Nuclear power plant cyber security event alarm method, device, storage medium and system

By acquiring and classifying network security alarm information from nuclear power control systems in nuclear power plants, generating alarm signals and prompts at different levels, the problem of the lack of centralized alarms in nuclear power plants is solved, and the efficiency of network security management and the accuracy of alarm processing are improved.

CN119694084BActive Publication Date: 2026-08-25CHINA NUCLEAR POWER ENGINEERING COMPANY LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411698219.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2026-08-25
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

Currently, nuclear power plants lack centralized alarm methods to handle cybersecurity incidents, which affects both cybersecurity and nuclear safety.

Method used

A method for alarming network security incidents in nuclear power plants is provided. This method acquires network security alarm information from multiple nuclear power control systems, classifies and aggregates it based on preset classification levels, and generates alarm signals and prompts of different levels until the operation signal is confirmed and the display stops.

Benefits of technology

It enables centralized alarm and processing of cybersecurity incidents in nuclear power plants, improves the level of cybersecurity management, ensures that operators can promptly detect and handle emergency alarm information, and reduces interference from invalid alarm prompts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119694084B_ABST
    Figure CN119694084B_ABST
Patent Text Reader

Abstract

The application discloses a nuclear power plant network security event alarm method and device, a storage medium and a system, relates to the nuclear safety technical field of nuclear power plants, and comprises the following steps: acquiring network security alarm information of a plurality of nuclear power control systems; classifying and collecting all the network security alarm information based on preset classification levels, wherein the classification levels comprise at least three; determining whether network security alarm information exists in each classification level, and if so, generating an alarm signal according to the network security alarm information in each classification level, displaying an alarm prompt corresponding to each classification level based on the alarm signal, and the network security alarm information in the same classification level corresponding to the same alarm prompt; and determining whether a confirmation operation signal is received, stopping the display of the alarm prompt if the confirmation operation signal is received or if the network security alarm information automatically disappears without receiving the confirmation operation signal. The application can realize alarm monitoring and processing of network security information of a nuclear power plant.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of nuclear safety technology for nuclear power plants, and in particular to a method, device, storage medium, and system for alarming network security incidents in nuclear power plants. Background Technology

[0002] The industrial control system (i.e., nuclear power control system) of a nuclear power plant is its nerve center, undertaking both automatic control of power production and core functions for nuclear safety. Currently, with the widespread application of information, digital, and intelligent technologies in the digital instrumentation and control systems of nuclear power plants, cybersecurity threats have arisen to the industrial control system, thus affecting the plant's cybersecurity and nuclear safety. Currently, there is no method for centralized alarm reporting of cybersecurity incidents to facilitate centralized handling by staff.

[0003] Therefore, how to achieve centralized alarm for cybersecurity incidents at nuclear power plants is an urgent problem that needs to be solved. Summary of the Invention

[0004] To address the current problem of the inability to centrally alarm network security incidents, this invention provides a method, device, storage medium, and system for alarming network security incidents in nuclear power plants.

[0005] The technical solution adopted by this invention to solve its technical problem is: to provide a method for alarming network security incidents in nuclear power plants, comprising:

[0006] Obtain network security alarm information from multiple nuclear power plant control systems;

[0007] Based on preset classification levels, all network security alarm information is classified and collected, with at least three classification levels;

[0008] Determine whether there are network security alarm messages in each category level. If so, generate alarm signals based on the network security alarm messages in each category level. Based on the alarm signals, display the alarm prompts corresponding to each category level. Network security alarm messages in the same category level correspond to the same alarm prompts.

[0009] Determine whether a confirmation signal has been received. If a confirmation signal has been received, stop displaying the alarm prompt. If no confirmation signal has been received and the network security alarm information disappears automatically, stop displaying the alarm prompt.

[0010] In one embodiment, the step of classifying and aggregating all network security alarm information based on a preset classification level includes:

[0011] Assess the extent of damage caused by network security alarm information to the nuclear power plant control system;

[0012] If the damage affects the nuclear safety protection function of the nuclear power control system or its important power production function, and there are no remedial measures, then the network security alarm information is classified as an emergency level information.

[0013] If the damage affects the nuclear safety protection function of the nuclear power control system or the important function of power production, but there are remedial measures, then the network security alarm information is classified as an important level information.

[0014] If the damage affects the nuclear safety protection function of the nuclear power control system and the general power production function, but does not affect the execution of nuclear safety protection of the nuclear power control system or the operation of power production control, then the network security alarm information is classified as a general level information.

[0015] In one embodiment, the alarm signals include general-level alarm signals, important-level alarm signals, and emergency-level alarm signals. The step of generating an alarm signal based on network security alarm information in each category level includes:

[0016] Generate a general-level alarm signal based on general-level information;

[0017] Generate alarm signals based on importance level information;

[0018] An emergency level alarm signal is generated based on the emergency level information.

[0019] In one embodiment, the alarm prompt includes a light prompt, wherein the light prompt includes multiple display colors, and different display colors correspond to different classification levels.

[0020] In one embodiment, after the step of generating an alarm signal based on network security alarm information in each classification level, the method further includes:

[0021] Each alarm signal corresponding to a classification level is output to the corresponding DO point via an independent signal line through the I / O system.

[0022] When an alarm signal is present at the DO point, the preset DCS HMI and ACP panel execute steps based on the alarm signal to display alarm prompts corresponding to each category level.

[0023] In one embodiment, the alarm prompts also include multiple audible alarm prompts, each audible alarm prompt corresponding to a specific light prompt.

[0024] In one embodiment, determining whether a confirmation operation signal has been received, and stopping the display of the alarm prompt if the confirmation operation signal is received, or stopping the display of the alarm prompt if the confirmation operation signal is not received and the network security alarm information automatically disappears, includes the following steps:

[0025] If a confirmation signal is received and a network security alarm is present, the alarm status will be changed.

[0026] If a confirmation signal is received and no network security alarm information is found, stop displaying alarm prompts;

[0027] If no confirmation signal is received and the network security alarm message disappears automatically, stop displaying alarm prompts.

[0028] In addition, the present invention also provides a device, which is a nuclear power plant network security incident alarm device, including a processor and a memory storing a computer program. When the processor executes the computer program, it implements the above-mentioned nuclear power plant network security incident alarm steps.

[0029] In addition, the present invention also provides a storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described nuclear power plant network security incident alarm method.

[0030] In addition, the present invention also provides a nuclear power plant network security incident alarm system, which is the aforementioned nuclear power plant network security incident alarm device.

[0031] In this invention, network security alarm information from multiple nuclear power plant control systems is acquired and aggregated, facilitating unified management and improving the overall network security management level of the nuclear power plant. Based on preset classification levels (at least three levels), all network security alarm information is categorized and collected. By dividing all network security alarm information according to different levels, accurate management of safety events at different levels is possible, ensuring hierarchical display of alarm information at each level, allowing operators to prioritize more urgent alarm information in the nuclear power plant control system. The system determines whether network security alarm information exists in each classification level. If so, an alarm signal is generated based on the network security alarm information in each classification level. Based on the alarm signal, the alarm prompt corresponding to each classification level is displayed (network security alarm information in the same classification level corresponds to the same alarm prompt). According to the classification level, the network security alarm information appearing in the nuclear power plant control systems of each nuclear power plant is displayed uniformly, allowing operators to intuitively identify network security problems in the nuclear power plant control system. The system determines whether a confirmation signal has been received. If a confirmation signal is received, it means that the operator has discovered and handled the network security alarm. At this point, the alarm notification stops being displayed. If no confirmation signal is received and the network security alarm automatically disappears, the alarm notification stops being displayed. The normalized display of alarm notifications facilitates the operator's handling of network security alarm information, thus realizing the alarm and handling of network security alarm events in nuclear power plants. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 This is a flowchart illustrating the first embodiment of the nuclear power plant network security incident alarm method of the present invention;

[0034] Figure 2 This is an event acquisition flowchart provided in the first embodiment of the nuclear power plant network security event alarm method of the present invention;

[0035] Figure 3 This is an alarm information classification diagram provided in the second embodiment of the nuclear power plant network security incident alarm method of the present invention;

[0036] Figure 4 This is a signal transmission diagram provided in the fourth embodiment of the nuclear power plant network security incident alarm method of the present invention. Detailed Implementation

[0037] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0038] This application provides a method for alarming network security incidents in nuclear power plants. (Refer to...) Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the nuclear power plant network security incident alarm method of this application.

[0039] In this embodiment, the data transmission method includes steps S10 to S40:

[0040] Step S10: Obtain network security alarm information from multiple nuclear power control systems;

[0041] It should be noted that each nuclear power plant's nuclear power control system is equipped with a network security alarm event collector, which acquires network security alarm information. After the network security alarm event collector acquires the information, it passes through a security isolation device before being centrally sent to the network security alarm event management platform. For example, the network security alarm event collector is similar to antivirus software on a computer, and the security isolation device is similar to a firewall on a computer.

[0042] Specifically, refer to Figure 2 There are n nuclear power plants and n nuclear power control systems, namely nuclear power control system 1, nuclear power control system 2, ..., nuclear power control system n. Each nuclear power control system in a nuclear power plant is equipped with a network security alarm event collector to collect network security alarm information from its corresponding nuclear power control system. This network security alarm information is then centrally transmitted to a single network security alarm event management platform via a security isolation device for each nuclear power control system. It should be noted that the purpose of the security isolation device is to prevent network connectivity between each nuclear power control system in the nuclear power plant when the network security alarm event collector transmits network security alarm information to the same network security alarm event management platform.

[0043] Step S20: Based on the preset classification levels, classify and collect all network security alarm information, wherein the classification levels include at least three.

[0044] It should be noted that the preset classification levels are artificially set based on the urgency of the alarm and the degree of damage to the nuclear power control system. The network security alarm event management platform classifies and collects all transmitted network security alarm information. In order to more accurately display the urgency of network security alarm information, the classification levels include at least three, rather than simply dividing them into two categories: urgent and non-urgent.

[0045] Specifically, network security alarm information from multiple nuclear power control systems in a nuclear power plant is centrally transmitted to a network security alarm event management platform via a security isolation device, where it is categorized.

[0046] Step S30: Determine whether there is network security alarm information in each category level. If so, generate an alarm signal based on the network security alarm information in each category level. Based on the alarm signal, display the alarm prompt corresponding to each category level. Network security alarm information in the same category level corresponds to the same alarm prompt.

[0047] It should be noted that the alarm signal can be an electrical signal, which can be implemented using digital or analog signals.

[0048] Specifically, for a certain category level, when network security alarm information exists in this category level, alarm signals for this category level will be continuously generated, continuously controlling the display of alarm prompts. When there is no network security alarm information in this category level, no alarm signal will be generated accordingly. It is determined whether there is network security alarm information in each category level. If there is, an electrical signal is generated based on the network security alarm information in each category level. The alarm prompts corresponding to each category level are controlled and displayed through the corresponding electrical signals.

[0049] Step S40: Determine whether a confirmation operation signal has been received. If the confirmation operation signal is received, stop displaying the alarm prompt. Or, if the confirmation operation signal is not received and the network security alarm information disappears automatically, stop displaying the alarm prompt.

[0050] It should be noted that the confirmation operation signal is input by the operator on the ACP panel or the DCS human-machine interface.

[0051] Specifically, when a confirmation signal is received, it indicates that the operator has processed the network security alarm information and the alarm prompt will stop being displayed. If no confirmation signal is received, but the network security alarm information disappears automatically, the alarm prompt will also stop being displayed. For example, if an alarm signal caused by a Trojan virus intrusion in the nuclear power control system of a nuclear power plant is not manually confirmed by the operator after the virus is removed, the nuclear power control system may determine through an automatic diagnostic mechanism (e.g., the virus removal program detects no abnormality or the system returns to normal) that the alarm information no longer needs to be displayed, and thus automatically stop the flashing of the alarm indicator light, cancel the alarm sound, and turn off the flashing icon on the DCS human-machine interface.

[0052] In one feasible implementation, the alarm prompt includes a light prompt, wherein the light prompt includes multiple display colors, and different display colors correspond to different classification levels.

[0053] In one feasible implementation, the alarm prompts also include multiple audible alarm prompts, each audible alarm prompt corresponding to a specific light prompt.

[0054] In this invention, network security alarm information from multiple nuclear power plant control systems is acquired and aggregated, facilitating unified management and improving the overall network security management level of the nuclear power plant. Based on preset classification levels (at least three levels), all network security alarm information is categorized and collected. By dividing all network security alarm information according to different levels, accurate management of safety events at different levels is possible, ensuring hierarchical display of alarm information at each level, allowing operators to prioritize more urgent alarm information in the nuclear power plant control system. The system determines whether network security alarm information exists in each classification level. If so, an alarm signal is generated based on the network security alarm information in each classification level. Based on the alarm signal, the alarm prompt corresponding to each classification level is displayed (network security alarm information in the same classification level corresponds to the same alarm prompt). According to the classification level, the network security alarm information appearing in the nuclear power plant control systems of each nuclear power plant is displayed uniformly, allowing operators to intuitively identify network security problems in the nuclear power plant control system. The system determines whether a confirmation signal has been received. If a confirmation signal is received, it means that the operator has discovered and handled the network security alarm. At this point, the alarm notification stops being displayed. If no confirmation signal is received and the network security alarm automatically disappears, the alarm notification stops being displayed. The normalized display of alarm notifications facilitates the operator's handling of network security alarm information, thus realizing the alarm and handling of network security alarm events in nuclear power plants.

[0055] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment can be referred to the above description, and will not be repeated hereafter. Based on this, refer to... Figure 3 Step S20, which involves classifying and collecting all network security alarm information based on preset classification levels, further includes steps S21 to S24:

[0056] Step S21: Determine the extent of damage caused by network security alarm information to the nuclear power control system;

[0057] Specifically, for each network security alarm, a thorough analysis is required to identify the attack source, possible attack paths, and the assets of the attacked nuclear power control system that may be affected. Based on the attacked assets, the system's functional execution capabilities affected by the attack, as well as the nuclear power control system's own response measures, must be analyzed to determine the extent of damage suffered by the nuclear power control system.

[0058] Step S22: If the damage level is such that it damages the nuclear safety protection function and important power production function of the nuclear power control system, and there are no remedial measures, then the network security alarm information is classified as an emergency level information.

[0059] It should be noted that nuclear safety protection functions refer to the critical control functions in a nuclear power plant used to ensure the safe shutdown of the nuclear reactor, prevent the release of radioactive materials, and protect the safety of on-site personnel and the public. Important power generation functions refer to the core control and operational functions that a nuclear power plant must possess to achieve safe and stable power generation. For example, the rapid insertion function of the reactor control rods is used to quickly stop the nuclear reaction in abnormal situations. If this function fails due to a cyberattack, it may lead to serious consequences such as core meltdown. Similarly, the automatic load regulation function of the generator set or the main steam pressure control function of the turbine. Failure of these functions may result in equipment damage or power outages.

[0060] Specifically, the extent of damage caused by cybersecurity alarm information to the nuclear power plant control system is determined. If the damage is to the safety protection function or the important functions of the plant's production and there are no remedial measures, then the cybersecurity alarm information is classified as an emergency level information.

[0061] Step S23: If the damage level is such that it damages the nuclear safety protection function and important power production function of the nuclear power control system but there are remedial measures, then the network security alarm information is classified as important information.

[0062] For example, a cyberattack may cause the main reactor cooling pump monitoring signal to be lost, but the backup cooling pump can be activated by backup sensors or manual operation to maintain the core cooling function.

[0063] Specifically, if the damage affects the nuclear safety protection function or important power production function of the nuclear power control system, but there are other remedial measures for certain equipment, such as directly controlling or replacing the equipment through buttons, control gates, backup equipment, etc., to ensure the normal operation of the equipment, then this network security alarm information is classified as an important level information.

[0064] Step S24: If the damage level is such that it damages the nuclear safety protection function and general power production function of the nuclear power control system but does not affect the execution of nuclear safety protection of the nuclear power control system or the operation of power production control, then the network security alarm information is classified as general level information.

[0065] It should be noted that general functions refer to some auxiliary systems, such as data acquisition systems, surveillance camera systems, and equipment health monitoring systems. They do not have a direct impact on nuclear safety protection, but they can improve the visibility and monitoring of the system.

[0066] In this embodiment, by classifying all network security alarm information from multiple nuclear power control systems into emergency level information, important level information, and general level information, it is ensured that operators can take timely and appropriate countermeasures in different network security threat scenarios during subsequent operations.

[0067] Based on the first and second embodiments of this application, in the third embodiment of this application, the content that is the same as or similar to the first or second embodiments described above can be referred to the above description and will not be repeated hereafter. In addition, the alarm signals include general-level alarm signals, important-level alarm signals, and emergency-level alarm signals. Step S30, which generates alarm signals based on network security alarm information in each classification level, further includes steps S31 to S33:

[0068] Step S31: Generate a general-level alarm signal based on the general-level information; Step S32: Generate an important-level alarm signal based on the important-level information; Step S33: Generate an emergency-level alarm signal based on the emergency-level information.

[0069] It should be noted that general alarm signals, important alarm signals, and emergency alarm signals are all control signals used to control the display and cessation of alarm prompts. These control signals can be digital signals (0 or 1) or logic signals (high level or low level). The three levels of alarm signals will be sent to different places. In addition, alarm signals are generated and output through I / O (input / output) systems or I / O devices.

[0070] Specifically, for general-level information, the I / O system will output an alarm signal to the corresponding alarm notification device; for important-level information, the I / O system will output an alarm signal to the alarm notification device corresponding to the important-level information; and for emergency-level information, the I / O system will similarly output an alarm signal to the alarm notification device corresponding to the emergency-level information.

[0071] Based on the first, second, and third embodiments of this application, in the fourth embodiment of this application, the content that is the same as or similar to the first, second, or third embodiments described above can be referred to the above description and will not be repeated hereafter. Furthermore, after step S30, which generates an alarm signal based on the network security alarm information in each classification level, steps S31 to S32 are also included:

[0072] Step S31: Output the alarm signal corresponding to each category level to the corresponding DO point through the I / O system with an independent signal line; Step S32: When there is an alarm signal at the DO point, execute the steps of displaying the alarm prompt corresponding to each category level based on the alarm signal on the preset DCS HMI and ACP panel.

[0073] It should be noted that the DO point is a data output point (logic quantity) used to control the start / stop, switching, and output strength of the equipment displaying alarm prompts. The DCS (Digital Control System, also known as the nuclear power control system of this invention) human-machine interface and ACP (Auxiliary control panel) are devices used to display alarm prompts and can also receive external input operations. The signal line refers to hard-wired wiring.

[0074] Additionally, it should be noted that through network communication, the DCS HMI will also display detailed information on network security alarms and their locations, making it easier for operators to view and handle them.

[0075] Specifically, network security alarm information corresponding to each category level is transmitted to the I / O system, which generates corresponding alarm signals. Then, through the I / O system, multiple hardwired connections are made to output the alarm signals corresponding to each category level to the corresponding DO points. The alarm signals output from the DO points control the DCS HMI and ACP panel to display the alarm prompts corresponding to each category level. In addition, the alarm signals output from the DO points also need to be connected to the DCS system's hardwired connections and equipment (such as switches) to be transmitted to the DCS HMI at the ACP panel.

[0076] Reference Figure 4In one feasible implementation, the emergency level information (orange) indicates that when the emergency level network security alarm information is transmitted to the I / O system, the network security alarm information is generated into an emergency level alarm signal through the I / O system. The I / O system is connected to a hardwire and the emergency level alarm signal is transmitted to the emergency level DO point through the hardwire. The alarm signal (e.g., high level (1)) is output through the emergency level DO point to the DCS HMI and ACP panel, controlling the orange icon of the DCS HMI to light up and emitting a continuous high-pitched alarm sound of 85dB to 110dB at the DCS host. It also controls an alarm light at the ACP panel to emit an orange light and emits a continuous high-pitched alarm sound of 85dB to 110dB at the ACP panel. The critical level information (yellow) indicates that when critical network security alarm information is transmitted to the I / O system, a critical level alarm signal is generated. This signal is hardwired to the critical level DO point. Similarly, the yellow icon on the DCS HMI illuminates, and an intermittent mid-tone alarm sound (75dB to 90dB) is emitted from the DCS host. Another alarm light on the ACP panel also illuminates yellow and emits a similar 75dB to 90dB intermittent mid-tone alarm sound. The general level information (white) indicates that when critical network security alarm information is transmitted to the I / O system, a general level alarm signal is generated. This signal is hardwired to the general level DO point. Similarly, the white icon on the DCS HMI illuminates, and a low-frequency intermittent alert sound (e.g., a "beep") (60dB to 75dB) is emitted from the DCS host. Another alarm light on the ACP panel illuminates white and emits a similar 60dB to 75dB intermittent mid-tone alarm sound.

[0077] In addition, network security alarm information at each category level will also be transmitted to the KSM (Plant-wide Industrial Control System Network Security Management Center) system.

[0078] In this embodiment, network security alarm information of different classification levels is converted into alarm signals and the corresponding alarm prompts are displayed on the same DCS human-machine interface and ACP panel. This unified display method makes it easier for operators to quickly process network security alarm information.

[0079] Based on the first, second, third, and fourth embodiments of this application, in the fifth embodiment of this application, the content that is the same as or similar to the first, second, third, or fourth embodiments described above can be referred to the above description and will not be repeated hereafter. Based on this, step S40 determines whether a confirmation operation signal is received. If the confirmation operation signal is received, the alarm prompt is stopped from being displayed; or if the confirmation operation signal is not received and the network security alarm information automatically disappears, the step of stopping the display of the alarm prompt further includes steps S41 to S43:

[0080] Step S41: If a confirmation operation signal is received and network security alarm information exists, change the alarm prompt status; Step S42: If a confirmation operation signal is received and network security alarm information does not exist, stop displaying the alarm prompt; Step S43: If no confirmation operation signal is received and network security alarm information disappears automatically, stop displaying the alarm prompt.

[0081] It should be noted that both the DCS HMI and the ACP panel can receive confirmation operations, and the two are synchronized. Confirmation operations received on the DCS HMI or the ACP panel will synchronously affect the other party.

[0082] Specifically, when an alarm signal is output, the alarm icon on the DCS HMI will flash, and the DCS system host will emit an audible sound. The ACP panel, equipped with alarm indicator lights corresponding to each category level, will also flash and emit an audible sound. If the operator confirms the alarm, the DCS HMI or ACP panel receives the confirmation signal, but the alarm source persists, the alarm indicator light will illuminate but not flash, and no sound will be emitted. The icon on the DCS HMI will illuminate but not flash, and the alarm sound will disappear. If the operator confirms the alarm, the DCS HMI or ACP panel receives the confirmation signal, and the alarm source disappears, the alarm indicator light will not illuminate, no sound will be emitted, the icon on the DCS HMI will not illuminate, and the alarm sound will disappear. If the alarm source disappears, but the operator has not confirmed the alarm, and the DCS HMI or ACP panel has not received a confirmation signal, the alarm indicator light will not flash, the icon on the DCS HMI will flash less frequently, and the alarm sound will disappear.

[0083] In this embodiment, by receiving confirmation operation signals and eliminating corresponding network security alarm information, the system ensures timely operator response and alarm confirmation, thereby reducing unnecessary alarm prompts and sound interference and improving the efficiency and accuracy of alarm handling. By simultaneously displaying the confirmation operation on the DCS human-machine interface and the ACP panel, after the operator confirms on either interface, the alarm indicator light and icon will stop flashing, and the alarm sound will disappear, avoiding repeated alarm interference. Simultaneously, determining whether network security alarm information exists in each category level and deciding whether to continue outputting alarm signals or stop displaying alarm prompts based on the presence of alarm signals ensures that alarm prompts remain valid while the alarm source persists and that alarm prompts are promptly stopped after the alarm source disappears. If the alarm source still exists, the system continues to output alarm signals and display alarm prompts; if the alarm source has disappeared, the system stops outputting alarm signals and turns off alarm prompts, avoiding interference from invalid alarm prompts and optimizing the alarm management process. Based on the alarm confirmation and status change processing flow, the alarm response efficiency of nuclear power plants is improved, while ensuring efficient operator response.

[0084] In conjunction with one or more of the above embodiments, for example, two nuclear power control systems (i.e., the nuclear power plant industrial control systems) of a nuclear power plant are invaded by a Trojan virus, causing the nuclear power control systems to be unable to control the reactor cooling system. The network security alarm event collector collects this network security alarm information, and after passing through a security isolation device, sends the network security alarm information to the network security alarm event management platform. According to the classification level, the network security alarm information is classified as important information in the network security alarm event management platform, and an important level alarm signal is generated in the I / O system. The important level alarm signal is transmitted to the important level DO point through a hard-wired connection. The alarm signal of the important level DO point controls an alarm indicator light on the ACP panel to emit a 2Hz yellow flashing light, and at the same time emits an intermittent mid-tone alarm sound of 75dB to 90dB. The alarm signal of the important level DO point controls the DCS human-machine interface to display a yellow flashing icon, and emits an intermittent mid-tone alarm sound of 75dB to 90dB at the DCS system host. A few minutes later, the operator controlled the reactor cooling system via buttons or controllers and cleared the Trojan virus from the two nuclear power control systems. The network security alarm disappeared, but no operator performed an alarm confirmation operation. Neither the DCS HMI nor the ACP panel received a confirmation operation signal. The alarm indicator flashing frequency changed to 0.5Hz and stopped emitting sound. At the same time, the flashing frequency of the icons on the DCS HMI also decreased, and the DCS system host did not emit an alarm sound. When the operator arrived at the main control room, they performed an alarm confirmation operation on the DCS HMI. The DCS HMI received the confirmation operation signal, the alarm disappeared, the alarm indicator stopped flashing and stopped emitting an alarm sound, the icons on the DCS HMI stopped illuminating, and the DCS system host stopped emitting sound.

[0085] Finally, it should be noted that the steps in the method of the embodiments of the present invention can be adjusted, combined, or deleted according to actual needs.

[0086] In addition, the present invention also provides a nuclear power plant network security incident alarm device, including a processor and a memory storing a computer program, wherein the processor implements the above-mentioned nuclear power plant network security incident alarm steps when executing the computer program.

[0087] The nuclear power plant network security incident alarm device provided in this application, employing the nuclear power plant network security incident alarm method in the above embodiments, can solve the technical problem of alarm monitoring and processing of nuclear power plant network security. Compared with the prior art, the beneficial effects of the intelligent device provided in this application are the same as those of the nuclear power plant network security incident alarm method provided in the above embodiments, and other technical features of this nuclear power plant network security incident alarm device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0088] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the nuclear power plant network security incident alarm method described above.

[0089] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing device-related hardware. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0090] In addition, the present invention also provides a nuclear power plant network security incident alarm system, which is the aforementioned nuclear power plant network security incident alarm device.

[0091] The nuclear power plant network security incident alarm method provided in this application can solve the technical problem of alarm monitoring and processing of nuclear power plant network security. Compared with the prior art, the beneficial effects of the nuclear power plant network security incident alarm system provided in this application are the same as the beneficial effects of the nuclear power plant network security incident alarm method provided in the above embodiments, and will not be repeated here.

[0092] Furthermore, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be accomplished by functional modules in the device, and will not be elaborated upon here.

[0093] The above-disclosed embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of the invention. Those skilled in the art will understand that all or part of the processes for implementing the above embodiments, and equivalent variations made in accordance with the claims of the present invention, still fall within the scope of the invention.

Claims

1. A method for alarming network security incidents in nuclear power plants, characterized in that, The nuclear power plant network security incident alarm method includes: Step S10: Obtain network security alarm information from multiple nuclear power control systems; Step S20: Based on preset classification levels, classify and aggregate all the network security alarm information, wherein the classification levels include at least three; this step includes: Step S21: Determine the extent of damage caused by the network security alarm information to the nuclear power control system; Step S22: If the degree of damage is such that it damages the nuclear safety protection function and important power production function of the nuclear power control system, and there are no remedial measures, then the classification level of the network security alarm information is emergency level information; Step S23: If the degree of damage is such that it damages the nuclear safety protection function and the important power production function of the nuclear power control system but there are remedial measures, then the classification level of the network security alarm information is important level information; Step S24: If the degree of damage is such that it damages the nuclear safety protection function and the general power production function of the nuclear power control system but does not affect the execution of the nuclear safety protection function or the operation of the power production control, then the classification level of the network security alarm information is general level information. Step S30: Determine whether the network security alarm information exists in each of the classification levels. If it exists, generate an alarm signal based on the network security alarm information in each of the classification levels. The alarm signal is continuously generated to continuously control the display of alarm prompts. Based on the alarm signal, display the alarm prompts corresponding to each of the classification levels respectively. The alarm prompts are displayed in a normalized manner, and the network security alarm information of the same classification level corresponds to the same alarm prompt. Then, the network security alarm information for each of the aforementioned classification levels is transmitted to the plant-wide industrial control system network security management center; Step S40: Determine whether a confirmation operation signal has been received. If the confirmation operation signal is received, stop displaying the alarm prompt. Or, if the confirmation operation signal is not received and the network security alarm information disappears automatically, stop displaying the alarm prompt.

2. The nuclear power plant network security incident alarm method as described in claim 1, characterized in that, The alarm signals include general-level alarm signals, important-level alarm signals, and emergency-level alarm signals. The step of generating an alarm signal based on the network security alarm information in each of the classification levels includes: Generate the general level alarm signal based on the general level information; Generate an alarm signal based on the importance level information; An emergency level alarm signal is generated based on the emergency level information.

3. The nuclear power plant network security incident alarm method as described in claim 1, characterized in that, The alarm prompts include light prompts, wherein the light prompts include multiple display colors, and different display colors correspond to different classification levels.

4. The nuclear power plant network security incident alarm method as described in claim 1, characterized in that, In step S30, after the step of generating an alarm signal based on the network security alarm information in each of the classification levels, the method further includes: Each alarm signal corresponding to each classification level is output to the corresponding DO point via an independent signal line through the I / O system. When the alarm signal exists at the DO point, the steps of displaying alarm prompts corresponding to each of the classification levels are performed on the preset DCS HMI and ACP panel based on the alarm signal.

5. The nuclear power plant network security incident alarm method as described in claim 3, characterized in that, The alarm prompts also include multiple sound alarm prompts, each of which corresponds to a light prompt.

6. The nuclear power plant network security incident alarm method as described in claim 1, characterized in that, Step S40 further includes: If the confirmation signal is received and the network security alarm information exists, then the alarm notification status is changed; If the confirmation signal is received and the network security alarm information does not exist, stop displaying the alarm prompt. If the confirmation signal is not received and the network security alarm information disappears automatically, the alarm prompt will stop being displayed.

7. A network security incident alarm device for a nuclear power plant, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the nuclear power plant network security incident alarm method according to any one of claims 1-6.

8. A storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the nuclear power plant network security incident alarm method according to any one of claims 1-6.

9. A network security incident alarm system for nuclear power plants, characterized in that, The nuclear power plant network security incident alarm system includes the nuclear power plant network security incident alarm device as described in claim 7.

Citation Information

Patent Citations

  • Network security event level classification method, device, equipment and medium

    CN115766068A

  • Network security early warning system and early warning method

    CN115766235A