Custom POC verification method, system and device based on power system security vulnerabilities and medium

By utilizing Pearson's correlation coefficient and Bayesian network algorithm, custom POC development and testing environment is solved, and the problems of low efficiency, poor timeliness and narrow coverage in the existing technology are achieved, achieving more efficient and accurate power system security vulnerability verification.

CN119939592APending Publication Date: 2025-05-06GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411899480.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, POC verification has problems such as low efficiency, poor timeliness of validity verification and narrow coverage, making it difficult to effectively detect and verify security vulnerabilities in the power system.

Method used

By obtaining detailed information of the power system, collecting security vulnerabilities information, using the Pearson correlation coefficient algorithm to calculate the correlation between unknown security vulnerabilities and known security vulnerabilities, a preliminary POC framework for determining unknown security vulnerabilities based on Bayesian network algorithm, and customizing the POC development and testing environment for verification.

Benefits of technology

The accuracy and reliability of vulnerability verification have been improved, and a relatively complete power system security vulnerability verification system has been formed, which has significantly improved the ability to discover, analyze and verify power system security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939592A_ABST
    Figure CN119939592A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of vulnerability verification, and provides a customized POC verification method, system and device based on power system security vulnerabilities, and a medium, the method comprises the following steps: obtaining detailed information of a to-be-verified power system, and collecting security vulnerability information corresponding to the power system based on the detailed information; when the security vulnerability information has a position security vulnerability, calculating the correlation between an unknown security vulnerability and a known security vulnerability by using a Pearson's correlation coefficient algorithm; screening known security vulnerabilities meeting correlation conditions based on the calculated correlation, and determining a preliminary POC framework of the unknown security vulnerabilities through a Bayesian network algorithm; customizing a POC development test environment according to the preliminary POC framework; and verifying the security vulnerabilities of the power system through the customized POC development test environment. According to the method, a perfect power system security vulnerability verification system is formed, and the capability of finding, analyzing and verifying the power system security vulnerabilities is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vulnerability verification, and in particular to a custom POC verification method, system, device and medium based on power system security vulnerabilities. Background Art

[0002] Power system security vulnerability verification refers to the process of using a series of technical means to determine whether there are security vulnerabilities in the power system, including hardware equipment, software systems and communication networks involved in power generation, transmission, transformation, distribution and consumption, and to assess the extent to which these vulnerabilities may affect the safety, reliability and stability of the power system.

[0003] In the prior art, security vulnerabilities include vulnerability scanning tools, POC verification, and penetration testing. Vulnerability scanning tools use professional tools to scan network devices and servers in the power system, and can detect common network security vulnerabilities, such as open high-risk ports, weak passwords, known operating system and software vulnerabilities, etc.; POC verification is to develop POC code for verification based on the specific equipment, software and network environment of the power system; penetration testing is to simulate real attack scenarios, and testers use various technical means to try to break through the security line of the power system as attackers. However, in these methods, vulnerability scanning tools cannot detect location vulnerabilities, and the penetration testing process is relatively complicated and time-consuming, and the cost is relatively high; POC verification requires a certain prior knowledge of the vulnerability, including the principle of the vulnerability, the way to use it, etc., in order to write an effective POC. In the attack and defense confrontation, the attacker may deform or bypass the vulnerability to evade detection and defense, and POC verification has the problems of low efficiency, poor timeliness of effectiveness verification, and narrow coverage.

[0004] In view of this, a customized POC verification method, system, equipment and medium based on power system security vulnerabilities are needed. Summary of the invention

[0005] The embodiment of the present application provides a customized POC verification method based on power system security vulnerabilities, which is used to solve the problems of low efficiency, poor timeliness of effectiveness verification and narrow coverage of POC verification.

[0006] The first aspect of the embodiment of the present application provides a custom POC verification method based on power system security vulnerabilities, including:

[0007] Obtaining detailed information of the power system to be verified, and collecting security vulnerability information corresponding to the power system based on the detailed information;

[0008] When the security vulnerability information contains a location security vulnerability, the correlation between the unknown security vulnerability and the known security vulnerability is calculated using a Pearson correlation coefficient algorithm;

[0009] Based on the calculated correlation, known security vulnerabilities that meet the correlation conditions are screened, and a preliminary POC framework of the unknown security vulnerabilities is determined through a Bayesian network algorithm;

[0010] Customize the POC development and testing environment based on the preliminary POC framework;

[0011] The power system security vulnerabilities are verified through the customized POC development test environment.

[0012] Furthermore, when the security vulnerability information contains a location security vulnerability, the correlation between the unknown security vulnerability and the known security vulnerability is calculated using a Pearson correlation coefficient algorithm, including:

[0013] Identify variables associated with known security vulnerabilities and variables associated with unknown security vulnerabilities;

[0014] Calculate the means, covariances, and standard deviations of variables related to known security vulnerabilities and variables related to unknown security vulnerabilities respectively;

[0015] Pearson correlation coefficient was calculated based on the calculated mean, covariance, and standard deviation;

[0016] The correlation between the unknown security vulnerability and the known security vulnerability is determined based on the Pearson correlation coefficient.

[0017] Furthermore, respectively calculating the means, covariances and standard deviations of the variables related to the known security vulnerabilities and the variables related to the unknown security vulnerabilities, includes:

[0018] Mean of variables:

[0019]

[0020]

[0021] in: and are the means of known security vulnerability variables and unknown security vulnerability variables, n is the number of samples, X i and Y i They are the i-th known security vulnerability variable and the i-th unknown security vulnerability variable in the sample respectively;

[0022] Covariance:

[0023]

[0024] Where: Cov(X,Y) is the covariance between the known security vulnerability variable X and the unknown security vulnerability variable Y;

[0025] Standard Deviation:

[0026]

[0027] Where: S X and S Y are the standard deviations of the known security vulnerability variable X and the unknown security vulnerability variable Y, respectively.

[0028] Furthermore, the calculating of the Pearson correlation coefficient according to the calculated mean, covariance and standard deviation includes:

[0029]

[0030] Where: r is the Pearson correlation coefficient.

[0031] Furthermore, the calculation-based correlation screening of known security vulnerabilities that meet the correlation conditions, and determining the preliminary POC framework of the unknown security vulnerabilities through the Bayesian network algorithm, include:

[0032] Based on the relevant attributes of unknown security vulnerabilities and the relevant attributes of known security vulnerabilities, the nodes of the Bayesian network include cause nodes and result nodes;

[0033] Determine the conditional probabilities between nodes and construct a Bayesian network structure based on the conditional probabilities between nodes;

[0034] Set the evidence nodes according to the constructed Bayesian network structure, and calculate the probability of the key nodes according to the set evidence nodes;

[0035] A preliminary POC framework for unknown security vulnerabilities is constructed based on the key node probabilities and the screened POC experience of known security vulnerabilities.

[0036] Furthermore, setting the evidence nodes according to the constructed Bayesian network structure and calculating the probability of the key nodes according to the set evidence nodes include:

[0037]

[0038] Where: P(Y|E1,E2,…,E m ) is the chain rule, Y is the key node to be calculated, E1, E2, …, E m is the evidence node, P(Y,E1,E2,…,E m ) is the probability of the key node, P(E1,E2,…,E m ) is the probability of the evidence node.

[0039] Furthermore, the preliminary POC framework of unknown security vulnerabilities is constructed based on the key node probabilities and the POC experience of known security vulnerabilities, including:

[0040] Analyze vulnerability characteristics based on screened known security vulnerabilities;

[0041] Determine the key elements of the POC framework based on the characteristics of the analyzed vulnerabilities;

[0042] Design the vulnerability trigger module, monitoring and verification module and data collection and analysis module of the POC framework according to the key elements of the POC framework;

[0043] Based on the vulnerability trigger module, monitoring and verification module, and data collection and analysis module, a preliminary POC framework was built for internal testing.

[0044] A second aspect of the embodiment of the present application provides a customized POC verification system based on power system security vulnerabilities, including:

[0045] A security vulnerability information collection unit, used to obtain detailed information of the power system to be verified, and collect security vulnerability information corresponding to the power system based on the detailed information;

[0046] A correlation calculation unit, used to calculate the correlation between the unknown security vulnerability and the known security vulnerability using a Pearson correlation coefficient algorithm when the security vulnerability information contains a location security vulnerability;

[0047] A preliminary POC framework determination unit, used to screen known security vulnerabilities that meet the correlation conditions based on the calculated correlation, and determine the preliminary POC framework of the unknown security vulnerability through a Bayesian network algorithm;

[0048] A POC development and testing environment customization unit, used to customize the POC development and testing environment according to the preliminary POC framework;

[0049] The power system security vulnerability verification unit is used to verify the power system security vulnerability through the customized POC development test environment.

[0050] A third aspect of the embodiments of the present application provides a computer device, including:

[0051] memories, transceivers, processors, and bus systems;

[0052] Wherein, the memory is used to store programs;

[0053] The processor is used to execute the program in the memory, including executing the customized POC verification method based on power system security vulnerabilities as described in any one of the above;

[0054] The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.

[0055] A fourth aspect of an embodiment of the present application provides a readable storage medium, including instructions, which, when executed on a computer, enables the computer to execute the steps of the customized POC verification method based on power system security vulnerabilities as described in any one of the above.

[0056] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0057] The present invention obtains detailed information of the power system to be verified, and collects security vulnerability information corresponding to the power system based on the detailed information; when there is an unknown security vulnerability in the security vulnerability information, the Pearson correlation coefficient algorithm is used to calculate the correlation between the unknown security vulnerability and the known security vulnerability; based on the calculated correlation, the known security vulnerability that meets the correlation condition is screened, and the preliminary POC framework of the unknown security vulnerability is determined by the Bayesian network algorithm; when the preliminary POC framework of the unknown security vulnerability is determined by the Bayesian network algorithm, the key known vulnerability information can be integrated more efficiently, and the analysis process can be prevented from being disturbed by too much redundant data, so that the constructed framework can fully absorb relevant and valuable experience and be more in line with the actual situation of the unknown vulnerability; finally, the POC development and testing environment is customized according to the preliminary POC framework; the power system security vulnerability is verified by the customized POC development and testing environment; it is ensured that the conditions under which the vulnerability is triggered and has an impact in the real scenario can be reproduced to the greatest extent during the test process, and the accuracy and reliability of the vulnerability verification are improved. The present invention forms a relatively complete power system security vulnerability verification system, which significantly improves the ability to discover, analyze and verify power system security vulnerabilities.

[0058] Other advantages, objectives, and features of the present invention will be set forth in part in the following description, and in part will be apparent to those skilled in the art based on an examination of the following or may be taught from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 It is a flowchart of an embodiment of a custom POC verification method based on power system security vulnerabilities in the present invention. DETAILED DESCRIPTION

[0060] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein, for example. In addition, the terms "including" and "corresponding to" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0061] Embodiment 1

[0062] The implementation method in this embodiment can be implemented in the system, can be implemented in the server, and can also be implemented in the terminal, without specific limitation. The following will introduce the custom POC verification method based on power system security vulnerabilities in this application from the perspective of system implementation. Figure 1 , the method provided in the embodiment of the present application comprises the following steps:

[0063] S11. Obtain detailed information of the power system to be verified, and collect security vulnerability information corresponding to the power system based on the detailed information;

[0064] In this embodiment, the detailed information of the power system includes system architecture and topology information, equipment parameters and characteristics information, operation data and working condition information, communication protocol and interface information. The system architecture and topology information includes the connection mode and layout of each component such as power plant, substation, transmission line, distribution network, etc., which can more accurately simulate the operation status and data flow of the power system; the equipment parameters and characteristics information include the rated power, voltage level, frequency characteristics of the generator, the ratio, capacity, loss characteristics of the transformer, and the resistance, reactance, capacitance and other parameters of the transmission line, which can affect the system's power flow distribution, voltage stability and other performance indicators; the operation data and working condition information includes load curves, power generation plans, voltage fluctuations, fault records, etc. These data can help build a test scenario that is closer to the actual operation, so that the test environment can reflect the performance of the power system under different working conditions; the communication protocol and interface information includes the communication protocol and interface specifications between various devices in the power system. When setting up the test environment, it is necessary to configure the corresponding communication equipment and software to ensure that the various devices can communicate and interact with each other normally.

[0065] The security vulnerability information related to the power system includes vulnerability type and feature information, vulnerability impact scope and severity information, vulnerability repair measures and patch information. Vulnerability type and feature information includes network attack vulnerabilities, operating system vulnerabilities, application vulnerabilities, database vulnerabilities, etc., the type, feature, attack method and possible impact of each vulnerability; vulnerability impact scope and severity information is used to evaluate the impact scope and severity of different security vulnerabilities on the power system, so that test cases and test priorities can be set in a targeted manner when building a test environment; vulnerability repair measures and patch information obtains repair measures and patch information for various security vulnerabilities. The vulnerability repair process can be simulated in the test environment to verify the effectiveness of the repair measures and the impact on system performance.

[0066] S12. When the security vulnerability information contains a location security vulnerability, the correlation between the unknown security vulnerability and the known security vulnerability is calculated using the Pearson correlation coefficient algorithm;

[0067] In this embodiment, step S12 includes the following:

[0068] 1. Determine the variables associated with known security vulnerabilities and the variables associated with unknown security vulnerabilities;

[0069] First, we need to identify the variables related to known security vulnerabilities and the variables related to unknown security vulnerabilities. For example, let the known security vulnerability variable be X and the unknown security vulnerability variable be Y. Collect sample data containing the observation values ​​of these two variables. Assume that there are n sample points, namely (X1, Y1), (X2, Y2), ..., (X n ,Y n ). The samples can come from data recorded by the security monitoring system at different time points, different system modules or different types of equipment.

[0070] Check whether the data is complete and whether there are missing values ​​or erroneous records. If there are missing values, you need to choose an appropriate processing method based on the data characteristics and analysis purpose, such as deleting samples with missing values, or using statistics such as mean, median, mode, etc. to fill in missing values. At the same time, ensure that the data types of variables X and Y are continuous data suitable for calculating the Pearson correlation coefficient.

[0071] 2. Calculate the mean, covariance and standard deviation of variables related to known security vulnerabilities and unknown security vulnerabilities respectively;

[0072] Mean of variables:

[0073]

[0074] in: and are the means of known security vulnerability variables and unknown security vulnerability variables, n is the number of samples, X i and Y i They are the i-th known security vulnerability variable and the i-th unknown security vulnerability variable in the sample respectively;

[0075] Covariance:

[0076]

[0077] Where: Cov(X,Y) is the covariance between the known security vulnerability variable X and the unknown security vulnerability variable Y;

[0078] Standard Deviation:

[0079]

[0080] Where: S X and S Y are the standard deviations of the known security vulnerability variable X and the unknown security vulnerability variable Y, respectively.

[0081] 3. Calculate the Pearson correlation coefficient based on the calculated mean, covariance and standard deviation;

[0082]

[0083] Where: r is the Pearson correlation coefficient.

[0084] The Pearson correlation coefficient eliminates the influence of variable units and scales, and standardizes the degree of correlation to the interval [-1,1]. Among them, r = 1 indicates a completely positive linear correlation, that is, when the known security vulnerability variable X increases, the unknown security vulnerability variable Y will also increase proportionally; r = -1 indicates a completely negative linear correlation, that is, when X increases, Y will decrease proportionally; r = 0 indicates that there is no linear correlation between the two variables.

[0085] 4. Determine the correlation between unknown security vulnerabilities and known security vulnerabilities based on the Pearson correlation coefficient.

[0086] Assume that the correlation coefficient between each known security vulnerability and the unknown security vulnerability has been calculated through the Pearson correlation coefficient. These correlation coefficients constitute a data set, in which each data point represents a correlation measure for a pair of known-unknown security vulnerabilities. At the same time, it is necessary to record detailed information for each known security vulnerability, including vulnerability type, affected system components, exploitation methods, attack conditions, etc. This information will be used in subsequent steps to build a Bayesian network and determine the POC framework. Before screening, set a correlation threshold. The threshold is determined based on industry standards, historical experience, or specific analysis purposes. For example, if you want to screen out known security vulnerabilities that are highly correlated with unknown security vulnerabilities, and based on past research on the correlation of security vulnerabilities, it is found that a Pearson correlation coefficient greater than 0.7 or less than -0.7 usually indicates a strong correlation, then 0.7 or -0.7 can be set as the threshold.

[0087] Here, screening of known security vulnerabilities includes single variable screening and multivariate comprehensive screening. Single variable screening is based on the correlation coefficient. Suppose the set of known security vulnerabilities is V = {v1, v2, ..., v n}, the corresponding Pearson correlation coefficient set with unknown security vulnerabilities is R = {r1,r2,...,r n}, the correlation threshold is set to T. For each known security vulnerability and its corresponding correlation coefficient r i , using the comparison formula r i ≥T or r i ≤―T. For example, if T=0.7, when r i =0.8, satisfying r i ≥T, then the known security vulnerability v i Pass the initial screening.

[0088] In addition to the correlation coefficient, multivariate comprehensive screening may also need to consider other factors. For example, the severity and frequency of known security vulnerabilities. i The severity is S i , the frequency of occurrence is F i , and set the severity threshold to S T , the frequency threshold is F T In addition to meeting the relevance condition, S i ≥S T and F i ≥F T For example, S T =6, indicating that only vulnerabilities with a severity of 6 or above are considered. T = 5 means that only vulnerabilities that have appeared 5 times or more in the past year are considered. iAt the same time, the correlation conditions such as r i ≥T, severity condition S i ≥S T and the frequency condition F i ≥F T Only then were they finally selected as references for the subsequent construction of the Bayesian network and determination of the POC framework.

[0089] The known security vulnerabilities that have passed the screening and their related information are organized into a new data set. This data set will be used as the input for building the Bayesian network, which contains detailed information on known security vulnerabilities that have a strong correlation with unknown security vulnerabilities and meet the requirements in other aspects, including vulnerability types, affected system components, exploitation methods, attack conditions, etc., providing a basis for the subsequent preliminary POC framework for using the Bayesian network to determine unknown security vulnerabilities.

[0090] S13. Based on the calculated correlation, known security vulnerabilities that meet the correlation conditions are screened, and a preliminary POC framework for unknown security vulnerabilities is determined through a Bayesian network algorithm;

[0091] In this embodiment, step S13 includes the following:

[0092] 1. Based on the relevant attributes of unknown security vulnerabilities and the relevant attributes of known security vulnerabilities, the nodes of the Bayesian network include cause nodes and result nodes;

[0093] The relevant attributes of unknown security vulnerabilities are used as nodes of the Bayesian network. These attributes include vulnerability type, affected system components, attack conditions, and vulnerability exploitability. At the same time, the same attributes of the screened known security vulnerabilities are also used as nodes. The nodes are divided into cause nodes and result nodes to clarify the possible causal relationship direction between nodes. For example, the satisfaction of attack conditions may lead to an increase in vulnerability exploitability, so "attack conditions" are the cause nodes of "vulnerability exploitability".

[0094] 2. Determine the conditional probabilities between nodes and construct a Bayesian network structure based on the conditional probabilities between nodes;

[0095] Gather information from historical security vulnerability data, experimental data, or expert knowledge to determine the conditional probability of each node given the state of its parent node. For example, for the "vulnerability exploitability" node, when both the "attack conditions meet" and "similar vulnerabilities are known to be exploitable" parent nodes are "yes", the probability of "vulnerability exploitability is high" obtained through historical data statistics may be 0.8.

[0096] Let A be the child node, B1, B2,…, B n For its parent node, the conditional probability P(A|B1,B2,…,Bn ) means that in the parent node B1, B2, ..., B n The probability of child node A occurring when the state of is known. This probability can be estimated through statistical frequency or based on expert experience. For example, if in the past 100 observations, when B1=true and B2=true, A=true appeared 80 times, then P(A=true|B1=true,B2=true)=0.8.

[0097] 3. Set the evidence nodes according to the constructed Bayesian network structure, and calculate the probability of the key nodes according to the set evidence nodes;

[0098] According to the determined nodes and conditional probability relationships, a directed acyclic graph of the Bayesian network is constructed. In the figure, arrows are used to represent the causal relationship between nodes, and the arrows point from the cause node to the result node. For example, from the "attack condition" node to the "vulnerability exploitability" node to reflect the causal relationship between them. According to the information of the screened known security vulnerabilities and the preliminary understanding of unknown security vulnerabilities, some known evidence nodes are set. For example, if it is known that the screened known security vulnerabilities are easily exploited in a specific system component such as the user authentication module of a power system software, and the module may also be involved in the unknown security vulnerability, then the node state of "involving user authentication module" is set to "yes" as evidence.

[0099] Use the chain rule of the Bayesian network to calculate the probability of other nodes. Suppose the nodes in the Bayesian network are X1, X2, …, X n , the evidence nodes are E1, E2, …, E m (m≤n), we need to calculate the probability of the target node Y. According to the chain rule Where P(Y,E1,E2,…,E m ) can be calculated through the conditional probability table of the Bayesian network and the joint probability distribution between nodes.

[0100] Through probabilistic reasoning, the probability of key nodes related to the exploitation method and impact scope of unknown security vulnerabilities is determined. For example, the probability of the node "unknown security vulnerabilities can lead to system privilege escalation" is calculated to understand the degree of security risk that unknown security vulnerabilities may bring.

[0101] 4. Build a preliminary POC framework for unknown security vulnerabilities based on key node probabilities and screened POC experience of known security vulnerabilities.

[0102] Specifically, the step also includes the following:

[0103] (1) Analyze vulnerability characteristics based on the screened known security vulnerabilities;

[0104] For the known security vulnerabilities that have been screened, we will conduct in-depth research on their characteristics in various aspects. We will look for the commonalities and differences between these known vulnerabilities. The commonalities may include similar affected system components, similar exploit conditions, etc.

[0105] (2) Determine the key elements of the POC framework based on the analyzed vulnerability characteristics;

[0106] Clearly define the goal of building a POC, which is to verify the existence and potential impact of unknown security vulnerabilities. Based on the characteristics of known vulnerabilities, determine the possible attack surface of unknown vulnerabilities. This includes aspects such as network interfaces, user input interfaces, system configuration files, and background service interfaces. Determine the test environment configuration required to verify unknown vulnerabilities. Considering the operating environment and conditions of known vulnerabilities, such as operating system versions, software dependencies, hardware configuration, etc., build a test environment that is as similar as possible.

[0107] (3) Design the vulnerability trigger module, monitoring and verification module, and data collection and analysis module of the POC framework based on the key elements of the POC framework;

[0108] The vulnerability triggering module includes designing methods that may trigger unknown vulnerabilities based on the exploitation methods of known vulnerabilities; for vulnerabilities that may be related to system status or events, designing corresponding event simulation modules. The monitoring and verification module includes establishing a system status monitoring mechanism to monitor the various state changes of the target system in real time after receiving the test input; setting verification points to determine whether the vulnerability is successfully triggered. The data collection and analysis module collects all relevant data during the POC execution process, including the sent test input data, the system response data, the monitored system status data, etc.; and designs data analysis methods.

[0109] (4) Build a preliminary POC framework based on the vulnerability trigger module, monitoring and verification module, and data collection and analysis module for internal testing.

[0110] After the POC framework is initially built, internal testing is carried out. Specifically, some simple simulated vulnerability scenarios are used to verify whether the various modules of the POC framework can work properly, whether the vulnerability trigger module can accurately send test data, whether the monitoring and verification module can effectively capture abnormal changes in the system, and whether the data collection and analysis module can completely collect and correctly analyze data. According to the results of internal testing, the POC framework is optimized.

[0111] S14. Customize the POC development and testing environment based on the preliminary POC framework;

[0112] S15. Verify power system security vulnerabilities through a customized POC development test environment.

[0113] According to the actual hardware composition of the power system, a simulation environment is built; the corresponding parameters are configured for the simulated hardware equipment to make it as close as possible to the hardware performance in the actual power system. On the simulated hardware environment, various software required for the operation of the power system are installed, including operating system, power system monitoring software, power automation control software, database management system and various communication protocol software. Ensure that the installed software version is consistent with the version used in the actual power system, and set the software parameters according to the actual configuration of the power system. Write the corresponding code according to the vulnerability triggering method determined in the preliminary POC framework. Develop the code to monitor and verify whether the vulnerability is successfully triggered. Integrate the data collection and analysis function into the POC, which includes real-time collection and storage of the sent test data, system response data and monitored system status data during the execution of the POC. Based on the known vulnerability information and the preliminary POC framework, design a series of detailed test cases. Each test case should include a specific test scenario description, expected vulnerability triggering conditions, expected system response and verification method. Conduct multiple rounds of vulnerability verification tests. The test environment and POC code can be adjusted between each round of tests based on the test results of the previous round. Comprehensively analyze the execution results of all test cases. Determine which test cases successfully verified the existence of vulnerabilities and which test cases did not achieve the expected results. Analyze the reasons for failure, which may be the absence of vulnerabilities, defects in the POC code, inaccurate configuration of the test environment, etc. Generate a detailed vulnerability verification report based on the test results analysis. The report should include a description of the test environment, details of the POC development, the design and execution of the test cases, the verification results of the vulnerabilities, and suggestions for the discovered vulnerabilities, so as to provide a strong basis and guidance for the safe maintenance and vulnerability repair of the power system.

[0114] Embodiment 2

[0115] An embodiment of a customized POC verification system based on power system security vulnerabilities in the present invention includes the following steps:

[0116] A security vulnerability information collection unit, used to obtain detailed information of the power system to be verified, and collect security vulnerability information corresponding to the power system based on the detailed information;

[0117] A correlation calculation unit, used to calculate the correlation between the unknown security vulnerability and the known security vulnerability using a Pearson correlation coefficient algorithm when the security vulnerability information contains a location security vulnerability;

[0118] A preliminary POC framework determination unit, used to screen known security vulnerabilities that meet the correlation conditions based on the calculated correlation, and determine the preliminary POC framework of unknown security vulnerabilities through a Bayesian network algorithm;

[0119] The POC development and testing environment customization unit is used to customize the POC development and testing environment according to the preliminary POC framework;

[0120] The power system security vulnerability verification unit is used to verify the power system security vulnerabilities through a customized POC development test environment.

[0121] For the specific definition of the system, please refer to the definition of the method above, which will not be repeated here. Each module in the above system can be implemented in whole or in part by software, hardware and a combination thereof. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0122] Embodiment 3

[0123] The present invention provides a computer device, comprising a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the above method are implemented.

[0124] Those of ordinary skill in the art will appreciate that the units of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0125] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored. In addition, each functional unit in each embodiment of the present invention can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units.

[0126] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nlyMemory), random access memory (RAM, RandomAccessMemory), mobile hard disk, magnetic disk or optical disk, etc., which can store program code.

[0127] It can be understood that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.

Claims

1. A custom POC verification method based on power system security vulnerabilities, characterized in that: include: Obtaining detailed information of the power system to be verified, and collecting security vulnerability information corresponding to the power system based on the detailed information; When the security vulnerability information contains a location security vulnerability, the correlation between the unknown security vulnerability and the known security vulnerability is calculated using a Pearson correlation coefficient algorithm; Based on the calculated correlation, known security vulnerabilities that meet the correlation conditions are screened, and a preliminary POC framework of the unknown security vulnerabilities is determined through a Bayesian network algorithm; Customize the POC development and testing environment based on the preliminary POC framework; The power system security vulnerabilities are verified through the customized POC development test environment.

2. The customized POC verification method based on power system security vulnerabilities according to claim 1 is characterized in that: When the security vulnerability information contains a location security vulnerability, the correlation between the unknown security vulnerability and the known security vulnerability is calculated using a Pearson correlation coefficient algorithm, including: Identify variables associated with known security vulnerabilities and variables associated with unknown security vulnerabilities; Calculate the means, covariances, and standard deviations of variables related to known security vulnerabilities and variables related to unknown security vulnerabilities respectively; Pearson correlation coefficient was calculated based on the calculated mean, covariance, and standard deviation; The correlation between the unknown security vulnerability and the known security vulnerability is determined based on the Pearson correlation coefficient.

3. The customized POC verification method based on power system security vulnerabilities according to claim 2 is characterized in that: The respectively calculating the means, covariances and standard deviations of the variables related to the known security vulnerabilities and the variables related to the unknown security vulnerabilities includes: Mean of variables: in: and are the means of known security vulnerability variables and unknown security vulnerability variables, n is the number of samples, X i and Y i They are the i-th known security vulnerability variable and the i-th unknown security vulnerability variable in the sample respectively; Covariance: Where: Cov(X,Y) is the covariance between the known security vulnerability variable X and the unknown security vulnerability variable Y; Standard Deviation: Where: S X and S Y are the standard deviations of the known security vulnerability variable X and the unknown security vulnerability variable Y, respectively.

4. The customized POC verification method based on power system security vulnerabilities according to claim 2 is characterized in that: The calculating of the Pearson correlation coefficient according to the calculated mean, covariance and standard deviation includes: Where: r is the Pearson correlation coefficient.

5. The customized POC verification method based on power system security vulnerabilities according to claim 1 is characterized in that: The calculation-based correlation screening of known security vulnerabilities that meet the correlation conditions, and the determination of the preliminary POC framework of the unknown security vulnerabilities through the Bayesian network algorithm, include: Based on the relevant attributes of unknown security vulnerabilities and the relevant attributes of known security vulnerabilities, the nodes of the Bayesian network include cause nodes and result nodes; Determine the conditional probabilities between nodes and construct a Bayesian network structure based on the conditional probabilities between nodes; Set the evidence nodes according to the constructed Bayesian network structure, and calculate the probability of the key nodes according to the set evidence nodes; A preliminary POC framework for unknown security vulnerabilities is constructed based on the key node probabilities and the screened POC experience of known security vulnerabilities.

6. The customized POC verification method based on power system security vulnerabilities according to claim 1 is characterized in that: The step of setting the evidence nodes according to the constructed Bayesian network structure and calculating the probability of the key nodes according to the set evidence nodes includes: Where: P(Y|E1,E2,…,E m ) is the chain rule, Y is the key node to be calculated, E1, E2, …, E m is the evidence node, P(Y,E1,E2,…,E m ) is the probability of the key node, P(E1,E2,…,E m ) is the probability of the evidence node.

7. The customized POC verification method based on power system security vulnerabilities according to claim 1 is characterized in that: The preliminary POC framework for unknown security vulnerabilities is constructed based on the key node probabilities and the POC experience of known security vulnerabilities, including: Analyze vulnerability characteristics based on screened known security vulnerabilities; Determine the key elements of the POC framework based on the characteristics of the analyzed vulnerabilities; Design the vulnerability trigger module, monitoring and verification module and data collection and analysis module of the POC framework according to the key elements of the POC framework; Based on the vulnerability trigger module, monitoring and verification module, and data collection and analysis module, a preliminary POC framework was built for internal testing.

8. A custom POC verification system based on power system security vulnerabilities, characterized in that: include: A security vulnerability information collection unit, used to obtain detailed information of the power system to be verified, and collect security vulnerability information corresponding to the power system based on the detailed information; A correlation calculation unit, used for calculating the correlation between the unknown security vulnerability and the known security vulnerability by using the Pearson correlation coefficient algorithm when the security vulnerability information contains a location security vulnerability; A preliminary POC framework determination unit, used to screen known security vulnerabilities that meet the correlation conditions based on the calculated correlation, and determine the preliminary POC framework of the unknown security vulnerability through a Bayesian network algorithm; A POC development and testing environment customization unit, used to customize the POC development and testing environment according to the preliminary POC framework; The power system security vulnerability verification unit is used to verify the power system security vulnerability through the customized POC development test environment.

9. A computer device, characterized in that: include: memories, transceivers, processors, and bus systems; Wherein, the memory is used to store programs; The processor is used to execute the program in the memory, including executing the customized POC verification method based on power system security vulnerabilities according to any one of claims 1 to 7; The bus system is used to connect the memory and the processor so that the memory and the processor can communicate with each other.

10. A readable storage medium, characterized in that: The method comprises instructions which, when executed on a computer, enable the computer to execute the steps of the customized POC verification method based on power system security vulnerabilities as claimed in any one of claims 1 to 7.