Zero-trust power monitoring safety risk assessment system, equipment and medium
By adopting a zero-trust power monitoring security risk assessment system in the power system, and using real-time data analysis and artificial intelligence models to automatically perform risk scoring and security policy implementation, the external hacker attacks and internal security risks faced by the power system are solved, and fast response and high-reliability security protection is achieved.
Patent Information
- Application Number
- CN202510062288.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
AI Technical Summary
Power systems face external hacker attacks and internal security risks. Existing defense systems appear to be insufficient in the face of complex and persistent cyber threats, and security risk assessment is periodic and emergency response lagging.
A zero-trust power monitoring security risk assessment system is adopted to collect and analyze diverse data in real time, and a modular processing method and artificial intelligence model are used to automatically perform risk scores and comprehensive scores, and the system security status level is generated based on user history scores, and corresponding security policies are implemented.
It realizes rapid identification and response to security threats, effectively reduces internal security risks and resists external attacks, ensures the robust operation and high reliability of the power monitoring system, reduces labor costs, and provides dynamic and accurate security support.
Smart Images

Figure CN119990751A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power system risk assessment, and in particular to a zero-trust power monitoring security risk assessment system, equipment and medium. Background Art
[0002] The safe and stable operation of the power system is of fundamental importance to maintaining national security and social stability. In recent years, the power monitoring system, as the core control link of the power system, has gradually become the main target of network security threats. At present, the security of the power monitoring system mainly faces two challenges: first, external hacker attacks, especially national APT organizations use advanced network attack technologies to destroy or control power supply, directly threatening national security; second, internal risks, including operators' lack of safety awareness, operational errors and lack of ability to apply new technologies. Although there are multi-layer defense systems, such as firewalls, intrusion detection systems (IDS), security information and event management systems (SIEM), etc., in the face of complex and persistent network threats, the existing defense systems often appear to be insufficient. In addition, the periodicity of security risk assessment and the lag in emergency response also limit the effectiveness of existing protection measures, further magnifying security vulnerabilities at the management level.
[0003] In view of these challenges, it is particularly urgent to build a strong security line of defense for the power monitoring system, improve the safety literacy and skills of personnel, establish a sound security assessment and emergency response mechanism, and ensure the safe operation of the power system. In the key area of the power monitoring system, the integration of the zero-trust security model creates an unbreakable barrier for the information protection architecture of power facilities. Through a strict authorization mechanism, the model only allows fully verified individuals to access the control system, effectively reducing internal security risks and resisting external attacks. Combined with continuous monitoring and automated emergency response mechanisms, the system can quickly identify and respond to security threats, ensuring the robust operation and high reliability of the power monitoring system. Summary of the invention
[0004] The purpose of the present invention is to provide a zero-trust power monitoring security risk assessment system to address the challenges faced by the power system from external hacker attacks and internal security risks.
[0005] The system collects and analyzes various data from the power system (such as key equipment logs, network traffic information, etc.) in real time, adopts a modular processing method, integrates the scores of each module, and combines user historical scores to generate the system security status level, execute corresponding security strategies, and provide dynamic and accurate support for the security protection of the power system.
[0006] Specifically, the present invention provides a zero-trust power monitoring security risk assessment system, including:
[0007] Data collection and preprocessing module, scoring module, comprehensive scoring module, real-time monitoring and alarm module and audit and reporting module;
[0008] The data acquisition and preprocessing module is used to collect and process data from power monitoring equipment;
[0009] The scoring module performs single data scoring based on the power monitoring equipment data;
[0010] The comprehensive scoring module integrates the scores of each single data and the user's historical data;
[0011] The real-time monitoring and alarm module monitors the fusion score and implements the security policy;
[0012] The Audit and Reporting module is responsible for monitoring and recording system activities, assessing compliance, and generating reports.
[0013] A storage medium stores instructions and data for implementing a zero-trust power monitoring security risk assessment system.
[0014] A power monitoring system security protection device with a zero-trust architecture includes: a processor and a storage medium; the processor loads and executes instructions and data in the storage medium to implement a zero-trust power monitoring security risk assessment system.
[0015] The beneficial effects provided by the present invention are:
[0016] 1. The present invention improves the existing security assessment system. The security risk assessment system constructed by the present invention is real-time. Compared with traditional multi-layer defense systems such as firewalls, intrusion detection systems (IDS), security information and event management systems (SIEM), etc., the present invention combines continuous monitoring and automated emergency response mechanisms to quickly identify and respond to security threats, effectively reduce internal security risks and resist external attacks, and ensure the robust operation and high reliability of the power monitoring system.
[0017] 2. The present invention realizes automated risk assessment and automated security strategy implementation. The present invention is based on real-time collection and analysis of diverse data from the power system, adopts a modular processing method, uses an artificial intelligence model to automatically perform risk scoring and score synthesis for each module, and combines user historical scores to generate a system security status level and execute corresponding security strategies. Compared with traditional manual remote monitoring, the present invention realizes automated risk identification and automated implementation of security strategies, reduces labor costs, and provides dynamic and accurate support for the security protection of the power system.
[0018] 3. The present invention provides a user trust level update strategy. The main steps include storing user historical risk score vectors, calculating similarity and trust level update. By generating and storing user risk score vectors (using KD tree structure), recording the user's standardized scores on each risk item, and calculating the cosine similarity of the risk score vector, the abnormality of user behavior can be judged. When an anomaly is detected, the system will lower the user's trust level and issue an alert to the administrator. This method can quickly identify abnormal behavior, use historical score comparison to achieve efficient and accurate risk assessment, and combine the KD tree structure to improve data processing speed, thereby enhancing the real-time and accuracy of user behavior monitoring.
[0019] In summary, the present invention can timely identify potential security threats and take corresponding preventive measures, effectively reducing false alarms and missed alarms, and can provide a practical security solution for the power monitoring field. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a schematic diagram of the system structure of the present invention;
[0021] Figure 2 It is a working schematic diagram of the hardware device of the present invention. DETAILED DESCRIPTION
[0022] To make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be further described below with reference to the accompanying drawings.
[0023] Before formally describing the present invention, the scheme of the present invention is first generally described for easy understanding.
[0024] Please refer to Figure 1 , Figure 1 It is a schematic diagram of the system structure of the present invention.
[0025] The present invention provides a zero-trust power monitoring security risk assessment system, comprising:
[0026] Data collection and preprocessing module, scoring module, comprehensive scoring module, real-time monitoring and alarm module and audit and reporting module;
[0027] The data acquisition and preprocessing module is used to collect and process data from power monitoring equipment;
[0028] The scoring module performs single data scoring based on the power monitoring equipment data;
[0029] The comprehensive scoring module integrates the scores of each single data and the user's historical data;
[0030] The real-time monitoring and alarm module monitors the fusion score and implements the security policy;
[0031] The Audit and Reporting module is responsible for monitoring and recording system activities, assessing compliance, and generating reports.
[0032] It should be further explained that the above-mentioned data acquisition and preprocessing module collects various data generated by users in the operation of the power system in real time, and cleans, preprocesses and classifies these data to facilitate subsequent preset modular data processing.
[0033] The data acquisition and preprocessing module includes: a data acquisition unit, a data preprocessing unit, and a data classification and processing unit.
[0034] As an embodiment, the above-mentioned data collection unit collects various relevant data in real time, including but not limited to operation logs, access flow records, and system events, and provides real-time raw data for subsequent data processing.
[0035] As an embodiment, the data preprocessing unit cleans and preprocesses the collected data based on predefined rules and algorithms, removes redundant and invalid information while ensuring the accuracy and integrity of the data, and facilitates subsequent data processing. For example, the predefined rules are to delete or retain data within a specified time period, or to remove certain fields in the data, perform certain standard formatting on the data, unify the data format, etc.
[0036] As an example, the data classification and processing unit may use a simple machine learning algorithm to classify data, and process the data according to the format required by the scoring module, providing input for each subsequent module to process data separately, thereby improving system efficiency. For example, machine learning algorithms such as SVM support vector machine and random forest are used for data classification.
[0037] It should be noted that the scoring module adopts a modular design and includes multiple scoring sub-modules for different data types; each scoring sub-module performs quantitative scoring on the corresponding type of data.
[0038] Specifically, the scoring module receives data provided by the data collection and preprocessing module, quantifies the risk factors represented by various data types, and generates risk scores to facilitate subsequent comprehensive assessment and trend analysis of the overall security status of the system, timely identify potential threats and formulate corresponding protective measures.
[0039] As an example, to ensure the accuracy of risk scoring, this scoring module uses different scoring calculation formulas for different data types, as follows:
[0040] Network traffic data rating:
[0041] R network= (abnormal traffic level × number of packets) / total traffic
[0042] Among them, the abnormal traffic degree indicates the abnormal deviation degree of traffic, the number of data packets indicates the total number of data packets in a specific time period, and the total traffic indicates the normal traffic level of the network.
[0043] User behavior data scoring:
[0044] R user = (Number of abnormal logins × User activity) / Total number of logins
[0045] Among them, the number of abnormal logins indicates the number of abnormal login events of the user within a specific time range, the user activity indicates the activity frequency of the user, and the total number of logins indicates the total number of all login events of the user.
[0046] System log data scoring:
[0047] R log =(error event frequency × error severity) / total number of logs
[0048] Among them, the error event frequency indicates the number of error logs within a specific period of time, the error severity indicates the severity of the error event (such as system crash, data leakage, etc.), and the total number of logs indicates the total number of all log entries in the time period.
[0049] Scoring of other data types: In addition to the common data types mentioned above, users can define scoring formulas for other data types based on actual needs and system characteristics to flexibly adapt to the identification of specific risk factors. For example, specific scoring formulas and quantitative rules can be designed for types such as equipment status data and environmental data to more accurately reflect the risk characteristics of different data types.
[0050] The above-mentioned scoring module adopts a modular design and integrates multiple sub-modules. Each sub-module contains a scoring model for risk scoring of a specific data type. The design of the sub-module and the data types it supports are customizable.
[0051] It should be noted that the comprehensive scoring module includes: a weight distribution module and a user history scoring module.
[0052] The weight allocation module presets different weights according to different types of data and calculates the user's current risk value score; the user history scoring module is used to score the user's historical risk based on the user's historical data; finally, the user's current risk score and the user's historical score are combined to obtain the user's trustworthiness.
[0053] Specifically, the above-mentioned comprehensive scoring module combines the various data scoring values provided by the scoring module and the various data weight values provided by the weight allocation module to calculate the user's current risk value score, and then combines the user's historical risk score value provided by the user history scoring module to calculate the user's trust level, providing a basis for the subsequent dynamic generation of the user's security status level.
[0054] In the risk score calculation, the risk values of different data types will be assigned different weights according to their impact on user security. The weight values can be initially set based on expert experience and can be dynamically adjusted based on the security reports provided by the audit and reporting module.
[0055] As an example, assume that there are three main data types in the system: user behavior data, system log data, and network traffic data. The initial weights are set as follows:
[0056] User behavior data (weight: 0.4):
[0057] Since user behavior patterns (such as abnormal logins, frequent password changes, etc.) are usually important indicators for identifying potential threats, user behavior data is weighted higher.
[0058] System log data (weight: 0.3):
[0059] System logs record the operations and abnormal situations within the system, reflecting the health status of the system. Although it has a certain impact on risk assessment, its weight is lower than that of user behavior data.
[0060] Network traffic data (weight: 0.3):
[0061] Abnormal behaviors of network traffic (such as DDoS attacks, abnormal traffic surges, etc.) can quickly expose potential external threats. Therefore, network traffic data also has a high risk indicator effect, but slightly lower than user behavior data.
[0062] The weight distribution module stores the weights of each sub-scoring module in the scoring module, which can be updated by analyzing the report content. The user history scoring module stores the comprehensive scoring value of users over a period of time, which helps to identify user behavior patterns and can provide a detailed historical scoring trend analysis for the report.
[0063] It should also be noted that the user trust level in the present invention will be updated, and the specific process of the update is as follows:
[0064] S1: stores the user's historical risk score vector;
[0065] Generate a user risk score vector. The user risk score vector is defined as a vector composed of the user's scores in each scoring submodule, and the scores have been standardized; record the user's risk scores in different time periods to form a user history score vector;
[0066] Store the user's historical score vector; use the KD tree structure, initialize the KD tree, and store the user's historical risk score as a node in the tree;
[0067] S2: Calculate the risk score vector similarity;
[0068] The risk score vector similarity is defined as the cosine similarity of the vector, vector v1 = (a1, a2, ..., a n ) and vector v2=(a1,a2,…,a n ) is calculated as follows:
[0069]
[0070] in
[0071] When the user's risk score vector is updated, the similarity between the new vector and the nodes in the KD tree is compared. If the similarity result is within the preset threshold, the user's behavior in the current time period is considered normal, otherwise it is considered abnormal;
[0072] S3: Record and trust level update; when an abnormality is detected in the currently recorded user risk score vector, the user's trust level is reduced by one level, an alert is sent to the administrator, and this operation is recorded; then the vector is deleted from the user's historical risk score vector record.
[0073] It should be noted that the real-time monitoring and alarm module includes a user trust level generation unit and a security policy real-time unit; the user trust level generation unit divides users into different trust levels according to their trustworthiness; the security policy real-time unit allocates different access rights based on user levels.
[0074] As an embodiment, the user trust level generation unit divides the user's trust level into four levels: trusted, risky, serious risk, and untrustworthy, which can be dynamically adjusted according to the user's current trust level.
[0075] The security policy implementation unit automatically applies different security policies based on the user's trust and the preset trust level interval. For high-trust users, the unit will provide a more convenient service experience, such as advanced access rights and reduced security checks; while for risky and untrustworthy users, the unit will gradually increase security control efforts, from reminders, enhanced checks to restricted functions, and even completely prohibiting access in the most extreme cases, while triggering a more stringent security review process.
[0076] Finally, the audit and reporting module is responsible for monitoring and recording system activities, evaluating compliance, generating reports, and issuing alerts when anomalies are found, supporting the security management of the system and the weight allocation of each scoring sub-module.
[0077] See also Figure 2 , Figure 2 It is a working diagram of the hardware device of an embodiment of the present invention, and the hardware device specifically includes: a power monitoring system security protection device 401 with a zero-trust architecture, a processor 402 and a storage medium 403.
[0078] A power monitoring system security protection device 401 with a zero-trust architecture: The power monitoring system security protection device 401 with a zero-trust architecture implements the zero-trust power monitoring security risk assessment system.
[0079] Processor 402: The processor 402 loads and executes instructions and data in the storage medium 403 to implement the zero-trust power monitoring security risk assessment system.
[0080] Storage medium 403: The storage medium 403 stores instructions and data; the storage medium 403 is used to implement the zero-trust power monitoring security risk assessment system.
[0081] The beneficial effects of the present invention are:
[0082] 1. The present invention improves the existing security assessment system. The security risk assessment system constructed by the present invention is real-time. Compared with traditional multi-layer defense systems such as firewalls, intrusion detection systems (IDS), security information and event management systems (SIEM), etc., the present invention combines continuous monitoring and automated emergency response mechanisms to quickly identify and respond to security threats, effectively reduce internal security risks and resist external attacks, and ensure the robust operation and high reliability of the power monitoring system.
[0083] 2. The present invention realizes automated risk assessment and automated security strategy implementation. The present invention is based on real-time collection and analysis of diverse data from the power system, adopts a modular processing method, uses an artificial intelligence model to automatically perform risk scoring and score synthesis for each module, and combines user historical scores to generate a system security status level and execute corresponding security strategies. Compared with traditional manual remote monitoring, the present invention realizes automated risk identification and automated implementation of security strategies, reduces labor costs, and provides dynamic and accurate support for the security protection of the power system.
[0084] 3. The present invention provides a user trust level update strategy. The main steps include storing user historical risk score vectors, calculating similarity and trust level update. By generating and storing user risk score vectors (using KD tree structure), recording the user's standardized scores on each risk item, and calculating the cosine similarity of the risk score vector, the abnormality of user behavior can be judged. When an anomaly is detected, the system will lower the user's trust level and issue an alert to the administrator. This method can quickly identify abnormal behavior, use historical score comparison to achieve efficient and accurate risk assessment, and combine the KD tree structure to improve data processing speed, thereby enhancing the real-time and accuracy of user behavior monitoring.
[0085] In summary, the present invention can timely identify potential security threats and take corresponding preventive measures, effectively reducing false alarms and missed alarms, and can provide a practical security solution for the power monitoring field.
[0086] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A zero-trust power monitoring security risk assessment system, characterized by: include: Data collection and preprocessing module, scoring module, comprehensive scoring module, real-time monitoring and alarm module and audit and reporting module; The data acquisition and preprocessing module is used to collect and process data from power monitoring equipment; The scoring module performs single data scoring based on the power monitoring equipment data; The comprehensive scoring module integrates the scores of each single data and the user's historical data; The real-time monitoring and alarm module monitors the fusion score and implements the security policy; The Audit and Reporting module is responsible for monitoring and recording system activities, assessing compliance, and generating reports.
2. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The data acquisition and preprocessing module includes: a data acquisition unit, a data preprocessing unit, and a data classification and processing unit.
3. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The data collection unit collects data including: operation logs, access traffic and system events; the data preprocessing unit cleans and standardizes the data based on preset rules; the data classification and processing unit uses a machine learning model to classify the preprocessed data.
4. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The scoring module adopts a modular design and includes multiple scoring submodules for different data types; each scoring submodule performs quantitative scoring on the corresponding type of data.
5. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The comprehensive scoring module includes: a weight allocation module and a user history scoring module.
6. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The weight allocation module presets different weights according to different types of data and calculates the user's current risk value score; The user history scoring module is used to score the user's historical risk based on the user's historical data; finally, the user's current risk score and the user's historical score are combined to obtain the user's trustworthiness.
7. A zero-trust power monitoring security risk assessment system as claimed in claim 1, characterized in that: The real-time monitoring and alarm module includes a user trust level generation unit and a security policy real-time unit; The user trust level generation unit divides users into different trust levels according to the user trust level; The security policy real-time unit assigns different access rights based on user level.
8. A zero-trust power monitoring security risk assessment system as claimed in claim 6, characterized in that: The process of updating user trust is as follows: S1: stores the user's historical risk score vector; Generate a user risk score vector. The user risk score vector is defined as a vector composed of the user's scores in each scoring submodule, and the scores have been standardized; Record the risk scores of users in different time periods to form a user history score vector; Store the user's historical score vector; use the KD tree structure, initialize the KD tree, and store the user's historical risk score as a node in the tree; S2: Calculate the risk score vector similarity; The risk score vector similarity is defined as the cosine similarity of the vector, vector v1 = (a1, a2, ..., a n ) and vector v2=(a1,a2,…,a n ) is calculated as follows: in When the user's risk score vector is updated, the similarity between the new vector and the nodes in the KD tree is compared. If the similarity result is within the preset threshold, the user's behavior in the current time period is considered normal, otherwise it is considered abnormal; S3: Record and trust level update; when an abnormality is detected in the currently recorded user risk score vector, the user's trust level is reduced by one level, an alert is sent to the administrator, and this operation is recorded; then the vector is deleted from the user's historical risk score vector record.
9. A storage medium, characterized in that: The storage medium stores instructions and data for implementing a zero-trust power monitoring security risk assessment system as described in any one of claims 1 to 8.
10. A zero-trust architecture power monitoring system security protection device, characterized by: include: Processor and storage medium; the processor loads and executes instructions and data in the storage medium to implement a zero-trust power monitoring security risk assessment system as described in any one of claims 1 to 8.