Power industry network security collaborative defense system based on threat hunting technology

By constructing a collaborative cybersecurity defense system for the power industry using threat hunting technology, and by collecting and analyzing security log information in real time, combined with a multi-layered defense architecture and a threat intelligence sharing platform, the system addresses the problem that the collaborative cybersecurity defense system for the power industry cannot provide comprehensive cybersecurity threat information. This enables timely detection and rapid response to potential threats, improving defense efficiency and cybersecurity assessment capabilities.

CN119652660BActive Publication Date: 2026-05-29HUANENG LANCANG RIVER HYDROPOWER CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUANENG LANCANG RIVER HYDROPOWER CO LTD
Filing Date
2025-01-13
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing cybersecurity collaborative defense systems in the power industry cannot effectively combine forensic and analytical techniques to provide comprehensive cybersecurity threat information.

Method used

Construct a collaborative cybersecurity defense system for the power industry based on threat hunting technology, including a threat intelligence defense model, a multi-layered defense architecture, a network attack behavior analysis unit, and a risk visualization unit. Collect and analyze security log information in real time, obtain cybersecurity threat information through a threat intelligence sharing platform and a multi-layered defense architecture, and establish a linkage response mechanism between each layer.

Benefits of technology

It enables timely detection and rapid response to potential threats, improves defense efficiency, reduces the frequency and losses of security incidents, provides comprehensive assessment indicators of network security status, and helps enterprises improve their network security level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652660B_ABST
    Figure CN119652660B_ABST
Patent Text Reader

Abstract

The application discloses a power industry network security cooperative defense system based on a threat hunting technology, and particularly relates to the technical field of network security defense, and constructs a threat intelligence defense model comprising a threat intelligence sharing platform, a multi-layer defense architecture building unit, a network attack behavior analysis unit and a risk visualization display unit, collects and analyzes security log information in a power system in real time, discovers potential network security threats in time, and automatically issues early warnings; network security threat information is acquired through the threat intelligence sharing platform and the multi-layer defense architecture building unit; and then, the risk visualization display unit is provided with rich intelligence resources, so that it can more accurately identify and analyze potential threats, a linkage response mechanism is established between levels, rapid response and effective disposal of threats are realized, and the problem that the power industry network security cooperative defense system in the prior art cannot provide perfect network security threat information is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security defense technology, and more specifically, to a collaborative network security defense system for the power industry based on threat hunting technology. Background Technology

[0002] Threat hunting refers to the proactive and continuous process of searching for threats in the network that can bypass security detection or cause harm, using threat data, analysis techniques, and expert experience. It is a continuous, closed-loop proactive defense technology.

[0003] Threat hunting primarily employs two techniques: forensic techniques and analytical techniques. Forensic techniques involve using existing tools and technologies to collect traces left by attackers, preparing for subsequent threat identification. Analytical techniques refer to the methods used to analyze and detect threat traces in order to identify threats. Based on the object of forensic investigation, analytical techniques can be divided into two categories: log analysis and network analysis. Log analysis involves acquiring event logs such as application logs and system logs from devices or systems, then feeding them into threat detection models for identification to determine if an intrusion has occurred. Network analysis involves using traffic acquisition tools to obtain network traffic data packets, then judging whether the traffic is abnormal, and thus identifying potential threats.

[0004] However, it still has many shortcomings in practical use. For example, the existing power industry network security collaborative defense system cannot combine forensic technology and analysis technology to provide comprehensive network security threat information. Summary of the Invention

[0005] To overcome the aforementioned deficiencies of the prior art, this invention provides a collaborative defense system for cybersecurity in the power industry based on threat hunting technology, in order to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a collaborative defense system for cybersecurity in the power industry based on threat hunting technology, comprising:

[0007] The threat intelligence defense model is used to collect and analyze security log information in the power system in real time, promptly detect potential cybersecurity threats, and automatically issue early warnings. The threat intelligence defense model includes a threat intelligence sharing platform, a multi-layer defense architecture building unit, a network attack behavior analysis unit, and a risk visualization display unit.

[0008] The threat intelligence sharing platform is used to collect, organize, analyze, and share cybersecurity threat intelligence within the power industry, enabling rapid transmission and sharing of intelligence.

[0009] The multi-layered defense architecture building unit is used to construct a multi-layered defense system that includes a perception layer, a network layer, and an application layer. Each layer has corresponding security protection measures and can respond quickly when a threat is detected.

[0010] The network attack behavior analysis unit is used to acquire network security threat information, including network attack behavior, attack techniques, attacker identity, attack intent, and attack path. Based on the threat intelligence sharing platform and multi-layered defense architecture, it acquires network attack behavior, attack techniques, and attacker identity. It uses the ATT&CK framework to analyze the text information of network attack behavior and attack techniques, and outputs attack intent and attack path.

[0011] The risk visualization unit is used to display cybersecurity threat information to the outside world. The risk visualization unit maintains a close collaborative working relationship with the threat intelligence sharing platform, the multi-layer defense architecture building unit, and the network attack behavior analysis unit.

[0012] Preferably, a linkage response mechanism is established between the perception layer, network layer, and application layer. If a potential threat is detected, the rapid response mechanism is immediately activated to isolate, trace, and handle the threat, prevent its further spread, and record network attack behavior.

[0013] Preferably, the process of acquiring network attack behavior, attack techniques, and attacker identity based on a threat intelligence sharing platform and a multi-layered defense architecture includes the following steps:

[0014] Step S11: Join the power industry's internal threat intelligence sharing platform to obtain the latest threat intelligence and attack technology information;

[0015] Step S12: Browse the latest cybersecurity threat intelligence in the platform's intelligence database, use the keyword search function to enter keywords related to cyberattack behavior and attack techniques to obtain relevant intelligence information; conduct a detailed analysis of the obtained intelligence information to understand the characteristics of the attack behavior, the principles of the attack techniques, and the scope of impact; record the analysis results in text form for later use.

[0016] Step S13: Collect security log information at each level of the multi-layered defense architecture; analyze the collected security log information to extract key information related to network attack behavior and attack techniques; use correlation analysis technology to correlate security log information from different sources to construct a complete attack chain; based on the log analysis and correlation results, identify network attack behavior, attack techniques and attacker identity, and record the identification results in text form.

[0017] Step S14: Integrate the network attack behaviors, attack techniques and attacker identities obtained from the threat intelligence sharing platform and multi-layer defense architecture; output text information related to network attack behaviors and attack techniques, and share the integrated intelligence information with other members or organizations in the power industry to achieve intelligence sharing and collaborative defense.

[0018] Preferably, the attack intent includes, but is not limited to, data theft, system damage, and ransomware attacks; the attack path refers to a series of steps and stages that the attacker goes through from launching an attack to achieving its goal; the attack path is divided into multiple attack stages, each of which corresponds to different actions and strategies of the attacker; the attack stages include, but are not limited to, initial access, malicious execution, persistent modification, privilege escalation, and defense bypass.

[0019] Preferably, the method for obtaining the attack intent and attack path is as follows:

[0020] The attack technique text information is obtained, and natural language processing technology is used to perform semantic analysis on the attack technique text in order to capture the context information in the text, accurately understand the meaning and context of the attack technique, and match it to the attack stage in the ATT&CK framework.

[0021] By combining the description of this attack phase in the ATT&CK framework, we can infer the attacker's intent, analyze the keywords and phrases in the attack technique text, confirm the attacker's goals and motives, and connect the attack phases in chronological order to obtain the attack path.

[0022] Preferably, the power industry cybersecurity collaborative defense system based on threat hunting technology also includes

[0023] The collaborative defense performance analysis module is used to test the collaborative defense performance of the threat intelligence defense model and output the collaborative defense performance index XF.

[0024] The attacker harm analysis module analyzes attacker information, uses the product of threat weight and attack intensity to represent the attacker's harm coefficient, predicts the probability of the attacker's occurrence, inputs the occurrence probability and harm coefficient into the attacker risk analysis model, and outputs the attacker risk coefficient Gf.

[0025] The real-time network attack behavior monitoring module is used to monitor and analyze network attack behavior in real time, and output the network attack behavior clustering degree Yx;

[0026] The network security assessment module jointly analyzes the collaborative defense performance index, attacker risk coefficient, and network attack behavior clustering degree. After standardization, the results are expressed using a formula. The network security coefficient (Text) is calculated.

[0027] The early warning module issues an early warning when the network security level falls below the threshold THa, and prompts the user to take measures such as blocking the attack source or strengthening security protection.

[0028] Preferably, the collaborative defense performance index is obtained in the following way:

[0029] Design test cases: Identify existing security vulnerabilities based on security log information, and design test cases for each identified security vulnerability. Test cases include input data, expected output, execution steps, and evaluation criteria.

[0030] A test environment was set up to test the threat intelligence defense model. Test cases were executed, and the number of threats detected by the threat intelligence defense model, response time, intelligence sharing efficiency, and intelligence quality coefficient were recorded. The intelligence quality coefficient is used to reflect the accuracy of the intelligence.

[0031] The ratio of the number of threats detected by the threat intelligence defense model to the actual number of threats is denoted as the threat detection rate Tdr; the average threat response time Trs is calculated by analyzing the response time required from the detection of a threat to the implementation of defensive measures; and the product of intelligence sharing efficiency and intelligence quality coefficient is denoted as the intelligence sharing quality coefficient Sle.

[0032] After dimensionless and linear normalization of threat detection rate (Tdr), average threat response time (Trs), and intelligence sharing quality coefficient (Sle), the results are obtained using the formula... The collaborative defense performance index XF was calculated.

[0033] Preferably, the attacker's risk factor is obtained in the following way:

[0034] By analyzing the homogeneity of network attack behaviors, the number of attackers is obtained, denoted as m, and k represents the sequential number of the attacker's identity.

[0035] Let PSqk, Uqk, and Dqk be the number of requests per second, the number of affected users, and the percentage of application performance degradation for the k-th attacker, respectively; let PSqk be the number of requests per second for the k-th attacker, the number of affected users, and the percentage of application performance degradation. k ×Uq k ×Dq k The base strength is used to calculate the attack strength using the following formula:

[0036]

[0037] Among them, max_1 is the maximum value of the basic strength;

[0038] Let P be the probability of the k-th attacker's appearance, the harm coefficient, the threat weight, and the attack strength. k W k wq k gqk ;

[0039] The attacker risk coefficient Gf is calculated using the following attacker risk analysis model:

[0040]

[0041] W k =wq k ×gq k

[0042] The threat weight ranges from 0 to 1 to reflect the potential threat level of attackers for different attack types.

[0043] Preferably, the method for obtaining the aggregation degree of network attack behavior is as follows:

[0044] The network attack behaviors in the security log information are marked with timestamps, and the network attack behaviors are sorted according to the timestamps. Let the number of network attack behaviors be n, and let i and j represent the sequence number of the network attack behaviors, where i ≠ j. The clustering degree of network attack behaviors Yx is calculated using the following formula.

[0045]

[0046] Among them, T ij T is the time interval between the i-th network attack and the j-th network attack. a T is the average of the time intervals. b q is the preset value for the time interval; i Let q be the weight coefficient corresponding to the i-th network attack behavior. j e is the weight coefficient corresponding to the j-th network attack behavior; -λtci Let be the decay function of the time e from the occurrence of the i-th network attack to the current time, where λ is the decay coefficient used to adjust the decay rate, and tci is the distance e from the occurrence of the i-th network attack to the current time; -λtcj Let tcj be the decay function of the time elapsed since the occurrence of the j-th network attack, and tcj be the distance elapsed since the occurrence of the j-th network attack.

[0047] Preferably, a weighting coefficient is assigned to the network attack behavior based on the abnormal traffic size at each time point, using the formula... The weight coefficient L corresponding to the i-th network attack behavior is calculated. i Let be the abnormal traffic size of the i-th network attack.

[0048] The technical effects and advantages of this invention are as follows:

[0049] (1) The power industry network security collaborative defense system based on threat hunting technology provided by this invention constructs a threat intelligence defense model including a threat intelligence sharing platform, a multi-layer defense architecture building unit, a network attack behavior analysis unit, and a risk visualization display unit. It collects and analyzes security log information in the power system in real time, discovers potential network security threats in a timely manner, and automatically issues warnings. It obtains network security threat information by building a threat intelligence sharing platform and a multi-layer defense architecture building unit. This provides rich intelligence resources for the risk visualization display unit, enabling it to more accurately identify and analyze potential threats. By establishing a linkage response mechanism between each level, it achieves rapid response and effective handling of threats, solving the problem that the existing power industry network security collaborative defense system cannot provide complete network security threat information. Through threat hunting technology, it can actively find and identify potential threats, significantly improve defense efficiency, and reduce the frequency and losses of security incidents.

[0050] (2) The power industry network security collaborative defense system based on threat hunting technology provided by this invention obtains real-time network security coefficients through collaborative defense performance analysis module, attacker harm analysis module, network attack behavior monitoring module, and network security assessment module, and takes measures based on the network security coefficients; it provides enterprises with a comprehensive indicator for assessing network security status, enabling enterprises to have a more comprehensive understanding of their own network security level. By regularly assessing and improving the network security coefficients, enterprises can continuously improve their network security protection capabilities and effectively solve the problem of the inability to quantify and assess the network security of the power industry.

[0051] (3) The power industry network security collaborative defense system based on threat hunting technology provided by this invention tests the collaborative defense performance of the threat intelligence defense model through the collaborative defense performance analysis module and outputs the collaborative defense performance index XF, which helps enterprises understand the effectiveness of the current defense system and thus carry out targeted optimization and upgrading; the attacker harm analysis module analyzes attacker information, calculates the attacker's harm coefficient and predicts its probability of occurrence, and then outputs the attacker risk coefficient Gf, enabling enterprises to understand the severity and possibility of potential threats more accurately; the network attack behavior implementation monitoring module monitors and analyzes network attack behavior in real time and outputs the network attack behavior aggregation degree Yx, which helps enterprises to discover and respond to network attacks in a timely manner and prevent the attack behavior from spreading further and causing greater damage. Attached Figure Description

[0052] Figure 1 This is a block diagram of the threat intelligence defense model of the present invention.

[0053] Figure 2 This is a block diagram of the collaborative defense system for cybersecurity in the power industry according to the present invention. Detailed Implementation

[0054] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0055] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.

[0056] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the scope of this application and its application or use.

[0057] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.

[0058] Example 1, see Figure 1 The invention provides a threat intelligence defense model structure diagram and the following technical solutions in its embodiments:

[0059] A collaborative cybersecurity defense system for the power industry based on threat hunting technology includes:

[0060] The threat intelligence defense model is used to collect and analyze security log information in the power system in real time, promptly detect potential cybersecurity threats, and automatically issue early warnings. The threat intelligence defense model includes a threat intelligence sharing platform, a multi-layer defense architecture building unit, a network attack behavior analysis unit, and a risk visualization display unit.

[0061] The threat intelligence sharing platform is used to collect, organize, analyze, and share cybersecurity threat intelligence within the power industry, enabling rapid transmission and sharing of intelligence.

[0062] The explanation is that the threat intelligence sharing platform supports the import and export of various intelligence formats, facilitating the exchange of intelligence between different systems. Establishing a threat intelligence sharing platform ensures that threat intelligence can be shared in real time among all stakeholders in the industry, so as to respond quickly to emerging threats.

[0063] This multi-layered defense architecture building unit is used to construct a multi-layered defense system comprising a perception layer, a network layer, and an application layer. Each layer has corresponding security protection measures and can respond rapidly when a threat is detected. A linkage response mechanism is established between the layers. If a potential threat is detected, a rapid response mechanism is immediately activated to isolate, trace, and handle the threat, preventing its further spread and recording network attack behavior. Once a threat is detected at one layer, other layers are immediately notified to coordinate defense. For example, when the perception layer or network layer detects a potential threat, an alarm will be triggered immediately. The linkage response mechanism records network attack behavior for subsequent analysis and improvement of defense strategies.

[0064] The network attack behavior analysis unit is used to acquire network security threat information, including network attack behavior, attack techniques, attacker identity, attack intent, and attack path. Based on the threat intelligence sharing platform and multi-layered defense architecture, it acquires network attack behavior, attack techniques, and attacker identity. It uses the ATT&CK framework to analyze the text information of network attack behavior and attack techniques, and outputs attack intent and attack path.

[0065] The risk visualization display unit is used to display cybersecurity threat information to the outside world.

[0066] The risk visualization unit maintains a close collaborative working relationship with the threat intelligence sharing platform, the multi-layered defense architecture building unit, and the network attack behavior analysis unit.

[0067] In this embodiment of the invention, it is necessary to further explain that the perception layer is responsible for monitoring network traffic and network attack behavior. Through sensors and monitoring devices deployed in the network, it captures the data flow in the network in real time, including network traffic, user behavior and system logs. The collected data is analyzed and filtered using preset rules, pattern matching or machine learning algorithms to detect abnormal traffic or behavior. Once abnormal traffic or behavior is detected, the perception layer will immediately issue an alarm, record the network traffic and network attack behavior in the security log and transmit it to the network attack behavior analysis unit.

[0068] The network layer is responsible for the security protection of the network boundary. By setting up security devices, such as firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS), it prevents external attackers from entering the internal network, prevents the leakage of sensitive internal information, and records abnormal network information (such as unauthorized access attempts, malicious traffic, etc.) in the security log and transmits it to the network attack behavior analysis unit.

[0069] The application layer is responsible for protecting the power industry's applications from attacks and damage. Through the security protection of the application layer, it prevents business interruption and data leakage caused by security vulnerabilities, and records abnormal application information (such as unauthorized access, data tampering, etc.) in the security log and transmits it to the network attack behavior analysis unit.

[0070] Establish a coordinated response mechanism among the perception layer, network layer, and application layer. If a potential threat is detected, immediately activate the rapid response mechanism to isolate, trace, and handle the threat, prevent its further spread, and record network attack behavior.

[0071] In this embodiment of the invention, it is necessary to further explain that the process of obtaining network attack behavior, attack techniques, and attacker identity based on a threat intelligence sharing platform and a multi-layered defense architecture includes the following steps:

[0072] Step S11: Join a threat intelligence sharing platform within the power industry, such as an existing professional cybersecurity intelligence sharing community or organization, and register as a formal member of the platform in order to obtain the latest threat intelligence and attack technology information.

[0073] Step S12: Browse the latest cybersecurity threat intelligence in the platform's intelligence database. Use the keyword search function to enter keywords related to cyberattack behavior and attack techniques, such as "DDoS attack" and "SQL injection," to obtain relevant intelligence information. Conduct a detailed analysis of the obtained intelligence information to understand the characteristics of the attack behavior, the principles of the attack techniques, and the scope of impact. Record the analysis results in text form for later use.

[0074] Step S13: Collect security log information at each layer of the multi-layered defense architecture (such as the perception layer, network layer, and application layer); analyze the collected security log information to extract key information related to network attack behavior and attack techniques; use correlation analysis technology to correlate security log information from different sources to construct a complete attack chain; based on the log analysis and correlation results, identify network attack behavior, attack techniques, and attacker identity, and record the identification results in text form.

[0075] Step S14: Integrate the network attack behaviors, attack techniques and attacker identities obtained from the threat intelligence sharing platform and multi-layer defense architecture; remove duplicate information to ensure the accuracy and completeness of the intelligence; output text information related to network attack behaviors and attack techniques, and share the integrated intelligence information with other members or organizations in the power industry to achieve intelligence sharing and collaborative defense.

[0076] In this embodiment of the invention, it is necessary to further explain that the attack intent includes, but is not limited to, data theft, system damage, and ransomware; the attack path refers to a series of steps and stages that the attacker goes through from launching an attack to achieving its goal; the attack path is divided into multiple attack stages, each of which corresponds to different actions and strategies of the attacker; the attack stages include, but are not limited to, initial access, malicious execution, persistent modification, privilege escalation, and defense bypass.

[0077] In this embodiment of the invention, it needs to be further explained that the method for obtaining the attack intent and attack path is as follows:

[0078] The attack technique text information is obtained, and natural language processing techniques (such as the ALBERT-BiLSTM model) are used to perform semantic analysis on the attack technique text to capture the context information in the text, accurately understand the meaning and context of the attack technique, and match it to the attack stage in the ATT&CK framework.

[0079] By combining the description of this attack phase in the ATT&CK framework, we can infer the attacker's intent, analyze the keywords and phrases in the attack technique text, and further confirm the attacker's goals and motives; we can also connect the attack phases in chronological order to obtain the attack path.

[0080] Example 2, see Figure 2 The present invention provides a block diagram of a collaborative defense system for cybersecurity in the power industry. The technical solution provided in this embodiment differs from Embodiment 1 in that it further includes...

[0081] The collaborative defense performance analysis module is used to test the collaborative defense performance of the threat intelligence defense model and output the collaborative defense performance index XF.

[0082] The attacker harm analysis module analyzes attacker information, uses the product of threat weight and attack intensity to represent the attacker's harm coefficient, predicts the probability of the attacker's occurrence, inputs the occurrence probability and harm coefficient into the attacker risk analysis model, and outputs the attacker risk coefficient Gf.

[0083] The real-time network attack behavior monitoring module is used to monitor and analyze network attack behavior in real time, and output the network attack behavior clustering degree Yx;

[0084] The network security assessment module jointly analyzes the collaborative defense performance index, attacker risk coefficient, and network attack behavior clustering degree. After standardization, the results are expressed using a formula. The network security coefficient (Text) is calculated.

[0085] The explanation is that the input parameters XF, Gf, and Yx are standardized to ensure that they are on the same order of magnitude, thereby avoiding the excessive influence of certain parameters on the final result. The standardization process is one of Z-score standardization and Min-Max standardization.

[0086] The early warning module issues an early warning when the network security level falls below the threshold THa, and prompts the user to take measures such as blocking the attack source or strengthening security protection.

[0087] In this embodiment of the invention, it needs to be further explained that the method for obtaining the collaborative defense performance index is as follows:

[0088] Design test cases: Identify existing security vulnerabilities based on security log information, and design test cases for each identified security vulnerability. Test cases include input data, expected output, execution steps, and evaluation criteria.

[0089] A test environment was set up to test the threat intelligence defense model. Test cases were executed, and the number of threats detected by the threat intelligence defense model, response time, intelligence sharing efficiency, and intelligence quality coefficient were recorded. The intelligence quality coefficient is used to reflect the accuracy of the intelligence.

[0090] The ratio of the number of threats detected by the threat intelligence defense model to the actual number of threats is denoted as the threat detection rate Tdr; the average threat response time Trs is calculated by analyzing the response time required from the detection of a threat to the implementation of defensive measures; and the product of intelligence sharing efficiency and intelligence quality coefficient is denoted as the intelligence sharing quality coefficient Sle.

[0091] After dimensionless and linear normalization of threat detection rate (Tdr), average threat response time (Trs), and intelligence sharing quality coefficient (Sle), the results are obtained using the formula... The collaborative defense performance index XF was calculated.

[0092] In this embodiment of the invention, it needs to be further explained that the attacker risk coefficient is obtained in the following way:

[0093] By analyzing the homogeneity of network attack behaviors, the number of attackers is obtained, denoted as m, and k represents the sequential number of the attacker's identity.

[0094] Let PSqk, Uqk, and Dqk be the number of requests per second, the number of affected users, and the percentage of application performance degradation for the k-th attacker, respectively; let PSqk be the number of requests per second for the k-th attacker, the number of affected users, and the percentage of application performance degradation. k ×Uq k ×Dq k The base strength is used to calculate the attack strength using the following formula:

[0095]

[0096] Among them, max_1 is the maximum value of the basic strength;

[0097] Let P be the probability of the k-th attacker's appearance, the harm coefficient, the threat weight, and the attack strength. k W k wq k gq k ;

[0098] The attacker risk coefficient Gf is calculated using the following attacker risk analysis model:

[0099]

[0100] W k =wq k ×gq k

[0101] The threat weight ranges from 0 to 1 to reflect the potential threat level of attackers for different attack types.

[0102] In this embodiment of the invention, it needs to be further explained that the method for obtaining the aggregation degree of the network attack behavior is as follows:

[0103] The network attack behaviors in the security log information are marked with timestamps, and the network attack behaviors are sorted according to the timestamps. Let the number of network attack behaviors be n, and let i and j represent the sequence number of the network attack behaviors, where i ≠ j. The clustering degree of network attack behaviors Yx is calculated using the following formula.

[0104]

[0105] Among them, T ij T is the time interval between the i-th network attack and the j-th network attack. a T is the average of the time intervals. b q is the preset value for the time interval; i Let q be the weight coefficient corresponding to the i-th network attack behavior. j e is the weight coefficient corresponding to the j-th network attack behavior; -λtci Let be the decay function of the time e from the occurrence of the i-th network attack to the current time, where λ is the decay coefficient used to adjust the decay rate, and tci is the distance e from the occurrence of the i-th network attack to the current time; -λtcj Let tcj be the decay function of the time elapsed since the occurrence of the j-th network attack, and tcj be the distance elapsed since the occurrence of the j-th network attack.

[0106] Explanation, Used to measure the degree of deviation of the time interval from the average time interval and the preset time interval; the weight coefficients qi and qj can be set according to factors such as the type and severity of the attack behavior and the vulnerability of the target system. The double summation traverses all possible attack behaviors to calculate the common contribution to the clustering degree.

[0107] In one possible implementation, a weighting coefficient is assigned to the network attack behavior based on the magnitude of abnormal traffic at each time point, using a formula... The weight coefficient L corresponding to the i-th network attack behavior is calculated. i Let be the abnormal traffic size of the i-th network attack.

[0108] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A collaborative defense system for cybersecurity in the power industry based on threat hunting technology, characterized in that: include: The threat intelligence defense model is used to collect and analyze security log information in the power system in real time, identify cybersecurity threats, and automatically issue early warnings. The threat intelligence defense model includes a threat intelligence sharing platform, a multi-layered defense architecture building unit, a network attack behavior analysis unit, and a risk visualization display unit. The threat intelligence sharing platform is used to collect, organize, analyze, and share network security threat intelligence within the power industry. The multi-layered defense architecture building unit is used to construct a multi-layered defense hierarchy including a perception layer, a network layer, and an application layer, with each layer having corresponding security protection measures. The network attack behavior analysis unit is used to acquire network security threat information; acquire network attack behavior, attack techniques, and attacker identities; analyze network attack behavior and attack technique text information using the ATT&CK framework; and output attack intent and attack paths. The risk visualization display unit is used to externally display network security threat information. The collaborative defense performance analysis module is used to test the collaborative defense performance of the threat intelligence defense model and outputs the collaborative defense performance index XF. After joint analysis of threat detection rate Tdr, average threat response time Trs, and intelligence sharing quality coefficient Sle, dimensionless and linearly normalized calculations are performed, and the results are expressed using the formula... The collaborative defense performance index XF is calculated; the methods for obtaining the collaborative defense performance index include: Based on security log information, identify existing security vulnerabilities and design test cases for each identified vulnerability. Test cases include input data, expected output, execution steps, and evaluation criteria. Build a test environment to test the threat intelligence defense model, execute test cases, record the number of threats detected by the model, response time, and intelligence sharing efficiency, and evaluate the intelligence quality coefficient, which reflects the accuracy of the intelligence. The ratio of the number of threats detected by the threat intelligence defense model to the actual number of threats is denoted as the threat detection rate (Tdr). Analyze the response time required from threat detection to taking defensive measures and calculate the average threat response time (Trs). The product of intelligence sharing efficiency and intelligence quality coefficient is denoted as the intelligence sharing quality coefficient (Sle). The attacker threat analysis module analyzes attacker information, represents the attacker's threat coefficient as the product of threat weight and attack strength, predicts the probability of the attacker's occurrence, and inputs the occurrence probability and threat coefficient into the attacker risk analysis model, outputting the attacker risk coefficient Gf; the attacker risk coefficient is obtained as follows: By analyzing the homogeneity of network attack behaviors, the number of attackers is obtained, denoted as m, and k represents the sequential number of the attacker's identity. The number of requests per second, the number of users affected, and the percentage of application performance degradation for the k-th attacker are denoted as PSq, respectively. k Uq k Dq k ;Will Recorded as the basic strength, using the formula The attack strength is calculated as follows: where max_1 is the maximum value of the base strength; the probability of the k-th attacker's appearance, the harm coefficient, the threat weight, and the attack strength are denoted as P. k W k wq k gq k ; Through attacker risk analysis model The attacker risk coefficient Gf is calculated: where the threat weight ranges from 0 to 1 to reflect the potential threat level of attackers for different attack types. The real-time network attack behavior monitoring module is used to monitor and analyze network attack behavior in real time, and output the network attack behavior clustering degree Yx; wherein, the network attack behavior clustering degree is obtained in the following way: The network attack behaviors in the security log information are marked with timestamps, and the network attack behaviors are sorted according to the timestamps. Let the number of network attack behaviors be n, and let i and j represent the sequence number of the network attack behaviors, where i ≠ j. The clustering degree of network attack behaviors Yx is calculated using the following formula. in, It is the first i The first cyberattack behavior and the first j The time interval between cyberattacks The average value of the time interval. q is the preset value for the time interval; i Let q be the weight coefficient corresponding to the i-th network attack behavior. j Here is the weight coefficient corresponding to the j-th network attack behavior; Let λ be the decay function of the time elapsed since the i-th network attack occurred, where λ is the decay coefficient used to adjust the decay rate, and tci is the distance elapsed since the i-th network attack occurred. Let tcj be the decay function of the time elapsed since the occurrence of the j-th network attack, and tcj be the distance between the time elapsed since the occurrence of the j-th network attack and the current time. Based on the magnitude of abnormal traffic at each time point, weight coefficients are assigned to the network attack behaviors according to the formula. The weight coefficient L corresponding to the i-th network attack behavior is calculated. i Let be the abnormal traffic size of the i-th network attack. The network security assessment module jointly analyzes the collaborative defense performance index, attacker risk coefficient, and network attack behavior clustering degree. After standardization, the results are expressed using a formula. The network security coefficient (Text) is calculated. The early warning module issues an early warning when the network security coefficient falls below the threshold THa, and prompts for action; the action includes blocking the attack source and strengthening security protection.

2. The power industry cybersecurity collaborative defense system based on threat hunting technology according to claim 1, characterized in that, Establish a coordinated response mechanism among the perception layer, network layer, and application layer. If a threat is detected, it should be isolated, traced, and dealt with to prevent its further spread, and network attack behavior should be recorded.

3. The power industry cybersecurity collaborative defense system based on threat hunting technology according to claim 1, characterized in that, The process of acquiring network attack behavior, attack techniques, and attacker identity based on a threat intelligence sharing platform and a multi-layered defense architecture includes the following steps: Step S11: Join the power industry's internal threat intelligence sharing platform to obtain the latest threat intelligence and attack technology information; Step S12: Browse the latest cybersecurity threat intelligence in the platform's intelligence database, use the keyword search function to enter keywords related to cyberattack behaviors and attack techniques to obtain relevant intelligence information; analyze the obtained intelligence information; record the analysis results in text form for later use. Step S13: Collect security log information at each level of the multi-layered defense architecture, analyze the collected security log information, and extract key information related to network attack behavior and attack techniques. Using correlation analysis technology, security log information from different sources is correlated to construct a complete attack chain; based on the log analysis and correlation results, network attack behaviors, attack techniques and attacker identities are identified, and the identification results are recorded in text form. Step S14: Integrate the network attack behaviors, attack techniques and attacker identities obtained from the threat intelligence sharing platform and multi-layer defense architecture; output text information related to network attack behaviors and attack techniques, and share the integrated intelligence information with other members or organizations in the power industry to achieve intelligence sharing and collaborative defense.

4. The power industry network security collaborative defense system based on threat hunting technology according to claim 3, characterized in that, The attack path refers to a series of steps and stages that an attacker goes through from launching an attack to achieving their goal; the attack path is divided into multiple attack stages, each of which corresponds to different actions and strategies of the attacker.

5. The power industry network security collaborative defense system based on threat hunting technology according to claim 3, characterized in that, The method for obtaining the attack intent and attack path is as follows: The attack technique text information is obtained, and natural language processing technology is used to perform semantic analysis on the attack technique text in order to capture the context information in the text, understand the meaning and context relationship of the attack technique, and match it to the attack stage in the ATT&CK framework. By combining the description of this attack phase in the ATT&CK framework, we can infer the attacker's intent, analyze the keywords and phrases in the attack technique text, confirm the attacker's goals and motives, and connect the attack phases in chronological order to obtain the attack path.