A Network Security Perception and Early Warning Method and System for Smart Power Plants
By building a network attack timing chart and a global attack chain, the problem of insufficient monitoring of network security status in multiple systems in smart power plants is solved, and timely warning of potential risks and awareness of security situations is achieved.
Patent Information
- Application Number
- CN202411485347.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-10-23
AI Technical Summary
The lack of overall network security status monitoring and analysis of various equipment and systems in smart power plants in the prior art has led to a timely warning of potential network security risks.
By reading the multi-source monitoring data set of smart power plants, using position coordinates and timestamps for space-time mapping, building a network attack timing chart, identifying the global attack chain, and performing historical risk backtracking, and outputting risk warning levels.
It realizes the overall network security situation awareness and timely warning of potential risks of multiple systems in smart power plants to ensure the safe and efficient operation of the power plants.
Smart Images

Figure CN119363438B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power plant network security early warning, and particularly to a network security perception early warning method and system for a smart power plant. Background Art
[0002] With the rapid development of smart power plants, the equipment and systems are becoming increasingly complex, posing higher requirements for the safe operation of power plants. However, most of the existing power plant early warning systems have limitations. Usually, they can only monitor a certain specific system or network behavior, such as separately monitoring the operation of industrial control systems or Internet of Things devices. This single - perspective monitoring method can, to a certain extent, ensure the stable operation of some systems, but it ignores the complex relationships and mutual influences among various internal devices and systems in a smart power plant. It is unable to analyze the overall network security status of various devices and systems in a smart power plant from a global perspective, posing a potential threat to the overall operation safety of the power plant.
[0003] In the prior art, there is a lack of comprehensive monitoring and analysis of the overall network security status of various devices and systems in a power plant, resulting in the technical problem that potential network security risks in the power plant are difficult to be timely warned. Summary of the Invention
[0004] This application provides a network security perception early warning method and system for a smart power plant, which is used to solve the technical problem that in the prior art, due to the lack of comprehensive monitoring and analysis of the overall network security status of various devices and systems in a power plant, potential network security risks in the power plant are difficult to be timely warned.
[0005] In view of the above problems, this application provides a network security perception early warning method and system for a smart power plant.
[0006] In the first aspect of this application, a network security perception early warning method for a smart power plant is provided. The method includes: reading a multi - source monitoring data set of the smart power plant in the first time zone, where the monitoring data is marked with position coordinates and timestamps; performing an anomaly judgment on the multi - source monitoring data set. If the anomaly index is 0, calculating the deviation of the multi - source monitoring data set using parameter reference values to determine multiple parameter deviation values; performing a spatio - temporal mapping distribution on the multiple parameter deviation values according to the position coordinates and timestamps to construct a network attack time - series graph; performing anomaly correlation identification based on the network attack time - series graph to determine a global attack chain, and performing historical risk backtracking according to the global attack chain to output a risk warning level.
[0007] In a second aspect of the present application, a network security perception and early warning system for an intelligent power plant is provided. The system includes: a data acquisition module configured to read a multi-source monitoring data set of the intelligent power plant in a first time zone, wherein the monitoring data is marked with location coordinates and timestamps; a data anomaly judgment module configured to perform anomaly judgment on the multi-source monitoring data set. If the anomaly index is 0, deviation calculation is performed on the multi-source monitoring data set using a parameter reference value to determine a plurality of parameter deviation values; a time series diagram construction module configured to perform spatio-temporal mapping distribution on the plurality of parameter deviation values according to the location coordinates and timestamps to construct a network attack time series diagram; a risk early warning level obtaining module configured to perform anomaly correlation identification based on the network attack time series diagram to determine a global attack chain, and perform historical risk backtracking according to the global attack chain to output a risk early warning level.
[0008] In a third aspect, the present application provides an electronic device, which includes: a memory for storing executable instructions; a processor for implementing the steps of the method according to any one of the above first aspects when executing the executable instructions stored in the memory.
[0009] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method according to any one of the above first aspects are implemented.
[0010] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0011] The method provided in the embodiment of the present application reads a multi-source monitoring data set of the intelligent power plant in a first time zone, wherein the monitoring data is marked with location coordinates and timestamps; performs anomaly judgment on the multi-source monitoring data set. If the anomaly index is 0, deviation calculation is performed on the multi-source monitoring data set using a parameter reference value to determine a plurality of parameter deviation values; performs spatio-temporal mapping distribution on the plurality of parameter deviation values according to the location coordinates and timestamps to construct a network attack time series diagram; performs anomaly correlation identification based on the network attack time series diagram to determine a global attack chain, and performs historical risk backtracking according to the global attack chain to output a risk early warning level. It achieves the technical effect of realizing the overall network security situation perception of multiple systems in the intelligent power plant and timely early warning of potential risks by collaboratively analyzing security data from different sources. Description of the Drawings
[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0013] Figure 1 It is a schematic flowchart of a network security perception and early warning method for a smart power plant provided by this application;
[0014] Figure 2 It is a schematic structural diagram of a network security perception and early warning system for a smart power plant provided by this application;
[0015] Figure 3 It is a schematic structural diagram of an electronic device provided by this application.
[0016] Explanation of reference numerals: data acquisition module 11, data anomaly judgment module 12, timing diagram construction module 13, risk early warning level acquisition module 14, input device 401, processor 402, memory 403, output device 404. Detailed implementation manners
[0017] This application provides a network security perception and early warning method and system for a smart power plant, which is used to solve the technical problem in the prior art that there is a lack of overall monitoring and analysis of the network security status of various devices and systems in the power plant, resulting in the difficulty of timely early warning of potential network security risks in the power plant. It achieves the technical effect of realizing the overall network security situation perception of multiple systems in the smart power plant and timely early warning of potential risks through collaborative analysis of security data from different sources.
[0018] Next, the technical solutions in the present invention will be clearly and completely described with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited by the example embodiments described here. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention. Additionally, it should be noted that for the sake of description, only the parts related to the present invention are shown in the drawings rather than all.
[0019] Embodiment 1, as Figure 1 shown, this application provides a network security perception and early warning method for a smart power plant, and the method includes:
[0020] Read the multi-source monitoring data set of the smart power plant in the first time zone, where the monitoring data is marked with position coordinates and timestamps.
[0021] Specifically, first, a variety of sensors and data acquisition devices are used to obtain real-time data generated by multiple devices in the first time zone from various devices in the smart power plant. The sensors include temperature sensors for monitoring the temperature changes of power plant devices (such as generators and transformers), voltage and current sensors for monitoring the working status of power equipment, video monitoring devices for real-time monitoring of key areas of the power plant, network traffic monitors for monitoring the network traffic situation inside the smart power plant, and device log recorders, etc. Then, these data are sorted in chronological order to form a multi-source monitoring data set for the same time period, that is, the first time zone. The specific duration of this time period is determined according to the monitoring requirements. The first time zone is mainly used to distinguish and classify data at different time points to ensure the temporal consistency of data within the same time zone. The multi-source monitoring data set includes multiple device systems distributed in the smart power plant, such as network traffic, device status, and operation logs. Each monitoring data in the multi-source monitoring data set is accompanied by a location coordinate and a timestamp. The location coordinate is used to locate the specific collection location of the data, such as the location of a certain power device or the geographical location of the data sensor. The timestamp refers to the time recorded for each piece of monitoring data, which is used to reflect the timeliness and accuracy of data collection. The timestamp is a sequence of character or encoded information. By obtaining a multi-source monitoring data set including location coordinates and timestamps, real-time monitoring and precise analysis of the power plant operation status can be achieved, providing accurate and reliable data support for the network security situation analysis and risk warning of the smart power plant.
[0022] Perform anomaly judgment on the multi-source monitoring data set. If the anomaly index is 0, use the parameter reference value to calculate the deviation of the multi-source monitoring data set to determine multiple parameter deviation values.
[0023] Specifically, compare and analyze the data in the multi-source monitoring data set from multiple sources with the anomaly standard to detect whether there is data information with abnormal conditions. The judgment process involves multiple indicators, such as sudden increases or decreases in the temperature, vibration, and network traffic of the device. If data anomalies are detected through analysis, record the anomaly index. When, through judgment and analysis, the anomaly index in the multi-source monitoring data set is 0, that is, no anomalies are detected, then based on the parameter reference value, calculate the deviation of each data in the multi-source monitoring data set. The parameter reference value refers to a reference value set according to historical data or parameters under normal operating conditions. For example, the normal temperature range of the device under normal working conditions, the normal ranges of voltage and current, etc. By comparing the collected monitoring data with the reference value, calculate multiple parameter deviation values. The parameter deviation value refers to the difference between the current monitoring data and the reference value. By calculating the parameter deviation value for the monitoring data without anomalies, potential threats that do not show obvious anomalies can be identified, ensuring the safe and efficient operation of various devices in the smart power plant.
[0024] Further, performing anomaly judgment on the multi-source monitoring dataset includes: obtaining a historical monitoring dataset for a preset period; analyzing network environment fluctuations and historical attack trends based on the historical monitoring dataset, adaptively correcting the parameter warning threshold according to the analysis results to obtain a dynamic warning threshold; performing anomaly judgment on the multi-source monitoring dataset according to the dynamic warning threshold, capturing anomaly indicators, and if the anomaly indicators are not 0, triggering network risk warnings based on the anomaly indicators.
[0025] Specifically, existing power plant warnings are generally based on fixed rule sets or models and cannot be adaptively adjusted according to changes in the network environment, resulting in a lack of flexibility in the system when facing changing attack patterns or new threats and being unable to dynamically adjust detection rules or strategies to address emerging threats. This application first obtains a historical monitoring dataset for a preset period, where the preset period is a time range set in historical data according to actual requirements, such as data in the past few days or weeks. By obtaining the historical data within this period, a comprehensive analysis of the device behavior and network activities of the smart power plant at different times can be carried out. Then, analyze network environment fluctuations and historical attack trends based on the historical monitoring dataset. The network environment fluctuations refer to the dynamic changes in behaviors such as communication traffic and device interactions in the network. Analyzing network environment fluctuations can identify the change patterns during the normal operation of the power plant and avoid false alarms. The historical attack trend analysis refers to analyzing historical attack events to identify the behavior patterns of historical attacks, including attack types, attack times, and attack methods. According to the analysis results of network environment fluctuations and historical attack trends, adaptively correct the set parameter warning threshold. The parameter warning threshold is a numerical standard set for judging whether a device or network is in an abnormal state. Through adaptive correction, the parameter warning threshold can be dynamically adjusted according to the actual network situation to obtain a dynamic warning threshold. For example, if the fluctuations in the network environment are large, the threshold can be appropriately relaxed to avoid frequent false alarms; conversely, if the historical attack trend indicates potential threats, the threshold can be appropriately tightened to capture attack signs in advance. Next, perform anomaly judgment on each item of data in the current multi-source monitoring dataset based on the dynamic warning threshold. If a certain parameter exceeds the dynamic threshold range, it means that the parameter is abnormal data, and the corresponding anomaly indicator is captured. When an anomaly indicator is detected in the multi-source monitoring dataset, that is, the anomaly indicator is not 0, it means that there may be risks or attacks in the current devices or network of the power plant. According to the anomaly indicator, trigger corresponding network risk warnings. Through this adaptive adjustment, anomalies can be captured more accurately, and more accurate risk warnings can be provided in the case of actual network environment changes, helping the smart power plant to respond to risks in a timely manner, take measures to prevent the spread of potential attacks or failures, and ensure the safe operation of the power plant.
[0026] Perform spatio-temporal mapping distribution on the multiple parameter deviation values according to the position coordinates and timestamps, and construct a network attack timing diagram.
[0027] Further, performing spatio-temporal mapping distribution on the multiple parameter deviation values according to the position coordinates and timestamps, and constructing a network attack timing diagram, includes: in a three-dimensional simulation space, performing spatial mapping on the multiple parameter deviation values according to the position coordinates to construct an abnormal parameter distribution; classifying the timestamps according to a preset time zone to determine multiple attack time zones; dividing the abnormal parameter distribution based on the multiple attack time zones to determine multiple attack feature diagrams, and arranging the multiple attack feature diagrams in sequence to generate the network attack timing diagram.
[0028] Specifically, process multiple parameter deviation values of the calculation, and perform spatio-temporal mapping analysis on the multiple parameter deviation values according to their position coordinates and timestamps, that is, in a three-dimensional simulation space, distribute the multiple parameter deviation values at corresponding time and space positions. The three-dimensional space refers to a virtual simulation environment used for spatial mapping and visualization of monitoring data of multiple devices or systems in a smart power plant. First, in the three-dimensional simulation space, perform spatial mapping on the multiple parameter deviation values according to the position coordinates, visually display the abnormal parameters at different physical positions, and construct a distribution map of abnormal parameters. The distribution map of abnormal parameters is used to display the abnormal conditions of each device or system in the smart power plant. For example, if the temperature of a certain device deviates, in the three-dimensional space, associate the spatial position of the device with the corresponding abnormal temperature deviation value, presenting the specific spatial distribution of the device abnormality. Through projection, it can intuitively reflect which areas in the power plant have abnormal conditions. Then, according to the preset time zone, classify according to the timestamps of the data, and divide the multiple parameter deviation values into different attack time zones. The attack time zone is to segment the timestamps according to the set time step, and each period of time is a time zone. For example, different time zones can be divided by units such as hours or minutes, and the set of abnormal data in each time zone will be used as a representative of an attack or potential risk. Finally, according to the divided multiple attack time zones, further divide the abnormal parameter distribution in each time zone to generate multiple attack feature maps. The attack feature map refers to the abnormal parameter distribution in different devices or systems within each time period. For example, in a certain time zone, if multiple devices simultaneously show parameter deviation values of different degrees, these abnormal conditions will be plotted into an attack feature map to show the device abnormality in that time period. Each feature map corresponds to a different time zone, showing the abnormal characteristics within a specific time period. Finally, arrange the multiple attack feature maps in chronological order to generate a complete network attack time series diagram. The network attack time series diagram shows the abnormal conditions of devices or networks in the smart power plant in different time zones, which can not only display the current abnormal distribution but also identify the propagation path of the attack. By constructing the network attack time series diagram, the smart power plant can more accurately understand the timing and spatial correlation of complex attacks and make timely and accurate responses.
[0029] Based on the network attack time series diagram, perform abnormal correlation identification to determine the global attack chain, and perform historical risk backtracking according to the global attack chain to output the risk warning level.
[0030] Further, based on the network attack timing diagram, perform anomaly correlation identification to determine the global attack chain, including: based on the power equipment association graph, perform anomaly correlation identification on the network attack timing diagram to determine the timing correlation feature, spatial correlation feature, and parameter similarity feature; respectively perform attack chain identification according to the timing correlation feature, spatial correlation feature, and parameter similarity feature to determine the timing attack chain, spatial attack chain, and parameter attack chain; fuse the timing attack chain, spatial attack chain, and parameter attack chain, and output the global attack chain.
[0031] Specifically, in combination with the power equipment association graph, according to the network attack timing diagram, through the time-series analysis of the monitoring data of multiple devices and systems in the network, perform correlation identification on the anomalies between different time periods and devices, and obtain the associations existing in the time, space, and parameter features, namely the timing correlation feature, spatial correlation feature, and parameter similarity feature. The power equipment association graph describes the logical relationships and mutual dependencies of various device systems in the smart power plant. For example, the operating states of a certain generator and transformer may be closely related, and the abnormal associations between devices can be identified through the device association graph. The timing correlation feature refers to the temporal front-back association of abnormal events of multiple devices or systems in the network attack timing diagram. By analyzing the time sequence of abnormal events, it is judged whether there is continuity in time for attack behaviors. The spatial correlation feature refers to the connection of multiple abnormal events in the physical space. By combining the position coordinates of devices, the geographical distribution between devices can be analyzed to judge whether there is a propagation trend of anomalies in space. The parameter similarity feature refers to that the parameter deviation values of abnormal events between different devices or systems have similar change patterns. For example, the parameters such as temperature, pressure, and flow rate of multiple devices deviate from the normal values in a similar time period, and the deviation amplitudes and directions are similar, indicating that these devices may be affected by the same type of attack or fault. By analyzing these parameter similarities, the associations between abnormal events can be further confirmed. Then, by analyzing the timing correlation feature, identify the continuous path of the attack in the time dimension to obtain the timing attack chain, by analyzing the spatial correlation feature, identify the diffusion path of the attack in the spatial dimension to obtain the spatial attack chain, and by analyzing the parameter similarity feature, identify the association of multiple devices or systems in parameter anomalies to obtain the parameter attack chain. After obtaining the timing attack chain, spatial attack chain, and parameter attack chain, fuse these chains to generate a complete global attack chain. The global attack chain includes the associations of the attack from multiple perspectives of time, space, and parameters. By obtaining the global attack chain, the propagation path, influence range, and potential impact of the smart power plant attack can be comprehensively understood, potential threats that are not significantly abnormal in a single system can be detected, especially complex cross-system attack behaviors, and potential attack chains can be identified, helping the smart power plant to respond to risks in a timely manner, take measures to prevent the spread of potential attacks or faults, and ensure the safe and efficient operation of the power plant.
[0032] Further, fuse the timing attack chain, the spatial attack chain, and the parameter attack chain to output the global attack chain, including: performing spatio-temporal fusion on the timing attack chain and the spatial attack chain, performing time-parameter fusion on the timing attack chain and the parameter attack chain, performing space-parameter fusion on the spatial attack chain and the parameter attack chain, and determining the spatio-temporal attack chain, the time-parameter attack chain, and the space-parameter attack chain; querying the historical network attack logs to obtain the historical attack dataset, and randomly selecting the first historical attack data from the historical attack dataset, where the first historical attack data includes the first spatio-temporal attack chain, the first time-parameter attack chain, the first space-parameter attack chain, and the first global attack chain; respectively performing similarity traversal on the spatio-temporal attack chain and the first spatio-temporal attack chain, the time-parameter attack chain and the first time-parameter attack chain, and the space-parameter attack chain and the first space-parameter attack chain to determine the first similarity, the second similarity, and the third similarity; if the first similarity, the second similarity, and the third similarity all meet the similarity criteria, adding the first global attack chain to the high-frequency global attack chain set, performing mode extraction on the high-frequency global attack chain set, and outputting the first global attack chain; analyzing and determining the global attack chain based on the first global attack chain.
[0033] Specifically, first perform spatio-temporal fusion on the timing attack chain and the spatial attack chain. The spatio-temporal fusion is to combine the attack chains in the time dimension and the space dimension. By associating the attack events in time with their corresponding device geographical locations, the spatio-temporal attack chain is determined. The spatio-temporal attack chain is used to describe the spatial path of the attack spreading in the smart power plant over time. Then, perform time-parameter fusion on the timing attack chain and the parameter attack chain. The time-parameter fusion means establishing an association between the time dimension and the device parameter dimension to judge whether there are abnormalities in the parameter changes of the device at different times. By fusing the timing attack chain and the parameter attack chain, the time-parameter attack chain is obtained, which can identify the consistency of parameter changes over time and confirm whether the attack shows similar trends in the parameters of multiple devices. Then, perform space-parameter fusion on the spatial attack chain and the parameter attack chain. The space-parameter fusion is to combine the spatial location and the parameter changes of the device to judge whether the devices in the same physical area show similar abnormalities in parameters. By performing space-parameter fusion, the space-parameter attack chain is obtained, which can identify the correlation of multiple devices in the parameter dimension within a specific area.
[0034] After completing the fusion of time-space, time parameters, and space parameters, query the historical network attack logs to obtain the previously recorded historical attack dataset, where the historical attack dataset includes historical network attacks and their corresponding time series, space, and parameter characteristics. Randomly select a first historical attack data from the historical attack dataset, and the first historical attack data includes a first time-space attack chain, a first time-parameter attack chain, a first space-parameter attack chain, and a first global attack chain. Then, perform similarity traversal on the currently identified time-space attack chain and the first time-space attack chain, time-parameter attack chain and the first time-parameter attack chain, and space-parameter attack chain and the first space-parameter attack chain respectively. The similarity traversal refers to comparing the similarity of the current attack chain and the historical attack chain in the time, space, and parameter dimensions one by one, and combining various algorithms such as Euclidean distance, dynamic time warping, Pearson correlation coefficient, etc. to determine their respective similarities. Through traversal, obtain the first similarity of the time-space attack chain, the second similarity of the time-parameter attack chain, and the third similarity of the space-parameter attack chain. Compare the first similarity, the second similarity, and the third similarity with the similarity index, where the similarity index refers to a preset threshold range. When the first similarity, the second similarity, and the third similarity are all within the preset threshold range, it means that the first similarity, the second similarity, and the third similarity all meet the similarity index. Then, add the first global attack chain to the high-frequency global attack chain set. The high-frequency global attack chain set is a set that contains high-frequency attack chains detected by the smart power plant, and these high-frequency attack chains have similar characteristics in historical attack events, indicating possible frequently occurring attack patterns. Furthermore, based on the high-frequency global attack chain set, perform mode extraction on multiple attack chains to extract the most frequently occurring chain and generate a representative first global attack chain. The first global attack chain has broad representativeness and consistency, reflecting the most common or most likely attack patterns in the smart power plant. Finally, based on the first global attack chain, combine the currently identified attack characteristics to obtain the global attack chain. The global attack chain can comprehensively display the propagation path and characteristics of the smart power plant attack in the time, space, and parameter dimensions, providing comprehensive attack chain identification and early warning capabilities for the network security of the smart power plant.
[0035] Further, analyzing and determining the global attack chain based on the first global attack chain includes: taking the smart power plant as a constraint feature, retrieving the sample time-space attack chain set, sample time-parameter attack chain set, sample space-parameter attack chain set, and sample global attack chain set through big data; training a decision forest with the sample time-space attack chain set, sample time-parameter attack chain set, sample space-parameter attack chain set, and sample global attack chain set to obtain an attack chain fusion plugin; using the attack chain fusion plugin to perform fusion analysis on the time-space attack chain, time-parameter attack chain, and space-parameter attack chain, and output a second global attack chain; fitting the first global attack chain and the second global attack chain, and output the global attack chain.
[0036] Specifically, taking the intelligent power plant as a constraint feature, an attack chain dataset related to the current intelligent power plant is obtained through big data retrieval, including a sample spatio-temporal attack chain set, a sample time-parameter attack chain set, a sample space-parameter attack chain set, and a sample global attack chain set. These sample sets are extracted from historical attack data, similar attack scenarios, or monitoring data of related devices and are used as reference data for the current attack chain analysis. Each sample set contains attack chain information in different dimensions, such as features in the time, space, and parameter dimensions. Then, the retrieved sample spatio-temporal attack chain set, sample time-parameter attack chain set, sample space-parameter attack chain set, and sample global attack chain set are used as training data to train a decision forest model to obtain an attack chain fusion plugin. A decision forest is an ensemble learning algorithm composed of multiple decision trees that can make judgments in different data dimensions. By training with multiple sample sets, the decision forest can learn how to identify patterns and features in multi-dimensional attack chain data. Using the trained attack chain fusion plugin, fusion analysis is performed on the spatio-temporal attack chain, time-parameter attack chain, and space-parameter attack chain, comprehensively analyzing the attack chains in the time, space, and parameter dimensions to determine whether there are interactive correlations between the attack characteristics in different dimensions. For example, if an attack event occurs in a time sequence and then anomalies are also shown in the parameters of multiple devices, and the location distribution of these devices presents a certain spatial pattern, the correlation between these dimensions can be determined through fusion analysis, and a more comprehensive second global attack chain is output. Finally, fitting analysis is performed on the second global attack chain and the previously identified first global attack chain. By comparing the time, space, and parameter characteristics of the first global attack chain and the second global attack chain, the similarity or difference between the two is obtained, and combining the common features in the two attack chains, a more comprehensive and accurate global attack chain is generated. The global attack chain synthesizes information from all dimensions, showing the propagation path of the attack in time, the diffusion route in space, and the trend of changes in the parameters of each device. Through the global attack chain, not only can the starting point and propagation path of the attack be identified, but also the potential targets and risks of the attack can be predicted, providing comprehensive support for the security protection of the intelligent power plant.
[0037] Furthermore, historical risk backtracking is performed according to the global attack chain, and a risk warning level is output, including: querying historical network attack logs according to the global attack chain to obtain the probability of risk events, where the probability of risk events is the ratio of the number of risk events to the number of attack events; inputting the probability of risk events into a preset probability-level comparison table and matching to output the risk warning level.
[0038] Specifically, according to the global attack chain, query the historical network attack logs stored in the database. The global attack chain contains multi-dimensional attack information, such as the association of time, space, and parameters, which can display the overall propagation path of the attack. By comparing this chain information with the historical attack logs, it is possible to trace back and locate events in the historical records that are similar or related to the current attack chain. In the historical network attack logs, extract the risk events that match the global attack chain. The risk events are attack events or abnormal behaviors that have been recorded and confirmed in the historical data. Then, count the occurrence frequency of the risk events and calculate the risk event probability. The risk event probability is calculated by taking the ratio of the number of occurrences of the risk event to the total number of corresponding attack events. By calculating the risk event probability, the risk level under each attack mode can be quantified. Input the calculated risk event probability into a preset probability-level comparison table. The probability-level comparison table is a pre-defined mapping table based on the security policies, historical data, expert experience, etc. of the smart power plant, and is used to match different risk event probabilities with the corresponding risk warning levels. Different probability intervals will correspond to different risk levels, such as multiple levels including low, medium, high, severe, etc. For example, the higher the probability value, the greater the risk caused by this type of attack, and the higher the corresponding risk warning level. By querying the probability-level comparison table, match the risk event probability with the warning level and output the corresponding risk warning level. For example, if the risk event probability of a certain type of attack event exceeds 70%, it may correspond to a high-risk warning level, while if the probability is low, it may correspond to a low-risk or medium-risk level. Through this matching method, the possibility of the risk event occurring can be quantified, and a more accurate risk assessment level can be provided to ensure that the risk assessment result can comprehensively and accurately reflect the actual threat level under the current attack chain, helping the smart power plant to timely identify and respond to potential cybersecurity threats and ensuring the safe and efficient operation of the power plant.
[0039] Embodiment 2, based on the same inventive concept as a network security perception and warning method for a smart power plant in the foregoing embodiment, as Figure 2 shown, the present application provides a network security perception and warning system for a smart power plant, and the system includes:
[0040] A data acquisition module 11, which is used to read the multi-source monitoring data set of the intelligent power plant in the first time zone, where the monitoring data is marked with position coordinates and timestamps; a data anomaly judgment module 12, which is used to judge the anomaly of the multi-source monitoring data set. If the anomaly index is 0, the deviation of the multi-source monitoring data set is calculated by using the parameter reference value to determine multiple parameter deviation values; a time series diagram construction module 13, which is used to perform spatio-temporal mapping distribution on the multiple parameter deviation values according to the position coordinates and timestamps to construct a network attack time series diagram; a risk warning level obtaining module 14, which is used to perform anomaly correlation identification based on the network attack time series diagram to determine the global attack chain, and perform historical risk backtracking according to the global attack chain to output the risk warning level.
[0041] Further, the data anomaly judgment module 12 includes: a historical data acquisition unit, which is used to acquire the historical monitoring data set of a preset period; a historical data analysis unit, which is used to analyze the network environment fluctuation and historical attack trend based on the historical monitoring data set, and adaptively correct the parameter warning threshold according to the analysis result to obtain a dynamic warning threshold; an anomaly index capture unit, which is used to judge the anomaly of the multi-source monitoring data set according to the dynamic warning threshold, capture the anomaly index, and if the anomaly index is not 0, perform network risk warning based on the anomaly index.
[0042] Further, the time series diagram construction module 13 includes: an abnormal parameter distribution construction unit, which is used to perform spatial mapping on the multiple parameter deviation values according to the position coordinates in a three-dimensional simulation space to construct an abnormal parameter distribution; a timestamp classification unit, which is used to classify the timestamps according to a preset time zone to determine multiple attack time zones; an abnormal parameter distribution division unit, which is used to divide the abnormal parameter distribution based on the multiple attack time zones to determine multiple attack feature diagrams, and arrange the multiple attack feature diagrams in sequence to generate the network attack time series diagram.
[0043] Further, the risk warning level obtaining module 14 includes: an abnormal association recognition unit, which is configured to perform abnormal association recognition on the network attack time series diagram based on the power equipment association map to determine time series association features, spatial association features, and parameter similarity features; an attack chain recognition unit, which is configured to perform attack chain recognition respectively according to the time series association features, spatial association features, and parameter similarity features to determine a time series attack chain, a spatial attack chain, and a parameter attack chain; a data fusion unit, which is configured to fuse the time series attack chain, the spatial attack chain, and the parameter attack chain and output the global attack chain.
[0044] Further, the data fusion unit is configured to perform the following steps: perform spatio-temporal fusion on the time series attack chain and the spatial attack chain, perform time-parameter fusion on the time series attack chain and the parameter attack chain, perform space-parameter fusion on the spatial attack chain and the parameter attack chain to determine a spatio-temporal attack chain, a time-parameter attack chain, and a space-parameter attack chain; query historical network attack logs, obtain a historical attack data set, and randomly select first historical attack data in the historical attack data set, where the first historical attack data includes a first spatio-temporal attack chain, a first time-parameter attack chain, a first space-parameter attack chain, and a first global attack chain; respectively perform similarity traversal on the spatio-temporal attack chain and the first spatio-temporal attack chain, the time-parameter attack chain and the first time-parameter attack chain, the space-parameter attack chain and the first space-parameter attack chain to determine a first similarity, a second similarity, and a third similarity; if the first similarity, the second similarity, and the third similarity all meet the similarity index, add the first global attack chain to the high-frequency global attack chain set, perform mode extraction on the high-frequency global attack chain set, and output the first global attack chain; analyze and determine the global attack chain based on the first global attack chain.
[0045] Further, the data fusion unit is further configured to perform the following steps: use the smart power plant as a constraint feature, retrieve big data to obtain a sample spatio-temporal attack chain set, a sample time-parameter attack chain set, a sample space-parameter attack chain set, and a sample global attack chain set; train a decision forest with the sample spatio-temporal attack chain set, the sample time-parameter attack chain set, the sample space-parameter attack chain set, and the sample global attack chain set to obtain an attack chain fusion plug-in; use the attack chain fusion plug-in to perform fusion analysis on the spatio-temporal attack chain, the time-parameter attack chain, and the space-parameter attack chain, and output a second global attack chain; fit the first global attack chain and the second global attack chain, and output the global attack chain.
[0046] Further, the risk warning level obtaining module 14 includes: a risk event probability obtaining unit, which is configured to query historical network attack logs according to the global attack chain to obtain the risk event probability, where the risk event probability is the ratio of the number of risk events to the number of attack events; and a risk warning level matching unit, which is configured to input the risk event probability into a preset probability-level comparison table and match and output the risk warning level.
[0047] Although the present application makes various references to certain modules in the device according to the embodiments of the present application, however, any number of different modules can be used and run on the user terminal and / or the server. The included individual units and modules are only divided according to functional logic, but are not limited to the above division as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for facilitating mutual distinction and do not limit the protection scope of the present invention.
[0048] Embodiment 3. Based on the foregoing embodiments, the present application further provides an electronic device and a computer-readable storage medium. When the computer program stored in the computer-readable storage medium is executed by the processor of the electronic device, it can implement the method described in any previous embodiment.
[0049] Figure 3 It is a schematic structural diagram of the electronic device provided by the embodiment of the present invention, showing a block diagram of an exemplary electronic device suitable for implementing the embodiment of the present invention. Figure 3 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present invention. The electronic device is presented in the form of a general computing device, and its components may include but are not limited to an input device 401, a processor 402, a memory 403, and an output device 404. Among them, the processor 402 may be one or more; the memory 403 may include a computer-readable medium and at least one program product, and this program product has a set (at least one) of program modules, and these program modules are configured to execute the functions of the embodiments of the present application.
[0050] The memory 403 shown in the embodiment of the present invention may adopt any combination of one or more computer-readable media; the computer-readable storage medium may be but is not limited to infrared rays, semiconductor devices, devices or components, or any combination of the above, for storing software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to a network security perception and warning method of a smart power plant in the embodiment of the present invention. The processor 402 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 403, that is, implements the above-mentioned network security perception and warning method of a smart power plant.
[0051] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
[0052] This specification and the accompanying drawings are merely exemplary descriptions of the present application and are considered to have covered any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and deformations to the present application without departing from the scope of the present application. Thus, if these modifications and deformations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and deformations.
Claims
1. A network security perception and early warning method for an intelligent power plant, characterized in that, Including: Read the multi-source monitoring data set of the intelligent power plant in the first time zone, where the monitoring data is marked with location coordinates and timestamps; Perform anomaly judgment on the multi-source monitoring data set. If the anomaly index is 0, calculate the deviation of the multi-source monitoring data set using the parameter reference value to determine multiple parameter deviation values; Perform spatio-temporal mapping distribution on the multiple parameter deviation values according to the location coordinates and timestamps to construct a network attack time series graph; Based on the network attack time series graph, perform anomaly correlation identification to determine the global attack chain, and perform historical risk backtracking according to the global attack chain to output the risk warning level; Based on the network attack time series graph, perform anomaly correlation identification to determine the global attack chain, including: Based on the power equipment association graph, perform anomaly correlation identification on the network attack time series graph to determine the time series correlation feature, spatial correlation feature, and parameter similarity feature; Identify the attack chain according to the time series correlation feature, spatial correlation feature, and parameter similarity feature respectively to determine the time series attack chain, spatial attack chain, and parameter attack chain; Fuse the time series attack chain, spatial attack chain, and parameter attack chain to output the global attack chain; Fuse the time series attack chain, spatial attack chain, and parameter attack chain to output the global attack chain, including: Perform spatio-temporal fusion on the time series attack chain and the spatial attack chain, perform time-parameter fusion on the time series attack chain and the parameter attack chain, and perform space-parameter fusion on the spatial attack chain and the parameter attack chain to determine the spatio-temporal attack chain, time-parameter attack chain, and space-parameter attack chain; Query the historical network attack log, obtain the historical attack data set, and randomly select the first historical attack data in the historical attack data set, where the first historical attack data includes the first spatio-temporal attack chain, the first time-parameter attack chain, the first space-parameter attack chain, and the first global attack chain; Perform similarity traversal on the spatio-temporal attack chain and the first spatio-temporal attack chain, the time-parameter attack chain and the first time-parameter attack chain, and the space-parameter attack chain and the first space-parameter attack chain respectively to determine the first similarity, the second similarity, and the third similarity; If the first similarity, the second similarity, and the third similarity all meet the similarity index, add the first global attack chain to the high-frequency global attack chain set, extract the mode of the high-frequency global attack chain set, and output the first global attack chain; Determine the global attack chain based on the analysis of the first global attack chain.
2. The network security perception and early warning method of an intelligent power plant according to claim 1, characterized in that, Perform anomaly judgment on the multi-source monitoring data set, including: Obtain the historical monitoring data set of the preset period; Based on the historical monitoring data set, perform network environment fluctuation and historical attack trend analysis, and adaptively correct the parameter warning threshold according to the analysis result to obtain the dynamic warning threshold; Perform anomaly judgment on the multi-source monitoring data set according to the dynamic warning threshold, capture the anomaly index, and if the anomaly index is not 0, perform network risk warning based on the anomaly index.
3. A network security perception and early warning method for an intelligent power plant according to claim 1, characterized in that, Perform spatio-temporal mapping distribution on the multiple parameter deviation values according to the location coordinates and timestamps to construct a network attack time series graph, including: In the three-dimensional simulation space, perform spatial mapping on the multiple parameter deviation values according to the position coordinates to construct an abnormal parameter distribution; Classify the timestamps according to a predetermined time zone to determine multiple attack time zones; Based on the multiple attack time zones, divide the abnormal parameter distribution to determine multiple attack feature maps, and arrange the multiple attack feature maps in sequence to generate the network attack time series diagram.
4. A network security perception and early warning method for an intelligent power plant according to claim 1, characterized in that, Based on the first global attack chain analysis, determine the global attack chain, including: Taking the intelligent power plant as a constraint feature, retrieve the sample spatio-temporal attack chain set, sample time-parameter attack chain set, sample space-parameter attack chain set, and sample global attack chain set through big data; Train a decision forest with the sample spatio-temporal attack chain set, sample time-parameter attack chain set, sample space-parameter attack chain set, and sample global attack chain set to obtain an attack chain fusion plugin; Use the attack chain fusion plugin to perform fusion analysis on the spatio-temporal attack chain, time-parameter attack chain, and space-parameter attack chain, and output a second global attack chain; Fit the first global attack chain and the second global attack chain to output the global attack chain.
5. A network security perception and early warning method for an intelligent power plant according to claim 1, characterized in that, Perform historical risk backtracking according to the global attack chain and output the risk warning level, including: Query the historical network attack logs according to the global attack chain to obtain the risk event probability, where the risk event probability is the ratio of the number of risk events to the number of attack events; Input the risk event probability into a preset probability-level comparison table and match and output the risk warning level.
6. A network security perception and early warning system for an intelligent power plant, characterized in that, The system includes: A data acquisition module, which is used to read the multi-source monitoring data set of the intelligent power plant in the first time zone, where the monitoring data is marked with position coordinates and timestamps; A data anomaly judgment module, which is used to judge the anomaly of the multi-source monitoring data set. If the anomaly index is 0, calculate the deviation of the multi-source monitoring data set using the parameter reference value to determine multiple parameter deviation values; A time series diagram construction module, which is used to perform spatio-temporal mapping distribution on the multiple parameter deviation values according to the position coordinates and timestamps to construct a network attack time series diagram; A risk warning level acquisition module, which is used to perform abnormal correlation identification based on the network attack time series diagram, determine the global attack chain, and perform historical risk backtracking according to the global attack chain to output the risk warning level; The risk warning level acquisition module includes: an abnormal correlation identification unit, which is used to perform abnormal correlation identification on the network attack time series diagram based on the power equipment association map to determine the time series correlation feature, space correlation feature, and parameter similarity feature; an attack chain identification unit, which is used to perform attack chain identification respectively according to the time series correlation feature, space correlation feature, and parameter similarity feature to determine the time series attack chain, space attack chain, and parameter attack chain; a data fusion unit, which is used to fuse the time series attack chain, space attack chain, and parameter attack chain and output the global attack chain; The data fusion unit is used to perform the following steps: perform spatio-temporal fusion on the temporal attack chain and the spatial attack chain, perform temporal-parameter fusion on the temporal attack chain and the parameter attack chain, perform spatial-parameter fusion on the spatial attack chain and the parameter attack chain, and determine the spatio-temporal attack chain, the temporal-parameter attack chain, and the spatial-parameter attack chain; query the historical network attack logs, obtain the historical attack dataset, and randomly select the first historical attack data from the historical attack dataset, where the first historical attack data includes the first spatio-temporal attack chain, the first temporal-parameter attack chain, the first spatial-parameter attack chain, and the first global attack chain; respectively perform similarity traversal on the spatio-temporal attack chain and the first spatio-temporal attack chain, the temporal-parameter attack chain and the first temporal-parameter attack chain, and the spatial-parameter attack chain and the first spatial-parameter attack chain to determine the first similarity, the second similarity, and the third similarity; if the first similarity, the second similarity, and the third similarity all meet the similarity criteria, add the first global attack chain to the high-frequency global attack chain set, perform mode extraction on the high-frequency global attack chain set, and output the first global attack chain; analyze and determine the global attack chain based on the first global attack chain.
7. An electronic device, characterized in that, The electronic device includes: a memory for storing executable instructions; a processor for implementing the steps of the method according to any one of claims 1 to 5 when executing the executable instructions stored in the memory.
8. A computer-readable storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Intelligent alarm method for network performance abnormity
CN109995599A
Abnormal traffic detection method and device and computer readable storage medium
CN116232612A
Network attack event tracing method and device, storage medium and electronic equipment
CN117692240A