Power system safety assessment method and device, electronic equipment and storage medium

By building a network security assessment knowledge graph and using historical data for keyword and semantic extraction, the problem of inefficient data retrieval in power system security assessment is solved, and more efficient security assessment is achieved.

CN120069668APending Publication Date: 2025-05-30ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510149035.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the power system security assessment, the evaluation efficiency is inefficient due to the need to search data in a large number of messy cyberattack-related data.

Method used

By obtaining historical network attack data and historical security detection and evaluation data of the power system, keyword extraction and semantic extraction are carried out, and network security evaluation knowledge graph is built, so as to quickly obtain security detection and evaluation data of current network attack behavior and conduct power system security evaluation.

Benefits of technology

It improves the efficiency of power system safety assessment, reduces the time to search in large amounts of data, and achieves faster and more accurate safety assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120069668A_ABST
    Figure CN120069668A_ABST
Patent Text Reader

Abstract

The invention discloses a power system safety assessment method and device, electronic equipment and a storage medium, and the method comprises the steps: carrying out the keyword extraction of a historical safety assessment report and a historical safety detection report of a power system, obtaining a corresponding first keyword set and a second keyword set, and carrying out the mapping association, corresponding keyword association relationship characteristics are obtained; performing semantic extraction on the historical security assessment report to obtain corresponding key semantic information; semantic keywords in the key semantic information are extracted, association is established between the feature keyword with the maximum similarity and the semantic keywords, and a corresponding association data set is generated; and constructing a corresponding network security assessment knowledge graph according to the associated data set, and obtaining security detection assessment data corresponding to the current network attack behavior to perform power system security assessment so as to obtain a corresponding power system security assessment result. According to the invention, the safety evaluation efficiency of the power system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system security monitoring, and in particular, to a power system security assessment method, device, electronic device, and storage medium. Background Art

[0002] A power system generally consists of multiple power control devices. The power control devices will conduct network communication with each other, and the power control devices will also communicate with the outside world and perform data interaction through Internet technology. Therefore, there may be a certain probability of network security attacks on the power system.

[0003] In the prior art, for the possible network attack behaviors in the power system, generally, a network firewall is set up to intercept the network attacks, and a network attack analysis tool is used to specifically analyze the network attack characteristics of the network attack behavior. Then, based on the network attack characteristics, a deep network is used to identify the specific network attack behavior. Subsequently, a security assessment of the power system is performed, and finally, targeted network attack defenses are implemented on the power system according to the security assessment results.

[0004] However, when performing a security assessment of the power system based on the identified specific network attack behavior, generally, data retrieval is performed in the system according to the identified specific network attack behavior to find relevant information about the network attack behavior, such as relevant security assessment data. Then, a power security assessment is performed based on the retrieved relevant information to obtain the corresponding security assessment result. However, due to the huge amount of network attack-related data and the large number of data types in the power system, this assessment method needs to perform data retrieval in a large amount of messy network attack-related data to find relevant data information, resulting in low assessment efficiency. Summary of the Invention

[0005] The present invention provides a power system security assessment method, device, electronic device, and storage medium to solve the technical problem that the current assessment method needs to perform data retrieval in a large amount of messy network attack-related data to find relevant data information, resulting in low assessment efficiency.

[0006] To solve the above technical problem, an embodiment of the present invention provides a power system security assessment method, including:

[0007] Obtain the historical network attack data of the power system and the corresponding historical security detection and evaluation data; wherein, the historical security detection and evaluation data includes: historical security evaluation reports and historical security detection reports; the historical security evaluation reports include: the historical network attack reasoning process, the historical network attack success rate, and the historical network attack losses of the power system; the historical security detection reports include: the hardware environment, software environment, and firewall settings of the power system when it is under historical network attacks;

[0008] Extract keywords from the historical security evaluation reports to obtain the corresponding first keyword set, and extract keywords from the historical security detection reports to obtain the corresponding second keyword set;

[0009] Map and associate the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features;

[0010] Extract semantic information from the historical security evaluation reports to obtain the corresponding key semantic information;

[0011] Extract semantic keywords from the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship features, establish an association between the feature keyword with the maximum similarity and the semantic keyword, and generate the corresponding association data set;

[0012] Use the historical network attack data and the corresponding historical security detection and evaluation data as the root nodes, use the data in the association data set as the branch nodes to construct the corresponding network security evaluation knowledge graph, then obtain the security detection and evaluation data corresponding to the current network attack behavior according to the network security evaluation knowledge graph, and perform a security evaluation of the power system based on the security detection and evaluation data to obtain the corresponding power system security evaluation result.

[0013] As a preferred solution, the step of extracting keywords from the historical security evaluation reports to obtain the corresponding first keyword set and extracting keywords from the historical security detection reports to obtain the corresponding second keyword set includes:

[0014] Input the historical security evaluation reports into a preset keyword extraction model, so that the keyword extraction model selects the words that match the historical security evaluation reports from the vocabulary according to the input historical security evaluation reports and the preset vocabulary as the first keywords corresponding to the historical security evaluation reports and outputs them, and then generates the corresponding first keyword set according to the output first keywords;

[0015] Input the historical security detection report into the keyword extraction model, so that the keyword extraction model selects words that match the historical security detection report from the vocabulary according to the input historical security detection report and the vocabulary as the second keywords corresponding to the historical security detection report and outputs them, and then generates a corresponding second keyword set according to the output second keywords.

[0016] As a preferred solution, the generation of the keyword extraction model includes:

[0017] Perform keyword marking on the corresponding security detection and evaluation data, and use the security detection and evaluation data after keyword marking as training text data;

[0018] Train a preset neural network model according to the training text data and the vocabulary to obtain the keyword extraction model.

[0019] As a preferred solution, the mapping and association of the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features includes:

[0020] Cluster the first keywords in the first keyword set to obtain the first clustering center corresponding to the first keyword set, and cluster the second keywords in the second keyword set to obtain the second clustering center corresponding to the second keyword set;

[0021] Calculate the first Euclidean distance between each first keyword in the first keyword set and the first clustering center, and then remove the first keywords in the first keyword set whose first Euclidean distance from the first clustering center is greater than the preset distance;

[0022] Calculate the second Euclidean distance between each second keyword in the second keyword set and the second clustering center, and then remove the second keywords in the second keyword set whose second Euclidean distance from the second clustering center is greater than the preset distance;

[0023] According to the first keyword set after removal and the second keyword set after removal, map and associate the first clustering center with all the second keywords in the second keyword set after removal, and map and associate the second clustering center with all the first keywords in the first keyword set after removal to obtain the corresponding keyword association relationship features.

[0024] As a preferred solution, the semantic extraction of the historical security assessment report to obtain the corresponding key semantic information includes:

[0025] Input the historical security assessment report into a preset semantic recognition model, so that the semantic recognition model performs semantic recognition on the input historical security assessment report, obtains the key semantic information corresponding to the historical security assessment report and outputs it; wherein, the key semantic information includes: network attack traffic characteristics, target vulnerability characteristics, attack inference characteristics, attack success rate characteristics, and attack loss characteristics;

[0026] Wherein, the semantic recognition model is trained by using a security assessment report with semantic annotations as input and the key semantic information corresponding to the security assessment report with semantic annotations as output on a preset neural network model.

[0027] As a preferred solution, extract the semantic keywords in the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature, establish an association between the feature keyword with the largest similarity and the semantic keyword, and generate a corresponding association data set, including:

[0028] Extract the semantic keywords in the key semantic information, and calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature;

[0029] Take the feature keyword with the largest similarity to the semantic keyword as the first similar keyword, and then index the semantic key information to the first similar keyword to generate a corresponding association data set.

[0030] As a preferred solution, use the historical network attack data and the corresponding historical security detection and assessment data as the root node, and use the data in the association data set as the tree branch nodes to construct a corresponding network security assessment knowledge graph, including:

[0031] Obtain a preset initial knowledge graph; wherein, the initial knowledge graph includes a root node and several tree branch nodes;

[0032] Fill the historical network attack data and the corresponding historical security detection and assessment data into the root node of the initial knowledge graph, and fill the data in the association data set into the tree branch nodes of the initial knowledge graph to construct a corresponding network security assessment knowledge graph.

[0033] On the basis of the above embodiments, another embodiment of the present invention provides a power system security assessment device, including: a data acquisition module, a keyword extraction module, a keyword association module, a key semantic information extraction module, an association data set generation module, and a power system security assessment module;

[0034] The data acquisition module is used to acquire the historical network attack data of the power system and the corresponding historical security detection and evaluation data; among them, the historical security detection and evaluation data includes: historical security evaluation reports and historical security detection reports; the historical security evaluation reports include: the historical network attack reasoning process, historical network attack success rate, and historical network attack losses of the power system; the historical security detection reports include: the hardware environment, software environment, and firewall settings of the power system when it is under historical network attacks.

[0035] The keyword extraction module is used to extract keywords from the historical security evaluation reports to obtain the corresponding first keyword set, and extract keywords from the historical security detection reports to obtain the corresponding second keyword set.

[0036] The keyword association module is used to map and associate the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features.

[0037] The key semantic information extraction module is used to extract semantic information from the historical security evaluation reports to obtain the corresponding key semantic information.

[0038] The associated data set generation module is used to extract semantic keywords from the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship features, establish an association between the feature keyword with the maximum similarity and the semantic keyword, and generate the corresponding associated data set.

[0039] The power system security evaluation module is used to use the historical network attack data and the corresponding historical security detection and evaluation data as the root nodes, and use the data in the associated data set as the tree branch nodes to construct the corresponding network security evaluation knowledge graph. Then, according to the network security evaluation knowledge graph, obtain the security detection and evaluation data corresponding to the current network attack behavior, and perform power system security evaluation according to the security detection and evaluation data to obtain the corresponding power system security evaluation result.

[0040] Based on the above embodiments, another embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power system security evaluation method described in the above embodiments of the present invention.

[0041] Based on the above embodiments, another embodiment of the present invention provides a storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute the power system security evaluation method described in the above embodiments of the present invention.

[0042] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0043] The present invention provides a method for power system security assessment, which obtains historical network attack data of the power system and corresponding historical security detection and assessment data; wherein, the historical security detection and assessment data includes: historical security assessment reports and historical security detection reports; keyword extraction is performed on the historical security assessment reports to obtain corresponding first keyword sets, and keyword extraction is performed on the historical security detection reports to obtain corresponding second keyword sets; keywords in the first keyword sets are mapped and associated with keywords in the second keyword sets to obtain corresponding keyword association relationship features; semantic extraction is performed on the historical security assessment reports to obtain corresponding key semantic information; semantic keywords in the key semantic information are extracted, and the similarity between the semantic keywords and each feature keyword in the keyword association relationship features is calculated, and the feature keyword with the largest similarity is associated with the semantic keyword to generate corresponding associated data sets; the historical network attack data and corresponding historical security detection and assessment data are used as root nodes, and the data in the associated data sets are used as branch nodes to construct a corresponding network security assessment knowledge graph.

[0044] Compared with the prior art for data retrieval in a large amount of messy network attack-related data, the present invention obtains historical network attack data of the power system and corresponding historical security detection and assessment data, performs keyword extraction processing on the historical security detection and assessment data, extracts key semantic information from the historical security assessment data, and constructs a corresponding network security assessment knowledge graph according to the construction method of the knowledge graph using the extracted keywords and key semantic information. Then, according to the network security assessment knowledge graph, the security detection and assessment data corresponding to the current network attack behavior can be quickly obtained, and then the power system security assessment can be performed according to the security detection and assessment data to obtain the corresponding power system security assessment result. Through the present invention, the security detection and assessment data corresponding to the current network attack behavior can be quickly obtained, improving the security assessment efficiency of the power system. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a schematic flowchart of a method for power system security assessment provided by an embodiment of the present invention;

[0046] Figure 2 is a schematic structural diagram of a power system security assessment device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following will describe the technical solutions in this application clearly and completely in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without making creative efforts fall within the scope of protection of this application.

[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the description of the specification, claims, and above-mentioned drawings of this application are intended to cover non-exclusive inclusion.

[0049] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order, or primary-secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "a plurality" is more than two, unless otherwise specifically defined.

[0050] Referring to "embodiments" herein means that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appearing in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0051] In the description of the embodiments of this application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this text generally represents an "or" relationship between the associated objects before and after.

[0052] In the description of the embodiments of this application, the term "a plurality" refers to more than two (including two). Similarly, "a plurality of groups" refers to more than two groups (including two groups), and "a plurality of pieces" refers to more than two pieces (including two pieces).

[0053] In the description of the embodiments of the present application, unless otherwise clearly defined and limited, technical terms such as "installation", "connection", "linkage", "fixation" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to specific circumstances.

[0054] Embodiment 1

[0055] Please refer to Figure 1 , which is a schematic flowchart of a power system security assessment method provided by an embodiment of the present invention, including the following specific steps:

[0056] S1. Obtain the historical network attack data of the power system and the corresponding historical security detection and evaluation data; wherein, the historical security detection and evaluation data includes: historical security assessment reports and historical security detection reports; the historical security assessment reports include: the historical network attack reasoning process, historical network attack success rate, and historical network attack losses of the power system; the historical security detection reports include: the hardware environment, software environment, and firewall settings of the power system when it is under historical network attacks.

[0057] Specifically, through the extraction and processing of the historical data of security requirements in the storage database of the power system set, the security detection and evaluation data corresponding to the security detection and evaluation during the network attacks of the power system in the past period of time is obtained. Generally, the security detection and evaluation data includes security assessment reports and security detection reports; generally, the security assessment report is a report generated according to the corresponding evaluation template, which is obtained by using the network vulnerabilities, network attack conditions, and network attack methods in the network attack when the power system is under the network attack formed by network traffic data, and by performing correlation analysis on the key attack attributes such as network vulnerabilities, network attack conditions, and network attack methods (after obtaining the key attack attributes such as network vulnerabilities, network attack conditions, and network attack methods, these key attack attributes are associated and analyzed in the way of prior experience to analyze the network attack reasoning process, network attack success rate, and the losses that the network attack may bring to the power system); the security detection report is a report generated according to the corresponding report template by extracting the current hardware environment, current software environment, and current firewall settings of the power system when it is under network attacks.

[0058] S2. Extract keywords from the historical security assessment report to obtain a corresponding first keyword set, and extract keywords from the historical security detection report to obtain a corresponding second keyword set;

[0059] Preferably, the extracting keywords from the historical security assessment report to obtain a corresponding first keyword set and extracting keywords from the historical security detection report to obtain a corresponding second keyword set includes: inputting the historical security assessment report into a preset keyword extraction model, so that the keyword extraction model selects words matching the historical security assessment report from the vocabulary according to the input historical security assessment report and the preset vocabulary as the first keywords corresponding to the historical security assessment report and outputs them, and then generates a corresponding first keyword set according to the output first keywords; inputting the historical security detection report into the keyword extraction model, so that the keyword extraction model selects words matching the historical security detection report from the vocabulary according to the input historical security detection report and the vocabulary as the second keywords corresponding to the historical security detection report and outputs them, and then generates a corresponding second keyword set according to the output second keywords.

[0060] Preferably, the generation of the keyword extraction model includes: performing keyword marking on the corresponding security detection and assessment data, and using the security detection and assessment data after keyword marking as training text data; training a preset neural network model according to the training text data and the vocabulary to obtain the keyword extraction model.

[0061] Specifically, after obtaining the security detection and assessment data, it is necessary to separately extract the security assessment report and the security detection report from the security detection and assessment data, and then it is necessary to use a keyword extraction algorithm to separately extract keywords from the security assessment report and the security detection report, so as to form a first keyword set corresponding to the security assessment report and a second keyword set corresponding to the security detection report.

[0062] In a specific embodiment, the KEA++ algorithm can be used to implement keyword extraction for security assessment reports and security detection reports. First, part of the security assessment reports and security detection reports are used as training text data respectively. The security assessment reports and security detection reports in the training text data are both formed after keyword extraction and marking by experts. After obtaining the training text data, a control vocabulary needs to be constructed. The control vocabulary is the source of vocabulary for keyword marking by the KEA++ algorithm. Generally, corresponding keywords are selected from a domain-related and specific vocabulary as the keyword identifiers for the documents, that is, the keywords in network security assessment and network security detection literature information in network attacks are extracted and assigned to the control vocabulary of the corresponding sub-domains to form the corresponding control vocabulary. Generation of keywords: According to the training text data and the control vocabulary, a learning model is trained using the KAE++ algorithm (this learning model is the trained KAE++ algorithm), and then this learning model is used to perform keyword extraction processing on the security assessment reports and security detection reports respectively. The first keyword set corresponding to the security assessment report and the second keyword set corresponding to the security detection report are generated based on the extracted keywords.

[0063] Among them, the above-mentioned control vocabulary is composed of terms in a certain field. For example, in the present invention related to the field of network security technology, this control vocabulary is composed of some professional terms in the field of network security. This is to ensure that the extracted keywords conform to the relevant field, that is, the keywords extracted in the present invention conform to the field of network security technology. When extracting keywords, the security assessment reports and security detection reports are used as the input of the trained KAE++ algorithm. Then, the trained KAE++ algorithm will extract the most suitable terms in the control vocabulary for the security assessment reports and security detection reports as the corresponding topic words, and then output the corresponding document sets for the security assessment reports and security detection reports respectively according to the topic words. There are several to dozens of extracted keywords in the document sets. By manually screening the extracted keywords in the document sets, the first keyword set corresponding to the security assessment report and the second keyword set corresponding to the security detection report are formed.

[0064] S3. Map and associate the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features;

[0065] Preferably, mapping and associating the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features includes: clustering the first keywords in the first keyword set to obtain the first clustering center corresponding to the first keyword set, and clustering the second keywords in the second keyword set to obtain the second clustering center corresponding to the second keyword set; calculating the first Euclidean distance between each first keyword in the first keyword set and the first clustering center, and then removing the first keywords in the first keyword set whose first Euclidean distance from the first clustering center is greater than the preset distance; calculating the second Euclidean distance between each second keyword in the second keyword set and the second clustering center, and then removing the second keywords in the second keyword set whose second Euclidean distance from the second clustering center is greater than the preset distance; according to the first keyword set after removal and the second keyword set after removal, mapping and associating the first clustering center with all the second keywords in the second keyword set after removal, and mapping and associating the second clustering center with all the first keywords in the first keyword set after removal, to obtain the corresponding keyword association relationship features.

[0066] Specifically, first, use the clustering algorithm to cluster the keywords in the first keyword set and the keywords in the second keyword set respectively to obtain the first clustering center corresponding to the keywords in the first keyword set and the second clustering center corresponding to the keywords in the second keyword set. Then calculate the Euclidean distance between the central keyword of the first clustering center and the other keywords in the first keyword set, and perform screening processing on the keywords in the first keyword set according to this Euclidean distance, that is, remove the keywords in the first keyword set whose Euclidean distance from the central keyword is greater than the preset distance to form the screened first keyword set. For the second keyword set, also calculate the Euclidean distance between the central keyword corresponding to the second clustering center and the other keywords in the second keyword set, and then perform screening processing on the keywords in the second keyword set according to this Euclidean distance, that is, remove the keywords in the second keyword set whose Euclidean distance from the central keyword is greater than the preset distance to form the screened second keyword set. Finally, perform mapping and association processing on the keywords in the screened first keyword set and the keywords in the screened second keyword set respectively. The keyword association relationship features (here, the mapping and association is to establish a mapping association between the keywords corresponding to the clustering center in the first keyword set and all the keywords in the second keyword set in a one-to-many manner; at the same time, also establish a mapping association between the keywords corresponding to the clustering center of the second keyword set and all the keywords in the first keyword set in a one-to-many manner. Through such a mapping association, the keyword association relationship features are formed, so that the security assessment report and the security detection report corresponding to the security detection can be mapped and associated together in the form of keywords).

[0067] S4. Semantically extract the historical security assessment report to obtain corresponding key semantic information;

[0068] Preferably, the semantically extracting the historical security assessment report to obtain corresponding key semantic information includes: inputting the historical security assessment report into a preset semantic recognition model, so that the semantic recognition model performs semantic recognition on the input historical security assessment report to obtain and output the key semantic information corresponding to the historical security assessment report; wherein, the key semantic information includes: network attack traffic characteristics, target vulnerability characteristics, attack inference characteristics, attack success rate characteristics, and attack loss characteristics; wherein, the semantic recognition model is trained by using a security assessment report with semantic annotation as the input and the key semantic information corresponding to the security assessment report with semantic annotation as the output for a preset neural network model.

[0069] Specifically, it is necessary to perform semantic extraction processing on the security assessment report to extract the key semantic information corresponding to the security assessment report, that is, input the security assessment report into the semantic recognition model for semantic recognition processing to obtain the key semantic information corresponding to the security assessment report. The semantic recognition model is trained by using the security assessment report semantically annotated by experts as the training data set of the semantic recognition model, that is, the training data set is sequentially input into the semantic expression extraction network for training processing until the training converges, and then the obtained semantic recognition model. Then input the security assessment report into the semantic recognition model for semantic extraction processing to obtain the corresponding key semantic information in the security assessment report, and the key semantic information includes network attack traffic characteristics, target vulnerability characteristics, attack inference characteristics, attack success rate characteristics, and attack loss characteristics.

[0070] S5. Extract semantic keywords from the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship characteristics, establish an association between the feature keyword with the largest similarity and the semantic keyword, and generate a corresponding association data set;

[0071] Preferably, extracting semantic keywords in the key semantic information, calculating the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature, and establishing an association between the feature keyword with the largest similarity and the semantic keyword to generate a corresponding association data set, including: extracting semantic keywords in the key semantic information, and calculating the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature; taking the feature keyword with the largest similarity to the semantic keyword as the first similar keyword, and then indexing the semantic key information to the first similar keyword to generate a corresponding association data set.

[0072] Specifically, perform semantic keyword extraction processing on multiple corresponding segments of key semantic information in the security assessment report. The semantic keyword extraction here is implemented through a keyword extraction model, which is a keyword extraction model based on a graph sorting algorithm. When this keyword extraction model extracts keywords for a single article or text with less document segmentation, it can more accurately extract the corresponding keywords. Therefore, it can accurately extract the semantic keywords corresponding to each segment of the multiple segments of key semantic information in the security assessment report. (This is different from the above. The above is for the keywords corresponding to the entire security assessment report. Here, it is necessary to segment the key semantic information corresponding to the security assessment report to form multiple segments of key semantic information, and then use the corresponding keyword extraction algorithm to extract the semantic keywords corresponding to each segment of key semantic information respectively).

[0073] Then, calculate the similarity between the semantic keywords corresponding to each segment of key semantic information and the keywords in the keyword association relationship feature through a keyword similarity calculation method, so as to obtain the first similar keyword with the highest similarity in the keyword association relationship feature for the semantic keywords corresponding to each segment of key semantic information, and index the key semantic information of this segment to the first similar keyword with the highest similarity in the keyword association relationship feature to form the final knowledge graph construction data set (by indexing the semantic keywords in the keyword association relationship feature, that is, establishing an association between the key semantic information and the keyword association relationship feature through the semantic keywords. The highest similarity indicates the highest degree of association between the semantic keyword and the keyword with the highest similarity).

[0074] S6. Use the historical network attack data and the corresponding historical security detection and assessment data as the root nodes, use the data in the association data set as the branch nodes to construct a corresponding network security assessment knowledge graph, and then, according to the network security assessment knowledge graph, obtain the security detection and assessment data corresponding to the current network attack behavior, and perform a power system security assessment based on the security detection and assessment data to obtain the corresponding power system security assessment result.

[0075] Preferably, constructing a corresponding network security assessment knowledge graph with the historical network attack data and the corresponding historical security detection and assessment data as the root node and the data in the associated data set as the branch nodes includes: obtaining a preset initial knowledge graph; wherein, the initial knowledge graph includes a root node and several branch nodes; filling the historical network attack data and the corresponding historical security detection and assessment data into the root node of the initial knowledge graph, and filling the data in the associated data set into the branch nodes of the initial knowledge graph to construct a corresponding network security assessment knowledge graph.

[0076] Specifically, it is first necessary to construct an initial knowledge graph architecture, which can be a tree-like structure in this knowledge graph architecture, with a root node and other multi-level branch nodes such as secondary and tertiary nodes. Starting from the root node, the network attack data and the security detection and assessment data corresponding to the network attack data are filled into the root node; then the data in the knowledge graph construction data set are filled into other multi-level branch nodes such as secondary and tertiary nodes according to the corresponding relationships, forming a network security assessment knowledge graph corresponding to the network attack data. Then, according to the network security assessment knowledge graph, the security detection and assessment data corresponding to the current network attack behavior can be obtained, and the power system security assessment can be carried out according to the security detection and assessment data to obtain the corresponding power system security assessment result.

[0077] Embodiment 2

[0078] Please refer to Figure 2 , which is a schematic structural diagram of a power system security assessment device provided by an embodiment of the present invention. The device includes: a data acquisition module, a keyword extraction module, a keyword association module, a key semantic information extraction module, an associated data set generation module, and a power system security assessment module;

[0079] The data acquisition module is used to acquire the historical network attack data of the power system and the corresponding historical security detection and assessment data; wherein, the historical security detection and assessment data includes: a historical security assessment report and a historical security detection report; the historical security assessment report includes: the historical network attack reasoning process, the historical network attack success rate, and the historical network attack loss of the power system; the historical security detection report includes: the hardware environment, the software environment, and the firewall settings of the power system when it is under a historical network attack;

[0080] The keyword extraction module is used to extract keywords from the historical security assessment report to obtain a corresponding first keyword set, and extract keywords from the historical security detection report to obtain a corresponding second keyword set;

[0081] The keyword association module is used to map and associate the keywords in the first keyword set with the keywords in the second keyword set to obtain the corresponding keyword association relationship features;

[0082] The key semantic information extraction module is used to perform semantic extraction on the historical security assessment report to obtain the corresponding key semantic information;

[0083] The associated data set generation module is used to extract the semantic keywords in the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship features, establish an association between the feature keyword with the maximum similarity and the semantic keyword, and generate the corresponding associated data set;

[0084] The power system security assessment module is used to use the historical network attack data and the corresponding historical security detection and assessment data as the root nodes, use the data in the associated data set as the tree branch nodes to construct the corresponding network security assessment knowledge graph, and then obtain the security detection and assessment data corresponding to the current network attack behavior according to the network security assessment knowledge graph, and perform power system security assessment according to the security detection and assessment data to obtain the corresponding power system security assessment result.

[0085] It should be noted that the device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement without creative work.

[0086] Those skilled in the art can clearly understand that for the convenience and conciseness, the specific working process of the device described above can refer to the corresponding process in the foregoing method embodiment, and will not be described in detail here.

[0087] Embodiment III

[0088] Correspondingly, an embodiment of the present invention provides an electronic device, the device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the power system security assessment method described in the foregoing embodiment of the present invention.

[0089] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The device may include, but is not limited to, a processor and a memory.

[0090] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc. The processor is the control center of the device, and connects various parts of the entire device through various interfaces and lines.

[0091] Embodiment 4

[0092] Correspondingly, an embodiment of the present invention provides a storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute the power system security assessment method described in the above-mentioned embodiment of the present invention.

[0093] The memory can be used to store the computer program. The processor realizes various functions of the device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0094] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0095] The above is the preferred embodiment of the present invention. It should be pointed out that for those of ordinary skill in the art of the present technology, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A power system security assessment method, characterized in that: include: Obtain historical network attack data of the power system and corresponding historical security detection and evaluation data; wherein the historical security detection and evaluation data includes: historical security assessment report and historical security detection report; the historical security assessment report includes: historical network attack reasoning process, historical network attack success rate and historical network attack loss of the power system; the historical security detection report includes: hardware environment, software environment and firewall settings of the power system when it was subjected to historical network attacks; Perform keyword extraction on the historical security assessment report to obtain a corresponding first keyword set, and perform keyword extraction on the historical security detection report to obtain a corresponding second keyword set; Mapping and associating the keywords in the first keyword set with the keywords in the second keyword set to obtain corresponding keyword association relationship features; Performing semantic extraction on the historical security assessment report to obtain corresponding key semantic information; Extracting semantic keywords from the key semantic information, and calculating the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature, associating the feature keyword with the greatest similarity with the semantic keyword, and generating a corresponding association data set; The historical network attack data and the corresponding historical security detection and evaluation data are used as root nodes, and the data in the associated data set are used as branch nodes to construct a corresponding network security assessment knowledge graph. Then, based on the network security assessment knowledge graph, the security detection and evaluation data corresponding to the current network attack behavior is obtained, and the power system security assessment is performed based on the security detection and evaluation data to obtain the corresponding power system security assessment result.

2. The power system security assessment method according to claim 1, characterized in that: The extracting keywords from the historical security assessment report to obtain a corresponding first keyword set, and extracting keywords from the historical security detection report to obtain a corresponding second keyword set, include: Inputting the historical security assessment report into a preset keyword extraction model, so that the keyword extraction model selects a word matching the historical security assessment report from the vocabulary according to the input historical security assessment report and a preset vocabulary as a first keyword corresponding to the historical security assessment report and outputs it, and then generates a corresponding first keyword set according to the output first keyword; The historical security inspection report is input into the keyword extraction model, so that the keyword extraction model selects a word matching the historical security inspection report in the vocabulary according to the input historical security inspection report and the vocabulary as the second keyword corresponding to the historical security inspection report and outputs it, and then generates a corresponding second keyword set according to the output second keyword.

3. The power system security assessment method according to claim 2, characterized in that: The generation of the keyword extraction model includes: Keyword tagging is performed on the corresponding security detection and evaluation data, and the keyword-tagged security detection and evaluation data is used as training text data; A preset neural network model is trained according to the training text data and the vocabulary to obtain the keyword extraction model.

4. The power system security assessment method according to claim 2, characterized in that: The mapping and associating the keywords in the first keyword set with the keywords in the second keyword set to obtain corresponding keyword association relationship features includes: Clustering the first keywords in the first keyword set to obtain a first cluster center corresponding to the first keyword set, and clustering the second keywords in the second keyword set to obtain a second cluster center corresponding to the second keyword set; Calculating the first Euclidean distance between each first keyword in the first keyword set and the first cluster center, and then removing the first keywords in the first keyword set whose first Euclidean distance to the first cluster center is greater than a preset distance; Calculating the second Euclidean distance between each second keyword in the second keyword set and the second cluster center, and then eliminating the second keywords in the second keyword set whose second Euclidean distance to the second cluster center is greater than a preset distance; According to the first keyword set after elimination and the second keyword set after elimination, the first cluster center is mapped and associated with all the second keywords in the second keyword set after elimination, and the second cluster center is mapped and associated with all the first keywords in the first keyword set after elimination to obtain corresponding keyword association relationship features.

5. The power system security assessment method according to claim 1, characterized in that: The semantic extraction of the historical security assessment report to obtain corresponding key semantic information includes: Input the historical security assessment report into a preset semantic recognition model, so that the semantic recognition model performs semantic recognition on the input historical security assessment report, obtains key semantic information corresponding to the historical security assessment report and outputs it; wherein the key semantic information includes: network attack traffic characteristics, target vulnerability characteristics, attack reasoning characteristics, attack success rate characteristics and attack loss characteristics; The semantic recognition model is obtained by training a preset neural network model with the semantically annotated security assessment report as input and the key semantic information corresponding to the semantically annotated security assessment report as output.

6. The power system security assessment method according to claim 1, characterized in that: The extracting of semantic keywords from the key semantic information, calculating the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature, associating the feature keyword with the greatest similarity with the semantic keyword, and generating a corresponding association data set includes: Extracting semantic keywords from the key semantic information, and calculating similarities between the semantic keywords and each feature keyword in the keyword association relationship feature; The feature keyword with the greatest similarity to the semantic keyword is used as the first similar keyword, and then the semantic key information is indexed to the first similar keyword to generate a corresponding associated data set.

7. The power system security assessment method according to claim 1, characterized in that: The historical network attack data and the corresponding historical security detection and evaluation data are used as root nodes, and the data in the associated data set are used as branch nodes to construct a corresponding network security evaluation knowledge graph, including: Obtain a preset initial knowledge graph; wherein the initial knowledge graph includes a root node and a plurality of branch nodes; The historical network attack data and the corresponding historical security detection and evaluation data are filled into the root node of the initial knowledge graph, and the data in the associated data set are filled into the branch nodes of the initial knowledge graph to construct a corresponding network security evaluation knowledge graph.

8. A power system security assessment device, characterized in that: include: Data acquisition module, keyword extraction module, keyword association module, key semantic information extraction module, association data set generation module and power system security assessment module; The data acquisition module is used to acquire historical network attack data of the power system and corresponding historical security detection and evaluation data; wherein the historical security detection and evaluation data includes: historical security assessment report and historical security detection report; the historical security assessment report includes: historical network attack reasoning process, historical network attack success rate and historical network attack loss of the power system; the historical security detection report includes: hardware environment, software environment and firewall settings of the power system when it was subjected to historical network attacks; The keyword extraction module is used to extract keywords from the historical security assessment report to obtain a corresponding first keyword set, and to extract keywords from the historical security detection report to obtain a corresponding second keyword set; The keyword association module is used to map and associate keywords in the first keyword set with keywords in the second keyword set to obtain corresponding keyword association relationship features; The key semantic information extraction module is used to perform semantic extraction on the historical security assessment report to obtain corresponding key semantic information; The associated data set generation module is used to extract semantic keywords from the key semantic information, calculate the similarity between the semantic keywords and each feature keyword in the keyword association relationship feature, associate the feature keyword with the greatest similarity with the semantic keyword, and generate a corresponding associated data set; The power system security assessment module is used to use the historical network attack data and the corresponding historical security detection and assessment data as root nodes, and the data in the associated data set as branch nodes to construct a corresponding network security assessment knowledge graph, and then obtain the security detection and assessment data corresponding to the current network attack behavior based on the network security assessment knowledge graph, perform power system security assessment based on the security detection and assessment data, and obtain the corresponding power system security assessment result.

9. An electronic device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the power system security assessment method as claimed in any one of claims 1 to 7 when executing the computer program.

10. A storage medium, characterized in that: The storage medium includes a stored computer program, wherein when the computer program is executed, the device where the storage medium is located is controlled to execute the power system security assessment method according to any one of claims 1 to 7.