Threat monitoring and defending method suitable for high-level attack and defense confrontation

By implementing the threat monitoring and defense method of "protection, verification, perception, and block" in the industrial control system, combined with a variety of security tools and technical means, the problem of traditional defense measures being difficult to deal with high-level offensive and defense threats is solved, and comprehensive protection and real-time response to network security is achieved.

CN120074855APending Publication Date: 2025-05-30STATE GRID HEBEI ELECTRIC POWER CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411867952.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Traditional defense measures and security monitoring methods are difficult to effectively respond to high-level offensive and defensive threats, resulting in many new risks and challenges in the network security of industrial control systems.

Method used

A threat monitoring and defense method that adapts to high-level offensive and defensive confrontation is adopted to achieve comprehensive protection of network security through four aspects: "protection, verification, perception, and blocking". Specific measures include equipped with basic security tools, structural security tools, ontology security tools and data security tools, using vulnerability mining tools, penetration testing tools, offense and defense drill tools, sand table deduction tools, network security threat perception tools, cyberspace asset perception tools, multi-level blocking tools and one-click stop control tools.

Benefits of technology

Real-time monitoring, threat discovery, situation analysis and situation prediction of network security are realized, and abnormal network behaviors and security incidents can be discovered in a timely manner, respond to security threats quickly, provide threat discovery and early warning, support security decisions, and help organizations take security protection and plan responses in advance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The invention discloses a threat monitoring and defending method adapted to high-level attack and defending confrontation, which comprises the following steps: acquiring a target task, configuring a safety tool, an evaluation verification tool, a safety protection tool and a blocking tool corresponding to the target task based on the target task, and executing threat monitoring and defending operation according to the target task and the configured tools. Wherein the safety tool comprises a basic safety tool, a structure safety tool, a body safety tool and a data safety tool; the evaluation and verification tools comprise a vulnerability mining tool, a penetration test tool, an attack and defense drill tool and a sand table deduction tool; the security protection tools comprise a network security threat perception tool and a network space asset perception tool; the blocking tools comprise a multi-stage blocking tool and a one-key stop control tool; according to the invention, comprehensive guarantee of network security is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of monitoring and defense, and particularly relates to a threat monitoring and defense method adapted to high-level offensive and defensive confrontations. Background Art

[0002] At present, a relatively complete technical protection system has been established for industrial control system security protection from five aspects: physical security, structural security, ontology security, data security, and security monitoring. However, with the intensification of cyber space confrontations between countries and the development and evolution of network attack and defense technologies, the network security of industrial control systems faces many new risks and challenges. These high-level offensive and defensive confrontation threats require new monitoring and defense methods and systems to cope with, and traditional defense measures and security monitoring means are difficult to effectively respond to. Summary of the Invention

[0003] Object of the Invention: The object of the present invention is to provide a threat monitoring and defense method adapted to high-level offensive and defensive confrontations, which comprehensively guarantees network security through four aspects of "protection, verification, perception, and blocking" to solve the problems existing in the background art.

[0004] Technical Solution: A threat monitoring and defense method adapted to high-level offensive and defensive confrontations according to the present invention includes the following steps: obtaining a target task, and based on the target task, equipping security tools, evaluation and verification tools, security protection tools, and blocking tools corresponding to the target task, and performing threat monitoring and defense operations according to the target task and the equipped tools; wherein, the security tools include: basic security tools, structural security tools, ontology security tools, and data security tools; the evaluation and verification tools include: vulnerability mining tools, penetration testing tools, offensive and defensive drill tools, and sand table deduction tools; the security protection tools include: network security threat perception tools, cyber space asset perception tools; the blocking tools include: multi-level blocking tools, one-key stop and control tools; the target tasks include constructing a protection measure system and a space perception network system.

[0005] Further, the basic security tools are realized through the computer room access control system and video monitoring equipment; the structural security tools are realized through network partitioning, horizontal isolation, and longitudinal encryption measures; the ontology security tools are realized by adopting self-controlled and controllable software and hardware, trusted computing, security reinforcement, and security operation and maintenance measures; the data security tools perform encryption, desensitization, and watermarking operations on sensitive data.

[0006] Further, the vulnerability mining tools are mined by comprehensively using signature detection, content detection, threat intelligence, and machine learning; the penetration testing tools comprehensively evaluate the system security by simulating malicious attack methods; the offensive and defensive drill tools comprehensively test the monitoring and early warning and emergency response capabilities of the system through actual combat offensive and defensive operations; the sand table deduction tools simulate scenarios to evaluate the potential impact of attacks and emergency response capabilities by using offensive and defensive drill data.

[0007] Furthermore, the network security threat perception tool is as follows: First, data is collected through sensors distributed at various network nodes; the collected data is transmitted to the central processing system for merging; threat detection models are established using machine learning and data analysis techniques to identify abnormal network behaviors and potential security threats. Finally, based on the established models, decisions are made. When a security threat is detected, the system automatically issues an intelligent alarm to notify relevant personnel to take corresponding measures.

[0008] Furthermore, the merging process is to integrate data from different sensors, remove duplicate information, and form a unified data format.

[0009] Furthermore, the network space asset perception tool is as follows: Through distributed acquisition, asset scanning tools are used to comprehensively scan assets such as hardware devices, software systems, and databases in the network; after these information are merged, an asset database is established; by analyzing and modeling the asset database, the distribution, importance, and vulnerability of assets in the network space are understood; based on the results of asset perception, security protection strategies are formulated.

[0010] Furthermore, the multi-level blocking tool cuts off the spread of threats in different range areas by using the method of blocking network communication layer by layer; the one-key stop and control tool only closes the control and adjustment instructions of the power industrial control system while maintaining the data acquisition function.

[0011] A threat monitoring and defense system adapted to high-level attack and defense confrontation according to the present invention includes: An acquisition module: used to acquire target tasks including constructing a protection measure system and a space perception network system; A tool module: Based on the target tasks, security tools, evaluation and verification tools, security protection tools, and blocking tools corresponding to the target tasks are equipped. The security tools include: basic security tools, structural security tools, ontological security tools, and data security tools; the evaluation and verification tools include: vulnerability mining tools, penetration testing tools, attack and defense drill tools, and sand table deduction tools; the security protection tools include: network security threat perception tools, network space asset perception tools; the blocking tools include: multi-level blocking tools, one-key stop and control tools; An execution module: used to perform threat monitoring and defense operations according to the target tasks and the equipped tools.

[0012] Furthermore, in the tool module, the basic security tools are implemented through the computer room access control system and video surveillance equipment; the structural security tools are implemented through network partitioning, horizontal isolation, and vertical encryption measures; the ontology security tools are implemented by adopting self - controllable software and hardware, trusted computing, security reinforcement, and security operation and maintenance measures; the data security tools perform encryption, desensitization, and watermarking operations on sensitive data.

[0013] Furthermore, in the tool module, the vulnerability mining tools are mined by comprehensively using signature detection, content detection, threat intelligence, and machine learning; the penetration testing tools comprehensively evaluate the system security by simulating malicious attack methods; the attack - defense drill tools comprehensively test the monitoring, early warning, and emergency response capabilities of the system by implementing actual combat attack and defense; the sand table deduction tools simulate scenarios to evaluate the potential impact of attacks and emergency response capabilities by using attack - defense drill data.

[0014] Furthermore, in the tool module, the network security threat perception tools are as follows: First, data is collected through sensors distributed at various network nodes; the collected data is transmitted to the central processing system for merging; threat detection models are established using machine learning and data analysis techniques to identify abnormal network behaviors and potential security threats. Finally, based on the established models, decisions are made. When a security threat is detected, the system automatically issues an intelligent alarm to notify relevant personnel to take corresponding measures. The merging process is to integrate data from different sensors, remove duplicate information, and form a unified data format.

[0015] Furthermore, in the tool module, the network space asset perception tools are as follows: Through distributed collection, asset scanning tools are used to comprehensively scan assets such as hardware devices, software systems, and databases in the network; after these information are merged, an asset database is established; by analyzing and modeling the asset database, the distribution of assets, the importance, and vulnerability of assets in the network space are understood; based on the results of asset perception, security protection strategies are formulated.

[0016] Furthermore, in the tool module, the multi - level blocking tools cut off the spread of threats in different range areas by using the method of blocking network communication layer by layer; the one - key stop - control tool only closes the control and adjustment instructions of the power industrial control system while maintaining the data collection function.

[0017] An electronic device according to the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, it implements any one of the threat monitoring and defense methods for adapting to high - level attack - defense confrontation.

[0018] A storage medium according to the present invention stores a computer program, and when the computer program is executed by a processor, it implements any one of the threat monitoring and defense methods adapted to high-level offensive and defensive confrontations.

[0019] Beneficial effects: Compared with the prior art, the present invention has the following remarkable advantages: Real-time monitoring. By real-time monitoring of network traffic, log data, etc., network abnormal behaviors and security incidents can be discovered in a timely manner, and security threats can be quickly responded to.

[0020] Threat discovery. Analyze abnormal traffic, attack behaviors, etc. in the network, identify potential security threats, and provide threat discovery and early warning. Situation analysis. Analyze security incidents and vulnerabilities in the network to provide data support for security decision-making. Situation prediction. Based on historical data and trend analysis, predict possible future security threats and risks, and help organizations make early security protection and contingency plans. Description of the Drawings

[0021] Figure 1 It is the overall schematic diagram of the present invention; Figure 2 It is the three-dimensional schematic diagram of the protection principle of the present invention; Figure 3 It is the three-dimensional schematic diagram of the verification principle of the present invention; Figure 4 It is the sensing schematic diagram of the present invention. Detailed Embodiments

[0022] The technical solution of the present invention will be further described below with reference to the drawings.

[0023] As Figures 1-4 shown, an embodiment of the present invention provides a threat monitoring and defense method adapted to high-level offensive and defensive confrontations, including the following steps: S1 Obtain the target task, including constructing a protection measure system and a space perception network system; S2 Based on the target task, equip security tools corresponding to the target task, including: Basic security tools are mainly implemented through means such as the computer room access control system and video monitoring equipment. The computer room access control system adopts advanced identity recognition technologies, such as fingerprint recognition, face recognition, or card swiping recognition, etc. Only authorized personnel can enter the computer room. At the same time, the video monitoring equipment conducts full-range real-time monitoring of all corners of the computer room, records the entry and exit of personnel and the activities in the computer room. Once an unauthorized person attempts to enter the computer room, the system will immediately issue an alarm and notify relevant personnel for handling. Through these measures, key prevention is carried out on unauthorized personnel entering the business premises at the physical level, providing reliable physical security for the network and business systems.

[0024] Structural security tools are mainly achieved through measures such as network partitioning, horizontal isolation, and vertical encryption. First, according to business requirements and security levels, the network is divided into different regions. Each region is independent of each other and is managed through strict access control policies. Horizontal isolation uses professional isolation devices such as firewalls and network gates to prevent illegal access and data transmission between different regions. Vertical encryption is to establish an encrypted channel between the upper and lower level networks to ensure the security of data transmission. Through the above measures, grid-like partition protection at the network level is achieved, effectively reducing the risk of threats spreading and ensuring the stability and security of the network structure.

[0025] Ontological security tools mainly enhance the endogenous security capabilities of business systems by adopting measures such as self-controlled software and hardware, trusted computing, security reinforcement, and security operation and maintenance. In terms of software and hardware, products independently developed and produced are preferred first to reduce dependence on foreign technologies and lower potential security risks. Trusted computing technology establishes a root of trust at the hardware level to verify the integrity of the system startup process and ensure the security of the system. Security reinforcement includes vulnerability scanning and repair of operating systems, databases, and applications, strengthening user identity authentication and access control, and setting security policies, etc. Security operation and maintenance is to establish a perfect operation and maintenance management system, regularly conduct security inspections and maintenance on business systems, and discover and handle security problems in a timely manner.

[0026] Data security tools mainly ensure the security of data throughout its life cycle by performing operations such as encrypting, desensitizing, and watermarking sensitive data. Encryption technology uses advanced encryption algorithms to encrypt and store sensitive data during transmission to prevent data from being illegally stolen and tampered with. Desensitization technology is to process sensitive data, remove or replace key information in it, so as to protect the privacy of data without affecting business use. Watermarking technology is to embed specific identification information in the data so that it can be traced back in case of data leakage. At the same time, strict security management is carried out for each link of data collection, storage, use, processing, transmission, provision, and disclosure, and detailed security policies and operating procedures are formulated to ensure the effective protection of data throughout its life cycle.

[0027] Evaluation and verification tools include: vulnerability mining tools, which comprehensively utilize various technologies such as signature detection, content detection, threat intelligence, and machine learning. During the signature detection process, in-depth analysis is carried out on the specific structures, code patterns, etc. of software and hardware. For example, for specific function call sequences of software and specific communication protocol formats of hardware, etc., are identified. Once a situation inconsistent with the normal mode is found, there may be a vulnerability. Content detection focuses on the specific code content and configuration files of software and hardware. By performing static analysis on the code, potential vulnerabilities such as possible logical errors and buffer overflows are searched for. At the same time, the configuration files are reviewed to ensure the rationality and security of the configuration parameters. The utilization of threat intelligence is mainly through cooperation with professional security intelligence agencies to timely obtain the latest vulnerability information globally. These intelligence are compared with the objects to be detected to quickly locate possible known vulnerabilities. Machine learning technology plays an important role in vulnerability mining. By learning a large number of known vulnerability samples, a vulnerability identification model is established. This model can automatically analyze new software and hardware and identify unknown vulnerability patterns, greatly improving the efficiency and accuracy of vulnerability mining.

[0028] Penetration testing tools: In terms of penetration testing, it aims to simulate malicious attack methods to comprehensively evaluate the system security. First, clarify the test objectives and scope, covering all levels of the network architecture, different types of servers, and various applications. For the network architecture, analyze its topology, routing settings, access control lists, etc. to determine possible attack paths. For servers, including physical servers and virtual servers, check the operating system version, open port services, user permission settings, etc. For applications, review their code quality, input-output verification mechanisms, database connection methods, etc. Then, various attack means are used for testing. In terms of vulnerability exploitation, actual attacks are attempted against the discovered vulnerabilities to verify the exploitable nature of the vulnerabilities. Password cracking uses methods such as brute force cracking and dictionary attacks to attempt to obtain user passwords. Social engineering attacks include phishing emails, impersonation, etc. to try to deceive users into obtaining sensitive information. During the testing process, every step and result of the attack are detailedly recorded. Analyze whether the attack successfully breaks through the system defense line to determine the severity of the vulnerability. After the testing is completed, a detailed test report is generated, clearly listing the discovered vulnerabilities, attack paths, and specific repair suggestions, providing a strong basis for the security improvement of the system.

[0029] The attack and defense drill tool comprehensively tests the network security protection, monitoring and early warning, and emergency response capabilities through the implementation of actual combat attacks and defenses. During the drill, the attacker and the defender are strictly divided. The attacker simulates real hacker attack methods, including network attacks, system intrusions, data theft, etc. Various attack tools and techniques, such as vulnerability scanners, penetration testing tools, malware, etc., are used to try to break through the network security defense line of the defender. The defender uses various security protection equipment and technologies to conduct real-time monitoring and early warning. Deploy intrusion detection systems, firewalls, security audit systems, etc., conduct real-time analysis of network traffic, system logs, etc., and detect abnormal behaviors in a timely manner. Once an attack is discovered, the emergency response plan is immediately activated. The emergency response plan includes measures such as cutting off the attack source, restoring the damaged system, and protecting key data. During the drill, the effectiveness of protection measures and the timeliness of emergency response are continuously evaluated, and lessons learned are summarized in a timely manner to provide practical support for further improving network security protection capabilities.

[0030] The sandbox simulation tool uses attack and defense drill data to evaluate the potential impact of attacks and emergency response capabilities through simulated scenarios. First, the data generated during the attack and defense drill is deeply analyzed to extract key information. This information includes the methods and means of attack, the attack path, the specific circumstances of vulnerability exploitation, and the effect of emergency response. Then, a simulation scenario is constructed based on this information. Attacks of different intensities and types are simulated to predict the possible impact on the system under various circumstances. For example, the scope of data leakage, the possibility of system paralysis, the time of business interruption, etc. are evaluated. In the simulation scenario, the feasibility and effectiveness of the emergency response plan are tested. By adjusting the plan parameters and simulating different emergency response strategies, its ability to respond to attacks is evaluated. At the same time, the problems and challenges that may arise during the emergency response process are analyzed to provide a reference for further optimizing the emergency response plan. Through sandbox simulation, a scientific basis and decision-making support are provided for the continuous improvement of network security protection strategies.

[0031] Security protection tools include: Threat perception tools, which first collect data through sensors distributed at various nodes of the network. These sensors can include intrusion detection systems, firewall loggers, network traffic monitoring devices, etc. They collect various data in the network in real time, such as network traffic, system logs, user behavior, etc. The collected data is transmitted to the central processing system for merging. The merging process integrates data from different sensors, removes duplicate information, and forms a unified data format. Then, modeling is carried out using machine learning and data analysis techniques. By learning from a large amount of historical data, a threat detection model is established, which can identify abnormal network behavior and potential security threats. Finally, decisions are made based on the established model. When a security threat is detected, the system can automatically issue an intelligent alarm to notify relevant personnel to take appropriate measures.

[0032] Asset perception tools, also through the method of distributed collection, use asset scanning tools to comprehensively scan assets such as hardware devices, software systems, and databases in the network. The collected asset information includes device models, operating system versions, software application lists, open ports, etc. After merging these information, an asset database is established. Through the analysis and modeling of the asset database, the distribution of assets, the importance and vulnerability of assets in the cyberspace can be understood. Based on the results of asset perception, security protection strategies can be better formulated, key assets can be protected preferentially, and security risks can be reduced.

[0033] Blocking tools include: multi-level blocking tools, which cut off the spread of threats in different range areas by blocking network communications layer by layer. Specifically, first set up the first blocking defense line in the local network area, and through technical means such as hosts, preliminarily screen and intercept the network traffic of suspicious hosts. When the threat breaks through the first line of defense, start the second blocking mechanism to block in a larger network range, such as through subnet isolation, etc., to limit the spread range of the threat. If the threat continues to spread, it can further block at the wide area network level and isolate from the external network to ensure that the threat cannot spread to a wider area.

[0034] One-key stop and control tools, by only closing the control and adjustment instructions of the power industrial control system while maintaining the data collection function. In the face of serious security threats, in order to prevent malicious operations from causing irreparable damage to the power industrial control system, the one-key stop and control function can be quickly started. This function will immediately stop the output of the system's control and adjustment instructions, avoid malicious instructions from having an adverse impact on the industrial production process, but still be able to master the status and security situation of the system and keep the data collection function running. In this way, the running data, security logs and other information of the system can be continuously collected, providing a basis for subsequent security analysis and recovery work.

[0035] S3 performs threat monitoring and defense operations according to the target task and the equipped tools.

[0036] The embodiment of the present invention also provides a threat monitoring and defense system suitable for high-level attack and defense confrontation, including: Acquisition module: used to acquire the target task including constructing a protection measure system and a space perception network system; Tool module: Based on the target task, equip security tools corresponding to the target task, including: basic security tools, structural security tools, ontology security tools and data security tools; evaluation and verification tools include: vulnerability mining tools, penetration testing tools, attack and defense drill tools, sand table deduction tools; security protection tools include: network security threat perception tools, network space asset perception tools; blocking tools include: multi-level blocking tools, one-key stop and control tools; Among them, the basic security tools are implemented through the computer room access control system and video surveillance equipment; the structural security tools are implemented through network partitioning, horizontal isolation, and vertical encryption measures; the ontology security tools are implemented through the adoption of self - controllable software and hardware, trusted computing, security reinforcement, and security operation and maintenance measures; the data security tools perform encryption, desensitization, and watermarking operations on sensitive data. The vulnerability mining tools are mined by comprehensively using signature detection, content detection, threat intelligence, and machine learning; the penetration testing tools comprehensively evaluate the system security by simulating malicious attack methods; the attack - defense drill tools comprehensively test the monitoring, early warning, and emergency response capabilities of the system through actual combat attack and defense; the sand table deduction tools simulate scenarios to evaluate the potential impact of attacks and emergency response capabilities by using attack - defense drill data. The network security threat perception tools are as follows: First, data is collected through sensors distributed at various network nodes; the collected data is transmitted to the central processing system for merging; threat detection models are established using machine learning and data analysis techniques to identify abnormal network behaviors and potential security threats. Finally, based on the established models, decisions are made. When a security threat is detected, the system automatically issues an intelligent alarm to notify relevant personnel to take corresponding measures. The merging process is to integrate data from different sensors, remove duplicate information, and form a unified data format.

[0037] The network space asset perception tools are as follows: Through the distributed acquisition method, asset scanning tools are used to comprehensively scan assets such as hardware devices, software systems, and databases in the network; after these information are merged, an asset database is established; by analyzing and modeling the asset database, the distribution of assets, the importance, and vulnerability of assets in the network space are understood; based on the results of asset perception, security protection strategies are formulated.

[0038] The multi - level blocking tools cut off the spread of threats in different range areas by using the method of blocking network communication layer by layer; the one - key stop - control tool only closes the control and adjustment instructions of the power industrial control system while maintaining the data acquisition function.

[0039] Execution module: Used to execute threat monitoring and defense operations according to the target task and equipped tools. An embodiment of the present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, it implements any one of the threat monitoring and defense methods adapted to high - level attack - defense confrontation.

[0040] An embodiment of the present invention also provides a storage medium. The storage medium stores a computer program. When the computer program is executed by the processor, it implements any one of the threat monitoring and defense methods adapted to high - level attack - defense confrontation.

Claims

1. A threat monitoring and defense method adapted to high-level attack and defense confrontation, characterized in that: include: Obtain the target task, and based on the target task, equip the security tools, assessment and verification tools, security protection tools, and blocking tools corresponding to the target task, and perform threat monitoring and defense operations according to the target task and the equipped tools; among them, security tools include: basic security tools, structural security tools, ontology security tools, and data security tools; assessment and verification tools include: vulnerability mining tools, penetration testing tools, attack and defense drill tools, and sandbox simulation tools; security protection tools include: network security threat perception tools and cyberspace asset perception tools; blocking tools include: multi-level blocking tools and one-button stop control tools; target tasks include building a protection measures system and a space perception network system.

2. A threat monitoring and defense method adapted to high-level attack and defense confrontation according to claim 1, characterized in that: Basic security tools are implemented through the computer room access control system and video surveillance equipment; structural security tools are implemented through network partitioning, horizontal isolation and vertical encryption measures; entity security tools are implemented through the use of autonomous and controllable software and hardware, trusted computing, security reinforcement and security operation and maintenance measures; data security tools are to encrypt, desensitize and watermark sensitive data.

3. A threat monitoring and defense method adapted to high-level attack and defense confrontation according to claim 1, characterized in that: Vulnerability mining tools use a combination of feature detection, content detection, threat intelligence, and machine learning to mine vulnerabilities. Penetration testing tools simulate malicious attack methods to comprehensively assess system security. Attack and defense drill tools conduct actual attack and defense operations to comprehensively test the system's monitoring, early warning, and emergency response capabilities. Sandbox simulation tools use attack and defense drill data to simulate scenarios and assess the potential impact of attacks and emergency response capabilities.

4. The threat monitoring and defense method adapted to high-level attack and defense confrontation according to claim 1 is characterized in that: The network security threat perception tool is as follows: first, data is collected through sensors distributed at various nodes of the network; the collected data is transmitted to the central processing system for merging; machine learning and data analysis techniques are used to establish a threat detection model to identify abnormal network behavior and potential security threats. Finally, decisions are made based on the established model. When a security threat is detected, the system automatically issues an intelligent alarm to notify relevant personnel to take corresponding measures; among them, the merging process is to integrate data from different sensors, remove duplicate information, and form a unified data format.

5. The threat monitoring and defense method adapted to high-level attack and defense confrontation according to claim 1 is characterized in that: The specific cyberspace asset perception tools are as follows: through distributed collection, use asset scanning tools to conduct a comprehensive scan of hardware devices, software systems, and database assets in the network; after this information is merged, an asset database is established; through analytical modeling of the asset database, the distribution of assets in cyberspace, the importance and vulnerability of assets are understood; based on the results of asset perception, security protection strategies are formulated.

6. A threat monitoring and defense method adapted to high-level attack and defense confrontation according to claim 1, characterized in that: The multi-level blocking tool cuts off the spread of threats in different areas by blocking network communications layer by layer; the one-button shutdown tool only shuts down the control and adjustment instructions of the power industrial control system while maintaining the data collection function.

7. A threat monitoring and defense system adapted to high-level attack and defense confrontation, characterized in that: The following steps are involved: Acquisition module: used to acquire target tasks including building protection measures system and space perception network system; Tool module: Based on the target tasks, equipped with security tools, assessment and verification tools, security protection tools, and blocking tools corresponding to the target tasks; among them, security tools include: basic security tools, structural security tools, ontology security tools, and data security tools; assessment and verification tools include: vulnerability mining tools, penetration testing tools, attack and defense drill tools, and sandbox simulation tools; security protection tools include: network security threat perception tools and cyberspace asset perception tools; blocking tools include: multi-level blocking tools and one-button stop control tools; Execution module: used to perform threat monitoring and defense operations based on target tasks and equipped tools.

8. A threat monitoring and defense system adapted to high-level attack and defense confrontation according to claim 7, characterized in that: In the tool module, basic security tools are implemented through the computer room access control system and video surveillance equipment; structural security tools are implemented through network partitioning, horizontal isolation and vertical encryption measures; entity security tools are implemented through the use of autonomous and controllable software and hardware, trusted computing, security reinforcement and security operation and maintenance measures; data security tools are to encrypt, desensitize and watermark sensitive data.

9. A threat monitoring and defense system adapted to high-level attack and defense confrontation according to claim 7, characterized in that: In the tool module, the vulnerability mining tool conducts mining by comprehensively using feature detection, content detection, threat intelligence and machine learning; the penetration testing tool comprehensively evaluates the system security by simulating malicious attack methods; the attack and defense drill tool comprehensively tests the system's monitoring, early warning and emergency response capabilities by implementing actual attack and defense; the sandbox simulation tool utilizes attack and defense drill data to simulate scenarios and evaluate the potential impact of attacks and emergency response capabilities.

10. A threat monitoring and defense system adapted to high-level attack and defense confrontation according to claim 7, characterized in that: In the tool module, the network security threat perception tool is as follows: first, data is collected through sensors distributed at various nodes of the network; the collected data is transmitted to the central processing system for merging; machine learning and data analysis techniques are used to establish a threat detection model to identify abnormal network behavior and potential security threats. Finally, decisions are made based on the established model. When a security threat is detected, the system automatically issues an intelligent alarm to notify relevant personnel to take corresponding measures; among them, the merging process is to integrate data from different sensors, remove duplicate information, and form a unified data format.

11. A threat monitoring and defense system adapted to high-level attack and defense confrontation according to claim 7, characterized in that: In the tool module, the cyberspace asset perception tool is as follows: through distributed collection, use the asset scanning tool to comprehensively scan the hardware equipment, software systems, and database assets in the network; after merging this information, establish an asset database; through analytical modeling of the asset database, understand the distribution of assets in cyberspace, the importance and vulnerability of assets; based on the results of asset perception, formulate security protection strategies.

12. A threat monitoring and defense system adapted to high-level attack and defense confrontation according to claim 7, characterized in that: In the tool module, the multi-level blocking tool cuts off the spread of threats in different areas by blocking network communications layer by layer; the one-button shutdown tool only shuts down the control and adjustment instructions of the power industrial control system while maintaining the data collection function.

13. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is loaded into the processor, a threat monitoring and defense method adapted to high-level attack and defense confrontation according to any one of claims 1 to 6 is implemented.

14. A storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, a threat monitoring and defense method adapted to high-level attack and defense confrontation according to any one of claims 1 to 6 is implemented.