Security identification method and device and terminal equipment
By conducting protocol analysis and security identification of communication messages in the substation monitoring system, and using the preset security rule database to identify risk messages, the problem that the existing technology cannot effectively identify the risks of the substation monitoring system is solved, and efficient security identification and system security improvement are achieved.
Patent Information
- Application Number
- CN202411962261.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-27
AI Technical Summary
Existing security identification methods cannot effectively identify the risks in the substation monitoring system, and rely on specialized hardware equipment or software systems, increasing deployment complexity and cost.
By collecting the current communication messages of the substation monitoring system, conducting protocol analysis, determining the target protocol data, and using the preset security rule database to securely identify the target protocol data to identify whether it is a risk message.
It realizes effective identification of risk messages in the substation monitoring system, improves system security, and reduces hardware dependence and deployment complexity.
Smart Images

Figure CN119945742A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of network security technology, and in particular, relates to a security identification method, device and terminal equipment. Background Art
[0002] With the development of smart substations, the network communication structure of substation monitoring systems has become increasingly large and complex, and often faces various network security threats. It is necessary not only to strengthen the identification of network access security, but also to identify and monitor security risks at the level of network communication protocol analysis.
[0003] However, existing security identification methods can only perform coarse-grained identification of communication messages, and the identification means are relatively simple and cannot effectively identify the risks existing in the substation monitoring system. Summary of the invention
[0004] The embodiments of the present application provide a security identification method, apparatus and terminal device, which can specifically identify communication messages and effectively identify risks existing in the substation monitoring system.
[0005] In a first aspect, an embodiment of the present application provides a security identification method, including:
[0006] Collect current communication messages from the substation monitoring system;
[0007] Performing protocol analysis on the current communication message to obtain protocol information of the current communication message, where the protocol information at least includes communication protocol data and message type;
[0008] According to whether the message type is the message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, and the target protocol data is the protocol data to be securely identified corresponding to the current communication message;
[0009] The preset security rule base is used to perform security identification on the target protocol data to obtain the security identification result of the current communication message. The preset security rule base is used to identify whether the current communication message is a risky message.
[0010] In a second aspect, an embodiment of the present application provides a security identification device, including:
[0011] The acquisition module is used to collect the current communication messages of the substation monitoring system;
[0012] The protocol analysis module is used to perform protocol analysis on the current communication message to obtain the protocol information of the current communication message, and the protocol information at least includes the communication protocol data and the message type;
[0013] A first determination module is used to determine the target protocol data corresponding to the current communication message using the communication protocol data according to whether the message type is the message type to be associated, where the target protocol data is the protocol data to be securely identified corresponding to the current communication message;
[0014] The first security identification module is used to perform security identification on the target protocol data using a preset security rule base to obtain a security identification result of the current communication message. The preset security rule base is used to identify whether the current communication message is a risky message.
[0015] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in any one of the first aspects is implemented.
[0016] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in any one of the first aspects is implemented.
[0017] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute any of the methods described in the first aspect above.
[0018] The embodiment of the present application provides a security identification method, device and terminal equipment, the method comprising: collecting the current communication message of the substation monitoring system; performing protocol analysis on the current communication message to obtain the protocol information of the current communication message, the protocol information at least including communication protocol data and message type; according to whether the message type is the message type to be associated, using the communication protocol data to determine the target protocol data corresponding to the current communication message, the target protocol data is the protocol data to be security identified corresponding to the current communication message; using a preset security rule library to perform security identification on the target protocol data to obtain the security identification result of the current communication message, the preset security rule library is used to identify whether the current communication message is a risk message. Utilizing the above technical solution, by determining whether the message type of the current communication message is the message type to be associated, the target protocol data of the current communication message can be accurately determined, and the preset security rule library is used to perform targeted identification on the target protocol data, thereby achieving effective identification of risk messages in the substation monitoring system and improving the security of the substation monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 It is a flowchart of a security identification method provided by an embodiment of the present application;
[0021] Figure 2 is a flowchart of a security identification method provided by another embodiment of the present application;
[0022] Figure 3 This is a schematic diagram of the working principle of a security rule engine library provided by an embodiment of the present application;
[0023] Figure 4 It is an overall schematic diagram of a security identification method provided by an embodiment of the present application;
[0024] Figure 5 This is a flow chart of a secure identification process of an IEC61850 communication message provided by an embodiment of the present application;
[0025] Figure 6 It is a flow chart of a secure identification of IEC104 communication messages provided by an embodiment of the present application;
[0026] Figure 7 This is a schematic diagram of a process of outputting a security alarm event provided by an embodiment of the present application;
[0027] Figure 8 It is a schematic diagram of a process for updating a preset security rule library provided by an embodiment of the present application;
[0028] Fig. 9 It is a structural block diagram of a security identification device provided by an embodiment of the present application;
[0029] Fig.10 It is a structural diagram of a terminal device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0030] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0031] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0032] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0033] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0034] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0035] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0036] It should be noted that the information collection process (such as system network traffic collection process, communication message collection, etc.) / feature extraction process involved in this application is performed with the user's knowledge and permission, that is, the information collection process / feature extraction process complies with the requirements of laws and regulations and does not constitute an act that harms the public interest.
[0037] The security identification method provided in the embodiments of the present application can be applied to terminal devices such as tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPC), personal digital assistants (PDA), etc. The embodiments of the present application do not impose any restrictions on the specific types of terminal devices.
[0038] It can be considered that in the substation monitoring system, the communication protocol is directly related to the stable operation of the power grid and the secure transmission of data, and it is crucial to ensure the security of the communication protocol.
[0039] Existing security identification methods mainly use dedicated network security equipment, such as firewalls, intrusion detection systems, network security monitoring devices, etc., to monitor and protect network security access to substation monitoring system equipment. The main problem they solve is monitoring network security access and blocking illegal connections. Although they can provide certain protection capabilities to a certain extent, they usually need to rely on specialized hardware equipment or software systems, which not only increases the complexity and cost of system deployment, but also limits its application in some resource-constrained environments.
[0040] At the same time, the above-mentioned dedicated network security equipment needs to be deployed in a dispersed manner during the substation deployment process, for example, multiple security devices need to be configured or security monitoring software needs to be deployed on multiple host devices, which makes deployment and maintenance inconvenient. In addition, existing security identification methods can often only perform coarse-grained identification of network access, lacking in-depth analysis of the data content of the mainstream communication protocols of substation secondary equipment and identification of security behavior risks; when dealing with large-scale substation network structures, there are problems such as insufficient security monitoring coverage and performance bottlenecks.
[0041] Based on this, the embodiment of the present application provides a security identification method that can establish a complete security rule base at the network communication protocol application data parsing level of the substation monitoring system without relying on special network security function hardware equipment, and the rule base can be flexibly expanded.
[0042] At the same time, it is not limited to coarse-grained security monitoring of network traffic access to the substation monitoring system. The embodiment of the present application can decode and analyze the communication data according to the communication network protocol technical standards / specifications used by the substation monitoring system, and combine the establishment of a complete security rule base to identify the security risks in the communication protocol data transmission and exchange process.
[0043] In addition, it can reduce the dispersion of the deployment of substation network security monitoring functions, reduce configuration and manual maintenance in different substation system scenarios, and be more universal and convenient; when dealing with large-scale network structures, it can conduct comprehensive risk identification and monitoring of the entire station control layer and interval layer network asset equipment of the substation monitoring system.
[0044] Figure 1 This is a flowchart of a security identification method provided in an embodiment of the present application. As an example but not a limitation, the method can be applied to a terminal device.
[0045] S101. Collect current communication messages of the substation monitoring system.
[0046] The substation monitoring system can refer to a system formed by the secondary equipment devices of the substation interval layer and the station control layer. The substation monitoring system network can be a communication network formed by interconnecting all the secondary equipment devices through switches. Among them, the interval layer mainly includes multiple types of equipment such as relay protection devices, measurement and control devices, stability control devices, fault recorders, etc. The station control layer mainly includes monitoring hosts, five-defense hosts, integrated application servers, data communication gateways, etc. The current communication message can be considered as the network message currently using the substation monitoring system network for communication.
[0047] This embodiment can collect the current communication messages of the substation monitoring system. The collection method and means are not limited. For example, the current communication messages in the substation monitoring system can be collected in real time, or all communication messages involved in the substation monitoring system can be collected periodically, and all collected communication messages can be used as the current communication messages corresponding to the current collection period.
[0048] S102: Perform protocol analysis on the current communication message to obtain protocol information of the current communication message, where the protocol information at least includes communication protocol data and message type.
[0049] Protocol information may refer to information related to the communication protocol in the current communication message, such as protocol information may at least include communication protocol data and message type. Communication protocol data may be understood as key information in the current communication message that characterizes the application level of the communication protocol. Communication protocol data corresponding to different communication protocols may be different. For example, the communication protocol data for the IEC61850 communication protocol may include key information such as PDU type, service type, MMS domain, MMS variable name, etc., and the communication protocol data for the IEC104 communication protocol may include information such as APCI frame type, ASDU type, transmission reason, ASDU public address, information body address, information body value, etc. The message type is the message type of the current communication message, such as the message type to be associated and other message types except the message type to be associated. The message type to be associated may refer to a message type that needs to be associated with other messages for subsequent security identification. The specific content is not limited, such as the request message type and the response message type corresponding to the request message type. It may also include messages belonging to a specified communication address, or other message types that need to be associated.
[0050] In this step, a protocol analysis can be performed on the collected current communication message to obtain the protocol information of the current communication message. The specific means of protocol analysis are not limited. For example, the protocol analysis can be performed based on a neural network model, and the current communication message is input into a preset neural network model to directly output the protocol information of the current communication message. The protocol information of the current communication message can also be obtained by gradually analyzing the current communication message. For example, the source / destination MAC address of the current communication message can be extracted at the network Ethernet layer, the source / destination IP of the current communication message can be extracted at the IP layer, the source / destination port of the current communication message can be extracted at the transport layer, and the current communication message can be decoded and analyzed at the application layer. The basis for the decoding analysis can be the specific definition of the data format of each frame of the communication message by the communication protocol, which is not limited in this embodiment.
[0051] S103. According to whether the message type is a message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, where the target protocol data is the protocol data to be securely identified corresponding to the current communication message.
[0052] The target protocol data may be considered as the protocol data to be securely identified corresponding to the current communication message.
[0053] After obtaining the protocol information of the current communication message through the above steps, this step can be used to specifically determine the target protocol data corresponding to the current communication message according to whether the message type is a message type to be associated. The determination method of the target protocol data corresponding to different message types may be different. For example, if the message type is not a message type to be associated, it means that the current communication message does not have a message that needs to be associated, then the communication protocol data can be directly determined as the target protocol data corresponding to the current communication message for subsequent security identification; correspondingly, if the message type is a message type to be associated, it means that the current communication message has a message that needs to be associated, then the target protocol data corresponding to the current communication message can be determined by combining the associated communication messages of the current communication message. This embodiment will not be further expanded on this.
[0054] In a specific implementation, it is possible to determine whether the message type is the message type to be associated for all current communication messages, or it is possible to determine whether the message type is the message type to be associated for only some of the current communication messages. For example, different operations may be performed according to the type of communication protocol used by the current communication message, or different execution operations may be performed according to other contents of the current communication message.
[0055] In some embodiments, the communication protocol data includes a communication protocol type, and according to whether the message type is a message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, including:
[0056] If the communication protocol type indicates that the communication protocol used by the current communication message is the network communication protocol specified by the substation monitoring system, the communication protocol data is used to determine the target protocol data corresponding to the current communication message according to whether the message type is the message type to be associated.
[0057] The network communication protocol specified by the substation monitoring system can be configured according to actual needs, and may include the mainstream network communication protocols in the substation monitoring system, such as the IEC104 and IEC61850 network communication protocols that are widely used in power systems, energy industries and other fields. Especially in the entire secondary equipment system network of the substation system, IEC61850 and IEC104 communication protocols can be used as the main communication protocols for data collection and remote data transmission between devices, or specific network communication protocols can be added or deleted according to system development.
[0058] In a specific implementation, the communication protocol data may include a communication protocol type. If the communication protocol type indicates that the communication protocol used by the current communication message is a network communication protocol specified by the substation monitoring system, the message type of the current communication message may be further judged to determine the target protocol data corresponding to the current communication message. On this basis, the target protocol data may be specifically determined for different current communication messages, thereby improving the accuracy of the target protocol data.
[0059] S104. Use a preset security rule base to perform security identification on the target protocol data to obtain a security identification result of the current communication message. The preset security rule base is used to identify whether the current communication message is a risky message.
[0060] The preset security rule library can be a pre-configured security rule library that stores multiple security rules for identifying whether the current communication message is a risky message. For example, a series of custom rules can be designed for the specific characteristics and potential threats of the substation network communication protocol, including the basic interaction process of the protocol, key field verification, specific byte stream data and other dimensions, to establish a security rule engine library containing multiple security rules. These security rules can accurately identify suspicious communication protocols in the substation system (such as communication protocols that are not allowed to be used in the substation monitoring system network), and can also identify malicious operations that occur in the actual use of network protocols, such as control command operations, file transfer operations, data tampering, etc.
[0061] Specifically, this embodiment can use a preset security rule library to perform security identification on the target protocol data to obtain a security identification result of the current communication message. The specific security identification process is not limited. For example, the security identification result of the current communication message can be obtained by feature matching the preset security rule library with the target protocol data, or the security identification result of the current communication message can be directly output through the identification model, as long as the security identification result of the current communication message can be obtained.
[0062] Exemplarily, each security rule may be a set of statements based on a pattern, and each security rule may be composed of multiple parts, including a header and an option part, wherein the header part may start with an alert field, defining the basic matching conditions of the security rule, including information such as communication protocol, source IP, destination IP, source port, and destination port. For example, a security rule may be alert tcp any any->192.168.110.0 / 24 80(msg:"Example rule";sid:1000001;), indicating that when TCP traffic of any source IP and port accesses port 80 of the 192.168.110.0 / 24 subnet, an alarm event is triggered.
[0063] The options part can further specify matching conditions and triggering actions. Common options may include msg (message), sid (rule ID), rev (rule version), content (content matching), etc. For example, a security rule may be alertmms any any->any any(msg:"MMS control";mms:pdu_type confirmed,service write,item\$CO\$\S+\$Oper,item_pcre,result any;classtype:important-operation;priority:4;sid:61850007;rev:1;), which means that when the flow data of mms (ie IEC61850 protocol) from any source to any destination is identified and matches the content of the protocol operation rule option field defined by content, an alarm event is triggered.
[0064] In a specific implementation, corresponding security rules may be formulated for each type of communication protocol.
[0065] (1) For the security rule configuration of the IEC61850 communication protocol, the security events involved in the communication protocol can be defined. For example, the security rules can be configured using the Suricata rule syntax, which is compatible with the original Suricata rules and expands the mms option field as the IEC61850 security rule configuration.
[0066] Specifically, the security rules of IEC61850 support the configuration of PDU type, service type, MMS domain, MMS variable name, and operation result. The format is "mms:[option],[option],...;". The rule starts with mms:; it contains several conditional options separated by commas and ends with a semicolon. The conditional options can include the following fields:
[0067] "pdu_type <type>”: Configure PDU type condition options, <type>The possible values are "Confirmed", "Cancel", "Initiate", "Conclude", and "Any", which are not case-sensitive.
[0068] "service <name>”: Configure the service name. It is valid when pdu_type is configured as "Comfirmed". The possible values are "read", "write", "fileDelete", "obtainFile" and other 78 types of services supported by the IEC61850 protocol. The service name is not case-sensitive.
[0069] "domain <name>”: Configure the MMS domain, which is valid when service is read or write. <name>It is a string (such as B5023XCTRL) and can be modified by domain_full, domain_nocase, and domain_pcre options. "domain_full": domain matching can be done with full matching, and non-full matching is the default; "domain_nocase": domain matching ignores case; "domain_pcre": domain matching uses regular expressions;
[0070] "item <name>”: Configure the MMS variable name, which is valid when service is read or write. <name>It is a string (such as CSWI1$CO$Pos$Oper), which can be modified by item_full, item_nocase, and item_pcre options. "item_full" means full matching of variable names; "item_nocase" means case is ignored when matching variable names; "item_pcre" means regular expressions are used when matching variable names.
[0071] "result <res>": Matching operation results, <res>Possible values are "any", "success", and "failed".
[0072] Exemplarily, the IEC61850 communication protocol may include the following security rules:
[0073] #alert mms any any->any any (msg: "MMS upload file"; mms: pdu_type confirmed, service obtainFile, result any; classtype: important-operation; priority: 2; sid: 61850001; rev: 1;);
[0074] #alert mms any any->any any(msg:"MMS write configuration"; mms:pdu_type confirmed,service write,item$SP$,result any;classtype:important-operation;priority:4;sid:61850006;rev:1;).
[0075] (2) For the security rule configuration of the IEC104 communication protocol, the security events involved in the communication protocol can be defined. For example, the IEC104 configuration rule supports the configuration of APCI frame type, ASDU type, transmission reason, ASDU public address, information body address, and information body value. The format is "iec104:[option],[option],...;". The rule starts with "iec104:", followed by several conditional options. Different options are separated by commas and end with a semicolon. The conditional options can include the following fields:
[0076] "apci_type <type>”: Configure APCI frame type, <type>Possible values are "any", "U.STARTDT_con", "U.STARTDT_act", "U.STOPDT_con", "U.STOPDT_act", "U.TESTFR_con", "U.TESTFR_act", "S", "I", used to check whether the frame type is U frame, I frame, or S frame;
[0077] "asdu_type <type>": Configure asdu type, valid when apci_type is configured as "I", <type>It is a number and supports all ASDU types defined in DL / T 634.5101 and DL / T 634.5104. It supports a single ASDU type and range. The range is separated by "<>" (such as: 20<>30);
[0078] "asdu_cot <cot>”: configure the transmission reason, <cot>For numbers, support configuration of single value and range; "asdu_addr <addr>”: Configure ASDU public address, <addr>For numbers, support configuration of single value and range; "asdu_ioa <ioa>”: configuration information body address, <ioa>For numbers, support configuration of single value and range; "asdu_data <data>”: Configuration information value, <data>For numbers, support configuration of single value and range; "result <res>": Matching operation results, <res>Possible values are "any", "success", and "failed".
[0079] Exemplarily, the IEC 104 communication protocol may include safety rules for control operation activation and control operation failure:
[0080] #alert iec104 any any->any any(msg:"iec104 yk single / double command"; iec104:apci any,asdu_type 45<>46,asdu_cot 6; sid:104103; rev:1;);
[0081] #alert iec104 any any->any any(msg:"iec104 yk single / double commandnak_con"; iec104:apci any,asdu_type 45<>46,asdu_cot 71;sid:104110;rev:1;).
[0082] (3) For the configuration of other communication protocol security rules, including the ability to define security events for some insecure protocol connections and their related operations.
[0083] Exemplarily, the following security rules may be included for detecting HTTP hypertext transfer protocol connections and SSH remote login protocol connections:
[0084] #alert http any any->any any(msg: "HTTP communication detected"; http.protocol; content: "HTTP"; nocase; flow:to_server; classtype: protoAdd; priority: 2; sid: 46; rev: 1;);
[0085] #alert ssh any any->any any(msg:"SSH connection detected"; ssh.proto; content:".; flow:to_server; classtype:protoAdd; priority:3; sid:45; rev:1;).
[0086] In some embodiments, a preset security rule base is used to perform security identification on target protocol data to obtain a security identification result of the current communication message, including:
[0087] Match each preset security rule in the preset security rule library with the target protocol data to obtain a matching result;
[0088] If the matching result indicates that at least one preset security rule in the preset security rule library successfully matches the target protocol data, the current communication message is determined to be a risky message, and a security alarm event is output based on the communication protocol data.
[0089] Specifically, each preset security rule in the preset security rule library can be matched with the target protocol data, such as using regular expressions and other custom logical operators to match the preset security rules with the data features in the target protocol data, detecting specific patterns or behaviors in the current communication message, so as to obtain specific matching results, and performing different processing operations according to different matching results. For example, if the matching result indicates that at least one preset security rule in the preset security rule library successfully matches the target protocol data, indicating that the target protocol data completely matches the data features in the preset security rules, then it can be determined that the current communication message is a risky message, and a security alarm event is output based on the communication protocol data.
[0090] The present embodiment provides a security identification method, which collects the current communication message of the substation monitoring system; performs protocol analysis on the current communication message to obtain the protocol information of the current communication message, and the protocol information at least includes communication protocol data and message type; according to whether the message type is the message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, and the target protocol data is the protocol data to be security identified corresponding to the current communication message; the preset security rule library is used to perform security identification on the target protocol data to obtain the security identification result of the current communication message, and the preset security rule library is used to identify whether the current communication message is a risk message. Using this method, by determining whether the message type of the current communication message is the message type to be associated, the target protocol data of the current communication message can be accurately determined, and the preset security rule library is used to perform targeted identification on the target protocol data, thereby achieving effective identification of risk messages in the substation monitoring system and improving the security of the substation monitoring system.
[0091] In some embodiments, after performing protocol analysis on the current communication message to obtain protocol information of the current communication message, the method further includes:
[0092] If the communication protocol type indicates that the communication protocol used by the current communication message is not the network communication protocol specified by the substation monitoring system, the communication protocol data is determined as the target protocol data corresponding to the current communication message;
[0093] Use preset security rules to perform security identification on the target protocol data and obtain the security identification result of the current communication message.
[0094] In a specific implementation manner, in addition to security identification of the network communication protocol specified by the substation monitoring system, this embodiment can also parse and identify the network communication protocol that may contain attack behaviors in the system network attack, that is, identify other network communication protocols other than the network communication protocol specified by the substation monitoring system, for example, it can include hypertext transfer protocol HTTP, simple mail transfer protocol SMTP, file transfer protocol FTP, transport layer security protocol TLS, network file system protocol NFS, dynamic host configuration protocol DHCP and post office protocol version 3 POP3 and other network communication protocols, and perform simple risk identification on such network communication protocols. For example, an alarm rule corresponding to the communication protocol type can be set in the security rule engine library. The alarm rule information can include data such as the protocol port number, the keyword of the protocol and the link channel negotiation information of the protocol. Assuming that the communication protocol type indicates that the communication protocol used by the current communication message is not the network communication protocol specified by the substation monitoring system, then the communication protocol data of the current communication message can be directly determined as the target protocol data corresponding to the current communication message, and the target protocol data can be retrieved and matched using the alarm rule corresponding to the communication protocol type to obtain the security identification result of the current communication message. On this basis, the target protocol data can be specifically determined for different current communication messages, thereby improving the accuracy of the target protocol data.
[0095] Among them, Suricata can be used to identify specific network communication protocols. For example, pattern matching can be used to identify protocols, and the version and type of application layer protocols can be determined by some protocol keywords in the traffic message payload. For example, the HTTP protocol can be identified by searching for keywords such as "HTTP1.0 / ". It is also possible to use the expected protocol method for identification. This method is based on the expectation of protocol interaction. For example, it is known that some application layer control protocols will negotiate data link channels, and the protocol is identified by the expected protocol interaction mode. Alternatively, the application layer protocol identification principle can be used for identification. Suricata's identification of application layer protocols can rely on the well-known port number of the communication protocol.
[0096] Figure 2 This is a flowchart of a security identification method provided by another embodiment of the present application. The communication protocol data includes a protocol identifier. This embodiment further optimizes the communication protocol data to determine the target protocol data corresponding to the current communication message according to whether the message type is a message type to be associated: if the message type is a message type to be associated, the associated communication message of the current communication message is determined based on the protocol identifier; the communication protocol data of the current communication message and the communication protocol data of the associated communication message are determined as the target protocol data corresponding to the current communication message. Figure 2 As shown, the method includes:
[0097] S201. Collect current communication messages from the substation monitoring system.
[0098] S202: Perform protocol analysis on the current communication message to obtain protocol information of the current communication message, where the protocol information at least includes communication protocol data and message type.
[0099] S203: If the message type is a message type to be associated, determine an associated communication message of the current communication message based on the protocol identifier.
[0100] S204: Determine the communication protocol data of the current communication message and the communication protocol data of the associated communication message as the target protocol data corresponding to the current communication message.
[0101] The associated communication message may refer to a communication message associated with the current communication message, such as the current communication message and the associated communication message have the same protocol identifier.
[0102] In a specific implementation, if the message type obtained by the above step analysis is a message type to be associated, then the associated communication message of the current communication message can be determined based on the protocol identifier, so that the communication protocol data of the current communication message and the communication protocol data of the associated communication message can be determined as the target protocol data corresponding to the current communication message for subsequent security identification. Among them, the specific process of determining the associated communication message is not limited, such as it can be determined according to the actual situation of the current communication message, and different message types to be associated can correspond to different associated communication message determination processes.
[0103] In some embodiments, the message type to be associated includes a response message type, and determining the associated communication message of the current communication message based on the protocol identifier includes:
[0104] Detecting whether there is a candidate communication message matching the protocol identifier, the candidate communication message being a communication message stored before the current communication message is collected;
[0105] If it is detected that there is a candidate communication message matching the protocol identifier, the candidate communication message matching the protocol identifier is determined as an associated communication message of the current communication message;
[0106] If it is detected that there is no candidate communication message matching the protocol identifier, a security alarm event is output based on the communication protocol data of the current communication message.
[0107] In a specific implementation, the message type to be associated may include a response message type. Accordingly, the message type of the associated communication message of the current communication message may be considered as a request message type. For example, the request message type may be understood as the communication message being data for requesting an operation, such as requesting to obtain certain data or requesting to perform a certain operation, etc. The response message type may refer to the communication message being data for responding to a previous data acquisition request or performing an operation. The candidate communication message may be a communication message stored before the current communication message is collected. For example, in this embodiment, when a communication message of the request message type is collected, the communication message of the request message type may be temporarily stored locally, and the subsequent communication messages may continue to be collected.
[0108] Specifically, the specific process of determining the associated communication message may be to detect whether there is a candidate communication message that matches the protocol identifier; if it is detected that there is a candidate communication message that matches the protocol identifier, it means that the candidate communication message is a communication message of the request message type corresponding to the current communication message, and the candidate communication message that matches the protocol identifier may be determined as the associated communication message of the current communication message; if it is detected that there is no candidate communication message that matches the protocol identifier, it means that before collecting the current communication message, no communication message of the request message type corresponding to the current communication message has been collected, and the current communication message has certain security risks, so a security alarm event may be output based on the communication protocol data of the current communication message.
[0109] In some embodiments, the type of message to be associated includes a request message type, and determining the associated communication message of the current communication message based on the protocol identifier includes:
[0110] Store the protocol information of the current communication message;
[0111] Return to the step of collecting the current communication message of the substation monitoring system until an associated communication message of a response message type is collected based on the protocol identifier.
[0112] In a specific implementation manner, the message type to be associated may include a request message type. At this time, the protocol information of the current communication message can be stored, and the subsequent communication messages can continue to be collected, that is, the step of collecting the current communication message of the substation monitoring system is returned. Furthermore, if the current communication message of the request message type is still collected subsequently, the protocol information of the current communication message can continue to be stored, and subsequent communication messages can be collected until an associated communication message with a message type of a response message type is collected. Then, it can be detected based on the protocol identifier whether there is a matching candidate communication message, and different operations can be performed according to different detection results. The specific content can refer to the above embodiment.
[0113] S205. Use a preset security rule base to perform security identification on the target protocol data to obtain a security identification result of the current communication message. The preset security rule base is used to identify whether the current communication message is a risky message.
[0114] A security identification method provided in this embodiment, by determining the associated communication message of the current communication message based on the protocol identifier when the message type is the message type to be associated, can achieve accurate determination of the target protocol data based on the communication protocol data of the current communication message and the associated communication message, thereby further improving the effectiveness of security identification and ensuring the security of the substation monitoring system.
[0115] The following is an exemplary description of the security identification method provided in this embodiment:
[0116] First, we can build a security rule engine library focusing on the communication protocol of the substation monitoring system. For example, we can design a communication protocol security rule engine library based on Suricata. Suricata is a fast, highly stable network intrusion detection system (NIDS), network intrusion prevention system (NIPS), network security monitoring (NSM) engine and offline communication message analysis tool, inline intrusion prevention and network security monitoring, including capture, collection, decoding, detection and output modules. Using Suricata's powerful and extensive rules and signature language to inspect network traffic can achieve real-time analysis and detection of communication protocol application data, and effectively identify malicious activities against power system communication protocols.
[0117] The process of constructing the Suricata communication protocol security rule engine library in this embodiment may include:
[0118] (1) The Suricata engine is selected as the core component, which can capture and analyze network traffic in real time as a data source for communication protocol security identification.
[0119] (2) Use Suricata to develop and identify the types of network communication protocols. For example, Suricata can be configured to have the ability to identify a variety of common Internet protocols, including Hypertext Transfer Protocol HTTP, Simple Mail Transfer Protocol SMTP, File Transfer Protocol FTP, Transport Layer Security Protocol TLS, Network File System Protocol NFS, Dynamic Host Configuration Protocol DHCP, Post Office Protocol Version 3 POP3 and other network communication protocols. On this basis, Suricata's network communication protocol identification function can be further expanded. In accordance with the technical specifications of relevant communication protocols of the power system, on the basis of the dedicated communication protocols of the substation monitoring system (IEC61850, IEC104 and other communication protocols), the security identification of other common communication protocols is added.
[0120] (3) Use Suricata to set up a security rule library for identifying network communication protocols. For example, Suricata can define signature-based security rules, including metadata, matching conditions, and actions. Specifically, it can define in detail the rule syntax for identifying security risks of communication protocols such as IEC61850 and IEC104 on the basis of compatibility with Suricata's original rule syntax, provide a unified security rule configuration method, and facilitate rule sharing and updating. At the same time, considering the continuous development of substation monitoring system communication protocols and the continuous emergence of new threats, security rules support manual addition and modification to quickly respond to new security needs.
[0121] Figure 3 This is a schematic diagram of the working principle of a security rule engine library provided by an embodiment of the present application. Figure 3 As shown, the security rule engine library based on Suricata can capture network traffic in real time, parse and process the network traffic, identify whether there are security risks in the application data operations of the communication protocol by matching the security rule engine library, and output security alarm events when there are security risks.
[0122] It can be considered that in the actual communication process of smart devices, some security identification schemes do not parse and analyze the results of each request operation. Taking the communication protocol such as IEC61850 as an example, if only each frame of the communication message is parsed and some fields in the communication protocol are extracted, the request frame and the reply frame data cannot be associated, and the actual operation process cannot be accurately restored. Therefore, the security identification method provided in this embodiment can well improve the above-mentioned shortcomings. For example, for the IEC61850 communication protocol, in addition to implementing the parsing of the message field, this embodiment can also cache the request operation according to the protocol characteristics, match the IEC61850_MMS protocol request message and response message through InvokeID, and obtain the result of each request operation (i.e., the parsed content of the response message corresponding to the request message), accurately restore the actual operation process, and then the matching information can be configured into the security rules for security identification, which can more accurately identify potential security risks. For example, if the matching result of a request operation corresponds to the security rule, or the InvokeID of the response message is inconsistent with the InvokeID of the request message, it can be considered as a sign of a non-security incident. InvokeID can be used to identify the ID of a specific operation in the IEC61850 protocol. Through this ID, the request message and the corresponding reply message can be associated to restore the entire operation process.
[0123] Figure 4 is an overall schematic diagram of a security identification method provided by an embodiment of the present application, such as Figure 4 As shown, first, the mirror traffic of the entire station network can be collected and captured from the central switch of the substation monitoring system (i.e., the current communication messages of the substation monitoring system are collected), and protocol analysis is performed on the mirror traffic, including protocol analysis at the network Ethernet layer to extract the source / destination MAC address, protocol analysis at the IP layer to extract the source / destination IP and transport layer protocol, protocol analysis at the transport layer to extract the source / destination port, and flow information is tracked through quintuples to identify the communication protocol. If the identification fails, an unknown protocol alarm event is output; if the identification is successful, the data content of each frame of the protocol is decoded and analyzed at the application layer, and the decoding is based on the specific definition of the format of each frame of data in the protocol standard.
[0124] Subsequently, two different risk identification processes can be performed according to the interactive characteristics of the data frame. For example, for data frame messages that do not require confirmation, the acquired information can be directly sent to the security rule library for matching and identification of security risks; for data frames with a corresponding relationship between request and confirmation (such as confirmedPDU in the IEC61850 protocol and ASDU45 data frame in the IEC104 protocol), when a request data frame message is received, the current request is cached first, and when a reply message is received, the protocol feature field (the InvokeID field of the protocol used in the IEC61850 message, IE The C104 protocol message uses the ASDU type identifier of the protocol to query the corresponding cached request message and associate the request message with the reply message, that is, to determine the correctness of the request and reply by identifying whether the characteristic fields in the request message and the reply message are consistent; then the parsed message information can be matched with all security rules in the security engine rule base. If the same protocol type is found in the rule, and the key information of the message is the same as the key information content of the Suricata rule option content, the match is successful, and the alarm information is output and saved; otherwise, it can be considered that the match failed and no alarm is triggered. Among them, the output alarm information can be used for alarm tracing, such as extracting traffic messages related to the alarm event.
[0125] Figure 5 FIG. 1 is a flow chart of a secure identification process of an IEC61850 communication message provided by an embodiment of the present application. Figure 5 As shown, first, a complete protocol message frame can be obtained (i.e., the current communication message of the substation monitoring system is collected), the protocol message is parsed, and various fields such as message type, service name, variable name, etc. are extracted, including the parsing of structures such as the request protocol data unit ConfirmedRequestPDU and the response protocol data unit ConfirmedResponsePDU. These structures contain key data information such as the request unique identifier InvokeID, the service request ConfirmedServiceRequest, and the service response ConfirmedServiceResponse.
[0126] Secondly, it can be determined whether the message type is unconfirmedPDU. If the message type is unconfirmedPDU, the decoded information can be directly sent to the rule engine for identification and matching (that is, if the message type is not the message type to be associated, the communication protocol data is determined to be the target protocol data corresponding to the current communication message; the target protocol data is securely identified using a preset security rule library to obtain a security identification result of the current communication message); if the message type is not unconfirmedPDU (that is, the message type is the message type to be associated), it is further determined whether the protocol message is a request message. If the protocol message is a request message, the current request message can be identified. Cache processing, returning to the step of obtaining a complete protocol message frame (i.e., the message type to be associated includes the request message type, and the protocol information of the current communication message is stored; returning to the step of executing the current communication message collection of the substation monitoring system, until the associated communication message of the response message type is collected based on the protocol identifier); if the protocol message is not a request message, that is, the protocol message is a service response message, the cached InvokeID can be used to query the corresponding request message (i.e., the message type to be associated includes the response message type, and it is detected whether there is a candidate communication message that matches the protocol identifier). If the corresponding cached request message is queried, the request and reply response message information are combined to obtain the command execution result.
[0127] Finally, the decoded information is sent to the rule engine for identification and matching. By traversing and retrieving the field information of the security rules in the security rule library, important security-related operations and operations with unknown InvokeID replies in the operation results are identified. If a security risk is identified, a security alarm event is output, or if the cached request message corresponding to the response message is not queried, an IEC61850 communication protocol decoding exception event is output.
[0128] Figure 6 FIG. 1 is a flow chart of a secure identification process of an IEC104 communication message provided by an embodiment of the present application, such as Figure 6 As shown, first, a complete protocol message frame can be obtained (i.e., the current communication message of the substation monitoring system is collected), the protocol message is parsed, and each field of the message, such as the APCI frame type, ASDU type, transmission reason, ASDU address, information body address, and information body value, is extracted.
[0129] Secondly, it can be determined whether the ASDU type is a request-confirmation message. If the ASDU type is not a request-confirmation message, the decoded information can be directly sent to the rule engine for identification and matching (that is, if the message type is not a message type to be associated, the communication protocol data is determined to be the target protocol data corresponding to the current communication message; the target protocol data is securely identified using a preset security rule library to obtain a security identification result of the current communication message); if the ASDU type is a request-confirmation message (that is, the message type is a message type to be associated), it can be further determined whether the protocol message is a request message. If it is determined that the protocol message is a request message, the current request message can be cached. , returning to the step of obtaining a complete protocol message frame (that is, the message type to be associated includes the request message type, and the protocol information of the current communication message is stored; returning to the step of executing the current communication message collection of the substation monitoring system, until the associated communication message whose message type is the response message type is collected based on the protocol identifier); if it is determined that the protocol message is not a request message, that is, it is a confirmation response message, the corresponding request message can be queried according to the ASDU type and the information body address (that is, the message type to be associated includes the response message type, and it is detected whether there is a candidate communication message matching the protocol identifier). If the corresponding cached request message is queried, the request and reply message information can be combined to obtain the command execution result.
[0130] Finally, the decoded information is sent to the rule engine for identification and matching. By traversing and retrieving the field information of the security rules in the security rule library, important security-related operations and operations with unknown reply messages in the operation results are identified. If a security risk is identified, a security alarm event is output, or if the cached request message corresponding to the response message is not found, an IEC104 communication protocol decoding exception event is output.
[0131] In addition, for the security identification of communication messages of other common protocols (such as FTP, HTTP, POP3, SMTP, NFS, etc.), the protocol communication port number, fixed key fields of the data content (such as keywords such as "HTTP1.0 / " in the HTTP protocol) and other information can be obtained through parsing, and this information can be traversed, searched and compared with the security rule engine library. If the corresponding security rule is found, a security risk identification alarm will be triggered.
[0132] Figure 7 FIG. 1 is a flow chart of outputting a security alarm event provided by an embodiment of the present application. Figure 7 As shown, after obtaining the deep analysis information of the message and matching it with the alarm rules, the communication protocol security rule engine can identify the dangers such as protocol control operations, abnormal data transmission, suspicious communication protocols, dangerous ports, etc. in the communication protocol data interaction process in the substation monitoring system network, and trigger security alarm events in real time.
[0133] Then, relevant information of the alarm event can be extracted, such as the time of occurrence and five-tuple information (i.e., source IP, source port, destination IP, destination port, and communication protocol type). Then, according to the extracted five-tuple information, the original message traffic corresponding to the alarm event is retrieved in the traffic stored in Suricata to extract the traffic information related to the alarm. The traffic information related to the alarm is extracted from the original message traffic and saved as a pcap format file. On the one hand, it can retain key evidence for customers, improve the system's ability to trace the source of alarms, and facilitate subsequent investigations of the cause of the accident; on the other hand, only the corresponding original message traffic for security risk identification is saved, and normal and risk-free original traffic is not saved, which can save storage space. It should be noted that after Suricata captures the original traffic, it can be stored for subsequent applications, such as storing the original traffic of the last 6 months, which can be stored in multiple files.
[0134] Furthermore, the present embodiment can regularly update the preset security rule base of the communication protocol to adapt to the ever-changing network environment and security threats. Among them, the security rules are saved in the form of files, and each rule contains information such as "rule name", "rule classification", "alarm level", "alarm description", "rule content", "rule ID (sid)", and "rule version (rev)", among which "rule ID" uniquely identifies a security rule, and "rule version" is the revised version of the current security rule, and the version number increases by 1 each time it is revised. Specifically, the rule update can be completed through the steps of rule testing, comparing rule ID and rule version, merging rules, and rule application, that is, when the new rule file that has been tested and meets the requirements is updated and imported, the ID and version information of the new rule and the original rule will be read during the update operation. If the version information is found to be changed (greater than the original version number), the rule will be overwritten. If the ID and version do not exist in the original rule, a new rule will be directly added at the end. For example, rule testing can identify security risks for newly added and modified rules, and confirm that the rules can monitor and identify the corresponding communication protocol security risks; comparing rule IDs and rule versions can be considered as importing and updating rule files. The old rule ID is first traversed in the old rule library to find the old rule ID. After the rule ID is found, the rule version information is compared; merging rules can mean that after comparing the rule ID and the rule version, the stored rule with the same ID is overwritten only when the rule version is incremented. If the corresponding rule ID cannot be found in the old rule, a new rule is directly added to the end of the rule library file; rule application can be considered as the rule application taking effect by restarting after the rule is successfully imported.
[0135] Figure 8 FIG. 1 is a flow chart of updating a preset security rule base provided by an embodiment of the present application. Figure 8 As shown, a new security rule can be read. If the new security rule is valid, the rules in the system can be queried according to the sid (i.e., rule ID) of the new security rule. If there is no security rule with the same sid in the query system, it will be added as a new rule; if there is a security rule with the same sid in the query system, the version number rev of the new security rule will be compared to determine whether the version number rev of the new security rule is greater than the version number of the old security rule. If the version number rev of the new security rule is greater than the version number of the old security rule, the new security rule will be used to replace the old security rule. Finally, determine whether the current new rule is the last rule. If the current new rule is not the last rule, repeat the above operation; if the current new rule is the last rule, the rule can be made effective by restarting the application service and other means to end the update of the preset security rule library.
[0136] From the above description, it can be found that the security identification method provided in this embodiment analyzes the flow information on the basis of obtaining the entire network flow information of the substation monitoring system, identifies the specific communication protocol in the network flow and performs application message parsing, and performs risk identification and matching according to the built-in security rule engine, thereby finally realizing the network security monitoring of the entire secondary equipment of the substation, effectively identifying the network attacks faced by various communication protocols of the substation monitoring system, and protecting the network security of the substation monitoring system.
[0137] Specifically, the security identification method provided in this embodiment can effectively identify various attacks and threats from the network level by building a communication protocol security rule base engine, thereby improving the security identification capability of the substation monitoring system at the communication protocol level.
[0138] By adopting Suricata as the network intrusion detection engine, the operation and maintenance process is centrally deployed. Network security monitoring can be performed by simply obtaining mirrored network traffic in the substation network center switch. Compared with existing solutions, the present invention does not need to rely on special hardware equipment or distributed deployment of security identification systems, which reduces the complexity and cost of equipment operation and maintenance, while also improving its application possibility in resource-constrained environments and optimizing the operation and maintenance efficiency of substation network security.
[0139] By monitoring the network traffic data of the communication protocol, it is possible to conduct in-depth analysis and security rule detection on the data content of the IEC104 and IEC61850 protocols. Compared with existing solutions, it improves the fine-grained detection of the network traffic of the substation monitoring system, can more accurately identify potential application-level network security threats, and improves the accuracy of protection.
[0140] At the same time, the rule detection process of this embodiment is reasonably designed, can effectively handle large-scale network traffic, and has a wider monitoring coverage of the substation secondary equipment network.
[0141] In summary, the security identification method provided in this embodiment can effectively improve the network security protection capability. Through in-depth analysis and rule judgment of the mainstream communication protocols of the power system, potential security threats can be discovered and prevented in a timely manner, thereby protecting the normal operation of the network. Secondly, the security identification method provided in this embodiment can be applied to industrial control systems. Through in-depth analysis of industrial control protocols such as IEC104 and IEC61850, security threats at the communication protocol level can be effectively monitored, thereby protecting the security of industrial control systems. Finally, the security identification method provided in this embodiment can also be applied to data storage security management. Through protocol monitoring of various transmission protocols (such as FTP, HTTP, POP3, SMTP, NFS, etc.), security threats such as data leakage and illegal access can be effectively prevented, thereby protecting data security.
[0142] Therefore, the security identification method provided in this embodiment can be widely used in application fields such as the field of power system network security technology, the field of industrial control systems, and the field of data storage technology.
[0143] Corresponding to the security identification method of the above embodiment, Fig. 9 This is a structural block diagram of a security identification device provided in one embodiment of the present application. For the sake of ease of explanation, only the parts related to the embodiment of the present application are shown.
[0144] Reference Fig. 9 , the device comprises:
[0145] The collection module 301 is used to collect the current communication messages of the substation monitoring system;
[0146] The protocol analysis module 302 is used to perform protocol analysis on the current communication message to obtain the protocol information of the current communication message, where the protocol information at least includes communication protocol data and message type;
[0147] A first determination module 303 is used to determine the target protocol data corresponding to the current communication message using the communication protocol data according to whether the message type is the message type to be associated, where the target protocol data is the protocol data to be securely identified corresponding to the current communication message;
[0148] The first security identification module 304 is used to perform security identification on the target protocol data using a preset security rule base to obtain a security identification result of the current communication message. The preset security rule base is used to identify whether the current communication message is a risky message.
[0149] The present embodiment provides a security identification device, which collects the current communication message of the substation monitoring system through the collection module; performs protocol analysis on the current communication message through the protocol analysis module to obtain the protocol information of the current communication message, and the protocol information at least includes communication protocol data and message type; through the first determination module, according to whether the message type is the message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, and the target protocol data is the protocol data to be security identified corresponding to the current communication message; through the first security identification module, the preset security rule library is used to perform security identification on the target protocol data to obtain the security identification result of the current communication message, and the preset security rule library is used to identify whether the current communication message is a risk message. Using this device, by determining whether the message type of the current communication message is the message type to be associated, the target protocol data of the current communication message can be accurately determined, and the preset security rule library is used to identify the target protocol data in a targeted manner, thereby realizing the effective identification of risk messages in the substation monitoring system and improving the security of the substation monitoring system.
[0150] Optionally, the communication protocol data includes a protocol identifier, and the first determining module includes:
[0151] A first determining unit, configured to determine an associated communication message of the current communication message based on a protocol identifier if the message type is a message type to be associated;
[0152] The second determining unit is used to determine the communication protocol data of the current communication message and the communication protocol data of the associated communication message as the target protocol data corresponding to the current communication message.
[0153] Optionally, the message type to be associated includes a response message type, and the first determining unit is specifically configured to:
[0154] Detecting whether there is a candidate communication message matching the protocol identifier, the candidate communication message being a communication message stored before the current communication message is collected;
[0155] If it is detected that there is a candidate communication message matching the protocol identifier, the candidate communication message matching the protocol identifier is determined as an associated communication message of the current communication message;
[0156] If it is detected that there is no candidate communication message matching the protocol identifier, a security alarm event is output based on the communication protocol data of the current communication message.
[0157] Optionally, the message type to be associated includes a request message type, and the first determining unit is specifically configured to:
[0158] Store the protocol information of the current communication message;
[0159] Return to the step of collecting the current communication message of the substation monitoring system until an associated communication message of a response message type is collected based on the protocol identifier.
[0160] Optionally, the first determining module is specifically configured to:
[0161] If the message type is not the message type to be associated, the communication protocol data is determined as the target protocol data corresponding to the current communication message.
[0162] Optionally, the communication protocol data includes a communication protocol type, and the first determining module is specifically used to:
[0163] If the communication protocol type indicates that the communication protocol used by the current communication message is the network communication protocol specified by the substation monitoring system, the communication protocol data is used to determine the target protocol data corresponding to the current communication message according to whether the message type is the message type to be associated.
[0164] Optionally, a security identification device provided in this embodiment further includes:
[0165] The second determination module is used to perform protocol analysis on the current communication message and obtain the protocol information of the current communication message, and if the communication protocol type indicates that the communication protocol adopted by the current communication message is not the network communication protocol specified by the substation monitoring system, determine the communication protocol data as the target protocol data corresponding to the current communication message;
[0166] The second security identification module is used to perform security identification on the target protocol data using preset security rules to obtain a security identification result of the current communication message.
[0167] Optionally, the first security identification module is specifically used to:
[0168] Match each preset security rule in the preset security rule library with the target protocol data to obtain a matching result;
[0169] If the matching result indicates that at least one preset security rule in the preset security rule library successfully matches the target protocol data, the current communication message is determined to be a risky message, and a security alarm event is output based on the communication protocol data.
[0170] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0171] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0172] The present application also provides a terminal device, Fig.10 is a schematic diagram of the structure of a terminal device provided by an embodiment of the present application, such as Fig.10 As shown, the terminal device includes: at least one processor 401, a memory 402, an input device 403, an output device 404, and a computer program stored in the memory 402 and executable on at least one processor 401. When the processor 401 executes the computer program, the steps in any of the above-mentioned method embodiments are implemented.
[0173] The input device 403 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the terminal device. The output device 404 may include a display device such as a display screen.
[0174] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by the processor 401, the steps in the above-mentioned method embodiments can be implemented.
[0175] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0176] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor 401, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the device / terminal device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.
[0177] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0178] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0179] In the embodiments provided in the present application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0180] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0181] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.< / res> < / res> < / data> < / data> < / ioa> < / ioa> < / addr> < / addr> < / cot> < / cot> < / type> < / type> < / type> < / type> < / res> < / res> < / name> < / name> < / name> < / name> < / name> < / type> < / type>
Claims
1. A security identification method, characterized in that: include: Collect current communication messages from the substation monitoring system; Performing protocol analysis on the current communication message to obtain protocol information of the current communication message, wherein the protocol information at least includes communication protocol data and message type; According to whether the message type is a message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message, wherein the target protocol data is the protocol data to be securely identified corresponding to the current communication message; The target protocol data is security identified by using a preset security rule base to obtain a security identification result of the current communication message, wherein the preset security rule base is used to identify whether the current communication message is a risky message.
2. The security identification method according to claim 1, characterized in that: The communication protocol data includes a protocol identifier, and the communication protocol data is used to determine the target protocol data corresponding to the current communication message according to whether the message type is a message type to be associated, including: If the message type is a message type to be associated, determining an associated communication message of the current communication message based on the protocol identifier; The communication protocol data of the current communication message and the communication protocol data of the associated communication message are determined as the target protocol data corresponding to the current communication message.
3. The security identification method according to claim 2, characterized in that: The message type to be associated includes a response message type, and the determining the associated communication message of the current communication message based on the protocol identifier includes: Detecting whether there is a candidate communication message matching the protocol identifier, the candidate communication message being a communication message stored before the current communication message is collected; If it is detected that there is a candidate communication message matching the protocol identifier, the candidate communication message matching the protocol identifier is determined as an associated communication message of the current communication message; If it is detected that there is no candidate communication message matching the protocol identifier, a security alarm event is output based on the communication protocol data of the current communication message.
4. The security identification method according to claim 2, characterized in that: The message type to be associated includes a request message type, and the determining the associated communication message of the current communication message based on the protocol identifier includes: Storing the protocol information of the current communication message; Return to the step of collecting the current communication message of the substation monitoring system until an associated communication message of a response message type is collected based on the protocol identifier.
5. The security identification method according to claim 1, characterized in that: The determining, according to whether the message type is a message type to be associated, the target protocol data corresponding to the current communication message using the communication protocol data comprises: If the message type is not the message type to be associated, the communication protocol data is determined as the target protocol data corresponding to the current communication message.
6. The security identification method according to claim 1, characterized in that: The communication protocol data includes a communication protocol type, and the determining, based on whether the message type is a message type to be associated, the target protocol data corresponding to the current communication message using the communication protocol data includes: If the communication protocol type indicates that the communication protocol used by the current communication message is the network communication protocol specified by the substation monitoring system, then according to whether the message type is a message type to be associated, the communication protocol data is used to determine the target protocol data corresponding to the current communication message.
7. The security identification method according to claim 6, characterized in that: After performing protocol analysis on the current communication message to obtain protocol information of the current communication message, the method further includes: If the communication protocol type indicates that the communication protocol adopted by the current communication message is not the network communication protocol specified by the substation monitoring system, the communication protocol data is determined as the target protocol data corresponding to the current communication message; The target protocol data is securely identified using preset security rules to obtain a security identification result of the current communication message.
8. The security identification method according to claim 1, characterized in that: The step of using a preset security rule base to perform security identification on the target protocol data to obtain a security identification result of the current communication message includes: Matching each preset security rule in the preset security rule library with the target protocol data to obtain a matching result; If the matching result indicates that at least one preset security rule in the preset security rule library successfully matches the target protocol data, the current communication message is determined to be a risky message, and a security alarm event is output based on the communication protocol data.
9. A security identification device, characterized in that: include: The acquisition module is used to collect the current communication messages of the substation monitoring system; A protocol analysis module, used to perform protocol analysis on the current communication message to obtain protocol information of the current communication message, wherein the protocol information at least includes communication protocol data and message type; A first determination module, configured to determine, according to whether the message type is a message type to be associated, target protocol data corresponding to the current communication message using communication protocol data, wherein the target protocol data is protocol data to be securely identified corresponding to the current communication message; The first security identification module is used to perform security identification on the target protocol data using a preset security rule base to obtain a security identification result of the current communication message, wherein the preset security rule base is used to identify whether the current communication message is a risky message.
10. A terminal device comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the terminal device implements the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
A packaging system
IE61850B1
Detection method of network anomaly message of intelligent substation
CN104579818A
Wireless attack defense method and wireless attack defense device applied to wireless access point (AP)
CN106790299A
Service-chain-based multi-protocol network message associated analysis and display method
CN108933780A
Networking scheme of dual-mode hybrid network based on broadband carrier and narrowband wireless
CN111200858A