Electric power information system security risk detection and defense method and system

By applying vulnerability identification methods, dynamic taint tracking and transparent object proxy technology based on LSTM and optimized reorganization algorithms in power information systems, combined with context perception and high-heuristic algorithms, the problem of lagging security risk management of power information system software is solved, and efficient security threat detection and defense are achieved.

CN119961178APending Publication Date: 2025-05-09ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202411568370.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

In the prior art, the software security risk management of power information systems is lagging behind and lacks systematic solutions, especially in the security issues of open source software components.

Method used

Using LSTM and optimized reorganization algorithm methods, we identify potential component vulnerabilities in source code and binary files, and monitor the environment in real time when the application runs, and use dynamic taint tracking and transparent object proxy technology to monitor the application's context and determine whether it is under attack. If an attack is detected, the attack code line is located using context-aware methods and self-protection mechanisms, and defend against unknown vulnerability attacks through a highly heuristic algorithm based on the attack behavior.

Benefits of technology

It significantly improves the detection and defense capabilities of the power information system against security threats, can promptly detect and prevent potential attacks, reduce the impact of security threats on the system, improve the system's self-protection capabilities, and ensure the safe and stable operation of the software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961178A_ABST
    Figure CN119961178A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software security detection and defense, in particular to a power information system security risk detection and defense method and system. Identifying potential component vulnerabilities of the source code and the binary file based on an LSTM and an optimization recombination algorithm; setting a hook at the key point to monitor the running environment of the application program in real time, and discovering a potential vulnerability attack behavior; a dynamic stain tracking algorithm and a transparent object proxy mode are adopted to monitor a context executed by an application program and a source of a tracking variable, so that whether the application program is attacked or not is judged; when the attack is judged, an attack code line is accurately positioned by utilizing a context sensing method and a self-protection mechanism, so that real-time measures are conveniently taken to prevent the attack from being successful; the high heuristic algorithm based on the attack behavior defends unknown vulnerability attacks. Potential safety copper leakage in the codes can be found in time, the use environment of the software is monitored, potential attack behaviors are found and stopped, and the safety of the system software is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software security detection and defense, and in particular to a method and system for detecting and defending security risks of an electric power information system. Background Art

[0002] In contemporary system development practice, in order to improve development efficiency, developers generally use open source software, that is, software that is released with source code and can be shared and modified. However, due to its popularity and the spontaneity of maintenance and updates, open source software faces unique security challenges. Cyber ​​attackers are also constantly using open source code bases to spread legitimate code to unsuspecting developers. Such software often lacks a clear provenance and is maintained unevenly, which poses security risks. Power grid software security reviews often ignore supply chain security. Software is usually spliced ​​together from multiple sources and old code with different security levels, making it complicated to trace the source and provenance of all code to manage supply chain risks. At the same time, the use of components is not thoroughly checked, there is a lack of automated means, and the security risk management of the code is also lagging behind, lacking a systematic solution.

[0003] In view of this, a method, system, medium and processor for detecting and defending security risks in a power information system is needed. Summary of the invention

[0004] In view of the above problems existing in the prior art, the present invention is proposed.

[0005] Therefore, the present invention provides a method for detecting and defending security risks in a power information system, which can solve the problems of lagging security risk management of codes and lack of systematic solutions in traditional technologies.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions, a method for detecting and defending security risks of power information systems, comprising: identifying potential component vulnerabilities of source code and binary files based on LSTM and optimized reorganization algorithms; setting hooks at key points to monitor the environment of application runtime in real time and discover potential vulnerability attack behaviors; using dynamic taint tracking algorithm and transparent object proxy method to monitor the context of application execution, track the source of variables, and determine whether the application is under attack; if it is determined to be under attack, using context-aware methods and self-protection mechanisms to locate the attack code lines; defending against unknown vulnerability attacks based on a high heuristic algorithm of attack behavior; and visualizing and counting threat behaviors.

[0007] As a preferred solution of the power information system security risk detection and defense method described in the present invention, the identifying potential component vulnerabilities of source code and binary files includes converting binary executable files, compilable source code projects and non-compilable source code files to obtain corresponding LLVM bitcode files, using a similarity comparison algorithm to calculate the similarity measure of the vulnerability function, obtaining a similar function set of the known vulnerability function in the LLVM bitcode file, performing backward slicing on the functions in the similar function set and generating constraint derivations, performing similarity comparison with the constraint derivations of the known vulnerability function, obtaining a new function similarity measure, and outputting functions with higher similarity to the vulnerability function as potential component vulnerabilities for monitoring.

[0008] As a preferred solution of the power information system security risk detection and defense method described in the present invention, the new function similarity measurement includes selecting constrained variables, relying on data flow and control flow, backward slicing the instruction sequence with the instruction where the constrained variable is located as the starting point, and generating a constraint derivation formula, performing similarity comparison with the constraint derivation formula of a known vulnerability function, recalculating the similarity between functions, and obtaining a new function similarity measurement.

[0009] As a preferred solution of the power information system security risk detection and defense method described in the present invention, the similarity between the recalculated functions includes calculating the similarity between two constraint derivations by using string edit distance calculation, and finding the optimal match among all constraint derivation combinations.

[0010] As a preferred solution of the method for detecting and defending security risks of a power information system described in the present invention, the finding of the optimal match includes calculating the similarity of two functions, and the formula is:

[0011]

[0012] Among them, f1 and f2 represent two different functions to be compared, sim(·) represents similarity, dist(·) represents the function of measuring differences, len(·) represents the function of calculating the length of the string, and cd i represents the i-th constraint derivation in the constraint derivation set CD, cd j Represents the set of constraint derivations CD * The j-th constraint derivation in , n, m represent the set CD, CD * The number of constraint derivations in , max(·) represents the maximum function, min(·) represents the minimum function, and ln(·) represents the logarithmic function.

[0013] As a preferred solution of the method for detecting and defending security risks of a power information system described in the present invention, the highly heuristic algorithm based on attack behavior to defend against unknown vulnerability attacks includes distinguishing normal business requests from potential attack requests by obtaining stack information, abnormal information user input and parameter information of the current function context;

[0014] The unknown vulnerability attacks include 0day attacks and unknown vulnerabilities of the application itself.

[0015] As a preferred solution of the power information system security risk detection and defense method described in the present invention, the visual statistics of threat behaviors include security checks on software configuration parameters and application reinforcement functions to enhance system security.

[0016] Another object of the present invention is to provide a power information system security risk detection and defense system to cope with the security challenges prevalent in current software development, especially the security issues of open source software components. Through automated means, the present invention can timely discover potential security vulnerabilities in the code, and monitor and defend against potential attack behaviors in real time in the software usage environment. Through vulnerability identification based on LSTM and optimized recombination algorithms, dynamic taint tracking, and high heuristic algorithms, not only the detection accuracy of known and unknown vulnerability attacks is improved, but also the self-protection ability of the system is enhanced, thereby ensuring the software security and stable operation of the power information system.

[0017] As a preferred solution of the power information system security risk detection and defense system described in the present invention, it includes: an identification module, a discovery module, a judgment module, a first defense module, a second defense module and a display module;

[0018] The identification module, based on LSTM and optimized reorganization algorithm, identifies potential component vulnerabilities in source code and binary files;

[0019] The discovery module sets hooks at key points to monitor the environment in which the application is running in real time and discover potential vulnerability attack behaviors;

[0020] The judgment module uses a dynamic taint tracking algorithm and a transparent object proxy method to monitor the context of application execution and the source of tracking variables to determine whether the application is under attack;

[0021] The first defense module, if it is determined to be under attack, uses context-aware methods and self-protection mechanisms to locate the attacking code line and take real-time measures to prevent the attack;

[0022] The second defense module uses a high heuristic algorithm based on attack behavior to defend against unknown vulnerability attacks;

[0023] The display module performs visual statistics on threat behaviors.

[0024] A computer device comprises a memory and a processor, wherein the memory stores a computer program, and wherein the processor implements the steps of any one of the methods for detecting and defending security risks in a power information system when executing the computer program.

[0025] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of any one of the methods for detecting and defending security risks in a power information system are implemented.

[0026] Beneficial effects of the invention: This patent significantly improves the detection and defense capabilities of the power information system against security threats by comprehensively applying a variety of security detection and defense technologies. Through LSTM and optimized reorganization algorithms, the present invention can effectively identify potential component vulnerabilities in source code and binary files, thereby preventing possible security risks in advance. By real-time monitoring of the application runtime environment, the present invention can promptly discover and prevent potential attack behaviors and reduce the impact of security threats on the system. Utilizing dynamic taint tracking and transparent object proxy technology, the present invention can accurately track and monitor the context of application execution and the source of variables, and effectively judge and defend against various attacks. The present invention adopts a highly heuristic algorithm based on attack behavior, which can defend against unknown vulnerability attacks. Through these measures, the present invention not only improves the security performance of the power information system, but also provides a strong guarantee for the stable operation of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0028] Figure 1 A schematic flow chart of a method for detecting and defending security risks in a power information system is provided for one embodiment of the present invention.

[0029] Figure 2 A schematic diagram of the jump structure between basic blocks of a power information system security risk detection and defense method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0030] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0031] Example 1, reference Figure 1-Figure 2 , which is the first embodiment of the present invention, and provides a method for detecting and defending security risks of a power information system, comprising:

[0032] S1: Identify potential component vulnerabilities in source code and binary files based on LSTM and optimized reorganization algorithms.

[0033] It should be noted that the binary executable file, compilable source code project or non-compilable source code file is converted to obtain the corresponding LLVM bitcode language file. Based on LLVM bitcode, different input forms can be simplified into the same type of input, which greatly simplifies the difficulty of LSTM module adaptation.

[0034] Furthermore, the similarity comparison algorithm is used on the obtained LLVM bitcode language file to calculate the similarity measure of the function, and a similar function set of the known vulnerable functions existing in the LLVM bitcode language file is obtained. The functions in the similar function set are back-sliced ​​and constraint derivations are generated, and the similarity is compared with the constraint derivations of the known vulnerable functions to obtain a new function similarity measure.

[0035] During the generation process, vulnerability patches sometimes only replace dangerous functions or modify the conditions that trigger the vulnerability. Such vulnerability patch functions are very similar to vulnerability functions in syntax and semantics. This scheme introduces constraint derivation to distinguish such functions.

[0036] Select constrained variables: Function vulnerability triggering is usually a process of exerting influence from the inside of the function to the outside. In the LLVM bitcode language file, there are mainly three types of instructions that can have an impact on the outside of the function: 1) return instructions; 2) sub-function call instructions; 3) memory operation instructions. Therefore, the constrained variables are mainly selected from the above three types of instructions.

[0037] Depends on data flow and control flow, takes the instruction where the constrained variable is located as the starting point to slice the instruction sequence backwards, and generates constraint derivation formulas. After selecting the constrained variable, take the instruction where the constrained variable is located as the starting point, use the path slicing algorithm to slice the instruction sequence backwards, find the relevant instructions that can affect the constrained variable through the data flow dependency, analyze the control flow jump, and extract the constraints of the data flow direction. In LLVM bitcode, the usedef chain can be used to restore the data flow dependency, and the Boolean value of the conditional comparison instruction can be restored through the jump direction between subsequent basic blocks, and the constraint formula can be generated based on the Boolean value.

[0038] like Figure 2 As shown, the return instruction is selected as the starting point of the slice. In the process of generating the conditional constraint of generating the function return value of 13200, the control flow relationship shows that the predecessor basic block of basic block BB3 is BB1. If the above control flow jump is to be satisfied, the value of the variable Var15 of the conditional jump instruction (bri 1) in basic block BB1 must be True, and it is deduced that the comparison instruction (icmpeq) must satisfy the constraint Var13==49200. At the same time, Var 13 is added to the constrained value set, and so on. The final generated constraint derivation formula is as follows:

[0039] Var 13==49200&.Var7==771->ret 131200

[0040] Among them, Var represents a variable, and ret represents a function return value operation.

[0041] Furthermore, by comparing the similarity with the constraint derivation of the known vulnerability function, the similarity between the functions is recalculated to obtain a new function similarity measure. A function usually contains multiple constraint derivations, and the function similarity calculation based on the constraint derivation needs to be implemented in two steps.

[0042] Given two functions f1 and f2 to be compared for similarity, their corresponding constraint derivation sets are cd i , cd j , G m×n is the matrix of matching factors of two sets of constraint derivations, that is, if cd i and cd j Match, then G i×j =1, otherwise G i×j = 0. Therefore, the similarity calculation problem of two functions can be transformed into finding the optimal matrix G m×n , so that the constraint derivation of the function minimum, that is, find the optimal combination to minimize the difference between the constraint derivations of the two functions, where dist(cd i ,cd j) is the metric constraint derivation formula cd i and cd j The difference function is implemented using string edit distance. Finding the above optimal combination is a typical integer linear programming problem.

[0043] Since the final result is a new similarity measure of the two functions, the function difference results are transformed. Let |CD| be the number of constraint derivations in the constraint derivation set CD. In order to reduce the result fluctuations caused by different function scales, the total length of the constraint derivation string is used as the normalized denominator. The number of constraint derivations of two similar functions should tend to be the same. If there is a large difference in the number of constraint derivations between two functions that are judged to be similar, it is very likely to be a misjudgment. Therefore, the formula adds the number of constraint derivations as a weight factor to the similarity calculation. The similarity calculation formula for functions f1 and f2 is:

[0044]

[0045] Among them, f1 and f2 represent two different functions to be compared, sim(·) represents similarity, dist(·) represents the function of measuring differences, len(·) represents the function of calculating the length of the string, and cd i represents the i-th constraint derivation in the constraint derivation set CD, cd j Represents the set of constraint derivations CD * The j-th constraint derivation in , n, m represent the set CD, CD * The number of constraint derivations in , max(·) represents the maximum function, min(·) represents the minimum function, and ln(·) represents the logarithmic function.

[0046] Furthermore, the functions with the highest similarity to the vulnerable functions are output as potential component vulnerabilities for monitoring.

[0047] Consider using eight static features such as string constants, numerical constants, assignment instruction numbers, general instruction numbers, arithmetic instruction numbers, basic block successors, and basic block intermediates to characterize basic blocks (such as BB1, BB2, and BB3). Use feature statistics to map basic blocks to an 8-dimensional vector space, so that the control flow graph CFG composed of basic blocks is converted into an ACFG graph (attributed control flow graph) composed of an 8-dimensional vector space. Use the graph embedding network Structure2vec to aggregate the ACFG graph node information into a p-dimensional vector output after multiple rounds of iterations. Among them, the role of iteration is mainly to diffuse the basic block initial vector information through the first-order neighbor nodes of the control flow graph CFG, so that each node contains the information of other nodes. The formula for the iteration process is:

[0048]

[0049] in, For x v The node information after the tth iteration update, the initial value is set to 0; v is the initial feature vector information of the basic block in the ACFG graph; W1 is a d×p matrix, where d is x v The feature dimension of , p is the dimension of the ACFG graph mapped to the output vector space; N (v) is the set of first-order neighbor nodes of node v in the ACFG graph; σ(·) is an l-layer fully connected neural network, specifically expressed as σ(1) = P1×ReLU(P2×ReLU(P l )), P i =(1,…,l) is a d×p matrix, l is the number of embedding layers, and ReLU(x) is the activation function.

[0050] After t rounds of iterations, a new ACFG graph is obtained. Each vector node in the graph is aggregated to obtain a p-dimensional vector The aggregation method formula is Where W2 is a p×p matrix and V is the set of all nodes in the ACFG graph.

[0051] Therefore, the similarity comparison between functions can be converted into a distance comparison of a fixed-dimensional vector space. The distance in the vector space is calculated using cosine similarity, and the cosine value of two vectors can be calculated using the Euclidean dot product formula. The specific calculation is as follows:

[0052]

[0053] Among them, <·> represents the dot product calculation of the vector, ||·|| represents the length calculation of the vector, cos(·) represents the cosine function, and g1 and g2 represent different vectors respectively.

[0054] The Structure2vec graph is embedded into the network and the Lisheng neural network architecture is used for model training. The functions with the same name in the training data are labeled y i =1, that is, the two are similar, otherwise they are labeled y i =-1. The following objective function is used during training, and the parameters of the model obtained through training are W1, P 1,...n , W2, the calculation formula of the minimum vector space distance model between functions is as follows:

[0055]

[0056] Wherein, sin(·) represents the sine function, and k is the index value.

[0057] There are all kinds of complex software in the power grid information system, including some special codes and binary files. By using similarity comparison algorithms to calculate function similarity and perform backward slicing, constraint derivation is generated. This process not only improves the accuracy of identifying similar parts of known vulnerability functions, but also can effectively distinguish those vulnerability patch functions that only have slight changes in syntax and semantics. The innovation of this method is to introduce similarity comparison of constraint derivation, further refine the similarity measurement between functions, optimize the accuracy of vulnerability detection, and provide more advanced candidate functions for manual verification, which is more advanced and efficient than previous technologies.

[0058] The method of the present invention can detect multiple vulnerability types, including SQL injection, command execution, XXE, path traversal, etc., thereby achieving multi-level vulnerability protection. This solution has a wide range of Web vulnerability detection functions, covering multiple vulnerability types, including SQL statement anomalies, UNC path injection, command execution, XXE, directory traversal, file operation vulnerabilities, etc.

[0059] S2: Set hooks at key points to monitor the environment of the application in real time and discover potential vulnerability attacks. A monitoring and governance method and system based on a multimodal and knowledge graph-based lake language model monitors the environment of the application in real time and discovers potential vulnerability attacks. A hook is a point in the system message processing mechanism where an application can install a subroutine to monitor the message traffic in the system and process certain types of messages before they reach the target window process if potential vulnerability attacks are found.

[0060] Supports protection against memory Trojans, and supports detection and protection against memory Trojans in the form of Cleaver, Ice Scorpion Ant Sword, etc. It can detect and intercept various potential threats, provide stack information and timestamp information, and help security personnel make further judgments.

[0061] S3: It uses a dynamic taint tracking algorithm and a transparent object proxy method to monitor the context of application execution, track the source of variables, and determine whether the application is under attack.

[0062] It should be noted that by using dynamic taint tracking algorithms and transparent object proxies, it is possible to losslessly hook the program, thereby monitoring the context of application execution and tracking the source of variables, thereby determining whether the application has been attacked.

[0063] The dynamic taint tracking algorithm is an important security detection technology that works based on the principle of abstracting data streams into triplets (sources, sanitizers, sinks). In this model:

[0064] Sources represent tainted input sources. It is generally believed that any data input from the outside is untrusted tainted data and may cause harm to the system. This data may come from user input, data read from files, etc.

[0065] Sanitizers refer to the harmless processing of tainted data, such as cleaning, verification, filtering and other operations.

[0066] Sinks represent taint sinks, which usually refer to sensitive operations that will cause security issues, such as executing SQL statements, executing operating system commands, etc.

[0067] The core of dynamic taint tracking is to track the tainted data (sources) input into the system. If the data is not adequately cleaned, verified, filtered, or sanitized during its flow through the code, it will directly cause sensitive operations (sinks) that may pose security risks. In this way, data flow paths that may lead to security vulnerabilities can be detected, thereby discovering and fixing potential security issues in advance.

[0068] Transparent proxy is a network proxy technology that can intercept and forward network traffic without the user's knowledge. The client does not need to know the existence of the proxy server at all. The proxy server will automatically process the user's network request and transmit the real IP address to the target server. This proxy method is mainly used in NAT forwarding of routers, and is commonly used in corporate networks as a gateway for LANs to access the Internet.

[0069] The characteristic of transparent proxy is that the client does not need to perform any proxy settings. It implements the proxy function by intercepting traffic at the network level. This technology is often used in network management, security policy implementation, traffic monitoring and optimization, such as content filtering, cache acceleration, traffic control and load balancing. Transparent proxy can be implemented using technologies such as TPROXY, NAT, Divert, and can also be implemented using technologies such as Pipy and eBPF. eBPF is an efficient and flexible kernel technology that allows user space programs to be executed securely in the Linux kernel space, providing another technical solution for transparent proxy.

[0070] The specific steps to determine whether an application has been attacked are as follows:

[0071] Data flow monitoring monitors the flow of untrusted input data while the program is running. For example, when a user enters information on a web page and submits it, dynamic taint tracking monitors how these inputs flow in the background code.

[0072] Taint propagation analysis analyzes the propagation path of tainted data in the program to determine whether it directly performs sensitive operations without proper processing. For example, if untrusted input affects key operations of the program without verification, such as executing system commands or modifying memory, this may be the starting point of an attack.

[0073] Security risk assessment: Based on the flow and processing of tainted data, determine whether the program may be attacked. If it is found that sensitive operations are performed directly on the data without sufficient processing, the system will issue an alarm to indicate possible security risks, that is, it is determined that the application has been attacked.

[0074] Through the above methods, it is possible to effectively determine whether an application has been attacked and take timely measures to prevent further damage.

[0075] S4: If it is determined that the system is under attack, use context-aware methods and self-protection mechanisms to locate the attacking code line.

[0076] It should be noted that the implementation of dynamic taint tracking usually relies on instrumentation technology, which records the flow of data by inserting additional code at key locations. The recorded data is then used for analysis to detect whether sensitive operations are performed directly without proper processing, thereby revealing potential security risks. Code instrumentation is used to monitor requests, continuously collect data, determine whether the service has been attacked through context and heuristic algorithms, and then send the attack data to the backend service.

[0077] By combining the context-aware computing framework and self-protection mechanism, threat semantic knowledge is collected from multi-source threat intelligence and local sandbox alarm logs, an attack organization knowledge base is built, and real-time, massive, multimodal alarm data is normalized and associated with the attack chain to ultimately discover the attack code lines.

[0078] Specific methods include:

[0079] Build an attack organization knowledge base: Combined with the context-aware computing framework, the threat semantic knowledge related to the attack organization is collected from multi-source threat intelligence and local sandbox alarm logs to build an attack organization knowledge base.

[0080] Normalized understanding and attack chain association: Based on big data streaming computing, normalized understanding and attack chain association of real-time, massive, multi-modal alarm data are performed, and the constructed attack organization knowledge base is combined to perform event threat semantic enrichment and attack organization feature association calculation.

[0081] Self-protection mechanism: Through AI's deep learning capabilities, attackers can quickly generate complex attack codes to bypass traditional firewalls and detection systems. Therefore, it is necessary to use AI to fight AI and improve the protection effect through self-protection mechanisms.

[0082] Through these methods, the attack code lines can be effectively located, improving the efficiency and accuracy of network security protection.

[0083] S5: A highly heuristic algorithm based on attack behavior defends against unknown vulnerability attacks.

[0084] It should be noted that, based on the principle of vulnerability attack, this solution uses a high heuristic detection algorithm, focusing on the behavior generated by the attack vector rather than specific attack features. This method can defend against unknown vulnerability attacks, including 0day attacks and unknown vulnerabilities of the application itself. Using a high heuristic behavior detection algorithm, the false alarm rate is reduced to ensure that real attack events are not ignored. By obtaining the stack information, abnormal information user input and parameter information of the current function context, it can accurately distinguish between normal business requests and potential attack requests, thereby improving the accuracy of detection.

[0085] S6: Visualize and count threat behaviors.

[0086] The visualization statistics of network threat behaviors mainly include the following aspects:

[0087] Attack type distribution: The frequency differences of different attack types are displayed through a bar chart to help analyze the popularity and changing trends of various attack methods.

[0088] Feature analysis: Box plot analysis is performed on key features (such as anomaly score, source port, packet length, etc.) to reveal the statistical characteristics of different attack types.

[0089] Protocol share: Use pie charts to show the usage frequency of major network protocols (such as UDP, ICMP, TCP) and assess their importance in attacks.

[0090] Time series analysis: Use heat maps to show the changing trends of attack events over time and months, and explore the periodicity of attack activities.

[0091] Payload Data content mining: Generate word clouds to reveal high-frequency words in attack payloads and gain insights into potential attack patterns and keywords.

[0092] The specific implementation steps are as follows:

[0093] Data collection and integration: Collect data from firewalls, IDS, probes, terminal anti-virus software and other nodes, unify the data format, and clean and classify it.

[0094] Data analysis: Use the Pandas library to clean the data, handle missing values ​​and redundant information, and convert timestamps into date and time formats.

[0095] Count the number of various attack types and visualize their distribution.

[0096] The key features are carefully explored and box plots are drawn.

[0097] Count the usage frequency of network protocols and display them in a pie chart.

[0098] Build a pivot table based on the timestamps of the attacks, and use a heat map to display the time series of attack events.

[0099] Perform text analysis on the payload data and generate a word cloud.

[0100] The purpose of visualizing statistics of network threat behaviors is to reveal attack patterns and defense strategy recommendations through data visualization technology. The complex network security situation places high demands on enterprise security construction. Defense measures usually lag behind the evolution of attack methods and are costly. Therefore, visual analysis can help security personnel better understand attack trends and take effective defense measures.

[0101] In-depth threat analysis from a memory perspective to detect and defend against memory injection attacks. By going deep inside the application, the product is able to process encrypted requests, including decrypted, structured, formatted, and deserialized data objects. This helps maintain effective detection capabilities when facing encrypted traffic, whether it is HTTPS or encrypted communication within the application.

[0102] Security checks on software configuration parameters and application hardening functions are performed to further strengthen system security, while the automatic reporting mechanism for attack events ensures that the operation and maintenance team can respond to security threats in a timely manner. Application hardening functions include: supporting the output of X-Frame-0ptions response headers to add clickjacking protection functions; outputting XContent-Type-0ptions response headers to add MIME sniffing protection functions; outputting X-XSS-Protection response headers to enable browser XSS Auditor protection functions; outputting X-Download-0ptions response headers to add file automatic run protection functions. Security checks include http0nly setting checks for key cookies, process startup account checks, Tomcat default configuration checks, database connection account audits, and JBoss default configuration checks. The automatic reporting mechanism includes configuring mail servers and receiving mailboxes to provide feedback to the operation and maintenance personnel on alarm events in the system in the first place, so that the system security trends can be known in the first place.

[0103] This solution is multi-platform compatible. Whether it is JAVA or PHP language, it can provide consistent protection effects in various operating systems and frameworks. JAVA language supports any combination of Windows / Linux, JDK7-17, 0racleJDK / 0penJDKTomcat / SpringBoot / Jboss / PHP / … and other environments. PHP language supports versions 5.4, 5.5, 5.6, 7.0, 7.1, 7.2, 7.3, and 7.4. It also supports key injection protection for local machines, Docker containers, and k8s.

[0104] Embodiment 2, the second embodiment of the present invention, is different from the previous embodiment in that:

[0105] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.

[0106] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0107] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0108] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0109] Embodiment 3, the third embodiment of the present invention, provides a power information system security risk detection and defense system, characterized by: comprising an identification module, a discovery module, a judgment module, a first defense module, a second defense module and a display module;

[0110] The identification module, based on LSTM and optimized reorganization algorithm, identifies potential component vulnerabilities in source code and binary files;

[0111] The discovery module sets hooks at key points to monitor the environment in which the application is running in real time and discover potential vulnerability attack behaviors;

[0112] The judgment module uses a dynamic taint tracking algorithm and a transparent object proxy method to monitor the context of application execution and the source of tracking variables to determine whether the application is under attack;

[0113] The first defense module, if it is determined to be under attack, uses context-aware methods and self-protection mechanisms to locate the attacking code line and take real-time measures to prevent the attack;

[0114] The second defense module uses a high heuristic algorithm based on attack behavior to defend against unknown vulnerability attacks;

[0115] The display module performs visual statistics on threat behaviors.

[0116] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for detecting and defending security risks in a power information system, characterized in that: include, Identify potential component vulnerabilities in source code and binary files based on LSTM and optimized reorganization algorithms; Set hooks at key points to monitor the runtime environment of the application in real time to discover potential vulnerability attacks; Adopt dynamic taint tracking algorithm and transparent object proxy method to monitor the execution context of application, track the source of variables, and determine whether the application is under attack; If it is determined that it is under attack, it uses context-aware methods and self-protection mechanisms to locate the attack code line; Highly heuristic algorithms based on attack behaviors defend against unknown vulnerability attacks; Visualize and count threat behaviors.

2. A method for detecting and defending against security risks in a power information system according to claim 1, characterized in that: The method for identifying potential component vulnerabilities in source code and binary files includes converting binary executable files, compilable source code projects, and non-compilable source code files to obtain corresponding LLVM bitcode files, using a similarity comparison algorithm to calculate a similarity measure of the vulnerable function, obtaining a similar function set of known vulnerable functions in the LLVM bitcode file, performing backward slicing on the functions in the similar function set and generating constraint derivations, performing similarity comparison with constraint derivations of known vulnerable functions, obtaining a new function similarity measure, and outputting functions with a higher similarity to the vulnerable function as potential component vulnerabilities for monitoring.

3. A method for detecting and defending against security risks in a power information system according to claim 2, characterized in that: The new function similarity metric includes selecting constrained variables, relying on data flow and control flow, slicing the instruction sequence backward with the instruction where the constrained variable is located as the starting point, and generating a constraint derivation formula. By performing a similarity comparison with the constraint derivation formula of a known vulnerable function, the similarity between functions is recalculated to obtain a new function similarity metric.

4. A method for detecting and defending against security risks in a power information system according to claim 3, characterized in that: The recalculating the similarity between functions includes implementing similarity calculation between two constraint derivations by using string edit distance calculation, and finding the best match among all constraint derivation combinations.

5. A method for detecting and defending against security risks in a power information system according to claim 4, characterized in that: The search for the best match includes calculating the similarity of two functions, and the formula is: Among them, f1 and f2 represent two different functions to be compared, sim(·) represents similarity, dist(·) represents the function of measuring differences, len(·) represents the function of calculating the length of the string, and cd i represents the i-th constraint derivation in the constraint derivation set CD, cd j Represents the set of constraint derivations CD * The j-th constraint derivation in , n, m represent the set CD, CD * The number of constraint derivations in , max(·) represents the maximum function, min(· represents the minimum function, and ln(·) represents the logarithmic function.

6. A method for detecting and defending against security risks in a power information system according to claim 5, characterized in that: The highly heuristic algorithm based on attack behavior to defend against unknown vulnerability attacks includes distinguishing normal business requests from potential attack requests by obtaining stack information, abnormal information user input and parameter information of the current function context; The unknown vulnerability attacks include 0day attacks and unknown vulnerabilities of the application itself.

7. A method for detecting and defending against security risks in a power information system according to claim 6, characterized in that: The visual statistics of threat behaviors include security checks on software configuration parameters and application hardening functions to enhance system security.

8. A system based on the power information system security risk detection and defense method according to any one of claims 1 to 7, characterized in that: It includes an identification module, a discovery module, a judgment module, a first defense module, a second defense module and a display module; The identification module, based on LSTM and optimized reorganization algorithm, identifies potential component vulnerabilities in source code and binary files; The discovery module sets hooks at key points to monitor the environment in which the application is running in real time and discover potential vulnerability attack behaviors; The judgment module uses a dynamic taint tracking algorithm and a transparent object proxy method to monitor the context of application execution and the source of tracking variables to determine whether the application is under attack; The first defense module, if it is determined to be under attack, uses context-aware methods and self-protection mechanisms to locate the attacking code line and take real-time measures to prevent the attack; The second defense module uses a high heuristic algorithm based on attack behavior to defend against unknown vulnerability attacks; The display module performs visual statistics on threat behaviors.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Defense method and system for multi-agent attack in steel production environment

    CN120710793A

  • Automatic operation and maintenance method and system based on artificial intelligence

    CN120768656A