Safety protection method and device for power monitoring system

By adopting deep learning-based threat detection modules and distributed protection strategies in the power monitoring system, the problem of network security threats that are difficult to deal with after access to new energy stations and IoT devices is solved, efficient network threat identification and defense is achieved, and the security protection level of the system is improved.

CN120074892APending Publication Date: 2025-05-30EAST CHINA BRANCH OF STATE GRID CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510144648.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

After the power monitoring system is connected to new energy stations and IoT devices, it faces problems that are difficult to deal with in network security threats. Traditional protection strategies have problems such as lagging response and insufficient detection accuracy.

Method used

A deep learning-based threat detection module is used to analyze multi-source data, and the nodes determined by synergistic factors are used to implement protection measures to build a distributed protection strategy to deal with complex network threats.

Benefits of technology

Real-time network threat identification and defense of the power monitoring system is realized, significantly improving the system's security protection level, ensuring the safe access of new energy stations and the stable operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074892A_ABST
    Figure CN120074892A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of deep learning and the technical field of electric power, and discloses a safety protection method and device for an electric power monitoring system. The method comprises the following steps: analyzing multi-source data through a deep learning-based threat detection module, and detecting whether network threats exist or not; detecting the network flow of each node in response to the detected network threat; in response to the abnormal network traffic detected at the first node, calculating a collaboration factor between the first node and each node; and controlling the first node and the second node with the cooperation factor meeting a preset condition to execute a protection measure. According to the invention, various threats in a complex network environment can be effectively handled, the safety protection level of a power monitoring system is remarkably improved, and the safety access of a new energy station and the stable operation of a power system are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of deep learning technology and the field of electric power, and in particular, to a security protection method and device for a power monitoring system. Background Art

[0002] With the transformation of the global energy structure and the rapid development of new energy, more and more new energy power stations are connected to the power monitoring system in the power dispatching production control area. Especially in the application of the power dispatching production control area, the network security problem is becoming increasingly prominent. The distributed characteristics of new energy power stations and the diversification of Internet of Things devices significantly expand the attack surface of the power system, and the system is vulnerable to network attacks. Traditional centralized protection strategies and rule-based detection means often have problems such as lagging response and insufficient detection accuracy when dealing with complex network threats, and cannot meet the high security requirements under the background of new energy access. Summary of the Invention

[0003] In view of the above situation, embodiments of the present application provide a security protection method and device for a power monitoring system, aiming to solve the above problems or at least partially solve the above problems.

[0004] In a first aspect, embodiments of the present application provide a security protection method for a power monitoring system, the method including: analyzing multi-source data through a threat detection module based on deep learning to detect whether there is a network threat; in response to detecting a network threat, detecting the network traffic of each node; in response to detecting abnormal network traffic at a first node, calculating the cooperation factor between the first node and each node; controlling the first node and a second node whose cooperation factor meets a preset condition to execute a protection measure.

[0005] In a second aspect, embodiments of the present application further provide a security protection device for a power monitoring system, including: a first detection module, configured to analyze multi-source data through a threat detection module based on deep learning to detect whether there is a network threat; in response to detecting a network threat, a second detection module is configured to detect the network traffic of each node; a processing module, configured to calculate the cooperation factor between the first node and each node in response to detecting abnormal network traffic at the first node; a control module, configured to control the first node and a second node whose cooperation factor meets a preset condition to execute a protection measure.

[0006] In a third aspect, embodiments of the present application further provide an electronic device, including: a processor; and a memory arranged to store computer-executable instructions, the executable instructions, when executed, causing the processor to execute the steps of the first aspect above.

[0007] Fourthly, an embodiment of the present application further provides a computer-readable storage medium storing one or more programs, which, when executed by an electronic device including multiple application programs, cause the electronic device to execute the steps of the first aspect described above.

[0008] The above at least one technical solution adopted in the embodiment of the present application can achieve the following beneficial effects: Through the multi-source data integration technology, real-time monitoring of multi-dimensional data such as network traffic, device status, and new energy processing in the power monitoring system is realized. Combined with deep learning, potential network threats can be efficiently identified. When a network threat is detected, by deploying local protection modules at each node to monitor network traffic in real time, when the first node detects abnormal network traffic, the second node determined by the cooperation factor quickly responds through the cooperation mechanism and executes protection measures to prevent the attack from spreading to the entire monitoring system. The present application constructs an efficient and robust network security protection system through deep learning combined with a distributed protection strategy, which can effectively cope with various threats in a complex network environment, significantly improve the security protection level of the power monitoring system, and ensure the safe access of new energy power stations and the stable operation of the power system. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The accompanying drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0010] Figure 1 The flowchart showing the security protection method of the power monitoring system provided by the embodiment of the present application is shown;

[0011] Figure 2 The flowchart showing the acquisition of multi-source data provided by the embodiment of the present application is shown;

[0012] Figure 3 The detection comparison diagram showing the deep learning algorithm and the traditional IDS provided by the embodiment of the present application is shown;

[0013] Figure 4 The protection result diagram showing the distributed protection strategy provided by the embodiment of the present application is shown;

[0014] Figure 5 The result diagram showing the dynamic authentication and permission management mechanism provided by the embodiment of the present application is shown;

[0015] Figure 6 The protection result comparison diagram showing the protection strategy provided by the embodiment of the present application is shown;

[0016] Figure 7 The structure diagram showing the security protection device of the power monitoring system provided by the embodiment of the present application is shown;

[0017] Figure 8 The figure shows a schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific embodiments

[0018] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0019] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such use can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the term "including" and its variants should be interpreted as open-ended terms meaning "including but not limited to".

[0020] As described in the background art, with the large-scale access of new energy power stations and Internet of Things devices, the network security challenges faced by power monitoring systems are becoming increasingly severe. The diversity and distributed characteristics of new energy power stations and Internet of Things devices make it difficult for traditional centralized protection strategies to effectively respond. First, the access of new energy power stations and Internet of Things devices increases the attack surface of the system, and network attackers can use these devices as springboards to launch attacks on a larger scale. Second, these devices usually have low computing and storage capabilities and cannot run complex security protection software, increasing the overall vulnerability of the system. In addition, the uncertainty and volatility of new energy output further increase the demand for real-time monitoring and rapid response, and traditional protection technologies are difficult to meet these demands.

[0021] In addition, an Advanced Persistent Threat (APT) is a complex and covert form of cyber attack. Usually, highly skilled attackers use various means to lurk in the target system for a long time, gradually obtaining the critical data and control rights of the system. Traditional network security protection means, such as rule-based Intrusion Detection Systems (IDS) and firewalls, are difficult to detect and defend against APT attacks. First of all, APT attacks are highly customized and covert, and traditional signature matching and rule bases cannot identify their characteristics. Secondly, APT attacks usually adopt a phased and multi-means attack strategy, and traditional centralized protection systems are difficult to provide effective protection at all stages of the attack. In addition, existing protection means lack a global perspective on the attack path and attack chain, and cannot detect and block the attack chain in time when an attack occurs, resulting in the attacker being able to lurk for a long time and gradually expand its control range.

[0022] Therefore, existing research methods have obvious limitations in dealing with the network security challenges and APTs brought about by new energy access. Traditional centralized protection strategies mainly rely on static rules and predefined features, and this method is difficult to dynamically cope with the complex and changeable network environment, especially when facing distributed, persistent and unknown threats, showing great deficiencies. Existing rule-based detection means can only identify known attack features and cannot effectively cope with advanced network threats and multi-point attacks. Therefore, when the power monitoring system faces the complex network security problems brought about by new energy access, new solutions are urgently needed.

[0023] Based on this, this application proposes a security protection method for a power monitoring system.

[0024] Before introducing the embodiments of this application in detail, the theoretical background on which the solution of this application is based will be introduced first.

[0025] 1. Structure and Functional Characteristics of Power Monitoring System

[0026] The power monitoring system is an indispensable part of modern power systems, undertaking real-time monitoring and dispatching management of the entire process of power production, transmission, distribution and consumption. Its structure and functional characteristics determine the complexity of the system and the high requirements for security. The power monitoring system usually consists of multiple subsystems, including but not limited to the Supervisory Control and Data Acquisition (SCADA) system, the Energy Management System (EMS) and the Distributed Control System (DCS). These subsystems achieve real-time data transmission and processing through various communication networks and protocols. Its core functions include real-time data acquisition, status monitoring, fault diagnosis, load forecasting and optimal dispatching, etc.

[0027] 2. Structure and Functional Characteristics of Power Monitoring System

[0028] Power monitoring systems are an essential part of modern power systems, responsible for real-time monitoring and dispatching management of the entire process of power production, transmission, distribution, and consumption. Their structure and functional characteristics determine the complexity of the system and the high requirements for security. Power monitoring systems usually consist of multiple subsystems, including but not limited to data acquisition and monitoring systems (SCADA), energy management systems (EMS), and distributed control systems (DCS). These subsystems achieve real-time data transmission and processing through various communication networks and protocols. Their core functions include real-time data acquisition, status monitoring, fault diagnosis, load forecasting, and optimal dispatching, etc.

[0029] In terms of structure, power monitoring systems usually exhibit a hierarchical and distributed characteristic. The upper layer is the central control room, responsible for global monitoring and dispatching; the middle layer is the regional control center, responsible for power dispatching and management within a specific area; the lower layer is the field device layer, including various sensors, actuators, and control devices. This hierarchical structure makes the system have strong scalability and flexibility, but also increases the complexity of security management.

[0030] In terms of functional characteristics, power monitoring systems need to possess high reliability, high real-time performance, and high security. High reliability requires the system to operate stably in various complex environments to ensure the continuity and stability of power supply. High real-time performance requires the system to be able to collect and process a large amount of data in real-time and quickly respond to various emergencies. High security requires the system to be able to effectively prevent various network attacks and protect sensitive data and key equipment.

[0031] To meet the above requirements, power monitoring systems usually adopt redundant design and multi-layer protection strategies. For example, data acquisition and monitoring systems (SCADA) usually adopt dual-machine hot standby and multiple communication links to ensure that the system can still operate normally in the case of a single-point failure. The energy management system (EMS) constructs a multi-layer security protection system through means such as multi-layer firewalls and intrusion detection systems (IDS). In specific implementation, power monitoring systems also widely apply advanced control theories and algorithms, such as state estimation, optimal control, and adaptive control, etc. For example, state estimation can estimate the true state of the system by using algorithms such as the Kalman Filter based on the voltage, current, etc. data collected in real-time, thereby improving the monitoring accuracy and reliability of the system. Optimal control determines the best dispatching strategy by solving optimization problems to ensure the economy and security of the system.

[0032] In summary, the hierarchical structure and multi-functional characteristics of the power monitoring system endow it with high reliability, high real-time performance, and high security requirements, while also bringing the need to address complexity and security challenges. Against this background, this application proposes an innovative real-time security protection system for new energy access networks in response to the network security risks caused by the access of new energy power stations and the introduction of Internet of Things devices. Through multi-source data integration technology, it realizes real-time monitoring of network traffic, device status, and new energy output, and combines threat detection algorithms based on deep learning and distributed protection strategies to dynamically identify and defend against advanced persistent threats (APTs) and other complex network attacks, thereby significantly enhancing the security, robustness, and overall protection capabilities of the power monitoring system.

[0033] 2. System Security Requirements for New Energy Access and Internet of Things Devices

[0034] New energy access is characterized by uncertainty and volatility. The power generation of renewable energy such as wind energy and solar energy is significantly affected by weather conditions, making the load forecasting and scheduling of the power system complex. In addition, the large number and wide distribution of new energy access points increase the vulnerability of the system. The application of Internet of Things devices in the power monitoring system further expands the attack surface of the system. These devices are diverse, including smart meters, sensors, controllers, etc., and usually have characteristics such as limited computing power, small storage space, and diverse communication protocols, making it difficult to effectively apply traditional security protection measures.

[0035] This application proposes a system security solution that combines deep learning technology with a dynamic authentication mechanism to address the above challenges. Deep learning technology can identify potential security threat patterns by analyzing a large amount of historical data, thereby realizing real-time monitoring and early warning of the system.

[0036] To further improve the security of the system, this application introduces a dynamic authentication mechanism. Traditional static authentication methods such as passwords and fixed keys are vulnerable in the face of complex network attacks, while the dynamic authentication mechanism enhances the anti-attack ability of the system through continuously changing authentication information.

[0037] 3. Interaction Model of Information Flow and Power Flow in the Power Monitoring System

[0038] In the power monitoring system, the interaction mechanism between information flow and power flow is the core to ensure the safe and stable operation of the system. This application proposes a detailed theoretical model to describe and analyze the interaction relationship between information flow and power flow in the power monitoring system. This model can not only monitor the power flow status in real time but also efficiently manage the relevant information flow, thereby ensuring the security and stability of the system.

[0039] First, the real-time monitoring of the power flow status is the foundation of the power monitoring system. The power flow status can be collected in real time through a series of sensors and detection devices. Set the status variable of the power flow as P(t), where t represents time, and P(t) includes multiple parameters such as voltage, current, and power. The goal of real-time monitoring is to ensure that P(t) can accurately reflect the current operating condition of the power system through the data acquisition and transmission mechanism.

[0040] The management of the information flow is one of the core tasks of the power monitoring system. The main function of the information flow is to process and transmit the power flow status information to ensure that all parts of the system can work in coordination. The status of the information flow can be expressed as I(t), where I(t) includes multiple links such as data acquisition, transmission, processing, and storage. The core of information flow management lies in ensuring that I(t) can efficiently and accurately reflect the changes in P(t) through optimization algorithms and data processing technologies.

[0041] To describe the interaction mechanism between the information flow and the power flow, this application assumes that the interaction relationship between the information flow and the power flow is f(P(t), I(t)), and this function is used to describe the feedback and control mechanism of the information flow on the power flow status. Specifically, the information flow affects the power flow status through the feedback control mechanism, which can be expressed by the following formula:

[0042] P(t + 1) = P(t) + ΔP(t)

[0043] where ΔP(t) represents the change amount of the power flow status, and its value depends on the feedback control effect of the information flow. Further, ΔP(t) can be expressed as:

[0044] ΔP(t) = g(I(t), P(t))

[0045] where g(I(t), P(t)) is a function used to describe the specific influence mechanism of the information flow on the power flow status. This function can be solved through optimization algorithms to ensure the optimal control of the power flow status.

[0046] To ensure the safe and stable operation of the system, this application also proposes a set of safety and stability analysis frameworks. This framework identifies potential safety risks by monitoring and analyzing the status of the information flow and the power flow in real time, and takes corresponding control measures. Set this indicator to evaluate the safe and stable state of the system. S(t) can be expressed as:

[0047] S(t) = h(P(t), I(t))

[0048] Among them, h(P(t), I(t)) is used to comprehensively evaluate the states of power flow and information flow. Through the real-time monitoring and in-depth analysis of S(t), not only can potential security hazards in the system be accurately identified, but also the protection strategy can be dynamically adjusted according to the severity and scope of the threats, and targeted control measures can be taken, thereby effectively ensuring the security and stability of the system.

[0049] 4. Analysis of the Conduction and Diffusion Mechanisms of Cybersecurity Threats

[0050] In a power monitoring system, the conduction and diffusion mechanisms of cybersecurity threats are the key to understanding the attacker's behavior patterns and formulating effective protection strategies. In this application, each component in the power monitoring system is regarded as a node in graph theory, and the connections between nodes represent information flow and control flow. By constructing a detailed graph theory model, this application can deeply analyze the propagation paths and diffusion laws of cybersecurity threats in the system.

[0051] First, this application defines a directed graph G = (V, E), where V represents each component node in the power monitoring system, and E represents the information flow and control flow connections between these nodes. Each node v i ∈V represents a specific power monitoring device or system component, such as a sensor, a controller, a data storage unit, etc. Each edge e ij ∈E represents the information or control flow from node v i to node v j .

[0052] To describe the conduction of cybersecurity threats, this application introduces a threat propagation probability matrix P. The element p ij of matrix P represents the probability that a threat conducts from node v i to node v j . This probability can be quantified according to factors such as the connection strength between nodes, communication frequency, and security protection measures. Specifically, the definition of the P matrix is as follows:

[0053]

[0054] Among them, 0 ≤ p ij ≤ 1, and

[0055] The diffusion of cybersecurity threats in the system can be described by the state vector x(t), where the element x i (t) of x(t) represents the probability that node v i is threatened at time t. The diffusion process of the threat can be expressed by the following recurrence formula:

[0056] x(t + 1) = Px(t)

[0057] Through the iterative calculation of the above formula, the present application can accurately simulate the dynamic diffusion process of network security threats in the system, and predict the probability distribution of threats suffered by each node at different time points, providing data support and decision-making basis for formulating effective distributed protection strategies.

[0058] To further analyze the diffusion mechanism of network security threats, the present application also needs to consider the protection measures of nodes. The present application introduces a protection matrix D, and its element d i represents the protection strength of node v i . The definition of the protection matrix D is as follows:

[0059]

[0060] where 0 ≤ d i ≤ 1, and the larger the value of d i , the stronger the protection measures of node v i .

[0061] Combined with the protection matrix D, the recurrence formula for threat diffusion can be corrected as:

[0062] x(t + 1) = DPx(t)

[0063] Through the above model, the present application can quantitatively analyze the impact of different protection measures on threat diffusion, so as to formulate more effective protection strategies.

[0064] The following describes the present application in detail through specific embodiments.

[0065] Figure 1 shows a schematic flowchart of the security protection of the power monitoring system provided by the embodiment of the present application. It can be seen from Figure 1 that the present application at least includes steps S101 - S104:

[0066] Step S101: Analyze multi-source data through a threat detection module based on deep learning to detect whether there are network threats.

[0067] Among them, through multi-source data integration technology, relevant multi-dimensional data is obtained from multiple sources such as new energy power stations, Internet of Things devices, and power dispatching systems. The multi-dimensional data includes, but is not limited to, network traffic, device operating status, real-time power generation data, etc. During the data collection process, diverse data collection modules and protocols are adopted to ensure that different types and different sources of data can be synchronized and effectively integrated.

[0068] In some embodiments, after obtaining the original data, preprocess the original data, including cleaning, normalization, and feature extraction. Specifically, it includes removing redundant data, filling in missing values, and normalizing numerical features to ensure data consistency and processability. To better capture the characteristics of the original traffic, this application also uses methods of time series analysis and traffic feature aggregation to convert the original data into a format suitable for neural network processing.

[0069] In some embodiments, the threat detection module based on deep learning is a threat detection model trained based on a convolutional neural network. Abnormal sample data and normal sample data that cause network threats are collected in advance, and the convolutional neural network is trained with the abnormal sample data and normal sample data to generate a threat detection model. The preprocessed multi-source data is analyzed through the threat detection model to determine whether there are network threats in the multi-source data.

[0070] Step S102: In response to detecting a network threat, detect the network traffic of each node.

[0071] In some embodiments, in step S101, unified threat detection is performed on the global traffic facing the entire system to identify potential global security threats in the system. Step S102 focuses on distributed protection nodes, and further refines and strengthens the threat detection of specific nodes by analyzing the local traffic of each node. Steps S101 and S102 work together. Global detection provides overall situation awareness, while local node detection focuses on refining threat identification. Global detection can quickly discover system-level security threats and locate potential attack sources, but it is difficult to specifically solve minor threats on specific nodes. Node detection relies on independent detection modules for each node, which can further detail threat information and provide more accurate node-level protection based on global detection. At the same time, local node detection can also support rapid response and threat isolation for nodes, preventing attacks from spreading from nodes to the entire system and enhancing the robustness of the protection.

[0072] Since the functional positions of global detection and local detection are different and complementary. Global detection provides a preliminary perception of macro threats, while local detection supplements the deficiencies of global detection through refined analysis, further confirming the nature and specific scope of influence of threats. More importantly, local detection provides the system with independent node-level protection capabilities. Even if global detection fails, each node can still resist threats independently. This multi-level collaborative mechanism significantly improves the security and robustness of the system.

[0073] Step S103: In response to detecting abnormal network traffic at the first node, calculate the collaboration factor between the first node and each node.

[0074] In some embodiments, the distributed protection strategy not only relies on the independent threat detection of each node, but also realizes a more extensive network protection through the cooperation mechanism among nodes. When the first node detects abnormal traffic, the second node for executing the cooperation mechanism is determined by calculating the cooperation factor between the first node and each node.

[0075] Among them, the role of the cooperation factor is to quantify the cooperation protection efficiency between nodes, so as to provide an optimization basis for system design and dynamic response. The calculation formula of the cooperation factor involves the physical distance and communication delay between nodes, and the larger the value, the higher the cooperation response efficiency between nodes. In the cooperation mechanism, calculating the cooperation factor is mainly to quickly evaluate which nodes have a high linkage efficiency in terms of physical distance and communication delay, so as to preferentially rely on these nodes to achieve efficient cooperation protection. Through such a design, the system can reasonably schedule network resources according to the cooperation factor, concentrate the protection force on the nodes with higher cooperation efficiency, quickly respond to threats and take preset measures, maximizing the security and protection capabilities of the overall network. This dynamic adjustment mechanism based on the cooperation factor further strengthens the robustness of the distributed protection, enabling the system to show higher adaptability and defense effect in complex network attack scenarios.

[0076] In one implementation, the cooperation factor is calculated based on the physical distance and communication delay between the first node and each node. For example, the cooperation factor is calculated based on the following formula:

[0077]

[0078] where d ij represents the physical distance between node i and node j, and τ ij is the communication delay between them.

[0079] Step S104: Control the first node and the second node whose cooperation factor meets the preset conditions to execute the protection measures.

[0080] In some embodiments, the larger the cooperation factor, the higher the cooperation protection efficiency between nodes. In one implementation, the nodes with a cooperation factor greater than the preset value are set as the second nodes.

[0081] In some embodiments, the preventive measures taken by nodes mainly include various modular security mechanisms deployed in the distributed protection strategy, such as firewalls, intrusion detection systems (IDSs), and intrusion prevention systems (IPSs). When a node detects abnormal traffic, the node will quickly activate the local protection module to limit the scope of influence of the threat, and at the same time notify neighboring nodes to share threat information through the cooperation mechanism. After receiving the cooperation information, these adjacent nodes will also adjust their own protection status according to the threat level, such as strengthening traffic monitoring, dynamically adjusting permission management, or deploying additional security rules, so as to form a linked distributed protection strategy to prevent the threat from spreading further.

[0082] In the embodiments of the present application, through the multi-source data integration technology, the real-time monitoring of multi-dimensional data such as network traffic, device status, and new energy processing in the power monitoring system is realized. Combining deep learning, potential network threats can be efficiently identified. When a network threat is detected, by deploying local protection modules at each node to monitor network traffic in real time, when the first node detects abnormal network traffic, the second node determined by combining the cooperation factor quickly responds through the cooperation mechanism and executes protection measures to prevent the attack from spreading to the entire monitoring system. The present application constructs an efficient and robust network security protection system by combining deep learning with a distributed protection strategy, which can effectively cope with various threats in a complex network environment, significantly improve the security protection level of the power monitoring system, and ensure the safe access of new energy stations and the stable operation of the power system.

[0083] In some embodiments of the present application, in the above method, when the threat detection module based on deep learning analyzes multi-source data in step S101, the specific process is as follows: In the feature extraction stage, the convolutional neural network extracts high-order features of the input data layer by layer through multiple convolutional layers, pooling layers, and fully connected layers. Assume that the input data is a three-dimensional tensor where n is the time step, m is the feature dimension, and c is the number of channels. The convolution operation can be expressed as:

[0084]

[0085] where, Y i,j,k is the convolution output, W u,v,k,c is the convolution kernel, b k is the bias term, h and w are the height and width of the convolution kernel respectively, and C is the number of input channels. Through multi-layer convolution operations, the network can extract the spatial and temporal features of the data layer by layer.

[0086] The pooling layer is used for downsampling to reduce the size of the feature map, thereby reducing the computational complexity and preventing overfitting. Common pooling operations include max pooling and average pooling, which are defined as follows:

[0087]

[0088] or

[0089]

[0090] Finally, the extracted feature maps are mapped to the classification space through the fully connected layer, and the Softmax function is used for classification to output the probability of each category. The Softmax function is defined as:

[0091]

[0092] where z i is the output of the fully connected layer, and K is the number of categories. By maximizing the log-likelihood function, the network parameters can be optimized through the backpropagation algorithm.

[0093] In the model training stage, the present application uses the cross-entropy loss function as the optimization objective, which is defined as:

[0094]

[0095] where N is the number of samples, K is the number of categories, y ij is the true label, is the predicted probability. Through the gradient descent algorithm, the network parameters are continuously updated, and finally an efficient deep learning model that can accurately distinguish normal traffic from attack traffic is obtained, providing strong technical support for real-time network threat detection.

[0096] In the embodiment of the present application, the system inputs the preprocessed data into the designed CNN-based threat detection module. Through multi-layer convolution operations and feature extraction, the detection module can efficiently identify potential network threats in the system, including complex network attack behaviors such as APT and distributed denial of service attack (DDoS), can quickly analyze high-dimensional and dynamically changing network traffic data, and issue accurate threat warnings in a short time.

[0097] In some embodiments of the present application, in the above method, when detecting the network traffic of each node in step S102, detection is performed by deploying a local threat detection module at each node.

[0098] In some embodiments, the local threat detection module detects the network traffic of each node based on the trained convolutional neural network to identify normal network traffic and abnormal network traffic.

[0099] Through multi-layer convolution and pooling operations, the system can extract spatio-temporal features from complex multi-dimensional network traffic data to identify abnormal behaviors. The convolution operation can be expressed as:

[0100] Z (l)= f(W (l) X (l-1) + b (l) )

[0101] where \(Z^{(l)}\) is the output of the \(l\)-th layer, \(W\ (l) is the convolutional kernel of the \(l\)-th layer, \(X\ (l-1) is the input feature map, \(b\ (l) is the bias term, and \(f\) is the activation function. Through multi-layer convolution and pooling operations, the system can extract important features in the network traffic layer by layer, and perform classification judgment through the fully connected layer and the Softmax function:

[0102]

[0103] where \(P(y = j|X)\) represents the probability that the data belongs to class \(j\), and \(z\ j is the score of class \(j\). In this way, the CNN model can classify the traffic and determine whether there is a threat behavior.

[0104] In some other embodiments, in order to further improve the accuracy of threat detection, the embodiments of the present application introduce GAN to enhance the detection of abnormal traffic. That is, the local threat detection module extracts the feature vectors of the network traffic of each node based on the trained convolutional neural network, inputs the feature vectors into the trained generative adversarial network, and identifies normal network traffic and abnormal network traffic through the generative adversarial network.

[0105] The generator is responsible for generating forged traffic similar to normal traffic, while the discriminator is used to distinguish real traffic and forged traffic. During the adversarial training process, the ability of the discriminator is continuously improved, and it can more accurately identify abnormal behaviors in the network. By continuously optimizing the generator and the discriminator, the system can improve the ability to identify complex network attacks, especially to cope with attacks with high concealment such as APT.

[0106] The loss function of the generative adversarial network can be expressed as:

[0107]

[0108] where \(D(x)\) represents the judgment probability of the discriminator for real data \(x\), \(G(z)\) represents the forged data generated by the generator, \(p\ data (x)\) is the distribution of real data, and \(p\ z (z)\) is the distribution of noise data.

[0109] In the embodiments of this application, a distributed protection strategy is introduced for the detected potential threats. Local protection modules are deployed at different nodes of the system, and these modules include firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), etc. Each node can independently monitor its own network traffic and device status. Once abnormal behavior is detected, the system will immediately take protection measures to prevent the threat from spreading to the entire power monitoring network. The core of the distributed protection strategy is the collaborative working mechanism among nodes. When a certain node is attacked, other nodes can quickly perceive the threat and accordingly adjust the protection strategy to avoid the attack from further spreading through the network. This strategy effectively enhances the robustness and security of the system.

[0110] To further ensure the security of the system, the embodiments of this application also introduce a dynamic authentication mechanism. By monitoring the behavior of the access device in real time, it is confirmed whether the access device passes the security authentication. Only the access device that passes the security authentication is allowed to access the system, thereby preventing unauthorized devices from accessing the system and ensuring the overall security of the system.

[0111] In some embodiments, the legitimacy score of the access device is calculated through the behavior feature vector of the access device. If the legitimacy score of the access device is greater than the preset security threshold, it is confirmed that the access device passes the security authentication.

[0112] Specifically, assume that the behavior feature of the device is the vector x = [x 1 , x 2 , …, x m , where each x i represents a behavior feature (such as access frequency, IP address, etc.). The system calculates the legitimacy score of the device based on these features:

[0113]

[0114] where, w i is the weight of the i-th feature, and f(x i ) is the normalized feature value.

[0115] To ensure the security of authentication, this application also adopts blockchain technology to store authentication records distributively. Each device generates a pair of public and private key pairs when accessing. The private key is used to sign the message, and the public key is published on the blockchain for verification. By obtaining the public key of the access device published on the blockchain to verify the signature of the access device, it is determined whether the access device passes the security authentication.

[0116] Specifically, the signature Sig i of the access device i is expressed as:

[0117] Sig i = Sign(M, ki,priv )

[0118] Wherein, M represents the information content sent by the device to be authenticated or verified when accessing the system, including the identity identifier of the device, access request or other specific data related to the device behavior; k i,pub represents the public key of the access device.

[0119] The system verifies the signature through the public key k of the device i,pub Verify signature:

[0120] Verify(M,Sig i ,k i,pub )=True

[0121] In the embodiments of the present application, the device scoring mechanism evaluates the legitimacy of the device by performing weighted calculations on device behavior characteristics (such as access frequency, IP address, etc.); meanwhile, signature verification authenticates the device identity through blockchain technology, verifies the authenticity and integrity of the information signature Sig sent by the device, and ensures that the data has not been tampered with and the device identity is legal. These two mechanisms authenticate the device at multiple levels from two dimensions of behavior characteristics and data integrity respectively. The device can only be allowed to access the system when the behavior is legal and the signature verification passes. Through this distributed authentication method, the system can ensure the authenticity of the device identity and the integrity of data transmission, and avoid the intrusion of malicious devices.

[0122] In some embodiments of the present application, the dynamic authentication mechanism of the present application also combines role-based access control (RBAC), calculates the risk assessment coefficient of the access device based on the behavior characteristics of the access device, and adjusts the permission access level of the access device through the initial permission access level of the access device and the real-time risk assessment coefficient.

[0123] Specifically, the risk assessment score R(x) is based on the behavior characteristic vector x = [x 1 ,x 2 ,…,x m , feature weight w i and feature scoring function f(x i ), and can be expressed in the following form:

[0124]

[0125] Wherein, x i represents the i-th behavior characteristic value (such as access frequency, IP address, historical behavior record, etc.). w i represents the importance weight of the i-th behavior characteristic, and is used to represent the contribution degree of this feature to the risk assessment. f(x i) is a normalized scoring function for eigenvalues, used to map eigenvalues of different dimensions to a unified scoring interval. m represents the total number of behavioral features.

[0126] The permission adjustment formula is:

[0127] L = L 0 -β·R(x)

[0128] where L 0 is the initial permission, and β is the risk coefficient.

[0129] When the risk assessment score of the device increases, its permission level decreases accordingly, ensuring that high-risk devices cannot access sensitive resources.

[0130] In the embodiments of the present application, by introducing a multi-factor authentication mechanism and a role-based access control (RBAC) policy, it is ensured that the operations of each access device or user are legal and comply with security standards. This mechanism can not only effectively prevent external attackers from illegally intruding, but also avoid internal authorized personnel from abusing their permissions, maximizing the security of the system.

[0131] In summary, by integrating multi-source data, threat detection based on deep learning, distributed protection strategies, and dynamic authentication and permission management mechanisms, this application constructs a comprehensive and efficient network security protection system, significantly enhancing the security and robustness of the power monitoring system in complex network environments. Specifically, through multi-source data integration technology, the system realizes the unified processing of multi-dimensional data from new energy power stations, Internet of Things devices, and power dispatching systems. Test results show that when processing data streams of up to 1000 pieces per second, the system can complete real-time analysis and processing of data within 0.5 seconds. This provides a solid data foundation for the system to achieve real-time monitoring of network security and improves the overall efficiency of the system. Through the threat detection algorithm based on convolutional neural networks, this application achieves a detection accuracy of over 98% when facing APT and other complex network attacks. Test results show that the system can complete the identification and response to threats within 0.5 seconds, greatly improving the system's protection ability against sudden network security incidents. Compared with traditional rule-based detection methods, deep learning algorithms not only have high detection accuracy and low false alarm rates but also can handle various unknown threat patterns. Distributed protection strategies can significantly improve the overall security of the system. In the test, each node in the system has the ability of independent protection and collaborative response. When a node is attacked, other nodes can quickly respond to block the spread of the attack. Test data shows that the response time of the distributed protection strategy is shortened by about 30% compared with the centralized protection system, and the single-point failure risk of the system is greatly reduced. In response to multi-point attack scenarios, the system effectively improves the overall protection efficiency through the collaborative working mechanism between nodes. The protection accuracy in a multi-node environment reaches over 95%, ensuring reliable operation in complex network environments. The dynamic authentication mechanism prevents unauthorized device access and permission abuse by adjusting the access permissions of devices in real time. Compared with the traditional static permission management mode, the dynamic authentication mechanism can detect and handle security threats such as permission tampering and illegal device access more quickly. Test results show that this mechanism exhibits high security and flexibility in complex network environments, with the response time shortened to 0.3 seconds, ensuring that the system can eliminate security hazards in the shortest time.

[0132] To verify the application effect of this application in the real-time security protection system for new energy access to the power monitoring system in the dispatching production control area, tests and verifications based on specific embodiments were carried out. The test environment includes hardware configurations and software tools to ensure the comprehensiveness and accuracy of the tests.

[0133] 1. Test Environment Setup

[0134] The new energy access network security real-time protection system for the power monitoring system in the dispatching production control area is simulated and tested using the MATLAB / Simulink platform to verify the effectiveness of the control strategy and optimization algorithm. The simulation model includes main components such as a multi-source data integration and preprocessing module, a threat detection algorithm module based on deep learning (such as a convolutional neural network), a distributed protection strategy module, and a dynamic authentication and permission management module, which can truly reflect the operating characteristics and control behaviors of the new energy access network security real-time protection system for the power monitoring system in the dispatching production control area. In terms of hardware configuration, it includes an Intel Xeon Gold 6248 processor (2.5GHz), 256GB DDR4 RAM, and 1TB NVMe SSD storage. In terms of software tools, MATLAB R2021a and its Simulink module are used, and Python 3.8 is used for deep learning model training and testing, with TensorFlow 2.4 as the deep learning framework. The data acquisition frequency is 1Hz, and data preprocessing includes normalization and denoising. Threat detection module: The CNN structure has 3 convolutional layers (64 filters in each layer, filter size 3x3), 2 fully connected layers (128 neurons in each layer), the activation function is ReLU, the learning rate is 0.001, the training batch is 5000 times, and the dataset splitting ratio is 80% for the training set and 20% for the test set. Distributed protection strategy module: The independent protection ability of each node is set to a detection accuracy of 0.95, and the response time is 200ms. Dynamic authentication and permission management module: The dynamic authentication frequency is once every 5 minutes, and the permission management response time is 50ms. Through the above configuration, it is ensured that the simulation environment can comprehensively test and verify the performance and effectiveness of this application in different scenarios, providing reliable data support and theoretical basis for practical applications.

[0135] 2. Simulation Parameters

[0136] Table 1 shows the specific parameter settings of the simulation model and algorithm, including the power system model, new energy power station model, Internet of Things device model, data acquisition module, network communication module, network delay parameters, and the parameters of the threat detection algorithm, convolutional layer, pooling layer, learning rate, number of training epochs, distributed protection strategy, and authentication mechanism. These parameter settings ensure that the simulation environment can comprehensively test and verify the performance and effectiveness of this invention in different scenarios, providing reliable data support and theoretical basis for practical applications. The specific parameter settings are shown in Table 1.

[0137] Table 1 Parameter Settings of the Simulation Model and Algorithm

[0138]

[0139]

[0140] 3. Results Analysis

[0141] 3.1 Analysis of Test Results

[0142] Figure 2 It shows how the system obtains data from multiple data sources (such as new energy power stations, Internet of Things devices, and power dispatching systems) and conducts real-time monitoring and analysis through a data processing center. The advantages of this architecture lie in its comprehensiveness, real-time nature, and security. First, the system can integrate multi-dimensional data from different sources to achieve comprehensive monitoring. Second, the data processing center can process data at a rate of 1000 pieces per second, and the monitoring system can complete preliminary analysis and threat identification within 0.50 seconds. Through real-time data analysis and monitoring, the system can generate security warnings in a timely manner, enhancing the overall network security protection level. Compared with the traditional single data stream monitoring architecture, this multi-source data integration system can more effectively address the network security challenges brought by new energy access and Internet of Things devices.

[0143] Figure 3 It compares the performance of deep learning algorithms and traditional IDSs in terms of key performance indicators such as detection accuracy, false alarm rate, and response time. According to Figure 3 (a), the detection accuracies of deep learning algorithms in the scenarios of advanced persistent threat (APT) and distributed denial of service attack (DDoS) are 98.76% and 97.28% respectively, which are significantly higher than 85.48% and 80.23% of the traditional IDS. This shows that deep learning algorithms have stronger feature extraction capabilities and can effectively cope with complex network threats. Especially when facing advanced and hidden attack behaviors, their accuracy performance is particularly prominent. The detection accuracy of the traditional IDS is relatively low, especially in the DDoS attack scenario, indicating its limited ability to identify multi-source complex traffic. According to Figure 3 (b), the false alarm rates of deep learning algorithms in the APT and DDoS scenarios are 1.23% and 2.68% respectively, which are significantly lower than 14.47% and 19.81% of the traditional IDS. This result shows that deep learning algorithms can not only effectively detect attacks but also significantly reduce the false alarm rate, reduce unnecessary interference, and improve the actual operation and maintenance efficiency of the system. In contrast, the traditional IDS has a higher false alarm rate, which is likely to lead to a large number of false alarms in a complex network environment, affecting the operation and maintenance efficiency and resource allocation of the system. According to Figure 3 the last figure in, the response times of deep learning algorithms are 0.33 seconds and 0.34 seconds, while the response times of the traditional IDS are 1.24 seconds and 1.27 seconds respectively. Deep learning algorithms show a faster reaction speed in terms of detection response time, which is of great significance for dealing with real-time network attacks and reducing potential damage. The disadvantage of the traditional IDS in terms of response time indicates its slow processing speed, and it may not be able to take effective protection measures in a high-frequency and rapidly changing attack environment in a timely manner.

[0144] In summary, the threat detection algorithm based on deep learning shows significant advantages in terms of detection accuracy, false alarm rate, and response time. Especially in complex attack scenarios such as APT and DDoS, the deep learning algorithm has higher detection accuracy and system efficiency. In addition, the low false alarm rate and fast response time further prove the superiority of this algorithm in practical network security protection applications. Although traditional IDS still has certain basic protection functions, its limitations in dealing with complex network attacks have gradually emerged. Therefore, in the scenario of new energy access, the distributed protection strategy driven by deep learning will become a more forward-looking solution.

[0145] Figure 4 It shows the performance of each node in the system in terms of key performance indicators such as attack detection ability, response speed, and security strength, revealing the improvement effect of the distributed protection strategy on the security of different nodes in the power monitoring system. The attack detection ability of each node remains at a high level. The detection abilities of the wind farm, photovoltaic power station, Internet of Things device, and control center are 95.34%, 93.72%, 94.15%, and 95.98% respectively. This result indicates that the distributed protection strategy can maintain high-efficiency threat detection ability on each node. Especially the control center and the wind farm show higher detection accuracy. This advantage is particularly important in complex attack scenarios such as advanced persistent threat (APT) and distributed denial of service attack (DDoS), indicating that the system has high sensitivity. Response speed, as another key indicator, reflects the speed at which each node takes countermeasures after detecting a threat. The results show that the Internet of Things device has the fastest response speed, reaching 0.26 seconds, while the response speeds of the wind farm, photovoltaic power station, and control center are 0.31 seconds, 0.34 seconds, and 0.29 seconds respectively. The improvement in the response speed of the Internet of Things device indicates that the distributed protection strategy can effectively cope with the multi-point attack scenario of distributed devices, ensuring that the system can quickly respond to network attacks and reduce the time window for the system to be attacked. In addition, the control center and the wind farm also show good response performance, ensuring the overall response efficiency of the system. Finally, the security strengths of each node are as follows: 90.15% for the wind farm, 88.95% for the photovoltaic power station, 89.60% for the Internet of Things device, and 91.20% for the control center. Overall, the security strengths of each node remain above 88%, indicating that the system can effectively improve the anti-attack ability of each node. Especially the control center and the wind farm, as the core nodes of the system, have security strengths of 91.20% and 90.15% respectively, ensuring the security and robustness of the entire power monitoring system.

[0146] Based on the above analysis, the distributed protection strategy enhances the system's attack detection ability, response speed, and overall security strength by deploying independent protection mechanisms among nodes. Especially at key nodes such as the control center, wind farm stations, and Internet of Things devices, the system demonstrates high detection accuracy and rapid response capabilities. This distributed protection strategy can effectively cope with complex network attacks, prevent the spread of attacks, and enhance the overall protection performance of the system. Especially in the context of new energy access and the wide application of the Internet of Things, it provides a solid technical guarantee for the secure operation of the power monitoring system.

[0147] 3.2 Comparison with Other Methods

[0148] Figure 5 The security of the dynamic authentication and permission management mechanism was compared. Under different access scenarios, there are significant differences in the response time performance between the dynamic authentication mechanism and static permission management. In the normal access scenario, the response time of the dynamic authentication mechanism is 0.20 seconds, while that of the static permission management is 0.65 seconds, indicating that the dynamic authentication mechanism shows a faster authentication speed. In the illegal access scenario, the response time of the dynamic authentication mechanism is 0.15 seconds. Compared with 0.75 seconds of the static permission management, the dynamic authentication mechanism is more efficient in detecting illegal access. In the permission tampering scenario, the response time of the dynamic authentication mechanism is 0.18 seconds, significantly lower than 0.85 seconds of the static permission management, indicating that the dynamic authentication mechanism has a higher reaction speed in detecting permission tampering. Generally speaking, the dynamic authentication mechanism shows a lower response time in various access scenarios, indicating that it has faster detection and response capabilities. This mechanism has particularly significant advantages in dealing with permission tampering and illegal device access, and can prevent the access of illegal devices in a shorter time, enhancing the overall security of the system. Compared with the traditional static permission management mechanism, the dynamic authentication mechanism shows more efficient response time and detection capabilities. Especially when facing permission tampering and illegal device access, its rapid response ability makes it more advantageous in practical applications.

[0149] Figure 6The comprehensive performances of the distributed protection strategy, the adaptive firewall, and the traditional static protection strategy are compared. As a key indicator for measuring whether a protection strategy can effectively identify potential network threats, the detection accuracy shows obvious differences. The distributed protection strategy has the highest detection accuracy, reaching 95.85%, significantly better than the adaptive firewall (92.45%) and the traditional static protection (89.35%). This result indicates that the distributed protection strategy can improve the threat recognition ability in complex environments through the collaborative work of each node and dynamic adjustment of security policies. Although the adaptive firewall has a certain dynamic adaptation ability, its detection accuracy still lags behind that of the distributed strategy. Due to its fixed rule set, the traditional static protection performs poorly in the face of advanced persistent threats (APTs) and distributed denial-of-service (DDoS) attacks. Secondly, in terms of the false alarm rate, the false alarm rate of the distributed protection strategy is 2.65%, while the false alarm rates of the adaptive firewall and the traditional static protection are 4.85% and 7.10% respectively. Since the distributed protection strategy can monitor the network status of each node in real time and perform traffic analysis by combining deep learning techniques, the false alarm rate is significantly reduced. However, due to its dependence on a fixed rule set, the traditional static protection has a high false alarm rate, which may lead to a large number of false alarms and increase the burden on network administrators. The response speed reflects the response time of different strategies after detecting a threat. The response time of the distributed protection strategy is 0.28 seconds, while the response times of the adaptive firewall and the traditional static protection are 0.52 seconds and 0.78 seconds respectively. Since the distributed protection strategy adopts a distributed collaborative protection mechanism between nodes, it can quickly respond when an attack occurs, greatly reducing the delay time of threat response. Although the adaptive firewall has a certain dynamic protection ability and a relatively fast response speed, it is slightly inferior to the distributed strategy. Due to the lack of flexibility, the traditional static protection has the slowest response speed, which may lead to the inability to contain attack behaviors in a timely manner. Finally, the resource occupancy rate shows the system resource consumption of each strategy in actual applications. The resource occupancy rate of the distributed protection strategy is 19.10%, that of the adaptive firewall is 22.50%, and the resource occupancy rate of the traditional static protection is the highest, reaching 26.30%. Although the distributed protection strategy achieves higher protection performance, its resource consumption still remains at a low level, indicating that through optimizing computing resources and distributed processing capabilities, it can reduce the consumption of system resources while ensuring the protection effect.

[0150] In some embodiments of the present application, a security protection device for a power monitoring system is provided, and the security protection device for the power monitoring system corresponds one-to-one with the security protection method for the power monitoring system in the above embodiments. As Figure 7 shown, the security protection device for the power monitoring system includes: a first detection module 201, a second detection module 202, a processing module 203, and a control module 204. The detailed descriptions of each functional module are as follows:

[0151] The first detection module 201 is configured to analyze multi-source data through a threat detection module based on deep learning to detect whether there is a network threat;

[0152] In response to detecting a network threat, the second detection module 202 is configured to detect the network traffic of each node;

[0153] The processing module 203 is configured to calculate a cooperation factor between the first node and each node in response to detecting abnormal network traffic at the first node;

[0154] The control module 204 is configured to control the first node and the second nodes whose cooperation factors meet preset conditions to execute protection measures.

[0155] In some embodiments of the present application, in the above device, the second detection module 202 is specifically configured to detect the network traffic of each node based on a trained convolutional neural network to distinguish normal network traffic from abnormal network traffic; or extract feature vectors of the network traffic of each node based on a trained convolutional neural network, and input the feature vectors of the network traffic of each node into a trained generative adversarial network to identify normal network traffic and abnormal network traffic.

[0156] In some embodiments of the present application, in the above device, the processing module 203 is specifically configured to calculate a cooperation factor between the first node and each node based on the physical distance and communication delay between the first node and each node.

[0157] In some embodiments of the present application, in the above device, the processing module 203 is further configured to perform real-time monitoring on the access device to confirm whether the access device passes a security authentication; connect the access device that passes the authentication to the power grid system.

[0158] In some embodiments of the present application, in the above device, the processing module 203 is specifically configured to determine a behavior feature vector of the access device; calculate a legality score of the access device based on the behavior feature vector of the access device; if the legality score of the access device is greater than a threshold, confirm that the access device passes the security authentication.

[0159] In some embodiments of the present application, in the above device, the processing module 203 is specifically configured to obtain a public key of the access device published on the blockchain; receive a signature sent by the access device; verify the signature of the access device based on the public key to determine whether the access device passes the security authentication.

[0160] In some embodiments of the present application, in the above device, the processing module 203 is further configured to calculate a real-time risk assessment coefficient of the access device based on the behavior features of the access device; adjust the permission access level of the access device based on the initial permission access level and the real-time risk assessment coefficient.

[0161] It should be noted that the security protection devices of any of the above power monitoring systems can implement the aforementioned security protection methods of the power monitoring systems one by one, which will not be elaborated here.

[0162] Figure 8 The structural schematic diagram of an electronic device provided by an embodiment of the present application is shown. As Figure 8 shown, at the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include internal memory, such as high-speed random access memory (Random-Access Memory, RAM), and may also include non-volatile memory, such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.

[0163] The processor, network interface, and memory can be interconnected through the internal bus, and the internal bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 8 only a bidirectional arrow is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0164] The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operation instructions. The memory may include internal memory and non-volatile memory, and provide instructions and data to the processor.

[0165] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, forming a security protection device of the power monitoring system at the logical level. The processor executes the program stored in the memory and is specifically used to execute the aforementioned method.

[0166] A processor may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0167] The electronic device can execute the security protection method of the power monitoring system provided in multiple embodiments of the present application and be implemented as a security protection device of the power monitoring system in Figure 7 the functions of the illustrated embodiments, which will not be elaborated herein in the embodiments of the present application.

[0168] The embodiments of the present application also propose a computer-readable storage medium. The computer-readable storage medium stores one or more programs. The one or more programs include instructions that, when executed by an electronic device including multiple application programs, can enable the electronic device to execute the security protection method of the power monitoring system provided in multiple embodiments of the present application.

[0169] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0170] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.

[0171] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.

[0172] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.

[0173] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0174] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.

[0175] A computer-readable medium includes permanent and non-permanent, removable and non-removable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transitory media that can be used to store information that can be accessed by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0176] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0177] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0178] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A safety protection method for an electric power monitoring system, characterized in that: The method comprises: Analyze multi-source data through a deep learning-based threat detection module to detect whether there are network threats; In response to detecting a network threat, inspecting network traffic of each node; In response to detecting abnormal network traffic at the first node, calculating a coordination factor between the first node and each node; Control the first node and the second node whose coordination factor meets the preset condition to execute the protection measure.

2. The method according to claim 1, characterized in that: The detecting of the network traffic of each node includes: Detect the network traffic of each node based on the trained convolutional neural network and distinguish between normal network traffic and abnormal network traffic; or Based on the trained convolutional neural network, the feature vector of the network traffic of each node is extracted, and the feature vector of the network traffic of each node is input into the trained generative adversarial network to identify normal network traffic and abnormal network traffic.

3. The method according to claim 1 or 2, characterized in that: The calculating the synergy factor between the first node and each node includes: Based on the physical distance and communication delay between the first node and each node, a cooperation factor between the first node and each node is calculated.

4. The method according to claim 1, characterized in that: The method further comprises: Monitor access devices in real time to confirm whether they have passed security authentication; Connect the certified access equipment to the power grid system.

5. The method according to claim 4, characterized in that The real-time monitoring of the access device to confirm whether the access device has passed the security authentication includes: Determine a behavioral feature vector of an access device; Calculate the legitimacy score of the access device based on the behavioral feature vector of the access device; If the legitimacy score of the access device is greater than the threshold, it is confirmed that the access device has passed the security authentication.

6. The method according to claim 4, characterized in that The real-time monitoring of the access device to confirm whether the access device has passed the security authentication further includes: Obtain the public key published by the access device on the blockchain; Receive the signature sent by the access device; Verify the signature of the access device based on the public key to determine whether the access device has passed the security authentication.

7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: Calculate the real-time risk assessment coefficient of the access device based on the behavioral characteristics of the access device; Adjust the access level of the connected device based on the initial access level and real-time risk assessment factor.

8. A safety protection device for an electric power monitoring system, characterized in that: The device comprises: A first detection module is used to analyze multi-source data through a threat detection module based on deep learning to detect whether there is a network threat; In response to detecting a network threat, the second detection module is used to detect network traffic of each node; A processing module, configured to calculate a coordination factor between the first node and each node in response to detecting abnormal network traffic at the first node; The control module is used to control the first node and the second node whose coordination factor meets the preset conditions to execute the protection measures.

9. An electronic device, comprising: processor; as well as A memory arranged to store computer executable instructions, characterized in that when the executable instructions are executed, the processor executes the steps of the safety protection method for the power monitoring system as described in any one of claims 1-7.

10. A computer-readable storage medium storing one or more programs, characterized in that: When the one or more programs are executed by an electronic device including a plurality of application programs, the electronic device executes the steps of the safety protection method for the power monitoring system as described in any one of claims 1-7.

Citation Information

Cited By

  • Multi-stage protection method and system for electric power system

    CN120528711A