Power business data security capability dynamic scheduling analysis method and system

By collecting, preprocessing and feature extraction of power system business data, establishing anomaly detection model using hierarchical analysis method and neural networks, and dynamically mobilizing security resources, it solves the problem that traditional static protection measures are difficult to deal with dynamic security threats, and achieves efficient and flexible network security protection.

CN120017314APending Publication Date: 2025-05-16STATE GRID FUJIAN ELECTRIC POWER CO LTD +3
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510003148.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional static data security protection measures are difficult to meet the dynamic security needs, especially in smart grid environments, facing complex network environments and diversified security threats.

Method used

A dynamic scheduling analysis method for data security capabilities of power services is proposed. By collecting, pre-processing and feature extraction of network user traffic abnormal data and network security parameters in power system business data, weight allocation is performed based on hierarchical analysis method, using neural network to establish an abnormality detection model, identify potential network security threats in real time, and dynamically mobilize security resources.

Benefits of technology

Real-time monitoring and effective response to potential network security threats in the power system is achieved, the accuracy of threat identification is improved, and the protection strategy is flexibly adjusted according to the threat level by dynamically scheduling security resources, which improves the flexibility of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017314A_ABST
    Figure CN120017314A_ABST
Patent Text Reader

Abstract

The invention relates to a power business data security capability dynamic scheduling analysis method and system, and the method comprises the steps: collecting network user flow abnormal data and network security parameters in power system business data in real time, and carrying out the preprocessing and feature extraction of the user flow abnormal data and the network security parameters; carrying out weight distribution on the extracted features based on an analytic hierarchy process to obtain the weight of each feature; based on the extracted features and the weight of each feature, establishing an anomaly detection model by using a neural network; and inputting user traffic abnormal data and network security parameters which are acquired in real time into the abnormal detection model, performing dynamic monitoring, identifying potential network security threats, and dynamically transferring security resources. According to the invention, potential network security threats can be found and dealt with in time; an anomaly detection model is established based on an analytic hierarchy process and a neural network, and the accuracy of threat identification is improved. By dynamically scheduling the security resources, the protection strategy is flexibly adjusted according to the threat level, and the flexibility of security protection is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of power system information security, and in particular relates to a method and system for dynamic scheduling and analysis of power business data security capabilities. Background Art

[0002] Power business data refers to various data information related to the operation, management and decision-making of the power system. Power business data plays an important role in operation management, intelligent scheduling, fault diagnosis, etc., which helps to improve the reliability, efficiency and safety of the power system, and supports the integrated application of clean energy and the construction of intelligent power systems.

[0003] With the rapid development of smart grids, new power systems are facing increasingly complex network environments and diverse security threats. Traditional static data security protection measures can no longer meet the dynamically changing security needs. Therefore, it is particularly important to develop a solution that can identify abnormal network behavior in real time and dynamically adjust data security protection strategies according to network status. Summary of the invention

[0004] In view of this, the purpose of the present invention is to propose a method and system for dynamic scheduling and analysis of power business data security capabilities, so as to solve the problem that traditional static data security protection measures are difficult to meet dynamically changing security needs.

[0005] Based on the above objectives, in a first aspect, the present invention provides a method for dynamic scheduling and analysis of power business data security capabilities, comprising:

[0006] Collect network user traffic anomaly data and network security parameters in the power system business data to obtain network user traffic anomaly data and network security parameters;

[0007] Preprocessing the obtained abnormal network user traffic data and the network security parameters, performing feature extraction on the preprocessed abnormal network user traffic data and the network security parameters, and obtaining extracted feature results;

[0008] Based on the hierarchical analysis method, weights are assigned to the extracted feature results to obtain weights of designated features;

[0009] Establishing an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features;

[0010] The network user traffic anomaly data and the network security parameters collected in real time are input into the anomaly detection model for dynamic monitoring, to identify potential network security threats to the power system, and to dynamically mobilize security resources.

[0011] As a preferred solution of the dynamic scheduling analysis method for power business data security capability, the network user traffic abnormality data includes at least one of user IP path abnormality data, IP traffic abnormality data, high-risk port scanning data and business access relationship abnormality data;

[0012] Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

[0013] As a preferred solution of the dynamic scheduling analysis method for power business data security capability, the network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk;

[0014] Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network;

[0015] Obtain the data network congestion risk through the SNMP protocol.

[0016] As a preferred solution of the dynamic scheduling analysis method for power business data security capability, the weight distribution of the extracted feature results based on the hierarchical analysis method to obtain the weight of the specified feature includes:

[0017] Determine the weight of each designated feature as the target layer, divide IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute a criterion layer;

[0018] Comparing the importance of the specified factors in the criterion layer in pairs, scoring them using a 1-9 scale according to the comparison results, and obtaining an average score for each comparison pair;

[0019] According to the average score of each comparison pair, an N*N comparison matrix is ​​constructed, where N is the number of criterion layer factors. The comparison matrix is ​​checked for consistency, the eigenvector of the comparison matrix is ​​calculated by the arithmetic mean method, and normalized to obtain the weight value of the specified factor of the criterion layer as the weight of the specified feature.

[0020] As a preferred solution of the dynamic scheduling analysis method for power business data security capability, the step of performing consistency check on the comparison matrix includes:

[0021] Calculate the consistency index CI. The calculation formula of the consistency index CI is:

[0022]

[0023] In the formula, λ maxis the maximum eigenvalue of the comparison matrix;

[0024] Find the random consistency index RI corresponding to the number N of criterion layer factors;

[0025] Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is:

[0026]

[0027] If the consistency ratio CR is less than the preset consistency ratio threshold, it is determined that the comparison matrix meets the consistency requirement.

[0028] As the optimal solution for the dynamic dispatch analysis method of power business data security capability, the expression of the N*N comparison matrix is:

[0029]

[0030] Where A represents an N*N comparison matrix.

[0031] As a preferred solution for the dynamic scheduling analysis method of power business data security capability, in the process of establishing an anomaly detection model using a neural network, the neural network adopts a recurrent neural network RNN. By adjusting the weights and bias parameters of the neural network, the anomaly detection model is enabled to distinguish between normal data and abnormal data, and the cross-validation method is used to evaluate the performance of the anomaly detection model.

[0032] As a preferred solution for the dynamic scheduling analysis method of power business data security capability, in the process of identifying potential network security threats to the power system, it is determined whether there is a security risk in the current network state according to the output results of the anomaly detection model;

[0033] When a security risk is identified in the current network status, the alarm mechanism is triggered; based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, starting intrusion detection systems, and restricting access rights of suspicious users; and security policies and resource allocation plans are adjusted as needed.

[0034] In a second aspect, the present invention provides a power business data security capability dynamic scheduling analysis system, comprising:

[0035] A business data collection module is used to collect network user flow abnormality data and network security parameters in the power system business data to obtain network user flow abnormality data and network security parameters;

[0036] A feature extraction module is used to preprocess the obtained abnormal network user traffic data and the network security parameters, perform feature extraction on the preprocessed abnormal network user traffic data and the network security parameters, and obtain extracted feature results;

[0037] A weight allocation module is used to allocate weights to the extracted feature results based on the hierarchical analysis method to obtain the weights of the specified features;

[0038] An anomaly detection model building module, used to build an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features;

[0039] The dynamic scheduling analysis module is used to input the network user traffic anomaly data and the network security parameters collected in real time into the anomaly detection model for dynamic monitoring, identify potential network security threats to the power system, and dynamically mobilize security resources.

[0040] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, in the business data collection module:

[0041] The network user traffic abnormality data includes at least one of user IP path abnormality data, IP traffic abnormality data, high-risk port scanning data and service access relationship abnormality data;

[0042] Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

[0043] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, in the business data collection module:

[0044] The network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk;

[0045] Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network;

[0046] Obtain the data network congestion risk through the SNMP protocol.

[0047] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, the weight allocation module includes:

[0048] The criterion layer construction submodule is used to determine the weight of each specified feature as the target layer, and divide the IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute the criterion layer;

[0049] A factor importance comparison submodule is used to compare the importance of the specified factors in the criterion layer in pairs, and score them using a 1-9 scale method according to the comparison results to obtain an average score for each comparison pair;

[0050] The specified feature weight calculation submodule is used to construct an N*N comparison matrix according to the average score of each comparison pair, where N is the number of criterion layer factors, perform consistency check on the comparison matrix, calculate the eigenvector of the comparison matrix by arithmetic mean method, and perform normalization processing to obtain the weight value of the specified factor of the criterion layer as the weight of the specified feature.

[0051] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, in the specified feature weight calculation submodule:

[0052] Calculate the consistency index CI. The calculation formula of the consistency index CI is:

[0053]

[0054] In the formula, λ max is the maximum eigenvalue of the comparison matrix;

[0055] Find the random consistency index RI corresponding to the number N of criterion layer factors;

[0056] Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is:

[0057]

[0058] If the consistency ratio CR is less than the preset consistency ratio threshold, it is determined that the comparison matrix meets the consistency requirement.

[0059] As a preferred solution of the dynamic dispatch analysis system for power business data security capability, in the specified feature weight calculation submodule, the expression of the N*N comparison matrix is:

[0060]

[0061] Where A represents an N*N comparison matrix.

[0062] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, in the anomaly detection model construction module:

[0063] The neural network adopts a recurrent neural network RNN. By adjusting the weight and bias parameters of the neural network, the anomaly detection model distinguishes normal data from abnormal data, and the performance of the anomaly detection model is evaluated by a cross-validation method.

[0064] As a preferred solution for the dynamic dispatch analysis system of power business data security capability, in the dynamic dispatch analysis module, it is determined whether there is a security risk in the current network state according to the output result of the anomaly detection model;

[0065] When a security risk is identified in the current network status, the alarm mechanism is triggered; based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, starting intrusion detection systems, and restricting access rights of suspicious users; and security policies and resource allocation plans are adjusted as needed.

[0066] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a method for dynamic scheduling and analysis of power business data security capabilities is implemented according to the first aspect or any possible implementation thereof.

[0067] In a fourth aspect, the present invention provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the steps of a dynamic scheduling analysis method for power business data security capabilities of the first aspect or any possible implementation thereof.

[0068] From the above, it can be seen that the technical solution provided by the present invention collects network user traffic anomaly data and network security parameters in the power system business data in real time, and preprocesses and extracts features of the user traffic anomaly data and network security parameters; weights the extracted features based on the hierarchical analysis method to obtain the weight of each feature; based on the extracted features and the weight of each feature, an anomaly detection model is established using a neural network; the user traffic anomaly data and network security parameters collected in real time are input into the anomaly detection model for dynamic monitoring, identifying potential network security threats, and dynamically mobilizing security resources. The present invention can timely discover and respond to potential network security threats through real-time collection and dynamic monitoring; the anomaly detection model established based on the hierarchical analysis method and neural network improves the accuracy of threat identification. By dynamically scheduling security resources, the protection strategy can be flexibly adjusted according to the threat level to improve the flexibility of security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0069] In order to more clearly illustrate the technical solutions in the present invention or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0070] Figure 1 A schematic diagram of a flow chart of a method for dynamic scheduling and analysis of power business data security capabilities provided by an embodiment of the present invention;

[0071] Figure 2 A weight allocation flow chart in a method for dynamic scheduling and analysis of power business data security capabilities provided in an embodiment of the present invention;

[0072] Figure 3 An architecture diagram of a power business data security capability dynamic scheduling analysis system provided by an embodiment of the present invention;

[0073] Figure 4 Schematic diagram of the structure of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0074] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0075] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present invention should have the usual meanings understood by people with ordinary skills in the field to which the present invention belongs. The words "include" or "comprise" and the like used in the embodiments of the present invention mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, but do not exclude other elements or objects.

[0076] With the rapid development of smart grids, new power systems are facing increasingly complex network environments and diverse security threats. Traditional static data security protection measures can no longer meet the dynamically changing security needs. Therefore, it is particularly important to develop a solution that can identify abnormal network behavior in real time and dynamically adjust data security protection strategies according to network status.

[0077] In view of this, in order to solve the problem that traditional static data security protection measures are difficult to meet dynamically changing security needs, an embodiment of the present invention provides a method and device for dynamic scheduling analysis of power business data security capabilities. The following is the specific content of the embodiment of the present invention.

[0078] See also Figure 1 The embodiment of the present invention provides a method for dynamic scheduling and analysis of power business data security capabilities, comprising the following steps:

[0079] S1. Collecting network user traffic anomaly data and network security parameters in the power system business data to obtain network user traffic anomaly data and network security parameters;

[0080] S2, preprocessing the obtained abnormal network user traffic data and the network security parameters, performing feature extraction on the preprocessed abnormal network user traffic data and the network security parameters, and obtaining extracted feature results;

[0081] S3, assigning weights to the extracted feature results based on the hierarchical analysis method to obtain the weights of the specified features;

[0082] S4, establishing an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features;

[0083] S5. Input the network user traffic anomaly data and the network security parameters collected in real time into the anomaly detection model for dynamic monitoring, identify potential network security threats to the power system, and dynamically mobilize security resources.

[0084] In this embodiment, in step S1, the network user traffic abnormality data includes at least one of user IP path abnormality data, IP traffic abnormality data, high-risk port scanning data and service access relationship abnormality data;

[0085] Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

[0086] The network structure and business components of the new power system are relatively complex. The business data types in the virtual power grid of the State Grid Power System can be mainly divided into the following categories:

[0087] Operation data: This is one of the most basic and important data types in the virtual power grid. It contains real-time data on power grid operation, such as voltage, current, power, etc., which is used to monitor the operating status of the power grid and ensure safe and stable operation of the power grid.

[0088] Equipment status data: records the status information of equipment in the power grid, including but not limited to the start and stop status of the equipment, maintenance records, fault records, etc. These data are helpful for equipment management, predictive maintenance, and reducing the occurrence of faults.

[0089] Environmental data: including meteorological information such as temperature, humidity, wind speed, sunshine, and early warning information of natural disasters such as earthquakes and floods. These data are of great significance for assessing the impact of the external environment on the power grid and taking protective measures in advance.

[0090] Consumption data: Collecting information on users’ electricity consumption, including power consumption, time of use, nature of use (industrial, commercial, residential), etc., helps power grid companies understand power demand patterns, optimize power distribution, and improve service quality.

[0091] Transaction data: electricity transaction data generated in the power grid. This data includes information such as electricity purchase and sale contracts, transaction volume, and transaction price, and plays an important role in market analysis and electricity pricing.

[0092] Fault and maintenance data: records the specific circumstances of power grid faults, including the time, location, type of fault, changes in power grid parameters before and after the fault, and the resulting maintenance activity data, providing an important basis for power grid maintenance and improvement.

[0093] Security monitoring data: Data used to ensure the safe operation of the power grid, which may include intrusion detection, abnormal behavior analysis, etc., to help timely detect and deal with security threats.

[0094] Scientific research data: In order to promote the development of power technology, power grid companies will also generate or collect data related to scientific research, such as test data of new power equipment, application effect evaluation data of new technologies, etc.

[0095] Other auxiliary data: including but not limited to grid-related policy and regulatory documents, employee management information, customer feedback information, etc. Although these data are not directly involved in the operation and management of the grid, they are also indispensable to the overall operation of the grid.

[0096] The above different types of data are interrelated and together constitute the information system of the State Grid's power system virtual power grid, supporting the intelligent management and optimization services of the power grid.

[0097] When the power system is affected by network attacks, system failures or other factors, abnormal network traffic characteristics such as abnormal IP paths, abnormal IP traffic, high-risk port access, and sudden increase in business access relationships will occur.

[0098] Among them, IP service path changes can be matched with link information through network traffic data (source service address, destination service address, interface information, etc.) to establish the link path baseline of the source service and destination service. Network failures, architecture adjustments, and network security issues may cause data packets to be redirected to new paths, causing user IP path anomalies. Malware or routing table tampering can affect network paths, and denial of service attacks may cause network congestion and change data transmission paths.

[0099] Among them, IP traffic anomaly data refers to the sudden increase in traffic of a certain IP address in the network or the behavior that is different from usual. This anomaly may be caused by various reasons, including but not limited to: DDoS attacks, malicious activities, internal problems, network outages and malicious behavior.

[0100] Among them, the high-risk port scan data comes from high-risk port scanning, which is a network attack behavior usually performed by hackers or malware. In this attack, the attacker will try to connect to the known high-risk ports of the target system. These ports are usually associated with common services or applications and may have known security vulnerabilities or weaknesses. By scanning these high-risk ports, the attacker attempts to find vulnerabilities that can be exploited to gain unauthorized access or conduct further attacks on the system.

[0101] Among them, abnormal service access relationships refer to a surge in the number of service access relationships of a certain IP when there are network security problems or abnormal user behavior. The surge in service access relationships may be mainly caused by various network security factors, including denial of service attacks, malware propagation, credential stuffing attacks, phishing attacks, internal threats, etc. In addition, network service access relationship abnormalities also include situations that are inconsistent with normal access behavior, involving illegal access sources or targets, abnormal data transmission volume, etc.

[0102] Specifically, the user IP path anomaly data, IP flow anomaly data, high-risk port scan data and service access relationship anomaly data are obtained through NetFlow flow data collection. NetFlow flow data is collected through existing network elements, and the flow data is preprocessed, analyzed, normalized, load and flow feature extracted, sensitive data discovered and identified, and service data feature extracted and analyzed to obtain data such as IP path anomaly, IP flow anomaly, high-risk port scan, and service access relationship anomaly.

[0103] In this embodiment, in step S1, the network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk;

[0104] Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network;

[0105] Obtain the data network congestion risk through the SNMP protocol.

[0106] Specifically, in step S1, the measurement and analysis of the characteristics of indicators such as network congestion risk, delay change, packet loss rate, and delay change are further combined to provide an application implementation basis for the dynamic deployment technology of data security protection.

[0107] Network congestion refers to the situation where the amount of data transmitted in the network exceeds the network's carrying capacity, resulting in a decrease in network performance. Network congestion can cause delays, packet loss, or reduced throughput during data transmission, thus affecting the overall performance of the network and user experience.

[0108] Among them, delay variation is also called jitter, which refers to the different delays presented by different packets in the same service flow. Jitter is mainly caused by the different waiting times of successive packets in the service flow, which is a problem that has a great impact on the security quality of the service. When network equipment fails or the network is attacked, the delay variation will increase, causing the services in the network to be affected.

[0109] The packet loss rate is the ratio of the number of lost data packets to the number of sent data packets during data transmission. When the packet loss rate in the network is too high, it will significantly affect the normal operation of the business.

[0110] Among them, network delay is the time interval from when a data packet enters a network device to when the last bit is output from the device. Different network services have different requirements for end-to-end delay. The main factors causing network delay include excessive network bandwidth utilization, network attacks, and device hardware failures.

[0111] Specifically, the network delay, delay variation and packet loss rate are obtained through the bypass probes deployed in the network. The traffic data packets in the network are captured, filtered and analyzed through the bypass probes deployed in the network to obtain network traffic and performance related information, so as to obtain network delay, packet loss rate, delay variation and other data.

[0112] Specifically, the data network congestion risk degree is obtained through the SNMP protocol; the relevant operating status and load information of the existing network equipment is obtained through the SNMP protocol, mainly including equipment status information (equipment operating status, CPU usage, memory utilization, interface status, etc.), network traffic information (the inflow and outflow traffic data of the network interface can be obtained to monitor the network load and traffic distribution), interface statistics (interface error rate, packet loss rate, retransmission rate, etc., used to diagnose the health status and performance problems of the network interface), equipment configuration information (equipment configuration items, such as routing tables, ACLs (access control lists), port configurations, etc., to help understand the current settings and policies of the equipment), events and alarm information (events and alarm information generated by the equipment, such as fault alarms, link status changes, etc.). The information involved can be processed to generate data such as network congestion risk degree.

[0113] In this embodiment, in step S2, the obtained network user traffic anomaly data and the network security parameters are preprocessed, and feature extraction is performed on the preprocessed network user traffic anomaly data and the network security parameters to obtain extracted feature results.

[0114] The pre-processed network user traffic anomaly data includes user IP path anomaly data, IP traffic anomaly data, high-risk port scanning data and service access relationship anomaly data, and the pre-processed network security parameters include network delay, delay variation, packet loss rate and data network congestion risk. The data pre-processing methods include:

[0115] Data cleaning, such as processing missing values, outliers, duplicate data, etc.; data integration, which needs to resolve data redundancy and conflicts, and ensure that data between different data sources are consistent and complementary; data transformation includes normalization, standardization and other operations, the purpose of which is to convert data into a form that is more suitable for analysis. For example, by scaling eigenvalues ​​to improve the convergence speed and stability of the algorithm; data reduction: Data reduction reduces the complexity of data by reducing the dimension or number of data. Common methods include dimensionality reduction, data compression, numerical compression, etc. to reduce storage space and processing time; feature selection is used to select the most useful features from the original feature set and remove irrelevant or redundant features to improve the performance and interpretability of the model. There are related technologies in the data preprocessing method itself, which will not be repeated here.

[0116] See also Figure 2 In this embodiment, in step S3, the weight distribution of the extracted feature results based on the hierarchical analysis method to obtain the weight of the specified feature includes:

[0117] S31, determining the weight of each designated feature as the target layer, dividing IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute a criterion layer;

[0118] S32, comparing the importance of the specified factors in the criterion layer in pairs, scoring them using a 1-9 scale according to the comparison results, and obtaining an average score for each comparison pair;

[0119] S33. According to the average score of each comparison pair, an N*N comparison matrix is ​​constructed, where N is the number of criterion layer factors. The comparison matrix is ​​checked for consistency. The eigenvector of the comparison matrix is ​​calculated by arithmetic mean method and normalized to obtain the weight value of the specified factor of the criterion layer as the weight of the specified feature.

[0120] Specifically, in step S31, it should be noted that the weight of each specified feature is first determined as the final goal. The eight features of IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk are used as the criterion layer, and each feature represents a decision criterion.

[0121] Specifically, in step S32, each designated factor of the criterion layer is compared in pairs, and the importance of the target layer, that is, the feature weight, is scored according to each designated factor. The embodiment of the present invention adopts a 1-9 scale, where 1 indicates that two factors are equally important, 9 indicates that one factor is extremely important than another factor, and the middle numbers represent different degrees of relative importance. The meaning of the digital scale is shown in Table 1. Each comparison pair is scored, and the average score of all comparison pairs is calculated to eliminate individual deviations. Each comparison pair is scored to form a scoring table as shown in Table 2.

[0122] Table 1 Meaning of digital scale

[0123]

[0124] Table 2 Scoring table

[0125]

[0126] Specifically, in step S33, based on the average score of each comparison pair, an N*N comparison matrix A is constructed, where N is the number of criteria layer factors, and the number of criteria layer factors N is taken as 8. Each element a in the comparison matrix A is ij It represents the importance score of factor i relative to factor j. The comparison matrix A is checked for consistency, and the eigenvector of the comparison matrix A is calculated by the arithmetic mean method, and then normalized to obtain the weight value of each factor in the criterion layer, which is used as the weight of each feature.

[0127] Since human judgment may be inconsistent, it is necessary to perform consistency check on the comparison matrix A. The steps of performing consistency check on the comparison matrix A include:

[0128] Calculate the consistency index CI. The calculation formula of the consistency index CI is:

[0129]

[0130] In the formula, λ max is the maximum eigenvalue of the comparison matrix;

[0131] Find the random consistency index RI corresponding to the number N of criterion layer factors; the value of the random consistency index RI can be obtained from a pre-calculated table;

[0132] Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is:

[0133]

[0134] If the consistency ratio CR is less than a preset consistency ratio threshold, usually 0.1, it is determined that the comparison matrix meets the consistency requirement. Otherwise, return to step S32 to perform pairwise comparison and scoring again.

[0135] Specifically, the expression of the N*N comparison matrix is:

[0136]

[0137] Where A represents an N*N comparison matrix.

[0138] If the comparison matrix A passes the consistency check, the eigenvector of the comparison matrix A is calculated by the arithmetic mean method and normalized to obtain the weight values ​​of each factor of the criterion layer, including:

[0139] Normalize each column of the comparison matrix A so that the sum of the elements in each column is 1;

[0140] Add the normalized matrices row by row to get a new vector;

[0141] Each element of the new vector is divided by the number of criterion layer factors N to obtain a normalized feature vector. Each element of the normalized feature vector is the weight value of each factor in the criterion layer.

[0142] In this embodiment, in step S4, in the process of establishing an anomaly detection model using a neural network, the neural network adopts a recurrent neural network RNN, and the weight and bias parameters of the neural network are adjusted to enable the anomaly detection model to distinguish normal data from abnormal data, and the performance of the anomaly detection model is evaluated by a cross-validation method.

[0143] Specifically, according to the characteristics of power business data and the needs of anomaly detection, as well as the timing and potential correlation of power business data, a recurrent neural network RNN ​​is selected to establish an anomaly detection model. The preprocessed user traffic anomaly data and network security parameters are used as the input of the neural network. According to the weights of each feature determined in step S3, the input data is weighted to emphasize the features that are more important for anomaly detection. Use a labeled data set containing normal and abnormal samples to train the neural network. During the training process, by adjusting the parameters of the neural network, such as weights and biases, the model can accurately distinguish between normal data and abnormal data. Among them, methods such as cross-validation are used to evaluate the performance of the model to ensure that it can maintain good generalization ability on unseen data.

[0144] In this embodiment, in step S5, during the process of identifying potential network security threats to the power system, it is determined whether there is a security risk in the current network state according to the output result of the anomaly detection model;

[0145] When a security risk is identified in the current network status, the alarm mechanism is triggered; based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, starting intrusion detection systems, and restricting access rights of suspicious users; and security policies and resource allocation plans are adjusted as needed.

[0146] Specifically, user traffic anomaly data and network security parameters are collected in real time through SNMP protocol, NetFlow traffic data collection, bypass probes, etc. The real-time collected data is then input into the anomaly detection model, and the data is preprocessed and feature extracted as necessary to meet the input requirements of the anomaly detection model. The input data is analyzed and processed using the anomaly detection model to identify potential network security threats. Based on the output results of the anomaly detection model, such as anomaly scores, anomaly types, etc., it is determined whether there are security risks in the current network status. Once a potential network security threat is identified, the alarm mechanism is immediately triggered and the relevant personnel or systems are notified. Based on the severity and type of the threat, security resources are dynamically mobilized to respond to the threat. This may include measures such as adding firewall rules, starting intrusion detection systems, and limiting access rights of suspicious users, and adjusting security policies and resource allocation plans as needed.

[0147] In summary, the present invention collects network user traffic anomaly data and network security parameters in the power system business data to obtain network user traffic anomaly data and network security parameters; preprocesses the obtained network user traffic anomaly data and network security parameters, and extracts features from the preprocessed network user traffic anomaly data and network security parameters to obtain extracted feature results; weights are assigned to the extracted feature results based on the hierarchical analysis method to obtain weights of specified features; an anomaly detection model is established using a neural network based on the extracted feature results and the weights of specified features; the network user traffic anomaly data and network security parameters collected in real time are input into the anomaly detection model for dynamic monitoring, identifying potential network security threats to the power system, and dynamically mobilizing security resources. Among them, in the process of obtaining the weight of the specified feature, the weight of each specified feature is determined as the target layer, and the IP path abnormal data, IP flow abnormal data, high-risk port scanning data, business access relationship abnormal data, network delay, delay change, packet loss rate and data network congestion risk are divided into eight preset criteria, and the eight preset criteria constitute the criterion layer; the importance of the specified factors in the criterion layer is compared in pairs, and the 1-9 scale method is used to score according to the comparison result to obtain the average score of each comparison pair; according to the average score of each comparison pair, an N*N comparison matrix is ​​constructed, N is the number of criterion layer factors, the comparison matrix is ​​checked for consistency, the eigenvector of the comparison matrix is ​​calculated by the arithmetic mean method, and normalized, and the weight value of the specified factor of the criterion layer is obtained as the weight of the specified feature. The present invention can realize real-time monitoring and effective response to potential network security threats in the power system, and improve the accuracy of threat identification based on the abnormal detection model established by the hierarchical analysis method and the neural network. By dynamically scheduling security resources, the protection strategy is flexibly adjusted according to the threat level, and the flexibility of security protection is improved.

[0148] It should be noted that the method of the embodiment of the present invention can be performed by a single device, such as a computer or a server. The method of this embodiment can also be applied in a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present invention, and the multiple devices will interact with each other to complete the described method.

[0149] It should be noted that some embodiments of the present invention are described above. In some cases, the actions or steps recorded can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the process depicted in the accompanying drawings does not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0150] See also Figure 3 Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, an embodiment of the present invention further provides a power business data security capability dynamic scheduling analysis system, including:

[0151] The business data collection module 100 is used to collect network user traffic anomaly data and network security parameters in the power system business data to obtain network user traffic anomaly data and network security parameters;

[0152] The feature extraction module 200 is used to pre-process the obtained abnormal network user traffic data and the network security parameters, perform feature extraction on the pre-processed abnormal network user traffic data and the network security parameters, and obtain extracted feature results;

[0153] The weight distribution module 300 is used to distribute weights to the extracted feature results based on the hierarchical analysis method to obtain the weights of the specified features;

[0154] Anomaly detection model building module 400, used to build an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features;

[0155] The dynamic dispatch analysis module 500 is used to input the network user traffic anomaly data and the network security parameters collected in real time into the anomaly detection model for dynamic monitoring, identify potential network security threats to the power system, and dynamically mobilize security resources.

[0156] In this embodiment, in the business data collection module 100:

[0157] The network user traffic abnormality data includes at least one of user IP path abnormality data, IP traffic abnormality data, high-risk port scanning data and service access relationship abnormality data;

[0158] Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

[0159] In this embodiment, in the business data collection module 100:

[0160] The network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk;

[0161] Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network;

[0162] Obtain the data network congestion risk through the SNMP protocol.

[0163] In this embodiment, the weight allocation module 300 includes:

[0164] The criterion layer construction submodule 301 is used to determine the weight of each specified feature as the target layer, and divide the IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute the criterion layer;

[0165] The factor importance comparison submodule 302 is used to compare the importance of the specified factors in the criterion layer in pairs, and score them using a 1-9 scale method according to the comparison results to obtain an average score for each comparison pair;

[0166] The designated feature weight calculation submodule 303 is used to construct an N*N comparison matrix according to the average score of each comparison pair, where N is the number of criterion layer factors, perform consistency check on the comparison matrix, calculate the eigenvector of the comparison matrix by arithmetic mean method, and perform normalization processing to obtain the weight value of the designated factor of the criterion layer as the weight of the designated feature.

[0167] In this embodiment, in the specified feature weight calculation submodule 303:

[0168] Calculate the consistency index CI. The calculation formula of the consistency index CI is:

[0169]

[0170] In the formula, λ max is the maximum eigenvalue of the comparison matrix;

[0171] Find the random consistency index RI corresponding to the number N of criterion layer factors;

[0172] Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is:

[0173]

[0174] If the consistency ratio CR is less than the preset consistency ratio threshold, it is determined that the comparison matrix meets the consistency requirement.

[0175] In this embodiment, in the specified feature weight calculation submodule 303, the expression of the N*N comparison matrix is:

[0176]

[0177] Where A represents an N*N comparison matrix.

[0178] In this embodiment, in the anomaly detection model building module 400:

[0179] The neural network adopts a recurrent neural network RNN. By adjusting the weight and bias parameters of the neural network, the anomaly detection model distinguishes normal data from abnormal data, and the performance of the anomaly detection model is evaluated by a cross-validation method.

[0180] In this embodiment, in the dynamic scheduling analysis module 500, it is determined whether there is a security risk in the current network state according to the output result of the anomaly detection model;

[0181] When a security risk is identified in the current network status, the alarm mechanism is triggered; based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, starting intrusion detection systems, and restricting access rights of suspicious users; and security policies and resource allocation plans are adjusted as needed.

[0182] The device of the above embodiment is used to implement a corresponding method for dynamic scheduling and analysis of power business data security capabilities in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0183] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a method for dynamic scheduling and analysis of power business data security capabilities as described in any of the above embodiments is implemented.

[0184] Figure 4 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 610, a memory 620, an input / output interface 630, a communication interface 640, and a bus 650. The processor 610, the memory 620, the input / output interface 630, and the communication interface 640 are connected to each other through the bus 650 in the device.

[0185] The processor 610 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0186] The memory 620 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 620 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 620 and are called and executed by the processor 610.

[0187] The input / output interface 630 is used to connect the input / output module to realize information input and output. The input / output module can be configured as a component in the device (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0188] The communication interface 640 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0189] The bus 650 comprises a pathway for transmitting information between the various components of the device (eg, the processor 610, the memory 620, the input / output interface 630, and the communication interface 640).

[0190] It should be noted that, although the above device only shows the processor 610, the memory 620, the input / output interface 630, the communication interface 640 and the bus 650, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0191] The electronic device of the above embodiment is used to implement a corresponding method for dynamic scheduling and analysis of power business data security capabilities in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0192] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present invention also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute a dynamic scheduling analysis method for power business data security capabilities as described in any of the above embodiments.

[0193] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0194] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute a method for dynamic scheduling and analysis of power business data security capabilities as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0195] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present invention is limited to these examples. Under the concept of the present invention, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of different aspects of the embodiments of the present invention as described above, which are not provided in detail for the sake of simplicity.

[0196] In addition, to simplify the description and discussion, and in order not to obscure the embodiments of the present invention, known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided figures. In addition, the devices may be shown in the form of block diagrams to avoid obscuring the embodiments of the present invention, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present invention will be implemented (i.e., these details should be fully within the scope of understanding of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present invention, it will be apparent to those skilled in the art that embodiments of the present invention may be implemented without these specific details or with variations in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0197] Although the invention has been described in conjunction with specific embodiments of the invention, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0198] The embodiments of the present invention are intended to cover all such substitutions, modifications and variations that fall within the scope of the claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for dynamic scheduling and analysis of power business data security capabilities, wherein: include: Collect network user traffic anomaly data and network security parameters in the power system business data to obtain network user traffic anomaly data and network security parameters; Preprocessing the obtained abnormal network user traffic data and the network security parameters, performing feature extraction on the preprocessed abnormal network user traffic data and the network security parameters, and obtaining extracted feature results; Based on the hierarchical analysis method, weights are assigned to the extracted feature results to obtain weights of designated features; Establishing an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features; The network user traffic anomaly data and the network security parameters collected in real time are input into the anomaly detection model for dynamic monitoring, to identify potential network security threats to the power system, and to dynamically mobilize security resources.

2. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 1, wherein: The network user traffic anomaly data includes at least one of user IP path anomaly data, IP traffic anomaly data, high-risk port scanning data and service access relationship anomaly data; Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

3. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 2, wherein: The network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk; Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network; Obtain the data network congestion risk through the SNMP protocol.

4. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 3, wherein: The step of performing weight distribution on the extracted feature results based on the hierarchical analysis method to obtain the weight of the specified feature includes: Determine the weight of each designated feature as the target layer, divide IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute a criterion layer; Comparing the importance of the specified factors in the criterion layer in pairs, scoring them using a 1-9 scale according to the comparison results, and obtaining an average score for each comparison pair; According to the average score of each comparison pair, an N*N comparison matrix is ​​constructed, where N is the number of criterion layer factors. The comparison matrix is ​​checked for consistency, the eigenvector of the comparison matrix is ​​calculated by the arithmetic mean method, and normalized to obtain the weight value of the specified factor of the criterion layer as the weight of the specified feature.

5. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 4, wherein: The step of performing consistency check on the comparison matrix includes: Calculate the consistency index CI. The calculation formula of the consistency index CI is: In the formula, λ max is the maximum eigenvalue of the comparison matrix; Find the random consistency index RI corresponding to the number N of criterion layer factors; Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is: If the consistency ratio CR is less than the preset consistency ratio threshold, it is determined that the comparison matrix meets the consistency requirement.

6. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 5, wherein: The expression of N*N comparison matrix is: Where A represents an N*N comparison matrix.

7. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 1, wherein: In the process of establishing an anomaly detection model using a neural network, the neural network adopts a recurrent neural network RNN. By adjusting the weight and bias parameters of the neural network, the anomaly detection model distinguishes normal data from abnormal data, and the performance of the anomaly detection model is evaluated using a cross-validation method.

8. A method for dynamic scheduling and analysis of power business data security capabilities according to claim 1, wherein: In the process of identifying potential network security threats to the power system, judging whether there is a security risk in the current network state according to the output result of the anomaly detection model; When the current network status is identified as a security risk, the alarm mechanism is triggered; Based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, launching intrusion detection systems, and restricting access rights of suspicious users; and adjusting security policies and resource allocation plans as needed.

9. A dynamic dispatch analysis system for power business data security capabilities, wherein: include: A business data collection module is used to collect network user flow abnormality data and network security parameters in the power system business data to obtain network user flow abnormality data and network security parameters; A feature extraction module is used to preprocess the obtained abnormal network user traffic data and the network security parameters, perform feature extraction on the preprocessed abnormal network user traffic data and the network security parameters, and obtain extracted feature results; A weight allocation module is used to allocate weights to the extracted feature results based on the hierarchical analysis method to obtain the weights of the specified features; An anomaly detection model building module, used to build an anomaly detection model using a neural network according to the extracted feature results and the weights of the specified features; The dynamic scheduling analysis module is used to input the network user traffic anomaly data and the network security parameters collected in real time into the anomaly detection model for dynamic monitoring, identify potential network security threats to the power system, and dynamically mobilize security resources.

10. A power business data security capability dynamic scheduling analysis system according to claim 9, wherein: In the business data collection module: The network user traffic anomaly data includes at least one of user IP path anomaly data, IP traffic anomaly data, high-risk port scanning data and service access relationship anomaly data; Through NetFlow traffic data collection, we can obtain user IP path abnormal data, IP traffic abnormal data, high-risk port scanning data and business access relationship abnormal data.

11. A power business data security capability dynamic scheduling analysis system according to claim 10, wherein: In the business data collection module: The network security parameter includes at least one of network delay, delay variation, packet loss rate and data network congestion risk; Obtain network delay, delay variation, and packet loss rate through bypass probes deployed in the network; Obtain the data network congestion risk through the SNMP protocol.

12. A power business data security capability dynamic scheduling analysis system according to claim 10, wherein: The weight distribution module comprises: The criterion layer construction submodule is used to determine the weight of each specified feature as the target layer, and divide the IP path abnormal data, IP flow abnormal data, high-risk port scanning data, service access relationship abnormal data, network delay, delay variation, packet loss rate and data network congestion risk into eight preset criteria, and the eight preset criteria constitute the criterion layer; A factor importance comparison submodule is used to compare the importance of the specified factors in the criterion layer in pairs, and score them using a 1-9 scale method according to the comparison results to obtain an average score for each comparison pair; The specified feature weight calculation submodule is used to construct an N*N comparison matrix according to the average score of each comparison pair, where N is the number of criterion layer factors, perform consistency check on the comparison matrix, calculate the eigenvector of the comparison matrix by arithmetic mean method, and perform normalization processing to obtain the weight value of the specified factor of the criterion layer as the weight of the specified feature.

13. A power business data security capability dynamic scheduling analysis system according to claim 12, wherein: In the specified feature weight calculation submodule: Calculate the consistency index CI. The calculation formula of the consistency index CI is: In the formula, λ max is the maximum eigenvalue of the comparison matrix; Find the random consistency index RI corresponding to the number N of criterion layer factors; Calculate the consistency ratio CR. The calculation formula of the consistency ratio CR is: If the consistency ratio CR is less than the preset consistency ratio threshold, it is determined that the comparison matrix meets the consistency requirement.

14. A power business data security capability dynamic scheduling analysis system according to claim 13, wherein: In the specified feature weight calculation submodule, the expression of the N*N comparison matrix is: Where A represents an N*N comparison matrix.

15. A power business data security capability dynamic scheduling analysis system according to claim 9, wherein: In the anomaly detection model building module: The neural network adopts a recurrent neural network RNN. By adjusting the weight and bias parameters of the neural network, the anomaly detection model distinguishes normal data from abnormal data, and the performance of the anomaly detection model is evaluated by a cross-validation method.

16. A power business data security capability dynamic scheduling analysis system according to claim 9, wherein: In the dynamic scheduling analysis module, judging whether there is a security risk in the current network state according to the output result of the anomaly detection model; When the current network status is identified as a security risk, the alarm mechanism is triggered; Based on the severity and type of network security threats, security resources are dynamically mobilized to respond to the threats. Dynamic mobilization of security resources includes adding firewall rules, launching intrusion detection systems, and restricting access rights of suspicious users; and adjusting security policies and resource allocation plans as needed.

17. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method for dynamic scheduling and analysis of power business data security capabilities as described in any one of claims 1 to 8 is implemented.

18. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable the computer to execute the steps in the method for dynamic scheduling and analysis of power business data security capabilities as described in any one of claims 1 to 8.

Citation Information

Cited By

  • Power network data driving optimization method and system based on dynamic authority modeling

    CN120611901A

  • Data application security protection method and device adaptive to novel power system

    CN120750573A

  • Communication network security control method

    CN121125363A