Network security early warning method, device, equipment and system for transformer substation

By collecting and preprocessing the mirror traffic of the secondary equipment communication network of the substation and identifying and generating risk alarm events, the problems of manual configuration dependence and communication protocol-level security identification in the existing technology are solved, and efficient network security monitoring and protection are achieved.

CN119945741AActive Publication Date: 2025-05-06STATE GRID HEILONGJIANG ELECTRIC POWER COMPANY +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411962246.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-06
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

The network security monitoring system of existing substations relies on manual configuration and debugging, resulting in inefficient risk monitoring and inability to effectively identify and deal with network security issues at the communication protocol level.

Method used

By collecting the mirror traffic of the network center switch and the dispatching data network switch connected to multiple asset devices in the substation secondary equipment communication network, preprocessing is performed to extract network traffic data, extracting and identifying power communication application protocols, equipment asset data, data traffic and ports respectively, and generating risk alarm events.

Benefits of technology

It has improved the real-time security monitoring of the secondary equipment communication network of the substation, improved the network security protection capabilities, simplified equipment access and asset management, and saved operation and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945741A_ABST
    Figure CN119945741A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of transformer substation network detection, and provides a network security early warning method, device, equipment and system for a transformer substation, and the method comprises the steps: collecting the mirror image traffic of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in a communication network of secondary equipment of the transformer substation, obtaining original network flow data of the plurality of asset devices, and preprocessing the original network flow data to obtain network flow data of the plurality of asset devices; respectively extracting a power communication application protocol, equipment asset data, data traffic and ports in the network traffic data, and identifying to obtain multiple pieces of risk data in the substation secondary equipment network; according to the invention, multiple risk data are integrated, multiple risk alarm events are generated, and the problems that the risk monitoring efficiency is low and the network security of a communication protocol level cannot be effectively identified and processed due to the fact that an existing transformer substation network security monitoring system depends on manual configuration debugging are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of substation network detection, and in particular, relates to a network security early warning method, device, equipment and system for a substation. Background Art

[0002] At present, with the development of digitalization and intelligence of power systems, network security issues of substations are becoming increasingly prominent. As an important part of the power system, various secondary devices in the substation system need to communicate and control through the network. Therefore, network security identification and early warning of substations are particularly important. Deploying network security monitoring software and equipment for substations is one of the important means to ensure network security of substations.

[0003] The existing network security monitoring system of substation mainly uses traditional network security equipment for network security protection and monitoring, such as firewalls, intrusion detection systems, etc. to ensure the security of power networks. However, these network security devices usually require complex configuration and management when in use. For example, firewall devices need to configure specific firewall policies for network environments; security situation awareness and network security monitoring devices need to configure the monitoring object's communication protocol, communication address, device type and other asset configuration information on the monitoring device. At the same time, the monitored asset equipment also needs to configure the monitoring equipment's communication address and protocol to finally achieve the final substation security monitoring. Therefore, these complex configurations and management increase the user's operation and maintenance burden and reduce the ease of use of the network security monitoring system of the substation. Secondly, these network security devices deployed in substations often only monitor the security risks of some important asset equipment in the substation secondary equipment network, such as switch equipment, workstation equipment, security equipment, etc. Most of the other secondary equipment in the substation, such as relay protection equipment, measurement and control equipment, are not supervised, and the network security of the entire station's secondary equipment is not monitored. Finally, the existing network security monitoring system of substations cannot effectively identify and handle new network attacks at the communication protocol level. Summary of the invention

[0004] The embodiments of the present application provide a network security early warning method, device, equipment and system for a substation, which can solve the problem that the existing network security monitoring system of a substation has low risk monitoring efficiency due to reliance on manual configuration and debugging, and cannot effectively identify and process network security at the communication protocol level.

[0005] In a first aspect, an embodiment of the present application provides a network security early warning method for a substation, the method comprising:

[0006] Collect the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices;

[0007] Preprocessing the original network traffic data to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value and backup storage data;

[0008] Extract the power communication application protocol, equipment asset data, data flow and port in the network flow data respectively, and identify multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data;

[0009] The plurality of risk data are integrated and processed to generate a plurality of risk warning events.

[0010] In a possible implementation of the first aspect, respectively extracting the power communication application protocol, the equipment asset data, the data flow and the port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network includes:

[0011] According to the data flow table, identifying power communication application protocol types of multiple data flows;

[0012] According to the power communication application protocol type and preset protocol decoding rules, the power communication application protocol of multiple data streams in the substation secondary equipment communication network is decoded by instruction set;

[0013] If the decoding fails, the protocol risk data is obtained;

[0014] If the decoding is successful, the protocol decoding results corresponding to the power communication application protocols of the multiple data streams are obtained, and the multiple protocol decoding results are matched with the preset protocol security rules to identify the multiple communication protocol risk data in the substation secondary equipment communication network.

[0015] In a possible implementation of the first aspect, respectively extracting the power communication application protocol, the equipment asset data, the data flow and the port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network includes:

[0016] Extracting source ports and destination ports of multiple data flows according to the data flow table;

[0017] The source ports and destination ports of the plurality of data flows are matched with preset high-risk port rules to identify and obtain the port risk data in the substation secondary equipment communication network.

[0018] In a possible implementation of the first aspect, respectively extracting the power communication application protocol, the equipment asset data, the data flow and the port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network includes:

[0019] Through multiple preset dimensions, the data flow value is compared with multiple preset flow safety thresholds to identify multiple flow risk data in the substation secondary equipment communication network; wherein, the multiple preset dimensions include at least one of the following: the total flow value of network flow data, the receiving and sending flow value of each asset equipment, and the communication data flow value between asset equipment.

[0020] In a possible implementation of the first aspect, respectively extracting the power communication application protocol, the equipment asset data, the data flow and the port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network includes:

[0021] Obtaining a source Internet Protocol address and a source physical address of a data flow from a data flow communicated between a plurality of the asset devices in the data flow table or from a reply data flow received after actively sending an asset detection ARP request;

[0022] According to the source Internet Protocol address and the source physical address, the device asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein the device asset data includes the asset Internet Protocol address and the asset physical address;

[0023] Identify multiple suspected asset data in the equipment asset data to obtain multiple asset risk data in the substation secondary equipment communication network; wherein the suspected asset data include: data on changes in the physical address corresponding to the asset Internet Protocol address, data on newly added asset Internet Protocol addresses, and data on newly added asset physical addresses.

[0024] In a possible implementation manner of the first aspect, the method further includes:

[0025] Sending asset detection ARP requests to the plurality of asset devices according to a preset rate;

[0026] When a plurality of ARP reply messages sent by a plurality of the asset devices are received, the asset Internet Protocol addresses and asset physical addresses of the plurality of the asset devices in the plurality of the ARP reply messages are added to the device asset data.

[0027] In a possible implementation manner of the first aspect, when receiving multiple ARP reply messages sent by multiple asset devices, after adding the asset Internet Protocol addresses and asset physical addresses of the multiple asset devices to the device asset data, the method further includes:

[0028] Comparing the source Internet Protocol address in the data flow table with the asset Internet Protocol addresses of the plurality of asset devices in the plurality of ARP reply messages;

[0029] If there is an asset Internet Protocol address in the ARP reply information that is the same as the source Internet Protocol address, it is determined that the asset device corresponding to the source Internet Protocol address has been detected;

[0030] If all the asset Internet Protocol addresses in the ARP reply information are different from the source Internet Protocol address, the source physical address and source Internet Protocol address in the data flow table are added to the device asset data to obtain updated device asset data.

[0031] In a possible implementation manner of the first aspect, the method further includes:

[0032] Perform port scanning on multiple asset devices in the substation secondary equipment communication network according to a preset scanning method through the network mapper Nmap, and identify multiple open ports; wherein the preset scanning method includes: a point-to-point port scanning method and a specified port range fast scanning method;

[0033] The plurality of open ports are matched with preset high-risk port rules to identify and obtain the port risk data in the substation secondary equipment communication network.

[0034] In a possible implementation manner of the first aspect, after generating multiple risk warning events, the method further includes:

[0035] According to the risk warning event, extract the data flow information corresponding to the risk warning event; wherein the data flow information includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port and power communication application protocol of the data flow;

[0036] Extracting, from the backup storage data, a plurality of message records corresponding to the risk warning event according to the data flow information;

[0037] Aggregate the plurality of message records to generate an alarm data record corresponding to the risk alarm event.

[0038] In a possible implementation manner of the first aspect, after generating multiple risk warning events, the method further includes:

[0039] A plurality of risk warning events are displayed and a voice alarm is issued.

[0040] In a second aspect, an embodiment of the present application provides a network security early warning device for a substation, the device comprising:

[0041] An acquisition module is used to collect the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices;

[0042] A processing module, used for preprocessing the original network flow data to obtain network flow data of a plurality of asset devices, wherein the preprocessing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value and backup storage data;

[0043] An identification module is used to extract the power communication application protocol, equipment asset data, data flow and port in the network flow data respectively, and identify and obtain multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, and port risk data;

[0044] The generating module is used to integrate and process the plurality of risk data to generate a plurality of risk warning events.

[0045] In a third aspect, an embodiment of the present application provides a network security warning device for a substation, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any of the above-described network security warning methods for the substation when executing the computer program.

[0046] In a fourth aspect, an embodiment of the present application provides a network security early warning system for a substation, the system comprising: a network security early warning device for the substation, a plurality of network center switches, a plurality of dispatching data network switches and a plurality of asset devices; wherein,

[0047] The multiple first physical network ports of the network security early warning device of the substation are connected to the mirror ports of the multiple network center switches; the multiple second physical network ports of the network security early warning device of the substation are connected to the mirror port of the dispatching data network switch; the multiple asset devices are directly or indirectly connected to the communication ports of the multiple network center switches and the communication ports of the multiple dispatching data network switches respectively;

[0048] The network security early warning device of the substation is used to obtain the original network flow data of multiple asset equipment in the substation secondary equipment communication network from the mirror ports of multiple network center switches and multiple dispatching data network switches; pre-process the original network flow data to obtain the network flow data of multiple asset equipment, wherein the pre-processing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value, backup storage data; and, respectively extract the power communication application protocol, equipment asset data, data flow and port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; and, integrate and process multiple risk data to generate multiple risk warning events; and, also used to detect multiple asset equipment from the communication ports of multiple network center switches and scan the open ports of multiple asset equipment.

[0049] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the network security early warning method for a substation described in any one of the above items is implemented.

[0050] In a sixth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a terminal device, the terminal device executes the network security early warning method for a substation described in any one of the above-mentioned first aspects.

[0051] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0052] The embodiment of the present application provides a network security early warning method for a substation, which collects the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the communication network of the secondary equipment of the substation, and obtains the original network traffic data of multiple asset devices; pre-processes the original network traffic data to obtain the network traffic data of multiple asset devices, wherein the pre-processing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value, backup storage data; respectively extracts the power communication application protocol, equipment asset data, data traffic and port in the network traffic data, and identifies multiple risk data in the communication network of the secondary equipment of the substation; wherein the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, port risk data; finally, integrates and processes multiple risk data to generate multiple risk alarm events. This method solves the problem that the existing network security monitoring system of the substation is inefficient due to its reliance on manual configuration and debugging, and cannot effectively identify and process the network security at the communication protocol level, thereby improving the real-time security monitoring of the communication network of the secondary equipment of the substation and improving the network security protection capability. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0054] Figure 1 It is a flow chart of a network security early warning method for a substation provided by an embodiment of the present application;

[0055] Figure 2 It is a schematic diagram of risk data identification in a substation secondary equipment communication network provided by an embodiment of the present application;

[0056] Figure 3 It is a schematic diagram of a flow chart of updating the flow direction identification of a data flow provided by an embodiment of the present application;

[0057] Figure 4 This is a flowchart of asset equipment discovery provided by an embodiment of the present application;

[0058] Figure 5 This is a flowchart of asset device discovery provided by another embodiment of the present application;

[0059] Figure 6This is a flow chart of a risk warning event output provided by an embodiment of the present application;

[0060] Figure 7 It is a structural schematic diagram of a network security early warning device for a substation provided by an embodiment of the present application;

[0061] Figure 8 It is a structural schematic diagram of a network security early warning device for a substation provided by an embodiment of the present application;

[0062] Fig. 9 It is a structural diagram of a network security early warning system for a substation provided by an embodiment of the present application;

[0063] Fig.10 This is a schematic diagram of a human-machine interface of a network security early warning device for a substation provided by an embodiment of the present application;

[0064] Fig.11 This is a system architecture diagram of a network security early warning device for a substation provided in one embodiment of the present application. DETAILED DESCRIPTION

[0065] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0066] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0067] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0068] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.

[0069] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0070] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0071] See also Figure 1 , Figure 1 This is a flow chart of a network security early warning method for a substation provided by an embodiment of the present application. The method includes:

[0072] S11, collecting the mirrored traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices;

[0073] S12, preprocessing the original network flow data to obtain network flow data of multiple asset devices, wherein the preprocessing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value and backup storage data;

[0074] S13, respectively extracting the power communication application protocol, equipment asset data, data flow and port in the network flow data, and identifying multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, and port risk data;

[0075] S14. Integrate and process multiple risk data to generate multiple risk warning events.

[0076] It should be noted that in this embodiment, the execution subject may be a terminal device such as a server, which is not specifically limited. The network security early warning method of the substation is mainly applied to the secondary equipment communication network of the substation, and is used to warn the communication network security of the secondary equipment of the substation.

[0077] The substation secondary equipment communication network refers to the network composed of equipment used for control, protection, measurement and other functions in the substation secondary system. These devices do not directly participate in the conversion and distribution of electric energy, but monitor, control and protect the operating status of the substation secondary system, which is crucial to the safe and reliable operation of the substation secondary system, such as relay protection and monitoring devices, measurement and control devices, communication equipment, etc. Asset equipment refers to various hardware equipment and software resources in the substation secondary equipment network, such as measurement and control devices, workstations, recorders, monitoring machines, etc.

[0078] The network center switch refers to a key device used to directly or indirectly connect multiple asset devices in the substation secondary equipment network, which is responsible for forwarding data traffic in the network. The dispatching data network switch transmits network traffic data from the substation to a higher-level network or data center. By setting the mirror traffic function on the network center switch and the dispatching data network switch, all data traffic passing through these switches can be collected in real time. Mirror traffic refers to the traffic obtained by copying the data traffic of a certain port of the network center switch or the dispatching data network switch through the mirror traffic function, that is, the original network traffic data. The original network traffic data is mainly used for subsequent traffic analysis and risk monitoring. Since the original network traffic data contains all the data traffic information in the substation secondary equipment network, it may also contain redundant, erroneous or irrelevant data. Therefore, a series of preprocessing operations are required for the original network traffic data to extract useful information, so as to obtain more accurate and useful network traffic data. Among them, preprocessing mainly includes data flow table processing, data traffic statistics processing and data backup storage processing.

[0079] Specifically, first, the mirror traffic function is set on the network center switch in the substation secondary equipment network, and the data traffic of the port where the asset equipment to be monitored is located is copied to the designated mirror port. Through the panoramic traffic collection and analysis technology, the data traffic on the mirror port is collected to obtain the original network traffic data. After that, the original network traffic data is preprocessed to extract useful information and obtain network traffic data.

[0080] Specifically, (1) data flow table processing is performed on the original network traffic data, that is, data flow table processing such as parsing and classifying the data flow in the original network traffic data is performed to generate a corresponding data flow table. The data flow table can accurately locate and record the data interaction flow direction of each asset device in the network. When the substation secondary equipment network is running stably, the data flow direction between asset devices is basically stable. By saving and recording stable data flows, newly emerging unsafe flow table data and unsafe asset risk data and port risk data can be identified. (2) Data flow statistics processing is performed on the original network traffic data, that is, statistics and analysis are performed on the data flow of multiple dimensions such as the total flow value of network traffic data, the receiving and sending flow value of each asset device, and the communication data flow value between multiple asset devices in the original network traffic data to obtain data flow values ​​that describe key indicators such as the rate and size of data flow, so as to identify traffic risk data such as network traffic overload and network storm attack in the substation secondary equipment network. (3) Data backup and storage processing is performed on the original network traffic data, that is, the original network traffic data is backed up and stored for subsequent analysis such as data recovery and troubleshooting of security risk events. At the same time, a secure disk storage policy is set for storage. When the storage capacity exceeds the disk storage space threshold, the old traffic data will be cyclically overwritten. It should be understood that by preprocessing the original network traffic data, more accurate and useful network traffic data can be obtained, providing strong support for subsequent security analysis and early warning.

[0081] Network traffic data refers to the network traffic transmitted by each asset equipment in the substation secondary equipment network, mainly including data flow table, data traffic value, and backup storage data. The data flow table mainly includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port and application protocol, which are used to describe the detailed information such as the source and destination of the data flow; the data traffic value is mainly used to describe the rate and flow size of the data flow; the backup storage data is mainly the data for backing up and storing the network traffic, which is used for subsequent analysis of security risk events.

[0082] Risk data refers to data that may threaten network security that is identified in network traffic data. The risk data includes but is not limited to asset risk data, traffic risk data, communication protocol risk data, and port risk data. Among them, asset risk data refers to risk data of equipment anomalies and configuration errors in asset equipment, such as newly added equipment and changes in the Internet Protocol address of asset equipment; traffic risk data refers to risk data such as traffic overload and abnormal traffic patterns in network traffic; communication protocol risk data refers to risk data such as the use of unsafe protocols, protocol vulnerabilities, device configuration file transmission, and device control type operations during data transmission; port risk data refers to risk data such as prohibition of opening security ports and high-risk ports. Usually, the power communication protocol, data traffic, port and other data extracted from the network traffic data are compared with the preset security rules to identify risk data, among which the preset security rules are pre-set security rules for detecting abnormal behavior or potential threats in the network.

[0083] Integration processing is to merge, classify, analyze and process multiple risk data in order to gain a clearer understanding of network security. Risk warning events are warning information generated based on risk data after integration processing.

[0084] Specifically, first, the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network is collected to obtain the original network traffic data of multiple asset devices; then, the original network traffic data is pre-processed by data flow table processing, data traffic statistics processing and data backup storage processing to obtain the network traffic data of all asset devices in the substation secondary equipment communication network; then, the power communication application protocol, equipment asset data, data traffic and port in the pre-processed network traffic data are extracted to identify the risk data in the network traffic data, which may involve multiple aspects such as assets, traffic, communication application protocols and ports; finally, the identified risk data is integrated and processed to obtain clear and specific risk warning events. These risk warning events can help administrators quickly locate and resolve potential security threats.

[0085] It can be understood that the network security early warning method of the substation provided in this embodiment collects the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the communication network of the secondary equipment of the substation, and obtains the original network traffic data of multiple asset devices; pre-processes the original network traffic data to obtain the network traffic data of multiple asset devices, wherein the pre-processing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value, backup storage data; respectively extracts the power communication application protocol, equipment asset data, data traffic and port in the network traffic data, and identifies multiple risk data in the communication network of the secondary equipment of the substation; wherein the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, port risk data; finally, integrates and processes multiple risk data to generate multiple risk alarm events. This method solves the problem that the existing network security monitoring system of the substation is inefficient due to its reliance on manual configuration and debugging, and cannot effectively identify and process the network security at the communication protocol level, thereby improving the real-time security monitoring of the communication network of the secondary equipment of the substation and improving the network security protection capability. At the same time, this method also improves the system's usability, reusability and deployment efficiency, reduces the user's operating burden, and thus saves operation and maintenance costs.

[0086] In a possible implementation, the power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including:

[0087] According to the data flow table, the power communication application protocol types of the multiple data flows are identified;

[0088] According to the power communication application protocol type and preset protocol decoding rules, the power communication application protocol of multiple data streams in the substation secondary equipment communication network is decoded by instruction set;

[0089] If the decoding fails, the protocol risk data is obtained;

[0090] If the decoding is successful, the protocol decoding results corresponding to the power communication application protocols of multiple data streams are obtained, and the multiple protocol decoding results are matched with the preset protocol security rules to identify multiple communication protocol risk data in the substation secondary equipment communication network.

[0091] It should be noted that the power communication application protocol type is the type of network protocol used by the data stream during data transmission, such as the substation communication network standard protocol IEC104, IEC61850 and the Internet's commonly used system log protocol (SYSLOG), simple network management protocol (SNMP), file transfer protocol (FTP), secure file transfer protocol (SFTP), etc. Different power communication application protocols correspond to different instruction sets and communication rules. The preset protocol decoding rules are decoding rules set for different power communication application protocol types, which are used to decode the data packets of the power communication application protocol into different instruction sets. Among them, the preset protocol decoding rules are usually message formats set based on standard documents of different protocols or known security vulnerabilities. The instruction set decoding process is to match the data structure, field, and byte stream according to the message format defined by each preset protocol decoding rule to identify dangerous operations in the power communication application protocol, such as remote control, remote adjustment, and setting value modification in the IEC104 and IEC61850 protocols; important equipment log record transmission operations in the SYSLOG protocol; equipment status query, equipment parameter configuration, and network fault diagnosis in the SNMP protocol; file transfer operations in the SFTP and FTP protocols, etc.; it can also identify whether the power communication application protocol that is not allowed to be used in the substation appears in the substation secondary equipment network, such as the Hypertext Transfer Protocol HTTP and other protocols, to monitor attack behaviors at the network communication protocol level. Communication protocol risk data is the potential security risks related to the power communication application protocol identified in the network traffic data, such as the use of unsafe protocols, protocol vulnerabilities, illegal data operations, etc. The preset protocol security rules are pre-set rules for detecting whether there are security risks related to the power communication application protocol in the network traffic data.

[0092] Specifically, Figure 2 As shown, Figure 2 FIG. 1 is a schematic diagram of risk data identification in a substation secondary equipment communication network provided by an embodiment of the present application. Figure 2As shown in, it includes in-depth analysis of power communication application protocols such as MMS (IEC61850) protocol, IEC104 protocol, FTP protocol, etc.; it also includes identifying dangerous communication protocols that are not allowed to be used in power communication, such as HTTP protocol identification; and matching with the corresponding preset protocol security rules. First, the data flow table is parsed, and the type of power communication application protocol used by each data flow is identified according to the protocol field in the data flow table; then, based on the identified power communication application protocol type, the data flow of the power communication application protocol type is decoded according to the preset protocol decoding rules to extract the instruction set and related information in the data flow; at this time, if the decoding fails, that is, a data flow that cannot be decoded is encountered during the decoding process or the data flow does not conform to the format of the preset protocol decoding rules, it indicates that these data flows may be tampered with, unknown protocols are used, or there are other security risks, and these data flows are regarded as communication protocol risk data; if the decoding is successful, the protocol decoding results corresponding to the power communication application protocol of each data flow will be obtained; by matching these protocol decoding results with the preset protocol security rules, if the protocol decoding results are the same as the preset protocol security rules, it indicates that unsafe instructions are used, and these data flows are regarded as communication protocol risk data.

[0093] It should be understood that through in-depth analysis of the power communication application protocol, potential security risks related to the power communication application protocol in the substation secondary equipment communication network can be identified, providing strong support for subsequent security response and protection.

[0094] In a possible implementation, the power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including:

[0095] According to the data flow table, the source ports and destination ports of multiple data flows are extracted;

[0096] The source ports and destination ports of multiple data streams are matched with the preset high-risk port rules to identify the port risk data in the substation secondary equipment communication network.

[0097] It should be noted that the source port is the starting port of the data stream, and the destination port is the target port of the data stream. The source port is usually used to identify the asset device that sends the data stream, and the destination port is used to identify the asset device that receives the data stream. The preset high-risk port rules are pre-set security rules for identifying high-risk ports that may exist in network traffic. These preset high-risk port rules are set based on known security vulnerabilities, attack patterns, etc. Port risk data is security risk data related to ports identified in network traffic data. This data may involve potential security risks such as using high-risk ports for communication or port scanning.

[0098] In this embodiment, Figure 2 As shown, the source port and destination port of the data flow are obtained from the data flow table, and matched with the built-in preset high-risk port rules, and the common high-risk ports appearing in the network traffic data in the substation secondary equipment communication network are monitored in real time to identify the common high-risk ports. Common high-risk ports may include 23, 25, 53, 80, 135, 137, 138, 139, 443, 445, 3389, 5901, etc.

[0099] It should be understood that the above method can identify potential security risks related to ports in the network traffic data of the substation secondary equipment communication network, provide strong support for subsequent security response and protection, and thus protect the safe and stable operation of the substation secondary equipment communication network.

[0100] In a possible implementation, the power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including:

[0101] Through multiple preset dimensions, the data flow value is compared with multiple preset flow safety thresholds to identify multiple flow risk data in the substation secondary equipment communication network; wherein, the multiple preset dimensions include at least one of the following: the total flow value of network flow data, the receiving and sending flow value of each asset equipment, and the communication data flow value between asset equipment.

[0102] It should be noted that the preset dimensions are pre-set angles for evaluating the security of network traffic values, mainly including the total traffic value of network traffic data, the receiving and sending traffic value of each asset device, and the data traffic value of communication between asset devices. Among them, the total traffic value of network traffic data is the sum of all data traffic in the communication network of the secondary equipment of the substation, reflecting the overall traffic situation in the network; the receiving and sending traffic value of each asset device is the traffic size of the data stream sent and received by a single asset device in the communication network of the secondary equipment of the substation, reflecting the network activity of a single asset device; the data traffic value of communication between asset devices is the traffic size of the data stream communicated between different asset devices, reflecting the interaction between asset devices. The preset traffic security threshold is a pre-set safety value of the traffic value, which is used to determine whether the network traffic is within the normal range. Traffic risk data is traffic-related security risks identified in network traffic data, such as traffic overload, abnormal traffic patterns, etc.

[0103] Specifically, the total network traffic data value, the receiving and sending traffic value of each asset device, and the communication data traffic value between production devices are obtained from the data traffic value, and these data traffic values ​​are compared with the preset traffic security thresholds of the corresponding dimensions. If the traffic value on a preset dimension exceeds the corresponding preset traffic security threshold, it indicates that there is a traffic risk, which is used as traffic risk data.

[0104] It should be understood that the above method can achieve real-time monitoring and identification of traffic risks in the substation secondary equipment communication network, which helps to promptly detect and respond to possible traffic attacks or abnormal behaviors, thereby ensuring the safe and stable operation of the substation secondary equipment communication network.

[0105] In a possible implementation, the power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including:

[0106] Obtain the source Internet Protocol address and source physical address of the data flow from the data flow communicated between multiple asset devices in the data flow table or from the reply data flow received after actively sending an asset detection ARP request;

[0107] According to the source Internet Protocol address and the source physical address, the equipment asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein the equipment asset data includes the asset Internet Protocol address and the asset physical address;

[0108] Multiple suspected asset data in the equipment asset data are identified to obtain multiple asset risk data in the substation secondary equipment communication network; wherein, the suspected asset data include: data of changes in the physical address corresponding to the asset Internet Protocol address, data of newly added asset Internet Protocol addresses, and data of newly added asset physical addresses. It should be noted that the source Internet Protocol address (source IP address) is the starting point of the data flow in the network, which is used to identify the device that sends the data flow; the source physical address (source MAC address) is the physical address of the starting device of the data flow in the network, which is usually used for network layer communication. The equipment asset data is the detailed information of each asset device in the substation secondary equipment network, including the asset Internet Protocol address, asset physical address and other information of the asset device. Suspected asset data is abnormal information related to the asset device identified in the network traffic data, such as the asset Internet Protocol address of the newly added asset device, the asset physical address of the newly added asset device, and the change in the physical address corresponding to the asset Internet Protocol address. The preset asset security rules are pre-set rules for detecting whether there are security risks related to the asset device in the network traffic data. The asset risk data is the actual risk information related to the asset device determined after comparing the suspected asset data with the actual asset device.

[0109] It should be noted that the detection of asset equipment mainly includes active request detection method and passive identification detection method. Among them, the active request detection method is to obtain the source IP address and source MAC address by regularly sending asset detection ping requests or ARP requests, so as to actively detect assets in the network; the passive identification detection method is to obtain and analyze network traffic data, extract the source IP address and source MAC address of the data flow between multiple asset equipment in the data flow table for asset discovery. The two methods are combined to detect and discover the assets of asset equipment in the communication network of substation secondary equipment, automatically generate and save the equipment asset data of asset equipment (including asset IP address, asset MAC address and other information), so that managers can confirm the number of assets in the communication network and basic communication five-tuple information.

[0110] Specifically, first, the source Internet Protocol address and source physical address of the data flow are obtained from the data flow of communication between multiple asset devices in the data flow table or the reply data flow received after actively sending the asset detection ARP request; then, based on the information such as the source IP address and the source MAC address, each asset device in the substation secondary equipment communication network is identified, and data about these asset devices are collected to form equipment asset data; then, in the subsequent operation, the status of each asset device is monitored in real time, and data such as the newly added asset Internet Protocol address, the newly added asset physical address, and the change of the physical address corresponding to the asset Internet Protocol address in the equipment asset data are extracted. These changes may be that unauthorized devices are connected to the network, or that devices are illegally replaced. These changes are regarded as suspected asset data; finally, the suspected asset data is compared with the actual asset devices in the communication network. If these suspected asset data do not match the asset Internet Protocol address and asset physical address of the actual asset devices in the communication network, they are regarded as asset risk data.

[0111] It should be understood that the above method can achieve real-time monitoring and risk assessment of asset equipment in the substation secondary equipment communication network, which helps to timely discover and respond to possible asset safety risks, thereby ensuring the safe and stable operation of the substation secondary equipment communication network.

[0112] It should be noted that in this embodiment, the transport layer protocol is tracked and analyzed using a flow table, the source port and destination port of the data flow are extracted, and a data flow table is established, as well as all network connections in the network are tracked, and the flow direction of the data flow is identified based on the three-way handshake information of the TCP connection, thereby obtaining the network port information to determine the high-risk port. At the same time, the flow information of each data flow is updated, and traffic statistics based on the data flow are performed. If the current data flow is discovered for the first time, the application protocol identification process is performed, and the application protocol is saved in the data flow table after the identification is completed. After the identification is completed, the flow table no longer needs to perform protocol identification. If an application protocol that is not allowed to appear is identified, protocol risk data is generated. However, the IEC104 protocol and IEC61850 protocol commonly used in power systems are both long connection protocols. When the system accesses the mirror port, it is usually unable to obtain the three-way handshake information of the TCP connection, so it is impossible to determine the flow direction of the data flow based on the three-way handshake message of the TCP connection. However, the flow direction is particularly important in high-risk port determination, asset type identification, topology generation, etc. Therefore, in this embodiment, the flow direction is accurately identified and the flow table is updated based on the communication message characteristics of the client / server in the IEC104 protocol and IEC61850 protocol communication connection.

[0113] The specific implementation method is as follows Figure 3 As shown, Figure 3FIG. 1 is a flow chart of updating the flow direction identification of a data flow provided by an embodiment of the present application. Figure 3 As shown in , the original message of the IEC104 protocol or the IEC61850 protocol is decoded, and then it is determined whether the flow direction of the data flow has been determined. If the flow direction of the data flow is not determined, the direction of the data flow is determined according to the ASDU type or the PDU type. If the direction of the data flow is consistent with the direction in the data flow table, the flow direction is marked; if the flow direction of the data flow is inconsistent with the flow direction in the data flow table, the flow direction in the data flow table is updated and the flow direction is marked. When judging the direction of data flow based on ASDU type or PDU type, for IEC104 protocol communication, different ASDU types are used for monitoring direction (S->C) and control direction (C->S). The IEC104 protocol communication message is deeply parsed, and the flow direction can be accurately identified by ASDU type (for example: ASDU type 1 is a monitoring direction message, and ASDU type 45 is a control direction message); for IEC61850 protocol communication, the confirmedRequestPDU in the protocol is the control direction (C->S), and the confirmedResponsePDU and unconfirmedPDU are the monitoring direction (S->C). The flow direction is accurately identified according to the parsed PDU type. After the flow direction is updated, the system will mark it, and there is no need to identify the data flow with a clear direction again. Through the decoding and analysis of the application protocol data, the specific application operations in the power communication application protocol are identified, including the remote control operation of the substation secondary equipment communication network by the local / remote client, the configuration download operation, the equipment setting value modification operation and other important operation behaviors are risk-warned.

[0114] In a possible implementation, the network security early warning method of the substation further includes:

[0115] Send asset detection ARP requests to multiple asset devices at a preset rate;

[0116] When multiple ARP reply messages sent by multiple asset devices are received, the asset Internet Protocol addresses and asset physical addresses of the multiple asset devices in the multiple ARP reply messages are added to the device asset data.

[0117] It should be noted that, in this embodiment, the detection of asset equipment includes not only passive identification detection for asset identification by obtaining and analyzing the source IP address in the network traffic data, but also active request detection for asset identification by periodically sending asset detection requests (ARP or ping).

[0118] The preset rate is the frequency of sending asset detection ARP requests in advance. Asset detection ARP requests are requests for the MAC address corresponding to the IP address of a device in the network. ARP reply information is the information that the asset device replies when it receives an ARP request. The ARP reply information contains the asset IP address and asset MAC address of the asset device.

[0119] Specifically, Figure 4 As shown, Figure 4 It is a flowchart of asset equipment discovery provided by an embodiment of the present application. Figure 4 In the process, when the active detection mode is turned on in the network security early warning system of the substation, the current network segment information is read, and asset detection ARP requests are sent to multiple asset devices at a preset rate (the default rate is 10 packets per second), and the ARP reply information sent by multiple asset devices is received, and the asset IP address and asset MAC address information of the asset device in the ARP reply information are added to the device asset data in the database. It should be noted that this method is only performed when the active detection mode of the network security early warning system of the substation is turned on by manual settings.

[0120] It should be understood that the above method can be used to update equipment asset data regularly or as needed to ensure that the latest information of all asset equipment in the substation secondary equipment communication network can be obtained to maintain the safe and stable operation of the substation secondary equipment communication network.

[0121] In a possible implementation, when receiving multiple ARP reply messages sent by multiple asset devices, after adding the asset Internet Protocol addresses and asset physical addresses of the multiple asset devices to the device asset data, the network security early warning method of the substation further includes:

[0122] comparing a source Internet Protocol address in the data flow table with asset Internet Protocol addresses of a plurality of asset devices in a plurality of ARP reply messages;

[0123] If there is an asset Internet Protocol address in the ARP reply information that is the same as the source Internet Protocol address, it is determined that the asset device corresponding to the source Internet Protocol address has been detected;

[0124] If all asset Internet Protocol addresses in the ARP reply information are different from the source Internet Protocol address, the source physical address and source Internet Protocol address in the data flow table are added to the device asset data to obtain updated device asset data.

[0125] Specifically, Figure 5 As shown, Figure 5 FIG. 1 is a flowchart of asset device discovery provided by another embodiment of the present application. Figure 5As shown, the source MAC address and source IP address are extracted from the obtained network traffic data, and illegal IP addresses such as local loopbacks and multicast addresses are filtered out. If there is an asset IP address in the ARP reply information that is the same as the source IP address, it is determined that the asset device with the same IP address has been actively detected and discovered, and the activity time of the asset device is updated; if all asset Internet Protocol addresses in the ARP reply information are different from the source Internet Protocol address, the source IP address and source MAC address are added to the device asset data, thereby obtaining updated device asset data.

[0126] It should be understood that the above method can accurately identify and track asset equipment in the substation secondary equipment communication network to ensure the integrity and accuracy of equipment asset data.

[0127] In a possible implementation, the network security early warning method of the substation further includes:

[0128] Through the network mapper Nmap, multiple asset devices in the substation secondary equipment communication network are port scanned according to the preset scanning method, and multiple open ports are identified; wherein the preset scanning methods include: point-to-point port scanning method, and designated port range fast scanning method;

[0129] Multiple open ports are matched with preset high-risk port rules to identify port risk data in the substation secondary equipment communication network.

[0130] It should be noted that the network mapper Nmap is an open source network scanning and security auditing tool. Nmap can scan hosts on the network and list their open ports and services. The preset scanning method is the scanning method that needs to be set before performing a port scan. The preset scanning methods mainly include point-to-point port scanning method and specified port range fast scanning method. Among them, the point-to-point port scanning method performs port scanning on asset devices at a slower rate to ensure that the port scan will not affect the entire operation of the device; the specified port range fast scanning method is to achieve fast scanning by specifying a port range or specific common ports. Both methods can discover the service ports open to asset devices in the network, thereby identifying high-risk service ports.

[0131] Specifically, when the active detection mode is turned on in the network security early warning system of the substation, the system will read the equipment asset data in the database, perform port scans on the asset equipment in turn through the network mapper Nmap, save the scan results in the database, and match the scanned port information with the preset high-risk port rules. If the match is successful, the port risk data will be output.

[0132] It should be understood that by actively performing port scanning on asset devices in the substation secondary equipment communication network through the Nmap tool, open ports that pose security risks can be discovered in a timely manner to ensure the safe and stable operation of the substation secondary equipment communication network.

[0133] In a possible implementation, after generating multiple risk warning events, the network security early warning method of the substation further includes:

[0134] According to the risk warning event, the data flow information corresponding to the risk warning event is extracted; wherein the data flow information includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port and power communication application protocol of the data flow;

[0135] According to the data flow information, multiple message records corresponding to the risk warning event are extracted from the backup storage data;

[0136] Aggregate multiple message records to generate alarm data records corresponding to risk alarm events.

[0137] It should be noted that risk warning events are warning information generated based on risk data after integration and processing. The risk warning event usually contains specific information about the risk, such as risk type, occurrence time, assets and equipment involved, etc. Data flow information is the basic information of data flow transmitted in the network, mainly including the source Internet Protocol address, source port, destination Internet Protocol address, destination port and power communication application protocol of the data flow. Backup storage data contains historical traffic information in the network.

[0138] Message records are detailed information about each data flow recorded during network monitoring, including message header information, load data, etc. Alarm data records are alarm data records generated after a risk alarm event is detected in order to record and analyze the event.

[0139] Specifically, Figure 6 As shown, Figure 6 FIG. 1 is a flow chart of a risk warning event output provided by an embodiment of the present application. Figure 6 As shown, according to the risk alarm event, the data flow information (i.e., source IP address, source port, destination IP address, destination port, and power communication application protocol) of the data flow to which the risk alarm event belongs is extracted; then, according to the data flow information, the message records related to the risk alarm event are extracted from the backup storage data and the corresponding alarm data record files are generated, thereby realizing the alarm tracing function.

[0140] It should be understood that by producing detailed alarm data records based on risk alarm events, comprehensive risk information and data support are provided to managers to timely discover and respond to security risks in the network.

[0141] It should be noted that for asset equipment syslog log alarm identification, some asset equipment in the substation secondary equipment communication network (such as switches, firewalls, forward and reverse isolation devices, vertical encryption devices, etc.) usually use the log communication protocol (syslog communication protocol) to transmit the network security alarm of the asset equipment. By extracting the traffic and restoring the syslog log information, the corresponding device type field can identify the asset type and the log alarm in the syslog format, and output the security alarm event.

[0142] In a possible implementation, after generating multiple risk warning events, the network security early warning method of the substation further includes:

[0143] Multiple risk warning events are displayed and voice alarms are issued.

[0144] It should be noted that if Figure 6 As shown, when a risk warning event occurs, the information of the risk warning event is presented to the management personnel in a visual form, that is, the detailed information of these risk warning events (risk type, event, involved assets and equipment, etc.) is displayed on the monitoring interface so that the management personnel can quickly identify and respond. While the risk warning event is displayed, an alarm is sent to the management personnel through a sound device (such as a speaker, etc.) to prompt the management personnel to receive the risk warning information in a timely manner.

[0145] It should be understood that through interface display and voice alarm, it can ensure that managers receive risk warning information in the first time and respond quickly, thereby effectively ensuring the safe and stable operation of the substation secondary equipment communication network.

[0146] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0147] Corresponding to a network security early warning method for a substation in the above embodiment, Figure 7 A schematic structural diagram of a network security early warning device for a substation provided by an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.

[0148] Reference Figure 7 The network security early warning device 3 of the substation of this embodiment includes:

[0149] The acquisition module 31 is used to collect the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices;

[0150] The processing module 32 is used to pre-process the original network flow data to obtain the network flow data of multiple asset devices, wherein the pre-processing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value and backup storage data;

[0151] The identification module 33 is used to extract the power communication application protocol, equipment asset data, data flow and port in the network flow data respectively, and identify multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, and port risk data;

[0152] The generating module 34 is used to integrate and process a plurality of risk data to generate a plurality of risk warning events.

[0153] It can be understood that the network security early warning device 3 of the substation provided in this embodiment collects the mirror traffic of multiple network center switches and multiple scheduling data network switches connected to multiple asset devices in the communication network of the secondary equipment of the substation through the acquisition module 31, and obtains the original network traffic data of multiple asset devices; then, the processing module 32 pre-processes the original network traffic data to obtain the network traffic data of multiple asset devices, wherein the pre-processing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value, backup storage data; then, the identification module 33 extracts the power communication application protocol, equipment asset data, data traffic and port in the network traffic data respectively, and identifies multiple risk data in the communication network of the secondary equipment of the substation; wherein the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, port risk data; finally, the generation module 34 integrates and processes the multiple risk data to generate multiple risk alarm events. The network security early warning device 3 of the substation solves the problem that the existing network security monitoring system of the substation has low risk monitoring efficiency due to reliance on manual configuration and debugging, and cannot effectively identify and handle network security issues at the communication protocol level, thereby improving the real-time security monitoring of the communication network of the substation secondary equipment and enhancing the network security protection capability.

[0154] It should be noted that the information interaction, execution process, etc. between the modules in the network security early warning device 3 of the above-mentioned substation are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0155] The present application also provides a network security early warning device for a substation, such as Figure 8 As shown, Figure 8 This is a schematic diagram of the structure of a network security early warning device for a substation provided by an embodiment of the present application. Figure 8 The network security warning device 4 of the substation in this embodiment includes: a memory 41, a processor 42, and a computer program stored in the memory 41 and executable on the processor 42. When the processor 42 executes the computer program, the steps in any one of the above-mentioned embodiments of the network security warning method for the substation are implemented.

[0156] The present application also provides a network security early warning system for a substation. Fig. 9 As shown, Fig. 9 This is a schematic diagram of the structure of a network security early warning system for a substation provided by an embodiment of the present application. Fig. 9 The network security early warning system 5 of the substation of this embodiment includes: a network security early warning device 4 of the substation, a plurality of network center switches 52, a plurality of dispatching data network switches 53 and a plurality of asset devices 54#n (where n is a natural number; n represents the sequence number of the asset device 54#n); wherein,

[0157] Multiple first physical network ports of the network security early warning device 4 of the substation are connected to the mirror ports of multiple network center switches 52; multiple second physical network ports of the network security early warning device 4 of the substation are connected to the mirror ports of the dispatching data network switch 53; multiple asset devices 54#n are directly or indirectly connected to the communication ports of multiple network center switches 52 and multiple dispatching data network switches 53 respectively;

[0158] The network security early warning device 4 of the substation is used to obtain the original network flow data of multiple asset equipment in the substation secondary equipment communication network from the mirror ports of multiple network center switches and multiple dispatching data network switches; pre-process the original network flow data to obtain the network flow data of multiple asset equipment, wherein the pre-processing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value, backup storage data; and, respectively extract the power communication application protocol, equipment asset data, data flow and port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; and, integrate and process multiple risk data to generate multiple risk warning events; and, also used to detect multiple asset equipment 54#n from the communication ports of multiple network center switches 52 and scan the open ports of multiple asset equipment 54#n.

[0159] It should be noted that the network security early warning device 4 of the substation is the core device in the network security early warning system 5 of the substation, which is installed with the network security risk early warning application software and human-machine client software of the substation, and has powerful data processing and analysis capabilities. The network security risk early warning application software of the substation implements any of the above-mentioned network security early warning methods of the substation, that is, it is used to obtain the original network flow data of multiple asset devices 54#n in the communication network of the secondary equipment of the substation from the mirror ports of multiple network center switches 52 and multiple dispatching data network switches 53; pre-process the original network flow data to obtain the network flow data of multiple asset devices 54#n, wherein the pre-processing includes data flow table processing , data flow statistics processing and data backup storage processing; network flow data includes data flow table, data flow value, backup storage data; and, respectively extract the power communication application protocol, equipment asset data, data flow and port in the network flow data, and identify multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; and, integrate and process multiple risk data to generate multiple risk alarm events; and, also used to detect multiple asset devices 54#n from the communication ports of multiple network center switches 52 and scan the open ports of multiple asset devices 54#n. Among them, the network center switch 52 is a key device for connecting multiple asset devices in the substation secondary equipment network, which is responsible for forwarding data flow in the network, allowing the network flow data to be copied to the network security early warning device 4 of the substation for analysis, and also allowing the network security early warning device 4 of the substation to detect and port scan the asset device 54#n. The dispatching data network switch 53 is to transmit the network flow data from the substation to a higher-level network or data center.

[0160] It should be noted that, in this embodiment, the number of network center switches 52 and dispatching data network switches 53 in the network security early warning system 5 of the substation is not limited.

[0161] It should be noted that, in the present embodiment, the asset equipment 54#n can be directly connected to the communication ports of multiple network center switches 52 and the communication ports of multiple scheduling data network switches 53; it can also be indirectly connected to the communication ports of multiple network center switches 52 and the communication ports of multiple scheduling data network switches 53, that is, the asset equipment 54#n is first connected to the next-level interval layer switch, and then interconnected with the communication ports of multiple network center switches 52 and the communication ports of multiple scheduling data network switches 53 through the interval layer switch.

[0162] In this embodiment, the operating system of the network security warning device 4 of the substation is the Linux security system, the memory capacity is not less than 16GB, the solid-state hard disk capacity is not less than 1TB, it is equipped with at least 4 gigabit electrical ports, and is equipped with a display screen of not less than 14 inches. By selecting these device parameters, the portability, stability and processing power of the network security warning device 4 of the substation are guaranteed, so that its software functions can operate normally in various environments, thereby realizing a plug-and-play substation network security warning system.

[0163] like Fig. 9 As shown, the system supports two network security working modes, namely, mirror traffic mode and hybrid mode. In the mirror traffic mode, the system will not actively send any message to the secondary equipment communication network of the substation, but only passively receive the mirror traffic of the network center switch 52. In this working mode, no extra configuration operation is required. It is only necessary to start the network security risk warning application software of the substation and connect the network security warning device 4 of the substation to the mirror port of the network center switch 52 of the substation. This mode will not have any impact on the network and asset equipment. This is the default operation mode. In the hybrid mode, the configuration is also simple. The first physical network port of the network security warning device 4 of the substation is connected to the mirror port of the network center switch 52 and the second physical network port of the network security warning device 4 of the substation is connected to the mirror port of the dispatching data network switch 53 to obtain the original network traffic data of multiple asset equipment in the secondary equipment communication network of the substation. Among them, the first physical network port and the second physical network port are the network ports used for physical connection on the network security warning device 4 of the substation. The network security early warning device 4 of the substation can also perform active detection functions from the communication ports of multiple network center switches 52. Active detection is mainly used for the discovery of asset equipment and the scanning of open ports of asset equipment. The system strictly controls the packet sending interval during active detection and can be adjusted manually to avoid affecting production equipment. It should be noted that the active detection function of the system can be turned on and off at any time without restarting the operating system or application software. The system automatically switches seamlessly between the two working modes according to the on and off settings of the active detection function.

[0164] The deployment of the network security early warning device 4 in the network security early warning system 5 of the substation is as follows: Fig. 9 As shown, there are generally two working area networks (i.e., safety area I network and safety area II network) in the substation secondary equipment network, and a substation network security early warning device 4 can be deployed at the network center switch 52 of each working area. Fig. 9 Among them, asset equipment 54#1, asset equipment 54#2, and asset equipment 54#3 can be a five-defense machine, a workstation, and a monitoring machine respectively.

[0165] like Fig.10As shown, Fig.10 1 is a schematic diagram of a human-machine interface of a network security early warning device for a substation provided by an embodiment of the present application. Fig.10 As shown, the network security risk warning application software of the substation in the network security warning device 4 of the substation integrates modules such as flow monitoring, asset management, warning rules, alarm event query, log query (user operation log query), debugging operation (real-time message capture and saving operation), user management (human-machine interface user authority management), and security overview (security overall information statistics).

[0166] like Fig.11 As shown, Fig.11 This is a system architecture diagram of a network security early warning device for a substation provided by an embodiment of the present application. Fig.11 As shown, the network security risk warning application software of the substation in the network security warning device 4 of the substation adopts a three-layer architecture, which is divided into a data collection layer, an analysis and processing layer, and a data display layer, and mainly includes functions such as asset detection, high-risk port detection, application protocol in-depth analysis, traffic statistics, and rule engine. The network security warning device 4 of the substation is deployed in the secondary equipment communication network of the substation, and collects network traffic data in the secondary equipment communication network through the mirror port of the network center switch 52 and the dispatching data network switch 53, analyzes and processes the network traffic data, identifies security risks and issues alarms, and displays alarms and voice alarms on the human-machine interface.

[0167] It can be understood that the network security early warning system 5 of the substation provided by this embodiment obtains the original network traffic data of multiple asset devices by collecting the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the communication network of the secondary equipment of the substation; preprocessing the original network traffic data to obtain the network traffic data of multiple asset devices, wherein the preprocessing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value, backup storage data; respectively extract the power communication application protocol, equipment asset data, data traffic and port in the network traffic data, and identify multiple risk data in the secondary equipment network of the substation; wherein the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, port risk data; finally, the multiple risk data are integrated and processed to generate multiple risk alarm events. Through this system, the existing network security monitoring system of the substation is solved, which is low in risk monitoring efficiency due to reliance on manual configuration and debugging, and cannot effectively identify and process the network security problem at the communication protocol level, thereby improving the real-time security monitoring of the communication network of the secondary equipment of the substation and improving the network security protection capability.

[0168] It can be understood that, compared with the existing network security monitoring system for substations, the network security monitoring system for substations provided in the embodiment of the present application has the following advantages:

[0169] (1) Improve the monitoring strength of the substation secondary equipment communication network: The system can conduct comprehensive monitoring and early warning of the substation secondary equipment communication network. It can not only collect and monitor the network traffic in the substation secondary equipment communication network, but also analyze and decode the communication application protocol of the power network on this basis, identify and warn of dangerous behaviors such as control type operations, file transfer operations, remote connection operations, and system login operations in the power communication application protocol in the network. At the same time, it can detect assets and equipment in the network in a combination of active and passive methods, identify risk data such as asset equipment status, asset security access, and asset changes, and finally, identify dangerous ports by scanning and flow table data analysis, thereby greatly improving the strength of network monitoring.

[0170] (2) Simplified equipment access: The access process of network security early warning equipment in the substation is simplified. It only needs to collect and access the mirror ports of the network center switch and the dispatching data network switch in the substation secondary equipment communication network. There is no need to configure the network communication configuration between the monitored network assets and the system. Plug and play is achieved, which greatly improves the access efficiency of the equipment.

[0171] (3) Strengthen asset management: The system has powerful asset management functions and can perform comprehensive intelligent management of substation secondary communication equipment without manual intervention, providing strong support for equipment maintenance and management.

[0172] (4) Improved security protection capabilities: The system adds analysis of the main communication application protocols in the substation secondary equipment communication network, and identifies dangerous operations in the power network from the power communication application protocol level, such as remote operation, set value modification, configuration download, file transfer, dangerous protocols, etc., so as to effectively identify and handle new types of network attacks and improve security protection capabilities.

[0173] (5) Save operation and maintenance costs: The design of this system greatly improves the system's usability, reusability, and deployment efficiency, reduces the operational burden on management personnel, and thus saves operation and maintenance costs.

[0174] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0175] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned method embodiments when executing the computer program product.

[0176] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera / terminal device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.

[0177] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0178] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0179] In the embodiments provided in the present application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0180] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0181] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A network security early warning method for a substation, characterized in that: include: Collect the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices; Preprocessing the original network traffic data to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data flow table processing, data traffic statistics processing and data backup storage processing; the network traffic data includes data flow table, data traffic value and backup storage data; Extract the power communication application protocol, equipment asset data, data flow and port in the network flow data respectively, and identify multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; The plurality of risk data are integrated and processed to generate a plurality of risk warning events.

2. The network security early warning method for a substation according to claim 1, characterized in that: The power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including: According to the data flow table, identifying power communication application protocol types of multiple data flows; According to the power communication application protocol type and preset protocol decoding rules, the power communication application protocol of multiple data streams in the substation secondary equipment communication network is decoded by instruction set; If the decoding fails, the protocol risk data is obtained; If the decoding is successful, the protocol decoding results corresponding to the power communication application protocols of the multiple data streams are obtained, and the multiple protocol decoding results are matched with the preset protocol security rules to identify the multiple communication protocol risk data in the substation secondary equipment communication network.

3. The network security early warning method for a substation according to claim 1, characterized in that: The power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including: Extracting source ports and destination ports of multiple data flows according to the data flow table; The source ports and destination ports of the plurality of data flows are matched with preset high-risk port rules to identify and obtain the port risk data in the substation secondary equipment communication network.

4. The network security early warning method for a substation according to claim 1, characterized in that: The power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including: Through multiple preset dimensions, the data flow value is compared with multiple preset flow safety thresholds to identify multiple flow risk data in the substation secondary equipment communication network; wherein, the multiple preset dimensions include at least one of the following: the total flow value of network flow data, the receiving and sending flow value of each asset equipment, and the communication data flow value between asset equipment.

5. The network security early warning method for a substation according to claim 1, characterized in that: The power communication application protocol, equipment asset data, data flow and port in the network flow data are extracted respectively to identify multiple risk data in the substation secondary equipment communication network, including: Obtaining a source Internet Protocol address and a source physical address of a data flow from a data flow communicated between a plurality of the asset devices in the data flow table or from a reply data flow received after actively sending an asset detection ARP request; According to the source Internet Protocol address and the source physical address, the device asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein the device asset data includes the asset Internet Protocol address and the asset physical address; Identify multiple suspected asset data in the equipment asset data to obtain multiple asset risk data in the substation secondary equipment communication network; wherein the suspected asset data include: data on changes in the physical address corresponding to the asset Internet Protocol address, data on newly added asset Internet Protocol addresses, and data on newly added asset physical addresses.

6. The network security early warning method for a substation according to claim 1, characterized in that: The method further comprises: Perform port scanning on multiple asset devices in the substation secondary equipment communication network according to a preset scanning method through the network mapper Nmap, and identify multiple open ports; wherein the preset scanning method includes: a point-to-point port scanning method and a specified port range fast scanning method; The plurality of open ports are matched with preset high-risk port rules to identify and obtain the port risk data in the substation secondary equipment communication network.

7. The network security early warning method for a substation according to claim 1, characterized in that: After generating a plurality of risk warning events, the method further includes: According to the risk warning event, extract the data flow information corresponding to the risk warning event; wherein the data flow information includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port and power communication application protocol of the data flow; Extracting, from the backup storage data, a plurality of message records corresponding to the risk warning event according to the data flow information; Aggregate the plurality of message records to generate an alarm data record corresponding to the risk alarm event.

8. A network security early warning device for a substation, characterized in that: include: An acquisition module is used to collect the mirror traffic of multiple network center switches and multiple dispatching data network switches connected to multiple asset devices in the substation secondary equipment communication network to obtain the original network traffic data of multiple asset devices; A processing module, used for preprocessing the original network flow data to obtain network flow data of a plurality of asset devices, wherein the preprocessing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value and backup storage data; An identification module is used to extract the power communication application protocol, equipment asset data, data flow and port in the network flow data respectively, and identify and obtain multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, and port risk data; The generating module is used to integrate and process the plurality of risk data to generate a plurality of risk warning events.

9. A network security early warning device for a substation, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the network security early warning method for a substation as claimed in any one of claims 1 to 7 is implemented.

10. A network security early warning system for a substation, characterized in that: The system includes: network security early warning equipment of the substation, multiple network center switches, multiple dispatching data network switches and multiple asset equipment; wherein, The multiple first physical network ports of the network security early warning device of the substation are connected to the mirror ports of the multiple network center switches; the multiple second physical network ports of the network security early warning device of the substation are connected to the mirror port of the dispatching data network switch; the multiple asset devices are directly or indirectly connected to the communication ports of the multiple network center switches and the communication ports of the multiple dispatching data network switches respectively; The network security early warning device of the substation is used to obtain the original network flow data of multiple asset equipment in the substation secondary equipment communication network from the mirror ports of multiple network center switches and multiple dispatching data network switches; pre-process the original network flow data to obtain the network flow data of multiple asset equipment, wherein the pre-processing includes data flow table processing, data flow statistics processing and data backup storage processing; the network flow data includes data flow table, data flow value, backup storage data; and, respectively extract the power communication protocol, equipment asset data, data flow and port in the network flow data to identify and obtain multiple risk data in the substation secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; and, integrate and process multiple risk data to generate multiple risk warning events; and, also used to detect multiple asset equipment from the communication ports of multiple network center switches and scan the open ports of multiple asset equipment.

Citation Information

Patent Citations

  • Network risk monitoring method and system for substation

    CN107241224A

  • Intelligent substation network security protection system

    CN110768846A

  • Security auditing method and system based on traditional substation configuration file and IEC103 protocol flow

    CN113285937A

  • Intelligent substation communication data safety monitoring method and system

    CN114513342A

  • Substation-oriented attack surface management method, device and equipment and medium

    CN118174920A