An all-round power grid network device scanning system and method
By deploying multiple distributed scanning modules and central control modules in the power grid network, automatically identifying and coordinating network equipment, the data transmission bottlenecks and single point of failure of the centralized scanning system are solved, and efficient, flexible and reliable network security assessment is achieved.
Patent Information
- Application Number
- CN202510088498.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-01-21
AI Technical Summary
In the prior art, centralized scanning systems face data transmission bottlenecks and processing capability limitations when dealing with large-scale distributed power grid networks, resulting in reduced scanning speed and efficiency, and single point failures are likely to cause overall system security monitoring and evaluation to be affected.
Multiple distributed scanning modules are adopted, each module is equipped with a network interface, scanning engine, storage unit and communication unit. It automatically identifies and connects network equipment, collects configuration information and security parameters, generates evaluation reports, and coordinates and summarizes data through the central control module to execute multi-level security evaluation algorithms.
It realizes efficient coverage and scanning of large-scale network equipment, avoids performance bottlenecks, improves scanning speed and efficiency, enhances system flexibility and reliability, and provides real-time updates and accuracy of global network security assessments.
Smart Images

Figure CN119561775B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and particularly to an all-round power grid network device scanning system and method. Background Art
[0002] In the prior art, the security and performance of power grid network devices are usually evaluated through a centralized scanning system. These systems generally include one or more scanning engines for identifying and connecting to devices in the network, collecting configuration information, operating status, and security parameters of the devices, and generating security assessment reports. These scanning systems rely on a central processing unit to process and analyze all data to detect potential security threats and performance issues. This centralized architecture is somewhat effective in small-scale networks, but when dealing with large-scale distributed networks, it often faces problems such as data transmission bottlenecks and processing capacity limitations.
[0003] When the centralized scanning system processes a large number of devices, it is prone to performance bottlenecks, resulting in a significant reduction in scanning speed and efficiency; the single central processing unit becomes a single point of failure of the entire system, and once a problem occurs, the security monitoring and assessment of the entire network will be severely affected.
[0004] Therefore, there is an urgent need to develop a new type of all-round power grid network device scanning system and method. Summary of the Invention
[0005] The present application provides an all-round power grid network device scanning system and method to improve the efficiency of network scanning.
[0006] The present application provides an all-round power grid network device scanning system, including:
[0007] Multiple distributed scanning modules, where each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to devices in the network, collect configuration information, operating status, and security parameters of the devices, and generate a security assessment report of the devices; a storage unit for storing scanning results and related data; a communication unit for transmitting the scanning results to the central control module;
[0008] A central control module for managing and coordinating multiple distributed scanning modules;
[0009] A data processing module connected to the central control module for summarizing scanning data from multiple distributed scanning modules; analyzing the scanning data to detect potential security threats and network performance issues; generating an overall security and performance assessment report of network devices;
[0010] The user interface module, connected to the central control module and the data processing module, is used to provide an interface for users to access the scan results and evaluation reports; and accept user input to customize scan parameters and report formats.
[0011] Furthermore, each distributed scan module realizes automatic adaptation to different types of network protocols and device types through the following steps:
[0012] Step S101: After starting the scan module, initialize the network interface to enter the protocol detection mode;
[0013] Step S102: In the protocol detection mode, the scan module sends probe packets to devices in the network, where the probe packets include different network protocol identifiers, including SNMP, HTTP, HTTPS, Telnet, SSH, and IPP;
[0014] Step S103: By analyzing the received device responses, determine the network protocol types supported by each device, specifically including:
[0015] Detect the SNMP protocol response and confirm the device type by reading the device's MIB information;
[0016] Detect the HTTP / HTTPS protocol response and confirm the device type by sending a GET request and analyzing the returned HTML header information;
[0017] Detect the Telnet / SSH protocol response and confirm the device type by attempting to establish a connection and parsing the handshake information;
[0018] Detect the IPP protocol response and confirm the device type by sending a print service request and parsing the returned information;
[0019] Step S104: According to the network protocol types supported by each device determined in step S103, dynamically configure the scan engine to adapt to the protocol requirements of different devices, including adjusting network interface parameters and communication methods;
[0020] Step S105: Perform a deep scan under the supported network protocol types to collect scan data of the devices, where the scan data includes configuration information, running status, and security parameters;
[0021] Step S106: Store the collected scan data in the storage unit and transmit the scan data to the central control module through the communication unit.
[0022] Furthermore, the scan engine of each scan module is used to execute a multi-level security assessment algorithm, and the multi-level security assessment algorithm includes the following steps:
[0023] Step S2001: Conduct a preliminary scan on each scanned network device to collect the basic configuration information of the scanned network device. The basic configuration information includes the device name, IP address, and operating system version. Calculate the preliminary security score of the scanned device according to the following formula 1 :
[0024]
[0025] where represents the security score of the th item of basic configuration information; represents the total number of basic configuration information; represents the weight of the security score of the th item of basic configuration information;
[0026] Step S2002: According to the preliminary security score, conduct an in-depth scan on the network devices with potential risks to collect the advanced configuration information of the scanned network device. The advanced configuration information includes open ports, running services, and installed software versions. Calculate the intermediate security score of the scanned device according to the following formula 2 :
[0027]
[0028] where represents the security score of the th item of advanced configuration information; represents the total number of advanced configuration information; represents the risk weight of the th item of advanced configuration information;
[0029] Step S2003: According to the intermediate security score, perform a comprehensive security vulnerability scan on high-risk devices; according to the security vulnerability scan results, calculate the advanced security score of the scanned device according to the following formula 3 :
[0030]
[0031] where represents the severity score of the th vulnerability; represents the total number of security vulnerabilities scanned; represents the repair difficulty score of the th vulnerability;
[0032] Step S2004: Calculate the scan adjustment factor according to the preliminary security score, intermediate security score, and advanced security score according to the following formula 4 ;
[0033]
[0034] Among them, 、 and are adjustment factors;
[0035] Step S2005: If the calculated scan adjustment factor is greater than the first preset threshold, it indicates high risk. The scanning engine will increase the scanning port range, increase the frequency of scanning packets, and extend the scanning time; re-execute steps S2001 - S2003 to obtain the preliminary security score, intermediate security score, and advanced security score; and directly execute step S2005;
[0036] Step S2005: Calculate the final security score of the network device to be scanned according to the following formula 5 :
[0037]
[0038] Among them, 、 and are weight coefficients;
[0039] Step S2006: When the final security score of the device to be scanned is higher than the second preset threshold, mark the network device as high risk and recommend taking repair measures immediately; when the final security score of the device to be scanned is between the third preset threshold and the fourth preset threshold, mark the network device as medium risk and recommend repairing within an acceptable time range; when the final security score of the device to be scanned is lower than the third preset threshold, mark the network device as low risk and recommend regular monitoring and maintenance.
[0040] Furthermore, the data processing module includes a global risk score calculation algorithm for evaluating the security risk of the entire network by combining the risk scores of each device provided by each distributed scanning module, and dividing the network into high-risk, medium-risk, and low-risk areas; the global risk score calculation algorithm includes the following steps:
[0041] Collect the final security score of each network device from each distributed scanning module , represents the final security score of the th network device in the th distributed scanning module;
[0042] Calculate the The device weight coefficient of the th network device in a distributed scanning module :
[0043]
[0044] Among them, represents the importance score of the th network device in the th distributed scanning module; represents the position coefficient of the th network device in the th distributed scanning module in the network topology; represents the total number of distributed scanning modules; represents the th total number of network devices in the
[0045] The network is divided into multiple regions according to the network topology structure, and the risk score of each region is calculated according to the following formula 7:
[0046]
[0047] Among them, represents the risk score of the th region in the network; represents the set of distributed scanning modules belonging to the th region; represents the th total number of network devices in a distributed scanning module;
[0048] According to the calculated risk score of the th region in the network, the network is divided into high-risk regions, medium-risk regions and high-risk regions;
[0049] Calculate the global risk score of the network according to the following formula 8 :
[0050]
[0051] Among them, represents the total number of regions in the network; represents the weight coefficient of the th region, determined according to the importance of the region and the number of devices;
[0052] According to the calculated global risk score of the network , determine the overall risk level of the network.
[0053] Furthermore, In the distributed scanning module Importance score of each network device , calculated according to the following formula 9:
[0054]
[0055] in, Indicates the In the distributed scanning module Device type rating for each device; Indicates the In the distributed scanning module The functional score of each device is determined based on the functional importance of the device in the network; Indicates the In the distributed scanning module The business importance score of each device is based on its impact on business continuity; 、 and is the weight coefficient.
[0056] Furthermore, In the distributed scanning module The location coefficient of each network device in the network topology , calculated according to the following formula 10:
[0057]
[0058] in, Indicates the In the distributed scanning module The number of hops from a device to the network core node.
[0059] Furthermore, the user interface module includes an interactive visualization panel, and the interactive visualization panel is used to:
[0060] Display the topology of the entire network through a graphical interface, including the distribution of network devices, connection relationships and traffic paths;
[0061] Displays the scanning results of each distributed scanning module, including device configuration information, operating status and security parameters;
[0062] Provide security assessment reports, including security scores, risk levels, and improvement suggestions for each device;
[0063] Allows users to view detailed information about specific devices, adjust the network view, and add callouts and annotations by clicking and dragging.
[0064] Furthermore, the user interface module further includes a custom report generation function, allowing users to generate customized security assessment reports according to their needs.
[0065] Furthermore, the user interface module includes a real-time alarm and notification function, which is used to notify users in a timely manner when high-risk devices or abnormal network activities are detected.
[0066] The present application provides a method for scanning all-round power grid network devices, including:
[0067] Deploy multiple distributed scanning modules in the network. Each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to devices in the network, collect configuration information, operating status, and security parameters of the devices, and generate a security assessment report of the devices; a storage unit for storing scanning results and related data; a communication unit for transmitting the scanning results to the central control module;
[0068] Summarize the scanning data from multiple distributed scanning modules;
[0069] Analyze the scanning data to detect potential security threats and network performance problems;
[0070] Generate an overall security and performance assessment report of the network devices.
[0071] The beneficial effects of the present application mainly include: (1) Through the deployment of multiple distributed scanning modules, the system can efficiently cover and scan devices in a large-scale network, avoiding the performance bottleneck problem of the centralized scanning system when dealing with a large number of devices, and improving the overall scanning speed and efficiency. (2) The scanning engine equipped with each scanning module can automatically identify and connect to devices in the network, adapting to different network protocols and device types. This automatic identification and dynamic adaptation ability reduces the need for manual configuration and enhances the flexibility and adaptability of the system. (3) The central control module manages and coordinates multiple distributed scanning modules, realizing efficient scheduling of scanning tasks and synchronous transmission of results. This not only avoids the problem of single-point failure but also ensures centralized management and real-time update of data, improving the reliability and availability of the system. (4) The data processing module can summarize the scanning data from multiple distributed scanning modules, conduct in-depth analysis to detect potential security threats and network performance problems. By generating a comprehensive security and performance assessment report of network devices, it provides a global view of the network status, facilitating timely adoption of security protection measures. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 is a schematic diagram of an all-round power grid network device scanning system provided by the first embodiment of the present application.
[0073] Figure 2 It is a flowchart of an all-round power grid network device scanning method provided by the second embodiment of the present application. Detailed implementation manners
[0074] Many specific details are set forth in the following description in order to provide a thorough understanding of the present application. However, the present application can be implemented in many other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the connotation of the present application. Therefore, the present application is not limited by the specific implementations disclosed below.
[0075] The first embodiment of the present application provides an all-round power grid network device scanning system. Please refer to Figure 1 , which is a schematic diagram of the first embodiment of the present application. The following will be combined with Figure 1 to describe in detail an all-round power grid network device scanning system provided by the first embodiment of the present application.
[0076] The all-round power grid network device scanning system includes a plurality of distributed scanning modules 101, a central control module 102, a data processing module 103, and a user interface module 104.
[0077] A plurality of distributed scanning modules 101, wherein each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to devices in the network, collect configuration information, operating status, and security parameters of the devices, and generate a security assessment report of the devices; a storage unit for storing scanning results and related data; and a communication unit for transmitting the scanning results to the central control module.
[0078] In the all-round power grid network device scanning system, the plurality of distributed scanning modules 101 are the core components, and each module has multiple functions to ensure comprehensive, accurate, and efficient network device scanning and data collection.
[0079] First, each distributed scanning module 101 is equipped with a network interface, which is used to establish communication with the device to be scanned. The network interface can support multiple protocols, such as Ethernet, Wi-Fi, etc., to ensure that it can connect to various network devices. The configuration of the network interface enables the scanning module to seamlessly dock with different types of network environments and automatically detect and adapt to the devices in the network.
[0080] Secondly, the distributed scanning module 101 incorporates an efficient scanning engine. This scanning engine is configured to automatically identify and connect to devices in the network. Specifically, the scanning engine can send probe packets to discover devices in the network, and by analyzing the response data of the devices, determine detailed information such as the type of device, operating system, open ports, and running services. The scanning engine can handle multiple protocols, including but not limited to SNMP, HTTP, HTTPS, Telnet, SSH, and IPP, thus being able to comprehensively cover the scanning requirements of various network devices.
[0081] In terms of data collection, the distributed scanning module 101 can collect the configuration information, running status, and security parameters of the devices. The configuration information includes basic information of the devices such as name, IP address, operating system version, etc.; the running status includes real-time running data of the devices such as CPU utilization, memory usage, etc.; the security parameters involve the security configuration and potential vulnerability information of the devices. Through the automatic analysis and processing of the scanning engine, these data generate a security assessment report of the devices.
[0082] Each distributed scanning module 101 is equipped with a storage unit for storing the scanning results and related data. The storage unit can be an internal flash memory or an externally connected storage device, ensuring the security and integrity of the data. The design of the storage unit takes into account the requirements of efficient data access and long-term preservation to support subsequent data analysis and processing.
[0083] The communication unit is another important component of the distributed scanning module 101, which is used to transmit the scanning results to the central control module 102. The communication unit can establish a connection with the central control module through a wired or wireless network to ensure real-time and reliable data transmission. The design of the communication unit ensures the security of data transmission, preventing the data from being intercepted or tampered with during the transmission process.
[0084] Through the collaborative work of the above-mentioned various components, multiple distributed scanning modules 101 can effectively cover the entire network, providing detailed device scanning and data collection functions. Each scanning module can not only work independently but also be uniformly managed and coordinated through the central control module 102. The central control module can allocate scanning tasks, synchronize the work progress of each module, and summarize the data collected by all modules.
[0085] In summary, through multiple distributed scanning modules 101, this embodiment provides an efficient, flexible, and reliable network device scanning system, which can adapt to various complex network environments and provide comprehensive security assessment functions.
[0086] Furthermore, each distributed scanning module achieves automatic adaptation to different types of network protocols and device types through the following steps:
[0087] Step S101: After starting the scanning module, initialize the network interface to enter the protocol detection mode;
[0088] Step S102: In the protocol detection mode, the scanning module sends probe packets to devices in the network, where the probe packets include different network protocol identifiers, including SNMP, HTTP, HTTPS, Telnet, SSH, and IPP;
[0089] Step S103: By analyzing the received device responses, determine the network protocol types supported by each device, specifically including:
[0090] Detect the SNMP protocol response and confirm the device type by reading the device's MIB information;
[0091] Detect the HTTP / HTTPS protocol response and confirm the device type by sending a GET request and analyzing the returned HTML header information;
[0092] Detect the Telnet / SSH protocol response and confirm the device type by attempting to establish a connection and parsing the handshake information;
[0093] Detect the IPP protocol response and confirm the device type by sending a print service request and parsing the returned information;
[0094] Step S104: According to the network protocol types supported by each device determined in Step S103, dynamically configure the scanning engine to adapt to the protocol requirements of different devices, including adjusting network interface parameters and communication methods;
[0095] Step S105: Perform a deep scan under the supported network protocol types to collect scan data of the devices, where the scan data includes configuration information, operating status, and security parameters;
[0096] Step S106: Store the collected scan data in the storage unit and transmit the scan data to the central control module through the communication unit.
[0097] In the all-round power grid network device scanning system, each distributed scanning module realizes automatic adaptation to different types of network protocols and device types through a series of steps. This process ensures that the scanning module can efficiently and accurately identify and scan various devices in the network, regardless of the protocols or specific types they use.
[0098] First, after the scanning module is started, the system initializes the network interface and enters the protocol detection mode. In this mode, the scanning module sends probe packets to various devices in the network through the network interface. These probe packets contain identifiers of multiple network protocols, including but not limited to SNMP, HTTP, HTTPS, Telnet, SSH, and IPP. These identifiers help the scanning module identify the specific protocol types supported by the devices in the network.
[0099] Next, the scanning module analyzes the received device responses to determine the network protocol types supported by each device. For example, when detecting the SNMP protocol response, the scanning module reads the device's MIB information (Management Information Base) and confirms the device type by analyzing this information; when detecting the HTTP / HTTPS protocol response, the scanning module sends a GET request and confirms the device type by parsing the returned HTML header information; for the Telnet / SSH protocol, the scanning module attempts to establish a connection and parse the handshake information to confirm the device type; when detecting the IPP protocol response, the scanning module sends a print service request and confirms the device type by parsing the returned information.
[0100] Based on the network protocol types supported by each device determined in the above steps, the scanning module dynamically configures its scanning engine to adapt to the protocol requirements of different devices. This includes adjusting the parameters and communication methods of the network interface to ensure that the scanning engine can effectively communicate with the devices and accurately collect the required data. This dynamic configuration process is automatic and does not require manual intervention, thus improving the efficiency and accuracy of the system.
[0101] After the configuration is completed, the scanning module performs a deep scan for specific network protocol types. This deep scan process includes collecting various scanning data of the device, such as configuration information, running status, and security parameters. Configuration information may include device name, IP address, MAC address, operating system version, etc.; running status may include CPU and memory usage, network traffic statistics, etc.; security parameters include discovered security vulnerabilities, potential threats, and the security score of the device, etc.
[0102] All the collected scanning data will be stored in the storage unit of the scanning module to ensure the security and integrity of the data. Subsequently, this data will be transmitted to the central control module through the communication unit. The central control module is responsible for further data aggregation and analysis and feeds back the results to the user interface module for generating a detailed security assessment report and providing improvement suggestions.
[0103] Through these steps, the distributed scanning module can automatically adapt to different types of network protocols and device types, perform a comprehensive and in-depth device scan, and ensure that the system can provide an efficient and accurate network security assessment.
[0104] Furthermore, the scanning engine of each scanning module is used to execute a multi-level security assessment algorithm, and the multi-level security assessment algorithm includes the following steps:
[0105] Step S2001: Perform a preliminary scan on each network device to be scanned, and collect the basic configuration information of the network device to be scanned. Among them, the basic configuration information includes the device name, IP address, and operating system version; calculate the preliminary security score of the device to be scanned according to the following formula 1 :
[0106]
[0107] Among them, represents the security score of the th item of basic configuration information; represents the total number of basic configuration information; represents the th weight of the security score of the basic configuration information;
[0108] Step S2002: According to the preliminary security score, perform an in-depth scan on the network devices with potential risks, and collect the advanced configuration information of the network devices to be scanned. Among them, the advanced configuration information includes open ports, running services, and installed software versions; calculate the intermediate security score of the device to be scanned according to the following formula 2 :
[0109]
[0110] Among them, the th security score of the advanced configuration information; represents the total number of advanced configuration information; represents the th risk weight of the basic configuration information;
[0111] Step S2003: According to the intermediate security score, perform a comprehensive security vulnerability scan on high-risk devices; according to the security vulnerability scan results, calculate the advanced security score of the device to be scanned according to the following formula 3 :
[0112]
[0113] Among them, represents the severity score of the th vulnerability; represents the total number of security vulnerabilities scanned; represents the th repair difficulty score of the vulnerability;
[0114] Step S2004: Calculate the scanning adjustment factor according to the preliminary security score, intermediate security score, and advanced security score using the following Formula 4 ;
[0115]
[0116] wherein, 、 and are adjustment factors;
[0117] Step S2005: If the calculated scanning adjustment factor is greater than the first preset threshold, it indicates high risk. The scanning engine will increase the scanning port range, increase the frequency of scanning packets, and extend the scanning time; re - execute Steps S2001 - S2003 to obtain the preliminary security score, intermediate security score, and advanced security score; and directly execute Step S2005;
[0118] Step S2005: Calculate the final security score of the network device to be scanned according to the following Formula 5 :
[0119]
[0120] wherein, 、 and are weight coefficients;
[0121] Step S2006: When the final security score of the device to be scanned is higher than the second preset threshold, mark the network device as high - risk and recommend taking repair measures immediately; when the final security score of the device to be scanned is between the third preset threshold and the fourth preset threshold, mark the network device as medium - risk and recommend repairing within an acceptable time range; when the final security score of the device to be scanned is lower than the third preset threshold, mark the network device as low - risk and recommend regular monitoring and maintenance.
[0122] In the all - around power grid network device scanning system, the scanning engine of each scanning module is used to execute a multi - level security assessment algorithm to comprehensively evaluate the security of network devices. This algorithm includes multiple steps. Each step aims to collect and analyze different information of the device, and calculate the security score based on this information, so as to determine the risk level of the device. The following is a detailed description of each step and its calculation formula.
[0123] In the initial scanning phase, the scanning engine conducts an initial scan of each network device being scanned to collect basic configuration information, including device name, IP address, and operating system version. This information is extracted from the device through standard network protocols (such as SNMP, HTTP, etc.). To calculate the initial security score of the device , the formula is used:
[0124]
[0125] where represents the security score of the th item of basic configuration information. For example, the security score of the device name may be based on whether it conforms to the naming convention, the security score of the IP address may be based on whether it is within a secure range, and the security score of the operating system version may be based on whether it is the latest version. represents the total number of basic configuration information items. The security score of each item is predefined and based on known security standards. The weight represents the importance of the th item of basic configuration information in the overall score. These weights are also predefined and reflect the degree of impact of each item of information on the overall security.
[0126] Based on the initial security score, for network devices with potential risks, the scanning engine will conduct an in-depth scan to collect advanced configuration information, including open ports, running services, and installed software versions. This advanced configuration information is obtained through more detailed probe packets and protocol interactions (such as reading port information through SNMP, checking running services through SSH or Telnet, etc.). Then, the following formula is used to calculate the intermediate security score :
[0127]
[0128] where represents the security score of the th item of advanced configuration information. For example, the score of an open port may be based on the open status and risk level of the port, the score of a running service may be based on the importance of the service and known vulnerabilities, and the score of the installed software version may be based on the known vulnerabilities and patch status of the software. represents the total number of advanced configuration information items. The risk weight represents the risk level of the th item of advanced configuration information. These weights are based on the specific impact of each item of information on the device security.
[0129] For devices determined to be at high risk, the scanning engine will perform a comprehensive security vulnerability scan. This step involves detecting matches in the known vulnerability database and attempting to exploit these vulnerabilities to confirm their existence. The security vulnerability scan results are used to calculate an advanced security score , using the formula:
[0130]
[0131] where, represents the severity score of the th vulnerability, usually based on the CVSS (Common Vulnerability Scoring System) score. represents the total number of security vulnerabilities found by the scan. The repair difficulty score represents the repair difficulty of the th vulnerability. The higher the score, the greater the repair difficulty. This formula takes into account the severity and repair difficulty of the vulnerabilities to comprehensively evaluate the impact of the vulnerabilities on the device's security.
[0132] To determine whether the scanning strategy needs to be adjusted, the scanning engine calculates a scan adjustment factor based on the preliminary, intermediate, and advanced security scores , using the formula:
[0133]
[0134] where, , and are adjustment factors representing the weights of the preliminary, intermediate, and advanced security scores. This formula combines the scores and adjusts them through a logistic function to determine whether to increase the depth and breadth of the scan. If is greater than the preset threshold, it indicates that the device has a high risk. The scanning engine will increase the scan scope, increase the frequency of scan packets, and extend the scan time, and re-perform a multi-level security assessment.
[0135] Finally, after completing the above steps, the scanning engine calculates the final security score of the device , using the formula:
[0136]
[0137] where, , and are weight coefficients representing the importance of each level of score. The final score Combined with preliminary, intermediate, and advanced scoring, it reflects the comprehensive security status of the device. According to the final score, the device is marked as high, medium, or low risk, and corresponding security recommendations are provided. For example, high-risk devices need to be repaired immediately, medium-risk devices need to be repaired within an acceptable time frame, and low-risk devices are monitored regularly.
[0138] Furthermore, the data processing module includes a global risk scoring calculation algorithm for combining the risk scores of each device provided by each distributed scanning module, evaluating the security risks of the entire network, and dividing the network into high-risk, medium-risk, and low-risk areas. The global risk scoring calculation algorithm includes the following steps:
[0139] Collect the final security scores of each network device from each distributed scanning module , Denote the final security score of the -th network device in the -th distributed scanning module;
[0140] Calculate the device weight coefficient of the -th network device in the -th distributed scanning module according to the following formula 6 :
[0141]
[0142] Wherein, Denote the importance score of the -th network device in the -th distributed scanning module; Denote the position coefficient of the -th network device in the -th distributed scanning module in the network topology; Denote the total number of distributed scanning modules; Denote the -th distributed scanning module in the total number of network devices;
[0143] Divide the network into multiple regions according to the network topology structure, and calculate the risk score of each region according to the following formula 7:
[0144]
[0145] Wherein, Denote the risk score of the -th region in the network; Denote the set of distributed scanning modules belonging to the -th region; Denote the The total number of network devices in a distributed scanning module;
[0146] According to the calculated risk score of the th area in the network, the network is divided into high-risk areas, medium-risk areas, and low-risk areas;
[0147] Calculate the global risk score of the network according to the following formula 8 :
[0148]
[0149] Where represents the total number of areas in the network; represents the th area's weight coefficient, determined according to the importance of the area and the number of devices;
[0150] According to the calculated global risk score of the network , determine the overall risk level of the network.
[0151] In the all-round power grid network device scanning system, the data processing module contains a global risk score calculation algorithm, which is used to comprehensively evaluate the security risks of the entire network and divide the network into high-risk, medium-risk, and low-risk areas. This algorithm combines the risk scores of each device provided by each distributed scanning module and accurately evaluates and divides the network risks through detailed calculation steps.
[0152] First, the data processing module collects the final security scores of each network device from each distributed scanning module . Where represents the final security score of the th network device in the th distributed scanning module, and these scores are calculated through the multi-level security assessment algorithm described above.
[0153] In order to evaluate the importance of each device in the overall network, the device weight coefficient of each device needs to be calculated through the following formula:
[0154]
[0155] In this formula, represents the importance score of the th network device in the th distributed scanning module. The importance score can be quantified based on the device type, business criticality, and historical risk data. The location coefficient Indicates the position of the device in the network topology, which can be obtained by calculating the hop count from the device to the network core node. The fewer the hop count, the higher the position coefficient. represents the total number of distributed scanning modules, while represents the total number of network devices in the th distributed scanning module. The denominator part of the formula ensures the normalization of the weight coefficient
[0156] so that the sum of the weights of all devices is 1. . The formula is as follows:
[0157]
[0158] where represents the risk score of the th area in the network. represents the set of distributed scanning modules belonging to the th area. Through this formula, the risk score of each device is multiplied by its weight coefficient, and these values are accumulated within the same area to obtain the overall risk score of the area. still represents the total number of network devices in the
[0159] th distributed scanning module. Based on the calculated risk scores of each area
[0160] , the network can be divided into high-risk areas, medium-risk areas, and low-risk areas. This division is based on the comparison between the preset risk threshold and the area risk score, helping to identify the high-risk areas that need to be prioritized. :
[0161]
[0162] In this formula, represents the total number of areas in the network, represents the weight coefficient of the th area. These weight coefficients are determined based on the importance of each area and the number of devices, reflecting the relative importance of each area in the overall network. By multiplying the risk scores Multiply and sum, then divide by the sum of all weight coefficients to get the global risk score of the entire network This global risk score is used to determine the overall risk level of the network and provide a basis for the formulation of network security policies.
[0163] Furthermore, In the distributed scanning module Importance score of each network device , calculated according to the following formula 9:
[0164]
[0165] in, Indicates the In the distributed scanning module Device type rating for each device; Indicates the In the distributed scanning module The functional score of each device is determined based on the functional importance of the device in the network; Indicates the In the distributed scanning module The business importance score of each device is based on its impact on business continuity; 、 and is the weight coefficient.
[0166] In the comprehensive power grid network equipment scanning system, the importance score of the network equipment in each distributed scanning module Calculated based on multiple factors, this score is designed to quantify the importance of each device within the overall network, thus playing a key role in calculating the overall risk score.
[0167] No. In the distributed scanning module Importance score of each network device It is calculated by the following formula:
[0168]
[0169] In this formula, This represents the device type score, which reflects the nature of the device and its role in the network. Device type scores can be preset based on the type of device. For example, core routers and switches might be given a higher score because they are critical to the overall function of the network, while common workstations or printers might receive a lower score. The specific score can be set by the network administrator based on the importance of the device type.
[0170] Denotes the functional score, which is scored based on the functional importance of the device in the network. The functional score of a device takes into account the specific tasks performed by the device in the network and its impact on network operations. For example, servers that undertake critical tasks (such as database servers, authentication servers, etc.) will be given a high functional score because their operation directly affects business continuity and efficiency; while ordinary file servers or backup devices may have a lower functional score. This score needs to be evaluated by the network administrator according to the actual functions and importance of the devices.
[0171] Denotes the business importance score, which reflects the impact of the device on business continuity. The business importance score considers the degree of impact of device downtime or failure on the entire business process. For example, if a server or storage device that supports the customer transaction system fails, it will have a significant impact on the business, so it will have a high business importance score; while problems with some auxiliary system devices may not have a direct impact on the core business, so the score is lower. This score also needs to be scored by the network administrator according to the role and importance of the device in the business process.
[0172] In the formula, 、 and are weight coefficients, which are used to adjust the weights of device type, function, and business importance scores in the overall importance score. The selection of weight coefficients can be determined according to the specific situation of the network and the focus of the security policy. For example, if the type of network device is particularly important for security assessment, the administrator can set a higher value; if the functionality of the device is more critical, the proportion of can be increased; if business continuity is the main concern, can account for a larger weight.
[0173] The calculated through the above formula comprehensively considers the type, function, and impact on the business of the device, and accurately reflects the importance of each device in the network. This importance score plays a crucial role in the global risk assessment, helping to conduct more accurate risk management and resource allocation.
[0174] Furthermore, the location coefficient of the rd network device in the th distributed scanning module is calculated according to the following formula 10:
[0175]
[0176] Where, Indicates the hop count from the th device in the
[0177] In an all-round power grid network device scanning system, the position coefficient of a network device in each distributed scanning module in the network topology is calculated based on the hop count from the device to the network core node. The position coefficient is calculated to quantify the relative position and importance of the device in the network, so as to more accurately reflect the risk weight of the device in the overall risk assessment.
[0178] The position coefficient of the th network device in the th distributed scanning module in the network topology is calculated by the following formula:
[0179]
[0180] In this formula, represents the hop count from the th device in the
[0181] th distributed scanning module to the network core node. The hop count is the number of intermediate nodes that need to be passed through to reach the network core node from this device. The core node usually refers to the central hub of the network, such as a core switch or router, which connects most devices in the network and undertakes the main data transmission tasks. The hop count can be obtained through a network topology discovery algorithm. When the distributed scanning module scans the network, it can determine the hop count of the device by sending probe packets and recording the hop count information in each response packet. These probe packets usually use ICMP (Internet Control Message Protocol) or routing protocols (such as OSPF, EIGRP, etc.) to obtain. The scanning module will record the response path of each device, thereby determining the hop count of each device to the core node.
[0182] The position coefficient in the formula is calculated by taking the reciprocal after adding 1 to the hop count . The operation of adding 1 is to avoid division by zero. Even if the device is directly connected to the core node (hop count is 0), its position coefficient can be correctly calculated. The operation of taking the reciprocal is to make the position coefficient inversely proportional to the hop count, that is, the fewer the hop counts, the larger the position coefficient, and vice versa. This design reflects that the closer the device is to the core node, the more important its position in the network, because they usually undertake more network traffic and key tasks.
[0183] For example, if a device is directly connected to the core node, its hop count is 0, then its position coefficient is 1. If a device needs to pass through two intermediate nodes to reach the core node, its hop count is 2, then its position coefficient is 1 / 3. In this way, through the calculation of the position coefficient the relative positions of all devices in the network can be quantified with a unified standard, so as to be used in the calculation of the global risk score.
[0184] To sum up, the position coefficient quantifies the position importance of a device in the network topology by accurately calculating the hop count from the device to the network core node. This position coefficient plays a key role in the overall risk assessment and helps to more accurately allocate the risk weights of devices.
[0185] The central control module 102 is used to manage and coordinate multiple distributed scanning modules.
[0186] In the all-round power grid network device scanning system, the central control module 102 plays a crucial role. Its main function is to manage and coordinate multiple distributed scanning modules 101 to ensure the efficient operation of the entire system and the unified processing of data.
[0187] The central control module 102 is first responsible for receiving and processing the scanning results from multiple distributed scanning modules 101. These scanning results are transmitted from each distributed scanning module to the central control module through the communication unit. To process a large amount of data, the central control module is equipped with powerful processing capabilities and can efficiently receive and store this data. It uses multi-threading or parallel processing technologies to ensure the real-time and integrity of data transmission.
[0188] In terms of data management, the central control module 102 performs unified data summarization and storage operations. The scanning data collected from each distributed scanning module will be integrated into a centralized storage repository. This centralized storage repository adopts an efficient data structure and indexing mechanism to ensure the fast access and management of data. Through this centralized management, the central control module can ensure the consistency and integrity of data, and avoid data duplication and conflicts.
[0189] In addition to data management, the central control module 102 is also responsible for scheduling and coordinating the tasks of multiple distributed scanning modules. It dynamically allocates scanning tasks to each distributed scanning module according to the pre-set scanning strategy and network topology. For example, the central control module can determine which scanning modules are responsible for scanning which devices based on the geographical location of the devices, the network load conditions, and the importance of the devices. This dynamic task allocation mechanism can optimize the utilization rate of scanning resources and improve the overall scanning efficiency.
[0190] The central control module 102 also has real-time monitoring and feedback functions. It continuously monitors the operating status of each distributed scanning module, including their task execution status, resource usage conditions (such as CPU and memory utilization), and network bandwidth usage. When an abnormality is detected in a certain scanning module (such as resource exhaustion or network connection interruption), the central control module can immediately issue an alarm and take corresponding measures, such as reallocating scanning tasks, adjusting the scanning frequency, or notifying the system administrator to intervene.
[0191] To improve the flexibility and adaptability of the system, the central control module 102 also implements intelligent adjustment and optimization functions. Based on real-time monitoring data and historical scanning data, the central control module can adjust scanning parameters, such as scanning depth, frequency, and range. For example, when the network traffic is low during a certain period, the central control module can increase the scanning frequency to more comprehensively detect potential threats; while during the peak period of network traffic, it can reduce the scanning frequency to reduce the impact on network performance. In addition, the central control module can also use machine learning algorithms to analyze historical data and predict possible future security threats, so as to adjust the scanning strategy in advance.
[0192] The central control module 102 is also responsible for the interaction with the data processing module 103 and the user interface module 104. It transfers the aggregated data to the data processing module 103 for in-depth analysis, detects potential security threats and network performance problems, and generates an overall security and performance evaluation report. At the same time, the central control module cooperates with the user interface module 104 to provide a user-friendly interface through which users can access the scanning results and evaluation reports and customize scanning parameters and report formats.
[0193] In summary, through effective management and coordination functions, the central control module 102 ensures the collaborative work of multiple distributed scanning modules 101, realizing centralized data processing, dynamic task allocation, real-time monitoring, and intelligent adjustment and optimization.
[0194] The data processing module 103, connected to the central control module, is used to aggregate the scan data from multiple distributed scan modules; analyze the scan data to detect potential security threats and network performance issues; and generate an overall security and performance evaluation report for network devices.
[0195] In the all-round power grid network device scanning system, the data processing module 103 plays a key role, responsible for aggregating, analyzing, and processing the scan data from multiple distributed scan modules 101, thereby detecting potential security threats and network performance issues, and generating a comprehensive security and performance evaluation report for network devices.
[0196] The data processing module 103 first receives the aggregated scan data from the central control module 102. The central control module is responsible for initially sorting out the raw data transmitted by multiple distributed scan modules and passing it to the data processing module after unifying the format. After receiving this data, the data processing module stores it in an internal high-efficiency database. This database is designed to be able to quickly access and store a large amount of data and support high-concurrency access to ensure the real-time and effectiveness of data processing.
[0197] In the data aggregation stage, the data processing module 103 merges the data from different distributed scan modules. These data include device configuration information, operating status, and security parameters. Through advanced data fusion technology, the data processing module can effectively remove redundant information and ensure the consistency and accuracy of the data. At the same time, it also preprocesses the data, such as data cleaning and format conversion, to facilitate subsequent analysis.
[0198] Entering the data analysis stage, the data processing module 103 uses a variety of analysis algorithms to deeply mine and analyze the aggregated data. First, it uses statistical analysis methods to detect common security problems and performance bottlenecks in the network. For example, by analyzing the operating status data of devices, it can identify devices with abnormally high CPU and memory usage, which may have potential performance problems. Secondly, the data processing module applies pattern recognition and machine learning algorithms to detect complex security threats. These algorithms can identify abnormal network behavior patterns, such as abnormal traffic surges or connection requests from unknown devices, which may indicate that the network is under attack.
[0199] After detecting potential threats and performance issues, the data processing module 103 also generates detailed security and performance assessment reports. These reports not only include the detected problems but also provide specific risk assessments and improvement suggestions. For example, if a known security vulnerability is detected in a certain device, the report will detail the severity of the vulnerability and the repair suggestions; if there is a performance bottleneck in a certain network area, the report will suggest optimizing the network configuration or increasing the bandwidth. Through these detailed reports, users can have a comprehensive understanding of the security status and performance of the network and take corresponding measures for improvement.
[0200] The data processing module 103 is also responsible for generating overall security and performance assessment reports for the network. These reports are based on the data analysis results of the entire network and provide a comprehensive evaluation of the security risks and performance status of the network as a whole. For example, by aggregating the risk scores of each device and each area, the data processing module can calculate the overall risk level of the entire network, helping users identify high-risk areas and key protection objects in the network. At the same time, the performance assessment report will provide key performance indicators such as network traffic distribution, bandwidth utilization, and latency, helping users optimize the configuration and use of network resources.
[0201] In addition, the data processing module 103 works closely with the user interface module 104 to ensure that users can easily access and utilize the analysis results. Users can access various reports generated by the data processing module through the user interface module and customize the report format and content according to actual needs. The user interface module provides an intuitive graphical interface through which users can view the network topology diagram, device status, and security risk details, and even generate customized reports to meet specific management and auditing requirements.
[0202] In summary, in the all-round power grid network device scanning system, the data processing module 103 receives, aggregates, analyzes, and processes data from multiple distributed scanning modules, detects potential security threats and performance issues, and generates comprehensive security and performance assessment reports.
[0203] The user interface module 104, connected to the central control module and the data processing module, is used to provide an interface for users to access the scanning results and assessment reports; accept user input to customize scanning parameters and report formats.
[0204] In the all-round power grid network device scanning system, the user interface module 104 is the interaction bridge between the system and users. It is finely designed and fully functional, ensuring that users can easily access the scanning results and assessment reports and customize the scanning parameters and report formats according to their needs.
[0205] The user interface module 104 first provides an intuitive and user-friendly graphical interface. Through modern UI / UX design, this interface enables users to easily navigate and operate. The interface includes multiple views and panels, presenting the network topology diagram, the status of each device, real-time scan results, and detailed security assessment reports. The network topology diagram visually shows the entire network structure. Users can click on nodes to view detailed information about specific devices, such as configuration information, operating status, and security parameters.
[0206] This module supports the display and update of real-time data. Users can view the changes in the network in real time. For example, when a new device is connected to the network or the status of an existing device changes, the interface will be updated immediately to ensure that users obtain the latest information. The real-time data display includes not only the basic information of the devices but also the security threats and performance issues discovered during the scan, enabling users to quickly respond to and handle potential risks.
[0207] To meet the different needs of users, the user interface module 104 provides powerful customization functions. Users can set scan parameters through the interface according to their own needs, such as selecting the types of devices to be scanned, specifying the scan time interval and depth, and choosing specific security metrics and performance parameters to be included in the report. Users can also create and save multiple scan configuration files for quick switching and application in different scenarios.
[0208] In addition, the user interface module 104 has a custom report generation function. Users can select predefined report templates or create custom templates according to their needs, setting the structure, content, and format of the report. The generated reports can include detailed information such as the basic information of the devices, security scores, detected security threats, performance analysis, and improvement suggestions. These reports can be exported in multiple formats, such as PDF, HTML, or Excel, for users to archive, share, or further analyze.
[0209] The user interface module 104 also integrates alarm and notification functions. Users can set alarm conditions through the interface. For example, when the security score of a certain device exceeds a certain threshold or when the network traffic increases abnormally, the system will automatically trigger an alarm. The alarm information will be notified to users through various methods such as interface pop-ups, emails, or text messages to ensure that users can take timely measures. This function greatly improves the security response ability of the system and prevents potential threats from evolving into actual damages.
[0210] The user interface module 104 is not just a display tool but also supports user interaction operations. Users can perform various operations through the interface, such as starting or stopping a scanning task, adjusting the scanning strategy, viewing and processing alarm information, etc. These operations are seamlessly integrated with the central control module 102 and the data processing module 103 in the background, ensuring that the user's operations can be executed quickly and effectively and are reflected in the overall operation of the system.
[0211] Finally, the user interface module 104 also provides rich help and support functions. The interface embeds detailed usage guides and FAQs to help users quickly get started and solve common problems. At the same time, users can submit technical support requests through the interface to communicate with the technical team and obtain timely help and services.
[0212] In summary, the user interface module 104 ensures that users can comprehensively and effectively utilize the various functions of the all-round power grid network device scanning system by providing an intuitive graphical interface, real-time data display and update, powerful customization and report generation functions, alarm and notification functions, as well as rich interaction and support functions.
[0213] Furthermore, the user interface module includes an interactive visualization panel, and the interactive visualization panel is used for:
[0214] Displaying the topology of the entire network through a graphical interface, including the distribution of network devices, connection relationships, and traffic paths;
[0215] Showing the scanning results of each distributed scanning module, including the configuration information, operating status, and security parameters of the devices;
[0216] Providing a security assessment report, including the security score, risk level, and improvement suggestions for each device;
[0217] Allowing users to view detailed information about specific devices, adjust the network view, and add markings and annotations through click and drag operations.
[0218] In the all-round power grid network device scanning system, the user interface module specifically designs an interactive visualization panel to provide comprehensive and intuitive network management and security assessment functions. The interactive visualization panel displays the topology of the entire network through a graphical interface, enabling users to clearly see the distribution of network devices, connection relationships, and traffic paths. This visual representation can not only help users intuitively understand the physical and logical structure of the network but also be updated in real time to reflect dynamic changes in the network.
[0219] The interactive visualization panel displays the scanning results of each distributed scanning module, which include the detailed configuration information, operating status, and security parameters of the devices. The configuration information may include the device name, IP address, MAC address, operating system version, etc.; the operating status may include CPU and memory usage, network traffic statistics, etc.; and the security parameters include discovered security vulnerabilities, potential threats, and the security score of the device. Through this detailed information display, users can comprehensively understand the current status of each network device.
[0220] In addition, the interactive visualization panel also provides a comprehensive security assessment report. This report details the security score, risk level, and improvement suggestions for each device. For example, for a certain device, if its security score is low, the panel will display its risk level as high and provide specific improvement suggestions, such as upgrading the operating system, patching known vulnerabilities, or changing insecure configurations. This security assessment report not only helps users identify the weak links in the network but also provides specific action guidance to enhance the overall network security.
[0221] The interactive visualization panel design of the user interface module allows users to view the detailed information of specific devices, adjust the network view, and add markings and annotations through click and drag operations. Through click operations, users can quickly view the detailed configuration information and security status of a certain device; through drag operations, users can rearrange the positions of network devices and adjust the layout of the network view to better meet actual needs or personal preferences; through the function of adding markings and annotations, users can mark and explain specific devices or connections in the network diagram for future reference or sharing with team members.
[0222] This interactive design greatly improves the convenience and efficiency of users for network management and security monitoring. Users can easily conduct network monitoring, problem diagnosis, and security management through these interactive operations without the need to deeply understand the underlying technical details. At the same time, the system will update and save the network configuration in real time according to the user's operations to ensure the consistency and synchronization of the user interface and background management.
[0223] In summary, this embodiment provides an intuitive, detailed, and highly interactive network management and security assessment tool through the interactive visualization panel in the user interface module. This panel displays the network topology structure and detailed device information, generates a comprehensive security assessment report, and supports users to perform interactive management through click and drag operations.
[0224] Furthermore, the user interface module also includes a custom report generation function that allows users to generate customized security assessment reports according to their needs.
[0225] In the all-round power grid network equipment scanning system, the user interface module is specifically designed with a custom report generation function to meet the personalized needs of users for security assessment reports. This function enables users to generate detailed security assessment reports according to specific requirements and preferences, so as to better understand and manage the security status of network equipment.
[0226] The custom report generation function of the user interface module first provides a friendly and intuitive user interface that allows users to easily select the report content and format. Users can select the scanning parameters and evaluation metrics to be included through the interface, such as the basic configuration information of the device, security scores, risk levels, discovered vulnerabilities, operating status, and network performance data, etc. In this way, users can decide which information is necessary according to specific needs and exclude irrelevant content, so as to generate concise and targeted reports.
[0227] To further enhance the customization of the report, the user interface module also allows users to select different report templates. These templates can be pre-designed or created and saved by users themselves. Users can set the report title, chapter structure, chart types, and layout methods to ensure that the generated report is not only rich in content but also meets the standards of users or organizations in terms of format. Users can adjust the position and order of each part of the report through drag-and-drop operations to make the report more in line with reading habits and review requirements.
[0228] During the report generation process, the user interface module will automatically extract the latest scanning data and analysis results from the central control module and the data processing module. The system will sort and summarize these data according to the user's selection and generate a report in a predetermined format. The whole process is highly automated, and users only need to make simple selections and settings to generate high-quality security assessment reports.
[0229] The generated report is not limited to screen display but can also be exported to various common formats, such as PDF, Word, and Excel files, etc., for easy printing, archiving, and sharing. Users can choose to send the report to a specific email address or upload it to the organization's internal sharing platform. This flexible export and sharing function ensures that the report can be widely reviewed and discussed, promoting the timely discovery and resolution of security issues.
[0230] The custom report generation function also includes options for generating and updating reports regularly. Users can set the time interval for automatically generating reports, such as daily, weekly, or monthly, and the system will automatically generate and send reports at the scheduled time. This regular report function ensures that users always keep abreast of the latest network security status and take necessary protection measures in a timely manner.
[0231] In summary, the custom report generation function in the user interface module enables users to generate detailed and customized security assessment reports according to their needs by providing a flexible selection and setting interface.
[0232] Furthermore, the user interface module includes real-time alarm and notification functions for promptly notifying users when high-risk devices or abnormal network activities are detected.
[0233] The comprehensive power grid network device scanning system incorporates real-time alarm and notification functionality within the user interface module, ensuring prompt notification of high-risk devices or unusual network activity. This functionality provides a rapid response mechanism, helping users identify and address potential security threats as quickly as possible, thereby maintaining overall network security.
[0234] The user interface module's real-time alarm and notification capabilities are primarily based on the system's continuous monitoring of network devices. The distributed scanning module regularly collects device operating status and security parameters, while the data processing module analyzes this data in real time. If a device's security score falls below a preset threshold, or if unusual network activity is detected (such as a surge in traffic or the access of an unknown device), the system immediately triggers an alarm.
[0235] Once the alert mechanism is activated, the user interface module notifies the user through various channels. The first is a pop-up notification window. While the user is using the system interface, a pop-up window will be prominently displayed on the screen, alerting the user to the abnormality. This pop-up window typically contains detailed alert information, including the name and IP address of the affected device, a description of the specific security issue or abnormal behavior, and recommended initial response measures.
[0236] To ensure users receive alarm notifications even when not using the user interface, the user interface module supports email and SMS notifications. Alarm notifications are automatically sent to pre-configured email addresses and mobile phone numbers. Emails and SMS messages are concise and contain key alarm information, along with links to detailed system reports. Users can click on these links to view detailed information and take appropriate action.
[0237] The user interface module also supports mobile push notifications. If users have installed the system's accompanying mobile app, the system can send alerts directly to their mobile devices via push notifications. This allows users to receive real-time network security updates and respond promptly, even when away from the office.
[0238] The real-time alarm and notification function of the user interface module also provides a detailed alarm record and management interface. Each alarm will be recorded by the system. Users can view the historical alarm records through the interface to understand the past security incidents, handling situations, and the current security status. The alarm records are arranged in chronological order and support multiple filtering and sorting methods. Users can quickly find specific alarm records according to conditions such as time period, alarm type, and device name.
[0239] In addition, the user interface module allows users to customize alarm rules and notification methods. Users can set different alarm thresholds and conditions according to specific security policies. For example, for critical servers, lower security score thresholds and more stringent monitoring conditions can be set. Users can also select different notification methods and recipient groups to ensure that alarm information can be transmitted to the appropriate personnel, improving the efficiency and accuracy of alarm handling.
[0240] Through the above design, when the real-time alarm and notification function of the user interface module detects high-risk devices or abnormal network activities, it can quickly and accurately notify users to ensure that users can take necessary security measures in a timely manner.
[0241] In the above embodiment, an all-round power grid network device scanning system is provided. Correspondingly, the present application also provides an all-round power grid network device scanning method. Please refer to Figure 2 , which is a flowchart of an embodiment of the all-round power grid network device scanning method of the present application. Since this embodiment, that is, the second embodiment, is basically similar to the first embodiment, the description is relatively simple. For related parts, refer to the partial description of the first embodiment. The method embodiments described below are merely illustrative.
[0242] An all-round power grid network device scanning method provided by the second embodiment of the present application includes:
[0243] Step S201: Deploy multiple distributed scanning modules in the network. Each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to devices in the network, collect the configuration information, operating status, and security parameters of the devices, and generate a security assessment report for the devices; a storage unit for storing scanning results and related data; a communication unit for transmitting the scanning results to the central control module;
[0244] Step S202: Aggregate the scanning data from multiple distributed scanning modules;
[0245] Step S203: Analyze the scanning data to detect potential security threats and network performance problems;
[0246] Step S204: Generate an overall security and performance evaluation report for the network device.
[0247] Although this application is disclosed above with preferred embodiments, it is not intended to limit this application. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of this application. Therefore, the protection scope of this application shall be subject to the scope defined by the claims of this application.
Claims
1. An all-round power grid network device scanning system, characterized in that, Comprising: Multiple distributed scanning modules, where each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to devices in the network, collect the configuration information, operating status, and security parameters of the devices, and generate a security assessment report for the devices; a storage unit for storing the scanning results and related data; a communication unit for transmitting the scanning results to the central control module; A central control module for managing and coordinating multiple distributed scanning modules; A data processing module connected to the central control module for aggregating the scanning data from multiple distributed scanning modules; analyzing the scanning data to detect potential security threats and network performance issues; generating an overall security and performance assessment report for the network devices; A user interface module connected to the central control module and the data processing module for providing an interface for the user to access the scanning results and assessment reports; accepting user input to customize the scanning parameters and report format; Wherein, the scanning engine of each scanning module is used to execute a multi-level security assessment algorithm, and the multi-level security assessment algorithm includes the following steps: Step S2001: Conduct a preliminary scan on each scanned network device to collect the basic configuration information of the scanned network device, where the basic configuration information includes the device name, IP address, and operating system version; calculate the preliminary security score of the scanned device according to the following formula 1 :[[]]END]] Among them, represents the security score of the th item of basic configuration information; represents the total number of basic configuration information; represents the weight of the security score of the th item of basic configuration information; Step S2002: According to the preliminary security score, conduct an in-depth scan of network devices with potential risks, and collect the high-level configuration information of the scanned network devices, where the high-level configuration information includes open ports, running services, and installed software versions; calculate the intermediate security score of the scanned device according to the following formula 2 : in, Indicates the Security score of advanced configuration information; Indicates the total number of advanced configuration information; Indicates the Risk weight of high-level configuration information; Step S2003: Perform a comprehensive security vulnerability scan on high-risk devices based on the intermediate security score; calculate the advanced security score of the scanned devices according to the following formula 3 based on the security vulnerability scan results : Among them, represents the severity score of the th vulnerability; represents the total number of security vulnerabilities scanned; represents the repair difficulty score of the th vulnerability; Step S2004: Calculate the scan adjustment factor according to the following formula 4 based on the preliminary security score, the intermediate security score and the advanced security score: ; in, 、 and is the adjustment factor; Step S2005: If the calculated scan adjustment factor If the score is greater than the first preset threshold, it indicates a high risk. The scanning engine will increase the scanning port range, increase the frequency of scanning packets, and extend the scanning time. Steps S2001-S2003 will be re-executed to obtain the preliminary security score, the intermediate security score, and the advanced security score. Step S2005 will then be directly executed. Step S2005: Calculate the final security score of the network device being scanned according to Formula 5 below : Among them, , and are weighting coefficients; Step S2006: When the final security score of the device to be scanned is higher than the second preset threshold, mark the network device as high-risk and recommend immediate repair measures; when the final security score of the device to be scanned is between the third preset threshold and the fourth preset threshold, mark the network device as medium-risk and recommend repair within an acceptable time range; when the final security score of the device to be scanned is lower than the third preset threshold, mark the network device as low-risk and recommend regular monitoring and maintenance.
2. The all-round power grid network device scanning system according to claim 1, wherein Each distributed scanning module realizes automatic adaptation to different types of network protocols and device types through the following steps: Step S101: After starting the scanning module, initialize the network interface to enter the protocol detection mode; Step S102: In the protocol detection mode, the scanning module sends probe packets to the devices in the network, where the probe packets include different network protocol identifiers, including SNMP, HTTP, HTTPS, Telnet, SSH, and IPP; Step S103: By analyzing the received device responses, determine the network protocol types supported by each device, specifically including: Detect the SNMP protocol response and confirm the device type by reading the MIB information of the device; Detect the HTTP / HTTPS protocol response and confirm the device type by sending a GET request and analyzing the returned HTML header information; Detect the Telnet / SSH protocol response and confirm the device type by attempting to establish a connection and parsing the handshake information; Detect the IPP protocol response and confirm the device type by sending a print service request and parsing the returned information; Step S104: According to the network protocol types supported by each device determined in step S103, dynamically configure the scanning engine to adapt to the protocol requirements of different devices, including adjusting the network interface parameters and communication methods; Step S105: Perform a deep scan under the supported network protocol types to collect the scanning data of the devices, and the scanning data includes configuration information, operating status, and security parameters; Step S106: Store the collected scanning data in the storage unit and transmit the scanning data to the central control module through the communication unit.
3. The all-round power grid network device scanning system according to claim 1, characterized in that, The data processing module includes a global risk score calculation algorithm for combining the risk scores of each device provided by each distributed scanning module, evaluating the security risks of the entire network, and dividing the network into high-risk, medium-risk, and low-risk areas; The global risk score calculation algorithm includes the following steps: Collect the final security score of each network device from each distributed scanning module , denote the final security score of the -th network device in the -th distributed scanning module; Calculate the first In the distributed scanning module Device weight coefficient of each network device : Among them, represents the importance score of the th network device in the th distributed scanning module; represents the location coefficient of the th network device in the th distributed scanning module in the network topology; represents the total number of distributed scanning modules; represents the total number of network devices in the th distributed scanning module; The network is divided into multiple regions according to the network topology structure, and the risk score of each region is calculated according to the following formula 7: in, Indicates the network Risk score for each region; Indicates that it belongs to A collection of distributed scanning modules in each area; Indicates the The total number of network devices in each distributed scanning module; According to the calculated risk scores of the th area in the network, the network is divided into high-risk areas, medium-risk areas, and low-risk areas; The global risk score of the network is calculated according to the following formula 8 : Among them, represents the total number of regions in the network; represents the weight coefficient of the th region, determined according to the importance of the region and the number of devices; Based on the calculated global risk score of the network , determine the overall risk level of the network.
4. The omnidirectional power grid network equipment scanning system according to claim 3, characterized in that: The importance score of the th network device in the th distributed scanning module is calculated according to the following formula 9: Among them, represents the device type score of the th device in the th distributed scanning module; represents the function score of the th device in the th distributed scanning module, which is determined according to the functional importance of the device in the network; represents the business importance score of the th device in the th distributed scanning module, which is scored according to the impact of the device on business continuity; , and are weight coefficients.
5. The all-round power grid network device scanning system according to claim 4, wherein No. In the distributed scanning module The location coefficient of each network device in the network topology , calculated according to the following formula 10: in, Indicates the In the distributed scanning module The number of hops from a device to the network core node.
6. The all-round power grid network device scanning system according to claim 1, characterized in that, The user interface module includes an interactive visualization panel, and the interactive visualization panel is used for: displaying the topology structure of the entire network through a graphical interface, including the distribution, connection relationship and traffic path of network devices; displaying the scanning results of each distributed scanning module, including the configuration information, operating status and security parameters of the devices; providing a security assessment report, including the security score, risk level and improvement suggestions of each device; allowing the user to view the detailed information of specific devices, adjust the network view, and add markings and annotations through click and drag operations.
7. The all-round power grid network device scanning system according to claim 1, characterized in that, The user interface module further includes a custom report generation function, allowing the user to generate a customized security assessment report according to requirements.
8. The omnidirectional power grid network equipment scanning system according to claim 1, characterized in that: The user interface module includes a real-time alarm and notification function, which is used to notify the user in a timely manner when high-risk devices or abnormal network activities are detected.
9. A method for scanning all-round power grid network devices, characterized in that, including: deploying multiple distributed scanning modules in the network, where each distributed scanning module includes a network interface for establishing communication with the device to be scanned; a scanning engine configured to automatically identify and connect to the devices in the network, collect the configuration information, operating status and security parameters of the devices, and generate a security assessment report of the devices; a storage unit for storing the scanning results and related data; a communication unit for transmitting the scanning results to the central control module; summarizing the scanning data from multiple distributed scanning modules; analyzing the scanning data to detect potential security threats and network performance problems; generating an overall security and performance assessment report of network devices; wherein, the scanning engine of each scanning module is used to execute a multi-level security assessment algorithm, and the multi-level security assessment algorithm includes the following steps: Step S2001: Conduct a preliminary scan on each scanned network device to collect the basic configuration information of the scanned network device, where the basic configuration information includes the device name, IP address, and operating system version; calculate the preliminary security score of the scanned device according to the following formula 1 :[[]]END]] Among them, represents the security score of the th item of basic configuration information; represents the total number of basic configuration information; represents the weight of the security score of the th item of basic configuration information; Step S2002: Based on the preliminary security score, perform an in-depth scan of network devices with potential risks and collect advanced configuration information of the scanned network devices, wherein the advanced configuration information includes open ports, running services, and installed software versions; calculate the intermediate security score of the scanned devices according to the following formula 2 : Among them, represents the security score of the th item of advanced configuration information; represents the total number of advanced configuration information; represents the risk weight of the th item of advanced configuration information; Step S2003: Perform a comprehensive security vulnerability scan on high-risk devices according to the intermediate security score; according to the security vulnerability scan results, calculate the advanced security score of the scanned devices according to the following formula 3 : Among them, represents the severity score of the th vulnerability; represents the total number of security vulnerabilities scanned; represents the repair difficulty score of the th vulnerability; Step S2004: Calculate a scan adjustment factor according to the preliminary security score, intermediate security score, and advanced security score, using the following Formula 4 ; Among them, , and are adjustment factors; Step S2005: If the calculated scan adjustment factor If the score is greater than the first preset threshold, it indicates a high risk. The scanning engine will increase the scanning port range, increase the frequency of scanning packets, and extend the scanning time. Steps S2001-S2003 will be re-executed to obtain the preliminary security score, the intermediate security score, and the advanced security score. Step S2005 will then be directly executed. Step S2005: Calculate the final security score of the scanned network device according to Formula 5 below : Among them, , and are weight coefficients; Step S2006: When the final security score of the device to be scanned is higher than the second preset threshold, mark the network device as high-risk and recommend taking immediate repair measures; when the final security score of the device to be scanned is between the third preset threshold and the fourth preset threshold, mark the network device as medium-risk and recommend repairing it within an acceptable time range; when the final security score of the device to be scanned is lower than the third preset threshold, mark the network device as low-risk and recommend regular monitoring and maintenance.
Citation Information
Patent Citations
Network session statistical characteristic based large-scale network scanning detection method
CN106027559A
Cooperative defense method and system for processor network protection
CN117614745A
Network attack blocking method
CN118764277A
SCAP-based security baseline checking method
CN119011300A