A Threat Alert Semantic Analysis System for Power Grid Network Security
By designing a threat alarm semantic analysis system for power grid network security, the shortcomings of existing systems in data acquisition and analysis are solved, the accuracy of threat alarm data and the overall efficiency of the system are improved, and the stability and security of power grid network security are ensured.
Patent Information
- Application Number
- CN202411218971.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-02
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2044-09-02
AI Technical Summary
The existing threat alarm semantic analysis system for power grid network security has problems such as insufficient data collection and analysis, errors and data loss during analysis, and lack of comprehensive mathematical models, resulting in reduced accuracy of threat alarm data.
A threat alarm semantic analysis system including detection time area division module, threat alarm data acquisition module, threat alarm data analysis module, comprehensive data processing module, comprehensive data judgment module and early warning module are designed. By dividing the detection time area into multiple sub-regions, collecting and analyzing various types of data, establishing a comprehensive data processing model, calculating safety evaluation values, and issuing early warning signals in a timely manner through the early warning module.
It improves the overall efficiency of threat alarm security, reduces errors in data collection and analysis, enhances the accuracy of threat alarm data, makes the system more intuitive and efficient, and ensures the stability and security of power grid network security.
Smart Images

Figure CN119299126B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and more specifically, to a threat warning semantic analysis system for power grid network security. Background Art
[0002] With the rise of cloud computing, the Internet of Things and mobile Internet, network security faces new challenges and is becoming increasingly important. Network security technology is a series of technical means and methods used to protect computer networks and network systems from unauthorized access, damage or interference. It aims to ensure the confidentiality, integrity and security of the network, and protect data and systems on the network from attacks and malicious behavior.
[0003] An existing threat alarm semantic analysis system for power grid network security mainly includes an alarm data collection module, an alarm data analysis module and a network security information discrimination module; the alarm data collection module mainly collects some threat alarm data through existing tools; the alarm data analysis module converts non-digital parameters into digitized alarm analysis parameters to make system analysis more convenient; the network security information discrimination module accurately judges the existing data through the security assessment data of previous years, and finally illustrates the safety and reliability of the system.
[0004] However, it still has some shortcomings in actual use. For example, in data collection, some threat alarm data are collected, which easily leads to the collected data being not comprehensive enough; in data analysis, the collected data is analyzed and processed, but when the existing technology analyzes and processes large amounts of data, errors and data loss will occur, and an island phenomenon will occur, which reduces the accuracy of the threat alarm data; the existing method lacks a comprehensive mathematical model to judge the parameters of network security threat alarms, which makes the analysis not intuitive and efficient enough, increases the consumption of manpower, material resources and time, and brings inconvenience to Internet companies.
[0005] There is an urgent need for a threat alert semantic analysis system for power grid network security. Summary of the invention
[0006] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a threat alarm semantic analysis system for power grid network security, which solves the problems raised in the above-mentioned background technology through the field of network security technology.
[0007] To achieve the above object, the present invention provides the following technical solution: a threat warning semantic analysis system for power grid network security, comprising:
[0008] Detection time area division module: used to divide the target detection time area of the threat alarm into various detection time sub-areas according to the equal time division method, and number each detection time sub-area in the target time area as i=1, 2, ..., n in sequence;
[0009] Threat alarm data collection module: used to collect various types of data in a time sub-area in the detection time area division, and transmit the collected various types of data to the threat alarm data analysis module; collect data of each time sub-area through a threat feature data collection unit and a defense feature collection unit; the threat feature data collection unit is used to collect attack target data, system leakage data and system damage data of each time sub-area; the defense feature collection unit is used to collect detection strategy data and vulnerability repair data of each time sub-area;
[0010] The threat alarm data analysis module: includes a threat feature data calculation unit and a defense feature calculation unit, which are used to analyze the data transmitted by the threat feature data collection unit and the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module; the threat feature data calculation unit is used to analyze various types of data transmitted by the threat feature data collection unit, and transmit the analysis results to the comprehensive data processing module; the threat feature data calculation unit includes an attack target data calculation subunit, a system leakage data calculation subunit and a system damage data calculation subunit; the defense feature calculation unit is used to analyze various types of data transmitted by the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module; the defense feature calculation unit includes a detection strategy data calculation subunit and a vulnerability repair data calculation subunit;
[0011] Comprehensive data processing module: used to establish a comprehensive data processing model, import the data transmitted by the threat alarm data analysis module into the comprehensive data processing model, calculate the security assessment value of the target time area, and transmit it to the comprehensive data identification module;
[0012] Comprehensive data judgment module: used to accurately compare the safety assessment value of the target time area with the safety assessment value of the preset target time area during the actual operation process, and transmit the judgment result to the early warning module;
[0013] Early warning module: used to receive the data transmitted by the comprehensive data identification module and send corresponding early warning signals to relevant management personnel for processing.
[0014] Preferably, the attack target data includes the number of failed logins to the target server, the number of traffic anomalies at the target network node, and the number of times the target database is accessed, which are respectively recorded as Gs, Gl, and Gf; the system leakage data includes the number of pieces of personal sensitive information, the capacity of the target enterprise's confidential data stolen (generally in GB), and the number of illegal user accesses, which are respectively recorded as Sx, Sq, and Sh; the system damage data includes the number of operating system damages, the number of VPN services attacked, and the number of system hardware device failures, which are respectively recorded as Xs, Xg, and Xz.
[0015] Preferably, the detection strategy data includes the number of system firewall updates, the number of false alarms of intrusion into the system, and the number of successful attacks intercepted by the system, which are respectively denoted as Jg, Jw, and Je; the vulnerability repair data includes the number of high-risk vulnerabilities, the number of recurrences of repaired vulnerabilities, and the vulnerability patch installation rate, which are respectively denoted as Lg, Ly, and Lb.
[0016] Preferably, the attack target data calculation subunit is used to establish an attack target data mathematical model, import the attack target data transmitted by the threat feature data acquisition unit into the attack target data mathematical model, and calculate the attack target coefficient value of each time sub-area, which is specifically expressed as:
[0017]
[0018] GA i represents the attack target coefficient value of the i-th time sub-area, Gs i Indicates the number of failed logins to the target server in the i-th time sub-region, Gs max Indicates the maximum number of failed logins to the target server in the target time sub-zone, Dl i-1 represents the number of traffic anomalies of the target network node in the i-1th time sub-area, Dl i Gf represents the number of traffic anomalies of the target network node in the i-th time sub-region, i It indicates the number of times the target database in the i-th time sub-region is accessed, and n indicates the number of sub-time sub-regions.
[0019] Preferably, the system leakage data calculation subunit is used to establish a system leakage data mathematical model, import the system leakage data transmitted by the threat feature data acquisition unit into the system leakage data mathematical model, and calculate the system leakage coefficient value of each time sub-area, which is specifically expressed as:
[0020]
[0021] SA i Represents the system leakage coefficient value of the i-th time sub-area, Sx i-1Sx represents the number of sensitive personal information in the i-1th time sub-region. i represents the number of sensitive personal information in the i-th time sub-region, Sq max The amount of confidential data stolen from the target enterprise in the target time sub-region, Sq i Sh represents the amount of confidential data stolen from the target enterprise in the i-th time sub-region. i It represents the number of illegal accesses by users in the i-th time sub-area, and n represents the number of sub-time areas.
[0022] Preferably, the system damage data calculation subunit is used to establish a system damage data mathematical model, import the system damage data transmitted by the threat feature data acquisition unit into the system damage data mathematical model, and calculate the system damage data coefficient value of each time sub-area, which is specifically expressed as:
[0023]
[0024] XA i represents the system damage data coefficient value of the i-th time sub-region, Xs i represents the number of operating system failures in the i-th time sub-region, Xg i-1 represents the number of times the VPN service in the i-1th time sub-region is attacked, Xg i represents the number of times the VPN service in the i-th time sub-region is attacked, Xz i represents the number of system hardware failures in the i-th time sub-region, Xz max It represents the maximum number of system hardware failures in the target time zone, n represents the number of sub-time zones, and α represents the fitting parameter value of the operating system damage, which ranges from [1,2).
[0025] Preferably, the detection strategy data calculation subunit is used to establish a detection strategy data mathematical model, import the detection strategy data transmitted by the defense feature acquisition unit into the detection strategy data mathematical model, and calculate the detection strategy coefficient value of each time sub-area, which is specifically expressed as:
[0026]
[0027] J A i represents the detection strategy coefficient value of the i-th time sub-region, Jg i represents the number of system firewall updates in the i-th time sub-area, Jw i represents the number of false alarms of the intrusion system in the i-th time sub-area, Je i represents the number of successful interception attacks by the system in the i-th time sub-area, Je maxIt represents the maximum number of successful interception attacks by the system in the target time sub-zone, and n represents the number of sub-time zones.
[0028] Preferably, the vulnerability repair data calculation subunit is used to establish a vulnerability repair data mathematical model, import the vulnerability repair data transmitted by the defense feature collection unit into the vulnerability repair data mathematical model, and calculate the vulnerability repair coefficient value of each time sub-area, which is specifically expressed as:
[0029]
[0030] LA i Indicates the vulnerability repair coefficient value of the i-th time sub-area, Lg i represents the number of high-risk vulnerabilities in the i-th time sub-area, Ly i represents the number of recurrences of the fixed vulnerability in the i-th time sub-region, Lb i represents the vulnerability patch installation rate of the i-th time sub-region, σ represents the fitting parameter value of the vulnerability repair, which ranges from [1,1.5), and n represents the number of sub-time regions.
[0031] Preferably, the comprehensive data processing model is obtained in the following manner:
[0032]
[0033] Where η represents the safety assessment value of the target time zone, γ i represents the characteristic value of the threat feature data of the i-th time sub-region, λ i represents the information security defense characteristic value of the i-th time sub-region, ζ i represents the safety assessment value of the i-th time sub-area, μ represents the mean of the safety assessment values of the target area, where i=1, 2, ..., n.
[0034] Preferably, the safety assessment value of the preset target time zone is recorded as η def , the safety assessment value of the target time area is accurately compared with the safety assessment value of the preset target time area during the actual operation. The specific calculation formula is:
[0035]
[0036] P safe The safety index P of the target time zone safe Indicates the safety index of the target time zone. According to the safety index P of the target time zone safe When P safe ≤0.25, a safety signal is issued. safe When >0.25, a warning signal is issued.
[0037] Technical effects and advantages of the present invention:
[0038] 1. The present invention can more effectively and accurately detect the data in each time period through the detection time area division module, thereby improving the overall efficiency of threat alarm security. Managers can more intuitively understand the attack situation of threat alarms in each time area, discover problems in time and take measures to solve them; through the threat alarm data collection module, detailed and accurate threat alarm data can be obtained, greatly reducing errors and improving accuracy;
[0039] 2. The present invention establishes a mathematical model through a threat alarm data analysis module to conduct in-depth analysis of the collected data. These analyses are conducive to identifying potential problems of threat alarms and provide an important basis for the subsequent system to implement threat alarm semantic analysis; a comprehensive data processing model is established through a comprehensive data processing module, and the data transmitted by the threat alarm data analysis module is imported into the comprehensive data processing model to calculate the security assessment value of the target time zone, so that the threat alarm semantic analysis system gives people a more intuitive effect;
[0040] 3. Through the comprehensive data identification module, the security assessment value of the target time zone is accurately compared with the security assessment value of the preset target time zone in the actual operation process, and the security index is divided into security levels to make the identification more accurate and intuitive; through the early warning module, the threat warning data and other attack risks can be discovered in time to avoid system freezes and freezes, and problems can be quickly discovered and handled to ensure the stability and security of the threat warning semantic analysis system; BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a schematic diagram of the overall structure of the present invention. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] As attached Figure 1 Shown in the figure is a threat alarm semantic analysis system for power grid network security, including a detection time area division module, a threat alarm data acquisition module, a threat alarm data analysis module, a comprehensive data processing module, a comprehensive data judgment module and an early warning module.
[0044] The output end of the detection time area division module is connected to the input end of the threat alarm data acquisition module, the output end of the threat alarm data acquisition module is connected to the input end of the threat alarm data analysis module, the output end of the threat alarm data analysis module is connected to the input end of the comprehensive data processing module, the output end of the comprehensive data processing module is connected to the input end of the comprehensive data discrimination module, and the output end of the comprehensive data discrimination module is connected to the input end of the early warning module.
[0045] The detection time area division module is used to divide the target detection time area of the threat alarm into various detection time sub-areas according to an equal time division method, and number the various detection time sub-areas in the target time area as i=1, 2, ..., n in sequence.
[0046] In this embodiment, it is specifically necessary to explain that a dedicated counter is installed in the hardware device of the system to preset the time interval, and a suitable time division precision is selected according to the actual requirements of the threat alarm semantics of the power grid network security, including every day, every hour, every half hour and every minute.
[0047] The threat alarm data collection module is used to collect various types of data in a time sub-area in the detection time area division, and transmit the collected various types of data to the threat alarm data analysis module; the data of each time sub-area is collected through the threat feature data collection unit and the defense feature collection unit.
[0048] The threat feature data collection unit is used to collect attack target data, system leakage data and system damage data in each time sub-area.
[0049] In this embodiment, it should be specifically explained that the attack target data includes the number of failed logins to the target server, the number of traffic anomalies at the target network node, and the number of times the target database is accessed, which are respectively recorded as Gs, Gl, and Gf; the system leakage data includes the number of pieces of personal sensitive information, the capacity of the target enterprise's confidential data stolen (generally in GB), and the number of illegal accesses by users, which are respectively recorded as Sx, Sq, and Sh; the system damage data includes the number of operating system damages, the number of VPN services attacked, and the number of system hardware device failures, which are respectively recorded as Xs, Xg, and Xz.
[0050] The method includes installing Splunk on an independent server or virtual machine to detect the number of failed logins to the target server, directly installing a system log analysis tool (Wireshark) on a network management server to monitor the number of traffic anomalies of the target network node, installing a traffic monitoring tool (Imperva SecureSphere) on an independent server connected to a database server to detect the number of times the target database is accessed; installing a data leakage prevention (DLP) tool (Symantec DLP) on a gateway device at a network exit to detect the number of pieces of personal sensitive information, installing a data audit and monitoring tool (McAfee ePolicy Orchestrator) in the network where a data storage server is located to detect the capacity of confidential data of the target enterprise being stolen, and installing Okta on the enterprise's authentication server, an IDS, at a key node of the network; installing a system monitoring tool (Nagios) on an independent monitoring server to detect the number of operating system damages, installing a network security monitoring tool (FortiAnalyzer) on an independent server to detect the number of times a VPN service is attacked, and usually installing Dell OpenManage at the management interface of the hardware device to detect the number of system hardware device failures.
[0051] The defense feature collection unit is used to collect detection strategy data and vulnerability repair data for each time sub-area.
[0052] In this embodiment, it should be specifically noted that the detection strategy data includes the number of system firewall updates, the number of false alarms of intrusion into the system, and the number of successful attacks intercepted by the system, which are respectively recorded as Jg, Jw, and Je; the vulnerability repair data includes the number of high-risk vulnerabilities, the number of recurrences of repaired vulnerabilities, and the vulnerability patch installation rate, which are respectively recorded as Lg, Ly, and Lb;
[0053] The method is described by installing a network monitoring tool (SolarWinds Network) on an independent server to detect the number of firewall updates, and installing the reporting and analysis tools provided by the intrusion detection / prevention system (IDS / IPS) on a dedicated server to detect the number of false alarms of intrusion into the system and the number of successful attacks intercepted by the system; installing a vulnerability scanning tool (Nessus) on an independent server to detect the number of high-risk vulnerabilities and the number of recurrences of fixed vulnerabilities, and installing a system management tool on the server to detect the vulnerability patch installation rate.
[0054] The threat warning data analysis module includes a threat feature data calculation unit and a defense feature calculation unit, which are used to analyze the data transmitted by the threat feature data collection unit and the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module.
[0055] The threat feature data calculation unit is used to analyze various types of data transmitted by the threat feature data collection unit, and transmit the analysis results to the comprehensive data processing module; the threat feature data calculation unit includes an attack target data calculation subunit, a system leakage data calculation subunit and a system damage data calculation subunit.
[0056] In this embodiment, it should be specifically explained that the attack target data calculation subunit is used to establish an attack target data mathematical model, import the attack target data transmitted by the threat feature data acquisition unit into the attack target data mathematical model, and calculate the attack target coefficient value of each time sub-region, which is specifically expressed as:
[0057]
[0058] GA i represents the attack target coefficient value of the i-th time sub-area, Gs i Indicates the number of failed logins to the target server in the i-th time sub-region, Gs max Indicates the maximum number of failed logins to the target server in the target time sub-zone, Dl i-1 represents the number of traffic anomalies of the target network node in the i-1th time sub-area, Dl i Gf represents the number of traffic anomalies of the target network node in the i-th time sub-region, i It indicates the number of times the target database in the i-th time sub-region is accessed, and n indicates the number of sub-time sub-regions.
[0059] In this embodiment, it should be specifically explained that the system leakage data calculation subunit is used to establish a system leakage data mathematical model, import the system leakage data transmitted by the threat feature data acquisition unit into the system leakage data mathematical model, and calculate the system leakage coefficient value of each time sub-area, which is specifically expressed as:
[0060]
[0061] SA i Represents the system leakage coefficient value of the i-th time sub-area, Sx i-1 Sx represents the number of sensitive personal information in the i-1th time sub-region. i represents the number of sensitive personal information in the i-th time sub-region, Sq max The amount of confidential data stolen from the target enterprise in the target time sub-region, Sq i Sh represents the amount of confidential data stolen from the target enterprise in the i-th time sub-region. i It represents the number of illegal accesses by users in the i-th time sub-area, and n represents the number of sub-time areas.
[0062] In this embodiment, it should be specifically explained that the system damage data calculation subunit is used to establish a system damage data mathematical model, import the system damage data transmitted by the threat feature data acquisition unit into the system damage data mathematical model, and calculate the system damage data coefficient value of each time sub-region, which is specifically expressed as:
[0063]
[0064] XA i represents the system damage data coefficient value of the i-th time sub-region, Xs i represents the number of operating system failures in the i-th time sub-region, Xg i-1 represents the number of times the VPN service in the i-1th time sub-region is attacked, Xg i represents the number of times the VPN service in the i-th time sub-region is attacked, Xz i represents the number of system hardware failures in the i-th time sub-region, Xz max It represents the maximum number of system hardware failures in the target time zone, n represents the number of sub-time zones, and α represents the fitting parameter value of the operating system damage, which ranges from [1,2).
[0065] The threat feature data acquisition unit establishes a threat feature data mathematical model through the attack target coefficient value of the i-th time sub-region, the system leakage coefficient value of the i-th time sub-region, and the system damage data coefficient value of the i-th time sub-region to obtain the threat feature data characteristic value of the i-th time sub-region, which is specifically expressed as: γ i =(GA i +SA i +XA i )×β 1 , G.A. i represents the attack target coefficient value of the i-th time sub-area, SA i represents the system leakage coefficient value of the i-th time sub-area, XA i Indicates the system damage data coefficient value, γ i represents the characteristic value of the threat feature data of the i-th time sub-region, β i Represents the fitting coefficient of the eigenvalue of the threat signature data.
[0066] The defense feature calculation unit is used to analyze various types of data transmitted by the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module; the defense feature calculation unit includes a detection strategy data calculation subunit and a vulnerability repair data calculation subunit.
[0067] In this embodiment, it should be specifically explained that the detection strategy data calculation subunit is used to establish a detection strategy data mathematical model, import the detection strategy data transmitted by the defense feature acquisition unit into the detection strategy data mathematical model, and calculate the detection strategy coefficient value of each time sub-area, which is specifically expressed as:
[0068]
[0069] J A i represents the detection strategy coefficient value of the i-th time sub-region, Jg i represents the number of system firewall updates in the i-th time sub-area, Jw i represents the number of false alarms of the intrusion system in the i-th time sub-area, Je i represents the number of successful interception attacks by the system in the i-th time sub-area, Je max It represents the maximum number of successful interception attacks by the system in the target time sub-zone, and n represents the number of sub-time zones.
[0070] In this embodiment, it should be specifically explained that the vulnerability repair data calculation subunit is used to establish a vulnerability repair data mathematical model, import the vulnerability repair data transmitted by the defense feature collection unit into the vulnerability repair data mathematical model, and calculate the vulnerability repair coefficient value of each time sub-area, which is specifically expressed as:
[0071]
[0072] LA i Indicates the vulnerability repair coefficient value of the i-th time sub-area, Lg i represents the number of high-risk vulnerabilities in the i-th time sub-area, Ly i represents the number of recurrences of the fixed vulnerability in the i-th time sub-region, Lb i represents the vulnerability patch installation rate of the i-th time sub-region, σ represents the fitting parameter value of the vulnerability repair, which ranges from [1,1.5), and n represents the number of sub-time regions.
[0073] The defense feature calculation unit establishes a mathematical model through the detection strategy coefficient value of the i-th time sub-region and the vulnerability repair coefficient value of the i-th time sub-region to calculate the information security defense feature value of the i-th time sub-region, which is specifically expressed as: i =(JA i +LA i )×β 2 ,λ i represents the information security defense characteristic value of the i-th time sub-region, β 2 Represents the fitting coefficient of the information security defense eigenvalue.
[0074] The comprehensive data processing module is used to establish a comprehensive data processing model, import the data transmitted by the threat alarm data analysis module into the comprehensive data processing model, calculate the security assessment value of the target time area, and transmit it to the comprehensive data identification module.
[0075] In this embodiment, it should be specifically explained that the method for obtaining the comprehensive data processing model is:
[0076]
[0077] Where η represents the safety assessment value of the target time zone, γ i represents the characteristic value of the threat feature data of the i-th time sub-region, λ i represents the information security defense characteristic value of the i-th time sub-region, ζ i represents the safety assessment value of the i-th time sub-area, μ represents the mean of the safety assessment values of the target area, where i=1, 2, ..., n.
[0078] The comprehensive data identification module is used to accurately compare the safety assessment value of the target time zone with the safety assessment value of the preset target time zone during the actual operation process, and transmit the judgment result to the early warning module.
[0079] In this embodiment, it should be specifically noted that the safety assessment value of the preset target time zone is denoted as η def , the safety assessment value of the target time area is accurately compared with the safety assessment value of the preset target time area during the actual operation. The specific calculation formula is:
[0080]
[0081] P safe The safety index of the target time zone and the safety level corresponding to the safety factor are shown in Table 1:
[0082] <![CDATA[P safe ]]> <![CDATA[P safe =0]]> <![CDATA[0<P safe ≤0.25]]> <![CDATA[0.25<P safe ≤0.6]]> <![CDATA[0.6<P safe ≤1]]> Security Level Very safe Safety Unsafe Very unsafe
[0083] Table 1
[0084] According to the safety index P of the target time zone safe When P safe When ≤0.25, it means that no threat alarm occurs and the system is in a safe state. safe When >0.25, it indicates that a threat alarm has occurred and the system is in an unsafe state.
[0085] The early warning module is used to receive the data transmitted by the comprehensive data identification module and send a corresponding early warning signal to relevant management personnel for processing.
[0086] The present invention can more effectively perform more accurate detection on the data in each time period through the detection time area division module, thereby improving the overall efficiency of threat alarm security, and managers can more intuitively understand the attack situation of threat alarms in each time period, discover problems in time and take measures to solve them; through the threat alarm data acquisition module, detailed and accurate threat alarm data of various types can be obtained, greatly reducing errors and improving accuracy; through the threat alarm data analysis module, a mathematical model is established to conduct in-depth analysis of the collected data, which is conducive to identifying potential problems of threat alarms and providing an important basis for the subsequent system to realize threat alarm semantic analysis; through comprehensive data The processing module establishes a comprehensive data processing model, imports the data transmitted by the threat alarm data analysis module into the comprehensive data processing model, and calculates the security assessment value of the target time area, making the threat alarm semantic analysis system more intuitive; through the comprehensive data judgment module, the security assessment value of the target time area is accurately compared with the security assessment value of the preset target time area during the actual operation, and the security index is divided into security levels to make the judgment more accurate and intuitive; through the early warning module, it can timely discover attack risks such as threat alarm data, avoid system freezes and freezes, quickly discover and deal with problems, and ensure the stability and security of the threat alarm semantic analysis system.
[0087] Secondly, in the drawings of the embodiments disclosed in the present invention, only the structures related to the embodiments disclosed in the present invention are involved, and other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of the present invention can be combined with each other;
[0088] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A threat warning semantic analysis system for power grid network security, characterized in that: include: Detection time area division module: used to divide the target detection time area of the threat alarm into various detection time sub-areas according to the equal time division method, and number each detection time sub-area in the target time area as i=1, 2, ..., n in sequence; Threat alarm data collection module: used to collect various types of data in a time sub-area in the detection time area division, and transmit the collected various types of data to the threat alarm data analysis module; collect data of each time sub-area through a threat feature data collection unit and a defense feature collection unit; the threat feature data collection unit is used to collect attack target data, system leakage data and system damage data of each time sub-area; the defense feature collection unit is used to collect detection strategy data and vulnerability repair data of each time sub-area; The threat alarm data analysis module: includes a threat feature data calculation unit and a defense feature calculation unit, which are used to analyze the data transmitted by the threat feature data collection unit and the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module; the threat feature data calculation unit is used to analyze various types of data transmitted by the threat feature data collection unit, and transmit the analysis results to the comprehensive data processing module; the threat feature data calculation unit includes an attack target data calculation subunit, a system leakage data calculation subunit and a system damage data calculation subunit; the defense feature calculation unit is used to analyze various types of data transmitted by the defense feature collection unit, and transmit the analysis results to the comprehensive data processing module; The defense feature calculation unit includes a detection strategy data calculation subunit and a vulnerability repair data calculation subunit; The attack target data calculation subunit is used to establish an attack target data mathematical model, import the attack target data transmitted by the threat feature data acquisition unit into the attack target data mathematical model, and calculate the attack target coefficient value of each time sub-area, which is specifically expressed as: GA i represents the attack target coefficient value of the i-th time sub-area, Gs i Indicates the number of failed logins to the target server in the i-th time sub-region, Gs max Indicates the maximum number of failed logins to the target server in the target time sub-zone, Dl i-1 represents the number of traffic anomalies of the target network node in the i-1th time sub-area, Dl i Gf represents the number of traffic anomalies of the target network node in the i-th time sub-region, i represents the number of times the target database in the i-th time sub-region is accessed, and n represents the number of sub-time regions; The system leakage data calculation subunit is used to establish a system leakage data mathematical model, import the system leakage data transmitted by the threat feature data acquisition unit into the system leakage data mathematical model, and calculate the system leakage coefficient value of each time sub-area, which is specifically expressed as: S i Represents the system leakage coefficient value of the i-th time sub-area, Sx i-1 Sx represents the number of sensitive personal information in the i-1th time sub-region. i represents the number of sensitive personal information in the i-th time sub-region, Sq max The amount of confidential data stolen from the target enterprise in the target time sub-region, Sq i Sh represents the amount of confidential data stolen from the target enterprise in the i-th time sub-region. i represents the number of illegal accesses by users in the i-th time sub-area, and n represents the number of sub-time areas; The system damage data calculation subunit is used to establish a system damage data mathematical model, import the system damage data transmitted by the threat feature data acquisition unit into the system damage data mathematical model, and calculate the system damage data coefficient value of each time sub-area, which is specifically expressed as: XA i represents the system damage data coefficient value of the i-th time sub-region, Xs i represents the number of operating system failures in the i-th time sub-region, Xg i-1 represents the number of times the VPN service in the i-1th time sub-region is attacked, Xg i represents the number of times the VPN service in the i-th time sub-region is attacked, Xz i represents the number of system hardware failures in the i-th time sub-region, Xz max Indicates the maximum number of system hardware failures in the target time zone, n represents the number of sub-time zones, and α represents the fitting parameter value of the operating system damage, which ranges from [1,2); The detection strategy data calculation subunit is used to establish a detection strategy data mathematical model, import the detection strategy data transmitted by the defense feature acquisition unit into the detection strategy data mathematical model, and calculate the detection strategy coefficient value of each time sub-area, which is specifically expressed as: J A i represents the detection strategy coefficient value of the i-th time sub-region, Jg i represents the number of system firewall updates in the i-th time sub-area, Jw i represents the number of false alarms of the intrusion system in the i-th time sub-area, Je i represents the number of successful interception attacks by the system in the i-th time sub-area, Je max It represents the maximum number of successful interception attacks by the system in the target time sub-zone, and n represents the number of sub-time zones; The vulnerability repair data calculation subunit is used to establish a vulnerability repair data mathematical model, import the vulnerability repair data transmitted by the defense feature collection unit into the vulnerability repair data mathematical model, and calculate the vulnerability repair coefficient value of each time sub-area, which is specifically expressed as: LA i Indicates the vulnerability repair coefficient value of the i-th time sub-area, Lg i represents the number of high-risk vulnerabilities in the i-th time sub-area, Ly i represents the number of recurrences of the fixed vulnerability in the i-th time sub-region, Lb i represents the vulnerability patch installation rate of the i-th time sub-region, σ represents the fitting parameter value of the vulnerability repair, which ranges from [1,1.5), and n represents the number of sub-time regions; The comprehensive data processing model is obtained in the following manner: Where η represents the safety assessment value of the target time zone, γ i represents the characteristic value of the threat feature data of the i-th time sub-region, λ i represents the information security defense characteristic value of the i-th time sub-region, ζ i represents the safety assessment value of the i-th time sub-area, μ represents the mean of the safety assessment values of the target area, where i = 1, 2, ..., n; Comprehensive data processing module: used to establish a comprehensive data processing model, import the data transmitted by the threat alarm data analysis module into the comprehensive data processing model, calculate the security assessment value of the target time area, and transmit it to the comprehensive data identification module; Comprehensive data identification module: used to accurately compare the safety assessment value of the target time area with the safety assessment value of the preset target time area during the actual operation process, and transmit the judgment result to the early warning module; Early warning module: used to receive the data transmitted by the comprehensive data identification module and send corresponding early warning signals to relevant management personnel for processing.
2. A threat warning semantic analysis system for power grid network security according to claim 1, characterized in that: The attack target data includes the number of failed logins to the target server, the number of traffic anomalies at the target network node, and the number of times the target database is accessed, which are respectively recorded as Gs, Gl, and Gf; the system leakage data includes the number of pieces of personal sensitive information, the capacity of confidential data of the target enterprise stolen, and the number of illegal accesses by users, which are respectively recorded as Sx, Sq, and Sh; the system damage data includes the number of operating system damages, the number of VPN services attacked, and the number of system hardware device failures, which are respectively recorded as Xs, Xg, and Xz.
3. A threat warning semantic analysis system for power grid network security according to claim 1, characterized in that: The detection strategy data includes the number of system firewall updates, the number of false alarms of intrusion into the system, and the number of successful attacks intercepted by the system, which are recorded as Jg, Jw, and Je respectively; the vulnerability repair data includes the number of high-risk vulnerabilities, the number of recurrences of repaired vulnerabilities, and the vulnerability patch installation rate, which are recorded as Lg, Ly, and Lb respectively.
4. The threat warning semantic analysis system for power grid network security according to claim 1 is characterized in that: The safety assessment value of the preset target time zone is recorded as n def , the safety assessment value of the target time area is accurately compared with the safety assessment value of the preset target time area during the actual operation. The specific calculation formula is: P safe Indicates the safety index of the target time zone. According to the safety index P of the target time zone safe When P safe ≤0.25, a safety signal is issued. safe When >0.25, a warning signal is issued.
Citation Information
Patent Citations
Computer network security prediction system for analysis based on big data information
CN116471124A
Network security protection method and system
CN117879970A