A method, device, power system and related equipment for collecting and analyzing power grid flow data

Through multi-channel reception and analysis of power grid traffic data, comprehensive coverage and real-time monitoring of power system network traffic is achieved, and the problem of low data collection and analysis efficiency in the existing technology is solved, and efficient, accurate and intelligent network management and decision-making support is provided.

CN119622367BActive Publication Date: 2025-05-27SHANXI HELI INNOVATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510163964.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-27
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

In the existing power system, it is difficult to achieve efficient, accurate and intelligent real-time collection, analysis and monitoring of network traffic data, resulting in low network operation efficiency and high security risks, making it difficult to support intelligent management and decision-making.

Method used

Provide a power grid traffic data acquisition and analysis method, which can realize comprehensive coverage and real-time monitoring of network traffic through multiple channels. The method includes determining a collection channel matching the traffic to be collected, collecting and preprocessing the traffic data through the acquisition channel, analyzing the business data, calculating business indicators, and performing correlation analysis and traceability analysis, and finally performing visual output.

Benefits of technology

It realizes comprehensive coverage and real-time monitoring of network traffic, ensures data integrity and diversity, and can promptly detect potential network congestion, abnormal access and other problems, providing strong support for network optimization and failure prevention. At the same time, by deeply exploring the value behind the data and accurately calculating various business indicators, the internal laws and potential problems of business operations are revealed, and a scientific basis for business optimization, cost control and market expansion are provided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622367B_ABST
    Figure CN119622367B_ABST
Patent Text Reader

Abstract

The present application provides a method for collecting and analyzing power grid flow data, comprising: in response to a flow collection start command, determining a collection channel that matches the flow to be collected; collecting the flow to be collected through the collection channel, and preprocessing the collected flow data; parsing the preprocessed flow data to obtain business data; calculating relevant business indicators based on the business data, and issuing early warnings for relevant businesses based on the calculation results; performing correlation analysis and traceability analysis on each business indicator and its data factors, and visually outputting the correlation analysis results and traceability analysis results; the present application can receive flow data through multiple channels to achieve comprehensive coverage and real-time monitoring of network flow, and data from different channels are captured simultaneously to ensure the integrity and diversity of the data; and is applicable to the field of power systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of power systems, and particularly to a method and device for collecting and analyzing grid traffic data, a power system, and related equipment. Background Art

[0002] In the context of the current highly informatized and intelligent era, network devices in power systems are increasingly showing the characteristics of complexity and large scale. This complex network system not only undertakes a large amount of power transmission and distribution tasks, but also involves frequent interactions among numerous applications. Therefore, building an efficient and accurate network collection and analysis system is of great significance for ensuring the safe and stable operation of power systems and improving energy utilization efficiency.

[0003] First of all, the network system in the power system consists of many infrastructure facilities such as power plants, substations, transmission lines, and distribution networks. These facilities are interconnected through complex communication protocols and technical means to form a huge power Internet of Things. In this network, various devices, systems, and applications frequently exchange data. The timeliness, accuracy, and integrity of this data are directly related to the safe, stable, and efficient operation of the power system.

[0004] Secondly, in the network system, traffic data is an important indicator reflecting the network operation status and business activity conditions. For power systems, traffic data can not only help operation and maintenance personnel to grasp the network operation status in real time, discover and handle potential safety hazards and fault problems in a timely manner; but also provide important data support for power system planning, dispatching, optimization, etc. By deeply analyzing traffic data, information such as the correlation relationship, data flow direction, and traffic distribution law among different services in the power system can be revealed, providing strong support for the intelligent management and decision-making of the power system.

[0005] In addition, due to the expansion of the scale of power systems and the increase in new energy access, the frequency and magnitude of data interaction are also continuously increasing, posing higher requirements for data collection, storage, processing, and analysis capabilities.

[0006] In summary, building an efficient, accurate, and intelligent network collection and analysis system is of great significance for power systems. This system can not only improve the operation efficiency and safety of the network system in power systems, but also provide strong support for the intelligent transformation and high-quality development of power systems. Summary of the Invention

[0007] In order to solve one of the above technical defects, the present application provides a method and device for collecting and analyzing grid traffic data, a power system, and related equipment.

[0008] According to the first aspect of the present application, a method for collecting and analyzing power grid traffic data is provided, and the method includes:

[0009] In response to a traffic collection start command, determine a collection channel that matches the traffic to be collected;

[0010] Collect the traffic to be collected through the collection channel and preprocess the collected traffic data;

[0011] Parse the preprocessed traffic data to obtain service data;

[0012] According to the service data, calculate relevant service indicators and issue early warnings for relevant services based on the calculation results;

[0013] Conduct correlation analysis and traceability analysis on each service indicator and its data factors, and visually output the correlation analysis results and traceability analysis results.

[0014] Preferably, the determining of the collection channel that matches the traffic to be collected specifically includes:

[0015] Judge whether the start command contains a specified command for the collection channel;

[0016] If it contains a specified command, first check whether there is an automatic matching record of the traffic to be collected and the specified collection channel in the channel automatic matching table. If there is such an automatic matching record, determine the specified collection channel as the collection channel that matches the traffic to be collected according to this automatic matching record. If there is no such automatic matching record, check whether there is a specified matching record of the traffic to be collected and the specified collection channel in the channel specified matching table. If there is such a specified matching record, determine the specified collection channel as the collection channel that matches the traffic to be collected according to this specified matching record. If there is no such specified matching record, store the specified matching relationship between the traffic to be collected and the specified collection channel in the channel specified matching table to form a new specified matching record, and determine the specified collection channel as the collection channel that matches the traffic to be collected according to this new specified matching record;

[0017] If it does not contain a specified command, according to the identification characteristics of the traffic to be collected, search for the automatic matching records of the traffic to be collected and all collection channels in the channel automatic matching table, and then determine all the matching collection channels as the collection channels that match the traffic to be collected according to the found automatic matching records.

[0018] Preferably, the determining of the collection channel that matches the traffic to be collected specifically further includes:

[0019] Count the number of matching times of each specified matching record in the channel specified matching table;

[0020] When the number of matches of a specified matching record reaches the specified matching threshold N, transfer the specified matching record to the channel automatic matching table and store it as a new automatic matching record.

[0021] Preferably, the preprocessing of the collected traffic data specifically includes:

[0022] During the process of receiving traffic data, according to the order in which the traffic data passes, specify a large time window in units of time, and divide the large time window into multiple small time windows in units of seconds. All traffic data packets passing within their respective time ranges are dynamically stored in each small time window;

[0023] After receiving each traffic data, when the traffic data passes through each small time window in turn, compare the content of the traffic data with the content of all traffic data packets dynamically stored in each small time window by hashing. If the hashing results are the same, continue to compare other auxiliary parameters. If all parameters are the same, determine that the traffic data is duplicate traffic data, and finally remove the duplicate traffic data according to the determination result;

[0024] Use the BPF interface to receive the mirrored traffic data collected from different acquisition channels and perform preliminary filtering on the received traffic data;

[0025] Perform preliminary parsing on the preliminarily filtered traffic data, identify the key information in the data header, decode the data packet body according to the key information, restore the original data, and then extract useful information from the data packet;

[0026] Perform secondary filtering on the preliminarily parsed traffic data and store the traffic data after secondary filtering.

[0027] Preferably, the parsing of the preprocessed traffic data to obtain service data specifically includes:

[0028] Deserialize the preprocessed traffic data to restore the collected data packets;

[0029] Intercept the control field of the first five bytes of the restored data header and parse out the protocol version number and data length of the current data packet;

[0030] Serialize the data with the protocol version number and data length and compress the serialized data;

[0031] Perform protocol identification and analysis on the compressed data, parse the data packet, and parse the original traffic data packet into application data recognizable by the service.

[0032] Preferably, the correlation analysis and traceability analysis of each service indicator and its data factor specifically include:

[0033] Using a timing calculation mechanism, calculate the relevant statistics of each business indicator at regular intervals according to a set period. Among them, the relevant statistics are one or more of the average value, maximum value, and minimum value;

[0034] Using an event trigger mechanism, after receiving an event notification sent by a set event bus, calculate the trend data of each business indicator. Among them, the trend data is one or more of year-on-year, month-on-month, and change rate;

[0035] According to the calculation results of the relevant statistics and the calculation results of the trend data, conduct trend analysis on each business indicator, calculate the data fluctuation law within a certain period of time, and analyze the change trend of key indicators at different time points;

[0036] According to the calculation formula of each business indicator, obtain the data factors that affect the calculation results of the indicators;

[0037] Trace back the alarm status of a certain business indicator at a certain moment, analyze the correlation relationship between different alarm messages, and obtain the internal connection and mutual influence between each business indicator and each data factor.

[0038] According to the second aspect of the present application, a power grid flow data acquisition and analysis device is provided. The device includes modules for implementing the power grid flow data acquisition and analysis method as described above.

[0039] According to the third aspect of the present application, a power system is provided. The power system includes:

[0040] Flow acquisition end: Used to respond to a flow acquisition start command, determine the acquisition channel matching the flow to be acquired; acquire the flow to be acquired through the acquisition channel, preprocess the acquired flow data, and serialize the preprocessed flow data and report it to the data analysis end;

[0041] Data analysis end: Used to parse the preprocessed flow data reported by the flow acquisition end to obtain service data; calculate relevant service indicators according to the service data, and issue early warnings for relevant services according to the calculation results; conduct correlation analysis and traceability analysis on each service indicator and its data factors, and visually output the correlation analysis results and traceability analysis results.

[0042] According to the fourth aspect of the present application, a power grid flow data acquisition and analysis device is provided. The device includes:

[0043] Memory;

[0044] Processor; and

[0045] Computer program;

[0046] Among them, the computer program is stored in the memory and is configured to be executed by the processor to implement the grid traffic data acquisition and analysis method as described above.

[0047] According to the fifth aspect of the present application, there is provided a computer-readable storage medium, on which a computer program is stored; the computer program is executed by a processor to implement the grid traffic data acquisition and analysis method as described above.

[0048] The grid traffic data acquisition and analysis method provided in the present application can receive traffic data through multiple channels, achieving comprehensive coverage and real-time monitoring of network traffic; data from different channels are captured simultaneously, ensuring the integrity and diversity of the data; the real-time monitoring ability enables network managers to quickly grasp the dynamic changes of network traffic, timely discover potential network congestion, abnormal access and other problems, providing strong support for network optimization and fault prevention; the intelligent processing and analysis system in the present application can deeply explore the value behind the data and accurately calculate various business indicators, which not only reflect the real-time state of business operation, but also reveal the internal laws and potential problems of business operation through methods such as trend analysis and correlation analysis, providing a scientific basis for business optimization, cost control and market expansion; in addition, through the real-time analysis of traffic data, the system can quickly identify abnormal traffic patterns, judge whether they reach the alarm conditions, and immediately trigger an alarm notification. This fast response mechanism greatly shortens the time interval from fault discovery to processing, reduces the impact of faults on business operations, and at the same time, the accuracy of the alarm information ensures the pertinence and effectiveness of fault handling; by retrieving historical data, the present application can reproduce a certain state of business operation, helping managers deeply understand the internal mechanism of business operation.

[0049] Other features and advantages of the present application will be described in the subsequent specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the content pointed out in the written specification and the drawings. Brief Description of the Drawings

[0050] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation to the present application. In the drawings:

[0051] Figure 1 is a flowchart of the grid traffic data acquisition and analysis method provided by the present application;

[0052] Figure 2 is a schematic diagram of the modules of the grid traffic data acquisition and analysis device provided by the present application;

[0053] In the figure: 101 is a channel determination module, 102 is a collection module, 103 is a preprocessing module, 104 is a business data acquisition module, 105 is a business metric calculation module, 106 is an early warning module, 107 is an analysis module, and 108 is a visualization module. Specific implementation manner

[0054] In order to make the technical solutions and advantages in the embodiments of the present application clearer and more understandable, the following further details the exemplary embodiments of the present application with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than an exhaustive list of all embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0055] Regarding some problems existing in the prior art:

[0056] In a first aspect, an electric power grid traffic data acquisition and analysis method is provided in an embodiment of the present application. This method can be executed by an electric power grid traffic data acquisition and analysis device, or by components configured inside the electric power grid traffic data acquisition and analysis device, such as chips, chip systems, etc., or can also be implemented by a logic module or software having some or all of the functions of the electric power grid traffic data acquisition and analysis device. The present application does not limit this.

[0057] Exemplarily, as Figure 1 shown, the electric power grid traffic data acquisition and analysis method includes:

[0058] In response to a traffic acquisition start command, determine an acquisition channel that matches the traffic to be acquired;

[0059] Acquire the traffic to be acquired through the acquisition channel and preprocess the acquired traffic data;

[0060] Parse the preprocessed traffic data to obtain business data;

[0061] According to the business data, calculate relevant business metrics and give early warnings to relevant businesses based on the calculation results;

[0062] Conduct correlation analysis and traceability analysis on each business metric and its data factors, and visually output the correlation analysis results and traceability analysis results.

[0063] Based on the above solution, the embodiments of the present application can receive traffic data through multiple channels, achieving comprehensive coverage and real-time monitoring of network traffic; data from different channels are captured simultaneously, ensuring the integrity and diversity of the data; the real-time monitoring ability enables network administrators to quickly grasp the dynamic changes in network traffic, promptly discover potential problems such as network congestion and abnormal access, providing strong support for network optimization and fault prevention; the intelligent processing and analysis system in the embodiments of the present application can deeply explore the value behind the data and accurately calculate various business metrics. These metrics not only reflect the real-time state of business operations but also reveal the internal laws and potential problems of business operations through methods such as trend analysis and correlation analysis, providing a scientific basis for business optimization, cost control, and market expansion; in addition, through the real-time analysis of traffic data, the system in the embodiments of the present application can quickly identify abnormal traffic patterns, determine whether they meet the alarm conditions, and immediately trigger an alarm notification. This rapid response mechanism greatly shortens the time interval from fault discovery to handling, reduces the impact of faults on business operations, and at the same time, the accuracy of the alarm information ensures the pertinence and effectiveness of fault handling; by retrieving historical data, the embodiments of the present application can reproduce a certain state of business operations, helping managers deeply understand the internal mechanism of business operations.

[0064] In some possible implementation manners of the first aspect, the determining the acquisition channel that matches the traffic to be acquired specifically includes:

[0065] Determine whether the start command contains a specified command for the acquisition channel;

[0066] If it contains a specified command, first check in the channel automatic matching table whether there is an automatic matching record between the traffic to be acquired and the specified acquisition channel. If there is such an automatic matching record, then determine the specified acquisition channel as the acquisition channel that matches the traffic to be acquired according to this automatic matching record. If there is no such automatic matching record, then check in the channel specified matching table whether there is a specified matching record between the traffic to be acquired and the specified acquisition channel. If there is such a specified matching record, then determine the specified acquisition channel as the acquisition channel that matches the traffic to be acquired according to this specified matching record. If there is no such specified matching record, then store the specified matching relationship between the traffic to be acquired and the specified acquisition channel into the channel specified matching table to form a new specified matching record, and determine the specified acquisition channel as the acquisition channel that matches the traffic to be acquired according to this new specified matching record;

[0067] If it does not contain a specified command, then according to the identification characteristics of the traffic to be acquired (the identification characteristics can be type characteristics, geographical characteristics, time domain characteristics, etc.), check in the channel automatic matching table for the automatic matching records between the traffic to be acquired and all acquisition channels, and then determine all the acquired channels that match as the acquisition channels that match the traffic to be acquired according to the found automatic matching records.

[0068] In specific implementation, each automatic matching record in the channel automatic matching table is actually the matching relationship between various types of traffic data preset by the system and the corresponding acquisition channels. Each specified matching record in the channel specified matching table is the matching relationship between the traffic data to be collected specified by the user when starting traffic collection and the corresponding acquisition channels. The acquisition channels can be network IP, port, protocol type, MAC address, etc. When the system receives a traffic collection start command, it first determines whether there is a user-specified command for the acquisition channel in the start command. If there is a specified command, it means that the traffic to be collected needs to be accurately collected. At this time, it first queries whether the matching relationship specified by the user exists in the channel automatic matching table. If it exists, the acquisition channel specified by the user is directly used as the accurate acquisition channel for the traffic to be collected. If it does not exist, it means that there is no matching relationship specified by the user in the channel automatic matching table. At this time, it then queries whether the matching relationship specified by the user exists in the channel specified matching table. If it exists, it means that this matching relationship has been specified by the user before, then the acquisition channel specified by the user is used as the accurate acquisition channel for the traffic to be collected. If it does not exist, it means that the matching relationship specified by the user appears for the first time. At this time, this matching relationship is first stored to form a recorded matching relationship, and then the acquisition channel specified by the user is used as the accurate acquisition channel for the traffic to be collected, so as to realize the accurate acquisition of the traffic to be collected. If there is no specified command in the start command, it means that the traffic to be collected needs to be widely collected. At this time, all acquisition channels corresponding to the traffic to be collected are matched in the channel automatic matching table according to the characteristics of the traffic to be collected, and the traffic to be collected is widely collected through these channels.

[0069] Based on the above solution, the embodiments of the present application can, according to actual usage requirements, not only accurately collect the traffic to be collected, reduce unnecessary data processing, save computing resources, and improve the collection efficiency, but also widely collect the traffic to be collected, ensure the integrity and diversity of data, and provide an excellent data basis for subsequent analysis and processing.

[0070] Optionally, when widely collecting the traffic to be collected, in order to further improve the data collection efficiency on the basis of ensuring data integrity and diversity, when the number of corresponding acquisition channels found in the channel automatic matching table is relatively large and exceeds the channel threshold M (for example, M can be set to 10), according to the channel priority list, the channels with the first M levels of priority are selected as the final acquisition channels; among them, the channel priority list is arranged according to the importance of the traffic data collected by each channel to each service index.

[0071] In some possible implementation manners of the first aspect, the determining the acquisition channels matching the traffic to be collected specifically further includes:

[0072] Count the number of matches for each specified matching record in the channel specified matching table;

[0073] When the number of matches for a certain specified matching record reaches the specified matching threshold N (for example, N can be set to 5), transfer this specified matching record to the channel automatic matching table and store it as a new automatic matching record.

[0074] Based on the above solution, the system will count the number of matches for each specified matching record in the channel specified matching table. When the number of matches for a certain specified matching record reaches the specified matching threshold N (for example, N can be set to 5), it indicates that the matching relationship corresponding to this specified matching record is specified by the user at a relatively high frequency, and it also reflects that this matching relationship is relatively important. At this time, the system will transfer this specified matching record to the channel automatic matching table and store it as a new automatic matching record, so that when accurately collecting the to-be-collected traffic for the next time, the collection channel can be matched at a faster speed, and more and more useful traffic data can be collected when collecting widely, achieving the purpose of further improving the accurate collection efficiency and ensuring the integrity and effectiveness of the data.

[0075] Optionally, the collection of the to-be-collected traffic through the collection channel specifically includes:

[0076] Identify the sampling rate for each determined collection channel respectively, and determine whether the collection channel has a specified sampling ratio;

[0077] If so, perform random sampling among all the obtained data packets according to the specified sampling ratio, and use the sampling result as the final collection result of the corresponding collection channel;

[0078] If not, use all the obtained data packets as the final collection result of the corresponding collection channel.

[0079] In some possible implementation manners of the first aspect, the preprocessing of the collected traffic data specifically includes:

[0080] During the process of receiving traffic data, specify a large time window in units of time in the order of the passing of traffic data, and divide this large time window into multiple small time windows in units of seconds. All the traffic data packets passing within their respective time ranges are dynamically stored in each small time window;

[0081] After receiving each traffic data, when the traffic data passes through each time window in sequence, the content of the traffic data is hashed and compared with the content of all traffic data packets dynamically stored in each time window. If the hash results are consistent, other auxiliary parameters (the other auxiliary parameters can be parameters such as IP, port, payload, etc.) are continued to be compared. If all parameters are consistent, the traffic data is determined to be duplicate traffic data, and finally the duplicate traffic data is removed according to the determination result;

[0082] Use the BPF interface to receive the mirror traffic data collected by different acquisition channels and perform preliminary filtering on the received traffic data; this step avoids copying other packets from the operating system kernel to the user state, reduces the CPU burden of packet capture and the required buffer space, and realizes preliminary filtering of data at the kernel layer. Compared with other subsequent filtering means, the filtering performance of this step is the highest;

[0083] Perform preliminary parsing on the preliminarily filtered traffic data, identify the key information in the data header (such as protocol type, source address, destination address, port number, etc.), decode the data packet body according to the key information (such as protocol type) to restore the original data, and then extract useful information from the data packet (such as packet size, packet sequence number, data window size, link status, etc.);

[0084] Perform secondary filtering on the preliminarily parsed traffic data and store the traffic data after secondary filtering; this secondary filtering step can filter the sending content in the application, abnormal data in the protocol, illegal operations on key ports, etc. through preset filtering rules, provides a flexible interface, and can be extended at any time through the interface in actual access, realizing the ability to be flexibly customized according to the business, and the filtering is more thorough.

[0085] Based on the above solution, the collected traffic data is first preliminarily filtered by the kernel and then precisely filtered twice, which improves the overall filtering efficiency and effect, ensures the quality of the collected traffic data, and provides a good data quality foundation for subsequent data analysis.

[0086] In some possible implementation manners of the first aspect, the parsing of the preprocessed traffic data to obtain business data specifically includes:

[0087] Deserialize the preprocessed traffic data to restore the collected data packets;

[0088] Intercept the control field of the first five bytes of the restored data header and parse out the protocol version number and data length of the current data packet; through the protocol version number, the protocol can be conveniently iteratively upgraded in the later stage and protocol compatibility processing can be performed using the version number. The specific data length can solve the problems of data packet splitting and packet sticking during network transmission;

[0089] Serialize the data with a protocol version number and data length, and compress the serialized data; specifically, the Protostuff tool can be used to serialize the data. Protostuff itself reduces the size of the serialized binary data through variable-length encoding, ignoring default values, etc. Then, by compressing the serialized data with gzip, the occupancy rate of the broadband can be greatly reduced;

[0090] Identify and analyze the protocol of the compressed data, parse the data packets (such as IEC104, IEC102, etc.), and parse the original traffic data packets into application data (i.e., service data) recognizable by the service, realizing the analysis ability of the data transmission and communication between the monitoring system and the remote station.

[0091] Optionally, the parsed service data and the original traffic data can be stored in the database, providing complete data input for subsequent operations of analysis and processing according to service requirements, facilitating the retrospective analysis of the data interaction and operation status of each system at a certain moment.

[0092] Optionally, the data stored in the database can be displayed, providing a visual service data display page for users, facilitating users to view the data content and data transmission situation in real time. It can also display the data content reported in real time by devices such as AGC, AVC, and RTU, and can also provide queries for the reported data in a specified period, so as to achieve the purpose of analyzing the communication process between the power plant and the dispatching master station at any time.

[0093] Optionally, calculate relevant service indicators based on the service data, and issue early warnings for relevant services according to the calculation results. Specifically, it includes:

[0094] Classify the service data, and match the service data with each calculation model for calculating the corresponding service indicators according to the classification results;

[0095] Identify the real-time performance of each calculation model, and configure the service data into the corresponding calculation model for calculation according to the identification results; perform real-time calculations on service indicators that are simple to calculate, rely on less data, and can be obtained through real-time queries (such as: statistics of the number of data anomalies, statistics of the number of reported points, etc.), and perform offline calculations on service indicators with high calculation complexity, relying on more data, and cannot be obtained in real time (such as: reported rate calculated by day, commissioning rate, etc.);

[0096] According to the calculation results of each calculation model, issue early warning outputs for relevant service data that meet the early warning conditions.

[0097] Optionally, the system can also standardize and normalize all alarm information, feedback the alarm data to the indicator report, and make effective identification in the business report, which is convenient for users to retrieve and view all alarm statuses, providing certain data support for analyzing and processing alarm events.

[0098] Optionally, the calculated business indicator data is summarized to form a data cube and pre-classified according to multiple dimensions; in response to an output display command, corresponding data values, analysis dimensions, summarization methods, etc. are output to the user; in addition, the system can also dynamically generate a data display model structure according to the settings, and when the relevant data is updated, the display data is updated in time according to the data display model structure. The embodiments of the present application can dynamically construct a model of a visual chart according to actual needs, realize flexible customization of data display reports, and more flexibly and intuitively display business indicator data.

[0099] Optionally, the business indicators can be: wind resource data assessment - reporting rate (number of reported points / total number of points × 100%), wind power theoretical availability - accuracy rate ((1 - (number of abnormal points / total number of uploaded points of theoretical and available power generation)) × 100%), AGC operation rate (AGC substation operation time / wind farm operation time × 100%), AVC operation rate (AVC substation operation time / wind farm operation time × 100%), AVC qualification rate (number of qualified executions / number of commands issued by the power dispatching agency × 100%), etc.

[0100] Based on the above solution, the embodiments of the present application use a self-developed computing engine, introduce operator orchestration capabilities, abstract basic operators for the calculation process, and pre-write the calculation logics of qualification rates, accuracy rates, etc. The calculation results can be obtained only by configuring the input parameters. For business indicators that need to be extended or modified, most of the calculation processes can be assembled through operators, providing timely support and reducing development and testing time.

[0101] In some possible implementation manners of the first aspect, the correlation analysis and traceability analysis of each business indicator and its data factors specifically include:

[0102] Using a timing calculation mechanism, regularly calculate relevant statistics of each business indicator at a set period (such as every hour, every day, every month), where the relevant statistics are one or more of the average value, maximum value, and minimum value;

[0103] Using an event trigger mechanism, after receiving an event notification sent by a set event bus, calculate the trend data of each business indicator, where the trend data is one or more of year-on-year, month-on-month, and change rate;

[0104] Based on the calculation results of relevant statistics and the calculation results of trend data, conduct trend analysis on the year-on-year and month-on-month of each business indicator on a daily, weekly, monthly, and annual basis, calculate the data fluctuation law within a certain period of time, analyze the change trend of key indicators at different time points, and mark them when the data fluctuation range far exceeds the past to identify potential problems or anomalies;

[0105] According to the calculation formula of each business indicator, obtain the data factors that affect the calculation result of the indicator;

[0106] Trace back the alarm status of a certain business indicator at a certain moment, analyze the correlation between different alarm messages, and obtain the internal connection and mutual influence between each business indicator and each data factor. For example: The AGC operation rate indicator and the AVC operation rate indicator both depend on the substation operation time. If the above two indicators alarm simultaneously, it may be that the substation operation time is abnormal. By taking the intersection of the data factors of the two indicators, it can be identified and output to the user to facilitate the user to judge the operation status of the substation or equipment.

[0107] Optionally, the system can also calculate the weights of each data factor in the entire business indicator system based on the calculation results of each business indicator, the alarm situation, and the influence degree of each data factor; trace back each data factor to determine the acquisition channel corresponding to each data factor; calculate the weights of each acquisition channel in the entire business indicator system according to the weights of the data factors corresponding to each acquisition channel; sort according to the weight size of each acquisition channel, and set the top P acquisition channels as the main channels and the rest as the standby channels; when using business data for business indicator calculation, preferentially use the business data collected by the main channels for calculation, and only use the business data of the standby channels for business indicator calculation when the business data calculation of the main channels is abnormal.

[0108] Optionally, the system can also provide detailed detailed data by tracing back the business indicator situation that triggered the alarm condition, construct an alarm event chain according to the time stamp and logical relationship, display the generation, propagation, and processing process of the alarm information, rely on the preprocessing technology of alarm data, preprocess the data, and perform multi-dimensional classification and aggregation on the data according to time and time type, support users to trace back the alarm information according to conditions such as time line and event type, and view the detailed processing process and results.

[0109] Optionally, the system can also provide a function to query the original data for calculating business metrics according to business metrics. Through correlation analysis, based on the original data input of the business metric calculation formula, it can be associated with relevant original data, and the original data for calculating the alarm metrics is displayed. For example, for the alarm of the reporting rate metric, according to the calculation formula: reporting rate = number of reported points / total number of points × 100%, the data of the number of reported points and the total number of points can be associated and displayed, providing support for fault location and cause analysis; the running state and working state of the device can be further judged through the original data.

[0110] Optionally, the system can also associate the original data for calculating metrics with the original traffic data packets. The original data packets are the most primitive data at the protocol layer. The original data for calculating metrics is obtained after parsing the original data packets, providing the most primitive binary data, which can trace back to the specific process of device communication, facilitating professionals to judge the running state at that time through this.

[0111] Optionally, the system can also analyze the change trend of the original traffic data corresponding to each business metric, analyze the network connectivity status, network transmission rate changes, whether there is abnormal traffic, etc., and give early warnings about network quality problems in a timely manner, so as to facilitate users to intervene and handle in a timely manner, avoiding the spread of faults and business losses.

[0112] In a second aspect, an apparatus is provided in an embodiment of the present application. The apparatus is a power grid traffic data acquisition and analysis apparatus, and the power grid traffic data acquisition and analysis apparatus includes modules for implementing the foregoing power grid traffic data acquisition and analysis method.

[0113] Exemplarily, as Figure 2 shown, the power grid traffic data acquisition and analysis apparatus includes:

[0114] Channel determination module 101: used to determine an acquisition channel that matches the traffic to be acquired in response to a traffic acquisition start command;

[0115] Acquisition module 102: used to acquire the traffic to be acquired through the acquisition channel;

[0116] Preprocessing module 103: used to preprocess the acquired traffic data;

[0117] Service data acquisition module 104: used to parse the preprocessed traffic data to obtain service data;

[0118] Business metric calculation module 105: used to calculate relevant business metrics according to service data:

[0119] Early warning module 106: used to give early warnings about relevant services according to the calculation results;

[0120] Analysis module 107: used for performing correlation analysis and traceability analysis on each business metric and its data factors;

[0121] Visualization module 108: used for visually outputting the results of correlation analysis and traceability analysis.

[0122] In some possible implementation manners of the second aspect, the channel determination module 101 includes:

[0123] The first judgment unit: used for judging whether the start command contains a specified command for the acquisition channel;

[0124] The first search unit: used for, when the start command contains a specified command for the acquisition channel, searching in the channel automatic matching table to see if there is an automatic matching record between the to-be-acquired traffic and the specified acquisition channel;

[0125] The first determination unit: used for, when there is an automatic matching record between the to-be-acquired traffic and the specified acquisition channel in the channel automatic matching table, determining the specified acquisition channel as the acquisition channel matching the to-be-acquired traffic according to this automatic matching record;

[0126] The second search unit: used for, when there is no automatic matching record between the to-be-acquired traffic and the specified acquisition channel in the channel automatic matching table, searching in the channel specified matching table to see if there is a specified matching record between the to-be-acquired traffic and the specified acquisition channel;

[0127] The second determination unit: used for, when there is a specified matching record between the to-be-acquired traffic and the specified acquisition channel in the channel specified matching table, determining the specified acquisition channel as the acquisition channel matching the to-be-acquired traffic according to this specified matching record;

[0128] The first saving unit: used for, when there is no specified matching record between the to-be-acquired traffic and the specified acquisition channel in the channel specified matching table, storing the specified matching relationship between the to-be-acquired traffic and the specified acquisition channel into the channel specified matching table to form a new specified matching record;

[0129] The third determination unit: used for, after storing the specified matching relationship between the to-be-acquired traffic and the specified acquisition channel into the channel specified matching table to form a new specified matching record, determining the specified acquisition channel as the acquisition channel matching the to-be-acquired traffic according to this new specified matching record;

[0130] The third search unit: used for, when the start command does not contain a specified command for the acquisition channel, searching in the channel automatic matching table for the automatic matching records between the to-be-acquired traffic and all acquisition channels according to the identification characteristics of the to-be-acquired traffic;

[0131] The fourth determination unit: used for determining all the acquired channels found as the acquisition channels matching the to-be-acquired traffic according to the found automatic matching records.

[0132] In some possible implementations of the second aspect, the channel determination module 101 further includes:

[0133] A counting unit: configured to count the number of matches of each specified match record in the channel specified match table;

[0134] A transfer unit: configured to transfer a specified match record to the channel automatic match table as a new automatic match record for storage when the number of matches of a specified match record reaches a specified match threshold N.

[0135] In some possible implementations of the second aspect, the preprocessing module 103 includes:

[0136] A specifying unit: configured to specify a large time window in units of time in the order of arrival of traffic data during the reception of traffic data;

[0137] A dividing unit: configured to divide the large time window into multiple small time windows in units of seconds, and all traffic data packets passing through within their respective time ranges are dynamically stored in each small time window;

[0138] A hash calculation unit: configured to, after receiving each traffic data, when the traffic data passes through each small time window in sequence, compare the content of the traffic data with the content of all traffic data packets dynamically stored in each small time window by hash. If the hash results are the same, continue to compare other auxiliary parameters;

[0139] A second determination unit: configured to determine that the traffic data is duplicate traffic data when all parameters are the same;

[0140] A deduplication unit: configured to remove duplicate traffic data according to the determination result;

[0141] A preliminary filtering unit: configured to receive mirror traffic data collected by different acquisition channels through a BPF interface and perform preliminary filtering on the received traffic data;

[0142] A first parsing unit: configured to perform preliminary parsing on the preliminarily filtered traffic data, identify key information in the data packet header, decode the data packet body according to the key information to restore the original data, and then extract useful information from the data packet;

[0143] A secondary filtering unit: configured to perform secondary filtering on the preliminarily parsed traffic data and store the traffic data after secondary filtering.

[0144] In some possible implementations of the second aspect, the service data acquisition module 104 includes:

[0145] Deserialization unit: used to deserialize the preprocessed traffic data and restore the collected data packets;

[0146] Second parsing unit: used to intercept the control field of the first five bytes of the restored data header and parse out the protocol version number and data length of the current data packet;

[0147] Serialization unit: used to serialize the data with the protocol version number and data length, and compress the serialized data;

[0148] Third parsing unit: used to identify and analyze the protocol of the compressed data, parse the data packet, and parse the original traffic data packet into application data recognizable by the service.

[0149] In some possible implementation manners of the second aspect, the analysis module 107 includes:

[0150] First calculation unit: used to calculate the relevant statistics of each service indicator regularly according to the set period by using the timing calculation mechanism, where the relevant statistics are one or more of the average value, maximum value, and minimum value;

[0151] Second calculation unit: used to calculate the trend data of each service indicator by using the event trigger mechanism after receiving the event notification sent by the set event bus, where the trend data is one or more of year-on-year, month-on-month, and change rate;

[0152] Third calculation unit: used to perform trend analysis on each service indicator according to the calculation results of the relevant statistics and the calculation results of the trend data, calculate the data fluctuation law within a certain period of time, and analyze the change trend of the key indicators at different time points;

[0153] Data factor acquisition unit: used to obtain the data factors that affect the calculation results of the indicators according to the calculation formulas of each service indicator;

[0154] Backtracking analysis unit: used to backtrack the alarm status of a certain service indicator at a certain moment, analyze the correlation between different alarm messages, and obtain the internal connections and mutual influences between each service indicator and each data factor.

[0155] In the third aspect, an embodiment of the present application provides a power system, including:

[0156] Traffic collection end: used to respond to the traffic collection start command, determine the collection channel that matches the traffic to be collected; collect the traffic to be collected through the collection channel, preprocess the collected traffic data, and serialize the preprocessed traffic data and report it to the data analysis end;

[0157] Data analysis terminal: It is used to analyze the preprocessed traffic data reported by the traffic collection terminal to obtain business data; calculate relevant business indicators based on the business data, and issue early warnings for relevant businesses according to the calculation results; conduct correlation analysis and traceability analysis on each business indicator and its data factors, and visually output the correlation analysis results and traceability analysis results.

[0158] In some possible implementation manners of the third aspect, the traffic collection end: specifically used to determine whether the start command contains a specified command for a collection channel; if it contains the specified command, first check whether there is an automatic matching record of the traffic to be collected and the specified collection channel in the channel automatic matching table. If there is such an automatic matching record, determine the specified collection channel as the collection channel matching the traffic to be collected according to this automatic matching record. If there is no such automatic matching record, check whether there is a specified matching record of the traffic to be collected and the specified collection channel in the channel specified matching table. If there is such a specified matching record, determine the specified collection channel as the collection channel matching the traffic to be collected according to this specified matching record. If there is no such specified matching record, store the specified matching relationship between the traffic to be collected and the specified collection channel in the channel specified matching table to form a new specified matching record, and determine the specified collection channel as the collection channel matching the traffic to be collected according to this new specified matching record; if it does not contain the specified command, according to the identification characteristics of the traffic to be collected, check the automatic matching records of the traffic to be collected and all collection channels in the channel automatic matching table, and then determine all the matched collection channels as the collection channels matching the traffic to be collected according to the found automatic matching records; count the matching times of each specified matching record in the channel specified matching table; when the matching times of a certain specified matching record reach the specified matching threshold N, transfer this specified matching record to the channel automatic matching table for storage as a new automatic matching record; during the process of receiving traffic data, specify a large time window in units of time in the order of the traffic data passing through, and divide this large time window into multiple small time windows in units of seconds. All traffic data packets passing through within their respective time ranges are dynamically stored in each small time window; after receiving each traffic data, when this traffic data passes through each small time window in turn, compare the content of this traffic data with the content of all traffic data packets dynamically stored in each small time window. If the hash results are the same, continue to compare other auxiliary parameters. If all parameters are the same, determine this traffic data as duplicate traffic data, and finally remove this duplicate traffic data according to the determination result; use the BPF interface to receive the mirrored traffic data collected by different collection channels, and perform preliminary filtering on the received traffic data; perform preliminary parsing on the preliminarily filtered traffic data, identify the key information in the data packet header, and decode the data packet body according to the key information to restore the original data, and then extract useful information from the data packet; perform secondary filtering on the preliminarily parsed traffic data, and store the secondarily filtered traffic data.

[0159] In some possible implementation manners of the third aspect, the data analysis end is specifically configured to: deserialize the preprocessed traffic data to restore the collected data packets; intercept the control field of the first five bytes of the restored data header, and parse out the protocol version number and data length of the current data packet; serialize the data with the protocol version number and data length, and compress the serialized data; perform protocol identification and analysis on the compressed data, parse the data packet, and parse the original traffic data packet into application data recognizable by the service; use a timing calculation mechanism to calculate the relevant statistics of each service indicator regularly according to the set period, where the relevant statistics are one or more of the average value, maximum value, and minimum value; use an event trigger mechanism to calculate the trend data of each service indicator after receiving an event notification sent by the set event bus, where the trend data is one or more of year-on-year, month-on-month, and change rate; perform trend analysis on each service indicator according to the calculation results of the relevant statistics and the calculation results of the trend data, calculate the data fluctuation law within a certain period of time, and analyze the change trend of the key indicators at different time points; obtain the data factors affecting the indicator calculation results according to the calculation formula of each service indicator; trace back the alarm status of a certain service indicator at a certain moment, analyze the correlation between different alarm messages, and obtain the internal connection and mutual influence between each service indicator and each data factor.

[0160] In a fourth aspect, an embodiment of the present application provides a power grid traffic data acquisition and analysis device. The device can be any device capable of implementing power grid traffic data acquisition and analysis. The device can be various terminal devices, such as: desktop computers, laptops, tablets, handheld devices, etc., and can be specifically implemented through software and / or hardware.

[0161] Exemplarily, the device includes:

[0162] a memory;

[0163] a processor; and

[0164] a computer program;

[0165] wherein, the computer program is stored in the memory and is configured to be executed by the processor to implement the power grid traffic data acquisition and analysis method as described above.

[0166] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which can be: ROM, RAM, disk, optical disc, etc.

[0167] Exemplarily, a computer program is stored on the computer-readable storage medium; the computer program is executed by the processor to implement the power grid traffic data acquisition and analysis method as described above.

[0168] Compared with the prior art, the present application has the following remarkable improvements:

[0169] 1. Comprehensiveness and real-time nature of traffic data monitoring: By receiving traffic data through multiple channels, comprehensive coverage and real-time monitoring of network traffic are achieved; data from different channels are captured simultaneously, ensuring data integrity and diversity; the real-time monitoring capability enables network administrators to quickly grasp the dynamic changes in network traffic, promptly detect potential network congestion, abnormal access, and other issues, providing strong support for network optimization and fault prevention;

[0170] 2. Precision and depth of business metric analysis: Based on the traffic data received through multiple channels, the intelligent processing and analysis system can deeply explore the value behind the data and accurately calculate various business metrics, such as voltage stability, switch status, commissioning rate, qualification rate, etc. These metrics not only reflect the real-time status of business operations but also reveal the internal laws and potential problems of business operations through methods such as trend analysis and correlation analysis. The in-depth analysis provides a scientific basis for business optimization, cost control, and market expansion;

[0171] 3. Rapidity and accuracy of fault alarm handling: The intelligent processing and analysis system is built with an efficient fault detection and alarm mechanism. Through real-time analysis of traffic data, the system can quickly identify abnormal traffic patterns, determine whether they meet the alarm conditions, and immediately trigger an alarm notification; this rapid response mechanism greatly shortens the time interval from fault discovery to handling, reducing the impact of faults on business operations; at the same time, the accuracy of the alarm information also ensures the pertinence and effectiveness of fault handling;

[0172] 4. Comprehensiveness and traceability of business operation status backtesting: During business operations, the intelligent processing and analysis system support backtesting analysis of specific time periods and specific metrics; by retrieving historical data, the system can reproduce a certain state of business operations, helping managers deeply understand the internal mechanism of business operations; in addition, comprehensive data records and traceability also provide strong support for business audits, compliance inspections, etc.;

[0173] 5. Provide strong support for business decision-making: The comprehensive application of receiving traffic data through multiple channels and intelligent processing and analysis methods provides comprehensive, accurate, and timely data support for business decision-making; by deeply analyzing traffic data, business metrics, and fault alarm information, managers can grasp the pulse of business operations, predict market trends, and formulate scientific and reasonable business strategies; these decisions not only help improve business competitiveness but also enable maintaining a leading position in the fierce market competition.

[0174] In summary, the present application has demonstrated remarkable effects and advantages in aspects such as traffic data monitoring, business metric analysis, fault alarm handling, business operation status backtesting, and providing support for business decision-making. With the continuous progress of technology and the continuous expansion of application scenarios, this method will play an important role in more fields, promoting digital transformation and intelligent upgrading.

[0175] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present application can be implemented in various computer languages. For example, C language, VHDL language, Verilog language, object-oriented programming language Java, and interpreted scripting language JavaScript, etc.

[0176] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses, systems, and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0177] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0178] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1Steps of functions specified in one or more boxes.

[0179] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features.

[0180] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments as well as all changes and modifications falling within the scope of the present application.

[0181] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A method for collecting and analyzing power grid flow data, characterized in that: include: In response to a flow collection start command, determining a collection channel that matches the flow to be collected; The flow to be collected is collected through the collection channel, and the collected flow data is pre-processed; Analyze the pre-processed traffic data to obtain business data; Calculate relevant business indicators based on business data, and issue early warnings for related businesses based on the calculation results; Conduct correlation analysis and traceability analysis on each business indicator and its data factors, and visualize the correlation analysis results and traceability analysis results; The step of determining a collection channel that matches the flow to be collected specifically includes: Determine whether the startup command contains the specified command of the acquisition channel; If a specified command is included, first search in the channel automatic matching table whether there is an automatic matching record between the flow to be collected and the specified collection channel; if the automatic matching record exists, determine the specified collection channel as the collection channel that matches the flow to be collected according to the automatic matching record; if the automatic matching record does not exist, search in the channel specified matching table whether there is a specified matching record between the flow to be collected and the specified collection channel; if the specified matching record exists, determine the specified collection channel as the collection channel that matches the flow to be collected according to the specified matching record; if the specified matching record does not exist, store the specified matching relationship between the flow to be collected and the specified collection channel in the channel specified matching table to form a new specified matching record, and determine the specified collection channel as the collection channel that matches the flow to be collected according to the new specified matching record; If the specified command is not included, the automatic matching records of the flow to be collected and all collection channels are searched in the channel automatic matching table according to the identification characteristics of the flow to be collected, and then all the matched collection channels are determined as the collection channels that match the flow to be collected according to the found automatic matching records.

2. The method for collecting and analyzing power grid flow data according to claim 1, characterized in that: The step of determining a collection channel that matches the flow to be collected specifically includes: Count the number of matches of each specified matching record in the channel specified matching table; When the matching times of a certain designated matching record reaches the designated matching threshold value N, the designated matching record is transferred to the channel automatic matching table and stored as a new automatic matching record.

3. The method for collecting and analyzing power grid flow data according to claim 1, characterized in that: The preprocessing of the collected flow data specifically includes: In the process of receiving traffic data, a large time window is specified in time units according to the order in which the traffic data passes, and the large time window is divided into multiple small time windows in seconds. Each small time window dynamically stores all traffic data packets that pass within the respective time range. After each flow data is received, when the flow data passes through each time window in turn, the flow data content is hashed and compared with the content of all flow data packets dynamically stored in each time window. If the hash results are consistent, other auxiliary parameters are compared. If all parameters are consistent, the flow data is determined to be duplicate flow data, and finally the duplicate flow data is removed according to the determination result; Use the BPF interface to receive the mirrored traffic data collected by different collection channels and perform preliminary filtering on the received traffic data; Perform preliminary analysis on the traffic data after preliminary filtering, identify the key information in the data packet header, decode the data packet body based on the key information, restore the original data, and then extract useful information from the data packet; The traffic data after the initial analysis is filtered for the second time, and the traffic data after the second filtering is stored.

4. The method for collecting and analyzing power grid flow data according to claim 1, characterized in that: The pre-processed traffic data is parsed to obtain service data, specifically including: Deserialize the preprocessed traffic data and restore the collected data packets; Intercept the first five bytes of the restored data header and parse out the protocol version number and data length of the current data packet; Serialize the data with the protocol version number and data length, and compress the serialized data; Perform protocol identification and analysis on the compressed data, parse the data packets, and parse the original traffic data messages into application data that can be identified by the business.

5. The method for collecting and analyzing power grid flow data according to claim 1, characterized in that: The correlation analysis and traceability analysis of each business indicator and its data factors specifically include: Using a timing calculation mechanism, the relevant statistics of each business indicator are calculated according to a set periodic timing, wherein the relevant statistics are one or more of an average value, a maximum value and a minimum value; By using the event trigger mechanism, after receiving the event notification sent by the set event bus, the trend data of each business indicator is calculated, where the trend data is one or more of the year-on-year, month-on-month and change rate; Based on the calculation results of relevant statistics and trend data, trend analysis is performed on each business indicator, the data fluctuation pattern within a period of time is calculated, and the change trend of key indicators at different time points is analyzed; According to the calculation formula of each business indicator, obtain the data factors that affect the calculation results of the indicator; Trace back the alarm status of a certain business indicator at a certain moment, analyze the correlation between different alarm information, and obtain the internal connection and mutual influence between various business indicators and data factors.

6. A power grid flow data collection and analysis device, characterized in that: It comprises a module for implementing the power grid flow data collection and analysis method described in any one of claims 1 to 5.

7. A power system, characterized in that: include: Traffic collection end: used to respond to the traffic collection start command and determine the collection channel that matches the traffic to be collected; The traffic to be collected is collected through the collection channel, and the collected traffic data is preprocessed. The preprocessed traffic data is serialized and reported to the data analysis end; Data analysis end: used to analyze the pre-processed traffic data reported by the traffic collection end to obtain business data; calculate relevant business indicators based on the business data, and issue early warnings for related businesses based on the calculation results; Conduct correlation analysis and traceability analysis on each business indicator and its data factors, and visualize the correlation analysis results and traceability analysis results; The flow collection end is also used to: determine whether the start command contains a designated command for a collection channel; if the designated command is contained, first search in the channel automatic matching table whether there is an automatic matching record between the flow to be collected and the designated collection channel; if the automatic matching record exists, determine the designated collection channel as the collection channel that matches the flow to be collected according to the automatic matching record; if the automatic matching record does not exist, search in the channel designated matching table whether there is a designated matching record between the flow to be collected and the designated collection channel; if the designated matching record exists, determine the designated collection channel as the collection channel that matches the flow to be collected according to the designated matching record; if the designated matching record does not exist, store the designated matching relationship between the flow to be collected and the designated collection channel in the channel designated matching table to form a new designated matching record, and determine the designated collection channel as the collection channel that matches the flow to be collected according to the new designated matching record; If the specified command is not included, the automatic matching records of the flow to be collected and all collection channels are searched in the channel automatic matching table according to the identification characteristics of the flow to be collected, and then all the matched collection channels are determined as the collection channels that match the flow to be collected according to the found automatic matching records.

8. A power grid flow data collection and analysis device, characterized in that: include: Memory; processor; as well as Computer programs; The computer program is stored in the memory and is configured to be executed by the processor to implement the power grid flow data collection and analysis method as described in any one of claims 1 to 5.

9. A computer-readable storage medium, characterized in that: A computer program is stored thereon; the computer program is executed by a processor to implement the power grid flow data collection and analysis method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Industrial control system network attack detection technology based on scene fingerprints

    CN107204975A

  • Systems and methods for providing process automation and artificial intelligence, market aggregation, and embedded marketplaces for a transactions platform

    WO2024025863A1