Network security protection method for thermal power core control area and related equipment
By obtaining and analyzing the full traffic data of the DCS system of the thermal power unit, detecting attack behaviors, and building a network security behavior handling rule database, the problem of numerous operating systems in the existing technology cannot be managed uniformly, and efficient network security protection and unified management are achieved.
Patent Information
- Application Number
- CN202411927553.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-13
AI Technical Summary
In the prior art, there are many operating systems for the DCS system of thermal power sets, which cannot be managed in a unified manner, affecting the efficiency of security protection work.
By obtaining the full flow data of the control system of the target thermal power unit, conducting security sense analysis, detecting attack behaviors, and auditing the log information, a network security behavior handling rule database is built, and the network in the core control area of the thermal power is protected based on this rule database.
The problem of repeated acquisition of network mirror traffic in the DCS system of the thermal power unit was effectively solved, and the network security situation awareness analysis results and network abnormal behavior analysis results were simultaneously generated, which realized the integrated analysis of network security situation awareness results and existing security protection system results, and formed a network behavior rule library built by AI technology + expert system integration learning, which improved the efficiency and unified management capabilities of network security protection.
Smart Images

Figure CN119995928A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a network security protection method and related equipment for a core control area of a thermal power plant. Background Art
[0002] The DCS of thermal power units belongs to the core industrial control system and is an information system related to the national economy and people's livelihood. Most industrial control systems are key information infrastructure. With the promulgation of the National Cybersecurity Law, clear requirements have been given for the network security of industrial control systems. The existing industrial control network security protection system in China is in a steady development stage. The deep integration of industrial control systems with the Internet of Things and the Internet has brought new security challenges. With the development of information technology, there is currently a lack of technical applications that combine the deep integration of AI technology. The industrial control network security protection system will pay more attention to comprehensive protection strategies, including physical security, network isolation, access control and other measures. In view of the differences in systems and functions of various security manufacturers, there is a lack of mutual integration between various systems. For example, there is a lack of coupling between the thermal power situation awareness system and the thermal power industrial control security protection system, resulting in a large number of operating systems that cannot be managed in a unified manner, affecting the efficiency of security protection work. Summary of the invention
[0003] Based on this, it is necessary to propose a network security protection method and related equipment for the core control area of thermal power plants in order to address the technical problems that the existing operating systems are numerous and cannot be managed in a unified manner, which affects the efficiency of security protection work.
[0004] In a first aspect, a network security protection method for a core control area of a thermal power plant is provided, the method comprising:
[0005] Acquire full flow data of the control system of the target thermal power unit, and perform safety state analysis on the full flow data to obtain abnormal behavior of the control system;
[0006] Detecting the full flow data according to a preset rule base to determine attack behaviors against the control system;
[0007] Obtaining log information of a control system for the target thermal power unit, and auditing the log information to obtain security data of the control system;
[0008] A network security behavior handling rule base is constructed according to the abnormal behavior, the attack behavior and the security data, and security protection is performed on the network of the core control area of the thermal power plant based on the network security behavior handling rule base.
[0009] Optionally, the step of acquiring full flow data of the control system for the target thermal power unit includes:
[0010] The mirrored flow of the control system for the target thermal power unit is obtained, and the mirrored flow is used as the full flow data of the control system for the target thermal power unit.
[0011] Optionally, the step of performing safety state analysis on the full flow data to obtain abnormal behavior of the control system further includes:
[0012] Perform security state analysis on the full traffic data according to the flink computing framework and the spark data analysis engine to obtain security situation information;
[0013] Abnormal behavior of the control system is determined based on the security situation information.
[0014] Optionally, the step of detecting the full flow data according to a preset rule base to determine the attack behavior against the control system includes:
[0015] Using a protocol identification algorithm to divide the full traffic data into a first type of database protocol traffic and a second type of HTTP protocol traffic;
[0016] Based on the detection rules corresponding to the database protocol traffic in the preset rule base, determining whether the database protocol traffic contains attack behavior; wherein the detection rules are set according to the attack characteristics corresponding to the database type;
[0017] Based on the detection rules corresponding to the HTTP protocol traffic in the preset rule base, it is determined whether the HTTP protocol traffic has attack behavior; wherein the HTTP protocol traffic detection rules are set according to the attack words of the HTTP protocol.
[0018] Optionally, the step of auditing the log information to obtain the security data of the control system includes:
[0019] Auditing the log information to determine abnormal events in the log information that violate security policies, wherein the abnormal events include security authentication failure events, compliance check failure events, and content check failure events;
[0020] Safety data of the control system is generated according to the abnormal event.
[0021] Optionally, the method further includes:
[0022] Obtaining operation and maintenance instructions for performing operation and maintenance operations on the control system;
[0023] Using strong identity authentication means to verify the identity information in the operation and maintenance instruction to obtain a verification result;
[0024] And based on the verification result, determine whether to execute the operation and maintenance operation corresponding to the operation and maintenance instruction.
[0025] Optionally, the step of building a network security behavior disposal rule base according to the abnormal behavior, the attack behavior and the security data, and performing security protection on the network of the thermal power core control area based on the network security behavior disposal rule base includes:
[0026] Extracting feature codes of the abnormal behavior, the attack behavior and the security data from different dimensions to obtain different types of feature code sets;
[0027] Synthesizing different security rules according to the feature code set and the preset threshold value to generate an initial security rule base;
[0028] Displaying the initial security rule base and obtaining user request information for the initial security rule base;
[0029] Obtaining the authority information of the user request information, and if the authority information is higher than the preset authority level, updating the initial security rule base based on the user request information to obtain a network security behavior disposal rule base;
[0030] According to the network security behavior handling rule base, the RETE algorithm is used to perform security protection on the network of the core control area of the thermal power plant.
[0031] On the other hand, the present application provides a network security protection device for a core control area of a thermal power plant, the device comprising:
[0032] A data acquisition module is used to obtain full flow data of the control system of the target thermal power unit, and perform safety state analysis on the full flow data to obtain abnormal behavior of the control system;
[0033] An attack determination module, used to detect the full flow data according to a preset rule base to determine attack behaviors against the control system;
[0034] An audit module, used to obtain log information of the control system of the target thermal power unit, and audit the log information to obtain security data of the control system;
[0035] The protection module is used to build a network security behavior processing rule base according to the abnormal behavior, the attack behavior and the security data, and to perform security protection on the network of the thermal power core control area based on the network security behavior processing rule base.
[0036] In a third aspect, a computer device for controlling a line voltage regulator is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the network security protection method for the core control area of a thermal power plant as described above are implemented.
[0037] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the network security protection method for the core control area of a thermal power plant are implemented.
[0038] This application obtains the full flow data of the control system for the target thermal power unit, and performs a security state analysis on the full flow data to obtain the abnormal behavior of the control system; detects the full flow data according to the preset rule base to determine the attack behavior against the control system; obtains the log information of the control system for the target thermal power unit, and audits the log information to obtain the security data of the control system; builds a network security behavior disposal rule base based on the abnormal behavior, the attack behavior and the security data, and performs security protection on the network of the core control area of the thermal power based on the network security behavior disposal rule base. Introduce single-channel traffic replication, integrate the mirror traffic data analysis of the existing situational awareness and industrial control intrusion detection system, effectively solve the repeated collection of network mirror traffic of the DCS system of the thermal power unit, and simultaneously generate network security situation awareness analysis results and network abnormal behavior analysis results; introduce a network security management and control platform, and realize the fusion analysis of network security situation awareness results and existing security protection system results based on the analysis results of the mirror traffic; form a network behavior rule base constructed by the fusion learning of AI technology + expert system. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0040] in:
[0041] Figure 1 Flow chart of a network security protection method for a core control area of a thermal power plant in one embodiment;
[0042] Figure 2 It is a schematic diagram of the operation of a network security protection method for a core control area of a thermal power plant in one embodiment;
[0043] Figure 3A structural block diagram of a network security protection system for a core control area of a thermal power plant in one embodiment;
[0044] Figure 4 A structural block diagram of a network security protection device for a core control area of a thermal power plant in one embodiment;
[0045] Figure 5 is a structural block diagram of a computer device in one embodiment;
[0046] Figure 6 It is a structural block diagram of a computer device in another embodiment. DETAILED DESCRIPTION
[0047] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0048] The present invention is described in detail below through specific embodiments.
[0049] See also Figure 1 As shown, Figure 1 A schematic flow chart of a network security protection method for a thermal power core control area provided by an embodiment of the present invention includes the following steps:
[0050] S101, acquiring full flow data of a control system for a target thermal power unit, and performing a safety state analysis on the full flow data to obtain abnormal behavior of the control system;
[0051] In a possible implementation manner, the step of acquiring full flow data of a control system for a target thermal power unit includes:
[0052] The mirrored flow of the control system for the target thermal power unit is obtained, and the mirrored flow is used as the full flow data of the control system for the target thermal power unit.
[0053] S102, detecting the full flow data according to a preset rule base to determine attack behaviors against the control system;
[0054] S103, obtaining log information of the control system of the target thermal power unit, and auditing the log information to obtain security data of the control system;
[0055] S104: construct a network security behavior handling rule base according to the abnormal behavior, the attack behavior and the security data, and perform security protection on the network of the thermal power core control area based on the network security behavior handling rule base.
[0056] Exemplarily, physical or isolation of the mirror network and the business network is achieved, and a network security management and control platform is used to uniformly manage the mirror network and the business network. The mirror network collects the entire network traffic through the industrial control security full-traffic collection system. The industrial control security state analysis system generates a network security situation awareness behavior analysis report based on the mirror traffic, deploys an intrusion monitoring system, and performs active network behavior defense for the entire business traffic. The business network deploys a security log audit system, a security operation and maintenance audit system, a host security protection system, and peripheral protection devices to protect the business network and ensure the stable and secure operation of the business network. The network security management and control platform adopts a model that integrates intelligence and expert systems to generate a network behavior rule library to achieve integrated management and control of network security devices and network security behaviors in the core control area network.
[0057] By acquiring the full flow data of the control system for the target thermal power unit and performing a security state analysis on the full flow data, the abnormal behavior of the control system is obtained; the full flow data is detected according to the preset rule base to determine the attack behavior against the control system; the log information of the control system for the target thermal power unit is obtained, and the log information is audited to obtain the security data of the control system; a network security behavior disposal rule base is constructed according to the abnormal behavior, the attack behavior and the security data, and the network of the core control area of the thermal power is protected based on the network security behavior disposal rule base. Introduce single-channel traffic replication, integrate the existing situational awareness and industrial control intrusion detection system's mirror traffic data analysis, effectively solve the repeated collection of network mirror traffic of the DCS system of the thermal power unit, and simultaneously generate network security situation awareness analysis results and network abnormal behavior analysis results; introduce a network security management and control platform, and realize the fusion analysis of network security situation awareness results and existing security protection system results based on the analysis results of the mirror traffic; form a network behavior rule base constructed by AI technology + expert system fusion learning.
[0058] In a possible implementation manner, the step of performing a safety state analysis on the full flow data to obtain abnormal behavior of the control system further includes:
[0059] Perform security state analysis on the full traffic data according to the flink computing framework and the spark data analysis engine to obtain security situation information;
[0060] Abnormal behavior of the control system is determined based on the security situation information.
[0061] Exemplarily, data is collected through the Flume data collection engine, and the collected traffic, logs, equipment operation status and other related security data are pushed to the Kafka message queue system and access service through the Syslog transmission protocol or the UDP transmission protocol. The security data is sent to the data layer. The data layer parses and processes the data through the Flink computing framework, the Spark data analysis engine and the background service to obtain security situation information and store it in the database.
[0062] In a possible implementation manner, the step of detecting the full flow data according to a preset rule base to determine the attack behavior against the control system includes:
[0063] Using a protocol identification algorithm to divide the full traffic data into a first type of database protocol traffic and a second type of HTTP protocol traffic;
[0064] Based on the detection rules corresponding to the database protocol traffic in the preset rule base, determining whether the database protocol traffic contains attack behavior; wherein the detection rules are set according to the attack characteristics corresponding to the database type;
[0065] Based on the detection rules corresponding to the HTTP protocol traffic in the preset rule base, it is determined whether the HTTP protocol traffic has attack behavior; wherein the HTTP protocol traffic detection rules are set according to the attack words of the HTTP protocol.
[0066] Exemplarily, for database protocol traffic, the corresponding detection rules can be selected based on the database type to which the database protocol traffic belongs to analyze the database protocol traffic, so as to determine whether there is attack behavior in the database protocol traffic. For HTTP protocol traffic, it can be determined based on the HTTP protocol traffic detection rules whether there is attack behavior in the HTTP protocol traffic. In an embodiment of the present application, network traffic is divided based on protocol type, and an appropriate detection method is adopted for network traffic of different protocol types, and matching detection rules are set based on different database types, thereby achieving comprehensive detection of attack behaviors and improving the detection rate of attack behaviors. By making detailed divisions of detection rules to make them more targeted, the accuracy of attack behavior detection is improved.
[0067] In a possible implementation, the step of auditing the log information to obtain the security data of the control system includes:
[0068] Auditing the log information to determine abnormal events in the log information that violate security policies, wherein the abnormal events include security authentication failure events, compliance check failure events, and content check failure events;
[0069] Safety data of the control system is generated according to the abnormal event.
[0070] Exemplarily, the security gateway system detects any abnormal events and data packets that violate security policies, including failure of security authentication, failure of compliance check, and failure of content check, blocks the communication operation, and issues an alarm message through screen display, mobile phone text message, and email. At the same time, the detailed information of the abnormal event is recorded in the log file for future query, audit, and tracing.
[0071] In a possible implementation, the method further includes:
[0072] Obtaining operation and maintenance instructions for performing operation and maintenance operations on the control system;
[0073] Using strong identity authentication means to verify the identity information in the operation and maintenance instruction to obtain a verification result;
[0074] And based on the verification result, determine whether to execute the operation and maintenance operation corresponding to the operation and maintenance instruction.
[0075] For example, the daily operation and maintenance, upgrade and other operations of the control system are difficult to monitor, and the operation and maintenance operations need to be controlled and audited. The operation and maintenance audit uniformly manages operations such as user (Account) management, authorization (Authorization) management, authentication (Authentication) management and comprehensive audit (Audit). The operation and maintenance audit technology can implement strict resource access policies for DCS system assets and use strong identity authentication methods to fully protect the security of system resources.
[0076] In a possible implementation manner, the step of building a network security behavior disposal rule base according to the abnormal behavior, the attack behavior and the security data, and performing security protection on the network of the thermal power core control area based on the network security behavior disposal rule base includes:
[0077] Extracting feature codes of the abnormal behavior, the attack behavior and the security data from different dimensions to obtain different types of feature code sets;
[0078] Synthesizing different security rules according to the feature code set and the preset threshold value to generate an initial security rule base;
[0079] Displaying the initial security rule base and obtaining user request information for the initial security rule base;
[0080] Obtaining the authority information of the user request information, and if the authority information is higher than the preset authority level, updating the initial security rule base based on the user request information to obtain a network security behavior disposal rule base;
[0081] According to the network security behavior handling rule base, the RETE algorithm is used to perform security protection on the network of the core control area of the thermal power plant.
[0082] Exemplarily, a model combining intelligence and expert system is adopted to generate a network behavior rule library, making the network behavior rule library more flexible and more in line with actual needs.
[0083] In a possible implementation, Figure 2-Figure 3 As shown, a network security protection system for a core control area of a thermal power plant includes: a mirror network protection subsystem, which realizes the behavior protection function of a passive monitoring and active defense linkage mode by introducing mirror traffic, combines internal and external network mirror traffic analysis and monitoring, realizes network security situation awareness behavior results through passive monitoring of network behavior, and adopts an active defense mode to monitor network abnormal behavior in the DCS core control area of the thermal power unit to prevent network attacks from within the DCS core control area of the thermal power unit.
[0084] The mirror network subsystem consists of an industrial control security traffic collection system, an industrial control security state analysis system, and an intrusion detection system.
[0085] The industrial control safety full-flow collection system collects the full flow of the DCS networking switches of the DCS main control and auxiliary control systems of the thermal power units. The full-flow data is transmitted to the industrial control safety state analysis system and the intrusion detection system through the network respectively. The full-flow collection does not affect the data transmission of the business network.
[0086] The industrial control safety state analysis system analyzes the full flow of the DCS main control and auxiliary control systems of the thermal power unit, monitors abnormal behavior in the internal network flow, and uploads the monitoring results to the network security management and control subsystem through the network.
[0087] The intrusion detection system is deployed on the network switch of the mirror network subsystem. It monitors and analyzes real-time network traffic, abnormal network attack behaviors and malicious codes, and detects and restricts network attack behaviors initiated from within the DCS in combination with the current rule base. The attack behavior disposal records are uploaded to the network security control subsystem through the network.
[0088] The business network security protection subsystem realizes the protection function of the business operation network of the DCS core control area of the thermal power unit by introducing log and operation and maintenance audit, host security system and peripheral management function modules, performs identity backup and audit entry backup for users, performs trusted verification of application execution, and implements integrity verification for data and storage, ensuring the safe, stable and reliable operation of the business network.
[0089] The log audit system is deployed in the business network security protection subsystem. It comprehensively collects logs (including operation, alarm, operation, message, status, etc.) generated by common security equipment, network equipment, database, server, application system, host and other equipment in the business system of thermal power units, and stores, audits and analyzes them to identify and discover potential security incidents and security risks.
[0090] The security operation and maintenance audit system is deployed in the business network security protection subsystem. The daily operation and maintenance, upgrade and other operations of the power plant production control system are difficult to monitor. It is necessary to control and audit the operation and maintenance operations. The operation and maintenance audit uniformly manages operations such as user (Account) management, authorization (Authorization) management, authentication (Authentication) management and comprehensive audit (Audit). The operation and maintenance operation audit technology can implement strict resource access policies for DCS system assets and use strong identity authentication methods to fully protect the security of system resources.
[0091] Peripheral protection device, deployed in the core business area network of the DCS of thermal power units, customized independent hardware plus heterogeneous system, can protect against new USB advanced attacks (USB bomb, BadUSB, LNK attack, blue screen of death, etc.
[0092] The host security protection system is deployed inside the DCS core business host of the thermal power unit. It introduces a whitelist protection mechanism, supports the automatic release of the trusted process whitelist execution strategy, and the trusted process subprocess can inherit permissions; it adopts a two-factor authentication method, supports USBKey+password for two-factor identity authentication, and can complete three-in-one binding based on USBKey, host, and operating system user; it supports sending logs to a unified security management platform for centralized management.
[0093] The network security management and control subsystem uses multiple security verification methods such as strong passwords and identity authentication to realize the control of the network security system, introduces a network security management and control platform, collects the result behavior data of the communication network mirror protection subsystem and the business network security protection subsystem, and uses AI and expert systems to realize automatic learning of network result behavior for the result behavior data in the network, generates a network security behavior disposal rule library, and uniformly manages the security equipment and security systems distributed in the bypass network, centrally monitors the operating status of the business operation main system equipment, and performs statistical analysis on the audit data of the equipment.
[0094] The network security management and control platform is connected to the mirror network protection subsystem and the business network protection subsystem respectively, and supports the access management of security products such as the industrial control security situation analysis system, the industrial control security traffic collection system, the log audit system, the security operation and maintenance audit system, and the host protection software. It adopts the AI+expert system combination model to realize the update of the rule policy library. For abnormal intrusion network behaviors that are not automatically handled, manual operations can be performed on the network security management and control platform. The log information of all security devices is collected, and the operating status of each network security device is monitored in real time based on the log information.
[0095] On the other hand, Figure 4 As shown, the present application provides a network security protection device for a core control area of a thermal power plant, the device comprising:
[0096] The data acquisition module 201 is used to obtain the full flow data of the control system of the target thermal power unit, and perform safety state analysis on the full flow data to obtain the abnormal behavior of the control system;
[0097] An attack determination module 202, configured to detect the full flow data according to a preset rule base and determine an attack behavior against the control system;
[0098] Audit module 203, used to obtain log information of the control system of the target thermal power unit, and audit the log information to obtain security data of the control system;
[0099] The protection module 204 is used to build a network security behavior processing rule base according to the abnormal behavior, the attack behavior and the security data, and to perform security protection on the network of the thermal power core control area based on the network security behavior processing rule base.
[0100] In one embodiment, a computer device for controlling a line voltage regulator is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 5As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the service side of a network security protection method for a thermal power core control area.
[0101] In one embodiment, a computer device for controlling a line voltage regulator is provided. The computer device may be a client, and its internal structure diagram may be as shown in FIG. Figure 6 As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a network security protection method for a thermal power core control area.
[0102] In one embodiment, an electronic device for controlling a line voltage regulator is proposed, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the following steps when executing the computer program: obtaining full flow data of a control system for a target thermal power unit, and performing a security state analysis on the full flow data to obtain abnormal behavior of the control system; detecting the full flow data according to a preset rule base to determine attack behavior against the control system; obtaining log information of the control system for the target thermal power unit, and auditing the log information to obtain security data of the control system; constructing a network security behavior disposal rule base according to the abnormal behavior, the attack behavior, and the security data, and performing security protection on the network of the thermal power core control area based on the network security behavior disposal rule base.
[0103] In one embodiment, a computer-readable storage medium is proposed, which stores a computer program. When the computer program is executed by a processor, the following steps are implemented: obtaining full flow data of a control system for a target thermal power unit, and performing a security state analysis on the full flow data to obtain abnormal behavior of the control system; detecting the full flow data according to a preset rule base to determine attack behavior against the control system; obtaining log information of the control system for the target thermal power unit, and auditing the log information to obtain security data of the control system; constructing a network security behavior disposal rule base according to the abnormal behavior, the attack behavior and the security data, and performing security protection on the network of the thermal power core control area based on the network security behavior disposal rule base.
[0104] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can refer to the relevant descriptions on the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0105] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0106] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0107] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A network security protection method for a thermal power core control area, characterized in that: The method comprises: Acquire full flow data of the control system of the target thermal power unit, and perform safety state analysis on the full flow data to obtain abnormal behavior of the control system; Detecting the full flow data according to a preset rule base to determine attack behaviors against the control system; Obtaining log information of a control system for the target thermal power unit, and auditing the log information to obtain security data of the control system; A network security behavior handling rule base is constructed according to the abnormal behavior, the attack behavior and the security data, and security protection is performed on the network of the core control area of the thermal power plant based on the network security behavior handling rule base.
2. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The step of obtaining full flow data of the control system for the target thermal power unit includes: The mirrored flow of the control system for the target thermal power unit is obtained, and the mirrored flow is used as the full flow data of the control system for the target thermal power unit.
3. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The step of performing safety state analysis on the full flow data to obtain abnormal behavior of the control system also includes: Perform security state analysis on the full traffic data according to the flink computing framework and the spark data analysis engine to obtain security situation information; Abnormal behavior of the control system is determined based on the security situation information.
4. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The step of detecting the full flow data according to a preset rule base to determine the attack behavior against the control system includes: Using a protocol identification algorithm to divide the full traffic data into a first type of database protocol traffic and a second type of HTTP protocol traffic; Based on the detection rules corresponding to the database protocol traffic in the preset rule base, determining whether the database protocol traffic contains attack behavior; wherein the detection rules are set according to the attack characteristics corresponding to the database type; Based on the detection rules corresponding to the HTTP protocol traffic in the preset rule base, it is determined whether the HTTP protocol traffic has attack behavior; wherein the HTTP protocol traffic detection rules are set according to the attack words of the HTTP protocol.
5. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The step of auditing the log information to obtain the security data of the control system includes: Auditing the log information to determine abnormal events in the log information that violate security policies, wherein the abnormal events include security authentication failure events, compliance check failure events, and content check failure events; Safety data of the control system is generated according to the abnormal event.
6. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The method further comprises: Obtaining operation and maintenance instructions for performing operation and maintenance operations on the control system; Using strong identity authentication means to verify the identity information in the operation and maintenance instruction to obtain a verification result; And based on the verification result, determine whether to execute the operation and maintenance operation corresponding to the operation and maintenance instruction.
7. The network security protection method for the core control area of a thermal power plant according to claim 1 is characterized in that: The step of building a network security behavior disposal rule base according to the abnormal behavior, the attack behavior and the security data, and performing security protection on the network of the thermal power core control area based on the network security behavior disposal rule base includes: Extracting feature codes of the abnormal behavior, the attack behavior and the security data from different dimensions to obtain different types of feature code sets; Synthesizing different security rules according to the feature code set and the preset threshold value to generate an initial security rule base; Displaying the initial security rule base and obtaining user request information for the initial security rule base; Obtaining the authority information of the user request information, and if the authority information is higher than the preset authority level, updating the initial security rule base based on the user request information to obtain a network security behavior disposal rule base; According to the network security behavior handling rule base, the RETE algorithm is used to perform security protection on the network of the core control area of the thermal power plant.
8. A network security protection device for a core control area of a thermal power plant, characterized in that: The device comprises: A data acquisition module is used to obtain full flow data of the control system of the target thermal power unit, and perform safety state analysis on the full flow data to obtain abnormal behavior of the control system; An attack determination module, used to detect the full flow data according to a preset rule base to determine the attack behavior against the control system; An audit module, used to obtain log information of the control system of the target thermal power unit, and audit the log information to obtain security data of the control system; The protection module is used to build a network security behavior processing rule base according to the abnormal behavior, the attack behavior and the security data, and to perform security protection on the network of the thermal power core control area based on the network security behavior processing rule base.
9. A computer device for controlling a line voltage regulator, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the network security protection method for the core control area of a thermal power plant as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the network security protection method for the core control area of a thermal power plant as described in any one of claims 1 to 7 are implemented.