A fine granularity of micro cell node device management method and system
By employing a fine-grained micro-element node device management method, mirrored micro-element nodes and security honeypots are constructed. Combined with virus detection programs, refined management of power grid equipment is achieved. This solves the problems of insufficient security and unified correlation analysis capabilities in the power grid control equipment management model, and realizes efficient and secure power grid equipment management.
Patent Information
- Application Number
- CN202411742841.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-11-29
AI Technical Summary
Existing power grid control equipment management models lack sufficient security and unified correlation analysis capabilities for multi-source heterogeneous data, resulting in low data security.
A fine-grained micro-element node device management method is adopted. By constructing mirrored micro-element nodes and security honeypots, combined with virus detection programs, the power grid equipment can be managed in a refined manner, and a secure data interaction environment can be built by encrypting communication data.
It has improved the safety and management efficiency of power grid equipment, enhanced the flexibility and scalability of the system, ensured the security of data transmission, reduced the occurrence of security incidents, and improved the management intelligence level and security protection capabilities of the smart grid.
Smart Images

Figure CN119675929B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data modeling technology, and in particular to a fine-grained micro-element node device management method and system. Background Technology
[0002] Currently, in the field of management models for power grid control equipment, the data structure of management models often adopts multi-source heterogeneous data. The structural data sources of multi-source heterogeneous data are highly diverse, and the ability to uniformly correlate and analyze multi-source heterogeneous data such as the trigger data, missing flow data and terminal data that threaten the management model during the data security protection process is low, which will greatly reduce the data security of the management model.
[0003] Currently, it is necessary to propose a fine-grained micro-element node device management method and system to address the shortcomings of traditional management models in terms of low security. Summary of the Invention
[0004] In view of the problems existing in the current fine-grained micro-element node device management methods and systems, this invention is proposed.
[0005] Therefore, the problem that this invention aims to solve is...
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, embodiments of the present invention provide a fine-grained micro-element node device management method, which includes: incorporating power grid devices into a management model; selecting a power grid device; constructing a fine-grained micro-element node based on the data transmission and reception characteristics of the power grid device and its corresponding data storage unit; mirroring the micro-element node to form a mirrored micro-element node; returning to select a power grid device; and repeating this process until all power grid devices have been selected; forming a security honeypot based on all the mirrored micro-element nodes; sending the received data to the security honeypot; obtaining the output results after analysis by the security honeypot; and performing a data interaction task based on the output results of the security honeypot.
[0008] As a preferred embodiment of the fine-grained micro-element node device management method of the present invention, the method of incorporating power grid devices into the management model includes, before incorporating each power grid device into the management model, receiving a list of power grid devices, selecting management data of a selected power grid device, abstracting the core capabilities of the management data into a function, forming access features of the management model based on the features of the function, returning the selected management data of a selected power grid device, until the management data of all power grid devices has been selected.
[0009] Before incorporating each power grid device into the management model, select a power grid device, divide the secure honeypot data storage area, and divide the secure honeypot data storage area into multiple data areas based on access characteristics. Incorporate the function characteristics of each data area into the management function, and associate the management function with the Trojan analysis program.
[0010] As a preferred embodiment of the fine-grained micro-element node device management method of the present invention, the response node receiving and transmitting data characteristics of the power grid equipment and the corresponding data storage unit include response nodes for extracting the power grid equipment's file library, response nodes for the database, response nodes for the code management library, response nodes for the account program, and response nodes for the password program.
[0011] The response nodes of the file library are parsed. The response nodes include identification units and access units. The data characteristics received by the identification unit and the data characteristics sent by the access unit are extracted. It is then determined whether the data characteristics received by the identification unit match the characteristics of the function.
[0012] If the characteristics of the data received by the identification unit match the characteristics of the function, the identification unit is incorporated into the management model using the access characteristics.
[0013] If the data characteristics received by the identifier unit do not match the characteristics of the function, then extract the differences between the data characteristics received by the identifier unit and the characteristics of the function.
[0014] Call the function corresponding to the application programming interface, form a matching function based on the differences, incorporate the identification unit into the management model based on the access characteristics of the matching function, replace the data receiving characteristics of the identification unit with the data sending characteristics of the access unit, and return a judgment on whether the data receiving characteristics of the identification unit match the characteristics of the function.
[0015] As a preferred embodiment of the fine-grained micro-node device management method of the present invention, the fine-grained micro-node construction includes: constructing fine-grained micro-nodes based on the data transmission and reception characteristics of response nodes and corresponding data storage units; setting communication passwords based on the security level of response nodes; encrypting the communication data between response nodes and the management model using the communication passwords; and establishing a one-to-one correspondence between the communication data and the data storage units. The specific steps are as follows:
[0016] The characteristics of the data sent and received by the response node are mirrored to form a mirror file. A mirror file is selected, and the database corresponding to the mirror file is invalidated to generate a inducement file. The inducement file is included in the data area, and a one-to-one correspondence is established between the mirror file and the data area. Mirror micro-nodes are formed based on the mirror file and the data area. The process of selecting a mirror file is repeated until all mirror files have been selected. A data area is selected, and a mapping relationship is established between the data area and the virus detection program. The process of selecting a data area is repeated until all data areas have been selected. The virus detection program is included in the management model, and the unified correlation analysis data of the management model is called to determine whether the unified correlation analysis data of the management model has reached the uniformity threshold.
[0017] If the unified correlation analysis data of the management model reaches the uniformity threshold, then security protection tasks are performed based on the risk protection conclusions in the unified correlation analysis data.
[0018] If the unified correlation analysis data of the management model does not reach the uniformity threshold, then all access devices will communicate with the security honeypot.
[0019] A fine-grained micro-element node device management system is provided, including a server for executing a fine-grained micro-element node device management method, and multiple power grid devices, all of which are communicatively connected to the server.
[0020] As a preferred embodiment of the fine-grained micro-element node device management method of the present invention, the mirroring of the micro-element node includes selecting a data area, establishing a mapping relationship between the data area and the virus detection program, returning to select a data area, until all data areas have been selected, and incorporating the virus detection program into the management model.
[0021] Incorporating virus detection procedures into the management model involves including each power grid device in the management system. This is achieved by extracting response nodes from the power grid device's file repository, database, code management repository, account program, and password program, thus extracting multi-source heterogeneous data. This multi-source heterogeneous data is then mirrored to form mirrored micro-nodes, and a security honeypot is formed based on all the mirrored micro-nodes.
[0022] As a preferred embodiment of the fine-grained micro-element node device management method of the present invention, the method of sending the received data to the security honeypot includes sending the received data to the security honeypot and obtaining the output results after analysis by the security honeypot.
[0023] Based on the output of the security honeypot, a data interaction task is performed. The system receives a list of power grid devices, selects the management data of one power grid device, abstracts the core capabilities of the management data into a function, forms the access characteristics of the management model based on the characteristics of the function, and returns the management data of the selected power grid device. This process continues until the management data of all power grid devices has been selected.
[0024] As a preferred embodiment of the fine-grained micro-element node device management method of the present invention, the data interaction task based on the output result of the security honeypot includes mirroring multi-source heterogeneous data to form mirrored micro-element nodes, and forming a security honeypot based on all mirrored micro-element nodes.
[0025] When receiving external interaction information, the security honeypot acts as the executor of the interaction information, sending the received data to the security honeypot, obtaining the output results after analysis by the security honeypot, and performing data interaction tasks based on the output results of the security honeypot.
[0026] Secondly, embodiments of the present invention provide a fine-grained micro-element node device management system, comprising: a construction module, which incorporates power grid devices into a management model, selects a power grid device, and constructs a fine-grained micro-element node based on the data transmission and reception characteristics of the power grid device and its corresponding data storage unit; a selection module, which mirrors the micro-element node to form a mirrored micro-element node, returns to select a power grid device, and continues until all power grid devices have been selected; and a management module, which forms a security honeypot based on all mirrored micro-element nodes, sends the received data to the security honeypot, obtains the output results after analysis by the security honeypot, and performs data interaction tasks based on the output results of the security honeypot.
[0027] Thirdly, embodiments of the present invention provide a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement any step of the above-described fine-grained micro-node device management method.
[0028] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the above-described fine-grained micro-node device management method.
[0029] The beneficial effects of this invention are as follows: This invention can effectively improve the security and management efficiency of power grid equipment. By abstracting the management data of each power grid device into functions and constructing a management model based on the characteristics of these functions, refined management of power grid equipment is achieved. This method also introduces a security honeypot mechanism, which improves system security by mirroring micro-nodes and combining them with virus detection programs to identify and analyze potential threats. Furthermore, this solution further ensures the security of data transmission and reduces the occurrence of security incidents through measures such as encrypting communication data and building a secure data interaction environment. Simultaneously, this technical solution supports the effective management and utilization of multi-source heterogeneous data, enhancing the system's flexibility and scalability, and providing strong technical support for the construction and operation of smart grids. In summary, this technical solution not only improves the intelligence level of power grid equipment management but also significantly enhances the system's security protection capabilities, which is of great significance for promoting the informatization of the power industry. Attached Figure Description
[0030] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:
[0031] Figure 1 The following is a detailed flowchart of a fine-grained micro-element node device management method and system provided in one embodiment of the present invention. Detailed Implementation
[0032] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0033] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0034] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0035] This invention is described in detail with reference to the schematic diagrams. When detailing the embodiments of this invention, for ease of explanation, the cross-sectional views illustrating the device structure may be partially enlarged, not adhering to the usual scale. Furthermore, the schematic diagrams are merely examples and should not be construed as limiting the scope of protection of this invention. In actual fabrication, the three-dimensional spatial dimensions of length, width, and depth should be included.
[0036] Furthermore, in the description of this invention, it should be noted that the terms "upper," "lower," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. These terms are used solely for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. In addition, the terms "first," "second," or "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0037] Unless otherwise explicitly specified and limited, the terms "installation," "connection," and "joining" in this invention should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; similarly, they can refer to mechanical connections, electrical connections, or direct connections, or indirect connections through an intermediate medium, or internal connections between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0038] Example 1
[0039] Reference Figure 1 This is the first embodiment of the present invention, which provides a fine-grained micro-element node device management method, including:
[0040] S1: Incorporate power grid equipment into the management model. Select a power grid device and construct fine-grained micro-nodes based on the device's data transmission and reception characteristics and corresponding data storage units.
[0041] The process of incorporating power grid equipment into the management model includes receiving a list of power grid equipment before incorporating each power grid equipment into the management model, selecting management data for one power grid equipment, abstracting the core capabilities of the management data into a function, forming access characteristics of the management model based on the characteristics of the function, and returning the selected management data for one power grid equipment, until the management data for all power grid equipment has been selected.
[0042] Before incorporating each power grid device into the management model, select a power grid device, divide the secure honeypot data storage area, and divide the secure honeypot data storage area into multiple data areas based on access characteristics. Incorporate the function characteristics of each data area into the management function, and associate the management function with the Trojan analysis program.
[0043] S1.1: Based on the data transmission and reception characteristics of the response nodes of power grid equipment and the corresponding data storage units, the response nodes of the file library, database, code management library, account program, and password program of the power grid equipment are extracted.
[0044] The response nodes of the file library are parsed. The response nodes include identification units and access units. The data characteristics received by the identification unit and the data characteristics sent by the access unit are extracted. It is then determined whether the data characteristics received by the identification unit match the characteristics of the function.
[0045] If the characteristics of the data received by the identification unit match the characteristics of the function, the identification unit is incorporated into the management model using the access characteristics.
[0046] If the data characteristics received by the identifier unit do not match the characteristics of the function, then extract the differences between the data characteristics received by the identifier unit and the characteristics of the function.
[0047] Call the function corresponding to the application programming interface, form a matching function based on the differences, incorporate the identification unit into the management model based on the access characteristics of the matching function, replace the data receiving characteristics of the identification unit with the data sending characteristics of the access unit, and return a judgment on whether the data receiving characteristics of the identification unit match the characteristics of the function.
[0048] S1.2: Constructing fine-grained micro-nodes involves building fine-grained micro-nodes based on the data transmission and reception characteristics of the response nodes and their corresponding data storage units. Communication passwords are set based on the security level of the response nodes, and these passwords are used to encrypt the communication data between the response nodes and the management model, establishing a one-to-one correspondence between the communication data and the data storage units. The specific steps are as follows:
[0049] The characteristics of the data sent and received by the response node are mirrored to form a mirror file. A mirror file is selected, and the database corresponding to the mirror file is invalidated to generate a inducement file. The inducement file is included in the data area, and a one-to-one correspondence is established between the mirror file and the data area. Mirror micro-nodes are formed based on the mirror file and the data area. The process of selecting a mirror file is repeated until all mirror files have been selected. A data area is selected, and a mapping relationship is established between the data area and the virus detection program. The process of selecting a data area is repeated until all data areas have been selected. The virus detection program is included in the management model, and the unified correlation analysis data of the management model is called to determine whether the unified correlation analysis data of the management model has reached the uniformity threshold.
[0050] If the unified correlation analysis data of the management model reaches the uniformity threshold, then security protection tasks are performed based on the risk protection conclusions in the unified correlation analysis data.
[0051] If the unified correlation analysis data of the management model does not reach the uniformity threshold, then all access devices will communicate with the security honeypot.
[0052] A fine-grained micro-element node device management system is provided, including a server for executing a fine-grained micro-element node device management method, and multiple power grid devices, all of which are communicatively connected to the server.
[0053] S2: Mirror the micro-element node to form a mirrored micro-element node, and return to select a power grid device until all power grid devices have been selected.
[0054] Among them, mirroring the micro-element node includes selecting a data area, establishing a mapping relationship between the data area and the virus detection program, returning to select a data area, and continuing until all data areas have been selected, and incorporating the virus detection program into the management model.
[0055] Incorporating virus detection procedures into the management model involves including each power grid device in the management system. This is achieved by extracting response nodes from the power grid device's file repository, database, code management repository, account program, and password program, thus extracting multi-source heterogeneous data. This multi-source heterogeneous data is then mirrored to form mirrored micro-nodes, and a security honeypot is formed based on all the mirrored micro-nodes.
[0056] S3: Based on all mirrored micro-element nodes, a secure honeypot is formed. The received data is sent to the secure honeypot, the output results after analysis by the secure honeypot are obtained, and the data interaction task is executed based on the output results of the secure honeypot.
[0057] Sending the received data to the security honeypot includes sending the received data to the security honeypot and obtaining the output results after analysis by the security honeypot.
[0058] Based on the output of the security honeypot, a data interaction task is performed. The system receives a list of power grid devices, selects the management data of one power grid device, abstracts the core capabilities of the management data into a function, forms the access characteristics of the management model based on the characteristics of the function, and returns the management data of the selected power grid device. This process continues until the management data of all power grid devices has been selected.
[0059] S3.1: The data interaction task based on the output of the security honeypot includes mirroring multi-source heterogeneous data to form mirrored micro-nodes, and forming a security honeypot based on all mirrored micro-nodes;
[0060] When receiving external interaction information, the security honeypot acts as the executor of the interaction information. It sends the received data to the security honeypot, obtains the output results after analysis by the security honeypot, and performs data interaction tasks based on the output results of the security honeypot.
[0061] In a preferred embodiment, a fine-grained micro-node device management system includes a construction module that incorporates power grid devices into a management model, selects a power grid device, and constructs a fine-grained micro-node based on the data transmission and reception characteristics of the power grid device and its corresponding data storage unit; a selection module that mirrors the micro-nodes to form mirrored micro-nodes, returns the selection of a power grid device, and continues until all power grid devices have been selected; and a management module that forms a security honeypot based on all mirrored micro-nodes, sends received data to the security honeypot, obtains the output results after analysis by the security honeypot, and performs data interaction tasks based on the output results of the security honeypot.
[0062] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0063] In summary, this invention effectively improves the security and management efficiency of power grid equipment. By abstracting the management data of each power grid device into functions and constructing a management model based on the characteristics of these functions, refined management of power grid equipment is achieved. This method also introduces a security honeypot mechanism, which improves system security by mirroring micro-nodes and combining them with virus detection programs to identify and analyze potential threats. Furthermore, this solution further ensures the security of data transmission and reduces the occurrence of security incidents through measures such as encrypting communication data and building a secure data interaction environment. Simultaneously, this technical solution supports the effective management and utilization of multi-source heterogeneous data, enhancing the system's flexibility and scalability, and providing strong technical support for the construction and operation of smart grids. In conclusion, this technical solution not only improves the intelligence level of power grid equipment management but also significantly enhances the system's security protection capabilities, which is of great significance for promoting the informatization of the power industry.
[0064] Example 2
[0065] Reference Figure 1 This is the second embodiment of the present invention, which provides a fine-grained micro-element node device management method. In order to verify the beneficial effects of the present invention, a simulation experiment is conducted for scientific demonstration.
[0066] In the aforementioned fine-grained micro-node device management method, the construction of fine-grained micro-nodes is based on the data transmission and reception characteristics of response nodes and their corresponding data storage units. The specific steps include: first, mirroring the data transmission and reception characteristics of response nodes to form a mirror file; then, selecting a mirror file, invalidating the database corresponding to the mirror file to generate an inducement file, and incorporating it into the data area to ensure a one-to-one correspondence between the mirror file and the data area; after forming mirrored micro-nodes based on the mirror file and the data area, repeating this process until all mirror files have been selected; next, selecting a data area and establishing a mapping relationship between the data area and the virus detection program, until all data areas have been selected; the virus detection program is then incorporated into the management model, which calls unified correlation analysis data to determine whether the data has reached a preset uniformity threshold, such as a 95% data consistency rate.
[0067] If the unified correlation analysis data of the management model shows that 95% of the data meets the consistency threshold, then corresponding security protection tasks are executed based on the risk protection conclusions in the unified correlation analysis data, such as automatically isolating suspicious devices or updating security policies. Conversely, if the unified correlation analysis data of the management model does not reach the 95% consistency threshold, the system will communicate with all accessing devices to the security honeypot to further detect and analyze potential security threats. This mechanism ensures that even in complex and ever-changing network environments, various security challenges can be efficiently identified and addressed, guaranteeing the stable operation of power grid equipment. The correlation analysis data thresholds of this invention are shown in Table 1 below:
[0068] Table 1 Threshold Table for Association Analysis Data in this Invention
[0069]
[0070] Table 1 comprehensively presents the key data points involved in the above technical solution, which helps to better understand and evaluate the performance and effectiveness of the solution. A comparison between the present invention and existing technologies is shown in Table 2 below:
[0071] Table 2 Comparison of the present invention and the prior art
[0072]
[0073] Table 2 shows that the technical solution of the present invention has significant advantages in many aspects, such as management strength, data encryption, security honeypot, multi-source heterogeneous data management, data analysis, data consistency threshold, virus detection program integration, response speed, system scalability, security protection task execution, maximum number of supporting devices, and maximum processing capacity per unit time, and can better meet the needs of modern power grid equipment management.
[0074] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for managing fine-grained micronode devices, the method comprising: Comprising, The grid equipment is brought into the management model, one grid equipment is selected, and a fine-grained micro-element node is constructed based on the data transmission characteristics of the response node of the grid equipment and the corresponding data storage unit; The fine-grained micro-element node includes constructing a fine-grained micro-element node based on the response node data transmission characteristics and the corresponding data storage unit, setting a communication password based on the security level of the response node, encrypting the communication data between the response node and the management model using the communication password, forming a one-to-one correspondence between the communication data and the data storage unit, and the specific steps are as follows: Mirror the response node data transmission characteristics to form a mirror file, select one mirror file, invalidate the database corresponding to the mirror file, generate an induction file, bring the induction file into the data area, form a one-to-one correspondence between the mirror file and the data area, form a mirror micro-element node based on the mirror file and the data area, return to select one mirror file until all mirror files are selected, select one data area, establish a mapping relationship between the data area and the virus detection program, return to select one data area until all data areas are selected; Bring the virus detection program into the management model, call the unified correlation analysis data of the management model, and judge whether the unified correlation analysis data of the management model reaches the uniformity threshold; If the unified correlation analysis data of the management model reaches the uniformity threshold, execute the security protection task based on the risk protection conclusion in the unified correlation analysis data; If the unified correlation analysis data of the management model does not reach the uniformity threshold, communicate all access devices with the security honeypot; A fine-grained micro-element node device management system is provided, comprising a server for executing a fine-grained micro-element node device management method, and a plurality of grid equipment each in communication connection with the server; Mirror the micro-element node to form a mirror micro-element node, and return to select one grid equipment until all grid equipment is selected; The mirroring of the micro-element node includes selecting one data area, establishing a mapping relationship between the data area and the virus detection program, returning to select one data area until all data areas are selected, and bringing the virus detection program into the management model; Bringing the virus detection program into the management model includes bringing each grid equipment into the management system through the management model, extracting the response nodes of the file library of the grid equipment, the response nodes of the database, the response nodes of the code management library, the response nodes of the account program, and the response nodes of the password program, completing the extraction of multi-source heterogeneous data, mirroring the multi-source heterogeneous data to form a mirror micro-element node, and forming a security honeypot based on all mirror micro-element nodes; Based on all mirror micro-element nodes to form a security honeypot, send the received data to the security honeypot, obtain the output result after the security honeypot analyzes, and execute the data interaction task based on the output result of the security honeypot.
2. The fine-grained micrornode device management method of claim 1, wherein: The management model includes receiving a list of power grid devices, selecting management data of one power grid device, abstracting core capabilities of the management data into functions, forming access features of the management model based on features of the functions, and returning the management data of the one power grid device until the management data of all power grid devices are selected. The selection of one power grid device includes dividing a security honeypot data storage area before each power grid device is included in the management model, dividing the security honeypot data storage area based on the access features to form a plurality of data areas, including the function features of each data area into a management function, and associating the management function with a Trojan analysis program.
3. The fine-grained micrornode device management method of claim 2, wherein: The data receiving and sending features of the response nodes of the power grid devices and the corresponding data storage units include extracting the response nodes of the file library of the power grid device, the response nodes of the database, the response nodes of the code management library, the response nodes of the account program, and the response nodes of the password program. The response nodes of the file library are parsed, and the response nodes include an identification unit and an access unit. The received data features of the identification unit and the sent data features of the access unit are extracted, and it is determined whether the received data features of the identification unit match the features of the functions. If the received data features of the identification unit match the features of the functions, the identification unit is included in the management model using the access features. If the received data features of the identification unit do not match the features of the functions, the difference between the received data features of the identification unit and the features of the functions is extracted. The application programming interface corresponding function is called, the difference is formed into a matching function, the identification unit is included in the management model using the access features based on the matching function, the received data features of the identification unit are replaced with the sent data features of the access unit, and it is determined whether the received data features of the identification unit match the features of the functions.
4. The fine granularity microcell node management method of claim 2 wherein: The received data is sent to the security honeypot, and the output result of the security honeypot analysis is obtained. Based on the output result of the security honeypot, a data interaction task is performed, a list of power grid devices is received, management data of one power grid device is selected, core capabilities of the management data are abstracted into functions, access features of a management model are formed based on features of the functions, and management data of one power grid device is returned until the management data of all power grid devices are selected.
5. The fine granularity microcell node management method of claim 4, wherein: Based on the output result of the security honeypot, a data interaction task is performed, a list of power grid devices is received, management data of one power grid device is selected, core capabilities of the management data are abstracted into functions, access features of a management model are formed based on features of the functions, and management data of one power grid device is returned until the management data of all power grid devices are selected. When receiving external interaction information, the security honeypot is the execution subject of the interaction information, the received data is sent to the security honeypot, the output result of the security honeypot analysis is obtained, and a data interaction task is performed based on the output result of the security honeypot.
6. A fine granularity micro node device management system based on the fine granularity micro node device management method of any of claims 1 to 5, characterized in that: The management model includes receiving a list of power grid devices, selecting management data of one power grid device, abstracting core capabilities of the management data into functions, forming access features of the management model based on features of the functions, and returning the management data of the one power grid device until the management data of all power grid devices are selected. The management model includes receiving a list of power grid devices, selecting management data of one power grid device, abstracting core capabilities of the management data into functions, forming access features of the management model based on features of the functions, and returning the management data of the one power grid device until the management data of all power grid devices are selected. The selecting module mirrors the micro-element node to form a mirror micro-element node, and returns to select one power grid device until all the power grid devices are selected; The management module forms a security honeypot based on all the mirror micro-element nodes, sends the received data to the security honeypot, obtains an output result after the security honeypot is analyzed, and performs a data interaction task based on the output result of the security honeypot. 7.A computer device, comprising a memory and a processor, the memory storing a computer program, and the computer device is characterized in that: The processor executes the computer program to implement the steps of the fine-grained micro-element node device management method of any one of claims 1-5.
8. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to implement the steps of the fine-grained micro-element node device management method of any one of claims 1-5.
Citation Information
Patent Citations
Honeypot defense method and system based on mimicry defense, equipment and medium
CN112187825A
Active defense method and system for novel power system
CN117240502A