Dynamic Verification Method and System for Security and Effectiveness of Complex Network Systems
By adopting a hierarchical distributed effective verification network in complex network systems, forward attack verification and backward sharing are carried out, the problems of single point of failure and lack of dynamic evaluation in the existing technology are solved, and systematic improvement and adaptability enhancement of security and effectiveness verification of complex network systems are achieved.
Patent Information
- Application Number
- CN202510412857.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-03
AI Technical Summary
The existing complex network system verification technology has a single point of failure risk and lacks a dynamic evaluation mechanism, which is difficult to meet the security and effectiveness requirements of complex and changeable network environments.
A layered distributed effective verification network is adopted, including a distributed security verification layer and a distributed functional verification layer. The node network and parameter set to be verified are obtained through the verification decomposition model, forward attack verification package is built, forward verification attacks are carried out, and forward verification attacks are carried out and backward sharing is carried out to ensure the real-time and reliability of the system.
It effectively avoids single point of failure, improves system reliability, realizes comprehensive and dynamic security and effectiveness verification of complex network systems, and adapts to complex and changeable network environments.
Smart Images

Figure CN119922019B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security verification, and particularly relates to a dynamic verification method and system for the security and effectiveness of complex network systems. Background Art
[0002] In the field of industrial control, the industrial control systems in industries such as electric power, petrochemical, and automobile manufacturing have extremely high requirements for real-time performance and reliability. In the complex network systems in the above fields, with the continuous expansion of the generation scale and the corresponding network scale and the increasing complexity of application scenarios, ensuring the security and effectiveness of the system has become a crucial issue; there are many deficiencies in the existing verification technologies for complex network systems. On the one hand, most traditional verification methods adopt a centralized architecture. When facing large-scale complex networks, centralized verification is prone to single-point failures, and the security verification of a single node cannot capture cross-node associated attacks, making it difficult to meet the requirements of real-time performance and security. On the other hand, for the security and effectiveness verification of nodes in a network system, there is often a lack of a comprehensive and dynamic evaluation mechanism, which only focuses on the verification of some parameters or specific scenarios and cannot adapt to the complex and changeable network environment.
[0003] For example, the effectiveness verification method and system of a threshold proxy re-encryption collaborative network disclosed in a Chinese patent with the authorization announcement number of CN116112284B generates relevant public verification parameters through the cooperation of a threshold encryption fragment generator and a data proxy, and the effectiveness verifier completes the effectiveness verification of the threshold proxy re-encryption collaborative network based on these parameters. However, from the architecture perspective, it is not clearly mentioned whether it can solve the single-point failure problem existing in the traditional centralized architecture. If the threshold encryption fragment generator or other key parts fail during the verification process, it may affect the effectiveness verification of the entire network and it is difficult to guarantee the real-time performance and reliability of the system. Secondly, in terms of the verification mechanism, it only focuses on the effectiveness verification of the threshold proxy re-encryption collaborative network, and there is a lack of a comprehensive evaluation for the security and effectiveness verification of nodes in the network system. It does not fully consider various associations between nodes and possible cross-node associated attacks in a complex network environment and cannot fully meet the requirements of security and effectiveness verification in the complex and changeable network environment in the industrial control field. Summary of the Invention
[0004] In view of the deficiencies of the prior art, the present invention proposes a dynamic verification method and system for the security and effectiveness of complex network systems. First, a hierarchical distributed effective verification network composed of a distributed security verification layer and a distributed functional verification layer is configured according to the attributes of the complex network system. Secondly, the parameters of the complex network system to be verified and updated are obtained, and through the built-in verification decomposition model, a continuous network of nodes to be verified and the first set of security parameters to be verified and the first set of functional parameters to be verified for each node are obtained. Then, according to the node parameters and the attributes of the connection relationship, a forward attack verification packet is constructed to perform a forward verification attack on the nodes and the data transmission chain, and the effectiveness of the parameters is judged. If it is effective, the verification continues until all nodes are completed. If it is invalid, the parameters to be verified are invalidated. Through the hierarchical distributed architecture, the present invention effectively avoids single-point failures and improves the reliability of the system.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A dynamic verification method for the security and effectiveness of a complex network system, including:
[0007] Configuring a hierarchical distributed effective verification network based on the attributes of the complex network system, where the hierarchical distributed effective verification network includes a distributed security verification layer and a distributed functional verification layer;
[0008] Obtaining the parameters of the complex network system to be verified and updated, and through the built-in verification decomposition model, obtaining a continuous network of nodes to be verified and the first set of security parameters to be verified and the first set of functional parameters to be verified corresponding to each node;
[0009] Based on the first set of security parameters to be verified, the first set of functional parameters to be verified, and the connection relationship attributes corresponding to two consecutive nodes in the continuous network of nodes to be verified, constructing a forward attack verification packet corresponding to each node to be verified and embedding it into the hierarchical distributed effective verification network;
[0010] Using the hierarchical distributed effective verification network to perform a forward verification attack on any node in the continuous network of nodes to be verified and the corresponding data transmission chain, and determining whether the first set of security parameters to be verified and the first set of functional parameters to be verified corresponding to each attacked node are effective;
[0011] If it is effective, continue the verification and share the attack type corresponding to the previous node in the continuous network of nodes to be verified backward until all nodes to be verified are completed. If it is invalid, the parameters of the complex network system to be verified and updated are invalidated.
[0012] Specifically, the corresponding distributed structures of the distributed security verification layer and the distributed functional verification layer are the same;
[0013] The number of security attack verification nodes in the distributed security verification layer is the same as and corresponds one-to-one to the number of nodes to be verified in the first-level continuous subnet of nodes to be verified in the continuous network of nodes to be verified;
[0014] The number of function attack verification nodes in the distributed function verification layer is the same as and corresponds one-to-one to the number of to-be-verified function sub-nodes in the secondary functional to-be-verified subnet in the continuous to-be-verified node network;
[0015] Each to-be-verified node contains M to-be-verified function sub-nodes;
[0016] The distributed security verification layer is used to perform attack verification on the data encryption strength and access control process corresponding to each to-be-verified node and the connection relationship between nodes in the continuous to-be-verified node network;
[0017] The distributed function verification layer is used to perform attack verification on the delay tolerance, load balancing, and node control standard parameters corresponding to each to-be-verified function sub-node and the connection relationship between sub-nodes in the secondary functional to-be-verified subnet.
[0018] Specifically, the steps for constructing the continuous to-be-verified node network include:
[0019] According to the parameters of the to-be-verified updated complex network system, obtain the information of each key function control point in the complex network system and the data transmission relationship information between key function control points;
[0020] Each of the key function control points corresponds one-to-one to the to-be-verified nodes in the primary continuous to-be-verified node subnet;
[0021] According to the information of each key function control point, perform secondary decomposition to obtain the set of sub-function control points corresponding to each key function control point, the data transmission relationship within the set of sub-function control points, and the data transmission relationship between the corresponding sets of sub-function control points between key function control points;
[0022] According to the set of sub-function control points corresponding to each key function control point, the data transmission relationship within the set of sub-function control points, and the data transmission relationship between the corresponding sets of sub-function control points between key function control points, perform clustering through an adaptive clustering algorithm to obtain sets of sub-function control points with the same function and mark the key function control point labels.
[0023] Specifically, the steps for constructing the continuous to-be-verified node network further include:
[0024] According to the number of key function control points and the data transmission relationship information between key function control points, construct the primary continuous to-be-verified node subnet through a topology algorithm and mark the data transmission direction on the connection relationship between nodes in the primary continuous to-be-verified node subnet;
[0025] According to the information of each key function control point in the level - continuous to - be - verified node subnet, through the function requirement analysis model, obtain the extensible function information of each key function control point and the corresponding required resources and memory;
[0026] According to the extensible function information of each corresponding key function control point and the corresponding required resources and memory, reserve the corresponding required resources and memory. When the system is updated, according to the update requirements and the reserved required resources and memory, mount the lower - level sub - function control points and allocate resources and memory at each corresponding key function control point.
[0027] Specifically, the construction steps of the continuous to - be - verified node network further include:
[0028] According to the set of sub - function control points corresponding to each key function control point and the data transmission relationship within the set of sub - function control points, obtain the secondary - area functional to - be - verified subnet corresponding to the set of to - be - verified function sub - nodes under each first - level continuous to - be - verified node;
[0029] Construct a set of directed connection relationships between the corresponding to - be - verified function sub - nodes among all the secondary - area functional to - be - verified subnets according to the data transmission relationship of the corresponding set of sub - function control points between key function control points;
[0030] Based on the set of directed connection relationships and all the secondary - area functional to - be - verified subnets, obtain the secondary - functional to - be - verified subnet.
[0031] Specifically, the forward - attack verification packet corresponding to each to - be - verified node consists of a security - attack verification sub - packet and a functional - attack verification sub - packet;
[0032] Specifically, the construction steps of the distributed security verification layer and the distributed function verification layer include:
[0033] Based on the number and connection relationship of the to - be - verified nodes in the first - level continuous to - be - verified node subnet, construct a distributed security verification node subnet with the same structure;
[0034] Based on the data transmission direction in the first - level continuous to - be - verified node subnet, construct an initial security - attack verification node and configure the security - attack verification sub - packet into the initial security - attack verification node;
[0035] Based on the secondary - functional to - be - verified subnet and the corresponding data transmission direction, construct a distributed function verification subnet and mark the verification order of each node in the distributed function verification subnet according to the data transmission direction;
[0036] At the same time, according to the verification order of each node in the distributed function verification subnet, configure the functional - attack verification sub - packet into each function - attack verification node in the initial - area function - attack verification subnet in the distributed function verification subnet;
[0037] Specifically, the distributed function verification subnet is composed of regional function attack verification subnets, and the structure and number of nodes of the regional function attack verification subnets are the same as those of the secondary regional functional subnets to be verified;
[0038] Configure a distributed synchronous verification evaluation control model, and build the distributed synchronous verification evaluation control model into the distributed security verification node subnet, the distributed function verification subnet, and the continuous subnet to be verified, perform synchronous verification evaluation control, and obtain the verification evaluation results corresponding to the continuous subnet to be verified.
[0039] Specifically, the distributed synchronous verification evaluation control model includes a distributed pass control submodel, a distributed evaluation parameter submodel, and a differential backward sharing submodel;
[0040] The distributed pass control submodel is used to control the synchronization of the corresponding security attack verification nodes and function attack verification nodes in the distributed security verification layer and the distributed function verification layer, and share the security attack verification sub-packets of the security attack verification nodes corresponding to the high-risk subnets to be verified according to the direction of the connection relationship in the distributed security verification node subnet to the next security attack verification node.
[0041] Specifically, the high-risk subnets to be verified are obtained by combining the preset danger evaluation interval levels through the distributed evaluation parameter submodel according to the first security parameter to be verified and the first function parameter to be verified corresponding to each synchronized attacked subnet to be verified and the corresponding M function subnets to be verified.
[0042] At the same time, share the effective attack parameters of the function attack verification nodes corresponding to the high-risk function subnets to be verified to the next function attack verification node corresponding to the set of sub-function control points with the same function obtained according to the clustering algorithm and the direction of the connection relationship in the distributed function verification subnet.
[0043] Specifically, the distributed evaluation parameter submodel is used to evaluate the first security parameter to be verified and the first function parameter to be verified corresponding to each synchronized attacked subnet to be verified and the corresponding M function subnets to be verified, and combine the preset danger evaluation interval levels to obtain the attack danger scores, corresponding danger levels, and effectiveness evaluation scores of the subnets to be verified and the corresponding M function subnets to be verified.
[0044] Specifically, for the differential backward sharing sub-model, according to the direction of the connection relationship in the continuous node network to be verified and the attack type parameters of the currently attacked node to be verified and the function sub-nodes to be verified, it performs sharing judgment backward on the nodes to be verified and the function sub-nodes to be verified in the same data transmission chain. If the corresponding node to be verified or function sub-node to be verified contains the same attack type parameter, sharing is not performed; if not, attack type parameter sharing is carried out.
[0045] Specifically, the steps for performing synchronous verification evaluation control to obtain the verification evaluation results corresponding to the continuous node network to be verified include:
[0046] Attack the initial nodes to be verified in the continuous node network to be verified and the directed connection relationship between the initial nodes to be verified and the second nodes to be verified according to the initial security attack verification nodes;
[0047] At the same time, through the distributed control sub-model, control the initial regional function attack verification subnet corresponding to the initial security attack verification nodes to attack the initial secondary regional functional subnet to be verified and the directed connection relationship between the initial secondary regional functional subnet to be verified and the second secondary regional functional subnet to be verified;
[0048] The initial secondary regional functional subnet to be verified corresponds to the initial nodes to be verified;
[0049] Obtain the first security verification parameters and the first function verification parameters after the initial nodes to be verified and the corresponding connection relationships and the initial secondary regional functional subnets to be verified and the corresponding directed connection relationships are attacked, and perform label marking on the corresponding nodes to be verified and function sub-nodes to be verified, and construct an initial attack parameter set;
[0050] Input the constructed initial attack parameter set into the distributed evaluation parameter sub-model to evaluate each function sub-node to be verified in the initial nodes to be verified and the initial secondary regional functional subnets to be verified, and obtain the corresponding danger level and effectiveness evaluation score for each function sub-node to be verified in the initial nodes to be verified and the initial secondary regional functional subnets to be verified.
[0051] Specifically, the steps for performing synchronous verification evaluation control to obtain the verification evaluation results corresponding to the continuous node network to be verified further include:
[0052] Construct an effectiveness evaluation threshold with the scoring value corresponding to the lower limit of the high-risk level interval within a preset danger evaluation interval. If the effectiveness evaluation score corresponding to any function sub-node to be verified in the initial nodes to be verified or the initial secondary regional functional subnets to be verified is greater than or equal to the effectiveness evaluation threshold, it is determined that the parameters of the complex network system to be verified for update are invalid;
[0053] If the validity evaluation scores corresponding to all the to-be-verified functional sub-nodes in the initial to-be-verified node and the initial secondary area functional to-be-verified subnet are less than the validity evaluation threshold, it is determined that the initial to-be-verified node and all the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet are valid;
[0054] After determining that the initial to-be-verified node and all the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet are valid, perform a backward sharing propagation judgment of attack parameters according to the risk levels corresponding to the initial to-be-verified node and all the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet.
[0055] Specifically, the steps of performing synchronous verification evaluation control to obtain the verification evaluation results corresponding to the continuous to-be-verified node network further include:
[0056] If the initial to-be-verified node is of high risk level or any of the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet is of high risk level, then, according to the direction of the connection relationship in the distributed security verification node subnet, share the security attack verification sub-packet corresponding to the initial security attack verification node with the next security attack verification node through the distributed passing control sub-model;
[0057] At the same time, share the functional attack verification sub-packet in the functional attack verification node corresponding to the high-risk to-be-verified functional sub-node in the initial secondary area functional to-be-verified subnet with the next functional attack verification node corresponding to the connection relationship direction in the distributed functional verification subnet according to the clustering algorithm for the obtained set of sub-functional control points with the same function;
[0058] If neither the initial to-be-verified node nor any of the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet is of high risk level, do not perform backward sharing of the attack verification sub-packet for the security attack verification node and the functional attack verification node;
[0059] At the same time, through the differential backward sharing sub-model, perform backward sharing of the attack type parameters corresponding to the initial to-be-verified node and all the to-be-verified functional sub-nodes in the corresponding initial secondary area functional to-be-verified subnet according to the connection relationship direction corresponding to the data transmission in the continuous to-be-verified node network.
[0060] Specifically, the steps of performing synchronous verification evaluation control to obtain the verification evaluation results corresponding to the continuous to-be-verified node network further include:
[0061] According to the connection relationship direction corresponding to data transmission in the continuous node network to be verified, repeat the attack process on the initial node to be verified and all the function sub-nodes to be verified in the initial secondary area functional subnet to be verified, and attack each subsequent node to be verified in the continuous node network to be verified and all the function sub-nodes to be verified in the corresponding secondary area functional subnet to be verified;
[0062] At the same time, according to the security attack verification node and the area function attack verification subnet corresponding to each node to be verified and the corresponding secondary area functional subnet to be verified, perform a forward verification attack on the verification nodes in the forward order and their corresponding connection relationships and the function sub-nodes to be verified and their corresponding connection relationships in the corresponding secondary area functional subnet on the data transmission chain where the current node to be verified and the corresponding secondary area functional subnet to be verified are located;
[0063] Judge the danger level and effectiveness evaluation score after the attack on each of the above nodes to be verified and the corresponding secondary area functional subnet to be verified. If the effectiveness evaluation score corresponding to the node to be verified and the corresponding secondary area functional subnet to be verified is greater than or equal to the effectiveness evaluation threshold, it is determined that the parameter update of the complex network system to be verified fails;
[0064] Otherwise, continue the verification and backward share the attack type parameters corresponding to all the function sub-nodes to be verified in each node to be verified and the corresponding secondary area functional subnet according to the connection relationship direction corresponding to data transmission in the continuous node network to be verified until all the nodes to be verified are verified.
[0065] A dynamic verification system for the security and effectiveness of a complex network system, including: a verification network module, a parameter analysis module, and an attack verification module;
[0066] The verification network module configures a hierarchical distributed effective verification network based on the attributes of the complex network system. The hierarchical distributed effective verification network includes a distributed security verification layer and a distributed function verification layer;
[0067] The parameter analysis module is used to obtain the parameters of the complex network system to be verified and updated, and through the built-in verification decomposition model, obtain the first security parameter set to be verified and the first function parameter set to be verified for the continuous node network to be verified and each node;
[0068] The attack verification module includes an attack construction unit and an attack verification unit;
[0069] The attack construction unit constructs a forward attack verification packet corresponding to each node to be verified based on the first security parameter to be verified, the first function parameter to be verified, and the connection relationship attributes corresponding to two consecutive nodes in the continuous node network to be verified, and builds it into the hierarchical distributed effective verification network;
[0070] The attack verification unit uses the hierarchical distributed effective verification network to perform a forward verification attack on any node in the continuous node network to be verified and the corresponding data transmission chain, and determines whether the first security parameter to be verified and the first function parameter to be verified corresponding to each attacked node are valid; if valid, continue to verify and share the attack type corresponding to the previous node in the continuous node network to be verified backward until the verification of all nodes to be verified is completed; if invalid, the updated complex network system parameters to be verified are invalid.
[0071] Compared with the prior art, the present invention has the following beneficial effects:
[0072] In view of the deficiencies of the prior art, the present invention constructs a three-in-one collaborative mechanism of "dynamic defense-correlation analysis-active verification" through a hierarchical distributed effective verification network, thereby achieving a systematic improvement in the verification efficiency of complex networks. In particular, through the decoupled collaboration of the distributed security verification layer and the distributed functional verification layer, a double protection barrier of security parameter verification and network parameter validity evaluation is formed while avoiding single point failures. The chain attack verification mechanism of the node-level verification package enables the cross-node attack path to be dynamically tracked, solving the problem of the separation of local protection and global security in traditional verification. Secondly, based on the parameter decoupling technology of the verification decomposition model, security verification (such as encryption strength, access control) and validity verification (such as delay tolerance, load balancing, node control standard parameters) are dynamically correlated and analyzed. Combined with the spatiotemporal modeling of connection relationship attributes, the coupling risk of parameter anomalies and topological evolution can be accurately identified, further improving the coverage of verification indicators.
[0073] The present invention also transforms traditional passive response into attack path preview verification through the active injection mechanism of forward attack verification packages and the backward attack sharing mechanism. This strategy of promoting defense through attack, combined with the recursive verification logic of the continuous node network, can expose the vulnerable links of multiple attack chains in advance and further improve the recognition speed of new compound attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] Figure 1 This is a flow chart of a dynamic verification method for security effectiveness of a complex network system according to Embodiment 1 of the present invention;
[0075] Figure 2 This is a module diagram of a dynamic verification system for the security and effectiveness of a complex network system according to Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0076] Example 1
[0077] In the field of industrial control, the industrial control systems in industries such as power, petrochemical, and automotive manufacturing have extremely high requirements for real-time performance and reliability. In the complex network systems in the above fields, as the scale of generation and the corresponding network scale continue to expand and the application scenarios become increasingly complex, and each control process corresponding to the generation step is extremely delicate and complex, but the corresponding complex network system is more vulnerable to attacks during updates, resulting in system failures and irreparable losses. To solve the above problems, refer to Figure 1 , an embodiment provided by the present invention: a dynamic verification method for the security and effectiveness of a complex network system, the steps including:
[0078] S1. Configure a hierarchical distributed effective verification network based on the complex network system attributes, and the hierarchical distributed effective verification network includes a distributed security verification layer and a distributed function verification layer;
[0079] Furthermore, in this embodiment, the complex network system attributes are used to obtain specific domain attribute parameters according to the corresponding field, and a hierarchical distributed effective verification network is constructed. For example, in the power field, it correspondingly includes: equipment parameters, operation parameters, communication parameters, etc.;
[0080] Among them, the equipment parameters include:
[0081] Power generation equipment: rated power, rated voltage, rated current, power factor, rotor speed, excitation current, etc. of the generator. These parameters determine the power generation capacity and operation characteristics of the generator. When the complex network system is updated, the change of its parameters may affect the stable supply of power. For example, the increase in the rated power of the generator may change the power balance of the power grid, and it is necessary to verify the load balancing ability of relevant nodes.
[0082] Power transmission equipment: electrical parameters such as resistance, reactance, capacitance, and conductance of the transmission line, as well as physical parameters such as line length, tower height, and conductor type. Resistance and reactance affect the power loss and voltage drop during power transmission, while capacitance and conductance are related to the charging power and leakage current of the line. For example, the change of the resistance of the transmission line may affect the transmission efficiency of the line, and it is necessary to verify the data encryption intensity to prevent the parameters from being maliciously tampered with.
[0083] Power transformation equipment: rated capacity, transformation ratio, short-circuit impedance, no-load loss, load loss, etc. of the transformer. The transformation ratio determines the ratio of voltage transformation, and the short-circuit impedance affects the short-circuit current and voltage fluctuation of the transformer. When the parameters of the transformer change, it is necessary to verify its impact on the operation of the power grid and whether the access control process is secure.
[0084] The operation parameters include:
[0085] Voltage parameters: The voltage amplitudes and phase angles of each node in the power grid. The stability of the voltage amplitude is crucial for ensuring the normal operation of power equipment, while the phase angle difference affects the direction and magnitude of power transmission. When updating a complex network system, the access of new equipment or the adjustment of lines may cause voltage fluctuations, and it is necessary to verify the delay tolerance of the connection relationship between nodes to ensure the timeliness of voltage stability control.
[0086] Current parameters: The magnitudes and phases of the currents in each line. The current magnitude reflects the load condition of the line, and the phase is related to the power factor. When the current exceeds the rated current of the line, problems such as overheating of the line may occur, and it is necessary to verify the load balancing mechanism to reasonably distribute the current.
[0087] Power parameters: The distribution of active power and reactive power. Active power is used for the conversion and consumption of electrical energy, and reactive power is used to maintain the establishment of electric and magnetic fields. The balance of power in the power grid is crucial for the stable operation of the system. When updating a complex network system, it is necessary to verify the standard parameters of node control to ensure the reasonable distribution and adjustment of power.
[0088] Communication parameters include:
[0089] Data transmission rate: The data transmission rates of each communication link in the power system, such as the communication rates between substations and dispatch centers and between different substations. The data transmission rate affects the timeliness and accuracy of information transmission. When updating a complex network system, it is necessary to verify whether it meets the real-time requirements and whether the data encryption strength can ensure communication security.
[0090] Communication delay: The delay time for data to be transmitted in the communication network. Communication delay may affect the control accuracy and stability of the power system, such as affecting the operating time of relay protection devices. During the verification process, it is necessary to pay attention to the delay tolerance to ensure that the communication delay is within an acceptable range.
[0091] Communication reliability: The reliability indicators of communication links, such as bit error rate and packet loss rate. Excessive bit error rate and packet loss rate may cause data transmission errors or losses, affecting the normal operation of the power system. In the distributed security verification layer and the distributed function verification layer, it is necessary to conduct attack verification on communication reliability to ensure the stability of communication.
[0092] Furthermore, the distributed security verification layer and the distributed function verification layer in this embodiment have the same corresponding distribution structure;
[0093] Furthermore, the number of verification nodes to be verified in the security attack verification nodes in the distributed security verification layer of this embodiment is the same as and corresponds one by one to the number of verification nodes in the first-level continuously verified node subnet in the continuously verified node network;
[0094] Further, in this embodiment, the number of function attack verification nodes in the distributed function verification layer is the same as and corresponds one by one to the number of to-be-verified function sub-nodes in the secondary functional to-be-verified subnet in the continuous to-be-verified node network;
[0095] Further, each to-be-verified node in this embodiment includes M to-be-verified function sub-nodes;
[0096] Further, the distributed security verification layer in this embodiment is used to perform attack verification on the data encryption strength and access control process corresponding to each to-be-verified node and the connection relationship between nodes in the continuous to-be-verified node network;
[0097] Further, the distributed function verification layer in this embodiment is used to perform attack verification on the delay tolerance, load balancing, and node control standard parameters corresponding to each to-be-verified function sub-node and the connection relationship between sub-nodes in the secondary functional to-be-verified subnet.
[0098] Further, the attack verification algorithms corresponding to the distributed security verification layer and the distributed function verification layer in this embodiment are specifically set by the corresponding personnel in the field according to the corresponding field and security requirements.
[0099] S2. Obtain the parameters of the to-be-verified updated complex network system, and through the built-in verification decomposition model, obtain the first set of security to-be-verified parameters and the first set of function to-be-verified parameters corresponding to the continuous to-be-verified node network and each node;
[0100] Further, the construction steps of the continuous to-be-verified node network in this embodiment include:
[0101] According to the parameters of the to-be-verified updated complex network system, obtain the information of each key function control point in the system and the data transmission relationship information between key function control points;
[0102] Each key function control point corresponds one by one to the to-be-verified nodes in the first-level continuous to-be-verified node subnet;
[0103] According to the information of each key function control point, perform secondary decomposition to obtain the set of sub-function control points corresponding to each key function control point, the data transmission relationship within the set of sub-function control points, and the data transmission relationship between the corresponding sets of sub-function control points between key function control points;
[0104] For example, in the power field, the first-level key function control points include the area control center, substations 1 to 10.
[0105] The secondary sub-function control points include feeder terminal units (20), smart meters (100), photovoltaic inverter control units (5), etc. under each substation.
[0106] According to the sub - function control point sets corresponding to each key function control point, the data transmission relationships within the sub - function control point sets, and the data transmission relationships between the corresponding sub - function control point sets among the key function control points, clustering is performed through an adaptive clustering algorithm to obtain sub - function control point sets with the same function and mark the key function control point labels.
[0107] According to the number of key function control points and the data transmission relationship information between the key function control points, a first - level continuous subnet of nodes to be verified is constructed through a topology algorithm, and the data transmission direction is marked on the connection relationships between the nodes within the first - level continuous subnet of nodes to be verified;
[0108] According to the information of each key function control point in the first - level continuous subnet of nodes to be verified, through a function requirement analysis model, the expandable function information of each key function control point and the corresponding required resources and memory are obtained;
[0109] Exemplarily, in this embodiment, through the function requirement analysis model, 5% of the computing resources need to be reserved for Substation 1 for the future calculation of newly added photovoltaic inverter control units. At the same time, 10MB of memory and 2 CPU cores are reserved for each photovoltaic inverter control unit for the update storage of subsequent newly added system functions or control sub - functions corresponding to control devices.
[0110] According to the expandable function information of each corresponding key function control point and the corresponding required resources and memory, the corresponding required resources and memory are reserved. When the system is updated, according to the update requirements and the reserved required resources and memory, the lower - level sub - function control points are mounted and resources and memory are allocated at each corresponding key function control point;
[0111] Furthermore, the function requirement analysis model in this embodiment is constructed by support vector machines, historical function parameters, and the corresponding required resources and memory;
[0112] According to the sub - function control point sets corresponding to each key function control point and the data transmission relationships within the sub - function control point sets, the second - level regional functional subnets to be verified corresponding to the sub - function sub - node sets to be verified under each first - level continuous node to be verified are obtained;
[0113] According to the data transmission relationships between the corresponding sub - function control point sets among the key function control points, a set of directed connection relationships between the corresponding sub - function sub - nodes to be verified among all the second - level regional functional subnets to be verified is constructed;
[0114] Exemplarily, in this embodiment for the power field, the first - level continuous subnet of nodes to be verified in this embodiment includes Area Control Center → Substation 1 → Substation 2 →... → Substation N (based on the physical topology of the power grid), and the corresponding directed arrows are the directions of data transmission.
[0115] In this embodiment, the secondary functional subnet to be verified is a subnet structure formed by hanging feeder terminal units (FTUs), smart meters, and photovoltaic inverter control units under each substation;
[0116] Based on the directed connection relationship set and all the secondary area functional subnets to be verified, the secondary functional subnets to be verified are obtained.
[0117] S3. Based on the first security parameter to be verified, the first function parameter to be verified, and the connection relationship attribute corresponding to two consecutive nodes in the consecutive nodes network to be verified, construct a forward attack verification packet corresponding to each node to be verified and embed it into the hierarchical distributed effective verification network;
[0118] Furthermore, the forward attack verification packet corresponding to each node to be verified in this embodiment is composed of a security attack verification sub-packet and a functional attack verification sub-packet;
[0119] Furthermore, the security attack verification sub-packet in this embodiment simulates a man-in-the-middle attack against Substation 1 in the power field (testing whether AES-256 encryption is cracked), and simulates unauthorized access (testing whether the operator privilege grading takes effect).
[0120] The functional attack verification sub-packet in this embodiment simulates network congestion (testing the delay tolerance of FTUs), simulates a sudden increase in photovoltaic power generation (testing the voltage regulation accuracy of inverters), and tampering with the corresponding smart meter control parameters (testing the process of tampering with the corresponding sub-function control parameters, such as the voltage regulation function corresponding to the smart meter. Assuming the standard safe voltage is 36V, it is tampered with to 72V during the update process);
[0121] The construction steps of the distributed security verification layer and the distributed function verification layer include:
[0122] Based on the number and connection relationship of the nodes to be verified in the primary consecutive nodes subnet to be verified, construct a distributed security verification node subnet with the same structure;
[0123] Based on the data transmission direction in the primary consecutive nodes subnet to be verified, construct an initial security attack verification node, and configure the security attack verification sub-packet into the initial security attack verification node;
[0124] Based on the secondary functional subnet to be verified and the corresponding data transmission direction, construct a distributed function verification subnet and mark the verification order of each node in the distributed function verification subnet according to the data transmission direction;
[0125] Meanwhile, according to the verification order of each node in the distributed function verification subnet, the functional attack verification sub-packets are configured into each functional attack verification node in the initial area functional attack verification subnet within the distributed function verification subnet;
[0126] Further, the distributed function verification subnet is composed of area functional attack verification subnets, and the area functional attack verification subnets have the same structure and the same number of nodes as the secondary area functional subnet to be verified;
[0127] Further, in this embodiment, the functional attack verification nodes in the distributed function verification subnet increase correspondingly with the increase of the corresponding function sub-nodes to be verified in the secondary functional subnet to be verified, and always maintain a one-to-one correspondence in real time.
[0128] The area effective attack verification subnet has the same structure as and corresponds one-to-one with the secondary area functional subnet to be verified;
[0129] Configure a distributed synchronous verification evaluation control model, and build the distributed synchronous verification evaluation control model into the distributed security verification node subnet, the distributed function verification subnet and the continuous subnet to be verified, perform synchronous verification evaluation control, and obtain the verification evaluation results corresponding to the continuous subnet to be verified.
[0130] Further, the distributed synchronous verification evaluation control model in this embodiment includes a distributed pass control sub-model, a distributed evaluation parameter sub-model and a differential backward sharing sub-model;
[0131] Further, the distributed pass control sub-model in this embodiment is used to control the synchronization of the corresponding security attack verification nodes and functional attack verification nodes in the distributed security verification layer and the distributed function verification layer, and share the security attack verification sub-packets of the security attack verification nodes corresponding to the high-risk nodes to be verified backward to the next security attack verification node according to the direction of the connection relationship in the distributed security verification node subnet;
[0132] Further, the high-risk nodes to be verified in this embodiment are obtained by combining the preset risk assessment interval levels through the distributed synchronous verification evaluation control model, and based on the first security parameter to be verified and the first function parameter to be verified corresponding to each synchronized node to be attacked and the corresponding M function sub-nodes to be verified;
[0133] Meanwhile, the effective attack parameters of the functional attack verification nodes corresponding to the high-risk functional sub-nodes to be verified are shared with the next functional attack verification node corresponding to the set of sub-function control points with the same function obtained according to the clustering algorithm and the direction of the connection relationship in the distributed function verification subnet.
[0134] Further, the distributed evaluation parameter sub-model in this embodiment is used to evaluate the first security parameter to be verified and the first functional parameter to be verified for each synchronously attacked node to be verified and the corresponding M functional sub-nodes to be verified, and combine the preset risk evaluation interval levels to obtain the attack risk scores, corresponding risk levels, and effectiveness evaluation scores of the node to be verified and the corresponding M functional sub-nodes to be verified;
[0135] Further, the preset risk evaluation interval levels in this embodiment are set by technicians in the corresponding field according to the specific security requirements in the corresponding field for specific intervals and the scores corresponding to the intervals;
[0136] Further, the differential backward sharing sub-model in this embodiment makes a sharing judgment backward to the nodes to be verified and the functional sub-nodes to be verified in the same data transmission chain according to the direction of the connection relationship in the continuous node network to be verified and the attack type parameters of the currently attacked node to be verified and the functional sub-nodes to be verified. If the corresponding node to be verified or the functional sub-node to be verified contains the same attack type parameters, sharing is not performed. If not, the attack type parameters are shared.
[0137] S4. Use the hierarchical distributed effective verification network to perform a forward verification attack on any node and the corresponding data transmission chain in the continuous node network to be verified, and determine whether the first security parameter to be verified and the first functional parameter to be verified corresponding to each attacked node are valid;
[0138] S5. If it is valid, continue the verification and backward share the attack type corresponding to the previous node in the continuous node network to be verified until all nodes to be verified are verified. If it is invalid, the parameters of the complex network system to be verified are updated and invalidated.
[0139] Further, the steps of performing synchronous verification evaluation control to obtain the verification evaluation result corresponding to the continuous node network to be verified in this embodiment include:
[0140] Attack the initial node to be verified in the continuous node network to be verified and the directed connection relationship between the initial node to be verified and the second node to be verified according to the initial security attack verification node;
[0141] At the same time, through the distributed control sub-model, control the initial regional functional attack verification subnet corresponding to the initial security attack verification node to attack the initial secondary regional functional subnet to be verified and the directed connection relationship between the initial secondary regional functional subnet to be verified and the second secondary regional functional subnet to be verified;
[0142] The initial secondary regional functional subnet to be verified corresponds to the initial node to be verified;
[0143] Obtain the initial node to be verified and the corresponding connection relationship, and the initial secondary area functional subnet to be verified and the corresponding directed connection relationship after being attacked. Obtain the first security parameter to be verified and the first function parameter to be verified, and perform label marking on the corresponding nodes to be verified and function sub-nodes to be verified, and construct the initial attack parameter set;
[0144] Input the constructed initial attack parameter set into the distributed evaluation parameter sub-model to evaluate each function sub-node to be verified in the initial node to be verified and the initial secondary area functional subnet to be verified, and obtain the corresponding danger level and effectiveness evaluation score for each function sub-node to be verified in the initial node to be verified and the initial secondary area functional subnet to be verified;
[0145] Construct an effectiveness evaluation threshold with the score value corresponding to the lower limit of the high-risk level interval within the preset danger evaluation interval. If the effectiveness evaluation score corresponding to any function sub-node to be verified in the initial node to be verified or the initial secondary area functional subnet to be verified is greater than or equal to the effectiveness evaluation threshold, it is determined that the parameters of the complex network system to be verified for update are invalid;
[0146] If the effectiveness evaluation scores corresponding to all function sub-nodes to be verified in the initial node to be verified and the initial secondary area functional subnet to be verified are all less than the effectiveness evaluation threshold, it is determined that all function sub-nodes to be verified in the initial node to be verified and the corresponding initial secondary area functional subnet to be verified are valid;
[0147] After determining that all function sub-nodes to be verified in the initial node to be verified and the corresponding initial secondary area functional subnet to be verified are valid, perform backward sharing propagation judgment of attack parameters according to the danger levels corresponding to all function sub-nodes to be verified in the initial node to be verified and the corresponding initial secondary area functional subnet to be verified.
[0148] If the initial node to be verified is at a high-risk level or any function sub-node to be verified in the corresponding initial secondary area functional subnet to be verified is at a high-risk level, then through the distributed control sub-model, the security attack verification sub-packet corresponding to the initial security attack verification node is shared with the next security attack verification node according to the direction of the connection relationship in the distributed security verification node subnet;
[0149] At the same time, the functional attack verification sub-packet in the functional attack verification node corresponding to the high-risk function sub-node to be verified in the initial secondary area functional subnet to be verified is shared with the next functional attack verification node according to the direction of the connection relationship of the current functional attack verification node in the distributed functional verification subnet by using the clustering algorithm for the obtained set of sub-function control points with the same function;
[0150] If neither the initial node to be verified nor any of the functional sub-nodes to be verified in the corresponding initial secondary area functional sub-network to be verified is of a high-risk level, then no backward attack verification sub-packet sharing is performed on the security attack verification node and the functional attack verification node;
[0151] Meanwhile, through the differential backward sharing sub-model, the attack type parameters corresponding to all the functional sub-nodes to be verified in the initial node to be verified and the corresponding initial secondary area functional sub-network to be verified are backward shared according to the connection relationship direction corresponding to the data transmission in the continuous node network to be verified.
[0152] According to the connection relationship direction corresponding to the data transmission in the continuous node network to be verified, repeat the attack process of all the functional sub-nodes to be verified in the initial node to be verified and the corresponding initial secondary area functional sub-network to be verified, and attack each subsequent node to be verified in the continuous node network to be verified and all the functional sub-nodes to be verified in the corresponding secondary area functional sub-network to be verified;
[0153] Meanwhile, according to the security attack verification node and the area functional attack verification sub-network corresponding to each node to be verified and the corresponding secondary area functional sub-network to be verified, perform a forward verification attack on the verification nodes in the forward order and their corresponding connection relationships and the functional sub-nodes to be verified and their corresponding connection relationships in the corresponding secondary area functional sub-network to be verified on the data transmission chain where the current node to be verified and the corresponding secondary area functional sub-network to be verified are located;
[0154] Judge the danger level and effectiveness evaluation score after the attack of each node to be verified and the corresponding secondary area functional sub-network to be verified. If the effectiveness evaluation score corresponding to the node to be verified and the corresponding secondary area functional sub-network to be verified is greater than or equal to the effectiveness evaluation threshold, it is determined that the parameter failure of the complex network system to be verified and updated;
[0155] Otherwise, continue the verification and backward share the attack type parameters corresponding to all the functional sub-nodes to be verified in each node to be verified and the corresponding secondary area functional sub-network to be verified according to the connection relationship direction corresponding to the data transmission in the continuous node network to be verified until all the nodes to be verified are verified.
[0156] To better illustrate the above forward verification attack process, assume that the primary continuous node sub-network in the current continuous node network to be verified includes 5 nodes to be verified and 5 corresponding secondary functional sub-networks to be verified;
[0157] First, attack the first node to be verified and the corresponding nodes in the secondary functional subnet to be verified, and evaluate and verify the first security parameter to be verified and the first functional parameter to be verified of the node to be verified and the secondary functional subnet to be verified after the attack. When the effective evaluation score of one of the nodes to be verified and the secondary functional subnet to be verified is greater than the effective evaluation score threshold, the entire system parameters to be updated become invalid. If it passes, according to the risk level, share the security attack verification nodes and functional attack verification nodes corresponding to the high-risk nodes to be verified and the functional sub-nodes to be verified in the secondary functional subnet to be verified with the functional attack verification nodes corresponding to the high-risk functional sub-nodes in the second node to be verified and the secondary functional subnet to be verified; and share the attack type parameters received by all the functional sub-nodes to be verified in the node to be verified and the secondary functional subnet to be verified with the functional sub-nodes to be verified in the subsequent 4 nodes to be verified and the corresponding 4 secondary functional subnets to be verified.
[0158] When verifying the 3rd node to be verified and the secondary functional subnet to be verified, in addition to attacking the functional sub-nodes to be verified in the 3rd node to be verified and the secondary functional subnet to be verified according to the same steps as above, simultaneously perform a synchronous attack on the directed connection process between the first and second nodes to be verified, the secondary functional subnet to be verified, the first and second or second and third nodes to be verified, and the secondary functional subnet to be verified through the security attack verification node and the regional functional attack verification subnet corresponding to the 3rd node to be verified and the secondary functional subnet to be verified, and verify that it is effective after the attack. Repeat the above steps until all the nodes to be verified are verified.
[0159] In this embodiment, the corresponding structure design of the distributed security verification layer and the distributed function verification layer and the continuous node network to be verified ensures the comprehensiveness and scalability of the verification. Specifically, the distributed security verification layer and the distributed function verification layer and the subnet of nodes to be verified adopt a corresponding structure design, and the functional attack verification nodes can be increased in real time and maintain a one-to-one correspondence as the functional sub-nodes to be verified increase. This design not only ensures a comprehensive verification coverage of each node and connection relationship in the network system, avoiding verification blind spots, but also can be flexibly expanded when the system scale expands or the function is extended, continuously meeting the verification requirements, and improving the adaptability and scalability of the system.
[0160] In this embodiment, the configuration of the distributed synchronous verification evaluation control model and the collaborative work of each sub-model therein greatly enhance the effectiveness of the verification process and the system's risk response ability. The distributed control sub-model ensures the synchronization of security and function verification nodes, realizes the sharing of attack parameters of high-risk nodes, enables subsequent nodes to perceive potential risks in advance and make preventive preparations, and promotes the collaborative defense among various parts of the system. The distributed evaluation parameter sub-model can quantitatively evaluate the parameters of nodes and sub-nodes, clarify the danger level and effectiveness score, and provide a scientific and objective basis for judging the effectiveness of system parameters. The differential backward sharing sub-model avoids resource waste and repeated verification by intelligently judging the sharing of attack type parameters, improves the verification efficiency, and enables the system to respond to various attack situations more quickly and accurately.
[0161] In this embodiment, the combination of forward verification and backward sharing corresponding thereto strengthens the system stability. Specifically, the verification method that combines forward verification attacks with backward sharing of attack type parameters can, while conducting one-by-one effectiveness tests on each node, also timely share the attack type information of the previous node with subsequent nodes. This enables subsequent nodes to take targeted measures in advance when facing the same or similar attacks, enhances the overall defense ability and stability of the system, effectively avoids the collapse or failure of the entire system due to the vulnerability of some nodes, and ensures the reliable operation of complex network systems.
[0162] In this embodiment, during the verification process, by setting clear effectiveness evaluation thresholds and failure determination rules, it is possible to accurately judge whether the parameters of the complex network system to be verified and updated are effective. If it is found that the effectiveness evaluation score of a node or sub-node exceeds the threshold, the parameter is timely determined to be invalid, avoiding parameters with potential safety hazards or functional defects from entering the system, ensuring the safety and reliability of the system update process, and providing a strong guarantee for the continuous and stable operation of the system.
[0163] To better illustrate the above complex system verification process, this embodiment takes the power industry as an example to decompose the specific instance verification process. The steps include:
[0164] 1. System hierarchical construction and parameter decomposition:
[0165] Target system: An intelligent power grid system in a certain area, including 1 area control center, 5 substations (Substation 1 - 5), with 20 FTUs (feeder terminal units), 100 smart meters, and 5 photovoltaic inverter control units mounted under each substation.
[0166] Step implementation:
[0167] 1.1. Construct a hierarchical verification network including:
[0168] Distributed Security Verification Layer: It contains 6 security attack verification nodes (regional control center + 5 substations), and its structure is consistent with the physical power grid.
[0169] Distributed Function Verification Layer: Each security verification node corresponds to a function verification subnet. For example, the function verification subnet of Substation 1 contains 20 FTU nodes, 100 smart meter nodes, and 5 photovoltaic inverter nodes.
[0170] 1.2. The decomposed key control points include:
[0171] Level 1 nodes (i.e., Level 1 continuously to-be-verified nodes): The regional control center, Substations 1 - 5 form a Level 1 continuously to-be-verified node subnet, and the data transmission direction is regional control center → Substation 1 → Substation 2 →... → Substation 5.
[0172] Level 2 sub-nodes (i.e., to-be-verified function sub-nodes): The FTUs, smart meters, and photovoltaic inverters under each substation form a Level 2 functional to-be-verified subnet. By using the adaptive clustering algorithm, the same type of devices (such as all FTUs) under the same substation are clustered into one category, marked as "Substation 1 - FTU Cluster".
[0173] 1.3. Resource Reservation and Scalability Design:
[0174] Use support vector machines (trained based on historical data) to predict resource requirements: Reserve 5% computing resources for each substation (for future newly added photovoltaic inverters) and 10MB memory / 2 CPU cores (for device expansion).
[0175] Example: Substation 1 currently has 5 photovoltaic inverters, and the reserved resources can support the addition of 1 inverter in the future.
[0176] 2. The configuration of forward attack verification packets includes:
[0177] 2.1. Attack Scenario Design:
[0178] Security attack verification sub-packets (Distributed Security Verification Layer):
[0179] Man-in-the-middle attack: Simulate an attacker intercepting the communication between the regional control center and Substation 1 and attempting to crack the AES - 256 encryption protocol.
[0180] Unauthorized access: Test the operator permission grading and simulate a low-privilege user attempting to modify the protection setting value of Substation 1.
[0181] Functional attack verification sub-packets (Distributed Function Verification Layer):
[0182] Network congestion attack: Inject high-traffic data into the FTU nodes of Substation 1 and test its delay tolerance (whether it responds within 50ms).
[0183] Sudden increase in photovoltaic power generation: Simulate the photovoltaic output increasing suddenly from 0% to 100%, and test whether the inverter control unit can control the voltage fluctuation within ±5% within 1 second.
[0184] Parameter tampering attack: Tamper with the safety voltage threshold of the smart meter (from 36V to 72V), and verify whether the control system can detect and alarm.
[0185] 3. Synchronization attack verification and dynamic sharing steps include:
[0186] 3.1 Verification process:
[0187] Initial attack (regional control center):
[0188] Security verification: Launch a man-in-the-middle attack. If AES-256 is not cracked and the permission grading takes effect, the security assessment score (such as 80 points) is lower than the high-risk threshold (90 points).
[0189] Function verification: Simulate the regional control center sending high-frequency instructions to Substation 1 and test its load balancing ability. If the CPU usage rate ≤ 70%, the function assessment score (such as 85 points) is valid.
[0190] Parameter sharing and subsequent attacks:
[0191] Backward sharing: After the regional control center passes the verification, share the attack type (such as the man-in-the-middle attack mode) to the security verification node of Substation 1.
[0192] Chain attack: The security verification node of Substation 1 launches the same attack on itself and its connection to Substation 2. At the same time, its function verification subnet simulates FTU congestion and inverter sudden increase attacks.
[0193] Dynamic expansion verification:
[0194] New device test: Mount the 6th photovoltaic inverter in the reserved resources and simulate whether the system can automatically allocate resources and maintain voltage stability when it is connected to the grid.
[0195] Cross-site attack: If the smart meter of Substation 3 is tampered with, synchronize the attack parameters to the same type of meter nodes of Substations 4 - 5 through the differential backward sharing model, and verify the immunity of the entire link.
[0196] From the above exemplary verification process, it can be seen that for the complex network system verification method, in terms of hierarchical targeted verification, it realizes the decoupling of security and function, independently verifies the encryption strength and device performance, avoids test blind spots, and designs a verification network for the hierarchical structure of substations in the power industry to adapt to the physical topology of the power grid; in terms of dynamic resource reservation and expansion, it supports the evolution of smart grids, realizes non-interruptible expansion of the system through reserved resources, and uses a support vector machine to train based on historical records, and the data-driven prediction accuracy is much higher than that of traditional empirical reservation methods; the intelligent sharing of attack parameters is reflected in the rapid spread of high-risk attacks. For example, when a smart meter being tampered with is evaluated as high-risk, the parameters are automatically shared to achieve rapid verification of the same type of devices across the network, and the time-consuming is only 1 / 5 of the individual test. At the same time, differential backward sharing is used to avoid repeated tests; the synchronous evaluation model improves the real-time performance and realizes multi-link coverage, and can discover cross-station data transmission vulnerabilities; in addition, this method also supports real-time verification system updates; and it successfully supports the grid connection transformation of wind farms, and reserves resources to verify and identify risks in advance to avoid downtime after going online.
[0197] Embodiment 2
[0198] Please refer to Figure 2 , another embodiment provided by the present invention: a dynamic verification system for the security and effectiveness of a complex network system, including: a verification network module, a parameter parsing module, and an attack verification module;
[0199] The verification network module configures a hierarchical distributed effective verification network based on the properties of the complex network system, and the hierarchical distributed effective verification network includes a distributed security verification layer and a distributed function verification layer;
[0200] The parameter parsing module is used to obtain the parameters of the complex network system to be verified and updated, and through the built-in verification decomposition model, obtain a continuous network of nodes to be verified and a first set of security parameters to be verified and a first set of function parameters to be verified corresponding to each node.
[0201] The attack verification module includes an attack construction unit and an attack verification unit;
[0202] The attack construction unit constructs a forward attack verification packet corresponding to each node to be verified based on the first security parameter to be verified, the first function parameter to be verified, and the connection relationship attribute corresponding to two consecutive nodes in the continuous network of nodes to be verified, and builds it into the hierarchical distributed effective verification network;
[0203] The attack verification unit uses the hierarchical distributed effective verification network to perform a forward verification attack on any node and the corresponding data transmission chain in the continuous node network to be verified, and determines whether the first security parameter to be verified and the first function parameter to be verified corresponding to each attacked node are valid; if valid, continue the verification and backward share the attack type corresponding to the previous node in the continuous node network to be verified until all nodes to be verified are completed. If invalid, the parameters of the complex network system to be verified and updated are invalid.
[0204] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments without departing from the spirit and scope of the present invention as protected by the claims. All of these fall within the protection scope of the present invention.
[0205] If the technical solution of the present disclosure involves personal information, before the product applying the technical solution of the present disclosure processes personal information, it has clearly informed the personal information processing rules and obtained the individual's independent consent. If the technical solution of the present disclosure involves sensitive personal information, before the product applying the technical solution of the present disclosure processes sensitive personal information, it has obtained the individual's separate consent and at the same time meets the requirements of "express consent". For example, at a personal information collection device such as a camera, a clear and prominent sign is set to inform that the personal information collection range has been entered and personal information will be collected. If an individual voluntarily enters the collection range, it is deemed to have consented to the collection of their personal information; or on a personal information processing device, when the personal information processing rules are informed by obvious signs / information, personal authorization is obtained through pop-up messages or by asking the individual to upload their personal information by themselves; among them, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.
Claims
1. A dynamic verification method for the security effectiveness of complex network systems, characterized by: include: Configuring a hierarchical distributed effective verification network based on complex network system properties, wherein the hierarchical distributed effective verification network includes a distributed security verification layer and a distributed function verification layer; Obtain the updated complex network system parameters to be verified, and obtain the continuous node network to be verified and the first security parameter set to be verified and the first function parameter set to be verified corresponding to each node through the built-in verification decomposition model; Based on the first security parameter to be verified and the first function parameter to be verified corresponding to two consecutive nodes in the continuous node network to be verified and the connection relationship attribute, a forward attack verification package corresponding to each node to be verified is constructed and built into the hierarchical distributed effective verification network; Using the hierarchical distributed effective verification network, a forward verification attack is performed on any node in the continuous node network to be verified and the corresponding data transmission chain, and determining whether the first security parameter to be verified and the first function parameter to be verified corresponding to each attacked node are valid; If it is valid, continue to verify and share the attack type corresponding to the previous node in the continuous node network to be verified backward until all nodes to be verified are verified. If it is invalid, the complex network system parameters to be verified will be invalid; The distributed security verification layer and the distributed function verification layer have the same corresponding distribution structure; The number of security attack verification nodes in the distributed security verification layer and the number of nodes to be verified in the first-level continuous node to be verified subnet in the continuous node to be verified network are the same and correspond one to one; The number of the function attack verification nodes in the distributed function verification layer and the number of the function sub-nodes to be verified in the secondary functional sub-network to be verified in the continuous node network to be verified are the same and correspond one to one; Each of the nodes to be verified includes M Function sub-nodes to be verified; The distributed security verification layer is used to perform attack verification on the data encryption strength and access control process corresponding to each node to be verified and the connection relationship between nodes in the continuous node network to be verified; The distributed function verification layer is used to perform attack verification on the delay tolerance, load balancing, and node control standard parameters corresponding to each function sub-node to be verified and the connection relationship between the sub-nodes in the secondary functional sub-network to be verified.
2. The dynamic verification method for security effectiveness of complex network systems according to claim 1, characterized in that: The steps of constructing the continuous network of nodes to be verified include: Update the complex network system parameters to be verified, obtain the information of each key function control point in the complex network system and the data transmission relationship information between the key function control points; Each of the key function control points corresponds one-to-one to a node to be verified in the first-level continuous node subnet to be verified; According to the information of each key function control point, secondary decomposition is performed to obtain the sub-function control point set corresponding to each key function control point and the data transmission relationship within the sub-function control point set and the data transmission relationship between the key function control points and the corresponding sub-function control point sets; According to the sub-function control point set corresponding to each key function control point, the data transmission relationship within the sub-function control point set, and the data transmission relationship between the sub-function control point sets corresponding to the key function control points, clustering is performed through an adaptive clustering algorithm to obtain the sub-function control point set with the same function and mark the key function control point labels.
3. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 2, characterized in that: The step of constructing the continuous node network to be verified also includes: According to the number of key function control points and the data transmission relationship information between the key function control points, a first-level continuous node subnet to be verified is constructed through a topology algorithm, and the data transmission direction is marked on the connection relationship between the nodes in the first-level continuous node subnet to be verified; According to the information of each key function control point in the first-level continuous node subnet to be verified, the scalable function information of each key function control point and the corresponding required resources and memory are obtained through the function requirement analysis model; According to the expandable function information and the corresponding required resources and memory of each corresponding key function control point, the corresponding required resources and memory are reserved. When the system is updated, the lower-level sub-function control points are mounted and the resources and memory are allocated at each corresponding key function control point according to the update requirements and the reserved required resources and memory.
4. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 3 is characterized in that: The step of constructing the continuous node network to be verified also includes: According to the sub-function control point set corresponding to each key function control point and the data transmission relationship within the sub-function control point set, the second-level regional functional subnet to be verified corresponding to the function sub-node set to be verified under each first-level continuous node to be verified is obtained; Constructing a directed connection relationship set between corresponding function sub-nodes to be verified between all the secondary regional functional sub-networks to be verified according to the data transmission relationship between the corresponding sub-function control point sets between the key function control points; Based on the directed connection relationship set and all the secondary regional functional subnets to be verified, a secondary functional subnet to be verified is obtained.
5. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 4, characterized in that: The forward attack verification package corresponding to each node to be verified consists of a security attack verification sub-package and a functional attack verification sub-package; The steps of constructing the distributed security verification layer and the distributed function verification layer include: Based on the number and connection relationship of the nodes to be verified in the first-level continuous node subnet to be verified, a distributed security verification node subnet with the same structure is constructed; Based on the direction of data transmission in the first-level continuous node subnet to be verified, construct an initial security attack verification node, and configure the security attack verification sub-package into the initial security attack verification node; Based on the secondary functional subnet to be verified and the corresponding data transmission direction, a distributed function verification subnet is constructed and the order of verification of each node in the distributed function verification subnet is marked according to the data transmission direction; At the same time, according to the order of verification of each node in the distributed function verification subnet, the functional attack verification sub-package is configured to each functional attack verification node in the initial area functional attack verification subnet in the distributed function verification subnet; The distributed function verification subnet is composed of a regional function attack verification subnet, and the regional function attack verification subnet has the same structure and number of nodes as the secondary regional functional subnet to be verified; A distributed synchronous verification and evaluation control model is configured, and the distributed synchronous verification and evaluation control model is built into the distributed security verification node subnet, distributed function verification subnet and continuous node network to be verified, and synchronous verification and evaluation control is performed to obtain verification and evaluation results corresponding to the continuous node network to be verified.
6. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 5, characterized in that: The distributed synchronous verification and evaluation control model includes a distributed pass control sub-model, a distributed evaluation parameter sub-model and a differential backward sharing sub-model; The distributed control sub-model is used to control the synchronization of the corresponding security attack verification nodes and functional attack verification nodes in the distributed security verification layer and the distributed functional verification layer, and share the security attack parameter of the security attack verification sub-package of the security attack verification node corresponding to the high-risk node to be verified with the next security attack verification node according to the direction of the connection relationship in the distributed security verification node subnet; The high-risk node to be verified is obtained by combining the distributed evaluation parameter sub-model with the preset risk assessment interval level according to the first security parameter to be verified and the first function parameter to be verified corresponding to each synchronously attacked node to be verified and the corresponding M function sub-nodes to be verified; At the same time, the effective attack parameters of the function attack verification node corresponding to the high-risk function sub-node to be verified are shared with the next function attack verification node corresponding to the direction of the connection relationship in the distributed function verification subnet and the sub-function control point set with the same function obtained according to the clustering algorithm.
7. The dynamic verification method for security effectiveness of complex network systems according to claim 6, characterized in that: The distributed evaluation parameter sub-model is used to evaluate the first security parameter to be verified and the first function parameter to be verified of each synchronously attacked node to be verified and the corresponding M function sub-nodes to be verified, and combine the preset risk assessment interval level to obtain the attack risk score of the node to be verified and the corresponding M function sub-nodes to be verified and the corresponding risk level and effectiveness assessment score; The differential backward sharing sub-model performs sharing judgment backward toward the nodes to be verified and the functional sub-nodes to be verified in the same data transmission chain according to the direction of the connection relationship in the continuous node network to be verified and the attack type parameters of the currently attacked nodes to be verified and the functional sub-nodes to be verified. If the corresponding nodes to be verified or the functional sub-nodes to be verified contain the same attack type parameters, they are not shared; if not, the attack type parameters are shared.
8. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 7, characterized in that: The step of performing synchronous verification and evaluation control to obtain verification and evaluation results corresponding to the continuous node network to be verified includes: Attacking the initial node to be verified in the continuous node to be verified network and the directed connection relationship between the initial node to be verified and the second node to be verified according to the initial security attack verification node; At the same time, the initial regional functional attack verification subnet corresponding to the initial security attack verification node is controlled by the distributed control submodel to attack the initial secondary regional functional subnet to be verified and the directed connection relationship between the initial secondary regional functional subnet to be verified and the second secondary regional functional subnet to be verified; The initial secondary regional functional subnet to be verified corresponds to the initial node to be verified; Obtain the first security parameters to be verified and the first functional parameters to be verified after the initial nodes to be verified and the corresponding connection relationships and the initial secondary regional functional subnets to be verified and the corresponding directed connection relationships are attacked, and label the corresponding nodes to be verified and the functional subnodes to be verified, so as to construct an initial attack parameter set; The constructed initial attack parameter set is input into the distributed evaluation parameter sub-model to evaluate the initial node to be verified and each functional sub-node to be verified in the initial secondary area functional sub-network to be verified, so as to obtain the corresponding danger level and effectiveness evaluation score of the initial node to be verified and each functional sub-node to be verified in the initial secondary area functional sub-network to be verified.
9. The dynamic verification method for security effectiveness of complex network systems as claimed in claim 8, characterized in that: The step of performing synchronous verification and evaluation control to obtain verification and evaluation results corresponding to the continuous node network to be verified also includes: The validity assessment threshold is constructed with the score value corresponding to the lower limit of the high-risk level interval within the preset risk assessment interval. If the validity assessment score corresponding to the initial node to be verified or any functional sub-node to be verified in the initial secondary regional functional sub-network to be verified is greater than or equal to the validity assessment threshold, the update of the complex network system parameters to be verified is determined to be invalid; If the validity evaluation scores corresponding to the initial node to be verified and all the functional sub-nodes to be verified in the initial secondary regional functional sub-network to be verified are less than the validity evaluation threshold, then the initial node to be verified and all the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified are determined to be valid; When it is determined that the initial node to be verified and all the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified are valid, the attack parameters are backward shared and propagated according to the danger levels corresponding to the initial node to be verified and all the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified.
10. The dynamic verification method for security effectiveness of complex network systems according to claim 9, characterized in that: The step of performing synchronous verification and evaluation control to obtain verification and evaluation results corresponding to the continuous node network to be verified also includes: If the initial node to be verified is of high risk level or any of the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified is of high risk level, the security attack verification sub-package corresponding to the initial security attack verification node is shared with the next security attack verification node through the distributed control sub-model according to the direction of the connection relationship in the distributed security verification node sub-network; At the same time, the functional attack verification sub-package in the functional attack verification node corresponding to the high-risk functional sub-node to be verified in the initial secondary regional functional to-be-verified sub-network is shared according to the clustering algorithm with the obtained sub-function control point set with the same function and the next functional attack verification node in the direction of the connection relationship corresponding to the current functional attack verification node in the distributed functional verification sub-network; If the initial node to be verified and any of the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified are not of high risk level, the backward attack verification sub-package sharing will not be performed on the security attack verification node and the functional attack verification node; At the same time, the attack type parameters corresponding to the initial node to be verified and all the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified are shared backwards according to the connection relationship direction corresponding to the data transmission in the continuous node to be verified network through the differential backward sharing sub-model.
11. The dynamic verification method for security effectiveness of complex network systems according to claim 10, characterized in that: The step of performing synchronous verification and evaluation control to obtain verification and evaluation results corresponding to the continuous node network to be verified also includes: Repeat the attack process of the initial node to be verified and all the functional sub-nodes to be verified in the corresponding initial secondary regional functional sub-network to be verified according to the connection relationship direction corresponding to the data transmission in the continuous node to be verified network, and attack each subsequent node to be verified in the continuous node to be verified network and all the functional sub-nodes to be verified in the corresponding secondary regional functional sub-network to be verified; At the same time, according to the security attack verification nodes and regional functional attack verification subnets corresponding to each node to be verified and the corresponding secondary regional functional subnet to be verified, a forward verification attack is performed on the verification nodes and corresponding connection relationships in the forward sequence on the data transmission chain where the current node to be verified and the corresponding secondary regional functional subnet to be verified are located, and the functional subnodes to be verified and the corresponding connection relationships in the corresponding secondary regional functional subnet to be verified; Determine the danger level and effectiveness evaluation score of each of the above-mentioned nodes to be verified and the corresponding secondary regional functional subnet to be verified after being attacked. If the effectiveness evaluation score corresponding to the corresponding node to be verified and the corresponding secondary regional functional subnet to be verified is greater than or equal to the effectiveness evaluation threshold, then determine that the update of the complex network system parameters to be verified is invalid; Otherwise, verification continues and the attack type parameters corresponding to each node to be verified and all the functional sub-nodes to be verified in the corresponding secondary regional functional sub-node to be verified are shared backward according to the connection relationship direction corresponding to the data transmission in the continuous node network to be verified until the verification of all nodes to be verified is completed.
12. A dynamic verification system for the security effectiveness of a complex network system, which is used to implement the dynamic verification method for the security effectiveness of a complex network system as claimed in any one of claims 1 to 11, characterized in that: include: Verify network module, parameter parsing module, and attack verification module; The verification network module configures a hierarchical distributed effective verification network based on complex network system properties, wherein the hierarchical distributed effective verification network includes a distributed security verification layer and a distributed function verification layer; The parameter parsing module is used to obtain the parameters of the complex network system to be verified and updated, and obtain the continuous node network to be verified and the first security parameter set to be verified and the first function parameter set to be verified corresponding to each node through the built-in verification decomposition model; The attack verification module includes an attack construction unit and an attack verification unit; The attack construction unit constructs a forward attack verification package corresponding to each node to be verified based on the first security parameter to be verified and the first function parameter to be verified corresponding to two consecutive nodes in the continuous node network to be verified and the connection relationship attribute, and builds the package into the hierarchical distributed effective verification network; The attack verification unit uses the hierarchical distributed effective verification network to perform a forward verification attack on any node in the continuous node network to be verified and the corresponding data transmission chain, and determines whether the first security parameter to be verified and the first function parameter to be verified corresponding to each attacked node are valid; if valid, continue to verify and share the attack type corresponding to the previous node in the continuous node network to be verified backward until the verification of all nodes to be verified is completed; if invalid, the updated complex network system parameters to be verified are invalid.
Citation Information
Patent Citations
A method and system for validating threshold proxy re-encrypted collaborative networks
CN116112284B
Network security system and network security method
CN111356135A
Authentication method and member node
CN112637298A