Network attack defense methods and systems for distributed new energy grid-connected systems

By combining dynamic defense strategies and random routing schemes in a distributed new energy grid-connected system, real-time monitoring of abnormal network traffic and information sharing and security auditing are achieved, thus solving the problem of insufficient network attack protection in the distributed new energy grid-connected system and realizing comprehensive security protection and stable system operation.

CN119341807BActive Publication Date: 2025-10-31GUANGXI POWER GRID CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411454024.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-17
Publication Date
2025-10-31
Estimated Expiration
2044-10-17

AI Technical Summary

Technical Problem

Distributed renewable energy grid-connected systems face insufficient protection against cyberattacks at multiple points. Data is at risk of leakage and tampering during storage and access, and existing protection strategies cannot fully cover all potential attack paths.

Method used

We employ a dynamic defense strategy based on IP addresses and a random routing scheme based on DDPG. By combining the dynamic defense strategy with the random routing scheme, we can share information and conduct security audits, monitor abnormal network traffic in real time, generate targeted defense strategies, and dynamically adjust the defense strategies and routing schemes to enhance the resilience and anti-attack capabilities of the network system.

Benefits of technology

It improves the accuracy and timeliness of network attack defense, enhances the stability and security of the system, effectively resists network attacks such as distributed denial of service, reduces the risk of unauthorized access and malicious operation, and improves the overall defense effect and operating efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119341807B_ABST
    Figure CN119341807B_ABST
Patent Text Reader

Abstract

This application relates to a network attack defense method and system for a distributed renewable energy grid-connected system. The method includes generating a dynamic defense strategy based on IP addresses based on abnormal network traffic and attack detection results when renewable energy terminals access the system; generating a random routing scheme based on a preset deep deterministic policy gradient; and performing dynamic defense by combining the dynamic defense strategy and the random routing scheme. This application improves the comprehensiveness and integration of network attack defense for renewable energy grid-connected systems, effectively ensuring the network and data security of the renewable energy grid-connected system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of network attack defense for new energy systems, and in particular to a network attack defense method and system for a distributed new energy grid-connected system. Background Technology

[0002] With the continuous growth of global energy demand and the increasing awareness of environmental protection, distributed renewable energy grid-connected systems, as a clean and renewable energy solution, are gradually becoming an important development direction in the energy sector. However, with the widespread application and high integration of these systems, the cybersecurity threats they face are becoming increasingly severe. Distributed renewable energy grid-connected systems not only involve the collection and transmission of large amounts of energy data, but also rely on complex network communication technologies and Internet of Things (IoT) devices, making them potential targets for cyber attackers.

[0003] Currently, network security protection for distributed renewable energy grid-connected systems largely focuses on single-point protection, such as installing firewalls and intrusion detection systems. However, this single-point protection strategy is inadequate in the face of complex and ever-changing network attacks. Because distributed renewable energy systems involve multiple links and multiple devices, single-point protection cannot fully cover all potential attack paths, easily leading to security vulnerabilities. In addition, data is the core resource of distributed renewable energy grid-connected systems, including sensitive information such as users' energy usage and energy suppliers' supply capacity. Existing data protection mechanisms often focus on encryption during data transmission, while neglecting the importance of data storage and access control. This means that even if data is encrypted during transmission, it may still face the risk of leakage and tampering during storage and access. Summary of the Invention

[0004] To improve the comprehensiveness and integration of network attack defense for new energy grid-connected systems and to ensure the network and data security of these systems, this application provides a network attack defense method and system for distributed new energy grid-connected systems.

[0005] Firstly, the above-mentioned inventive objective of this application is achieved through the following technical solution:

[0006] A network attack defense method for a distributed renewable energy grid-connected system, the method comprising:

[0007] Based on abnormal network traffic and attack detection results when new energy terminals are connected, a dynamic defense strategy based on IP address is generated.

[0008] Random routing schemes are generated based on a pre-defined deep deterministic strategy gradient.

[0009] Dynamic defense is achieved by combining the dynamic defense strategy and the random routing scheme.

[0010] By adopting the above technical solutions, abnormal network traffic and attack detection results during the access of new energy terminals can be monitored in real time, and targeted defense strategies can be generated accordingly. This enables accurate identification and isolation of potential attack sources, effectively reducing false alarms and missed alarms, and improving the accuracy and timeliness of defense. By dynamically adjusting the defense strategies, the network system of the new energy grid-connected system can quickly adapt to the ever-changing network threat environment, ensuring the stable operation of the new energy grid-connected system. The DDPG-based random routing scheme uses a deep deterministic policy gradient algorithm to generate random routing schemes, which can increase the complexity and unpredictability of network traffic, thereby effectively resisting network attacks such as Distributed Denial of Service (DDoS), breaking the attacker's predictive patterns, and making attack traffic difficult to predict. By focusing attacks on a specific target, the resilience and anti-attack capabilities of the entire network system are improved. Combining IP address-based dynamic defense strategies with DDPG-based random routing schemes, this approach not only addresses security threats during new energy terminal access but also constructs a comprehensive security protection system covering all aspects and levels of the new energy grid connection system. This effectively resists various network attacks from both internal and external sources, enhances the overall security of the system, and achieves integrated defense and collaborative combat effects. The dynamic defense strategy is responsible for accurately identifying and isolating attack sources, while the random routing scheme is responsible for dispersing and obfuscating attack traffic. The two complement each other, jointly building an impenetrable network security defense line.

[0011] In a preferred embodiment, this application can be further configured such that the dynamic defense combining the dynamic defense strategy and the random routing scheme includes:

[0012] Establish an information sharing path between the dynamic defense strategy and the random routing scheme;

[0013] Information is shared based on the information sharing path, and dynamic defense is performed by utilizing the shared information in conjunction with the dynamic defense strategy and the random routing scheme.

[0014] The dynamic defense strategy and the random routing scheme are subjected to security audits, and the dynamic defense strategy and the random routing scheme are adjusted based on the security audit results.

[0015] By adopting the above technical solutions and establishing an information-sharing path between the dynamic defense strategy and the random routing scheme, close collaboration between the two is achieved. This ensures that the dynamic defense strategy can respond and adjust rapidly in the face of network attacks, while the random routing scheme can also dynamically adjust its routing strategy according to changes in the defense strategy. This enhances the collaborative combat capability of the entire defense system and effectively improves the overall defense effect. Real-time information sharing based on the information-sharing path allows the dynamic defense strategy and the random routing scheme to adjust instantly according to the latest trends and characteristics of network attacks. This enables the defense system to quickly respond to constantly changing network threats, effectively reducing the risk of attackers bypassing or breaking through the defense and ensuring the stable operation of the new energy grid-connected system. Regular security audits of the dynamic defense strategy and the random routing scheme not only promptly identify and fix potential security vulnerabilities and weaknesses but also allow for continuous optimization and improvement of the defense strategy based on the audit results. This enhances the robustness and reliability of the defense system, ensuring that the new energy grid-connected system maintains a high level of defense when facing complex and ever-changing network threats.

[0016] In a preferred embodiment, this application can be further configured such that: establishing the information sharing path between the dynamic defense strategy and the random routing scheme includes:

[0017] Based on the dynamic defense strategy, obtain the dynamic defense perception results;

[0018] The dynamic defense perception result is used as the input to the random routing scheme, and the routing policy of the random routing scheme is used as the input to the dynamic defense policy to establish an information sharing path between the dynamic defense policy and the random routing scheme.

[0019] By adopting the above technical solution, the perception results of the dynamic defense strategy are used as input to the random routing scheme, and the routing strategy of the random routing scheme is used as input to the dynamic defense strategy. This achieves an instant feedback mechanism between the two. The two-way information flow enables the dynamic defense strategy to adjust its defense measures in a timely manner based on changes in the routing strategy. At the same time, the routing strategy can also optimize its route selection according to the needs of the defense strategy, significantly improving the response speed and accuracy of the defense system to network threats. The establishment of information sharing paths means that the dynamic defense strategy and the random routing scheme are no longer isolated system components, but form an interdependent and collaboratively optimized whole. During the defense process, the two can make collaborative decisions based on shared information to jointly respond to network attacks, improve the effectiveness and targeting of the defense strategy, and ensure that the routing strategy achieves efficient transmission of network traffic while ensuring network security. The information sharing between the dynamic defense perception results and the random routing strategy promotes the deep integration and intelligent analysis of information within the defense system. Through intelligent algorithms processing the shared information, the defense system can automatically identify the type, scale, and scope of network threats, and generate the optimal defense strategy and routing scheme accordingly.

[0020] In a preferred embodiment, this application can be further configured as follows: the dynamic defense, utilizing the shared information and combining the dynamic defense strategy with the random routing scheme, includes:

[0021] Using the shared information, when dynamically allocating the IP address of the new energy terminal based on the dynamic defense strategy, the random routing scheme is combined to determine the security threat areas that the data packet can avoid during transmission.

[0022] Using the shared information, known attack source IP addresses are added to a blacklist. When allocating routes based on the random routing scheme, the attack source IP addresses are treated as critical network areas that cannot be routed. A whitelist mechanism is used to restrict legitimate IP addresses from performing predetermined operations or accessing predetermined resources.

[0023] By adopting the above technical solutions, combining dynamic defense strategies with random routing schemes, when allocating IP addresses for new energy terminals, potential security threat areas can be intelligently identified and avoided based on shared information. This reduces the risk of data packets being maliciously intercepted or tampered with during transmission and ensures the secure transmission path of critical data, thereby significantly improving the overall security of network transmission. Adding known attack source IP addresses to a blacklist and treating these addresses as unroutable critical network areas in the random routing scheme can quickly isolate and block threats from known attack sources, preventing further penetration and spread. Simultaneously, combined with a whitelist mechanism, only legitimate IP addresses are allowed to perform specific operations or access specific resources, further strengthening the system's security defenses and reducing the risk of unauthorized access and malicious operations. During dynamic defense, the rational allocation of network resources through shared information not only ensures the secure transmission of critical data but also optimizes the utilization efficiency of network resources. For example, avoiding security threat areas during route allocation can reduce unnecessary network congestion and latency, improving the efficiency and stability of data transmission. Furthermore, the combined use of blacklist and whitelist mechanisms helps reduce the system's burden of processing invalid or malicious requests, further improving the overall operating efficiency of the system.

[0024] In a preferred embodiment, this application can be further configured as follows: performing security audits on the dynamic defense strategy and the random routing scheme, and adjusting the dynamic defense strategy and the random routing scheme based on the security audit results, includes:

[0025] Using a pre-defined security audit mechanism, the security status of new energy terminal access network is regularly audited. The security audit includes network security device configuration audit, security policy execution audit, and routing scheme execution effect audit.

[0026] Based on the audit results and changes in the network security situation, the dynamic defense strategy and the random routing scheme are dynamically adjusted.

[0027] By adopting the above technical solutions, the pre-set security audit mechanism regularly conducts a comprehensive audit of the security status of new energy terminal access networks, including multiple dimensions such as network security equipment configuration, security policy implementation, and routing scheme execution effects. This ensures real-time monitoring of system security, enabling timely detection of potential security risks and vulnerabilities. Security auditing is not only an assessment of system security but also a test of the effectiveness of defense strategies and routing schemes. Through the feedback of audit results, it is possible to accurately determine whether the current defense strategies and routing schemes meet current security requirements and whether there is redundancy or inadequacy. This allows for dynamic adjustments to defense strategies and routing schemes, significantly improving their adaptability and accuracy. It ensures that the system can always maintain the best security defense status in complex and ever-changing network environments. At the same time, based on the audit results and changes in the network security situation, dynamic defense strategies and random routing schemes are dynamically adjusted, enabling the defense system to keep pace with the development of security threats.

[0028] Secondly, the above-mentioned inventive objective of this application is achieved through the following technical solutions:

[0029] A network attack defense system for a distributed renewable energy grid-connected system, the network attack defense system for the distributed renewable energy grid-connected system comprising:

[0030] The dynamic defense strategy module is used to generate dynamic defense strategies based on IP addresses in response to abnormal network traffic and attack detection results when new energy terminals access the network.

[0031] The random routing scheme module is used to generate random routing schemes based on a preset deep deterministic policy gradient.

[0032] The defense integration module is used to combine the dynamic defense strategy and the random routing scheme to perform dynamic defense.

[0033] Optionally, the defense integration module includes:

[0034] The shared path establishment submodule is used to establish an information sharing path between the dynamic defense strategy and the random routing scheme;

[0035] Combined with the defense submodule, it is used to share information based on the information sharing path, and to perform dynamic defense by using the shared information in conjunction with the dynamic defense strategy and the random routing scheme;

[0036] The audit submodule is used to perform security audits on the dynamic defense strategy and the random routing scheme, and adjust the dynamic defense strategy and the random routing scheme based on the security audit results.

[0037] Optionally, the shared path establishment submodule includes:

[0038] The dynamic defense result unit is used to obtain dynamic defense perception results based on the dynamic defense strategy.

[0039] The path establishment unit is used to take the dynamic defense perception result as input to the random routing scheme, take the routing policy of the random routing scheme as input to the dynamic defense policy, and establish an information sharing path between the dynamic defense policy and the random routing scheme.

[0040] Thirdly, the above-mentioned inventive objective of this application is achieved through the following technical solutions:

[0041] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the network attack defense method for the distributed new energy grid-connected system described above.

[0042] Fourthly, the above-mentioned inventive objective of this application is achieved through the following technical solutions:

[0043] A computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the network attack defense method for the distributed new energy grid-connected system described above.

[0044] In summary, this application includes at least one of the following beneficial technical effects:

[0045] 1. Real-time monitoring of abnormal network traffic and attack detection results during new energy terminal access, and generation of targeted defense strategies accordingly. This enables accurate identification and isolation of potential attack sources, effectively reducing false alarms and missed alarms, and improving the accuracy and timeliness of defense. By dynamically adjusting defense strategies, the network system of the new energy grid-connected system can quickly adapt to the ever-changing network threat environment, ensuring the stable operation of the new energy grid-connected system. The DDPG-based random routing scheme utilizes a deep deterministic policy gradient algorithm to generate random routing schemes, increasing the complexity and unpredictability of network traffic. This effectively resists network attacks such as Distributed Denial-of-Service (DDoS), breaking the attacker's predictive patterns and making it difficult for attack traffic to concentrate. To achieve a specific objective, this approach enhances the resilience and anti-attack capabilities of the entire network system. By combining IP address-based dynamic defense strategies with DDPG-based random routing schemes, it not only addresses security threats during the access of new energy terminals but also constructs a comprehensive security protection system covering all aspects and levels of the new energy grid connection system. This effectively resists various network attacks from both internal and external sources, improves the overall security of the system, and achieves the effect of comprehensive defense and collaborative operations. The dynamic defense strategy is responsible for accurately identifying and isolating attack sources, while the random routing scheme is responsible for dispersing and obfuscating attack traffic. The two complement each other, jointly building an unbreakable network security defense line.

[0046] 2. By establishing an information-sharing path between the dynamic defense strategy and the random routing scheme, close collaboration between the two is achieved. This ensures that the dynamic defense strategy can respond and adjust rapidly in the face of network attacks, while the random routing scheme can also dynamically adjust its routing strategy according to changes in the defense strategy. This enhances the collaborative combat capability of the entire defense system and effectively improves the overall defense effect. Real-time information sharing based on the information-sharing path allows the dynamic defense strategy and the random routing scheme to adjust instantly according to the latest trends and characteristics of network attacks. This enables the defense system to quickly respond to constantly changing network threats, effectively reducing the risk of attackers bypassing or breaking through the defense and ensuring the stable operation of the new energy grid-connected system. Regular security audits of the dynamic defense strategy and the random routing scheme not only promptly identify and fix potential security vulnerabilities and weaknesses but also allow for continuous optimization and improvement of the defense strategy based on the audit results. This enhances the robustness and reliability of the defense system, ensuring that the new energy grid-connected system maintains a high level of defense when facing complex and ever-changing network threats.

[0047] 3. By using the perception results of the dynamic defense strategy as input to the random routing scheme, and the routing strategy of the random routing scheme as input to the dynamic defense strategy, an instant feedback mechanism is achieved between the two. This two-way information flow allows the dynamic defense strategy to adjust its defense measures promptly based on changes in the routing strategy, while the routing strategy can also optimize its route selection according to the needs of the defense strategy, significantly improving the response speed and accuracy of the defense system to network threats. The establishment of information sharing paths means that the dynamic defense strategy and the random routing scheme are no longer isolated system components, but rather form an interdependent and collaboratively optimized whole. During the defense process, they can make collaborative decisions based on shared information to jointly respond to network attacks, improving the effectiveness and targeting of the defense strategy, while ensuring efficient network traffic transmission under the premise of network security. Information sharing between the dynamic defense perception results and the random routing strategy promotes deep integration and intelligent analysis of information within the defense system. Through intelligent algorithms processing the shared information, the defense system can automatically identify the type, scale, and scope of network threats, and generate the optimal defense strategy and routing scheme accordingly. Attached Figure Description

[0048] Figure 1 This is a flowchart illustrating the implementation of the network attack defense method for the distributed new energy grid-connected system in this application embodiment;

[0049] Figure 2 This is a flowchart illustrating the implementation of S30 of the network attack defense method for a distributed new energy grid-connected system in this application embodiment;

[0050] Figure 3 This is a flowchart illustrating the implementation of S31 of the network attack defense method for a distributed new energy grid-connected system in this application embodiment;

[0051] Figure 4 This is a flowchart illustrating the implementation of S32 of the network attack defense method for a distributed new energy grid-connected system in this application embodiment;

[0052] Figure 5 This is a flowchart illustrating the implementation of S33 of the network attack defense method for a distributed new energy grid-connected system in this application embodiment;

[0053] Figure 6 This is a principle block diagram of the network attack defense system of the distributed new energy grid-connected system in the embodiments of this application;

[0054] Figure 7 This is an internal structural diagram of the computer device in the embodiments of this application. Detailed Implementation

[0055] The following is in conjunction with the appendix Figure 1-7 This application will be described in further detail.

[0056] In one embodiment, such as Figure 1 As shown, this application discloses a network attack defense method for a distributed new energy grid-connected system, which specifically includes the following steps:

[0057] S10: Generate dynamic defense strategies based on IP addresses based on abnormal network traffic and attack detection results when new energy terminals access the network.

[0058] Specifically, network monitoring tools are used to monitor network traffic data of new energy terminals accessing the network in real time, including IP address, port number and protocol type, etc., to collect network traffic data when terminal devices access the network and analyze it to determine abnormal traffic and attack types. For example, deep packet inspection (DPI) is performed on network traffic to analyze packet content and identify abnormal traffic patterns, or normal traffic database and abnormal traffic database are built based on historical network traffic data. Machine learning or statistical methods, such as cluster analysis and anomaly detection algorithms, are used to classify real-time network traffic data and distinguish between normal traffic and abnormal traffic.

[0059] Secondly, by combining network traffic analysis results, attack behaviors such as Distributed Denial-of-Service (DDoS) attacks, IP spoofing, and Address Resolution Protocol (ARP) spoofing are identified. The characteristics of the attack behaviors are extracted, such as the attack source IP, attack type, and attack intensity. Once an attack behavior is detected, the IP address is identified for abnormal traffic and attacks, and corresponding defense strategies are formulated. The response mechanism is triggered immediately, including blocking, restricting access, blocking the attack source IP, adjusting firewall rules, and isolating the attacked device. Attack logs are also recorded to provide a basis for subsequent security analysis and tracing.

[0060] Furthermore, dynamic defense strategies based on IP addresses may also include:

[0061] Dynamic IP address allocation strategy:

[0062] New energy terminals are assigned dynamic IP addresses, which are changed periodically, increasing the difficulty for attackers to track and locate them.

[0063] When changing IP addresses, ensure the continuity and stability of network services;

[0064] IP address blacklist and whitelist policies:

[0065] Maintain an IP address blacklist, add known attack source IP addresses to it, and deny access requests from these IP addresses;

[0066] At the same time, an IP address whitelist is established, allowing only IP addresses in the whitelist to perform specific operations or access specific resources;

[0067] IP address access control policy:

[0068] Implement strict IP address access control policies to restrict unnecessary IP address access permissions;

[0069] Encrypt critical resources and sensitive data during transmission to prevent data from being stolen or tampered with during transmission;

[0070] Dynamically adjust firewall policies:

[0071] Based on network traffic and attack detection results, dynamically adjust firewall rules to enhance the defense against new attacks and unknown threats;

[0072] Regularly review and update firewall rules to ensure the effectiveness and security of the firewall;

[0073] IP / MAC binding policy:

[0074] Bind IP addresses to MAC addresses to prevent unauthorized access that does not meet the binding requirements;

[0075] Intrusion prevention strategies:

[0076] Develop an attack detection strategy based on the five-tuple (source IP, destination IP, source port, destination port, service) to statistically analyze and reject abnormal attacks, while allowing normal business operations.

[0077] Behavioral learning and baseline management strategies:

[0078] Common IoT terminals use industrial control protocols such as Modbus, IEC104, GOOSE, MMS, and SV, as well as protocols such as MQTT used for sensor transmission. By learning these network traffic and analyzing the protocols in the traffic, basic information of the current new energy device can be constructed to form a baseline of behavior. Then, by comparing subsequent traffic with the baseline traffic, information such as sensor information (temperature and humidity changes, pressure changes, switch opening and closing) that deviates significantly from the baseline can be filtered and reported to form risk alarms.

[0079] S20: Generate a random routing scheme based on a preset deep deterministic strategy gradient.

[0080] Specifically, the Deep Deterministic Policy Gradient (DDPG) method is a reinforcement learning algorithm that can be used to solve the control problem of continuous state and action space. Random routing is also a kind of dynamic defense. This study investigates the DDPG-based random routing strategy in distributed new energy scenarios to reduce the probability of attackers succeeding in attacking and thus improve the security of the system.

[0081] Therefore, generating a random routing scheme that balances security and quality of service requirements based on a preset deep deterministic strategy gradient can specifically include the following steps:

[0082] Network status monitoring:

[0083] Utilize in-band network telemetry technology to monitor and acquire network status information in real time, including key indicators such as link status, traffic distribution, latency, and packet loss rate;

[0084] Policy network construction:

[0085] Design and train a deep neural network as an actor network that takes the current network state as input and outputs a deterministic routing action (i.e., the next hop address or path that the data packet should be transmitted to).

[0086] Evaluate network construction:

[0087] Simultaneously, an evaluation network (Critic Network) is constructed to assess the quality of the routing actions output by the policy network. The evaluation network receives the current state, the routing action, and the new state after executing the action as input, and outputs a scalar value representing the expected reward obtained by starting from the current state, executing the routing action, and reaching the new state.

[0088] Strategy optimization:

[0089] By using optimization algorithms such as gradient descent, the parameters of the policy network and the evaluation network are continuously adjusted to maximize the scalar value of the evaluation network output, so that the policy network can gradually learn the optimal routing action in a given network state.

[0090] Random routing scheme generation:

[0091] After the policy network is trained, a random routing scheme is generated using the policy network based on the real-time network status. It should be noted that "random" here does not mean that the routing action itself is random, but rather that the routing scheme can be dynamically adjusted according to different network states, thereby achieving defense against potential attacks and ensuring service quality requirements.

[0092] Furthermore, the generated random routing scheme can be executed by a programmable switch under the P4 framework. The P4 framework provides high flexibility, allowing network administrators to customize the packet processing flow according to actual needs, thereby achieving random routing defense at the packet level.

[0093] S30: Dynamic defense is achieved by combining dynamic defense strategies and random routing schemes.

[0094] Specifically, IP address-based dynamic defense strategies mainly identify potential threat sources (such as attackers' IP addresses) by real-time monitoring of abnormal traffic and attack behavior in the network, and dynamically adjust network configuration or security policies to block or restrict these threat sources from accessing network resources. DDPG-based random routing schemes mainly utilize deep deterministic policy gradient algorithms to dynamically adjust the transmission path of data packets according to changes in network status, thereby increasing the difficulty for attackers to track and predict, and improving network security.

[0095] Therefore, by combining the two defense methods, the dynamic defense strategy based on IP addresses can quickly identify and respond to known or suspicious attack sources, while the random routing scheme based on the DDPG method can increase network security at a broader level and prevent potential unknown threats.

[0096] In one embodiment, such as Figure 2 As shown, in step S30, dynamic defense is performed by combining dynamic defense strategies and random routing schemes, including:

[0097] S31: Establish an information sharing path between dynamic defense strategies and random routing schemes.

[0098] Specifically, abnormal traffic and attack detection results detected in the IP address-based dynamic defense strategy are used as input to the random routing scheme, thereby establishing an information sharing path between the dynamic defense strategy and the random routing scheme.

[0099] S32: Information sharing is based on information sharing paths. Dynamic defense is carried out by utilizing the shared information and combining dynamic defense strategies and random routing schemes.

[0100] Specifically, information sharing is based on information sharing paths. The random routing scheme can dynamically adjust the routing strategy according to the input abnormal information to avoid routing data packets to network areas that may be attacked or have abnormal traffic. Combined with the front-end defense of dynamic defense strategies, the effectiveness of network attack defense is further improved.

[0101] S33: Conduct security audits on dynamic defense strategies and random routing schemes, and adjust dynamic defense strategies and random routing schemes based on the security audit results.

[0102] Specifically, a security audit mechanism is used to regularly audit the security status of the distributed new energy terminal access network, including the configuration of network security equipment, the implementation of security policies, and the effectiveness of random routing schemes. Based on the audit results and changes in the network security situation, dynamic defense strategies based on IP addresses and DDPG routing schemes are dynamically adjusted to ensure the continuous effectiveness of the network security protection system.

[0103] In one embodiment, such as Figure 3 As shown, in step S31, establishing an information sharing path between the dynamic defense strategy and the random routing scheme includes:

[0104] S311: Obtain dynamic defense perception results based on the dynamic defense strategy.

[0105] Specifically, network monitoring mechanisms, such as high-performance network packet capture tools or hardware, can ensure complete capture of data packets even in high-speed network environments, without missing any potential threat information. The captured data packets are preprocessed, such as deduplication, protocol parsing, and session reassembly, to reduce the pressure on subsequent analysis and improve accuracy. For example, using hardware acceleration technologies (such as FPGA and ASIC) to perform preliminary filtering and parsing of data packets can significantly improve processing speed.

[0106] The system analyzes key information such as traffic characteristics (e.g., packet size, transmission frequency), source IP, destination IP, port number, and protocol type of captured data packets. Furthermore, it can analyze more complex features such as packet size distribution, time interval patterns, and session duration to more accurately identify complex attack patterns. The parsed information is processed in real-time, and algorithms such as machine learning, statistical analysis, or rule matching are used to perform in-depth analysis of monitored network traffic, identifying abnormal traffic patterns such as DDoS attacks, SQL injection, and malicious scanning. The detected abnormal traffic and attack perception results are integrated into structured reports or events, including detailed information such as anomaly type, occurrence time, impact scope, and attack source IP. Further, unsupervised learning (e.g., cluster analysis) can be used to discover abnormal traffic patterns, combined with supervised learning (e.g., classifiers) to identify known attack types. Simultaneously, an online learning mechanism is introduced, enabling the model to adaptively update to adapt to new attack methods.

[0107] Machine learning algorithms (such as neural networks, decision trees, and random forests) are used to train network traffic data to establish a behavioral model of normal traffic. When the actual traffic deviates significantly from the model's prediction, it can be considered abnormal traffic.

[0108] By analyzing the statistical characteristics of network traffic (such as mean, variance, and distribution), thresholds can be set to determine whether the traffic is abnormal. For example, when an IP address sends a large number of data packets in a short period of time, it may indicate a DDoS attack, or...

[0109] Based on known attack patterns or signature databases, write rules to match abnormal behaviors in network traffic;

[0110] The detected abnormal traffic and attack awareness results are integrated into a structured report or event. For example, the integrated information may include the following details:

[0111] Clearly indicate the type of abnormal traffic detected (e.g., DDoS attack, SQL injection, malicious scanning, etc.).

[0112] Record the time when the abnormal traffic first appeared and the duration of the abnormal traffic;

[0113] Assess the impact of abnormal traffic on the network, including affected IP addresses, ports, and services;

[0114] Record the IP addresses that launch the attack to provide a basis for subsequent blacklist management;

[0115] Information such as traffic volume, attack intensity, and potential attack targets.

[0116] S312: Use the dynamic defense perception results as input to the random routing scheme, and use the routing policy of the random routing scheme as input to the dynamic defense policy to establish an information sharing path between the dynamic defense policy and the random routing scheme.

[0117] Specifically, the dynamic defense perception results are used as input to the random routing scheme, and the routing strategy of the random routing scheme is used as input to the dynamic defense strategy. An information sharing path between the dynamic defense strategy and the random routing scheme is established. At the same time, in order to ensure the confidentiality, integrity and availability of information during transmission, security measures can be taken. For example, encryption technology can be used to encrypt the transmitted information to prevent it from being stolen or tampered with during transmission; identity verification and authorization of the information recipient can be performed to ensure that only the legitimate recipient can receive and process this information; and reliable communication protocols and transmission mechanisms can be adopted to ensure that the information is not lost or damaged during transmission.

[0118] In one embodiment, the dynamic defense system, through an efficient monitoring mechanism and advanced anomaly detection algorithm, can capture and analyze abnormal traffic and potential threats in the network in real time, including key information such as attack source IP, attack type, attack intensity, and scope of impact, which will be transmitted to the random routing decision system in real time or near real time.

[0119] Upon receiving threat intelligence from the dynamic defense system, the random routing decision system immediately conducts a risk assessment. It considers not only conventional factors such as network topology, link load, and node status, but also focuses on analyzing potential attack paths and high-risk areas mentioned in the threat intelligence. Based on the risk assessment results, the random routing decision system dynamically adjusts routing strategies, such as changing the transmission path of data packets, increasing the randomness of routing, and enabling backup links, to avoid potential security threat areas and ensure the security and reliability of data transmission.

[0120] To cope with the ever-changing cyber threat environment, random routing decision systems need to be able to continuously receive threat intelligence from dynamic defense systems and adjust routing strategies in real time based on this intelligence.

[0121] In addition, the random routing decision system not only adjusts the routing strategy based on the threat intelligence of the dynamic defense system, but also feeds back the adjusted routing strategy to the dynamic defense system, so that the dynamic defense system can understand the actual flow and distribution of current network traffic, thereby more accurately assessing the network security situation.

[0122] For example, if a routing path is frequently attacked, a dynamic defense system can strengthen security monitoring and defense measures on that path; if a backup link is proven to be secure, the dynamic defense system can incorporate it into the regular defense strategy to improve the overall defense effectiveness.

[0123] By establishing an information sharing path, a close collaborative relationship is formed between the dynamic defense strategy and the random routing scheme. To ensure the smooth flow of information sharing between the dynamic defense strategy and the random routing scheme, a series of safeguards are required. For example, encrypting the transmitted information to ensure its confidentiality and integrity during transmission; verifying and authorizing the identities of all parties involved in information sharing to ensure that only authorized users can access the shared information; redundantly backing up critical information to prevent information loss or damage from causing serious impacts on the system; and monitoring the information sharing path in real time, triggering an alarm mechanism immediately upon detecting any anomalies so that timely measures can be taken to address the issue.

[0124] In one embodiment, such as Figure 4 As shown, in step S32, dynamic defense is performed using shared information, combined with dynamic defense strategies and random routing schemes, including:

[0125] S321: Utilizing shared information, when dynamically allocating IP addresses for new energy terminals based on a dynamic defense strategy, and combining this with a random routing scheme, determine the security threat areas that data packets can avoid during transmission.

[0126] Specifically, by utilizing shared information and dynamically allocating IP addresses for new energy terminals based on a dynamic defense strategy, a random routing scheme is combined to determine the security threat areas that data packets can avoid during transmission. For example, a dynamic IP address pool is first established for IP address allocation to new energy terminals. This pool should be updated regularly to ensure the availability and security of IP addresses. Then, combined with the DDPG routing scheme, an intelligent IP address allocation algorithm is designed. This algorithm considers multiple factors such as network status, security threats, and terminal type when allocating IP addresses to ensure that the allocated IP addresses can avoid potential security threat areas. After the IP address allocation is completed, the optimal routing path is generated for the new energy terminals according to the DDPG routing scheme. This path should avoid known attack sources and abnormal traffic areas as much as possible to ensure the security and efficiency of data transmission.

[0127] S322: Using shared information, add known attack source IP addresses to a blacklist. When allocating routes based on a random routing scheme, treat the attack source IP addresses as critical network areas that cannot be routed, and use a whitelist mechanism to restrict legitimate IP addresses from performing scheduled operations or accessing scheduled resources.

[0128] Specifically, using shared information, a blacklist database is established to store known attack source IP addresses. This database should be updated regularly to reflect the latest security threat information. At the same time, a whitelist database is established to store legitimate IP addresses and terminal information. Only IP addresses and terminals that meet the whitelist criteria can access critical network areas or perform specific operations.

[0129] In one embodiment, upon receiving abnormal information, the routing decision system immediately initiates a real-time analysis mechanism. For example, it learns about the current network topology, including node distribution and link connectivity, to facilitate considering the overall network layout when adjusting routing strategies; it monitors the load of each link, including indicators such as bandwidth utilization, latency, and packet loss rate, to help determine which links may become bottlenecks or potential security threats; and it checks the operating status of each node in the network, including CPU utilization, memory usage, and disk space.

[0130] Based on the results of real-time analysis and the received anomaly information, the random routing decision system also conducts risk assessments on network areas that may be attacked or have abnormal traffic. For example, it assesses the threat level of abnormal traffic or potential attacks to the network, including attack intensity and scope of impact; analyzes the specific impacts that abnormal traffic or potential attacks may have on the network, such as service interruption and data leakage; and assesses the vulnerability of each node and service in the network to determine which parts are more susceptible to attack or impact.

[0131] Upon detecting potential security threats or abnormal traffic, the random routing decision system dynamically alters the data packet transmission path based on real-time analysis and risk assessment. This avoids potentially vulnerable security areas and redirects packets from potentially attacked or high-risk links to safer, more stable paths. For example, based on the current network topology and link load, it recalculates and plans the optimal routing path, avoiding known attack sources, abnormal traffic areas, and overloaded links to ensure efficient and secure data transmission.

[0132] When multiple paths are available in a network, a random routing decision system may choose to enable backup links to transmit data packets. Backup links are usually links that are not frequently used under normal circumstances, but they can quickly take over data transmission tasks when the main link is threatened or fails, ensuring the continuity and stability of the network. When adjusting routing strategies, the system also considers load balancing factors. By reasonably distributing network traffic to different links and nodes, it can prevent certain links or nodes from becoming new security threat points due to overload.

[0133] In addition to changing the transmission path, the random routing decision system can also optimize the routing strategy by adjusting the routing weight. The routing weight is an indicator that is comprehensively evaluated based on factors such as the performance, security and reliability of the link. By adjusting the weight of different links, the system can guide data packets to be transmitted through links with better performance and higher security. For example, for links that have passed security checks and have not detected abnormal traffic, the system can appropriately increase the weight, making it more likely that data packets will choose these links for transmission. For links with potential threats or abnormal traffic, the system can reduce their weight, reducing the likelihood of data packets passing through these links.

[0134] In addition, during the routing decision optimization process, the random routing decision system can also enable corresponding security policies based on the results of risk assessment. For example, for detected abnormal traffic, a traffic cleaning mechanism can be enabled to filter and clean the traffic, remove malicious components, and ensure that only legitimate traffic can enter the network. For network areas or nodes with high risks, security isolation measures can be implemented to isolate them from other network areas or nodes to prevent abnormal traffic or attacks from spreading in the network.

[0135] In one embodiment, such as Figure 5 As shown, in step S33, a security audit is performed on the dynamic defense strategy and the random routing scheme, and the dynamic defense strategy and the random routing scheme are adjusted according to the security audit results, including:

[0136] S331: Utilize a pre-set security audit mechanism to periodically audit the security status of new energy terminal access networks. The security audit includes auditing network security equipment configuration, auditing the implementation of security policies, and auditing the effectiveness of routing schemes.

[0137] Specifically, by utilizing a pre-defined security audit mechanism, a comprehensive audit of the security status of new energy terminal access networks can be conducted regularly. This can be achieved through a combination of automated audit tools and manual auditing, allowing for in-depth examination and analysis of all aspects within the audit scope. For example, professional network security audit software or tools can be used to automatically scan and test network security devices and policies, identifying security issues and configuration errors such as unpatched vulnerabilities, weak passwords, and insecure protocol versions. Based on automated auditing, in-depth manual analysis and evaluation can then be conducted. Manual auditing focuses on understanding and judging complex security issues, such as the logical rationality of security policies and the potential threats of abnormal traffic.

[0138] The audit scope includes network security equipment configuration (such as firewalls and intrusion detection systems), security policy implementation (such as access control policies and data encryption policies), and the effectiveness of DDPG routing schemes.

[0139] More specifically, the scope of the audit includes, but is not limited to:

[0140] Network security equipment configuration: Conduct a detailed inspection of the configuration of key security equipment such as firewalls, intrusion detection systems (IDS / IPS), and security incident information management (SIEM) systems, including the validity of rule sets, consistency of policies, completeness of log records, and interoperability between devices, as well as whether there are any unauthorized configuration changes or potential security vulnerabilities.

[0141] Security policy implementation status: Evaluate the implementation status of security policies such as access control policies, data encryption policies, identity authentication and authorization mechanisms, check whether the policies are implemented correctly, whether there are policy conflicts or policy bypasses, verify whether the policies are suitable for the current network environment and business needs, and whether adjustments are needed to address new security threats;

[0142] The execution effect of the DDPG routing scheme: In-depth analysis of the execution effect of the DDPG (Distributed Deep Packet Inspection) routing scheme, including the accuracy and real-time performance of routing decisions, the responsiveness in the event of network anomalies or attacks, whether the routing strategy effectively avoids potential security threat areas, and whether it ensures the security and reliability of data transmission;

[0143] Terminal security status: operating system patch updates, antivirus software installation and updates, security configuration (such as disabling unnecessary services and ports), etc.

[0144] Furthermore, a detailed audit report should be generated based on the audit results. This report should include all security issues discovered during the audit process, such as issue descriptions, scope of impact, and severity. For each issue, specific evidence and supporting materials such as screenshots should be provided. The potential impact of each issue on network security should be assessed, including possible service interruptions and data breaches. At the same time, the root causes and reasons for the issues should be analyzed to provide a basis for subsequent remediation. Specific improvement measures and suggestions should be proposed for the issues discovered in the audit.

[0145] S332: Based on the audit results and changes in the network security situation, dynamically adjust the dynamic defense strategy and random routing scheme.

[0146] Specifically, dynamic defense strategies and random routing schemes can be dynamically adjusted based on audit results and changes in the network security landscape. For example, the parameters and rules of the monitoring mechanism can be adjusted based on security issues and vulnerabilities discovered during audits to improve the accuracy and real-time performance of monitoring. New monitoring technologies and tools can also be introduced to address emerging security threats. Routing strategies can be dynamically adjusted based on changes in network topology and the evolution of security threats.

[0147] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0148] In one embodiment, a network attack defense system for a distributed new energy grid-connected system is provided, which corresponds one-to-one with the network attack defense method for the distributed new energy grid-connected system described in the above embodiments. For example... Figure 6 As shown, the network attack defense system of this distributed new energy grid-connected system includes a dynamic defense strategy module, a random routing scheme module, and a combined defense module. Detailed descriptions of each functional module are as follows:

[0149] The dynamic defense strategy module is used to generate dynamic defense strategies based on IP addresses in response to abnormal network traffic and attack detection results when new energy terminals access the network.

[0150] The random routing scheme module is used to generate random routing schemes based on a preset deep deterministic policy gradient.

[0151] The defense integration module is used to combine dynamic defense strategies and random routing schemes for dynamic defense.

[0152] Optional, the defense integration module includes:

[0153] The shared path establishment submodule is used to establish information sharing paths between dynamic defense strategies and random routing schemes;

[0154] Combined with the defense submodule, it is used for information sharing based on information sharing paths. By utilizing the shared information, combined with dynamic defense strategies and random routing schemes, dynamic defense is carried out.

[0155] Combined with the audit submodule, it is used to perform security audits on dynamic defense strategies and random routing schemes, and adjust dynamic defense strategies and random routing schemes based on the security audit results.

[0156] Optionally, the shared path establishment submodule includes:

[0157] The dynamic defense result unit is used to obtain dynamic defense perception results based on the dynamic defense strategy.

[0158] The path establishment unit is used to take the dynamic defense perception results as input to the random routing scheme, and take the routing policy of the random routing scheme as input to the dynamic defense policy, to establish an information sharing path between the dynamic defense policy and the random routing scheme.

[0159] Optionally, the defense submodules include:

[0160] The dynamic direction combination unit is used to utilize shared information and, when dynamically allocating the IP address of new energy terminals based on a dynamic defense strategy, combine a random routing scheme to determine the security threat areas that data packets can avoid during transmission.

[0161] The random routing direction combination unit is used to add known attack source IP addresses to a blacklist using shared information. When allocating routes based on a random routing scheme, the attack source IP addresses are treated as critical network areas that cannot be routed, and a whitelist mechanism is used to restrict only legitimate IP addresses to perform specific operations or access specific resources.

[0162] Optionally, the audit submodule may include:

[0163] The audit unit is used to periodically audit the security status of new energy terminals accessing the network using a preset security audit mechanism. The security audit includes auditing the network security equipment configuration, auditing the implementation of security policies, and auditing the effectiveness of routing schemes.

[0164] The dynamic adjustment unit is used to dynamically adjust dynamic defense strategies and random routing schemes based on audit results and changes in the network security situation.

[0165] Specific limitations regarding the network attack defense system for distributed renewable energy grid-connected systems can be found in the above description of the network attack defense methods for distributed renewable energy grid-connected systems, and will not be repeated here. Each module in the aforementioned network attack defense system for distributed renewable energy grid-connected systems can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0166] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides the environment for the operating system and computer programs in the non-volatile storage media to run. The database stores abnormal network traffic, attack detection results, dynamic defense strategies, and random routing schemes. The network interface communicates with external terminals via a network connection. When the computer program is executed by the processor, it implements a network attack defense method for a distributed new energy grid-connected system.

[0167] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps:

[0168] Based on abnormal network traffic and attack detection results when new energy terminals are connected, a dynamic defense strategy based on IP address is generated.

[0169] Random routing schemes are generated based on a pre-defined deep deterministic strategy gradient.

[0170] Dynamic defense is achieved by combining dynamic defense strategies with random routing schemes.

[0171] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0172] Based on abnormal network traffic and attack detection results when new energy terminals are connected, a dynamic defense strategy based on IP address is generated.

[0173] Random routing schemes are generated based on a pre-defined deep deterministic strategy gradient.

[0174] Dynamic defense is achieved by combining dynamic defense strategies with random routing schemes.

[0175] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0176] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above.

[0177] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A network attack defense method for a distributed new energy grid-connected system, characterized in that, The network attack defense method for the distributed new energy grid-connected system includes: Based on abnormal network traffic and attack detection results when new energy terminals are connected, a dynamic defense strategy based on IP address is generated. Random routing schemes are generated based on a pre-defined deep deterministic strategy gradient. Dynamic defense is achieved by combining the dynamic defense strategy and the random routing scheme, including: Establishing an information-sharing path between the dynamic defense strategy and the random routing scheme includes: Based on the dynamic defense strategy, obtain the dynamic defense perception results; The dynamic defense perception result is used as the input to the random routing scheme, and the routing strategy of the random routing scheme is used as the input to the dynamic defense strategy to establish an information sharing path between the dynamic defense strategy and the random routing scheme. Information sharing is conducted based on the aforementioned information sharing path. Dynamic defense is then performed using the shared information, combined with the dynamic defense strategy and the random routing scheme, including: Using the shared information, when dynamically allocating the IP address of the new energy terminal based on the dynamic defense strategy, the random routing scheme is combined to determine the security threat areas that the data packet can avoid during transmission. Using the shared information, known attack source IP addresses are added to a blacklist. When allocating routes based on the random routing scheme, the attack source IP addresses are treated as critical network areas that cannot be routed. A whitelist mechanism is used to restrict legitimate IP addresses from performing predetermined operations or accessing predetermined resources. The dynamic defense strategy and the random routing scheme are subjected to security audits, and the dynamic defense strategy and the random routing scheme are adjusted based on the security audit results.

2. The network attack defense method for a distributed new energy grid-connected system according to claim 1, characterized in that, The step of performing security audits on the dynamic defense strategy and the random routing scheme, and adjusting the dynamic defense strategy and the random routing scheme based on the security audit results, includes: Using a pre-defined security audit mechanism, the security status of new energy terminal access network is regularly audited. The security audit includes network security device configuration audit, security policy execution audit, and routing scheme execution effect audit. Based on the audit results and changes in the network security situation, the dynamic defense strategy and the random routing scheme are dynamically adjusted.

3. A network attack defense system for a distributed new energy grid-connected system, characterized in that, The network attack defense system of the distributed new energy grid connection system includes: The dynamic defense strategy module is used to generate dynamic defense strategies based on IP addresses in response to abnormal network traffic and attack detection results when new energy terminals access the network. The random routing scheme module is used to generate random routing schemes based on a preset deep deterministic policy gradient. The defense integration module is used to combine the dynamic defense strategy and the random routing scheme for dynamic defense. The defense integration module includes: A shared path establishment submodule is used to establish an information-sharing path between the dynamic defense strategy and the random routing scheme. The shared path establishment submodule includes: The dynamic defense result unit is used to obtain dynamic defense perception results based on the dynamic defense strategy. The path establishment unit is used to take the dynamic defense perception result as input to the random routing scheme, take the routing policy of the random routing scheme as input to the dynamic defense policy, and establish an information sharing path between the dynamic defense policy and the random routing scheme. The combined defense submodule is used for information sharing based on the information sharing path, and utilizes the shared information, combined with the dynamic defense strategy and the random routing scheme, to perform dynamic defense. The combined defense submodule includes: The dynamic direction combination unit is used to utilize shared information and, when dynamically allocating the IP address of new energy terminals based on a dynamic defense strategy, combine a random routing scheme to determine the security threat areas that data packets can avoid during transmission. The random routing direction combination unit is used to add known attack source IP addresses to a blacklist using shared information. When allocating routes based on a random routing scheme, the attack source IP addresses are treated as critical network areas that cannot be routed, and a whitelist mechanism is used to restrict only legitimate IP addresses to perform specific operations or access specific resources. The audit submodule is used to perform security audits on the dynamic defense strategy and the random routing scheme, and adjust the dynamic defense strategy and the random routing scheme based on the security audit results.

4. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the network attack defense method for the distributed new energy grid-connected system as described in any one of claims 1 to 2.

5. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the network attack defense method for the distributed new energy grid-connected system as described in any one of claims 1 to 2.

Citation Information

Patent Citations

  • Network dynamic defense system and method

    CN109347830A

  • Intelligent abnormal traffic blocking system based on machine learning algorithm and real-time traffic monitoring

    CN118784266A