New energy station network security protection system and method based on multi-mode intelligent perception

By deploying multimodal data acquisition and dynamic causal model analysis systems in new energy stations, the problem that traditional monitoring technology is difficult to fully reflect the station situation and lack of intelligent analysis is solved, and the timely discovery and processing of network security risks of new energy stations is achieved, and network security protection capabilities are improved.

CN119945766APending Publication Date: 2025-05-06CHINA POWER INVESTMENT NORTHEAST NEW ENERGY DEV CO LTD
View PDF 0 Cites 7 Cited by

Patent Information

Application Number
CN202510076512.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Traditional new energy station monitoring technology relies on a single sensor or data collection method, making it difficult to fully reflect the station situation, lacks intelligent analysis and early warning mechanisms, and it is difficult to detect and handle network security risks in a timely manner.

Method used

The network security protection system of new energy stations based on multimodal intelligent perception is adopted, and multiple parts such as multimodal data collection, data storage and management, dynamic causal model construction and analysis, traceability analysis and responsibility identification, and protection decision-making and execution are integrated. The equipment operation, network traffic and environmental data are collected through sensors and traffic sniffing devices, and the data fusion and causal discovery algorithm are used for real-time monitoring and analysis.

Benefits of technology

It realizes comprehensive monitoring of the operation of new energy station equipment, network traffic and environmental data, can promptly detect and warn of potential network security risks, quickly locate the source of events and divide responsibilities, and improves network security protection capabilities and emergency response speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945766A_ABST
    Figure CN119945766A_ABST
Patent Text Reader

Abstract

The invention discloses a new energy station network security protection system and method based on multi-mode intelligent perception, and relates to the technical field of new energy station network security protection. The system comprises the following components: a multi-modal data acquisition module, a data storage and management unit, a dynamic causal model construction and analysis module, a traceability analysis and responsibility determination module and a protection decision and execution module. Through construction and analysis of the dynamic causal model, the causal network can be updated and remodeled in real time so as to adapt to changes of working conditions of a new energy station, so that the method can continuously learn and adapt to a new network environment, the intelligent level of the method is improved, and by mining a potential causal relationship among multi-modal data, the dynamic causal model is constructed and analyzed. Potential network security risks can be found and early warned in time, at the same time, by combining traceability analysis and responsibility determination, an event source can be quickly positioned, and responsibility subjects can be divided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security protection for new energy stations, and specifically to a network security protection system and method for new energy stations based on multi-modal intelligent perception. Background Art

[0002] With the vigorous development of the new energy industry, new energy sites such as wind farms and photovoltaic power stations are accounting for an increasing proportion in the power grid. These sites are not only related to the stability and reliability of energy supply, but also involve important issues of network security. In order to ensure the safe and efficient operation of new energy sites, it is necessary to conduct real-time monitoring and comprehensive analysis of their equipment status, network traffic and environmental factors. This has given rise to the research and development of new energy site network security protection systems based on multimodal intelligent perception.

[0003] Traditional new energy station monitoring technology mainly relies on a single sensor or data collection method, such as monitoring the operating status only through the equipment's own monitoring system, or simply recording network traffic data. These methods have obvious shortcomings: on the one hand, a single data source is difficult to fully reflect the actual situation of the station, resulting in blind spots in monitoring; on the other hand, the lack of intelligent analysis and early warning mechanisms makes it difficult to timely discover and deal with potential network security risks. In addition, traditional technologies often trace responsibility after the fact, making it difficult to prevent in advance, posing hidden dangers to the safe operation of new energy stations.

[0004] Therefore, developing a network security protection system and method for new energy sites based on multimodal intelligent perception is of great significance to ensuring the stable development of the new energy industry. Summary of the invention

[0005] The purpose of the present invention is to make up for the shortcomings of the prior art and to provide a network security protection system and method for new energy stations based on multimodal intelligent perception. The present invention integrates multimodal data acquisition, data storage and management, dynamic causal model construction and analysis, traceability analysis and responsibility identification, and protection decision-making and execution. By deploying various sensors and traffic sniffing devices, it comprehensively collects equipment operation, network traffic and environmental data, and uses advanced data fusion and causal discovery algorithms to monitor the network security status of new energy stations in real time. Once an abnormality occurs, it can quickly trace back the source of the event, intelligently match and execute corresponding protection strategies, thereby improving the network security protection capability and emergency response speed of new energy stations.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: On the one hand, a network security protection system for new energy stations based on multimodal intelligent perception, the system includes the following components: a multimodal data acquisition module, a data storage and management unit, a dynamic causal model construction and analysis module, a traceability analysis and responsibility identification module, and a protection decision and execution module; The multimodal data acquisition module: deploys sensor acquisition equipment on the equipment of the new energy station, installs traffic sniffing devices on network switches and router nodes to obtain network traffic data, arranges sensors in environmentally sensitive areas to collect environmental data, configures microprocessors for acquisition terminals, eliminates environmental noise interference, and normalizes data to a standard range, transmits it to a data storage and management center via a wireless communication link, and fuses multi-source data in the data center; The data storage and management unit: builds a distributed storage architecture based on the Hadoop ecosystem, divides the device data storage area, the network traffic storage area, and the environment data storage area, uses HDFS to store data in a dispersed manner, and at the same time, establishes a multi-dimensional data index, manages data according to timestamps, device numbers, and data type labels, and builds a data scheduling engine. When a data retrieval request is received, the relevant data storage location is located according to the index label to retrieve the data; The dynamic causal model construction and analysis module: uses historical accumulated data combined with causal discovery algorithms to build a causal model, mines and identifies potential causal relationships between multimodal data, enters the operation period, continuously monitors the inflow of new data, sets model update trigger conditions, and sets the total observation time to , divided into time intervals of equal length , for any two variables and , which is in the time interval The internal observation value, The specific data recorded at each interval are and , calculate the leading influence function according to the formula , the formula is: ,in and The variables are and The causal strength coefficient is calculated based on the average value of the entire observation period. , the formula is: ,in, is the attenuation factor. Reaching a set threshold or maximum causal strength coefficient If the specified range is exceeded, the trigger indicator is calculated according to the formula , the formula is: , where α and β are empirical calibration coefficients, , the updated model is activated, the causal analysis process is automatically restarted, the model node relationship and weight coefficient are dynamically adjusted according to the latest data, the causal network is reshaped, and the station working condition changes are adapted in real time. Based on the dynamic model, the abnormal causal link activation is monitored and multi-level risk warning signals are generated; The traceability analysis and responsibility identification module: once receiving a network security incident trigger signal, quickly lock the time point of the incident, take this as the end point, trace back at least 2 hours of multimodal historical data, retrieve equipment operation logs, network traffic records, and environmental monitoring data in reverse chronological order, build a responsibility assessment matrix, and based on the traced data clues and operation and maintenance information, comprehensively consider the factors of each link, quantify the contribution of each responsible party in the process of the incident, divide the main responsibility, secondary responsibility, and indirect responsibility, and generate a traceability report; The protection decision-making and execution module pre-builds a protection strategy library, and prepares a strategy set covering equipment isolation and shutdown, network traffic blocking and banning, system vulnerability repair and upgrade, and personnel authority management and adjustment operation plans for various network security risks and liability situations encountered by new energy sites. After receiving the traceability results transmitted by the traceability analysis and responsibility identification module, it intelligently matches the appropriate protection strategy combination, issues protection instructions, directs each control terminal, continuously monitors the protection results, and iterates and optimizes the strategy as needed.

[0007] Furthermore, the devices used in each part of the multimodal data acquisition module are: Wind turbine: Nacelle: vibration sensor; Hub: temperature sensor, stress strain sensor; Tower base: speed sensor; Photovoltaic equipment: photovoltaic panel surface: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; inverter interior: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; junction box node: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; Energy storage equipment: Next to the battery module cells: voltage monitoring point, current Hall sensor, temperature probe; Network traffic data collection module: Core network switches and router mirror ports: network traffic collection devices; Environmental data collection module: In the center of the open space: anemometer; in the equipment concentration area and distribution room: temperature and humidity sensors; additional settings for photovoltaic stations: light intensity sensor.

[0008] Furthermore, the multi-source data is fused by the fusion formula in the multi-modal data acquisition module. The weight of the equipment operation data calculated by the weight fusion formula is , the network traffic data weight is , the weight of environmental data is , the data matrices corresponding to the modes are , Run the data dimension for the device, each Represents specific equipment operating parameter values ​​such as fan speed and photovoltaic panel temperature, , Dimensions of network traffic data, such as packet size, transmission rate parameters, , is the environmental data dimension), the integrated feature vector after fusion The calculation method is: , ,in According to the values ​​of different modal data dimensions, they correspond to , , .

[0009] Furthermore, the calculation of the multimodal data fusion weight in the multimodal data acquisition module is as follows: Indicates Class modal data, is the stability index of the corresponding modal data, is the correlation coefficient between the data and the core business process of the current station, is the weight of the modality data during fusion, and the calculation formula is: ,in The calculation formula is: , is the standard deviation of the historical observation value of the corresponding modal data, To preset the upper limit of the mode standard deviation.

[0010] Furthermore, the construction of the causal model in the dynamic causal model construction and analysis module is as follows: is the comprehensive feature vector after fusion, Fusion vector dimensions to build a causal association matrix , the calculation formula is: ,in, is the number of data samples, · represents the vector dot product operation, is the predefined inter-dimension association weight, ,matrix The elements on the diagonal are set to 0 and the causal strength index is calculated. The formula for measuring the strength of potential causal relationships is: , set the threshold according to the historical normal data statistics and safety requirements of the station ,when ,determination Modal and There is a significant potential causal relationship between the modalities.

[0011] Furthermore, the threshold value of the newly collected data volume in the dynamic causal model construction and analysis module is set Determined according to the threshold setting formula, the formula is: ,in, Indicates the average amount of data collected per unit time during the same period of history. is the standard deviation of the historical data collection volume, and is the empirical coefficient. , triggering subsequent model update operations.

[0012] Furthermore, the maximum causal strength coefficient in the dynamic causal model construction and analysis module The formula for determining the prescribed range is: , ,in, is the mean of the causal intensity coefficients of multiple groups of causal pairs under historical normal working conditions, is the corresponding standard deviation, is the calibration factor, determine the lower limit With upper limit , when real-time monitoring If it is not within this range, it is considered to be beyond the normal range, triggering subsequent model update operations.

[0013] Furthermore, the dynamic causal model construction and analysis module generates multi-level risk warning signals through a comprehensive network security risk assessment formula. Indicates the network security risk level. is the set of causal strengths involving key safety indicators, is the average causal strength, that is Mean, is the variance of the causal strength value, and is the risk preference coefficient, and the calculation formula is: ,in accordance with The values ​​are divided into different levels. For low risk, For medium risk, For high risk.

[0014] On the other hand, a new energy station network security protection method based on multi-modal intelligent perception, the specific steps of the protection method are: S100, multi-modal data collection: deploy sensors on the equipment of new energy stations to collect equipment operation data, install traffic sniffing devices on network switches and router nodes to obtain network traffic data, and deploy sensors in environmentally sensitive areas to collect environmental data. By building a microprocessor into the collection terminal, the environmental noise interference is eliminated and the data is normalized, and then transmitted to the data storage and management center via a wireless communication link, and multi-source data is fused at the same time; S200, Data Storage and Management: Building a distributed storage architecture based on the Hadoop ecosystem, dividing different data storage areas, using HDFS to disperse data storage, establishing multi-dimensional data indexes, classifying and managing data, and building a data scheduling engine; S300, Dynamic Causal Model Construction and Analysis: Use historical accumulated data combined with causal discovery algorithms to build causal models, explore potential causal relationships between multimodal data, continuously monitor the inflow of new data during operation, set model update trigger conditions, and determine whether to update the model based on whether the amount of newly collected data or the maximum causal strength coefficient exceeds the normal range. Monitor abnormal causal link activation based on dynamic models and generate multi-level risk warning signals; S400, source tracing analysis and responsibility identification: After receiving the trigger signal of the network security incident, lock the time point of the incident, trace back the multimodal historical data, link the operation and maintenance management system, build a responsibility assessment matrix, quantify the contribution of each responsible party in the incident, divide the responsibility and generate a source tracing report; S500, protection decision and execution: pre-build a protection strategy library, intelligently match protection strategy combinations according to traceability results, issue protection instructions and continuously monitor protection results, and iterate and optimize strategies as needed.

[0015] Compared with the prior art, the network security protection system and method of new energy stations based on multimodal intelligent perception have the following beneficial effects: 1. Through the construction and analysis of dynamic causal models, the present invention can update and reshape the causal network in real time to adapt to changes in the operating conditions of new energy stations, so that the present invention can continuously learn and adapt to new network environments, improve the intelligence level of the present invention, and timely discover and warn of potential network security risks by mining potential causal relationships between multimodal data. At the same time, combined with traceability analysis and responsibility identification, it can quickly locate the source of the incident and divide the responsible parties, providing strong support for subsequent protection decisions. This intelligent security protection mechanism improves the network security protection capabilities of new energy stations.

[0016] 2. The present invention realizes comprehensive monitoring of new energy station equipment operation, network traffic and environmental data through multimodal data collection and fusion technology. Compared with the traditional single-modal monitoring system, the present invention can more accurately capture and identify potential network security risks. Through sensors deployed in key parts of the equipment, traffic sniffing devices at network switches and router nodes, and sensors in environmentally sensitive areas, various types of data can be collected in real time, and data preprocessing and fusion are performed through the built-in microprocessor, thereby improving the accuracy and reliability of the data.

[0017] Other advantages, objectives and features of the present invention will be set forth in part in the following description and, in part, will be apparent to those skilled in the art based on an examination of the following or may be taught from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 This is a flow chart of a network security protection system for new energy stations based on multi-modal intelligent perception; Figure 2 The figure is a flow chart of a network security protection method for new energy stations based on multimodal intelligent perception. DETAILED DESCRIPTION

[0020] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] Embodiment 1: In a wind farm, the multimodal data acquisition module deploys vibration sensors in the nacelle of the wind turbine, temperature sensors and stress-strain sensors in the hub, and speed sensors at the tower base; network traffic acquisition equipment is placed in the network core switch and router mirror port; anemometers are set up in the center of the open space of the station, and temperature and humidity sensors are set up in indoor spaces such as equipment concentration areas and distribution rooms. The data obtained by each acquisition terminal is processed and transmitted to the data storage and management unit for storage and processing. The weight of the equipment operation data is calculated through the weight fusion formula: , the network traffic data weight is , the weight of environmental data is , the data matrices corresponding to the modes are , Run the data dimension for the device, each Represents specific equipment operating parameter values ​​such as fan speed and photovoltaic panel temperature, , Dimensions of network traffic data, such as packet size, transmission rate parameters, , is the environmental data dimension), the integrated feature vector after fusion The calculation method is: , ,in According to the values ​​of different modal data dimensions, they correspond to , , .

[0022] In the dynamic causal model construction and analysis module, the causal model is constructed by combining historical accumulated data with the causal discovery algorithm. is the comprehensive feature vector after fusion, Fusion vector dimensions to build a causal association matrix , the calculation formula is: ,in, is the number of data samples, · represents the vector dot product operation, is the predefined inter-dimension association weight, ,matrix The elements on the diagonal are set to 0 and the causal strength index is calculated. The formula for measuring the strength of potential causal relationships is: , set the threshold according to the historical normal data statistics and safety requirements of the station ,when ,determination Modal and There is a significant potential causal relationship between the modalities.

[0023] During the operation period, the inflow of new data is continuously monitored. Suppose the amount of new collected data is , according to the threshold setting formula to determine the set threshold , the formula is: ,in Indicates the average amount of data collected per unit time during the same period of history. is the standard deviation of the historical data collection volume, and is the empirical coefficient, when Meet or exceed , triggering the subsequent model update operation, and at the same time, setting the maximum causal strength coefficient to , the lower limit of its conventional range is determined by the formula With upper limit , the formula is: , , is the mean of the causal intensity coefficients of multiple groups of causal pairs under historical normal working conditions, is the corresponding standard deviation, is the calibration coefficient. When real-time monitoring If it is not within this range, it is considered to be beyond the normal range, triggering subsequent model update operations.

[0024] At a certain moment, a network security incident occurs in a wind farm. The source tracing analysis and responsibility identification module quickly locks the time point of the incident, traces back at least 2 hours of multi-modal historical data, retrieves equipment operation logs, network traffic records, and environmental monitoring data in reverse chronological order, mines and analyzes each modal data, associates the site's operation and maintenance management system, obtains detailed operation and maintenance log information, builds a responsibility assessment matrix, and sets and is the dependent variable, in the time interval The internal observation value, The specific data recorded at each interval are and , calculate the leading influence function according to the formula , the formula is: ,in and The variables are and The causal strength coefficient is calculated based on the average value of the entire observation period. , the formula is: ,in It is an attenuation factor. Based on the traceable data clues and operation and maintenance information, it comprehensively considers the factors of each link, quantifies the contribution of each responsible party in the process of the incident, divides the main responsibility, secondary responsibility and indirect responsibility, and generates a traceability report. The protection decision-making and execution module pre-builds a protection strategy library. After receiving the traceability results delivered by the traceability analysis and responsibility identification module, it intelligently matches the appropriate protection strategy combination, issues protection instructions, directs each control terminal, continuously monitors the protection results, and iterates and optimizes the strategy as needed.

[0025] In summary, the network security protection system of the new energy station based on multimodal intelligent perception of the present invention has demonstrated excellent performance in the wind farm scenario. Through the multimodal data acquisition module, data on key parts of the equipment, network nodes and environmentally sensitive areas are collected to achieve comprehensive data acquisition. The data storage and management unit is based on the distributed architecture of the Hadoop ecosystem, which ensures efficient storage and rapid retrieval of data. The dynamic causal model construction and analysis module can explore the potential causal relationship between multimodal data, and update the model in real time according to the new data situation, timely discover abnormal causal links and generate risk warning signals. The traceability analysis and responsibility identification module can quickly trace back data and determine the responsible party when a network security incident occurs. The protection decision-making and execution module can intelligently match the protection strategy according to the traceability results to ensure the network security of the station. The modules work together to provide a strong guarantee for the network security of the wind farm.

[0026] Embodiment 2: In a large photovoltaic power plant, the multimodal data acquisition module deploys current sensors, voltage sensors, power sensors, and heat dissipation temperature sensors on the surface of each photovoltaic panel, and also deploys corresponding sensors inside the inverter and junction box nodes; network traffic acquisition equipment is installed in the network core switch and router mirror port; anemometers are installed in the center of the open space of the station, and temperature and humidity sensors are installed in the equipment concentration area and indoor spaces such as the distribution room, and additional light intensity sensors are installed. The data obtained by each acquisition terminal is transmitted to the data storage and management unit after processing, and the weight of the equipment operation data is calculated by the weight fusion formula: , the network traffic data weight is , the weight of environmental data is , the data matrices corresponding to the modes are ( Run the data dimension for the device, each Represents specific equipment operating parameter values ​​such as photovoltaic panel current and voltage), ( is the network traffic data dimension, such as the parameters of packet size and transmission rate), ( is the environmental data dimension), the integrated feature vector after fusion The calculation method is: , , According to the values ​​of different modal data dimensions, they correspond to , , .

[0027] Dynamic causal model construction and analysis module: Use historical accumulated data combined with causal discovery algorithms to build causal models, mine and identify potential causal relationships between multimodal data, and design is the comprehensive feature vector after fusion, Fusion vector dimensions to build a causal association matrix , the calculation formula is: ,in, is the number of data samples, · represents the vector dot product operation, is the predefined inter-dimension association weight, ,matrix The elements on the diagonal are set to 0 and the causal strength index is calculated. The formula for measuring the strength of potential causal relationships is: , set the threshold according to the historical normal data statistics and safety requirements of the station ,when ,determination Modal and There is a significant potential causal relationship between the modalities.

[0028] During the operation period, the inflow of new data is continuously monitored. Suppose the amount of new collected data is , according to the threshold setting formula to determine the set threshold , the formula is: ,in Indicates the average amount of data collected per unit time during the same period of history. is the standard deviation of the historical data collection volume, and is the empirical coefficient, when , triggering the subsequent model update operation, and at the same time, setting the maximum causal strength coefficient to , the lower limit of its conventional range is determined by the formula With upper limit , the formula is: ,in is the mean of the causal intensity coefficients of multiple groups of causal pairs under historical normal working conditions, is the corresponding standard deviation, is the calibration coefficient, when real-time monitoring If it is not within this range, it is considered to be beyond the normal range, triggering subsequent model update operations.

[0029] Based on the dynamic model, the activation of abnormal causal links can be monitored in real time. For example, when it is found that the light intensity suddenly drops sharply at a certain moment, and the output power of the photovoltaic panel does not decrease accordingly according to the normal causal relationship, but instead shows abnormal fluctuations, the system will immediately identify this abnormal causal link and generate multi-level risk warning signals. Indicates the network security risk level. is the set of causal strengths involving key safety indicators, is the average causal strength (i.e. mean), is the variance of the causal strength value, and is the risk preference coefficient, and the risk level is calculated through the comprehensive network security risk assessment formula: Calculate the risk level when When the risk is low, When the risk is medium, When the risk is high.

[0030] One day, a network security incident occurred in a photovoltaic power plant. The traceability analysis and responsibility identification module quickly locked the time of the incident, traced back at least 2 hours of multimodal historical data, and retrieved equipment operation logs, network traffic records, and environmental monitoring data in reverse chronological order. and is the dependent variable, in the time interval The internal observation value, The specific data recorded at each interval are and , calculate the leading influence function according to the formula , the formula is: ,in and The variables are and The causal strength coefficient is calculated based on the average value of the entire observation period. , the formula is: ,in To serve as the attenuation factor, Jishi traced back the data clues and operation and maintenance information, constructed a responsibility assessment matrix, comprehensively considered the factors in each link, quantified the contribution of each responsible party in the process of the incident, divided the main responsibility, secondary responsibility, indirect responsibility, and generated a traceability report.

[0031] The protection decision-making and execution module pre-builds a protection strategy library. After receiving the traceability results transmitted by the traceability analysis and responsibility identification module, it intelligently matches the appropriate protection strategy combination, issues protection instructions to each management and control terminal, and continuously monitors the protection results, iterating and optimizing the strategy as needed.

[0032] To sum up, in the photovoltaic power field scenario, the present invention uses a multimodal data acquisition module to accurately acquire various types of data, a data storage and management unit to effectively manage data, a dynamic causal model construction and analysis module to deeply analyze the causal relationship between data, dynamically adjust the model to adapt to changes in working conditions, accurately monitor anomalies and evaluate risk levels, and a source tracing analysis and responsibility identification module to quickly locate the source of the problem after an incident occurs and clarify responsibilities. The protection decision-making and execution module quickly implements protection measures and continuously optimizes based on the results.

[0033] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A new energy station network security protection system based on multi-modal intelligent perception, characterized in that: The system includes the following components: multimodal data acquisition module, data storage and management unit, dynamic causal model construction and analysis module, traceability analysis and responsibility identification module, and protection decision-making and execution module; The multimodal data acquisition module: deploys sensor acquisition equipment on the equipment of the new energy station, installs traffic sniffing devices on network switches and router nodes to obtain network traffic data, arranges sensors in environmentally sensitive areas to collect environmental data, configures microprocessors for acquisition terminals, eliminates environmental noise interference, and normalizes data to a standard range, transmits it to a data storage and management center via a wireless communication link, and fuses multi-source data in the data center; The data storage and management unit: builds a distributed storage architecture based on the Hadoop ecosystem, divides the device data storage area, the network traffic storage area, and the environment data storage area, uses HDFS to store data in a dispersed manner, and at the same time, establishes a multi-dimensional data index, manages data according to timestamps, device numbers, and data type labels, and builds a data scheduling engine. When a data retrieval request is received, the relevant data storage location is located according to the index label to retrieve the data; The dynamic causal model construction and analysis module: uses historical accumulated data combined with causal discovery algorithms to build a causal model, mines and identifies potential causal relationships between multimodal data, enters the operation period, continuously monitors the inflow of new data, sets model update trigger conditions, and sets the total observation time to , divided into time intervals of equal length , for any two variables and , which is in the time interval The internal observation value, The specific data recorded at each interval are and , calculate the leading influence function according to the formula , the formula is: ,in and The variables are and The causal strength coefficient is calculated based on the average value of the entire observation period. , the formula is: ,in, is the attenuation factor. Reaching a set threshold or maximum causal strength coefficient If the specified range is exceeded, the trigger indicator is calculated according to the formula , the formula is: , where α and β are empirical calibration coefficients, , the updated model is activated, the causal analysis process is automatically restarted, the model node relationship and weight coefficient are dynamically adjusted according to the latest data, the causal network is reshaped, and the station working condition changes are adapted in real time. Based on the dynamic model, the abnormal causal link activation is monitored and multi-level risk warning signals are generated; The traceability analysis and responsibility identification module: once receiving a network security incident trigger signal, quickly lock the time point of the incident, take this as the end point, trace back at least 2 hours of multimodal historical data, retrieve equipment operation logs, network traffic records, and environmental monitoring data in reverse chronological order, build a responsibility assessment matrix, and based on the traced data clues and operation and maintenance information, comprehensively consider the factors of each link, quantify the contribution of each responsible party in the process of the incident, divide the main responsibility, secondary responsibility, and indirect responsibility, and generate a traceability report; The protection decision-making and execution module pre-builds a protection strategy library, and prepares a strategy set covering equipment isolation and shutdown, network traffic blocking and banning, system vulnerability repair and upgrade, and personnel authority management and adjustment operation plans for various network security risks and liability situations encountered by new energy sites. After receiving the traceability results transmitted by the traceability analysis and responsibility identification module, it intelligently matches the appropriate protection strategy combination, issues protection instructions, directs each control terminal, continuously monitors the protection results, and iterates and optimizes the strategy as needed.

2. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: Equipment used in each part of the multimodal data acquisition module: Wind turbine: Nacelle: vibration sensor; Hub: temperature sensor, stress strain sensor; Tower base: speed sensor; Photovoltaic equipment: photovoltaic panel surface: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; inverter interior: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; junction box node: current sensor, voltage sensor, power sensor, heat dissipation temperature sensor; Energy storage equipment: Next to the battery module cells: voltage monitoring point, current Hall sensor, temperature probe; Network traffic data collection module: Core network switches and router mirror ports: network traffic collection devices; Environmental data collection module: In the center of the open space: anemometer; in the equipment concentration area and distribution room: temperature and humidity sensors; additional settings for photovoltaic stations: light intensity sensor.

3. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The multi-source data is fused in the multi-modal data acquisition module through a fusion formula. The weight of the equipment operation data calculated by the weight fusion formula is: , the network traffic data weight is , the weight of environmental data is , the data matrices corresponding to the modes are , Run the data dimension for the device, each Represents specific equipment operating parameter values ​​such as fan speed and photovoltaic panel temperature, , Dimensions of network traffic data, such as packet size, transmission rate parameters, , is the environmental data dimension), the integrated feature vector after fusion The calculation method is: , ,in According to the values ​​of different modal data dimensions, they correspond to , , .

4. According to claim 3, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The calculation of the multimodal data fusion weight in the multimodal data acquisition module is as follows: Indicates Class modal data, is the stability index corresponding to the modal data, is the correlation coefficient between the data and the core business process of the current station, is the weight of the modality data during fusion, and the calculation formula is: ,in The calculation formula is: , is the standard deviation of the historical observation value of the corresponding modal data, To preset the upper limit of the mode standard deviation.

5. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The construction of the causal model in the dynamic causal model construction and analysis module is as follows: is the comprehensive feature vector after fusion, Fusion vector dimensions to build a causal association matrix , the calculation formula is: ,in, is the number of data samples, · represents the vector dot product operation, is the predefined inter-dimension association weight, ,matrix The elements on the diagonal are set to 0 and the causal strength index is calculated. The formula for measuring the strength of potential causal relationships is: , set the threshold according to the historical normal data statistics and safety requirements of the station ,when ,determination Modal and There is a significant potential causal relationship between the modalities.

6. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The threshold value of the newly collected data volume in the dynamic causal model construction and analysis module is set Determined according to the threshold setting formula, the formula is: ,in, Indicates the average amount of data collected per unit time during the same period of history. is the standard deviation of the historical data collection volume, and is the empirical coefficient. , triggering subsequent model update operations.

7. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The maximum causal strength coefficient in the dynamic causal model construction and analysis module The formula for determining the prescribed range is: , ,in, is the mean of the causal intensity coefficients of multiple groups of causal pairs under historical normal conditions, is the corresponding standard deviation, is the calibration factor, determine the lower limit With upper limit , when real-time monitoring If it is not within this range, it is considered to be beyond the normal range, triggering subsequent model update operations.

8. According to claim 1, a new energy station network security protection system based on multi-modal intelligent perception is characterized in that: The dynamic causal model construction and analysis module generates multi-level risk warning signals through a comprehensive network security risk assessment formula. Indicates the network security risk level. is the set of causal strengths involving key safety indicators, is the average causal strength, that is Mean, is the variance of the causal strength value, and is the risk preference coefficient, and the calculation formula is: ,in accordance with The values ​​are divided into different levels. For low risk, For medium risk, For high risk.

9. A new energy station network security protection method based on multi-modal intelligent perception, characterized in that: The specific steps of this protection method are: S100, multi-modal data collection: deploy sensors on the equipment of new energy stations to collect equipment operation data, install traffic sniffing devices on network switches and router nodes to obtain network traffic data, and deploy sensors in environmentally sensitive areas to collect environmental data. By building a microprocessor into the collection terminal, the environmental noise interference is eliminated and the data is normalized, and then transmitted to the data storage and management center via a wireless communication link, and multi-source data is fused at the same time; S200, Data Storage and Management: Building a distributed storage architecture based on the Hadoop ecosystem, dividing different data storage areas, using HDFS to disperse data storage, establishing multi-dimensional data indexes, classifying and managing data, and building a data scheduling engine; S300, Dynamic Causal Model Construction and Analysis: Use historical accumulated data combined with causal discovery algorithms to build causal models, explore potential causal relationships between multimodal data, continuously monitor the inflow of new data during operation, set model update trigger conditions, and determine whether to update the model based on whether the amount of newly collected data or the maximum causal strength coefficient exceeds the normal range. Monitor abnormal causal link activation based on dynamic models and generate multi-level risk warning signals; S400, source tracing analysis and responsibility identification: After receiving the trigger signal of the network security incident, lock the time point of the incident, trace back the multimodal historical data, link the operation and maintenance management system, build a responsibility assessment matrix, quantify the contribution of each responsible party in the incident, divide the responsibility and generate a source tracing report; S500, protection decision and execution: pre-build a protection strategy library, intelligently match protection strategy combinations according to traceability results, issue protection instructions and continuously monitor protection results, and iterate and optimize strategies as needed.

Citation Information

Cited By

  • Multi-source data fusion underground pipe gallery real-time state dynamic monitoring method and system

    CN120499529A

  • Key equipment change analysis method and device based on dynamic working condition real-time perception

    CN120804585A

  • Method and device for analyzing key equipment change based on real-time sensing of dynamic working conditions

    CN120804585B

  • Electric power data safety early warning management method and system

    CN120931278A

  • A power data security early warning management method and system

    CN120931278B