Power monitoring system safety analysis method and system, electronic equipment and storage medium
Through the agent, the attack chain data of the power monitoring system is analyzed and the disposal information is generated, which solves the problems of low accuracy and low efficiency of security analysis in the existing technology, and achieves fast, accurate and real-time protection of the power monitoring system.
Patent Information
- Application Number
- CN202510173896.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-27
AI Technical Summary
The safety analysis of power monitoring systems in the prior art depends on expert experience, and there are shortcomings in low accuracy, low efficiency and difficulty in meeting large-scale real-time protection.
By obtaining the attack chain data of the power monitoring system, identifying the attack type of attack events, extracting the attack summary and attack process in the attack data, and inputting this information into the agent to generate disposal information, including threat level, number of matching schemes, recommended response time limit and target disposal plan.
It improves the accuracy and efficiency of safety analysis of power monitoring systems, without manual intervention, and can quickly respond and meet the real-time protection needs of large-scale power monitoring systems.
Smart Images

Figure CN120046144A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of power monitoring systems, and more specifically, to a method, system, electronic device, and storage medium for security analysis of a power monitoring system. Background Art
[0002] With the continuous development of power monitoring systems, the current power monitoring systems are undergoing digital transformation, and people are paying more and more attention to the security of power monitoring systems. However, the security protection of power monitoring systems faces many challenges. In order to ensure the security of power monitoring systems, security analysis can be performed on power monitoring systems.
[0003] In the prior art, the security analysis of power monitoring systems mainly relies on the experience judgment of security experts. However, this method has many limitations. Specifically, since expert experience is difficult to quickly replicate and inherit, the security analysis capabilities of power monitoring systems vary; moreover, with the continuous evolution of attack means, it is difficult to cope with new attack means solely relying on expert experience, resulting in a low accuracy rate of security analysis of power monitoring systems. In addition, performing security analysis on power monitoring systems manually not only has low efficiency but also is difficult to meet the real-time protection requirements of large-scale power monitoring systems. Summary of the Invention
[0004] In view of this, the present application provides a method, system, electronic device, and storage medium for security analysis of a power monitoring system, aiming to improve the accuracy rate and efficiency of security analysis of power monitoring systems and meet the real-time protection requirements of large-scale power monitoring systems.
[0005] The first aspect of the present application provides a method for security analysis of a power monitoring system, and the method includes:
[0006] Obtain attack chain data of a power monitoring system, and identify the attack types of each attack event in the attack chain data;
[0007] Extract corresponding attack data from the attack chain data; wherein, the attack data at least includes an attack summary and the attack process of each attack event, and the attack summary includes multiple attack characteristics;
[0008] Input the attack summary, the attack process of each attack event, and each pre-set disposal plan into an intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event, and each pre-set disposal plan; wherein, the disposal information at least includes the threat level suffered by the power monitoring system, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0009] Optionally, obtaining the attack chain data of the power monitoring system and identifying the attack types of each attack event in the attack chain data includes:
[0010] Obtaining the attack chain data of the power monitoring system, where the attack chain data includes multiple attack events, an attack link graph, affected asset information, and attack technical characteristics;
[0011] Determining the attack type of each attack event according to the attack link, the affected asset information, and the attack technical characteristics.
[0012] Optionally, extracting the corresponding attack data from the attack chain data includes:
[0013] For each attack event, analyzing the attack chain data to extract the attack process of the attack event from the attack chain data;
[0014] Analyzing the attack processes of each attack event to extract multiple attack characteristics from the attack processes of each attack event, and generating corresponding attack summaries according to each attack characteristic.
[0015] Optionally, inputting the attack summary, the attack process of each attack event, and each pre-set disposal plan into an intelligent agent, and enabling the intelligent agent to generate corresponding disposal information according to the attack summary, the attack process of each attack event, and each pre-set disposal plan, includes:
[0016] Generating corresponding prompt words according to the attack summary, the attack process of each attack event, and each pre-set disposal plan, and inputting the prompt words into the intelligent agent;
[0017] Determining the threat level and recommended response time limit of the power monitoring system by the intelligent agent according to the attack process of each attack event and the network threat level standard;
[0018] Obtaining the context information of each attack event by the intelligent agent, and calculating the relevance between each disposal plan and the attack summary according to the attack summary, the context information of each attack event, and each disposal plan, and screening at least one target disposal plan from each disposal plan according to the relevance of each disposal plan;
[0019] Determining the corresponding number of matching plans by the intelligent agent according to at least one target disposal plan, and generating corresponding disposal information according to the threat level, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0020] Optionally, the method further includes:
[0021] The intelligent agent generates a corresponding security analysis report according to the attack type of each of the attack events, the attack process of each of the attack events, and each of the target handling solutions.
[0022] A second aspect of the present application provides a security analysis system for a power monitoring system, the system comprising:
[0023] An attack type recognition unit, configured to obtain attack chain data of an attack on a power monitoring system, and recognize the attack type of each attack event in the attack chain data;
[0024] An extraction unit, configured to extract corresponding attack data from the attack chain data; wherein, the attack data at least includes an attack summary and the attack process of each attack event, and the attack summary includes a plurality of attack features;
[0025] A security analysis unit, configured to input the attack summary, the attack process of each attack event, and each preset handling solution into an intelligent agent, so that the intelligent agent generates corresponding handling information according to the attack summary, the attack process of each attack event, and each preset handling solution; wherein, the handling information at least includes the threat level suffered by the power monitoring system, the number of matching solutions, the recommended response time limit, and at least one target handling solution.
[0026] Optionally, the attack type recognition unit includes:
[0027] An attack chain data acquisition unit, configured to obtain attack chain data of an attack on a power monitoring system, wherein the attack chain data includes a plurality of attack events, an attack link diagram, affected asset information, and attack technical features;
[0028] An attack type recognition subunit, configured to determine the attack type of each attack event according to the attack link, the affected asset information, and the attack technical features.
[0029] Optionally, the extraction unit includes:
[0030] An attack process extraction unit, configured to analyze the attack chain data for each attack event, so as to extract the attack process of the attack event from the attack chain data;
[0031] An attack summary generation unit, configured to analyze the attack processes of each of the attack events, so as to extract a plurality of attack features from the attack processes of each of the attack events, and generate a corresponding attack summary according to each of the attack features.
[0032] A third aspect of the present application provides an electronic device, including: a processor and a memory, where the processor and the memory are connected through a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store a program, and the program is used to implement the power monitoring system security analysis method provided in the first aspect of the present application.
[0033] A fourth aspect of the present application provides a storage medium, in which computer-executable instructions are stored, and the computer-executable instructions are used to execute the power monitoring system security analysis method provided in the first aspect of the present application.
[0034] The present application provides a power monitoring system security analysis method, system, electronic device and storage medium. By obtaining attack chain data of a power monitoring system and identifying the attack types of each attack event in the attack chain data; extracting corresponding attack data from the attack chain data; wherein, the attack data at least includes an attack summary and the attack process of each attack event, and the attack summary includes multiple attack features; inputting the attack summary, the attack process of each attack event and each pre-set disposal plan into an intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event and each pre-set disposal plan; wherein, the disposal information at least includes the threat level suffered by the power monitoring system, the number of matching plans, the recommended response time limit and at least one target disposal plan. The technical solution provided by the present application does not require manual intervention, and can effectively avoid the uneven security analysis capabilities of the power monitoring system caused by the difficulty of quickly replicating and inheriting expert experience, and the low accuracy of the security analysis of the power monitoring system due to the difficulty of dealing with new attack means relying on expert experience. It can not only quickly realize the security analysis of the power monitoring system, but also meet the real-time protection requirements of large-scale power monitoring systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0036] Figure 1 It is a schematic flowchart of a power monitoring system security analysis method provided by an embodiment of the present application;
[0037] Figure 2 It is an example diagram of a power monitoring system security analysis method provided by an embodiment of the present application;
[0038] Figure 3A schematic structural diagram of a power monitoring system security analysis system provided by an embodiment of the present application;
[0039] Figure 4 A schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0040] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0041] In the present application, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0042] Refer to Figure 1 , which shows a schematic flow diagram of a power monitoring system security analysis method provided by an embodiment of the present application. The power monitoring system security analysis method specifically includes the following steps:
[0043] S101: Obtain attack chain data of the power monitoring system and identify the attack types of each attack event in the attack chain data.
[0044] During the specific execution of step S101, the power monitoring system can be detected in real time. When it is detected that the power monitoring system is continuously invaded by an attacker, the attack chain data corresponding to the continuous invasion behavior can be obtained, and the attack chain data can be analyzed to identify the attack types corresponding to each attack event in the attack chain data.
[0045] It should be noted that the continuous invasion behavior may include: initial access behavior, privilege escalation behavior, lateral movement behavior, etc. The attack chain data includes attack event sequences, temporal correlation information, affected asset information, attack technical characteristics, etc. The embodiments of the present application do not limit this here.
[0046] Optionally, the process of obtaining the attack chain data of the power monitoring system and identifying the attack types of each attack event in the attack chain data may be as follows: Obtain the attack chain data of the power monitoring system, where the attack chain data includes multiple attack events, an attack link diagram, affected asset information, and attack technique characteristics; Determine the attack type of each attack event according to the attack link, affected asset information, and attack technique characteristics.
[0047] It should be noted that the attack event sequence includes the attack events corresponding to each intrusion behavior in the continuous intrusion behavior, and each attack event is arranged in the chronological order of the corresponding intrusion behavior; The timing correlation information includes an attack link diagram constructed according to the chronological order and causal relationship between each attack event; The affected asset information includes the electronic monitoring system assets involved in each attack event, for example, the electronic monitoring system assets may include attributes such as device type and importance level; The attack technique characteristics include the specific techniques used in each attack event marked based on the ATT&CK framework.
[0048] In some embodiments, the attack events corresponding to each intrusion behavior suffered by the power monitoring system may be determined according to the attack event sequence, and the power monitoring system assets involved in each attack event may be determined from the affected asset information, and the specific techniques used in each attack event may be determined from the attack technique characteristics; For each attack event, the attack type of the attack event is analyzed by using the attack link diagram in combination with the power monitoring system assets and the specific techniques involved in the attack event, and the corresponding attack type is marked for each attack event. In this way, after obtaining the attack chain data of the power monitoring system, the attack type marked on each attack event can be directly identified.
[0049] It should be noted that in the case of the initial access of an attack behavior, the attack type of the attack event corresponding to the attack behavior may be: Spearphishing, Supply Chain Compromise, External Remote Services; in the case of the attack behavior being execution, the attack type of the attack event corresponding to the attack behavior may be: Command and Scripting Interpreter, System Services, Software Deployment Tools; in the case of the attack behavior being persistence, the attack type of the attack event corresponding to the attack behavior may be: Boot or Logon Autostart Execution, Account Manipulation, Scheduled Task / Job; in the case of the attack behavior being privilege escalation, the attack type of the attack event corresponding to the attack behavior may be: Exploitation for Privilege Escalation, Access Token Manipulation, Valid Accounts; in the case of the attack behavior being defense evasion, the attack type of the attack event corresponding to the attack behavior may be: File Deletion, Process Injection, Invalid Code Signature; in the case of the attack behavior being credential acquisition, the attack type of the attack event corresponding to the attack behavior may be: Brute Force, OS Credential Dumping, Steal WebSession Cookie; regarding the attack type corresponding to each attack event, it can be determined according to the actual analysis, and the embodiments of the present application do not limit it here.
[0050] S102: Extract the corresponding attack data from the attack chain data; wherein, the attack data at least includes the attack summaries of each attack event, and the attack summary includes multiple attack features.
[0051] In the process of specifically executing step S102, the attack chain data can be analyzed to obtain the attack summaries related to each attack event, wherein the attack summary includes multiple attack features, and the attack features are the features used to match the protection policies of the attack events.
[0052] It should be noted that multiple attack features may include the time range corresponding to each attack event, the attack targets of each attack event, the final impact caused by each attack event, etc., which are not limited in the embodiments of the present application.
[0053] Optionally, the process of extracting corresponding attack data from the attack chain data may be: for each attack event, analyzing the attack chain data to extract the attack process of the attack event from the attack chain data; analyzing the attack processes of each attack event to extract multiple attack features from the attack processes of each attack event, and generating corresponding attack summaries according to each attack feature.
[0054] For example, the obtained attack chain data is as follows:
[0055] {
[0056] "attack_sequence":
[0057] {
[0058] "timestamp(Time)": "2024-03-15 10:30:45",
[0059] "target(Target)": "Power distribution station control terminal",
[0060] "technique": "T1133",
[0061] "tactic": "Initial Access",
[0062] "sub_technique": "External Remote Services",
[0063] "detail(Final Impact)": "Exploiting the vulnerability of the VPN remote connection service"
[0064] },
[0065] {
[0066] "timestamp": "2024-03-15 10:35:12",
[0067] "technique": "T1078",
[0068] "tactic": "Privilege Escalation",
[0069] "detail": "Obtaining the system administrator privilege",
[0070] "target": "Domain Controller"
[0071] },
[0072] {
[0073] "timestamp": "2024-03-15 10:40:33",
[0074] "technique": "T1003",
[0075] "tactic": "Credential Access",
[0076] "sub_technique": "OS Credential Dumping",
[0077] "detail": "Export domain controller password hash",
[0078] "target": "Domain Controller"
[0079] },
[0080] {
[0081] "timestamp": "2024-03-15 11:05:27",
[0082] "technique": "T1021",
[0083] "tactic": "Lateral Movement",
[0084] "sub_technique": "Remote Services",
[0085] "detail": "Lateral movement using stolen credentials",
[0086] "target": "SCADA server"
[0087] },
[0088] {
[0089] "timestamp": "2024-03-15 11:15:39",
[0090] "technique": "T1136",
[0091] "tactic": "Persistence",
[0092] "sub_technique": "Create Account",
[0093] "detail": "Create a hidden administrator account",
[0094] "target": "SCADA server"
[0095] },
[0096] {
[0097] "timestamp": "2024-03-15 11:30:52",
[0098] "technique": "T1030",
[0099] "tactic": "Exfiltration",
[0100] "sub_technique": "Data Transfer Size Limits",
[0101] "detail": "Steal SCADA configuration data in batches",
[0102] "target": "SCADA server",
[0103] "impact": "Leakage of critical configuration data"
[0104] }
[0106] }
[0107] First, the attack chain data can be formalized to obtain a formalized attack process. Among them, the formalized attack process includes the attack process of each attack event. The formalized attack process can be as follows: 1. Phase: Initial Access, Time: 2024-03-15 10:30:45, Target: Substation Control Terminal, Technique: External Remote Services (T1133), Behavior: Exploiting the vulnerability of the VPN remote connection service, Result: Successfully established an initial foothold; 2. Phase: Privilege Escalation, Time: 2024-03-15 10:35:12, Target: Domain Controller, Technique: Valid Accounts (T1078), Behavior: Obtaining the system administrator privilege, Result: Obtaining the domain administrator privilege; 3. Phase: Credential Access, Time: 2024-03-15 10:40:33, Target: Domain Controller, Technique: OS Credential Dumping (T1003), Behavior: Exporting the password hash of the domain controller, Result: Obtaining the credentials of the domain accounts; 4. Phase: Lateral Movement, Time: 2024-03-15 11:05:27, Target: SCADA Server, Technique: Remote Services (T1021), Behavior: Lateral movement using the stolen credentials, Result: Successfully accessing the SCADA server; 5. Phase: Persistence, Time: 2024-03-15 11:15:39, Target: SCADA Server, Technique: Create Account (T1136), Behavior: Creating a hidden administrator account, Result: Establishing a persistent access channel; 6. Phase: Exfiltration, Time: 2024-03-15 11:30:52, Target: SCADA Server, Technique: Data Transfer Size Limits (T1030), Behavior: Stealing the SCADA configuration data in batches, Result: Leakage of key configuration data.
[0108] Secondly, extract the time range when each attack event was attacked, the attack target of each attack event, and the final impact caused by each attack event from the attack process of each attack event, and generate the corresponding attack summary according to each attack feature. Among them, the attack features included in the attack summary can be: Time range: 2024-03-15 10:30:45 - 11:30:52, Attack target: Substation Control Terminal, Domain Controller, SCADA Server, Final impact: Leakage of SCADA server configuration data.
[0109] S103: Input the attack summary, the attack process of each attack event, and each pre-set handling solution into the agent, so that the agent generates corresponding handling information according to the attack summary, the attack process of each attack event, and each pre-set handling solution.
[0110] In the embodiment of the present application, multiple typical attack events can be collected in advance, the handling solution and its handling solution information corresponding to each typical attack event are determined, the association relationship between each typical attack event and its handling solution is established, and finally each typical attack event and its handling solution are stored in the power security knowledge base.
[0111] It should be noted that the handling solution can include the corresponding solution ID, title, applicable scenario, main measures, implementation complexity, response timeliness, etc., which are not limited in the embodiment of the present application.
[0112] For example, each handling solution stored in the power security knowledge base may include: Handling Solution 1. Solution ID: ICS-DR-001; Title: Industrial Control Network Isolation and Access Control Solution; Applicable Scenario: For attacks such as IT-OT network boundary breakthrough and lateral movement; Main Measures: Network partition isolation, enhanced access control, boundary protection; Implementation Complexity: Medium; Response Timeliness: High; Handling Solution 2. Solution ID: ICS-DR-002; Title: Industrial Control System Data Leakage Prevention Solution; Applicable Scenario: For attacks such as configuration data theft and sensitive information leakage; Main Measures: Data encryption, access auditing, DLP deployment; Implementation Complexity: Medium; Response Timeliness: High; Handling Solution 3. Solution ID: ICS-DR-003; Title: Supply Chain Attack Protection Solution; Applicable Scenario: For attacks such as software supply chain and controlled update servers; Main Measures: Software integrity verification, patch management, third-party access control; Implementation Complexity: High; Response Timeliness: Medium; Handling Solution 4. Solution ID: ICS-DR-004; Title: Malicious Program Protection Solution; Applicable Scenario: For attacks such as virus trojans and ransomware; Main Measures: Terminal protection, malicious code detection, backup and recovery; Implementation Complexity: Medium; Response Timeliness: High; Handling Solution 5. Solution ID: ICS-DR-005; Title: Identity Authentication and Privilege Elevation Protection Solution; Applicable Scenario: For attacks such as credential theft and privilege elevation; Main Measures: Multi-factor authentication, privileged account management, audit tracking; Implementation Complexity: Medium; Response Timeliness: High.
[0113] In the specific process of executing step S103, after obtaining the corresponding attack summary and the attack process of each attack event, the attack summary, the attack process of each attack event, and each preset disposal plan can be input into the intelligent agent, so that the intelligent agent determines the threat level and the recommended response time limit of the power monitoring system according to the attack process of each attack event, screens out at least one target disposal plan from each disposal plan according to the attack summary and each disposal plan, determines the corresponding number of matching plans at the same time, and finally generates corresponding disposal information according to the threat level, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0114] It should be noted that the intelligent agent can be a large language model, which is not limited in the embodiments of the present application.
[0115] Optionally, the intelligent agent can be pre-trained to learn the network threat level standard related to the power monitoring system and the context information related to each preset disposal plan, so that after obtaining the corresponding attack summary and the attack process of each attack event, corresponding prompt words can be generated according to the attack summary, the attack process of each attack event, and each preset disposal plan, and the prompt words can be input into the intelligent agent; the intelligent agent determines the threat level and the recommended response time limit of the power monitoring system according to the attack process of each attack event and the network threat level standard; the intelligent agent obtains the context information of each attack event, calculates the relevance between each disposal plan and the attack summary according to the attack summary, the context information of each attack event, and each disposal plan, and screens out at least one target disposal plan from each disposal plan according to the relevance of each disposal plan; the intelligent agent determines the corresponding number of matching plans according to at least one target disposal plan, and generates corresponding disposal information according to the threat level, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0116] It should be noted that the processing information can include the threat level of the power monitoring system, the number of matching plans, the recommended response time limit, and at least one target disposal plan and its relevance. Among them, the threat level can be divided into high, medium, and low. Similarly, the relevance can also be high, medium, and low, which is not limited in the embodiments of the present application.
[0117] In some embodiments, the intelligent agent determines at least one security vulnerability actually occurring in the power monitoring system according to the attack process of each attack event, and determines the threat level of the power monitoring system according to the determined at least one security vulnerability and the network threat level standard; determines the corresponding basis according to the attack process of each attack event, and determines the corresponding recommended response time limit according to the determined basis.
[0118] It should be noted that while the intelligent agent determines the corresponding number of matching solutions based on at least one target handling solution, it can also determine the matching reasons and key measures for each target handling solution based on the attack summary and each target handling solution, so that subsequent handling information can be generated based on the threat level, the number of matching solutions, the recommended response time limit, and at least one target handling solution and its relevance, matching reasons, and key measures.
[0119] It should also be noted that the intelligent agent can further combine real-time suggestions according to the relevance of each target handling solution, where the combined real-time suggestions include the execution order of each target handling solution.
[0120] It should also be noted that while the intelligent agent screens out each target handling solution from each handling solution, it can also generate the corresponding implementation timing, where the implementation timing includes the implementation order and response time limit of each target handling solution.
[0121] For example, referring to Figure 2 , taking the pre-set handling solutions shown in step S103, and the attack summary and the attack process of each attack event shown in step S102 as examples, the attack summary, the process of each attack event, and each handling solution can be input into the corresponding positions in the pre-set prompt template to obtain the corresponding prompt words, and the obtained prompt words are input into the intelligent agent collaboration layer of the intelligent agent. Among them, it can be seen from Figure 2 that the power security knowledge base is pre-set in the knowledge processing layer.
[0122] The intelligent agent extracts the attack process of each attack event from the prompt words and obtains the pre-learned network threat level through the FindMitigations function in the business layer called by its own MitigatonFinder intelligent agent, and analyzes multiple security vulnerabilities that occur in the power monitoring system after being attacked corresponding to each attack event. Among them, the multiple security vulnerabilities can include 1. successfully breaking through the IT-OT isolation boundary, 2. obtaining domain controller permissions, and 3. SCADA key configuration data leakage; determine the threat level of the power monitoring system according to each security vulnerability and the pre-learned network threat standard, where the threat level is high; determine the corresponding basis according to the attack process of each attack event, where the determined basis can include 1. the attacker has established a persistent channel, 2. the risk of continuous leakage of sensitive data, and 3. the criticality of the system, and determine the recommended response time limit according to the determined basis.
[0123] The agent extracts the attack summary and each mitigation solution from the prompt words through the FindMitigations function in its own business layer, obtains the context information of each pre-learned attack event, and calculates the relevance between each mitigation solution and the attack summary based on the attack summary, the context information of each attack event, and each mitigation solution. Sort each mitigation solution from high to low according to the relevance of each mitigation solution, and determine the target mitigation solutions from the top several (for example, the top 3) in the obtained sorted sequence, where each target mitigation solution includes Mitigation Solution 1, Mitigation Solution 2, and Mitigation Solution 5; determine the matching reasons and key measures for each target mitigation solution based on the attack summary and each target mitigation solution; according to the relevance of each target mitigation solution, correspondingly combine real-time suggestions and implementation timings; finally, corresponding mitigation information can be generated based on the threat level, the number of matching solutions, the recommended response time limit, the combined real-time suggestions, the implementation timing, and the target mitigation solutions and their relevance, matching reasons, and key measures; where the generated mitigation information can be as follows:
[0124] Threat level of the power monitoring system: High;
[0125] Number of matching solutions: 3, where the coverage: data leakage prevention, network isolation, permission management;
[0126] Recommended response time limit: within 24 hours;
[0127] Mitigation Solution 2. ICS-DR-002 (Relevance: High);
[0128] Matching reason: Directly targeting the SCADA configuration data stealing behavior;
[0129] Key measures: Deploy a DLP system, encrypt configuration files, and strengthen data access auditing;
[0130] Mitigation Solution 2. ID: ICS-DR-002, Title: Industrial Control Network Isolation and Access Control Solution, Applicable Scenarios: For IT-OT network boundary breakthrough and lateral movement attacks, Main Measures: Network partition isolation, access control enhancement, Complexity of boundary protection implementation: Medium, Response timeliness: High;
[0131] Mitigation Solution 1. ICS-DR-001 (Relevance: High);
[0132] Matching reason: Corresponding to the lateral movement behavior in the attack chain;
[0133] Key measures: Strengthen the IT-OT network boundary protection and implement network partitioning;
[0134] Disposal Plan 1. ID: ICS-DR-001, Title: Industrial Control System Data Leakage Prevention Plan, Applicable Scenarios: For attacks such as configuration data theft and sensitive information leakage, Main Measures: Data encryption, access auditing, DLP deployment, Implementation Complexity: Medium, Response Timeliness: High;
[0135] Disposal Plan 5. ICS-DR-005 (Relevance: Medium);
[0136] Reason for Matching: Involves domain controller credential theft and privilege escalation;
[0137] Key Measures: Strengthen privileged account management, implement multi-factor authentication;
[0138] Disposal Plan 5. ID: ICS-DR-005, Title: Identity Authentication and Privilege Escalation Protection Plan, Applicable Scenarios: For attacks such as credential theft and privilege escalation, Main Measures: Multi-factor authentication, privileged account management, audit tracking, Implementation Complexity: Medium, Response Timeliness: High;
[0139] Combined Implementation Suggestions:
[0140] 1. Prioritize implementing the ICS-DR-002 plan to prevent data leakage;
[0141] 2. Implement ICS-DR-001 synchronously to strengthen network isolation;
[0142] 3. Cooperate with ICS-DR-005 to strengthen privilege management;
[0143] Implementation Timeline:
[0144] First Phase (0 - 24h): Implement Disposal Plan 2 to deploy DLP and configure encryption;
[0145] Second Phase (24 - 48h): Implement Disposal Plan 1 to perform network partitioning and access control;
[0146] Third Phase (48 - 72h): Implement Disposal Plan 5 to conduct privilege sorting and authentication enhancement.
[0147] The present application provides a method for security analysis of a power monitoring system. By obtaining attack chain data of the power monitoring system and identifying the attack types of each attack event in the attack chain data; extracting corresponding attack data from the attack chain data; wherein the attack data at least includes an attack summary and the attack process of each attack event, and the attack summary includes multiple attack features; inputting the attack summary, the attack process of each attack event, and each preset disposal plan into an intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event, and each preset disposal plan; wherein the disposal information at least includes the threat level suffered by the power monitoring system, the number of matching plans, the recommended response time limit, and at least one target disposal plan. The technical solution provided by the present application does not require manual intervention, and can effectively avoid the uneven security analysis capabilities of the power monitoring system due to the difficulty of quickly replicating and inheriting expert experience, and the difficulty of coping with new attack means by relying on expert experience, resulting in a low accuracy rate of the security analysis of the power monitoring system. It can not only quickly realize the security analysis of the power monitoring system, but also meet the real-time protection requirements of large-scale power monitoring systems.
[0148] Further, on the basis of the method for security analysis of the power monitoring system provided in the embodiment of the present application, the present application can also generate a corresponding security analysis report through the intelligent agent according to the attack types of each attack event, the attack process of each attack event, and each target disposal plan.
[0149] In practical applications, referring to Figure 2 , corresponding input information can be generated according to the attack types of each attack event, the attack process of each attack event, and each target disposal plan, and the input information is input into the intelligent agent; the intelligent agent calls the GenerateSolutionWithModel function in the business layer through its own SolutionGenerator intelligent agent to perform scenario analysis according to the attack types of each attack event and the attack process of each attack event, generates a corresponding scenario analysis report, and finally generates a final security analysis report according to the scenario analysis report and each target disposal plan (disposal suggestions) in the output layer, and outputs the generated security analysis report.
[0150] It should be noted that the security analysis report at least includes a report summary, an event overview, attack chain analysis information, and emergency disposal measures.
[0151] For example, taking each preset disposal plan and the generated disposal information shown in step S103, and the attack summary and the attack process of each attack event shown in step S102 as examples; corresponding input information is generated according to the attack types of each attack event, the attack process of each attack event, and each target disposal plan, and the input information is input into the intelligent agent.
[0152] The agent conducts scenario analysis through the GenerateSolutionWithModel function in its own business layer based on the attack types and attack processes of each attack event, generates corresponding scenario analysis reports, and finally generates the final security analysis report according to the scenario analysis reports and each target handling solution; among them, the generated security analysis report can be as follows:
[0153] I. Report Summary
[0154] On March 15, 2024, an advanced persistent threat attack event occurred in the power monitoring system. The attacker adopted a multi-stage penetration strategy, broke through from the substation control terminal, went through multiple stages such as privilege escalation and lateral movement, and finally stole the key configuration data of the SCADA system. This attack exposed the vulnerabilities existing in the current power monitoring system in aspects such as network boundary protection, privilege management, and data protection. Currently, a comprehensive response plan (Handling Solution 2, Handling Solution 1, and Handling Solution 5) has been formulated, including protection measures at three levels: data leakage prevention, network isolation, and privilege management.
[0155] II. Event Overview
[0156] 1. Event Classification and Grading
[0157] This event is classified as a data theft / exfiltration attack and has the following characteristics:
[0158] Power monitoring systems are often of special danger as attack targets because such systems directly control industrial processes in the physical world. The attacker showed clear target orientation in this operation, specifically targeting the theft of SCADA configuration data, and this behavior may indicate preparations for a larger-scale attack. Judging from the accuracy and persistence of the attack, this is very likely an organized advanced persistent threat (APT) attack.
[0159] Based on the scope of influence and harm degree of the attack, this event is rated as a high-level security event. This rating is mainly based on the following three aspects: First, the attack successfully broke through the IT-OT isolation boundary (Security Vulnerability 1); second, the attacker obtained domain administrator privileges (Security Vulnerability 2); finally, it caused the leakage of SCADA key configuration data (Security Vulnerability 3). These factors together constitute a serious threat to the power monitoring system.
[0160] 2. Impact Scope Assessment
[0161] The scope of influence of this attack involves multiple key system levels:
[0162] At the network security level, the IT-OT isolation boundary has been breached, which means that the original network partition protection mechanism has failed. This breach may lead to more security risks because attackers may have gained in-depth understanding of the network architecture.
[0163] At the system control level, the attacker has obtained domain administrator privileges, which enables the attacker to freely access various resources within the domain. The leakage of such high-level privileges means that the attacker may have gained complete control of the system.
[0164] At the data security level, the leakage of SCADA configuration data directly threatens the secure operation of industrial control systems. These configuration data contain the core operating parameters of the system and may be used to launch more targeted destructive attacks.
[0165] 3. Timeline of the incident
[0166] The attack started at 10:30 am on March 15, 2024 and ended at 11:30 am, lasting for about an hour in total. This timeline shows that the attacker has very proficient technical capabilities and clear attack objectives. The attack process can be clearly divided into six main stages (initial access - privilege escalation - credential acquisition - lateral movement - persistence - data theft), and the transition between each stage is very rapid and precise.
[0167] III. Information on attack chain analysis
[0168] 1. Technical analysis information
[0169] In the initial access stage (10:30:45), it shows that the attacker exploited a vulnerability in the VPN remote connection service and successfully established an initial foothold. This attack method indicates that the attacker had conducted sufficient reconnaissance on the target system in advance and precisely located exploitable vulnerabilities.
[0170] In the privilege escalation stage (10:35:12), the attacker quickly obtained domain administrator privileges, and this efficiency indicates that they may have pre-known relevant vulnerability information or internal credentials.
[0171] In the subsequent lateral movement stage (11:05:27), the attacker used the obtained credentials to successfully access the SCADA server, which reflects that the internal network may lack effective lateral movement detection and blocking mechanisms.
[0172] 2. Impact assessment information
[0173] In the short term, the configuration data of the system has been leaked, which directly threatens the secure operation of the power monitoring system. The attacker may use this data to formulate more targeted attack strategies.
[0174] In the long run, since the attacker has established a persistent backdoor in the system, if it cannot be completely removed, the system will continue to face security threats. In addition, the effectiveness of the IT-OT isolation boundary also needs to be re-evaluated.
[0175] 3. Key Findings
[0176] First, there are problems with the security configuration of the VPN service, which provides an initial entry point for attackers. This reminds us that we need to strengthen the security management of external access services.
[0177] Second, the privilege management mechanism of the domain controller is not perfect enough, and attackers can relatively easily obtain high-level privileges. This reflects that the privilege management system needs to be optimized.
[0178] Finally, the data protection mechanism is insufficient, and sensitive configuration data is not adequately encrypted, which directly leads to data leakage.
[0179] 4. Potential Risk Information
[0180] (1) The leakage of configuration data may enable attackers to conduct more precise attack planning. They may use this information to design targeted attack methods, causing greater damage.
[0181] (2) The existence of persistent backdoors means that attackers may regain control of the system at any time. If these backdoors cannot be completely removed, the system will remain in danger.
[0182] (3) The effectiveness of IT-OT isolation is questioned, which may lead to more security risks. It is necessary to re-evaluate and strengthen the network partitioning strategy.
[0183] IV. Disposal Solutions
[0184] 1. Emergency Disposal Measures
[0185] At the data protection level, it is recommended to immediately deploy a data loss prevention system (DLP), encrypt all sensitive configuration files, and implement a strict data access audit mechanism, that is, execute Disposal Solution 2, which can effectively prevent further data leakage.
[0186] At the network security level, it is necessary to reconstruct the IT-OT isolation solution and strengthen the boundary protection, that is, execute Disposal Solution 1, deploy more strict access control policies and a more perfect network monitoring system.
[0187] At the privilege management level, it is recommended to implement multi-factor authentication, optimize the management of privileged accounts, and strengthen the audit tracking mechanism, that is, execute Disposal Solution 5, to raise the threshold for privilege abuse.
[0188] 2. Phased Implementation Plan
[0189] The first stage (0 - 24 hours) mainly focuses on emergency response, implementing Disposal Plan 2, comprehensively encrypting and protecting the SCADA configuration data, clearing all suspicious system accounts and services, and deploying an emergency data leakage prevention solution.
[0190] The second stage (24 - 48 hours) focuses on strengthening protection, that is, implementing Disposal Plan 1, reconstructing the network partition, deploying new access control policies, and enhancing the system monitoring ability.
[0191] The third stage (48 - 72 hours) establishes a long-term mechanism, that is, implementing Disposal Plan 5, improving the permission management system, establishing a normalized security audit system, and formulating an emergency response plan.
[0192] 3. Technical protection suggestions
[0193] At the technical level, deploy a new generation of data leakage prevention system with the capabilities of sensitive data identification, behavior analysis, and real-time blocking, which can effectively prevent the unauthorized transmission of configuration data; upgrade the existing network isolation devices to achieve more precise access control and more comprehensive traffic analysis. This helps to detect and block abnormal network behaviors in a timely manner; implement an access control system based on the zero-trust architecture, which requires all access requests to undergo strict authentication and authorization, and can significantly improve the security of the system.
[0194] 4. Management suggestions
[0195] At the management level, establish a dedicated security operation team responsible for daily security monitoring and emergency response, which needs to have professional knowledge of industrial control system security; conduct regular security training to improve employees' security awareness and skills, and the training content should include the latest security threats and protection knowledge; formulate a complete set of security policies and operation specifications to ensure that all operations meet security requirements, and the specifications need to be updated regularly to adapt to new security challenges.
[0196] V. Follow-up suggestions
[0197] 1. Preventive measures
[0198] Establish a perfect security assessment mechanism, regularly conduct security vulnerability scanning and penetration testing on the system, which can detect and repair security hazards in a timely manner; implement a defense-in-depth strategy, deploy multiple security protection measures at different levels, which can effectively reduce the risk of single-point protection failure; establish a security configuration baseline and conduct regular compliance checks to ensure that the system always maintains a secure configuration state.
[0199] 2. Continuous monitoring plan
[0200] Deploy an advanced threat detection system that can identify complex attack patterns and abnormal behaviors. Among them, such a system should possess machine learning capabilities to adapt to evolving threats; establish a comprehensive log collection and analysis mechanism to ensure that all important system activities are recorded and analyzed, which helps with retrospective and analysis after the fact; implement 7×24-hour security monitoring and equip a professional security analysis team to ensure that security incidents can be detected and responded to in a timely manner.
[0201] 3. Security construction suggestions
[0202] Formulate a complete security plan, including a technology roadmap and an investment plan, to ensure the orderly progress of security construction; establish a security management system to clarify the responsibilities and work processes of all parties, which helps improve the efficiency and effectiveness of security management; maintain cooperation with security vendors and professional institutions to obtain the latest threat intelligence and protection suggestions in a timely manner, enabling better response to new security challenges.
[0203] Based on the power monitoring system security analysis method provided in the embodiments of the present application above, correspondingly, the embodiments of the present application also provide a power monitoring system security analysis system, as Figure 3 shown. This power monitoring system security analysis system includes:
[0204] An attack type recognition unit 31, configured to obtain attack chain data of the power monitoring system and identify the attack type of each attack event in the attack chain data;
[0205] An extraction unit 32, configured to extract corresponding attack data from the attack chain data; wherein the attack data includes at least an attack summary and the attack process of each attack event, and the attack summary includes multiple attack characteristics;
[0206] A security analysis unit 33, configured to input the attack summary, the attack process of each attack event, and each pre-set disposal plan into an intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event, and each pre-set disposal plan; wherein the disposal information includes at least the threat level suffered by the power monitoring system, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0207] The specific principles and execution processes of each unit in the power monitoring system security analysis system disclosed in the embodiments of the present application above are the same as those of the power monitoring system security analysis method disclosed in the embodiments of the present application above. For details, reference can be made to the corresponding parts of the power monitoring system security analysis method disclosed in the embodiments of the present application above, which will not be elaborated here.
[0208] The present application provides a security analysis method, system, electronic device and storage medium for a power monitoring system. By obtaining attack chain data of the power monitoring system and identifying the attack types of each attack event in the attack chain data; extracting corresponding attack data from the attack chain data; wherein the attack data at least includes an attack summary and the attack process of each attack event, and the attack summary includes multiple attack characteristics; inputting the attack summary, the attack process of each attack event and each pre-set disposal plan into an intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event and each pre-set disposal plan; wherein the disposal information at least includes the threat level suffered by the power monitoring system, the number of matching plans, the recommended response time limit and at least one target disposal plan. The technical solution provided by the present application does not require manual intervention, can effectively avoid the uneven security analysis capabilities of the power monitoring system caused by the difficulty of quickly replicating and inheriting expert experience, and the low accuracy of the security analysis of the power monitoring system due to the difficulty of coping with new attack means relying on expert experience. It can not only quickly realize the security analysis of the power monitoring system, but also meet the real-time protection requirements of large-scale power monitoring systems.
[0209] Optionally, the attack type recognition unit includes:
[0210] The attack chain data acquisition unit is used to acquire the attack chain data of the power monitoring system, wherein the attack chain data includes multiple attack events, an attack link diagram, affected asset information and attack technical characteristics;
[0211] The attack type recognition subunit is used to determine the attack type of each attack event according to the attack link, the affected asset information and the attack technical characteristics.
[0212] Optionally, the extraction unit includes:
[0213] The attack process extraction unit is used to analyze the attack chain data for each attack event to extract the attack process of the attack event from the attack chain data;
[0214] The attack summary generation unit is used to analyze the attack processes of each attack event to extract multiple attack characteristics from the attack processes of each attack event and generate a corresponding attack summary according to each attack characteristic.
[0215] Optionally, the security analysis unit includes:
[0216] The prompt word generation unit is used to generate corresponding prompt words according to the attack summary, the attack process of each attack event and each pre-set disposal plan, and input the prompt words into the intelligent agent;
[0217] The first security analysis subunit is used to determine the threat level and recommended response time limit of the power monitoring system through an intelligent agent according to the attack process of each attack event and the network threat level standard;
[0218] The second security analysis subunit is used to obtain the context information of each attack event through an intelligent agent, and calculate the relevance between each disposal plan and the attack summary according to the attack summary, the context information of each attack event, and each disposal plan. At least one target disposal plan is selected from each disposal plan according to the relevance of each disposal plan;
[0219] The third security analysis subunit is used to determine the corresponding number of matching plans through an intelligent agent according to at least one target disposal plan, and generate corresponding disposal information according to the threat level, the number of matching plans, the recommended response time limit, and at least one target disposal plan.
[0220] Optionally, the power monitoring system security analysis system provided in the embodiment of the present application further includes:
[0221] The security analysis report generation unit is used to generate a corresponding security analysis report through an intelligent agent according to the attack type of each attack event, the attack process of each attack event, and each target disposal plan.
[0222] The present application also provides a storage medium, in which program instructions are stored. When the program instructions are loaded and executed by a processor, the embodiments of any one of the above program automatic debugging methods are implemented.
[0223] The present application also provides an electronic device, as Figure 4 shown. The electronic device includes a processor 401 and a memory 402, and the processor and the memory are connected through a communication bus; the processor and the memory are connected through a communication bus; wherein, the processor is used to call and execute the program stored in the memory; the memory is used to store the program, and the program is used to implement any one of the above SFC program automatic debugging methods.
[0224] The processor of the present application may be the CPU of the terminal, or, an MCU integrated in the terminal, or, may also be a combination of the CPU and the MCU; moreover, the processor includes a kernel, and the kernel retrieves the corresponding program from the memory, and one or more kernels may be set.
[0225] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.
[0226] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for a system or system embodiment, since it is basically similar to a method embodiment, the description is relatively simple, and reference can be made to the relevant part of the method embodiment for the relevant content. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.
[0227] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0228] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0229] The above is only the preferred embodiment of this application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A method for safety analysis of a power monitoring system, characterized in that: The method comprises: Acquire attack chain data on the power monitoring system, and identify the attack type of each attack event in the attack chain data; Extracting corresponding attack data from the attack chain data; wherein the attack data at least includes an attack summary and an attack process of each attack event, and the attack summary includes a plurality of attack features; The attack summary, the attack process of each attack event and the pre-set disposal plans are input into the intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event and the pre-set disposal plans; wherein the disposal information at least includes the threat level of the power monitoring system, the number of matching plans, the recommended response time limit and at least one target disposal plan.
2. The method according to claim 1, characterized in that The acquiring of attack chain data on the power monitoring system and identifying the attack type of each attack event in the attack chain data includes: Acquire attack chain data on the power monitoring system, wherein the attack chain data includes multiple attack events, attack chain diagrams, affected asset information, and attack technical features; The attack type of each of the attack events is determined according to the attack link, the affected asset information and the attack technical characteristics.
3. The method according to claim 1, characterized in that: The extracting corresponding attack data from the attack chain data includes: For each of the attack events, analyzing the attack chain data to extract the attack process of the attack event from the attack chain data; The attack process of each of the attack events is analyzed to extract a plurality of attack features from the attack process of each of the attack events, and a corresponding attack summary is generated according to each of the attack features.
4. The method according to claim 1, characterized in that: The attack summary, the attack process of each attack event and each preset disposal scheme are input into the intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event and each preset disposal scheme, including: Generate corresponding prompt words according to the attack summary, the attack process of each attack event and each pre-set disposal plan, and input the prompt words into the intelligent agent; Determining the threat level and recommended response time limit of the power monitoring system according to the attack process of each attack event and the network threat level standard by the intelligent agent; Obtaining the context information of each of the attack events through the agent, and calculating the correlation between each of the disposal solutions and the attack summary according to the attack summary, the context information of each of the attack events and each disposal solution, and selecting at least one target disposal solution from each of the disposal solutions according to the correlation of each of the disposal solutions; The intelligent agent determines the corresponding number of matching solutions according to at least one of the target disposal solutions, and generates corresponding disposal information according to the threat level, the number of matching solutions, the recommended response time limit and at least one of the target disposal solutions.
5. The method according to claim 1, characterized in that The method further comprises: The intelligent agent generates a corresponding security analysis report according to the attack type of each attack event, the attack process of each attack event and each target disposal plan.
6. A power monitoring system safety analysis system, characterized in that: The system comprises: An attack type identification unit, used to obtain attack chain data on the power monitoring system and identify the attack type of each attack event in the attack chain data; An extraction unit, configured to extract corresponding attack data from the attack chain data; wherein the attack data at least includes an attack summary and an attack process of each attack event, and the attack summary includes a plurality of attack features; The security analysis unit is used to input the attack summary, the attack process of each attack event and the pre-set disposal solutions into the intelligent agent, so that the intelligent agent generates corresponding disposal information according to the attack summary, the attack process of each attack event and the pre-set disposal solutions; wherein the disposal information at least includes the threat level of the power monitoring system, the number of matching solutions, the recommended response time limit and at least one target disposal solution.
7. The system according to claim 6, characterized in that The attack type identification unit includes: An attack chain data acquisition unit, used to acquire attack chain data on the power monitoring system, wherein the attack chain data includes multiple attack events, attack chain diagrams, affected asset information and attack technology features; The attack type identification subunit is used to determine the attack type of each of the attack events according to the attack link, the affected asset information and the attack technical characteristics.
8. The system according to claim 6, characterized in that The extraction unit comprises: an attack process extraction unit, configured to analyze the attack chain data for each of the attack events, so as to extract the attack process of the attack event from the attack chain data; The attack summary generating unit is used to analyze the attack process of each of the attack events to extract multiple attack features from the attack process of each of the attack events, and generate a corresponding attack summary according to each of the attack features.
9. An electronic device, characterized in that: include: A processor and a memory, wherein the processor and the memory are connected via a communication bus; wherein the processor is used to call and execute a program stored in the memory; The memory is used to store a program, and the program is used to implement the power monitoring system safety analysis method as described in any one of claims 1-5.
10. A storage medium, characterized in that: The storage medium stores computer executable instructions, and the computer executable instructions are used to execute the power monitoring system security analysis method as described in any one of claims 1-5.