Network security management system and method for transformer substation
By dividing the information sharing network into multiple network structures, risk identification and simulation processing is performed on each network access request for the network structure, the problem of difficulty in detecting and defending complex network attacks in a timely manner in the existing technology is solved, and efficient security management of substation networks and data is achieved.
Patent Information
- Application Number
- CN202510213340.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-16
AI Technical Summary
Current network security management strategies are difficult to detect and defend against complex cyber attacks in a timely manner, resulting in threats to the security of substation network and data.
By dividing the information sharing network into multiple network structures, risk identification is performed on each network access request for attention, risk coefficient is generated, and access simulation is performed on requests suspected of abnormal identification, and finally processing network access requests and updating preset network security management models.
It improves the accuracy of risk identification of network access requests, reduces the impact of partial network failures on the overall substation, improves business continuity, and ensures the security of substation network and data.
Smart Images

Figure CN120017396A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network security for substations, and in particular to a network security management system and method for substations. Background Art
[0002] With the networking, informatization and intelligence of substation systems, smart substations bring intelligent convenience, but related network security and data security issues and risks are also highlighted. As attack methods become increasingly complex, current network security management strategies cannot detect and defend against current network attack behaviors in a timely manner. Therefore, enhancing the accuracy of risk identification of network access requests is an important prerequisite for realizing substation network security management and the basis for further improving network and data security. Summary of the invention
[0003] To solve the above technical problems, the present application provides a network security management system and method for a substation, which divides an information sharing network into multiple network structures of interest, performs risk identification on network access requests for each network structure of interest, obtains a risk coefficient and sets an initial identifier, performs access simulation on network access requests that are initially identified as suspected abnormal identifiers, obtains a final identifier and processes the corresponding network access requests, thereby improving the accuracy of risk identification of network access requests for each network structure of interest, reducing the impact of partial network failures on the overall substation and improving business continuity, thereby ensuring the security of the substation network and data.
[0004] In some embodiments of the present application, a network security management system for a substation is provided, including: An acquisition module is used to acquire network topology information and basic information of the information sharing network of the substation, and divide the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; An identification module is used to obtain a network access request for each concerned network structure, parse the network access request, obtain network access information and extract access features of the network access information, perform risk identification on the access features, and obtain a corresponding risk coefficient; A simulation module is used to generate an initial identification of a corresponding network access request according to a risk factor. If the initial identification is a suspected abnormal identification, an access simulation is performed on the network access request, and a final identification of the corresponding network access request is generated according to the simulation result. The management module is used to process the network access request according to the final identification and update the preset network security management model that focuses on the network structure accordingly.
[0005] In some embodiments of the present application, the information sharing network is divided into a plurality of concerned network structures according to the network topology information and the basic information, including: The basic information includes multiple functional areas of the information sharing network, important data of each functional area and characteristic device nodes; Constructing the network topology structure of the substation according to the network topology information of the information sharing network of the substation; Based on multiple functional areas, the network topology structure is hierarchically divided to obtain the initial network structure of different functional areas; The corresponding initial network structure is annotated according to the important data of each functional area and the characteristic device nodes, and a number of divisible nodes corresponding to the initial network structure are obtained; According to a number of divisible nodes of the same initial network structure, the initial network structure is divided and simulated to obtain a plurality of simulated network structures after the initial network structure corresponds to the divisible nodes; Evaluate multiple simulated network structures, obtain the simulated application degree of each simulated network structure according to the evaluation results, and determine the final division nodes of the corresponding initial network structure for multiple simulated network structures whose simulated application degrees in the same initial network structure are greater than a preset application degree threshold; The corresponding initial network structure is divided according to the final division nodes to obtain multiple focus network structures of the substation information sharing network.
[0006] In some embodiments of the present application, multiple simulated network structures are evaluated, and the simulated application degree of each simulated network structure is obtained according to the evaluation results, including: Presetting a plurality of network evaluation indicators, the network evaluation indicators including network communication quality evaluation indicators, network structure rationality evaluation indicators, network security management evaluation indicators and network service continuity evaluation indicators; Analyze the historical data of multiple simulated network structures, extract the historical associated data associated with each network evaluation indicator, evaluate the corresponding historical associated data of each simulated network structure based on the preset network structure evaluation model of each network evaluation indicator, and obtain the corresponding network sub-evaluation value; A total network evaluation value of the corresponding simulated network structure is generated according to the network sub-evaluation values corresponding to the multiple network evaluation indicators of each simulated network structure and the corresponding weight coefficients, and a simulation application degree of the corresponding simulated network structure is set according to the total network evaluation value.
[0007] In some embodiments of the present application, risk identification is performed on access features to obtain corresponding risk coefficients, including: Extracting access features of network access information, wherein the access features include access level, access purpose, access action, and access frequency; Compare the access level in the network access information with the preset access level threshold of the corresponding concerned network structure, and if the access level is less than the preset access level threshold, reject the corresponding network access request; If the access level is greater than a preset access level threshold, the access purpose is compared with a preset purpose reference library corresponding to the concerned network structure to obtain a first similarity between the preset purpose in the preset purpose reference library and the current access purpose, wherein the preset purpose reference library includes a plurality of preset purposes corresponding to the concerned network structure, and each preset purpose is associated with a corresponding first preset utilization coefficient; Generate a first credibility coefficient according to a first similarity between the access purpose and a preset purpose in a preset purpose reference library; The access action is divided into multiple access sub-actions, and the multiple access sub-actions are compared with a preset action reference library of a corresponding attention network structure to obtain a second sub-similarity between multiple preset sub-actions of the same preset action in the preset action reference library and multiple access sub-actions; The preset action reference library includes a plurality of preset actions corresponding to the concerned network structure, and each preset action is associated with a corresponding second preset utilization coefficient; Each preset action includes a plurality of preset sub-actions, each preset sub-action is associated with a corresponding preset importance coefficient, a corresponding preset correlation coefficient is set between the plurality of preset sub-actions in the same preset action, and a set of associated preset sub-actions of each preset sub-action in the same preset action is constructed according to the preset correlation coefficient; Generate a second similarity between the access action and the corresponding preset action according to the second sub-similarities between the multiple access sub-actions and the multiple preset sub-actions of the same preset action in the preset action reference library; generating a second credibility coefficient according to a second similarity between the access action and the preset action in the preset action reference library; Compare the access frequency with a preset access frequency value of the corresponding concerned network structure to obtain an access frequency difference, and generate a third credibility coefficient according to the access frequency difference; A risk coefficient corresponding to the network access request is generated according to the first credibility coefficient, the second credibility coefficient, and the third credibility coefficient.
[0008] In some embodiments of the present application, the number of preset purposes whose first similarity is greater than a first preset similarity threshold, the first similarity difference whose first similarity is greater than the first preset similarity threshold, and the first preset utilization coefficient of the preset purpose whose first similarity is greater than the first preset similarity threshold are obtained, and a first credibility coefficient is generated; The calculation formula of the first credibility coefficient is: ; Wherein, X1 is the first credibility coefficient, z1 is the first credibility conversion coefficient, n1 is the number of preset purposes whose first similarity is greater than the first preset similarity threshold, N1 is the total number of preset purposes, is the i-th first similarity difference value, L1i is the first preset utilization coefficient of the preset purpose of the i-th first similarity difference value; Screening out preset sub-actions whose second sub-similarity of the same preset action is greater than a preset second sub-similarity threshold, comparing all the screened preset sub-actions with the associated preset sub-action set corresponding to each of the screened preset sub-actions, and generating a compensation coefficient of the second sub-similarity of each of the screened preset sub-actions according to the comparison result; Correcting the corresponding second sub-similarity according to the compensation coefficient, and generating a second similarity between the access action and the corresponding preset action according to the corrected second sub-similarity of multiple preset sub-actions of the same preset action; Obtaining the number of preset actions whose second similarity is greater than a second preset similarity threshold, the second similarity difference whose second similarity is greater than the second preset similarity threshold, and the second preset utilization coefficient of the preset action whose second similarity is greater than the second preset similarity threshold, and generating a second credibility coefficient; The calculation formula of the second credibility coefficient is: ; Wherein, X2 is the second credibility coefficient, z2 is the second credibility conversion coefficient, n2 is the number of preset actions whose second similarity is greater than the second preset similarity threshold, and N2 is the total number of preset actions. is the i-th second similarity difference, L2i is the second preset utilization coefficient of the preset action corresponding to the i-th second similarity difference; The calculation formula of the risk coefficient is: ; Among them, X0 is the risk coefficient, f0 is the risk conversion coefficient, a1 is the weight coefficient of the first credibility coefficient, a2 is the weight coefficient of the second credibility coefficient, a3 is the weight coefficient of the third credibility coefficient, and X3 is the third credibility coefficient.
[0009] In some embodiments of the present application, generating an initial identifier corresponding to a network access request according to a risk factor includes: Presetting a first risk factor threshold and a second risk factor threshold; When the risk factor is less than the first risk factor threshold, an initial identification of the corresponding network access request is generated as a normal identification, and the corresponding network access request is approved; When the risk factor is between the first risk factor threshold and the second risk factor threshold, an initial identification of the corresponding network access request is generated as a suspected abnormal identification, and access simulation is performed on the corresponding network access request; When the risk coefficient is greater than the second risk coefficient threshold, an initial identification of the corresponding network access request is generated as an abnormal identification, and the corresponding network access request is not approved.
[0010] In some embodiments of the present application, performing access simulation on a network access request and generating a final identifier corresponding to the network access request according to the simulation result includes: Analyze the historical attack logs of the network structure corresponding to the network access requests with suspected abnormal signs, and determine multiple historical attack nodes and corresponding historical attack behaviors; Analyze the correlation between the historical attack nodes and the corresponding historical attack behaviors and the access behaviors in the network access requests with suspected abnormal identification, and set the historical attack behaviors and the corresponding historical attack nodes with correlation greater than a preset correlation threshold as the suspected attack behaviors and the corresponding suspected attack nodes of the network access requests with suspected abnormal identification; Constructing a virtual scene of a network structure corresponding to a network access request with a suspected abnormal identification, wherein the virtual scene includes a plurality of virtual nodes; Introducing the network access request with the suspected abnormal identification into the virtual scene of the corresponding concerned network structure for multiple times, and obtaining simulated behavior data of the network access request being introduced into the corresponding virtual scene for multiple times; Matching the operation points of the simulated behavior data with the virtual nodes in the virtual scene to obtain a matching relationship between the virtual nodes in the virtual scene and the simulated behavior data; If the virtual node is a suspected attack node, the simulated behavior data matched at the virtual node is analyzed with the attack behavior data of the suspected attack behavior corresponding to the suspected attack node to obtain the degree of data deviation between the simulated behavior data and the attack behavior data; If the data deviation degree is less than the preset deviation degree threshold, it is determined that the corresponding simulated behavior data is consistent with the attack behavior data; The number of virtual nodes whose simulated behavior data and attack behavior data are consistent with each network access request is obtained and averaged to obtain the number of simulated suspected attack nodes corresponding to the network access request; When the number of simulated suspected attack nodes is greater than a preset number threshold, an abnormal flag is generated for the network access request with the suspected abnormal flag; When the number of simulated suspected attack nodes is less than a preset number threshold, a normal mark is generated for the network access request with the suspected abnormal mark.
[0011] In some embodiments of the present application, updating a preset network security management model corresponding to the network structure includes: Obtaining a network access request with an abnormal identification and access characteristics corresponding to the network access request; Analyze the network access request with abnormal identification and the access characteristics of the corresponding network access request to determine the possible attack nodes of the network access request with abnormal identification in the corresponding network structure of concern and the corresponding possible attack behaviors; Based on the abnormally identified network access requests, possible attack nodes and corresponding possible attack behaviors, the preset network security management model of the corresponding network structure is iteratively updated.
[0012] In some embodiments of the present application, a network security management method for a substation is also included: Acquire network topology information and basic information of the information sharing network of the substation, and divide the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; Obtaining each network access request of the concerned network structure, parsing the network access request, obtaining network access information and extracting access features of the network access information, identifying risks of the access features, and obtaining corresponding risk coefficients; Generate an initial identification of the corresponding network access request according to the risk factor. If the initial identification is a suspected abnormal identification, perform access simulation on the network access request and generate a final identification of the corresponding network access request according to the simulation result. The network access request is processed according to the final identification, and the preset network security management model focusing on the network structure is updated accordingly.
[0013] Compared with the prior art, the network security management system and method for a substation in the embodiment of the present application have the following beneficial effects: By dividing the information sharing network into multiple network structures of concern, risk identification is performed on network access requests of each network structure of concern, the risk coefficient is obtained and an initial identification is set, access simulation is performed on network access requests initially identified as suspected abnormal identification, the final identification is obtained and the corresponding network access requests are processed, the accuracy of risk identification of network access requests for each network structure of concern is improved, the impact of partial network failures on the overall substation is reduced, business continuity is improved, and the security of substation network and data is guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 is a schematic diagram of a network security management system for a substation in an embodiment of the present application; Figure 2 It is a flow chart of a network security management method for a substation in an embodiment of the present application. DETAILED DESCRIPTION
[0015] The specific implementation methods of the present application are further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present application but are not intended to limit the scope of the present application.
[0016] In the description of the present application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.
[0017] The terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "plurality" means two or more.
[0018] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0019] like Figure 1 As shown, a network security management system for a substation according to an embodiment of the present application includes: An acquisition module is used to acquire network topology information and basic information of the information sharing network of the substation, and divide the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; An identification module is used to obtain a network access request for each concerned network structure, parse the network access request, obtain network access information and extract access features of the network access information, perform risk identification on the access features, and obtain a corresponding risk coefficient; A simulation module is used to generate an initial identification of a corresponding network access request according to a risk factor. If the initial identification is a suspected abnormal identification, an access simulation is performed on the network access request, and a final identification of the corresponding network access request is generated according to the simulation result. The management module is used to process the network access request according to the final identification and update the preset network security management model that focuses on the network structure accordingly.
[0020] In some embodiments of the present application, the information sharing network is divided into a plurality of concerned network structures according to the network topology information and the basic information, including: The basic information includes multiple functional areas of the information sharing network, important data of each functional area and characteristic device nodes; Constructing the network topology structure of the substation according to the network topology information of the information sharing network of the substation; Based on multiple functional areas, the network topology structure is hierarchically divided to obtain the initial network structure of different functional areas; The corresponding initial network structure is annotated according to the important data of each functional area and the characteristic device nodes, and a number of divisible nodes corresponding to the initial network structure are obtained; According to a number of divisible nodes of the same initial network structure, the initial network structure is divided and simulated to obtain a plurality of simulated network structures after the initial network structure corresponds to the divisible nodes; Evaluate multiple simulated network structures, obtain the simulated application degree of each simulated network structure according to the evaluation results, and determine the final division nodes of the corresponding initial network structure for multiple simulated network structures whose simulated application degrees in the same initial network structure are greater than a preset application degree threshold; The corresponding initial network structure is divided according to the final division nodes to obtain multiple focus network structures of the substation information sharing network.
[0021] In this embodiment, the information sharing network refers to the communication network between information systems of different levels, departments, and equipment in the substation, and the characteristic equipment node refers to the node where the important equipment in the functional area corresponding to each initial network structure is located.
[0022] In this embodiment, by converting the information sharing network into a network topology structure and dividing it hierarchically according to functional areas, multiple initial network structures are obtained, and the divisible nodes are determined according to the important data and characteristic equipment nodes in each initial network structure, that is, each initial network structure is divided again to obtain a network structure of interest. By dividing the information sharing network multiple times, multiple network structures of interest are obtained, thereby reducing the impact of virus invasion of part of the network on other services of the substation, thereby improving the overall network security of the substation.
[0023] In some embodiments of the present application, multiple simulated network structures are evaluated, and the simulated application degree of each simulated network structure is obtained according to the evaluation results, including: Presetting a plurality of network evaluation indicators, the network evaluation indicators including network communication quality evaluation indicators, network structure rationality evaluation indicators, network security management evaluation indicators and network service continuity evaluation indicators; Analyze the historical data of multiple simulated network structures, extract the historical associated data associated with each network evaluation indicator, evaluate the corresponding historical associated data of each simulated network structure based on the preset network structure evaluation model of each network evaluation indicator, and obtain the corresponding network sub-evaluation value; A total network evaluation value of the corresponding simulated network structure is generated according to the network sub-evaluation values corresponding to the multiple network evaluation indicators of each simulated network structure and the corresponding weight coefficients, and a simulation application degree of the corresponding simulated network structure is set according to the total network evaluation value.
[0024] In this embodiment, the network communication quality evaluation index refers to the clarity, stability and reliability of the data or signal received or transmitted by the simulated network structure. The higher the clarity, stability and reliability of the data or signal received or transmitted, the larger the network sub-evaluation value of the corresponding network communication quality evaluation index, and vice versa.
[0025] In this embodiment, when the network structure rationality evaluation index refers to a comprehensive evaluation of the hierarchy, redundant design, scalability, and maintainability of the simulated network structure, the clearer the hierarchy, the more reasonable the redundant design, the better the scalability, and the easier the maintainability, the larger the network sub-evaluation value of the corresponding network structure rationality evaluation index, and vice versa.
[0026] In this embodiment, the network security management evaluation index refers to the possible vulnerabilities in the simulated network structure and the difficulty of handling the vulnerabilities. The corresponding historical vulnerabilities and difficulty levels are determined based on historical management logs. When the vulnerability is smaller and easier to handle, the network sub-evaluation value of the corresponding network security management evaluation index is larger, and vice versa.
[0027] In this embodiment, the network service continuity evaluation index refers to the degree of impact on other services when a simulated network structure fails and the degree of impact caused by other service failures. When the degree of impact is smaller, the network sub-evaluation value of the corresponding network management security evaluation index is larger, and vice versa.
[0028] In this embodiment, when the total network evaluation value is larger, the corresponding simulation application degree is larger, and vice versa. The network evaluation index is used to determine the network structure of the information sharing network, reduce the impact of partial network failures or loopholes on the overall network, and improve the network security of the substation.
[0029] In some embodiments of the present application, risk identification is performed on access features to obtain corresponding risk coefficients, including: Extracting access features of network access information, wherein the access features include access level, access purpose, access action, and access frequency; Compare the access level in the network access information with the preset access level threshold of the corresponding concerned network structure, and if the access level is less than the preset access level threshold, reject the corresponding network access request; If the access level is greater than a preset access level threshold, the access purpose is compared with a preset purpose reference library corresponding to the concerned network structure to obtain a first similarity between the preset purpose in the preset purpose reference library and the current access purpose, wherein the preset purpose reference library includes a plurality of preset purposes corresponding to the concerned network structure, and each preset purpose is associated with a corresponding first preset utilization coefficient; Generate a first credibility coefficient according to a first similarity between the access purpose and a preset purpose in a preset purpose reference library; The access action is divided into multiple access sub-actions, and the multiple access sub-actions are compared with a preset action reference library of a corresponding attention network structure to obtain a second sub-similarity between multiple preset sub-actions of the same preset action in the preset action reference library and multiple access sub-actions; The preset action reference library includes a plurality of preset actions corresponding to the concerned network structure, and each preset action is associated with a corresponding second preset utilization coefficient; Each preset action includes a plurality of preset sub-actions, each preset sub-action is associated with a corresponding preset importance coefficient, a corresponding preset correlation coefficient is set between the plurality of preset sub-actions in the same preset action, and a set of associated preset sub-actions of each preset sub-action in the same preset action is constructed according to the preset correlation coefficient; Generate a second similarity between the access action and the corresponding preset action according to the second sub-similarities between the multiple access sub-actions and the multiple preset sub-actions of the same preset action in the preset action reference library; generating a second credibility coefficient according to a second similarity between the access action and the preset action in the preset action reference library; Compare the access frequency with a preset access frequency value of the corresponding concerned network structure to obtain an access frequency difference, and generate a third credibility coefficient according to the access frequency difference; A risk coefficient corresponding to the network access request is generated according to the first credibility coefficient, the second credibility coefficient, and the third credibility coefficient.
[0030] In this embodiment, a preset purpose reference library is constructed based on the access purpose in the normal network access request of the network structure of interest. The first similarity between the preset purpose and the access purpose refers to the degree of similarity between the two in terms of the goals and the results achieved. The first preset utilization coefficient refers to the frequency of occurrence of each preset purpose in the corresponding network structure of interest and the degree of influence of different completion degrees of the corresponding preset purpose on the network structure of interest and other involved network structures of interest. When the frequency of occurrence of each preset purpose increases and the difference in the degree of influence of different completion degrees on the network structure of interest and other involved network structures of interest is greater, the corresponding first preset utilization coefficient is greater, and vice versa.
[0031] In this embodiment, the preset action reference library is constructed based on the access action corresponding to the access purpose in the normal network access request of the network structure, including multiple preset actions, and each preset action is divided into multiple preset sub-actions. The second sub-similarity refers to the similarity between the access sub-action and the preset sub-action in terms of method, means, time and place. The greater the similarity in multiple aspects, the greater the corresponding second sub-similarity, and vice versa.
[0032] In this embodiment, the second preset utilization coefficient refers to the frequency of occurrence of each preset action in the corresponding network structure of interest and the degree of influence of different completion levels of the corresponding preset actions on the network structure of interest and other involved network structures of interest. When the frequency of occurrence of each preset action increases and the difference in the degree of influence of different completion levels on the network structure of interest and other involved network structures of interest is greater, the corresponding second preset utilization coefficient is greater, and vice versa.
[0033] In this embodiment, the preset access frequency value is obtained by averaging the historical access frequencies of the current network access request in the corresponding network structure of interest in multiple historical preset time periods, that is, the normal access frequency of the current network access request in the preset time period, the access frequency difference = access frequency - preset access frequency value, when the access frequency difference is smaller, the corresponding third credibility coefficient is larger, and vice versa.
[0034] In some embodiments of the present application, the number of preset purposes whose first similarity is greater than a first preset similarity threshold, the first similarity difference whose first similarity is greater than the first preset similarity threshold, and the first preset utilization coefficient of the preset purpose whose first similarity is greater than the first preset similarity threshold are obtained, and a first credibility coefficient is generated; The calculation formula of the first credibility coefficient is: ; Wherein, X1 is the first credibility coefficient, z1 is the first credibility conversion coefficient, n1 is the number of preset purposes whose first similarity is greater than the first preset similarity threshold, N1 is the total number of preset purposes, is the i-th first similarity difference value, L1i is the first preset utilization coefficient of the preset purpose of the i-th first similarity difference value; Screening out preset sub-actions whose second sub-similarity of the same preset action is greater than a preset second sub-similarity threshold, comparing all the screened preset sub-actions with the associated preset sub-action set corresponding to each of the screened preset sub-actions, and generating a compensation coefficient of the second sub-similarity of each of the screened preset sub-actions according to the comparison result; Correcting the corresponding second sub-similarity according to the compensation coefficient, and generating a second similarity between the access action and the corresponding preset action according to the corrected second sub-similarity of multiple preset sub-actions of the same preset action; Obtaining the number of preset actions whose second similarity is greater than a second preset similarity threshold, the second similarity difference whose second similarity is greater than the second preset similarity threshold, and the second preset utilization coefficient of the preset action whose second similarity is greater than the second preset similarity threshold, and generating a second credibility coefficient; The calculation formula of the second credibility coefficient is: ; Wherein, X2 is the second credibility coefficient, z2 is the second credibility conversion coefficient, n2 is the number of preset actions whose second similarity is greater than the second preset similarity threshold, and N2 is the total number of preset actions. is the i-th second similarity difference, L2i is the second preset utilization coefficient of the preset action corresponding to the i-th second similarity difference; The calculation formula of the risk coefficient is: ; Among them, X0 is the risk coefficient, f0 is the risk conversion coefficient, a1 is the weight coefficient of the first credibility coefficient, a2 is the weight coefficient of the second credibility coefficient, a3 is the weight coefficient of the third credibility coefficient, and X3 is the third credibility coefficient.
[0035] In this embodiment, all the filtered preset sub-actions and the repeated sub-actions of all the preset sub-actions in the associated preset sub-action set corresponding to each preset sub-action are obtained, and the compensation coefficient = the number of repeated sub-actions / the number of all the preset sub-actions in the associated preset sub-action set corresponding to each preset sub-action.
[0036] In this embodiment, when the first similarity difference is larger and the corresponding first preset utilization coefficient of the preset purpose is larger, the first credibility coefficient obtained by conversion is larger, otherwise it is smaller; when the second similarity difference is larger and the corresponding second preset utilization coefficient of the preset action is larger, the second credibility coefficient obtained by conversion is larger, otherwise it is smaller.
[0037] In this embodiment, the second sub-similarity of the corresponding preset sub-action is corrected according to the compensation coefficient, so as to improve the accuracy of the second sub-similarity and the accuracy of the subsequent second credibility coefficient.
[0038] In this embodiment, a first credibility coefficient of the access purpose is calculated based on a first similarity between the access purpose and the preset purpose, a second similarity between the multiple access sub-actions of the access action and the multiple preset sub-actions of the preset action and a second credibility coefficient of the access action are calculated, and a third credibility coefficient of the access frequency is generated based on the access frequency difference between the access frequency and the preset access frequency value, that is, a comprehensive evaluation of multiple access features of the network access request is performed to accurately evaluate the risk coefficient of the corresponding network access request, thereby improving the network security management efficiency of the substation.
[0039] 6. The network security management system for a substation according to claim 5, characterized in that generating an initial identifier corresponding to a network access request according to a risk factor comprises: Presetting a first risk factor threshold and a second risk factor threshold; When the risk factor is less than the first risk factor threshold, an initial identification of the corresponding network access request is generated as a normal identification, and the corresponding network access request is approved; When the risk factor is between the first risk factor threshold and the second risk factor threshold, an initial identification of the corresponding network access request is generated as a suspected abnormal identification, and access simulation is performed on the corresponding network access request; When the risk coefficient is greater than the second risk coefficient threshold, an initial identification of the corresponding network access request is generated as an abnormal identification, and the corresponding network access request is not approved.
[0040] In some embodiments of the present application, performing access simulation on a network access request and generating a final identifier corresponding to the network access request according to the simulation result includes: Analyze the historical attack logs of the network structure corresponding to the network access requests with suspected abnormal signs, and determine multiple historical attack nodes and corresponding historical attack behaviors; Analyze the correlation between the historical attack nodes and the corresponding historical attack behaviors and the access behaviors in the network access requests with suspected abnormal identification, and set the historical attack behaviors and the corresponding historical attack nodes with correlation greater than a preset correlation threshold as the suspected attack behaviors and the corresponding suspected attack nodes of the network access requests with suspected abnormal identification; Constructing a virtual scene of a network structure corresponding to a network access request with a suspected abnormal identification, wherein the virtual scene includes a plurality of virtual nodes; Introducing the network access request with the suspected abnormal identification into the virtual scene of the corresponding concerned network structure for multiple times, and obtaining simulated behavior data of the network access request being introduced into the corresponding virtual scene for multiple times; Matching the operation points of the simulated behavior data with the virtual nodes in the virtual scene to obtain a matching relationship between the virtual nodes in the virtual scene and the simulated behavior data; If the virtual node is a suspected attack node, the simulated behavior data matched at the virtual node is analyzed with the attack behavior data of the suspected attack behavior corresponding to the suspected attack node to obtain the degree of data deviation between the simulated behavior data and the attack behavior data; If the data deviation degree is less than the preset deviation degree threshold, it is determined that the corresponding simulated behavior data is consistent with the attack behavior data; The number of virtual nodes whose simulated behavior data and attack behavior data are consistent with each network access request is obtained and averaged to obtain the number of simulated suspected attack nodes corresponding to the network access request; When the number of simulated suspected attack nodes is greater than a preset number threshold, an abnormal flag is generated for the network access request with the suspected abnormal flag; When the number of simulated suspected attack nodes is less than a preset number threshold, a normal mark is generated for the network access request with the suspected abnormal mark.
[0041] In this embodiment, by performing access simulation on network access requests with suspected abnormal identification, simulated behavior data after each introduction of network access requests is obtained, and compared with the attack behavior data of the suspected attack behavior to obtain the degree of data deviation. The greater the degree of data deviation, the greater the deviation between the simulated behavior data and the attack behavior data, that is, the simulated behavior data and the attack behavior data are different. Otherwise, there is consistency. The number of virtual nodes with consistency is calculated and averaged to obtain the number of simulated suspected attack nodes.
[0042] In this embodiment, the preset number threshold is set according to the suspected attack nodes of the network access request with the current suspected abnormal identification, which is 1 / 3 of the number of suspected attack nodes.
[0043] In this embodiment, by re-judging the network access request with suspected abnormal identification, multiple simulated behavior data of the corresponding network access request are obtained, and the degree of data deviation is analyzed with the attack behavior data to obtain the number of simulated suspected attack nodes, and the network access request with suspected abnormal identification is divided into normal identification or abnormal identification, thereby improving the accuracy of risk judgment for different network access requests, thereby ensuring the security of the substation network and data.
[0044] In some embodiments of the present application, updating a preset network security management model corresponding to the network structure includes: Obtaining a network access request with an abnormal identification and access characteristics corresponding to the network access request; Analyze the network access request with abnormal identification and the access characteristics of the corresponding network access request to determine the possible attack nodes of the network access request with abnormal identification in the corresponding network structure of concern and the corresponding possible attack behaviors; Based on the abnormally identified network access requests, possible attack nodes and corresponding possible attack behaviors, the preset network security management model of the corresponding network structure is iteratively updated.
[0045] In this embodiment, the preset network security management model refers to a pre-trained network security management model for each concerned network structure, which is obtained by neural network training based on historical abnormal network access requests, historical attack nodes and corresponding historical attack behaviors in historical attack logs.
[0046] In this embodiment, the preset network security management model is iteratively updated through the network access request with abnormal identification, so as to improve the network security management efficiency of each concerned network structure, thereby ensuring the security of the overall network and important data of the substation.
[0047] In some embodiments of the present application, Figure 2 As shown, a network security management method for a substation is also included: Step S201: obtaining network topology information and basic information of the information sharing network of the substation, and dividing the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; Step S202: Obtain a network access request for each concerned network structure, parse the network access request, obtain network access information and extract access features of the network access information, identify risks on the access features, and obtain corresponding risk coefficients; Step S203: generating an initial identification of the corresponding network access request according to the risk factor; if the initial identification is a suspected abnormal identification, performing access simulation on the network access request, and generating a final identification of the corresponding network access request according to the simulation result; Step S204: Process the network access request according to the final identifier, and update the preset network security management model that focuses on the corresponding network structure.
[0048] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and substitutions can be made without departing from the technical principles of the present application. These improvements and substitutions should also be regarded as the scope of protection of the present application.
Claims
1. A network security management system for a substation, characterized in that: include: An acquisition module is used to acquire network topology information and basic information of the information sharing network of the substation, and divide the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; An identification module is used to obtain a network access request for each concerned network structure, parse the network access request, obtain network access information and extract access features of the network access information, perform risk identification on the access features, and obtain a corresponding risk coefficient; A simulation module is used to generate an initial identification of a corresponding network access request according to a risk factor. If the initial identification is a suspected abnormal identification, an access simulation is performed on the network access request, and a final identification of the corresponding network access request is generated according to the simulation result. The management module is used to process the network access request according to the final identification and update the preset network security management model that focuses on the network structure accordingly.
2. The network security management system for a substation according to claim 1, characterized in that: According to the network topology information and basic information, the information sharing network is divided into multiple network structures of interest, including: The basic information includes multiple functional areas of the information sharing network, important data of each functional area and characteristic device nodes; Constructing the network topology structure of the substation according to the network topology information of the information sharing network of the substation; Based on multiple functional areas, the network topology structure is hierarchically divided to obtain the initial network structure of different functional areas; The corresponding initial network structure is annotated according to the important data of each functional area and the characteristic device nodes, and a number of divisible nodes corresponding to the initial network structure are obtained; According to a number of divisible nodes of the same initial network structure, the initial network structure is divided and simulated to obtain a plurality of simulated network structures after the initial network structure corresponds to the divisible nodes; Evaluate multiple simulated network structures, obtain the simulated application degree of each simulated network structure according to the evaluation results, and determine the final division nodes of the corresponding initial network structure for multiple simulated network structures whose simulated application degrees in the same initial network structure are greater than a preset application degree threshold; The corresponding initial network structure is divided according to the final division nodes to obtain multiple focus network structures of the substation information sharing network.
3. The network security management system for a substation according to claim 2, characterized in that: Evaluate multiple simulated network structures, and obtain the simulated application degree of each simulated network structure based on the evaluation results, including: Presetting a plurality of network evaluation indicators, the network evaluation indicators including network communication quality evaluation indicators, network structure rationality evaluation indicators, network security management evaluation indicators and network service continuity evaluation indicators; Analyze the historical data of multiple simulated network structures, extract the historical associated data associated with each network evaluation indicator, evaluate the corresponding historical associated data of each simulated network structure based on the preset network structure evaluation model of each network evaluation indicator, and obtain the corresponding network sub-evaluation value; A total network evaluation value of the corresponding simulated network structure is generated according to the network sub-evaluation values corresponding to the multiple network evaluation indicators of each simulated network structure and the corresponding weight coefficients, and a simulation application degree of the corresponding simulated network structure is set according to the total network evaluation value.
4. The network security management system for a substation according to claim 3, characterized in that: Identify the risks of access features and obtain the corresponding risk coefficients, including: Extracting access features of network access information, wherein the access features include access level, access purpose, access action, and access frequency; Compare the access level in the network access information with the preset access level threshold of the corresponding concerned network structure, and if the access level is less than the preset access level threshold, reject the corresponding network access request; If the access level is greater than a preset access level threshold, the access purpose is compared with a preset purpose reference library corresponding to the concerned network structure to obtain a first similarity between the preset purpose in the preset purpose reference library and the current access purpose, wherein the preset purpose reference library includes a plurality of preset purposes corresponding to the concerned network structure, and each preset purpose is associated with a corresponding first preset utilization coefficient; Generate a first credibility coefficient according to a first similarity between the access purpose and a preset purpose in a preset purpose reference library; The access action is divided into multiple access sub-actions, and the multiple access sub-actions are compared with a preset action reference library of a corresponding attention network structure to obtain a second sub-similarity between multiple preset sub-actions of the same preset action in the preset action reference library and multiple access sub-actions; The preset action reference library includes a plurality of preset actions corresponding to the concerned network structure, and each preset action is associated with a corresponding second preset utilization coefficient; Each preset action includes a plurality of preset sub-actions, each preset sub-action is associated with a corresponding preset importance coefficient, a corresponding preset correlation coefficient is set between the plurality of preset sub-actions in the same preset action, and a set of associated preset sub-actions of each preset sub-action in the same preset action is constructed according to the preset correlation coefficient; Generate a second similarity between the access action and the corresponding preset action according to the second sub-similarities between the multiple access sub-actions and the multiple preset sub-actions of the same preset action in the preset action reference library; generating a second credibility coefficient according to a second similarity between the access action and the preset action in the preset action reference library; Compare the access frequency with a preset access frequency value of the corresponding concerned network structure to obtain an access frequency difference, and generate a third credibility coefficient according to the access frequency difference; A risk coefficient corresponding to the network access request is generated according to the first credibility coefficient, the second credibility coefficient, and the third credibility coefficient.
5. The network security management system for a substation according to claim 4, characterized in that: Obtaining the number of preset purposes whose first similarity is greater than a first preset similarity threshold, a first similarity difference whose first similarity is greater than the first preset similarity threshold, and a first preset utilization coefficient of the preset purpose whose first similarity is greater than the first preset similarity threshold, and generating a first credibility coefficient; The calculation formula of the first credibility coefficient is: ; Wherein, X1 is the first credibility coefficient, z1 is the first credibility conversion coefficient, n1 is the number of preset purposes whose first similarity is greater than the first preset similarity threshold, N1 is the total number of preset purposes, is the i-th first similarity difference value, L1i is the first preset utilization coefficient of the preset purpose of the i-th first similarity difference value; Screening out preset sub-actions whose second sub-similarity of the same preset action is greater than a preset second sub-similarity threshold, comparing all the screened preset sub-actions with the associated preset sub-action set corresponding to each of the screened preset sub-actions, and generating a compensation coefficient of the second sub-similarity of each of the screened preset sub-actions according to the comparison result; Correcting the corresponding second sub-similarity according to the compensation coefficient, and generating a second similarity between the access action and the corresponding preset action according to the corrected second sub-similarity of multiple preset sub-actions of the same preset action; Obtaining the number of preset actions whose second similarity is greater than a second preset similarity threshold, the second similarity difference whose second similarity is greater than the second preset similarity threshold, and the second preset utilization coefficient of the preset action whose second similarity is greater than the second preset similarity threshold, and generating a second credibility coefficient; The calculation formula of the second credibility coefficient is: ; Wherein, X2 is the second credibility coefficient, z2 is the second credibility conversion coefficient, n2 is the number of preset actions whose second similarity is greater than the second preset similarity threshold, and N2 is the total number of preset actions. is the i-th second similarity difference, L2i is the second preset utilization coefficient of the preset action corresponding to the i-th second similarity difference; The calculation formula of the risk coefficient is: ; Among them, X0 is the risk coefficient, f0 is the risk conversion coefficient, a1 is the weight coefficient of the first credibility coefficient, a2 is the weight coefficient of the second credibility coefficient, a3 is the weight coefficient of the third credibility coefficient, and X3 is the third credibility coefficient.
6. The network security management system for a substation according to claim 5, characterized in that: Generate an initial identification of the corresponding network access request based on the risk factor, including: Presetting a first risk factor threshold and a second risk factor threshold; When the risk factor is less than the first risk factor threshold, an initial identification of the corresponding network access request is generated as a normal identification, and the corresponding network access request is approved; When the risk factor is between the first risk factor threshold and the second risk factor threshold, an initial identification of the corresponding network access request is generated as a suspected abnormal identification, and access simulation is performed on the corresponding network access request; When the risk coefficient is greater than the second risk coefficient threshold, an initial identification of the corresponding network access request is generated as an abnormal identification, and the corresponding network access request is not approved.
7. The network security management system for a substation according to claim 6, characterized in that: Perform access simulation on the network access request and generate the final identification of the corresponding network access request according to the simulation result, including: Analyze the historical attack logs of the network structure corresponding to the network access requests with suspected abnormal signs, and determine multiple historical attack nodes and corresponding historical attack behaviors; Analyze the correlation between the historical attack nodes and the corresponding historical attack behaviors and the access behaviors in the network access requests with suspected abnormal identification, and set the historical attack behaviors and the corresponding historical attack nodes with correlation greater than a preset correlation threshold as the suspected attack behaviors and the corresponding suspected attack nodes of the network access requests with suspected abnormal identification; Constructing a virtual scene of a network structure corresponding to a network access request with a suspected abnormal identification, wherein the virtual scene includes a plurality of virtual nodes; Introducing the network access request with the suspected abnormal identification into the virtual scene of the corresponding concerned network structure for multiple times, and obtaining simulated behavior data of the network access request being introduced into the corresponding virtual scene for multiple times; Matching the operation points of the simulated behavior data with the virtual nodes in the virtual scene to obtain a matching relationship between the virtual nodes in the virtual scene and the simulated behavior data; If the virtual node is a suspected attack node, the simulated behavior data matched at the virtual node is analyzed with the attack behavior data of the suspected attack behavior corresponding to the suspected attack node to obtain the degree of data deviation between the simulated behavior data and the attack behavior data; If the data deviation degree is less than the preset deviation degree threshold, it is determined that the corresponding simulated behavior data is consistent with the attack behavior data; The number of virtual nodes whose simulated behavior data and attack behavior data are consistent with each network access request is obtained and averaged to obtain the number of simulated suspected attack nodes corresponding to the network access request; When the number of simulated suspected attack nodes is greater than a preset number threshold, an abnormal flag is generated for the network access request with the suspected abnormal flag; When the number of simulated suspected attack nodes is less than a preset number threshold, a normal mark is generated for the network access request with the suspected abnormal mark.
8. The network security management system for a substation according to claim 7, characterized in that: Update the preset network security management model with corresponding attention to network structure, including: Obtaining a network access request with an abnormal identification and access characteristics corresponding to the network access request; Analyze the network access request with abnormal identification and the access characteristics of the corresponding network access request to determine the possible attack nodes of the network access request with abnormal identification in the corresponding concerned network structure and the corresponding possible attack behaviors; Based on the abnormally identified network access requests, possible attack nodes and corresponding possible attack behaviors, the preset network security management model of the corresponding network structure is iteratively updated.
9. A network security management method for a substation, characterized in that: include: Acquire network topology information and basic information of the information sharing network of the substation, and divide the information sharing network into a plurality of concerned network structures according to the network topology information and the basic information; Obtaining each network access request of the concerned network structure, parsing the network access request, obtaining network access information and extracting access features of the network access information, identifying risks of the access features, and obtaining corresponding risk coefficients; Generate an initial identification of the corresponding network access request according to the risk factor. If the initial identification is a suspected abnormal identification, perform access simulation on the network access request and generate a final identification of the corresponding network access request according to the simulation result. The network access request is processed according to the final identification, and the preset network security management model focusing on the network structure is updated accordingly.