A network security early warning method, device, equipment and system of a substation

By collecting and analyzing the mirror traffic of the communication network of secondary equipment in substations, identifying and integrating risk data, the problem of low network security monitoring efficiency in existing technologies is solved. Effective monitoring at the communication protocol level and security protection of all equipment in the station are achieved, improving network security protection capabilities and ease of use.

CN119945741BActive Publication Date: 2025-11-21STATE GRID HEILONGJIANG ELECTRIC POWER COMPANY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411962246.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-11-21
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Existing substation network security monitoring systems rely on manual configuration and debugging, resulting in low risk monitoring efficiency, inability to effectively identify and handle network security issues at the communication protocol level, and incomplete network security monitoring of all secondary equipment in the substation.

Method used

By collecting, preprocessing and analyzing the mirrored traffic of the network center switch and dispatch data network switch connected to multiple asset devices in the substation secondary equipment communication network, risk data is identified and integrated to generate risk alarm events, including asset risk, traffic risk, communication protocol risk and port risk data.

Benefits of technology

It enhances real-time security monitoring of communication networks for secondary equipment in substations, improves network security protection capabilities, reduces user workload, and increases system usability and deployment efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945741B_ABST
    Figure CN119945741B_ABST
Patent Text Reader

Abstract

The application is suitable for the technical field of substation network detection, and provides a network security early warning method, device, equipment and system for a substation, which comprises the following steps: collecting mirror traffic of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in a communication network of secondary equipment of the substation, obtaining original network traffic data of the plurality of asset devices, and preprocessing the data to obtain network traffic data of the plurality of asset devices; respectively extracting power communication application protocols, device asset data, data traffic and ports in the network traffic data, and identifying a plurality of risk data in the network of secondary equipment of the substation; and integrating and processing the plurality of risk data to generate a plurality of risk alarm events, thereby solving the problem that the existing substation network security monitoring system is low in risk monitoring efficiency due to reliance on manual configuration and debugging, and cannot effectively identify and process network security at the communication protocol level.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of substation network detection, and particularly relates to a network security early warning method, device, equipment and system for a substation. BACKGROUND

[0002] At present, with the development of digitalization and intelligentization of the power system, the network security problem of substations is increasingly prominent. As an important part of the power system, the substation needs to communicate and control various secondary devices in the system through the network, and therefore, the network security identification and early warning of the substation are particularly important. Deploying network security monitoring software and devices for the substation is one of the important means to protect the network security of the substation.

[0003] The existing network security monitoring system of the substation mainly uses traditional network security devices such as firewalls, intrusion detection systems, etc. to protect the security of the power network. However, these network security devices usually need complex configuration and management when used. For example, the firewall device needs to configure specific firewall policies according to the network environment; the security posture perception and network security monitoring devices need to configure asset configuration information such as the communication protocol, communication address and device type of the monitored object on the monitoring device, and the monitored asset device also needs to configure the communication address and protocol of the monitoring device to finally realize the security monitoring of the substation. Therefore, these complex configurations and management increase the operation and maintenance burden of the user and reduce the ease of use of the network security monitoring system of the substation. Secondly, the network security devices deployed in the substation usually only monitor the security risks of part of the important asset devices in the secondary device network of the substation, such as switch devices, workstation devices and security devices, and do not monitor the network security of the other secondary devices of the substation, such as relay protection devices and measurement and control devices. Finally, the existing network security monitoring system of the substation cannot effectively identify and handle network attacks at the communication protocol level. SUMMARY

[0004] The embodiments of the application provide a network security early warning method, device, equipment and system for a substation, which can solve the problem that the existing network security monitoring system of the substation has low risk monitoring efficiency due to the dependence on manual configuration and debugging, and cannot effectively identify and handle network security at the communication protocol level.

[0005] In a first aspect, the embodiments of the application provide a network security early warning method for a substation, and the method comprises:

[0006] Mirror traffic of a plurality of network center switches connected with a plurality of asset devices and a plurality of dispatch data network switches in a substation secondary equipment communication network is collected to obtain original network traffic data of the plurality of asset devices;

[0007] The original network traffic data is preprocessed to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data flow table processing, data traffic statistical processing, and data backup storage processing; and the network traffic data includes a data flow table, a data traffic value, and backup storage data.

[0008] Power communication application protocols, device asset data, data traffic, and ports in the network traffic data are extracted respectively to identify a plurality of risk data in the substation secondary equipment communication network, wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data.

[0009] The plurality of risk data is integrated to generate a plurality of risk alarm events.

[0010] In a possible implementation manner of the first aspect, the extracting, from the network traffic data, power communication application protocols, device asset data, data traffic, and ports respectively to identify a plurality of risk data in the substation secondary equipment communication network includes:

[0011] According to the data flow table, power communication application protocol types of a plurality of data flows are identified.

[0012] According to the power communication application protocol types and a preset protocol decoding rule, power communication application protocols of the plurality of data flows in the substation secondary equipment communication network are instruction set decoded.

[0013] If the decoding fails, the protocol risk data is obtained.

[0014] If the decoding succeeds, protocol decoding results corresponding to the power communication application protocols of the plurality of data flows are obtained, and the protocol decoding results are matched with a preset protocol security rule to identify a plurality of communication protocol risk data in the substation secondary equipment communication network.

[0015] In a possible implementation manner of the first aspect, the extracting, from the network traffic data, power communication application protocols, device asset data, data traffic, and ports respectively to identify a plurality of risk data in the substation secondary equipment communication network includes:

[0016] According to the data flow table, source ports and destination ports of a plurality of data flows are extracted.

[0017] The source port and the destination port of the plurality of data streams are matched with a preset high-risk port rule, and the port risk data in the substation secondary equipment communication network is identified.

[0018] In a possible implementation manner of the first aspect, the power communication application protocol, the device asset data, the data flow and the port in the network flow data are extracted respectively, and the plurality of risk data in the substation secondary equipment communication network are identified, including:

[0019] The data flow value is compared with a plurality of preset flow safety threshold values through a plurality of preset dimensions, and the plurality of flow risk data in the substation secondary equipment communication network are identified; wherein the plurality of preset dimensions at least include one of the following: network flow data total flow value, transceiving flow value of each asset device, communication data flow value between asset devices.

[0020] In a possible implementation manner of the first aspect, the power communication application protocol, the device asset data, the data flow and the port in the network flow data are extracted respectively, and the plurality of risk data in the substation secondary equipment communication network are identified, including:

[0021] The source Internet protocol address and the source physical address of the data flow are obtained from the data flow communicated between the plurality of asset devices in the data flow table or the reply data flow received after the asset probe ARP request is actively issued;

[0022] According to the source Internet protocol address and the source physical address, the device asset data of the asset device in the substation secondary equipment communication network are identified; wherein the device asset data includes asset Internet protocol address and asset physical address.

[0023] The plurality of suspected asset data in the device asset data are identified, and the plurality of asset risk data in the substation secondary equipment communication network are obtained; wherein the suspected asset data includes data that the physical address corresponding to the asset Internet protocol address is changed, data that the asset Internet protocol address is newly added, and data that the asset physical address is newly added.

[0024] In a possible implementation manner of the first aspect, the method further includes:

[0025] The asset probe ARP request is sent to the plurality of asset devices according to a preset rate;

[0026] When receiving a plurality of ARP reply messages sent by a plurality of asset devices, asset Internet Protocol addresses and asset physical addresses of the plurality of asset devices in the plurality of ARP reply messages are added to the device asset data.

[0027] In a possible implementation manner of the first aspect, after the when receiving a plurality of ARP reply messages sent by a plurality of asset devices, asset Internet Protocol addresses and asset physical addresses of the plurality of asset devices in the plurality of ARP reply messages are added to the device asset data, the method further includes:

[0028] comparing a source Internet Protocol address in the data flow table with asset Internet Protocol addresses of a plurality of asset devices in a plurality of ARP reply messages;

[0029] if the asset Internet Protocol address in the ARP reply message is the same as the source Internet Protocol address, it is determined that the asset device corresponding to the source Internet Protocol address has been detected;

[0030] if all the asset Internet Protocol addresses in the ARP reply message are different from the source Internet Protocol address, a source physical address and a source Internet Protocol address in the data flow table are added to the device asset data to obtain updated device asset data.

[0031] In a possible implementation manner of the first aspect, the method further includes:

[0032] performing port scanning on a plurality of asset devices in the substation secondary equipment communication network according to a preset scanning mode by using a network mapper Nmap to identify a plurality of open ports; wherein the preset scanning mode includes a point-to-point port scanning mode and a specified port range fast scanning mode.

[0033] matching a plurality of open ports with a preset high-risk port rule to identify the port risk data in the substation secondary equipment communication network.

[0034] In a possible implementation manner of the first aspect, after the generating a plurality of risk alarm events, the method further includes:

[0035] extracting data flow information corresponding to the risk alarm event according to the risk alarm event; wherein the data flow information includes a source Internet Protocol address, a source port, a destination Internet Protocol address, a destination port and a power communication application protocol of a data flow.

[0036] extracting a plurality of packet records corresponding to the risk alarm event from the backup storage data according to the data flow information.

[0037] The multiple message records are aggregated to generate an alarm data record corresponding to the risk alarm event.

[0038] In a possible implementation manner of the first aspect, after the multiple risk alarm events are generated, the method further includes:

[0039] The multiple risk alarm events are displayed and a voice alarm is issued.

[0040] In the second aspect, the embodiments of the present application provide a network security early warning device of a substation, and the device includes:

[0041] The acquisition module is configured to collect mirror traffic of multiple network center switches and multiple dispatch data network switches connected to multiple asset devices in a secondary equipment communication network of the substation, to obtain original network traffic data of the multiple asset devices.

[0042] The processing module is configured to pre-process the original network traffic data to obtain network traffic data of the multiple asset devices, wherein the pre-processing includes data stream table processing, data traffic statistical processing, and data backup storage processing; and the network traffic data includes a data stream table, a data traffic value, and backup storage data.

[0043] The identification module is configured to extract power communication application protocols, device asset data, data traffic, and ports in the network traffic data respectively, to identify multiple risk data in the secondary equipment communication network of the substation; wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data.

[0044] The generation module is configured to integrate and process the multiple risk data to generate multiple risk alarm events.

[0045] In the third aspect, the embodiments of the present application provide a network security early warning device of a substation, which includes a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the processor implements the network security early warning method of the substation as described in any of the above aspects when executing the computer program.

[0046] In the fourth aspect, the embodiments of the present application provide a network security early warning system of a substation, and the system includes a network security early warning device of a substation, multiple network center switches, multiple dispatch data network switches, and multiple asset devices; wherein,

[0047] The multiple first physical network ports of the network security early warning device of the substation are connected with the mirror ports of the multiple network center switches; the multiple second physical network ports of the network security early warning device of the substation are connected with the mirror ports of the dispatching data network switches; and the multiple asset devices are directly or indirectly connected with the communication ports of the multiple network center switches and the communication ports of the multiple dispatching data network switches.

[0048] The network security early warning device of the substation is configured to acquire original network flow data of the multiple asset devices in the substation secondary equipment communication network from the mirror ports of the multiple network center switches and the multiple dispatching data network switches; to preprocess the original network flow data to obtain network flow data of the multiple asset devices, wherein the preprocessing includes data stream table processing, data flow statistical processing and data backup storage processing; the network flow data includes data stream table, data flow value and backup storage data; and to extract power communication application protocol, device asset data, data flow and port in the network flow data respectively to identify multiple risk data in the substation secondary equipment communication network, wherein the risk data at least includes one of asset risk data, flow risk data, communication protocol risk data and port risk data; and to integrate the multiple risk data to generate multiple risk alarm events; and to further detect the multiple asset devices from the communication ports of the multiple network center switches and scan open ports of the multiple asset devices.

[0049] In the fifth aspect, the embodiments of the present application provide a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the network security early warning method of the substation according to any one of the above aspects.

[0050] In the sixth aspect, the embodiments of the present application provide a computer program product. When the computer program product is run on a terminal device, the terminal device executes the network security early warning method of the substation according to any one of the first aspect.

[0051] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0052] The embodiment of the present application provides a network security early warning method of a transformer substation, which comprises the following steps: collecting mirror image flows of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in a secondary equipment communication network of the transformer substation, to obtain original network flow data of the plurality of asset devices; preprocessing the original network flow data to obtain network flow data of the plurality of asset devices, wherein the preprocessing comprises data stream table processing, data flow statistical processing and data backup storage processing; the network flow data comprises a data stream table, a data flow value and backup storage data; power communication application protocols, device asset data, data flow and ports in the network flow data are extracted respectively, and a plurality of risk data in the secondary equipment communication network of the transformer substation are identified; wherein the risk data at least comprises one of the following: asset risk data, flow risk data, communication protocol risk data and port risk data; finally, the plurality of risk data are integrated and processed to generate a plurality of risk alarm events. Through the method, the problem that the existing network security monitoring system of the transformer substation is low in risk monitoring efficiency due to dependence on manual configuration and debugging and cannot effectively identify and process network security at the communication protocol level is solved, so that the real-time security monitoring strength of the secondary equipment communication network of the transformer substation is improved, and the network security protection capability is improved. BRIEF DESCRIPTION OF DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0054] Figure 1 Fig. 1 is a flow schematic diagram of a network security early warning method of a transformer substation provided by an embodiment of the present application;

[0055] Figure 2 Fig. 2 is a schematic diagram of risk data identification in a secondary equipment communication network of a transformer substation provided by an embodiment of the present application;

[0056] Figure 3 Fig. 3 is a flow schematic diagram of flow direction identification update of a data stream provided by an embodiment of the present application;

[0057] Figure 4 Fig. 4 is a flow schematic diagram of asset device discovery provided by an embodiment of the present application;

[0058] Figure 5 Fig. 5 is a flow schematic diagram of asset device discovery provided by another embodiment of the present application;

[0059] Figure 6is a flowchart of a risk alarm event output provided by an embodiment of the present application;

[0060] Figure 7 is a structural diagram of a network security early warning device of a substation provided by an embodiment of the present application;

[0061] Figure 8 is a structural diagram of a network security early warning device of a substation provided by an embodiment of the present application;

[0062] Figure 9 is a structural diagram of a network security early warning system of a substation provided by an embodiment of the present application;

[0063] Figure 10 is a human-machine interface diagram of a network security early warning device of a substation provided by an embodiment of the present application;

[0064] Figure 11 is a system architecture diagram of a network security early warning device of a substation provided by an embodiment of the present application. DETAILED DESCRIPTION

[0065] In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular system configurations, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known systems, devices, circuits, and methods are omitted so as not to obscure the description of the present application with unnecessary detail.

[0066] It is to be understood that the terminology "includes", "has", "holds", "contains" and / or "comprising", when used in this specification and in the following claims, indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0067] It is also to be understood that the terminology "and / or" when used in this specification and in the following claims, refers to at least one of the items, or any combination of one or more of the items, associated with the "and / or" term.

[0068] As used in this specification and in the claims, the terms "if" and "when" can be interpreted to mean "upon" or "in response to a determination" or "in response to a detection" depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be interpreted to mean "upon determining" or "in response to determining" or "upon detecting [the described condition or event]" or "in response to detecting [the described condition or event]" depending on the context.

[0069] In addition, in the description of the present application and the appended claims, the terms "first", "second", "third", etc. are used only to distinguish descriptions and cannot be understood as indicating or implying relative importance.

[0070] In the present application, the reference "one embodiment" or "some embodiments" means that the specific features, structures or characteristics described in connection with the embodiment are included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in further some embodiments" and the like appearing in the present specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "include", "contain", "have" and their variants mean "include but not limited to", unless otherwise specifically emphasized.

[0071] Please refer to Figure 1 , Figure 1 is a flowchart of a network security early warning method of a substation provided by an embodiment of the present application. The method comprises:

[0072] S11, mirror image traffic of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in a substation secondary equipment communication network is collected to obtain original network traffic data of the plurality of asset devices;

[0073] S12, the original network traffic data is preprocessed to obtain network traffic data of the plurality of asset devices, wherein the preprocessing comprises data stream table processing, data traffic statistical processing and data backup storage processing; the network traffic data comprises data stream table, data traffic value and backup storage data;

[0074] S13, power communication application protocol, device asset data, data traffic and port in the network traffic data are extracted respectively to identify a plurality of risk data in the substation secondary equipment communication network; wherein the risk data at least comprises one of the following: asset risk data, traffic risk data, communication protocol risk data and port risk data;

[0075] S14, the plurality of risk data is integrated to generate a plurality of risk alarm events.

[0076] It should be noted that in the present embodiment, the execution subject can be a terminal device such as a server, which is not specifically limited. The network security early warning method of the substation is mainly applied in the secondary equipment communication network of the substation, and is used for early warning of the communication network security of the secondary equipment of the substation.

[0077] The substation secondary equipment communication network refers to a network composed of devices for control, protection, measurement and other functions in the substation secondary system. These devices do not directly participate in the transformation and distribution of electric energy, and are important for monitoring, controlling and protecting the operation state of the substation secondary system, and for the safe and reliable operation of the substation secondary system, such as relay protection and monitoring devices, measurement and control devices, communication equipment, etc. Asset devices refer to various hardware devices and software resources in the substation secondary equipment network, such as measurement and control devices, workstations, wave recorders, monitoring machines, etc.

[0078] The network center switch refers to a key device in the substation secondary equipment network for directly or indirectly connecting multiple asset devices, which is responsible for forwarding data traffic in the network. The dispatch data network switch is used to transmit network traffic data from the substation to a higher level network or data center. By setting up a mirror traffic function on the network center switch and the dispatch data network switch, all data traffic passing through these switches can be collected in real time. Mirror traffic refers to the traffic obtained by copying the data traffic of a certain port of the network center switch or the dispatch data network switch through the mirror traffic function, i.e. the original network traffic data. The original network traffic data is mainly used for subsequent traffic analysis and risk monitoring. Since the original network traffic data contains all the data traffic information in the substation secondary equipment network, it may also contain redundant, erroneous or irrelevant data, therefore, a series of preprocessing operations are needed to extract useful information and obtain more accurate and useful network traffic data. The preprocessing mainly includes data flow table processing, data traffic statistical processing and data backup storage processing.

[0079] Specifically, first, a mirror traffic function is set up on the network center switch in the substation secondary equipment network, the data traffic of the port where the asset device to be monitored is located is copied to the designated mirror port, and the panoramic traffic collection and analysis technology is used to collect the data traffic on the mirror port to obtain the original network traffic data. Then, the original network traffic data is preprocessed to extract useful information and obtain network traffic data.

[0080] Specifically, (1) the original network traffic data is processed by data flow table, that is, the data flow table processing such as parsing and classification of data flow in the original network traffic data is performed to generate a corresponding data flow table. Through the data flow table, the data interaction flow direction of each asset device in the network can be accurately located. When the secondary equipment network of the substation is stably operated, the data flow direction between asset devices is basically stable. By saving the record of the stable data flow direction, new unsafe flow table data, unsafe asset risk data and port risk data, etc. can be identified. (2) The original network traffic data is processed by data flow statistics, that is, the data flow of various dimensions such as the total flow value of network traffic data, the receiving and transmitting flow value of each asset device, and the communication data flow value between multiple asset devices in the original network traffic data is counted and analyzed to obtain the data flow value of the key indicators such as the rate and size of the data flow, so as to identify the flow risk data such as network flow overload and network storm attack in the secondary equipment network of the substation. (3) The original network traffic data is processed by data backup storage, that is, the original network traffic data is backed up and stored for subsequent analysis such as data recovery and troubleshooting of security risk events. At the same time, a secure disk storage strategy is set. When the storage capacity exceeds the disk storage space threshold, the old flow data will be overwritten in a cycle. It should be understood that by preprocessing the original network traffic data, more accurate and useful network traffic data can be obtained, which provides strong support for subsequent security analysis and early warning.

[0081] The network traffic data refers to the network traffic transmitted by each asset device in the secondary equipment network of the substation, mainly including data flow table, data flow value, and backup storage data. The data flow table mainly includes source Internet protocol address, source port, destination Internet protocol address, destination port and application protocol, which are used to describe the detailed information of the source and destination of the data flow. The data flow value is mainly used to describe the rate and flow size of the data flow. The backup storage data is mainly the data of the network traffic backup storage, which is used for subsequent analysis of security risk events.

[0082] The risk data is data that may threaten network security identified in the network traffic data, and includes but is not limited to asset risk data, traffic risk data, communication protocol risk data, and port risk data. The asset risk data refers to risk data of abnormal devices, such as newly added devices, changes in the Internet Protocol address of asset devices, and configuration errors of asset devices; the traffic risk data refers to risk data of abnormal traffic patterns, such as traffic overload; the communication protocol risk data refers to risk data of insecure protocols, protocol vulnerabilities, device configuration file transmission, and device control type operations in the data transmission process; and the port risk data refers to risk data of prohibited open security ports and high-risk ports. The power communication protocol, data traffic, and port data extracted from the network traffic data are compared with preset security rules to identify the risk data, wherein the preset security rules are security rules preset for detecting abnormal behavior or potential threats in the network.

[0083] The integration processing is a processing operation of merging, classifying, and analyzing multiple risk data, so as to more clearly understand the network security situation. The risk alarm event is alarm information generated according to the risk data after the integration processing.

[0084] Specifically, first, the mirror traffic of the multiple network center switches connected with the multiple asset devices and the multiple dispatch data network switches in the substation secondary device communication network is collected to obtain the original network traffic data of the multiple asset devices; then, the original network traffic data is preprocessed by data stream table processing, data traffic statistical processing, and data backup storage processing to obtain the network traffic data of all asset devices in the substation secondary device communication network; then, the power communication application protocol, device asset data, data traffic, and port in the network traffic data after the preprocessing are extracted to identify the risk data existing in the network traffic data, which may involve multiple aspects such as assets, traffic, communication application protocol, and port; finally, the identified risk data is integrated to obtain clear and specific risk alarm events. These risk alarm events can help administrators quickly locate and solve potential security threats.

[0085] It can be understood that the power substation network security early warning method provided by the embodiment collects mirror traffic of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in a power substation secondary equipment communication network, to obtain original network traffic data of the plurality of asset devices; the original network traffic data is preprocessed to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data stream table processing, data traffic statistical processing and data backup storage processing; the network traffic data includes a data stream table, a data traffic value and backup storage data; power communication application protocols, device asset data, data traffic and ports in the network traffic data are extracted respectively to identify a plurality of risk data in the power substation secondary equipment communication network; wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data and port risk data; finally, the plurality of risk data is integrated and processed to generate a plurality of risk alarm events. Through the method, the problem that the existing power substation network security monitoring system is low in risk monitoring efficiency due to dependence on manual configuration and debugging, and cannot effectively identify and process network security at the communication protocol level is solved, so as to improve real-time security monitoring of the power substation secondary equipment communication network and enhance network security protection capability. At the same time, the method also improves the usability, reusability and deployment efficiency of the system, reduces the operation burden of the user, thereby saving operation and maintenance cost.

[0086] In a possible implementation, the power communication application protocols, the device asset data, the data traffic and the ports in the network traffic data are extracted respectively to identify a plurality of risk data in the power substation secondary equipment communication network, including:

[0087] According to the data stream table, a power communication application protocol type of a plurality of data streams is identified;

[0088] According to the power communication application protocol type and a preset protocol decoding rule, an instruction set of the power communication application protocols of the plurality of data streams in the power substation secondary equipment communication network is decoded;

[0089] If the decoding fails, protocol risk data is obtained;

[0090] If the decoding succeeds, a protocol decoding result corresponding to the power communication application protocols of the plurality of data streams is obtained, and the plurality of protocol decoding results are matched with a preset protocol security rule to identify a plurality of communication protocol risk data in the power substation secondary equipment communication network.

[0091] It should be noted that the power communication application protocol type is a network protocol type used by a data stream in a data transmission process, such as the substation communication network standard protocol IEC104, IEC61850, and the commonly used system log protocol (SYSLOG) of the Internet, the simple network management protocol (SNMP), the file transfer protocol (FTP), the secure file transfer protocol (SFTP), and the like. Different power communication application protocols correspond to different instruction sets and communication rules. The preset protocol decoding rule is a decoding rule set according to different power communication application protocol types, and is used to decode the data packet of the power communication application protocol into different instruction sets. Among them, the preset protocol decoding rule is usually a message format set based on the standard document or known security vulnerabilities of different protocols. The instruction set decoding process is to match the data structure, field, and byte stream according to the message format defined by each preset protocol decoding rule, so as to identify the dangerous operations existing in the power communication application protocol, such as the remote control, remote adjustment, and modification of the value control type operation in the IEC104 and IEC61850 protocols; the important log record transmission operation of the device in the SYSLOG protocol; the device state query, device parameter configuration, and network fault diagnosis in the SNMP protocol; the file transmission operation in the SFTP and FTP protocols; and whether the power communication application protocol not allowed to be used in the substation, such as the hypertext transfer protocol (HTTP) and the like, is present in the substation secondary equipment network, so as to monitor the attack behavior on the network communication protocol level. The communication protocol risk data is the potential security risk related to the power communication application protocol identified in the network traffic data, such as the use of an unsafe protocol, a protocol vulnerability, and an illegal data operation. The preset protocol security rule is a rule for detecting whether there is a security risk related to the power communication application protocol in the network traffic data.

[0092] Specifically, as shown in Figure 2 , Figure 2 is a schematic diagram of risk data identification in a substation secondary equipment communication network according to an embodiment of the present application. As shown in Figure 2As shown in the method, the depth analysis of the power communication application protocol, such as the MMS (IEC61850) protocol, the IEC104 protocol, the FTP protocol, and the like, is included. The dangerous communication protocol, such as the HTTP protocol, which is not allowed to be used in power communication, is also identified and matched with the preset protocol security rule. First, the data stream table is analyzed, and the power communication application protocol type used by each data stream is identified according to the protocol field in the data stream table. Then, the instruction set decoding of the data stream of the identified power communication application protocol type is performed according to the preset protocol decoding rule, so as to extract the instruction set and related information in the data stream. At this time, if the decoding fails, that is, the data stream cannot be decoded or the data stream does not conform to the format of the preset protocol decoding rule during the decoding process, it is indicated that the data stream may be tampered, unknown protocol is used, or other security risks exist, and the data stream is regarded as the communication protocol risk data. If the decoding is successful, the protocol decoding result corresponding to the power communication application protocol of each data stream is obtained. The protocol decoding result is matched with the preset protocol security rule. If the protocol decoding result is the same as the preset protocol security rule, it is indicated that the unsafe instruction is used, and the data stream is regarded as the communication protocol risk data.

[0093] It should be understood that, by performing the depth analysis on the power communication application protocol, the potential security risk related to the power communication application protocol in the substation secondary equipment communication network can be identified, thereby providing strong support for subsequent security response and protection.

[0094] In a possible implementation, the power communication application protocol, the device asset data, the data flow, and the port in the network traffic data are extracted respectively, and a plurality of risk data in the substation secondary equipment communication network are identified, including:

[0095] According to the data stream table, the source port and the destination port of the plurality of data streams are extracted.

[0096] The source port and the destination port of the plurality of data streams are matched with the preset high-risk port rule, and the port risk data in the substation secondary equipment communication network is identified.

[0097] It should be noted that the source port is the starting port of the data flow, and the destination port is the target port of the data flow. Usually, the asset device sending the data flow is identified by the source port, and the asset device receiving the data flow is identified by the destination port. The preset high-risk port rule is a security rule for identifying possible high-risk ports in network traffic. These preset high-risk port rules are set based on known security vulnerabilities, attack patterns, etc. Port risk data is security risk data related to ports identified in network traffic data. These data may involve potential security risks such as using high-risk ports for communication or port scanning.

[0098] In this embodiment, as shown in Figure 2 The source port and destination port of the data flow are obtained from the data flow table, and the built-in preset high-risk port rule is matched to identify common high-risk ports in the network traffic data in the communication network of the secondary equipment of the substation in real time. Common high-risk ports can include 23, 25, 53, 80, 135, 137, 138, 139, 443, 445, 3389, 5901, etc.

[0099] It should be understood that the above method can identify potential security risks related to ports in the network traffic data of the communication network of the secondary equipment of the substation, providing strong support for subsequent security response and protection, thereby protecting the safe and stable operation of the communication network of the secondary equipment of the substation.

[0100] In one possible implementation, the power communication application protocol, device asset data, data flow and port in the network traffic data are extracted respectively, and multiple risk data in the communication network of the secondary equipment of the substation are identified, including:

[0101] By comparing the data flow value with multiple preset flow security threshold values through multiple preset dimensions, multiple flow risk data in the communication network of the secondary equipment of the substation are identified. The multiple preset dimensions at least include one of the following: total flow value of network traffic data, transceiving flow value of each asset device, communication data flow value between asset devices.

[0102] It should be noted that the preset dimension is a pre-set angle for evaluating the security of network traffic value, mainly including network traffic data total traffic value, transceiving traffic value of each asset device, and communication data traffic value between asset devices. Among them, the network traffic data total traffic value is the sum of all data traffic in the communication network of the secondary equipment of the substation, which reflects the overall traffic situation in the network; the transceiving traffic value of each asset device is the traffic size of the data stream sent and received by a single asset device in the communication network of the secondary equipment of the substation, which reflects the network activity of a single asset device; the communication data traffic value between asset devices is the traffic size of the data stream communicated between different asset devices, which reflects the interaction between asset devices. The preset traffic safety threshold is a pre-set safe value of the traffic value, which is used to judge whether the network traffic is within the normal range. The traffic risk data is the security risk related to traffic identified in the network traffic data, such as traffic overload and abnormal traffic pattern.

[0103] Specifically, the network traffic data total traffic value, the transceiving traffic value of each asset device and the communication data traffic value between asset devices are obtained from the data traffic value, and these data traffic values are compared with the preset traffic safety threshold of the corresponding dimension. If the traffic value in a certain preset dimension exceeds the corresponding preset traffic safety threshold, it indicates that there is a traffic risk, which is taken as the traffic risk data.

[0104] It should be understood that the above method can realize real-time monitoring and identification of traffic risks in the communication network of the secondary equipment of the substation, which helps to discover and respond to possible traffic attacks or abnormal behaviors in time, so as to ensure the safe and stable operation of the communication network of the secondary equipment of the substation.

[0105] In one possible implementation, the power communication application protocol, device asset data, data traffic and port in the network traffic data are extracted respectively, and a plurality of risk data in the communication network of the secondary equipment of the substation are identified, including:

[0106] The source Internet protocol address and the source physical address of the data stream are obtained from the data stream communicated between the plurality of asset devices in the data stream table or the reply data stream received after actively issuing an asset probe ARP request;

[0107] According to the source Internet protocol address and the source physical address, the device asset data of the asset device in the communication network of the secondary equipment of the substation are identified; wherein the device asset data includes asset Internet protocol address and asset physical address;

[0108] The plurality of suspected asset data in the device asset data is identified to obtain a plurality of asset risk data in the secondary equipment communication network of the transformer substation; wherein, the suspected asset data includes: data of change of the physical address corresponding to the asset Internet protocol address, data of the newly added asset Internet protocol address, and data of the newly added asset physical address. It should be noted that the source Internet protocol address (source IP address) is the starting point of the data flow in the network, which is used to identify the device sending the data flow; the source physical address (source MAC address) is the physical address of the starting device of the data flow in the network, which is usually used for communication at the network layer. The device asset data is the detailed information of each asset device in the secondary equipment network of the transformer substation, including the asset Internet protocol address of the asset device, the asset physical address and other information. The suspected asset data is the abnormal information related to the asset device identified in the network flow data, such as the asset Internet protocol address of the newly added asset device, the asset physical address of the newly added asset device, and the change of the physical address corresponding to the asset Internet protocol address. The preset asset security rule is a rule preset for detecting whether there is a security risk related to the asset device in the network flow data. The asset risk data is the actual risk information related to the asset device determined after comparing the suspected asset data with the actual asset device.

[0109] It should be noted that the detection of the asset device mainly includes an active request detection method and a passive identification detection method, wherein the active request detection method is to obtain the source IP address and the source MAC address by periodically sending asset detection ping requests or ARP requests, thereby actively detecting the assets in the network; the passive identification detection method is to obtain and analyze the network flow data, extract the source IP address and the source MAC address of the data flow between a plurality of asset devices in the data flow table to discover the assets. The two methods are combined to detect and discover the assets of the asset device in the secondary equipment communication network of the transformer substation, automatically generate and save the device asset data (including asset IP address, asset MAC address and other information) of the asset device, and facilitate the management personnel to confirm the number of assets in the communication network and the basic communication five-tuple information.

[0110] Specifically, first, the source Internet protocol address and the source physical address of the data flow are obtained from the data flow communicated between the plurality of asset devices in the data flow table or the reply data flow received after actively issuing an asset probe ARP request; then, according to the source IP address and the source MAC address, each asset device in the substation secondary equipment communication network is identified, and data about the asset devices is collected to form device asset data; then, the state of each asset device is monitored in real time in subsequent operation, and the newly added asset Internet protocol address, the newly added asset physical address, and the change of the asset Internet protocol address corresponding to the physical address in the device asset data are extracted, which may be that an unauthorized device accesses the network or that a device is illegally replaced, and these changes are regarded as suspected asset data; finally, the suspected asset data is compared with the actual asset devices in the communication network, and if the suspected asset data does not match the asset Internet protocol address and the asset physical address of the actual asset devices in the communication network, it is regarded as asset risk data.

[0111] It should be understood that the real-time monitoring and risk assessment of the asset devices in the substation secondary equipment communication network can be realized by the above method, which helps to discover and respond to possible asset security risks in time, thereby ensuring the safe and stable operation of the substation secondary equipment communication network.

[0112] It should be noted that in the present embodiment, the flow table is used to track and analyze the transmission layer protocol, the source port and the destination port of the data flow are extracted, and the data flow table is established, and all network connections in the network are tracked, the flow direction of the data flow is identified according to the three-way handshake information of the TCP connection, thereby obtaining the port information of the network for high-risk port judgment. At the same time, the traffic information of each data flow is updated, and the traffic statistics based on the data flow are performed. If the current data flow is discovered for the first time, the application protocol identification process is performed, and after the identification is completed, the application protocol is saved to the data flow table. The flow table after identification does not need to be identified again, and if an application protocol that is not allowed to appear is identified, protocol risk data is generated. However, the IEC104 protocol and the IEC61850 protocol commonly used in the power system are long connection protocols, and the three-way handshake information of the TCP connection cannot be obtained when the system accesses the mirror port, so the flow direction of the data flow cannot be judged according to the three-way handshake message of the TCP connection. However, the flow direction is particularly important in high-risk port judgment, asset type identification, topology generation, etc. Therefore, in the present embodiment, the flow direction is accurately identified according to the communication message characteristics of the client / server in the IEC104 protocol and the IEC61850 protocol communication connection, and the flow table is updated.

[0113] The specific implementation method is as shown in Figure 3 Figure 3 ​This is a schematic diagram illustrating a process for updating the flow direction of a data stream, provided in one embodiment of this application. For example... Figure 3 As shown, the original messages of the IEC104 or IEC61850 protocol are decoded. Then, it is determined whether the flow direction of the data stream has been determined. If the flow direction is not determined, it is determined based on the ASDU or PDU type. If the flow direction matches the direction in the data flow table, the flow direction is marked; if the flow direction does not match the flow direction in the data flow table, the flow direction in the data flow table is updated and marked. When determining the direction of data flow based on ASDU or PDU types, for IEC 104 protocol communication, different ASDU types are used for monitoring direction (S->C) and control direction (C->S). Deep analysis of IEC 104 protocol communication messages allows for accurate identification of the flow direction through the ASDU type (e.g., ASDU type 1 is for monitoring direction messages, ASDU type 45 is for control direction messages). For IEC 61850 protocol communication, confirmedRequest PDUs are for control direction (C->S), while confirmedResponse PDUs and unconfirmed PDUs are for monitoring direction (S->C). The flow direction is accurately identified based on the parsed PDU type. After the flow direction is updated, the system marks it, eliminating the need for re-identification of data flows with clearly defined directions. Through decoding and analysis of application protocol data, specific application operations in the power communication application protocol are identified, including remote control operations of local / remote clients on the substation secondary equipment communication network, configuration download operations, and equipment setting modification operations, providing risk warnings for these important operations.

[0114] In one possible implementation, the network security early warning method for this substation also includes:

[0115] Send asset probe ARP requests to multiple asset devices at a preset rate;

[0116] When multiple ARP reply messages are received from multiple asset devices, the asset Internet Protocol address and asset physical address of the multiple asset devices in the multiple ARP reply messages are added to the device asset data.

[0117] It should be noted that, in this embodiment, the detection of assets and devices includes not only passive identification detection by acquiring and analyzing the source IP address in network traffic data, but also active request detection by periodically sending asset detection requests (ARP or ping) to identify assets.

[0118] The preset rate is a sending frequency preset when sending the asset probe ARP request. The asset probe ARP request is a request for inquiring the MAC address corresponding to the IP address of the device in the network. The ARP reply information is information replied when the asset device receives the ARP request, and the ARP reply information includes the asset IP address and the asset MAC address of the asset device.

[0119] Specifically, as shown in Figure 4 , Figure 4 is a flowchart about asset device discovery provided by an embodiment of the present application. Figure 4 In the method, when the active probe mode of the network security early warning system of the substation is started, the current network segment information is read, and asset probe ARP requests are sent to the plurality of asset devices at a preset rate (a default rate of 10 packets per second). ARP reply information sent by the plurality of asset devices is received, and information about the asset IP address and the asset MAC address of the asset device in the ARP reply information is added to the device asset data in the database. It should be noted that the method is only performed when the active probe mode of the network security early warning system of the substation is started by human setting.

[0120] It should be understood that the device asset data can be updated regularly or on demand by the above method, so that the latest information of all asset devices in the communication network of the secondary equipment of the substation can be obtained, so as to maintain the safe and stable operation of the communication network of the secondary equipment of the substation.

[0121] In a possible implementation, after the asset IP address and the asset physical address of the plurality of asset devices are added to the device asset data when the plurality of ARP reply information sent by the plurality of asset devices is received, the network security early warning method of the substation further includes:

[0122] Comparing the source IP address in the data flow table with the asset IP addresses of the plurality of asset devices in the plurality of ARP reply information;

[0123] If one asset IP address in the ARP reply information is the same as the source IP address, it is determined that the asset device corresponding to the source IP address has been probed;

[0124] If all asset IP addresses in the ARP reply information are different from the source IP address, the source physical address and the source IP address in the data flow table are added to the device asset data to obtain updated device asset data.

[0125] Specifically, as shown in Figure 5 , Figure 5 is a flowchart about asset device discovery provided by another embodiment of the present application. As shown in Figure 5As shown, the source MAC address and the source IP address are extracted from the obtained network traffic data, and illegal IP addresses such as local loopback and multicast addresses are filtered out. If an asset IP address in the ARP reply information is the same as the source IP address, it is determined that the asset device with the same IP address has been actively detected and discovered, and the activity time of the asset device is updated. If all asset Internet protocol addresses in the ARP reply information are different from the source Internet protocol address, the source IP address and the source MAC address are added to the device asset data, so as to obtain updated device asset data.

[0126] It should be understood that the asset device in the substation secondary equipment communication network can be accurately identified and tracked by the above method, so as to ensure the completeness and accuracy of the device asset data.

[0127] In a possible implementation, the network security early warning method of the substation further includes:

[0128] The network mapper Nmap performs port scanning on the plurality of asset devices in the substation secondary equipment communication network according to a preset scanning mode, and identifies a plurality of open ports; wherein the preset scanning mode includes a point-to-point port scanning mode and a specified port range fast scanning mode.

[0129] The plurality of open ports are matched with a preset high-risk port rule to identify port risk data in the substation secondary equipment communication network.

[0130] It should be noted that the network mapper Nmap is an open source network scanning and security auditing tool. Nmap can scan hosts on the network and list their open ports and services. The preset scanning mode is a scanning mode that needs to be set before port scanning. The preset scanning mode mainly includes a point-to-point port scanning mode and a specified port range fast scanning mode. The point-to-point port scanning mode scans the asset device at a slower rate to ensure that the port scanning does not affect the overall operation of the device. The specified port range fast scanning mode realizes fast scanning by specifying a port range or a specific common port. Both modes can discover open service ports of asset devices in the network, thereby identifying high-risk service ports.

[0131] Specifically, when the active detection mode of the network security early warning system of the substation is turned on, the system reads the device asset data in the database, performs port scanning on the asset devices in turn through the network mapper Nmap, saves the scanning results to the database, and matches the scanned port information with the preset high-risk port rule. If the matching is successful, the port risk data is output.

[0132] It should be understood that by proactively scanning the ports of assets and equipment in the substation's secondary equipment communication network using the Nmap tool, open ports that pose security risks can be identified in a timely manner, thereby ensuring the safe and stable operation of the substation's secondary equipment communication network.

[0133] In one possible implementation, after generating multiple risk alert events, the network security early warning method for the substation also includes:

[0134] Based on the risk alarm event, the data flow information corresponding to the risk alarm event is extracted; the data flow information includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port, and power communication application protocol of the data flow.

[0135] Based on the data stream information, multiple message records corresponding to risk alarm events are extracted from the backup storage data;

[0136] Multiple message records are aggregated to generate alarm data records corresponding to risk alarm events.

[0137] It should be noted that risk alarm events are alarm information generated based on integrated and processed risk data. These risk alarm events typically contain specific information about the risk, such as the risk type, time of occurrence, and involved assets and equipment. Data flow information is the basic information of data flows transmitted in the network, mainly including the source Internet Protocol address, source port, destination Internet Protocol address, destination port, and power communication application protocol. Backup storage data contains historical traffic information from the network.

[0138] Message logging is the recording of detailed information for each data stream during network monitoring, including message header information, payload data, etc. Alarm data logging is the recording of alarm data generated after a risk alarm event is detected, in order to record and analyze the event.

[0139] Specifically, such as Figure 6 As shown, Figure 6 This is a schematic diagram illustrating a process for outputting risk alarm events, provided in one embodiment of this application. Figure 6 As shown, based on the risk alarm event, the data flow information (i.e., source IP address, source port, destination IP address, destination port, and power communication application protocol) of the data flow to which the risk alarm event belongs is extracted; then, based on the data flow information, the message records related to the risk alarm event are extracted from the backup storage data and the corresponding alarm data record file is generated, thereby realizing the alarm tracing function.

[0140] It should be understood that by generating detailed alarm data records based on risk alarm events, comprehensive risk information and data support are provided to managers to promptly identify and address security risks in the network.

[0141] It should be noted that the asset device syslog log alarm identification, the secondary equipment communication network in the transformer substation part of the asset device (such as switch, firewall, forward and reverse isolation device, longitudinal encryption device, etc.) usually transmits the network security alarm of the asset device in the form of log communication protocol (syslog communication protocol), and the corresponding device type field can identify the asset type and syslog format log alarm by extracting the traffic to restore syslog log information, and output the security alarm event.

[0142] In a possible implementation, after generating the plurality of risk alarm events, the network security warning method of the transformer substation further includes:

[0143] Displaying the plurality of risk alarm events and issuing a voice alarm.

[0144] It should be noted that, as shown in Figure 6 When the risk alarm event occurs, the information of the risk alarm event is presented to the manager in a visual form, that is, the detailed information (risk type, event, involved asset device, etc.) of the risk alarm event is displayed on the monitoring interface, so that the manager can quickly identify and respond. At the same time of displaying the risk alarm event, the manager is alarmed by a sound device (such as a loudspeaker, etc.) to prompt the manager to receive the risk alarm information in time.

[0145] It should be understood that through the interface display and voice alarm, the manager can receive the risk alarm information in the first time and respond quickly, thereby effectively ensuring the safe and stable operation of the secondary equipment communication network of the transformer substation.

[0146] It should be understood that the size of the serial number of each step in the above embodiment does not mean the execution order, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.

[0147] A network security warning method of a transformer substation corresponding to the above embodiment, Figure 7 Fig. 3 shows a structural schematic diagram of a network security warning device of a transformer substation according to an embodiment of the present application. For ease of illustration, only parts related to the embodiments of the present application are shown.

[0148] Referring to Figure 7 The network security warning device 3 of the transformer substation of the embodiment includes:

[0149] The acquisition module 31 is configured to collect the mirror traffic of the plurality of network center switches and the plurality of dispatching data network switches connected to the plurality of asset devices in the secondary equipment communication network of the transformer substation, and obtain the original network traffic data of the plurality of asset devices;

[0150] The processing module 32 is configured to preprocess the original network traffic data to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data flow table processing, data traffic statistical processing and data backup storage processing; and the network traffic data includes data flow table, data traffic value and backup storage data.

[0151] The identification module 33 is configured to extract power communication application protocol, device asset data, data traffic and port in the network traffic data respectively, and identify a plurality of risk data in the secondary equipment communication network of the substation; wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data and port risk data.

[0152] The generation module 34 is configured to integrate the plurality of risk data to generate a plurality of risk alarm events.

[0153] It can be understood that the substation network security early warning device 3 provided by the embodiment is configured to collect the mirror traffic of the plurality of network center switches and the plurality of dispatching data network switches connected with the plurality of asset devices in the secondary equipment communication network of the substation by the acquisition module 31 to obtain original network traffic data of the plurality of asset devices; then, the processing module 32 is configured to preprocess the original network traffic data to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data flow table processing, data traffic statistical processing and data backup storage processing; and the network traffic data includes data flow table, data traffic value and backup storage data; then, the identification module 33 is configured to extract power communication application protocol, device asset data, data traffic and port in the network traffic data respectively, and identify a plurality of risk data in the secondary equipment communication network of the substation; wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data and port risk data; finally, the generation module 34 is configured to integrate the plurality of risk data to generate a plurality of risk alarm events. The substation network security early warning device 3 solves the problem that the existing substation network security monitoring system has low risk monitoring efficiency due to relying on manual configuration and debugging, and cannot effectively identify and process network security at the communication protocol level, thereby improving the real-time security monitoring of the secondary equipment communication network of the substation and enhancing the network security protection capability.

[0154] It should be noted that the information interaction, execution process and the like between the modules in the substation network security early warning device 3 described above are based on the same concept as the method embodiments of the present application, and the specific functions and the technical effects brought by them can be referred to the method embodiments part, which will not be described here.

[0155] The substation network security early warning device provided by the embodiment of the present application is shown in FIG. 4. Figure 8 ​Figure 8 A structural schematic diagram of a network security early warning device of a substation is provided for an embodiment of the present application. Referring to Figure 8 The network security early warning device 4 of the substation of this embodiment comprises a memory 41, a processor 42, and a computer program stored in the memory 41 and executable on the processor 42, and the processor 42 implements the steps in any of the network security early warning method embodiments of the substation when executing the computer program.

[0156] The present application also provides a network security early warning system of a substation, as shown in Figure 9 Figure 9 A structural schematic diagram of a network security early warning system of a substation is provided for an embodiment of the present application. Referring to Figure 9 The network security early warning system 5 of the substation of this embodiment comprises a network security early warning device 4 of a substation, a plurality of network center switches 52, a plurality of dispatch data network switches 53, and a plurality of asset devices 54#n (wherein n is a natural number; n represents the serial number of the asset device 54#n); wherein,

[0157] The plurality of first physical network ports of the network security early warning device 4 of the substation are connected with the mirror ports of the plurality of network center switches 52; the plurality of second physical network ports of the network security early warning device 4 of the substation are connected with the mirror ports of the dispatch data network switches 53; the plurality of asset devices 54#n are directly or indirectly connected with the communication ports of the plurality of network center switches 52 and the communication ports of the plurality of dispatch data network switches 53;

[0158] The network security early warning device 4 of the substation is configured to acquire original network flow data of a plurality of asset devices in a substation secondary equipment communication network from the mirror ports of the plurality of network center switches and the plurality of dispatch data network switches; pre-process the original network flow data to obtain network flow data of the plurality of asset devices, wherein the pre-processing comprises data flow table processing, data flow statistical processing, and data backup storage processing; the network flow data comprises a data flow table, a data flow value, and backup storage data; and extract power communication application protocols, device asset data, data flow, and ports in the network flow data, respectively, to identify a plurality of risk data in the substation secondary equipment communication network; wherein the risk data at least comprises one of the following: asset risk data, flow risk data, communication protocol risk data, and port risk data; and integrate the plurality of risk data to generate a plurality of risk alarm events; and is further configured to detect the plurality of asset devices 54#n from the communication ports of the plurality of network center switches 52 and scan open ports of the plurality of asset devices 54#n.

[0159] ​It should be noted that the network security early warning device 4 of the substation is the core device in the network security early warning system 5 of the substation, which is installed with the network security risk early warning application software and the man-machine client software of the substation, has powerful data processing and analysis capabilities, and realizes the network security early warning method of the substation in any of the above aspects through the network security risk early warning application software of the substation, that is, for obtaining the original network flow data of a plurality of asset devices 54#n in the substation secondary equipment communication network from the mirror ports of a plurality of network center switches 52 and a plurality of dispatching data network switches 53; preprocessing the original network flow data to obtain network flow data of the plurality of asset devices 54#n, wherein the preprocessing includes data flow table processing, data flow statistical processing and data backup storage processing; the network flow data includes data flow table, data flow value, backup storage data; and extracting the power communication application protocol, device asset data, data flow and port in the network flow data respectively, and identifying a plurality of risk data in the substation secondary equipment communication network; wherein the risk data at least includes one of the following: asset risk data, flow risk data, communication protocol risk data, port risk data; and integrating processing the plurality of risk data to generate a plurality of risk alarm events; and further for detecting the plurality of asset devices 54#n from the communication ports of the plurality of network center switches 52 and scanning the open ports of the plurality of asset devices 54#n. Wherein the network center switch 52 is a key device for connecting a plurality of asset devices in the substation secondary equipment network, which is responsible for forwarding data flow in the network, allowing network flow data to be copied into the network security early warning device 4 of the substation for analysis, and also allowing the network security early warning device 4 of the substation to detect and port scan the asset devices 54#n. The dispatching data network switch 53 is to transmit network flow data from the substation to a higher level network or data center.

[0160] It should be noted that in this embodiment, the number of network center switches 52 and dispatching data network switches 53 in the network security early warning system 5 of the substation is not limited.

[0161] It should be noted that in this embodiment, the asset devices 54#n can be directly connected to the communication ports of the plurality of network center switches 52 and the communication ports of the plurality of dispatching data network switches 53; or indirectly connected to the communication ports of the plurality of network center switches 52 and the communication ports of the plurality of dispatching data network switches 53, that is, the asset devices 54#n are first connected to the next level of interval layer switches, and then interconnected with the communication ports of the plurality of network center switches 52 and the communication ports of the plurality of dispatching data network switches 53 through the interval layer switches.

[0162] In the embodiment, the operating system of the network security early warning device 4 of the transformer substation is a Linux security system, the memory capacity is not less than 16 GB, the solid state disk capacity is not less than 1 TB, at least 4 Giga electric ports are equipped, and a display screen of not less than 14 inches is equipped. These device parameters are selected to ensure the portability, stability and processing capacity of the network security early warning device 4 of the transformer substation, so that the software functions can normally operate in various environments, thereby realizing the plug-and-play network security early warning system of the transformer substation.

[0163] As shown in Figure 9 , the system supports two network security working modes, namely, a mirror flow mode and a mixed mode. In the mirror flow mode, the system does not actively send any message to the secondary equipment communication network of the transformer substation, and only passively receives the mirror flow of the network center switch 52. In this working mode, no additional configuration operation is needed, and only the network security risk early warning application software of the transformer substation needs to be started, and the network security early warning device 4 of the transformer substation is connected to the mirror port of the network center switch 52. This mode does not affect the network and asset devices, and this is the default running mode. In the mixed mode, the configuration is also simple. The first physical network port of the network security early warning device 4 of the transformer substation is connected to the mirror port of the network center switch 52, and the second physical network port of the network security early warning device 4 of the transformer substation is connected to the mirror port of the dispatching data network switch 53, so as to obtain the original network flow data of multiple asset devices in the secondary equipment communication network of the transformer substation. The first physical network port and the second physical network port are the network ports of the network security early warning device 4 of the transformer substation for physical connection. The network security early warning device 4 of the transformer substation can also perform active detection from the communication ports of multiple network center switches 52. The active detection is mainly used for the discovery of asset devices and the scanning of open ports of asset devices. The system strictly controls the packet sending interval during the active detection, and can be manually adjusted to avoid affecting the production devices. It should be noted that the active detection function of the system can be turned on and turned off at any time without the need to restart the operating system or the application software. The system automatically switches between the two working modes according to the on and off settings of the active detection function.

[0164] The deployment of the network security early warning device 4 of the transformer substation in the network security early warning system 5 of the transformer substation is shown in Figure 9 . In the secondary equipment network of the transformer substation, there are generally two working area networks (i.e., a safety I area network and a safety II area network), and one network security early warning device 4 of the transformer substation can be deployed at each network center switch 52 of the working area network. Figure 9 In the embodiment, the asset device 54#1, the asset device 54#2 and the asset device 54#3 can be a five-proof machine, a workstation and a monitoring machine respectively.

[0165] As shown in Figure 10As shown in the figure, Figure 10 is a human-computer interface schematic diagram of a network security early warning device for a substation according to an embodiment of the present application. As shown in the figure, Figure 10 The network security risk early warning application software in the network security early warning device 4 for the substation integrates modules such as traffic monitoring, asset management, early warning rules, alarm event query, log query (user operation log query), debugging operation (real-time message capture and saving operation), user management (human-computer interface user permission management), security overview (security overall information statistics), etc.

[0166] As shown in the figure, Figure 11 Figure 11 is a system architecture diagram of a network security early warning device for a substation according to an embodiment of the present application. As shown in the figure, Figure 11 The network security risk early warning application software in the network security early warning device 4 for the substation adopts a three-layer architecture, which is divided into a data acquisition layer, an analysis processing layer, and a data display layer, and mainly includes functions such as asset detection, high-risk port detection, application protocol deep analysis, traffic statistics, rule engine, etc. The network security early warning device 4 for the substation is deployed in the secondary equipment communication network of the substation, collects network traffic data in the secondary equipment communication network through the mirror ports of the network center switch 52 and the dispatching data network switch 53, analyzes and processes the network traffic data, identifies and alarms security risks, and displays the alarm and voice alarm on the human-computer interface.

[0167] It can be understood that the network security early warning system 5 for the substation provided in this embodiment collects the mirror traffic of a plurality of network center switches and a plurality of dispatching data network switches connected with a plurality of asset devices in the secondary equipment communication network of the substation to obtain original network traffic data of the plurality of asset devices; pre-processes the original network traffic data to obtain network traffic data of the plurality of asset devices, wherein the preprocessing includes data stream table processing, data traffic statistics processing, and data backup storage processing; the network traffic data includes data stream table, data traffic value, and backup storage data; extracts power communication application protocols, device asset data, data traffic, and ports in the network traffic data to identify a plurality of risk data in the secondary equipment network of the substation; wherein the risk data at least includes one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data; and finally, integrates and processes the plurality of risk data to generate a plurality of risk alarm events. Through this system, the problem that the existing network security monitoring system for the substation is inefficient in risk monitoring due to reliance on manual configuration and debugging, and cannot effectively identify and process network security at the communication protocol level is solved, thereby improving the real-time security monitoring strength of the secondary equipment communication network of the substation and enhancing the network security protection capability. ​

[0168] It can be understood that, compared with the existing network security monitoring system of the transformer substation, the network security monitoring system of the transformer substation provided in the application has the following advantages:

[0169] (1) Improve the monitoring strength of the secondary equipment communication network of the transformer substation: the system can comprehensively monitor and early warn the secondary equipment communication network of the transformer substation, not only can collect and monitor the network traffic in the secondary equipment communication network of the transformer substation, but also can analyze and decode the communication application protocol of the power network on this basis, identify and early warn dangerous behaviors such as control type operation, file transmission operation, remote connection operation, system login operation and the like in the power communication application protocol in the network, at the same time, can detect asset devices in the network in an active and passive combined manner, identify risk data such as asset device state, asset security access, asset change, and finally realize identification of dangerous ports in two ways of scanning and flow table data analysis, thereby greatly improving the network monitoring strength.

[0170] (2) Simplify device access: the network security early warning device access process of the transformer substation in the system is simplified, only the mirror port of the network center switch and the dispatching data network switch in the secondary equipment communication network of the transformer substation needs to be collected, without the need to configure the network communication configuration between the monitored network assets and the system, realizing plug and play, greatly improving the device access efficiency.

[0171] (3) Strengthen asset management: the system has a powerful asset management function, can comprehensively and intelligently manage the secondary communication equipment of the transformer substation, without manual intervention, providing strong support for the maintenance and management of the equipment.

[0172] (4) Improve security protection capability: the system increases the analysis of the main communication application protocol in the secondary equipment communication network of the transformer substation, identifies dangerous operations existing in the power network from the power communication application protocol layer, such as remote operation, value modification, configuration download, file transmission, dangerous protocol and the like, thereby effectively identifying and processing new network attack methods, improving the security protection capability.

[0173] (5) Save operation and maintenance cost: the design of the system greatly improves the usability, reusability and deployment efficiency of the system, reduces the operation burden of the management personnel, thereby saving the operation and maintenance cost.

[0174] The application embodiment also provides a computer readable storage medium, the computer readable storage medium stores a computer program, and the computer program is executed by a processor to realize the steps in each of the above method embodiments.

[0175] The embodiment of the present application provides a computer program product, when the computer program product is run on the mobile terminal, the mobile terminal is caused to execute the steps in the above-mentioned various method embodiments.

[0176] The integrated unit, if in the form of a software function unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on such understanding, the present application can implement all or part of the processes in the above-mentioned embodiment methods, which can be completed by instructing related hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, an executable file, or some intermediate form. The computer-readable medium at least includes any entity or device capable of carrying the computer program code to the photographing device / terminal equipment, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunications signal, and a software distribution medium. For example, a U disk, a mobile hard disk, a magnetic disk or an optical disk, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunications signal.

[0177] In the above-mentioned embodiments, the description of each embodiment has its own focus, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0178] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0179] In the embodiments provided by the present application, it should be understood that the disclosed apparatus / network device and method can be implemented in other manners. For example, the embodiments of the apparatus / network device described above are merely illustrative. For example, the division of the modules or units is merely logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.

[0180] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.

[0181] The above embodiments are merely used to describe the technical solutions of the present application, but not to limit the present application; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: the technical solutions recorded in the foregoing embodiments can still be modified, or some technical features can be replaced by equivalent replacements; and these modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A network security early warning method for substations, characterized in that, include: The mirror traffic of multiple network center switches and multiple dispatch data network switches connected to multiple asset devices in the communication network of substation secondary equipment is collected to obtain the original network traffic data of the multiple asset devices. The raw network traffic data is preprocessed to obtain network traffic data for multiple asset devices. The preprocessing includes data flow table processing, data traffic statistics processing, and data backup and storage processing. The network traffic data includes data flow tables, data traffic values, and backup and storage data. The power communication application protocol, equipment asset data, data traffic, and port data in the network traffic data are extracted respectively to identify multiple risk data in the communication network of the substation secondary equipment; wherein, the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data; Multiple risk data points are integrated and processed to generate multiple risk alarm events; wherein, the power communication application protocol, equipment asset data, data traffic, and ports are extracted from the network traffic data to identify multiple risk data points in the substation secondary equipment communication network, including: Based on the data flow table, the power communication application protocol types of multiple data flows are identified; Based on the power communication application protocol type and preset protocol decoding rules, instruction set decoding is performed on the power communication application protocols of multiple data streams in the substation secondary equipment communication network to obtain multiple communication protocol risk data in the substation secondary equipment communication network; and... Based on the data flow table, the source ports and destination ports of multiple data flows are extracted; By matching the source and destination ports of multiple data streams with preset high-risk port rules, the port risk data in the substation secondary equipment communication network is identified; and... By comparing the data traffic value with multiple preset traffic security thresholds using multiple preset dimensions, multiple traffic risk data in the substation secondary equipment communication network are identified; wherein the multiple preset dimensions include at least one of the following: total network traffic data traffic value, transmit / receive traffic value of each asset device, and communication data traffic value between asset devices; and, The source Internet Protocol address and source physical address of the data stream are obtained from the data streams of communication between multiple asset devices in the data stream table or from the response data streams received after actively sending an asset probe ARP request. Based on the source Internet Protocol address and source physical address, the equipment asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein, the equipment asset data includes the asset Internet Protocol address and the asset physical address; Multiple suspected asset data in the equipment asset data are identified to obtain multiple asset risk data in the substation secondary equipment communication network; wherein, the suspected asset data includes: data on changes in the physical address corresponding to the asset Internet Protocol address, data on newly added asset Internet Protocol addresses, and data on newly added asset physical addresses.

2. The network security early warning method for substations as described in claim 1, characterized in that, The step involves decoding the power communication application protocols of multiple data streams in the substation secondary equipment communication network according to the power communication application protocol type and preset protocol decoding rules, to obtain multiple communication protocol risk data in the substation secondary equipment communication network, including: If decoding fails, the communication protocol risk data is obtained. If decoding is successful, the protocol decoding results corresponding to the power communication application protocols of multiple data streams are obtained, and the multiple protocol decoding results are matched with preset protocol security rules to identify multiple communication protocol risk data in the substation secondary equipment communication network.

3. The network security early warning method for substations as described in claim 1, characterized in that, The method further includes: The network mapper Nmap performs port scanning on multiple asset devices in the substation secondary equipment communication network according to a preset scanning method to identify multiple open ports; wherein, the preset scanning method includes: point-to-point port scanning method and specified port range fast scanning method; By matching multiple open ports with preset high-risk port rules, the port risk data in the substation secondary equipment communication network is identified.

4. The network security early warning method for substations as described in claim 1, characterized in that, After generating multiple risk alarm events, the method further includes: Based on the risk alarm event, the data stream information corresponding to the risk alarm event is extracted; wherein, the data stream information includes the source Internet Protocol address, source port, destination Internet Protocol address, destination port, and power communication application protocol of the data stream; Based on the data stream information, multiple message records corresponding to the risk alarm event are extracted from the backup storage data. The multiple message records are aggregated to generate an alarm data record corresponding to the risk alarm event.

5. A network security early warning device for a substation, characterized in that, include: The acquisition module is used to collect the mirror traffic of multiple network center switches and multiple scheduling data network switches connected to multiple asset devices in the communication network of the substation secondary equipment, and obtain the original network traffic data of the multiple asset devices. The processing module is used to preprocess the raw network traffic data to obtain network traffic data of multiple asset devices. The preprocessing includes data flow table processing, data traffic statistics processing, and data backup and storage processing. The network traffic data includes data flow tables, data traffic values, and backup and storage data. The identification module is used to extract power communication application protocols, equipment asset data, data traffic, and ports from the network traffic data, and identify multiple risk data in the communication network of the substation secondary equipment; wherein, the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data; The generation module is used to integrate and process multiple risk data sets to generate multiple risk alarm events; wherein, The identification module is specifically used for: Based on the data flow table, the power communication application protocol types of multiple data flows are identified; Based on the power communication application protocol type and preset protocol decoding rules, instruction set decoding is performed on the power communication application protocols of multiple data streams in the substation secondary equipment communication network to obtain multiple communication protocol risk data in the substation secondary equipment communication network; and... Based on the data flow table, the source ports and destination ports of multiple data flows are extracted; By matching the source and destination ports of multiple data streams with preset high-risk port rules, the port risk data in the substation secondary equipment communication network is identified; and... By comparing the data traffic value with multiple preset traffic security thresholds using multiple preset dimensions, multiple traffic risk data in the substation secondary equipment communication network are identified; wherein the multiple preset dimensions include at least one of the following: total network traffic data traffic value, transmit / receive traffic value of each asset device, and communication data traffic value between asset devices; and, The source Internet Protocol address and source physical address of the data stream are obtained from the data streams of communication between multiple asset devices in the data stream table or from the response data streams received after actively sending an asset probe ARP request. Based on the source Internet Protocol address and source physical address, the equipment asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein, the equipment asset data includes the asset Internet Protocol address and the asset physical address; Multiple suspected asset data in the equipment asset data are identified to obtain multiple asset risk data in the substation secondary equipment communication network; wherein, the suspected asset data includes: data on changes in the physical address corresponding to the asset Internet Protocol address, data on newly added asset Internet Protocol addresses, and data on newly added asset physical addresses.

6. A network security early warning device for a substation, characterized in that, The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the network security early warning method for a substation as described in any one of claims 1 to 4.

7. A network security early warning system for substations, characterized in that, The system includes: network security early warning equipment for substations, multiple network center switches, multiple dispatch data network switches, and multiple asset equipment; among which, The network security early warning device of the substation has multiple first physical network ports connected to multiple mirror ports of the network center switch; the network security early warning device of the substation has multiple second physical network ports connected to the mirror ports of the dispatch data network switch; and multiple asset devices are directly or indirectly connected to the communication ports of the multiple network center switches and the multiple dispatch data network switches, respectively. The network security early warning device of the substation is used to acquire raw network traffic data of multiple asset devices in the substation secondary equipment communication network from mirror ports of multiple network center switches and multiple scheduling data network switches; preprocess the raw network traffic data to obtain network traffic data of multiple asset devices, wherein the preprocessing includes data flow table processing, data traffic statistics processing, and data backup storage processing; the network traffic data includes data flow tables, data traffic values, and backup storage data; and extracts power communication protocols, equipment asset data, data traffic, and ports from the network traffic data to identify the substation. Multiple risk data points in the power plant secondary equipment communication network; wherein the risk data includes at least one of the following: asset risk data, traffic risk data, communication protocol risk data, and port risk data; and, integrating and processing the multiple risk data points to generate multiple risk alarm events; and, further used to probe multiple asset devices from the communication ports of multiple network central switches and scan the open ports of multiple asset devices; wherein, the extraction of power communication application protocols, equipment asset data, data traffic, and ports from the network traffic data to identify multiple risk data points in the substation secondary equipment communication network includes: Based on the data flow table, the power communication application protocol types of multiple data flows are identified; Based on the power communication application protocol type and preset protocol decoding rules, instruction set decoding is performed on the power communication application protocols of multiple data streams in the substation secondary equipment communication network to obtain multiple communication protocol risk data in the substation secondary equipment communication network; and... Based on the data flow table, the source ports and destination ports of multiple data flows are extracted; By matching the source and destination ports of multiple data streams with preset high-risk port rules, the port risk data in the substation secondary equipment communication network is identified; and... By comparing the data traffic value with multiple preset traffic security thresholds using multiple preset dimensions, multiple traffic risk data in the substation secondary equipment communication network are identified; wherein the multiple preset dimensions include at least one of the following: total network traffic data traffic value, transmit / receive traffic value of each asset device, and communication data traffic value between asset devices; and, The source Internet Protocol address and source physical address of the data stream are obtained from the data streams of communication between multiple asset devices in the data stream table or from the response data streams received after actively sending an asset probe ARP request. Based on the source Internet Protocol address and source physical address, the equipment asset data of the asset equipment in the substation secondary equipment communication network is identified; wherein, the equipment asset data includes the asset Internet Protocol address and the asset physical address; Multiple suspected asset data in the equipment asset data are identified to obtain multiple asset risk data in the substation secondary equipment communication network; wherein, the suspected asset data includes: data on changes in the physical address corresponding to the asset Internet Protocol address, data on newly added asset Internet Protocol addresses, and data on newly added asset physical addresses.

Citation Information

Patent Citations

  • Network risk monitoring method and system for substation

    CN107241224A

  • Intelligent substation network security protection system

    CN110768846A