coefficient is as follows: obtaining the network traffic abnormality degree assessment coefficient, obtaining the network traffic abnormality degree threshold, comparing the network traffic abnormality degree assessment coefficient with the network traffic abnormality degree threshold, when the network traffic abnormality degree assessment coefficient is less than the network traffic abnormality degree threshold, it indicates that the power system performs normally in terms of network traffic; when the network traffic abnormality degree assessment coefficient is greater than or equal to the network traffic abnormality degree threshold, it indicates that the power system performs abnormally in terms of network traffic.
[0048] In this embodiment, historical network traffic anomaly degree parameter data is obtained, and historical network traffic anomaly degree assessment coefficients are analyzed based on the historical network traffic anomaly degree parameter data. The network traffic anomaly degree assessment coefficients in the historical network traffic anomaly degree assessment coefficients that indicate that the power system performs normally in terms of network traffic are arranged in order from large to small, and the network traffic anomaly degree assessment coefficient ranked first is used as the network traffic anomaly degree threshold.
[0049] Obtain the network traffic anomaly evaluation coefficient and the network traffic anomaly threshold. The network traffic anomaly threshold is φ, and the value range of φ is [1.65, 1.67]. Compare the network traffic anomaly evaluation coefficient with the network traffic anomaly threshold. When the network traffic anomaly evaluation coefficient is less than the network traffic anomaly threshold, that is, When , it means that the power system is performing normally in terms of network traffic; when the network traffic abnormality evaluation coefficient is greater than or equal to the network traffic abnormality threshold, that is, When , it indicates that the power system is behaving abnormally in terms of network traffic.
[0050] Furthermore, the specific analysis process of the abnormality degree of the power system in terms of system files is as follows: obtaining system file abnormality degree parameter data based on penetration test parameter data; obtaining a system file abnormality degree evaluation index based on the analysis of the system file abnormality degree parameter data, and the system file abnormality degree evaluation index is used to express the abnormality degree of the power system in terms of system files; analyzing the abnormality degree of the power system in terms of system files based on the system file abnormality degree evaluation index.
[0051] In this embodiment, when abnormal file modification or creation occurs in the power system or the system file is damaged, the power system has an abnormality in the system file, and the power system may be at risk of information leakage. Therefore, it is necessary to analyze the power system in terms of system files. Here, the system file abnormality degree parameter data is analyzed to obtain the system file abnormality degree evaluation index, and then the abnormality degree of the power system in terms of system files is analyzed according to the system file abnormality degree evaluation index, making the analysis of the abnormality degree of the power system in terms of system files more accurate.
[0052] The method for obtaining the system file abnormality evaluation index is as follows: obtaining the weight ratio of the number of preset storage configuration files and the number of normally accessible storage configuration files from the database; obtaining system file abnormality parameter data; and constructing a system file abnormality evaluation index calculation formula based on the system file abnormality parameter data. The specific system file abnormality evaluation index calculation formula is:
[0053]
[0054] Where, It is expressed as the system file abnormality evaluation index of the power system at the k0th penetration detection, It is represented by the number of storage configuration files during the k0th penetration test and the h0th data collection. It represents the number of references to the storage configuration files during the k0th penetration test. It is represented by the number of normally accessible storage configuration files during the k0th penetration test and the h0th data collection. It is represented by the reference number of normally accessible storage configuration files in the k0th penetration test, W1 is represented by the weight ratio of the number of storage configuration files in the system file abnormality degree evaluation index, and W2 is represented by the weight ratio of the number of normally accessible storage configuration files in the system file abnormality degree evaluation index.
[0055] The system file abnormality parameter data includes the number of stored configuration files, the number of stored configuration file references, the number of normally accessible stored configuration files, and the number of normally accessible stored configuration file references.
[0056] Based on historical system file anomaly parameter data, a mapping relationship table is created between the number of stored configuration files, the number of normally accessible stored configuration files, and the system file anomaly assessment index. The mapping table is queried based on the real-time number of stored configuration files and the number of normally accessible storage configuration files to determine the weighted ratio of the number of stored configuration files to the number of normally accessible storage configuration files.
[0057] When unusual file modifications or creation occur in a power system, for example, a new file may appear in a directory dedicated to storing configuration files on a power system server during routine monitoring. This file, created outside maintenance hours, could be a compressed file created by an attacker to steal configuration information or a backdoor file for persistent access. If the configuration file contains sensitive information (such as database passwords or system credentials), it could be used to further attack the system. Furthermore, if the file is malware, it could execute arbitrary code within the system. When unusual system file corruption occurs in a power system, it could be caused by hardware failure, software errors, or malicious attacks. In the event of a security incident, an attacker might intentionally tamper with or delete critical files to disrupt the system. System file corruption could prevent the system from booting properly, impacting the stable operation of the power system. Tampering with system files could also lead to unauthorized access or the execution of malicious code.
[0058] Before conducting a penetration test on the power system, the total number of configuration files in the file manager of the power system is searched to obtain the reference number of stored configuration files, and the number of readable files in the reference number of stored configuration files is obtained to obtain the reference number of normally accessible stored configuration files. After conducting the penetration test, the number of stored configuration files and the number of readable files in the stored configuration files of the power system are searched to obtain the number of stored configuration files and the number of normally accessible stored configuration files. In the algorithm of this embodiment, a more accurate system file abnormality evaluation index is obtained by performing a nonlinear transformation on the system file abnormality parameter data using an inverse tangent function, which is conducive to accurately analyzing the abnormality level of the power system in terms of system files based on the system file abnormality evaluation index.
[0059] In a specific embodiment, Figure 2 As shown, this is a curve chart of the system file abnormality evaluation index provided by an embodiment of the present application, with the number of stored configuration files as the independent variable and the system file abnormality evaluation index as the dependent variable. For example, when collecting data once for the third penetration test, through the increase and decrease analysis of curves 1, 2, and 3, it can be seen that when the number of stored configuration files is larger, the system file abnormality evaluation index is larger; when the number of stored configuration files is smaller, the system file abnormality evaluation index is smaller. The statistical table of relevant data of the system file abnormality evaluation index is shown in Table 1:
[0060] Table 1 Statistics of system file abnormality evaluation index
[0061]
[0062]
[0063] When the number of normally accessible storage configuration files for curves 1, 2, and 3 is 45, 44, and 43, respectively, and other parameters are consistent, the system file abnormality assessment indexes for curves 1, 2, and 3 are 0.79, 0.46, and 0.35, respectively. It can be seen that when the number of storage configuration files and other parameters are consistent, the greater the number of normally accessible storage configuration files, the greater the system file abnormality assessment index.
[0064] Furthermore, the specific analysis process of analyzing the abnormality level of the power system in terms of system files based on the system file abnormality level assessment index is as follows: obtaining the system file abnormality level assessment index, obtaining the first system file abnormality level threshold and the second system file abnormality level threshold, comparing the system file abnormality level assessment index with the first system file abnormality level threshold and the second system file abnormality level threshold; when the system file abnormality level assessment index is greater than the first system file abnormality level threshold and less than the second system file abnormality level threshold, it indicates that the power system performs normally in terms of system files; when the system file abnormality level assessment index is less than or equal to the first system file abnormality level threshold or the system file abnormality level assessment index is greater than or equal to the second system file abnormality level threshold, it indicates that the power system performs abnormally in terms of system files.
[0065] In this embodiment, historical system file abnormality degree parameter data is obtained, and the historical system file abnormality degree parameter data includes the historical number of stored configuration files, the number of stored configuration file references, the number of normally accessible storage configuration files, and the number of normally accessible storage configuration file references. A historical system file abnormality degree evaluation index is obtained based on the historical system file abnormality degree parameter data, and the historical system file abnormality degree evaluation index indicating that the power system performs normally in terms of system files is extracted. The historical system file abnormality degree evaluation indexes are arranged in ascending order, and the first and last historical system file abnormality degree evaluation indices are used as the first system file abnormality degree threshold and the second system file abnormality degree threshold.
[0066] Obtain the first threshold value of the system file abnormality level and the second threshold value of the system file abnormality level. The first threshold value of the system file abnormality level and the second threshold value of the system file abnormality level are A1 and A2 respectively. The value range of A1 is [0.74, 0.75], and the value range of A2 is [0.80, 0.81]. Compare the system file abnormality level evaluation index with the first threshold value of the system file abnormality level and the second threshold value of the system file abnormality level. When the system file abnormality level evaluation index is greater than the first threshold value of the system file abnormality level and less than the second threshold value of the system file abnormality level, that is, When , it indicates that the power system is performing normally in terms of system files; when the system file abnormality evaluation index is less than or equal to the first system file abnormality threshold or the system file abnormality evaluation index is greater than or equal to the second system file abnormality threshold, that is, or , it indicates that the power system is behaving abnormally in terms of system files.
[0067] Furthermore, the specific analysis process of the abnormality degree of the power system in terms of vulnerabilities is as follows: obtaining vulnerability safety degree parameter data based on penetration test parameter data; normalizing the vulnerability safety degree parameter data; obtaining a vulnerability safety degree assessment index based on the analysis of the normalized vulnerability safety degree parameter data, the vulnerability safety degree assessment index is used to express the abnormality degree of the power system in terms of vulnerabilities; analyzing the abnormality degree of the power system in terms of vulnerabilities based on the vulnerability safety degree assessment index.
[0068] In this embodiment, the vulnerability security level parameter data is normalized so that the data in the vulnerability security level parameter data maintains the same magnitude and range, making it less prone to errors in the process of calculating the vulnerability security level assessment index, which is conducive to obtaining a more accurate vulnerability security level assessment index.
[0069] As a critical infrastructure, the power system's security vulnerabilities may have a significant impact on national security, the economy, and people's lives. The following are some common cybersecurity vulnerabilities in power systems: Software and system vulnerabilities: Many power systems rely on complex software platforms that may have programming errors or design flaws, providing hackers with attack opportunities. Communication protocol vulnerabilities: The communication protocols in the power system may not be secure enough and may be vulnerable to interception, tampering, or forgery. Weak physical security: Lax physical access control to power infrastructure may lead to security vulnerabilities. For example, unauthorized personnel may be able to access critical equipment. When there are many vulnerabilities in the power system, the power system is very susceptible to external interference.
[0070] The method for obtaining the vulnerability security level assessment index is as follows: obtaining vulnerability security level parameter data; obtaining the preset weight ratio of the number of first-category vulnerabilities, the number of all vulnerabilities, and the number of second-category vulnerabilities from the database; and constructing the vulnerability security level assessment index based on the vulnerability security level parameter data. The specific vulnerability security level assessment index calculation formula is:
[0071]
[0072] Where, It is expressed as the vulnerability security evaluation index of the power system at the k0th penetration detection. It is represented by the number of first-class vulnerabilities in the k0th penetration test at the h0th data collection time, It represents the number of existing vulnerabilities in the power system during the k0th penetration test. It is represented by the total number of vulnerabilities in the k0th penetration test at the h0th data collection time, It is expressed as the number of second-category vulnerabilities in the k0-th penetration test at the h0-th data collection, L1 is expressed as the weight ratio of the number of first-category vulnerabilities in the vulnerability security level assessment index, L2 is expressed as the weight ratio of the total number of vulnerabilities in the vulnerability security level assessment index, and L3 is expressed as the weight ratio of the number of second-category vulnerabilities in the vulnerability security level assessment index.
[0073] The vulnerability safety level parameter data includes the number of first-category vulnerabilities, the number of existing vulnerabilities in the power system, the number of all vulnerabilities, and the number of second-category vulnerabilities.
[0074] Based on historical vulnerability safety parameter data, which includes the historical number of Category 1 vulnerabilities, the number of existing power system vulnerabilities, the number of all vulnerabilities, and the number of Category 2 vulnerabilities, a mapping relationship table is established between the number of Category 1 vulnerabilities, the number of all vulnerabilities, and the vulnerability safety assessment index. The mapping relationship table is queried based on the real-time number of Category 1 vulnerabilities, the number of all vulnerabilities, and the number of Category 2 vulnerabilities to obtain the weighted ratio of the number of Category 1 vulnerabilities, the number of all vulnerabilities, and the number of Category 2 vulnerabilities.
[0075] Before conducting a penetration test on the power system, vulnerability scanning tools are used to detect existing vulnerabilities and count them to obtain the number of existing vulnerabilities in the power system. After the penetration test, vulnerability scanning tools are used to find all vulnerabilities. The total number of all vulnerabilities is counted as the total number of vulnerabilities. Among all the vulnerabilities, the number of vulnerabilities that overlap with the number of existing vulnerabilities in the power system is counted and obtained as the number of first-category vulnerabilities. The number of vulnerabilities that were successfully attacked during the penetration test is counted and obtained as the number of second-category vulnerabilities.
[0076] After a penetration test of a power system, if the total number of vulnerabilities differs significantly from the number of existing vulnerabilities or the number of Category II vulnerabilities, this indicates that the power system has significant vulnerability issues. The algorithm in this embodiment uses a hyperbolic sine function to perform a nonlinear transformation on the vulnerability safety level parameter data, thereby smoothing out the effects of extreme values in the vulnerability safety level parameter data and producing a more accurate vulnerability safety level assessment index.
[0077] Furthermore, the specific analysis process of analyzing the abnormality degree of the power system in terms of vulnerability based on the vulnerability safety degree assessment index is as follows: obtaining the vulnerability safety degree assessment index, obtaining the first vulnerability safety degree threshold and the second vulnerability safety degree threshold; when the vulnerability safety degree assessment index is greater than the first vulnerability safety degree threshold and less than the second vulnerability safety degree threshold, it indicates that the power system behaves normally in terms of vulnerability; when in other situations, it indicates that the power system behaves abnormally in terms of vulnerability.
[0078] In this embodiment, historical vulnerability safety level parameter data is obtained, and a historical vulnerability safety level assessment index is obtained based on the historical vulnerability safety level parameter data. The historical vulnerability safety level assessment index indicating that the power system is performing normally in terms of vulnerability is extracted and arranged in ascending order. The first and last historical vulnerability safety level assessment indexes are used as the first and second vulnerability safety level thresholds.
[0079] Get the vulnerability security level assessment index, get the first vulnerability security level threshold and the second vulnerability security level threshold. When the vulnerability security level assessment index is greater than the first vulnerability security level threshold and less than the second vulnerability security level threshold, that is, When , it means that the power system is normal in terms of vulnerability; when it is in other situations, that is, or When , it means that the power system is behaving abnormally in terms of vulnerability.
[0080] Furthermore, the specific analysis process for analyzing the power system security situation and issuing early warning reminders is as follows: obtaining the power system security situation; when one or more of the power system's abnormal network traffic, abnormal system file performance, and abnormal vulnerability performance occur in the power system security situation, it indicates that the power system is operating normally and no early warning reminder is issued; when two or more of the power system's abnormal network traffic, abnormal system file performance, and abnormal vulnerability performance occur in the power system security situation, it indicates that the power system is abnormal and an early warning reminder is issued.
[0081] In this embodiment, when one or more of the following situations occur in the power system safety situation: the power system behaves abnormally in terms of network traffic, the power system behaves abnormally in terms of system files, and the power system behaves abnormally in terms of vulnerabilities, it indicates that the power system may be affected by slight external abnormalities, but does not affect the operation of the power system, indicating that the power system is operating normally and no early warning reminder is issued; when two or more of the following situations occur in the power system safety situation: the power system behaves abnormally in terms of network traffic, the power system behaves abnormally in terms of system files, and the power system behaves abnormally in terms of vulnerabilities, it indicates that the power system may be affected by serious external abnormalities, affecting the operation of the power system, indicating that the power system is abnormal and an early warning reminder is issued.
[0082] like Figure 3 As shown, it is a structural diagram of an intelligent penetration detection system for an electric power system provided in an embodiment of the present application. An intelligent penetration detection system for an electric power system provided in an embodiment of the present application includes: a penetration testing module, a parameter acquisition module, a data processing module and an early warning analysis module; wherein, the penetration testing module is used to perform penetration testing on the electric power system; the parameter acquisition module is used to monitor and obtain penetration testing parameter data during the penetration testing process; the data processing module is used to perform data processing on the penetration testing parameter data; the early warning analysis module is used to analyze the security situation of the electric power system according to the penetration testing parameter data after data processing and to issue early warning reminders.
[0083] In this embodiment, the parameter acquisition module stores the power system security status and penetration test parameter data. The power system security status includes: the abnormality degree of the power system in network traffic, the abnormality degree of the power system in system files, and the abnormality degree of the power system in vulnerabilities; the penetration test parameter data includes network traffic abnormality degree parameter data, system file abnormality degree parameter data, and vulnerability security degree parameter data.
[0084] The early warning analysis module analyzes the security situation of the power system based on the penetration test parameter data after data processing, that is, it analyzes the abnormality of the power system in network traffic, the abnormality of the power system in system files and the abnormality of the power system in vulnerabilities through the network traffic abnormality parameter data, system file abnormality parameter data and vulnerability security parameter data after data processing, thereby analyzing the security situation of the power system and issuing early warning reminders.
[0085] The technical solution in the above-mentioned embodiment of the present application obtains network traffic anomaly degree parameter data based on penetration test parameter data, analyzes the network traffic anomaly degree parameter data to obtain a network traffic anomaly degree evaluation coefficient, and then analyzes the abnormality degree of the power system in network traffic based on the network traffic anomaly degree evaluation coefficient, thereby realizing a detailed and accurate analysis of the abnormality degree of the power system in network traffic.
[0086] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0087] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0088] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0089] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0090] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0091] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. An intelligent penetration detection method for power system, characterized in that: The following steps are involved: Conduct penetration testing of power systems; Monitor and obtain penetration test parameter data during the penetration test; Performing data processing on the penetration test parameter data; Analyze the power system security situation based on the penetration test parameter data after data processing and issue early warning reminders; The power system security conditions include: Analyzing the network flow anomaly degree parameter data to obtain a network flow anomaly degree evaluation coefficient, wherein the network flow anomaly degree evaluation coefficient is used to reflect the degree of abnormality of the power system in terms of network flow; Analyze the abnormality of the power system in terms of network traffic according to the network traffic abnormality evaluation coefficient; The network traffic anomaly degree parameter data includes the number of ports used by the power system, the reference number of ports used by the power system, the Modbus protocol traffic used by the power system, the DNP3 protocol traffic used by the power system, the HTTP protocol traffic used by the power system, and the FTP protocol traffic used by the power system; The specific analysis process of the abnormality degree of the power system in terms of system files is as follows: Obtaining a system file abnormality degree evaluation index based on system file abnormality degree parameter data analysis, wherein the system file abnormality degree evaluation index is used to represent the abnormality degree of the power system in terms of system files; Analyze the abnormality level of the power system in terms of system files based on the system file abnormality evaluation index; The system file abnormality parameter data includes the number of stored configuration files, the number of stored configuration file references, the number of normally accessible stored configuration files, and the number of normally accessible stored configuration file references; The specific analysis process of analyzing the abnormality degree of the power system in terms of system files according to the system file abnormality degree evaluation index is as follows: When the system file abnormality evaluation index is less than or equal to the first system file abnormality evaluation index or the system file abnormality evaluation index is greater than or equal to the second system file abnormality evaluation index, it indicates that the power system has abnormal performance in terms of system files; The specific analysis process of the abnormality degree of the power system in terms of vulnerability is as follows: Obtaining a vulnerability safety degree assessment index based on the normalized vulnerability safety degree parameter data analysis, wherein the vulnerability safety degree assessment index is used to represent the abnormality degree of the power system in terms of vulnerability; Analyze the abnormality level of power system vulnerability based on vulnerability safety assessment index; The vulnerability safety parameter data includes the number of first-category vulnerabilities, the number of existing vulnerabilities in the power system, the number of all vulnerabilities, and the number of second-category vulnerabilities; The specific analysis process of analyzing the abnormality degree of the power system in terms of vulnerability according to the vulnerability safety degree assessment index is as follows: Obtaining a vulnerability safety level assessment index, a first vulnerability safety level threshold, and a second vulnerability safety level threshold. When the vulnerability safety level assessment index is greater than the first vulnerability safety level threshold and less than the second vulnerability safety level threshold, it indicates that the power system is performing normally in terms of vulnerability. When in other situations, it means that the power system behaves abnormally in terms of vulnerability; The specific analysis process of analyzing the power system security situation and issuing early warning reminders is as follows: When two or more of the following situations occur in the power system security situation: abnormal network traffic, abnormal system files, and abnormal vulnerabilities, it means that the power system is abnormal and an early warning alert is issued; The calculation formula for the system file abnormality evaluation index is: Where, It is expressed as the system file abnormality evaluation index of the power system at the k0th penetration detection, It is represented by the number of storage configuration files during the k0th penetration test and the h0th data collection. It represents the number of references to the storage configuration files during the k0th penetration test. It is represented by the number of normally accessible storage configuration files during the k0th penetration test and the h0th data collection. It represents the reference number of normally accessible storage configuration files in the k0th penetration test, W1 represents the weight ratio of the number of storage configuration files in the system file abnormality evaluation index, and W2 represents the weight ratio of the number of normally accessible storage configuration files in the system file abnormality evaluation index; The calculation formula for the vulnerability security level assessment index is: Where, It is expressed as the vulnerability security evaluation index of the power system at the k0th penetration detection. It is expressed as the number of first-class vulnerabilities in the k0th penetration test at the h0th data collection time, It represents the number of existing vulnerabilities in the power system during the k0th penetration test. It is represented by the total number of vulnerabilities in the k0th penetration test at the h0th data collection time, It is expressed as the number of second-category vulnerabilities in the k0-th penetration test at the h0-th data collection, L1 is expressed as the weight ratio of the number of first-category vulnerabilities in the vulnerability security level assessment index, L2 is expressed as the weight ratio of the total number of vulnerabilities in the vulnerability security level assessment index, and L3 is expressed as the weight ratio of the number of second-category vulnerabilities in the vulnerability security level assessment index.
2. The intelligent penetration detection method for a power system according to claim 1, characterized in that: The power system security situation also includes: the abnormality degree of the power system in terms of network traffic, the abnormality degree of the power system in terms of system files, and the abnormality degree of the power system in terms of vulnerabilities; The penetration test parameter data includes network traffic abnormality parameter data, system file abnormality parameter data and vulnerability security parameter data; The specific analysis process of the abnormality degree of the power system in terms of network traffic is as follows: The network traffic anomaly degree parameter data is obtained based on the penetration test parameter data.
3. The intelligent penetration detection method for a power system according to claim 2, characterized in that: The specific analysis process of analyzing the abnormality degree of the power system in terms of network traffic according to the network traffic abnormality degree evaluation coefficient is as follows: Obtaining a network traffic anomaly degree assessment coefficient, obtaining a network traffic anomaly degree threshold, and comparing the network traffic anomaly degree assessment coefficient with the network traffic anomaly degree threshold. When the network traffic anomaly degree assessment coefficient is less than the network traffic anomaly degree threshold, it indicates that the power system is performing normally in terms of network traffic. When the network traffic anomaly degree assessment coefficient is greater than or equal to the network traffic anomaly degree threshold, it indicates that the power system exhibits abnormal network traffic.
4. The intelligent penetration detection method for a power system according to claim 2, characterized in that: The specific analysis process of the abnormality level of the power system in terms of system files also includes: Obtain system file abnormality parameter data based on penetration test parameter data.
5. The intelligent penetration detection method for a power system according to claim 4, characterized in that: The specific analysis process of analyzing the abnormality degree of the power system in terms of system files according to the system file abnormality degree evaluation index also includes: Obtain a system file abnormality degree assessment index, obtain a first system file abnormality degree threshold and a second system file abnormality degree threshold, compare the system file abnormality degree assessment index with the first system file abnormality degree threshold and the second system file abnormality degree threshold; when the system file abnormality degree assessment index is greater than the first system file abnormality degree threshold and less than the second system file abnormality degree threshold, it indicates that the power system performs normally in terms of system files.
6. The intelligent penetration detection method for a power system according to claim 2, characterized in that: The specific analysis process of the abnormality degree of the power system in terms of vulnerability also includes: Obtain vulnerability security parameter data based on penetration test parameter data; Normalize the vulnerability security level parameter data.
7. The intelligent penetration detection method for a power system according to claim 1, characterized in that: The specific analysis process of analyzing the power system security situation and issuing early warning reminders also includes: Obtain power system security status; When one or more of the following situations occur in the power system security situation, such as abnormal network traffic, abnormal system files, and abnormal vulnerabilities, it means that the power system is operating normally and no early warning reminder is issued.
8. The intelligent penetration detection method for a power system according to claim 1, characterized in that: The specific method for obtaining the network traffic anomaly degree evaluation coefficient is as follows: Perform penetration testing on the power system, obtain the number of penetration testing times, and number the penetration testing times; During each penetration test, multiple data acquisitions are performed and the data acquisition times are numbered; Obtaining from the database the preset number of ports used by the power system and the weight ratio of HTTP protocol traffic used by the power system and FTP protocol traffic used by the power system; Obtain parameter data on the degree of abnormality of network traffic; Construct a network traffic anomaly degree evaluation coefficient calculation formula based on network traffic anomaly degree parameter data; The specific calculation formula for the network traffic anomaly evaluation coefficient is: Where, It is represented as the evaluation coefficient of the abnormal degree of network traffic in the power system at the k0th penetration test, k0=1,2,...,k, k0 represents the number of penetration tests, k represents the total number of penetration tests, It represents the number of ports used in the power system during the k0th penetration test at the h0th data collection time, h0=1,2,...,h, h0 represents the number of data acquisition times, h represents the total number of data acquisition times, It is represented as the reference number of ports used by the power system during the k0th penetration test of the power system. It represents the Modbus protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the DNP3 protocol traffic of the power system during the k0th penetration test and the h0th data collection. It represents the HTTP protocol traffic used by the power system during the k0th penetration test and the h0th data collection. It represents the FTP protocol traffic used by the power system during the k0th penetration detection at the h0th data collection time. D1 represents the weight ratio of the number of ports used by the power system in the network traffic anomaly evaluation coefficient. D2 represents the weight ratio of the HTTP protocol traffic used by the power system and the FTP protocol traffic used by the power system in the network traffic anomaly evaluation coefficient.
9. An intelligent penetration detection system for power systems, characterized in that: The intelligent penetration detection system is used to execute the intelligent penetration detection method for a power system according to any one of claims 1 to 8, and the system includes: a penetration testing module, a parameter acquisition module, a data processing module and an early warning analysis module; Wherein, the penetration test module is used to perform penetration testing on the power system; The parameter acquisition module is used to monitor and obtain penetration test parameter data during the penetration test process; The data processing module is used to process the penetration test parameter data; The early warning analysis module is used to analyze the safety status of the power system based on the penetration test parameter data after data processing and provide early warning reminders.
Citation Information
Patent Citations
A Penetration Attack Method for an AI-Based Automated Penetration Testing System
CN111475818B
Rapid penetration testing method and testing device for mobile equipment
CN115659348A
Security detecting method of automatic power dispatching system
CN107612927A
Abnormal data detection method and abnormal data detection device
CN118034979A
Computer network security monitoring system and method
CN118101331A