Electric power closed source terminal system risk alarm method based on graph database model
Through the risk alerting method of power closed source terminal system based on graph database model, the problem that existing technology is difficult to effectively deal with complex network security threats is solved, and more accurate threat identification and more efficient security protection are achieved.
Patent Information
- Application Number
- CN202510159540.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-03
AI Technical Summary
When existing power closed-source terminal systems face increasingly complex network security threats, it is difficult to effectively identify and respond to advanced threats, resulting in rising security risks.
The risk alarm method of power closed source terminal system based on the graph database model is adopted. By saving attack source diagrams, generating IIP diagrams, and TPG diagrams, and using threat scoring algorithms to perform threat assessments, comprehensive threat assessments and risk warnings are provided.
This method can more accurately identify and prioritize potential high-risk threats, significantly improve the effectiveness of network security protection, and reduce the impact of security accidents on system stability.
Smart Images

Figure CN120090824A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of power systems, and particularly to a risk warning method for a power closed-source terminal system based on a graph database model. Background Art
[0002] The risk warning method for a power closed-source terminal system is a method for monitoring the safe operation of a power system. With the rapid progress of information technology, the power system is gradually moving towards automation and intelligence. Especially for the power closed-source terminal system, its security in the power grid has a crucial impact on the stable operation of the power system. With the continuous development of technology, people's requirements for the manufacturing process of the risk warning method for the power closed-source terminal system are also getting higher and higher.
[0003] There are certain drawbacks in the existing power closed-source terminal systems during use. With the increase of network security risks in recent years, the security problems faced by power closed-source terminal devices are becoming increasingly severe. On the one hand, some key security devices have gradually become obsolete and cannot effectively resist modern network attack means; on the other hand, in addition to traditional virus attacks, attackers may launch APT advanced threat attacks by taking advantage of system vulnerabilities. The long-term lurking of hackers or malicious programs may lead to data leakage, service interruption or further damage, bringing serious impacts on social stability and people's lives. At the same time, due to the lack of professional security management and operation and maintenance personnel, the system is also difficult to quickly respond to various security problems. These problems have led to the security risks faced by the power closed-source terminal system becoming more and more severe. Against the background of the increasingly complex network security environment today, the security risks faced by the power closed-source terminal system are constantly rising. These power systems often form a part of critical infrastructure, so their security is particularly crucial for the stable operation of the overall power system. Therefore, it is particularly crucial to build and implement an efficient security risk warning plan. For this reason, we propose a risk warning method for a power closed-source terminal system based on a graph database model. Summary of the Invention
[0004] Technical problems to be solved: Aiming at the deficiencies of the prior art, the present invention provides a risk warning method for a power closed-source terminal system based on a graph database model, provides a risk warning model for the power closed-source terminal system, more effectively responds to the increasingly severe network security challenges, further strengthens the overall security protection level, ensures the stable and reliable operation of the power system, and can effectively solve the problems in the background art.
[0005] Technical solution: To achieve the above purpose, the technical solution adopted by the present invention is: A risk warning method for a power closed-source terminal system based on a graph database model, specifically including the following operation steps:
[0006] S1: Save the attack source graph based on the graph database: The high-definition trace data generated by the closed-source terminal undergoes rule matching to generate IOA alarm events. Both the original events and the alarm events are stored in the attack source graph database and saved based on the graph database model. IOA is an indicator used to detect and identify network attacks, indicating signs of possible attack activities. IOA pays more attention to the behavior and activities of attacks rather than just the results or consequences of attacks;
[0007] S2: Generate the IIP graph based on the attack source graph: Generate the IIP graph from the attack source graph. Based on any alarm in the attack source graph, use the forward-tracking search method to identify the initial infection point vertex, that is, the first vertex that generates a threat alarm in the timeline. Then, based on the IIP vertex, connect all the alarms backward to form the IIP graph. IIP is to identify the initial infection point;
[0008] S3: Generate the TPG graph based on the IIP graph: Generate the TPG graph from the IIP graph. In the IIP graph, if two alarms Ea and Eb meet one of the following conditions, an ordered edge can be generated between Ea and Eb. TPG is the tactical source graph;
[0009] S4: Threat scoring algorithm based on the TPG graph: The score of each technical point in the technical knowledge base framework can be associated with the CAPEC metadata, and the two indicators of attack likelihood and severity defined therein are used for scoring. The values of these two indicators range from 1 to 5. CAPEC metadata is a public classification available for attack patterns, with additional comprehensive planning and classification methods;
[0010] S5: Threat assessment: When conducting threat assessment, it is necessary to consider the severity and likelihood of the alarms, as well as the order between the alarms and the consistency of the tactical phases, so as to provide a comprehensive threat assessment. The security team can more accurately identify and prioritize potential high-risk threats, enhancing the effectiveness of network security protection.
[0011] As a preferred technical solution of this application, the algorithm performance of the risk alarm model in the S1 - S5 steps is crucial for timely identifying and responding to security threats. By comparing and analyzing the performance of existing risk alarm model algorithms, we can better understand the advantages and limitations of each algorithm, thereby providing a basis for selecting the appropriate algorithm.
[0012] As a preferred technical solution of this application, the risk alarm model in the S1 - S5 steps includes a general risk alarm model and a risk alarm model for specific attack and threat scenarios.
[0013] As a preferred technical solution of this application, the general risk alarm model specifically includes the following content:
[0014] A1: Define risk factors: First, it is necessary to clearly define the factors related to the risks of concern, including various data characteristics, indicators, and rules, such as historical data, behavior patterns, anomaly detection, and geographical locations;
[0015] A2: Data collection and preprocessing: Collect and organize data related to risks, involving preprocessing steps such as data cleaning, data transformation, and feature engineering to make the data suitable for model input;
[0016] A3: Model selection and training: Select appropriate machine learning and statistical models according to the characteristics of the problem, including decision trees, logistic regression, support vector machines, neural networks, use historical data for model training, and use techniques such as cross-validation for model selection and tuning;
[0017] A4: Feature weight learning: Through feature weight learning during model training, obtain the importance of different features, which can help the model better capture features related to risks;
[0018] A5: Risk score calculation: Use the trained model and weights to calculate the scores for new risk events, involving feature transformation and normalization of the input data and inputting it into the model for prediction;
[0019] A6: Threshold setting: To convert the scores into risk levels, an appropriate threshold needs to be set, which can be adjusted according to actual needs and risk tolerance;
[0020] A7: Risk alert output: According to the scores and thresholds, classify risk events into different risk levels, such as low risk, medium risk, and high risk, and provide accurate risk descriptions and corresponding recommended measures;
[0021] A8: Model evaluation and iteration: Regularly evaluate the performance of the model and make adjustments and improvements according to actual results, including updating the model with new data, introducing new features and algorithms.
[0022] As a preferred technical solution of this application, the risk alert model for specific attack and threat scenarios specifically includes the following:
[0023] B1: Scenario definition: Clearly define specific attack or threat scenarios, including network intrusion, malware, social engineering. For each scenario, it is necessary to understand the characteristics, patterns, and behaviors of the attack;
[0024] B2: Data collection and annotation: Collect data related to specific scenarios and perform annotation, involving attack logs, network traffic, malicious files. The annotated data will help the model learn and understand the attack characteristics in specific scenarios;
[0025] B3: Feature Extraction and Selection: According to the characteristics of a specific scenario, select appropriate features for extraction, including network traffic features, file attributes, and user behavior. Appropriate feature selection and extraction will help the model better capture the characteristics of attacks;
[0026] B4: Model Selection and Training: Select an appropriate machine learning or deep learning model according to the scenario characteristics, involving traditional machine learning algorithms and deep learning models. Use labeled data for model training, and use techniques such as cross-validation for model selection and optimization;
[0027] B5: Risk Alarm Output: According to the trained model and labeled data, conduct risk assessment and alarm output for new data. The model can determine whether the input data belongs to a specific attack or threat scenario, and provide corresponding risk levels and recommended countermeasures;
[0028] B6: Model Evaluation and Iteration: Regularly evaluate the performance of the model, and make adjustments and improvements according to the actual results. New data can be used for model update, introducing more features or algorithms, and continuously improving the model.
[0029] As a preferred technical solution of this application, in the S1-S5 steps, the risk alarm model of the power closed-source terminal system is tested and verified to ensure its accuracy and reliability. Simulate attacks and introduce known threats to test the system's response and accuracy, and improve the risk model and alarm mechanism according to the test results and actual feedback.
[0030] As a preferred technical solution of this application, in the S1-S5 steps, threat alarm is a warning issued by the security system after detecting any infringement or unusual behavior. It has a unique alarm ID, alarm type, ID of associated assets, timestamp of the event occurrence, and severity classification based on the impact and urgency caused. Timely analysis of these reports can help quickly face potential security hazards, thus ensuring the stable security of the entire system.
[0031] As a preferred technical solution of this application, in the S1-S5 steps, a risk alarm data monitoring and processing system is set up, including a historical data monitoring module, a behavior pattern monitoring module, an anomaly detection monitoring module, a geographical location monitoring module, a data collection module, a data preprocessing module, a central processing module, an alarm module, and a display module. The output ends of the historical data monitoring module, the behavior pattern monitoring module, the anomaly detection monitoring module, and the geographical location monitoring module are connected to the data collection module. The output end of the data collection module is connected to the data preprocessing module. The output end of the data preprocessing module is connected to the central processing module. The output end of the central processing module is connected to the alarm module and the display module.
[0032] Beneficial effects: Compared with the prior art, the present invention provides a risk warning method for a power closed-source terminal system based on a graph database model, having the following beneficial effects: For this risk warning method for a power closed-source terminal system based on a graph database model, in order to prevent in advance or respond quickly and reduce damages, high-definition trace data is collected on the closed-source terminal, and a risk warning model is constructed to deeply study network behaviors and various activities of the system, and thus hidden security risks can be detected at all times.
[0033] The risk warning model can also utilize artificial intelligence technologies such as machine learning and large models to adapt to this continuously changing environment, learn and identify new attack methods, thereby strengthening the defense level of the entire system.
[0034] The risk warning model can effectively improve the accuracy of threat detection, avoid false alarms of individual IOAs or IOCs generated based on high-definition trace data, and contribute to improving the work efficiency of secure operation. Based on accurate detection, various security events can be automatically processed, while reducing the dependence on artificial intervention factors, thereby optimizing the effectiveness of security operation. By adopting an automated analysis and response mechanism, not only can the response speed of events be significantly shortened, but also the workload of the security team can be reduced.
[0035] The continuous and stable operation of the power closed-source terminal system is crucial for ensuring the stability and reliability of power supply. By adopting the risk warning model, advanced threats that cannot be identified by traditional security products can be discovered and responded to in a timely manner, most effectively reducing the adverse effects of security incidents on the stability and reliability of the system.
[0036] Generally speaking, providing a risk warning model for the power closed-source terminal system is not only necessary but also an urgent requirement. This technology can help these devices more effectively cope with the increasingly severe network security challenges, further strengthen the overall security protection level, ensure the stable and reliable operation of the power system, and the entire risk warning method for the power closed-source terminal system has a simple structure, convenient operation, and better use effects compared with traditional methods. Brief description of the drawings
[0037] Figure 1 It is the overall schematic diagram of a risk warning method for a power closed-source terminal system based on a graph database model of the present invention.
[0038] Figure 2 It is the schematic diagram of constructing a risk warning model for a specific scenario in a risk warning method for a power closed-source terminal system based on a graph database model of the present invention.
[0039] Figure 3 It is the schematic diagram of the first embodiment in a risk warning method for a power closed-source terminal system based on a graph database model of the present invention.
[0040] Figure 4 This is the second schematic diagram of the risk warning method for the power closed-source terminal system based on the graph database model in the present invention.
[0041] Figure 5 This is the third schematic diagram of the risk warning method for the power closed-source terminal system based on the graph database model in the present invention. Detailed implementation manners
[0042] The technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings and specific implementation manners. However, those skilled in the art will understand that the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments, and are only used to illustrate the present invention and should not be construed as limiting the scope of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention. For those conditions not specified in the embodiments, they shall be carried out according to the conventional conditions or the conditions recommended by the manufacturer. Those reagents or instruments not specified by the manufacturer can be obtained as conventional products through commercial purchase.
[0043] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the present invention. In addition, the terms "first", "second", "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0044] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0045] As Figures 1-5 shown, a risk warning method for a power closed-source terminal system based on a graph database model specifically includes the following operation steps:
[0046] S1: Save the attack source graph based on the graph database: The high-definition trace data generated by the closed-source terminal undergoes rule matching to generate IOA alarm events. Both the original events and the alarm events are stored in the attack source graph database and saved based on the graph database model. IOA is a metric used to detect and identify network attacks, indicating signs of possible attack activities. IOA focuses more on the behavior and activities of attacks rather than just the results or consequences of the attacks;
[0047] S2: Generate the IIP graph based on the attack source graph: Generate the IIP graph from the attack source graph. Based on any alarm in the attack source graph, use a forward-tracking search method to identify the initial infection point vertex, which is the first vertex in the timeline that generates a threat alarm. Then, based on the IIP vertex, connect all the alarms backward to form the IIP graph. IIP is to identify the initial infection point;
[0048] S3: Generate the TPG graph based on the IIP graph: Generate the TPG graph from the IIP graph. In the IIP graph, if two alarms Ea and Eb satisfy one of the following conditions, an ordered edge can be generated between Ea and Eb. TPG is the tactical source graph;
[0049] S4: Threat scoring algorithm based on the TPG graph: The score of each technical point in the technical knowledge base framework can be associated with CAPEC metadata and scored using two metrics, attack likelihood and severity, defined therein. The values of these two metrics range from 1 to 5. CAPEC metadata is a public classification available for attack patterns, with additional comprehensive planning and classification methods;
[0050] S5: Threat assessment: Conducting threat assessment requires considering the severity and likelihood of alarms, as well as the order between alarms and the consistency of tactical phases, so as to provide a comprehensive threat assessment. The security team can more accurately identify and prioritize potential high-risk threats, enhancing the effectiveness of network security protection.
[0051] Provide a risk alarm model for the power closed-source terminal system, more effectively respond to the increasingly severe network security challenges, further strengthen the overall security protection level, and ensure the stable and reliable operation of the power system.
[0052] Furthermore, the algorithm performance of the risk alarm model in steps S1 - S5 is crucial for timely identifying and responding to security threats. By comparing and analyzing the performance of existing risk alarm model algorithms, we can better understand the advantages and limitations of each algorithm, thus providing a basis for selecting the appropriate algorithm.
[0053] Furthermore, the risk alarm model in steps S1 - S5 includes a general risk alarm model and a risk alarm model for specific attack and threat scenarios.
[0054] Furthermore, the general risk warning model specifically includes the following content:
[0055] A1: Define risk factors: First, it is necessary to clearly define the factors related to the risks of concern, including various data characteristics, indicators, and rules, such as historical data, behavior patterns, anomaly detection, and geographical locations;
[0056] A2: Data collection and preprocessing: Collect and organize data related to risks, involving preprocessing steps such as data cleaning, data transformation, and feature engineering to make the data suitable for model input;
[0057] A3: Model selection and training: Select appropriate machine learning and statistical models according to the characteristics of the problem, including decision trees, logistic regression, support vector machines, and neural networks. Use historical data for model training, and use techniques such as cross-validation for model selection and tuning;
[0058] A4: Feature weight learning: Through feature weight learning during the model training process, obtain the importance of different features, which can help the model better capture features related to risks;
[0059] A5: Risk score calculation: Use the trained model and weights to calculate the scores for new risk events, involving feature transformation and normalization of the input data, and inputting it into the model for prediction;
[0060] A6: Threshold setting: In order to convert the scores into risk levels, appropriate thresholds need to be set, which can be adjusted according to actual needs and risk tolerance;
[0061] A7: Risk warning output: According to the scores and thresholds, classify risk events into different risk levels, such as low risk, medium risk, and high risk, and provide accurate risk descriptions and corresponding recommended measures;
[0062] A8: Model evaluation and iteration: Regularly evaluate the performance of the model, and make adjustments and improvements according to the actual results, including updating the model with new data, introducing new features and algorithms.
[0063] Furthermore, the risk warning model for specific attack and threat scenarios specifically includes the following content:
[0064] B1: Scenario definition: Clearly define specific attack or threat scenarios, including network intrusion, malware, and social engineering. For each scenario, it is necessary to understand the characteristics, patterns, and behaviors of the attack;
[0065] B2: Data collection and annotation: Collect data related to specific scenarios and perform annotation, which involves attack logs, network traffic, and malicious files. The annotated data will help the model learn and understand the attack characteristics in specific scenarios;
[0066] B3: Feature extraction and selection: According to the characteristics of specific scenarios, select appropriate features for extraction, including network traffic features, file attributes, and user behavior. Appropriate feature selection and extraction will help the model better capture the characteristics of attacks;
[0067] B4: Model selection and training: Select appropriate machine learning or deep learning models according to the scenario characteristics, which involves traditional machine learning algorithms and deep learning models. Use the annotated data for model training, and use techniques such as cross-validation for model selection and tuning;
[0068] B5: Risk warning output: According to the trained model and the annotated data, conduct risk assessment and warning output for new data. The model can determine whether the input data belongs to a specific attack or threat scenario, and provide the corresponding risk level and recommended countermeasures;
[0069] B6: Model evaluation and iteration: Regularly evaluate the performance of the model, and make adjustments and improvements according to the actual results. New data can be used for model update, more features or algorithms can be introduced, and continuous improvement of the model can be carried out.
[0070] Furthermore, in steps S1 - S5, the risk warning model of the power closed-source terminal system is tested and verified to ensure its accuracy and reliability. Simulate attacks and introduce known threats to test the system's response and accuracy, and improve the risk model and warning mechanism according to the test results and actual feedback.
[0071] Furthermore, in steps S1 - S5, threat warning is a warning issued by the security system after detecting any infringement or unusual behavior. It has a unique warning ID, warning type, ID of associated assets, timestamp of the event occurrence, and severity classification based on the impact and urgency caused. Timely analysis of these reports can help quickly face potential security risks, thus ensuring the stable security of the entire system.
[0072] Further, in steps S1 - S5, a risk warning data monitoring and processing system is set up, including a historical data monitoring module, a behavior pattern monitoring module, an anomaly detection monitoring module, a geographical location monitoring module, a data collection module, a data pre - processing module, a central processing module, an alarm module, and a display module. The output ends of the historical data monitoring module, the behavior pattern monitoring module, the anomaly detection monitoring module, and the geographical location monitoring module are connected to the data collection module. The output end of the data collection module is connected to the data pre - processing module. The output end of the data pre - processing module is connected to the central processing module. The output end of the central processing module is connected to the alarm module and the display module.
[0073] Embodiment:
[0074] Detection of the attack scenario of the Silver Fox Trojan
[0075] During the process of designing and evaluating a specific scenario risk warning model, applied research has become a key factor in understanding how the model can be applied in an actual operating environment. Next, a case study of the application specifically for the "Silver Fox" attack scenario is provided, including the model construction process and the practical application explanation of the code.
[0076] As a Trojan virus that has become relatively popular since 2023, the Silver Fox Trojan spreads through phishing emails, IM chat tools, etc. It controls the victim's WeChat to establish group chats for financial fraud. Common anti - detection methods of the Silver Fox Trojan include white - plus - black, encrypted payload, memory loading, etc. The steps for model construction are as follows:
[0077] Step 1: Analyze the attack scenario of the Silver Fox Trojan
[0078] During the detection process of this attack scenario, first, analyze the attack process of the Silver Fox Trojan and select the attack features to be concerned about.
[0079] Silver Fox Trojan variant 1: The sample is in the executable file format and spreads through phishing emails, WeChat, etc. It is packaged through SetupFactory, which increases the difficulty of analysis. During the execution process, it repeatedly uses the white - plus - black and decompression of encrypted packages to release malicious programs, and these compressed packages all have passwords. Some passwords come from the encoding in the script released from memory, and some passwords are the decompression passwords hard - coded in the "white file". In addition, this program is carefully written. The program released in the early stage seems to be a picture, but actually uses the Overlay at the end of the picture to load the Shellcode in the final stage;
[0080] Silver Fox Trojan Variant 2: The sample is also in the executable file format and is spread through phishing emails, WeChat, etc. The overall execution logic of Variant 2 is similar to that of Variant 1, but the difference lies in changing the release method of the malicious sample: from SetupFactory in Variant 1 to a self-written Loader program in Variant 2. After that, the rest of the behavior remains unchanged;
[0081] Silver Fox Trojan Variant 3: The sample is in the CHM document format or VBS script format. After running the CHM, it executes the embedded HTML file in memory and loads malicious JS code (some samples are in VBS format, and the code function and format are the same as the JS code). This JS code is generated by modifying with DotNetToJScript and loads.NET malicious code in memory. Subsequently, the.NET malicious code writes to the configuration file by reading internal strings, and accesses the cloud service object storage (OSS) to download and execute multiple files by calling the shellcode stored in the array;
[0082] Silver Fox Trojan Variant 4: The sample is in the.MSI format. This variant releases multiple components through MSI and calls BAT to run the executable program; after two decryption and loading operations, it executes the GhostRAT malicious code in the memory space of the white sample and accepts the control of the attacker.
[0083] Step 2: Sample Collection and Preprocessing
[0084] Collect Silver Fox Trojan samples, including the sample set and the test set, and conduct a detailed behavior analysis on the sample data of the sample set, especially the behaviors related to file download sources, code injection characteristics, memory decryption characteristics, IP external connection characteristics, etc. It is necessary to clean these data, delete irrelevant content, and save key information, and at the same time, these key information should also be included in the detailed information of IOA and IOC alarms.
[0085] Step 3: Feature Extraction
[0086] According to the collected sample behavior data, extract the following features: file download source, memory injection characteristics, injected code binary characteristics, memory decryption characteristics, external connection to malicious domains, etc.
[0087] Step 4: Model Selection and Calculation Formula
[0088] Select and adopt the above risk warning model algorithm calculation formula, set the weight of each feature for these feature values of the Silver Fox Trojan, and set the threshold of weighted summation to test the effectiveness of the detection model.
[0089] Step 5: Implementation and Monitoring
[0090] Using the test set samples and by means of cross - validation, the overall performance of the model can be accurately evaluated, and it is ensured that the model has the ability to generalize and detect new attack samples that have not been observed.
[0091] Step 6: Actual deployment in the product
[0092] Deploying this model in an actual system can effectively detect known and unknown attacks of the Silver Fox Trojan.
[0093] Test data description:
[0094] In the applied research of the "Silver Fox" attack scenario, the test results of this model are shown in the following table:
[0095]
[0096]
[0097] In the above table, the accuracy rate, recall rate, and F1 - score of each feature are listed. The accuracy rate represents the proportion of the model correctly predicting Silver Fox attacks or non - Silver Fox attacks; the recall rate represents the proportion of samples that are actually Silver Fox being correctly predicted as Silver Fox; the F1 - score is the harmonic mean of the accuracy rate and the recall rate, which is used to comprehensively evaluate the performance of the model.
[0098] Using this table, it can be clearly seen that the model performance is affected by various features. For example, the features of injected code binary signature and externally connected malicious domain names perform relatively well in terms of accuracy and recall rate. However, in some cases, the features of file download source and memory injection may not be ideal. Our research data can help determine which key features are crucial in detecting the "Silver Fox" attack and provide ideas for optimizing the entire model to improve efficiency.
[0099] In this applied research, the above - mentioned processes and technical means have been successfully applied to construct and complete a risk reporting model for the "Silver Fox" Trojan attack. This model can also be applicable to the detection of other types of attack scenarios, providing an additional protection layer for the closed - source terminal system of electricity.
[0100] It should be noted that in this text, relational terms such as first and second (No. 1, No. 2, etc.) are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.
[0101] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only to illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed.
Claims
1. A risk warning method for closed-source power terminal system based on a graph database model, characterized in that: The specific steps include the following: S1: Save attack source graph based on graph database: The high-definition trace data generated by the closed-source terminal generates IOA alarm events through rule matching. The original events and alarm events are stored in the attack source graph database and saved based on the graph database model. IOA is an indicator used to detect and identify network attacks. It is used to indicate signs of possible attack activities. IOA focuses more on the behavior and activities of the attack, not just the results or consequences of the attack. S2: Generate IIP graph based on attack source graph: Generate IIP graph from attack source graph. Based on any alarm in the attack source graph, use forward tracking to identify the initial infection point vertex, that is, the first vertex in the timeline that generates a threat alarm. Then, based on the IIP vertex, connect all alarms backward to form an IIP graph. IIP is used to identify the initial infection point. S3: Generate TPG graph based on IIP graph: Generate TPG graph from IIP graph. In IIP graph, if there are two alarms Ea and Eb that meet one of the following conditions, an ordered edge can be generated between Ea and Eb, and TPG is a tactical source graph; S4: Threat scoring algorithm based on TPG graph: The score of each technical point in the technical knowledge base framework can be associated with the CAPEC metadata, and the score is performed using the two indicators of attack possibility and severity defined therein. The values of these two indicators range from 1 to 5. CAPEC metadata is a public classification that provides attack patterns, with an additional comprehensive plan and classification method. S5: Threat Assessment: Threat assessment needs to consider the severity and likelihood of the alerts, as well as the sequence between alerts and the consistency of tactical stages, to provide a comprehensive threat assessment. Security teams can more accurately identify and prioritize potential high-risk threats and enhance the effectiveness of network security protection.
2. According to claim 1, a method for warning risk of closed-source power terminal system based on graph database model is characterized by: The algorithm performance of the risk warning model in steps S1-S5 is crucial for timely identification and response to security threats. By comparing and analyzing the performance of existing risk warning model algorithms, we can better understand the advantages and limitations of each algorithm, thereby providing a basis for selecting an appropriate algorithm.
3. According to claim 1, a method for warning risk of closed-source power terminal system based on a graph database model is characterized in that: The risk warning model in steps S1-S5 includes a general risk warning model and a risk warning model for specific attack and threat scenarios.
4. According to claim 3, a method for warning risk of a closed-source power terminal system based on a graph database model is characterized in that: The general risk warning model specifically includes the following contents: A1: Define risk factors: First, you need to clearly define the factors related to the risks of concern, including various data features, indicators and rules, such as historical data, behavioral patterns, anomaly detection, and geographic location; A2: Data collection and preprocessing: Collect and organize risk-related data, involving preprocessing steps such as data cleaning, data conversion, and feature engineering to make the data suitable for model input; A3: Model selection and training: Select appropriate machine learning and statistical models according to the characteristics of the problem, including decision trees, logistic regression, support vector machines, and neural networks. Use historical data for model training, and use cross-validation and other techniques for model selection and tuning. A4: Feature weight learning: The importance of different features can be obtained through feature weight learning during model training, which can help the model better capture risk-related features. A5: Risk score calculation: Use the trained model and weights to calculate the score of new risk events, which involves feature conversion and normalization of the input data, and inputting it into the model for prediction; A6: Threshold setting: In order to convert the score into a risk level, an appropriate threshold needs to be set, which can be adjusted according to actual needs and risk tolerance; A7: Risk warning output: Based on the scores and thresholds, risk events are classified into different risk levels, such as low risk, medium risk, and high risk, and accurate risk descriptions and corresponding recommended measures can be provided; A8: Model evaluation and iteration: Regularly evaluate the performance of the model and make adjustments and improvements based on actual results, including using new data to update the model and introducing new features and algorithms.
5. According to claim 3, a method for warning risk of closed-source power terminal system based on graph database model is characterized in that: The risk warning model for specific attack and threat scenarios includes the following: B1: Scenario definition: Clearly define specific attack or threat scenarios, including network intrusion, malware, and social engineering. For each scenario, you need to understand the characteristics, patterns, and behaviors of the attack; B2: Data collection and annotation: Collect and annotate data related to specific scenarios, including attack logs, network traffic, and malicious files. Annotated data will help the model learn and understand the attack characteristics in specific scenarios. B3: Feature extraction and selection: According to the characteristics of a specific scenario, select appropriate features for extraction, including network traffic characteristics, file attributes, and user behavior. Appropriate feature selection and extraction will help the model better capture the characteristics of attacks. B4: Model selection and training: Select appropriate machine learning or deep learning models based on scenario characteristics, involving traditional machine learning algorithms and deep learning models, using labeled data for model training, and using cross-validation and other techniques for model selection and tuning; B5: Risk warning output: Based on the trained model and labeled data, new data is evaluated for risk and warned. The model can determine whether the input data belongs to a specific attack or threat scenario, and provide the corresponding risk level and recommended countermeasures. B6: Model evaluation and iteration: Regularly evaluate the performance of the model and make adjustments and improvements based on actual results. You can use new data to update the model, introduce more features or algorithms, and continuously improve the model.
6. According to claim 1, a method for warning risk of closed-source power terminal system based on graph database model is characterized by: In the steps S1-S5, the risk warning model of the closed-source power terminal system is tested and verified to ensure its accuracy and reliability. The system's response and accuracy are tested by simulating attacks and introducing known threats. The risk model and warning mechanism are improved based on the test results and actual feedback.
7. The method for risk warning of electric power closed-source terminal system based on graph database model according to claim 1 is characterized in that: The threat alarm in steps S1-S5 is a warning issued by the security system after detecting any intrusion or unusual behavior. It has a unique alarm ID, alarm type, ID of the associated asset, timestamp of the event, and severity classification based on the impact and urgency. Timely analysis of these reports can help to quickly address potential security risks, thereby ensuring the stability and security of the entire system.
8. The method for risk warning of electric power closed-source terminal system based on graph database model according to claim 1 is characterized in that: In the steps S1-S5, a risk warning data monitoring and processing system is set up, including a historical data monitoring module, a behavior pattern monitoring module, an anomaly detection monitoring module, a geographic location monitoring module, a data acquisition module, a data preprocessing module, a central processing module, an alarm module and a display module. The output ends of the historical data monitoring module, the behavior pattern monitoring module, the anomaly detection monitoring module and the geographic location monitoring module are connected to the data acquisition module, the output end of the data acquisition module is connected to the data preprocessing module, the output end of the data preprocessing module is connected to the central processing module, and the output end of the central processing module is connected to the alarm module and the display module.